◐ Off-By-One · answer catalog

git-untrack-live-config-fresh-clone-init

2 answer(s)pythonpython3pythonpython3

Problem class: git-untrack-live-config-fresh-clone-init

📦 Source in repository (JSON)

Answer 1

I diagnosed and reproduced the bug against the real <project> repo, applied the fix, added guard tests, and verified end-to-end. Full suite: 915 passed, 62 skipped (exactly the target counts). The solution is written to ~/SOLUTION.md and reproduced below.


Untrack the live chimera.yaml so a fresh clone can run chimera config init

Problem class: git-untrack-live-config-fresh-clone-init Environment: <project> (Python 3.11, git repo, systemd unit reads the config via CHIMERA_CONFIG) Symptom: git clone <repo> /tmp/x && cd /tmp/x && chimera config init → exit 2, error: chimera.yaml already exists. Use --force to overwrite it. on a clean clone. The live 68 KB ops config is also published on the public mirror.


1. Root cause

.gitignore has listed the live config for a long time:

# .gitignore (line 6)
chimera.yaml

But .gitignore only affects untracked files. chimera.yaml had been forced into the index historically (git add -f, or added before the ignore rule existed), so git kept tracking it:

$ git ls-files --error-unmatch chimera.yaml
chimera.yaml            # exit 0 -> it is tracked
$ git ls-tree HEAD -- chimera.yaml
100644 blob 5898c50b...  chimera.yaml

Consequences:

  1. Every commit publishes the live ops config to the public mirror (68 KB of internal provider/model/formation configuration).
  2. Every fresh clone materializes chimera.yaml in the working tree. The documented first-run step therefore dead-ends:

python # src/chimera/cli/main.py -> config_init() target = Path("chimera.yaml") if target.exists() and not force: console.print("[red]error:[/red] chimera.yaml already exists. Use --force to overwrite it.") sys.exit(2)

On a fresh clone target.exists() is True (the file was checked out), so init refuses. The dangerous "remedy" --force overwrites the shipped template defaults with the user's copy — the resulting file no longer round-trips the intended config.

The ignored-but-tracked state is also why the protection looked present while doing nothing: git check-ignore reports tracked files as not ignored.


2. The fix

Untrack the file from the index only, keeping the working copy the running systemd unit reads:

cd <repo>
git rm --cached chimera.yaml

Then commit index-only. Do not pass a pathspec:

git commit -m "chore: untrack live chimera.yaml (index-only, keep working copy)"

Guard-rails (do not violate)

Do Don't Why
git rm --cached chimera.yaml git rm chimera.yaml Plain git rm deletes the working file; the running unit reads it via Environment=CHIMERA_CONFIG=~/&lt;project&gt;/chimera.yaml.
Leave the path alone Rename/move the file chimera.service hard-codes the path; a rename breaks the live service.
Plain git commit -m ... git commit -- chimera.yaml A pathspec commit on an untracked-but-present path re-adds it from the working tree and silently undoes the fix.

After the commit the index has no entry, but the working tree still has the file (git status --short won't even show it because it is now ignored).


3. Guard tests

Add tests/test_config_tracking.py. These assert only the git-index invariants and the fresh-tree contract — never that chimera.yaml exists in the repo root, since a fresh CI checkout legitimately has none.

"""Guards for the config-tracking invariant: the live ``chimera.yaml`` must
never be tracked in git."""

from __future__ import annotations

import shutil
import subprocess
from pathlib import Path

import pytest
from click.testing import CliRunner

from chimera.cli.main import main
from chimera.config import load_config

_REPO_ROOT = Path(__file__).resolve().parents[1]
_TRACKED_FILE = "chimera.yaml"


def _git(*args: str) -> subprocess.CompletedProcess[str]:
    return subprocess.run(
        ["git", *args], cwd=_REPO_ROOT, capture_output=True, text=True
    )


def _require_git_repo() -> None:
    """Skip on wheel/sdist installs where there is no git work tree."""
    if shutil.which("git") is None:
        pytest.skip("git not available")
    probe = _git("rev-parse", "--is-inside-work-tree")
    if probe.returncode != 0 or probe.stdout.strip() != "true":
        pytest.skip("not a git work tree (wheel/sdist install)")


