igneum/tools/ci
igneum-labs 2ed3dabe66 Jobs publisher: the class checks run on the script before it is signed (row C27)
A PC job is published from a worktree by packaging/ota/publish-jobs.sh and never passes CI before it runs; tonight
the root-socket fault came back from a job on a branch without the check. `add --kind run` now runs, on the script
being published and before anything is signed: tools/ci/bash-body-check.sh for a PowerShell script (every inline
bash body parses; a body it cannot read fails, never skips), `bash -n` for a .sh script, and
tools/ci/prover-socket-check.sh for both (a root prover run kills sp1-gpu-server and unlinks its socket). A failure
refuses the publish with the check's output; a missing check file refuses too. Kinds without a script (fetch,
collect, restart, update-now, shard-benchmark, build) are untouched.

tools/ci/prover-socket-check.sh is copied from proving-v1 (344cba8; master lacks it) with two additions: file
arguments check those files only (the publisher's call), and an allow list for packaging/ota/test-publish-jobs.sh,
which carries a known-bad root prover script on purpose. Its ci.yml step is left to proving-v1 to avoid a duplicate.

packaging/ota/test-publish-jobs.sh: four refusals (a lost quote in a PowerShell bash body, an unreadable body, a
.sh with a lost quote, a root prover script without the cleanup) and the envelope unchanged after a refusal.
32 passed, 0 failed on this Mac with the main checkout's signer. packaging/README-ship.md: the publish-time gate.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:14:19 +00:00
..
fixtures CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
windows Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened 2026-10-04 13:52:45 +00:00
bash-body-check.sh CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
check-workflow-shell.mjs Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page 2026-10-04 22:54:56 +00:00
copied-sources-check.sh Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule 2026-10-05 09:12:38 +00:00
forbidden-strings.txt Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
identity-check.sh Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
install-hooks.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
link-check.mjs Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI 2026-10-05 19:35:40 +00:00
no-conflict-markers.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
no-secrets-check.sh Key custody: inventory, encrypted backup and restore, no-secrets CI check 2026-10-05 17:01:01 +00:00
pinned-guests-check.sh ci: the pinned-guests check ignores comment lines 2026-10-05 13:01:38 +00:00
prover-socket-check.sh Jobs publisher: the class checks run on the script before it is signed (row C27) 2026-10-05 22:14:19 +00:00
public-api-check.mjs Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check 2026-10-05 19:35:40 +00:00