Commit d4c806be81
Verified · cmc ci/build: success ci/test: success
deploy/gitbay-runner.override.conf +9 −1
| @@ -103,7 +103,15 @@ ProtectSystem=full | ||
| 103 | 103 | # as this user — the container now covers: a build gets its own proc, |
| 104 | 104 | # with those paths masked by the runtime. Under -isolation none, set it |
| 105 | 105 | # back to yes. |
| 106 | ProtectControlGroups=yes | |
| 106 | # ProtectControlGroups is off because the runner writes cgroups: it | |
| 107 | # creates one per build under this unit's delegated cgroup to carry | |
| 108 | # -memory and -cpus (#188). The flag mounts /sys/fs/cgroup read-only in | |
| 109 | # the unit's namespace, which makes even a delegated cgroup unwritable, | |
| 110 | # and the runner then refuses to start when a limit is set. Delegate=yes | |
| 111 | # already hands this unit its subtree; what the flag protected beyond | |
| 112 | # that is other units' cgroups, which are root-owned and not writable | |
| 113 | # by this user regardless. | |
| 114 | ProtectControlGroups=no | |
| 107 | 115 | RestrictSUIDSGID=yes |
| 108 | 116 | Delegate=yes |
| 109 | 117 | # The runner's home is /var/lib/gitbay-runner (see the Admin page), and |