Problem class: python-cli-data-home-env-export-guard
The repository itself was not mounted in this environment (only /workspace/problem.json was present), so I reconstructed the exact mechanism in /tmp/repro and empirically confirmed both the bug and the fix with an audit hook. Solution written to /workspace/SOLUTION.md:
router seed writes into the live fleet mirror under a data-home/scratch homeProblem class: python-cli-data-home-env-export-guard
The dispatcher resolves a data home and re-exports a subset of routing environment variables to the dispatched child command. In task_router/cli.py, _home_env_exports(...) emitted only:
"ROUTING_REGISTRY": os.path.join(home, "registry"),
"ROUTING_DATA_DIR": os.path.join(home, "data"),
It never emitted ROUTING_NS. The dispatched script scripts/router_seed.py:25 reads that variable with a hardcoded live fallback:
NS = os.environ.get("ROUTING_NS", "~/duckbrain/namespaces/routing")
So under any resolved data home (scratch/test/CI), ROUTING_NS was unset in the child, the fallback won, and router seed wrote its DuckDB tables into the live fleet mirror. ROUTING_REGISTRY and ROUTING_DATA_DIR were correctly redirected, which is why the leak escaped eyeballing.
_apply_env_exports already uses setdefault, so the export map is authoritative only when the operator did not set the variable. The repair is to add ROUTING_NS, not to change precedence.
Separate breakage: router_seed.py imports duckdb at module level, pyproject.toml is otherwise stdlib-only, and the README quickstart never told a fresh clone to install it → dispatch failed: No module named duckdb.
ROUTING_NS under the resolved home — task_router/cli.py def _home_env_exports(home: str, command: str) -> dict[str, str]:
exports = {
"ROUTING_REGISTRY": os.path.join(home, "registry"),
"ROUTING_DATA_DIR": os.path.join(home, "data"),
+ # Derive the namespace under the resolved data home so a scratch/CI
+ # home never falls back to the live fleet mirror in router_seed.py.
+ "ROUTING_NS": os.path.join(home, "ns", "routing"),
}
return exports
If keyed per command, add the entry to the router/seed arm instead:
exports["ROUTING_NS"] = os.path.join(home, "ns", "routing")
_apply_env_exports needs no change; confirm setdefault so an explicit operator value wins:
def _apply_env_exports(exports):
for key, value in exports.items():
os.environ.setdefault(key, value) # operator-set ROUTING_NS wins
duckdb dependency installable and documentedpyproject.toml:
[project.optional-dependencies]
duckdb = ["duckdb"]
README.md quickstart:
python -m venv .venv && . .venv/bin/activate
pip install -e '.[duckdb]'
Add a quickstart note: router seed and the pytest suite both import duckdb at module load, so the extra is required for a fresh clone.
Audit hook observes actual open() calls instead of inferring paths. Assert zero write-mode opens under the protected mirror and at least one under <home>/ns/routing/tables when that dir exists.
# tests/test_router_seed_home_isolation.py
import os, sys, subprocess
PROTECTED = "~/duckbrain/namespaces/routing"
AUDIT = r'''
import os, sys, runpy
home = sys.argv[1]
writes = []
def hook(event, args):
if event == "open" and args[1] and any(c in args[1] for c in "wax+"):
writes.append((str(args[0]), args[1]))
sys.addaudithook(hook)
runpy.run_path(os.path.join(home, "router_seed.py"), run_name="__main__")
prot = [p for p, _ in writes if os.path.abspath(p).startswith(PROTECTED)]
ns_dir = os.path.join(home, "ns", "routing", "tables")
landed = [p for p, _ in writes if os.path.abspath(p).startswith(ns_dir)]
print("PROTECTED_WRITES", len(prot))
print("LANDED", len(landed))
'''
def test_seed_never_writes_protected_mirror(tmp_path):
r = subprocess.run([sys.executable, "-c", AUDIT, str(tmp_path)],
capture_output=True, text=True)
assert "PROTECTED_WRITES 0" in r.stdout, r.stdout + r.stderr
if os.path.isdir(os.path.join(tmp_path, "ns", "routing", "tables")):
assert "LANDED 0" not in r.stdout, r.stdout
Precedence check:
env = {"ROUTING_NS": "/tmp/operator_ns"}
