!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

702 Members
Coordination and triage of security issues in nixpkgs214 Servers

Load older messages


SenderMessageTime
9 Aug 2021
@tim:stratum0.orgdadada (they/them) changed their display name from dadada to dadada (they/them).15:59:54
@hexa:lossy.networkhexaa gpsd issue will cause time to rollback to some time before 200121:35:06
@hexa:lossy.networkhexawe need to update to gpsd 3.23 and backport it 21:35:16
@nixinator:nixos.devnixinatorback to the future....21:38:27
@hexa:lossy.networkhexaanyway, there is https://github.com/NixOS/nixpkgs/pull/133216/files21:43:27
@hexa:lossy.networkhexaI'm cleaining it up a bit right now21:43:31
10 Aug 2021
@anubhavkini:matrix.organubhavkini left the room.05:50:58
@hexa:lossy.networkhexahttps://c-ares.haxx.se/adv_20210810.html10:59:01
@hexa:lossy.networkhexahttps://nostarttls.secvuln.info/11:20:11
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/133375 https://github.com/NixOS/nixpkgs/pull/13337813:27:48
@hexa:lossy.networkhexagave up the latter pr because the bump contains a few more security fixes13:37:54
@hexa:lossy.networkhexa * https://github.com/NixOS/nixpkgs/pull/133375 https://github.com/NixOS/nixpkgs/pull/133378 13:38:09
11 Aug 2021
@hexa:lossy.networkhexahttps://github.com/NixOS/nixpkgs/pull/13349913:28:17
@aanderse:nixos.devaanderse

hexa: i ping you because you're good at looking at CVEs and judging whether they should be backported, etc... :)
i mean, this definitely should be merged and backported, i know that
but everyone likes having a second set of eyes, it makes things more legit

and i mean... ❤️ hexa , of course

13:30:11
@hexa:lossy.networkhexa thanks for the vote of confidence. I can say that it builds and I slapped that Severity: Very Nasty Backportworthy label on! 13:30:59
@hexa:lossy.networkhexa * thanks for the vote of confidence. I can say that it builds and I slapped that Severity: Very Nasty Backportworthy label onto it! 13:31:13
@sandro:supersandro.deSandroJust went ahead and merged it13:31:20
@aanderse:nixos.devaanderse ❤️ Sandro too, for all the amazing work you do 😃 13:31:49
@corbin:matrix.orgCorbin left the room.16:53:03
12 Aug 2021
@nullrequest:matrix.orgnullrequest joined the room.09:49:39
@nullrequest:matrix.orgnullrequestI would like to submit a pr to enable the landlock lsm however the contributing guide says to open an issue about this. I'm not sure which template to use10:03:20
@qyliss:fairydust.spaceAlyssa RossI think you don't have to use a template if none fits10:03:43
@nullrequest:matrix.orgnullrequestcool10:07:39
@nullrequest:matrix.orgnullrequestalso is there any reason no one has enabled the lockdown lsm?10:09:07
@qyliss:fairydust.spaceAlyssa Rossunless you can find previous discussion in GitHub search, probably not10:09:33
@qyliss:fairydust.spaceAlyssa Rossusually the answer to "why hasn't [new thing] been enabled?" is nobody got to it yet10:09:53
@nullrequest:matrix.orgnullrequestI'll throw it in my pr10:13:10
@nullrequest:matrix.orgnullrequest * looked into the file its not enabled since we don't sign kernel modules yet12:19:21
@nullrequest:matrix.orgnullrequestcould someone add the security role to my pr https://github.com/NixOS/nixpkgs/pull/133618 13:27:54
@roosemberth:orbstheorem.chRoos left the room.14:07:16

There are no newer messages yet.


Back to Room ListRoom Version: 6