!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

700 Members
Coordination and triage of security issues in nixpkgs216 Servers

Load older messages


SenderMessageTime
30 May 2021
@philipp:xndr.dephilipp about unpriviliged users can install packages: That is true on any normal linux desktop/server. Even if the package manager doesn't help you, local users will be able to execute all the code they want to. 18:38:41
@andi:kack.itandi-I also have a few ideas for PoCs on how to demonstrate downsides of our current stuff and what the average NixOS contributor should be aware of... DM me (in a few days/weeks) if you feel like you need more :)18:38:44
@andi:kack.itandi-
I thought about mentioning security of NixOS containers where root in container is root on the host
This was mitigated some time ago IRRC?
18:39:07
@andi:kack.itandi- *

I thought about mentioning security of NixOS containers where root in container is root on the host

This was mitigated some time ago IRRC?

18:39:11
@kunrooted:matrix.orgkunrooted
In reply to @philipp:xndr.de
about unpriviliged users can install packages: That is true on any normal linux desktop/server. Even if the package manager doesn't help you, local users will be able to execute all the code they want to.
you can limit them
18:39:11
@andi:kack.itandi- *

I thought about mentioning security of NixOS containers where root in container is root on the host

This was mitigated some time ago IRRC?

18:39:16
@kunrooted:matrix.orgkunrootedafaik 18:39:16
@kunrooted:matrix.orgkunrootedyou can make specific users having just write access to just specific things, it's really flexible af 18:39:37
@andi:kack.itandi-You can set noexec on ~18:39:39
@kunrooted:matrix.orgkunrooted
In reply to @andi:kack.it

I thought about mentioning security of NixOS containers where root in container is root on the host

This was mitigated some time ago IRRC?

it won't be an issue anymore?
18:39:55
@andi:kack.itandi-I vaguely recall someone talking about it months ago18:40:10
@kunrooted:matrix.orgkunrootedI was writing a container a while ago and it was mentioned an issue then by some of my collegues18:40:14
@andi:kack.itandi-perhaps this? https://github.com/NixOS/nixpkgs/pull/6733618:41:05
@kunrooted:matrix.orgkunrootedah, so it limits a root on the container?18:41:36
@kunrooted:matrix.orgkunrootedI think that still not many people might know about this option 18:42:19
@andi:kack.itandi-It wasn't merged yet so who knows what the actual state is :D18:42:43
@kunrooted:matrix.orgkunrootedyeah, it's a 'draft', weird 18:42:53
31 May 2021
@0x4a6f:matrix.org[0x4A6F] changed their display name from [0x4A6F] to 0x4A6F.08:23:41
@r_i_s:matrix.orgris_ hah. i've heard of squash-merges before but this author squashes their entire releases https://github.com/pgpartman/pg_partman/commit/0b6565ad378c358f8a6cd1d48ddc482eb7f854d3 13:01:19
@r_i_s:matrix.orgris_ luckily the search_path changes are all i need and they are separable by file 13:01:56
@r_i_s:matrix.orgris_ nothing fetchpatch can't handle 13:02:09
@r_i_s:matrix.orgris_still13:02:12
@synthetica:matrix.orgSyntheticawhy13:02:42
@synthetica:matrix.orgSyntheticawhy would one do that13:02:50
@reptarmigam:matrix.orgre-ptarmigan❄️🐦️ changed their display name from reptarmigan to re-ptarmigan❄️🐦️.21:56:28
1 Jun 2021
@0x4a6f:matrix.org[0x4A6F] changed their display name from 0x4A6F to [0x4A6F].06:35:18
@tilpner:tx0.cotilpner joined the room.11:01:44
@sgo:matrix.orgstigo joined the room.13:11:00
@charlotte:vanpetegem.mechvp joined the room.13:12:26
@buckley310:matrix.orgBuckley joined the room.13:56:15

Show newer messages


Back to Room ListRoom Version: 6