Skip to content

🩺 Runner Doctor Update3 new self-hosted lessons: pids-limit/cgroup visibility (B21), strict-mode host-ports confirmation (B22), Copilot tool-cache-hit [Content truncated due to length] #7159

Description

@github-actions

Summary

  • Scan window: updated:>=2026-08-07 on github/gh-aw-firewall.
  • Reviewed all issues/PRs updated since 2026-08-07 (~50+ items); most were dependency bumps or unrelated enclave/Firecracker feature work.
  • Found 3 genuinely new, not-yet-captured lessons relevant to self-hosted/sandbox behavior (none of their citation numbers appear in the current catalog).

Proposed knowledge-base changes

For .github/workflows/shared/self-hosted-failure-modes.md, append to Category B — Self-hosted runners:

B21 | unable to create native thread / Cannot create worker GC thread from concurrent JVM builds (javac, Android manifest merger) inside the AWF agent container; /sys/fs/cgroup exposes no pids.max/pids.current, ulimit -u reports unlimited | AWF hardcoded Docker's pids_limit to 1000 with no visibility or configurability, so JVM tools can't discover or size against the real ceiling | Fixed in AWF (PR #7150, merged 2026-08-09): new --pids-limit <n> CLI flag (default 1000, matches prior behavior) with container.pidsLimit config-file support, plumbed through cli-options.ts → validators/log-and-limits.ts (parsePidsLimit) → build-config.ts → services/agent-service.ts. containers/agent/entrypoint.sh adds mount_host_cgroupfs() (best-effort) to bind-mount the container's delegated /sys/fs/cgroup read-only onto /host/sys/fs/cgroup so pids.max/pids.current are visible inside chroot. | Inside agent: cat /host/sys/fs/cgroup/pids.max — presence confirms fix; raise ceiling with --pids-limit 4000 for concurrent JVM builds | #7148, #7150

B22 | Strict-security (--network-isolation, no --legacy-security) workflows appear unable to reach a GitHub Actions services: container port (e.g. Postgres 5432) via --enable-host-access | Not an AWF defect — applySecurityMode() already preserves --enable-host-access/--allow-host-ports in strict mode (host access is served via Squid port ACLs + host.docker.internal hosts-file entry, not host iptables). The gh-aw compiler is the actual gap: it only emits these flags in legacy-security mode with a hardcoded 80,443, port list, never deriving ports from services:. | Confirmed and documented in AWF (PR #7152, merged 2026-08-09), no code change needed: docs/awf-config-spec.md now states security.allowHostPorts works standalone with security.enableHostAccess in strict mode; docs/usage.md adds a worked psql -h host.docker.internal -p 5432 example; regression test added in security-mode.test.ts. The gh-aw-side compiler fix (deriving ports from services:) remains open — tracked separately in #7132. | awf --enable-host-access --allow-host-ports 5432 --allow-domains host.docker.internal -- psql -h host.docker.internal -p 5432 ... in strict mode (no --legacy-security) — succeeds on documented AWF versions | #7149, #7152 (compiler-side gap still open: #7132)

B23 | Copilot-engine workflows fail with spawn /usr/local/bin/copilot ENOENT specifically when the runner's tool-cache already has copilot-cli installed (cache hit) | Not an AWF defect. gh-aw's install_copilot_cli.sh activate_cached_copilot_bin() prepends the cached dir to PATH and returns early on cache hits (skipping the wrapper install to /usr/local/bin/copilot), while the compiler-emitted harness (copilot_harness.cjs) always spawns the hardcoded absolute path /usr/local/bin/copilot. AWF's agent container mounts host /usr//usr/local read-only, reflecting host state at container start — a workaround symlink must exist on the host before awf is invoked. | No AWF code change (documentation only, PR #7151, merged 2026-08-09): docs/troubleshooting.md gets a "Harness Binary Resolution Issues" section explaining the read-only /usr mount timing and that chroot.binariesSourcePath only helps PATH-based lookups, not hardcoded-absolute-path harness bugs. Durable fix belongs in gh-aw's installer/harness (tracked as #7130, open). Workaround: sudo ln -sf "$(command -v copilot)" /usr/local/bin/copilot on the host, before invoking awf. | ls -la /usr/local/bin/copilot on the host before running awf — absence combined with a tool-cache hit reproduces the ENOENT; confirm gh-aw's installer took the cache-hit path (GITHUB_PATH already set) | #7130, #7147, #7151

Proposed doctor changes

For .github/workflows/self-hosted-runner-doctor.md:

  • Add B21/B22/B23 rows to the embedded/linked catalog reference (if inlined) and to the error-string quick-lookup table:
    • unable to create native thread / Cannot create worker GC thread inside AWF agent → B21
    • spawn /usr/local/bin/copilot ENOENT specifically on a tool-cache hit (distinguish from the general PATH-resolution note already covered elsewhere) → B23

Proposed portable agent changes

For .github/agents/self-hosted-runner-doctor.md: mirror the same three B21/B22/B23 catalog rows and the two new quick-lookup entries above so the portable, self-contained doctor stays in sync with shared/self-hosted-failure-modes.md and self-hosted-runner-doctor.md.

Source issues and PRs

Generated by Runner Doctor Updater · auto · 45.8 AIC · ⊞ 39.4K · ◷

  • expires on Sep 8, 2026, 7:11 PM UTC

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions