!UNVBThoJtlIiVwiDjU:nixos.org

Staging

306 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/104 Servers

Load older messages


SenderMessageTime
13 Nov 2025
@k900:0upti.meK900 But if it doesn't trivially work I have no idea what to do 11:22:11
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)My bet is you'll at least have to pull out the mergiraf and stuff won't just cleanly apply11:22:39
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)but do try!11:22:50
@k900:0upti.meK900 No I mean like 11:23:21
@k900:0upti.meK900 Try updating it 11:23:27
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)oh11:23:31
@k900:0upti.meK900 I am not backporting things in a codebase I don't understand and if I break it then science explodes 11:23:45
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)actually hold on, hdf5 is only 1200 rebuilds11:24:56
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)reverting that in a staging cycle wouldn't be that bad11:25:05
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)i guess we gamble11:25:16
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) Science is one thing. CAD and computer vision also uses hdf5 11:26:04
@leona:leona.isleonaok, then I would also try to update11:26:21
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)if vtk keeps building, i call the update worth11:27:09
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)thats all i care about, though i guess the opencv people want opencv to work too11:27:23
@vcunat:matrix.orgvcunatAre you sure that the CVEs are serious?11:30:28
@vcunat:matrix.orgvcunatI mean, they seem to have been publicly open for months.11:30:39
@vcunat:matrix.orgvcunatAnd they're not even mentioned in the release announcement.11:30:48
@vcunat:matrix.orgvcunatSo do we now need to patch them within days?11:31:08
@k900:0upti.meK900Well netcdf is immediately bork11:31:43
@k900:0upti.meK900configure: error: HDF5 was not built with zlib, which is required. Rebuild HDF5 with zlib11:31:53
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) Its file (de-)serialization, it is potentially thinkable someone sends a specially crafted malicious cad file. I don't like having these vulnerabilities around. But there certainly are worse CVEs out there. 11:32:38
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)its all memory safety issues11:33:38
@vcunat:matrix.orgvcunatAlternate route is: lots of distros use hdf5 1.x. If it's serious, someone should have backports soon.11:34:16
@vcunat:matrix.orgvcunat(even if upstream didn't provide them now)11:34:30
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) it probably is not that serious, other than all those 3d printing model bazaars you find 11:34:48
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)like, clearly some browser issue is worse, but i still don't like this11:35:31
@k900:0upti.meK900 -DHDF5_ENABLE_ZLIB_SUPPORT=ON got that working 11:36:09
@k900:0upti.meK900And then11:36:27
@k900:0upti.meK900
  > H5FDhttp.c:57:2: error: #error "Cannot determine version of H5FD_class_t"
┃        >    57 | #error "Cannot determine version of H5FD_class_t"
┃        >       |  ^~~~~
┃        > In file included from H5FDhttp.c:75:
┃        > H5FDhttp.c: In function 'H5Pset_fapl_http':
┃        > H5FDhttp.h:34:26: error: implicit declaration of function 'H5FDperform_init' [-Wimplicit-function-declaration]
┃        >    34 | #define H5FD_HTTP       (H5FDperform_init(H5FD_http_init))
┃        >       |                          ^~~~~~~~~~~~~~~~
11:36:30
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)Amazing11:37:14

Show newer messages


Back to Room ListRoom Version: 6