!PbtOpdWBSRFbEZRLIf:numtide.com

Nix Community Projects

644 Members
Meta discussions related to https://nix-community.org. (For project specific discussions use github issues or projects own matrix channel). Need help from an admin? Open an issue on https://github.com/nix-community/infra/issues163 Servers

Load older messages


SenderMessageTime
30 Nov 2023
@kranzes:matrix.orgIlan Joselevich (Kranzes)Hercules uses runc for its effects 16:11:59
@kranzes:matrix.orgIlan Joselevich (Kranzes)So there's lots of layers of hardening and sandboxing16:12:20
@kranzes:matrix.orgIlan Joselevich (Kranzes)Robert might just be paranoid 16:12:27
@kranzes:matrix.orgIlan Joselevich (Kranzes)Because that used to be his main reason against it16:12:42
@joerg:thalheim.ioMic92Maybe this is also to make the environment that is local the same as on the ci machine16:12:54
@kranzes:matrix.orgIlan Joselevich (Kranzes)Effects are basically rootless oci containers with access to the Internet and nix daemon of host16:14:26
@kranzes:matrix.orgIlan Joselevich (Kranzes)I also have a PR open for adding systemd hardening to the agent on top of that 16:15:25
@roberthensing:matrix.orgRobert Hensing (roberth)I'm in the process of doing some optimizations around Hercules' I/O, which is currently where the eval latency is18:15:08
@roberthensing:matrix.orgRobert Hensing (roberth)Indeed effect sandbox is for both security and reproducibility of the environment18:15:34
1 Dec 2023
@lotte:chir.rs@lotte:chir.rs changed their profile picture.09:44:32
@moritz.hedtke:matrix.orgMoritz Hedtke set their display name to Moritz Hedtke.11:08:12
@zowoq:matrix.orgzowoqWe're switching a couple of the community machines for better ones, the CI systems and the build box may be down for a bit but hopefully not for too long.21:35:32
@kranzes:matrix.orgIlan Joselevich (Kranzes)What specs difference?22:13:17
2 Dec 2023
@zowoq:matrix.orgzowoqThe new machine is a ryzen 9 3900 12 core, 128gb RAM, 2x 1.92tb nvme for CI (buildbot/hercules/hydra). The machine that used to do CI will become the community build box. See https://github.com/nix-community/infra/pull/989. 00:17:14
@mao_tse-tung:matrix.orgmao_tse-tung joined the room.04:20:32
3 Dec 2023
@joerg:thalheim.ioMic92 zowoq: raitobezarius It would be interesting if change fixes the github race condition that you see in lanzaboote: https://github.com/Mic92/buildbot-nix/commit/590f31eb6f205a47313a3525cd504fa4a405b6a4#diff-df8c266d76f942a320d71b583a24da5fa8ecd8135993a696f376dbd960359be7R334 15:23:25
@joerg:thalheim.ioMic92(not yet deployed on build03)15:23:31
@joerg:thalheim.ioMic92Do you have a better way of reproducing the issue?15:24:20
@joerg:thalheim.ioMic92I wasn't able to trigger this anymore15:24:33
@zowoq:matrix.orgzowoq
In reply to @joerg:thalheim.io
(not yet deployed on build03)
It has been deployed.
22:25:55
4 Dec 2023
@kranzes:matrix.orgIlan Joselevich (Kranzes)do we have some community darwin box I can use?03:06:00
@lily:lily.flowersLily Foster
In reply to @kranzes:matrix.org
do we have some community darwin box I can use?
https://nix-community.org/community-builder/
03:07:36
@kranzes:matrix.orgIlan Joselevich (Kranzes)cheers03:09:48
@zowoq:matrix.orgzowoq
In reply to @joerg:thalheim.io
zowoq: raitobezarius It would be interesting if change fixes the github race condition that you see in lanzaboote: https://github.com/Mic92/buildbot-nix/commit/590f31eb6f205a47313a3525cd504fa4a405b6a4#diff-df8c266d76f942a320d71b583a24da5fa8ecd8135993a696f376dbd960359be7R334
Looks like it worked, retried this automatically. https://buildbot.nix-community.org/#/builders/6/builds/52
03:14:06
@kranzes:matrix.orgIlan Joselevich (Kranzes)image.png
Download image.png
03:14:23
@kranzes:matrix.orgIlan Joselevich (Kranzes)#100003:14:25
@kranzes:matrix.orgIlan Joselevich (Kranzes)🚀03:14:29
@kranzes:matrix.orgIlan Joselevich (Kranzes)

zowoq

[kranzes@pongo ~]$ ssh darwin-build-box.nix-community.org
kranzes@darwin-build-box.nix-community.org: Permission denied (publickey).

seems to have deployed already, is there anything else that needs to be done?

03:24:10
@zowoq:matrix.orgzowoqNo, it should be working.03:52:08
@kranzes:matrix.orgIlan Joselevich (Kranzes)
In reply to @zowoq:matrix.org
No, it should be working.
That's really weird then
03:55:25

Show newer messages


Back to Room ListRoom Version: 6