go-root-suite-test-fixture-invokes-real-docker-build
Diagnosed and verified. The solution is written to:
~/bunker/INT-CI-002-solution.md
Root cause: TestSpawn_ValidSpecNilBuilderRejected depends on newTestManager returning a manager with imageBuilder == nil. But GAP-064 (9ff18e6) made NewAgentManager always construct a real imagespec.Builder, and newTestManager calls that constructor (manager.go:53). So the Step 1.7 nil-builder guard in manager_spawn.go no longer fired. With a valid spec (apt: jq), Spawn sailed through validation and reached Step 5b.5 → Builder.BuildValidated → execRunner.Run → docker --host ... build, hanging the root suite until the 5m panic.
Fix (test-only, 1 functional line): set m.imageBuilder = nil explicitly after newTestManager(t) in the test, plus clarifying comments. No production code, timeout, or other test changed.
m := newTestManager(t)
// Force the nil-builder gate: newTestManager wires a real builder via
// NewAgentManager (GAP-064). Without this, a valid spec sails past the
// Step 1.7 gate and reaches a real rootless Docker build in Step 5b.5.
m.imageBuilder = nil
Verification performed here:
- go build ./... and go build ./internal/agent/ — pass
- go vet ./internal/agent/ — clean
- Target test runs/compiles (SKIP as non-root, as designed)
- Confirmed the standalone patch applies cleanly to the pre-fix tree f8192c0 and builds
CI verification (run 34605653448): root-suite success in 4m13s (was timing out at 5m), plus build-and-test, regression/E2E, and gitreins-guard all green.
The markdown includes the full root-cause trace, exact diff/patch, git cherry-pick ddb6d44 alternative, rationale for rejecting weaker fixes, and the root-suite verification commands.
# Evidence - Problem class: go-root-suite-test-fixture-invokes-real-docker-build - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-11T14:03:22.165Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A root-gated Go test intended to verify a nil dependency used a shared helper that had evolved to initialize the real dependency. The test's valid request bypassed the nil guard and reached a real docker build, hanging the CI suite until its 300-second timeout. The panic stack identified the exact test and exec path. Fix the test fixture explicitly by setting the dependency nil before the call; do not weaken the timeout or alter production behavior. Verify with the targeted root test and the full root suite in CI.", "environment": "Go 1.26, Linux self-hosted root GitHub Actions runner, rootless Docker", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-root-suite-test-fixture-invokes-real-docker-build", "provider": "openrouter", "solved_at": "2026-09-11T14:03:22.165Z", "version": "fix commit ddb6d44"}Diagnosed and verified. The solution is written to:
~/bunker/INT-CI-002-solution.md
Root cause: TestSpawn_ValidSpecNilBuilderRejected depends on newTestManager returning a manager with imageBuilder == nil. But GAP-064 (9ff18e6) made NewAgentManager always construct a real imagespec.Builder, and newTestManager calls that constructor (manager.go:53). So the Step 1.7 nil-builder guard in manager_spawn.go no longer fired. With a valid spec (apt: jq), Spawn sailed through validation and reached Step 5b.5 → Builder.BuildValidated → execRunner.Run → docker --host ... build, hanging the root suite until the 5m panic.
Fix (test-only, 1 functional line): set m.imageBuilder = nil explicitly after newTestManager(t) in the test, plus clarifying comments. No production code, timeout, or other test changed.
m := newTestManager(t)
// Force the nil-builder gate: newTestManager wires a real builder via
// NewAgentManager (GAP-064). Without this, a valid spec sails past the
// Step 1.7 gate and reaches a real rootless Docker build in Step 5b.5.
m.imageBuilder = nil
Verification performed here:
- go build ./... and go build ./internal/agent/ — pass
- go vet ./internal/agent/ — clean
- Target test runs/compiles (SKIP as non-root, as designed)
- Confirmed the standalone patch applies cleanly to the pre-fix tree f8192c0 and builds
CI verification (run 34605653448): root-suite success in 4m13s (was timing out at 5m), plus build-and-test, regression/E2E, and gitreins-guard all green.
The markdown includes the full root-cause trace, exact diff/patch, git cherry-pick ddb6d44 alternative, rationale for rejecting weaker fixes, and the root-suite verification commands.
# Evidence - Problem class: go-root-suite-test-fixture-invokes-real-docker-build - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-11T14:03:22.165Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A root-gated Go test intended to verify a nil dependency used a shared helper that had evolved to initialize the real dependency. The test's valid request bypassed the nil guard and reached a real docker build, hanging the CI suite until its 300-second timeout. The panic stack identified the exact test and exec path. Fix the test fixture explicitly by setting the dependency nil before the call; do not weaken the timeout or alter production behavior. Verify with the targeted root test and the full root suite in CI.", "environment": "Go 1.26, Linux self-hosted root GitHub Actions runner, rootless Docker", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-root-suite-test-fixture-invokes-real-docker-build", "provider": "openrouter", "solved_at": "2026-09-11T14:03:22.165Z", "version": "fix commit ddb6d44"}