Commit 060250459e

060250459e855670cd3bba6fab3c1641ef5c0c46

parent: 748122ef10

Verified · cmc ci/build: success ci/test: failure

cmc <hello@cleberg.net> · 2026-09-29 03:46 UTC

wiki, changelog: flood test checks the log; runner needs build cgroups on the forge's host

Ref #260

Layout: unified · split

.gitbay/wiki/CI.org +2 −1
@@ -98,7 +98,8 @@ To check a runner, run =deploy/runner-auth-flood-test.sh= against a
9898scratch repository, once as a push and once with =--untrusted=: the
9999build probes what it reaches, then fails SSH logins with an expired key
100100until the limiter locks its address, and the script checks that the
101runner still reported the build and kept polling.
101runner still reported the build and kept polling, and that the build's
102log shows what the table allowed and refused.
102103
103104* The table
104105
CHANGELOG.org +3 −1
@@ -22,7 +22,9 @@ anything beyond "replace the binary and restart" is needed.
2222 private range; a trusted build keeps the internet and the forge's public 22,
2323 80 and 443; an untrusted build gets TCP 80 and 443 and DNS, and not
2424 the forge. The runner's drop-in creates the cgroups and loads the
25 table on every start, and the start fails without it. =make
25 table on every start, and the start fails without it. A runner
26 with =-untrusted= or a loopback =-remote= refuses to start without
27 build cgroups, which the table needs to match anything. =make
2628 deploy-runner= installs it. =deploy/runner-auth-flood-test.sh= runs
2729 the scratch-repository test: a build failing SSH logins must not
2830 lock the runner out. Run it before pointing the runner back at real