!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

676 Members
Coordination and triage of security issues in nixpkgs | Discussions in #security-discuss:nixos.org | Open PRs: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+sort%3Aupdated-desc+label%3A%221.severity%3A+security%22211 Servers

Load older messages


SenderMessageTime
29 Oct 2024
@scrumplex:duckhub.ioScrumplex * https://github.com/NixOS/nixpkgs/pull/35216119:13:30
@hexa:lossy.networkhexaare you planning to test these?19:33:19
@scrumplex:duckhub.ioScrumplex
In reply to @hexa:lossy.network
are you planning to test these?
I was just setting up a remote builder to be able to build them in a reasonable time
19:46:30
@hexa:lossy.networkhexaI queued build for firefox-unwrapped.tests and firefox-esr-unwrapped.tests on x86-64-linux and aarch64-linux19:52:47
@hexa:lossy.networkhexa * I queued builds for firefox-unwrapped.tests and firefox-esr-unwrapped.tests on x86-64-linux and aarch64-linux19:52:52
@scrumplex:duckhub.ioScrumplexfirefox-bin firefox-beta-bin firefox-devedition-bin thunderbird-bin all work19:57:40
@scrumplex:duckhub.ioScrumplex both -devedition and -beta fail to apply /nix/store/9lx1746yy56pn3dpc35l1xr6l3lykbin-env_var_for_system_dir-ff111.patch 20:05:47
@hexa:lossy.networkhexa #mozilla:nixos.org 20:07:35
@hexa:lossy.networkhexa vcunat: https://www.openwall.com/lists/oss-security/2024/10/29/2 20:39:42
@vcunat:matrix.orgvcunatI certainly can't do anything tonight anymore.20:50:06
@scrumplex:duckhub.ioScrumplexI can submit a PR but I don't think I'll be able to test them beyond building them20:53:34
@scrumplex:duckhub.ioScrumplex * I can submit a PR but I don't think I'll be able to test them beyond building them Edit: PR: https://github.com/NixOS/nixpkgs/pull/35219121:16:01
30 Oct 2024
@stigo:matrix.orgstigoThis seems to have been merged into staging, any ETA on when this fix will arrive in the unstable channels?11:22:08
@lt1379:matrix.orgLunhttps://github.com/NixOS/nixpkgs/issues/35244519:24:20
@vcunat:matrix.orgvcunatLike... a month, I'd guess.19:25:32
@emilazy:matrix.orgemily uh, we're doing one more staging before release though right? 19:26:10
@emilazy:matrix.orgemilythere's some pretty important fixes in there19:26:14
@emilazy:matrix.orgemilyand the schedule calls for it19:26:22
@emilazy:matrix.orgemily I thought we would go straight into staging-next-24.05 in a couple days when we merge, and then do one last 24.11-pre. 19:26:55
@grossmap:in.tum.de@grossmap:in.tum.de joined the room.19:59:46
@joerg:thalheim.ioMic92https://github.com/NixOS/nixpkgs/pull/352455 https://github.com/NixOS/nixpkgs/pull/35245620:36:43
@joerg:thalheim.ioMic92nix: fix macOS sandbox escape via builtin builders20:36:55
@emilazy:matrix.orgemilyRedacted or Malformed Event20:44:35
@emilazy:matrix.orgemilywill handle this one20:48:58
@hexa:lossy.networkhexahttps://www.openwall.com/lists/oss-security/2024/10/30/4 qbittorrent23:55:19
31 Oct 2024
@scrumplex:duckhub.ioScrumplexhttps://github.com/NixOS/nixpkgs/pull/352499 for master00:11:01
@scrumplex:duckhub.ioScrumplex24.05 is on 4.x. Just blindly applying the relevant patches doesn't work Relevant patch: https://github.com/qbittorrent/qBittorrent/commit/2a4425380292baedc3be1d1e57506e45172da6fc Part of the same PR but not strictly needed to fix vulnerability: https://github.com/qbittorrent/qBittorrent/commit/2a4077414f44f370d4bb66c3fd91ec755d4ce04d00:17:48
@emilazy:matrix.orgemily the advisory is somewhat (subtextually) withering about their security practices. I think knownVulnerabilities for 24.05 is okay, and it's not clear to me if the other issues they disclosed have been fixed. 00:18:32
@emilazy:matrix.orgemily * the advisory is somewhat (subtextually) withering about their security practices. I think knownVulnerabilities for 24.05 is okay, and it's not clear to me if the other issues they disclosed have been fixed. (edit: actually, I guess they implied they're at least unexploitable due to TLS validation now) 00:19:12
@scrumplex:duckhub.ioScrumplexI'll propose this: https://github.com/NixOS/nixpkgs/pull/352501 Maybe we can safely update 24.05 to qBittorrent 5.0.1, as I couldn't see any breaking changes, but maybe other people can handle that ^^00:21:57

Show newer messages


Back to Room ListRoom Version: 6