From a9f6ab7cd9b56a996f64ba7bad569f5a3d92d95b Mon Sep 17 00:00:00 2001 From: igneum-josh <337424239+igneum-josh@users.noreply.github.com> Date: Wed, 7 Oct 2026 08:31:42 +0100 Subject: [PATCH] Observer sync follows GitHub: the deploy-key probe captured before grep (ssh -T exits 1 under pipefail); plan 5c done Josh added the read-only deploy key on 7 October 2026 (SHA256:51ice3W8...). The sync still said 'mirror' because ssh -T to GitHub exits 1 after its greeting and observer-sync.sh runs under pipefail, so su ... | grep -q reported failure although grep had matched (the same line by hand, without pipefail, said authenticated; shown under the unit's environment with systemd-run -v). The probe's output is captured first. First github pass 07:30:54 UTC: the clone moved from the mirror's 8397781 to origin/master 8aab05ce, the observer restarted on it. Co-Authored-By: Claude Fable 5.1 --- docs/plans/build-server.md | 11 ++++++++++- infra/build-server/hands/install-hands.sh | 5 ++++- 2 files changed, 14 insertions(+), 2 deletions(-) diff --git a/docs/plans/build-server.md b/docs/plans/build-server.md index df10fd16d..c56ba6f3b 100644 --- a/docs/plans/build-server.md +++ b/docs/plans/build-server.md @@ -120,7 +120,16 @@ Self-test: `tools/build-remote.sh --self-test-repro [--full]` from a fork worktr | Consequence: glibc ceiling 2.38 | runs on the fleet (Ubuntu 22.04 containers are glibc 2.35: NO, 2.38 > 2.35; Ubuntu 24.04 hosts yes). The Mac's zig build (`infra/cross/build-workers-linux.sh`, glibc 2.36) is the one for Debian 12 and HiveOS; the fleet agent must check its boxes' glibc before swapping the worker. Fix if needed: zig on the box (open row in section 6) or `clang -target x86_64-linux-gnu.2.35` via zig; both a day's work, not done | | Runner fix found on the way | a command string carrying `set -e` leaked into remote-run.sh through `eval` and killed the runner before its RESULT line (reported as rc 101); the runner now evaluates the command in a subshell | -## 5c. Deploy key for the observer clone (steps for Josh, 7 October 2026) +## 5c. Deploy key for the observer clone (DONE: Josh added the key on 7 October 2026, morning) + +Done. Josh added the public half as the read-only deploy key "igneum-build-1 observer (read-only)" (SHA256:51ice3W8...; the +organisation's deploy-key policy had to be switched to Enabled first). The sync's own test then still said "mirror": `ssh -T` to +GitHub exits 1 after its greeting and the script runs under pipefail, so `su ... | grep -q` reported failure although grep had +matched; fixed by capturing the output first (install-hands.sh). First pass reading "source: github (deploy key accepted)": +7 Oct 2026 07:30:54 UTC, "observer files changed (8aab05ce); restarting igneum-observer": the clone went from the mirror's 8397781 to +GitHub's master 8aab05ce in that pass, the observer restarted on it and is active; remote `github` = git@github-igneum-observer:igneum-network/igneum.git. The clone now follows origin/master every 5 minutes; the mirror stays the fallback whenever GitHub refuses. + +The steps as they were, for the record: The observer on the box runs tools/observer from a clone that follows the mirror `/srv/igneum.git`, which moves only when a Mac agent pushes. With a read-only deploy key it follows GitHub directly (every 5 minutes, `igneum-observer-sync.timer`). The key pair diff --git a/infra/build-server/hands/install-hands.sh b/infra/build-server/hands/install-hands.sh index bf5daf911..cff63a1cf 100755 --- a/infra/build-server/hands/install-hands.sh +++ b/infra/build-server/hands/install-hands.sh @@ -90,7 +90,10 @@ set -uo pipefail cd /srv/observer/igneum || exit 1 g() { su - build -c "git -C /srv/observer/igneum $*"; } # the clone is build's; root's git refuses it (safe.directory), so every git call runs as build before=$(g rev-parse HEAD:tools/observer HEAD:site/lib 2>/dev/null | tr '\n' ' ') -if su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 | grep -q "successfully authenticated"; then +# `ssh -T` to GitHub exits 1 after its greeting, so under this script's pipefail a `su ... | grep -q` reported failure although grep +# had matched (7 Oct 2026: the pass said "mirror" while the same line by hand said authenticated); the output is captured first +probe=$(su - build -c "ssh -o BatchMode=yes -o ConnectTimeout=10 -T git@github-igneum-observer" 2>&1 || true) +if grep -q "successfully authenticated" <<<"$probe"; then su - build -c "git -C /srv/observer/igneum remote get-url github >/dev/null 2>&1 || git -C /srv/observer/igneum remote add github git@github-igneum-observer:igneum-network/igneum.git" if su - build -c "git -C /srv/observer/igneum pull -q --ff-only github master" 2>&1 | head -2; then echo "source: github (deploy key accepted)"; else echo "source: github refused the pull, mirror next"; su - build -c "git -C /srv/observer/igneum pull -q --ff-only origin master" 2>&1 | head -2; fi else