depot

Public

Run full CI pipeline of the depot, TVL's monorepo.

  • //users/tazjin/tgsa: 4 advisories for Cargo.lock
  • //users/tazjin/finito: 4 advisories for Cargo.lock
    • chrono 0.4.11: RUSTSEC-2020-0159, patched: >=0.4.20
    • generic-array 0.9.0: RUSTSEC-2020-0146 (CVE-2020-36465, GHSA-3358-4f7f-p4j4), patched: >=0.8.4, <0.9.0; >=0.9.1, <0.10.0; >=0.10.1, <0.11.0; >=0.11.2, <0.12.0; >=0.12.4, <0.13.0; >=0.13.3
    • smallvec 1.4.0: RUSTSEC-2021-0003 (CVE-2021-25900, GHSA-43w2-9j62-hq99), patched: >=0.6.14, <1.0.0; >=1.6.1
    • time 0.1.43: RUSTSEC-2020-0071 (CVE-2020-26235, GHSA-wcg3-cvx6-7396), patched: >=0.2.23
  • //users/tazjin/yddns: 5 advisories for Cargo.lock
  • //users/aspen/achilles: 2 advisories for Cargo.lock
  • //users/aspen/xanthous/server: 3 advisories for Cargo.lock
    • mio 0.8.4: RUSTSEC-2024-0019 (CVE-2024-27308, GHSA-r8w9-5wcg-vfj7), patched: >=0.8.11
    • remove_dir_all 0.5.3: RUSTSEC-2023-0018 (GHSA-mc8h-8q98-g5hr), patched: >=0.8.0
    • tokio 1.21.2: RUSTSEC-2023-0001 (CVE-2023-22466, GHSA-7rrj-xr53-82p7), patched: >=1.18.4, <1.19.0; >=1.20.3, <1.21.0; >=1.23.1
  • //ops/journaldriver: 1 advisories for Cargo.lock
  • //ops/yandex-cloud-rs: 6 advisories for Cargo.lock
    • h2 0.3.19: RUSTSEC-2024-0003 (GHSA-8r5v-vm4m-4g25), patched: ^0.3.24; >=0.4.2
    • h2 0.3.19: RUSTSEC-2024-0332 (GHSA-q6cp-qfwq-4gcv), patched: ^0.3.26; >=0.4.4
    • mio 0.8.8: RUSTSEC-2024-0019 (CVE-2024-27308, GHSA-r8w9-5wcg-vfj7), patched: >=0.8.11
    • ring 0.16.20: RUSTSEC-2025-0009, patched: >=0.17.12
    • rustls 0.21.1: RUSTSEC-2024-0336 (CVE-2024-32650, GHSA-6g7w-8wpp-frhj), patched: >=0.23.5; >=0.22.4, <0.23.0; >=0.21.11, <0.22.0
    • rustls-webpki 0.100.1: RUSTSEC-2023-0053 (GHSA-fh2r-99q2-6mmg), patched: >=0.100.2, <0.101.0; >=0.101.4
  • //corp/rih/backend: 4 advisories for Cargo.lock
  • //web/atward: 1 advisories for Cargo.lock
  • //web/planet-mars: 2 advisories for Cargo.lock
  • //web/converse: 16 advisories for Cargo.lock
  • //net/alcoholic_jwt: 2 advisories for Cargo.lock
  • //tvix: 1 advisories for Cargo.lock
  • //fun/paroxysm: 2 advisories for Cargo.lock
  • //tools/cheddar: 1 advisories for Cargo.lock

This is a build of cl/13292 (at patchset #1)

:buildkite:buildkite-agent pipeline upload ops/pipelines/static-pipeline.yaml
Waited 1s
ยท
Ran in 3s
:llama:set -ue && if test -n "${GERRIT_CHANGE_URL-}"; then && echo "This is a build of [cl/$GERRIT_CHANGE_ID]($GERRIT_CHANGE_URL) (at patchset #$GERRIT_PATCHSET)" | \ && buildkite-agent annotate --context cl-annotation && fi && # Attempt to fetch a target map from a parent commit on canon, && # except on builds of canon itself. && [ "cl/13292" != "refs/heads/canon" ] && \ && nix/buildkite/fetch-parent-targets.sh && PIPELINE_ARGS="" && if [[ -f tmp/parent-target-map.json ]]; then && PIPELINE_ARGS="--arg parentTargetMap tmp/parent-target-map.json" && fi && nix-build --option restrict-eval true --include "depot=${PWD}" \ && --include "store=/nix/store" \ && --allowed-uris 'https://' \ && -A ops.pipelines.depot \ && -o pipeline --show-trace $PIPELINE_ARGS && # Steps need to be uploaded in reverse order because pipeline && # upload prepends instead of appending. && ls pipeline/build-chunk-*.json | tac | while read chunk; do && buildkite-agent pipeline upload $chunk && done && buildkite-agent artifact upload "pipeline/*"
Waited 1s
ยท
Ran in 2m 12s
โš™๏ธ ๐Ÿƒ protoCheck (from nix/bufCheck)set -ueo pipefail && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/v0x24rg3jifqajgx77sqfnmng3py3gxw-ci-buf-check-step.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/v0x24rg3jifqajgx77sqfnmng3py3gxw-ci-buf-check-step.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "protoCheck" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "bufCheck" (builtins.getAttr "nix" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 2s