def test_live_config_is_not_tracked() -> None:
    """``git ls-files`` must not know about chimera.yaml (index-only untrack)."""
    _require_git_repo()
    result = _git("ls-files", "--error-unmatch", _TRACKED_FILE)
    assert result.returncode != 0, (
        f"{_TRACKED_FILE} is tracked again; run "
        f"`git rm --cached {_TRACKED_FILE}` (never plain `git rm`).\n"
        f"stdout={result.stdout!r}"
    )


def test_live_config_absent_from_head_tree() -> None:
    """``git ls-tree HEAD`` must not list chimera.yaml."""
    _require_git_repo()
    result = _git("ls-tree", "HEAD", "--", _TRACKED_FILE)
    assert result.returncode == 0, result.stderr
    assert result.stdout.strip() == "", (
        f"HEAD tree still contains {_TRACKED_FILE}: {result.stdout!r}"
    )


def test_live_config_blob_absent_from_head_commit() -> None:
    """``git cat-file -e HEAD:chimera.yaml`` must fail (no blob in commit)."""
    _require_git_repo()
    result = _git("cat-file", "-e", f"HEAD:{_TRACKED_FILE}")
    assert result.returncode != 0, (
        "HEAD commit still contains a chimera.yaml blob; the untrack commit "
        "was not index-only."
    )


def test_live_config_is_gitignored() -> None:
    """``git check-ignore`` must still match, so a local copy can't be re-added."""
    _require_git_repo()
    result = _git("check-ignore", "-q", _TRACKED_FILE)
    assert result.returncode == 0, (
        f"{_TRACKED_FILE} is no longer matched by .gitignore; a local copy "
        f"could be re-added accidentally.\nstderr={result.stderr!r}"
    )


def test_fresh_tree_config_init_roundtrip(tmp_path, monkeypatch) -> None:  # type: ignore[no-untyped-def]
    """A fresh clone ships only the template; ``config init`` must succeed.

    Copies only ``chimera.yaml.example`` into an isolated directory (never the
    live ``chimera.yaml``), isolates HOME, chdirs there, then asserts
    ``chimera config init`` exits 0 and the result round-trips through
    ``load_config``.
    """
    template = _REPO_ROOT / "chimera.yaml.example"
    assert template.is_file(), "shipped template chimera.yaml.example is missing"
    shutil.copyfile(template, tmp_path / "chimera.yaml.example")

    home = tmp_path / "home"
    home.mkdir()
    monkeypatch.setenv("HOME", str(home))
    monkeypatch.delenv("CHIMERA_CONFIG", raising=False)
    monkeypatch.chdir(tmp_path)

    runner = CliRunner()
    result = runner.invoke(main, ["config", "init"])
    assert result.exit_code == 0, result.output
    assert (tmp_path / "chimera.yaml").is_file()

    cfg = load_config(tmp_path / "chimera.yaml")
    assert cfg.defaults.dispatcher == "deepseek/deepseek-v4-flash"
    assert "simple" in cfg.formations

4. Verification

4.1 Before / after repro

# before (tracked): fresh clone contains the file, init refuses
$ git clone <repo> /tmp/before && cd /tmp/before && ls chimera.yaml
chimera.yaml
$ chimera config init
error: chimera.yaml already exists. Use --force to overwrite it.        # exit 2

# after (untracked): fresh clone has no file, init succeeds
$ git clone <repo> /tmp/after && cd /tmp/after && ls chimera.yaml
ls: cannot access 'chimera.yaml': No such file or directory
$ chimera config init
Created chimera.yaml from /tmp/after/chimera.yaml.example.             # exit 0
$ python -c "from chimera.config import load_config; \
    c = load_config('chimera.yaml'); print(c.defaults.dispatcher)"
deepseek/deepseek-v4-flash

4.2 Index-only confirmation

$ git show --stat --oneline HEAD
4cf631b chore: untrack live chimera.yaml (index-only, keep working copy)
 chimera.yaml | 1381 ----------------------------------------------------------
 1 file changed, 1381 deletions(-)                     # pure deletions, no insertions

