{ "schema_version": 1, "channel": "homelab-runtime", "command_id": "HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z", "status": "FAIL", "rc": 3, "host": "pve01", "mode": "verify", "component": "cluster-knowledge-base-error-system", "started_at_utc": "2026-08-06T00:49:24Z", "finished_at_utc": "2026-08-06T00:49:29Z", "reference_register_checked": true, "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", "error_register_checked": true, "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", "command_sha256": "8618865b73e07435e9e3f5d746b656bb78264fcb05f8de9b338159f052b0040e", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, "change_declared": false, "result_contract_valid": true, "result_contract_status": null, "result_contract_error": null, "command_rc": 3, "changes_made": false, "rollback_started": false, "rollback_restored": null, "mutation_outcome": "NO_MUTATION", "sanitized": true, "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, "raw_evidence_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", "sanitized_output_sha256": "73227f43f05e8b6420a66a329965ec2535c0818d192de99b156a9c24ca2a52d6", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"ERROR\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R7-20260806T005000Z\",\"command_rc\":3,\"control_plane_error\":null,\"error_system_v2_future_record\":{\"classification\":\"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER\",\"fingerprint\":\"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023\",\"id\":\"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE\",\"negative_control\":\"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision\",\"normalized_signature\":\"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update\",\"positive_control\":\"protected main has direct push disabled and the previous real push was rejected\",\"prevention_rule\":\"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.\",\"regression_test_required\":true,\"space\":\"runtime\"},\"exact_error\":{\"code\":\"UNEXPECTED_READ_ONLY_DIAGNOSTIC_FAILURE\",\"evidence\":{\"exception\":\"KeyError\"},\"message\":\"Unexpected exception in read-only diagnostic\"},\"identity_confirmed\":false,\"mode\":\"READ_ONLY\",\"mutation_outcome\":\"NO_MUTATION\",\"next_step\":\"Prepare no mutation command until the read-only diagnostic implementation failure is resolved.\",\"output_truncated_in_json\":false,\"rc\":3,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":\"homelab.read-only-diagnostic.v4\",\"status\":\"ERROR\"}\n" }