fosskar/fencr build #53 succeeded ← #52 #54 →
eval warnings
2 kinds
· 3 occurrences
- warn fencr: smt is on, so a guest shares a core with the host and every other vm, where a cross-thread side channel reads what the vm boundary does not stop; set boot.kernelParams = [ "nosmt" ] to take Firecracker's tenant-separation guidance, at the cost of the second thread of every core. ×2
- warn fencr: swap without randomEncryption (/dev/sda2) can hold guest memory on disk; enable swapDevices.*.randomEncryption or use zramSwap. ×1
8 already built ⚠ 2
| status | attribute | duration |
|---|---|---|
checks.x86_64-linux.nixos-boot
|
— | |
checks.x86_64-linux.nixos-module
|
— | |
checks.x86_64-linux.cli
|
— | |
checks.x86_64-linux.core
|
— | |
checks.x86_64-linux.egress
|
— | |
checks.x86_64-linux.formatting
|
— | |
checks.x86_64-linux.mcp-gateway
|
— | |
checks.x86_64-linux.mcp-module
|
— |
Effect checks dependencies built, not run
| status | effect | duration | cancel |
|---|---|---|---|
schedule.update-flake-inputs.update-flake-inputs
|
22s |