From e1eb8ae7b10ffda3e52265fff38c31e316fe65f1 Mon Sep 17 00:00:00 2001 From: homelab-runtime-publisher Date: Thu, 6 Aug 2026 00:49:30 +0000 Subject: [PATCH] runtime: publish HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z --- ...GNOSTIC-READ-ONLY-R7-20260806T005000Z.json | 38 +++++++++++++++++++ ...AGNOSTIC-READ-ONLY-R7-20260806T005000Z.txt | 34 +++++++++++++++++ runtime/latest.json | 34 ++++++++--------- runtime/latest.txt | 34 ++++++++--------- 4 files changed, 106 insertions(+), 34 deletions(-) create mode 100644 runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.json create mode 100644 runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.txt diff --git a/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.json b/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.json new file mode 100644 index 0000000..2ca211a --- /dev/null +++ b/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.json @@ -0,0 +1,38 @@ +{ + "schema_version": 1, + "channel": "homelab-runtime", + "command_id": "HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z", + "status": "FAIL", + "rc": 3, + "host": "pve01", + "mode": "verify", + "component": "cluster-knowledge-base-error-system", + "started_at_utc": "2026-08-06T00:49:24Z", + "finished_at_utc": "2026-08-06T00:49:29Z", + "reference_register_checked": true, + "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", + "error_register_checked": true, + "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", + "command_sha256": "8618865b73e07435e9e3f5d746b656bb78264fcb05f8de9b338159f052b0040e", + "duplicate_failed_command_blocked": false, + "block_reason": null, + "execution_started": true, + "change_declared": false, + "result_contract_valid": true, + "result_contract_status": null, + "result_contract_error": null, + "command_rc": 3, + "changes_made": false, + "rollback_started": false, + "rollback_restored": null, + "mutation_outcome": "NO_MUTATION", + "sanitized": true, + "secrets_included": false, + "private_addresses_included": false, + "raw_evidence_retained_locally": true, + "raw_evidence_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", + "sanitized_output_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", + "output_truncated_in_json": false, + "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", + "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"ERROR\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"error_system_v2_future_record\":{\"classification\":\"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER\",\"fingerprint\":\"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023\",\"id\":\"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE\",\"negative_control\":\"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision\",\"normalized_signature\":\"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update\",\"positive_control\":\"protected main has direct push disabled and the previous real push was rejected\",\"prevention_rule\":\"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.\",\"regression_test_required\":true,\"space\":\"runtime\"},\"exact_error\":{\"code\":\"UNEXPECTED_READ_ONLY_DIAGNOSTIC_FAILURE\",\"evidence\":{\"exception\":\"KeyError\"},\"message\":\"Unexpected exception in read-only diagnostic\"},\"identity_confirmed\":false,\"mode\":\"READ_ONLY\",\"mutation_outcome\":\"NO_MUTATION\",\"next_step\":\"Prepare no mutation command until the read-only diagnostic implementation failure is resolved.\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":\"homelab.read-only-diagnostic.v4\",\"status\":\"ERROR\"}\n" +} diff --git a/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.txt b/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.txt new file mode 100644 index 0000000..ed33dfa --- /dev/null +++ b/runtime/history/HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z.txt @@ -0,0 +1,34 @@ +CHAT_OUTPUT_BEGIN +COMMAND_ID=HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z +STATUS=FAIL +RC=3 +HOST=pve01 +MODE=verify +COMPONENT=cluster-knowledge-base-error-system +REFERENCE_REGISTER_CHECK=OK +REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e +ERROR_REGISTER_CHECK=OK +ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83 +COMMAND_SHA256=8618865b73e07435e9e3f5d746b656bb78264fcb05f8de9b338159f052b0040e +DUPLICATE_FAILED_COMMAND_BLOCKED=false +EXECUTION_STARTED=true +CHANGE_DECLARED=false +RESULT_CONTRACT_VALID=true +RESULT_CONTRACT_STATUS=NOT_APPLICABLE +RESULT_CONTRACT_ERROR=NONE +COMMAND_RC=3 +CHANGES_MADE=false +ROLLBACK_STARTED=false +ROLLBACK_RESTORED=null +MUTATION_OUTCOME=NO_MUTATION +SANITIZED=yes +SECRETS_INCLUDED=no +PRIVATE_ADDRESSES_INCLUDED=no +RAW_EVIDENCE_SHA256=73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6 +SANITIZED_OUTPUT_SHA256=73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6 +OUTPUT_BEGIN +HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z","command_rc":3,"control_plane_error":null,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":3,"rollback_restored":null,"rollback_started":false,"status":"ERROR","version":1} +{"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z","command_rc":3,"control_plane_error":null,"error_system_v2_future_record":{"classification":"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER","fingerprint":"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023","id":"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE","negative_control":"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision","normalized_signature":"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update","positive_control":"protected main has direct push disabled and the previous real push was rejected","prevention_rule":"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.","regression_test_required":true,"space":"runtime"},"exact_error":{"code":"UNEXPECTED_READ_ONLY_DIAGNOSTIC_FAILURE","evidence":{"exception":"KeyError"},"message":"Unexpected exception in read-only diagnostic"},"identity_confirmed":false,"mode":"READ_ONLY","mutation_outcome":"NO_MUTATION","next_step":"Prepare no mutation command until the read-only diagnostic implementation failure is resolved.","output_truncated_in_json":false,"rc":3,"rollback_restored":null,"rollback_started":false,"schema":"homelab.read-only-diagnostic.v4","status":"ERROR"} + +OUTPUT_END +CHAT_OUTPUT_END diff --git a/runtime/latest.json b/runtime/latest.json index 0d0fe84..2ca211a 100644 --- a/runtime/latest.json +++ b/runtime/latest.json @@ -1,38 +1,38 @@ { "schema_version": 1, "channel": "homelab-runtime", - "command_id": "HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z", + "command_id": "HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z", "status": "FAIL", - "rc": 76, + "rc": 3, "host": "pve01", - "mode": "change", - "component": "homelab-cluster-admin-update-visibility", - "started_at_utc": "2026-08-06T00:48:32Z", - "finished_at_utc": "2026-08-06T00:48:34Z", + "mode": "verify", + "component": "cluster-knowledge-base-error-system", + "started_at_utc": "2026-08-06T00:49:24Z", + "finished_at_utc": "2026-08-06T00:49:29Z", "reference_register_checked": true, "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", "error_register_checked": true, "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", - "command_sha256": "34f7ae0524db98b883dac5b6a06408d0724cba0e0d1681216646389fcff55f92", + "command_sha256": "8618865b73e07435e9e3f5d746b656bb78264fcb05f8de9b338159f052b0040e", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, - "change_declared": true, - "result_contract_valid": false, + "change_declared": false, + "result_contract_valid": true, "result_contract_status": null, - "result_contract_error": "INVALID_CONTRACT:ValueError", - "command_rc": 1, - "changes_made": null, - "rollback_started": null, + "result_contract_error": null, + "command_rc": 3, + "changes_made": false, + "rollback_started": false, "rollback_restored": null, - "mutation_outcome": "UNKNOWN", + "mutation_outcome": "NO_MUTATION", "sanitized": true, "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, - "raw_evidence_sha256": "82d4c214d757c8bd440e147d78fd526866cf538ecad144f47917463d2f20401d", - "sanitized_output_sha256": "9091ce6d593c87b57b01759393cac085569d71afbdf30b9a8904be4bacfc2c96", + "raw_evidence_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", + "sanitized_output_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", - "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z\",\"command_rc\":1,\"control_plane_error\":null,\"mutation_outcome\":\"ROLLED_BACK\",\"rc\":1,\"report_bytes\":2378,\"report_sha256\":\"0a6c5d44e399a67835ada32d323748a444f10ceaf9e4b4d1ebed2ab9f035a983\",\"rollback_restored\":true,\"rollback_started\":true,\"status\":\"FAIL\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z\",\"error\":\"RuntimeError: HTML route auth guard {'path': '/cluster-admin-updates.html', 'rc': 0, 'http_status': 500, 'location': None, 'body_sha256': 'e41656eb2ba6c6293bf6dd928e5a88cdbc50535cab661c1969e0f598e497ed62', 'body_bytes': 21, 