diff --git a/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.json b/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.json new file mode 100644 index 0000000..d576e14 --- /dev/null +++ b/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.json @@ -0,0 +1,38 @@ +{ + "schema_version": 1, + "channel": "homelab-runtime", + "command_id": "HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z", + "status": "FAIL", + "rc": 1, + "host": "pve01", + "mode": "verify", + "component": "cluster-knowledge-base-error-system", + "started_at_utc": "2026-08-05T10:58:31Z", + "finished_at_utc": "2026-08-05T10:58:31Z", + "reference_register_checked": true, + "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", + "error_register_checked": true, + "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", + "command_sha256": "0f512bef46a7291845ac35d31178c3b276aeedb7c7b92b5b49ae9c01f1b893ee", + "duplicate_failed_command_blocked": false, + "block_reason": null, + "execution_started": true, + "change_declared": false, + "result_contract_valid": true, + "result_contract_status": null, + "result_contract_error": null, + "command_rc": 1, + "changes_made": false, + "rollback_started": false, + "rollback_restored": null, + "mutation_outcome": "NO_MUTATION", + "sanitized": true, + "secrets_included": false, + "private_addresses_included": false, + "raw_evidence_retained_locally": true, + "raw_evidence_sha256": "8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde", + "sanitized_output_sha256": "8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde", + "output_truncated_in_json": false, + "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", + "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z\",\"command_rc\":1,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":1,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"FAIL\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z\",\"command_rc\":1,\"error\":\"result exceeds output bound after deterministic compaction\",\"error_fingerprint\":\"0141f0f7009c41a327fbbeeaae86d192975993f5aa135b01e747778c1a5219ac\",\"error_type\":\"RuntimeError\",\"latest_exact_result_basis\":{\"capsule_sha256\":\"9580200bb633ed9c4b7eebab6e160d723a728d8b9dbcf34803f6d43627d0c838\",\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-FAKE-DEPENDENCY-CONTRACT-FIX-READ-ONLY-20260805T104000Z\",\"command_rc\":0,\"control_plane_error\":null,\"error_fingerprint\":\"f625204be2a45aca4b0e31f18a66146eee3d05ca9cb2d6705b9a821bfc0e993e\",\"mutation_outcome\":\"NO_MUTATION\",\"next_action\":\"RUN_ONE_READ_ONLY_READER_V3_EXACT_MANIFEST_SCHEMA_TRACE\",\"output_complete\":true,\"output_sha256\":\"8b175d403825bf21d0222a3ecb18a502790378b739bf85e140c62740af58fb89\",\"output_truncated_in_json\":false,\"rc\":0,\"rollback_restored\":null,\"rollback_started\":false,\"root_cause_classification\":\"READER_V3_FEED_CAUGHT_EXCEPTION_ORIGIN_PROVEN\",\"runner_document_rc\":0,\"runner_json_sha256\":\"d68de9445fcdff0647bfac60d5b424d99a59e0ad332834fe78f0fef5ab3e8eba\",\"runner_rc\":0,\"runner_text_sha256\":\"4ba1efeb392165326b413d950f48fbb24144f2c844a3453157b438df51a4534d\",\"runner_wrapper_matches_document\":true,\"status\":\"OK\"},\"mutation_outcome\":\"NO_MUTATION\",\"next_action\":\"FIX_ONLY_THE_PROVEN_PAYLOAD_ERROR_THEN_RETRY\",\"output_truncated_in_json\":false,\"pre_command_known_error_gate\":{\"checked\":true,\"items\":[{\"id\":\"candidate-scan-limit-20260805\",\"prevention\":\"exact files only; bounded AST, simulation, response and output limits\"},{\"id\":\"runner-wrapper-mismatch-20260805\",\"prevention\":\"single compact JSON below 42000 bytes; no raw source, secret or response body\"},{\"id\":\"gitea-owner-hardcoded-20260805\",\"prevention\":\"no repository owner, guest ID or repository URL is assumed\"},{\"id\":\"gitea-git-auth-unavailable-20260805\",\"prevention\":\"no Git or Gitea authentication attempt\"},{\"id\":\"pvesh-adapter-context-unreadable-20260805\",\"prevention\":\"the