Range-diff !479
back to !479 runner: disposable home for untrusted builds
-: ------- > 1: 9002a0b control: move the feed-line sentence renderer from httpd, so the CLI can share it
-: ------- > 2: e0ae401 feed: a labelled event names the labels
-: ------- > 3: cf66fc3 dashboard, feed: render activity as the web's sentence, not the raw payload
-: ------- > 4: 6dae104 feedline: extract FeedLine.Sentence, dedupe runDashboard/runFeed
-: ------- > 5: 2737992 dashboard: an assigned issue no longer repeats under open issues
-: ------- > 6: b39ffae notifications list: name --all when the empty inbox is just read items
-: ------- > 7: 061bd06 feedline: space between the repository and a tag, job or sha
-: ------- > 8: 3815908 notifications list: name --all only when read items exist
-: ------- > 9: 45230cb e2e: an assigned issue is not listed under open_issues
-: ------- > 10: d2db7d8 changelog: unreleased entry for #265
-: ------- > 11: a3fa0f0 usage, help: print the program and the CLI's own path for the command
-: ------- > 12: a8523b1 cli: send --path= where the CLI path differs from the server path
-: ------- > 13: a1e67e4 e2e: usage prints the CLI's own path, stock ssh the registered one
-: ------- > 14: d905c69 flags: print a bad-flag usage line the way a usage refusal does
-: ------- > 15: 44191b1 auth keys add, pgp add: check --help before reading stdin
-: ------- > 16: 4eb0f95 help: auth (and any future CLI-only grouping) renders with the registry layout, in the CLI's own paths
-: ------- > 17: 7664da8 auth --help: force --path= for a bare CLI-only alias group
-: ------- > 18: d5968a8 summaries: verb phrases instead of bare nouns
-: ------- > 19: 004ff6f control, cmd/gitbay: guard nounAliases and aliasGroupNames against drift
-: ------- > 20: ba0a7d3 changelog: #267 and the --path= upgrade note
-: ------- > 21: fd270da help: no auth <verb> usage or footer over stock ssh
-: ------- > 22: bc76b6f changelog: usage refusals name ssh git@<host> outside the CLI
-: ------- > 23: 3595439 sshd: unregistered-key message names the fingerprint and the real host
-: ------- > 24: e3ba425 issue create: --label, --milestone, --assignee
-: ------- > 25: ea552d4 mr show: pluralize commits/checks/reviews section headings
-: ------- > 26: 86c82f6 repo readme: print a repository's README, the web page's file order
-: ------- > 27: 6bf4591 repo show: truncate the mirror's last-sync time to the second
-: ------- > 28: 4fa1930 issue create: resolve milestone and assignees first, set fields through issue label/milestone/assign
-: ------- > 29: 79fdea2 sshd: unregistered-key settings link from the site URL, scheme and port kept
-: ------- > 30: a4152dd wiki: issue create synopsis names --label, --milestone, --assignee
-: ------- > 31: 0338e6a store: run foreign_key_check inside the migration transaction, before commit
-: ------- > 32: d0e26d3 web: pin and watch toggles dispatch through repo pin/watch/mute/unwatch
-: ------- > 33: 8a379d4 web: Cache-Control: no-store on the login-link request
-: ------- > 34: 4ffdc2c wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception
-: ------- > 35: 9bcf573 account: quote whoami, token create and auth export in forms that run
-: ------- > 36: 0e46097 cmd/gitbay: test every quoted web command against the registry
-: ------- > 37: f4f897e web: range-diff page for a merge request's revisions
-: ------- > 38: e0a00fb web: list each MR revision with a compare-to-previous link
-: ------- > 39: 6ddd002 wiki: Parity reflects the web range-diff view
1: 848f79b = 40: ca8187d runner next: say whether the build is trusted
2: 5f01597 = 41: 94f55ff runner: disposable home for untrusted builds
3: bb4a146 ! 42: 7b64442 wiki: trusted and untrusted build homes
@@ .gitbay/wiki/Admin.org: allocates without bound, and it sits above the e2e suite
## .gitbay/wiki/Architecture/04-Trust-Boundaries.org ##
@@
| TB4 | Z1 → Z3 git | argv, repository path, stdin packs | argv built by code, never a shell; repository path from the database, not the request (=internal/gitutil=) |
- | TB5 | Z3 → Z1 hook socket | ref updates, repository id, user id, key scope, commit objects | the daemon decides with =policy.CheckPush= and =sig.VerifyCommit= (=internal/hookd/hookd.go=). The socket trusts the ids in the request, so access to the socket is equivalent to acting as any user; it is reachable only through the =gitbay= user's filesystem |
+ | TB5 | Z3 → Z1 hook socket | ref updates, repository id, user id, key scope, push token, commit objects | the socket is mode 0600 and, on Linux, refuses a peer whose uid is not the daemon's; a request must carry the token sshd minted for its receive-pack (stored hashed in =push_tokens=) and name the same repository, account and scope. The daemon then decides with =policy.CheckPush= and =sig.VerifyCommit= (=internal/hookd/hookd.go=) |
| TB6 | Z4 ↔ Z1 runner channel | build claims (with secrets for trusted builds), logs, results | runner-scoped SSH key; claims limited to attached repositories; secrets only when the build is trusted (=internal/control/build.go=) |
-| TB7 | Z5 → Z4 container | build steps, workspace, build home | rootless podman, operator-provisioned image, cgroup limits; the build home is shared per repository and the network is open (#255, #260) |
+| TB7 | Z5 → Z4 container | build steps, workspace, build home | rootless podman, operator-provisioned image, cgroup limits; a trusted build's home is its repository's, an untrusted build's is discarded with it; the network is open (#260) |
@@ .gitbay/wiki/Architecture/10-Known-Gaps.org: what the 2026-09-27 review found; r
| Issue | Area | Gap | Severity |
|-------+------------------+-----------------------------------------------------------------------+----------|
-| #255 | CI isolation | Untrusted and trusted builds of a repository share a writable build home | high |
- | #256 | Authentication | A removed SSH key keeps working on connections already open | high |
- | #257 | Credentials | An expiring token can create credentials that outlive it; tokens default to full scope | high |
| #258 | CI integrity | Any writer can post a =ci/*= status; tree reuse ignores trust and image | high |
+ | #259 | Recovery | No restore has been exercised; verification does not check git connectivity | high |
+ | #260 | CI network | Builds share the runner's source address; no egress policy | medium |
## .gitbay/wiki/Threat-Model.org ##
@@ .gitbay/wiki/Threat-Model.org: runner, polling over SSH, clones the commit and runs its steps.