39 lines
10 KiB
JSON
39 lines
10 KiB
JSON
{
|
|
"schema_version": 1,
|
|
"channel": "homelab-runtime",
|
|
"command_id": "HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z",
|
|
"status": "OK",
|
|
"rc": 0,
|
|
"host": "pve01",
|
|
"mode": "verify",
|
|
"component": "cluster-knowledge-base-error-system",
|
|
"started_at_utc": "2026-08-06T01:22:58Z",
|
|
"finished_at_utc": "2026-08-06T01:23:09Z",
|
|
"reference_register_checked": true,
|
|
"reference_sha256": "5763f2f8edc75fcf6f3951f8c95896d1cc112ceccb6cf5b64a383f540a4deb8e",
|
|
"error_register_checked": true,
|
|
"error_register_sha256": "24934a2c7fa5c26f6e828583c4aefac7f143b40c0171736ed7571e617d55ab83",
|
|
"command_sha256": "d76aad5f8c9f6a022038639803f0209544f1fe74b91258185a6ce576d49d803b",
|
|
"duplicate_failed_command_blocked": false,
|
|
"block_reason": null,
|
|
"execution_started": true,
|
|
"change_declared": false,
|
|
"result_contract_valid": true,
|
|
"result_contract_status": null,
|
|
"result_contract_error": null,
|
|
"command_rc": 0,
|
|
"changes_made": false,
|
|
"rollback_started": false,
|
|
"rollback_restored": null,
|
|
"mutation_outcome": "NO_MUTATION",
|
|
"sanitized": true,
|
|
"secrets_included": false,
|
|
"private_addresses_included": false,
|
|
"raw_evidence_retained_locally": true,
|
|
"raw_evidence_sha256": "b17c9d74cb7409c9a0dcdaf522d4b7aaacc067096dbf2972b99e8a4a159e82bc",
|
|
"sanitized_output_sha256": "b17c9d74cb7409c9a0dcdaf522d4b7aaacc067096dbf2972b99e8a4a159e82bc",
|
|
"output_truncated_in_json": false,
|
|
"full_sanitized_output_url": "https://git.gram1.ru/.well-known/homelab-runtime/latest.txt",
|
|
"output": "HOMELAB_RESULT_CONTRACT={\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z\",\"command_rc\":0,\"control_plane_error\":null,\"mutation_outcome\":\"NO_MUTATION\",\"output_truncated_in_json\":false,\"rc\":0,\"rollback_restored\":null,\"rollback_started\":false,\"status\":\"OK\",\"version\":1}\n{\"changes_made\":false,\"command_id\":\"HOMELAB-GITEA-ALLOWED-PUSH-PATH-DIAGNOSTIC-READ-ONLY-R10-20260806T012000Z\",\"command_rc\":0,\"control_plane_error\":null,\"diagnosis\":{\"allowed_path_diagnostics\":{\"actions_workflow_count\":1,\"admin_branch_protection_change_capability\":true,\"admin_branch_protection_change_selected\":false,\"candidate_branch\":\"homelab/cluster-kb-error-system-v2\",\"candidate_branch_exists\":false,\"documented_automation_write_path\":false,\"main_user_can_merge\":true,\"main_user_can_push\":false,\"matching_protection_rules\":[],\"merge_styles\":{\"fast_forward_only\":false,\"merge\":true,\"rebase\":true,\"rebase_explicit\":true,\"squash\":true},\"other_write_capable_collaborators\":[],\"owner_admin_direct_push_bypass_proven\":false,\"pull_request_api_readable\":true,\"pull_requests_enabled\":true,\"read_write_deploy_key_count\":0,\"service_account_or_deploy_key_path_selected\":false,\"team_write_evidence_available\":false,\"teams_endpoint_status\":405,\"teams_endpoint_supported\":false,\"temp_branch_push_dry_run\":{\"allowed\":true,\"note\":\"corroborative only; dry-run is not proof of acceptance of a real server-side