Range-diff !482
back to !482 ci: reserve ci/ statuses; trusted reuse; required contexts
-: ------- > 1: 9002a0b control: move the feed-line sentence renderer from httpd, so the CLI can share it
-: ------- > 2: e0ae401 feed: a labelled event names the labels
-: ------- > 3: cf66fc3 dashboard, feed: render activity as the web's sentence, not the raw payload
-: ------- > 4: 6dae104 feedline: extract FeedLine.Sentence, dedupe runDashboard/runFeed
-: ------- > 5: 2737992 dashboard: an assigned issue no longer repeats under open issues
-: ------- > 6: b39ffae notifications list: name --all when the empty inbox is just read items
-: ------- > 7: 061bd06 feedline: space between the repository and a tag, job or sha
-: ------- > 8: 3815908 notifications list: name --all only when read items exist
-: ------- > 9: 45230cb e2e: an assigned issue is not listed under open_issues
-: ------- > 10: d2db7d8 changelog: unreleased entry for #265
-: ------- > 11: a3fa0f0 usage, help: print the program and the CLI's own path for the command
-: ------- > 12: a8523b1 cli: send --path= where the CLI path differs from the server path
-: ------- > 13: a1e67e4 e2e: usage prints the CLI's own path, stock ssh the registered one
-: ------- > 14: d905c69 flags: print a bad-flag usage line the way a usage refusal does
-: ------- > 15: 44191b1 auth keys add, pgp add: check --help before reading stdin
-: ------- > 16: 4eb0f95 help: auth (and any future CLI-only grouping) renders with the registry layout, in the CLI's own paths
-: ------- > 17: 7664da8 auth --help: force --path= for a bare CLI-only alias group
-: ------- > 18: d5968a8 summaries: verb phrases instead of bare nouns
-: ------- > 19: 004ff6f control, cmd/gitbay: guard nounAliases and aliasGroupNames against drift
-: ------- > 20: ba0a7d3 changelog: #267 and the --path= upgrade note
-: ------- > 21: fd270da help: no auth <verb> usage or footer over stock ssh
-: ------- > 22: bc76b6f changelog: usage refusals name ssh git@<host> outside the CLI
-: ------- > 23: 3595439 sshd: unregistered-key message names the fingerprint and the real host
-: ------- > 24: e3ba425 issue create: --label, --milestone, --assignee
-: ------- > 25: ea552d4 mr show: pluralize commits/checks/reviews section headings
-: ------- > 26: 86c82f6 repo readme: print a repository's README, the web page's file order
-: ------- > 27: 6bf4591 repo show: truncate the mirror's last-sync time to the second
-: ------- > 28: 4fa1930 issue create: resolve milestone and assignees first, set fields through issue label/milestone/assign
-: ------- > 29: 79fdea2 sshd: unregistered-key settings link from the site URL, scheme and port kept
-: ------- > 30: a4152dd wiki: issue create synopsis names --label, --milestone, --assignee
-: ------- > 31: 0338e6a store: run foreign_key_check inside the migration transaction, before commit
-: ------- > 32: d0e26d3 web: pin and watch toggles dispatch through repo pin/watch/mute/unwatch
-: ------- > 33: 8a379d4 web: Cache-Control: no-store on the login-link request
-: ------- > 34: 4ffdc2c wiki: fix API token-refusal claim, batched-review status, watch/pin dispatch, login-link URL exception
-: ------- > 35: 9bcf573 account: quote whoami, token create and auth export in forms that run
-: ------- > 36: 0e46097 cmd/gitbay: test every quoted web command against the registry
-: ------- > 37: f4f897e web: range-diff page for a merge request's revisions
-: ------- > 38: e0a00fb web: list each MR revision with a compare-to-previous link
-: ------- > 39: 6ddd002 wiki: Parity reflects the web range-diff view
1: 848f79b = 40: ca8187d runner next: say whether the build is trusted
2: 5f01597 = 41: 94f55ff runner: disposable home for untrusted builds
3: bb4a146 ! 42: 7b64442 wiki: trusted and untrusted build homes
@@ .gitbay/wiki/Admin.org: allocates without bound, and it sits above the e2e suite
## .gitbay/wiki/Architecture/04-Trust-Boundaries.org ##
@@
| TB4 | Z1 → Z3 git | argv, repository path, stdin packs | argv built by code, never a shell; repository path from the database, not the request (=internal/gitutil=) |
- | TB5 | Z3 → Z1 hook socket | ref updates, repository id, user id, key scope, commit objects | the daemon decides with =policy.CheckPush= and =sig.VerifyCommit= (=internal/hookd/hookd.go=). The socket trusts the ids in the request, so access to the socket is equivalent to acting as any user; it is reachable only through the =gitbay= user's filesystem |
+ | TB5 | Z3 → Z1 hook socket | ref updates, repository id, user id, key scope, push token, commit objects | the socket is mode 0600 and, on Linux, refuses a peer whose uid is not the daemon's; a request must carry the token sshd minted for its receive-pack (stored hashed in =push_tokens=) and name the same repository, account and scope. The daemon then decides with =policy.CheckPush= and =sig.VerifyCommit= (=internal/hookd/hookd.go=) |
