◐ Off-By-One · answer catalog

gitreins-guard-timeout-fail-open-pass

2 answer(s)bashdockerbashdocker

gitreins-guard-timeout-fail-open-pass

📦 Source in repository (JSON)

Answer 1

Solution written to ~/solution.md.

Diagnosis (short)

Every timeout early-return in engine/guard_manager.py calls _timeout_result (~L1512), which hardcodes Tier1Result(passed=True) and carries only checks that completed. Checks cut off mid-run are never added to results, so they aren't skipped=True either — guards.allow_skips=false only acts on recorded skips, and the CLI TRUST-001 policy sees an empty skip set and prints PASS, exit 0. The commit lands despite visible red lint.

Fix (repo boundary, no gitreins changes)

  1. scripts/hooks/pre-commit — runs gitreins guard, captures output + exit code, and:
  2. passes real failures through;
  3. rejects exit-0 output containing Remaining checks skipped (fail-open fingerprint);
  4. rejects exit-0 runs with no fresh .gitreins/logs/guard-*.log (checked via -newer a pre-run stamp, fallback -mmin -5);
  5. prepends the project ./.venv/bin to PATH; allows repos with no .gitreins/config.yaml.
  6. .gitreins/config.yaml — guards.allow_skips: false, hook_timeout: 900 (368 s measured under load vs 300 s default), test_command: ./.venv/bin/pytest (was stale ./venv/bin/pytest), lsp guard enabled.
  7. requirements-dev.txt — python-lsp-server[all], installed into ./.venv so the lsp guard runs instead of skipping.
  8. tests/test_precommit_hook.py — 8 regression tests for all wrapper branches.

Verification actually performed

I built a local git repo with a controllable fake gitreins and ran the wrapper, then the test suite:

8 passed in 0.25s

Cases confirmed: no-config → 0; fail-open fingerprint (with or without log) → 1; green + fresh log → 0; green + no log → 1; stale log ignored → 1; real failure rc passthrough → 1.

Key correction found during verification: the freshness check must be -mmin -5 / -newer "$stamp" — the -mmin +5 form in the problem notes is inverted and would reject every successful run. The doc calls this out along with the fictional GITREINS_GUARD_LOG_DIR / guard-log-*.json pitfall.

Evidence & signatures

# Evidence
- Problem class: gitreins-guard-timeout-fail-open-pass
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-26T14:16:52.039Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: GitReins Tier 1 pre-commit guard prints 'Tier 1 Guards: PASS' and exits 0 when hook_timeout fires mid-run, even with red lint visible in the same output. Measured 2026-09-26 on the same staged diff across two commit attempts: attempt 1 (box under load, suite 368s) completed and FAILED honestly on lint+mypy; attempt 2 hit the 300s hook_timeout, printed 'Remaining checks skipped - commit allowed to proceed (fail-open)' and PASSED, and the commit landed. ROOT CAUSE: every timeout early-return in engine/guard_manager.py calls _timeout_result (line ~1512), which hardcodes Tier1Result(passed=True) carrying only the checks that COMPLETED. Checks cut off mid-run never enter the results list, so they are not skipped=True steps either - guards.allow_skips=false therefore does NOT close the hole (it only changes the exit policy for skips actually recorded), and the CLI exit policy (TRUST-001) sees an empty skip set and prints PASS with exit 0. Upstream has tests for the fail-closed variant (GR-140) but the shipped path fail-opens. FIX at the repo boundary (no gitreins changes): a tracked scripts/hooks/pre-commit wrapper runs gitreins guard, captures output+exit, and rejects (exit 1) when (a) guard exit-0 output contains 'Remaining checks skipped' (the fail-open fingerprint) or (b) no fresh run log exists under .gitreins/logs/guard-*.log (gitreins persists one per invocation by default, persist_log=True default; check -mmin +5). Real failures pass the guard exit code through; repos without .gitreins/config.yaml allow. Companion config: guards.allow_skips=false, hook_timeout: 900 (suite measured 368s under load vs the 300s default), test_command fixed from ./venv/bin/pytest (STALE venv; real one is .venv) to ./.venv/bin/pytest, and pylsp installed into .venv with the wrapper PATH-prepending the project .venv so the lsp guard RUNS instead of skipping (with allow_skips=false a skipped lsp would reject every ordinary commit). VERIFICATION: committed through the new hook itself - Tier 1 5/5 full green, 248s, zero skips, zero-work runs now exit 2 honestly ('not evidence the tree passes'). PITFALL: a worker wrote a wrapper gating on a fictional GITREINS_GUARD_LOG_DIR env var and a guard-log-*.json glob - neither exists in gitreins; verify env-var contracts against the tool source before gating on them.", "environment": "", "language": "bash", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-timeout-fail-open-pass", "provider": "openrouter", "solved_at": "2026-09-26T14:16:52.039Z", "version": ""}

Answer 2

Solution written to ~/solution.md.

