oxedyne/daimond/dev/repro-check.sh
6.4 KiB, 1 run
created by r2519314175:117, which is this file's identity for as long as the history lasts, whatever it is later renamed to
download · who wrote it · its history
| 1 | #!/bin/bash |
| 2 | # repro-check.sh -- prove that somebody else could reproduce the sealed bundle. |
| 3 | # |
| 4 | # The published claim is that a stranger can clone the public repository, build |
| 5 | # it, and get the bytes the site serves. That is only ever true by accident |
| 6 | # unless it is checked the way a stranger would experience it, so this does |
| 7 | # exactly that and nothing cheaper: |
| 8 | # |
| 9 | # * a FRESH CLONE of the public mirror, not the working tree, because the |
| 10 | # working tree carries generated files and uncommitted fixes that a cloner |
| 11 | # will not have -- that is how the mirror's Cargo.toml sat broken with path |
| 12 | # dependencies from 2026-07-21 to 2026-07-27, unbuildable by anyone outside |
| 13 | # while every local build kept working; |
| 14 | # * a SEPARATE cargo home and a DIFFERENT directory depth, because build paths |
| 15 | # get baked into the binary. Rebuilding where it was sealed proves nothing: |
| 16 | # it is the one arrangement guaranteed to agree with itself. |
| 17 | # |
| 18 | # It then compares the rebuild against the SEALED MANIFEST, so the thing under |
| 19 | # test is the released bundle rather than another copy of itself. |
| 20 | # |
| 21 | # THE MACHINE HAND IS CHECKED DIFFERENTLY, AND PROVES LESS. The hand is a native |
| 22 | # binary, not wasm: nobody publishes one, everybody builds their own, and a Rust |
| 23 | # release build is not byte-identical across toolchain versions. So there is no |
| 24 | # binary comparison to make and none is attempted. What is checked instead is the |
| 25 | # pair of things that are true: the published source is exactly what was sealed |
| 26 | # (`verify/hand.json`), and the published source BUILDS -- from the clone, with |
| 27 | # the pinned toolchain, using the command the seal names. The second is not a |
| 28 | # formality: the hand pins fe2o3 by git revision, and a revision that was never |
| 29 | # pushed, or that no longer has the API the hand calls, produces a mirror that |
| 30 | # reads fine and compiles for nobody. |
| 31 | # |
| 32 | # bash dev/repro-check.sh # ~8 minutes, mostly cold dependency builds |
| 33 | # SKIP_HAND=1 bash dev/repro-check.sh |
| 34 | # |
| 35 | # Slow and disk-hungry by nature, so it is not part of `run_all.sh`. Run it at |
| 36 | # release, which is the only time its answer can change. |
| 37 | set -e |
| 38 | cd "$(dirname "$0")/.." |
| 39 | DEV=$(pwd -P) |
| 40 | MIRROR=${MIRROR:-$DEV/../daimond-oss} |
| 41 | WORK=${WORK:-$HOME/.cache/daimond-repro-check} |
| 42 | |
| 43 | # Never under /tmp: it is a tmpfs, so a cargo target directory there is held in |
| 44 | # RAM and charged to whoever wrote it. |
| 45 | rm -rf "$WORK" |
| 46 | mkdir -p "$WORK/a/deeper/nested" |
| 47 | export CARGO_HOME="$WORK/cargo-home" |
| 48 | mkdir -p "$CARGO_HOME" |
| 49 | |
| 50 | echo "── cloning the public mirror into a path of its own" |
| 51 | git clone -q "$MIRROR" "$WORK/a/deeper/nested/clone" |
| 52 | cd "$WORK/a/deeper/nested/clone" |
| 53 | |
| 54 | # The sealed manifest names the pkg files, so the clone must carry the manifest |
| 55 | # of the release being checked. It is committed, so a clone already has it. |
| 56 | # |
| 57 | # WHICH RELEASE IS BEING CHECKED, THOUGH. `git clone` takes the mirror's |
| 58 | # COMMITTED state, and `dev/publish.mjs` says in its own header that it neither |
| 59 | # commits nor pushes. So a carve that has not been committed leaves this script |
| 60 | # cloning the PREVIOUS release, rebuilding it faithfully, comparing it against |
| 61 | # its own manifest and reporting OK -- a true statement about a release nobody |