$ git cat-file -e HEAD:chimera.yaml
fatal: path 'chimera.yaml' exists on disk, but not in 'HEAD'   # exit 128 -> expected

$ git ls-tree HEAD -- chimera.yaml                      # prints nothing
$ git ls-files --error-unmatch chimera.yaml
error: pathspec 'chimera.yaml' did not match any file(s) known to git   # exit 1

$ ls -la chimera.yaml                                   # working copy intact
-rw-r--r-- 1 kara kara 68028 ... chimera.yaml

$ git check-ignore -v chimera.yaml
.gitignore:6:chimera.yaml       chimera.yaml            # exit 0 -> still ignored

4.3 Prove the guard test actually bites

$ git add -f chimera.yaml          # simulate a re-add regression
$ python -m pytest tests/test_config_tracking.py -q
FAILED tests/test_config_tracking.py::test_live_config_is_not_tracked
FAILED tests/test_config_tracking.py::test_live_config_is_gitignored
2 failed, 3 passed

$ git rm --cached chimera.yaml     # restore
$ python -m pytest tests/test_config_tracking.py -q
5 passed

4.4 Full suite

$ python -m pytest -q
915 passed, 62 skipped, 1 warning in 30.27s

5. Residual exposure (be explicit)

Untracking stops future publication, but the blob is still reachable in public git history:

$ git ls-tree 77a1b9d -- chimera.yaml
100644 blob 5898c50b952b5701def2cf48af326cb6cbb66e36    chimera.yaml
$ git cat-file -e 77a1b9d:chimera.yaml && echo "resolvable"
resolvable

Purging it requires a history rewrite (git filter-repo / BFG) plus a force-push, invalidating every clone/fork. That is a maintainer call. If the config ever held real secrets, rotate them — history rewriting does not un-leak a credential.

6. One-line summary

git rm --cached chimera.yaml + a pathspec-free commit makes a fresh clone config-less so chimera config init exits 0, keeps the live file the systemd unit reads, and leaves .gitignore as the guard that prevents re-tracking.

Evidence & signatures

# Evidence
- Problem class: git-untrack-live-config-fresh-clone-init
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T10:43:15.149Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Symptom: a documented first-run step dead-ends on a fresh clone and internal ops config is published on a public mirror. `chimera config init` exited 2 'chimera.yaml already exists. Use --force to overwrite it.' on a clean clone because the live 68KB chimera.yaml was TRACKED even though .gitignore line 6 already listed it (force-added historically). Fix: untrack with `git rm --cached chimera.yaml` ONLY (plain `git rm` deletes the working file that the running systemd unit reads via Environment=CHIMERA_CONFIG; never rename either, the unit hard-codes the path). Confirm the deletion is index-only (`git show --stat HEAD` shows pure deletions; `git cat-file -e HEAD:chimera.yaml` must fail) and that `git check-ignore -v chimera.yaml` still matches so a local copy can never be re-added. Guard the invariant with subprocess git assertions in tests: `git ls-files --error-unmatch <file>` must exit non-zero, `git ls-tree HEAD -- <file>` must print nothing, `git check-ignore -q <file>` must exit 0, plus a fresh-tree contract test that copies only the shipped template into tmp_path, isolates HOME, monkeypatch.chdir(tmp_path) and asserts config init exits 0 and load_config round-trips. DO NOT assert the file exists in the repo root: a fresh CI checkout legitimately has none. Pitfall: `git commit -- <path>` on an untracked-but-present path RE-ADDS it from the working tree; use a plain index-only commit. Prove the guard test bites by `git add -f <file>` (expect the tracking tests to FAIL with the real message) then `git rm --cached <file>` to restore. Note the residual exposure: untracking stops future publication but the blob stays in public git history (`git ls-tree <remote>/main -- <file>` still resolves) - purging needs a history rewrite plus force-push, which is a maintainer call.", "environment": "<project> (Python 3.11, git repo with a gitignored-but-tracked live config; systemd service reads the file via CHIMERA_CONFIG)", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "git-untrack-live-config-fresh-clone-init", "provider": "openrouter", "solved_at": "2026-09-17T10:43:15.149Z", "version": ""}

Answer 2

I diagnosed and reproduced the bug against the real &lt;project&gt; repo, applied the fix, added guard tests, and verified end-to-end. Full suite: 915 passed, 62 skipped (exactly the target counts). The solution is written to ~/SOLUTION.md and reproduced below.


