Commit 42a7b1230c
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
.gitbay/wiki/CI.org +17 −11
| @@ -5,17 +5,20 @@ Three mechanisms decide what a push does to CI, and they interact: | ||
| 5 | 5 | - *Dedupe.* A job's result is a property of the commit's tree. A commit |
| 6 | 6 | that already has a passed, queued or running build for a job is not |
| 7 | 7 | queued again; a commit whose tree already passed a job gets that |
| 8 | result as its status, naming the build it came from (#177). Only a trusted build counts, and for tree reuse only one on the | |
| 9 | image the job names: a fork's green build does not stand for the | |
| 10 | repository's own, so its commit is built again when it lands on a | |
| 11 | branch (#258). A job that names no =image:= is compared as naming | |
| 12 | none: its reuse does not notice the runner's default image changing, | |
| 13 | because reuse is decided when the push is queued, before any runner | |
| 14 | claims the build, and runners can differ in their default. Name the | |
| 15 | image in =ci.yml= to tie reuse to it; after an operator changes a | |
| 16 | runner's =-image=, =build trigger= builds a job afresh, since a | |
| 17 | triggered build is never reused. A failed, | |
| 18 | cancelled or abandoned build does not count: that commit runs again. | |
| 8 | result as its status, naming the build it came from (#177). Only a | |
| 9 | trusted build counts, and for tree reuse only one on the image the | |
| 10 | job names: a fork's green build does not stand for the repository's | |
| 11 | own, so its commit is built again when it lands on a branch (#258). A | |
| 12 | job that names no =image:= is compared as naming none: its reuse does | |
| 13 | not notice the runner's default image changing, because reuse is | |
| 14 | decided when the push is queued, before any runner claims the build, | |
| 15 | and runners can differ in their default. Name the image in =ci.yml= | |
| 16 | to tie reuse to it; after an operator changes a runner's =-image=, | |
| 17 | =build trigger= builds a job afresh, since a triggered build is never | |
| 18 | reused. When a trusted and an untrusted build of the same commit both | |
| 19 | run, the one that finishes last sets =ci/<job>= on that commit. A | |
| 20 | failed, cancelled or abandoned build does not count: that commit runs | |
| 21 | again. | |
| 19 | 22 | - *Path filters.* =paths= and =paths-ignore= on a job are evaluated |
| 20 | 23 | against the files the push changed. The diff base is the old tip when |
| 21 | 24 | it is an ancestor of the new one, and the merge base with the default |
| @@ -136,6 +139,9 @@ Rows worth a second look: | ||
| 136 | 139 | branch push, no merge-base fallback: every job runs, without secrets. |
| 137 | 140 | Filtering a head down to no jobs would make it unmergeable under |
| 138 | 141 | =require-checks= (#172). |
| 142 | - A context named in =repo settings require-contexts= must be one that | |
| 143 | reports on merge request heads. A schedule-only or tag-only job never | |
| 144 | reports there, so the gate stays pending (#258). | |
| 139 | 145 | |
| 140 | 146 | =TestPushShapes= in =internal/hookd= runs every row against real git |
| 141 | 147 | and the store, and =TestPushShapesTableOnWiki= checks that this page |
CHANGELOG.org +10
| @@ -123,6 +123,16 @@ for the eighteen commands whose CLI path differs from the registry's | ||
| 123 | 123 | browser (#269). |
| 124 | 124 | - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255) |
| 125 | 125 | - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258) |
| 126 | - Untrusted builds (merge requests from forks) get a fresh HOME | |
| 127 | removed after the build and no secrets; trusted builds keep a | |
| 128 | per-repository home under =<workdir>/trusted-home=. Deploy gitbayd | |
| 129 | before the runner; the old shared homes under the runner's workdir | |
| 130 | can be deleted. (#255) | |
| 131 | - =status set= refuses =ci/= contexts, which belong to the instance's | |
| 132 | builds. Build results are reused only from trusted builds on the | |
| 133 | same image. =repo settings require-contexts= names status contexts | |
| 134 | that must report green; setting any turns require-checks on, and one | |
| 135 | not yet reported counts as pending. (#258) | |
| 126 | 136 | |
| 127 | 137 | * v1.36.0 — 2026-09-23 |
| 128 | 138 | |