!aRKdLCkUeIFjRPZuJT:nixos.org

NixOS JVM

122 Members
27 Servers

Load older messages


SenderMessageTime
2 Nov 2024
@tomodachi94:matrix.orgTomodachi94 (they/them)Hmm maybe we just drop it right away and leave 24.05 alone?01:11:26
@tomodachi94:matrix.orgTomodachi94 (they/them)I'll see if anyone on the Fediverse knows what's up with Oracle JDK01:13:18
@emilazy:matrix.orgemilysorry, I'm a bit confused01:13:46
@emilazy:matrix.orgemilythere's nothing up with Oracle JDK except that it has a weird licence and is pointless to use since you can get OpenJDKs with normal licences01:13:59
@emilazy:matrix.orgemilythe problem with our package is that nobody has updated it with 2021, and clearly nobody will, and even if they would there's no reason for us to carry it since it's just a footgun to use it01:14:19
@emilazy:matrix.orgemily * the problem with our package is that nobody has updated it since 2021, and clearly nobody will, and even if they would there's no reason for us to carry it since it's just a footgun to use it01:14:24
@tomodachi94:matrix.orgTomodachi94 (they/them)Oh, so it's OpenJDK with the Oracle nametag01:14:32
@emilazy:matrix.orgemily it should definitely get knownVulnerabilities on 24.05, since it's unsafe to use 01:14:33
@emilazy:matrix.orgemilyyeah01:14:36
@emilazy:matrix.orgemilyand a really onerous licence01:14:40
@emilazy:matrix.orgemilythere's basically no reason for it to exist beyond Oracle's business model of entrapping people into having to pay them money01:15:07
@emilazy:matrix.orgemilyin the past, we carried it for AArch64, apparently01:15:44
@emilazy:matrix.orgemily per doc/languages-frameworks/java.section.md 01:15:54
@emilazy:matrix.orgemilywhich needs updating to reflect reality01:15:57
@tomodachi94:matrix.orgTomodachi94 (they/them)
In reply to@emilazy:matrix.org
it should definitely get knownVulnerabilities on 24.05, since it's unsafe to use
So a message like "Oracle JDKs are unsafe to use and are unmaintained in Nixpkgs. OpenJDK provides a comparable implementation." ?
01:18:19
@emilazy:matrix.orgemily
In reply to @emilazy:matrix.org
would you mind knownVulnerabilitiesing the Oracle JDKs on 24.05 too? no need to go CVE-hunting, can just say e.g. "Not updated for 4 years, many disclosed vulnerabilities"
I would just go for something like this ^ with the URL
01:19:46
@emilazy:matrix.orgemily fine to say "use openjdk" too if you'd like 01:19:53
@emilazy:matrix.orgemily and then on master we can e.g. oraclejdk = throw "Oracle JDKs were removed as they had been unmaintained in Nixpkgs since 2021 and contained many known vulnerabilities; use `openjdk` instead"; 01:20:37
@emilazy:matrix.orgemilyand we should update the docs too, but that's less pressing01:21:10
@tomodachi94:matrix.orgTomodachi94 (they/them)Tweaked wording as you suggested01:24:16
@emilazy:matrix.orgemilyLGTM :)01:25:48
@emilazy:matrix.orgemily will merge once nixpkgs-vet passes 01:26:28
@emilazy:matrix.orgemily uh wow, javacard-devkit is i686-linux 01:27:28
@tomodachi94:matrix.orgTomodachi94 (they/them)Wtf01:27:42
@emilazy:matrix.orgemilydoes it like, actually run?01:27:42
@tomodachi94:matrix.orgTomodachi94 (they/them)Only one way to find out 😉 does anyone have an i686 machine running Nix?01:28:17
@emilazy:matrix.orgemilyyou don't need it, the package will work on x86-6401:28:38
@tomodachi94:matrix.orgTomodachi94 (they/them)Oh oops01:28:46
@emilazy:matrix.orgemily (we don't support hosting a full NixOS on i686-linux) 01:28:54
@tomodachi94:matrix.orgTomodachi94 (they/them) Is it even technically restricted to i686 if it's a JAR? 😉 01:30:32

Show newer messages


Back to Room ListRoom Version: 6