Skip to main content
Read this before you choose a host’s hooks or build repositories you do not fully trust.

What each kind of build protects

Each build records the kind of isolation it ran with.

What the keys limit

  • The host key ties the runner key to one machine. The runner key’s first claim binds it to the host key. From then on, a leaked runner key is useless without that host key. Until that first claim, anyone holding the runner key can bind it to their own machine. See The host key.
  • The item key is what a build uses in place of the runner key. It acts only on the claimed item and stops working when the claim ends. A container or microVM build never holds it. A builtin:process build can read it from the attempt’s job file. See Item key, and Concepts for claims and leases.

Honest limits

  • Executable hooks and builtin:process run the command as the host’s own user, with the host’s files in reach. That includes the runner key and the host key, so the host key does not protect a runner key from these builds. Only builtin:vm, builtin:container, or hooks with isolation of their own isolate a build.
  • With executable hooks, a child process that leaves the process group (for example with setsid) keeps running after the build stops.
  • On macOS, only the Linux VM isolates a build. The runner key lives inside it, so a build that escaped its container would reach the key.
  • A container build has no Docker inside it. A repository whose tests start Docker needs builtin:vm and a recipe that adds the docker-in-docker feature, or its own hooks.
  • A container build reaches only public addresses. A local, private or Tailscale address is unreachable from inside it.
  • A build can read every value in build.variables, and its gh read token, and send them to any public host the tunnel allows. List the hosts it needs in build.allowHosts.
  • The runner checks which branch a push updates, not what it contains. The review covers the diff.
  • On a branch under outerlayer/, the runner forwards any push, a force-push included. On any other branch it forwards only a push that creates the branch or moves it forward.
  • A container build’s disk limit is checked every thirty seconds, so the build can pass it briefly. A microVM build’s disk is a fixed size.
  • A claim made just before the runner restarts may not be recovered. It expires on its own within fifteen minutes.
  • outerlayer sync’s upload checkpoint lives in the user’s home directory, one per gateway and factory. Two runners under one account, for the same factory, share it.