runner: a build workspace another user could have created first !252

merged merged by cmc on 2026-09-05 00:02 UTC · krz/gitbay:sonar-runner-workdir into main

Discussion

cmc

Stacked on !251. The CRITICAL from #153.

The default -workdir was <tmp>/gitbay-runner — a fixed name in a world-writable directory, created with MkdirAll, which succeeds against a directory whoever already owns it. On a shared host another user could create or symlink it first, and this is the process that clones repositories and exports build secrets into step environments.

bay1 was never exposed (its unit passes -workdir /var/lib/gitbay-runner/work); the weakness is the default anyone gets running the binary by hand.

Default moves under the user cache directory, workspace is created 0700, and checkWorkdir verifies what MkdirAll cannot — being able to create a directory says nothing about who made it.

One deployment hazard I caught while writing it: my first version refused an over-permissive workspace. Every runner before this one created /var/lib/gitbay-runner/work as 0755, so that version would have taken the production runner down on upgrade over a permission it is entitled to change. It now tightens what it owns and refuses only what it cannot repair — a symlink, or a directory owned by someone else. A check that breaks the deploy it ships in is worse than the hole it closes.

Ref #153

retargeted from sonar-redirect to main: !251 merged

2026-09-05 00:02 UTC