!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

758 Members
Coordination and triage of security issues in nixpkgs235 Servers

Load older messages


SenderMessageTime
23 Jun 2021
@hexa:lossy.networkhexaRedacted or Malformed Event14:11:44
@hexa:lossy.networkhexawouldn't expect it unless someone takes a special interest, the maintainers certainly won't 14:12:28
@linus.heckemann:matrix.mayflower.deLinux HackermanI saw that, should I ask him about it? :>14:12:31
@hexa:lossy.networkhexalol :)14:12:36
@linus.heckemann:matrix.mayflower.deLinux Hackermanhe's just around the corner14:12:40
@hexa:lossy.networkhexaask him about his general maintainer status in nixpkgs14:12:46
@pennae:matrix.eno.spacepennaehaven't trusted networkd too much since it kept segfaulting on our router config D: otherwise we'd probably use that too just for convenience14:15:54
@hexa:lossy.networkhexa pennae: looks like it needs to have a user configured at compile time, which would mean some tie-in with a module creating that user 14:16:20
@hexa:lossy.networkhexanetworkd runs pretty well on multiple machines here, even on one carrying a bgp fulltable14:18:29
@pennae:matrix.eno.spacepennaenever quite found out why it segfaulted here either, but it seemed to dislike vlan ifs in bridges for some reason14:19:44
@pennae:matrix.eno.spacepennae but only sometimes 14:20:04
@hexa:lossy.networkhexa that is a pretty common setup, best take it to #networking:nixos.org 14:22:17
@kraftnix:matrix.orgkraftnix I also have seg faults with networkd when building up network configurations sometimes as well. The deepest I got on the debugging was that for some reason when I had a bad networkd config (some bad nix code), /etc/ld-nix.so.preload was missing when running the nix build, which causes a seg fault. The only work around I had was rolling back changes until I found the bad piece of code. I am still not unsure whether it's directly related to networkd or not, but it does happen when I am writing networkd configurations 14:23:12
@hexa:lossy.networkhexa rough. can we move it to #networking:nixos.org still? 14:24:00
@hexa:lossy.networkhexa * rough. can we move it to #networking:nixos.org still? if both of you have issues like this it should probably be investigated further. 14:24:21
@hexa:lossy.networkhexa pennae: on the topic of privsep, dhcpcd should get a privsep user when we can ensure it is used through the module, which in turn ensures the user exists 14:26:14
@hexa:lossy.networkhexaat one point there as a dhcpcd user allocated, see e9cd877921cc4164aa0ba57ae1fd7526ec6440c314:28:37
@hexa:lossy.networkhexa * at one point there even was a dhcpcd user allocated, see e9cd877921cc4164aa0ba57ae1fd7526ec6440c314:28:40
@pennae:matrix.eno.spacepennaethat's been a while14:29:06
@hexa:lossy.networkhexawould you want to look into that further?14:29:12
@pennae:matrix.eno.spacepennaenot sure we're qualified14:29:49
@hexa:lossy.networkhexacan only encourage you to try 😀14:34:18
@pennae:matrix.eno.spacepennaemight try at some point. the last module we tried to modify kind of fizzled in review 😶14:35:38
@hexa:lossy.networkhexathere are even nixos tests that you can use to verify you didn't break anything :)14:35:42
@pennae:matrix.eno.spacepennae grubbing around in system daemons is a bit scary tbh
at least mosquitto isn't that important (and also had tests (that were half broken))
14:39:27
@hexa:lossy.networkhexamosquitto was also haphazardly bumped a major version number just before the release14:51:25
@hexa:lossy.networkhexaignoring the resulitng breakage, not nice.14:51:43
@pennae:matrix.eno.spacepennaeand our PR to fix the module being extremely limited has seen basically no review since ... when was it, beginning of may?14:53:53
@pennae:matrix.eno.spacepennae at leas the bump didn't break anything here :/ 14:54:31
@pennae:matrix.eno.spacepennae oh hey, you're on that one as a reviewer hexa 😛 15:26:13

Show newer messages


Back to Room ListRoom Version: 6