!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

695 Members
Coordination and triage of security issues in nixpkgs217 Servers

Load older messages


SenderMessageTime
16 Jun 2021
@philipp:xndr.dephilippThere doesn't seem to be any tests or anything in nixpkgs for connman. How would one go about to update it over just doing it, seeing whether nixpkgs still builds and hoping for the best?20:41:41
@hexa:lossy.networkhexawell, not hoping, trying to find a user, someone who previously bumped it, testing it yourself20:42:15
@hexa:lossy.networkhexabest case: 1.39->1.40 is just a security & bugfix release20:43:10
@hexa:lossy.networkhexaif not we would prefer a patch be applied to the stable release20:44:05
@moritz.hedtke:matrix.orgmoritz.hedtkehttps://github.com/NixOS/nixpkgs/pull/126553 should we just wait for alyssais or is this more urgent (update of httpd)?20:47:31
@Las:matrix.orgLas
In reply to @hexa:lossy.network
best case: 1.39->1.40 is just a security & bugfix release
https://git.kernel.org/pub/scm/network/connman/connman.git/commit/?h=1.40&id=25479cf866e60b0101cda0d80e825cd8128bb4eb
20:48:37
@Las:matrix.orgLasso yeah that's just what it is seemingly20:48:40
@Las:matrix.orgLasI'm trying to update it but running into problems with the openconnect dependency20:48:58
@philipp:xndr.dephilippIf validation happened last time while updating connman in stable or unstable, it's not documented in the pull requests.20:49:25
@hexa:lossy.networkhexa

for testing connman maybe poke romildo https://github.com/NixOS/nixpkgs/pull/83473#pullrequestreview-383268673

20:53:52
@hexa:lossy.networkhexa * for testing connman maybe poke romildo https://github.com/NixOS/nixpkgs/pull/83473#pullrequestreview-38326867320:54:08
@hexa:lossy.networkhexaRedacted or Malformed Event20:54:08
@hexa:lossy.networkhexa
In reply to @moritz.hedtke:matrix.org
https://github.com/NixOS/nixpkgs/pull/126553 should we just wait for alyssais or is this more urgent (update of httpd)?
if the tests are still working and the change looks reasonable I think we can go for a merge
20:54:54
@moritz.hedtke:matrix.orgmoritz.hedtkeI'm currently working on testing it - give me aminute20:55:23
@moritz.hedtke:matrix.orgmoritz.hedtke * I'm currently working on testing it - give me a minute20:55:28
@hexa:lossy.networkhexacan't wait until we have threading here20:56:06
@andreas.schraegle:helsinki-systems.deajs124We should also bump exiv2, now that they published a release21:01:05
@moritz.hedtke:matrix.orgmoritz.hedtke * I'm currently working on testing it - give me a minute (a few more it's rebuilding quite a bit, also I'm not using the release branch on my system so I setup a container)21:02:51
@moritz.hedtke:matrix.orgmoritz.hedtke * I'm currently working on testing it - give me a minute (a few more it's rebuilding quite a bit, also I'm not using the release branch on my system so I setup a container) - super annoying that all php versions are dependent on apache21:16:27
@moritz.hedtke:matrix.orgmoritz.hedtkeAnybody knows what the error in https://logs.nix.ci/?key=nixos/nixpkgs.126553&attempt_id=99721217-08a7-4bce-92cb-7d09c4259452 is supposed to mean? Because that's the same error I also get locally. Or should I ask in the main channel.21:31:05
@moritz.hedtke:matrix.orgmoritz.hedtke For nix build -L github:NixOS/nixpkgs/backport-126422-to-release-21.05#nixosTests.acme and equivalent non-flake command - also when rebasing 21:32:09
@Las:matrix.orgLasBTW connman seems to work fine if you just update the version, source hash, and add openconnect to buildInputs, but I can't make the PR due to my nix store being unrecoverably corrupt.21:34:10
@sandro:supersandro.deSandro
In reply to @moritz.hedtke:matrix.org
Anybody knows what the error in https://logs.nix.ci/?key=nixos/nixpkgs.126553&attempt_id=99721217-08a7-4bce-92cb-7d09c4259452 is supposed to mean? Because that's the same error I also get locally. Or should I ask in the main channel.
yes and maybe it tries to connect to b.example.com?
21:43:54
@moritz.hedtke:matrix.orgmoritz.hedtke
In reply to @sandro:supersandro.de
yes and maybe it tries to connect to b.example.com?
but how is the acme test suddenly failing? I'm not an expert with the nixos test system but that doesn't make sense to me
21:46:15
@moritz.hedtke:matrix.orgmoritz.hedtkeTest is broken on nixos-21.05 but working on master - will investigate21:51:59
@moritz.hedtke:matrix.orgmoritz.hedtkeLikely https://github.com/NixOS/nixpkgs/commit/b00bcf21abc392ecb1d93bd49f7a5ffbc8524ecf#diff-352faa44c3da86e70bd6b5a55ff13f0a900b0f2fac44229f352ed1fd5b93a262?21:53:01
@moritz.hedtke:matrix.orgmoritz.hedtke * Likely https://github.com/NixOS/nixpkgs/commit/b00bcf21abc392ecb1d93bd49f7a5ffbc8524ecf#diff-352faa44c3da86e70bd6b5a55ff13f0a900b0f2fac44229f352ed1fd5b93a262? which is missing on release-21.0521:54:40
@moritz.hedtke:matrix.orgmoritz.hedtkebtw. until when / are we still backporting security fixes to 20.0921:58:24
@hexa:lossy.networkhexa Foxboron: are you using schleuder for disclosures? 22:04:43
@hexa:lossy.networkhexa moritz.hedtke: roughly end of the month 22:07:50

Show newer messages


Back to Room ListRoom Version: 6