Commit statuses that gate merges can be written by anyone with write access, and tree dedupe reuses results across trust domains.
status set(internal/control/status.go:76) requires write and accepts any context,ci/*included. A writer can markci/testgreen on their own MR head before or instead of the build. The runner's own path is internal/control/build.go:687.MergeGates(internal/control/mr.go:1579) requires every present status to be green. Built-in CI writespendingfor every job at push time (build.go:890), so the gap is external reporters: the first green one satisfies the gate before the others report.SuccessBuildForTree(internal/store/builds.go:458) keys on repo, tree and job. A successful untrusted fork build, or one on an older image, can stand in for a trusted run.
Changes:
- Reserve the
ci/prefix for the build subsystem;status setrefuses it. - Tree reuse excludes untrusted builds and includes the job's image in the key.
- Optional: a required-contexts list under
repo settings, missing contexts pending.
referenced in commit 7a6343d02d by cmc: wiki: architecture and security pages
2026-09-28 04:30 UTC