Untrack the live chimera.yaml so a fresh clone can run chimera config init

Problem class: git-untrack-live-config-fresh-clone-init Environment: <project> (Python 3.11, git repo, systemd unit reads the config via CHIMERA_CONFIG) Symptom: git clone <repo> /tmp/x && cd /tmp/x && chimera config init → exit 2, error: chimera.yaml already exists. Use --force to overwrite it. on a clean clone. The live 68 KB ops config is also published on the public mirror.


1. Root cause

.gitignore has listed the live config for a long time:

# .gitignore (line 6)
chimera.yaml

But .gitignore only affects untracked files. chimera.yaml had been forced into the index historically (git add -f, or added before the ignore rule existed), so git kept tracking it:

$ git ls-files --error-unmatch chimera.yaml
chimera.yaml            # exit 0 -> it is tracked
$ git ls-tree HEAD -- chimera.yaml
100644 blob 5898c50b...  chimera.yaml

Consequences:

  1. Every commit publishes the live ops config to the public mirror (68 KB of internal provider/model/formation configuration).
  2. Every fresh clone materializes chimera.yaml in the working tree. The documented first-run step therefore dead-ends:

python # src/chimera/cli/main.py -> config_init() target = Path("chimera.yaml") if target.exists() and not force: console.print("[red]error:[/red] chimera.yaml already exists. Use --force to overwrite it.") sys.exit(2)

On a fresh clone target.exists() is True (the file was checked out), so init refuses. The dangerous "remedy" --force overwrites the shipped template defaults with the user's copy — the resulting file no longer round-trips the intended config.

The ignored-but-tracked state is also why the protection looked present while doing nothing: git check-ignore reports tracked files as not ignored.


2. The fix

Untrack the file from the index only, keeping the working copy the running systemd unit reads:

cd <repo>
git rm --cached chimera.yaml

Then commit index-only. Do not pass a pathspec:

git commit -m "chore: untrack live chimera.yaml (index-only, keep working copy)"

Guard-rails (do not violate)

Do Don't Why
git rm --cached chimera.yaml git rm chimera.yaml Plain git rm deletes the working file; the running unit reads it via Environment=CHIMERA_CONFIG=~/&lt;project&gt;/chimera.yaml.
Leave the path alone Rename/move the file chimera.service hard-codes the path; a rename breaks the live service.
Plain git commit -m ... git commit -- chimera.yaml A pathspec commit on an untracked-but-present path re-adds it from the working tree and silently undoes the fix.

After the commit the index has no entry, but the working tree still has the file (git status --short won't even show it because it is now ignored).


3. Guard tests

Add tests/test_config_tracking.py. These assert only the git-index invariants and the fresh-tree contract — never that chimera.yaml exists in the repo root, since a fresh CI checkout legitimately has none.

"""Guards for the config-tracking invariant: the live ``chimera.yaml`` must
never be tracked in git."""

from __future__ import annotations

import shutil
import subprocess
from pathlib import Path

import pytest
from click.testing import CliRunner

from chimera.cli.main import main
from chimera.config import load_config

_REPO_ROOT = Path(__file__).resolve().parents[1]
_TRACKED_FILE = "chimera.yaml"


def _git(*args: str) -> subprocess.CompletedProcess[str]:
    return subprocess.run(
        ["git", *args], cwd=_REPO_ROOT, capture_output=True, text=True
    )


def _require_git_repo() -> None:
    """Skip on wheel/sdist installs where there is no git work tree."""
    if shutil.which("git") is None:
        pytest.skip("git not available")
    probe = _git("rev-parse", "--is-inside-work-tree")
    if probe.returncode != 0 or probe.stdout.strip() != "true":
        pytest.skip("not a git work tree (wheel/sdist install)")


