!UNVBThoJtlIiVwiDjU:nixos.org

Staging

281 Members
Staging merges | Find currently open staging-next PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+sort%3Aupdated-desc+head%3Astaging-next+head%3Astaging-next-21.05+is%3Aopen97 Servers

Load older messages


SenderMessageTime
8 Jul 2025
@yuka:yuka.devYureka (she/her)not saying it shouldn't be done, but the decision to try it the first time shouldn't be taken lightly19:03:14
@vcunat:matrix.orgVladimír ČunátJust recommendations on discourse, etc.19:03:16
@vcunat:matrix.orgVladimír Čunát* Just recommendations on discourse so far, etc.19:03:24
@vcunat:matrix.orgVladimír Čunát* Just recommendations/snippets on discourse so far, etc.19:03:34
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)last time we had comparable was xz, which had replaceDependencies on discourse, no official release of such though19:06:25
@fabianhjr:matrix.orgFabián Heredia* Preparing a PR to ugrade git to the suggested version 2.50.1 but unsure, will leave it on top of the merge base of the main branch and staging-next EDIT: on top of staging-next, there is a git update this cycle19:07:04
@qyliss:fairydust.spaceAlyssa Ross
In reply to @k900:0upti.me
Do we scrap the cycle
Now this is a more compelling reason
19:22:51
@fabianhjr:matrix.orgFabián Heredia *

2.49 → 2.50.0 is on staging-next but not main branch, targetting staging-next

https://github.com/NixOS/nixpkgs/pull/423559

Was dupe, this one was submitted before: https://github.com/NixOS/nixpkgs/pull/423553

19:23:02
@qyliss:fairydust.spaceAlyssa RossWe're only a few days in, right?19:23:11
@k900:0upti.meK900We're a lot in tbh19:23:20
@qyliss:fairydust.spaceAlyssa RossOh :(19:23:26
@k900:0upti.meK900But I don't think it matters really19:23:30
@qyliss:fairydust.spaceAlyssa RossI guess the question is what would we be delaying19:24:37
@qyliss:fairydust.spaceAlyssa RossAre there any good security updates in the current batch?19:24:51
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)pam? maybe?19:25:49
@fabianhjr:matrix.orgFabián Heredia
git log origin/master..origin/staging-next --grep CVE

> linux-pam: apply patch for CVE-2025-6020 (#418180)
> A flaw was found in linux-pam. The module pam_namespace may use access user-controlled paths without proper protection, allowing local users to elevate their privileges to root via multiple symlink attacks and race conditions.

> openssl_3_5: 3.5.0 -> 3.5.1
> The most severe CVE fixed in this release is Low.

>  libxml2: Apply ABI breaking patch from Chromium needed for libxslt CVE fixes

> openssl_3_5: fix for CVE-2025-4575
> Use of -addreject option with the openssl x509 application adds a trusted use instead of a rejected use for a certificate. Impact summary: If a user intends to make a trusted certificate rejected for a particular use it will be instead marked as trusted for that use.
19:28:06
@fabianhjr:matrix.orgFabián HerediaThese are the 4 I could find, most severe seems to be pam19:28:08
@fabianhjr:matrix.orgFabián Heredia

Also

libxslt: Fix three security issues (#418055)
19:28:48
@qyliss:fairydust.spaceAlyssa RossWould there be any sense merging now, and then restarting?19:29:34
@qyliss:fairydust.spaceAlyssa RossWould presumably be less bad than sending an update straight to master, and still accelerate getting git update out?19:30:06
@fabianhjr:matrix.orgFabián Heredialibxslt ones issues seems to have been hidden/removed, could still be under embargo19:30:50
@fabianhjr:matrix.orgFabián Heredia* libxslt issues seems to have been hidden/removed, could still be under embargo19:31:50
@fr0de_0xa:matrix.orgFred Lahde joined the room.19:43:14
@fabianhjr:matrix.orgFabián HerediaI don't think the git update can go straight to the main branch, it is a mass rebuild. So the options would be staging-next or staging. Regarding that there are still some pending fixes on staging-next so I don't think the overall cycle would be delayed much more vs merging the git update into staging. (But a lot of rebuilds would be incured)19:44:23
@fabianhjr:matrix.orgFabián HerediaWe are currently 4 days into this staging-next cycle19:44:47
@fabianhjr:matrix.orgFabián Herediaimage.png
Download image.png
19:47:07
@fabianhjr:matrix.orgFabián HerediaJobs wise it is about 3/5ths builds done19:47:13
@fabianhjr:matrix.orgFabián Heredia vcunat are you inclined / prefer staging-next or staging for this git security update? 19:50:07
@vcunat:matrix.orgVladimír Čunát

Rebuild: linux 44750, darwin 29576

19:51:05
@vcunat:matrix.orgVladimír ČunátThat's most builds.19:51:11

Show newer messages


Back to Room ListRoom Version: 6