benchstandard

command
v1.2.11 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 11, 2026 License: MIT Imports: 19 Imported by: 0

Documentation

Overview

Command benchstandard is the acceptance WITNESS for a Linux bench: it checks the bench it runs on against the standard and prints one DRIFT line per finding.

It is a witness and never a provisioner. It installs no package, creates no user, writes no unit file, arms no timer, mounts nothing and authorizes no seat key; all of that is the fleet declaration's job, and a DRIFT line is the witness that the declaration and the host disagree, not a ticket for this tool to repair. Its one mutation is --apply, which sends SIGTERM to stray runner listeners: a process holding the runner's listener that is not under the runner's systemd unit. No other action is taken on any path, with or without --apply.

The checks, in the order they print: each self-hosted runner has one listener under its unit and a unit file with the standard stanzas (Linux only); the toolchain roots the sandbox wall grants exist; go is the version go.mod names; go and sbcl can be EXECUTED inside the wall, not merely found on PATH; sbcl is the pinned version under $HOME/sdk; the pro rung and sqlite3 under $HOME/sdk are present; NOVA_SLOT_SHARE is declared; the agent harness exists and starts inside the wall, and the network is reachable from inside it (Linux only); each nova binary reports the wanted version; exactly one seat key exists per owner and the secrets tool accepts it; no plaintext provider key is on the bench; the disk has headroom.

Exit 0 prints "STANDARD OK ..."; exit 1 prints "STANDARD DRIFT (see lines above)" after the DRIFT lines.

The witness runs ON the bench, so it must not need the toolchain it judges: a bench whose go is the thing in doubt cannot `go run` it. Build it as a static binary on another machine, copy it over, and run it there:

GOOS=linux GOARCH=amd64 CGO_ENABLED=0 go build -o bin/benchstandard ./tools/benchstandard
scp bin/benchstandard bench:
ssh bench NOVA_WANT=v1.2.3 NOVA_GO=go1.26.5 NOVA_SLOT_SHARE=64 ./benchstandard

On a bench whose go is good, `go run ./tools/benchstandard` from a checkout does the same, and reads the wanted go from that checkout's go.mod.

Environment:

NOVA_GO            the wanted go, such as go1.26.5; default the `go` line of go.mod
                   in the directory above the binary, or above the working directory
NOVA_WANT          the wanted nova version each binary reports
NOVA_SBCL          the pinned sbcl version (default 2.5.8)
NOVA_SLOT_SHARE    the bench's declared slot share, a positive whole number
NOVA_PRO_RUNG      an executable that is the pro rung
NOVA_HARNESS       the harness binary, instead of $HOME/nova-bench/harness-*/opencode
NOVA_PROBE_URL     the URL the sandbox's network probe fetches
NOVA_SECRETS_STORE the seat store for the seat check
NOVA_MIN_FREE_G    the disk floor in gigabytes (default 25)
NOVA_RESOLV_CONF   the resolver file the wall's resolver directory is read from

The card's environment is built before any tool is resolved: if $HOME/sdk/env.sh exists it is sourced, so the verdict does not depend on the caller's PATH.

example:
  NOVA_WANT=v1.2.3 NOVA_SLOT_SHARE=64 benchstandard
  DRIFT sbcl version [SBCL 2.6.0] want 2.5.8 (NOVA_SBCL)
  STANDARD DRIFT (see lines above)

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL