Skip to content

Documentation

Prompt rewrite 3.0

Corpus 3.0 rewrites every `tasks/*/prompt.md` to fix two problems with the 2.0

Maintained in docs/prompt-rewrite-3.0.md

Documentation

Corpus 3.0 rewrites every tasks/*/prompt.md to fix two problems with the 2.0 prompts:

  1. **Leaks.** 18 of 29 prompts ended with a "Source Context" section linking

to the forum thread or issue the task was modeled on. Those threads usually contain the accepted fix, so the links pointed the agent at the answer. The links and their prose now live only in research-derived-tasks.md, verbatim, under "Source notes".

  1. **Over-specification.** Most prompts listed the rubric itself: option paths,

helper names, and exact attribute shapes. The hidden evaluators then measured instruction-following, not Nix knowledge.

The rewritten prompts describe what the user observes (the error text, the failing command, or the wrong behaviour), the expected behaviour, and the hard constraints that are part of the task. They name an implementation detail only when the evaluator cannot accept an alternative. In that case the detail is phrased as a requirement, not a recipe. Arbitrary interface names, such as output attribute names, fixed identities, and marker values, stay explicit because no amount of Nix knowledge can recover them.

No evaluator (tests/check.sh) changed as part of this rewrite. The evaluator-semantics work for 3.0 makes evaluators accept idiomatic alternatives: a real vendored lib with evalModules, enable probes instead of fixed mkIf placement, two-argument overrideAttrs, modern buildPythonPackage attributes, an optional leaveDotGit, and allowing lib.getExe. Rows marked † dropped a detail that only the 2.0 evaluator required. They assume that evaluator change and must ship with it.

Every reference solution was re-read against its rewritten prompt and satisfies it. No reference changed.

