Found live, minutes after #71 unblocked the builder's user: its first credentialed clone of a private repository answered "Repository not found". The packages team's units_map named only repo.packages — and units_map is exhaustive, so members had no code unit at all; gitea hides what a user cannot read. One credential answering npm and git alike was the whole design of the builder's grant (mesh-controller#65); the team now says so with repo.code: read.
Second half: ensureTeam now patches a found team's units instead of just returning its id. A team is configuration the reconcile loop owns — the same philosophy as setting the user's password every run — so this fix reaches the team that already exists on this mesh, not only the next mesh raised from scratch.
Verification plan after merge: rebuild + roll out gitea, wait one reconcile, then re-run the queued novox.be/de-spiegel builds — the clone either succeeds or fails loudly with a real reason.
Found live, minutes after #71 unblocked the builder's user: its first credentialed clone of a private repository answered "Repository not found". The packages team's `units_map` named only `repo.packages` — and `units_map` is exhaustive, so members had **no code unit at all**; gitea hides what a user cannot read. One credential answering npm and git alike was the whole design of the builder's grant (mesh-controller#65); the team now says so with `repo.code: read`.
Second half: `ensureTeam` now **patches a found team's units** instead of just returning its id. A team is configuration the reconcile loop owns — the same philosophy as setting the user's password every run — so this fix reaches the team that already exists on this mesh, not only the next mesh raised from scratch.
Verification plan after merge: rebuild + roll out gitea, wait one reconcile, then re-run the queued novox.be/de-spiegel builds — the clone either succeeds or fails loudly with a real reason.
The builder's first credentialed clone of a private repository answered
'not found': the packages team named only repo.packages in its
units_map, which is exhaustive — so members had no code unit at all, and
gitea hides what a user cannot read. One credential answering npm and
git alike was the whole design of the builder's grant; the team now says
so.
And found teams are patched, not just returned: a team is configuration
the reconcile loop owns, the same as a user's password, so a unit this
code gains reaches the team that already exists rather than only the
next mesh raised from scratch.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Found live, minutes after #71 unblocked the builder's user: its first credentialed clone of a private repository answered "Repository not found". The packages team's
units_mapnamed onlyrepo.packages— andunits_mapis exhaustive, so members had no code unit at all; gitea hides what a user cannot read. One credential answering npm and git alike was the whole design of the builder's grant (mesh-controller#65); the team now says so withrepo.code: read.Second half:
ensureTeamnow patches a found team's units instead of just returning its id. A team is configuration the reconcile loop owns — the same philosophy as setting the user's password every run — so this fix reaches the team that already exists on this mesh, not only the next mesh raised from scratch.Verification plan after merge: rebuild + roll out gitea, wait one reconcile, then re-run the queued novox.be/de-spiegel builds — the clone either succeeds or fails loudly with a real reason.