Closed
opened 2026-08-28 18:52:25 +02:00 by timothy
·
2 comments
No Branch/Tag Specified
main
renovate/meziantou.analyzer-3.x
release/v26.15.0-notes
fix/830-add-items-error-surface
renovate/lucene.net
renovate/cliwrap-3.x
issue-806-guard-populations
renovate/dotnet-monorepo
scratch/767b-poisoned
scratch/767b-control
release/v26.14.0-notes
release/v26.14.0
renovate/sqlitepclraw.bundle_e_sqlite3-3.x
docs/510-skill-logo-bug-policy
fix/510-watermark-resolution-policy
fix/629-verdict-classifier-falseopens
fix/609-decisions-edit-token-scope
issue-135-clear-to-none
release/v26.12.0-notes
fix/409b-lastscan-api-parity
fix/401-updatechannel-mirror-422
fix/327-playlist-rename-validation
fix/410-scancancel-log-level
fix/409-447-librariesscreen-neverscanned
fix/338-zap-exit-code
fix/367-plex-budget-message
fix/310-debom-legacy-cs
ci/604-lane-rebalance
feat/388-design-mirror
feat/247-test-ownership
feat/247-primary-action
feat/357-player-owned-playback
feat/357-jellyfin-plugin-poc
fix/289-mcp-hardening
issue58-mcp
feat/244-channels-extract
ci/auto-bump-prod-compose
feat/multi-rerun-collections-api
feat/collections-api
feat/quick-wins
feat/185-docs-part2
feat/140-collections-screen
feat/146-channel-edit
feat/147-classic-ui-link
issue22-renovate-dashboard
feat/91-cutover
feat/63-composite-create
feat/65-library-browse
feat/85-epg
feat/86-schedule-editor
feat/109-dashboard-data
feat/99-session-tracking
fix/dockerfile-node-tag
feat/59-spa-foundation
docs/59-ui-redesign-brief
feat/102-json-guide
feat/111-schedule-durations
feat/104-artwork-upload
feat/103-media-sources-api
feat/playouts-read-api
feat/108-health-api
feat/105-picker-list-endpoints
issue-97-channel-state-api
issue42-jellyfin-musicvideos
issue46-rest-api-error-contract
dependabot/nuget/ErsatzTV.FFmpeg.Tests/multi-d307a2e06f
qsv-improvements
hdr-vulkan-cuda-test
v26.15.0
v26.14.0
v26.13.0
v26.12.0
v26.11.0
v26.10.0
v26.9.0
v26.8.0
v26.7.0
blazor-final
v26.6.0
v26.5.0
v26.4.0
v26.3.1
v26.3.0
v26.2.0
v26.1.1
v26.1.0
v25.9.0
v25.8.0
v25.7.1
v25.7.0
v25.6.0
v25.5.0
v25.4.0
v25.3.1
v25.3.0
v25.2.0
v25.1.0
v0.8.8-beta
v0.8.7-beta
v0.8.6-beta
v0.8.5-beta
v0.8.4-beta
v0.8.3-beta
v0.8.2-beta
v0.8.1-beta
v0.8.0-beta
v0.7.9-beta
v0.7.8-beta
v0.7.7-beta
v0.7.6-beta
v0.7.5-beta
v0.7.4-beta
v0.7.3-beta
v0.7.2-beta
v0.7.1-beta
v0.7.0-beta
v0.6.9-beta
v0.6.8-beta
v0.6.7-beta
v0.6.6-beta
v0.6.5-beta
v0.6.4-beta
v0.6.3-beta
v0.6.2-beta
v0.6.1-beta
v0.6.0-beta
v0.5.8-beta
v0.5.7-beta
v0.5.6-beta
v0.5.5-beta
v0.5.4-beta
v0.5.3-beta
v0.5.2-beta
v0.5.1-beta
v0.5.0-beta
v0.4.5-alpha
v0.4.4-alpha
v0.4.3-alpha
v0.4.2-alpha
v0.4.1-alpha
v0.4.0-alpha
v0.3.8-alpha
v0.3.7-alpha
develop
v0.3.6-alpha
v0.3.5-alpha
v0.3.4-alpha
v0.3.3-alpha
v0.3.2-alpha
v0.3.1-alpha
v0.3.0-alpha
v0.2.5-alpha
v0.2.4-alpha
v0.2.3-alpha
v0.2.2-alpha
v0.2.1-alpha
v0.2.0-alpha
v0.1.5-alpha
v0.1.4-alpha
v0.1.3-alpha
v0.1.2-alpha
v0.1.1-alpha
v0.1.0-alpha
v0.0.62-alpha
v0.0.61-alpha
v0.0.60-alpha
v0.0.59-alpha
v0.0.58-alpha
v0.0.57-alpha
v0.0.56-alpha
v0.0.55-alpha
v0.0.54-alpha
v0.0.53-alpha
v0.0.52-alpha
v0.0.51-alpha
v0.0.50-alpha
v0.0.49-prealpha
v0.0.48-prealpha
v0.0.47-prealpha
v0.0.46-prealpha
v0.0.45-prealpha
v0.0.44-prealpha
v0.0.43-prealpha
v0.0.42-prealpha
v0.0.41-prealpha
v0.0.40-prealpha
v0.0.39-prealpha
v0.0.38-prealpha
v0.0.37-prealpha
v0.0.36-prealpha
v0.0.35-prealpha
v0.0.34-prealpha
v0.0.33-prealpha
v0.0.32-prealpha
v0.0.31-prealpha
v0.0.30-prealpha
v0.0.29-prealpha
v0.0.28-prealpha
v0.0.27-prealpha
