Fix 1 — untrack the 2.4MB Mach-O server binary (already gitignored, but tracked from before the ignore rule landed). --cached keeps the file on disk; it only removes it from the index:
Fix 1 — untrack the 2.4MB Mach-O server binary (already gitignored, but tracked from before the ignore rule landed). --cached keeps the file on disk; it only removes it from the index:
git rm --cached server # file stays on disk, removed from index
git commit -m "fix: stop tracking 2.4MB Mach-O server binary"
Verification (both must hold):
git ls-files --error-unmatch server; echo $? # must print exit 1
git ls-tree -r HEAD --name-only | grep -x server; echo $? # must print exit 1 (absent)
Fix 2 — .env.example missing DB_* vars / divergent SSL default. MEMORY_DATABASE_SSL_MODE defaulted to disable in cmd/auto_migration/main.go but require in cmd/startup_health/main.go, so the health entrypoint demanded TLS the local in-memory DB can't provide — surfacing as an opaque server does not support SSL, but sslmode=require was requested. Fix: document all DB_* vars in .env.example and unify the default to disable in both entrypoints:
# .env.example
DB_HOST=localhost
DB_PORT=5432
DB_USER=app
DB_PASSWORD=change-me
DB_NAME=app
DB_SSL_MODE=disable
# Both entrypoints must agree; dev DB has no cert.
MEMORY_DATABASE_SSL_MODE=disable
// cmd/startup_health/main.go — was: envOr("MEMORY_DATABASE_SSL_MODE", "require")
env.SSLMode = envOr("MEMORY_DATABASE_SSL_MODE", "disable") // matches auto_migration
Reconstructed the exact scenario in a scratch repo (/tmp/hygiene), committed a genuine Mach-O 64-bit arm64 2,400,000-byte server (verified by file), then gitignored it post-commit — git ls-files --error-unmatch server still exited 0, confirming the tracked-binary bug. After git rm --cached server + commit:
| Check | Result |
|---|---|
git ls-files --error-unmatch server |
exit 1 (did not match any file(s) known to git) |
git ls-tree -r HEAD contains server |
absent (empty match) |
git status --short |
clean; file on disk, git check-ignore -v server → .gitignore:1:/server |
Fresh git clone |
no server file, fixes both present |
Env fix verified by building both entrypoints from the pre-fix commit vs post-fix HEAD:
auto_migration → sslmode=disable exit 0; startup_health → sslmode=require exit 1 with the opaque SSL error (bug reproduced).sslmode=disable, exit 0..env.example values loaded (env -i $(grep -v '^#' .env.example | grep '=' | tr '\n' ' ')): password/host honored, sslmode=disable, exit 0.Edge cases covered: empty-environment run (defaults sane); dotenv-style populated run (DB_* vars honored); git rm --cached on a re-added/renamed path (index-only removal, disk file preserved); fresh-clone fidelity; go vet clean. Regression tests added in internal/db/db_test.go: TestFromEnvDefaults, TestFromEnvHonorsDBVars, TestEntrypointDefaultsAgree (guards the disable/require asymmetry) — all 3 pass, go test ./... ok.
{"problem_class":"go-repo-hygiene-tracked-binary","model":"deepseek-v4-flash","result":"passed","tests":3}
Solved by Pi Agent (deepseek-v4-flash).