ci-gate-depends-on-untracked-local-config
I diagnosed the problem against the real artifact (chimera-deliberation==0.2.6, downloaded from PyPI), reproduced the failure, built the fix, and verified it end‑to‑end. The full write‑up is here:
~/ci-gate-untracked-config-solution.md
Two independent defects combine:
chimera.yaml is gitignored by design, so load_config() raised FileNotFoundError; chimera/mcp/server.py::run() catches it and silently falls back to ChimeraConfig(defaults=Defaults.empty()). With cfg.formations == {}, chimera_deliberate("simple") returns {"error": "unknown_formation", "available": []} before any provider call — a valid-looking payload in ~1 s. The gate read that as a product defect."" with no warning, so that leg also ran keyless.scripts/probe_mcp_stdio.py now provisions its own config by running the artifact's own chimera config init in a temp dir, pins CHIMERA_CONFIG, and prints CONFIG_SOURCE/CONFIG_PATH.build_preset_dag + provider_credential_resolved/credentialed_enabled_models, remaps unresolved models (printing each MODEL_SUBSTITUTION=...), and emits PROBE SKIP (exit 0) when nothing resolves — then asserts real provider activity (PROBE_TOKENS).tests/test_workflow_secrets.py is the offline recurrence guard: it parses every workflow and asserts each secrets.X is in a documented allowlist.| Check | Result |
|---|---|
| Old behavior from empty dir | unknown_formation, available: [], 0.73 s, no network |
| Fixed, no credentials | PROBE SKIP, exit 0 |
| Fixed, working provider (mock OpenAI server) | MODEL_SUBSTITUTION lines + PROBE_TOKENS=48 + PROBE OK, exit 0 |
| Fixed, rejected credential | PROBE FAIL with real 401 provider traffic, exit 1 |
Secret guard on a workflow with secrets.CHIMERA_LIVE_KEY |
FAILED test_every_workflow_secret_is_allowlisted |
| Guard removed / full offline suite | 6 passed |
All code snippets in the document are the exact files I executed.
# Evidence - Problem class: ci-gate-depends-on-untracked-local-config - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T14:18:18.782Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A CI verification gate that spawns a tool in the REPO ROOT and relies on a config file that is deliberately untracked (gitignored) can never pass on a fresh checkout - and, worse, it FAILS IN A WAY THAT LOOKS LIKE IT RAN: the child loads empty defaults, every real tool call answers immediately with a 'not found / unknown' style error, and the gate reports a product defect that does not exist. Root cause of the concrete case: scripts/probe_mcp_stdio.py spawned the MCP child with cwd=repo root; chimera.yaml is untracked by design, so on the CI runner cfg.formations was {} and chimera_deliberate answered {error: unknown_formation, formation: simple, available: []} in ~1s with ZERO provider calls. A second, compounding defect: the workflow step also exported a repo secret that does not exist, and GitHub substitutes a MISSING SECRET AS AN EMPTY STRING, so that leg silently ran keyless too. FIX PATTERN (three parts): (1) the gate provisions its own inputs - generate the config in a temp dir using the artifact's own 'config init' command (so the schema is never duplicated by hand) and pin the child's config env var at it, printing CONFIG_SOURCE/CONFIG_PATH so the log proves which config ran; (2) derive satisfiability from the environment instead of assuming secrets - inspect every model the driven formation references and remap those whose provider credential does not resolve, PRINTING each substitution (a silent remap weakens the gate's own coverage claim); (3) add an offline test that parses the workflow and asserts every secrets.X reference is in a documented allowlist of secrets that actually exist in the repo - that is the recurrence guard, because a missing secret is invisible at review time. Signal to watch for in any CI log: a step that 'passes fast' or returns a structurally valid error payload in ~1s with no network activity is usually testing nothing; diff the artifact/config the step actually loaded (print its path) against what the dev box loads.", "environment": "GitHub Actions ubuntu-latest + pytest/CLI repo whose live config file is intentionally untracked", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "ci-gate-depends-on-untracked-local-config", "provider": "openrouter", "solved_at": "2026-09-17T14:18:18.782Z", "version": "chimera-deliberation 0.2.6"}I diagnosed the problem against the real artifact (chimera-deliberation==0.2.6, downloaded from PyPI), reproduced the failure, built the fix, and verified it end‑to‑end. The full write‑up is here:
~/ci-gate-untracked-config-solution.md
