Backup covered-marker task: verifier sandbox correction¶
Task: 2f64e433-00e0-483e-8eb2-e106213a093c, frozen version 15,
read through HeyAira task_get before continuing.
Repository: h8v6/heyaira; branch: heyaira/2f64e433.
Continuation base: 6f8354830a628ddcd57d49d78bb48157d8ebf756.
The new candidate is the commit containing this report; its SHA is recorded
in the HeyAira RESULT receipt after committing.
Finding and correction¶
The verifier reported nine deployment-guard failures at git init and a
suite result of 9 failed, 408 passed, 231 skipped, 2 deselected.
Its sandbox denied the macOS xcrun cache and writes to worker Git metadata.
The tests inherited Bridge Git routing variables, including the object-store
location, although their synthetic repositories were supposed to stand alone.
tests/test_deployment_guard.py now supplies isolated subprocess environments
to fixture Git commands and deployment-script test invocations. It removes
inherited GIT_* routing/configuration variables, disables host global/system
configuration and, on macOS, selects an already installed Xcode or Command Line
Tools Git binary directly. An intermediate fixture run also exposed denied
host Git configuration reads; disabling host configuration addresses that case.
The caller's environment and Git routing are not modified.
Two integration regressions exercise actual fixture commits and successful dry-run preflight with an unavailable inherited metadata/configuration location and a synthetic failing macOS launcher. They verify that objects stay inside the synthetic repository and the original routing environment is preserved. The launcher regression also runs on Linux by substituting candidate binary paths. Existing deployment guard assertions and production scripts are unchanged; all Docker operations in these tests remain stubs.
Only this report and tests/test_deployment_guard.py changed in this correction.
The backup implementation, its regressions and earlier evidence remain intact.
No amend, rebase or reset was performed.
Actual checks¶
The two new regressions initially reproduced the failures before environment isolation was added:
2 failed, 10 deselected in 0.42s
Final checks ran in the repository root with
TMPDIR="$PWD/.local-review-tmp". No caller-side PATH override was supplied;
the caller still resolved git to /usr/bin/git. Only the fixture helper
selects the installed binary for its child processes.
$ PYTHONPATH=src python -m pytest -q -p no:cacheprovider tests/test_deployment_guard.py tests/test_backup_runtime.py
................................................ [100%]
48 passed in 6.53s
The complete prescribed version-15 command:
$ PYTHONPATH=src python -m pytest -q -p no:cacheprovider --deselect tests/test_server_beat_audit.py::test_R6_02_tcp_connect_gets_only_the_budget_left_after_resolution --deselect tests/test_server_beat_audit.py::test_F3_smtp_tarpit_is_cut_at_the_deadline
419 passed, 231 skipped, 2 deselected in 45.37s
git diff --check passed. No additional tests were skipped or deselected by
this patch. Existing skips require isolated PostgreSQL or listening sockets;
the two SMTP deselections are exactly those authorized by task version 15.
Criteria and handoff¶
tiers-read: pass, including daily/monthly-only coverage, newest recorded creation time across tiers and duplicate-copy handling.deleting-ignored: pass, including fallback past deleting-marked copies.listing-guards: pass, including existing rolling truncation checks and incomplete/malformed promoted-tier listings.suite: pass, with the complete result above and the two new regressions.
Confidence is based on actual local subprocess and synthetic-bucket checks. The verifier's own sandbox still needs its independent rerun; database-backed tests, excluded SMTP timing tests and real R2 latency remain for CI or follow-up. No push, pull request, merge, installation, real deployment or production bucket/database mutation was performed. The next step is independent verification of this descendant candidate against frozen task version 15.