35 lines
9.3 KiB
Plaintext
35 lines
9.3 KiB
Plaintext
CHAT_OUTPUT_BEGIN
|
|
COMMAND_ID=HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z
|
|
STATUS=OK
|
|
RC=0
|
|
HOST=pve01
|
|
MODE=verify
|
|
COMPONENT=cluster-knowledge-base-error-system
|
|
REFERENCE_REGISTER_CHECK=OK
|
|
REFERENCE_SHA256=5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e
|
|
ERROR_REGISTER_CHECK=OK
|
|
ERROR_REGISTER_SHA256=24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83
|
|
COMMAND_SHA256=d76aad5f8c9f6a022038639803f0209544f1fe74b91258185a6ce576d49d803b
|
|
DUPLICATE_FAILED_COMMAND_BLOCKED=false
|
|
EXECUTION_STARTED=true
|
|
CHANGE_DECLARED=false
|
|
RESULT_CONTRACT_VALID=true
|
|
RESULT_CONTRACT_STATUS=NOT_APPLICABLE
|
|
RESULT_CONTRACT_ERROR=NONE
|
|
COMMAND_RC=0
|
|
CHANGES_MADE=false
|
|
ROLLBACK_STARTED=false
|
|
ROLLBACK_RESTORED=null
|
|
MUTATION_OUTCOME=NO_MUTATION
|
|
SANITIZED=yes
|
|
SECRETS_INCLUDED=no
|
|
PRIVATE_ADDRESSES_INCLUDED=no
|
|
RAW_EVIDENCE_SHA256=b17c9d74cb7409c9a0dcdaf522d4b7aaacc067096dbf2972b99e8a4a159e82bc
|
|
SANITIZED_OUTPUT_SHA256=b17c9d74cb7409c9a0dcdaf522d4b7aaacc067096dbf2972b99e8a4a159e82bc
|
|
OUTPUT_BEGIN
|
|
HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z","command_rc":0,"control_plane_error":null,"mutation_outcome":"NO_MUTATION","output_truncated_in_json":false,"rc":0,"rollback_restored":null,"rollback_started":false,"status":"OK","version":1}
|
|
{"changes_made":false,"command_id":"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z","command_rc":0,"control_plane_error":null,"diagnosis":{"allowed_path_diagnostics":{"actions_workflow_count":1,"admin_branch_protection_change_capability":true,"admin_branch_protection_change_selected":false,"candidate_branch":"homelab/cluster-kb-error-system-v2","candidate_branch_exists":false,"documented_automation_write_path":false,"main_user_can_merge":true,"main_user_can_push":false,"matching_protection_rules":[],"merge_styles":{"fast_forward_only":false,"merge":true,"rebase":true,"rebase_explicit":true,"squash":true},"other_write_capable_collaborators":[],"owner_admin_direct_push_bypass_proven":false,"pull_request_api_readable":true,"pull_requests_enabled":true,"read_write_deploy_key_count":0,"service_account_or_deploy_key_path_selected":false,"team_write_evidence_available":false,"teams_endpoint_status":405,"teams_endpoint_supported":false,"temp_branch_push_dry_run":{"allowed":true,"note":"corroborative only; dry-run is not proof of acceptance of a real server-side update","rc":0,"stderr_sha256":"d8a74ae6048f6ad139a285d6449b83b4911a0feea23b3bd51b1aa2e495872178","stdout_sha256":"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855"},"workflow_or_bot_path_selected":false,"workflow_write_evidence":[],"write_capable_deploy_key_available_to_current_transaction":false,"write_capable_teams":[]},"branch":"main","identity":{"active":true,"api_auth_mode":"basic","api_identity_verified":true,"candidate_count":1,"credential_source":"git-credentials-file","credential_values_exposed":false,"git_ls_remote_verified":true,"permission":"owner","repository_permissions":{"admin":true,"pull":true,"push":true},"repository_pull_permission_verified":true,"repository_push_permission_verified":true,"restricted":false,"selected_alias_source_count":1,"source_detail_sha256":null,"source_path_sha256":"8243365621e06dc272481f7e8bddbc15f93de999624148dbf66b71a0c7dee5cb","username_sha256":"17be8cd40a805524484650e38ba17226d72606f6868226bfc7ddadcd407344a7","valid_credential_set_count":1},"main_protection":{"current_user_in_push_whitelist":false,"current_user_merge_allowed":true,"effective_branch_protection_name_present":true,"enable_merge_whitelist":true,"enable_push":false,"enable_push_whitelist":false,"enable_status_check":false,"merge_allow_basis":"current_user_in_merge_whitelist","merge_whitelist_team_count":0,"protected":true,"protected_file_patterns_present":false,"push_whitelist_team_count":0,"require_signed_commits":false,"required_approvals":0,"user_can_merge":true,"user_can_push":false},"read_only_clone_clean":true,"read_only_clone_head":"fe1221b06643db3b00a621b0230f92a46a4edc2b","remote_main":"fe1221b06643db3b00a621b0230f92a46a4edc2b","remote_unchanged_since_previous_rejection":true,"repository":"homelab-admin/homelab-ops","repository_policy_evidence":{"conflicting_direct_main_policy_found":false,"explicit_pr_policy_found":false,"files_with_policy_evidence":[{"matched_categories":{"branch":[17],"workflow":[12]},"path":"README.md","sha256":"d9cb129e009176a7dde2a07f59760acddd9e17237eef563e97a55b3e62838bd1"},{"matched_categories":{"branch":[8]},"path":"docs/ARCHITECTURE.md","sha256