Commit 060250459e
Verified · cmc ci/build: success ci/test: failure
Layout: unified · split
.gitbay/wiki/CI.org +2 −1
| @@ -98,7 +98,8 @@ To check a runner, run =deploy/runner-auth-flood-test.sh= against a | ||
| 98 | 98 | scratch repository, once as a push and once with =--untrusted=: the |
| 99 | 99 | build probes what it reaches, then fails SSH logins with an expired key |
| 100 | 100 | until the limiter locks its address, and the script checks that the |
| 101 | runner still reported the build and kept polling. | |
| 101 | runner still reported the build and kept polling, and that the build's | |
| 102 | log shows what the table allowed and refused. | |
| 102 | 103 | |
| 103 | 104 | * The table |
| 104 | 105 | |
CHANGELOG.org +3 −1
| @@ -22,7 +22,9 @@ anything beyond "replace the binary and restart" is needed. | ||
| 22 | 22 | private range; a trusted build keeps the internet and the forge's public 22, |
| 23 | 23 | 80 and 443; an untrusted build gets TCP 80 and 443 and DNS, and not |
| 24 | 24 | the forge. The runner's drop-in creates the cgroups and loads the |
| 25 | table on every start, and the start fails without it. =make | |
| 25 | table on every start, and the start fails without it. A runner | |
| 26 | with =-untrusted= or a loopback =-remote= refuses to start without | |
| 27 | build cgroups, which the table needs to match anything. =make | |
| 26 | 28 | deploy-runner= installs it. =deploy/runner-auth-flood-test.sh= runs |
| 27 | 29 | the scratch-repository test: a build failing SSH logins must not |
| 28 | 30 | lock the runner out. Run it before pointing the runner back at real |