igneum/tools/ci
igneum-labs a5533177d3 CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class)
Twice on 5 October 2026 a PowerShell job script carried a bash body inside a string, a quote was lost on the way
through PowerShell, and bash refused the body: pc1-cpu-prove.ps1 (first version) reported exit 0 having done
nothing, the 0.3.10 installer job failed in 4 s. tools/amd-prove/check-job-bash.sh covered only its own here-string.

tools/ci/bash-body-check.sh reads every *.ps1 under relay/playbooks/ and tools/, finds each bash body however it is
handed over (bash -c "...", bash -lc '...', bash -c $var, a + concatenation in parentheses, the Start-Process argument
list, a here-string written to a file that is later run with bash), unescapes it the way PowerShell would (backtick
escapes and "" in double-quoted strings, '' in single-quoted strings, here-strings verbatim; $var left as-is, a $(...)
subexpression replaced by ${PS_SUBEXPR}), and runs bash -n on it. One line per body with the file line of the error.
A body it sees but cannot read is "unextractable body" and fails too: a skip would be a hole in the class check.
bash 3.2 compatible; python3 for the extractor.

--self-test runs three fixtures under tools/ci/fixtures/: the correct shapes (8 bodies, must pass), the lost quotes
(the awk apostrophe, a dropped closing quote in a literal and in a variable; must fail with the line), and three
unreadable bodies (must fail). Wired into ci.yml next to the copied-sources check, self-test first. The current tree:
7 inline bodies in 3 playbooks, all parse. packaging/README-ship.md: the job-script rule (body to a file, bash <file>).

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 21:38:41 +00:00
..
fixtures CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
windows Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened 2026-10-04 13:52:45 +00:00
bash-body-check.sh CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
check-workflow-shell.mjs Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page 2026-10-04 22:54:56 +00:00
copied-sources-check.sh Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule 2026-10-05 09:12:38 +00:00
forbidden-strings.txt Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
identity-check.sh Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
install-hooks.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
link-check.mjs Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI 2026-10-05 19:35:40 +00:00
no-conflict-markers.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
no-secrets-check.sh Key custody: inventory, encrypted backup and restore, no-secrets CI check 2026-10-05 17:01:01 +00:00
pinned-guests-check.sh ci: the pinned-guests check ignores comment lines 2026-10-05 13:01:38 +00:00
public-api-check.mjs Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check 2026-10-05 19:35:40 +00:00