Oregami
Repositories/oxedyne/daimond

oxedyne/daimond/dev/repro-check.sh

6.4 KiB, 1 run

created by r2519314175:117, which is this file's identity for as long as the history lasts, whatever it is later renamed to

download · who wrote it · its history

1#!/bin/bash
2# repro-check.sh -- prove that somebody else could reproduce the sealed bundle.
3#
4# The published claim is that a stranger can clone the public repository, build
5# it, and get the bytes the site serves. That is only ever true by accident
6# unless it is checked the way a stranger would experience it, so this does
7# exactly that and nothing cheaper:
8#
9# * a FRESH CLONE of the public mirror, not the working tree, because the
10# working tree carries generated files and uncommitted fixes that a cloner
11# will not have -- that is how the mirror's Cargo.toml sat broken with path
12# dependencies from 2026-07-21 to 2026-07-27, unbuildable by anyone outside
13# while every local build kept working;
14# * a SEPARATE cargo home and a DIFFERENT directory depth, because build paths
15# get baked into the binary. Rebuilding where it was sealed proves nothing:
16# it is the one arrangement guaranteed to agree with itself.
17#
18# It then compares the rebuild against the SEALED MANIFEST, so the thing under
19# test is the released bundle rather than another copy of itself.
20#
21# THE MACHINE HAND IS CHECKED DIFFERENTLY, AND PROVES LESS. The hand is a native
22# binary, not wasm: nobody publishes one, everybody builds their own, and a Rust
23# release build is not byte-identical across toolchain versions. So there is no
24# binary comparison to make and none is attempted. What is checked instead is the
25# pair of things that are true: the published source is exactly what was sealed
26# (`verify/hand.json`), and the published source BUILDS -- from the clone, with
27# the pinned toolchain, using the command the seal names. The second is not a
28# formality: the hand pins fe2o3 by git revision, and a revision that was never
29# pushed, or that no longer has the API the hand calls, produces a mirror that
30# reads fine and compiles for nobody.
31#
32# bash dev/repro-check.sh # ~8 minutes, mostly cold dependency builds
33# SKIP_HAND=1 bash dev/repro-check.sh
34#
35# Slow and disk-hungry by nature, so it is not part of `run_all.sh`. Run it at
36# release, which is the only time its answer can change.
37set -e
38cd "$(dirname "$0")/.."
39DEV=$(pwd -P)
40MIRROR=${MIRROR:-$DEV/../daimond-oss}
41WORK=${WORK:-$HOME/.cache/daimond-repro-check}
42
43# Never under /tmp: it is a tmpfs, so a cargo target directory there is held in
44# RAM and charged to whoever wrote it.
45rm -rf "$WORK"
46mkdir -p "$WORK/a/deeper/nested"
47export CARGO_HOME="$WORK/cargo-home"
48mkdir -p "$CARGO_HOME"
49
50echo "── cloning the public mirror into a path of its own"
51git clone -q "$MIRROR" "$WORK/a/deeper/nested/clone"
52cd "$WORK/a/deeper/nested/clone"
53
54# The sealed manifest names the pkg files, so the clone must carry the manifest
55# of the release being checked. It is committed, so a clone already has it.
56#
57# WHICH RELEASE IS BEING CHECKED, THOUGH. `git clone` takes the mirror's
58# COMMITTED state, and `dev/publish.mjs` says in its own header that it neither
59# commits nor pushes. So a carve that has not been committed leaves this script
60# cloning the PREVIOUS release, rebuilding it faithfully, comparing it against
61# its own manifest and reporting OK -- a true statement about a release nobody
62# asked about, arriving in the words of the one about to ship. Seq 115 was nearly
63# sealed on a check of seq 114 that way, and seq 114 itself very likely on 113.
64#
65# The build id is what tells them apart, so it is compared rather than trusted.
66# This is a MECHANISM where the release runbook had only an ordering: get the
67# order wrong and the run stops, instead of congratulating you.
68HERE_BUILD=$(node -e 'process.stdout.write(require("'"$DEV"'/www/manifest.json").build||"")' 2>/dev/null || true)
69CLONE_BUILD=$(node -e 'process.stdout.write(require("./www/manifest.json").build||"")' 2>/dev/null || true)
70if [ -z "$HERE_BUILD" ] || [ -z "$CLONE_BUILD" ]; then
71 echo "FAILED — could not read a build id from both manifests:"
72 echo " working tree: ${HERE_BUILD:-<none>} clone: ${CLONE_BUILD:-<none>}"
73 echo " A repro-check that cannot name the release it checked proves nothing."
74 exit 1
75fi
76if [ "$HERE_BUILD" != "$CLONE_BUILD" ]; then
77 echo "FAILED — this would have checked the WRONG RELEASE."
78 echo " the working tree is sealed as: $HERE_BUILD"
79 echo " the mirror's clone carries: $CLONE_BUILD"
80 echo
81 echo " The carve has not been committed in $MIRROR, so a clone still holds the"
82 echo " previous release. Commit and push the mirror, THEN run this. Nothing is"
83 echo " wrong with the build; the check was about to be aimed at the wrong one."
84 exit 1
85fi
86echo " both manifests name build $HERE_BUILD"
87echo "── building as an outsider would"
88rustup target add wasm32-unknown-unknown >/dev/null 2>&1 || true
89bash dev/build-wasm.sh >"$WORK/build.log" 2>&1 || {
90 echo "FAILED — the public mirror does not build. Last lines:"
91 tail -20 "$WORK/build.log"
92 exit 1
93}
94
95echo "── comparing the rebuild against the sealed manifest"
96node verify/check.mjs --dir www
97
98if [ "${SKIP_HAND:-0}" = "1" ]; then
99 echo "── the machine hand: skipped (SKIP_HAND=1)"
100 exit 0
101fi
102
103# ── The machine hand ────────────────────────────────────────────────────
104#
105# Two questions, and neither of them is "are the bytes the same". The hand runs
106# programs on the reader's computer, so what they need before they install it is
107# that the source in their hands is the sealed source, and that it is a thing
108# that actually builds.
109echo "── the machine hand: is this the sealed source"
110node verify/check.mjs --hand hand
111
112echo "── the machine hand: does the published source build"
113# `--manifest-path`, never `-p`: the hand is its own cargo workspace. And a
114# target directory of its own under $WORK, because /tmp is a tmpfs and a cargo
115# target there is held in RAM.
116export CARGO_TARGET_DIR="$WORK/hand-target"
117if ! cargo build --release --manifest-path hand/Cargo.toml >"$WORK/hand-build.log" 2>&1; then
118 echo "FAILED — the published hand does not build. Last lines:"
119 tail -20 "$WORK/hand-build.log"
120 exit 1
121fi
122BIN="$CARGO_TARGET_DIR/release/daimond-hand"
123echo " built $(du -h "$BIN" | cut -f1) at $BIN"
124echo
125echo " Not claimed: that this binary is byte-identical to anyone else's. It is not"
126echo " compared with one, because no hand binary is published and a Rust release"
127echo " build is not reproducible across toolchain versions. What is shown is that"
128echo " the published source is the sealed source and that it compiles as written."