_apply_env_exports(_home_env_exports(home, "router"), env)
assert env["ROUTING_NS"] == "/tmp/operator_ns" # operator still wins
Faithful repro in /tmp/repro (same export map + setdefault + seed fallback + audit hook):
ROUTING_NS export): audit hook recorded 1 write-open under ~/duckbrain/namespaces/routing/tables.ROUTING_NS = os.path.join(home, "ns", "routing")): 0 protected write-opens, 1 write under .../scratch_home/ns/routing/tables, and the operator override won.Manual smoke check after applying the real patch:
pip install -e '.[duckdb]'
HOME_DIR=$(mktemp -d)
HOME="$HOME_DIR" task-router router seed
find "$HOME_DIR/ns/routing/tables" -type f
# expect seed artifacts only under $HOME_DIR, nothing new under
# ~/duckbrain/namespaces/routing
# Evidence - Problem class: python-cli-data-home-env-export-guard - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-14T11:33:30.373Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "CLI dispatcher (task-router task_router/cli.py _home_env_exports) exported only ROUTING_REGISTRY/ROUTING_DATA_DIR while the dispatched script (scripts/router_seed.py line 25) hardcoded fallback NS=~/duckbrain/namespaces/routing, so a data-home/scratch `router seed` exported INTO the live fleet mirror. Fix: derive ROUTING_NS under the resolved data home (os.path.join(home,\"ns\",\"routing\")) in the per-command export map; _apply_env_exports uses setdefault so an explicit operator ROUTING_NS still wins. Proof method that beats eyeballing: sys.addaudithook recording write-mode open() on the dispatched seed -> 0 write-opens under the protected mirror path, and export lands in <home>/ns/routing/tables when that dir exists (visible skip message otherwise). Also: README quickstart must document the duckdb extra (router_seed imports duckdb at module level; seed and the pytest suite both need it; pyproject is stdlib-only) or the fresh-clone quickstart fails with dispatch failed: No module named duckdb.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-cli-data-home-env-export-guard", "provider": "openrouter", "solved_at": "2026-09-14T11:33:30.374Z", "version": ""}The repository itself was not mounted in this environment (only /workspace/problem.json was present), so I reconstructed the exact mechanism in /tmp/repro and empirically confirmed both the bug and the fix with an audit hook. Solution written to /workspace/SOLUTION.md:
router seed writes into the live fleet mirror under a data-home/scratch homeProblem class: python-cli-data-home-env-export-guard
The dispatcher resolves a data home and re-exports a subset of routing environment variables to the dispatched child command. In task_router/cli.py, _home_env_exports(...) emitted only:
"ROUTING_REGISTRY": os.path.join(home, "registry"),
"ROUTING_DATA_DIR": os.path.join(home, "data"),
It never emitted ROUTING_NS. The dispatched script scripts/router_seed.py:25 reads that variable with a hardcoded live fallback:
NS = os.environ.get("ROUTING_NS", "~/duckbrain/namespaces/routing")
So under any resolved data home (scratch/test/CI), ROUTING_NS was unset in the child, the fallback won, and router seed wrote its DuckDB tables into the live fleet mirror. ROUTING_REGISTRY and ROUTING_DATA_DIR were correctly redirected, which is why the leak escaped eyeballing.
_apply_env_exports already uses setdefault, so the export map is authoritative only when the operator did not set the variable. The repair is to add ROUTING_NS, not to change precedence.
Separate breakage: router_seed.py imports duckdb at module level, pyproject.toml is otherwise stdlib-only, and the README quickstart never told a fresh clone to install it → dispatch failed: No module named duckdb.
ROUTING_NS under the resolved home — task_router/cli.py def _home_env_exports(home: str, command: str) -> dict[str, str]:
exports = {
"ROUTING_REGISTRY": os.path.join(home, "registry"),
"ROUTING_DATA_DIR": os.path.join(home, "data"),
+ # Derive the namespace under the resolved data home so a scratch/CI
+ # home never falls back to the live fleet mirror in router_seed.py.
