!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

704 Members
Coordination and triage of security issues in nixpkgs214 Servers

You have reached the beginning of time (for this room).


SenderMessageTime
29 Mar 2024
@m00dy:matrix.orgmoody joined the room.17:20:21
@pareto-optimal-dev:matrix.orgpareto-optimal-dev joined the room.17:25:15
@mjm:midna.devmjm joined the room.17:26:08
@mjm:midna.devmjm 17:31:16
@Minijackson:matrix.orgMinijackson joined the room.17:33:44
@christian:kampka.netChristian joined the room.17:38:47
@hemant:cyberia.clubhemant (he/they) joined the room.17:48:51
@bear454:librem.one@bear454:librem.one joined the room.18:28:44
@mattleon:matrix.orgmattleon joined the room.18:31:48
@robgssp:matrix.orgrobgssp joined the room.18:32:48
@bear454:librem.one@bear454:librem.one left the room.18:32:54
@dp:anarchyislove.xyzDustin Plattner joined the room.18:45:10
@brokenpip3:matrix.orgbrokenpip3 joined the room.18:48:08
@cleverca22:matrix.orgcleverca22
In reply to @vcunat:matrix.org
Because release tarballs need less dependencies to build from.

i suspect thats also part of the exploit chain

configure isnt in git, and has to be generated when making the release tarball
and users are trusting that configure was generated properly

19:09:45
@cleverca22:matrix.orgcleverca22so the critical piece in making it all work, isnt in git, and there is no evidence of it in the history19:10:05
@winston:milli.ng@winston:milli.ng joined the room.19:34:49
@entheogenesis:matrix.org@entheogenesis:matrix.org joined the room.20:12:35
@hexa:lossy.networkhexaRedacted or Malformed Event20:52:12
@anthr76:mozilla.organthr76 joined the room.20:54:54
@gaelans:matrix.orgGaelan Steele joined the room.21:13:50
@magic_rb:matrix.redalder.orgmagic_rb joined the room.21:45:27
@r_i_s:matrix.orgris_i think we've encountered situations before where the github automatically generated tarball has been "overridden" by a release file being supplied in its place - which unnerved me a bit at the time - but makes me wonder if it's actually possible to get a tarball link to a git tag that will definitely have been auto-generated22:09:23
@r_i_s:matrix.orgris_ i.e. even fetchFromGitHub was returning the manually-uploaded tarball 22:11:32
@tomberek:matrix.orgtomberek ris_: if you use a tree-hash you have much better guarantees from their archive-tarball API. Fetching by commit-hash may encounter git-filter+smudging issues. 22:37:10
@tpw_rules:matrix.org@tpw_rules:matrix.org joined the room.23:01:50
@tpw_rules:matrix.org@tpw_rules:matrix.orghttps://bugs.debian.org/cgi-bin/bugreport.cgi?bug=106802423:01:55
@tpw_rules:matrix.org@tpw_rules:matrix.orgdebian is considering reverting xz further23:02:08
@tpw_rules:matrix.org@tpw_rules:matrix.orggiven our long lead time on a fix we should too23:06:13
@hexa:lossy.networkhexaas mentioned this would remove symbols that packages now depend on, so not as simple23:07:06
@hexa:lossy.networkhexalet's wait a week and see how the world looks then23:07:20

Show newer messages


Back to Room ListRoom Version: 6