Observer sync follows GitHub: the deploy-key probe captured before grep (ssh -T exits 1 under pipefail); plan 5c done
Josh added the read-only deploy key on 7 October 2026 (SHA256:51ice3W8...). The sync still said 'mirror' because ssh -T to GitHub exits 1 after its greeting and observer-sync.sh runs under pipefail, so su ... | grep -q reported failure although grep had matched (the same line by hand, without pipefail, said authenticated; shown under the unit's environment with systemd-run -v). The probe's output is captured first. First github pass 07:30:54 UTC: the clone moved from the mirror's8397781to origin/master8aab05ce, the observer restarted on it. Co-Authored-By: Claude Fable 5.1 <noreply@anthropic.com>
This commit is contained in:
parent
8aab05ce8c
commit
a9f6ab7cd9
2 changed files with 14 additions and 2 deletions
|
|
@ -120,7 +120,16 @@ Self-test: `tools/build-remote.sh --self-test-repro [--full]` from a fork worktr
|
|||
| Consequence: glibc ceiling 2.38 | runs on the fleet (Ubuntu 22.04 containers are glibc 2.35: NO, 2.38 > 2.35; Ubuntu 24.04 hosts yes). The Mac's zig build (`infra/cross/build-workers-linux.sh`, glibc 2.36) is the one for Debian 12 and HiveOS; the fleet agent must check its boxes' glibc before swapping the worker. Fix if needed: zig on the box (open row in section 6) or `clang -target x86_64-linux-gnu.2.35` via zig; both a day's work, not done |
|
||||
| Runner fix found on the way | a command string carrying `set -e` leaked into remote-run.sh through `eval` and killed the runner before its RESULT line (reported as rc 101); the runner now evaluates the command in a subshell |
|
||||
|
||||
## 5c. Deploy key for the observer clone (steps for Josh, 7 October 2026)
|
||||
## 5c. Deploy key for the observer clone (DONE: Josh added the key on 7 October 2026, morning)
|
||||
|
||||
Done. Josh added the public half as the read-only deploy key "igneum-build-1 observer (read-only)" (SHA256:51ice3W8...; the
|
||||
organisation's deploy-key policy had to be switched to Enabled first). The sync's own test then still said "mirror": `ssh -T` to
|
||||
GitHub exits 1 after its greeting and the script runs under pipefail, so `su ... | grep -q` reported failure although grep had
|
||||
matched; fixed by capturing the output first (install-hands.sh). First pass reading "source: github (deploy key accepted)":
|
||||
7 Oct 2026 07:30:54 UTC, "observer files changed (8aab05ce); restarting igneum-observer": the clone went from the mirror's 8397781 to
|
||||
GitHub's master 8aab05ce in that pass, the observer restarted on it and is active; remote `github` = git@github-igneum-observer:igneum-network/igneum.git. The clone now follows origin/master every 5 minutes; the mirror stays the fallback whenever GitHub refuses.
|
||||
|
||||
The steps as they were, for the record:
|
||||
|
||||
The observer on the box runs tools/observer from a clone that follows the mirror `/srv/igneum.git`, which moves only when a Mac
|
||||
agent pushes. With a read-only deploy key it follows GitHub directly (every 5 minutes, `igneum-observer-sync.timer`). The key pair
|
||||
|
|
|
|||
|
|
@ -90,7 +90,10 @@ set -uo pipefail
|
|||
cd /srv/observer/igneum || exit 1
|
||||
g() { su - build -c "git -C /srv/observer/igneum $*"; } # the clone is build's; root's git refuses it (safe.directory), so every git call runs as build
|
||||
before=$(g rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ')
|
||||
if su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 | grep -q "successfully authenticated"; then
|
||||
# `ssh -T` to GitHub exits 1 after its greeting, so under this script's pipefail a `su ... | grep -q` reported failure although grep
|
||||
# had matched (7 Oct 2026: the pass said "mirror" while the same line by hand said authenticated); the output is captured first
|
||||
probe=$(su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 || true)
|
||||
if grep -q "successfully authenticated" <<<"$probe"; then
|
||||
su - build -c "git -C /srv/observer/igneum remote get-url github >/dev/null 2>&1 || git -C /srv/observer/igneum remote add github git@github-igneum-observer:igneum-network/igneum.git"
|
||||
if su - build -c "git -C /srv/observer/igneum pull -q --ff-only github master" 2>&1 | head -2; then echo "source: github (deploy key accepted)"; else echo "source: github refused the pull, mirror next"; su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2; fi
|
||||
else
|
||||
|
|
|
|||
Loading…
Reference in a new issue