test(registry): a declared repository nobody can publish to is a failure #63
Loading…
Reference in a new issue
No description provided.
Delete branch "sean/zot-publisher-writable-check"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
The ARM tools publish failed because build/node-tools-arm64 had no write policy: publish-item-node-tools-arm64 died in 1.8 s with 'POST /v2/build/node-tools-arm64/blobs/uploads/: DENIED'. The entry and the expected count are already fixed on trunk; this adds the check that catches the next one, plus the retention entry that was missed. The guard's hand-kept list of 30 names proves each listed name has a policy, but cannot prove the reverse -- a repository declared with the publisher left out of its policies passes every assertion, because its name is not in the list yet, and fails at publish time with the same DENIED. So this derives both facts from the rendered config: every declared repository except the deliberate catch-all must grant create or update to a non-admin identity, and the builder-images publisher must write exactly 30 build repositories. Two controls confirmed red. node-tools-arm64 also joins the ARM node chain in retention rather than falling to the catch-all; retention is still dryRun with gc false, so that changes nothing today. https://claude.ai/code/session_01KZoQin34jeyt6nDGqvJA76