igneum/tools/ci/prover-socket-check.sh

19 lines
1.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# The root-socket class (5 October 2026, 20:00Z): a PC 2 job ran igneum-prove-host as root inside WSL2, which started
# an sp1-gpu-server whose socket /tmp/sp1-cuda-0.sock stayed root-owned after the job; the live prover (the app's user)
# then failed every shard with "CudaClientError: Connect(PermissionDenied)" until the socket was gone. Rule: every
# playbook that runs the prover host as root on a shared card kills the server AND unlinks its socket (at the start
# and at the end), or runs as the app's user. This check fails CI when a script runs `igneum-prove-host` under a
# `-u root` WSL session without both lines.
set -euo pipefail
cd "$(dirname "$0")/../.."
fail=0
while IFS= read -r f; do
# a playbook that only runs `--mode id` or `--mode verify` starts no GPU server; the prove modes do
if grep -qE 'igneum-prove-host' "$f" && grep -qE -- '--mode (compressed|chain|aggregate|block|shard|all)\b' "$f" && grep -qE -- '-u root' "$f"; then
if ! grep -qE 'pkill -f sp1-gpu-server' "$f"; then echo "prover-socket: $f runs the prover host as root without killing sp1-gpu-server"; fail=1; fi
if ! grep -qE 'rm -f /tmp/sp1-cuda-' "$f"; then echo "prover-socket: $f runs the prover host as root without unlinking /tmp/sp1-cuda-*.sock"; fail=1; fi
fi
done < <(git ls-files 'tools/**' 'relay/playbooks/**' 'proving/**' 'packaging/**' | grep -E '\.(sh|ps1|mjs)$')
[ "$fail" = 0 ] && echo "prover-socket: every root prover playbook kills the GPU server and unlinks its socket"
exit $fail