HasDiffBase is false for the empty or all-zero old sha a hook sends for a new
branch, so the filter failed open and every job ran. Failing open there is
right, but the branch-commit-merge-request workflow means the first push is
always a new branch, so a docs-only change ran the full suite anyway. !264
showed it: nothing but .gitbay/wiki/** changed and test, vuln and sonar all
queued despite carrying paths-ignore for exactly that.
A branch push with no diff base now derives one from the merge base of the default branch and the new sha. Every other case still fails open: no merge base, a merge base equal to the new sha (a fresh default branch), a failed diff, and a job declaring neither key all run the job.
QueueMRBuilds keeps failing open with no merge-base derivation. Filtering a
merge request head's jobs to nothing would leave it with no ci/<job>
statuses, and the check gate refuses a merge when none were reported at all
(#172), so a docs-only merge request would become unmergeable. A test pins that
decision rather than a comment.
Closes #171