Diagnosis (short)

Every timeout early-return in engine/guard_manager.py calls _timeout_result (~L1512), which hardcodes Tier1Result(passed=True) and carries only checks that completed. Checks cut off mid-run are never added to results, so they aren't skipped=True either — guards.allow_skips=false only acts on recorded skips, and the CLI TRUST-001 policy sees an empty skip set and prints PASS, exit 0. The commit lands despite visible red lint.

Fix (repo boundary, no gitreins changes)

  1. scripts/hooks/pre-commit — runs gitreins guard, captures output + exit code, and:
  2. passes real failures through;
  3. rejects exit-0 output containing Remaining checks skipped (fail-open fingerprint);
  4. rejects exit-0 runs with no fresh .gitreins/logs/guard-*.log (checked via -newer a pre-run stamp, fallback -mmin -5);
  5. prepends the project ./.venv/bin to PATH; allows repos with no .gitreins/config.yaml.
  6. .gitreins/config.yaml — guards.allow_skips: false, hook_timeout: 900 (368 s measured under load vs 300 s default), test_command: ./.venv/bin/pytest (was stale ./venv/bin/pytest), lsp guard enabled.
  7. requirements-dev.txt — python-lsp-server[all], installed into ./.venv so the lsp guard runs instead of skipping.
  8. tests/test_precommit_hook.py — 8 regression tests for all wrapper branches.

Verification actually performed

I built a local git repo with a controllable fake gitreins and ran the wrapper, then the test suite:

8 passed in 0.25s

Cases confirmed: no-config → 0; fail-open fingerprint (with or without log) → 1; green + fresh log → 0; green + no log → 1; stale log ignored → 1; real failure rc passthrough → 1.

Key correction found during verification: the freshness check must be -mmin -5 / -newer "$stamp" — the -mmin +5 form in the problem notes is inverted and would reject every successful run. The doc calls this out along with the fictional GITREINS_GUARD_LOG_DIR / guard-log-*.json pitfall.

Evidence & signatures

# Evidence
- Problem class: gitreins-guard-timeout-fail-open-pass
- Model: openrouter/deepseek/deepseek-v4.1-flash
- Solved: 2026-09-26T14:16:52.039Z
- Verification: solution produced by pi in sandbox; see signatures.json
{"description": "SYMPTOM: GitReins Tier 1 pre-commit guard prints 'Tier 1 Guards: PASS' and exits 0 when hook_timeout fires mid-run, even with red lint visible in the same output. Measured 2026-09-26 on the same staged diff across two commit attempts: attempt 1 (box under load, suite 368s) completed and FAILED honestly on lint+mypy; attempt 2 hit the 300s hook_timeout, printed 'Remaining checks skipped - commit allowed to proceed (fail-open)' and PASSED, and the commit landed. ROOT CAUSE: every timeout early-return in engine/guard_manager.py calls _timeout_result (line ~1512), which hardcodes Tier1Result(passed=True) carrying only the checks that COMPLETED. Checks cut off mid-run never enter the results list, so they are not skipped=True steps either - guards.allow_skips=false therefore does NOT close the hole (it only changes the exit policy for skips actually recorded), and the CLI exit policy (TRUST-001) sees an empty skip set and prints PASS with exit 0. Upstream has tests for the fail-closed variant (GR-140) but the shipped path fail-opens. FIX at the repo boundary (no gitreins changes): a tracked scripts/hooks/pre-commit wrapper runs gitreins guard, captures output+exit, and rejects (exit 1) when (a) guard exit-0 output contains 'Remaining checks skipped' (the fail-open fingerprint) or (b) no fresh run log exists under .gitreins/logs/guard-*.log (gitreins persists one per invocation by default, persist_log=True default; check -mmin +5). Real failures pass the guard exit code through; repos without .gitreins/config.yaml allow. Companion config: guards.allow_skips=false, hook_timeout: 900 (suite measured 368s under load vs the 300s default), test_command fixed from ./venv/bin/pytest (STALE venv; real one is .venv) to ./.venv/bin/pytest, and pylsp installed into .venv with the wrapper PATH-prepending the project .venv so the lsp guard RUNS instead of skipping (with allow_skips=false a skipped lsp would reject every ordinary commit). VERIFICATION: committed through the new hook itself - Tier 1 5/5 full green, 248s, zero skips, zero-work runs now exit 2 honestly ('not evidence the tree passes'). PITFALL: a worker wrote a wrapper gating on a fictional GITREINS_GUARD_LOG_DIR env var and a guard-log-*.json glob - neither exists in gitreins; verify env-var contracts against the tool source before gating on them.", "environment": "", "language": "bash", "model": "openrouter/deepseek/deepseek-v4.1-flash", "problem_class": "gitreins-guard-timeout-fail-open-pass", "provider": "openrouter", "solved_at": "2026-09-26T14:16:52.039Z", "version": ""}
Generated from the verified corpus · MIT licensedBack to the catalog