ยท
Ran in 2s
:nix: ops/nixos:sandunySystemset -o pipefail; (nix-store --realise '/nix/store/a5hvkh2i9p67vb2msl3wbjq8s0p353js-nixos-system-sanduny-25.05pre-git.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/a5hvkh2i9p67vb2msl3wbjq8s0p353js-nixos-system-sanduny-25.05pre-git.drv' && nix-build -E 'builtins.getAttr "sandunySystem" (builtins.getAttr "nixos" (builtins.getAttr "ops" (import ./. {})))' --show-trace --out-link 'result')
Waited 1s
ยท
Ran in 16s
:nix: ops/nixos:bugrySystemset -o pipefail; (nix-store --realise '/nix/store/ywfb8ria2hw9bdwwxmhczfc7aacbjwax-nixos-system-bugry-25.05pre-git.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/ywfb8ria2hw9bdwwxmhczfc7aacbjwax-nixos-system-bugry-25.05pre-git.drv' && nix-build -E 'builtins.getAttr "bugrySystem" (builtins.getAttr "nixos" (builtins.getAttr "ops" (import ./. {})))' --show-trace --out-link 'result')
Waited 1s
ยท
Ran in 17s
:nix: ops/nixos:nevskySystemset -o pipefail; (nix-store --realise '/nix/store/cyxp267bbhinkr34g2li65scmr4kcpih-nixos-system-nevsky-25.05pre-git.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/cyxp267bbhinkr34g2li65scmr4kcpih-nixos-system-nevsky-25.05pre-git.drv' && nix-build -E 'builtins.getAttr "nevskySystem" (builtins.getAttr "nixos" (builtins.getAttr "ops" (import ./. {})))' --show-trace --out-link 'result')
Waited 2s
ยท
Ran in 21s
:nix: ops/yandex-base-imageset -o pipefail; (nix-store --realise '/nix/store/pafs2yvzq0n9585maqlzdajs7kbk5wcx-nixos-disk-image.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/pafs2yvzq0n9585maqlzdajs7kbk5wcx-nixos-disk-image.drv' && nix-build -E 'builtins.getAttr "yandex-base-image" (builtins.getAttr "ops" (import ./. {}))' --show-trace --out-link 'result')
Waited 2s
ยท
Ran in 1m 16s
โš™๏ธ depot formatting check (from tools/depotfmt)set -ueo pipefail && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/n1rz8aps4hph1d8xajvnwv8783f0nd1d-depotfmt-check.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/n1rz8aps4hph1d8xajvnwv8783f0nd1d-depotfmt-check.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "depotfmt" (builtins.getAttr "tools" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 2s
ยท
Ran in 2s
โš™๏ธ Check all crates used in depot for advisories (from tools/rust-crates-advisory:tree-lock-file-report)set -ueo pipefail && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/w7a4ab10l6ckhmx8ls8xss14s6gsjh6p-buildkite-report-depot-advisory-report.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/w7a4ab10l6ckhmx8ls8xss14s6gsjh6p-buildkite-report-depot-advisory-report.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "run" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "tree-lock-file-report" (builtins.getAttr "rust-crates-advisory" (builtins.getAttr "tools" (import ./. {}))))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 2s
ยท
Ran in 2s
โš™๏ธ ๐Ÿƒ ensure generated protobuf files match (from tvix/build-go)set -ueo pipefail && echo '~~~ Preparing build output of tvix/build-go' && set -o pipefail; (nix-store --realise '/nix/store/m09nib3nxsxs28ybwwnavygmhxxlgrci-build-go.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/m09nib3nxsxs28ybwwnavygmhxxlgrci-build-go.drv' && nix-build -E 'builtins.getAttr "build-go" (builtins.getAttr "tvix" (import ./. {}))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/kb5g1hmxgz6vhhygj6rhrz3kx1jn066y-pb-go-check.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/kb5g1hmxgz6vhhygj6rhrz3kx1jn066y-pb-go-check.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "build-go" (builtins.getAttr "tvix" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 3s
