Commit 42d56acf6e
Verified · cmc
Layout: unified · split
deploy/runner-podman-setup.sh +11
| @@ -73,6 +73,17 @@ printf '[storage]\ndriver = "overlay"\ngraphroot = "%s/.local/share/containers/s | |||
| 73 | chown "$RUNNER_USER:$RUNNER_USER" "$conf" | 73 | chown "$RUNNER_USER:$RUNNER_USER" "$conf" |
| 74 | echo " written" | 74 | echo " written" |
| 75 | 75 | ||
| 76 | # podman sets net.ipv4.ping_group_range in every container by default, | ||
| 77 | # for unprivileged ping. The service runs with ProtectKernelTunables, so | ||
| 78 | # /proc/sys is read-only and crun fails to start the container with | ||
| 79 | # "open /proc/sys/net/ipv4/ping_group_range: Read-only file system". A | ||
| 80 | # build has no use for ping; drop the default rather than the hardening. | ||
| 81 | cconf="$home/.config/containers/containers.conf" | ||
| 82 | echo "==> container defaults in $cconf" | ||
| 83 | printf '[containers]\ndefault_sysctls = []\n' >"$cconf" | ||
| 84 | chown "$RUNNER_USER:$RUNNER_USER" "$cconf" | ||
| 85 | echo " written" | ||
| 86 | |||
| 76 | # Lingering keeps the user's systemd session alive when nobody is logged | 87 | # Lingering keeps the user's systemd session alive when nobody is logged |
| 77 | # in, which podman's pause process relies on. | 88 | # in, which podman's pause process relies on. |
| 78 | echo "==> lingering for $RUNNER_USER" | 89 | echo "==> lingering for $RUNNER_USER" |