eduos-demo-db-pin-drift-judge-tier1-reseed
I wrote the solution to /workspace/SOLUTION.md (also copied to ~/SOLUTION.md).
Note: the environment has no EduOS repo mounted — only /workspace/problem.json (the triage record). So this is a self-contained, directly-usable runbook rather than a patch against real files; every command/code block is written to be dropped into the live repo.
1. Root cause
The post-UI baseline pins exact live demo-DB counts. gitreins task complete runs pnpm -r run test as its tier1 tests step from the repo root; those seed fixtures aren't isolated — they register display-test-<ms>@test.com users (non-idempotent Date.now() suffix), insert quizzes, and grow ae +5. The judge itself writes to the DB after the pin, so the next tick reports DRIFT with no external actor. Two observations in t573 = the two tier1 test steps in that verdict.
2. Evidence / correlation
- jq over .gitreins/history/*.json for evaluated_at + tier1.steps[tests].
- rg 'display-test-' in history output.
- SQL on users WHERE email LIKE 'display-test-%' to show created_at sits inside [baseline.pinned_at, drift.observed_at] and brackets the verdict's evaluated_at.
3. Immediate remedy (never mutate/delete rows)
Add a schema-safe --write-baseline mode to demo-db-pin-precheck.py (atomic temp-file + os.replace), re-pin from live post-judge counts, re-run keeper to MATCH twice, commit the new pin.
4. Durable fix
- Test bootstrap refuses non-ephemeral / live-looking DATABASE_URL (fail fast).
- Per-test transaction rollback + deterministic seed IDs.
- Tier1 env override (TEST_DATABASE_URL) in .gitreins/task.toml, fail-closed root test script, optional project filter.
- Before/after DB-mutation tripwire around tier1.
5. Verification
4× 30s stability probes (identical hashes, no writer processes), drift-window correlation, double MATCH, and a regression test proving a full test run no longer moves the pin.
6. Anti-recurrence checklist, with the explicit rule that existing display-test-* rows are captured by the new pin, not deleted.
# Evidence - Problem class: eduos-demo-db-pin-drift-judge-tier1-reseed - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-11T05:53:53.788Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "EduOS foreman rotation tick: demo-db-pin-precheck.py reports DRIFT (users/quizzes/newest_user_email changed vs the prior tick's post-UI baseline) with no external actor running. Root cause: gitreins task complete re-executes the workspace test suite (pnpm -r run test) inside the judge's tier1 stage from the repo root; its seed fixtures register display-test-<ms>@test.com users and create quizzes in the live demo DB (ae grows passively +5). Verify by correlating the drift window with the verdict's evaluated_at + tier1 steps[tests] output in .gitreins/history/, then probe stability 4x over ~2min AFTER the judge exits: counts stable at new values, no writer processes. Remedy: never mutate the DB; write a fresh baseline JSON from the live post-judge counts and re-run the keeper for MATCH. Seen twice in one tick (t573) and documented in the t571 pointer ('judge tier1 root suite x2 -> reseed drift re-pinned post-judge').", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-demo-db-pin-drift-judge-tier1-reseed", "provider": "openrouter", "solved_at": "2026-09-11T05:53:53.789Z", "version": ""}I wrote the solution to /workspace/SOLUTION.md (also copied to ~/SOLUTION.md).
Note: the environment has no EduOS repo mounted — only /workspace/problem.json (the triage record). So this is a self-contained, directly-usable runbook rather than a patch against real files; every command/code block is written to be dropped into the live repo.
1. Root cause
The post-UI baseline pins exact live demo-DB counts. gitreins task complete runs pnpm -r run test as its tier1 tests step from the repo root; those seed fixtures aren't isolated — they register display-test-<ms>@test.com users (non-idempotent Date.now() suffix), insert quizzes, and grow ae +5. The judge itself writes to the DB after the pin, so the next tick reports DRIFT with no external actor. Two observations in t573 = the two tier1 test steps in that verdict.
2. Evidence / correlation
- jq over .gitreins/history/*.json for evaluated_at + tier1.steps[tests].
- rg 'display-test-' in history output.
- SQL on users WHERE email LIKE 'display-test-%' to show created_at sits inside [baseline.pinned_at, drift.observed_at] and brackets the verdict's evaluated_at.
3. Immediate remedy (never mutate/delete rows)
Add a schema-safe --write-baseline mode to demo-db-pin-precheck.py (atomic temp-file + os.replace), re-pin from live post-judge counts, re-run keeper to MATCH twice, commit the new pin.
4. Durable fix
- Test bootstrap refuses non-ephemeral / live-looking DATABASE_URL (fail fast).
- Per-test transaction rollback + deterministic seed IDs.
- Tier1 env override (TEST_DATABASE_URL) in .gitreins/task.toml, fail-closed root test script, optional project filter.
- Before/after DB-mutation tripwire around tier1.
5. Verification
4× 30s stability probes (identical hashes, no writer processes), drift-window correlation, double MATCH, and a regression test proving a full test run no longer moves the pin.
6. Anti-recurrence checklist, with the explicit rule that existing display-test-* rows are captured by the new pin, not deleted.
# Evidence - Problem class: eduos-demo-db-pin-drift-judge-tier1-reseed - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-11T05:53:53.788Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "EduOS foreman rotation tick: demo-db-pin-precheck.py reports DRIFT (users/quizzes/newest_user_email changed vs the prior tick's post-UI baseline) with no external actor running. Root cause: gitreins task complete re-executes the workspace test suite (pnpm -r run test) inside the judge's tier1 stage from the repo root; its seed fixtures register display-test-<ms>@test.com users and create quizzes in the live demo DB (ae grows passively +5). Verify by correlating the drift window with the verdict's evaluated_at + tier1 steps[tests] output in .gitreins/history/, then probe stability 4x over ~2min AFTER the judge exits: counts stable at new values, no writer processes. Remedy: never mutate the DB; write a fresh baseline JSON from the live post-judge counts and re-run the keeper for MATCH. Seen twice in one tick (t573) and documented in the t571 pointer ('judge tier1 root suite x2 -> reseed drift re-pinned post-judge').", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "eduos-demo-db-pin-drift-judge-tier1-reseed", "provider": "openrouter", "solved_at": "2026-09-11T05:53:53.789Z", "version": ""}