Problem class: go-seam-landed-but-unwired-var-never-set
rootlessInstallerCacheDir landed but never wiredProblem class: go-seam-landed-but-unwired-var-never-set
Seam: rootlessInstallerCacheDir (package var)
Symptom: re-download of the rootless installer per agent spawn → throughput collapse → 500s.
I reproduced the class in a minimal Go module, proved the failure, applied the fix, and verified it: buggy = 3 downloads / 3 temp paths; fixed = 1 download / shared path, with go vet and go test -race green. Full doc: /workspace/SOLUTION.md, repro: /workspace/<project>-repro/.
The caching PR landed all the machinery (cached download, checksum validation, atomic promotion), but every branch is gated on a package variable that no production code assigns:
var rootlessInstallerCacheDir string // declaration only
func EnsureInstaller(version string) (string, error) {
if rootlessInstallerCacheDir == "" {
tmp, _ := os.MkdirTemp("", "rootless-installer-*") // fresh dir, re-download every spawn
return stageAndValidate(tmp, version)
}
// ...shared cache + validation + atomic promote (the "fixed" path)
}
In Go a declared-but-unused package-level var is legal, so build/vet stayed green. The PR's tests assigned the var directly (= t.TempDir()), so they passed too. Production always took the =="" fallback. The seam had readers but no writer — the fix was merged, the board row closed, and the original failure persisted.
grep -rnE --include='*.go' \
'rootlessInstallerCacheDir[[:space:]]*=[[:space:]]*[^=]' . \
| grep -v '_test\.go:' \
| grep -vE '=[[:space:]]*""'
Reusable detector /workspace/<project>-repro/detect-unwired-seam.sh (exit 1 = unwired) filters declarations, comparisons (==, !=), and empty resets.
rootless/config.go (new)package rootless
import (
"os"
"path/filepath"
)
const EnvRootlessInstallerCacheDir = "BUNKERD_ROOTLESS_INSTALLER_CACHE_DIR"
func DefaultRootlessInstallerCacheDir() string {
if c, err := os.UserCacheDir(); err == nil && c != "" {
return filepath.Join(c, "bunkerd", "rootless-installer")
}
return filepath.Join(os.TempDir(), "bunkerd-rootless-installer")
}
// Precedence: explicit config > env > compiled default.
func ResolveRootlessInstallerCacheDir(configured string) string {
if configured != "" {
return configured
}
if env := os.Getenv(EnvRootlessInstallerCacheDir); env != "" {
return env
}
return DefaultRootlessInstallerCacheDir()
}
// Single production writer for the seam.
func ConfigureRootlessInstallerCache(configured string) string {
dir := ResolveRootlessInstallerCacheDir(configured)
rootlessInstallerCacheDir = dir
return dir
}
func ConfigureFromEnv() string { return ConfigureRootlessInstallerCache("") }
cmd/bunkerd/main.gofunc main() {
cacheDir := flag.String("rootless-installer-cache-dir", "",
"shared cache dir for the validated rootless installer bundle")
flag.Parse()
rootless.ConfigureRootlessInstallerCache(*cacheDir) // wire before first spawn
...
}
(For YAML config add agent.rootless_installer_cache_dir → mapstructure:"rootless_installer_cache_dir" and pass it in; env/default still apply when empty.)
rootless/seam_test.go (new regression)func TestSeamWiredFromEnvAndReusesCache(t *testing.T) {
resetForTest()
t.Cleanup(resetForTest)
cache := t.TempDir()
t.Setenv(EnvRootlessInstallerCacheDir, cache)
if got := ConfigureFromEnv(); got != cache {
t.Fatalf("env knob ignored: got %q want %q", got, cache)
}
first, _ := EnsureInstaller("1.2.3")
second, _ := EnsureInstaller("1.2.3")
if first != second {
t.Fatalf("cache miss across spawns: %q then %q", first, second)
}
if got := downloads(); got != 1 {
t.Fatalf("expected 1 download for 2 spawns, got %d", got)
}
}
func TestSeamDefaultWhenUnset(t *testing.T) {
resetForTest()
t.Cleanup(resetForTest)
t.Setenv(EnvRootlessInstallerCacheDir, "")
if got := ConfigureFromEnv(); got == "" {
t.Fatal("unwired seam: default resolved to empty string")
}
}
Upstream: if the seam is owned by a sibling project (WarpFS-side installer), bunkerd cannot own the writer — file an upstream issue asking for a Configure…/Options entry point, documented env var + default, and the same non-empty-default test; meanwhile consume it via the env knob.
# BEFORE
$ go run ./cmd/bunkerd
spawned agent-1 with installer /tmp/rootless-installer-2551091995/bundle.tgz
spawned agent-2 with installer /tmp/rootless-installer-1725900355/bundle.tgz
spawned agent-3 with installer /tmp/rootless-installer-151334901/bundle.tgz
downloads=3
$ ./detect-unwired-seam.sh rootlessInstallerCacheDir /tmp/seam-buggy
UNWIRED: 'rootlessInstallerCacheDir' is never assigned a non-empty value in production code.
exit=1
# AFTER
$ go vet ./...