v0.0.26-prealpha
v0.0.25-prealpha
v0.0.24-prealpha
v0.0.23-prealpha
v0.0.22-prealpha
v0.0.21-prealpha
v0.0.20-prealpha
v0.0.19-prealpha
v0.0.18-prealpha
v0.0.17-prealpha
v0.0.16-prealpha
v0.0.15-prealpha
v0.0.14-prealpha
v0.0.13-prealpha
v0.0.12-prealpha
v0.0.11-prealpha
v0.0.10-prealpha
v0.0.9-prealpha
v0.0.8-prealpha
v0.0.7-prealpha
v0.0.6-prealpha
v0.0.5-prealpha
v0.0.4-prealpha
v0.0.3-prealpha
v0.0.2-prealpha
v0.0.1-prealpha
Labels
Clear labels
ad-hoc
api
bug
ci-cd
content
dependencies
enhancement
frontend
in-progress
jellyfin
parked
priority: high
priority: low
priority: medium
review
security
One-off / ad-hoc work not tracked by a dedicated issue
REST API / HTTP endpoints
Something isn't working
Build, test, deploy pipeline
Channel content / schedules / playlists
Dependency updates (Renovate)
New feature or improvement
ChicoryTV React SPA frontend
Claimed by an active session — do not pick up
Jellyfin tuner / IPTV integration
Excluded from automatic queue pickup; work only when explicitly selected
Adversarial review finding
Security / vulnerability fix
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: timothy/ersatztv#869
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Residue from #747 (PR #867), named there rather than implied closed. #747 re-probed the
merge-gating claims it prioritised; it was not a sweep of the corpus, and
ci.actions-credential-scopingnow says so explicitly rather than implying coverage.What is still 1.25.4-dated
1.
review-verdict.yml's three comments (lines ~69, ~633, ~746). Deliberately untouched by #747:#763 was in-progress on that file and its
/statuses/{sha}paging work overlaps those lines, soediting them would have conflicted. Line ~746 is the load-bearing one — it records the COMBINED-endpoint
behaviour for a status POSTed with a user token, which is the
creatorattribution the H10 allow-listrests on (#742, #845). A second copy lives at
scripts/tests/test_pr_changed_files.py:1679.2.
ci.actions-credential-scoping's own three items. Thev1.25.4scope enum(
access_token_scope.go) and thereqRepoWritergate (routers/api/v1/api.go) were established byREADING GITEA SOURCE at the version tag — re-running them needs only a source read at
v1.27.1, not acredential. Only the
write:package403 needs a scoped PAT minted against the live instance. #747 didnone of the three.
3.
--depth=1has no merge base (ci.exemption-provenance,scripts/pr-changed-files.sh). #747split the sentence so the 1.27.1 re-confirmation binds to the
comparecall only; this clause isstill 1.25.4-dated.
4. Claims deliberately left dated because the cheap probe route is gone, not because nobody looked
— re-state the reason rather than re-deriving it: push-supersession auto-cancel and the
pull_request_targetoverlap/serialization probes. No workflow triggers on a push to a non-mainbranch and
mainrefuses direct pushes, so the disposable scratch-branch route those measurementsused no longer exists. Both are recorded in
ci.verdict-write-retarget-fence.Method that worked in #747, worth reusing
A branch-protection or merge-path question is probeable without touching
main: a scratch BASEbranch carries its own protection rule, so the whole experiment is disposable. That is what let #747
measure
block_admin_merge_overrideafter #743 had recorded it as source-attested-only on the groundsthat probing it meant merging an unreviewed PR. Derive the population with
git ls-files, not from alist of keys in an issue body.
