igneum/infra/build-server/capacity/install.sh
igneum-labs 6836115d65 Capacity layer: idle-core background workload on igneum-build-1 that yields to builds
infra/build-server/capacity: igneum-capacity.service (user build, Nice 19, SCHED_IDLE,
CPUQuota leaving 8 threads free) runs run.sh, a controller over a priority queue of jobs
that pauses (SIGSTOP) the instant a build slot or the measure hold is taken (5 s poll of
/srv/builds/_locks) and resumes after. Jobs, each with a dry-run and a 10-min smoke:
pow fuzz (continuous, seed base advances), sync-request fuzz against a throwaway pruned
node on loopback (the Horizon 28-unwrap gate, igneum-p2p-probe sync-fuzz), GHOSTDAG and
finality sweeps seeds 1 to 1,000, model.py sweeps cached, clippy+audit per recent branch.
Summaries to /srv/workers/capacity.json; the worker dashboard gains a Background lane
(collect.mjs doc.background, page renderBackground). Night battery stops and restarts the
layer. docs/plans/build-server.md section 8. igneum-pow fuzz tests and ghostdag_sim.py /
attacks.py gain a seed-base knob for the continuous sweeps.

Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
2026-10-06 20:58:42 +00:00

63 lines
5.5 KiB
Bash
Executable file

#!/usr/bin/env bash
# Install or refresh the background capacity layer on igneum-build-1 from this Mac. Idempotent.
# infra/build-server/capacity/install.sh copy the scripts and the unit, push the probe branch, enable the service
# infra/build-server/capacity/install.sh --no-start install but do not start (enable only)
# infra/build-server/capacity/install.sh --smoke <job> install, then run one job's 10-minute smoke on the box and print its summary
# Needs root over ssh (root@<ip> with ~/.ssh/igneum_ed25519); the host ip comes from ~/.config/igneum/build-server.
# The layer takes no build slot and writes only under /srv/capacity and /srv/workers/capacity.json.
set -euo pipefail
HERE="$(cd "$(dirname "${BASH_SOURCE[0]}")" && pwd)"; ROOT="$(cd "$HERE/../../.." && pwd)"
KEY="${IGNEUM_BUILD_KEY:-$HOME/.ssh/igneum_ed25519}"
HOST_LINE="$(head -1 "${IGNEUM_BUILD_HOST_FILE:-$HOME/.config/igneum/build-server}" | tr -d '[:space:]')"
IP="${HOST_LINE#*@}"; [ -n "$IP" ] || { echo "no build server in ~/.config/igneum/build-server" >&2; exit 1; }
SSH=(ssh -i "$KEY" -o BatchMode=yes -o StrictHostKeyChecking=accept-new -o ConnectTimeout=10)
NOSTART=0; SMOKE_JOB=""
while [ $# -gt 0 ]; do case "$1" in --no-start) NOSTART=1;; --smoke) SMOKE_JOB="$2"; shift;; *) echo "unknown arg $1" >&2; exit 2;; esac; shift; done
echo "capacity: installing on $IP"
# the probe branch (igneum-p2p-probe sync-fuzz) must exist on the node mirror so the box can check it out. The branch
# may live in this worktree's fork, or in the shared main checkout's fork (both share the same git); use whichever has it.
FORK="$ROOT/vendor/igneum-node-capacity"
[ -d "$FORK/.git" ] || git -C "$FORK" rev-parse -q --verify capacity-probe >/dev/null 2>&1 || FORK="$ROOT/vendor/igneum-node"
[ -d "$FORK" ] || FORK="$(cd "$ROOT/.." && pwd)/igneum/vendor/igneum-node"
if [ -d "$FORK" ] && git -C "$FORK" rev-parse -q --verify capacity-probe >/dev/null 2>&1; then
GIT_SSH_COMMAND="ssh -i $KEY -o BatchMode=yes" git -C "$FORK" push -q --force build capacity-probe && echo "capacity: pushed capacity-probe to the node mirror" || echo "capacity: WARNING push of capacity-probe failed (the box will fall back to the newest release-*-node)" >&2
