Problem class: git-untrack-live-config-fresh-clone-init
I diagnosed and reproduced the bug against the real <project> repo, applied the fix, added guard tests, and verified end-to-end. Full suite: 915 passed, 62 skipped (exactly the target counts). The solution is written to ~/SOLUTION.md and reproduced below.
chimera.yaml so a fresh clone can run chimera config initProblem class: git-untrack-live-config-fresh-clone-init
Environment: <project> (Python 3.11, git repo, systemd unit reads the config via CHIMERA_CONFIG)
Symptom: git clone <repo> /tmp/x && cd /tmp/x && chimera config init → exit 2, error: chimera.yaml already exists. Use --force to overwrite it. on a clean clone. The live 68 KB ops config is also published on the public mirror.
.gitignore has listed the live config for a long time:
# .gitignore (line 6)
chimera.yaml
But .gitignore only affects untracked files. chimera.yaml had been forced into the index historically (git add -f, or added before the ignore rule existed), so git kept tracking it:
$ git ls-files --error-unmatch chimera.yaml
chimera.yaml # exit 0 -> it is tracked
$ git ls-tree HEAD -- chimera.yaml
100644 blob 5898c50b... chimera.yaml
Consequences:
chimera.yaml in the working tree. The documented first-run step therefore dead-ends:python
# src/chimera/cli/main.py -> config_init()
target = Path("chimera.yaml")
if target.exists() and not force:
console.print("[red]error:[/red] chimera.yaml already exists. Use --force to overwrite it.")
sys.exit(2)
On a fresh clone target.exists() is True (the file was checked out), so init refuses. The dangerous "remedy" --force overwrites the shipped template defaults with the user's copy — the resulting file no longer round-trips the intended config.
The ignored-but-tracked state is also why the protection looked present while doing nothing: git check-ignore reports tracked files as not ignored.
Untrack the file from the index only, keeping the working copy the running systemd unit reads:
cd <repo>
git rm --cached chimera.yaml
Then commit index-only. Do not pass a pathspec:
git commit -m "chore: untrack live chimera.yaml (index-only, keep working copy)"
| Do | Don't | Why |
|---|---|---|
git rm --cached chimera.yaml |
git rm chimera.yaml |
Plain git rm deletes the working file; the running unit reads it via Environment=CHIMERA_CONFIG=~/<project>/chimera.yaml. |
| Leave the path alone | Rename/move the file | chimera.service hard-codes the path; a rename breaks the live service. |
Plain git commit -m ... |
git commit -- chimera.yaml |
A pathspec commit on an untracked-but-present path re-adds it from the working tree and silently undoes the fix. |
After the commit the index has no entry, but the working tree still has the file (git status --short won't even show it because it is now ignored).
Add tests/test_config_tracking.py. These assert only the git-index invariants and the fresh-tree contract — never that chimera.yaml exists in the repo root, since a fresh CI checkout legitimately has none.
"""Guards for the config-tracking invariant: the live ``chimera.yaml`` must
never be tracked in git."""
from __future__ import annotations
import shutil
import subprocess
from pathlib import Path
import pytest
from click.testing import CliRunner
from chimera.cli.main import main
from chimera.config import load_config
_REPO_ROOT = Path(__file__).resolve().parents[1]
_TRACKED_FILE = "chimera.yaml"
def _git(*args: str) -> subprocess.CompletedProcess[str]:
return subprocess.run(
["git", *args], cwd=_REPO_ROOT, capture_output=True, text=True
)
def _require_git_repo() -> None:
"""Skip on wheel/sdist installs where there is no git work tree."""
if shutil.which("git") is None:
pytest.skip("git not available")
probe = _git("rev-parse", "--is-inside-work-tree")
if probe.returncode != 0 or probe.stdout.strip() != "true":
pytest.skip("not a git work tree (wheel/sdist install)")
def test_live_config_is_not_tracked() -> None:
"""``git ls-files`` must not know about chimera.yaml (index-only untrack)."""
