gitreins-guard-timeout-inflation-masks-test-hang
I diagnosed the problem, reproduced the masking behavior with the real GitReins 0.12.1 engine, and wrote the solution.
Deliverable: /workspace/solution.md
Root cause: GitReins has two timers with opposite semantics:
- guards.test_timeout → per-test subprocess, fail-hard (passed=False)
- guards.hook_timeout → whole Tier-1 budget checked after each guard, fail-open (Tier1Result(passed=True))
In GuardManager.run_all(), if a hung test trips test_timeout and the clock is already past hook_timeout, the trailing _timed_out() branch returns an overall PASS, overriding the ✗ go_tests failure. Masking happens when pre_test_seconds >= hook_timeout - test_timeout. The old 2400/2520 left only 120 s headroom, so fleet-load slowdowns in secrets/build/lint masked the hang — and the wall clock was 40+ min.
Fix (config-only, .gitreins/config.yaml):
guards:
test_timeout: 900
hook_timeout: 1200 # 300s headroom; test timeout always fires first
test_timeout=900 < hook_timeout=1200, headroom 300 s, parses through GuardManager.3 < 8 → EXIT=1 FAIL; 6 >= 3 → EXIT=0 PASS with ✗ go_tests (exact masking bug).go test -count=1 ./... on a real Go module → ok..gitreins/config.yaml commit through gitreins guard → PASS..go files, check_go_tests returns passed=True | "No Go files staged" — vacuous green, so it cannot be used as evidence.gitreins task create → commit → gitreins task complete → gitreins report) because a Tier 2 verdict is mandatory for this problem class.Note: no target Go repository was present in this environment, so verification was performed in a scratch Go module using the actual gitreins==0.12.1 wheel; the solution document gives exact commands to reproduce and apply it in the real repo.
# Evidence - Problem class: gitreins-guard-timeout-inflation-masks-test-hang - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T11:37:14.577Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "After fixing the actual lifecycle hang, restore bounded fail-hard ordering: test_timeout must expire before hook_timeout. In this repo, measured healthy full short sweeps were under 300s, so test_timeout=900 and hook_timeout=1200 preserve fleet-load headroom without the prior 2400/2520 masking window. Do not use a no-staged-diff gitreins guard as evidence; run fresh package tests and require a real staged config commit plus Tier 2 verification.", "environment": "GitReins pre-commit guard in a Go repository", "language": "yaml/go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-timeout-inflation-masks-test-hang", "provider": "openrouter", "solved_at": "2026-09-12T11:37:14.577Z", "version": ""}I diagnosed the problem, reproduced the masking behavior with the real GitReins 0.12.1 engine, and wrote the solution.
Deliverable: /workspace/solution.md
Root cause: GitReins has two timers with opposite semantics:
- guards.test_timeout → per-test subprocess, fail-hard (passed=False)
- guards.hook_timeout → whole Tier-1 budget checked after each guard, fail-open (Tier1Result(passed=True))
In GuardManager.run_all(), if a hung test trips test_timeout and the clock is already past hook_timeout, the trailing _timed_out() branch returns an overall PASS, overriding the ✗ go_tests failure. Masking happens when pre_test_seconds >= hook_timeout - test_timeout. The old 2400/2520 left only 120 s headroom, so fleet-load slowdowns in secrets/build/lint masked the hang — and the wall clock was 40+ min.
Fix (config-only, .gitreins/config.yaml):
guards:
test_timeout: 900
hook_timeout: 1200 # 300s headroom; test timeout always fires first
test_timeout=900 < hook_timeout=1200, headroom 300 s, parses through GuardManager.3 < 8 → EXIT=1 FAIL; 6 >= 3 → EXIT=0 PASS with ✗ go_tests (exact masking bug).go test -count=1 ./... on a real Go module → ok..gitreins/config.yaml commit through gitreins guard → PASS..go files, check_go_tests returns passed=True | "No Go files staged" — vacuous green, so it cannot be used as evidence.gitreins task create → commit → gitreins task complete → gitreins report) because a Tier 2 verdict is mandatory for this problem class.Note: no target Go repository was present in this environment, so verification was performed in a scratch Go module using the actual gitreins==0.12.1 wheel; the solution document gives exact commands to reproduce and apply it in the real repo.
# Evidence - Problem class: gitreins-guard-timeout-inflation-masks-test-hang - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T11:37:14.577Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "After fixing the actual lifecycle hang, restore bounded fail-hard ordering: test_timeout must expire before hook_timeout. In this repo, measured healthy full short sweeps were under 300s, so test_timeout=900 and hook_timeout=1200 preserve fleet-load headroom without the prior 2400/2520 masking window. Do not use a no-staged-diff gitreins guard as evidence; run fresh package tests and require a real staged config commit plus Tier 2 verification.", "environment": "GitReins pre-commit guard in a Go repository", "language": "yaml/go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-timeout-inflation-masks-test-hang", "provider": "openrouter", "solved_at": "2026-09-12T11:37:14.577Z", "version": ""}