igneum/tools/ci/founder-strings-check.sh
igneum-labs 09c2634d2c Pre-public scrub, second pass (7 October 2026, 20:0x UK, main's rulings 2 and 4): the public tree names igneum-labs only; the public ledger generated from the full ledger
Ruling 2: every tracked text mention of the login's pre-rename spelling becomes igneum-labs (29 files); the commit identity in the scripts becomes igneum-labs <337424239+igneum-labs@users.noreply.github.com> (the same noreply id); the three scripts that hand the stored gh keyring name to gh (register.sh, fetch-ci-artifacts.sh, ship-app.mjs) read it from ~/.config/igneum/gh-user (never in the repository), default igneum-labs; fresh-repo.sh reads the login to rewrite from the encoded list's row 10; the old spelling joins the founder-strings list, so no tracked file may spell it; CLAUDE.md's GitHub paragraph rewritten. The red watcher's self-test fixtures use a neutral author.

Ruling 4: docs/ledger-public.md, one row per ledger item (id, the claim in one line, status, what was done in one line, the evidence link or the evidence in words), generated by tools/ledger/export-public.mjs from docs/fud-ledger.md: no round or status-update sections, no commit ids, no time of day, no lane, agent or branch names. 190 items. The gate runs its self-test (a fixture with a commit id, a time, a lane and a branch name comes out clean; --check fails on drift) and its --check on every merge; the founder check reads the output like every tracked file.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-07 18:56:08 +00:00

66 lines
4.6 KiB
Bash
Executable file

#!/usr/bin/env bash
# No founder name, personal login, earlier business or personal address in any tracked text file (the pre-public scrub,
# 7 October 2026, main's item (4): forbidden strings over tracked files on every merge, known-failed first). The identity
# check (tools/ci/identity-check.sh) reads the public EXPORT list; this one reads EVERY tracked file, because the repository
# itself goes public at the testnet (docs/fud-fixes.md section 5).
#
# The patterns are not written in this tree in plain text: a plaintext list would be the hit it looks for. They live
# base64-encoded in tools/ci/founder-strings.b64 (one decoded line per pattern: perl regex, a tab, a sample the self-test plants;
# case-insensitive; # comments ignored)
# and are decoded into a private temporary file at run time. The login's pre-rename spelling is in the list too (main's ruling,
# 7 October 2026: the public tree names igneum-labs only); the fresh-repository step rewrites it in the history (tools/repo/fresh-repo.sh).
#
# tools/ci/founder-strings-check.sh # exit 1 with file:line for every hit over the tracked text files
# tools/ci/founder-strings-check.sh --self-test # a fixture tree with one hit per pattern class fails and names the file; a clean
# # fixture passes; the encoded list decodes to at least five patterns
set -euo pipefail
HERE="$(cd "$(dirname "$0")" && pwd)"
LIST="$HERE/founder-strings.b64"
REPO="${FOUNDER_CHECK_REPO:-$(cd "$HERE/../.." && pwd)}"
decode() { # [samples]: the regexes (or, with "samples", the sample per regex), one per line, into a 0600 file whose name is printed
local f col=1; [ "${1:-}" = samples ] && col=2
f="$(mktemp)"; chmod 600 "$f"
base64 -d < "$LIST" | grep -vE '^\s*(#|$)' | cut -f"$col" > "$f"
echo "$f"
}
scan() { # <repo>: every tracked text file against the decoded list; prints file:line:text, exit 1 on any hit (perl: the Mac's grep has no -P)
local repo="$1" pats hits
pats="$(decode)"
hits="$(cd "$repo" && git ls-files -z -- . ':!*.png' ':!*.jpg' ':!*.jpeg' ':!*.gif' ':!*.ico' ':!*.woff' ':!*.woff2' ':!*.ttf' ':!*.pdf' ':!*.zip' ':!*.bin' ':!*.b64' \
| xargs -0 perl -e '
my $pf = shift @ARGV; open(my $ph, "<", $pf) or die; my @pats = map { chomp; qr/$_/i } grep { /\S/ } <$ph>; close $ph;
for my $f (@ARGV) { next unless -f $f && -T $f; open(my $h, "<", $f) or next; my $n = 0;
while (my $l = <$h>) { $n++; for my $p (@pats) { if ($l =~ $p) { chomp $l; print "$f:$n:" . substr($l, 0, 160) . "\n"; last } } } close $h; }
' "$pats" 2>/dev/null || true)"
rm -f "$pats"
if [ -n "$hits" ]; then printf '%s\n' "$hits" | sed 's/^/founder-strings: /' >&2; return 1; fi
return 0
}
if [ "${1:-}" = "--self-test" ]; then
n="$(base64 -d < "$LIST" | grep -vcE '^\s*(#|$)')"
[ "$n" -ge 5 ] || { echo "self-test failed: the encoded list decodes to $n pattern(s), expected at least 5"; exit 1; }
fx="$(mktemp -d)"; trap 'rm -rf "$fx"' EXIT
( cd "$fx" && git init -q -b master . )
mkdir -p "$fx/docs"
# a clean tree: the standing login, the project, a neutral owner word
printf 'Commit as igneum-labs. The founder decided on 5 October 2026. Igneum Labs LTD, DIFC.\n' > "$fx/docs/clean.md"
( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m c )
FOUNDER_CHECK_REPO="$fx" bash "$0" >/dev/null 2>&1 || { echo "self-test failed: a clean tree was reported"; exit 1; }
# one hit per pattern class, each from the encoded list's own sample column, so this script never spells them; every hit
# must name its file
samples="$(decode samples)"; i=0; fails=0
while IFS= read -r word; do
i=$((i + 1)); [ -n "$word" ] || continue
printf 'a line that names %s in passing\n' "$word" > "$fx/docs/hit-$i.md"
( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "h$i" )
if out="$(FOUNDER_CHECK_REPO="$fx" bash "$0" 2>&1)"; then echo "self-test failed: pattern $i was not caught"; fails=1
else case "$out" in *"docs/hit-$i.md"*) ;; *) echo "self-test failed: the hit for pattern $i did not name its file: $out"; fails=1 ;; esac; fi
rm -f "$fx/docs/hit-$i.md"; ( cd "$fx" && git add -A && git -c user.name=t -c user.email=t@t commit -q -m "r$i" )
done < "$samples"; rm -f "$samples"
# a binary file carrying a pattern is not read (images are not text)
[ "$fails" = 0 ] && echo "self-test passed: a clean tree passes; every pattern class in the encoded list is caught in a fixture file and named; the list decodes to $n patterns"
exit $fails
fi
scan "$REPO" && echo "founder-strings: no founder name, personal login, earlier business or personal address in any tracked text file"