Untrusted builds get a disposable HOME.
runner nextalways carries"trusted": true|falsein the claim; a runner reads a missing field as untrusted.- Trusted builds keep a per-repository home at
<workdir>/trusted-home/<owner>/<name>. The old shared homes are no longer read. - Untrusted builds get a fresh
<workdir>/build-<id>-home, removed after the build (read-only module-cache directories included), and no secrets whatever the claim carries. - Threat-Model, Admin and Architecture pages updated; #255 leaves Known-Gaps.
Deploy order: gitbayd first, then the runner. Before pointing the runner at real repositories, validate on a scratch repository (plan runbook R1–R2), then delete the old per-repository homes under the runner's workdir.
First MR of the CI trust stack (plan docs/plans/2026-09-27-ci-trust-and-build-reporting.md).
Closes #255