| 2 Nov 2024 |
emily | 🤡 | 02:21:51 |
Tomodachi94 (they/them) | So much for dropping OracleJDK/JRE 🤡 | 02:22:20 |
emily | are you sure? | 02:22:27 |
emily | you assume that these packages are, themselves, maintained | 02:22:40 |
emily | damn apparently at least one of them is | 02:22:59 |
emily | anyway, Atlassian definitely won't support running on an Oracle JDK from 2021 | 02:23:14 |
Tomodachi94 (they/them) | The Atlassian stuff is in the NixOS modules (I suspect it should actually be something configured in the package, but I digress) | 02:23:52 |
emily | https://jira.atlassian.com/browse/JRASERVER-46152 | 02:24:01 |
emily | this doesn't actually back up the assertion | 02:24:04 |
emily | imo, set it to the corresponding OpenJDK packages in the PR, ping @techknowlogick since they seem to maintain them | 02:25:20 |
emily | people deploying atlassian software on NixOS should certainly know that they're running an unsupported JDK, and AFAICT the issue linked is just about, like… a regex issue? | 02:26:02 |
emily | [emily@build01:~]$ nix run nixpkgs#jdk8 -- -version
openjdk version "1.8.0_422"
| 02:26:22 |
emily | and AFAICT our JDKs should pass the regex just fine | 02:26:28 |
Tomodachi94 (they/them) | In reply to@emilazy:matrix.org people deploying atlassian software on NixOS should certainly know that they're running an unsupported JDK, and AFAICT the issue linked is just about, like… a regex issue? Well they'll know now that knownVulns is set /j | 02:26:32 |
emily | this is what sucks about Nixpkgs. if you stare at anything for too long you discover fractal cobwebs covering everything | 02:27:27 |
Tomodachi94 (they/them) | There's no nixosTests for any of those modules either 🫠| 02:28:10 |
Tomodachi94 (they/them) | In reply to@emilazy:matrix.org this is what sucks about Nixpkgs. if you stare at anything for too long you discover fractal cobwebs covering everything drop pkgs/* /j | 02:28:45 |
Tomodachi94 (they/them) | Anyways time to copy/paste the same throw message 8 times | 02:32:38 |
Tomodachi94 (they/them) | * Anyways time to copy/paste the same throw message 8 times for the drop OracleJDK PR | 02:32:51 |
Tomodachi94 (they/them) | In reply to@emilazy:matrix.org IMO the justification is: it depends on a package being removed for being an unmaintained security disaster, is many years of out of date compared to what we could be packaging (there are modern Linux versions: https://www.oracle.com/java/technologies/javacard-downloads.html#sdk-sim), and it has been untouched since 2018 so there is no reason to expect that the former two will be resolved (and it's not your job to do so) Should I call OracleJDK an unmaintained security disaster in the drop message? :) | 02:36:11 |
emily | 😅 | 02:36:21 |
Tomodachi94 (they/them) | Not sure if I should be more eloquent | 02:36:22 |
emily | that's your call | 02:36:23 |
emily | do you mean the throw? | 02:36:30 |
emily | I gave some more diplomatic wording earlier | 02:36:37 |
Tomodachi94 (they/them) | Yes, and the changelog | 02:36:40 |
emily | you can go wild in the commit message if you want :P | 02:36:45 |
Tomodachi94 (they/them) | https://github.com/NixOS/nixpkgs/pull/353043 | 02:43:35 |
Tomodachi94 (they/them) | (oops, committed a syntax error... somewhere) | 02:44:05 |
emily | hehe | 02:56:40 |