Stacked on !251. The CRITICAL from #153.
The default -workdir was <tmp>/gitbay-runner — a fixed name in a
world-writable directory, created with MkdirAll, which succeeds against
a directory whoever already owns it. On a shared host another user could
create or symlink it first, and this is the process that clones
repositories and exports build secrets into step environments.
bay1 was never exposed (its unit passes -workdir /var/lib/gitbay-runner/work); the weakness is the default anyone gets
running the binary by hand.
Default moves under the user cache directory, workspace is created 0700,
and checkWorkdir verifies what MkdirAll cannot — being able to create
a directory says nothing about who made it.
One deployment hazard I caught while writing it: my first version
refused an over-permissive workspace. Every runner before this one
created /var/lib/gitbay-runner/work as 0755, so that version would have
taken the production runner down on upgrade over a permission it is
entitled to change. It now tightens what it owns and refuses only what it
cannot repair — a symlink, or a directory owned by someone else. A check
that breaks the deploy it ships in is worse than the hole it closes.
Ref #153
retargeted from sonar-redirect to main: !251 merged
2026-09-05 00:02 UTC