tools/ci/founder-strings.b64 was the founder check's pattern list base64-encoded: a grep could not read it, any reader of the public host could (git.igneum.network was public from 21:26 UK; read off at 21:36). The list now lives only in a private file (~/.config/igneum/founder-strings on the Mac, /srv/discord-hooks/founder-strings on build-1 for the Discord guard; $IGNEUM_FOUNDER_STRINGS overrides) and site/forbidden-strings.txt carries no encoded copy. Readers: founder-strings-check.sh (skips with a line where the file is absent; the Mac's hook is the guard), site/scrub.mjs and launch-gates-check.mjs (the private file's patterns added where it exists), discord-hooks.mjs (three locations; the test writes a fixture list and loads the module after it), fresh-repo.sh (the private file; drops tools/ci/founder-strings.b64 from every commit; rewrites the base64 of every list regex out of every blob and scans for it). The check's second pass (main's addition): every base64 literal of 24 characters or more, every hex literal of 24 or more and every *.b64 file is decoded and scanned, so no encoding hides a term again; the self-test plants each fixture sample in plain text, in a .b64 file, as a base64 literal and as a hex literal, each caught and named, and a tree without the list skips with its line. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| fixtures | ||
| windows | ||
| bash-body-check.sh | ||
| box-locks-check.sh | ||
| build-kind-default-check.sh | ||
| check-workflow-shell.mjs | ||
| ci-state.mjs | ||
| commit-string-check.sh | ||
| copied-sources-check.sh | ||
| defaults-line-check.sh | ||
| docs-only-check.sh | ||
| engine-check.sh | ||
| export-exclude.txt | ||
| forbidden-strings.txt | ||
| founder-strings-check.sh | ||
| glibc-ceiling-check.sh | ||
| identity-check.sh | ||
| install-hooks.sh | ||
| kill-by-name-check.sh | ||
| kit-path-check.sh | ||
| launch-gates-check.mjs | ||
| ledger-text-check.mjs | ||
| link-check.mjs | ||
| merge-to-master.sh | ||
| mirror-reset-check.sh | ||
| no-conflict-markers.sh | ||
| no-foreign-tree-writes.sh | ||
| no-secrets-check.sh | ||
| overlap-check.mjs | ||
| override-json-check.sh | ||
| padding-check.mjs | ||
| pinned-guests-check.sh | ||
| playbook-quit-check.sh | ||
| pre-push.sh | ||
| prover-socket-check.sh | ||
| ps-drive-ref-check.sh | ||
| public-api-check.mjs | ||
| publish-jobs-check.sh | ||
| README.md | ||
| red-watch.mjs | ||
| retry-once.sh | ||
| route-spill-check.sh | ||
| scratch-spare-check.sh | ||
| scroll-width-check.mjs | ||
| second-engine-check.sh | ||
| signer-pipe-check.sh | ||
| sims-branch-check.sh | ||
| site-contrast-check.mjs | ||
| site-nav-check.mjs | ||
| site-orphan-check.mjs | ||
| whole-body-check.sh | ||
| windows-paths-check.sh | ||
| windows-spawn-check.mjs | ||
| workflow-timeouts-check.sh | ||
CI checks
| Check | What it fails | Since |
|---|---|---|
no text overlaps (overlap-check.mjs) |
A served page, or a miner or wallet screen (behind IGNEUM_OVERLAP_APPS=1), where a visible run of text is covered by another element (a pill over a caption, a label over a value, a card over its neighbour, text under the header at rest), clipped by an overflow-hidden ancestor, or past the viewport; a page that scrolls sideways. Five widths, light and dark, the home hero at rest and at each step. A fixture with one deliberate overlap of each kind must be flagged first (--self-test). Needs a headless Chromium: CI installs Playwright; the Mac ships the pages to build-2 (infra/build-server/overlap-browser.sh). |
7 October 2026: the hero's step pill sat on the caption's second line ("Two thirds of the weight sign. The checkpoint locks.") at every desktop width, found by the founder on the live site |
| master takes only CI-passed commits (ci-state.mjs, merge-to-master.sh, the hook's master_ci_ok) | A push to master whose commit, or whose merge's branch parent, has no green ci run on that exact sha (the runs API through gh: red, queued, none or gh unreachable all refuse); a merge onto a master whose last compiled run is red, unless declared the fix (--fixes-master). The merge tool pushes an unrun branch for a run and waits for a queued one with the clock. A feature-branch push prints the branch's previous red first (--branch-red). | 7 October 2026: era-vdf's tip 0e2d6b1c merged with no ci run; master's igneum-pow suite red from 16:31 UK under five docs-only green merges |
| every workflow job carries timeout-minutes (workflow-timeouts-check.sh) | A job in .github/workflows without timeout-minutes, or a budget off its measured line (site 15, changes 10, pow 60, sims 45). | 7 October 2026: three hosted site jobs on master hung over two hours each in the tree gate; the six-hour default was the only stop |
| a box or network check gets one retry (retry-once.sh) | Nothing by itself: wraps the box-locks check, the scene parity check and the live public API check so a first failure is printed and retried once; the second is the verdict. The checks keep their own skip line on a runner without the resource. | 7 October 2026 |
| the red watcher fires on cancelled and timed-out runs too (ci-red.yml, red-watch.mjs) | The watcher's if missing any of failure, cancelled, timed_out, or the conclusion not handed to the record step (the self-test reads the workflow file); the line names the kind: CI red, CI cancelled, CI timed out. | 7 October 2026 |
| kill by exact command or pid file (owed as a check) | 6 October 2026, 21:09Z: a Mac-side pkill -f <log file name> matched nothing (the log name was a redirect, not part of the command line), the roll-everything script lived on and wiped a box it had been told to hold. Rule: a job is stopped by its pid file (tools/fleet/fleet-bg.sh start|stop <name>) or by a pattern anchored on its exact command line (^python3 -u /root/fleet/in/box-prover.py), never by a word that may or may not appear in it. The check that flags a pkill -f/pgrep -f whose literal is a path or a name that never starts a command line is owed to the CI lane |