fix(ci): memory-bounded eval — one output per nix process
Some checks failed
Check / eval (push) Failing after 7m59s
Some checks failed
Check / eval (push) Failing after 7m59s
check.yml has been permanently red since the runner container was
capped at 2 GB (uncapped, it OOM'd the whole 4 GB VPS). Root cause,
measured with GNU time (eval-cache off): `nix flake check --no-build`
walks every output in ONE evaluator process and peaks at ~6.0 GB RSS
on this repo — the checks.* suite alone is ~15 runNixOSTests, each a
full NixOS eval, all accumulating in one heap.
New tools/ci-eval.sh: identical coverage (all checks.* drvPaths, both
nixosConfigurations toplevels, the HM activationPackage — enumerated
dynamically, no drift), one fresh nix process per output so the heap is
freed between outputs. Cold per-output peaks: worst check 0.99 GB
(hardware-toggles), nomarchy toplevel 0.78 GB, HM 0.60 GB; the one
outlier is nomarchy-live at 2.69 GB (live-ISO eval), which fits the
2 GB cap only via the container's swap allowance (docker's default
--memory-swap is 2x memory). check.yml and bump.yml both call the
script now; bump.yml also gains max-jobs=1/cores=2 (it had no limits,
so its V1 build gate could spawn parallel builders in the capped
container). ROADMAP's stale "no CI today" corrected: bump.yml landed
8fded63 on schedule 2026-07-06.
Verified: V1+ — ci-eval.sh green locally end-to-end (3m22s, tree peak
2.75 GB = nomarchy-live's process); per-output peaks measured
individually. The decisive proof is the next Actions run on the VPS
itself — watch the nomarchy-live step; if it OOMs there, the runner
needs swap allowed: --memory=2g --memory-swap=6g.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -36,6 +36,8 @@ jobs:
|
||||
timeout-minutes: 90
|
||||
env:
|
||||
NIX_CONFIG: |
|
||||
max-jobs = 1
|
||||
cores = 2
|
||||
experimental-features = nix-command flakes
|
||||
sandbox = false
|
||||
NIX_SSL_CERT_FILE: /etc/ssl/certs/ca-certificates.crt
|
||||
@@ -68,9 +70,12 @@ jobs:
|
||||
fi
|
||||
id: update
|
||||
|
||||
- name: Gate — nix flake check (eval only)
|
||||
- name: Gate — evaluate every output (eval tier, memory-bounded)
|
||||
# Per-output processes, not one big `nix flake check --no-build`:
|
||||
# the single-process walk peaks ~6 GB RSS and OOMs inside the
|
||||
# runner's 2 GB container cap (details in tools/ci-eval.sh).
|
||||
if: steps.update.outputs.changed == '1'
|
||||
run: nix flake check --no-build
|
||||
run: bash tools/ci-eval.sh
|
||||
|
||||
- name: Gate — V1 build (toplevel + home-manager)
|
||||
if: steps.update.outputs.changed == '1'
|
||||
|
||||
@@ -57,11 +57,15 @@ jobs:
|
||||
curl -L "https://releases.nixos.org/nix/nix-${NIX_VERSION}/install" | sh -s -- --no-daemon
|
||||
echo "$HOME/.nix-profile/bin" >> "$GITHUB_PATH"
|
||||
|
||||
- name: nix flake check (eval only)
|
||||
# Full module-system evaluation of every output — both nixos
|
||||
- name: Evaluate every output (eval tier, memory-bounded)
|
||||
# Same coverage as `nix flake check --no-build` — both nixos
|
||||
# configs, the home config, the checks.* derivations (instantiated,
|
||||
# not run) and the downstream template through lib.mkFlake.
|
||||
run: nix flake check --no-build
|
||||
# not run) and the downstream template through lib.mkFlake — but
|
||||
# ONE output per nix process. A single process walking everything
|
||||
# peaks at ~6.0 GB RSS (measured 2026-07-12): it OOM'd the 4 GB
|
||||
# VPS itself, and can never fit this runner's 2 GB container cap.
|
||||
# Per-output processes cap at the largest single output (~1 GB).
|
||||
run: bash tools/ci-eval.sh
|
||||
|
||||
- name: Python syntax (all tracked scripts)
|
||||
# Every tracked *.py — theme-sync, the installer composers
|
||||
|
||||
Reference in New Issue
Block a user