update\",\"rc\":0,\"stderr_sha256\":\"d8a74ae6048f6ad139a285d6449b83b4911a0feea23b3bd51b1aa2e495872178\",\"stdout_sha256\":\"e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855\"},\"workflow_or_bot_path_selected\":false,\"workflow_write_evidence\":[],\"write_capable_deploy_key_available_to_current_transaction\":false,\"write_capable_teams\":[]},\"branch\":\"main\",\"identity\":{\"active\":true,\"api_auth_mode\":\"basic\",\"api_identity_verified\":true,\"candidate_count\":1,\"credential_source\":\"git-credentials-file\",\"credential_values_exposed\":false,\"git_ls_remote_verified\":true,\"permission\":\"owner\",\"repository_permissions\":{\"admin\":true,\"pull\":true,\"push\":true},\"repository_pull_permission_verified\":true,\"repository_push_permission_verified\":true,\"restricted\":false,\"selected_alias_source_count\":1,\"source_detail_sha256\":null,\"source_path_sha256\":\"8243365621e06dc272481f7e8bddbc15f93de999624148dbf66b71a0c7dee5cb\",\"username_sha256\":\"17be8cd40a805524484650e38ba17226d72606f6868226bfc7ddadcd407344a7\",\"valid_credential_set_count\":1},\"main_protection\":{\"current_user_in_push_whitelist\":false,\"current_user_merge_allowed\":true,\"effective_branch_protection_name_present\":true,\"enable_merge_whitelist\":true,\"enable_push\":false,\"enable_push_whitelist\":false,\"enable_status_check\":false,\"merge_allow_basis\":\"current_user_in_merge_whitelist\",\"merge_whitelist_team_count\":0,\"protected\":true,\"protected_file_patterns_present\":false,\"push_whitelist_team_count\":0,\"require_signed_commits\":false,\"required_approvals\":0,\"user_can_merge\":true,\"user_can_push\":false},\"read_only_clone_clean\":true,\"read_only_clone_head\":\"fe1221b06643db3b00a621b0230f92a46a4edc2b\",\"remote_main\":\"fe1221b06643db3b00a621b0230f92a46a4edc2b\",\"remote_unchanged_since_previous_rejection\":true,\"repository\":\"homelab-admin/homelab-ops\",\"repository_policy_evidence\":{\"conflicting_direct_main_policy_found\":false,\"explicit_pr_policy_found\":false,\"files_with_policy_evidence\":[{\"matched_categories\":{\"branch\":[17],\"workflow\":[12]},\"path\":\"README.md\",\"sha256\":\"d9cb129e009176a7dde2a07f59760acddd9e17237eef563e97a55b3e62838bd1\"},{\"matched_categories\":{\"branch\":[8]},\"path\":\"docs/ARCHITECTURE.md\",\"sha256\":\"5e7236f3b8072ff6115ab5bc50ad448425882e86463e90d85df1a1c8eb502d65\"},{\"matched_categories\":{\"workflow\":[1]},\"path\":\"docs/WORKFLOW.md\",\"sha256\":\"87a6f9a0960ee7240261138ecea122fd8fbd727d87bb0b27b02c103c3bc2f122\"},{\"matched_categories\":{\"workflow\":[14]},\"path\":\"docs/planned/skladchik-moderator-assistant.md\",\"sha256\":\"e74454f528cdb5522e2c43d959472a04b7cc36e33da7aa5a5bd664fc79015344\"}],\"workflows\":[{\"has_pull_request_trigger\":true,\"has_push_trigger\":true,\"mentions_write_permission\":false,\"path\":\".gitea/workflows/ci.yml\",\"sha256\":\"b078ac1b57e0846a90fd6acb1f3cb0866dbed0fb3bbde0d7070d29a344907681\"}]},\"single_proven_safe_path\":{\"classification\":\"TEMP_BRANCH_PULL_REQUEST_SERVER_MERGE_TO_PROTECTED_MAIN\",\"next_atomic_transaction\":\"Re-read exact main and the ten pinned paths; build and fully test the candidate in a temporary directory; push exactly one candidate commit to the unused dedicated temporary branch; create one pull request to main; merge it using one currently enabled server merge mechanism; verify main and all ten path hashes; delete the temporary branch only after success; on any failure close the PR if created and delete the temporary branch, leaving main unchanged. Do not modify branch protection.