!UNVBThoJtlIiVwiDjU:nixos.org

Staging

316 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/108 Servers

Load older messages


SenderMessageTime
21 Sep 2025
@vcunat:matrix.orgVladimír Čunát* I don't expect we even need libxml2 2.15 in 25.11 when it comes to it.11:47:53
@vcunat:matrix.orgVladimír Čunát2.13 is still getting security fixes apparently, so I expect 2.14 can hold for several more months.11:48:36
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)we are manually backporting them, and only because there is things that insist on the old ABI11:52:02
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)if it were me we'd have dropped that long ago11:52:13
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i do NOT want to repeat this backport hell on 25.1111:52:22
@vcunat:matrix.orgVladimír Čunát 2.13 is getting security fixes upstream 11:52:48
@vcunat:matrix.orgVladimír ČunátReleased about a week ago: https://gitlab.gnome.org/GNOME/libxml2/-/commit/04af2cabb9f859c198b8a553c028a8748119941011:53:15
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)it got 2.13.9 apparently last week. After like 15 other CVEs went unfixed for several months and we needed to do manual backport11:53:25
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)so yes, that exists, but i am not confident this is something we can bet on for our release11:54:03
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)don't get me wrong, 2.13.9 is nice and we should absolutely pick that to 25.05 and drop our current patches on 25.11 where we have our own patches on top of 2.13.8. However, upstream already announced they'd only be maintaining libxml2 until the end of 2025. The libxslt maintainer said they'd step up for libxml2, but expecting them to carry along old versions is a bet that is quite dangerous.11:56:11
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)I am only willing to do it if you are the idiot volunteering to backport all the patches yourself if 2.14.x doesn't get backports!11:56:40
@k900:0upti.meK900Actually a decent chance that I'll finish the rebuild today11:57:49
@vcunat:matrix.orgVladimír ČunátOK. I wasn't really following this long-term, just happened to see this 2.13.9. One possibility is always to piggy-back on some distro that takes security seriously (and happens to follow a particular package branch).11:59:17
@k900:0upti.meK900Somehow11:57:52
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)debian is still on ANCIENT versions with tens of patches. Fedora could work...12:02:12
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i expect arch to just yolo, either upgrading or not patching. That is the arch way anyways, i have looked at this before.12:02:46
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)yeah arch already did 2.15.012:03:20
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)https://repology.org/project/libxml2/versions12:03:23
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)wait even fedora is still on 2.1212:03:47
@vcunat:matrix.orgVladimír ČunátFedora is 2.12 ?! https://packages.fedoraproject.org/pkgs/libxml2/libxml2/12:03:47
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)ugh12:03:48
@vcunat:matrix.orgVladimír ČunátUbuntu also doesn't go beyond 2.12.12:04:20
@vcunat:matrix.orgVladimír Čunát* Ubuntu also doesn't go beyond 2.12 thus far.12:04:25
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)gentoo is patching along 2.1312:04:27
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)and apparently 2.14 too12:04:42
@vcunat:matrix.orgVladimír Čunát* Ubuntu also doesn't go beyond 2.12 thus far. (just following Debian in here, I expect)12:04:44
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)so i guess we could fetch gentoo12:04:50
@vcunat:matrix.orgVladimír ČunátAh, they have a separate package after the ABI bump? https://packages.ubuntu.com/questing/libxml2-1612:05:58
@vcunat:matrix.orgVladimír ČunátIt all looks like a mess.12:06:18
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)thats what i am saying12:06:55

Show newer messages


Back to Room ListRoom Version: 6