{ "schema_version": 1, "channel": "homelab-runtime", "command_id": "HOMELAB-SKLADCHIK-COOKIE-EDGE-APPLY-391", "status": "FAIL", "rc": 1, "host": "pve01", "mode": "change", "component": "cluster-audit", "started_at_utc": "2026-07-23T20:03:03Z", "finished_at_utc": "2026-07-23T20:03:03Z", "reference_register_checked": true, "reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e", "error_register_checked": true, "error_register_sha256": "08b3a769b8e38eaa1acec915352fb328180d70caa7ff6cd9d1ec0da426262752", "command_sha256": "52ebc1e89e03dff252c4e9109ac86d619f4b80bde4db2df633ffedcf821d0a78", "duplicate_failed_command_blocked": false, "block_reason": null, "execution_started": true, "changes_made": true, "sanitized": true, "secrets_included": false, "private_addresses_included": false, "raw_evidence_retained_locally": true, "raw_evidence_sha256": "31278db600d4b4272ba419d9ea127e9261a79673b4843aea0ee96e331acfef8a", "sanitized_output_sha256": "433a43f5b12c61beb4202dd34e9b9812530eb190c2e2e9f45173a708bfd50577", "output_truncated_in_json": false, "full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt", "output": "DETAIL=PRIOR_COMMAND_390=FAILED_BEFORE_MUTATION|ROOT_CAUSE=UNQUOTED_REMOTE_STAT_PIPE_CHARACTERS|ROLLBACK=NOT_REQUIRED\nDETAIL=PENDING_COOKIE_CONTRACT=PASS|SHA256=3c260f0622999b94e1c3b45d5042532fe001b8118dff0d326636b2ad8609d8c4|BYTES=752|PAIRS=5|SECRET_OUTPUT=NONE\nprintf: warning: ignoring excess arguments, starting with ‘escaped’\nenvironment: line 59: escaped: unbound variable\ndebug1: OpenSSH_10.0p2 Debian-7+deb13u4, OpenSSL 3.5.6 7 Apr 2026\ndebug1: Reading configuration data [SENSITIVE_PATH]\ndebug1: Reading configuration data /etc/ssh/ssh_config\ndebug1: Reading configuration data /etc/ssh/ssh_config.d/20-systemd-ssh-proxy.conf\ndebug1: Reading configuration data /etc/ssh/ssh_config.d/99-netbird.conf\ndebug1: /etc/ssh/ssh_config line 21: Applying options for *\ndebug1: Connecting to [PRIVATE_IP] [[PRIVATE_IP]] port 22.\ndebug1: fd 3 clearing O_NONBLOCK\ndebug1: Connection established.\ndebug1: identity file [SENSITIVE_PATH] type 0\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type 3\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: identity file [SENSITIVE_PATH] type -1\ndebug1: Local version string SSH-2.0-OpenSSH_10.0p2 Debian-7+deb13u4\ndebug1: Remote protocol version 2.0, remote software version OpenSSH_10.0p2 Debian-7+deb13u4\ndebug1: compat_banner: match: OpenSSH_10.0p2 Debian-7+deb13u4 pat OpenSSH* compat 0x04000000\ndebug1: Authenticating to [PRIVATE_IP]:22 as 'debian'\ndebug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory\ndebug1: SSH2_MSG_KEXINIT sent\ndebug1: SSH2_MSG_KEXINIT received\ndebug1: kex: algorithm: mlkem768x25519-sha256\ndebug1: kex: host key algorithm: ssh-ed25519\ndebug1: kex: server->client cipher: aes128-ctr MAC: umac-64-etm@openssh.com compression: none\ndebug1: kex: client->server cipher: aes128-ctr MAC: umac-64-etm@openssh.com compression: none\ndebug1: expecting SSH2_MSG_KEX_ECDH_REPLY\ndebug1: SSH2_MSG_KEX_ECDH_REPLY received\ndebug1: Server host key: ssh-ed25519 SHA256:YQsA2nif7qAaa5mSUb9U0h8Q5DGy8SRCV5f+FyKUpOo\ndebug1: load_hostkeys: fopen /etc/ssh/ssh_known_hosts2: No such file or directory\ndebug1: Host '[PRIVATE_IP]' is known and matches the ED25519 host key.