!UNVBThoJtlIiVwiDjU:nixos.org

Staging

315 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/108 Servers

Load older messages


SenderMessageTime
20 Sep 2025
@emilazy:matrix.orgemilyhttps://github.com/haproxy/haproxy/blob/34cdc5e191784cdae671a6c337fd4385522855af/INSTALL#L28-L3916:19:37
@emilazy:matrix.orgemilydunno, it seems like HAProxy basically suggests people use OpenSSL 3.5 QUIC16:19:50
@emilazy:matrix.orgemilybut AWS-LC may be the safe choice16:20:37
@emilazy:matrix.orgemily"Three OpenSSL derivatives called LibreSSL, QUICTLS, and AWS-LC are reported to work as well. While there are some efforts from the community to ensure they work well, OpenSSL remains the primary target and this means that in case of conflicting choices, OpenSSL support will be favored over other options. Note that QUIC is not fully supported when haproxy is built with OpenSSL < 3.5 version. In this case, QUICTLS is the preferred alternative. As of writing this, the QuicTLS project follows OpenSSL very closely and provides update simultaneously, but being a volunteer-driven project, its long-term future does not look certain enough to convince operating systems to package it, so it needs to be build locally. See the section about QUIC in this document."16:20:55
@emilazy:matrix.orgemilyseems like a pretty explicit recommendation for OpenSSL 3.5 even for QUIC16:21:04
@marie:marie.cologneMarie
As of writing this, the QuicTLS project follows OpenSSL very closely and provides
update simultaneously
16:25:40
@marie:marie.cologneMarie
As of writing this, the QuicTLS project follows OpenSSL very closely and provides update simultaneously
16:25:43
@marie:marie.cologneMariethats a bit outdated from what I've heard16:25:55
@marie:marie.cologneMarie also successfully built nghttp2.override { enableHttp3 = true; } 16:26:35
@emilazy:matrix.orgemilyfwiw https://github.com/haproxy/haproxy/commit/bbe302087ccc1471a97d88ec1c24fbc55e4d1c5116:27:56
@emilazy:matrix.orgemilyis where they said "OpenSSL 3.5 fine" (and did not change their description of QuicTLS)16:28:06
@gsaurel:laas.frnim65szvbi is failing before that16:28:17
@gsaurel:laas.frnim65s ntsc-cc.c:55:11: fatal error: 'X11/X.h' file not found 16:28:27
@emilazy:matrix.orgemily why on earth is thrift pulling in zvbi16:29:18
@gsaurel:laas.frnim65simage.png
Download image.png
16:30:17
@emilazy:matrix.orgemilythe bumps need moving up above "ngtcp2: use openssl instead of quictls" to avoid intermediate broken states, and I think the curl and nghttp2 changes should be squashed into that. otherwise LGTM. can worry about HAProxy later I suppose, but we should probably get it off QuicTLS…16:30:38
@emilazy:matrix.orgemily aha. well, … we'll need to fix that anyway, because obviously ffmpeg-headless needs to work on Darwin 16:31:01
@emilazy:matrix.orgemily so that's just staging noise 16:31:05
@emilazy:matrix.orgemilyas you can see, ~all of Python is broken there :)16:31:20
@marie:marie.cologneMarie alright 16:31:57
@marie:marie.cologneMariedoing another build right now, since i forgot to rebase16:32:27
@aloisw:julia0815.dealoisw Unless something has changed in the last couple of days and GitHub search is weird, nginx also still uses quictls package. However OpenSSL seems to work there fine as well. 16:44:58
@emilazy:matrix.orgemily rg quictls pkgs/servers/http/nginx/ returns nothing for me 16:47:00
@aloisw:julia0815.dealoisw It's overridden in all-packages.nix. 16:47:14
@emilazy:matrix.orgemilyhttps://github.com/search?q=repo%3ANixOS%2Fnixpkgs%20quictls&type=code doesn't show Nginx for me either, am I missing something?16:47:24
@aloisw:julia0815.dealoisw (do not read the comment) 16:47:25
@emilazy:matrix.orgemily aha. only for nginxQuic 16:47:46
@emilazy:matrix.orgemilyok, we can punt what to do for that stuff for later.16:48:09
@emilazy:matrix.orgemilyOpenSSL 3.5 or AWS-LC seem like the sensible options.16:48:17
@aloisw:julia0815.dealoisw all-packages.nix is excluded from that due to its size I guess? 16:48:17

Show newer messages


Back to Room ListRoom Version: 6