Repository navigation
Expand self-hosted runner diagnostics for GHES, orphaned networks, and ARC/DinD logs - #9207
Conversation
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Canonical registry outputs and B27/C5 records are incomplete, the A28 probe violates the read-only contract, and portable routing is missing entries.
Review effort: Balanced
Findings: 1
Open (4)
What changed in this PR
Expands runner-doctor diagnostics for ARC/DinD streaming logs, orphaned networks, and GHES metadata handling.
Changes:
- Adds A28 and updates B27/C5 guidance.
- Mirrors diagnostics across workflow and portable-agent artifacts.
- Updates regression assertions and generated workflow metadata.
| File | Description |
|---|---|
scripts/ci/self-hosted-runner-doctor-workflow.test.ts |
Extends alignment assertions. |
docs/diagnostics/findings/runner/A28.json |
Adds canonical A28 finding. |
.github/workflows/shared/self-hosted-failure-modes.md |
Updates shared diagnostic catalog. |
.github/workflows/self-hosted-runner-doctor.md |
Adds probes and symptom routing. |
.github/workflows/self-hosted-runner-doctor.lock.yml |
Updates generated workflow hash. |
.github/agents/self-hosted-runner-doctor.md |
Updates portable diagnostic guidance. |
💡 Configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
| { | ||
| "$schema": "../../schema.json", | ||
| "id": "A28", |
| - `error mounting "/dev/null" to .../.npmrc: create mountpoint ...: read-only file system` on `arc-dind` persisting even after upgrading past github/gh-aw-firewall#7998 (A23's fix), where the credential mountpoint is missing under a declared-`rw` home bind backed by a genuinely read-only directory → A24 (`pruneUnmountableCredentialOverlays` only checked declared bind mode, never real filesystem writability for `rw`-declared covers; fixed in github/gh-aw-firewall#8086) | ||
| - `docker network connect --alias <name> awf-net <service_container>` is needed for raw-protocol GitHub Actions `services:` containers under `runner.topology: arc-dind` → A25 (service container must join `awf-net` for direct protocol access while the agent stays isolated; documented in github/gh-aw-firewall#8085) | ||
| - `a network with name awf-net exists but was not created for project` → B27 (orphaned fixed-name `awf-net` from a prior run on a persistent self-hosted runner; fixed in github/gh-aw-firewall#7817) | ||
| - `a network with name awf-net exists but was not created for project`, or a missing bridge in legacy iptables mode → B27 (inspect `docker network inspect awf-net --format '{{json .Options}}'`; an empty options map without `com.docker.network.bridge.name` identifies an unoccupied orphan; fixed in github/gh-aw-firewall#9130) |
| - `error mounting "/dev/null" to .../.npmrc: create mountpoint ...: read-only file system` on `arc-dind` persisting even after upgrading past github/gh-aw-firewall#7998 (A23's fix), where the credential mountpoint is missing under a declared-`rw` home bind backed by a genuinely read-only directory → A24 (`pruneUnmountableCredentialOverlays` only checked declared bind mode, never real filesystem writability for `rw`-declared covers; fixed in github/gh-aw-firewall#8086) | ||
| - `docker network connect --alias <name> awf-net <service_container>` is needed for raw-protocol GitHub Actions `services:` containers under `runner.topology: arc-dind` → A25 (service container must join `awf-net` for direct protocol access while the agent stays isolated; documented in github/gh-aw-firewall#8085) | ||
| - `a network with name awf-net exists but was not created for project` → B27 (orphaned fixed-name `awf-net` from a prior run on a persistent self-hosted runner; fixed in github/gh-aw-firewall#7817) | ||
| - `a network with name awf-net exists but was not created for project`, or a missing bridge in legacy iptables mode → B27 (inspect `docker network inspect awf-net --format '{{json .Options}}'`; an empty options map without `com.docker.network.bridge.name` identifies an unoccupied orphan; fixed in github/gh-aw-firewall#9130) |
|
@copilot address review feedback |
Addressed the review feedback in commit |
|
✅ Copilot review passed with no inline comments. @copilot Add the |
Documentation PreviewDocumentation has been built for this PR. To view locally:
Built from commit 906d32e |
✅ Coverage Check PassedOverall Coverage
📁 Per-file Coverage Changes (1 files)
Coverage comparison generated by |
|
❌ Smoke Copilot BYOK AOAI (Entra) reports failed. AOAI BYOK (Entra) mode investigation needed...
|
|
🔌 Smoke Services — All services reachable! ✅
|
|
🌑 The shadows whisper... Smoke Codex failed. The oracle requires further meditation... Warning Firewall blocked 1 domainThe following domain was blocked by the firewall during workflow execution:
To allow these domains, add them to the network:
allowed:
- defaults
- "clients2.google.com"See Network Configuration for more information.
|
|
Smoke Cloud Hypervisor completed. Cloud Hypervisor + Copilot passed.
|
|
📰 VERDICT: Smoke Copilot has concluded. All systems operational. This is a developing story. 🎤
|
|
🚀 Security Guard has started processing this pull request |
|
✅ Smoke Copilot BYOK completed. Copilot BYOK mode operational. 🔓
|
|
Chroot tests passed! Smoke Chroot - All security and functionality tests succeeded.
|
|
✅ Build Test Suite completed successfully!
|
|
📡 Smoke OTel Tracing completed. All tracing scenarios validated. ✅
|
|
❌ Smoke Copilot BYOK AOAI (api-key) reports failed. AOAI BYOK (api-key) mode investigation needed...
|
|
❌ Smoke Gemini reports failed. Facets need polishing...
|
|
🛡️ Smoke Copilot Network Isolation confirmed the egress allowlist is enforced. ✅
|
|
❌ Smoke Claude failed
|
|
Smoke Copilot — PASS ✅
|
Smoke Test: Copilot BYOK (Direct) Mode ✅
Running in direct BYOK mode ( Status: PASS
|
Smoke Test: Cloud Hypervisor + Copilot
All checks PASS.
|
|
OTEL smoke test
|
|
EGRESS_RESULT allow=pass deny=pass
Overall: PASS — cc
|
|
Services smoke test
Overall: PASS
|
Chroot Version Comparison
Result: Not all tests passed (Node.js version mismatch), so the
|
🏗️ Build Test Suite Results
Overall: 6/8 ecosystems passed — FAIL Failure details
|



Updates runner-doctor coverage for three newly identified failure modes: GHES
/metaresponses ingh-proxymode, orphanedawf-netnetworks, and read-only ARC/DinD streaming-log paths.Diagnostics catalog
/metashim mitigation and remaining upstream limitation.sandbox/agentstreaming-log paths, including unresolvedgh-awcompiler work.Doctor workflows
Generated artifacts
Example orphan-network probe:
docker network inspect awf-net --format '{{json .Options}}'An empty options map without
com.docker.network.bridge.nameidentifies the affected orphaned network.