!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

688 Members
Coordination and triage of security issues in nixpkgs215 Servers

Load older messages


SenderMessageTime
1 Jul 2024
@qyliss:fairydust.spaceAlyssa Rossalready on it08:48:23
@emilazy:matrix.orgemilydon't have my VM up right now08:48:24
@qyliss:fairydust.spaceAlyssa Ross23.11 is EOL as of yesterday btw08:48:25
@emilazy:matrix.orgemilyI figured we might as well throw people a bone when it's a root RCE08:48:43
@emilazy:matrix.orgemilyI was considering backporting to 23.05, even08:48:47
@qyliss:fairydust.spaceAlyssa Rossyeah fair enough08:48:49
@qyliss:fairydust.spaceAlyssa RossI've had RMs yell at me for backporting too far before, to avoid giving a false sense of security to users on ancient releases, so I wouldn't do 23.05.08:49:17
@qyliss:fairydust.spaceAlyssa Rossbut it's probably still 30 June somewhere in the world :P08:49:41
@emilazy:matrix.orgemilynot every day you get a bug this bad in a package this ubiquitous. but I'll let someone else decide to 23.05 if they feel like it then08:50:20
@tgerbet:matrix.orgtgerbet23.11 seems fair, 23.05 I would not bother08:51:34
@emilazy:matrix.orgemily macOS build is on checkPhase, can probably just merge when that finishes and the NixOS test passes 08:53:45
@emilazy:matrix.orgemilyyeah it finished08:53:50
@qyliss:fairydust.spaceAlyssa RossI'm 14 minutes into checkPhase on aarch64-linux08:54:21
@qyliss:fairydust.spaceAlyssa Ross* 14 minutes into the build08:54:42
@emilazy:matrix.orgemilydo we care about waiting for Gentoo's fix backport for stable or should we just do the major bump?08:56:03
@emilazy:matrix.orgemilyhttps://github.com/gentoo/gentoo/commit/1633ef45475afb9eea04e9cf27021c9d994af33808:56:24
@emilazy:matrix.orgemilyah, the backport is already here08:56:27
@emilazy:matrix.orgemilyand is from upstream08:56:38
@emilazy:matrix.orgemilywill defer to others' judgement as to how we want to do the stable fixes08:57:15
@qyliss:fairydust.spaceAlyssa Rossif there's a backport available that probably makes sense08:57:27
@emilazy:matrix.orgemilyI'll do it that way then08:58:39
@emilazy:matrix.orgemilyI don't have merge permissions btw so feel free to hit the button on the master PR when you're confident08:59:23
@emilazy:matrix.orgemilywe probably need to mark _hpn as insecure or see if the patch applies also08:59:59
@qyliss:fairydust.spaceAlyssa Rossmerged09:00:42
@k900:0upti.meK900Thanks whoever started unstable-small09:02:45
@emilazy:matrix.orgemilyI'll look at the HPN nonsense once the stable stuff is done09:04:12
@qyliss:fairydust.spaceAlyssa Ross(finished building on aarch64-linux)09:04:27
@qyliss:fairydust.spaceAlyssa Rossoh, should we move out of the triage channel?09:04:43
@emilazy:matrix.orgemilyI'll move to the discussion room09:06:15
@fadenb:utzutzutz.netfadenb joined the room.10:09:53

Show newer messages


Back to Room ListRoom Version: 6