'stderr': ''}\",\"error_type\":\"RuntimeError\",\"mutation_outcome\":\"ROLLED_BACK\",\"remote\":{\"backup\":\"/var/backups/homelab-cluster-admin/HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z/incident-engine-app.py\",\"candidate_sha256\":\"26787f335382f6d6beff9a31a185e4998f50f91eed9b8b94831619c5a87a9647\",\"changed\":false,\"error\":\"RuntimeError: HTML route auth guard {'path': '/cluster-admin-updates.html', 'rc': 0, 'http_status': 500, 'location': None, 'body_sha256': 'e41656eb2ba6c6293bf6dd928e5a88cdbc50535cab661c1969e0f598e497ed62', 'body_bytes': 21, 'stderr': ''}\",\"original_sha256\":\"17d95ebfc28cef34846a8999664019d5d032ee8176b7fedd9ceeebfc5c97e3b6\",\"rollback_errors\":[],\"service_after_rollback\":{\"ActiveState\":\"active\",\"ExecMainStatus\":\"0\",\"ExecStart\":\"{ path=/usr/bin/python3 ; argv[]=/usr/bin/python3 -m uvicorn app:app --host 0.0.0.0 --port 8081 --proxy-headers --forwarded-allow-ips=[PRIVATE_IP],127.0.0.1 ; ignore_errors=no ; start_time=[Thu 2026-08-06 00:48:34 UTC] ; stop_time=[n/a] ; pid=2130676 ; code=(null) ; status=0/0 }\",\"FragmentPath\":\"/etc/systemd/system/cluster-admin-incident-engine.service\",\"LoadState\":\"loaded\",\"MainPID\":\"2130676\",\"Result\":\"success\",\"SubState\":\"running\",\"UnitFileState\":\"enabled\",\"WorkingDirectory\":\"/opt/cluster-admin-incident-engine\"},\"service_before\":{\"ActiveState\":\"active\",\"ExecMainStatus\":\"0\",\"ExecStart\":\"{ path=/usr/bin/python3 ; argv[]=/usr/bin/python3 -m uvicorn app:app --host 0.0.0.0 --port 8081 --proxy-headers --forwarded-allow-ips=[PRIVATE_IP],127.0.0.1 ; ignore_errors=no ; start_time=[Thu 2026-08-06 00:19:50 UTC] ; stop_time=[n/a] ; pid=2125508 ; code=(null) ; status=0/0 }\",\"FragmentPath\":\"/etc/systemd/system/cluster-admin-incident-engine.service\",\"LoadState\":\"loaded\",\"MainPID\":\"2125508\",\"Result\":\"success\",\"SubState\":\"running\",\"UnitFileState\":\"enabled\",\"WorkingDirectory\":\"/opt/cluster-admin-incident-engine\"},\"status\":\"FAILED_ROLLED_BACK\"},\"rollback_errors\":[],\"rollback_restored\":true,\"rollback_started\":true,\"schema\":45,\"status\":\"FAIL\"}\n" + "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"ERROR\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"error_system_v2_future_record\":{\"classification\":\"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER\",\"fingerprint\":\"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023\",\"id\":\"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE\",\"negative_control\":\"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision\",\"normalized_signature\":\"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update\",\"positive_control\":\"protected main has direct push disabled and the previous real push was rejected\",\"prevention_rule\":\"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.\",\"regression_test_required\":true,\"space\":\"runtime\"},\"exact_error\":{\"code\":\"UNEXPECTED_READ_ONLY_DIAGNOSTIC_FAILURE\",\"evidence\":{\"exception\":\"KeyError\"},\"message\":\"Unexpected exception in read-only diagnostic\"},\"identity_confirmed\":false,\"mode\":\"READ_ONLY\",\"mutation_outcome\":\"NO_MUTATION\",\"next_step\":\"Prepare no mutation command until the read-only diagnostic implementation failure is resolved.\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":\"homelab.read-only-diagnostic.v4\",\"status\":\"ERROR\"}\n" } diff --git a/runtime/latest.txt b/runtime/latest.txt index e432f13..ed33dfa 100644 --- a/runtime/latest.txt +++ b/runtime/latest.txt @@ -1,34 +1,34 @@ CHAT_OUTPUT_BEGIN -COMMAND_ID=HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z +COMMAND_ID=HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z STATUS=FAIL -RC=76 +RC=3 HOST=pve01 -MODE=change -COMPONENT=homelab-cluster-admin-update-visibility +MODE=verify +COMPONENT=cluster-knowledge-base-error-system REFERENCE_REGISTER_CHECK=OK REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e ERROR_REGISTER_CHECK=OK ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83 -COMMAND_SHA256=34f7ae0524db98b883dac5b6a06408d0724cba0e0d1681216646389fcff55f92 +COMMAND_SHA256=8618865b73e07435e9e3f5d746b656bb78264fcb05f8de9b338159f052b0040e DUPLICATE_FAILED_COMMAND_BLOCKED=false EXECUTION_STARTED=true -CHANGE_DECLARED=true -RESULT_CONTRACT_VALID=false -RESULT_CONTRACT_STATUS=UNKNOWN -RESULT_CONTRACT_ERROR=INVALID_CONTRACT:ValueError -COMMAND_RC=1 -CHANGES_MADE=unknown -ROLLBACK_STARTED=unknown +CHANGE_DECLARED=false +RESULT_CONTRACT_VALID=true +RESULT_CONTRACT_STATUS=NOT_APPLICABLE +RESULT_CONTRACT_ERROR=NONE +COMMAND_RC=3 +CHANGES_MADE=false +ROLLBACK_STARTED=false ROLLBACK_RESTORED=null -MUTATION_OUTCOME=UNKNOWN +MUTATION_OUTCOME=NO_MUTATION