+ "ROUTING_NS": os.path.join(home, "ns", "routing"),
}
return exports
If keyed per command, add the entry to the router/seed arm instead:
exports["ROUTING_NS"] = os.path.join(home, "ns", "routing")
_apply_env_exports needs no change; confirm setdefault so an explicit operator value wins:
def _apply_env_exports(exports):
for key, value in exports.items():
os.environ.setdefault(key, value) # operator-set ROUTING_NS wins
duckdb dependency installable and documentedpyproject.toml:
[project.optional-dependencies]
duckdb = ["duckdb"]
README.md quickstart:
python -m venv .venv && . .venv/bin/activate
pip install -e '.[duckdb]'
Add a quickstart note: router seed and the pytest suite both import duckdb at module load, so the extra is required for a fresh clone.
Audit hook observes actual open() calls instead of inferring paths. Assert zero write-mode opens under the protected mirror and at least one under <home>/ns/routing/tables when that dir exists.
# tests/test_router_seed_home_isolation.py
import os, sys, subprocess
PROTECTED = "~/duckbrain/namespaces/routing"
AUDIT = r'''
import os, sys, runpy
home = sys.argv[1]
writes = []
def hook(event, args):
if event == "open" and args[1] and any(c in args[1] for c in "wax+"):
writes.append((str(args[0]), args[1]))
sys.addaudithook(hook)
runpy.run_path(os.path.join(home, "router_seed.py"), run_name="__main__")
prot = [p for p, _ in writes if os.path.abspath(p).startswith(PROTECTED)]
ns_dir = os.path.join(home, "ns", "routing", "tables")
landed = [p for p, _ in writes if os.path.abspath(p).startswith(ns_dir)]
print("PROTECTED_WRITES", len(prot))
print("LANDED", len(landed))
'''
def test_seed_never_writes_protected_mirror(tmp_path):
r = subprocess.run([sys.executable, "-c", AUDIT, str(tmp_path)],
capture_output=True, text=True)
assert "PROTECTED_WRITES 0" in r.stdout, r.stdout + r.stderr
if os.path.isdir(os.path.join(tmp_path, "ns", "routing", "tables")):
assert "LANDED 0" not in r.stdout, r.stdout
Precedence check:
env = {"ROUTING_NS": "/tmp/operator_ns"}
_apply_env_exports(_home_env_exports(home, "router"), env)
assert env["ROUTING_NS"] == "/tmp/operator_ns" # operator still wins
Faithful repro in /tmp/repro (same export map + setdefault + seed fallback + audit hook):
ROUTING_NS export): audit hook recorded 1 write-open under ~/duckbrain/namespaces/routing/tables.ROUTING_NS = os.path.join(home, "ns", "routing")): 0 protected write-opens, 1 write under .../scratch_home/ns/routing/tables, and the operator override won.Manual smoke check after applying the real patch:
pip install -e '.[duckdb]'
HOME_DIR=$(mktemp -d)
HOME="$HOME_DIR" task-router router seed
find "$HOME_DIR/ns/routing/tables" -type f
# expect seed artifacts only under $HOME_DIR, nothing new under
# ~/duckbrain/namespaces/routing
# Evidence - Problem class: python-cli-data-home-env-export-guard - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-14T11:33:30.373Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "CLI dispatcher (task-router task_router/cli.py _home_env_exports) exported only ROUTING_REGISTRY/ROUTING_DATA_DIR while the dispatched script (scripts/router_seed.py line 25) hardcoded fallback NS=~/duckbrain/namespaces/routing, so a data-home/scratch `router seed` exported INTO the live fleet mirror. Fix: derive ROUTING_NS under the resolved data home (os.path.join(home,\"ns\",\"routing\")) in the per-command export map; _apply_env_exports uses setdefault so an explicit operator ROUTING_NS still wins. Proof method that beats eyeballing: sys.addaudithook recording write-mode open() on the dispatched seed -> 0 write-opens under the protected mirror path, and export lands in <home>/ns/routing/tables when that dir exists (visible skip message otherwise). Also: README quickstart must document the duckdb extra (router_seed imports duckdb at module level; seed and the pytest suite both need it; pyproject is stdlib-only) or the fresh-clone quickstart fails with dispatch failed: No module named duckdb.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "python-cli-data-home-env-export-guard", "provider": "openrouter", "solved_at": "2026-09-14T11:33:30.374Z", "version": ""}