Commit 42a7b1230c

42a7b1230c6d661ad3355dcccc90f28f0b33b994

parent: 7a5f2a1a5c

Verified · cmc ci/build: success ci/test: success

cmc <hello@cleberg.net> · 2026-09-28 08:22 UTC

wiki, changelog: last finisher sets ci/<job>; required contexts report on heads

Ref #258

Layout: unified · split

.gitbay/wiki/CI.org +17 −11
@@ -5,17 +5,20 @@ Three mechanisms decide what a push does to CI, and they interact:
55- *Dedupe.* A job's result is a property of the commit's tree. A commit
66 that already has a passed, queued or running build for a job is not
77 queued again; a commit whose tree already passed a job gets that
8 result as its status, naming the build it came from (#177). Only a trusted build counts, and for tree reuse only one on the
9 image the job names: a fork's green build does not stand for the
10 repository's own, so its commit is built again when it lands on a
11 branch (#258). A job that names no =image:= is compared as naming
12 none: its reuse does not notice the runner's default image changing,
13 because reuse is decided when the push is queued, before any runner
14 claims the build, and runners can differ in their default. Name the
15 image in =ci.yml= to tie reuse to it; after an operator changes a
16 runner's =-image=, =build trigger= builds a job afresh, since a
17 triggered build is never reused. A failed,
18 cancelled or abandoned build does not count: that commit runs again.
8 result as its status, naming the build it came from (#177). Only a
9 trusted build counts, and for tree reuse only one on the image the
10 job names: a fork's green build does not stand for the repository's
11 own, so its commit is built again when it lands on a branch (#258). A
12 job that names no =image:= is compared as naming none: its reuse does
13 not notice the runner's default image changing, because reuse is
14 decided when the push is queued, before any runner claims the build,
15 and runners can differ in their default. Name the image in =ci.yml=
16 to tie reuse to it; after an operator changes a runner's =-image=,
17 =build trigger= builds a job afresh, since a triggered build is never
18 reused. When a trusted and an untrusted build of the same commit both
19 run, the one that finishes last sets =ci/<job>= on that commit. A
20 failed, cancelled or abandoned build does not count: that commit runs
21 again.
1922- *Path filters.* =paths= and =paths-ignore= on a job are evaluated
2023 against the files the push changed. The diff base is the old tip when
2124 it is an ancestor of the new one, and the merge base with the default
@@ -136,6 +139,9 @@ Rows worth a second look:
136139 branch push, no merge-base fallback: every job runs, without secrets.
137140 Filtering a head down to no jobs would make it unmergeable under
138141 =require-checks= (#172).
142- A context named in =repo settings require-contexts= must be one that
143 reports on merge request heads. A schedule-only or tag-only job never
144 reports there, so the gate stays pending (#258).
139145
140146=TestPushShapes= in =internal/hookd= runs every row against real git
141147and the store, and =TestPushShapesTableOnWiki= checks that this page
CHANGELOG.org +10
@@ -123,6 +123,16 @@ for the eighteen commands whose CLI path differs from the registry's
123123 browser (#269).
124124- Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
125125- =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
126- Untrusted builds (merge requests from forks) get a fresh HOME
127 removed after the build and no secrets; trusted builds keep a
128 per-repository home under =<workdir>/trusted-home=. Deploy gitbayd
129 before the runner; the old shared homes under the runner's workdir
130 can be deleted. (#255)
131- =status set= refuses =ci/= contexts, which belong to the instance's
132 builds. Build results are reused only from trusted builds on the
133 same image. =repo settings require-contexts= names status contexts
134 that must report green; setting any turns require-checks on, and one
135 not yet reported counts as pending. (#258)
126136
127137* v1.36.0 — 2026-09-23
128138