\",\"proof\":{\"candidate_branch_absent\":true,\"candidate_branch_authorized_by_repository_permission\":true,\"candidate_branch_dry_run_corroboration_only\":true,\"candidate_branch_has_no_matching_protection_rule\":true,\"candidate_branch_unprotected\":true,\"current_identity_allowed_to_merge\":true,\"dry_run_not_used_as_write_proof\":true,\"main_branch_api_user_can_merge\":true,\"no_conflicting_repository_policy_detected\":true,\"pull_request_api_available\":true,\"pull_requests_enabled\":true,\"repository_push_permission\":true,\"required_approvals_zero_or_unset\":true,\"server_merge_mechanism_enabled\":true,\"signed_commits_not_required_or_unset\":true,\"status_checks_disabled_or_unset\":true},\"proven\":true,\"proven_path_count\":1,\"proven_paths\":[\"TEMP_BRANCH_PULL_REQUEST_SERVER_MERGE_TO_PROTECTED_MAIN\"],\"scope_paths\":[\".gitea/workflows/ci.yml\",\"docs/CLUSTER-HANDBOOK.md\",\"docs/ERROR-SYSTEM-V2.md\",\"docs/WORKFLOW.md\",\"errors/error-registry.jsonl\",\"errors/superseded-commands.json\",\"inventory/cluster-reference.json\",\"schemas/error-record.schema.json\",\"tests/test_error_system_v2.py\",\"tools/pre_command_gate.py\"]}},\"error_system_v2_future_record\":{\"classification\":\"GITEA_BRANCH_PROTECTION_REJECTS_DIRECT_PUSHER\",\"fingerprint\":\"40795f946c36fcaaf8413b2b46b1900a5df4771d93aeb24f2a596287df0a8023\",\"id\":\"GITEA_PROTECTED_MAIN_DIRECT_PUSH_DRY_RUN_FALSE_POSITIVE\",\"negative_control\":\"dry-run may return rc=0 without exercising the server-side protected-branch mutation decision\",\"normalized_signature\":\"gitea protected main rejects direct push while git push --dry-run succeeds; dry-run does not prove that the server-side protected-branch pre-receive path will accept a real update\",\"positive_control\":\"protected main has direct push disabled and the previous real push was rejected\",\"prevention_rule\":\"A successful git push --dry-run must never be treated as proof that a real update to a protected branch is allowed; the configured branch-protection write path must be proven separately by read-only evidence.\",\"regression_test_required\":true,\"space\":\"runtime\"},\"exact_error\":null,\"identity_confirmed\":true,\"mode\":\"READ_ONLY\",\"mutation_outcome\":\"NO_MUTATION\",\"next_step\":\"Re-read exact main and the ten pinned paths; build and fully test the candidate in a temporary directory; push exactly one candidate commit to the unused dedicated temporary branch; create one pull request to main; merge it using one currently enabled server merge mechanism; verify main and all ten path hashes; delete the temporary branch only after success; on any failure close the PR if created and delete the temporary branch, leaving main unchanged. Do not modify branch protection.\",\"output_truncated_in_json\":false,\"previous_exact_result\":{\"capsule_sha256\":\"b91fe4c5e9c8d9c2c13ae442814541f4a14ed41f304334227fbd5b31c4a55fd5\",\"command_id\":\"HOMELAB-GITEA-R9-API-405-ENDPOINT-DIAGNOSTIC-READ-ONLY-20260806T011500Z\",\"identity_confirmed\":true,\"output_complete\":true,\"output_sha256\":\"61a298a66b6e307dd84363f18a534d5990c7e858b49854e7cac54c202250350c\",\"published_resources_checked\":3,\"runner_document_rc\":0,\"runner_json_sha256\":\"4b6bd045af359f55b2a467991e2c9bfda7db07aaa455a9592c4fd80fa196175a\",\"runner_rc\":0,\"runner_text_sha256\":\"28bb5c4409cf5a0e520e08434487724b267ea2f10c38bb41b81015aee52fb122\",\"runner_wrapper_matches_document\":true,\"semantic_fields_verified\":[\"exact_envelope\",\"result_contract\",\"runner_document\",\"output_contract\",\"report_contract\",\"diagnosis.teams_http_405\",\"diagnosis.authorized_channel\",\"diagnosis.remote_main\",\"diagnosis.endpoint_statuses\"],\"slot_directory_count\":12,\"slot_lane\":\"d\"},\"rc\":0,\"rollback_restored\":null,\"rollback_started\":false,\"schema\":\"homelab.read-only-diagnostic.v7\",\"status\":\"OK\"}\n"
|
|
}
|