igneum/tools/ci/commit-tz-check.sh
igneum-labs 64780403e1 relay: three auth tiers, signed run tasks, machine secrets, retention; clients on headers; TZ=UTC and curl -K checks (X23 X24 X25 X26 X27 X28 X29 G13 G14)
Relay (X23, X27): the intake key is its own tier (upload and file drops only, RELAY_INTAKE_COMPAT=0 closes it);
a run task needs an Ed25519 signature by the Mac run key over {to, nonce, body sha256, flags} (RELAY_RUN_PUB,
401 without) and an HMAC tag with the target's machine secret that the agent verifies before anything runs;
results and registration are bound to the machine the secret proves (403 on a forged from).
X24: every client and Mac tool sends x-relay-token as a header to /api/relay?fn=; the path token stays for the
phone page only. X25: the agent arms the logon task only for a restart a task asked for and disarms on start
and exit. X26: 30-day retention with blob deletion, feed capped at 100, the dl base as RELAY_DL_BASE held by the
agent, never in a body. X28: GET inbox never acks (POST inbox does), RELAY-REBOOT on its own line and only with a
reboot flag, 120/min and 10 failed auths/min per IP, no username or folder on register, WSL sudo scoped to
apt-get and dpkg with SETENV, no password on a command line. X29: the intake key reaches curl through -K in
upload.sh and both upload-log.bat; tools/ci/curl-header-check.sh fails the class. G14: TZ=UTC in ship-app.mjs
and publish-jobs.sh; tools/ci/commit-tz-check.sh fails the class; history-rewrite.md names the .old-2026-10-05
files as the values in the history. The handler moved to relay/lib/handler.mjs with injected sql and blobs
(relay/lib/blob.mjs holds @vercel/blob) so relay/test/handler.test.mjs drives it without a database:
47 tests across 6 suites, all green.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 18:46:13 +00:00

35 lines
2.3 KiB
Bash
Executable file

#!/usr/bin/env bash
# Every commit path the tooling owns runs git with TZ=UTC, so no commit carries the local offset (review round 4,
# ledger G14; docs/plans/history-rewrite.md step 7). The class check (standing rule, 5 October 2026): any script under
# tools/, packaging/, infra/ or .github/ that invokes `git commit` (shell) or `['commit'` (node) must set TZ=UTC in
# the same file, or this fails. It also prints how many commits on the current branch still carry a non-UTC offset
# (the history rewrite is the owner's date; the count is information, not a failure).
#
# bash tools/ci/commit-tz-check.sh [--self-test]
set -euo pipefail
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
check_tree() { # <root> -> 0 when clean; prints offenders
local root="$1" bad=0 f
while IFS= read -r f; do
if grep -Eq "git commit|git\\b.*\\['commit'|\\['commit',|\"commit\"," "$f" 2>/dev/null; then
if ! grep -Eq "TZ=UTC|TZ: 'UTC'|TZ: \"UTC\"" "$f"; then echo "commit without TZ=UTC: ${f#$root/}"; bad=1; fi
fi
done < <(find "$root/tools" "$root/packaging" "$root/infra" "$root/.github" -type f \( -name '*.sh' -o -name '*.mjs' -o -name '*.js' -o -name '*.yml' -o -name '*.yaml' -o -name '*.py' \) 2>/dev/null | grep -v '/node_modules/' | grep -v '/fixtures/')
return $bad
}
if [ "${1:-}" = "--self-test" ]; then
T="$(mktemp -d)"; trap 'rm -rf "$T"' EXIT
mkdir -p "$T/tools" "$T/packaging" "$T/infra" "$T/.github"
printf '#!/bin/sh\nexport TZ=UTC\ngit commit -m x\n' > "$T/tools/good.sh"
printf "const git = a => run('git', a, { env: { TZ: 'UTC' } }); git(['commit', '-m', 'x']);\n" > "$T/tools/good.mjs"
check_tree "$T" >/dev/null || { echo "self-test: the clean tree failed"; exit 1; }
printf '#!/bin/sh\ngit commit -m x\n' > "$T/packaging/bad.sh"
if check_tree "$T" >/dev/null; then echo "self-test: the bad tree passed"; exit 1; fi
echo "commit-tz-check self-test: fires on the bad case, passes the good one"
exit 0
fi
if check_tree "$ROOT"; then echo "commit-tz-check: every tooling commit path sets TZ=UTC"; else exit 1; fi
if git -C "$ROOT" rev-parse --is-inside-work-tree >/dev/null 2>&1; then
n="$(git -C "$ROOT" log --format='%ad %cd' --date=raw 2>/dev/null | grep -cvE '^\S+ \+0000 \S+ \+0000$' || true)"
echo "commits on this branch with a non-UTC offset (author or committer): $n (0 after the history rewrite, docs/plans/history-rewrite.md)"
fi