!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

686 Members
Coordination and triage of security issues in nixpkgs211 Servers

Load older messages


SenderMessageTime
1 Oct 2023
@vcunat:matrix.orgvcunatI really hate when importance is not stated and bug report links are private, so what one could do is only analyze the commit. Sure, no need to publish how to exploit it, but if you don't indicate severity...05:51:17
@vcunat:matrix.orgvcunatMaybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)05:57:31
@vcunat:matrix.orgvcunat *

Maybe just wait, e.g. Firefox only released for the previous bug (VP8, not VP9 yet)

EDIT: now I noticed the topic on #security-discuss:nixos.org but even there these questions aren't answered yet.

06:23:22
@errornointernet:envs.netErrorNoInternet joined the room.08:32:35
@rwx-rwx-rwx:matrix.orgMikael Fangel joined the room.09:31:50
2 Oct 2023
@ajs124:ajs124.deajs124https://github.com/NixOS/nixpkgs/pull/258581 haven't tested much, but will do so now. if I don't draft it in the next hour or so, this can probably be merged.13:25:15
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:49:55
@nam3l33ss:matrix.org·☽•Nameless☆•777 · ± changed their profile picture.15:56:16
3 Oct 2023
@domenkozar:matrix.orgDomen Kožarhttps://twitter.com/bagder/status/170910392091452652514:14:43
@raitobezarius:matrix.orgraitobezarius

pretty much, yes. But this time actually the worst security problem found in curl in a long time.

14:15:06
@raitobezarius:matrix.orgraitobezarius(hope it's not my code)14:15:14
@delroth:delroth.netdelroth cc vcunat - we should figure out a staging-next timeline that works well with this (libcurl patch dropping on Oct 11) 14:59:17
@delroth:delroth.netdelrothdunno if we should extend the current staging-next cycle or make a short next cycle14:59:42
@vcunat:matrix.orgvcunatcurl is mainly a problem because of rebuilding darwin stdenvs. Not that much otherwise IIRC.15:00:09
@vcunat:matrix.orgvcunatOur farm has constant amount of darwin. (almost all aarch64+rosetta)15:01:20
@delroth:delroth.netdelrothhttps://github.com/NixOS/nixpkgs/pull/244468 5001+ Linux too apparently (let's maybe switch this discussion to the other channel)15:01:58
@vcunat:matrix.orgvcunat * curl is mainly a problem because of rebuilding darwin stdenvs. Not that much otherwise IIRC. EDIT: I was wrong, probably, looks big on linux, too.15:15:40
@insurgo:matrix.orgtlaurion aka Insurgo [ Timezone: ET ] changed their display name from Insurgo aka tlaurion (AFK) to Insurgo aka tlaurion (TZ: UTC-4).23:41:16
4 Oct 2023
@hexa:lossy.networkhexahttps://lists.x.org/archives/xorg/2023-October/061506.html01:24:04
@hexa:lossy.networkhexano idea who to tag tbh01:24:43
@raitobezarius:matrix.orgraitobezarius cc K900 ⚡️ Jan Tojnar and NickCao who touched this stuff last time AFAIK 01:26:23
@artturin:matrix.orgArtturin
In reply to @hexa:lossy.network
https://lists.x.org/archives/xorg/2023-October/061506.html
https://github.com/NixOS/nixpkgs/pull/258841
02:18:35
@k900:0upti.meK900Wait me05:56:46
@k900:0upti.meK900When did I touch Xorg stuff05:56:56
@fabianhjr:matrix.orgFabián Herediai'm suggested by github and don't remember commiting/changing that either 😅05:58:56
@fabianhjr:matrix.orgFabián Herediaimage.png
Download image.png
05:59:31
@k900:0upti.meK900Oh06:00:13
@k900:0upti.meK900https://github.com/NixOS/nixpkgs/commit/c018561f5467bdbcae1364220000d69431771d6806:00:14
@k900:0upti.meK900lmao06:00:15
@fabianhjr:matrix.orgFabián Herediaoh wait I did https://github.com/NixOS/nixpkgs/pull/23811606:00:28

Show newer messages


Back to Room ListRoom Version: 6