{ "schema_version": 1, "channel": "homelab-runtime", "command_id": "HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-20260805T165900Z", "status": "FAIL", "rc": 2, "host": "pve01", "mode": "verify", "component": "cluster-knowledge-base-error-system", "started_at_utc": "2026-08-05T23:59:50Z", "finished_at_utc": "2026-08-05T23:59:55Z", "reference_register_checked": true, "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", "error_register_checked": true, "error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83", "command_sha256": "09b6606c2edf48917dc56d27d5e10e526f99f357ae27463d9459c5f3152472fd", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, "change_declared": false, "result_contract_valid": true, "result_contract_status": null, "result_contract_error": null, "command_rc": 2, "changes_made": false, "rollback_started": false, "rollback_restored": null, "mutation_outcome": "NO_MUTATION", "sanitized": true, "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, "raw_evidence_sha256": "53d38d4587051b38a7a63af7faf5baba2775e0db83bd8eac918f8cdd1f8398b6", "sanitized_output_sha256": "53d38d4587051b38a7a63af7faf5baba2775e0db83bd8eac918f8cdd1f8398b6", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", "output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-20260805T165900Z\",\"command_rc\":2,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":2,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"ERROR\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-20260805T165900Z\",\"command_rc\":2,\"control_plane_error\":null,\"error_system_v2_future_record\":{\"classification\":\"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER\",\"fingerprint\":\"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023\",\"id\":\"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE\",\"negative_control\":\"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision\",\"normalized_signature\":\"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update\",\"positive_control\":\"protected main has direct push disabled and the previous real push was rejected\",\"prevention_rule\":\"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.\",\"regression_test_required\":true,\"space\":\"runtime\"},\"exact_error\":{\"code\":\"HTTP_READ_FAILED\",\"evidence\":{\"status\":404,\"url_sha256\":\"35cfa68b510e0f5b871072b99661ddf8f8726f808b5025114b925cd3b4c26cbe\"},\"message\":\"Read-only HTTP request failed\"},\"identity_confirmed\":false,\"mode\":\"READ_ONLY\",\"mutation_outcome\":\"NO_MUTATION\",\"next_step\":\"Prepare no mutation command until this read-only proof failure is resolved by exact evidence.\",\"output_truncated_in_json\":false,\"rc\":2,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":\"homelab.read-only-diagnostic.v2\",\"status\":\"ERROR\"}\n" }