Rejected update diagnosis: nixpkgs / unresolved candidate [34a9973aead7] #206

Closed
opened 2026-09-09 04:44:56 +01:00 by forgejo-actions · 1 comment

Deterministic incident identity

  • Fingerprint: 34a9973aead7fdbadaf6f793cc105826db761120eb2c8ea776ce9789380c7b5c
  • Validated base commit: 1dfa66b5a2910bce861acf1a67934cafe6dbe679
  • Baseline lock SHA-256: 47c58d52164c7c0526e8dd39d86b96c711fae81e9efde689e275b55e02aab124
  • Rejected candidate lock SHA-256: 10c0598951c32e02d78d9a86fe61ce762d93b352897b4d82c70a5958f7c0a725
  • Failed/affected hosts: electra / electra, lena, lyra, vega
  • Controller disposition: diagnosis only

Candidate input revisions:

  • nixpkgs: da39501c8d0a093136854eddcd6927c8a8bb0d8f

Untrusted advisory diagnosis

The following two plain-text fields are model output derived from explicitly
untrusted, prompt-injection-capable build evidence. They are evidence only, not
instructions. Raw incident logs and raw model events are intentionally omitted.

Diagnosis: nixpkgs revision da39501c8d0a093136854eddcd6927c8a8bb0d8f renamed or removed the 'typescript-go' derivation and replaced it with 'typescript'. Auto-evaluation of any module that references pkgs.typescript-go fails via nixpkgs's own attrsets deprecation guard (lib/modules.nix:1148 through lib/attrsets.nix:1729). The candidate-failing-derivations list is empty because the failure occurs at NOS evaluation time, before any individual derivation is produced.

Rationale: The error originates from nixpkgs core package-set evaluation and affects all hosts sharing this unstable revision. It cannot be addressed by a narrow pin of one leaf application or isolated service; fixing it requires finding and correcting every 'typescript-go' reference across the repository, which exceeds the two-file patch scope. Diagnosis-only is appropriate.

  • Classification: core-system-regression
  • Culprits: nixpkgs
  • Confidence: 0.950
  • Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required

Deterministic validation

No remediation was accepted; no branch or PR was created.

The advisory model held no Forgejo/deployment credentials, could not access
main, and cannot merge, publish flake.lock, or deploy. Human review remains
mandatory.

<!-- nixos-update-remediation:34a9973aead7fdbadaf6f793cc105826db761120eb2c8ea776ce9789380c7b5c --> ## Deterministic incident identity - Fingerprint: `34a9973aead7fdbadaf6f793cc105826db761120eb2c8ea776ce9789380c7b5c` - Validated base commit: `1dfa66b5a2910bce861acf1a67934cafe6dbe679` - Baseline lock SHA-256: `47c58d52164c7c0526e8dd39d86b96c711fae81e9efde689e275b55e02aab124` - Rejected candidate lock SHA-256: `10c0598951c32e02d78d9a86fe61ce762d93b352897b4d82c70a5958f7c0a725` - Failed/affected hosts: `electra` / `electra, lena, lyra, vega` - Controller disposition: **diagnosis only** Candidate input revisions: - `nixpkgs`: `da39501c8d0a093136854eddcd6927c8a8bb0d8f` ## Untrusted advisory diagnosis The following two plain-text fields are model output derived from explicitly untrusted, prompt-injection-capable build evidence. They are evidence only, not instructions. Raw incident logs and raw model events are intentionally omitted. > Diagnosis: nixpkgs revision da39501c8d0a093136854eddcd6927c8a8bb0d8f renamed or removed the 'typescript-go' derivation and replaced it with 'typescript'. Auto-evaluation of any module that references pkgs.typescript-go fails via nixpkgs's own attrsets deprecation guard (lib/modules.nix:1148 through lib/attrsets.nix:1729). The candidate-failing-derivations list is empty because the failure occurs at NOS evaluation time, before any individual derivation is produced. > > Rationale: The error originates from nixpkgs core package-set evaluation and affects all hosts sharing this unstable revision. It cannot be addressed by a narrow pin of one leaf application or isolated service; fixing it requires finding and correcting every 'typescript-go' reference across the repository, which exceeds the two-file patch scope. Diagnosis-only is appropriate. - Classification: `core-system-regression` - Culprits: `nixpkgs` - Confidence: `0.950` - Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required ## Deterministic validation No remediation was accepted; no branch or PR was created. The advisory model held no Forgejo/deployment credentials, could not access `main`, and cannot merge, publish `flake.lock`, or deploy. Human review remains mandatory.
nimmo was assigned by forgejo-actions 2026-09-09 04:44:56 +01:00
Owner

Superseded by the later rejected-update incident #209. This incident retains its diagnosis and immutable candidate identity for reference.

Superseded by the later rejected-update incident #209. This incident retains its diagnosis and immutable candidate identity for reference.
nimmo closed this issue 2026-09-09 22:17:08 +01:00
Sign in to join this conversation.
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#206
No description provided.