fix(nix): refresh the registry pnpmDeps hash — npm.forgegraf.com could not build #491

Closed
gmackie wants to merge 0 commits from fix/registry-pnpm-deps-hash into main
Owner

One of 8 critical deploy_failed alerts, and the one that is ours.

npm-registry has not deployed since 2026-08-13. Every attempt dies the same way:

error: hash mismatch in fixed-output derivation forgegraph-registry-pnpm-deps.drv
  specified: sha256-cSpsy3dC16ypMlnRe7hSygIEGukW+vw/ez415BnlH9g=
       got:  sha256-KPYVfGFQcIJpoXeea+uJpzxs7I4AWW1Ub15oHyCN69k=

The flake's pnpmDeps hash still describes an older pnpm-lock.yaml. That matters more than one red app: npm.forgegraf.com is the registry serving every @forgegraph package — agent releases and @forgegraph/check-events publish through it — so a stale hash here quietly blocks the publish path while everything else looks green.

The replacement hash is the build's own reported got: at rev 145d0cd17f, which is still main's head with pnpm-lock.yaml untouched since (verified: no commit between that rev and main touches the lockfile), so it is current rather than already-drifted.

Diagnosis of the other seven, for the record — they are six unrelated causes, not one outage:

  • playtrek, playtrek-engine — same ERR_PNPM_NO_OFFLINE_TARBALL / pnpmDeps drift, in their own repo
  • jobs-pulse — wrangler deploy --name jobs-pulse-onebox exits 1
  • gt-ops-edge — the frappe-edge-proxy systemd unit fails to start
  • linear-clone — native better-sqlite3 install fails
  • latchflow-beta — cp: cannot stat wrangler.beta.jsonc: the file is gone
  • check-events-demo — mine, from the fork-bomb build; retires on its own

🤖 Generated with Claude Code

One of 8 critical `deploy_failed` alerts, and the one that is ours. **npm-registry has not deployed since 2026-08-13.** Every attempt dies the same way: ``` error: hash mismatch in fixed-output derivation forgegraph-registry-pnpm-deps.drv specified: sha256-cSpsy3dC16ypMlnRe7hSygIEGukW+vw/ez415BnlH9g= got: sha256-KPYVfGFQcIJpoXeea+uJpzxs7I4AWW1Ub15oHyCN69k= ``` The flake's `pnpmDeps` hash still describes an older `pnpm-lock.yaml`. That matters more than one red app: npm.forgegraf.com is the registry serving every `@forgegraph` package — agent releases and `@forgegraph/check-events` publish through it — so a stale hash here quietly blocks the publish path while everything else looks green. The replacement hash is the build's own reported `got:` at rev `145d0cd17f`, which is still main's head with `pnpm-lock.yaml` untouched since (verified: no commit between that rev and main touches the lockfile), so it is current rather than already-drifted. **Diagnosis of the other seven, for the record** — they are six unrelated causes, not one outage: - `playtrek`, `playtrek-engine` — same `ERR_PNPM_NO_OFFLINE_TARBALL` / pnpmDeps drift, in their own repo - `jobs-pulse` — `wrangler deploy --name jobs-pulse-onebox` exits 1 - `gt-ops-edge` — the frappe-edge-proxy systemd unit fails to start - `linear-clone` — native `better-sqlite3` install fails - `latchflow-beta` — `cp: cannot stat wrangler.beta.jsonc`: the file is gone - `check-events-demo` — mine, from the fork-bomb build; retires on its own 🤖 Generated with [Claude Code](https://claude.com/claude-code)
gmackie closed this pull request 2026-08-27 19:32:52 +00:00
gmackie reopened this pull request 2026-08-27 19:44:30 +00:00
Author
Owner

Superseded by a fresh PR from the same branch — see below.

This PR's record is stuck on a stale cached merge-base. It was opened when the branch pointed at 8cf344f2 (a commit from 2026-08-17 that is already in main, which is why this PR showed 0 files for so long). I have now pushed the actual fix, but Forgejo still reports merge_base: 8cf344f2 and renders a bogus 696 files / +74300 −43101 diff. Git disagrees:

merge-base(head, main):  e641b37d   (== main)
files in head...main:    1

Closing and reopening did not clear the cache, so the PR is reopened cleanly rather than left displaying a diff that would be alarming and unreviewable.

The fix itself is on fix/registry-pnpm-deps-hash at 99c34804 — one line in flake.nix, and the hash was computed rather than transcribed (built .#registry on hetzner-worker with a sentinel hash and took what nix reported). Worth noting the value quoted in this PR's original description differs from the computed one by a single character — …KPYVfGFW… vs …KPYVfGFQ… — which would have reproduced the same deploy failure while looking right.

Superseded by a fresh PR from the same branch — see below. This PR's record is stuck on a **stale cached merge-base**. It was opened when the branch pointed at `8cf344f2` (a commit from 2026-08-17 that is already in `main`, which is why this PR showed 0 files for so long). I have now pushed the actual fix, but Forgejo still reports `merge_base: 8cf344f2` and renders a bogus **696 files / +74300 −43101** diff. Git disagrees: ``` merge-base(head, main): e641b37d (== main) files in head...main: 1 ``` Closing and reopening did not clear the cache, so the PR is reopened cleanly rather than left displaying a diff that would be alarming and unreviewable. **The fix itself is on `fix/registry-pnpm-deps-hash` at `99c34804`** — one line in `flake.nix`, and the hash was computed rather than transcribed (built `.#registry` on hetzner-worker with a sentinel hash and took what nix reported). Worth noting the value quoted in this PR's original description differs from the computed one by a single character — `…KPYVfGFW…` vs `…KPYVfGFQ…` — which would have reproduced the same deploy failure while looking right.
gmackie closed this pull request 2026-08-27 19:44:54 +00:00
All checks were successful
CI / gitleaks (pull_request) Successful in 6s
Required
Details
CI / ci (pull_request) Successful in 9m9s
Required
Details
forgegraph/ci CI passed

Pull request closed

Sign in to join this conversation.
No reviewers
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
gmackie/ForgeGraph!491
No description provided.