!VhzbGHamdfMiGxpXyg:robins.wtf

NixOS Incus and LXC

51 Members
lxc, lxd, incus discussions related to NixOS19 Servers

Load older messages


SenderMessageTime
25 May 2026
@tom:dragar.deTom *

adamcstephens: looking at the job i'm wondering wheter the logic should be changed to a if [ "$RELEASE" = "release-25.11" ]; then as not do the repackaging for 26.05 and onward?

(i'm currently assuming that this wasn't done for 25.11 because that would've required changes? It's not explained anywhere as far as i can tell)

https://github.com/lxc/lxc-ci/blob/c76d66f24ec00222932431bb922e338d6ca20b01/jenkins/jobs/image-nixos.yaml#L44-L58

16:55:27
@tom:dragar.deTom *

adamcstephens: looking at the job i'm wondering wheter the logic should be changed to a if [ "$RELEASE" = "25.11" ]; then as not do the repackaging for 26.05 and onward?

(i'm currently assuming that this wasn't done for 25.11 because that would've required changes? It's not explained anywhere as far as i can tell)

https://github.com/lxc/lxc-ci/blob/c76d66f24ec00222932431bb922e338d6ca20b01/jenkins/jobs/image-nixos.yaml#L44-L58

16:55:49
@adam:robins.wtfadamcstephensit was done for unstable only as an initial test of using purely our images. it's been a success so yes, setting != 25.11 sounds right and then we can remove completely the distrobuilder stuff when retiring it18:23:54
@adam:robins.wtfadamcstephensweird that there's no PR associated with this commit https://github.com/lxc/lxc-ci/commit/999a75491447910bcc6ea20be4928cc584600bb718:33:56
@adam:robins.wtfadamcstephensi don't have push access to that repo...18:34:06
@adam:robins.wtfadamcstephenshttps://github.com/lxc/lxc-ci/pull/94018:35:55
@tom:dragar.deTomyeah, noticed that github weirdness to19:38:54
@tom:dragar.deTom* yeah, noticed that github weirdness too19:39:01
@tom:dragar.deTomhttps://github.com/lxc/lxc-ci/pull/99419:39:30
26 May 2026
@adam:robins.wtfadamcstephensi'm wondering if we should mark 25.11 incus LTS as insecure once 26.05 is officially released. still seems to be no movement on security fixes12:06:03
@tom:dragar.deTom7.1.0 is due in around two days (28.05. https://github.com/lxc/incus/milestone/36) that probably also means 7.0.1 is gonna happen then and i kinda suspect 6.0.7 is also going to happen around that same time13:27:38
@tom:dragar.deTomwe'll see but it really isn't ideal13:29:41
@tom:dragar.deTom* we'll see, but it really isn't ideal13:30:01
@tom:dragar.deTom* we'll see, and it definitly isn't ideal13:30:59
@tom:dragar.deTombut especially since we have 7.0.0+15 on 25.11 with the incus package i also wouldn't feel too badly with just marking the lts package as insecure on 25.11. We then just shouldn't backport 7.1.0 to 25.1113:34:00
@tom:dragar.deTom* but especially since we have 7.0.0+15 on 25.11 with the incus package i also wouldn't feel too bad about just marking the lts package as insecure on 25.11. We then just shouldn't backport 7.1.0 to 25.1113:36:19
@tom:dragar.deTombtw. there is now a lts-7.0 branch for the zabbly package https://github.com/zabbly/incus/tree/lts-7.013:37:42
27 May 2026
@dag0bertz:matrix.orgDieselgert Baghetto joined the room.05:40:07
29 May 2026
@tom:dragar.deTomhttps://github.com/lxc/incus/security/advisories/GHSA-ccjc-4qc3-jxqc 🫠07:19:45
@tom:dragar.deTomhttps://github.com/NixOS/nixpkgs/pull/52545607:19:51
@tom:dragar.deTomit doesn't look like the security fixes have been pushed to a stable-7.0 branch in the incus Repo or the lts-7.0 branch from the zabbly repo yet07:45:38
@tom:dragar.deTomhttps://github.com/NixOS/nixpkgs/pull/52546107:45:50
@adam:robins.wtfadamcstephensof course not13:24:34
@adam:robins.wtfadamcstephensat what point do we stop offering LTS at all, if it's not going to get sufficient maintenance upstream?13:25:28
@tom:dragar.deTomthat thought crossed my mind as well13:26:06
@tom:dragar.deTomor we keep it but permanently mark it as insecure. The handfull version bumps shouldn't be too much work 🙃13:32:42
@tom:dragar.deTom* or we keep it but permanently mark it as insecure. The handful version bumps shouldn't be too much work 🙃13:33:16
@adam:robins.wtfadamcstephensif it's permanently marked insecure, then it wouldn't be default and almost nobody would use it. could simplify and just drop14:01:02
@tom:dragar.deTomYeah, i was coping by joking14:15:18
@adam:robins.wtfadamcstephens;)14:24:09

Show newer messages


Back to Room ListRoom Version: 10