docs/security/keys.md: every key the project depends on (the folder, the gh keyring, the Vercel env of three projects, the GitHub secrets) with where it lives, what it unlocks, the blast radius lost and leaked, who rotates it and the rotation status, written from the files and the scripts that read them. No value, no private fingerprint. Section 4: the second OTA signing key kept offline, the app change (a key list plus revocation in the manifest), 0.3.9 as the carrier, and the emergency path if the one key leaks today (a manifest signed with a new key is useless to 0.3.x apps; the mitigation in order). tools/keys/backup.sh: ~/Desktop/igneum-keys-<date>.dmg, AES-256, hdiutil's own prompt (never argv, history or a file), the folder minus build-slots, dlsite-dir and pytools/, plus a README; attached read-only, every file compared by sha256, listed, detached. --dry-run lists. restore.sh: --check compares the image against the live folder without printing values, --to copies back with 0600/0644 and 0700. test-backup.sh: the end-to-end test on a scratch folder with a throwaway passphrase, 8 steps, passed. tools/ci/no-secrets-check.sh, in ci.yml: no tracked file named like a key of ~/.config/igneum, no 64-hex value assigned to a token/key/secret name outside tests and the allowlist (the OTA public key, the published Hardhat and Anvil accounts); a --self-test fires on a known-bad tree first. 776 files, 0 hits. Also: ~/.config/igneum, vercel/ and txgen/ are 0700 now (were 0755). Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
79 lines
3.8 KiB
YAML
79 lines
3.8 KiB
YAML
# CI on every push and pull request (private repository, free runner minutes).
|
|
#
|
|
# What runs: the lottery-hash crate's tests (igneum-pow, release profile), the census tool's build, the two Python
|
|
# simulators' --quick modes (each under two minutes), the site build with an internal link check, the gh-free
|
|
# identity grep of the public export list (tools/ci/forbidden-strings.txt), and the no-secrets check of the tree
|
|
# (tools/ci/no-secrets-check.sh: no file named like a key of ~/.config/igneum, no 64-hex value assigned to a
|
|
# token/key/secret name outside tests and the allowlist; docs/security/keys.md).
|
|
#
|
|
# What does not run, on purpose: the node fork (vendor/igneum-node*, a rusty-kaspa fork of about 500 crates with
|
|
# rocksdb, blst and the execution layer) is gitignored here and too big for the free runners today (a cold build is
|
|
# 20 to 55 minutes on 2 to 8 vCPU, docs/bench-log.md). The workflow builds igneum-pow only; the fork's own tests run
|
|
# on the Mac and the seed node (infra/seed-nodes, infra/fast-time).
|
|
name: ci
|
|
on:
|
|
push:
|
|
pull_request:
|
|
jobs:
|
|
pow:
|
|
name: igneum-pow tests, igneum-census build
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- name: toolchain
|
|
run: rustc --version && cargo --version
|
|
- name: igneum-pow tests (release)
|
|
working-directory: igneum-pow
|
|
run: cargo test --release
|
|
- name: igneum-census build (release)
|
|
working-directory: igneum-census
|
|
run: cargo build --release
|
|
sims:
|
|
name: simulators, quick modes
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-python@v5
|
|
with:
|
|
python-version: '3.12'
|
|
- run: python3 -m pip install --quiet numpy
|
|
- name: finality_v2.py --quick (under two minutes)
|
|
working-directory: sim
|
|
run: time timeout 120 python3 finality_v2.py --quick > finality_quick.md
|
|
- name: difficulty/sim.py --quick (under two minutes)
|
|
working-directory: sim/difficulty
|
|
run: time timeout 120 python3 sim.py --quick > difficulty_quick.md
|
|
- uses: actions/upload-artifact@v4
|
|
with:
|
|
name: sim-quick-output
|
|
path: |
|
|
sim/finality_quick.md
|
|
sim/difficulty/difficulty_quick.md
|
|
site:
|
|
name: site build, link check, identity grep
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- uses: actions/checkout@v4
|
|
- uses: actions/setup-node@v4
|
|
with:
|
|
node-version: '22'
|
|
- name: site build
|
|
run: node site/build.mjs
|
|
- name: internal link check of site/*.html
|
|
run: node tools/ci/link-check.mjs
|
|
- name: identity grep of the public export list
|
|
run: bash tools/ci/identity-check.sh
|
|
- name: copied sources are re-stamped before a build
|
|
run: bash tools/ci/copied-sources-check.sh
|
|
- name: pinned guest programs match their manifest and are built only by pin-guests.sh
|
|
run: bash tools/ci/pinned-guests-check.sh
|
|
- name: no secret file names and no 64-hex secrets in the tree (self-test first, then the tree)
|
|
run: bash tools/ci/no-secrets-check.sh --self-test && bash tools/ci/no-secrets-check.sh
|
|
- name: faucet unit tests (validation, the daily limits, the signed transaction; keccak, RLP and secp256k1 vectors)
|
|
run: node --test site/api/faucet.test.mjs
|
|
- name: ship tool self-test (version bump, the dl-both and public manifest helpers)
|
|
run: node tools/ship-app.mjs --self-test
|
|
- name: relay unit tests (parsers, secret compare, the wake endpoint)
|
|
run: node --test relay/test/parse.test.mjs relay/test/auth.test.mjs relay/test/wake.test.mjs
|
|
- name: miner app notice strip and update card (ordering, keys, wording, timers, when the card shows)
|
|
run: node --test app/igneum-app/ui/notices.test.mjs app/igneum-app/ui/update-card.test.mjs
|