A manual pipeline creation instantiates every file in .crow/, and a declared
variable default is applied even when the run never passed that variable. So a
gate like target_arch, defaulting to amd64, matched its own amd64 matrix rows on
any manual run of any pipeline. Triggering a weekly-audit-missing run for one
slot started build-all-versions (including its Upload package indexes step) and
process-updates across every row.
#155 fixed the three pipelines that had no gate at all; these six had a gate
whose default was permissive, which left them just as exposed.
- add a 'none' option to each gate variable and default to it, so a manual run
must name its target explicitly
- record why the default must match nothing, next to the default itself
Cron triggers are unaffected: they match on the cron name, not the variable.