CHAT_OUTPUT_BEGIN
COMMAND_ID=SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1
STATUS=OK
RC=0
HOST=pve01
MODE=read-only
COMPONENT=homelab-backup-git-push-route-rca
REFERENCE_REGISTER_CHECK=OK
REFERENCE_SHA256=5a3d8e5154c41cb582a4e0aca68090be1f0138918bf82131a948df326f9d8d66
ERROR_REGISTER_CHECK=OK
ERROR_REGISTER_SHA256=3b09a553ec0f527ed3afeed4753f52a74ee3036045bbfb3c685e9f8af4ba7ba0
COMMAND_SHA256=af88af9350b0bf23b8c37a94b0c520545170e33e839524b750f1d74c7761139a
DUPLICATE_FAILED_COMMAND_BLOCKED=false
EXECUTION_STARTED=true
CHANGE_DECLARED=false
RESULT_CONTRACT_VALID=true
RESULT_CONTRACT_STATUS=NOT_APPLICABLE
RESULT_CONTRACT_ERROR=NONE
COMMAND_RC=0
CHANGES_MADE=false
ROLLBACK_STARTED=false
ROLLBACK_RESTORED=null
MUTATION_OUTCOME=NO_MUTATION
SANITIZED=yes
SECRETS_INCLUDED=no
PRIVATE_ADDRESSES_INCLUDED=no
RAW_EVIDENCE_SHA256=bde5b53dae7c17e77083db11c8da3df556a47ee2b18b4127063fbf2b28ced1f8
SANITIZED_OUTPUT_SHA256=bde5b53dae7c17e77083db11c8da3df556a47ee2b18b4127063fbf2b28ced1f8
OUTPUT_BEGIN
WORKERS2_BACKUP_GIT_PUSH_ROUTE_RCA_BEGIN=1
COMMAND_ID=SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1
MODE=read-only
COMPONENT=homelab-backup-git-push-route-rca
HOST=pve01
UID=0
MUTATION_BOUNDARY=READ_ONLY_GIT_CONFIG_AND_NETWORK_DRY_RUN_ONLY_NO_FETCH_NO_CHECKOUT_NO_RESET_NO_COMMIT_NO_PUSH_UPDATE_NO_PRODUCTION_NO_SERVICE_ACTION_NO_BACKUP_NO_RESTORE_NO_RETENTION_NO_DELETE_NO_MAIL
WORKTREE_BRANCH=cr-2026-1005-backup-v2-health-alerting-remediation
WORKTREE_HEAD=46c6f9aaf8fa93ce9f0cee686f948704c1a61336
WORKTREE_HEAD_EXPECTED=true
WORKTREE_CLEAN=true
WORKTREE_STATUS_LINES=[]
LIVE_POLICY_META={"baseline_match":true,"exists":true,"expected_baseline":"ea6526bec7d7591bef876799cecddff4849631a936edc9f593b47211fbad715c","sha256":"ea6526bec7d7591bef876799cecddff4849631a936edc9f593b47211fbad715c"}
LIVE_HELPER_META={"baseline_match":true,"exists":true,"expected_baseline":"6b7ec1ab3ee1c540a9113b5620c3b4b5a50de6536f3a069d31b2e1243f23bafa","sha256":"6b7ec1ab3ee1c540a9113b5620c3b4b5a50de6536f3a069d31b2e1243f23bafa"}
ORIGIN_FETCH_URL_META={"fragment_present":false,"host":"git.gram1.ru","kind":"url","path":"/homelab-admin/homelab-ops.git","port":null,"present":true,"query_present":false,"safe_display":"https://git.gram1.ru/homelab-admin/homelab-ops.git","scheme":"https","sha256":"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9","userinfo_present":false}
ORIGIN_PUSH_URL_META={"kind":"sentinel","present":true,"sha256":"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12","value":"DISABLED"}
ORIGIN_FETCH_URL_SOURCE={"rc":0,"rows":[{"origin":"file:/srv/homelab-ops/.git/config","scope":"local","value_meta":{"fragment_present":false,"host":"git.gram1.ru","kind":"url","path":"/homelab-admin/homelab-ops.git","port":null,"present":true,"query_present":false,"safe_display":"https://git.gram1.ru/homelab-admin/homelab-ops.git","scheme":"https","sha256":"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9","userinfo_present":false}}],"stderr_sha256":null}
ORIGIN_PUSH_URL_SOURCE={"rc":0,"rows":[{"origin":"file:/srv/homelab-ops/.git/config","scope":"local","value_meta":{"kind":"sentinel","present":true,"sha256":"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12","value":"DISABLED"}}],"stderr_sha256":null}