_require_git_repo()
result = _git("ls-files", "--error-unmatch", _TRACKED_FILE)
assert result.returncode != 0, (
f"{_TRACKED_FILE} is tracked again; run "
f"`git rm --cached {_TRACKED_FILE}` (never plain `git rm`).\n"
f"stdout={result.stdout!r}"
)
def test_live_config_absent_from_head_tree() -> None:
"""``git ls-tree HEAD`` must not list chimera.yaml."""
_require_git_repo()
result = _git("ls-tree", "HEAD", "--", _TRACKED_FILE)
assert result.returncode == 0, result.stderr
assert result.stdout.strip() == "", (
f"HEAD tree still contains {_TRACKED_FILE}: {result.stdout!r}"
)
def test_live_config_blob_absent_from_head_commit() -> None:
"""``git cat-file -e HEAD:chimera.yaml`` must fail (no blob in commit)."""
_require_git_repo()
result = _git("cat-file", "-e", f"HEAD:{_TRACKED_FILE}")
assert result.returncode != 0, (
"HEAD commit still contains a chimera.yaml blob; the untrack commit "
"was not index-only."
)
def test_live_config_is_gitignored() -> None:
"""``git check-ignore`` must still match, so a local copy can't be re-added."""
_require_git_repo()
result = _git("check-ignore", "-q", _TRACKED_FILE)
assert result.returncode == 0, (
f"{_TRACKED_FILE} is no longer matched by .gitignore; a local copy "
f"could be re-added accidentally.\nstderr={result.stderr!r}"
)
def test_fresh_tree_config_init_roundtrip(tmp_path, monkeypatch) -> None: # type: ignore[no-untyped-def]
"""A fresh clone ships only the template; ``config init`` must succeed.
Copies only ``chimera.yaml.example`` into an isolated directory (never the
live ``chimera.yaml``), isolates HOME, chdirs there, then asserts
``chimera config init`` exits 0 and the result round-trips through
``load_config``.
"""
template = _REPO_ROOT / "chimera.yaml.example"
assert template.is_file(), "shipped template chimera.yaml.example is missing"
shutil.copyfile(template, tmp_path / "chimera.yaml.example")
home = tmp_path / "home"
home.mkdir()
monkeypatch.setenv("HOME", str(home))
monkeypatch.delenv("CHIMERA_CONFIG", raising=False)
monkeypatch.chdir(tmp_path)
runner = CliRunner()
result = runner.invoke(main, ["config", "init"])
assert result.exit_code == 0, result.output
assert (tmp_path / "chimera.yaml").is_file()
cfg = load_config(tmp_path / "chimera.yaml")
assert cfg.defaults.dispatcher == "deepseek/deepseek-v4-flash"
assert "simple" in cfg.formations
# before (tracked): fresh clone contains the file, init refuses
$ git clone <repo> /tmp/before && cd /tmp/before && ls chimera.yaml
chimera.yaml
$ chimera config init
error: chimera.yaml already exists. Use --force to overwrite it. # exit 2
# after (untracked): fresh clone has no file, init succeeds
$ git clone <repo> /tmp/after && cd /tmp/after && ls chimera.yaml
ls: cannot access 'chimera.yaml': No such file or directory
$ chimera config init
Created chimera.yaml from /tmp/after/chimera.yaml.example. # exit 0
$ python -c "from chimera.config import load_config; \
c = load_config('chimera.yaml'); print(c.defaults.dispatcher)"
deepseek/deepseek-v4-flash
$ git show --stat --oneline HEAD
4cf631b chore: untrack live chimera.yaml (index-only, keep working copy)
chimera.yaml | 1381 ----------------------------------------------------------
1 file changed, 1381 deletions(-) # pure deletions, no insertions
$ git cat-file -e HEAD:chimera.yaml
fatal: path 'chimera.yaml' exists on disk, but not in 'HEAD' # exit 128 -> expected
$ git ls-tree HEAD -- chimera.yaml # prints nothing
$ git ls-files --error-unmatch chimera.yaml
error: pathspec 'chimera.yaml' did not match any file(s) known to git # exit 1
$ ls -la chimera.yaml # working copy intact
-rw-r--r-- 1 kara kara 68028 ... chimera.yaml
$ git check-ignore -v chimera.yaml
.gitignore:6:chimera.yaml chimera.yaml # exit 0 -> still ignored
