igneum/tools/ci/copied-sources-check.sh

21 lines
1.6 KiB
Bash
Executable file

#!/usr/bin/env bash
# The stale-build class (4 and 5 October 2026): a script copies a source tree to another machine (rsync, unzip, tar,
# Expand-Archive keep the Mac's file dates) and builds it there against a cargo target dir that survives between
# runs; cargo rebuilds by mtime, so sources older than the last build are taken as unchanged and the new code links
# against stale crates (shard run 2 on 4 October, the 0.3.6 PC build on 5 October). Rule: every script that copies
# sources and then runs cargo re-stamps the copied files (`touch`) before building. This check fails CI when a
# script copies AND builds without a touch. Scripts that copy binaries only are listed in the allow list below.
set -euo pipefail
cd "$(dirname "$0")/../.."
ALLOW='^(packaging/windows/make-payload\.sh|app/igneum-app/src/jobrun\.rs)$'
fail=0
while IFS= read -r f; do
[[ "$f" =~ $ALLOW ]] && continue
# code lines only: a comment that mentions rsync or cargo is not a copy or a build (tools/workers/collect.mjs, 6 October 2026)
code=$(grep -vE '^\s*(#|//|\*|/\*)' "$f")
if grep -qE 'rsync|unzip|tar -x|tar x|Expand-Archive|Copy-Item' <<<"$code" && grep -qE 'cargo (build|test)' <<<"$code"; then
if ! grep -qE '\btouch\b' <<<"$code"; then echo "copied-sources: $f copies sources and runs cargo without re-stamping them (touch)"; fail=1; fi
fi
done < <(git ls-files 'packaging/**' 'proving/**' 'infra/**' 'tools/**' 'relay/playbooks/**' 'app/igneum-app/src/**' | grep -E '\.(sh|ps1|mjs|rs)$')
[ "$fail" = 0 ] && echo "copied-sources: every copying build script re-stamps its sources"
exit $fail