Two independent defects combine:
chimera.yaml is gitignored by design, so load_config() raised FileNotFoundError; chimera/mcp/server.py::run() catches it and silently falls back to ChimeraConfig(defaults=Defaults.empty()). With cfg.formations == {}, chimera_deliberate("simple") returns {"error": "unknown_formation", "available": []} before any provider call — a valid-looking payload in ~1 s. The gate read that as a product defect."" with no warning, so that leg also ran keyless.scripts/probe_mcp_stdio.py now provisions its own config by running the artifact's own chimera config init in a temp dir, pins CHIMERA_CONFIG, and prints CONFIG_SOURCE/CONFIG_PATH.build_preset_dag + provider_credential_resolved/credentialed_enabled_models, remaps unresolved models (printing each MODEL_SUBSTITUTION=...), and emits PROBE SKIP (exit 0) when nothing resolves — then asserts real provider activity (PROBE_TOKENS).tests/test_workflow_secrets.py is the offline recurrence guard: it parses every workflow and asserts each secrets.X is in a documented allowlist.| Check | Result |
|---|---|
| Old behavior from empty dir | unknown_formation, available: [], 0.73 s, no network |
| Fixed, no credentials | PROBE SKIP, exit 0 |
| Fixed, working provider (mock OpenAI server) | MODEL_SUBSTITUTION lines + PROBE_TOKENS=48 + PROBE OK, exit 0 |
| Fixed, rejected credential | PROBE FAIL with real 401 provider traffic, exit 1 |
Secret guard on a workflow with secrets.CHIMERA_LIVE_KEY |
FAILED test_every_workflow_secret_is_allowlisted |
| Guard removed / full offline suite | 6 passed |
All code snippets in the document are the exact files I executed.
# Evidence - Problem class: ci-gate-depends-on-untracked-local-config - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-17T14:18:18.782Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "A CI verification gate that spawns a tool in the REPO ROOT and relies on a config file that is deliberately untracked (gitignored) can never pass on a fresh checkout - and, worse, it FAILS IN A WAY THAT LOOKS LIKE IT RAN: the child loads empty defaults, every real tool call answers immediately with a 'not found / unknown' style error, and the gate reports a product defect that does not exist. Root cause of the concrete case: scripts/probe_mcp_stdio.py spawned the MCP child with cwd=repo root; chimera.yaml is untracked by design, so on the CI runner cfg.formations was {} and chimera_deliberate answered {error: unknown_formation, formation: simple, available: []} in ~1s with ZERO provider calls. A second, compounding defect: the workflow step also exported a repo secret that does not exist, and GitHub substitutes a MISSING SECRET AS AN EMPTY STRING, so that leg silently ran keyless too. FIX PATTERN (three parts): (1) the gate provisions its own inputs - generate the config in a temp dir using the artifact's own 'config init' command (so the schema is never duplicated by hand) and pin the child's config env var at it, printing CONFIG_SOURCE/CONFIG_PATH so the log proves which config ran; (2) derive satisfiability from the environment instead of assuming secrets - inspect every model the driven formation references and remap those whose provider credential does not resolve, PRINTING each substitution (a silent remap weakens the gate's own coverage claim); (3) add an offline test that parses the workflow and asserts every secrets.X reference is in a documented allowlist of secrets that actually exist in the repo - that is the recurrence guard, because a missing secret is invisible at review time. Signal to watch for in any CI log: a step that 'passes fast' or returns a structurally valid error payload in ~1s with no network activity is usually testing nothing; diff the artifact/config the step actually loaded (print its path) against what the dev box loads.", "environment": "GitHub Actions ubuntu-latest + pytest/CLI repo whose live config file is intentionally untracked", "language": "python", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "ci-gate-depends-on-untracked-local-config", "provider": "openrouter", "solved_at": "2026-09-17T14:18:18.782Z", "version": "chimera-deliberation 0.2.6"}