| TB6 | Z4 ↔ Z1 runner channel | build claims (with secrets for trusted builds), logs, results | runner-scoped SSH key; claims limited to attached repositories; secrets only when the build is trusted (=internal/control/build.go=) |
-| TB7 | Z5 → Z4 container | build steps, workspace, build home | rootless podman, operator-provisioned image, cgroup limits; the build home is shared per repository and the network is open (#255, #260) |
+| TB7 | Z5 → Z4 container | build steps, workspace, build home | rootless podman, operator-provisioned image, cgroup limits; a trusted build's home is its repository's, an untrusted build's is discarded with it; the network is open (#260) |
@@ .gitbay/wiki/Architecture/10-Known-Gaps.org: what the 2026-09-27 review found; r
| Issue | Area | Gap | Severity |
|-------+------------------+-----------------------------------------------------------------------+----------|
-| #255 | CI isolation | Untrusted and trusted builds of a repository share a writable build home | high |
- | #256 | Authentication | A removed SSH key keeps working on connections already open | high |
- | #257 | Credentials | An expiring token can create credentials that outlive it; tokens default to full scope | high |
| #258 | CI integrity | Any writer can post a =ci/*= status; tree reuse ignores trust and image | high |
+ | #259 | Recovery | No restore has been exercised; verification does not check git connectivity | high |
+ | #260 | CI network | Builds share the runner's source address; no egress policy | medium |
## .gitbay/wiki/Threat-Model.org ##
@@ .gitbay/wiki/Threat-Model.org: runner, polling over SSH, clones the commit and runs its steps.
4: 2e830df = 43: b022fed status set: ci/ is reserved for the instance's builds
5: 3453d63 = 44: b1f4bf1 ci: reuse only trusted results on the job's image
6: bba63a3 ! 45: dc10160 repo settings: required contexts turn the checks gate on, pending until reported
@@ internal/control/mr.go: func MergeGates(st *store.Store, repo store.Repo, mr sto
}
## internal/control/mr_test.go ##
-@@ internal/control/mr_test.go: package control
- import (
- "bytes"
+@@ internal/control/mr_test.go: import (
"encoding/json"
+ "os"
+ "path/filepath"
+ "slices"
"strconv"
"strings"
"testing"
-@@ internal/control/mr_test.go: func TestMREditSupersededByOnOpenMRRefused(t *testing.T) {
- t.Fatalf("stderr = %q, want the closed-only refusal", errOut.String())
+@@ internal/control/mr_test.go: func TestMRShowPluralizesMultiRowSections(t *testing.T) {
+ }
}
}
+
7: 60cf9c5 ! 46: d19e518 wiki: reserved ci/ statuses, trusted reuse, required contexts
@@ .gitbay/wiki/Architecture/09-Controls.org: chapter names of OWASP ASVS 4.0 where
## .gitbay/wiki/Architecture/10-Known-Gaps.org ##
@@ .gitbay/wiki/Architecture/10-Known-Gaps.org: what the 2026-09-27 review found; remove a row when its issue closes.
+
+ | Issue | Area | Gap | Severity |
|-------+------------------+-----------------------------------------------------------------------+----------|
- | #256 | Authentication | A removed SSH key keeps working on connections already open | high |
- | #257 | Credentials | An expiring token can create credentials that outlive it; tokens default to full scope | high |
-| #258 | CI integrity | Any writer can post a =ci/*= status; tree reuse ignores trust and image | high |
| #259 | Recovery | No restore has been exercised; verification does not check git connectivity | high |
| #260 | CI network | Builds share the runner's source address; no egress policy | medium |
8: 734d0a4 < -: ------- changelog: #255, #258
-: ------- > 47: 7a5f2a1 changelog: #255, #258
9: ef74a96 ! 48: 42a7b12 wiki, changelog: last finisher sets ci/<job>; required contexts report on heads
@@ .gitbay/wiki/CI.org: Rows worth a second look:
and the store, and =TestPushShapesTableOnWiki= checks that this page
## CHANGELOG.org ##
-@@ CHANGELOG.org: anything beyond "replace the binary and restart" is needed.
-
- * Unreleased
-
--- Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
--- =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
+@@ CHANGELOG.org: for the eighteen commands whose CLI path differs from the registry's
+ browser (#269).
+ - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
+ - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
+- Untrusted builds (merge requests from forks) get a fresh HOME
+ removed after the build and no secrets; trusted builds keep a
+ per-repository home under =<workdir>/trusted-home=. Deploy gitbayd