Commit a869e55ced
Verified · cmc ci/build: success ci/test: success
Layout: unified · split
CHANGELOG.org +70
| @@ -4,6 +4,76 @@ Versioning follows semver from v0.1.0. Database migrations run | ||
| 4 | 4 | automatically on daemon start; upgrade notes appear per release when |
| 5 | 5 | anything beyond "replace the binary and restart" is needed. |
| 6 | 6 | |
| 7 | * v1.15.0 — 2026-09-07 | |
| 8 | ||
| 9 | Builds run in containers, a rebase is not rebuilt, and a runner restart | |
| 10 | no longer strands the build it was running. | |
| 11 | ||
| 12 | ** CI | |
| 13 | ||
| 14 | - A build's steps run in a rootless podman container, one per job. The | |
| 15 | runner clones outside the container with its key and bind-mounts the | |
| 16 | workspace in, so a step cannot reach the key, the runner's environment, | |
| 17 | or another build's workspace. =image:= is required per job and is | |
| 18 | validated as a reference, never pulled: an operator provisions images | |
| 19 | on the host. A runner configured for podman that has none refuses to | |
| 20 | start rather than fall back to the host. =-isolation none= is the | |
| 21 | explicit host-execution mode. =-cpus= and =-memory= cap a build's | |
| 22 | container. #144 | |
| 23 | - Builds have a home directory that outlives the build, so the Go module | |
| 24 | cache and the sonar scanner survive between runs. It is mounted into | |
| 25 | the container at the same path, and only that directory. Ref #144 | |
| 26 | - The host preparation script, the unit drop-in and the weekly image | |
| 27 | prune ship with =make deploy-runner=; each hardening flag the drop-in | |
| 28 | relaxes carries the reason in place. Ref #144 | |
| 29 | - A nightly canary on the runner host proves the boundary holds: | |
| 30 | =cmc/ci-smoke= runs a job that tries to read the key and list sibling | |
| 31 | workspaces, and fails if either succeeds. Ref #144 | |
| 32 | - Dedupe keys on the commit's tree, not its sha. A rebase that changes | |
| 33 | nothing is not rebuilt: the new commit gets the earlier success as its | |
| 34 | status, naming the build. Scheduled and tag builds carry no tree and | |
| 35 | are never reused. #177 | |
| 36 | - =vuln= and =sonar= run nightly on =main= rather than on every push; | |
| 37 | neither could inform a merge. Branches run =build= and =test=. #177 | |
| 38 | - A rewritten branch is filtered against the merge base rather than the | |
| 39 | old tip, so a rebased branch whose own commits change code no longer | |
| 40 | reads as a docs-only push and skips its jobs. #176 | |
| 41 | - A build whose runner's log stream ended with no outcome is failed two | |
| 42 | minutes later, instead of sitting =running= until a fixed deadline. | |
| 43 | Migration 0046. Ref #179 | |
| 44 | - The runner retries reporting a finished build's outcome, four times | |
| 45 | over about thirty seconds, when the server is unreachable. A gitbayd | |
| 46 | restart at that moment used to lose the result. Ref #179 | |
| 47 | - The runner drains on SIGTERM: it claims nothing more, finishes and | |
| 48 | reports the build in flight, then exits. A second signal exits at once. | |
| 49 | The unit allows fifty minutes. #179 | |
| 50 | ||
| 51 | ** Repositories | |
| 52 | ||
| 53 | - =repo show= reports the caller's watch and bookmark state, and the | |
| 54 | parent of a fork when the caller can read it. #178 | |
| 55 | - =repo unwatch= clears the row from either state; =repo mute= is the | |
| 56 | explicit silence. Watch then unwatch used to leave an account below | |
| 57 | the default with no way back. The web header toggle follows. #180 | |
| 58 | ||
| 59 | ** Upgrading | |
| 60 | ||
| 61 | Replace the binary and reinstall the CLI. One migration (0046, the | |
| 62 | build log's close time), applied on start. | |
| 63 | ||
| 64 | The runner now defaults to =-isolation podman= and refuses to start | |
| 65 | without a working podman and a named image. Prepare the host with | |
| 66 | =deploy/runner-podman-setup.sh= and build =localhost/gitbay-ci:1= from | |
| 67 | =deploy/Containerfile.ci= before deploying it, or pass =-isolation | |
| 68 | none= to keep running steps on the host. Validate on a scratch | |
| 69 | repository with =-repos= scoped to it first; the wiki's Admin page has | |
| 70 | the procedure. | |
| 71 | ||
| 72 | The runner's unit gains =TimeoutStopSec=50min= and =KillMode=mixed= so | |
| 73 | a stop reaches the runner alone and it can drain; under the default | |
| 74 | kill mode systemd ends the build's container with the runner. | |
| 75 | =make deploy-runner= therefore waits for a build in flight. | |
| 76 | ||
| 7 | 77 | * v1.14.0 — 2026-09-06 |
| 8 | 78 | |
| 9 | 79 | Logging into the web without an SSH key, wikis inside the repository, |