payload does not call pvesh or any real executor\"},{\"id\":\"gitea-process-self-match-20260805\",\"prevention\":\"Reader identity is bound to exact systemd ControlGroup\"},{\"id\":\"sanitize-non-string-attributeerror-20260805\",\"prevention\":\"sanitize converts Any to str; embedded bool test\"},{\"id\":\"reader-path-env-misclassified-as-route-20260805\",\"prevention\":\"PATH and filesystem-like values are excluded from request candidates\"},{\"id\":\"reader-loopback-only-probe-20260805\",\"prevention\":\"owned listeners are inspected but no network connection is made\"},{\"id\":\"reader-capability-not-secret-20260805\",\"prevention\":\"capability values are redacted before every output projection\"},{\"id\":\"reader-systemd-unit-parsed-as-python-20260805\",\"prevention\":\"only the exact Python server source is parsed or compiled\"},{\"id\":\"reader-helper-contract-coverage-gap-20260805\",\"prevention\":\"all handler methods reachable from do_GET/do_HEAD are traced\"},{\"id\":\"reader-capability-root-empty-suffix-404-20260805\",\"prevention\":\"never infer inventory from capability-only paths; trace the exact post-prefix suffix and response branch with fake executors first\"},{\"id\":\"reader-generic-suffix-missed-exact-operation-20260805\",\"prevention\":\"derive route operations from exact compiled branch constants and intersect them with AST path literals before sandbox execution\"},{\"id\":\"reader-feed-500-without-origin-20260805\",\"prevention\":\"before any live feed request, trace global helper reachability, exact executor/file argument origins and caught sandbox exceptions; health alone never proves inventory safety\"},{\"id\":\"reader-sandbox-global-binding-undefined-20260805\",\"prevention\":\"materialize reachable module globals only through a strict AST allowlist; Path joins and re.compile are allowed, arbitrary calls are blocked, and MANIFEST/RESULTS/RESULT_RE are regression-tested before any live request\"},{\"id\":\"reader-negative-control-exception-polluted-classification-20260805\",\"prevention\":\"negative-control exceptions are reported separately and can never determine the production readiness classification\"},{\"id\":\"reader-result-regex-candidate-not-proven-20260805\",\"prevention\":\"derive one bounded matching filename from the exact compiled RESULT_RE in memory, verify fullmatch, and emit only length and hashes\"},{\"id\":\"reader-fake-dependency-contract-incomplete-20260805\",\"prevention\":\"derive manifest access keys and container shapes from the exact handler AST, test bounded list/object/map/scalar fixtures, and require two distinct read-only file paths before any live request\"},{\"id\":\"reader-manifest-alias-dataflow-gap-20260805\",\"prevention\":\"trace MANIFEST bytes through decode/json.loads, aliases, nested get/subscript, loop targets and mapping items before constructing any fixture\"}]},\"rc\":1,\"read_only\":true,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":1,\"status\":\"FAIL\"}\n" +} diff --git a/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.txt b/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.txt new file mode 100644 index 0000000..83bd0a7 --- /dev/null +++ b/runtime/history/HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z.txt @@ -0,0 +1,34 @@ +CHAT_OUTPUT_BEGIN +COMMAND_ID=HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z +STATUS=FAIL +RC=1 +HOST=pve01 +MODE=verify +COMPONENT=cluster-knowledge-base-error-system +REFERENCE_REGISTER_CHECK=OK +REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e +ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83 +COMMAND_SHA256=0f512bef46a7291845ac35d31178c3b276aeedb7c7b92b5b49ae9c01f1b893ee +DUPLICATE_FAILED_COMMAND_BLOCKED=false +EXECUTION_STARTED=true +CHANGE_DECLARED=false +RESULT_CONTRACT_VALID=true +RESULT_CONTRACT_STATUS=NOT_APPLICABLE +RESULT_CONTRACT_ERROR=NONE +COMMAND_RC=1 +CHANGES_MADE=false +ROLLBACK_STARTED=false +ROLLBACK_RESTORED=null +MUTATION_OUTCOME=NO_MUTATION +SANITIZED=yes +SECRETS_INCLUDED=no +PRIVATE_ADDRESSES_INCLUDED=no +RAW_EVIDENCE_SHA256=8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde +SANITIZED_OUTPUT_SHA256=8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde +OUTPUT_BEGIN +HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z","command_rc":1,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":1,"rollback_restored":null,"rollback_started":false,"status":"FAIL","version":1} +{"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z","command_rc":1,"error":"result exceeds output bound after deterministic compaction","error_fingerprint":"0141f0f7009c41a327fbbeeaae86d192975993f5aa135b01e747778c1a5219ac","error_type":"RuntimeError","latest_exact_result_basis":{"capsule_sha256":"9580200bb633ed9c4b7eebab6e160d723a728d8b9dbcf34803f6d43627d0c838","changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-FAKE-DEPENDENCY-CONTRACT-FIX-READ-ONLY-20260805T104000Z","command_rc":0,"control_plane_error":null,"error_fingerprint":"f625204be2a45aca4b0e31f18a66146eee3d05ca9cb2d6705b9a821bfc0e993e","mutation_outcome":"NO_MUTATION","next_action":"RUN_ONE_READ_ONLY_READER_V3_EXACT_MANIFEST_SCHEMA_TRACE","output_complete":true,"output_sha256":"8b175d403825bf21d0222a3ecb18a502790378b739bf85e140c62740af58fb89","output_truncated_in_json":false,"rc":0,"rollback_restored":null,"rollback_started":false,"root_cause_classification":"READER_V3_FEED_CAUGHT_EXCEPTION_ORIGIN_PROVEN","runner_document_rc":0,"runner_json_sha256":"d68de9445fcdff0647bfac60d5b424d99a59e0ad332834fe78f0fef5ab3e8eba","runner_rc":0,"runner_text_sha256":"4ba1efeb392165326b413d950f48fbb24144f2c844a3453157b438df51a4534d","runner_wrapper_matches_document":true,"status":"OK"},"mutation_outcome":"NO_MUTATION","next_action":"FIX_ONLY_THE_PROVEN_PAYLOAD_ERROR_THEN_RETRY","output_truncated_in_json":false,"pre_command_known_error_gate":{"checked":true,"items":[{"id":"candidate-scan-limit-20260805","prevention":"exact files only; bounded AST, simulation, response and output limits"},{"id":"runner-wrapper-mismatch-20260805","prevention":"single compact JSON below 42000 bytes; no raw source, secret or response body"},{"id":"gitea-owner-hardcoded-20260805","prevention":"no repository owner, guest ID or repository URL is assumed"},{"id":"gitea-git-auth-unavailable-20260805","prevention":"no Git or Gitea authentication attempt"},{"id":"pvesh-adapter-context-unreadable-20260805","prevention":"the payload does not call pvesh or any real executor"},{"id":"gitea-process-self-match-20260805","prevention":"Reader identity is bound to exact systemd ControlGroup"},{"id":"sanitize-non-string-attributeerror-20260805","prevention":"sanitize converts Any to str; embedded bool test"},{"id":"reader-path-env-misclassified-as-route-20260805","prevention":"PATH and filesystem-like values are excluded from request candidates"},{"id":"reader-loopback-only-probe-20260805","prevention":"owned listeners are inspected but no network connection is made"},{"id":"reader-capability-not-secret-20260805","prevention":"capability values are redacted before every output projection"},{"id":"reader-systemd-unit-parsed-as-python-20260805","prevention":"only the exact Python server source is parsed or compiled"},{"id":"reader-helper-contract-coverage-gap-20260805","prevention":"all handler methods reachable from do_GET/do_HEAD are traced"},{"id":"reader-capability-root-empty-suffix-404-20260805","prevention":"never infer inventory from capability-only paths; trace the exact post-prefix suffix and response branch with fake executors first"},{"id":"reader-generic-suffix-missed-exact-operation-20260805","prevention":"derive route operations from exact compiled branch constants and intersect them with AST path literals before sandbox execution"},{"id":"reader-feed-500-without-origin-20260805","prevention":"before any live feed request, trace global helper reachability, exact