| 10 Apr 2024 |
cole-h | It was merged before ofborg could run lol | 21:18:36 |
Lily Foster | oh 💀 | 21:18:43 |
cole-h |  Download image.png | 21:19:07 |
Lily Foster | hmmmmm https://github.com/NixOS/nixpkgs/blob/4e2ce36aab7183f1d800cd5417cfa3d4d6c72d93/pkgs/build-support/trivial-builders/test/default.nix#L23-L27 | 21:21:01 |
Lily Foster | yeah that conditional can just straight up be removed | 21:22:11 |
Lily Foster | it doesn't do the right thing anyway | 21:22:19 |
| 11 Apr 2024 |
| Anthony Rsl set a profile picture. | 21:59:15 |
| Anthony Rsl removed their profile picture. | 22:12:50 |
| 13 Apr 2024 |
symphorien | ofborg validated a hash which then was invalidated, but upstream says the source was not force-pushed. does by any chance the source that ofborg fetched still exist (it was two weeks ago) ? | 21:06:05 |
| 14 Apr 2024 |
Julien | I'd try to look if there is a software heritage archive that contains it | 12:32:48 |
| 15 Apr 2024 |
symphorien | unfortunately not | 18:38:09 |
| 17 Apr 2024 |
| JoelMcCracken joined the room. | 16:28:42 |
| K900 changed their display name from K900 ⚡️ to K9Ö0. | 17:16:44 |
| K900 changed their display name from K9Ö0 to K900. | 17:21:55 |
| K900 | 17:21:55 |
| 24 Apr 2024 |
| @stablejoy:matrix.org changed their profile picture. | 08:59:07 |
| aleksana 🏳️⚧️ (force me to bed after 18:00 UTC) joined the room. | 11:50:17 |
| 25 Apr 2024 |
| delroth left the room. | 14:45:02 |
| adamcstephens left the room. | 19:15:23 |
| 26 Apr 2024 |
| @stablejoy:matrix.org changed their profile picture. | 14:03:45 |
| @federicodschonborn:matrix.org changed their profile picture. | 14:48:00 |
| 27 Apr 2024 |
| nadir joined the room. | 18:22:47 |
| 28 Apr 2024 |
| @federicodschonborn:matrix.org changed their profile picture. | 22:46:56 |
| @federicodschonborn:matrix.org left the room. | 23:13:48 |
| 29 Apr 2024 |
| NixOS Moderation Botchanged room power levels. | 15:29:42 |
| 1 May 2024 |
| NixOS Moderation Botchanged room power levels. | 15:07:20 |
| 6 May 2024 |
ris_ | just making sure you're up to date with discussions going on @ https://github.com/NixOS/nix/issues/969, https://github.com/NixOS/ofborg/issues/68, https://github.com/NixOS/rfcs/pull/171 (towards bottom of each thread) | 16:18:54 |
ris_ | short version: the fact that a FOD will quite blindly trust a cached outpath introduces a potential cache-poisoning attack for nixpkgs if someone is able to get their malicious outpath included (somehow) in cache.nixos.org | 16:22:17 |
ris_ | how is this relevant to ofborg? several of us are thinking that we should introduce a CI check to counter this - one that will perform a fresh download of "new" FODs introduced by a PR and check the resulting hash | 16:24:55 |
ris_ | i've developed a proof-of-concept of such a CI check in bash @ https://gist.github.com/risicle/3a521d040022c3e29faadcca8d8d4a20 | 16:26:05 |