ci: build merge request heads in the target repository !200

merged merged by cmc on 2026-09-03 22:24 UTC · krz/gitbay:mr-head-builds into main

Discussion

cmc

Builds queued only for branch pushes to the pushed repository, so a merge request from a fork had no ci/<job> statuses in the target and require-checks refused it with "none were reported".

The head is already fetched into the target at refs/merge-requests/<n>/head. That fetch, on mr create and on every push to the source branch, now queues the target's push jobs against it (QueueMRBuilds, sharing queueJobs with the branch path). The existing per-commit check skips a head the branch push already built, so a same-repository merge request is not built twice.

A head from another repository runs untrusted: migration 0032 adds builds.trusted (default 1), runner next withholds the repository's secrets for an untrusted build, and the runner fetches the merge request ref before checkout, since a clone does not carry refs/merge-requests/. The runner binary changes, so this needs make deploy-runner as well as make deploy.

TestForkMRHeadIsBuilt: a fork's merge request queues both jobs in the target at the MR ref, the claim carries no secrets, the real runner fetches and builds the head, and require-checks then admits the merge. The CI, build, runner, status, and MR e2e tests pass.

Closes #98