$ git add -f chimera.yaml # simulate a re-add regression
$ python -m pytest tests/test_config_tracking.py -q
FAILED tests/test_config_tracking.py::test_live_config_is_not_tracked
FAILED tests/test_config_tracking.py::test_live_config_is_gitignored
2 failed, 3 passed
$ git rm --cached chimera.yaml # restore
$ python -m pytest tests/test_config_tracking.py -q
5 passed
$ python -m pytest -q
915 passed, 62 skipped, 1 warning in 30.27s
Untracking stops future publication, but the blob is still reachable in public git history:
$ git ls-tree 77a1b9d -- chimera.yaml
100644 blob 5898c50b952b5701def2cf48af326cb6cbb66e36 chimera.yaml
$ git cat-file -e 77a1b9d:chimera.yaml && echo "resolvable"
resolvable
Purging it requires a history rewrite (git filter-repo / BFG) plus a force-push, invalidating every clone/fork. That is a maintainer call. If the config ever held real secrets, rotate them — history rewriting does not un-leak a credential.
git rm --cached chimera.yaml + a pathspec-free commit makes a fresh clone config-less so chimera config init exits 0, keeps the live file the systemd unit reads, and leaves .gitignore as the guard that prevents re-tracking.
# Evidence - Problem class: git-untrack-live-config-fresh-clone-init - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T10:43:15.149Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Symptom: a documented first-run step dead-ends on a fresh clone and internal ops config is published on a public mirror. `chimera config init` exited 2 'chimera.yaml already exists. Use --force to overwrite it.' on a clean clone because the live 68KB chimera.yaml was TRACKED even though .gitignore line 6 already listed it (force-added historically). Fix: untrack with `git rm --cached chimera.yaml` ONLY (plain `git rm` deletes the working file that the running systemd unit reads via Environment=CHIMERA_CONFIG; never rename either, the unit hard-codes the path). Confirm the deletion is index-only (`git show --stat HEAD` shows pure deletions; `git cat-file -e HEAD:chimera.yaml` must fail) and that `git check-ignore -v chimera.yaml` still matches so a local copy can never be re-added. Guard the invariant with subprocess git assertions in tests: `git ls-files --error-unmatch <file>` must exit non-zero, `git ls-tree HEAD -- <file>` must print nothing, `git check-ignore -q <file>` must exit 0, plus a fresh-tree contract test that copies only the shipped template into tmp_path, isolates HOME, monkeypatch.chdir(tmp_path) and asserts config init exits 0 and load_config round-trips. DO NOT assert the file exists in the repo root: a fresh CI checkout legitimately has none. Pitfall: `git commit -- <path>` on an untracked-but-present path RE-ADDS it from the working tree; use a plain index-only commit. Prove the guard test bites by `git add -f <file>` (expect the tracking tests to FAIL with the real message) then `git rm --cached <file>` to restore. Note the residual exposure: untracking stops future publication but the blob stays in public git history (`git ls-tree <remote>/main -- <file>` still resolves) - purging needs a history rewrite plus force-push, which is a maintainer call.", "environment": "<project> (Python 3.11, git repo with a gitignored-but-tracked live config; systemd service reads the file via CHIMERA_CONFIG)", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "git-untrack-live-config-fresh-clone-init", "provider": "openrouter", "solved_at": "2026-09-17T10:43:15.149Z", "version": ""}I diagnosed and reproduced the bug against the real <project> repo, applied the fix, added guard tests, and verified end-to-end. Full suite: 915 passed, 62 skipped (exactly the target counts). The solution is written to ~/SOLUTION.md and reproduced below.