Per-task changes

TaskRemoved from the promptKept, and why
container-native-vs-oci †Source Context. The option names autoStart, privateNetwork, bindMounts, isReadOnly, and services.openssh.enable. The list of forbidden OCI fields. The fake-lib description for the nested config.The container name, the four behaviours (start at boot, private network, writable USB bind at the same path, SSH server), and the no-OCI constraint, which is the point of the task.
debug-infinite-recursionNothing substantive.Added the observed infinite recursion encountered error. Kept the exact expected attrset, because the evaluator checks exact output. Kept the default-lib constraint, because the file must evaluate with only optional in its default lib.
debug-network-false-leadSource Context. The case-by-case decision table (ARP case, DNS case, and "even if DNS fails").The input schema and output fields, the fact-code sets, and the discarded code vocabulary. All of these are an API contract graded by exact value. The decision table is replaced by one diagnostic principle (bottom-up, lowest failing layer), from which the graded cases follow.
devshell-tooling-contract †The mkShell recipe wording and the packages attribute; any of packages, nativeBuildInputs, or buildInputs passes. The instruction to preserve existing NIX_CONFIG, which was ungraded and which the reference does not do. It is now conditional guidance: if you keep the old value, use a new line. The shell-hook location for NIX_CONFIG.The shell name, the four tools, optional alejandra, NIXBENCH_FORMATTER (an arbitrary project contract), and the experimental features enabled through NIX_CONFIG.
fetcher-source-pin †The attribute recipe (owner =, rev, fetchSubmodules = true, leaveDotGit = false).The repository identity, the commit-pin and SRI-hash requirements (the regex-graded shapes, stated as requirements), and the submodule and no-.git behaviour, stated as outcomes.
fhs-binary-wrapper †Source Context. The appimageTools.wrapType2 and buildFHSUserEnv helper names, the attribute-by-attribute recipe, and the literal run-script value.The output attribute names appimage and fhsEnv, the identities (pname, version, environment name), the fetchurl and SRI pin, the required libraries, and that the environment launches vendor-tool. Added the type-2 AppImage fact a packager would know. Kept the no-host-mutation constraint.
flake-input-package-selection †Source Context. The exact attribute path inputs.legacylauncher.packages.${pkgs.system}.legacylauncher.Added the observed attribute 'default' missing error. Kept the three-package result, the per-system selection, package values rather than strings, no default, and the function signature.
flake-per-system-outputsThe builtins.derivation with builtin:buildenv implementation hint.The systems list, identities, app program location and meta.package, the checks.eval and dev shell tools contract, and lib.systems. These are arbitrary interface values graded exactly. Kept the no-inputs and real-derivation constraints.
home-manager-extra-special-argsSource Context. The answer itself (home-manager.extraSpecialArgs = { inherit inputs; }). The line-by-line restatement of the starter.Added the observed attribute 'inputs' missing error. Kept "keep NixOS specialArgs", the NixOS-module integration, the no-standalone constraint, and the inline settings module (where the evaluator looks for Home Manager settings).
home-manager-wsl-module-importSource Context. The attribute recipe (imports, useGlobalPkgs, useUserPackages, users.nixos.programs.git.enable).Added the pure-evaluation lookup error. Kept the homeManagerModule argument, WSL with default user nixos, behavioural descriptions of the two Home Manager settings, Git for the user, and the ban on channel paths and the standalone entry point.
home-manager-xdg-filesSource Context. The option paths xdg.userDirs.*, xdg.configFile."…".text, and home.file."…".text.The directory locations and file contents as outcomes. Kept XDG config-file support and inline text, because the evaluator reads that option's text. Kept the function signature and the no-imperative constraint.
issue-report-qualitySource Context. The literal values for failureClass, expectedStatus, actualStatus, and confidence.The report schema (field names are an API contract). The literal values are now chosen from stated vocabularies, so the agent must classify the failure. Kept the bounded-analysis rule and the no-AI-mention rule.
lang-attrsets-normalizeNothing substantive; the prompt was already behavioural.The function shape and output fields. Made explicit two graded requirements the old prompt left implicit: keep both argument defaults, and sort every name list.
module-path-compositionThe recipe: use path addition with string suffixes, parenthesize additions in lists, and the interpolation explanation.Added the real parse error. Kept the expected imports and file sources, the passthru.importNames contract, and the path-not-string constraint (graded by type).
module-service-options †lib.mkEnableOption, lib.mkIf cfg.enable, the networking.firewall.allowedTCPPorts path, and the restricted-lib warning.The option names, types, and defaults (the module's public interface), the ExecStart command line, the firewall outcome (added to, not replacing, ports other modules open), and "disabled means no config".
module-stale-option-migrationSource Context. All four current option paths, which were the answer.The rename and removal symptoms on 25.05 and the intended machine state (SDDM, Plasma 6, graphics, KDE Connect). Kept the constraint that no stale path may remain.
module-system-boundariesSource Context. The per-module option recipe (environment.systemPackages and home.packages).Added the two option does not exist errors. Kept the output attribute names, the shared-data contract, and the forbidden cross-system option namespaces.
mutable-config-home-managerSource Context. The full policies JSON and option paths (programs.thunderbird.enable, home.sessionVariables…).The read-only-profile symptom. Kept the THUNDERBIRD_PROFILE_DIR variable, the mutableState contract, the DisableAppUpdate policy name (Firefox-family policies offer a non-equivalent alternative), the policy file location, and the profile-ownership constraint.
nushell-command-not-found †Source Context. The lib.mkIf instruction.The Bash-versus-Nushell symptom. Kept programs.nushell.extraConfig and Nushell's hooks.command_not_found, the delivery points the fragment must use. Kept the nix-index executable call, the package install, and the gating behaviour.
overlay-module-boundarySource Context. Thirteen bullet points restating every value already present in the starter.The symptom (overlays cannot declare systemd.user, and they shadow systemd), "package unchanged, built with prev", "same unit settings in the module via pkgs", and both boundary constraints.
overlay-override-package †The overrideAttrs recipe and the attribute names doCheck, meta.broken, and dontStrip.The broken-on-musl scenario, the version and patch order, tests enabled, metadata preserved, the tinygrep-debug identity, and derivation from the final package set. Kept "modify rather than redefine" as a requirement, because the evaluator counts overrides.
package-name-lookup-contractSource Context. The exact attribute names eza, nixfmt-rfc-style, and nil, and the list of bad names.Added the attribute 'exa' missing symptom and the nixpkgs 24.11 naming baseline, so the correct attributes are determinable. The tools are described by role, and the exact-set constraint stays.
package-python-application †Every attribute recipe: buildPythonApplication, pyproject = true, nativeBuildInputs, pythonImportsCheck, pytestFlagsArray, and lib.licenses.asl20.Project facts (pyproject with hatchling, runtime and test dependencies, test directory, module name, Apache-2.0, executable) from which the attributes follow. Kept the identity and the meta fields that are checked.
package-stdenv-cli †The attribute recipe (fetchFromGitHub fields, nativeBuildInputs, doCheck, meta.* names, and the exact makeFlags list).The upstream facts (repository, tag, Makefile honouring PREFIX, tests, completions, license, platforms). Kept the need for a custom installPhase that puts the binary at $out/bin/tinygrep, because the evaluator executes that phase.
purity-wrapper-derivation †The nativeBuildInputs recipe, lib.makeBinPath, and the lib.getExe ban.Added the impurity symptoms. Kept the identity, a makeWrapper wrapper around the provided bash, coreutils on PATH, the passthru.pure marker (an arbitrary interface value, now optional), and the purity constraints.
python-cuda-uv2nix-patch †Source Context. The input-list recipe, the location of hatchling, and the preFixup hook.The generic-Linux symptoms, the identity, the runtime and CUDA inputs as outcomes, CUDA_HOME, autoPatchelfHook, and that autoPatchelf must also search torch's lib directory for any python. Kept the purity constraints.
rust-no-network-buildSource Context. Restructured around the observed sandbox failure.Already outcome-oriented. Kept the preservation list, the system onnxruntime, the pinned model with passthru.assets.model, store paths in env (the evaluator reads env), and the sandbox and network constraints.
string-escaping-systemdSource Context. The ${pkgs.bash}/bin/bash recipe.Added the undefined variable 'STATE_DIRECTORY' error. Kept the service shape, the starter's bash -c plus printf append approach (graded by pattern), the literal ${…} expansions, and the purity constraints.
xdg-portal-merge †Source Context. The lib.mkAfter hint.Added the user-visible symptom (portals broken in other sessions). Kept the merge outcomes, the "do not read the option you define" constraint, and the no-disable constraint.