Done-when
reason that is true today — all three re-established on 1.27.1 (PR #905)
creator-attribution claim inreview-verdict.ymlspecifically settled, since the H10allow-list depends on it — re-measured over 4 merged heads on both endpoints; the stated
MECHANISM was also found wrong in review and corrected (it is
CreatorID == -2, not== 0)and one such reason turned out to be INVENTED (MCP
cancel_run); it now states the true onefinal verdict CLEAN
Claiming — Claude Code session (Opus 5), bundled with #893.
Both issues are the same mechanism: a claim dated against an old Gitea version that needs re-establishing by reading the v1.27.1 source, then recorded as dated. Verified reachable at the exact tag (
raw.githubusercontent.com/go-gitea/gitea/v1.27.1/...→ 200) and this instance reports{"version":"1.27.1"}, so the source read and the live instance agree on the version being claimed.Population will be derived with
git ls-files, not from this issue's item list.Closing record
Outcome: Finished the sweep #747 left incomplete. PR #905. Population derived with
git ls-files— 17 files, 43 occurrences of1.25.4, against the 4 items this issue's body named, which is exactly the trap the body itself warned about.Re-established on 1.27.1: the
creator-attribution claim the H10 allow-list rests on (4 merged PR heads, both endpoints); the scope enum (nostatusscope; 9 categories, 0 occurrences); thereqRepoWriter(unit.TypeCode)gate onPOST /statuses/{sha}; thewrite:package403 (live probe, read control 200 + write control 201, throwaway repo, artifacts deleted and deletion confirmed); the absence of any REST cancel route (source, which a 404 alone cannot establish); andpull_request/pull_request_targetdefinition resolution.Two claims were corrected, not merely re-dated:
--depth=1has no merge base was filed against the wrong axis. It is a git property — a Gitea upgrade cannot change it, a git upgrade can. Re-probed on git 2.55.0.enable_bypass_allowlistpostdating 1.25.4 had an issue body as its only provenance. Checked in both trees: it holds. Its neighbourblock_admin_merge_overridedoes not share that history (present at 1.25.4 in all three structs), now stated so the paragraph cannot invite the inference.Root cause: #747 prioritised the merge-gating claims and said so rather than implying coverage; the remainder simply had no owner. Underneath that, the durable cause is that a version stamp records when something was measured but not what could invalidate it — which is how the
--depth=1claim ended up carrying a Gitea version it was never sensitive to.Decisions/conventions changed: no new keys. Updated in place:
ci.actions-credential-scoping(all three items re-established),ci.batch-pushes-no-cancel-route(source-confirmed REST absence; retitled),ci.exemption-provenance(git-axis correction),ci.gate-trigger-base-resolved(definition-resolution half from source),ci.verdict-write-retarget-fence,release.main-direct-push-disabled.Reusable knowledge:
git greppointer — each went wrong inside the commit that wrote them: the list omitted three residuals that commit created, and the pointer missed a second spelling that commit introduced. Deleted both; each residual states its reason where it lives.cancel_run("no disposable run to spend") was false — 4 of 6 workflows carryworkflow_dispatch:, and the record itself saiddispatch_workflowworks. The real reason was that the agent harness refused the call, and that is now what the record says.Verification:
scripts/tests1565 passed / 3 skipped;decisions_validate.pyOK; catalog regenerated (unchanged — norule:moved); ruff lint+format clean;bash -nand YAML parse clean. Every changed line inscripts/and.gitea/is a comment — zero executable change, verified mechanically. Four cold review rounds (worktree-isolated) plus a cross-family Codex pass; each of the first three found real defects, all fixed.Deferred: MCP
cancel_runand the web-UI/CSRF cancel findings stay 1.25.4-dated, each with its own stated reason. Thepush-supersession andpull_request_targetfence measurements likewise. Nothing new filed — these are decisions, not gaps.Docs updated:
docs/ci-cd.md,docs/decisions/records/ci/{actions-credential-scoping,batch-pushes-no-cancel-route,exemption-provenance,gate-trigger-base-resolved,verdict-write-retarget-fence}.md,docs/decisions/records/release/main-direct-push-disabled.md,docs/decisions/workflow-process.md, regenerateddocs/decisions/README.md.