!MthpOIxqJhTgrMNxDS:nixos.org

NixOS ACME / LetsEncrypt

104 Members
Another day, another cert renewal44 Servers

Load older messages


SenderMessageTime
19 Oct 2022
@m1cr0man:m1cr0man.comm1cr0manDepending on the renewal target in nginx shouldn't be triggering the timer? Unless, the timer is aware of when the unit last ran? Maybe I'm wrong though.22:57:28
20 Oct 2022
@hjulle:matrix.orghjulle joined the room.12:04:33
24 Oct 2022
@andreas.schraegle:helsinki-systems.deAndreas Schräglethe acme nixos test broke recently https://hydra.nixos.org/job/nixos/trunk-combined/nixos.tests.acme.x86_64-linux / https://hydra.nixos.org/log/hv4qwbrhmnxf6h0fq70m8lxy5an0xf89-vm-test-run-acme.drv logs indicate minica being denied a system call, if I'm not reading them wrong. any ideas why this might be happening?08:30:55
@arianvp:matrix.orgArianodd08:32:13
@arianvp:matrix.orgArianseems both minica and lego dumped core08:33:26
@arianvp:matrix.orgArianthis is really odd. maybe the go package broke?08:34:10
@arianvp:matrix.orgArianaaah wait08:34:45
@arianvp:matrix.orgArianWe have a whitelist of syscalls here: 08:35:15
@arianvp:matrix.orgArianhttps://github.com/NixOS/nixpkgs/blob/master/nixos/modules/security/acme/default.nix#L63-L7008:35:16
@arianvp:matrix.orgArianso maybe lego and minica are doing new syscalls that aren't in this list08:35:27
@arianvp:matrix.orgArianlego seems to be calling setrlimit (which tbh is a weird thing for a process to do themselves) and idk if that one is allowed by default08:36:04
@arianvp:matrix.orgArianminica stacktrace is very... uninformative08:36:14
@arianvp:matrix.orgAriananyhow this means that the acme module is properly broken. this is a release blocker08:36:44
@arianvp:matrix.orgArian Andreas Schrägle: could you please open an issue so we can add it to the release blocker list? 08:37:07
@andreas.schraegle:helsinki-systems.deAndreas Schrägle
In reply to @arianvp:matrix.org
Andreas Schrägle: could you please open an issue so we can add it to the release blocker list?
does this not block the (non -small) channel anyways?
08:38:39
@arianvp:matrix.orgArianidk if this VM test is in the list. 08:38:57
@arianvp:matrix.orgArianif it is then we're good :)08:39:00
@andreas.schraegle:helsinki-systems.deAndreas Schräglelooks like it isn't. I'll open an issue.08:41:04
@arianvp:matrix.orgArianWe should probably change that btw08:41:29
@arianvp:matrix.orgArianchannel update shouldnt cause people's certs to expire =)08:42:09
@hexa:lossy.networkhexathis is about @resources12:43:59
@hexa:lossy.networkhexaand go 1.1912:44:01
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/issues/19744312:44:34
@hexa:lossy.networkhexa * this is about @resources, setrlimit specifically12:45:24
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/19754413:11:12
@m1cr0man:m1cr0man.comm1cr0manOnly checking here now. Approved that pr 🙂13:15:09
@hexa:lossy.networkhexastill running the tests13:19:16
@arianvp:matrix.orgArianYikes13:19:38
@hexa:lossy.networkhexawonder why it failed on ofborg for x86_64-linux13:19:39
@arianvp:matrix.orgArianSo much for Go stability guarantee.13:19:45

Show newer messages


Back to Room ListRoom Version: 6