!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
29 Mar 2024
@magic_rb:matrix.redalder.orgmagic_rb joined the room.21:45:27
@r_i_s:matrix.orgris_i think we've encountered situations before where the github automatically generated tarball has been "overridden" by a release file being supplied in its place - which unnerved me a bit at the time - but makes me wonder if it's actually possible to get a tarball link to a git tag that will definitely have been auto-generated22:09:23
@r_i_s:matrix.orgris_ i.e. even fetchFromGitHub was returning the manually-uploaded tarball 22:11:32
@tomberek:matrix.orgtomberek ris_: if you use a tree-hash you have much better guarantees from their archive-tarball API. Fetching by commit-hash may encounter git-filter+smudging issues. 22:37:10
@tpw_rules:matrix.org@tpw_rules:matrix.org joined the room.23:01:50
@tpw_rules:matrix.org@tpw_rules:matrix.orghttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=106802423:01:55
@tpw_rules:matrix.org@tpw_rules:matrix.orgdebian is considering reverting xz further23:02:08
@tpw_rules:matrix.org@tpw_rules:matrix.orggiven our long lead time on a fix we should too23:06:13
@hexa:lossy.networkhexaas mentioned this would remove symbols that packages now depend on, so not as simple23:07:06
@hexa:lossy.networkhexalet's wait a week and see how the world looks then23:07:20
@tpw_rules:matrix.org@tpw_rules:matrix.orgok23:07:57
@tpw_rules:matrix.org@tpw_rules:matrix.orgthanks all23:12:00
@remcoschrijver:tchncs.deRemco Schrijver joined the room.23:13:28
@amarshall:matrix.orgamarshall joined the room.23:13:43
@r_i_s:matrix.orgris_ i'm struggling to reproduce this now, but I'm sure we've had at least one case in the past where fetchFromGitHub wasn't returning the vanilla repo source 23:16:40
@r_i_s:matrix.orgris_ tomberek: not sure how we'd fit any of that in with the UX of fetchFromGitHub though 23:17:57
@tomberek:matrix.orgtomberekI don't think fetchFromGitHub can. I was talking about the underlying mechanism from GitHub.23:18:51
@r_i_s:matrix.orgris_fundamentally for f-f-g-h we want a user to supply a tag name and unmistakably get the repo source for that commit. perhaps we can and i'm just delusional/mis-remembering23:20:42
@r_i_s:matrix.orgris_ anyway, we should probably investigate how we might make it easier to build packages from raw source, despite bootstrapping issues 23:22:14
@quentinmit:matrix.orgquentin joined the room.23:53:18
30 Mar 2024
@qubitnano:matrix.orgqubitnano joined the room.01:28:55
@raitobezarius:matrix.orgraitobezariusPost bootstrap verification seems a cheap first step, let's double check we get the expected stuff01:39:02
@lycheefox:matrix.org@lycheefox:matrix.org joined the room.02:19:40
@spiralp:matrix.orgSpiralP joined the room.03:09:15
@vcunat:matrix.orgvcunat
In reply to @hexa:lossy.network
as mentioned this would remove symbols that packages now depend on, so not as simple
Maybe it's simpler for us thanks to doing all the rebuilds, but I haven't investigated whether those packages can build without the symbols.
05:58:31
@andmuz:matrix.org@andmuz:matrix.org joined the room.07:29:28
@Minijackson:matrix.orgMinijackson
In reply to @r_i_s:matrix.org
i'm struggling to reproduce this now, but I'm sure we've had at least one case in the past where fetchFromGitHub wasn't returning the vanilla repo source
You light have encountered a case were git attributes were used, which can modify the generated git archive. An example that I have on hand: https://github.com/paulscherrerinstitute/StreamDevice/blob/master/.gitattributes
08:21:08
@r_i_s:matrix.orgris_the seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth11:05:44
@r_i_s:matrix.orgris_ * that seems feasible - didn't know about that. at least changes to gitattributes have to be checked in, which limits their stealth 11:05:51
@cAkwNLHysr:matrix.orgRW joined the room.11:32:07

Show newer messages


Back to Room ListRoom Version: 6