Range-diff !489
back to !489 builds: name the failed step and duration; jump to failure
1: 848f79b = 1: 848f79b runner next: say whether the build is trusted
2: 5f01597 = 2: 5f01597 runner: disposable home for untrusted builds
3: bb4a146 = 3: bb4a146 wiki: trusted and untrusted build homes
4: 2e830df = 4: 2e830df status set: ci/ is reserved for the instance's builds
5: 3453d63 = 5: 3453d63 ci: reuse only trusted results on the job's image
6: bba63a3 = 6: bba63a3 repo settings: required contexts turn the checks gate on, pending until reported
7: 60cf9c5 = 7: 60cf9c5 wiki: reserved ci/ statuses, trusted reuse, required contexts
8: 734d0a4 = 8: 734d0a4 changelog: #255, #258
-: ------- > 9: ef74a96 wiki, changelog: last finisher sets ci/<job>; required contexts report on heads
9: 53b38a9 = 10: ee343ff runner next: send the instance's public ssh destination
10: 807cc74 = 11: 457dbd2 runner: builds off the host's loopback when the runner polls over it
11: 7d25186 = 12: debffbc sshd: test the auth limiter's lockout by registration mode
12: e585e87 = 13: 6caa5ef runner host: builds reach only the forge's public ports on it
13: 867e976 = 14: 32cf32b runner egress: remove the rule when it blocks the runner's poll
14: 3e39e00 ! 15: d50a925 wiki: what a build can reach
@@ .gitbay/wiki/Users.org: with =sh -c= on the instance's runner, stopping at the f
## CHANGELOG.org ##
@@ CHANGELOG.org: anything beyond "replace the binary and restart" is needed.
-
- - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
- - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
-+- Builds lose host loopback and reach only the forge's public 22, 80 and 443 on the host. Deploy gitbayd, then the runner, after validating on a scratch repository per the CI page. (#260)
+ same image. =repo settings require-contexts= names status contexts
+ that must report green; setting any turns require-checks on, and one
+ not yet reported counts as pending. (#258)
++- Builds lose host loopback and reach only the forge's public 22, 80
++ and 443 on the host. Deploy gitbayd, then the runner, after
++ validating on a scratch repository per the CI page. (#260)
* v1.36.0 — 2026-09-23
-: ------- > 16: b32d8de runner: builds reach the forge at pasta's host address
-: ------- > 17: 2e26fae runner: only a loopback runner's podman builds leave -remote
15: bbc35bc = 18: c3ec5a0 store: failed step and reason on a build
16: c64f9c7 = 19: c413cd8 runner done: record the failed step and reason
17: 84932b0 = 20: b3597da runner: name the failed step and report it
18: f4be5ab ! 21: ba1f3e1 build show: failed step and duration; build log --step, --tail
@@ Commit message
## CHANGELOG.org ##
@@ CHANGELOG.org: anything beyond "replace the binary and restart" is needed.
- - Untrusted builds (merge requests from forks) get a fresh HOME removed after the build and no secrets; trusted builds keep a per-repository home under =<workdir>/trusted-home=. Deploy gitbayd before the runner; the old shared homes under the runner's workdir can be deleted. (#255)
- - =status set= refuses =ci/= contexts, which belong to the instance's builds. Build results are reused only from trusted builds on the same image. =repo settings require-contexts= names status contexts that must report green; setting any turns require-checks on, and one not yet reported counts as pending. (#258)
- - Builds lose host loopback and reach only the forge's public 22, 80 and 443 on the host. Deploy gitbayd, then the runner, after validating on a scratch repository per the CI page. (#260)
-+- =build show= names a failed build's step and duration; =build log --step <n>|failed --tail <lines>= reads one step's output or the last lines of the stored log. (#266)
+ =deploy/runner-podman-setup.sh= (it installs nftables) before =make
+ deploy-runner=. Deploy gitbayd, then the runner, after validating on
+ a scratch repository per the CI page. (#260)
++- =build show= names a failed build's step and duration; =build log
++ --step <n>|failed --tail <lines>= reads one step's output or the
++ last lines of the stored log. (#266)
* v1.36.0 — 2026-09-23
19: 8d5621a = 22: b11b571 web: build log folded by step, failed step open
20: e6fb980 = 23: 396c1c3 wiki: failed step, build log --step and --tail
-: ------- > 24: 9ddb593 web: step fold shows the step's first line; changelog: deploy order