!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

744 Members
Coordination and triage of security issues in nixpkgs229 Servers

Load older messages


SenderMessageTime
1 Jul 2021
@synthetica:matrix.orgSyntheticaD:11:35:53
@linus.heckemann:matrix.mayflower.deLinux Hackerman
In reply to @janne.hess:helsinki-systems.de
AppArmor works pretty well for this
really, in spite of the files being created by nixbld$n?
11:36:03
@janne.hess:helsinki-systems.dedas_jmain reason I don't use DAC for this kind of stuff is exactly inflexibilities like that ;)11:36:04
@janne.hess:helsinki-systems.dedas_j
In reply to @linus.heckemann:matrix.mayflower.de
really, in spite of the files being created by nixbld$n?
You are probably mistaking this for SELinux
11:36:17
@janne.hess:helsinki-systems.dedas_jAppArmor works path-based, not label-based11:36:25
@kunrooted:matrix.orgkunrootedbased11:36:36
@balsoft:balsoft.rubalsoftI can't even reboot11:36:47
@balsoft:balsoft.rubalsoftREISUB it is then11:36:52
@synthetica:matrix.orgSyntheticaoof11:36:55
@synthetica:matrix.orgSyntheticasorry 11:36:57
@balsoft:balsoft.rubalsoftOh11:37:36
@balsoft:balsoft.rubalsoftNo liveusb needed11:37:39
@balsoft:balsoft.rubalsoftNixOS is fairly self-repairing actually11:37:55
@synthetica:matrix.orgSyntheticawait, a reisub-reboot fixed it?11:38:35
@balsoft:balsoft.rubalsoftWhat if I do it in the activation script? :P11:38:43
@r_i_s:matrix.orgris_could i get some eyes on https://github.com/NixOS/nixpkgs/pull/126280 before permanent bitrot sets in?19:31:37
@hexa:lossy.networkhexathanks, lgtm19:43:36
2 Jul 2021
@irenes:matrix.orgIrenes joined the room.09:22:13
@hexa:lossy.networkhexahttps://www.djangoproject.com/weblog/2021/jul/01/security-releases/14:18:35
@obfusk:matrix.org幸猫 (𝗍𝗁𝖾𝗒/𝗍𝗁𝖾𝗆) joined the room.16:07:01
@_xmpp_julm=40sourcephile.fr:matrix.orgjulm left the room.18:11:39
@r_i_s:matrix.orgris_CVE-2021-34552 seems to map to https://github.com/python-pillow/Pillow/pull/5567, which looks pretty hard to expose18:28:53
@hexa:lossy.networkhexaotoh it looks pretty easy to backport18:29:57
@r_i_s:matrix.orgris_ you'd have to be passing in mode from untrusted input 18:29:59
@r_i_s:matrix.orgris_sure18:30:02
@hexa:lossy.networkhexauh, should post security advisories here and βœ… them when PR is up or so18:30:58
@hexa:lossy.networkhexajust so that the state of these things becomes more visible18:31:15
@philipp:xndr.dephilippMaybe a separate room just for them?18:32:25
@hexa:lossy.networkhexamaybe a separate room for the chit chat? 😊18:32:52
@balsoft:balsoft.rubalsoftI would love a room with advisories18:32:54

Show newer messages


Back to Room ListRoom Version: 6