go-test-env-contamination-openai-key-leaks-into-config-override-test
Solution: /workspace/solution.md (verified with a minimal Go repro that mirrors Defaults() + applyEnvOverrides).
TestApplyEnvOverrides_OpenRouterUnsetKeepsDeepSeek is not hermetic. It cleared only OPENROUTER_API_KEY via os.Unsetenv (not auto-restored) and ignored OPENAI_API_KEY — but applyEnvOverrides consults OPENAI_API_KEY first when starting from Defaults() (provider "openai", APIKey == ""). A leaked Codex sk-svcacct-... key therefore wins before the DeepSeek branch runs, breaking the assertion in the judge's env while the suite stays green in a clean shell.
internal/config/config_test.go)t.Setenv("OPENAI_API_KEY", "") // neutralize leaked keys
t.Setenv("OPENROUTER_API_KEY", "") // replaces os.Unsetenv; auto-restored
t.Setenv("DEEPSEEK_API_KEY", "sk-deepseek-...")
Empty strings disable the v != "" branches in applyEnvOverrides, and t.Setenv auto-restores at test end. Drop the unused "os" import. No production change needed.
| Env | Buggy test | Fixed test |
|---|---|---|
Clean (env -u all three keys) |
ok |
ok, exit 0 |
OPENAI_API_KEY=sk-svcacct-codex-leaked-123 |
FAIL ... expected deepseek key, got "sk-svcacct-codex-leaked-123" (provider=openai) |
ok, exit 0 |
| All three keys exported | — | ok, exit 0 |
The full markdown (with root-cause walkthrough, exact before/after code, and the two acceptance commands) is in /workspace/solution.md.
# Evidence - Problem class: go-test-env-contamination-openai-key-leaks-into-config-override-test - Model: openrouter/deepseek/deepseek-v4-flash-0731 - Solved: 2026-08-16T09:51:36.434Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Go config-override unit test fails when OPENAI_API_KEY is set in the shell env: TestApplyEnvOverrides_OpenRouterUnsetKeepsDeepSeek asserts DEEPSEEK_API_KEY applies when OPENROUTER_API_KEY is unset, but applyEnvOverrides checks OPENAI_API_KEY FIRST (when cfg.LLM.Provider == 'openai', which is the Defaults() provider) and cfg.LLM.APIKey == '', so a leaked OPENAI_API_KEY (e.g. Codex auth sk-svcacct-...) wins over the t.Setenv DeepSeek key and the assertion fails with the real key value. Symptom: gitreins Tier2 judge reports 'go test -short NOT green' with FAIL in internal/config even though the suite is green in a clean env. Root cause: test not hermetic - it used os.Unsetenv('OPENROUTER_API_KEY') (not auto-restored) and never considered OPENAI_API_KEY. Fix: replace os.Unsetenv with t.Setenv('OPENAI_API_KEY', '') + t.Setenv('OPENROUTER_API_KEY', '') (empty string disables the != '' branches, t.Setenv auto-restores at test end). Verification: env -u OPENROUTER_API_KEY -u OPENAI_API_KEY -u DEEPSEEK_API_KEY go test -short -count=1 ./... exit 0; same test passes even with all three keys exported.", "environment": "", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "go-test-env-contamination-openai-key-leaks-into-config-override-test", "provider": "openrouter", "solved_at": "2026-08-16T09:51:36.434Z", "version": ""}