Preserve evaluation evidence and distinguish verified remediation findings #205
Labels
No labels
area:authentication
area:flake-utilities
area:performance
area:tbd
host:chaos
host:electra
host:fleet
host:lyra
host:nova
host:vega
investigation
phase:cutover
phase:deploy
phase:mcp
phase:module
phase:packaging
phase:prep
phase:validation
priority:high
priority:medium
project:attic-postgres-lyra-rollout
project:auto-update-reliability
project:auto-update-remediation
project:declarative-purity-cleanup
project:external-review
project:fleet-boundary-cleanup
project:host-facts-refactor
project:lyra-nixos-deploy
project:lyra-service-stack-migration
project:nebula-mesh-network
project:nixos-build-deployment-pipeline
project:security-hardening
project:service-stack-migration
project:vega-sillytavern-cutover
project:wiki-rebuild
repo:numtide/flake-utils
repo:numtide/nix-auth
repo:numtide/nixos-passthru-cache
repo:numtide/nix-relay
service:auto-update
service:mem0
service:nix
service:sillytavern
service:slskd
service:synthseek
No milestone
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set
Reference
nimmo/nixos-config#205
Loading…
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Context
Follow-up to #204 and the result-output fix in #201/#202. The model now returns a valid diagnosis, but evidence omits evaluation traces and the report confuses affected hosts with observed failures.
Scope
Validation and completion
Prepared changes and evidence
Real-model replay evidence (2026-09-09)
Two separate disposable, non-publishing replays used real OpenCode/Bubblewrap/Ollama and qwen3.6:35b-a3b-q8_0 under the unchanged 600-second model deadline. The original #204 incident and state hashes were unchanged.
The detailed dependency-chain reconstruction and model confidence/classification remain advisory; this test does not independently validate every causal edge claimed by the model or demonstrate repair eligibility.
The controller now supplies real line breaks and wraps diagnostic lines at 512 characters without dropping content. Regression coverage emulates OpenCode's per-line clipping and verifies the final error survives, text remains read-only, and the original evidence characters are preserved. The remediation regression/integration suite passed after this fix. This Python/prompt follow-up changes no Nix configuration; the prior combined flake/VM checks remain recorded above.
No branches were pushed, no MR was opened, no configuration was deployed, and no scheduled production incident was reprocessed. Coordinated publication and input-pin integration remain pending.
Historical package replay: Moonlight #172 (2026-09-09)
User accepted keeping evaluation failures diagnosis-only and requested a replay of a historical package failure. Selected #172 (928eda57...), the Moonlight 6.1.0 / FFmpeg 9 compilation failure from before the manually approved #170 compatibility pin. Used the unchanged retained incident, exact baseline
999961b155, and rejected candidate lock in a disposable Nova repository with the updated controller/prompt. No policy or eligibility data was altered.Real qwen3.6:35b-a3b-q8_0 replay completed diagnosis-ready in 229.356 seconds, exit code 0, no timeout or resource-limit breach. It identified Moonlight's use of the removed FFmpeg AVCodec.pix_fmts API, but classified the incident as core-system-regression (culprit ffmpeg), returned diagnosis-only, and proposed no patch. Controller reason: exactly one failing derivation is required. No baseline/patched build validation or temporary-pin generation occurred.
Confirmed blockers:
Original incident hashes unchanged. Assessment retained locally at /tmp/nixos-172-real-model-assessment.json; disposable remote replay cleaned up. No MR publication, deployment, eligibility relaxation, or implementation changes in this replay. Next work should correct actual-failed-builder attribution (preserving rejection of genuinely multiple independent failures) and assess a narrowly permitted leaf compatibility-override path before expecting an end-to-end automatic pin proposal.
Closure evidence: Electra deployed revision
4ba715cb38, containing the merged evaluation-evidence integration, at 20:11 on 2026-09-09. Its 22:15 normal follow-up confirmed origin/main and the running system were current at4a03f7ebc9, with no build or activation and a successful exit.