| 16 Jan 2024 |
K900 | * Oh god | 15:28:28 |
vcunat | I don't think you need to run it. | 15:30:41 |
vcunat | Just update version and hash. (version repeats IIRC) | 15:30:54 |
vcunat | Surely a security update won't change the set of dependencies. | 15:31:29 |
vcunat | (the X stuff is very unmoving anyway) | 15:31:49 |
Fabián Heredia | ok, doing manually then. | 15:35:26 |
K900 | The script seems to be working for me | 15:35:49 |
K900 | OK the script kinda works | 15:46:35 |
Fabián Heredia | https://github.com/NixOS/nixpkgs/pull/281350 | 15:49:06 |
K900 | https://github.com/NixOS/nixpkgs/pull/281349 ? | 15:49:45 |
K900 | I have another thing there | 15:49:54 |
Fabián Heredia | :O | 15:50:13 |
Fabián Heredia | closing as dupe then | 15:50:20 |
K900 | It builds, Plasma test passes, merged | 15:56:54 |
| Moved to @sashanoraa:matrix.org joined the room. | 17:06:21 |
| @adam:robins.wtf joined the room. | 17:18:46 |
tgerbet | https://blog.quarkslab.com/pixiefail-nine-vulnerabilities-in-tianocores-edk-ii-ipv6-network-stack.html
https://github.com/tianocore/edk2/security/advisories/GHSA-hc6x-cw6p-gj7h | 20:17:35 |
K900 | Not really much we can do | 20:17:55 |
K900 | I guess update our EDK2 | 20:17:59 |
tgerbet | Yep update is not yet available but there is a patch for 7 out of 9 issues in edk2 bugtracker, I will take a look in a moment.
| 20:22:06 |
K900 | Thing is, our EDK2 is only used for VM tests basically | 20:24:46 |
K900 | Which is not very relevant to this | 20:24:56 |
raitobezarius | I did enable the IPv6 stack recently | 20:25:27 |
raitobezarius | And some people deploy that EDK2 on real systems ahem | 20:25:47 |
hexa | my local qemu test vms use edk2 | 21:00:44 |
@adam:robins.wtf | incus and lxd are using edk2 too | 23:07:44 |
@adam:robins.wtf | running the virtual-machine test should be sufficient | 23:08:05 |
raitobezarius | In reply to @tgerbet:matrix.org Yep update is not yet available but there is a patch for 7 out of 9 issues in edk2 bugtracker, I will take a look in a moment.
Can you put me in the loop or ping me if you need my actions? I am not sure if I want to patch too early EDK2 shit because their QA is outright bad in general | 23:21:46 |
tgerbet | I just requested a review from you 👍
https://github.com/NixOS/nixpkgs/pull/281405
| 23:26:39 |
| Bailey (she/they) joined the room. | 23:36:16 |