!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

119 Members
Another day, another cert renewal47 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
24 Oct 2022
@arianvp:matrix.orgArianodd08:32:13
@arianvp:matrix.orgArianseems both minica and lego dumped core08:33:26
@arianvp:matrix.orgArianthis is really odd. maybe the go package broke?08:34:10
@arianvp:matrix.orgArianaaah wait08:34:45
@arianvp:matrix.orgArianWe have a whitelist of syscalls here: 08:35:15
@arianvp:matrix.orgArianhttps://github.com/NixOS/nixpkgs/blob/master/nixos/modules/security/acme/default.nix#L63-L7008:35:16
@arianvp:matrix.orgArianso maybe lego and minica are doing new syscalls that aren't in this list08:35:27
@arianvp:matrix.orgArianlego seems to be calling setrlimit (which tbh is a weird thing for a process to do themselves) and idk if that one is allowed by default08:36:04
@arianvp:matrix.orgArianminica stacktrace is very... uninformative08:36:14
@arianvp:matrix.orgAriananyhow this means that the acme module is properly broken. this is a release blocker08:36:44
@arianvp:matrix.orgArian Andreas Schrägle: could you please open an issue so we can add it to the release blocker list? 08:37:07
@andreas.schraegle:helsinki-systems.deAndreas Schrägle
In reply to @arianvp:matrix.org
Andreas Schrägle: could you please open an issue so we can add it to the release blocker list?
does this not block the (non -small) channel anyways?
08:38:39
@arianvp:matrix.orgArianidk if this VM test is in the list. 08:38:57
@arianvp:matrix.orgArianif it is then we're good :)08:39:00
@andreas.schraegle:helsinki-systems.deAndreas Schräglelooks like it isn't. I'll open an issue.08:41:04

Show newer messages


Back to Room ListRoom Version: 6