ยท
Ran in 1s
โš™๏ธ ๐Ÿƒ ensure generated protobuf files match (from tvix/castore-go)set -ueo pipefail && echo '~~~ Preparing build output of tvix/castore-go' && set -o pipefail; (nix-store --realise '/nix/store/1xidsxw6g0c61xkhdxr1sjaing6wf1hj-castore-go.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/1xidsxw6g0c61xkhdxr1sjaing6wf1hj-castore-go.drv' && nix-build -E 'builtins.getAttr "castore-go" (builtins.getAttr "tvix" (import ./. {}))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/ljnh5mfajsnnb9qr07f75kr2bvbm7sqr-pb-go-check.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/ljnh5mfajsnnb9qr07f75kr2bvbm7sqr-pb-go-check.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "castore-go" (builtins.getAttr "tvix" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 3s
ยท
Ran in 1s
โš™๏ธ ๐Ÿƒ ensure generated protobuf files match (from tvix/store-go)set -ueo pipefail && echo '~~~ Preparing build output of tvix/store-go' && set -o pipefail; (nix-store --realise '/nix/store/7w07dbsq3p1n8m6hpgkrprc3v82spcs0-store-go.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/7w07dbsq3p1n8m6hpgkrprc3v82spcs0-store-go.drv' && nix-build -E 'builtins.getAttr "store-go" (builtins.getAttr "tvix" (import ./. {}))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/m8ns2hk69nyxmycx9hvn1a3w5mh7cg8a-pb-go-check.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/m8ns2hk69nyxmycx9hvn1a3w5mh7cg8a-pb-go-check.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "store-go" (builtins.getAttr "tvix" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 3s
ยท
Ran in 1s
โš™๏ธ crate2nix check for tvix (from tvix:crate2nix-check)set -ueo pipefail && echo '~~~ Preparing build output of tvix:crate2nix-check' && set -o pipefail; (nix-store --realise '/nix/store/ysr9i9imdpi98gab1xf89yya4c06grhz-crate2nix-check-for-tvix.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/ysr9i9imdpi98gab1xf89yya4c06grhz-crate2nix-check-for-tvix.drv' && nix-build -E 'builtins.getAttr "crate2nix-check" (builtins.getAttr "tvix" (import ./. {}))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/ysr9i9imdpi98gab1xf89yya4c06grhz-crate2nix-check-for-tvix.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/ysr9i9imdpi98gab1xf89yya4c06grhz-crate2nix-check-for-tvix.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "crate2nix-check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "crate2nix-check" (builtins.getAttr "tvix" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 3s
ยท
Ran in 2s
โš™๏ธ crate2nix check for users/picnoir/tvix-daemon (from users/picnoir/tvix-daemon:crate2nix-check)set -ueo pipefail && echo '~~~ Preparing build output of users/picnoir/tvix-daemon:crate2nix-check' && set -o pipefail; (nix-store --realise '/nix/store/lh83z1hfzl6wyjmivc6zns45wiw32scm-crate2nix-check-for-users-picnoir-tvix-daemon.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/lh83z1hfzl6wyjmivc6zns45wiw32scm-crate2nix-check-for-users-picnoir-tvix-daemon.drv' && nix-build -E 'builtins.getAttr "crate2nix-check" (builtins.getAttr "tvix-daemon" (builtins.getAttr "picnoir" (builtins.getAttr "users" (import ./. {}))))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/lh83z1hfzl6wyjmivc6zns45wiw32scm-crate2nix-check-for-users-picnoir-tvix-daemon.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/lh83z1hfzl6wyjmivc6zns45wiw32scm-crate2nix-check-for-users-picnoir-tvix-daemon.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "crate2nix-check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "crate2nix-check" (builtins.getAttr "tvix-daemon" (builtins.getAttr "picnoir" (builtins.getAttr "users" (import ./. {})))))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 3s