executor/file argument origins and caught sandbox exceptions; health alone never proves inventory safety"},{"id":"reader-sandbox-global-binding-undefined-20260805","prevention":"materialize reachable module globals only through a strict AST allowlist; Path joins and re.compile are allowed, arbitrary calls are blocked, and MANIFEST/RESULTS/RESULT_RE are regression-tested before any live request"},{"id":"reader-negative-control-exception-polluted-classification-20260805","prevention":"negative-control exceptions are reported separately and can never determine the production readiness classification"},{"id":"reader-result-regex-candidate-not-proven-20260805","prevention":"derive one bounded matching filename from the exact compiled RESULT_RE in memory, verify fullmatch, and emit only length and hashes"},{"id":"reader-fake-dependency-contract-incomplete-20260805","prevention":"derive manifest access keys and container shapes from the exact handler AST, test bounded list/object/map/scalar fixtures, and require two distinct read-only file paths before any live request"},{"id":"reader-manifest-alias-dataflow-gap-20260805","prevention":"trace MANIFEST bytes through decode/json.loads, aliases, nested get/subscript, loop targets and mapping items before constructing any fixture"}]},"rc":1,"read_only":true,"rollback_restored":null,"rollback_started":false,"schema":1,"status":"FAIL"} + +OUTPUT_END +CHAT_OUTPUT_END diff --git a/runtime/latest.json b/runtime/latest.json index 8895587..d576e14 100644 --- a/runtime/latest.json +++ b/runtime/latest.json @@ -1,19 +1,19 @@ { "schema_version": 1, "channel": "homelab-runtime", - "command_id": "HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z", + "command_id": "HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z", "status": "FAIL", "rc": 1, "host": "pve01", "mode": "verify", - "component": "homelab-cluster-admin-update-visibility", - "started_at_utc": "2026-08-05T10:56:52Z", - "finished_at_utc": "2026-08-05T10:56:52Z", + "component": "cluster-knowledge-base-error-system", + "started_at_utc": "2026-08-05T10:58:31Z", + "finished_at_utc": "2026-08-05T10:58:31Z", "reference_register_checked": true, "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", "error_register_checked": true, "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", - "command_sha256": "381d850eea17b79e69b75ac173c5ec93fce76c737a81a03834e82a2d888b4493", + "command_sha256": "0f512bef46a7291845ac35d31178c3b276aeedb7c7b92b5b49ae9c01f1b893ee", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, @@ -30,9 +30,9 @@ "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, - "raw_evidence_sha256": "0ddc5dc757a2edd836eb8be0ebe617aa17226cef08f56344303ed5581af2ddac", - "sanitized_output_sha256": "0ddc5dc757a2edd836eb8be0ebe617aa17226cef08f56344303ed5581af2ddac", + "raw_evidence_sha256": "8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde", + "sanitized_output_sha256": "8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", - "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z\",\"command_rc\":1,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"rc\":1,\"rollback_restored\":false,\"rollback_started\":false,\"status\":\"FAIL\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z\",\"error\":\"V6 report command_id mismatch actual=\",\"error_type\":\"RuntimeError\",\"mutation_outcome\":\"NO_MUTATION\",\"read_only\":true,\"rollback_restored\":false,\"rollback_started\":false,\"schema\":8,\"status\":\"FAIL\"}\n" + "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z\",\"command_rc\":1,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":1,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"FAIL\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z\",\"command_rc\":1,\"error\":\"result exceeds output bound after deterministic