!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

728 Members
Coordination and triage of security issues in nixpkgs227 Servers

Load older messages


SenderMessageTime
6 May 2026
@codec:fnord.cxcodec joined the room.16:33:12
@hexa:lossy.networkhexasame17:42:41
@hexa:lossy.networkhexablocked17:43:32
@williamvds:matrix.orgaveryv joined the room.19:06:21
@williamvds:matrix.orgaveryvHiya, I'm looking at handling https://github.com/NixOS/nixpkgs/issues/517209, pi-hole vuln, coming back to it after a while of neglecting it. Another contributor has been working on updating the package. Annoyingly it now depends on mbedtls 4.0, which that contributor has packaged here https://github.com/NixOS/nixpkgs/pull/509801. But they're getting nixpkgs-vet errors blocking it. Is it possible to disable nixpkgs-vet so we can get the vuln fixed and refactor later?19:17:01
@kuflierl:matrix.orgkuflierlInteresting attack. But i am quite sure that we do not build, only eval in ci and send stuff to hydra where github tokens are non-existant19:17:02
@kuflierl:matrix.orgkuflierl* Interesting attack. But i am quite sure that we do not build, only eval in ci and send builds to hydra where github tokens are non-existant19:17:52
@williamvds:matrix.orgaveryv* Hiya, I'm looking at handling https://github.com/NixOS/nixpkgs/issues/517209, pi-hole vuln, coming back to it after a while of neglecting it. Another contributor has been working on updating the package. Annoyingly it now depends on mbedtls 4.0, which that contributor has packaged here https://github.com/NixOS/nixpkgs/pull/509801. But they're getting nixpkgs-vet errors blocking it. Is it possible to disable nixpkgs-vet for the PR so we can get the vuln fixed and refactor later?19:18:04
@winter:catgirl.cloudWinterwe do not send ANYTHING to hydra from github ci.19:24:44
@hexa:lossy.networkhexatangential https://docs.lix.systems/manual/lix/stable/installation/multi-user.html#the-lix-daemon-as-a-security-non-boundary19:25:55
@kuflierl:matrix.orgkuflierlIs this outdated information? i remember seing seeing my changes in the hydra build queue for days until hydra picks it up19:26:32
@kuflierl:matrix.orgkuflierlIt was used more before we switched somewhat to github actions19:26:57
@leona:leona.isleonaGHA is not involved in this process.19:27:08
@jappie:jappie.devjappie the nixpkgs-vet errors in question say that the package should be added under pkgs/by-name & that __structuredAttrs should be enabled, is there a reason why you can't ask the author of the PR to do these things? if they're unresponsive, you can open a new PR & amend their work
also, I think this discussion is more suited for https://matrix.to/#/#dev:nixos.org, this channel is for triaging security issues
19:27:31
@kuflierl:matrix.orgkuflierlElaborate19:27:58
@jappie:jappie.devjappie maybe elaborate in #NixOS Security Discussions :p 19:28:43
@jappie:jappie.devjappie maybe elaborate in #NixOS Security Discussions or the CI channel or something :p 19:28:54
7 May 2026
@mdaniels5757:matrix.orgmdaniels5757Are you thinking of Ofborg?01:55:11
@mdaniels5757:matrix.orgmdaniels5757* kuflierl: Are you thinking of Ofborg?01:55:31
@vcunat:matrix.orgvcunathydra.nixos.org only reads the git repo (some particular branches). There's no other interaction with GitHub.06:38:17
@vcunat:matrix.orgvcunatWell, the machine doing channel updates then moves those branches in the git repo, but that's tangential here.06:38:46
@kuflierl:matrix.orgkuflierl
In reply to @mdaniels5757:matrix.org
Are you thinking of Ofborg?
As discussed in Discussions, yes
19:52:56
@hexa:lossy.networkhexahttps://github.com/V4bel/dirtyfrag19:57:24
@steinbes04:matrix.spline.desteinbes04 joined the room.20:07:55
@netali:cuties.devJennySeems to be related, but exploits other kernel modules: https://github.com/0xdeadbeefnetwork/Copy_Fail2-Electric_Boogaloo21:58:29
@raitobezarius:matrix.orgraitobezariusIt's the same root cause21:59:32
@kybe:kybe.xyzkybe joined the room.22:04:14
@kuflierl:matrix.orgkuflierl https://github.com/NixOS/nixpkgs/pull/517642
Pretty old stuff I just forgot about because the bot didn't notify me
23:13:39
8 May 2026
@jopejoe1:matrix.orgjopejoe1 changed their display name from jopejoe1 (4094@epvpn) to jopejoe1.08:44:11
@k900:0upti.meK900https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.20614:49:02

Show newer messages


Back to Room ListRoom Version: 6