runner: disposable home for untrusted builds !479

merged merged by cmc on 2026-09-28 22:33 UTC · krz/gitbay:ci-untrusted-home into main

Discussion

cmc

Untrusted builds get a disposable HOME.

  • runner next always carries "trusted": true|false in the claim; a runner reads a missing field as untrusted.
  • Trusted builds keep a per-repository home at <workdir>/trusted-home/<owner>/<name>. The old shared homes are no longer read.
  • Untrusted builds get a fresh <workdir>/build-<id>-home, removed after the build (read-only module-cache directories included), and no secrets whatever the claim carries.
  • Threat-Model, Admin and Architecture pages updated; #255 leaves Known-Gaps.

Deploy order: gitbayd first, then the runner. Before pointing the runner at real repositories, validate on a scratch repository (plan runbook R1–R2), then delete the old per-repository homes under the runner's workdir.

First MR of the CI trust stack (plan docs/plans/2026-09-27-ci-trust-and-build-reporting.md).

Closes #255