MAIN_ORIGIN_FETCH_URL_META={"fragment_present":false,"host":"git.gram1.ru","kind":"url","path":"/homelab-admin/homelab-ops.git","port":null,"present":true,"query_present":false,"safe_display":"https://git.gram1.ru/homelab-admin/homelab-ops.git","scheme":"https","sha256":"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9","userinfo_present":false}
MAIN_ORIGIN_PUSH_URL_META={"kind":"sentinel","present":true,"sha256":"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12","value":"DISABLED"}
REMOTE_METADATA=[{"fetch":{"fragment_present":false,"host":"git.gram1.ru","kind":"url","path":"/homelab-admin/homelab-ops.git","port":null,"present":true,"query_present":false,"safe_display":"https://git.gram1.ru/homelab-admin/homelab-ops.git","scheme":"https","sha256":"7507b97d441d05c4e33306608cbf655e96bf2add0ec7683cc2f4e5539f64daf9","userinfo_present":false},"name":"origin","push":{"kind":"sentinel","present":true,"sha256":"0c7ef33e451eadb5c230e83d5155fe481df0dccf42529851a31110a88a776d12","value":"DISABLED"}}]
GIT_CONFIG_ENV_OVERLAY=[]
EXPLICIT_FETCH_URL_LS_REMOTE={"combined_sha256":"7b8ab49b5592ffea89971a6a8059abaf434142cd964f9d26c957c2d75e8f20e9","lines":["326622a4864fa9b5f43b69981733236bb42c4d7b\trefs/heads/main"],"rc":0}
EXPLICIT_MAIN_SHA=326622a4864fa9b5f43b69981733236bb42c4d7b
REMOTE_TARGET_BRANCH_SHA=null
REMOTE_TARGET_BRANCH_ABSENT=true
EXPLICIT_FETCH_URL_PUSH_DRY_RUN={"combined_sha256":"7a93936ba141ba96f5779a108732095ee5de42822d60f23391d4797743894652","lines":["To <GIT_URL_REDACTED>","*\tHEAD:refs/heads/cr-2026-1005-backup-v2-health-alerting-remediation\t[new branch]","Done"],"rc":0}
LOCAL_GIT_PUSH_HELPER_PATHS=[]
CANONICAL_PUSH_PATTERN_LINES=["HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:13:- CR `origin` fetch points to Gitea while `origin` push is deliberately `<GIT_URL_REDACTED>`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:17:1. Freshly verify source HEAD/clean state, reference SHA, read/write credentials, remote branch absence, Gitea fetch URL, and `origin` push URL `<GIT_URL_REDACTED>`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Control_Plane_Remediation_Resume_Plan_20260823.md:40:- source `origin` fetch still points to Gitea and push remains `<GIT_URL_REDACTED>`;","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:28:- Boundary: safe-run KB/auth/check-only succeeded. Phase B created local commit `710dc3036d9a2d3fcfba687559253f28b298bf8b` and failed only at `git push`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:34:## CMD-1403 \u2014 SOURCE_AUDIT_FIX / SYMBOLIC ORIGIN PUSH TARGET `<GIT_URL_REDACTED>`","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:36:- Symptom: `CR0086_RECEIPT|cmd_id=1403|status=ERROR|rc=1`; Phase B state recorded `GIT_PUSH_RC_128` with diagnostic `fatal: '<GIT_URL_REDACTED>' does not appear to be a git repository`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:38:- Root cause: v2 verified remote access with the explicit Gitea repository URL but executed `git push origin`. The CR worktree intentionally separates `origin` fetch and push destinations: fetch resolves to Gitea while push resolves to `<GIT_URL_REDACTED>`. The preflight never audited `git remote get-url --push origin`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:39:- Invalid assumption: a valid fetch URL, valid write token, and successful explicit `ls-remote` do not imply that symbolic remote `origin` uses the same URL for push. Git supports a separate `remote.