$ go test -race -count=1 ./...
ok example.com/bunkerd/rootless 1.012s
$ go run ./cmd/bunkerd
rootless installer cache: ~/.cache/bunkerd/rootless-installer
spawned agent-1 with installer .../v1.2.3/bundle.tgz
spawned agent-2 with installer .../v1.2.3/bundle.tgz
spawned agent-3 with installer .../v1.2.3/bundle.tgz
downloads=1
$ BUNKERD_ROOTLESS_INSTALLER_CACHE_DIR=/tmp/bunker-shared-cache go run ./cmd/bunkerd # env wins, downloads=1
$ go run ./cmd/bunkerd --rootless-installer-cache-dir /tmp/bunker-flag-cache # flag wins, downloads=1
$ ./detect-unwired-seam.sh rootlessInstallerCacheDir .
WIRED: 'rootlessInstallerCacheDir' assigned in production code:
./rootless/config.go:36: rootlessInstallerCacheDir = dir
exit=0
Acceptance checklist: detection finds ≥1 non-empty assignment in production; writer runs before first spawn; N spawns = 1 download/one shared path; env and flag override the default; ConfigureFromEnv() never returns ""; go vet + go test -race pass.
detect-unwired-seam.sh <seam> for each seam var; fail on zero non-empty production writers.ConfigureRootlessInstallerCache returns "".# Evidence - Problem class: go-seam-landed-but-unwired-var-never-set - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-20T01:52:20.613Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "WarpFS DF-WARPFS-3 -> bunker GAP-091: a fix PR landed full machinery (cached download, validation, atomic promotion) keyed off a package var (rootlessInstallerCacheDir) but nothing in production sets the var \u2014 no env/config/flag assignment, only the declaration. Symptom: the original failure (re-download per spawn, throughput-collapse 500s) persists despite the fix being merged and its board row closed. Detection: grep for assignments to the seam var excluding the declaration and tests; if only the declaration exists, the seam is unwired. Fix: wire env/config knob with a default + regression test; file upstream if the seam owner is a sibling project.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-seam-landed-but-unwired-var-never-set", "provider": "openrouter", "solved_at": "2026-09-20T01:52:20.613Z", "version": ""}rootlessInstallerCacheDir landed but never wiredProblem class: go-seam-landed-but-unwired-var-never-set
Seam: rootlessInstallerCacheDir (package var)
Symptom: re-download of the rootless installer per agent spawn → throughput collapse → 500s.
I reproduced the class in a minimal Go module, proved the failure, applied the fix, and verified it: buggy = 3 downloads / 3 temp paths; fixed = 1 download / shared path, with go vet and go test -race green. Full doc: /workspace/SOLUTION.md, repro: /workspace/<project>-repro/.
The caching PR landed all the machinery (cached download, checksum validation, atomic promotion), but every branch is gated on a package variable that no production code assigns:
var rootlessInstallerCacheDir string // declaration only
func EnsureInstaller(version string) (string, error) {
if rootlessInstallerCacheDir == "" {
tmp, _ := os.MkdirTemp("", "rootless-installer-*") // fresh dir, re-download every spawn
return stageAndValidate(tmp, version)
}
// ...shared cache + validation + atomic promote (the "fixed" path)
}
In Go a declared-but-unused package-level var is legal, so build/vet stayed green. The PR's tests assigned the var directly (= t.TempDir()), so they passed too. Production always took the =="" fallback. The seam had readers but no writer — the fix was merged, the board row closed, and the original failure persisted.
grep -rnE --include='*.go' \
'rootlessInstallerCacheDir[[:space:]]*=[[:space:]]*[^=]' . \
| grep -v '_test\.go:' \
| grep -vE '=[[:space:]]*""'
Reusable detector /workspace/<project>-repro/detect-unwired-seam.sh (exit 1 = unwired) filters declarations, comparisons (==, !=), and empty resets.
rootless/config.go (new)package rootless
import (
"os"
"path/filepath"
)
const EnvRootlessInstallerCacheDir = "BUNKERD_ROOTLESS_INSTALLER_CACHE_DIR"
func DefaultRootlessInstallerCacheDir() string {
if c, err := os.UserCacheDir(); err == nil && c != "" {
return filepath.Join(c, "bunkerd", "rootless-installer")
}
return filepath.Join(os.TempDir(), "bunkerd-rootless-installer")
}
// Precedence: explicit config > env > compiled default.
func ResolveRootlessInstallerCacheDir(configured string) string {
if configured != "" {
return configured
}
if env := os.Getenv(EnvRootlessInstallerCacheDir); env != "" {
return env
}
return DefaultRootlessInstallerCacheDir()
}
// Single production writer for the seam.
func ConfigureRootlessInstallerCache(configured string) string {
dir := ResolveRootlessInstallerCacheDir(configured)
rootlessInstallerCacheDir = dir
return dir
}
func ConfigureFromEnv() string { return ConfigureRootlessInstallerCache("") }
cmd/bunkerd/main.gofunc main() {
cacheDir := flag.String("rootless-installer-cache-dir", "",
"shared cache dir for the validated rootless installer bundle")
flag.Parse()
rootless.ConfigureRootlessInstallerCache(*cacheDir) // wire before first spawn
...
