igneum/tools/ci
igneum-labs c0a557f69b Ledger page: strip config and home paths, process ids, listen addresses, machine names and repository paths; the render fails on a leak
The public /ledger page (site/ledger.html) carried ~/.config/igneum paths five times, "pid 33114", --rpclisten=0.0.0.0:26610,
"PC 2" fifteen times, "the Mac" nineteen times and 202 repository file paths, because tools/ledger-page.mjs scrubbed with its
own short list and never ran the forbidden-strings hard stop (found by the site audit of 6 October 2026, docs/plans/site-ui-3-audit.md).

Now: the generator's scrub replaces every config or home-directory path with "a config file" or "a home-directory file", a pid with
"the process", a listen flag or 0.0.0.0 address with its plain words, "PC 1" and "PC 2" with "the Windows machine", "the Mac" with
"the Apple M5 Max" (the bench log's rule), and every repository file path with "a repository file"; the page's own source note
names no path. After rendering, the page is grepped with tools/ci/forbidden-strings.txt plus the leak classes and the render
exits 1 on a hit. The pattern list gains ~/.config, pid N, 0.0.0.0:port, PC 1 and PC 2 and --rpclisten=, and the identity grep
now covers site/ledger.html (html added to its file types). Regenerated: 167 entries, 0 leaks, identity grep 0 hits over 231
files, link check 0 broken.

Consequence per reader: the ledger keeps every criticism, status and answer; what a reader loses is the exact repository path
of a fix, which meant nothing outside the private repository. Nothing else on the site changes.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 19:07:20 +00:00
..
fixtures CI: run jobs test their fetched kit before use (the wiped-jobs-folder class) 2026-10-05 22:37:29 +00:00
windows Evidence: 4 October measurements (live hourly swap, first live lock and the 280 locks since, first GPU proof, one-click worker, generator v2, difficulty oscillation and v2 pending, 12-node propagation and partition, clock skew); rows 29 and 30 added; difficulty and floor claims softened 2026-10-04 13:52:45 +00:00
bash-body-check.sh CI: bash bodies in PowerShell jobs pass bash -n (the lost-quote class) 2026-10-05 21:38:41 +00:00
check-workflow-shell.mjs Public-testnet readiness: fee floors and pgas table analysis, testnet identity doc, G14 rewrite plan with dry run, G13 signed build inputs, testnet terms, MetaMask page 2026-10-04 22:54:56 +00:00
commit-string-check.sh Build server adopted: box-first build rule in CLAUDE.md, reproducible Windows exes, the commit-string gate, PC and Mac recipes 2026-10-06 17:50:39 +00:00
copied-sources-check.sh Merge origin/master into ca3-coord: Counter ASIC 3.0 complete (every gate green, P2 green, P1 written); the drive-ref check skips single-quoted here-strings and the copied-sources check reads code lines only (master's CI red on 9d23b70); main's decisions and the close in the status file 2026-10-06 18:05:54 +00:00
forbidden-strings.txt Ledger page: strip config and home paths, process ids, listen addresses, machine names and repository paths; the render fails on a leak 2026-10-06 19:07:20 +00:00
identity-check.sh Ledger page: strip config and home paths, process ids, listen addresses, machine names and repository paths; the render fails on a leak 2026-10-06 19:07:20 +00:00
install-hooks.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
kit-path-check.sh CI: run jobs test their fetched kit before use (the wiped-jobs-folder class) 2026-10-05 22:37:29 +00:00
link-check.mjs Explorer pages: /explorer, /block/<hash|number>, /address/<addr>, the search router, a local preview server, CI 2026-10-05 19:35:40 +00:00
no-conflict-markers.sh ci: no conflict markers in tracked files (check + pre-push hook that also builds the site) 2026-10-05 16:45:09 +00:00