compaction\",\"error_fingerprint\":\"0141f0f7009c41a327fbbeeaae86d192975993f5aa135b01e747778c1a5219ac\",\"error_type\":\"RuntimeError\",\"latest_exact_result_basis\":{\"capsule_sha256\":\"9580200bb633ed9c4b7eebab6e160d723a728d8b9dbcf34803f6d43627d0c838\",\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-KB-V1-READER-V3-FAKE-DEPENDENCY-CONTRACT-FIX-READ-ONLY-20260805T104000Z\",\"command_rc\":0,\"control_plane_error\":null,\"error_fingerprint\":\"f625204be2a45aca4b0e31f18a66146eee3d05ca9cb2d6705b9a821bfc0e993e\",\"mutation_outcome\":\"NO_MUTATION\",\"next_action\":\"RUN_ONE_READ_ONLY_READER_V3_EXACT_MANIFEST_SCHEMA_TRACE\",\"output_complete\":true,\"output_sha256\":\"8b175d403825bf21d0222a3ecb18a502790378b739bf85e140c62740af58fb89\",\"output_truncated_in_json\":false,\"rc\":0,\"rollback_restored\":null,\"rollback_started\":false,\"root_cause_classification\":\"READER_V3_FEED_CAUGHT_EXCEPTION_ORIGIN_PROVEN\",\"runner_document_rc\":0,\"runner_json_sha256\":\"d68de9445fcdff0647bfac60d5b424d99a59e0ad332834fe78f0fef5ab3e8eba\",\"runner_rc\":0,\"runner_text_sha256\":\"4ba1efeb392165326b413d950f48fbb24144f2c844a3453157b438df51a4534d\",\"runner_wrapper_matches_document\":true,\"status\":\"OK\"},\"mutation_outcome\":\"NO_MUTATION\",\"next_action\":\"FIX_ONLY_THE_PROVEN_PAYLOAD_ERROR_THEN_RETRY\",\"output_truncated_in_json\":false,\"pre_command_known_error_gate\":{\"checked\":true,\"items\":[{\"id\":\"candidate-scan-limit-20260805\",\"prevention\":\"exact files only; bounded AST, simulation, response and output limits\"},{\"id\":\"runner-wrapper-mismatch-20260805\",\"prevention\":\"single compact JSON below 42000 bytes; no raw source, secret or response body\"},{\"id\":\"gitea-owner-hardcoded-20260805\",\"prevention\":\"no repository owner, guest ID or repository URL is assumed\"},{\"id\":\"gitea-git-auth-unavailable-20260805\",\"prevention\":\"no Git or Gitea authentication attempt\"},{\"id\":\"pvesh-adapter-context-unreadable-20260805\",\"prevention\":\"the payload does not call pvesh or any real executor\"},{\"id\":\"gitea-process-self-match-20260805\",\"prevention\":\"Reader identity is bound to exact systemd ControlGroup\"},{\"id\":\"sanitize-non-string-attributeerror-20260805\",\"prevention\":\"sanitize converts Any to str; embedded bool test\"},{\"id\":\"reader-path-env-misclassified-as-route-20260805\",\"prevention\":\"PATH and filesystem-like values are excluded from request candidates\"},{\"id\":\"reader-loopback-only-probe-20260805\",\"prevention\":\"owned listeners are inspected but no network connection is made\"},{\"id\":\"reader-capability-not-secret-20260805\",\"prevention\":\"capability values are redacted before every output projection\"},{\"id\":\"reader-systemd-unit-parsed-as-python-20260805\",\"prevention\":\"only the exact Python server source is parsed or compiled\"},{\"id\":\"reader-helper-contract-coverage-gap-20260805\",\"prevention\":\"all handler methods reachable from do_GET/do_HEAD are traced\"},{\"id\":\"reader-capability-root-empty-suffix-404-20260805\",\"prevention\":\"never infer inventory from capability-only paths; trace the exact post-prefix suffix and response branch with fake executors first\"},{\"id\":\"reader-generic-suffix-missed-exact-operation-20260805\",\"prevention\":\"derive route operations from exact compiled branch constants and intersect them with AST path literals before sandbox execution\"},{\"id\":\"reader-feed-500-without-origin-20260805\",\"prevention\":\"before any live feed request, trace global helper reachability, exact executor/file argument origins and caught sandbox exceptions; health alone never proves inventory safety\"},{\"id\":\"reader-sandbox-global-binding-undefined-20260805\",\"prevention\":\"materialize reachable module globals only through a strict AST allowlist; Path joins and re.compile are allowed, arbitrary calls are blocked, and MANIFEST/RESULTS/RESULT_RE are regression-tested before any live request\"},{\"id\":\"reader-negative-control-exception-polluted-classification-20260805\",\"prevention\":\"negative-control exceptions are reported separately