igneum/tools/ci
igneum-labs b2e6d6159e CI: run jobs test their fetched kit before use (the wiped-jobs-folder class)
The app's install clears the jobs folder on a PC, so a run job whose kit was fetched by an earlier fetch job finds
nothing after an update and fails in seconds (5 October 2026, 21:49Z, the AMD kit; bench-log 4df339f). Rule: a run
playbook that reaches a path under the jobs folder other than its own tests the kit is there before its first use,
and the fetch is republished under a new id after any app update.

tools/ci/kit-path-check.sh reads every *.ps1 under relay/playbooks/ and tools/. A kit root is a path derived from
the jobs folder (`$jobs = Split-Path $env:IGNEUM_JOB_DIR` then `Join-Path $jobs '<fetch id>'`, the race-5090.ps1
shape) or one carrying a literal `jobs\` (the amd-card-test.ps1 shape); every path built from it belongs to that kit.
A presence check (Test-Path, [IO.File]::Exists, [IO.Directory]::Exists, Get-Item or Get-ChildItem with -ErrorAction)
on the root or anything under it covers the whole kit. A use before that line fails with "kit path used before a
presence check: republish the fetch after any app update", as does a literal jobs\ path in a command with no check.
The job's own folder ($env:IGNEUM_JOB_DIR) is not a kit path.

Fixtures: kit-path-ok.ps1 (both shapes, checked; a sibling pack file covered by the worker's check) and
kit-path-unchecked.ps1 (the worker run before its check, a literal never checked); --self-test asserts the lines.
Wired into ci.yml after the bash-body step, and into publish-jobs.sh add --kind run beside the other two checks;
test-publish-jobs.sh gains the refusal (34 passed, 0 failed). The current tree: race-5090.ps1 is the one playbook
with a kit, checked before use. README-ship.md: the rule.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-05 22:37:29 +00:00
..
fixtures CI: run jobs test their fetched kit before use (the wiped-jobs-folder class) 2026-10-05 22:37:29 +00:00
windows Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened 2026-10-04 13:52:45 +00:00
bash-body-check.sh CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
check-workflow-shell.mjs Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page 2026-10-04 22:54:56 +00:00
copied-sources-check.sh Stale-build class closed: every script that copies sources re-stamps them before building, CI check, repo rule 2026-10-05 09:12:38 +00:00
forbidden-strings.txt Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
identity-check.sh Entity, contact route and repository date: Igneum Labs LTD imprint in the footer, litepaper and miner fee, hello@igneum.network as the flaw route, repository public at the public testnet 2026-10-05 16:41:38 +00:00
install-hooks.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
kit-path-check.sh CI: run jobs test their fetched kit before use (the wiped-jobs-folder class) 2026-10-05 22:37:29 +00:00
link-check.mjs Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI 2026-10-05 19:35:40 +00:00
no-conflict-markers.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
no-secrets-check.sh Key custody: inventory, encrypted backup and restore, no-secrets CI check 2026-10-05 17:01:01 +00:00
pinned-guests-check.sh ci: the pinned-guests check ignores comment lines 2026-10-05 13:01:38 +00:00
prover-socket-check.sh Jobs publisher: the class checks run on the script before it is signed (row C27) 2026-10-05 22:14:19 +00:00
public-api-check.mjs Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check 2026-10-05 19:35:40 +00:00