<name>.pushurl`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Error_RCA_Ledger_20260823.md:42:- Prevention: `remote.origin.pushurl=<GIT_URL_REDACTED>` is now a required safety invariant. Source publication must never change or bypass that setting from the CR worktree. A temporary isolated publisher clone imports the local commit, publishes through the explicit Gitea URL with the separated write credential and an absent-ref `--force-with-lease`, verifies the exact remote SHA, and is destroyed. All network readback and compensation use the explicit repository URL rather than symbolic `origin`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:67:CMD-1400 proved that the default root Git credential must remain read-only. The v1 remediation correctly installed a `read:repository` credential for `git.gram1.ru`, allowing `homelab-safe-run` to perform its mandatory authenticated `ls-remote` and shallow clone. The same credential cannot be used for `git push`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:80:CMD-1403 proved that the CR worktree's Git remote has intentionally different fetch and push behavior. `origin` fetch resolves to `<GIT_URL_REDACTED>`, while `origin` push resolves to `<GIT_URL_REDACTED>`. This is a safety feature, not a broken remote.","HEAD:docs/operations/workers2/2026-08-23/Workers2_GramCrypto_Operational_Audit_20260823.md:88:- after publication, the remote ref must equal the exact local commit SHA and the source worktree must still report the original Gitea fetch URL plus push URL `<GIT_URL_REDACTED>`;","HEAD:docs/operations/workers2/2026-08-23/Workers2_Pre_Command_Contract_20260823.md:69:- `git remote get-url --push origin` \u2192 `<GIT_URL_REDACTED>`.","HEAD:docs/operations/workers2/2026-08-23/Workers2_Pre_Command_Contract_20260823.md:71:`<GIT_URL_REDACTED>` is an invariant to preserve, not a value to replace. A source publisher must use a disposable isolated repository and the explicit audited Gitea URL. No source command may infer push routing from the fetch URL, and no final readback may use symbolic `origin` for a network assertion.","HEAD:docs/superpowers/plans/2026-08-18-gitea-edge-publisher-v3.md:23:- No blind `git fetch`, `git pull`, `git push`, reset, checkout, or canonical dirty-tree cleanup."]
CANONICAL_PUSH_PATTERN_COUNT=15
RCA_DECISION=ORIGIN_PUSHURL_DISABLED_EXPLICIT_FETCH_URL_DRY_RUN_PUSH_CAPABLE
NO_MUTATION=true
NO_GIT_FETCH=true
NO_GIT_COMMIT=true
NO_GIT_PUSH_UPDATE=true
NETWORK_OPERATION=LS_REMOTE_PLUS_PUSH_DRY_RUN_ONLY
NO_PRODUCTION_MUTATION=true
NO_SERVICE_ACTION=true
NO_BACKUP_STARTED=true
NO_RESTORE_STARTED=true
NO_RETENTION_STARTED=true
NO_DELETE=true
NO_MAIL_SENT=true
RCA_DURATION_SEC=2.74
TASK_RESULT=PASS_HOMELAB_BACKUP_GIT_PUSH_ROUTE_RCA_READONLY
HOMELAB_RESULT_CONTRACT={"changes_made":false,"command_id":"SUPPORT-260921-HOMELAB-BACKUP-GIT-PUSH-ROUTE-RCA-READONLY-1024R1","rollback_restored":null,"rollback_started":false,"status":"OK","version":1}
WORKERS2_BACKUP_GIT_PUSH_ROUTE_RCA_END=1

OUTPUT_END
CHAT_OUTPUT_END
