Commit f5b05a2161
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
cmd/gitbay-runner/main.go +10 −9
| @@ -127,19 +127,12 @@ func main() { | ||
| 127 | 127 | memory: *memory, |
| 128 | 128 | cpus: *cpus, |
| 129 | 129 | } |
| 130 | var cgErr error | |
| 130 | 131 | if r.isolation == isolationPodman { |
| 131 | 132 | // Before podman runs anything: its pause process lands in the |
| 132 | 133 | // cgroup of the first invocation, and that must be the runner's |
| 133 | 134 | // leaf, not a build's. |
| 134 | cg, err := prepareBuildCgroups() | |
| 135 | switch why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); { | |
| 136 | case err == nil: | |
| 137 | r.cgroups = cg | |
| 138 | case why != "": | |
| 139 | log.Fatalf("%s: build cgroups unavailable: %v", why, err) | |
| 140 | default: | |
| 141 | log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", err) | |
| 142 | } | |
| 135 | r.cgroups, cgErr = prepareBuildCgroups() | |
| 143 | 136 | } |
| 144 | 137 | if err := r.checkIsolation(); err != nil { |
| 145 | 138 | // Refusing to start is the point. A runner that quietly fell back |
| @@ -149,6 +142,14 @@ func main() { | ||
| 149 | 142 | // one of them is honest about why (#144). |
| 150 | 143 | log.Fatalf("isolation: %v", err) |
| 151 | 144 | } |
| 145 | if cgErr != nil { | |
| 146 | // After checkIsolation, so a missing image or podman is reported | |
| 147 | // as that rather than as the cgroups it would also lack. | |
| 148 | if why := buildCgroupsRequired(r.memory, r.cpus, *untrusted, r.loopbackRemote()); why != "" { | |
| 149 | log.Fatalf("%s: build cgroups unavailable: %v", why, cgErr) | |
| 150 | } | |
| 151 | log.Printf("build cgroups unavailable (%v); builds run unconfined in the service cgroup", cgErr) | |
| 152 | } | |
| 152 | 153 | if *sshOpts != "" { |
| 153 | 154 | r.sshOpts = strings.Fields(*sshOpts) |
| 154 | 155 | } |