kb-eval-nix: a failed .drv closure push fails the eval (SPEC §7.3) #26

Manually merged
krisbuild merged 1 commit from lu/eval-push-fatal into main 2026-09-27 22:47:40 +02:00
Owner

What

  • A failed .drv closure push fails the eval. With a cache-push target configured, publishing the evaluated derivation closure that fails every retry now fails the eval whatever KB_CACHE_PUSH_ON_FAILURE says. The error names the target and the push error ("publishing the evaluated derivation closure to failed; no other node could build this graph, so the eval fails rather than be cached" + the "failed after 3 attempts: …" cause). No target: unchanged. Logic in publish_derivations() (run.rs).
  • Honest log summary. The evaluated line is logged after publishing, with reconciled (locally-held outputs pushed so their derivations could be pruned — the old, misleading pushed=) and published (roots whose .drv closure reached the target).
  • Docs: OnFailure governs output pushes only; SPEC §7.3; forgejo-setup.md on_failure row.

Why

Live incident: the ares agent's attic token lacked push permission. Its evals logged WARN … derivation closure not published … AccessError, exited 0 and were cached (an eval is pure), so tasks placed on nuxbox failed downstream with "no substituter can build " — and since a cached eval replay never re-pushes derivations, not even a rerun could recover; only a new tree did. warn trades a missing output for a green task; it doesn't fit the drv closure, without which no other node can build anything in the graph.

Tests

  • run::tests::a_failed_derivation_push_fails_the_eval_even_under_warn (always-failing push command under warn → error naming the closure, retries and target; no target → Ok(0); working push → Ok(1)).
  • e2e (needs nix; skipped in the sandbox): an_unreachable_push_target_fails_the_evaluation now expects failure under warn; a_locally_held_path_is_published_before_it_is_pruned reads reconciled/published.

Operational note: the evaluated log field pushed= is now reconciled=.

🤖 Generated with Claude Code

### What - **A failed `.drv` closure push fails the eval.** With a cache-push target configured, publishing the evaluated derivation closure that fails every retry now fails the eval whatever `KB_CACHE_PUSH_ON_FAILURE` says. The error names the target and the push error ("publishing the evaluated derivation closure to <target> failed; no other node could build this graph, so the eval fails rather than be cached" + the "failed after 3 attempts: …" cause). No target: unchanged. Logic in `publish_derivations()` (`run.rs`). - **Honest log summary.** The `evaluated` line is logged after publishing, with `reconciled` (locally-held outputs pushed so their derivations could be pruned — the old, misleading `pushed=`) and `published` (roots whose `.drv` closure reached the target). - Docs: `OnFailure` governs output pushes only; SPEC §7.3; forgejo-setup.md `on_failure` row. ### Why Live incident: the ares agent's attic token lacked push permission. Its evals logged `WARN … derivation closure not published … AccessError`, exited 0 and were **cached** (an eval is pure), so tasks placed on nuxbox failed downstream with "no substituter can build <drv>" — and since a cached eval replay never re-pushes derivations, not even a rerun could recover; only a new tree did. `warn` trades a missing *output* for a green task; it doesn't fit the drv closure, without which no other node can build anything in the graph. ### Tests - `run::tests::a_failed_derivation_push_fails_the_eval_even_under_warn` (always-failing push command under `warn` → error naming the closure, retries and target; no target → `Ok(0)`; working push → `Ok(1)`). - e2e (needs nix; skipped in the sandbox): `an_unreachable_push_target_fails_the_evaluation` now expects failure under `warn`; `a_locally_held_path_is_published_before_it_is_pruned` reads `reconciled`/`published`. Operational note: the `evaluated` log field `pushed=` is now `reconciled=`. 🤖 Generated with [Claude Code](https://claude.com/claude-code)
kb-eval-nix: a failed .drv closure push fails the eval (SPEC §7.3)
All checks were successful
krisbuild/kris/krisbuild/nix/test-deps cached
krisbuild/kris/krisbuild/nix/hello cached
krisbuild/kris/krisbuild/nix/workspace-deps cached
krisbuild/kris/krisbuild/nix/world cached
krisbuild/kris/krisbuild/nix/test cached
krisbuild/kris/krisbuild/nix/clippy cached
krisbuild/kris/krisbuild/nix/build succeeded
krisbuild/kris/krisbuild/nix/kb-check succeeded
krisbuild/kris/krisbuild krisbuild kris/krisbuild: all tasks succeeded
krisbuild/queue merged
94f09318b3
With a push target configured, publishing the evaluated derivation closure
failing every retry now fails the eval regardless of
KB_CACHE_PUSH_ON_FAILURE, with an error naming the target and the push
error. `warn` is an output-push policy: without the derivations no other
node can build any task of the graph, and an eval is pure, so a success
was cached and replayed with its drvs still missing - not even a rerun
recovered, only a new tree. Without a target nothing changes.

The `evaluated` summary now logs after publishing and says what it
counts: `reconciled` (locally-held outputs pushed so their derivations
could be pruned, formerly the misleading `pushed`) and `published` (roots
whose .drv closure reached the target; 0 without one).

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Author
Owner
@krisbuild r+
Collaborator

The pull request head's own build failed (graph 658).

  • nix/build: exit-code on nuxbox, exit 1 — log

Push a fix, or comment @krisbuild retry to rerun the failed tasks and requeue.

The pull request head's own build failed ([graph 658](http://192.168.0.2:1337/ui/graphs/658)). - `nix/build`: exit-code on nuxbox, exit 1 — [log](http://192.168.0.2:1337/ui/instances/18191) Push a fix, or comment `@krisbuild retry` to rerun the failed tasks and requeue.
Collaborator

Removed from the merge queue: the pull request was closed.

Removed from the merge queue: the pull request was closed.
Author
Owner
@krisbuild r+
krisbuild manually merged commit 7adbaf5522 into main 2026-09-27 22:47:40 +02:00
Collaborator

Merged as 7adbaf5522.

Merged as 7adbaf552256.
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
2 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
kris/krisbuild!26
No description provided.