gitea: the package team may read code, and its units are reconciled #72

Merged
jschoubben merged 1 commits from fix/gitea-package-team-reads-code into main 2026-09-25 19:59:26 +00:00
Owner

Found live, minutes after #71 unblocked the builder's user: its first credentialed clone of a private repository answered "Repository not found". The packages team's units_map named only repo.packages — and units_map is exhaustive, so members had no code unit at all; gitea hides what a user cannot read. One credential answering npm and git alike was the whole design of the builder's grant (mesh-controller#65); the team now says so with repo.code: read.

Second half: ensureTeam now patches a found team's units instead of just returning its id. A team is configuration the reconcile loop owns — the same philosophy as setting the user's password every run — so this fix reaches the team that already exists on this mesh, not only the next mesh raised from scratch.

Verification plan after merge: rebuild + roll out gitea, wait one reconcile, then re-run the queued novox.be/de-spiegel builds — the clone either succeeds or fails loudly with a real reason.

Found live, minutes after #71 unblocked the builder's user: its first credentialed clone of a private repository answered "Repository not found". The packages team's `units_map` named only `repo.packages` — and `units_map` is exhaustive, so members had **no code unit at all**; gitea hides what a user cannot read. One credential answering npm and git alike was the whole design of the builder's grant (mesh-controller#65); the team now says so with `repo.code: read`. Second half: `ensureTeam` now **patches a found team's units** instead of just returning its id. A team is configuration the reconcile loop owns — the same philosophy as setting the user's password every run — so this fix reaches the team that already exists on this mesh, not only the next mesh raised from scratch. Verification plan after merge: rebuild + roll out gitea, wait one reconcile, then re-run the queued novox.be/de-spiegel builds — the clone either succeeds or fails loudly with a real reason.
jschoubben added 1 commit 2026-09-25 19:59:19 +00:00
The builder's first credentialed clone of a private repository answered
'not found': the packages team named only repo.packages in its
units_map, which is exhaustive — so members had no code unit at all, and
gitea hides what a user cannot read. One credential answering npm and
git alike was the whole design of the builder's grant; the team now says
so.

And found teams are patched, not just returned: a team is configuration
the reconcile loop owns, the same as a user's password, so a unit this
code gains reaches the team that already exists rather than only the
next mesh raised from scratch.
jschoubben merged commit 3875987656 into main 2026-09-25 19:59:26 +00:00
jschoubben deleted branch fix/gitea-package-team-reads-code 2026-09-25 19:59:26 +00:00
Sign in to join this conversation.
No Reviewers
No labels
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: novox/mesh-catalog#72