!lymvtcwDJ7ZA9Npq:lix.systems

Lix Development

418 Members
(Technical) development of Lix, the package manager, a Nix implementation. Please be mindful of ongoing technical conversations in this channel.140 Servers

Load older messages


SenderMessageTime
19 Aug 2025
@emilazy:matrix.orgemilyOpenSSL is not nearly as bad as it was a decade ago16:53:27
@emilazy:matrix.orgemilythough still not great16:53:30
@just1602:systemli.orgjust1602This is still awesome news to read IMO16:55:16
@jade_:matrix.orgjade_the one good thing about crypto code is if it were producing wrong results you would damn well know about it, so the limit of what can be screwed up in practice is pretty low and limited to mostly side channels and protocol screwups. but we are using primitives sooooooo it's really not so important regardless18:21:45
@jade_:matrix.orgjade_it is on release branches, the only problem is with if you are using 1. lix's own packaging and 2. on a tag18:27:35
@jade_:matrix.orgjade_if we wanted to kill a dependency by using openssl in place of libsodium that sounds good to me, i am not at all fussed either way.18:28:26
@jade_:matrix.orgjade_p low on my concerns priority list in the end18:28:38
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)
In reply to @aloisw:julia0815.de
Libsodium also had quality incidents in the past, like https://github.com/jedisct1/libsodium/commit/ad4584d45590654b9d863ced90d2b2561d5cfbda .
hm oof indeed
18:33:53
@jade_:matrix.orgjade_however, as stated, crypto code breaks very loudly and we are not encrypting anything confidential18:34:12
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)oh lol vcunat intervening in that commit in the comment area18:34:25
@jade_:matrix.orgjade_so it is very hard for them to fuck up in a way that materially affects us18:34:30
@jade_:matrix.orgjade_ ... besides that 18:34:54
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)yeah, i can review a patch moving to openssl if needed18:36:34
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)i doubt that openssl can fuck up ed25519 but also it's a bit frightening because i think most people using ed25519 use it via libsodium18:38:07
@raitobezarius:matrix.orgraitobezarius (DECT: 7248) https://git.lix.systems/lix-project/lix/issues/969 cc Kira as aloisw pointed very good reasons to perform that switch 18:42:10
@jade_:matrix.orgjade_ raitobezarius: is your epyc still available for room-heating (mass scale remote builds)? i um, have a use case for a large scale change by messing with the pytest packaging. 18:42:58
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)yes it is18:43:05
@jade_:matrix.orgjade_awesome18:43:09
@commentator2.0:elia.gardenRutile (Commentator2.0) feel free to pingis it relevant for me to know what you are (planning to) doing?18:45:26
@helle:tacobelllabs.nethelle (just a stray cat girl) sweats profusely at this idea oh no jade, I am worried 18:45:54
@jade_:matrix.orgjade_ setting dontWrapPythonPrograms = true on it 18:47:15
@jade_:matrix.orgjade_globally18:47:19
@commentator2.0:elia.gardenRutile (Commentator2.0) feel free to ping raitobezarius: can you punch ci/pipeline for 3992? it just says "verfied -1" without any explenation and doesn't update on push 18:47:25
@emilazy:matrix.orgemily I'm pretty sure nixpkgs-review on a pytest change will rebuild most of the package set 18:47:27
@jade_:matrix.orgjade_i also think this will happen :P18:47:36
@emilazy:matrix.orgemilyI would recommend testing direct dependencies only (which will still be a billion things)18:47:37
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)
In reply to @commentator2.0:elia.garden
raitobezarius: can you punch ci/pipeline for 3992? it just says "verfied -1" without any explenation and doesn't update on push
it's the ASAN flakiness
18:48:05
@jade_:matrix.orgjade_ hm, is there a way to bazel uquery 'rdeps(//:pytest)' in nix? 18:48:06
@raitobezarius:matrix.orgraitobezarius (DECT: 7248)i kicked it again18:48:08
@emilazy:matrix.orgemily trofi has a script lying around somewhere. you can also just rg 18:48:29

Show newer messages


Back to Room ListRoom Version: 10