igneum/tools/ci/pinned-guests-check.sh
igneum-labs 7f1884290a ci: the pinned-guests check ignores comment lines
Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 13:01:38 +00:00

37 lines
2.4 KiB
Bash
Executable file

#!/usr/bin/env bash
# The divergent-guest class (5 October 2026): the host used to compile the SP1 guests on whatever machine built it
# (`sp1_build::build_program` in host/build.rs), and the Mac's and PC 2's toolchains produced different ELFs, so
# the two nodes had different shard program ids and neither accepted the other's proofs. Rule: the guests are
# pinned under proving/igneum-prove/elf/ with a manifest of hashes and ids, the host embeds them, and only
# proving/igneum-prove/pin-guests.sh builds a guest. This check fails CI when (a) a committed elf/ file does not
# hash to the manifest, or (b) any script other than pin-guests.sh sets IGNEUM_BUILD_GUESTS, or calls
# `cargo prove build`, or builds a guest crate (-p igneum-prove-program / igneum-prove-aggregator) directly.
set -euo pipefail
cd "$(dirname "$0")/../.."
fail=0
E=proving/igneum-prove/elf
for f in manifest.json igneum-prove-program.elf igneum-prove-program.vk igneum-prove-aggregator.elf igneum-prove-aggregator.vk; do
[ -f "$E/$f" ] || { echo "pinned-guests: $E/$f is missing"; fail=1; }
done
if [ "$fail" = 0 ]; then
while IFS= read -r line; do
file="${line%% *}"; want="${line#* }"
got="0x$(shasum -a 256 "$E/$file" | cut -c1-64)"
if [ "$got" != "$want" ]; then echo "pinned-guests: $E/$file hashes to $got, the manifest says $want (run proving/igneum-prove/pin-guests.sh)"; fail=1; fi
done < <(python3 -c '
import json,sys
m=json.load(open(sys.argv[1]))
assert m["format"]=="igneum-prove-elf-manifest-v1", m["format"]
for k in ("shard","aggregator"):
print(m[k]["elf"], m[k]["elf_sha256"]); print(m[k]["vk"], m[k]["vk_sha256"])
' "$E/manifest.json")
fi
ALLOW='^(proving/igneum-prove/pin-guests\.sh|proving/igneum-prove/host/build\.rs|proving/igneum-prove/host/src/bin/pin\.rs|tools/ci/pinned-guests-check\.sh)$'
while IFS= read -r f; do
[[ "$f" =~ $ALLOW ]] && continue
if grep -vE '^\s*(//|#)' "$f" | grep -qE 'IGNEUM_BUILD_GUESTS=1|cargo prove build|-p igneum-prove-(program|aggregator)\b'; then # comments do not build
echo "pinned-guests: $f builds a guest outside pin-guests.sh (the host embeds the pinned elf/ files; never build a guest elsewhere)"; fail=1
fi
done < <(git ls-files 'packaging/**' 'proving/**' 'infra/**' 'tools/**' 'relay/playbooks/**' 'app/igneum-app/src/**' '.github/**' | grep -E '\.(sh|ps1|mjs|rs|yml|bat)$')
[ "$fail" = 0 ] && echo "pinned-guests: elf/ matches its manifest and no script builds a guest outside pin-guests.sh"
exit $fail