Fix service restarter test
Deploy HEOS panel / deploy (push) Failing after 44s

This commit is contained in:
2026-09-15 00:08:00 +02:00
parent 9a5f2ac639
commit ce8596945e
2 changed files with 34 additions and 4 deletions
+23 -3
View File
@@ -34,6 +34,7 @@ jobs:
- name: Check runner tools - name: Check runner tools
run: | run: |
echo "running as $(id -un) on $(hostname)"
command -v python3 command -v python3
command -v rsync command -v rsync
command -v curl command -v curl
@@ -43,8 +44,25 @@ jobs:
test -d "$DEPLOY_PATH" test -d "$DEPLOY_PATH"
test -w "$DEPLOY_PATH" test -w "$DEPLOY_PATH"
# `sudo -n -l <cmd>` asks "may I run this?" without prompting, so the
# job stops here with the line to add rather than deploying and then
# falling over on the restart at the very end.
- name: Check the restart is allowed without a password - name: Check the restart is allowed without a password
run: sudo -n systemctl is-active "$SERVICE" || true run: |
SYSTEMCTL="$(command -v systemctl)"
if sudo -n -l "$SYSTEMCTL" restart "$SERVICE" >/dev/null 2>&1; then
echo "$(id -un) may restart $SERVICE"
exit 0
fi
echo "$(id -un) cannot restart $SERVICE without a password. Once, here:"
echo
echo " echo '$(id -un) ALL=(ALL) NOPASSWD: $SYSTEMCTL restart $SERVICE' \\"
echo " | sudo tee /etc/sudoers.d/$SERVICE"
echo " sudo chmod 440 /etc/sudoers.d/$SERVICE"
echo
echo "The path matters: sudo matches what it resolves from PATH"
echo "against the sudoers line, without following symlinks."
exit 1
# A throwaway virtualenv in the workspace -- this is the npm ci of a # A throwaway virtualenv in the workspace -- this is the npm ci of a
# Python project. The one under $DEPLOY_PATH/.venv is what the running # Python project. The one under $DEPLOY_PATH/.venv is what the running
@@ -80,8 +98,10 @@ jobs:
test -d "$DEPLOY_PATH/.venv" || python3 -m venv "$DEPLOY_PATH/.venv" test -d "$DEPLOY_PATH/.venv" || python3 -m venv "$DEPLOY_PATH/.venv"
"$DEPLOY_PATH/.venv/bin/pip" install --quiet -r "$DEPLOY_PATH/requirements.txt" "$DEPLOY_PATH/.venv/bin/pip" install --quiet -r "$DEPLOY_PATH/requirements.txt"
# The same absolute path the check above validated, so PATH order
# cannot leave sudo matching a different one (/bin vs /usr/bin).
- name: Restart - name: Restart
run: sudo systemctl restart "$SERVICE" run: sudo -n "$(command -v systemctl)" restart "$SERVICE"
- name: Wait for the panel to answer - name: Wait for the panel to answer
run: | run: |
@@ -95,5 +115,5 @@ jobs:
sleep 1 sleep 1
done done
echo "panel did not come back -- last of its log:" echo "panel did not come back -- last of its log:"
sudo systemctl status "$SERVICE" --no-pager --lines 30 || true systemctl status "$SERVICE" --no-pager --lines 30 || true
exit 1 exit 1
+11 -1
View File
@@ -120,11 +120,21 @@ runner can write to is enough:
sudo mkdir -p /var/www/html/heos sudo mkdir -p /var/www/html/heos
sudo chown "$(id -un)": /var/www/html/heos sudo chown "$(id -un)": /var/www/html/heos
echo "$(id -un) ALL=(ALL) NOPASSWD: /usr/bin/systemctl restart heos-panel" \ echo "$(id -un) ALL=(ALL) NOPASSWD: $(command -v systemctl) restart heos-panel" \
| sudo tee /etc/sudoers.d/heos-panel | sudo tee /etc/sudoers.d/heos-panel
sudo chmod 440 /etc/sudoers.d/heos-panel sudo chmod 440 /etc/sudoers.d/heos-panel
``` ```
Run those **as the user the runner runs as**, not as yourself — the first
step of the workflow prints who that is. Two things in that sudoers line are
easy to get wrong, and the workflow checks both before it deploys anything,
printing the line back at you with the right values filled in:
- the user has to be the runner's, and
- the path has to be the one `sudo` resolves from `PATH`. It compares that
string against the sudoers line without following symlinks, so on a system
where `/bin` links to `/usr/bin` the two spellings are not interchangeable.
Then push. That first run deploys the files and builds the virtualenv, and Then push. That first run deploys the files and builds the virtualenv, and
stops at the restart, because the service does not exist yet. Install it stops at the restart, because the service does not exist yet. Install it
from the copy it just put there: from the copy it just put there: