build: stamp the commit into gitbayd and the runner !117

merged merged by cmc on 2026-08-30 03:43 UTC · krz/gitbay:build-provenance into main

Discussion

cmc

A deployed binary could not say where it came from, so checking meant rebuilding from main and comparing hashes. That is how the stale runner surfaced: nothing had touched cmd/gitbay-runner, so by the Makefile's own "only when it changed" rule the deploy looked unnecessary — but it links internal/store, and it had been running unmerged code since the night before.

LDFLAGS now sets internal/buildinfo.Commit for every binary the Makefile builds. The -dirty suffix can only appear under ALLOW_DIRTY=1, since preflight otherwise refuses an uncommitted tree. A binary built by hand falls back to the revision the toolchain embeds, so go build still reports honestly.

  • gitbayd version prints it; --version previously errored.
  • gitbayd serve logs it as its first line, so the journal records which commit is serving.
  • gitbay-runner -version prints it, and it logs at startup for the same reason.

Tests cover stamp-wins, the VCS fallback, and that the fallback agrees with HEAD; checked against unpatched code to confirm they fail without it.

Ref #28.