igneum/infra/build-server/capacity/jobs/clippy-audit.sh
igneum-labs 58dacf6f38 Capacity layer: fixes from the smoke runs
- pow-fuzz: list saved mismatches from the directory, not an ls|node pipe (pipefail ran
  the || echo too, giving invalid JSON [][]); drop the dead inner accumulation line
- sync-fuzz: merge the override with python, not node (node rounds the u64::MAX activation
  fields to a float the Rust parser rejects); retention-period-days 2 (the 2-day minimum);
  grep -c without || echo (pipefail doubled the count)
- clippy-audit: cap_cargo_t (timeout cannot run the cap_cargo shell function); grep -c fix
- all jobs sync the checkout unconditionally and lib.sh defaults the branch vars so a
  standalone job or smoke never trips set -u on CAP_NODE_BRANCH

Smokes on igneum-build-1, all 0 panics: pow-fuzz 98 rounds / 19,600 programs / 78,400
units; sync-fuzz 142,883 requests, node alive, every kind disconnected or answered;
sim-sweeps 5 rows; model-sweeps 7 sections; clippy-audit 69 branches, 1,192 warnings,
1 error (ca2-coord), 0 advisories.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 21:32:55 +00:00

56 lines
3.8 KiB
Bash
Executable file

#!/usr/bin/env bash
# Capacity job 5 (lowest priority): cargo clippy and cargo audit on every branch pushed to the box mirror within the
# last day, results per branch. Uses its own checkout (CAP_ROOT/clippy) so it never disturbs the other jobs' tree, and
# records which branches it has already done at a given commit so a slice only picks up new pushes.
# jobs/clippy-audit.sh --dry-run list the branches it would check; run nothing
# jobs/clippy-audit.sh --smoke clippy+audit one crate of the newest branch (~10 min)
# jobs/clippy-audit.sh --slice-s N check branches until about this long elapses
set -uo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"; export CAP_JOB=clippy-audit; export CAP_PRIORITY=5
. "$HERE/../lib.sh"
DRY=0; SMOKE=0; SLICE_S="${CAP_SLICE_S:-2400}"; DAYS="${CAP_CLIPPY_DAYS:-1}"
while [ $# -gt 0 ]; do case "$1" in --dry-run) DRY=1;; --smoke) SMOKE=1; SLICE_S=600;; --slice-s) SLICE_S="$2"; shift;; *) cap_say "unknown arg $1";; esac; shift; done
since=$(( $(date +%s) - DAYS * 86400 ))
# branches pushed to the repo mirror within the window, newest first
mapfile -t BRANCHES < <(git -C "$REPO_MIRROR" for-each-ref --sort=-committerdate --format='%(refname:short) %(committerdate:unix) %(objectname:short)' refs/heads 2>/dev/null | awk -v s="$since" '$2 >= s {print $1" "$3}')
if [ "$DRY" = 1 ]; then
cap_say "DRY RUN: branches pushed in the last $DAYS day(s): ${#BRANCHES[@]}"
for b in "${BRANCHES[@]}"; do echo " $b"; done >&2
printf '{"state":"idle","summary":%s,"counters":{"branches_due":%s,"checked":0},"dry_run":true}' "$(cap_json_str "dry run: ${#BRANCHES[@]} branch(es) in the last $DAYS day")" "${#BRANCHES[@]}" | cap_summary clippy-audit
exit 0
fi
CLIP="$CAP_ROOT/clippy"; mkdir -p "$CLIP"
[ -d "$CLIP/.git" ] || git clone -q "$REPO_MIRROR" "$CLIP" >/dev/null 2>&1 || { cap_say "clone failed"; exit 1; }
git -C "$CLIP" fetch -q origin '+refs/heads/*:refs/remotes/origin/*' 2>/dev/null || true
OUT=$(cap_out_dir clippy-audit); done_file="$CAP_STATE/clippy-done.tsv"; touch "$done_file"
export CARGO_TARGET_DIR="$CLIP/target-capacity"
CRATES="${CAP_CLIPPY_CRATES:-igneum-pow igneum-census pool proto-vdf}"
[ "$SMOKE" = 1 ] && CRATES="igneum-pow"
deadline=$(( $(date +%s) + SLICE_S )); checked=0; warn_total=0; err_total=0; audit_vulns=0
for entry in "${BRANCHES[@]}"; do
[ "$(date +%s)" -lt "$deadline" ] || break
b="${entry% *}"; sha="${entry#* }"
grep -qF "$b $sha" "$done_file" && continue
git -C "$CLIP" checkout -q -- . 2>/dev/null || true
git -C "$CLIP" checkout -q -B "cap-$b" "origin/$b" 2>/dev/null || { cap_say "cannot check out $b"; continue; }
bdir="$OUT/$b"; mkdir -p "$bdir"; bw=0; be=0
for c in $CRATES; do
[ -f "$CLIP/$c/Cargo.toml" ] || continue
[ "$(date +%s)" -lt "$deadline" ] || break
if cap_cargo_t 1200 "$CLIP/$c" clippy --release --all-targets > "$bdir/clippy-$c.log" 2>&1; then :; else be=$((be + 1)); fi
bw=$((bw + $(grep -c '^warning: ' "$bdir/clippy-$c.log" 2>/dev/null) + 0))
if cap_cargo_t 300 "$CLIP/$c" audit --color never > "$bdir/audit-$c.log" 2>&1; then :; else audit_vulns=$((audit_vulns + $(grep -c '^Crate:' "$bdir/audit-$c.log" 2>/dev/null) + 0)); fi
done
echo -e "$b\t$sha\t$(date -u +%H:%M:%SZ)\twarnings=$bw\terrors=$be" >> "$done_file"
warn_total=$((warn_total + bw)); err_total=$((err_total + be)); checked=$((checked + 1))
cap_say "$b @ $sha: $bw clippy warnings, $be clippy errors"
done
sum="checked $checked branch(es) this slice of ${#BRANCHES[@]} due; $warn_total clippy warnings, $err_total clippy errors, $audit_vulns audit advisories"
printf '{"state":"ran","summary":%s,"counters":{"branches_due":%s,"checked":%s,"warnings":%s,"errors":%s,"audit_advisories":%s},"out":%s}' \
"$(cap_json_str "$sum")" "${#BRANCHES[@]}" "$checked" "$warn_total" "$err_total" "$audit_vulns" "$(cap_json_str "$OUT")" | cap_summary clippy-audit
cap_say "$sum"