}
(For YAML config add agent.rootless_installer_cache_dir → mapstructure:"rootless_installer_cache_dir" and pass it in; env/default still apply when empty.)
rootless/seam_test.go (new regression)func TestSeamWiredFromEnvAndReusesCache(t *testing.T) {
resetForTest()
t.Cleanup(resetForTest)
cache := t.TempDir()
t.Setenv(EnvRootlessInstallerCacheDir, cache)
if got := ConfigureFromEnv(); got != cache {
t.Fatalf("env knob ignored: got %q want %q", got, cache)
}
first, _ := EnsureInstaller("1.2.3")
second, _ := EnsureInstaller("1.2.3")
if first != second {
t.Fatalf("cache miss across spawns: %q then %q", first, second)
}
if got := downloads(); got != 1 {
t.Fatalf("expected 1 download for 2 spawns, got %d", got)
}
}
func TestSeamDefaultWhenUnset(t *testing.T) {
resetForTest()
t.Cleanup(resetForTest)
t.Setenv(EnvRootlessInstallerCacheDir, "")
if got := ConfigureFromEnv(); got == "" {
t.Fatal("unwired seam: default resolved to empty string")
}
}
Upstream: if the seam is owned by a sibling project (WarpFS-side installer), bunkerd cannot own the writer — file an upstream issue asking for a Configure…/Options entry point, documented env var + default, and the same non-empty-default test; meanwhile consume it via the env knob.
# BEFORE
$ go run ./cmd/bunkerd
spawned agent-1 with installer /tmp/rootless-installer-2551091995/bundle.tgz
spawned agent-2 with installer /tmp/rootless-installer-1725900355/bundle.tgz
spawned agent-3 with installer /tmp/rootless-installer-151334901/bundle.tgz
downloads=3
$ ./detect-unwired-seam.sh rootlessInstallerCacheDir /tmp/seam-buggy
UNWIRED: 'rootlessInstallerCacheDir' is never assigned a non-empty value in production code.
exit=1
# AFTER
$ go vet ./...
$ go test -race -count=1 ./...
ok example.com/bunkerd/rootless 1.012s
$ go run ./cmd/bunkerd
rootless installer cache: ~/.cache/bunkerd/rootless-installer
spawned agent-1 with installer .../v1.2.3/bundle.tgz
spawned agent-2 with installer .../v1.2.3/bundle.tgz
spawned agent-3 with installer .../v1.2.3/bundle.tgz
downloads=1
$ BUNKERD_ROOTLESS_INSTALLER_CACHE_DIR=/tmp/bunker-shared-cache go run ./cmd/bunkerd # env wins, downloads=1
$ go run ./cmd/bunkerd --rootless-installer-cache-dir /tmp/bunker-flag-cache # flag wins, downloads=1
$ ./detect-unwired-seam.sh rootlessInstallerCacheDir .
WIRED: 'rootlessInstallerCacheDir' assigned in production code:
./rootless/config.go:36: rootlessInstallerCacheDir = dir
exit=0
Acceptance checklist: detection finds ≥1 non-empty assignment in production; writer runs before first spawn; N spawns = 1 download/one shared path; env and flag override the default; ConfigureFromEnv() never returns ""; go vet + go test -race pass.
detect-unwired-seam.sh <seam> for each seam var; fail on zero non-empty production writers.ConfigureRootlessInstallerCache returns "".# Evidence - Problem class: go-seam-landed-but-unwired-var-never-set - Model: openrouter/deepseek/deepseek-v4.1-flash - Solved: 2026-09-20T01:52:20.613Z - Verification: solution produced by pi in sandbox; see signatures.json
{"description": "WarpFS DF-WARPFS-3 -> bunker GAP-091: a fix PR landed full machinery (cached download, validation, atomic promotion) keyed off a package var (rootlessInstallerCacheDir) but nothing in production sets the var \u2014 no env/config/flag assignment, only the declaration. Symptom: the original failure (re-download per spawn, throughput-collapse 500s) persists despite the fix being merged and its board row closed. Detection: grep for assignments to the seam var excluding the declaration and tests; if only the declaration exists, the seam is unwired. Fix: wire env/config knob with a default + regression test; file upstream if the seam owner is a sibling project.", "environment": "", "language": "", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "go-seam-landed-but-unwired-var-never-set", "provider": "openrouter", "solved_at": "2026-09-20T01:52:20.613Z", "version": ""}