Commit 060250459e
Verified · cmc ci/build: success ci/test: failure
Layout: unified · split
.gitbay/wiki/CI.org +2 −1
| @@ -98,7 +98,8 @@ To check a runner, run =deploy/runner-auth-flood-test.sh= against a | |||
| 98 | scratch repository, once as a push and once with =--untrusted=: the | 98 | scratch repository, once as a push and once with =--untrusted=: the |
| 99 | build probes what it reaches, then fails SSH logins with an expired key | 99 | build probes what it reaches, then fails SSH logins with an expired key |
| 100 | until the limiter locks its address, and the script checks that the | 100 | until the limiter locks its address, and the script checks that the |
| 101 | runner still reported the build and kept polling. | 101 | runner still reported the build and kept polling, and that the build's |
| 102 | log shows what the table allowed and refused. | ||
| 102 | 103 | ||
| 103 | * The table | 104 | * The table |
| 104 | 105 | ||
CHANGELOG.org +3 −1
| @@ -22,7 +22,9 @@ anything beyond "replace the binary and restart" is needed. | |||
| 22 | private range; a trusted build keeps the internet and the forge's public 22, | 22 | private range; a trusted build keeps the internet and the forge's public 22, |
| 23 | 80 and 443; an untrusted build gets TCP 80 and 443 and DNS, and not | 23 | 80 and 443; an untrusted build gets TCP 80 and 443 and DNS, and not |
| 24 | the forge. The runner's drop-in creates the cgroups and loads the | 24 | the forge. The runner's drop-in creates the cgroups and loads the |
| 25 | table on every start, and the start fails without it. =make | 25 | table on every start, and the start fails without it. A runner |
| 26 | with =-untrusted= or a loopback =-remote= refuses to start without | ||
| 27 | build cgroups, which the table needs to match anything. =make | ||
| 26 | deploy-runner= installs it. =deploy/runner-auth-flood-test.sh= runs | 28 | deploy-runner= installs it. =deploy/runner-auth-flood-test.sh= runs |
| 27 | the scratch-repository test: a build failing SSH logins must not | 29 | the scratch-repository test: a build failing SSH logins must not |
| 28 | lock the runner out. Run it before pointing the runner back at real | 30 | lock the runner out. Run it before pointing the runner back at real |