| 62 | # asked about, arriving in the words of the one about to ship. Seq 115 was nearly |
| 63 | # sealed on a check of seq 114 that way, and seq 114 itself very likely on 113. |
| 64 | # |
| 65 | # The build id is what tells them apart, so it is compared rather than trusted. |
| 66 | # This is a MECHANISM where the release runbook had only an ordering: get the |
| 67 | # order wrong and the run stops, instead of congratulating you. |
| 68 | HERE_BUILD=$(node -e 'process.stdout.write(require("'"$DEV"'/www/manifest.json").build||"")' 2>/dev/null || true) |
| 69 | CLONE_BUILD=$(node -e 'process.stdout.write(require("./www/manifest.json").build||"")' 2>/dev/null || true) |
| 70 | if [ -z "$HERE_BUILD" ] || [ -z "$CLONE_BUILD" ]; then |
| 71 | echo "FAILED — could not read a build id from both manifests:" |
| 72 | echo " working tree: ${HERE_BUILD:-<none>} clone: ${CLONE_BUILD:-<none>}" |
| 73 | echo " A repro-check that cannot name the release it checked proves nothing." |
| 74 | exit 1 |
| 75 | fi |
| 76 | if [ "$HERE_BUILD" != "$CLONE_BUILD" ]; then |
| 77 | echo "FAILED — this would have checked the WRONG RELEASE." |
| 78 | echo " the working tree is sealed as: $HERE_BUILD" |
| 79 | echo " the mirror's clone carries: $CLONE_BUILD" |
| 80 | echo |
| 81 | echo " The carve has not been committed in $MIRROR, so a clone still holds the" |
| 82 | echo " previous release. Commit and push the mirror, THEN run this. Nothing is" |
| 83 | echo " wrong with the build; the check was about to be aimed at the wrong one." |
| 84 | exit 1 |
| 85 | fi |
| 86 | echo " both manifests name build $HERE_BUILD" |
| 87 | echo "── building as an outsider would" |
| 88 | rustup target add wasm32-unknown-unknown >/dev/null 2>&1 || true |
| 89 | bash dev/build-wasm.sh >"$WORK/build.log" 2>&1 || { |
| 90 | echo "FAILED — the public mirror does not build. Last lines:" |
| 91 | tail -20 "$WORK/build.log" |
| 92 | exit 1 |
| 93 | } |
| 94 | |
| 95 | echo "── comparing the rebuild against the sealed manifest" |
| 96 | node verify/check.mjs --dir www |
| 97 | |
| 98 | if [ "${SKIP_HAND:-0}" = "1" ]; then |
| 99 | echo "── the machine hand: skipped (SKIP_HAND=1)" |
| 100 | exit 0 |
| 101 | fi |
| 102 | |
| 103 | # ── The machine hand ──────────────────────────────────────────────────── |
| 104 | # |
| 105 | # Two questions, and neither of them is "are the bytes the same". The hand runs |
| 106 | # programs on the reader's computer, so what they need before they install it is |
| 107 | # that the source in their hands is the sealed source, and that it is a thing |
| 108 | # that actually builds. |
| 109 | echo "── the machine hand: is this the sealed source" |
| 110 | node verify/check.mjs --hand hand |
| 111 | |
| 112 | echo "── the machine hand: does the published source build" |
| 113 | # `--manifest-path`, never `-p`: the hand is its own cargo workspace. And a |
| 114 | # target directory of its own under $WORK, because /tmp is a tmpfs and a cargo |
| 115 | # target there is held in RAM. |
| 116 | export CARGO_TARGET_DIR="$WORK/hand-target" |
| 117 | if ! cargo build --release --manifest-path hand/Cargo.toml >"$WORK/hand-build.log" 2>&1; then |
| 118 | echo "FAILED — the published hand does not build. Last lines:" |
| 119 | tail -20 "$WORK/hand-build.log" |
| 120 | exit 1 |
| 121 | fi |
| 122 | BIN="$CARGO_TARGET_DIR/release/daimond-hand" |
| 123 | echo " built $(du -h "$BIN" | cut -f1) at $BIN" |
| 124 | echo |
| 125 | echo " Not claimed: that this binary is byte-identical to anyone else's. It is not" |
| 126 | echo " compared with one, because no hand binary is published and a Rust release" |
| 127 | echo " build is not reproducible across toolchain versions. What is shown is that" |
| 128 | echo " the published source is the sealed source and that it compiles as written." |