Commit f5b05a2161
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
cmd/gitbay-runner/main.go +10 −9
| @@ -127,19 +127,12 @@ func main() { | |||
| 127 | memory: *memory, | 127 | memory: *memory, |
| 128 | cpus: *cpus, | 128 | cpus: *cpus, |
| 129 | } | 129 | } |
| 130 | var cgErr error | ||
| 130 | if r.isolation == isolationPodman { | 131 | if r.isolation == isolationPodman { |
| 131 | // Before podman runs anything: its pause process lands in the | 132 | // Before podman runs anything: its pause process lands in the |
| 132 | // cgroup of the first invocation, and that must be the runner's | 133 | // cgroup of the first invocation, and that must be the runner's |
| 133 | // leaf, not a build's. | 134 | // leaf, not a build's. |
| 134 | cg, err := prepareBuildCgroups() | 135 | r.cgroups, cgErr = prepareBuildCgroups() |
| 135 | switch why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); { | ||
| 136 | case err == nil: | ||
| 137 | r.cgroups = cg | ||
| 138 | case why != "": | ||
| 139 | log.Fatalf("%s: build cgroups unavailable: %v", why, err) | ||
| 140 | default: | ||
| 141 | log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", err) | ||
| 142 | } | ||
| 143 | } | 136 | } |
| 144 | if err := r.checkIsolation(); err != nil { | 137 | if err := r.checkIsolation(); err != nil { |
| 145 | // Refusing to start is the point. A runner that quietly fell back | 138 | // Refusing to start is the point. A runner that quietly fell back |
| @@ -149,6 +142,14 @@ func main() { | |||
| 149 | // one of them is honest about why (#144). | 142 | // one of them is honest about why (#144). |
| 150 | log.Fatalf("isolation: %v", err) | 143 | log.Fatalf("isolation: %v", err) |
| 151 | } | 144 | } |
| 145 | if cgErr != nil { | ||
| 146 | // After checkIsolation, so a missing image or podman is reported | ||
| 147 | // as that rather than as the cgroups it would also lack. | ||
| 148 | if why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); why != "" { | ||
| 149 | log.Fatalf("%s: build cgroups unavailable: %v", why, cgErr) | ||
| 150 | } | ||
| 151 | log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", cgErr) | ||
| 152 | } | ||
| 152 | if *sshOpts != "" { | 153 | if *sshOpts != "" { |
| 153 | r.sshOpts = strings.Fields(*sshOpts) | 154 | r.sshOpts = strings.Fields(*sshOpts) |
| 154 | } | 155 | } |