runner: disposable HOME for untrusted builds #255

closed cmc opened this on 2026-09-28 02:36 UTC · ci priority security

Discussion

cmc 2026-09-28 02:36 UTC

Untrusted builds share a writable HOME with trusted builds of the same repository.

buildHomeFor(r.workdir, j.Repo) (cmd/gitbay-runner/main.go:325) keys the home on the repository alone, and the container mounts it read-write (cmd/gitbay-runner/isolate.go:160). The bay1 runner runs with -untrusted, so a fork MR build can write to the Go module and build caches, or plant dotfiles, that the next trusted krz/gitbay build uses.

No secrets are attached to krz/gitbay or cmc/cleberg.net today, so the current impact is trusted-build integrity. Any repository that adds a secret turns it into disclosure.

  • Untrusted builds get a disposable home, removed with the workspace.
  • The claim payload carries the trust classification explicitly; absence of secrets is not the signal.
  • Persistent caches only within one trust domain; nothing written by an untrusted build is reused by a trusted one.
  • Discard the existing shared homes on bay1 when this deploys.

referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages

2026-09-28 04:30 UTC

referenced in commit 4e0958a163 by cmc: plans: open issues from the architecture and UX reviews

2026-09-28 05:43 UTC

closed by cmc in commit 7b644421d3: wiki: trusted and untrusted build homes

2026-09-28 22:33 UTC

referenced in commit 94f55ffbcd by cmc: runner: disposable home for untrusted builds

2026-09-28 22:33 UTC

referenced in commit ca8187d6b5 by cmc: runner next: say whether the build is trusted

2026-09-28 22:33 UTC

referenced in commit 7a5f2a1a5c by cmc: changelog: #255, #258

2026-09-28 22:33 UTC