chimera.yaml so a fresh clone can run chimera config initProblem class: git-untrack-live-config-fresh-clone-init
Environment: <project> (Python 3.11, git repo, systemd unit reads the config via CHIMERA_CONFIG)
Symptom: git clone <repo> /tmp/x && cd /tmp/x && chimera config init → exit 2, error: chimera.yaml already exists. Use --force to overwrite it. on a clean clone. The live 68 KB ops config is also published on the public mirror.
.gitignore has listed the live config for a long time:
# .gitignore (line 6)
chimera.yaml
But .gitignore only affects untracked files. chimera.yaml had been forced into the index historically (git add -f, or added before the ignore rule existed), so git kept tracking it:
$ git ls-files --error-unmatch chimera.yaml
chimera.yaml # exit 0 -> it is tracked
$ git ls-tree HEAD -- chimera.yaml
100644 blob 5898c50b... chimera.yaml
Consequences:
chimera.yaml in the working tree. The documented first-run step therefore dead-ends:python
# src/chimera/cli/main.py -> config_init()
target = Path("chimera.yaml")
if target.exists() and not force:
console.print("[red]error:[/red] chimera.yaml already exists. Use --force to overwrite it.")
sys.exit(2)
On a fresh clone target.exists() is True (the file was checked out), so init refuses. The dangerous "remedy" --force overwrites the shipped template defaults with the user's copy — the resulting file no longer round-trips the intended config.
The ignored-but-tracked state is also why the protection looked present while doing nothing: git check-ignore reports tracked files as not ignored.
Untrack the file from the index only, keeping the working copy the running systemd unit reads:
cd <repo>
git rm --cached chimera.yaml
Then commit index-only. Do not pass a pathspec:
git commit -m "chore: untrack live chimera.yaml (index-only, keep working copy)"
| Do | Don't | Why |
|---|---|---|
git rm --cached chimera.yaml |
git rm chimera.yaml |
Plain git rm deletes the working file; the running unit reads it via Environment=CHIMERA_CONFIG=~/<project>/chimera.yaml. |
| Leave the path alone | Rename/move the file | chimera.service hard-codes the path; a rename breaks the live service. |
Plain git commit -m ... |
git commit -- chimera.yaml |
A pathspec commit on an untracked-but-present path re-adds it from the working tree and silently undoes the fix. |
After the commit the index has no entry, but the working tree still has the file (git status --short won't even show it because it is now ignored).
Add tests/test_config_tracking.py. These assert only the git-index invariants and the fresh-tree contract — never that chimera.yaml exists in the repo root, since a fresh CI checkout legitimately has none.
"""Guards for the config-tracking invariant: the live ``chimera.yaml`` must
never be tracked in git."""
from __future__ import annotations
import shutil
import subprocess
from pathlib import Path
import pytest
from click.testing import CliRunner
from chimera.cli.main import main
from chimera.config import load_config
_REPO_ROOT = Path(__file__).resolve().parents[1]
_TRACKED_FILE = "chimera.yaml"
def _git(*args: str) -> subprocess.CompletedProcess[str]:
return subprocess.run(
["git", *args], cwd=_REPO_ROOT, capture_output=True, text=True
)
def _require_git_repo() -> None:
"""Skip on wheel/sdist installs where there is no git work tree."""
if shutil.which("git") is None:
pytest.skip("git not available")
probe = _git("rev-parse", "--is-inside-work-tree")
if probe.returncode != 0 or probe.stdout.strip() != "true":
pytest.skip("not a git work tree (wheel/sdist install)")
def test_live_config_is_not_tracked() -> None:
"""``git ls-files`` must not know about chimera.yaml (index-only untrack)."""
