#!/usr/bin/env bash # The root-socket class (5 October 2026, 20:00Z): a PC 2 job ran igneum-prove-host as root inside WSL2, which started # an sp1-gpu-server whose socket /tmp/sp1-cuda-0.sock stayed root-owned after the job; the live prover (the app's user) # then failed every shard with "CudaClientError: Connect(PermissionDenied)" until the socket was gone. Rule: every # playbook that runs the prover host as root on a shared card kills the server AND unlinks its socket (at the start # and at the end), or runs as the app's user. This check fails CI when a script runs `igneum-prove-host` under a # `-u root` WSL session without both lines. With file arguments it checks those files only (the jobs publisher runs it # on the script being published, packaging/ota/publish-jobs.sh add --kind run; a PC job never passes CI before it runs). set -euo pipefail cd "$(dirname "$0")/../.." fail=0 # the publisher's test writes a known-bad root prover script on purpose, to prove the publish refuses it ALLOW='^(packaging/ota/test-publish-jobs\.sh|tools/amd-prove/pc1-cpu-prove(-sp)?\.ps1)$' # pc1-cpu-prove: the CPU path starts no GPU server (its author's allow entry, 5 October 2026) list_files() { if [ $# -gt 0 ]; then printf '%s\n' "$@"; else git ls-files 'tools/**' 'relay/playbooks/**' 'proving/**' 'packaging/**' | grep -E '\.(sh|ps1|mjs)$'; fi; } while IFS= read -r f; do [[ "$f" =~ $ALLOW ]] && continue # a playbook that only runs `--mode id` or `--mode verify` starts no GPU server; the prove modes do if grep -qE 'igneum-prove-host' "$f" && grep -qE -- '--mode (compressed|chain|aggregate|block|shard|all)\b' "$f" && grep -qE -- '-u root' "$f"; then if ! grep -qE 'pkill -f sp1-gpu-server' "$f"; then echo "prover-socket: $f runs the prover host as root without killing sp1-gpu-server"; fail=1; fi if ! grep -qE 'rm -f /tmp/sp1-cuda-' "$f"; then echo "prover-socket: $f runs the prover host as root without unlinking /tmp/sp1-cuda-*.sock"; fail=1; fi fi done < <(list_files "$@") [ "$fail" = 0 ] && echo "prover-socket: every root prover playbook kills the GPU server and unlinks its socket" exit $fail