SANITIZED=yes SECRETS_INCLUDED=no PRIVATE_ADDRESSES_INCLUDED=no -RAW_EVIDENCE_SHA256=82d4c214d757c8bd440e147d78fd526866cf538ecad144f47917463d2f20401d -SANITIZED_OUTPUT_SHA256=9091ce6d593c87b57b01759393cac085569d71afbdf30b9a8904be4bacfc2c96 +RAW_EVIDENCE_SHA256=73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6 +SANITIZED_OUTPUT_SHA256=73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6 OUTPUT_BEGIN -HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z","command_rc":1,"control_plane_error":null,"mutation_outcome":"ROLLED_BACK","rc":1,"report_bytes":2378,"report_sha256":"0a6c5d44e399a67835ada32d323748a444f10ceaf9e4b4d1ebed2ab9f035a983","rollback_restored":true,"rollback_started":true,"status":"FAIL","version":1} -{"changes_made":false,"command_id":"HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z","error":"RuntimeError: HTML route auth guard {'path': '/cluster-admin-updates.html', 'rc': 0, 'http_status': 500, 'location': None, 'body_sha256': 'e41656eb2ba6c6293bf6dd928e5a88cdbc50535cab661c1969e0f598e497ed62', 'body_bytes': 21, 'stderr': ''}","error_type":"RuntimeError","mutation_outcome":"ROLLED_BACK","remote":{"backup":"/var/backups/homelab-cluster-admin/HOMELAB-CLUSTER-ADMIN-UPDATES-V45-MISSING-V42-CONSTANT-FIXED-PATCH-20260806T004600Z/incident-engine-app.py","candidate_sha256":"26787f335382f6d6beff9a31a185e4998f50f91eed9b8b94831619c5a87a9647","changed":false,"error":"RuntimeError: HTML route auth guard {'path': '/cluster-admin-updates.html', 'rc': 0, 'http_status': 500, 'location': None, 'body_sha256': 'e41656eb2ba6c6293bf6dd928e5a88cdbc50535cab661c1969e0f598e497ed62', 'body_bytes': 21, 'stderr': ''}","original_sha256":"17d95ebfc28cef34846a8999664019d5d032ee8176b7fedd9ceeebfc5c97e3b6","rollback_errors":[],"service_after_rollback":{"ActiveState":"active","ExecMainStatus":"0","ExecStart":"{ path=/usr/bin/python3 ; argv[]=/usr/bin/python3 -m uvicorn app:app --host 0.0.0.0 --port 8081 --proxy-headers --forwarded-allow-ips=[PRIVATE_IP],127.0.0.1 ; ignore_errors=no ; start_time=[Thu 2026-08-06 00:48:34 UTC] ; stop_time=[n/a] ; pid=2130676 ; code=(null) ; status=0/0 }","FragmentPath":"/etc/systemd/system/cluster-admin-incident-engine.service","LoadState":"loaded","MainPID":"2130676","Result":"success","SubState":"running","UnitFileState":"enabled","WorkingDirectory":"/opt/cluster-admin-incident-engine"},"service_before":{"ActiveState":"active","ExecMainStatus":"0","ExecStart":"{ path=/usr/bin/python3 ; argv[]=/usr/bin/python3 -m uvicorn app:app --host 0.0.0.0 --port 8081 --proxy-headers --forwarded-allow-ips=[PRIVATE_IP],127.0.0.1 ; ignore_errors=no ; start_time=[Thu 2026-08-06 00:19:50 UTC] ; stop_time=[n/a] ; pid=2125508 ; code=(null) ; status=0/0 }","FragmentPath":"/etc/systemd/system/cluster-admin-incident-engine.service","LoadState":"loaded","MainPID":"2125508","Result":"success","SubState":"running","UnitFileState":"enabled","WorkingDirectory":"/opt/cluster-admin-incident-engine"},"status":"FAILED_ROLLED_BACK"},"rollback_errors":[],"rollback_restored":true,"rollback_started":true,"schema":45,"status":"FAIL"} +HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z","command_rc":3,"control_plane_error":null,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":3,"rollback_restored":null,"rollback_started":false,"status":"ERROR","version":1} +{"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z","command_rc":3,"control_plane_error":null,"error_system_v2_future_record":{"classification":"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER","fingerprint":"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023","id":"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE","negative_control":"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision","normalized_signature":"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update","positive_control":"protected main has direct push disabled and the previous real push was rejected","prevention_rule":"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.","regression_test_required":true,"space":"runtime"},"exact_error":{"code":"UNEXPECTED_READ_ONLY_DIAGNOSTIC_FAILURE","evidence":{"exception":"KeyError"},"message":"Unexpected exception in read-only diagnostic"},"identity_confirmed":false,"mode":"READ_ONLY","mutation_outcome":"NO_MUTATION","next_step":"Prepare no mutation command until the read-only diagnostic implementation failure is resolved.","output_truncated_in_json":false,"rc":3,"rollback_restored":null,"rollback_started":false,"schema":"homelab.read-only-diagnostic.v4","status":"ERROR"} OUTPUT_END CHAT_OUTPUT_END