Hi,
There's a repo [1] (owner in CC) that, during the last 2 days, is sending hundreds of builds of the same misconfigured package, taking resources and then failing with a timeout. Not sure what is triggering so many builds, but more builds certainly won't improve the situation. :)
[1] https://copr.fedorainfracloud.org/coprs/ndthanh7/test/
Thank you for the report!
On Monday, June 21, 2021 10:25:10 AM CEST Iñaki Ucar wrote:
There's a repo [1] (owner in CC) that, during the last 2 days, is sending hundreds of builds of the same misconfigured package, taking resources and then failing with a timeout. Not sure what is triggering so many builds, but more builds certainly won't improve the situation. :)
This looks like some attempt for crypto mining. Dear submitter, Fedora Copr build system is not supposed to be used for mining. Copr is for wide packager audience, and such behavior eats the quota and hurts the whole Copr user base.
I've removed the builds, and removed the project. And we will give you permanent BAN in case of any other similar attempt. Also note that Copr Build system is by design a public service - we don't obfuscate build logs. So any credentials, or similar stuff you could need for authentication when mining would be visible to general public - there's a chance anyone could use those credentials to deplete accounts, etc.
Pavel
copr-devel@lists.fedorahosted.org