else
echo "capacity: note: no capacity-probe branch in $FORK; the box will fall back to the newest release-*-node for the sync-fuzz probe" >&2
fi
# directories owned by build
"${SSH[@]}" "root@$IP" 'install -d -o build -g build /srv/capacity /srv/capacity/bin /srv/capacity/bin/jobs /srv/capacity/out /srv/capacity/state /srv/capacity/log; install -d -o build -g build /srv/workers'
# the scripts
scp -q -i "$KEY" "$HERE/run.sh" "$HERE/lib.sh" "$HERE/summary.mjs" "build@$IP:/srv/capacity/bin/"
scp -q -i "$KEY" "$HERE/jobs/"*.sh "build@$IP:/srv/capacity/bin/jobs/"
"${SSH[@]}" "root@$IP" 'chown -R build:build /srv/capacity/bin; chmod +x /srv/capacity/bin/run.sh /srv/capacity/bin/jobs/*.sh'
# the unit, and the night battery unit (it now kills and restarts the layer)
scp -q -i "$KEY" "$HERE/igneum-capacity.service" "root@$IP:/etc/systemd/system/"
if [ -f "$HERE/../night/igneum-night-battery.service" ]; then scp -q -i "$KEY" "$HERE/../night/igneum-night-battery.service" "root@$IP:/etc/systemd/system/"; fi
# the layer tracks the repo branch master in production. Until this work merges, the box mirror's master lacks
# infra/build-server/capacity and the sim seed-base edits, so point the layer at box-capacity with a drop-in and push
# that branch. The drop-in removes itself once master carries the capacity run.sh (self-healing after the merge).
REPO_SRC="$ROOT"; [ -f "$REPO_SRC/infra/build-server/capacity/run.sh" ] || REPO_SRC="$(cd "$ROOT/.." && pwd)/igneum"
if git -C "$REPO_SRC" rev-parse -q --verify box-capacity >/dev/null 2>&1; then
GIT_SSH_COMMAND="ssh -i $KEY -o BatchMode=yes" git -C "$REPO_SRC" push -q --force build box-capacity 2>/dev/null \
&& echo "capacity: pushed box-capacity to the repo mirror" || echo "capacity: WARNING could not push box-capacity (is the build remote wired? run-from-mac.sh)" >&2
fi
if "${SSH[@]}" "build@$IP" 'git -C /srv/igneum.git cat-file -e master:infra/build-server/capacity/run.sh 2>/dev/null'; then
"${SSH[@]}" "root@$IP" 'rm -f /etc/systemd/system/igneum-capacity.service.d/branch.conf; rmdir /etc/systemd/system/igneum-capacity.service.d 2>/dev/null || true'
echo "capacity: master carries the capacity layer; the layer tracks master"
else
"${SSH[@]}" "root@$IP" 'install -d /etc/systemd/system/igneum-capacity.service.d; printf "[Service]\nEnvironment=CAP_REPO_BRANCH=box-capacity\n" > /etc/systemd/system/igneum-capacity.service.d/branch.conf'
echo "capacity: master does not carry the capacity layer yet; drop-in pins CAP_REPO_BRANCH=box-capacity until the merge"
fi
"${SSH[@]}" "root@$IP" 'systemctl daemon-reload; systemctl enable --quiet igneum-capacity.service 2>/dev/null || true'
if [ -n "$SMOKE_JOB" ]; then
echo "capacity: smoke $SMOKE_JOB (up to ~10 min)"
"${SSH[@]}" "build@$IP" "IGNEUM_CAPACITY_JSON=/srv/workers/capacity.json nice -n 19 chrt -i 0 bash /srv/capacity/bin/jobs/$SMOKE_JOB.sh --smoke; echo '--- capacity.json ---'; cat /srv/workers/capacity.json"
exit 0
fi
if [ "$NOSTART" = 1 ]; then echo "capacity: installed and enabled, NOT started (--no-start)"; exit 0; fi
"${SSH[@]}" "root@$IP" 'systemctl restart igneum-capacity.service; sleep 2; systemctl is-active igneum-capacity.service; systemctl --no-pager --lines=0 status igneum-capacity.service | sed -n 1,3p'
echo "capacity: running; journalctl -u igneum-capacity -n 30; summary at /srv/workers/capacity.json"