!UNVBThoJtlIiVwiDjU:nixos.org

Staging

315 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/108 Servers

Load older messages


SenderMessageTime
13 Nov 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)reverting that in a staging cycle wouldn't be that bad11:25:05
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i guess we gamble11:25:16
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) Science is one thing. CAD and computer vision also uses hdf5 11:26:04
@leona:leona.isleonaok, then I would also try to update11:26:21
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)if vtk keeps building, i call the update worth11:27:09
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)thats all i care about, though i guess the opencv people want opencv to work too11:27:23
@vcunat:matrix.orgVladimír ČunátAre you sure that the CVEs are serious?11:30:28
@vcunat:matrix.orgVladimír ČunátI mean, they seem to have been publicly open for months.11:30:39
@vcunat:matrix.orgVladimír ČunátAnd they're not even mentioned in the release announcement.11:30:48
@vcunat:matrix.orgVladimír ČunátSo do we now need to patch them within days?11:31:08
@k900:0upti.meK900Well netcdf is immediately bork11:31:43
@k900:0upti.meK900configure: error: HDF5 was not built with zlib, which is required. Rebuild HDF5 with zlib11:31:53
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) Its file (de-)serialization, it is potentially thinkable someone sends a specially crafted malicious cad file. I don't like having these vulnerabilities around. But there certainly are worse CVEs out there. 11:32:38
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)its all memory safety issues11:33:38
@vcunat:matrix.orgVladimír ČunátAlternate route is: lots of distros use hdf5 1.x. If it's serious, someone should have backports soon.11:34:16
@vcunat:matrix.orgVladimír Čunát(even if upstream didn't provide them now)11:34:30
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) it probably is not that serious, other than all those 3d printing model bazaars you find 11:34:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)like, clearly some browser issue is worse, but i still don't like this11:35:31
@k900:0upti.meK900 -DHDF5_ENABLE_ZLIB_SUPPORT=ON got that working 11:36:09
@k900:0upti.meK900And then11:36:27
@k900:0upti.meK900
  > H5FDhttp.c:57:2: error: #error "Cannot determine version of H5FD_class_t"
┃        >    57 | #error "Cannot determine version of H5FD_class_t"
┃        >       |  ^~~~~
┃        > In file included from H5FDhttp.c:75:
┃        > H5FDhttp.c: In function 'H5Pset_fapl_http':
┃        > H5FDhttp.h:34:26: error: implicit declaration of function 'H5FDperform_init' [-Wimplicit-function-declaration]
┃        >    34 | #define H5FD_HTTP       (H5FDperform_init(H5FD_http_init))
┃        >       |                          ^~~~~~~~~~~~~~~~
11:36:30
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Amazing11:37:14
@k900:0upti.meK900OK yeah that's just gone from 2.011:39:02
@k900:0upti.meK900According to the changelog11:39:07
@k900:0upti.meK900I am out lol11:39:09
@vcunat:matrix.orgVladimír Čunáthttps://github.com/HDFGroup/hdf5/blob/develop/release_docs/CHANGELOG.md#%EF%B8%8F-breaking-changes11:42:46
@vcunat:matrix.orgVladimír Čunát* https://github.com/HDFGroup/hdf5/blob/hdf5_2_0_0/release_docs/CHANGELOG.md#%EF%B8%8F-breaking-changes11:43:43
@leona:leona.isleonaI think most of the PRs to staging are merged now and trunk-combined will also be ready soon. So we can probably start tomorrow morning (CET side of the planet) with staging-next?23:16:29
@ivy:faggot.shivybut cachix23:26:19
@leona:leona.isleona that might block trunk, but we don't have the time to wait for that to be fixed 23:27:29

Show newer messages


Back to Room ListRoom Version: 6