The public /ledger page (site/ledger.html) carried ~/.config/igneum paths five times, "pid 33114", --rpclisten=0.0.0.0:26610, "PC 2" fifteen times, "the Mac" nineteen times and 202 repository file paths, because tools/ledger-page.mjs scrubbed with its own short list and never ran the forbidden-strings hard stop (found by the site audit of 6 October 2026, docs/plans/site-ui-3-audit.md). Now: the generator's scrub replaces every config or home-directory path with "a config file" or "a home-directory file", a pid with "the process", a listen flag or 0.0.0.0 address with its plain words, "PC 1" and "PC 2" with "the Windows machine", "the Mac" with "the Apple M5 Max" (the bench log's rule), and every repository file path with "a repository file"; the page's own source note names no path. After rendering, the page is grepped with tools/ci/forbidden-strings.txt plus the leak classes and the render exits 1 on a hit. The pattern list gains ~/.config, pid N, 0.0.0.0:port, PC 1 and PC 2 and --rpclisten=, and the identity grep now covers site/ledger.html (html added to its file types). Regenerated: 167 entries, 0 leaks, identity grep 0 hits over 231 files, link check 0 broken. Consequence per reader: the ledger keeps every criticism, status and answer; what a reader loses is the exact repository path of a fix, which meant nothing outside the private repository. Nothing else on the site changes. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
65 lines
4.4 KiB
Bash
Executable file
65 lines
4.4 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Identity grep of the public export list, gh-free, for CI (tools/ci/forbidden-strings.txt).
|
|
#
|
|
# Copies the paths that igneum-public/tools/sync.sh publishes into a temporary directory, applies the same generic
|
|
# scrub that sync.sh applies (model names for machines, <lan-ip> for LAN addresses, ~ for home paths, UTC stamps),
|
|
# then greps the result with the committed pattern list. A hit means a change would reach the public mirror with
|
|
# a machine name, a LAN address, a home path or the log-intake key pattern that the generic scrub does not catch.
|
|
# The private rules of the mirror (sync.local.sed, identity.local) are not here; they run at export time.
|
|
#
|
|
# tools/ci/identity-check.sh # exit 1 on any hit, with file:line
|
|
set -euo pipefail
|
|
HERE="$(cd "$(dirname "$0")" && pwd)"
|
|
REPO="$(cd "$HERE/../.." && pwd)"
|
|
PATTERNS="$HERE/forbidden-strings.txt"
|
|
|
|
# The export list of igneum-public/tools/sync.sh (keep in step with it), plus the two files published with the repository
|
|
# at the public testnet (decision of 5 October 2026: the criticism ledger and its fixes file). They are not in sync.sh,
|
|
# because the spec mirror is public today and the repository is not until the public testnet.
|
|
DIRS=(docs/spec docs/analysis sim igneum-pow igneum-census tools/harness proto-cuda/packs docs/benchmarks tools/finality-attacks tools/exec-attacks)
|
|
FILES=(site/ledger.html docs/provenance.md docs/bench-log.md docs/evidence.md docs/fud-ledger.md docs/fud-fixes.md proto-cuda/README.md proto-cuda/CHECKLIST.md proto-cuda/host.cu proto-cuda/build.sh
|
|
proto-cuda/build.bat proto-cuda/.gitignore proto-cuda/emu/emu.sh proto-cuda/emu/shim.cpp proto-cuda/emu/cuda_runtime.h proto-metal/README.md
|
|
proto-metal/MEMHARD.md proto-metal/TESTS.md proto-metal/main.swift proto-opencl/README.md proto-opencl/WAVEFRONT.md proto-opencl/host.c
|
|
proto-opencl/build.sh proto-opencl/build.bat proto-opencl/.gitignore proto-opencl/emu/emu.sh proto-opencl/emu/emu_main.cpp proto-opencl/emu/emu_opencl.h)
|
|
|
|
TMP="$(mktemp -d)"; trap 'rm -rf "$TMP"' EXIT
|
|
for d in "${DIRS[@]}"; do [ -d "$REPO/$d" ] && { mkdir -p "$TMP/$(dirname "$d")"; cp -R "$REPO/$d" "$TMP/$d"; }; done
|
|
for f in "${FILES[@]}"; do [ -f "$REPO/$f" ] && { mkdir -p "$TMP/$(dirname "$f")"; cp "$REPO/$f" "$TMP/$f"; }; done
|
|
# prune what sync.sh prunes
|
|
find "$TMP" \( -name target -o -name __pycache__ -o -name out -o -name 'build-*' -o -name node_modules -o -name results -o -name runs \) -prune -exec rm -rf {} + 2>/dev/null || true
|
|
find "$TMP" \( -name .DS_Store -o -name '*.pyc' \) -type f -delete
|
|
|
|
# the generic scrub of sync.sh step 3 (its public half; the rules are public text, not secrets)
|
|
TEXT_FILES="$(find "$TMP" -type f \( -name '*.md' -o -name '*.rs' -o -name '*.py' -o -name '*.mjs' -o -name '*.sh' -o -name '*.bat' \
|
|
-o -name '*.c' -o -name '*.cu' -o -name '*.cl' -o -name '*.h' -o -name '*.cpp' -o -name '*.swift' -o -name '*.metal' -o -name '*.json' \
|
|
-o -name '*.csv' -o -name '*.toml' -o -name '*.txt' -o -name '*.log' -o -name '*.html' \) -print)"
|
|
while IFS= read -r f; do
|
|
[ -n "$f" ] || continue
|
|
perl -pi -e '
|
|
s/the PC node at 192\.168\.[0-9.]+/the RTX 5090 node on the LAN/g;
|
|
s/\bthe PC node\b/the RTX 5090 node/g;
|
|
s/\bWindows PC\b/an RTX 5090 on Windows/g;
|
|
s/\bthe PC\x27s\b/the RTX 5090 machine\x27s/g;
|
|
s/\bthe PC\b/the RTX 5090 machine/g;
|
|
s/\bPC (joins|start|period)\b/RTX 5090 $1/g;
|
|
s/192\.168\.[0-9]+\.[0-9]+/<lan-ip>/g;
|
|
s/DESKTOP-[A-Z0-9]{7}/<pc-hostname>/g;
|
|
s/~\/Desktop\//`/g; s/``/`/g;
|
|
s/~\/\.cargo\/bin\/cargo/cargo/g;
|
|
s/\/Users\/[A-Za-z0-9_.-]+/~/g;
|
|
s/C:\\Users\\[A-Za-z0-9_.-]+/%USERPROFILE%/g;
|
|
s/(\d{1,2}:\d{2}(?::\d{2})? UTC) = \d{1,2}:\d{2} B[S]T/$1/g;
|
|
s/(\d{1,2}):(\d{2})(:\d{2})? to (\d{1,2}):(\d{2})(:\d{2})? B[S]T/sprintf("%02d:%s%s to %02d:%s%s UTC",($1+23)%24,$2,$3\/\/"",($4+23)%24,$5,$6\/\/"")/ge;
|
|
s/(\d{1,2}):(\d{2})(:\d{2})? B[S]T/sprintf("%02d:%s%s UTC",($1+23)%24,$2,$3\/\/"")/ge;
|
|
' "$f"
|
|
done <<< "$TEXT_FILES"
|
|
perl -pi -e 's/\(Mac side only;/(Apple M5 Max side only;/g; s/\bthe Mac\x27s\b/the Apple M5 Max\x27s/g; s/\bthe Mac\b/the Apple M5 Max/g;' "$TMP/docs/bench-log.md" 2>/dev/null || true
|
|
|
|
PAT="$(grep -vE '^\s*(#|$)' "$PATTERNS")"
|
|
HITS="$(grep -rEn -f <(printf '%s\n' "$PAT") "$TMP" || true)"
|
|
if [ -n "$HITS" ]; then
|
|
echo "identity grep: HITS in the public export list (after the generic scrub):"
|
|
printf '%s\n' "$HITS" | sed "s#^$TMP/##" | cut -c1-200
|
|
exit 1
|
|
fi
|
|
echo "identity grep: 0 hits over $(printf '%s\n' "$TEXT_FILES" | grep -c .) files"
|