_require_git_repo()
result = _git("ls-files", "--error-unmatch", _TRACKED_FILE)
assert result.returncode != 0, (
f"{_TRACKED_FILE} is tracked again; run "
f"`git rm --cached {_TRACKED_FILE}` (never plain `git rm`).\n"
f"stdout={result.stdout!r}"
)
def test_live_config_absent_from_head_tree() -> None:
"""``git ls-tree HEAD`` must not list chimera.yaml."""
_require_git_repo()
result = _git("ls-tree", "HEAD", "--", _TRACKED_FILE)
assert result.returncode == 0, result.stderr
assert result.stdout.strip() == "", (
f"HEAD tree still contains {_TRACKED_FILE}: {result.stdout!r}"
)
def test_live_config_blob_absent_from_head_commit() -> None:
"""``git cat-file -e HEAD:chimera.yaml`` must fail (no blob in commit)."""
_require_git_repo()
result = _git("cat-file", "-e", f"HEAD:{_TRACKED_FILE}")
assert result.returncode != 0, (
"HEAD commit still contains a chimera.yaml blob; the untrack commit "
"was not index-only."
)
def test_live_config_is_gitignored() -> None:
"""``git check-ignore`` must still match, so a local copy can't be re-added."""
_require_git_repo()
result = _git("check-ignore", "-q", _TRACKED_FILE)
assert result.returncode == 0, (
f"{_TRACKED_FILE} is no longer matched by .gitignore; a local copy "
f"could be re-added accidentally.\nstderr={result.stderr!r}"
)
def test_fresh_tree_config_init_roundtrip(tmp_path, monkeypatch) -> None: # type: ignore[no-untyped-def]
"""A fresh clone ships only the template; ``config init`` must succeed.
Copies only ``chimera.yaml.example`` into an isolated directory (never the
live ``chimera.yaml``), isolates HOME, chdirs there, then asserts
``chimera config init`` exits 0 and the result round-trips through
``load_config``.
"""
template = _REPO_ROOT / "chimera.yaml.example"
assert template.is_file(), "shipped template chimera.yaml.example is missing"
shutil.copyfile(template, tmp_path / "chimera.yaml.example")
home = tmp_path / "home"
home.mkdir()
monkeypatch.setenv("HOME", str(home))
monkeypatch.delenv("CHIMERA_CONFIG", raising=False)
monkeypatch.chdir(tmp_path)
runner = CliRunner()
result = runner.invoke(main, ["config", "init"])
assert result.exit_code == 0, result.output
assert (tmp_path / "chimera.yaml").is_file()
cfg = load_config(tmp_path / "chimera.yaml")
assert cfg.defaults.dispatcher == "deepseek/deepseek-v4-flash"
assert "simple" in cfg.formations
# before (tracked): fresh clone contains the file, init refuses
$ git clone <repo> /tmp/before && cd /tmp/before && ls chimera.yaml
chimera.yaml
$ chimera config init
error: chimera.yaml already exists. Use --force to overwrite it. # exit 2
# after (untracked): fresh clone has no file, init succeeds
$ git clone <repo> /tmp/after && cd /tmp/after && ls chimera.yaml
ls: cannot access 'chimera.yaml': No such file or directory
$ chimera config init
Created chimera.yaml from /tmp/after/chimera.yaml.example. # exit 0
$ python -c "from chimera.config import load_config; \
c = load_config('chimera.yaml'); print(c.defaults.dispatcher)"
deepseek/deepseek-v4-flash
$ git show --stat --oneline HEAD
4cf631b chore: untrack live chimera.yaml (index-only, keep working copy)
chimera.yaml | 1381 ----------------------------------------------------------
1 file changed, 1381 deletions(-) # pure deletions, no insertions
$ git cat-file -e HEAD:chimera.yaml
fatal: path 'chimera.yaml' exists on disk, but not in 'HEAD' # exit 128 -> expected
$ git ls-tree HEAD -- chimera.yaml # prints nothing
$ git ls-files --error-unmatch chimera.yaml
error: pathspec 'chimera.yaml' did not match any file(s) known to git # exit 1
$ ls -la chimera.yaml # working copy intact
