Rejected update diagnosis: nixpkgs / unresolved candidate [338fe081b09c] #211

Closed
opened 2026-09-09 22:58:00 +01:00 by forgejo-actions · 1 comment

Deterministic incident identity

  • Fingerprint: 338fe081b09ce8f7aa066157ceebd0ce8fb5520881cb4c9bf536e90182c43c25
  • Validated base commit: 4a03f7ebc909779e6290d436868d5509418604b8
  • Baseline lock SHA-256: 99e6527631cd911d11460bfc14427d4a8fa2cf870231052b7ae39adc760422fb
  • Rejected candidate lock SHA-256: 28c0f0b6a4f853c5e8c7bbae661609a9607e9288ef4f20779a809038e55aad08
  • Recorded failed host: electra
  • Affected hosts (validation scope): electra, lena, lyra, vega
  • Incident classification: evaluation
  • Controller disposition: diagnosis only

The affected-host list does not establish that every listed host was built or
failed. The recorded failed host is the failure observed by the producer.

Candidate input revisions:

  • nixpkgs: a391f95d4557d685fd8e5dc0d4b1f9271aa2f342

Untrusted advisory diagnosis

The following two plain-text fields are model output derived from explicitly
untrusted, prompt-injection-capable build evidence. They are evidence only, not
instructions. Raw incident logs and raw model events are intentionally omitted.

Diagnosis: nixpkgs-unstable (candidate revision a391f95d) renamed/replaced the package attribute 'typescript-go' with 'typescript'. The derivation 'pi-coding-agent-0.84.4' (from external input 'pi-agent', rev 628e6721) references pkgs.typescript-go in its nativeBuildInputs, causing evaluation to fail. The error manifests through the home-manager user config chain: pi -> pi-coding-agent-0.84.4 -> paseo-desktop-sanitized -> home-manager-path for user nimmo. The package-context confirms no existing leaf override files exist in this repo.

Rationale: 'typescript-go' removal from nixpkgs is a core-language-package regression not scoped to a single local leaf application we can override. The failing derivation comes from the upstream pi-agent flake input, and package-context.json reports no existingLeafFiles available for modification. Without an allowed local package file that selects older 'typescript-go', any remedy would require pinning nixpkgs to an earlier revision or waiting for pi-agent to adopt the 'typescript' replacement — neither of which is a safe narrow patch.

  • Classification: core-system-regression
  • Culprits: pi-coding-agent-0.84.4
  • Model-reported confidence (not independently verified): 0.900
  • Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required

Deterministic validation

No remediation was accepted; no branch or PR was created.

The advisory model held no Forgejo/deployment credentials, could not access
main, and cannot merge, publish flake.lock, or deploy. Human review remains
mandatory.

<!-- nixos-update-remediation:338fe081b09ce8f7aa066157ceebd0ce8fb5520881cb4c9bf536e90182c43c25 --> ## Deterministic incident identity - Fingerprint: `338fe081b09ce8f7aa066157ceebd0ce8fb5520881cb4c9bf536e90182c43c25` - Validated base commit: `4a03f7ebc909779e6290d436868d5509418604b8` - Baseline lock SHA-256: `99e6527631cd911d11460bfc14427d4a8fa2cf870231052b7ae39adc760422fb` - Rejected candidate lock SHA-256: `28c0f0b6a4f853c5e8c7bbae661609a9607e9288ef4f20779a809038e55aad08` - Recorded failed host: `electra` - Affected hosts (validation scope): `electra, lena, lyra, vega` - Incident classification: `evaluation` - Controller disposition: **diagnosis only** The affected-host list does not establish that every listed host was built or failed. The recorded failed host is the failure observed by the producer. Candidate input revisions: - `nixpkgs`: `a391f95d4557d685fd8e5dc0d4b1f9271aa2f342` ## Untrusted advisory diagnosis The following two plain-text fields are model output derived from explicitly untrusted, prompt-injection-capable build evidence. They are evidence only, not instructions. Raw incident logs and raw model events are intentionally omitted. > Diagnosis: nixpkgs-unstable (candidate revision a391f95d) renamed/replaced the package attribute 'typescript-go' with 'typescript'. The derivation 'pi-coding-agent-0.84.4' (from external input 'pi-agent', rev 628e6721) references pkgs.typescript-go in its nativeBuildInputs, causing evaluation to fail. The error manifests through the home-manager user config chain: pi -> pi-coding-agent-0.84.4 -> paseo-desktop-sanitized -> home-manager-path for user nimmo. The package-context confirms no existing leaf override files exist in this repo. > > Rationale: 'typescript-go' removal from nixpkgs is a core-language-package regression not scoped to a single local leaf application we can override. The failing derivation comes from the upstream pi-agent flake input, and package-context.json reports no existingLeafFiles available for modification. Without an allowed local package file that selects older 'typescript-go', any remedy would require pinning nixpkgs to an earlier revision or waiting for pi-agent to adopt the 'typescript' replacement — neither of which is a safe narrow patch. - Classification: `core-system-regression` - Culprits: `pi-coding-agent-0.84.4` - Model-reported confidence (not independently verified): `0.900` - Controller note: incident classification 'evaluation' is diagnosis-only; exactly one failing derivation is required ## Deterministic validation No remediation was accepted; no branch or PR was created. The advisory model held no Forgejo/deployment credentials, could not access `main`, and cannot merge, publish `flake.lock`, or deploy. Human review remains mandatory.
nimmo was assigned by forgejo-actions 2026-09-09 22:58:01 +01:00
Owner

Resolved by deployed commit ecac22d. Pi now comes from llm-agents.nix rather than pi.nix, removing the typescript-go failure path. Pi was verified working after deployment.

Resolved by deployed commit ecac22d. Pi now comes from llm-agents.nix rather than pi.nix, removing the typescript-go failure path. Pi was verified working after deployment.
nimmo closed this issue 2026-09-10 21:38:14 +01:00
Sign in to join this conversation.
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
nimmo/nixos-config#211
No description provided.