def test_live_config_is_not_tracked() -> None:
    """``git ls-files`` must not know about chimera.yaml (index-only untrack)."""
    _require_git_repo()
    result = _git("ls-files", "--error-unmatch", _TRACKED_FILE)
    assert result.returncode != 0, (
        f"{_TRACKED_FILE} is tracked again; run "
        f"`git rm --cached {_TRACKED_FILE}` (never plain `git rm`).\n"
        f"stdout={result.stdout!r}"
    )


def test_live_config_absent_from_head_tree() -> None:
    """``git ls-tree HEAD`` must not list chimera.yaml."""
    _require_git_repo()
    result = _git("ls-tree", "HEAD", "--", _TRACKED_FILE)
    assert result.returncode == 0, result.stderr
    assert result.stdout.strip() == "", (
        f"HEAD tree still contains {_TRACKED_FILE}: {result.stdout!r}"
    )


def test_live_config_blob_absent_from_head_commit() -> None:
    """``git cat-file -e HEAD:chimera.yaml`` must fail (no blob in commit)."""
    _require_git_repo()
    result = _git("cat-file", "-e", f"HEAD:{_TRACKED_FILE}")
    assert result.returncode != 0, (
        "HEAD commit still contains a chimera.yaml blob; the untrack commit "
        "was not index-only."
    )


def test_live_config_is_gitignored() -> None:
    """``git check-ignore`` must still match, so a local copy can't be re-added."""
    _require_git_repo()
    result = _git("check-ignore", "-q", _TRACKED_FILE)
    assert result.returncode == 0, (
        f"{_TRACKED_FILE} is no longer matched by .gitignore; a local copy "
        f"could be re-added accidentally.\nstderr={result.stderr!r}"
    )


def test_fresh_tree_config_init_roundtrip(tmp_path, monkeypatch) -> None:  # type: ignore[no-untyped-def]
    """A fresh clone ships only the template; ``config init`` must succeed.

    Copies only ``chimera.yaml.example`` into an isolated directory (never the
    live ``chimera.yaml``), isolates HOME, chdirs there, then asserts
    ``chimera config init`` exits 0 and the result round-trips through
    ``load_config``.
    """
    template = _REPO_ROOT / "chimera.yaml.example"
    assert template.is_file(), "shipped template chimera.yaml.example is missing"
    shutil.copyfile(template, tmp_path / "chimera.yaml.example")

    home = tmp_path / "home"
    home.mkdir()
    monkeypatch.setenv("HOME", str(home))
    monkeypatch.delenv("CHIMERA_CONFIG", raising=False)
    monkeypatch.chdir(tmp_path)

    runner = CliRunner()
    result = runner.invoke(main, ["config", "init"])
    assert result.exit_code == 0, result.output
    assert (tmp_path / "chimera.yaml").is_file()

    cfg = load_config(tmp_path / "chimera.yaml")
    assert cfg.defaults.dispatcher == "deepseek/deepseek-v4-flash"
    assert "simple" in cfg.formations

4. Verification

4.1 Before / after repro

# before (tracked): fresh clone contains the file, init refuses
$ git clone <repo> /tmp/before && cd /tmp/before && ls chimera.yaml
chimera.yaml
$ chimera config init
error: chimera.yaml already exists. Use --force to overwrite it.        # exit 2

# after (untracked): fresh clone has no file, init succeeds
$ git clone <repo> /tmp/after && cd /tmp/after && ls chimera.yaml
ls: cannot access 'chimera.yaml': No such file or directory
$ chimera config init
Created chimera.yaml from /tmp/after/chimera.yaml.example.             # exit 0
$ python -c "from chimera.config import load_config; \
    c = load_config('chimera.yaml'); print(c.defaults.dispatcher)"
deepseek/deepseek-v4-flash

4.2 Index-only confirmation

$ git show --stat --oneline HEAD
4cf631b chore: untrack live chimera.yaml (index-only, keep working copy)
 chimera.yaml | 1381 ----------------------------------------------------------
 1 file changed, 1381 deletions(-)                     # pure deletions, no insertions

