!NBBFPbiuttRgTqbrcY:nixos.org

NixOS Security Discussions

365 Members
Discussions around Security | Triaging happens in #security:nixos.org123 Servers

Load older messages


SenderMessageTime
28 Nov 2024
@emilazy:matrix.orgemily okay, the good news is that MySQL 8.0 is building fine on staging so it was only my WIP changes breaking it :) 09:10:30
@emilazy:matrix.orgemilybad news is Percona definitely needs bumps09:10:34
@tgerbet:matrix.orgtgerbetLooking at it today 🙂09:11:06
@os:matrix.flyingcircus.ioosnyx (he/him)
In reply to @tgerbet:matrix.org
Looking at it today 🙂
Feel free to do this, but being one of the maintainers I finally subscribed to the new-releases feed of Percona to not miss updates anymore 🤐
09:43:31
@os:matrix.flyingcircus.ioosnyx (he/him)So hopefully the timeliness of Percona updates is going to improve.09:44:05
@shawn8901:matrix.org@shawn8901:matrix.org left the room.18:48:47
29 Nov 2024
@lassulus:lassul.uslassulus changed their profile picture.18:30:08
3 Dec 2024
@stigo:matrix.orgstigo changed their display name from stigo (away) to stigo.00:52:15
@getchoo:matrix.orggetchoo changed their profile picture.06:06:38
6 Dec 2024
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)https://github.com/ultralytics/ultralytics/issues/1802712:31:20
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)Not packaging stuff is the best way to avoid supply chain attack12:32:04
@aleksana:mozilla.orgaleksana (force me to bed after 18:00 UTC)Not dealing with package request is even better: https://github.com/NixOS/nixpkgs/issues/30815412:34:59
@ity:itycodes.orgTranquil ItyRofl12:53:36
@joerg:thalheim.ioMic92Is there some issue here, I don't see? https://github.com/NixOS/nixos-wiki-infra/issues/161 18:05:55
@tgerbet:matrix.orgtgerbetI will check, I can reach out to laluka directly. Should probably have been reported to upstream anyway18:10:34
7 Dec 2024
@hexa:lossy.networkhexaso quite recently someone pointed out to me that AMD does not publish microcode updates for consumer CPUs to linux-firmwares17:59:56
@hexa:lossy.networkhexa * so quite recently someone pointed out to me that AMD does not publish microcode updates for consumer CPUs to linux-firmwares, and that those are only shipped through BIOS updates18:00:19
@hexa:lossy.networkhexaThe ones shipped from linux-firmware are apparently only for server CPUs.18:00:37
@zzywysm:matrix.orgzzywysm hexa: that sounds like a fairly recent change? 18:00:35
@hexa:lossy.networkhexawhat makes you say that?18:00:53
@zzywysm:matrix.orgzzywysmwhen i was messing around with an AMD gaming PC (from Dell) in 2019-2020, i feel like i remember that there was an appropriate microcode update in linux-firmware that got loaded at boot18:01:39
@hexa:lossy.networkhexa
❯ ./amd_ucode_info.py kernel/x86/microcode/AuthenticAMD.bin 
Microcode patches in kernel/x86/microcode/AuthenticAMD.bin:
  Family=0x10 Model=0x02 Stepping=0x03: Patch=0x01000083 Length=960 bytes
  Family=0x10 Model=0x02 Stepping=0x02: Patch=0x01000083 Length=960 bytes
  Family=0x10 Model=0x02 Stepping=0x0a: Patch=0x01000084 Length=960 bytes