no-foreign-tree-writes.sh Site: the downloads snapshot is written only on SITE_DOWNLOADS_REFRESH=1 or in CI; a CI check against scripts writing into other worktrees 2026-10-06 18:19:58 +00:00
no-secrets-check.sh Key custody: inventory, encrypted backup and restore, no-secrets CI check 2026-10-05 17:01:01 +00:00
override-json-check.sh Counter ASIC 3.0 gates (node): class v4 = mx8+sh256x27 through the stack (igneum-pow ProgramClass::V4, V4_CLASS, generator 4, program_id(4, seed, attempt), the era composed as v3's; program.h and program.json class v4; packcheck, packfile.h, the CUDA and OpenCL identity rule and the Metal worker accept generator 4 and the class=v4 token, the Metal worker takes v4 from the prepared pack only; v2 and v3 byte-identical, the pinned packs diffed); the G4 harness class-v4.mjs (two switches, the never case); override-60x.json: the v4 field at never, the duplicated proving v1 block removed, the four 0.3.12/0.3.13 fields added; CI check override-json-check.sh (no duplicate key in any override file) 2026-10-06 15:58:49 +00:00
pinned-guests-check.sh ci: the pinned-guests check ignores comment lines 2026-10-05 13:01:38 +00:00
playbook-quit-check.sh Merge release-0.3.14: Igneum Miner 0.3.14 (exec-sync deep-reorg reload, miner-ui-3, ember-tune), publish 1 on the thirteen-field object 2026-10-06 18:18:17 +00:00
prover-socket-check.sh CI on the merged 0.3.11 tree: MacBook reworded in the analysis prose (the identity check's hostname pattern), a presence check before the kit's first use in the three proving-v1 PC 2 scripts (C32), pc1-cpu-prove.ps1 on the socket check's allow list (the CPU path starts no GPU server) 2026-10-05 22:44:09 +00:00
ps-drive-ref-check.sh Merge origin/master into ca3-coord: Counter ASIC 3.0 complete (every gate green, P2 green, P1 written); the drive-ref check skips single-quoted here-strings and the copied-sources check reads code lines only (master's CI red on 9d23b70); main's decisions and the close in the status file 2026-10-06 18:05:54 +00:00
public-api-check.mjs Public stats API: /api/stats and /api/supply, documented with live examples, contract test and a live check 2026-10-05 19:35:40 +00:00
second-engine-check.sh A card never shows 0 MH/s without a reason word (the project lead, 6 October 2026, watching PC 1 during the table run): the Mine row reads 'tuning: step k of n · measuring W W' with the live rate, 'held for a remote job: <title>' while a job holds the miners, and the Tuned line at the end; the big button reads 'Tuning, mining again in about N min'; the strip carries one tune line; a measurement engine prints a TUNE progress line every 10 s and the playbook forwards it (and TUNE chosen as done) to the installed app's POST /api/tune-progress, a post of state, never quit, pause or resume; the rule in ember-tune.md 6a; UI tests for the three states 2026-10-06 15:36:07 +00:00
signer-pipe-check.sh C4 fix: certificate-driven reorg written into spec 3.5, 3.2 C4, 3.10 C4 and F1/F2, 3.11.7; ledger C4 fix paragraph, F16 note (the honest-partition row for option B is gone), O-3.6 narrowed; bench-log "the C4 fix" with every harness row; c4.mjs v2 mode, WINDOW knob, forced reconnect at the heal (addPeer, nodes on --unsaferpc), adopted-lock count; two tooling classes fixed: the signer piped into head (SIGPIPE panic under pipefail, four scripts, tools/ci/signer-pipe-check.sh in CI) and the one shared build-inputs.zip (build-job.mjs names every job's zip, push-build-inputs.sh --name and pruning) 2026-10-05 18:17:36 +00:00
windows-spawn-check.mjs app: every elevated launch through one hidden-console builder; CI check for Windows spawns; PC 1 console watchers 2026-10-06 08:21:46 +00:00