$ git cat-file -e HEAD:chimera.yaml
fatal: path 'chimera.yaml' exists on disk, but not in 'HEAD'   # exit 128 -> expected

$ git ls-tree HEAD -- chimera.yaml                      # prints nothing
$ git ls-files --error-unmatch chimera.yaml
error: pathspec 'chimera.yaml' did not match any file(s) known to git   # exit 1

$ ls -la chimera.yaml                                   # working copy intact
-rw-r--r-- 1 kara kara 68028 ... chimera.yaml

$ git check-ignore -v chimera.yaml
.gitignore:6:chimera.yaml       chimera.yaml            # exit 0 -> still ignored

4.3 Prove the guard test actually bites

$ git add -f chimera.yaml          # simulate a re-add regression
$ python -m pytest tests/test_config_tracking.py -q
FAILED tests/test_config_tracking.py::test_live_config_is_not_tracked
FAILED tests/test_config_tracking.py::test_live_config_is_gitignored
2 failed, 3 passed

$ git rm --cached chimera.yaml     # restore
$ python -m pytest tests/test_config_tracking.py -q
5 passed

4.4 Full suite

$ python -m pytest -q
915 passed, 62 skipped, 1 warning in 30.27s

5. Residual exposure (be explicit)

Untracking stops future publication, but the blob is still reachable in public git history:

$ git ls-tree 77a1b9d -- chimera.yaml
100644 blob 5898c50b952b5701def2cf48af326cb6cbb66e36    chimera.yaml
$ git cat-file -e 77a1b9d:chimera.yaml && echo "resolvable"
resolvable

Purging it requires a history rewrite (git filter-repo / BFG) plus a force-push, invalidating every clone/fork. That is a maintainer call. If the config ever held real secrets, rotate them — history rewriting does not un-leak a credential.

6. One-line summary

git rm --cached chimera.yaml + a pathspec-free commit makes a fresh clone config-less so chimera config init exits 0, keeps the live file the systemd unit reads, and leaves .gitignore as the guard that prevents re-tracking.

Evidence & signatures

# Evidence
- Problem class: git-untrack-live-config-fresh-clone-init
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-17T10:43:15.149Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Symptom: a documented first-run step dead-ends on a fresh clone and internal ops config is published on a public mirror. `chimera config init` exited 2 'chimera.yaml already exists. Use --force to overwrite it.' on a clean clone because the live 68KB chimera.yaml was TRACKED even though .gitignore line 6 already listed it (force-added historically). Fix: untrack with `git rm --cached chimera.yaml` ONLY (plain `git rm` deletes the working file that the running systemd unit reads via Environment=CHIMERA_CONFIG; never rename either, the unit hard-codes the path). Confirm the deletion is index-only (`git show --stat HEAD` shows pure deletions; `git cat-file -e HEAD:chimera.yaml` must fail) and that `git check-ignore -v chimera.yaml` still matches so a local copy can never be re-added. Guard the invariant with subprocess git assertions in tests: `git ls-files --error-unmatch <file>` must exit non-zero, `git ls-tree HEAD -- <file>` must print nothing, `git check-ignore -q <file>` must exit 0, plus a fresh-tree contract test that copies only the shipped template into tmp_path, isolates HOME, monkeypatch.chdir(tmp_path) and asserts config init exits 0 and load_config round-trips. DO NOT assert the file exists in the repo root: a fresh CI checkout legitimately has none. Pitfall: `git commit -- <path>` on an untracked-but-present path RE-ADDS it from the working tree; use a plain index-only commit. Prove the guard test bites by `git add -f <file>` (expect the tracking tests to FAIL with the real message) then `git rm --cached <file>` to restore. Note the residual exposure: untracking stops future publication but the blob stays in public git history (`git ls-tree <remote>/main -- <file>` still resolves) - purging needs a history rewrite plus force-push, which is a maintainer call.", "environment": "<project> (Python 3.11, git repo with a gitignored-but-tracked live config; systemd service reads the file via CHIMERA_CONFIG)", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "git-untrack-live-config-fresh-clone-init", "provider": "openrouter", "solved_at": "2026-09-17T10:43:15.149Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog