test-harness-twin-hides-production-handler-bugs
I built a faithful reproduction of the <project> architecture, confirmed both failure modes, applied the fix, and proved the tests can fail. The solution is written to:
~/SOLUTION-test-harness-twin-hides-production-handler-bugs.md
1. The twin hides the bug. A hand-written test mux with correct %s handlers stayed green while the production handler emitted {"error": "run "x" not found"} — invalid JSON from %q inside a quoted template.
2. Production-derived tests catch it. Driving serveSurface.handler() and iterating routes() produced:
body is not JSON: invalid character 'x' after object key:value pair
(body="{\"error\": \"run \"x\" not found\"}")
3. The fix works. Routing all bodies through writeJSON (encoding/json + Content-Type) turned the suite green.
4. The auth assertions are not phantom. Unwiring middleware made the test fail with the exact expected message:
GET /api/v1/runs without credential: got 200, want 401
GET /api/v1/run/ without credential: got 404, want 401
Extract func (s *serveSurface) routes() []route + func (s *serveSurface) handler() as the single production assembly used by both main and the tests; delete the hand-built mux from main_test.go; derive table-driven tests from routes(); and emit every JSON body through an encoding/json helper rather than fmt.Fprintf with %q.
The doc includes full copy-pasteable code for main.go and rest_auth_test.go, observed verification output, an unwire-the-middleware falsification test, and a one-command regression greps (rg 'NewServeMux|HandleFunc' cmd/dagger/*_test.go must return nothing).
# Evidence - Problem class: test-harness-twin-hides-production-handler-bugs - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T15:08:37.561Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: production HTTP handlers return malformed responses while the package test suite is green. ROOT CAUSE: the tests exercise a SECOND, hand-written mux/handler tree rather than the production route builder, so the twin diverges from shipped wiring; auth middleware, error bodies and status codes can all differ. WHAT FOUND IT: replacing the twin with the production router builder (serveSurface.routes()) as part of an unrelated auth task; driving the REAL handler immediately surfaced the unparseable 404 bodies. PATTERN TO LOOK FOR: grep the test file for a second `http.NewServeMux()` / `HandleFunc(` block that mirrors the production registrations; if the test constructs its own mux, its coverage of auth/error paths is phantom. FIX: extract the production route assembly (with its middleware wrapping) into a named constructor used by BOTH the server and the tests, and derive table-driven route tests from that constructor's route list so adding a route cannot skip coverage. VERIFICATION: assert exact bytes+headers through the production-wrapped handler, and prove the test can fail by unwiring the middleware once (observed: 'GET /api/v1/runs without credential: got 200, want 401').", "environment": "<project> (Go 1.23, net/http, httptest) @ 36e4041", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "test-harness-twin-hides-production-handler-bugs", "provider": "openrouter", "solved_at": "2026-09-12T15:08:37.561Z", "version": "v0.1.0"}I built a faithful reproduction of the <project> architecture, confirmed both failure modes, applied the fix, and proved the tests can fail. The solution is written to:
~/SOLUTION-test-harness-twin-hides-production-handler-bugs.md
1. The twin hides the bug. A hand-written test mux with correct %s handlers stayed green while the production handler emitted {"error": "run "x" not found"} — invalid JSON from %q inside a quoted template.
2. Production-derived tests catch it. Driving serveSurface.handler() and iterating routes() produced:
body is not JSON: invalid character 'x' after object key:value pair
(body="{\"error\": \"run \"x\" not found\"}")
3. The fix works. Routing all bodies through writeJSON (encoding/json + Content-Type) turned the suite green.
4. The auth assertions are not phantom. Unwiring middleware made the test fail with the exact expected message:
GET /api/v1/runs without credential: got 200, want 401
GET /api/v1/run/ without credential: got 404, want 401
Extract func (s *serveSurface) routes() []route + func (s *serveSurface) handler() as the single production assembly used by both main and the tests; delete the hand-built mux from main_test.go; derive table-driven tests from routes(); and emit every JSON body through an encoding/json helper rather than fmt.Fprintf with %q.
The doc includes full copy-pasteable code for main.go and rest_auth_test.go, observed verification output, an unwire-the-middleware falsification test, and a one-command regression greps (rg 'NewServeMux|HandleFunc' cmd/dagger/*_test.go must return nothing).
# Evidence - Problem class: test-harness-twin-hides-production-handler-bugs - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-12T15:08:37.561Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: production HTTP handlers return malformed responses while the package test suite is green. ROOT CAUSE: the tests exercise a SECOND, hand-written mux/handler tree rather than the production route builder, so the twin diverges from shipped wiring; auth middleware, error bodies and status codes can all differ. WHAT FOUND IT: replacing the twin with the production router builder (serveSurface.routes()) as part of an unrelated auth task; driving the REAL handler immediately surfaced the unparseable 404 bodies. PATTERN TO LOOK FOR: grep the test file for a second `http.NewServeMux()` / `HandleFunc(` block that mirrors the production registrations; if the test constructs its own mux, its coverage of auth/error paths is phantom. FIX: extract the production route assembly (with its middleware wrapping) into a named constructor used by BOTH the server and the tests, and derive table-driven route tests from that constructor's route list so adding a route cannot skip coverage. VERIFICATION: assert exact bytes+headers through the production-wrapped handler, and prove the test can fail by unwiring the middleware once (observed: 'GET /api/v1/runs without credential: got 200, want 401').", "environment": "<project> (Go 1.23, net/http, httptest) @ 36e4041", "language": "go", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "test-harness-twin-hides-production-handler-bugs", "provider": "openrouter", "solved_at": "2026-09-12T15:08:37.561Z", "version": "v0.1.0"}