-rw-r--r-- 1 kara kara 68028 ... chimera.yaml
$ git check-ignore -v chimera.yaml
.gitignore:6:chimera.yaml chimera.yaml # exit 0 -> still ignored
$ git add -f chimera.yaml # simulate a re-add regression
$ python -m pytest tests/test_config_tracking.py -q
FAILED tests/test_config_tracking.py::test_live_config_is_not_tracked
FAILED tests/test_config_tracking.py::test_live_config_is_gitignored
2 failed, 3 passed
$ git rm --cached chimera.yaml # restore
$ python -m pytest tests/test_config_tracking.py -q
5 passed
$ python -m pytest -q
915 passed, 62 skipped, 1 warning in 30.27s
Untracking stops future publication, but the blob is still reachable in public git history:
$ git ls-tree 77a1b9d -- chimera.yaml
100644 blob 5898c50b952b5701def2cf48af326cb6cbb66e36 chimera.yaml
$ git cat-file -e 77a1b9d:chimera.yaml && echo "resolvable"
resolvable
Purging it requires a history rewrite (git filter-repo / BFG) plus a force-push, invalidating every clone/fork. That is a maintainer call. If the config ever held real secrets, rotate them — history rewriting does not un-leak a credential.
git rm --cached chimera.yaml + a pathspec-free commit makes a fresh clone config-less so chimera config init exits 0, keeps the live file the systemd unit reads, and leaves .gitignore as the guard that prevents re-tracking.
# Evidence - Problem class: git-untrack-live-config-fresh-clone-init - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T10:43:15.149Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "Symptom: a documented first-run step dead-ends on a fresh clone and internal ops config is published on a public mirror. `chimera config init` exited 2 'chimera.yaml already exists. Use --force to overwrite it.' on a clean clone because the live 68KB chimera.yaml was TRACKED even though .gitignore line 6 already listed it (force-added historically). Fix: untrack with `git rm --cached chimera.yaml` ONLY (plain `git rm` deletes the working file that the running systemd unit reads via Environment=CHIMERA_CONFIG; never rename either, the unit hard-codes the path). Confirm the deletion is index-only (`git show --stat HEAD` shows pure deletions; `git cat-file -e HEAD:chimera.yaml` must fail) and that `git check-ignore -v chimera.yaml` still matches so a local copy can never be re-added. Guard the invariant with subprocess git assertions in tests: `git ls-files --error-unmatch <file>` must exit non-zero, `git ls-tree HEAD -- <file>` must print nothing, `git check-ignore -q <file>` must exit 0, plus a fresh-tree contract test that copies only the shipped template into tmp_path, isolates HOME, monkeypatch.chdir(tmp_path) and asserts config init exits 0 and load_config round-trips. DO NOT assert the file exists in the repo root: a fresh CI checkout legitimately has none. Pitfall: `git commit -- <path>` on an untracked-but-present path RE-ADDS it from the working tree; use a plain index-only commit. Prove the guard test bites by `git add -f <file>` (expect the tracking tests to FAIL with the real message) then `git rm --cached <file>` to restore. Note the residual exposure: untracking stops future publication but the blob stays in public git history (`git ls-tree <remote>/main -- <file>` still resolves) - purging needs a history rewrite plus force-push, which is a maintainer call.", "environment": "<project> (Python 3.11, git repo with a gitignored-but-tracked live config; systemd service reads the file via CHIMERA_CONFIG)", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "git-untrack-live-config-fresh-clone-init", "provider": "openrouter", "solved_at": "2026-09-17T10:43:15.149Z", "version": ""}