The fleet's 22:09 UK incident (a Mac-side pkill -f <log file name> matched nothing, the roll-everything script lived on and wiped a held box) and the day's two pgrep self-matches are one class. The check flags pgrep -f / pkill -f with a plain literal (every one on a line), any pgrep/pkill on a file-name shape, and ps | grep with a literal; it allows the bracket form, -x, -F pidfile, kill $(cat pidfile), a variable and a full path; 11 banned and 16 allowed shapes in its self-test; 0.15 s over the tree. The 25 pkill -f sp1-gpu-server inside bash -c bodies (which matched the calling bash) are pkill -x; the other 11 literals take the bracket form; prover-socket-check accepts both. Row R in the record; the CLAUDE.md rule names the check and covers pkill and file names. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
98 lines
3.7 KiB
Bash
Executable file
98 lines
3.7 KiB
Bash
Executable file
#!/usr/bin/env bash
|
|
# Starts a throwaway 3-node igneumd simnet (PoW skipped) for the execution-layer attacks, on ports 27600 and
|
|
# above, data under /tmp/igneum-exec-attacks, with one honest stub miner on node 1 by default. The live devnet
|
|
# (26610, 26611, 26640, 26641, 28640) and other agents' ports (up to 27599) are never touched.
|
|
#
|
|
# ./net.sh start [miners] miners = 1 (default) or 3
|
|
# ./net.sh stop
|
|
# ./net.sh grpc1 prints node 1's gRPC url (for igneum-inject)
|
|
#
|
|
# Node i (i=1..3): gRPC 276{i}0, p2p 276{i}1, eth RPC 2769{i-1}. Node 1 gRPC 27610, eth 27690.
|
|
set -u
|
|
ROOT="$(cd "$(dirname "$0")/../.." && pwd)"
|
|
BIN="$ROOT/vendor/igneum-node-exec-attacks/target/release"
|
|
DATA=/tmp/igneum-exec-attacks
|
|
PIDS="$DATA/pids"
|
|
DURATION="${DURATION:-1200}"
|
|
HOLD_MS="${HOLD_MS:-1000}"
|
|
MINER1_VKH=0x00000000000000000000000070997970c51812dc3a010c7d01b50e0d17dc79c8
|
|
MINER2_VKH=0x00000000000000000000000015d34aaf54267db7d7c367839aaf71a00a2c6a65
|
|
MINER3_VKH=0x00000000000000000000000001d47ee52ebca6d0b0beac0f124acde471e0968a
|
|
|
|
grpc1() { echo "grpc://127.0.0.1:27610"; }
|
|
grpc2() { echo "grpc://127.0.0.1:27620"; }
|
|
grpc3() { echo "grpc://127.0.0.1:27630"; }
|
|
|
|
start_node() {
|
|
local i=$1 connect=$2
|
|
local grpc=276${i}0 p2p=276${i}1 eth=2769$((i-1))
|
|
local dir="$DATA/n$i"
|
|
mkdir -p "$dir"
|
|
local extra=""
|
|
[ -n "$connect" ] && extra="--connect=$connect"
|
|
"$BIN/igneumd" --simnet --utxoindex --loglevel=info --disable-upnp --enable-unsynced-mining --unsaferpc \
|
|
--appdir="$dir" \
|
|
--rpclisten=0.0.0.0:$grpc \
|
|
--listen=0.0.0.0:$p2p \
|
|
--evm-rpclisten=127.0.0.1:$eth \
|
|
$extra > "$dir/node.log" 2>&1 &
|
|
echo $! >> "$PIDS"
|
|
}
|
|
|
|
# Block until a node's gRPC server accepts connections (log line), up to ~40 s.
|
|
wait_grpc() {
|
|
local dir=$1 t=0
|
|
until grep -q "GRPC Server starting on" "$dir/node.log" 2>/dev/null || [ $t -ge 40 ]; do sleep 1; t=$((t+1)); done
|
|
sleep 2
|
|
}
|
|
|
|
start_miner() {
|
|
local grpc=$1 vkh=$2 label=$3
|
|
"$BIN/igneum-miner" mine "$grpc" 1 "$DURATION" "$label" \
|
|
--engine stub --hold-ms "$HOLD_MS" --network simnet --vote-key-hash "$vkh" \
|
|
> "$DATA/miner_$label.log" 2>&1 &
|
|
echo $! >> "$PIDS"
|
|
}
|
|
|
|
case "${1:-}" in
|
|
start)
|
|
miners="${2:-1}"
|
|
rm -rf "$DATA"; mkdir -p "$DATA"; : > "$PIDS"
|
|
start_node 1 ""
|
|
start_node 2 "127.0.0.1:27611"
|
|
start_node 3 "127.0.0.1:27611"
|
|
wait_grpc "$DATA/n1"; wait_grpc "$DATA/n2"; wait_grpc "$DATA/n3"
|
|
start_miner "$(grpc1)" "$MINER1_VKH" node1
|
|
if [ "$miners" = "3" ]; then
|
|
start_miner "$(grpc2)" "$MINER2_VKH" node2
|
|
start_miner "$(grpc3)" "$MINER3_VKH" node3
|
|
fi
|
|
echo "started $miners miner(s); data $DATA; eth RPCs 27690 27691 27692"
|
|
;;
|
|
start-split)
|
|
# Partition P1 = {node1}, P2 = {node2, node3}. No link between the partitions until heal (igneum-inject addpeer).
|
|
rm -rf "$DATA"; mkdir -p "$DATA"; : > "$PIDS"
|
|
start_node 1 ""
|
|
start_node 2 ""
|
|
start_node 3 "127.0.0.1:27621"
|
|
wait_grpc "$DATA/n1"; wait_grpc "$DATA/n2"; wait_grpc "$DATA/n3"
|
|
start_miner "$(grpc1)" "$MINER1_VKH" node1
|
|
start_miner "$(grpc2)" "$MINER2_VKH" node2
|
|
start_miner "$(grpc3)" "$MINER3_VKH" node3
|
|
echo "started split: P1={node1}, P2={node2,node3}; eth RPCs 27690 27691 27692"
|
|
;;
|
|
stop)
|
|
if [ -f "$PIDS" ]; then
|
|
while read -r p; do [ -n "$p" ] && kill "$p" 2>/dev/null; done < "$PIDS"
|
|
sleep 1
|
|
while read -r p; do [ -n "$p" ] && kill -9 "$p" 2>/dev/null; done < "$PIDS"
|
|
fi
|
|
pkill -f "[i]gneum-node-exec-attacks/target/release/igneumd --simnet" 2>/dev/null
|
|
pkill -f "[i]gneum-miner mine grpc://127.0.0.1:276" 2>/dev/null
|
|
echo "stopped"
|
|
;;
|
|
grpc1) grpc1 ;;
|
|
grpc2) grpc2 ;;
|
|
grpc3) grpc3 ;;
|
|
*) echo "usage: $0 start [miners] | stop | grpc1|grpc2|grpc3"; exit 2 ;;
|
|
esac
|