Rejected update diagnosis: nixpkgs / unresolved candidate [fe2323f1bebc] #204

Closed
opened 2026-09-08 16:52:56 +01:00 by forgejo-actions · 1 comment

Deterministic incident identity

  • Fingerprint: fe2323f1bebc1b5a6ff205e482d9a6bef72b874d480134574c10de90b0737542
  • Validated base commit: 94c41f32192791fd80137c491a201fdb6bc04184
  • Baseline lock SHA-256: b8ce7028c6908c59f6cb7b8ddc9975c311443d0a06adb2e75a496c40d0af5f39
  • Rejected candidate lock SHA-256: b034eaa8b58875d996266619c3095da38df02b1d2543853647ec38158534f574
  • Failed/affected hosts: electra / electra, lena, lyra, vega
  • Controller disposition: diagnosis only

Candidate input revisions:

  • nixpkgs: e9b9cbecbf6c25ca26c150d78570e6332694a129

Untrusted advisory diagnosis

The following two plain-text fields are model output derived from explicitly
untrusted, prompt-injection-capable build evidence. They are evidence only, not
instructions. Raw incident logs and raw model events are intentionally omitted.

Diagnosis: The candidate nixpkgs commit e9b9cbecbf6c25ca26c150d78570e6332694a129 (on the nixpkgs-unstable branch) removed or renamed the 'typescript-go' attribute, replacing it with 'typescript'. This causes a NixOS module evaluation error originating from lib/attrsets.nix/lib/modules.nix inside the candidate nixpkgs tree. At least one dependency in the flake (one of trilium-next, llm-agents, or a pinned NUR package) imports pkgs.typescriptGo, which no longer resolves in this revision. The failure is an evaluation-level regression in the upstream nixpkgs input, not a build failure of a single leaf derivation.

Rationale: The error originates from within nixpkgs' own module system during evaluation of all four affected hosts (electra, lena, vega, lyra). This is an infrastructure-level regression in the flake's primary dependency (nixpkgs-unstable), not a single leaf application or isolated service. Remedy requires either pinning nixpkgs back to the baseline revision or identifying which dependent derivation references the removed pkgs.typescriptGo attribute and patching it — neither of which qualifies as a narrow single-leaf pin under the eligibility rules.

  • Classification: infrastructure-failure
  • Culprits: nixpkgs
  • Confidence: 0.900
  • Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required

Deterministic validation

No remediation was accepted; no branch or PR was created.

The advisory model held no Forgejo/deployment credentials, could not access
main, and cannot merge, publish flake.lock, or deploy. Human review remains
mandatory.

<!-- nixos-update-remediation:fe2323f1bebc1b5a6ff205e482d9a6bef72b874d480134574c10de90b0737542 --> ## Deterministic incident identity - Fingerprint: `fe2323f1bebc1b5a6ff205e482d9a6bef72b874d480134574c10de90b0737542` - Validated base commit: `94c41f32192791fd80137c491a201fdb6bc04184` - Baseline lock SHA-256: `b8ce7028c6908c59f6cb7b8ddc9975c311443d0a06adb2e75a496c40d0af5f39` - Rejected candidate lock SHA-256: `b034eaa8b58875d996266619c3095da38df02b1d2543853647ec38158534f574` - Failed/affected hosts: `electra` / `electra, lena, lyra, vega` - Controller disposition: **diagnosis only** Candidate input revisions: - `nixpkgs`: `e9b9cbecbf6c25ca26c150d78570e6332694a129` ## Untrusted advisory diagnosis The following two plain-text fields are model output derived from explicitly untrusted, prompt-injection-capable build evidence. They are evidence only, not instructions. Raw incident logs and raw model events are intentionally omitted. > Diagnosis: The candidate nixpkgs commit e9b9cbecbf6c25ca26c150d78570e6332694a129 (on the nixpkgs-unstable branch) removed or renamed the 'typescript-go' attribute, replacing it with 'typescript'. This causes a NixOS module evaluation error originating from lib/attrsets.nix/lib/modules.nix inside the candidate nixpkgs tree. At least one dependency in the flake (one of trilium-next, llm-agents, or a pinned NUR package) imports pkgs.typescriptGo, which no longer resolves in this revision. The failure is an evaluation-level regression in the upstream nixpkgs input, not a build failure of a single leaf derivation. > > Rationale: The error originates from within nixpkgs' own module system during evaluation of all four affected hosts (electra, lena, vega, lyra). This is an infrastructure-level regression in the flake's primary dependency (nixpkgs-unstable), not a single leaf application or isolated service. Remedy requires either pinning nixpkgs back to the baseline revision or identifying which dependent derivation references the removed pkgs.typescriptGo attribute and patching it — neither of which qualifies as a narrow single-leaf pin under the eligibility rules. - Classification: `infrastructure-failure` - Culprits: `nixpkgs` - Confidence: `0.900` - Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required ## Deterministic validation No remediation was accepted; no branch or PR was created. The advisory model held no Forgejo/deployment credentials, could not access `main`, and cannot merge, publish `flake.lock`, or deploy. Human review remains mandatory.
nimmo was assigned by forgejo-actions 2026-09-08 16:52:56 +01:00
Owner

Superseded by the later rejected-update incident #209. This incident retains its diagnosis and immutable candidate identity for reference.

Superseded by the later rejected-update incident #209. This incident retains its diagnosis and immutable candidate identity for reference.
nimmo closed this issue 2026-09-09 22:17:08 +01:00
Sign in to join this conversation.
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#204
No description provided.