## Problem
A manual `crow pipeline create` instantiates **every** pipeline in `.crow/`, and each one decides for itself whether to run. Three had nothing to decide with — their only manual condition was a bare `event: manual`:
- `auto-apply-patches` — pushes to `auto/registry-patch-proposals` and opens/updates a PR
- `weekly-patch-proposals` — posts and edits two Forgejo issues
- `trial-build-registry` — starts a build per matrix row, on both arches
So they fired on *any* manual trigger in this repo, whatever it was for. That is how they came to run alongside a manual `process-updates` run for `alpine-324-arm64` (#10723), which is also why that pipeline is marked failure.
`repair-built-stamp.yaml` already documents the rule this breaks:
> The gate variable is `repair_built_stamp`, not `target_arch` … Every pipeline here gates on a variable named after itself for exactly that reason.
## What this changes
Each of the three gets a gate variable named after the pipeline, `evaluate`d on the manual event, defaulting to off:
```yaml
variables:
auto_apply_patches:
description: 'Run the auto-patch proposer. Also gates this pipeline.'
options: ['true', 'false']
default: 'false'
when:
- event: manual
evaluate: 'auto_apply_patches == "true"'
- event: cron
cron: auto-apply-patches
```
Cron triggers are untouched, so the scheduled runs behave exactly as before.
The run-manually comments in all three headers were also stale: they documented `--var task=<name>` with `woodpecker-cli`, and no pipeline evaluates a `task` variable. They now show the real invocation.
## Note on the sibling pipelines
The already-gated pipelines use `default: all` (e.g. `weekly_rebuild_missing`). If Crow applies a declared default to a variable that an API-created pipeline never passed, those would match on an unrelated manual run too — `weekly-rebuild-missing` would be an expensive way to find out. I could not settle that from #10723 because its step logs have since expired, so I left them alone rather than guess. The three fixed here default to `'false'`, which is safe under either semantics.
## Verification
`crow lint .crow/` passes. Auditing every pipeline that accepts a manual event now reports a gate on all ten:
```
build-all-versions-install-deps.yaml: gated
auto-apply-patches.yaml: gated
weekly-patch-proposals.yaml: gated
weekly-audit-missing.yaml: gated
repair-built-stamp.yaml: gated
archive-missed-packages.yaml: gated
weekly-rebuild-missing.yaml: gated
trial-build-registry.yaml: gated
build-all-versions.yaml: gated
process-updates.yaml: gated
```
Reviewed-on: #155