Commit 61564b7c32
Verified · cmc ci/build: success ci/sonar: success ci/test: success ci/vuln: success
Layout: unified · split
CHANGELOG.org +50
| @@ -4,6 +4,56 @@ Versioning follows semver from v0.1.0. Database migrations run | ||
| 4 | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | |
| 7 | * v1.13.2 — 2026-09-04 | |
| 8 | ||
| 9 | The first SonarCloud scan's findings: eight fixed, the rest triaged and | |
| 10 | dismissed with reasons. | |
| 11 | ||
| 12 | - A pages directory redirect could leave the site. Both redirects passed | |
| 13 | the raw request path to =http.Redirect= while the cleaned path sat a | |
| 14 | line above; =net/url= keeps a leading =//=, and Go emits | |
| 15 | =Location: //evil.example/= unchanged, which a browser reads as | |
| 16 | protocol-relative. Reaching it needed a public repository named like a | |
| 17 | host under the subdomain's own owner — repository names permit dots — | |
| 18 | so it was narrow rather than impossible. The destination is built from | |
| 19 | the cleaned path through =url.URL= now, which also settles the two | |
| 20 | spellings the first fix missed: a =..= that escapes to the root, and a | |
| 21 | backslash, which browsers following the WHATWG rules treat as a | |
| 22 | separator. #153 | |
| 23 | - The runner's default workspace was =<tmp>/gitbay-runner=: a fixed name | |
| 24 | in a world-writable directory, created with =MkdirAll=, which succeeds | |
| 25 | against a directory whoever already owns it. bay1 was never exposed — | |
| 26 | its unit names a workspace — but the default is what anyone running the | |
| 27 | binary by hand gets, and this is the process that clones repositories | |
| 28 | and exports build secrets. The default moves under the user's cache | |
| 29 | directory, the workspace is created 0700, and a symlink or a directory | |
| 30 | owned by someone else is refused. One we own that is merely too | |
| 31 | permissive is tightened rather than refused, since every runner before | |
| 32 | this one made it 0755 and refusing would take the runner down on | |
| 33 | upgrade. #153 | |
| 34 | - Logout and flash consumption expire their cookies with the attributes | |
| 35 | the setting calls used. Deletion worked either way; the difference was | |
| 36 | a reviewer's puzzle, and four findings. #153 | |
| 37 | - The topics-remove field has a label. A placeholder is not an accessible | |
| 38 | name. TestEveryInputHasAnAccessibleName is the guard that was missing, | |
| 39 | and it knows both associations — six inputs use | |
| 40 | =<label>Name <input></label>=, which is as good as for/id. #153 | |
| 41 | - git and ssh are resolved once at start-up rather than searched on every | |
| 42 | spawn, and gitbayd refuses to start when one is absent instead of | |
| 43 | failing on whichever request first needed it. This was 74 of the 118 | |
| 44 | findings; a dashboard that is mostly permanent noise is one nobody | |
| 45 | reads. #153 | |
| 46 | ||
| 47 | Also: SQLite migrations are excluded from analysis. They were read as | |
| 48 | PL/SQL, where ='' is NULL=, so =WHERE col = ''= on a =NOT NULL DEFAULT ''= | |
| 49 | column — correct SQLite, and the shape used throughout — read as a | |
| 50 | null-comparison bug. | |
| 51 | ||
| 52 | Replace the binary and reinstall the CLI. No migration. A runner whose | |
| 53 | workspace is group- or world-readable will have it tightened to 0700 on | |
| 54 | next start, and will refuse to start if that workspace is a symlink or | |
| 55 | belongs to another user. | |
| 56 | ||
| 7 | 57 | * v1.13.1 — 2026-09-04 |
| 8 | 58 | |
| 9 | 59 | A command that reads its payload from stdin says so, and SonarCloud runs |