ยท
Ran in 1s
:nix: web/bubblegum/examplesset -o pipefail; (nix-store --realise '/nix/store/gn8qrcpr9awzxbc9bk3bswdx37p8940b-serve-examples.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/gn8qrcpr9awzxbc9bk3bswdx37p8940b-serve-examples.drv' && nix-build -E 'builtins.getAttr "examples" (builtins.getAttr "bubblegum" (builtins.getAttr "web" (import ./. {})))' --show-trace --out-link 'result')
Waited 1s
ยท
Ran in 1s
:nix: web/todolistset -o pipefail; (nix-store --realise '/nix/store/axhw2c9qhdr6h0856sn1ar52i8xadl7n-tvl-todos.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/axhw2c9qhdr6h0856sn1ar52i8xadl7n-tvl-todos.drv' && nix-build -E 'builtins.getAttr "todolist" (builtins.getAttr "web" (import ./. {}))' --show-trace --out-link 'result')
Waited 1s
ยท
Ran in 1s
โš™๏ธ crate2nix check for web/tvixbolt (from web/tvixbolt)set -ueo pipefail && echo '~~~ Preparing build output of web/tvixbolt' && set -o pipefail; (nix-store --realise '/nix/store/abicikvd7dhpbrn17pa2d6qygj11f40g-rust_tvixbolt-0.1.0.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/abicikvd7dhpbrn17pa2d6qygj11f40g-rust_tvixbolt-0.1.0.drv' && nix-build -E 'builtins.getAttr "tvixbolt" (builtins.getAttr "web" (import ./. {}))' --show-trace --out-link 'result') && echo '--- Building extra step script' && command_script="$(set -o pipefail; (nix-store --realise '/nix/store/mmgx53842595z1an5r2hc09hf6xv7vz4-crate2nix-check-for-web-tvixbolt.drv' --add-root 'nix-buildkite-extra-step-command-script' --indirect | xargs -r realpath) || (test ! -f '/nix/store/mmgx53842595z1an5r2hc09hf6xv7vz4-crate2nix-check-for-web-tvixbolt.drv' && nix-build -E 'builtins.getAttr "command" (builtins.getAttr "crate2nix-check" (builtins.getAttr "extraSteps" (builtins.getAttr "ci" (builtins.getAttr "meta" (builtins.getAttr "tvixbolt" (builtins.getAttr "web" (import ./. {})))))))' --show-trace --out-link 'nix-buildkite-extra-step-command-script'))" && echo '+++ Running extra step script' && # ATTN: buildkite substitutes this variable outside of the execution for some reason && exec "$command_script"
Waited 2s
ยท
Ran in 2s
:nix: web/tvlset -o pipefail; (nix-store --realise '/nix/store/2gpsrspm15kzxhcbwb8cv75g02hxwq7f-website.drv' --add-root 'result' --indirect | xargs -r realpath) || (test ! -f '/nix/store/2gpsrspm15kzxhcbwb8cv75g02hxwq7f-website.drv' && nix-build -E 'builtins.getAttr "tvl" (builtins.getAttr "web" (import ./. {}))' --show-trace --out-link 'result')
Waited 2s
ยท
Ran in 2s
Build will continue even if previous stage fails
๐Ÿฆ†set -ueo pipefail && readonly FAILED_JOBS=$(curl 'https://graphql.buildkite.com/v1' \ && --silent \ && -H "Authorization: Bearer $(cat /run/agenix/buildkite-graphql-token)" \ && -d "{\"query\": \"query BuildStatusQuery { build(uuid: \\\"0195c32f-f830-45f6-ad0b-4145a768098b\\\") { jobs(passed: false, first: 500 ) { edges { node { ... on JobTypeCommand { retried } } } } } }\"}" | \ && jq -r '.data.build.jobs.edges | map(select(.node.retried == false)) | length') && echo "$FAILED_JOBS build jobs failed." && if (( $FAILED_JOBS > 0 )); then && exit 1 && fi
Waited 1s
ยท
Ran in 2s
โคต๏ธset -ueo pipefail && buildkite-agent artifact download "pipeline/*" . && find ./pipeline -name 'release-chunk-*.json' | tac | while read chunk; do && buildkite-agent pipeline upload $chunk && done
Waited 1s
ยท
Ran in 4s
Total Job Run Time: 4m 50s