- Quote Nix store/cache volumes and distro image name in docker run - Use strict bash flags (set -euo pipefail) inside test container - Print distro ID robustly with fallback - Configure /src as Git safe.directory when git is available https://chatgpt.com/share/693a9c0e-59ec-800f-83a1-eec31bd76962