\ndebug1: Found key in [SENSITIVE_PATH]\ndebug1: ssh_packet_send2_wrapped: resetting send seqnr 3\ndebug1: rekey out after 4294967296 blocks\ndebug1: SSH2_MSG_NEWKEYS sent\ndebug1: Sending SSH2_MSG_EXT_INFO\ndebug1: expecting SSH2_MSG_NEWKEYS\ndebug1: ssh_packet_read_poll2: resetting read seqnr 3\ndebug1: SSH2_MSG_NEWKEYS received\ndebug1: rekey in after 4294967296 blocks\ndebug1: SSH2_MSG_EXT_INFO received\ndebug1: kex_ext_info_client_parse: server-sig-algs=\ndebug1: kex_ext_info_check_ver: publickey-hostbound@openssh.com=<0>\ndebug1: kex_ext_info_check_ver: ping@openssh.com=<0>\ndebug1: SSH2_MSG_SERVICE_ACCEPT received\ndebug1: SSH2_MSG_EXT_INFO received\ndebug1: kex_ext_info_client_parse: server-sig-algs=\ndebug1: Authentications that can continue: publickey\ndebug1: Next authentication method: publickey\ndebug1: Will attempt key: [SENSITIVE_PATH] RSA SHA256:bSyxARbKzSylpKwBNth7zTODkgTExZdhFwrYEH9zRO4\ndebug1: Will attempt key: [SENSITIVE_PATH] \ndebug1: Will attempt key: [SENSITIVE_PATH] \ndebug1: Will attempt key: [SENSITIVE_PATH] ED25519 SHA256:s0CusF0IHQGVJ02oi7ejWkGhH9NkhTWonn3441toe5M\ndebug1: Will attempt key: [SENSITIVE_PATH] \ndebug1: Will attempt key: [SENSITIVE_PATH] \ndebug1: Offering public key: [SENSITIVE_PATH] RSA SHA256:bSyxARbKzSylpKwBNth7zTODkgTExZdhFwrYEH9zRO4\ndebug1: Server accepts key: [SENSITIVE_PATH] RSA SHA256:bSyxARbKzSylpKwBNth7zTODkgTExZdhFwrYEH9zRO4\nAuthenticated to [PRIVATE_IP] ([[PRIVATE_IP]]:22) using \"publickey\".\ndebug1: channel 0: new session [client-session] (inactive timeout: 0)\ndebug1: Requesting no-more-sessions@openssh.com\ndebug1: Entering interactive session.\ndebug1: pledge: network\ndebug1: client_input_global_request: rtype hostkeys-00@openssh.com want_reply 0\ndebug1: Remote: /home/debian/.ssh/authorized_keys:2: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding\ndebug1: Remote: /home/debian/.ssh/authorized_keys:2: key options: agent-forwarding port-forwarding pty user-rc x11-forwarding\ndebug1: Sending environment.\ndebug1: channel 0: setting env LANG = \"en_US.UTF-8\"\ndebug1: pledge: fork\ndebug1: client_input_channel_req: channel 0 rtype exit-status reply 0\ndebug1: channel 0: free: client-session, nchannels 1\nTransferred: sent 5072, received 4912 bytes, in 0.3 seconds\nBytes per second: sent 19127.0, received 18523.6\ndebug1: Exit status 0\nFAILURE_REASON=SSH_REMOTE_QUOTE_PROBE_MISMATCH\nDETAIL=ROLLBACK_STATE=NOT_REQUIRED\nCHANGES_MADE=NO\n" }