!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

699 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
6 Jul 2021
@linus.heckemann:matrix.mayflower.deLinux Hackerman * Hm, where? The derivation looks straightforward to me16:21:44
@hexa:lossy.networkhexahttps://github.com/AcademySoftwareFoundation/openexr/commit/6442fb71a86c09fb0a8118b6dbd93bcec4883a3c16:24:34
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/blob/master/pkgs/development/libraries/openexr/default.nix#L2616:25:11
@linus.heckemann:matrix.mayflower.deLinux Hackermanoh, and that patch no longer applies?16:25:14
@hexa:lossy.networkhexaneither on 2.5.7 nor on 3.0.516:25:28
@linus.heckemann:matrix.mayflower.deLinux Hackermanaah ok. I'll take a look16:25:42
@linus.heckemann:matrix.mayflower.deLinux Hackermanhttps://github.com/AcademySoftwareFoundation/openexr/pull/815 hm looks like it was merged so we can probably remove it.16:26:16
@linus.heckemann:matrix.mayflower.deLinux Hackermanor not :)16:28:40
@hexa:lossy.networkhexa
/nix/store/qdf49mvm79r83n9c9s7pkmmjqwhrw8jv-stdenv-linux/setup: line 88: cd: IlmBase: No such file or directory
16:29:11
@linus.heckemann:matrix.mayflower.deLinux Hackermanhttps://github.com/NixOS/nixpkgs/pull/12946216:40:39
@linus.heckemann:matrix.mayflower.deLinux Hackermanhm wait that might not be quite right.16:42:23
@hexa:lossy.networkhexaheh, weird. I remember that failing for me on staging-21.05 as well16:42:34
@linus.heckemann:matrix.mayflower.deLinux Hackermansince it was only merged into 3.x16:42:38
@hexa:lossy.networkhexaalso please target staging16:42:42
@hexa:lossy.networkhexahttps://github.com/AcademySoftwareFoundation/openexr/pull/103716:44:10
@hexa:lossy.networkhexathis pr was tagged with v2.5.7, and the release notes for that release mentions two oss-fuzz fixes16:44:31
@linus.heckemann:matrix.mayflower.deLinux HackermanYeah jtojnar's fix doesn't affect the build of openexr, it affects the builds of dependencies, so I'll forward-port his patch16:46:02
@linus.heckemann:matrix.mayflower.deLinux Hackerman * Yeah jtojnar's fix doesn't affect the build of openexr, it affects the builds of dependencies, so I'll backport his patch16:46:05
@linus.heckemann:matrix.mayflower.deLinux Hackermanoh lol there's a fix upstream https://github.com/AcademySoftwareFoundation/openexr/commit/2f19a01923885fda75ec9d19332de080ec7102bd just not in 2.5.7 >_<16:53:32
@obfusk:matrix.org幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆) changed their display name from 幸猫 to 幸猫 (they/them).18:58:16
@obfusk:matrix.org幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆) changed their display name from 幸猫 (they/them) to 幸猫 (π‘‘β„Žπ‘’π‘¦/π‘‘β„Žπ‘’π‘š).19:11:06
@spacesbot:nixos.devspacesbot - keeps a log of public NixOS channels changed their display name from spacesbot to spacesbot - keeps a log of public NixOS channels.22:11:49
@obfusk:matrix.org幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆) changed their display name from 幸猫 (π‘‘β„Žπ‘’π‘¦/π‘‘β„Žπ‘’π‘š) to 幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆).22:40:30
7 Jul 2021
@quantumghost:matrix.orgquantumghost joined the room.03:58:19
@lassulus:nixos.devlassulus joined the room.08:12:31
@stefandeml:matrix.orgstefandeml joined the room.08:25:55
@red:evil.redredFYI: I found an exploitable bug in the ponyc compiler which allowed an attacker to do silently(ish) bypass ponyc's supply chain attack defenses. It got fixed within a few hours and a new version of the compiler has been released. I'm testing the new nixpkgs package for it and will tag it with security when I get the PR up.17:56:20
@red:evil.redredThere is no assigned CVE or anything, didn't seem like any point since they fixed it within an hour :-P{17:57:45
@red:evil.redred * There is no assigned CVE or anything, didn't seem like any point since they fixed it within an hour :-P17:57:50
@red:evil.redredalthough now that I've said that out loud I'm doubting myself...17:58:33

There are no newer messages yet.


Back to Room ListRoom Version: 6