tests: run every suite hermetic, with none of this machine's settings - #1206
Merged
Conversation
A test that looked a flag up through os.environ read the settings of whoever ran it: with CATSTACK_UNVERIFIED_TAG_BEHAVIOR=do_not_emit in ~/.catstack.env, seven unverified-tag-ledger tests failed locally and passed in CI. Exported CATSTACK_* variables, the checkout's own .env, the real HOME (hook state under ~/.cache, git config) and the real codex install leaked the same way. run_all_tests.sh now sources scripts/test/hermetic_env.sh first. It unsets every inherited CATSTACK_, GIT_, CLAUDE_, CODEX_, CURSOR_ and XDG_ variable, points HOME and the global git config at a throwaway directory, and sets CATSTACK_SKIP_ENV_FILES so the flag reader never opens the real ~/.catstack.env or the checkout's .env. tests/test_hermetic_test_env.py starts that setup from a polluted environment and fails if anything gets through. Tests the stricter run exposed: JudgeTestCase now stubs the codex model catalog and config instead of running the real codex binary, the run_all_tests tests copy hermetic_env.sh into their fake repo, and the ledger tests set the skip list themselves so they are clean when run alone. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com> Change-Id: Iafa1d66bc02d271ee4717d27f030ac4e075c7b6a
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_ca4a2015-8f21-46d5-88a7-f6b89a918a95) |
Contributor
|
Queued — the merge queue status continues in this comment ↓. |
added 2 commits
September 28, 2026 04:24
Bugbot couldn't run - usage limit reachedBugbot is counted against Cursor usage for this user or team, and this run hit a usage or spend limit. A user or team admin can review and increase usage limits in the Cursor dashboard. (requestId: serverGenReqId_a6c23fc1-7aa4-43b7-b8d9-91e940fc14bd) |
Owner
Author
|
@Mergifyio queue |
Contributor
Merge Queue Status
This pull request spent 32 minutes 32 seconds in the queue, including 32 minutes 14 seconds running CI. Required conditions to merge
|
6 tasks done
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Catstack comes with automatic self-checks that prove its safety checkers work. They should give the same result on any machine.
The problem: the self-checks read the personal settings of whoever ran them. On one machine, seven failed while the code was fine.
The cause: the run kept the person's home folder, shell settings and project settings, and the self-checks read them.
The fix: before anything runs, the runner clears those out and hands over an empty home folder. A new self-check fails if anything gets through.
Review Claim
A full self-check run gives the same result no matter whose machine runs it.
Review Lane
behavior
Review Unit
engine-runtime
Safety Invariant
Hooks on a real machine behave exactly as before: the flag reader's new skip list is empty unless set, and only the test runner and the ledger tests set it.
Slice Rationale
One claim, hermetic tests. The setup script, the reader's skip list, the guard test, and the four test files the stricter run exposed ship together because the runner fails on those four until they stop reading the machine.
Non-goals
python3 -m unittestoutside the runner still sees the shell; only the ledger suites protect themselves there.node_modules/node_moduleslink in one local checkout is not touched.Test Plan
Test Plan
CATSTACK_UNVERIFIED_TAG_BEHAVIOR=do_not_emitin~/.catstack.env:python3 -m unittest discover -s engine/hooks/unverified-tag-ledger/testsonorigin/main→FAILED (failures=7);python3 -m unittest tests/test_hermetic_test_env.py→FAILED (failures=4)(setup script absent).test_judgeread the real codex install; runner tests lacked the new script; install tests hit a local node_modules link loop, cleared by a realnpm ci).CATSTACK_UNVERIFIED_TAG_BEHAVIOR=do_not_emit CATSTACK_HOOK_MODE_DIU_STOP=off bash scripts/test/run_all_tests.sh→exit=0, 0FAIL:/ERROR:lines, 3365 tests run, nocatstack-test-home.*folder left behind.Revert Plan
Revert Plan
git revert <sha>🤖 Generated with Claude Code
Note
Low Risk
Production hook behavior is unchanged unless
CATSTACK_SKIP_ENV_FILESis set; only the test runner and explicit test setup use it.Overview
Makes
scripts/test/run_all_tests.shsource a newhermetic_env.shthat strips inheritedCATSTACK_*,GIT_*, and related vars, pointsHOMEat a temp directory with isolated git config, and setsCATSTACK_SKIP_ENV_FILESso the real~/.catstack.envand repo.envare not consulted during the full run.The shared flag reader gains optional
CATSTACK_SKIP_ENV_FILES(path-separated, realpath-matched) so listed env files drop out ofenv_file_candidateswithout changing default lookup order when unset. Ledger hook suites set the same skip when run standalone;tests/test_hermetic_test_env.pyguards that the setup actually isolates the runner.Supporting fixes: LLM judge tests stub Codex config/catalog so defaults do not depend on the host install; runner fake-repo tests copy
hermetic_env.sh; exit traps also removeCATSTACK_TEST_HOME.Reviewed by Cursor Bugbot for commit 20ae939. Bugbot is set up for automated code reviews on this repo. Configure here.