":"5e7236f3b8072ff6115ab5bc50ad448425882e86463e90d85df1a1c8eb502d65"},{"matched_categories":{"workflow":[1]},"path":"docs/WORKFLOW.md","sha256":"87a6f9a0960ee7240261138ecea122fd8fbd727d87bb0b27b02c103c3bc2f122"},{"matched_categories":{"workflow":[14]},"path":"docs/planned/skladchik-moderator-assistant.md","sha256":"e74454f528cdb5522e2c43d959472a04b7cc36e33da7aa5a5bd664fc79015344"}],"workflows":[{"has_pull_request_trigger":true,"has_push_trigger":true,"mentions_write_permission":false,"path":".gitea/workflows/ci.yml","sha256":"b078ac1b57e0846a90fd6acb1f3cb0866dbed0fb3bbde0d7070d29a344907681"}]},"single_proven_safe_path":{"classification":"TEMP_BRANCH_PULL_REQUEST_SERVER_MERGE_TO_PROTECTED_MAIN","next_atomic_transaction":"Re-read exact main and the ten pinned paths; build and fully test the candidate in a temporary directory; push exactly one candidate commit to the unused dedicated temporary branch; create one pull request to main; merge it using one currently enabled server merge mechanism; verify main and all ten path hashes; delete the temporary branch only after success; on any failure close the PR if created and delete the temporary branch, leaving main unchanged. Do not modify branch protection.","proof":{"candidate_branch_absent":true,"candidate_branch_authorized_by_repository_permission":true,"candidate_branch_dry_run_corroboration_only":true,"candidate_branch_has_no_matching_protection_rule":true,"candidate_branch_unprotected":true,"current_identity_allowed_to_merge":true,"dry_run_not_used_as_write_proof":true,"main_branch_api_user_can_merge":true,"no_conflicting_repository_policy_detected":true,"pull_request_api_available":true,"pull_requests_enabled":true,"repository_push_permission":true,"required_approvals_zero_or_unset":true,"server_merge_mechanism_enabled":true,"signed_commits_not_required_or_unset":true,"status_checks_disabled_or_unset":true},"proven":true,"proven_path_count":1,"proven_paths":["TEMP_BRANCH_PULL_REQUEST_SERVER_MERGE_TO_PROTECTED_MAIN"],"scope_paths":[".gitea/workflows/ci.yml","docs/CLUSTER-HANDBOOK.md","docs/ERROR-SYSTEM-V2.md","docs/WORKFLOW.md","errors/error-registry.jsonl","errors/superseded-commands.json","inventory/cluster-reference.json","schemas/error-record.schema.json","tests/test_error_system_v2.py","tools/pre_command_gate.py"]}},"error_system_v2_future_record":{"classification":"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER","fingerprint":"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023","id":"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE","negative_control":"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision","normalized_signature":"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update","positive_control":"protected main has direct push disabled and the previous real push was rejected","prevention_rule":"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.","regression_test_required":true,"space":"runtime"},"exact_error":null,"identity_confirmed":true,"mode":"READ_ONLY","mutation_outcome":"NO_MUTATION","next_step":"Re-read exact main and the ten pinned paths; build and fully test the candidate in a temporary directory; push exactly one candidate commit to the unused dedicated temporary branch; create one pull request to main; merge it using one currently enabled server merge mechanism; verify main and all ten path hashes; delete the temporary branch only after success; on any failure close the PR if created and delete the temporary branch, leaving main unchanged. Do not modify branch protection.","output_truncated_in_json":false,"previous_exact_result":{"capsule_sha256":"b91fe4c5e9c8d9c2c13ae442814541f4a14ed41f304334227fbd5b31c4a55fd5","command_id":"HOMELAB-GITEA-R9-API-405-ENDPOINT-DIAGNOSTIC-READ-ONLY-20260806T011500Z","identity_confirmed":true,"output_complete":true,"output_sha256":"61a298a66b6e307dd84363f18a534d5990c7e858b49854e7cac54c202250350c","published_resources_checked":3,"runner_document_rc":0,"runner_json_sha256":"4b6bd045af359f55b2a467991e2c9bfda7db07aaa455a9592c4fd80fa196175a","runner_rc":0,"runner_text_sha256":"28bb5c4409cf5a0e520e08434487724b267ea2f10c38bb41b81015aee52fb122","runner_wrapper_matches_document":true,"semantic_fields_verified":["exact_envelope","result_contract","runner_document","output_contract","report_contract","diagnosis.teams_http_405","diagnosis.authorized_channel","diagnosis.remote_main","diagnosis.endpoint_statuses"],"slot_directory_count":12,"slot_lane":"d"},"rc":0,"rollback_restored":null,"rollback_started":false,"schema":"homelab.read-only-diagnostic.v7","status":"OK"}
|
|
|
|
OUTPUT_END
|
|
CHAT_OUTPUT_END
|