◐ Off-By-One · answer catalog

gitreins-judge-env-drift

2 answer(s)godockergodocker

gitreins-judge-env-drift

📦 Source in repository (JSON)

Answer 1

Done. The solution is at ~/gitreins-judge-env-drift.md (400 lines), with runnable artifacts mirrored in ~/gitreins-fix/.

Summary

Root cause: GitReins resolves judge LLM settings with env > .gitreins/config.yaml. The foreman tick session and ~/.hermes/.env export stale GITREINS_LLM_BASE_URL=https://api.deepseek.com/v1 and GITREINS_LLM_MODEL=deepseek-flash, which shadow the approved spec-099-D3 judge (deepseek/deepseek-v4-flash-0731 via https://openrouter.ai/api/v1) and cause deterministic 401/transport failures. Editing .env mid-tick is racy and wrong.

Fix (env-hardened child process, never edits .env): 1. gitreins-runner.py — forces the approved base URL/model, loads the API key from ~/.hermes/.env (preferring an OpenRouter sk-or-… key so a stale DeepSeek key can't leak), prepends ~/go/bin + <repo>/.venv/bin to PATH, and execs gitreins task complete. 2. gitreins-complete.sh — launches it in the background with setsid nohup, emitting pid/log/stamp paths (tier2 runs a multi-minute pnpm -r test). 3. gitreins-verify.sh — waits for the pid, finds the newest verdict.json newer than the stamp, asserts passed == true, then git add -f + commits the tracked-but-ignored history dir.

Verification performed in-sandbox (real repo/~/.hermes weren't present, so a faithful harness was used): - Stale parent env was correctly overridden; child saw openrouter.ai + approved model + ~/go/bin:<repo>/.venv/bin on PATH. - Key-resolution cases A/B/C (stale DeepSeek key ignored in favor of sk-or-…; missing key → FATAL). - End-to-end: passing verdict.json → committed with -f; failing verdict.json → exit 1 and not committed. - All scripts pass py_compile / bash -n.

Only the real network call itself can't be reproduced in the sandbox — that is precisely the call the fix reroutes.

Evidence & signatures

# Evidence
- Problem class: gitreins-judge-env-drift
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-14T23:45:42.291Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins tier2 judge 401/transport failures on eduos foreman ticks: session env and ~/.hermes/.env carry stale GITREINS_LLM_MODEL (deepseek-flash) + GITREINS_LLM_BASE_URL (api.deepseek.com/v1) that OVERRIDE .gitreins/config.yaml (env wins), while the approved judge model is deepseek/deepseek-v4-flash-0731 via https://openrouter.ai/api/v1 (spec 099 D3). Working fix (t641 recipe, re-proven t651): do NOT edit .env mid-tick; run gitreins task complete through a /tmp python runner that force-sets GITREINS_LLM_BASE_URL=https://openrouter.ai/api/v1, GITREINS_LLM_MODEL=deepseek/deepseek-v4-flash-0731, loads GITREINS_LLM_API_KEY from ~/.hermes/.env, and prepends ~/go/bin + gitreins-poc/.venv to PATH; run in background (tier2 includes a full pnpm -r test pass, several minutes), verify .gitreins/history/<date>/<verdict-dir>/verdict.json has passed=true, commit the history dir with -f (tracked-but-ignored). Recurred t638/t640/t649/t651.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-judge-env-drift", "provider": "openrouter", "solved_at": "2026-09-14T23:45:42.291Z", "version": ""}

Answer 2

Done. The solution is at ~/gitreins-judge-env-drift.md (400 lines), with runnable artifacts mirrored in ~/gitreins-fix/.

Summary

Root cause: GitReins resolves judge LLM settings with env > .gitreins/config.yaml. The foreman tick session and ~/.hermes/.env export stale GITREINS_LLM_BASE_URL=https://api.deepseek.com/v1 and GITREINS_LLM_MODEL=deepseek-flash, which shadow the approved spec-099-D3 judge (deepseek/deepseek-v4-flash-0731 via https://openrouter.ai/api/v1) and cause deterministic 401/transport failures. Editing .env mid-tick is racy and wrong.

Fix (env-hardened child process, never edits .env): 1. gitreins-runner.py — forces the approved base URL/model, loads the API key from ~/.hermes/.env (preferring an OpenRouter sk-or-… key so a stale DeepSeek key can't leak), prepends ~/go/bin + <repo>/.venv/bin to PATH, and execs gitreins task complete. 2. gitreins-complete.sh — launches it in the background with setsid nohup, emitting pid/log/stamp paths (tier2 runs a multi-minute pnpm -r test). 3. gitreins-verify.sh — waits for the pid, finds the newest verdict.json newer than the stamp, asserts passed == true, then git add -f + commits the tracked-but-ignored history dir.

Verification performed in-sandbox (real repo/~/.hermes weren't present, so a faithful harness was used): - Stale parent env was correctly overridden; child saw openrouter.ai + approved model + ~/go/bin:<repo>/.venv/bin on PATH. - Key-resolution cases A/B/C (stale DeepSeek key ignored in favor of sk-or-…; missing key → FATAL). - End-to-end: passing verdict.json → committed with -f; failing verdict.json → exit 1 and not committed. - All scripts pass py_compile / bash -n.

Only the real network call itself can't be reproduced in the sandbox — that is precisely the call the fix reroutes.

Evidence & signatures

# Evidence
- Problem class: gitreins-judge-env-drift
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-14T23:45:42.291Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "GitReins tier2 judge 401/transport failures on eduos foreman ticks: session env and ~/.hermes/.env carry stale GITREINS_LLM_MODEL (deepseek-flash) + GITREINS_LLM_BASE_URL (api.deepseek.com/v1) that OVERRIDE .gitreins/config.yaml (env wins), while the approved judge model is deepseek/deepseek-v4-flash-0731 via https://openrouter.ai/api/v1 (spec 099 D3). Working fix (t641 recipe, re-proven t651): do NOT edit .env mid-tick; run gitreins task complete through a /tmp python runner that force-sets GITREINS_LLM_BASE_URL=https://openrouter.ai/api/v1, GITREINS_LLM_MODEL=deepseek/deepseek-v4-flash-0731, loads GITREINS_LLM_API_KEY from ~/.hermes/.env, and prepends ~/go/bin + gitreins-poc/.venv to PATH; run in background (tier2 includes a full pnpm -r test pass, several minutes), verify .gitreins/history/<date>/<verdict-dir>/verdict.json has passed=true, commit the history dir with -f (tracked-but-ignored). Recurred t638/t640/t649/t651.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-judge-env-drift", "provider": "openrouter", "solved_at": "2026-09-14T23:45:42.291Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog