Commit f5b05a2161

f5b05a21614553542cc8a1804151d16976fd7a73

parent: 060250459e

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-29 03:53 UTC

runner: report a missing image or podman before missing build cgroups

Ref #260

Layout: unified · split

cmd/gitbay-runner/main.go +10 −9
@@ -127,19 +127,12 @@ func main() {
127127 memory: *memory,
128128 cpus: *cpus,
129129 }
130 var cgErr error
130131 if r.isolation == isolationPodman {
131132 // Before podman runs anything: its pause process lands in the
132133 // cgroup of the first invocation, and that must be the runner's
133134 // leaf, not a build's.
134 cg, err := prepareBuildCgroups()
135 switch why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); {
136 case err == nil:
137 r.cgroups = cg
138 case why != "":
139 log.Fatalf("%s: build cgroups unavailable: %v", why, err)
140 default:
141 log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", err)
142 }
135 r.cgroups, cgErr = prepareBuildCgroups()
143136 }
144137 if err := r.checkIsolation(); err != nil {
145138 // Refusing to start is the point. A runner that quietly fell back
@@ -149,6 +142,14 @@ func main() {
149142 // one of them is honest about why (#144).
150143 log.Fatalf("isolation: %v", err)
151144 }
145 if cgErr != nil {
146 // After checkIsolation, so a missing image or podman is reported
147 // as that rather than as the cgroups it would also lack.
148 if why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); why != "" {
149 log.Fatalf("%s: build cgroups unavailable: %v", why, cgErr)
150 }
151 log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", cgErr)
152 }
152153 if *sshOpts != "" {
153154 r.sshOpts = strings.Fields(*sshOpts)
154155 }