!vxTmkuJzhGPsMdkAOc:transformierende-gesellschaft.org

NixOS Matrix Subsystem

128 Members
Coordination and discussion about the matrix subsystem in NixOS - https://nixos.wiki/wiki/Matrix65 Servers

Load older messages


SenderMessageTime
26 Mar 2025
@sumner:nevarro.spaceSumner Evanshttps://github.com/element-hq/synapse/releases/tag/v1.127.1 was just released which contains a critical security fix for CVE-2025-30355. I updated https://github.com/NixOS/nixpkgs/pull/393086 to bump to the patched version. Can I get some eyes on it and a committer to merge?21:44:12
@ma27:nicht-so.sexyma27deploying it rn.21:51:58
@ma27:nicht-so.sexyma27Given the apparent severity I'm willing to make an exception and merge right away.21:52:16
@emilazy:matrix.orgemilyperhaps a good idea to get someone to kick the channel?21:53:04
@sumner:nevarro.spaceSumner EvansI think that's the right call. I've been running 1.127.0 for a few days and it's been fine, and the diff to 1.127.1 is not too large.21:53:51
@sumner:nevarro.spaceSumner Evansfrom what I understand, this vulnerability is why matrix.org has been having issues today21:54:08
@emilazy:matrix.orgemilywhat do we do for backports?21:54:19
@max:klandest.inmax invited @willi:butz.cloudWilli Butz.21:54:25
@ma27:nicht-so.sexyma27we backport all synapse updates anyways21:54:28
@willi:butz.cloudWilli Butz joined the room.21:54:28
@ma27:nicht-so.sexyma27so same procedure as every bump imho21:54:42
@emilazy:matrix.orgemilythe diff looks like DoS at a glance, maybe not channel-kicking levels of severe (though of course that could be misleading)21:55:26
@willi:matrix.butz.cloud@willi:matrix.butz.cloud left the room.21:56:08
@willi:butz.cloudWilli Butzty :)21:56:19
@emilazy:matrix.orgemilyoh, https://github.com/element-hq/synapse/commit/2277df2a1eb685f85040ef98fa21d41aa4cdd389 explicitly says DoS21:56:24
@emma:rory.gayEmma [it/its] joined the room.21:58:28
@sumner:nevarro.spaceSumner Evansanyone know NickCao's mxid? looks like he went ahead and merged. We should get him into this room if he's on Matrix21:58:32
@emma:rory.gayEmma [it/its]👋21:59:13
@sumner:nevarro.spaceSumner EvansRedacted or Malformed Event21:59:27
@ma27:nicht-so.sexyma27there's none in the maintainer entry. will leave a message in the PR.21:59:27
@emilazy:matrix.orgemilyhaven't seen him on Matrix21:59:30
@emilazy:matrix.orgemilyironically :)21:59:41
@ma27:nicht-so.sexyma27would be kinda funny if the person who regularly merges synapse PRs doesn't use it :D21:59:53
@sumner:nevarro.spaceSumner EvansI assume that he must have one because he said that he tested on his homeserver21:59:55
@emilazy:matrix.orgemilyright, I just mean in the NixOS space22:00:04
@emilazy:matrix.orgemily @nickcao:nichi.co is in #dev:nixos.org 22:00:21
@emilazy:matrix.orgemilyso presumably that22:00:27
@sumner:nevarro.spaceSumner Evansthat matches the website in his GitHub profile, so that is probably it22:01:05
@ma27:nicht-so.sexyma27 invited @nickcao:nichi.coNick Cao.22:01:29
@nickcao:nichi.coNick Cao joined the room.22:02:21

Show newer messages


Back to Room ListRoom Version: 4