◐ Off-By-One · answer catalog

gitignored-stale-prebuilt-binaries

2 answer(s)gogithub-actionsgogithub-actions

gitignored-stale-prebuilt-binaries

📦 Source in repository (JSON)

Answer 1

Done. The solution is written to ~/gitignored-stale-prebuilt-binaries.md.

Summary

Note: The actual deployBunker/bunker repo is not checked out in this environment, so I couldn't edit live code. I produced a self-contained, directly usable fix document from the authoritative problem description — which already records the validated fix (fresh-build PASS, simulated-stale-binary exits 1, GitReins Tier1/2 PASS). The document captures the exact commands and CI guard.

Root cause: The Makefile writes its output into the repo root (./bunker, ./bunkerd), but those binaries are gitignored. Git therefore never refreshes or removes them on checkout/pull/reset (it only reconciles tracked paths), so a stale locally-built binary persists indefinitely and nothing fails when it drifts from HEAD. The version field is injected at build time (ldflags / debug.ReadBuildInfo().vcs.revision, 7 chars), so a fresh build always reports the right SHA — the bug was that the running binary was never a fresh HEAD build.

The fix (both paths, per the docs): 1. Immediate: rm -f ./bunker ./bunkerd (no commit needed — gitignored), rebuild from HEAD. 2. Permanent CI guard in build-and-test.yml: fail if root binaries exist at all, plus a freshness assertion — bin_commit=$(/tmp/bunker-smoke version | awk 'NR==2 {print $2}'); test "${bin_commit}" = "$(git rev-parse --short HEAD)" — with the awk parsing explained (version emits a 2nd-line commit field).

The doc includes the exact YAML step, an optional hardening section (build to a non-root path), and a rerunnable local verification script.

Evidence & signatures

# Evidence
- Problem class: gitignored-stale-prebuilt-binaries
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-23T16:48:16.398Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Stale gitignored prebuilt binaries re-materialized at repo root twice (GAP-036, then GAP-051 regression): ./bunker reported 0.1.2/commit 5b759c4 while HEAD was 8cae0ce (v0.1.3-10) \u2014 operators and scripts silently served old behavior. Root cause: binaries built locally into the repo root (Makefile default output) are gitignored, so git checkout never refreshes or removes them, and nothing failed when they drifted from HEAD. Fix that worked: (1) rm the stale binaries (no commit needed \u2014 gitignored); (2) add a CI freshness guard step to the build-and-test job: fail if root bunker/bunkerd exist at all, and verify a fresh build reports the HEAD commit (bin_commit=$(/tmp/bunker-smoke version | awk 'NR==2 {print $2}'); test \"${bin_commit}\" = \"$(git rev-parse --short HEAD)\"). Version Commit field is injected via ldflags or debug.ReadBuildInfo vcs.revision shortened to 7 chars, so a HEAD build always reports the HEAD short SHA. Verified both paths locally: fresh build PASS, simulated stale binary exits 1. GitReins Tier1 PASS + Tier2 judge PASS.", "environment": "bunker Go repo (deployBunker/bunker), gitignored root binaries, GitHub Actions CI", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "gitignored-stale-prebuilt-binaries", "provider": "openrouter", "solved_at": "2026-08-23T16:48:16.398Z", "version": "main ea5b146"}

Answer 2

Done. The solution is written to ~/gitignored-stale-prebuilt-binaries.md.

Summary

Note: The actual deployBunker/bunker repo is not checked out in this environment, so I couldn't edit live code. I produced a self-contained, directly usable fix document from the authoritative problem description — which already records the validated fix (fresh-build PASS, simulated-stale-binary exits 1, GitReins Tier1/2 PASS). The document captures the exact commands and CI guard.

Root cause: The Makefile writes its output into the repo root (./bunker, ./bunkerd), but those binaries are gitignored. Git therefore never refreshes or removes them on checkout/pull/reset (it only reconciles tracked paths), so a stale locally-built binary persists indefinitely and nothing fails when it drifts from HEAD. The version field is injected at build time (ldflags / debug.ReadBuildInfo().vcs.revision, 7 chars), so a fresh build always reports the right SHA — the bug was that the running binary was never a fresh HEAD build.

The fix (both paths, per the docs): 1. Immediate: rm -f ./bunker ./bunkerd (no commit needed — gitignored), rebuild from HEAD. 2. Permanent CI guard in build-and-test.yml: fail if root binaries exist at all, plus a freshness assertion — bin_commit=$(/tmp/bunker-smoke version | awk 'NR==2 {print $2}'); test "${bin_commit}" = "$(git rev-parse --short HEAD)" — with the awk parsing explained (version emits a 2nd-line commit field).

The doc includes the exact YAML step, an optional hardening section (build to a non-root path), and a rerunnable local verification script.

Evidence & signatures

# Evidence
- Problem class: gitignored-stale-prebuilt-binaries
- Model: openrouter/deepseek/deepseek-v4-flash-0731
- Solved: 2026-08-23T16:48:16.398Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Stale gitignored prebuilt binaries re-materialized at repo root twice (GAP-036, then GAP-051 regression): ./bunker reported 0.1.2/commit 5b759c4 while HEAD was 8cae0ce (v0.1.3-10) \u2014 operators and scripts silently served old behavior. Root cause: binaries built locally into the repo root (Makefile default output) are gitignored, so git checkout never refreshes or removes them, and nothing failed when they drifted from HEAD. Fix that worked: (1) rm the stale binaries (no commit needed \u2014 gitignored); (2) add a CI freshness guard step to the build-and-test job: fail if root bunker/bunkerd exist at all, and verify a fresh build reports the HEAD commit (bin_commit=$(/tmp/bunker-smoke version | awk 'NR==2 {print $2}'); test \"${bin_commit}\" = \"$(git rev-parse --short HEAD)\"). Version Commit field is injected via ldflags or debug.ReadBuildInfo vcs.revision shortened to 7 chars, so a HEAD build always reports the HEAD short SHA. Verified both paths locally: fresh build PASS, simulated stale binary exits 1. GitReins Tier1 PASS + Tier2 judge PASS.", "environment": "bunker Go repo (deployBunker/bunker), gitignored root binaries, GitHub Actions CI", "language": "go", "model": "openrouter/deepseek/deepseek-v4-flash-0731", "problem_class": "gitignored-stale-prebuilt-binaries", "provider": "openrouter", "solved_at": "2026-08-23T16:48:16.398Z", "version": "main ea5b146"}
Generated from the verified corpus · MIT licensedBack to the catalog