Range-diff !489

back to !489 builds: name the failed step and duration; jump to failure

 1:  848f79b =  1:  848f79b runner next: say whether the build is trusted
 2:  5f01597 =  2:  5f01597 runner: disposable home for untrusted builds
 3:  bb4a146 =  3:  bb4a146 wiki: trusted and untrusted build homes
 4:  2e830df =  4:  2e830df status set: ci/ is reserved for the instance's builds
 5:  3453d63 =  5:  3453d63 ci: reuse only trusted results on the job's image
 6:  bba63a3 =  6:  bba63a3 repo settings: required contexts turn the checks gate on, pending until reported
 7:  60cf9c5 =  7:  60cf9c5 wiki: reserved ci/ statuses, trusted reuse, required contexts
 8:  734d0a4 =  8:  734d0a4 changelog: #255, #258
 -:  ------- >  9:  ef74a96 wiki, changelog: last finisher sets ci/<job>; required contexts report on heads
 9:  53b38a9 = 10:  ee343ff runner next: send the instance's public ssh destination
10:  807cc74 = 11:  457dbd2 runner: builds off the host's loopback when the runner polls over it
11:  7d25186 = 12:  debffbc sshd: test the auth limiter's lockout by registration mode
12:  e585e87 = 13:  6caa5ef runner host: builds reach only the forge's public ports on it
13:  867e976 = 14:  32cf32b runner egress: remove the rule when it blocks the runner's poll
14:  3e39e00 ! 15:  d50a925 wiki: what a build can reach
    @@ .gitbay/wiki/Users.org: with =sh -c= on the instance's runner, stopping at the f
     
      ## CHANGELOG.org ##
     @@ CHANGELOG.org: anything beyond "replace the binary and restart" is needed.
    - 
    - - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
    - - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
    -+- Builds lose host loopback and reach only the forge's public 22, 80 and 443 on the host. Deploy gitbayd, then the runner, after validating on a scratch repository per the CI page. (#260)
    +   same image. =repo settings require-contexts= names status contexts
    +   that must report green; setting any turns require-checks on, and one
    +   not yet reported counts as pending. (#258)
    ++- Builds lose host loopback and reach only the forge's public 22, 80
    ++  and 443 on the host. Deploy gitbayd, then the runner, after
    ++  validating on a scratch repository per the CI page. (#260)
      
      * v1.36.0 — 2026-09-23
      
 -:  ------- > 16:  b32d8de runner: builds reach the forge at pasta's host address
 -:  ------- > 17:  2e26fae runner: only a loopback runner's podman builds leave -remote
15:  bbc35bc = 18:  c3ec5a0 store: failed step and reason on a build
16:  c64f9c7 = 19:  c413cd8 runner done: record the failed step and reason
17:  84932b0 = 20:  b3597da runner: name the failed step and report it
18:  f4be5ab ! 21:  ba1f3e1 build show: failed step and duration; build log --step, --tail
    @@ Commit message
     
      ## CHANGELOG.org ##
     @@ CHANGELOG.org: anything beyond "replace the binary and restart" is needed.
    - - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
    - - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
    - - Builds lose host loopback and reach only the forge's public 22, 80 and 443 on the host. Deploy gitbayd, then the runner, after validating on a scratch repository per the CI page. (#260)
    -+- =build show= names a failed build's step and duration; =build log --step <n>|failed --tail <lines>= reads one step's output or the last lines of the stored log. (#266)
    +   =deploy/runner-podman-setup.sh= (it installs nftables) before =make
    +   deploy-runner=. Deploy gitbayd, then the runner, after validating on
    +   a scratch repository per the CI page. (#260)
    ++- =build show= names a failed build's step and duration; =build log
    ++  --step <n>|failed --tail <lines>= reads one step's output or the
    ++  last lines of the stored log. (#266)
      
      * v1.36.0 — 2026-09-23
      
19:  8d5621a = 22:  b11b571 web: build log folded by step, failed step open
20:  e6fb980 = 23:  396c1c3 wiki: failed step, build log --step and --tail
 -:  ------- > 24:  9ddb593 web: step fold shows the step's first line; changelog: deploy order