  Family=0x10 Model=0x06 Stepping=0x02: Patch=0x010000c7 Length=960 bytes
  Family=0x10 Model=0x04 Stepping=0x03: Patch=0x010000c8 Length=960 bytes
  Family=0x10 Model=0x06 Stepping=0x03: Patch=0x010000c8 Length=960 bytes
  Family=0x10 Model=0x05 Stepping=0x03: Patch=0x010000c8 Length=960 bytes
  Family=0x10 Model=0x08 Stepping=0x01: Patch=0x010000d9 Length=960 bytes
  Family=0x10 Model=0x09 Stepping=0x01: Patch=0x010000d9 Length=960 bytes
  Family=0x10 Model=0x08 Stepping=0x00: Patch=0x010000da Length=960 bytes
  Family=0x10 Model=0x04 Stepping=0x02: Patch=0x010000db Length=960 bytes
  Family=0x10 Model=0x05 Stepping=0x02: Patch=0x010000db Length=960 bytes
  Family=0x10 Model=0x0a Stepping=0x00: Patch=0x010000dc Length=960 bytes
  Family=0x11 Model=0x03 Stepping=0x01: Patch=0x02000032 Length=512 bytes
  Family=0x12 Model=0x01 Stepping=0x00: Patch=0x03000027 Length=960 bytes
  Family=0x14 Model=0x01 Stepping=0x00: Patch=0x05000029 Length=1568 bytes
  Family=0x14 Model=0x02 Stepping=0x00: Patch=0x05000119 Length=1568 bytes
Microcode patches in kernel/x86/microcode/AuthenticAMD.bin+0x318c:
  Family=0x15 Model=0x01 Stepping=0x02: Patch=0x0600063e Length=2592 bytes
  Family=0x15 Model=0x02 Stepping=0x00: Patch=0x06000852 Length=2592 bytes
  Family=0x15 Model=0x10 Stepping=0x01: Patch=0x06001119 Length=2592 bytes
Microcode patches in kernel/x86/microcode/AuthenticAMD.bin+0x5050:
  Family=0x16 Model=0x00 Stepping=0x01: Patch=0x0700010f Length=3458 bytes
Microcode patches in kernel/x86/microcode/AuthenticAMD.bin+0x5e06:
  Family=0x17 Model=0x01 Stepping=0x02: Patch=0x0800126f Length=3200 bytes
  Family=0x17 Model=0x31 Stepping=0x00: Patch=0x0830107c Length=3200 bytes
  Family=0x17 Model=0x08 Stepping=0x02: Patch=0x0800820d Length=3200 bytes
  Family=0x17 Model=0xa0 Stepping=0x00: Patch=0x08a00008 Length=3200 bytes
Microcode patches in kernel/x86/microcode/AuthenticAMD.bin+0x9082:
  Family=0x19 Model=0x01 Stepping=0x00: Patch=0x0a00107a Length=5568 bytes
  Family=0x19 Model=0x11 Stepping=0x02: Patch=0x0a101248 Length=5568 bytes
  Family=0x19 Model=0xa0 Stepping=0x02: Patch=0x0aa00215 Length=5568 bytes
  Family=0x19 Model=0x01 Stepping=0x02: Patch=0x0a001238 Length=5568 bytes
  Family=0x19 Model=0x11 Stepping=0x01: Patch=0x0a101148 Length=5568 bytes
  Family=0x19 Model=0x01 Stepping=0x01: Patch=0x0a0011d5 Length=5568 bytes
  Family=0x19 Model=0xa0 Stepping=0x01: Patch=0x0aa00116 Length=5568 bytes
18:02:40
@hexa:lossy.networkhexa this is what's in the current microcodeAmd package 18:03:01
@hexa:lossy.networkhexamy Ryzen 5600X is family 25, model 3318:03:19
@hexa:lossy.networkhexaso 0x19 and 0x21 in hexadecimal18:03:33
@hexa:lossy.networkhexanow one thought about interpreting that was that a given model can match multiple cpu models? but that seems weird18:04:43
@hexa:lossy.networkhexa e.g. 0x21 & 0xa0 = 0x21 18:05:10
@hexa:lossy.networkhexathe gentoo wiki has this table18:05:39
@hexa:lossy.networkhexaimage.png
Download image.png
18:05:40
@hexa:lossy.networkhexahuh, so linux-firmware seems to have newer microcode for my cpu now18:17:54

Show newer messages


Back to Room ListRoom Version: 9