!rGlCMuXgAhgEpdvJUz:nixos.org

NixOS KDE

201 Members
55 Servers

Load older messages


SenderMessageTime
18 Aug 2025
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)worked decently well in libsoup ocne we were under 100 users: https://github.com/NixOS/nixpkgs/pull/42781316:23:20
@marie:marie.cologneMarie it does but it's a bit broken so they default to x11 16:23:54
@emilazy:matrix.orgemilywe need to backport the mark though16:24:31
@emilazy:matrix.orgemilybut it's probably fine16:24:32
@emilazy:matrix.orgemilythat libsoup thing should also be backported but the fallout seems bad16:24:40
@k900:0upti.meK900 No it's not? 16:25:20
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)we had most of the libsoup migrations merged before 25.05 for a reason16:25:19
@emilazy:matrix.orgemily actually isn't fcitx5-chinese-addons sort of important 16:25:23
@k900:0upti.meK900It's pretty active16:25:26
@emilazy:matrix.orgemilyI know fcitx is very popular with Chinese users16:25:29
@emilazy:matrix.orgemilybut not sure if that package specifically is16:25:35
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)

https://github.com/NixOS/nixpkgs/pull/398783#issuecomment-2824682603

We need this no matter what since it is security relevant and will block further security updates in the future.

Sandro actually had a good point here. And as such on 25.05 the libsoup2 usage is below 100 too

16:26:27
@emilazy:matrix.orgemilyhttps://github.com/jellyfin/jellyfin-media-player/pull/599 😔16:26:41
@emilazy:matrix.orgemilywell I just mean I see people complaining regularly about all their stuff being broken because of it16:27:00
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all) but thats offtopic here, would continue that in #security-discuss:nixos.org , lets get back to qtwebengine 16:27:08
@emilazy:matrix.orgemilybackporting that kind of stuff hurts16:27:06
@emilazy:matrix.orgemilyI'm satisfied by the list here though, I think we can move forward with it16:27:20
@emilazy:matrix.orgemilyI don't think we need to block Plasma removal on it16:27:34
@emilazy:matrix.orgemilyer, vice versa16:27:42
@emilazy:matrix.orgemilybecause it's just … choosing what error people get16:27:44
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)fair enough16:27:54
@emilazy:matrix.orgemilyor at least we can get a PR up marking it as vulnerable and land them together16:27:57
@emilazy:matrix.orgemilyhttps://github.com/jellyfin/jellyfin-media-player/pull/844 does not look like anyone is putting real work into it16:28:33
@grimmauld:grapevine.grimmauld.deGrimmauld (any/all)should we dig out like 20 CVEs that affect the old qtwebengine or do we not bother and just slap it with some text?16:29:03
@k900:0upti.meK900Probably fine to just say "uses outdated chromium version, figure it out"16:30:54
@emilazy:matrix.orgemily"EOL since April 2025, vulnerable to all Chromium CVEs since then"16:32:03
@emilazy:matrix.orgemily (well, technically there can be CVEs that don't apply to their ancient Chromium) 16:32:21
@emilazy:matrix.orgemily (…there can also be CVEs that apply only to their ancient Chromium) 16:32:33
@emilazy:matrix.orgemilyit's Chromium 87, from 202016:33:20
@emilazy:matrix.orgemilywith half a decade of backported security patches16:33:25

Show newer messages


Back to Room ListRoom Version: 9