go-test-openai-api-key-env-leak-config-precedence
The fix is verified. Solution written to /tmp/consensus/SOLUTION-go-test-openai-api-key-env-leak-config-precedence.md.
Diagnosis confirmed: This is host environment contamination, not a code regression. Defaults() sets LLM.Provider: "openai" with an empty APIKey. applyEnvOverrides evaluates the OPENAI_API_KEY branch (conditional on provider == "openai" && APIKey == "") before the DEEPSEEK_API_KEY branch (which only fires when APIKey == "" || strings.HasPrefix("${")). On your session the shell exports OPENAI_API_KEY=sk-svcacct-... (OpenAI Codex auth), so the openai branch populates APIKey first, and the guarded DeepSeek branch is skipped → got "sk-svcacct-...".
Reproduced exactly with OPENAI_API_KEY=sk-svcacct-ABCXYZ123 go test ./internal/config/ -run TestApplyEnvOverrides_OpenRouterUnsetKeepsDeepSeek → FAIL.
Fix applied — make the test hermetic in internal/config/config_test.go:
t.Setenv("OPENAI_API_KEY", "") // neutralise leaked host key
t.Setenv("DEEPSEEK_API_KEY", "sk-deepseek-test")
os.Unsetenv("OPENROUTER_API_KEY")
(t.Setenv gives automatic cleanup; the empty value is rejected by the loader's v != "" guard.)
Verified:
- Contaminated env, go test ./internal/config/ -run 'TestApplyEnvOverrides' → 3/3 PASS.
- OPENAI_API_KEY=sk-svcacct-X go test -short ./... → 30/30 packages ok.
- Diff is test-only (+6 lines), no production behavior changed. Alternative (no code change) is env -u OPENAI_API_KEY go test -short ./....
The doc is fully self-contained with title, root-cause analysis, the exact patch, and the verification section.
# Evidence - Problem class: go-test-openai-api-key-env-leak-config-precedence - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T02:51:50.489Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "consensus internal/config TestApplyEnvOverrides_OpenRouterUnsetKeepsDeepSeek fails locally with got=sk-svcacct- OpenAI service-account key even though the test unsets OPENROUTER_API_KEY. Root cause: session env exports OPENAI_API_KEY (OpenAI Codex auth); config loader Defaults() has LLM.Provider=openai, and applyEnvOverrides' OPENAI_API_KEY branch (checked before DEEPSEEK) sets cfg.LLM.APIKey unconditionally when provider==openai, so the DEEPSEEK branch (which only applies when APIKey=='' or starts with '${') never fires. Not a CI failure (CI runners lack OPENAI_API_KEY); local-only contamination. Fix: run tests env-clean (env -u OPENAI_API_KEY go test -short ./... = 30/30 pass) or make the test hermetic with t.Setenv(\"OPENAI_API_KEY\", \"\"). Document as standing host condition, not a code regression.", "environment": "hermes-scheduler-session", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-test-openai-api-key-env-leak-config-precedence", "provider": "openrouter", "solved_at": "2026-08-16T02:51:50.489Z", "version": "go1.26"}