and can never determine the production readiness classification\"},{\"id\":\"reader-result-regex-candidate-not-proven-20260805\",\"prevention\":\"derive one bounded matching filename from the exact compiled RESULT_RE in memory, verify fullmatch, and emit only length and hashes\"},{\"id\":\"reader-fake-dependency-contract-incomplete-20260805\",\"prevention\":\"derive manifest access keys and container shapes from the exact handler AST, test bounded list/object/map/scalar fixtures, and require two distinct read-only file paths before any live request\"},{\"id\":\"reader-manifest-alias-dataflow-gap-20260805\",\"prevention\":\"trace MANIFEST bytes through decode/json.loads, aliases, nested get/subscript, loop targets and mapping items before constructing any fixture\"}]},\"rc\":1,\"read_only\":true,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":1,\"status\":\"FAIL\"}\n" } diff --git a/runtime/latest.txt b/runtime/latest.txt index 6cbd307..83bd0a7 100644 --- a/runtime/latest.txt +++ b/runtime/latest.txt @@ -1,15 +1,15 @@ CHAT_OUTPUT_BEGIN -COMMAND_ID=HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z +COMMAND_ID=HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z STATUS=FAIL RC=1 HOST=pve01 MODE=verify -COMPONENT=homelab-cluster-admin-update-visibility +COMPONENT=cluster-knowledge-base-error-system REFERENCE_REGISTER_CHECK=OK REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e ERROR_REGISTER_CHECK=OK ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83 -COMMAND_SHA256=381d850eea17b79e69b75ac173c5ec93fce76c737a81a03834e82a2d888b4493 +COMMAND_SHA256=0f512bef46a7291845ac35d31178c3b276aeedb7c7b92b5b49ae9c01f1b893ee DUPLICATE_FAILED_COMMAND_BLOCKED=false EXECUTION_STARTED=true CHANGE_DECLARED=false @@ -24,11 +24,11 @@ MUTATION_OUTCOME=NO_MUTATION SANITIZED=yes SECRETS_INCLUDED=no PRIVATE_ADDRESSES_INCLUDED=no -RAW_EVIDENCE_SHA256=0ddc5dc757a2edd836eb8be0ebe617aa17226cef08f56344303ed5581af2ddac -SANITIZED_OUTPUT_SHA256=0ddc5dc757a2edd836eb8be0ebe617aa17226cef08f56344303ed5581af2ddac +RAW_EVIDENCE_SHA256=8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde +SANITIZED_OUTPUT_SHA256=8c3f6ed1219cc3da1930e50b0e144855232f89bcd84c4126397488d91036bbde OUTPUT_BEGIN -HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z","command_rc":1,"control_plane_error":null,"mutation_outcome":"NO_MUTATION","rc":1,"rollback_restored":false,"rollback_started":false,"status":"FAIL","version":1} -{"changes_made":false,"command_id":"HOMELAB-CLUSTER-ADMIN-UPDATES-V8-ARCHITECTURE-READ-ONLY-20260805T105500Z","error":"V6 report command_id mismatch actual=","error_type":"RuntimeError","mutation_outcome":"NO_MUTATION","read_only":true,"rollback_restored":false,"rollback_started":false,"schema":8,"status":"FAIL"} +HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z","command_rc":1,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":1,"rollback_restored":null,"rollback_started":false,"status":"FAIL","version":1} +{"changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-EXACT-MANIFEST-SCHEMA-TRACE-READ-ONLY-20260805T105500Z","command_rc":1,"error":"result exceeds output bound after deterministic compaction","error_fingerprint":"0141f0f7009c41a327fbbeeaae86d192975993f5aa135b01e747778c1a5219ac","error_type":"RuntimeError","latest_exact_result_basis":{"capsule_sha256":"9580200bb633ed9c4b7eebab6e160d723a728d8b9dbcf34803f6d43627d0c838","changes_made":false,"command_id":"HOMELAB-CLUSTER-KB-V1-READER-V3-FAKE-DEPENDENCY-CONTRACT-FIX-READ-ONLY-20260805T104000Z","command_rc":0,"control_plane_error":null,"error_fingerprint":"f625204be2a45aca4b0e31f18a66146eee3d05ca9cb2d6705b9a821bfc0e993e","mutation_outcome":"NO_MUTATION","next_action":"RUN_ONE_READ_ONLY_READER_V3_EXACT_MANIFEST_SCHEMA_TRACE","output_complete":true,"output_sha256":"8b175d403825bf21d0222a3ecb18a502790378b739bf85e140c62740af58fb89","output_truncated_in_json":false,"rc":0,"rollback_restored":null,"rollback_started":false,"root_cause_classification":"READER_V3_FEED_CAUGHT_EXCEPTION_ORIGIN_PROVEN","runner_document_rc":0,"runner_json_sha256":"d68de9445fcdff0647bfac60d5b424d99a59e0ad332834fe78f0fef5ab3e8eba","runner_rc":0,"runner_text_sha256":"4ba1efeb392165326b413d950f48fbb24144f2c844a3453157b438df51a4534d","runner_wrapper_matches_document":true,"status":"OK"},"mutation_outcome":"NO_MUTATION","next_action":"FIX_ONLY_THE_PROVEN_PAYLOAD_ERROR_THEN_RETRY","output_truncated_in_json":false,"pre_command_known_error_gate":{"checked":true,"items":[{"id":"candidate-scan-limit-20260805","prevention":"exact