Commit 1aaf5bca7b
Verified · cmc ci/build: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +40
| @@ -4,6 +4,46 @@ Versioning follows semver from v0.1.0. Database migrations run | ||
| 4 | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | |
| 7 | * v1.7.0 — 2026-09-02 | |
| 8 | ||
| 9 | What an open instance needs before it is open: a cap on what one | |
| 10 | account can take, a way out of a browser session you no longer hold, | |
| 11 | and accounts that never verified do not stay forever. | |
| 12 | ||
| 13 | - =limits.max_repos_per_user= caps the repositories an account owns | |
| 14 | directly; =repo create=, =fork= and =import= refuse past it with the | |
| 15 | numbers. =limits.max_bytes_per_user= caps their disk: a push may be no | |
| 16 | larger than what the owner has left, riding the same | |
| 17 | =receive.maxInputSize= as the pack cap, and is refused outright when | |
| 18 | nothing is left. Organizations are not capped. Migration 0031 adds | |
| 19 | per-account overrides, set with =admin user limits <name> [--repos | |
| 20 | n|default] [--bytes n|default]= and shown by =admin user show=. Both | |
| 21 | default to 0, unlimited, so nothing changes until set. #82 | |
| 22 | - =registration.pending_expiry=, a duration, removes self-registered | |
| 23 | accounts still unverified after that long, hourly and once at start, | |
| 24 | audited as =pending.expired=. Empty keeps them, as before. #82 | |
| 25 | - =web sessions list= shows each unexpired browser session by a short id | |
| 26 | with its creation and expiry; =web sessions revoke <id>= ends one and | |
| 27 | =--all= ends every one. SSH-only, matching the token commands, and | |
| 28 | scoped to the caller. #83 | |
| 29 | - A step runs in its own process group and a cancel or timeout kills the | |
| 30 | group. On a host whose =/bin/sh= is dash, killing the shell alone left | |
| 31 | its child holding the log pipe, so a cancelled build held the runner | |
| 32 | until the child finished on its own, minutes for a test suite. The | |
| 33 | wait after a kill is capped at ten seconds besides. | |
| 34 | - A commit with a build still queued or running is not queued again | |
| 35 | when a fast-forward lands it; the v1.6.0 skip counted only a finished | |
| 36 | success. #90 | |
| 37 | ||
| 38 | - =golang.org/x/crypto= v0.56.0: GO-2026-6354 and GO-2026-6355 in its | |
| 39 | =ssh= package, both reached through =ssh.NewServerConn= in the | |
| 40 | embedded SSH server; one is a denial of service on a deadlocked | |
| 41 | undecided channel. | |
| 42 | ||
| 43 | Replace both binaries and restart: =make deploy= for the daemon | |
| 44 | (migration 0031 adds two columns to =users= on start), then | |
| 45 | =make deploy-runner= for the process-group kill. | |
| 46 | ||
| 7 | 47 | * v1.6.1 — 2026-09-02 |
| 8 | 48 | |
| 9 | 49 | A cancel reaches a build in its clone. |