files only; bounded AST, simulation, response and output limits"},{"id":"runner-wrapper-mismatch-20260805","prevention":"single compact JSON below 42000 bytes; no raw source, secret or response body"},{"id":"gitea-owner-hardcoded-20260805","prevention":"no repository owner, guest ID or repository URL is assumed"},{"id":"gitea-git-auth-unavailable-20260805","prevention":"no Git or Gitea authentication attempt"},{"id":"pvesh-adapter-context-unreadable-20260805","prevention":"the payload does not call pvesh or any real executor"},{"id":"gitea-process-self-match-20260805","prevention":"Reader identity is bound to exact systemd ControlGroup"},{"id":"sanitize-non-string-attributeerror-20260805","prevention":"sanitize converts Any to str; embedded bool test"},{"id":"reader-path-env-misclassified-as-route-20260805","prevention":"PATH and filesystem-like values are excluded from request candidates"},{"id":"reader-loopback-only-probe-20260805","prevention":"owned listeners are inspected but no network connection is made"},{"id":"reader-capability-not-secret-20260805","prevention":"capability values are redacted before every output projection"},{"id":"reader-systemd-unit-parsed-as-python-20260805","prevention":"only the exact Python server source is parsed or compiled"},{"id":"reader-helper-contract-coverage-gap-20260805","prevention":"all handler methods reachable from do_GET/do_HEAD are traced"},{"id":"reader-capability-root-empty-suffix-404-20260805","prevention":"never infer inventory from capability-only paths; trace the exact post-prefix suffix and response branch with fake executors first"},{"id":"reader-generic-suffix-missed-exact-operation-20260805","prevention":"derive route operations from exact compiled branch constants and intersect them with AST path literals before sandbox execution"},{"id":"reader-feed-500-without-origin-20260805","prevention":"before any live feed request, trace global helper reachability, exact executor/file argument origins and caught sandbox exceptions; health alone never proves inventory safety"},{"id":"reader-sandbox-global-binding-undefined-20260805","prevention":"materialize reachable module globals only through a strict AST allowlist; Path joins and re.compile are allowed, arbitrary calls are blocked, and MANIFEST/RESULTS/RESULT_RE are regression-tested before any live request"},{"id":"reader-negative-control-exception-polluted-classification-20260805","prevention":"negative-control exceptions are reported separately and can never determine the production readiness classification"},{"id":"reader-result-regex-candidate-not-proven-20260805","prevention":"derive one bounded matching filename from the exact compiled RESULT_RE in memory, verify fullmatch, and emit only length and hashes"},{"id":"reader-fake-dependency-contract-incomplete-20260805","prevention":"derive manifest access keys and container shapes from the exact handler AST, test bounded list/object/map/scalar fixtures, and require two distinct read-only file paths before any live request"},{"id":"reader-manifest-alias-dataflow-gap-20260805","prevention":"trace MANIFEST bytes through decode/json.loads, aliases, nested get/subscript, loop targets and mapping items before constructing any fixture"}]},"rc":1,"read_only":true,"rollback_restored":null,"rollback_started":false,"schema":1,"status":"FAIL"} OUTPUT_END CHAT_OUTPUT_END