!vxTmkuJzhGPsMdkAOc:transformierende-gesellschaft.org

NixOS Matrix Subsystem

130 Members
Coordination and discussion about the matrix subsystem in NixOS - https://nixos.wiki/wiki/Matrix63 Servers

Load older messages


SenderMessageTime
26 Mar 2025
@nickcao:nichi.coNick CaoAh I was expecting worse, that's some relief22:07:32
@emma:rory.gayEmma [it/its] i cant have my synapse going down when running multiple moderation bots for various communities says me running custom patches 22:08:11
@ma27:nicht-so.sexyma27merged the backport (cherry-picked the commit on 24.11 before to deploy my hs). I guess I can go to bed now, then :)22:11:06
@emilazy:matrix.orgemilyembargoed vulns don't work so well when you write a helpful commit message 😆22:12:14
@ralith:ralith.comRalithstill not on the channel?22:52:33
@sumner:nevarro.spaceSumner Evansdon't we have to wait for it to get built and such?22:53:33
@emilazy:matrix.orgemilyyes, it'll probably be a couple days (unless someone bumps the channels now)22:54:06
@emilazy:matrix.orgemily(which can be done for a sufficiently severe vuln but not clear to me if this DoS would qualify)22:54:30
@emilazy:matrix.orgemily people can get a patched Synapse from master though 22:54:49
@emma:rory.gayEmma [it/its]fwiw, the vuln breaks joining affected rooms22:55:13
@emma:rory.gayEmma [it/its]being in any affected room completely breaks federation for all rooms (the old nixos space is affected btw)22:55:57
@emma:rory.gayEmma [it/its]matrix:roomid/brXHJeAtqliwNGqHQx:lossy.network22:56:15
@emma:rory.gayEmma [it/its] * matrix:roomid/brXHJeAtqliwNGqHQx:lossy.network for those still in it 22:56:40
@dandellion:dodsorf.asDandellionhow are we chatting here then?22:56:46
@emma:rory.gayEmma [it/its] * to the best of my understanding 22:57:04
@emma:rory.gayEmma [it/its]the patch fixes federation and handling broken rooms fwiw22:57:49
@emma:rory.gayEmma [it/its]in particular, if either your server or any server youre joining via arent patched, the join will fail with a number out of range error22:58:43
@sumner:nevarro.spaceSumner Evansfrom what I understand, it's only outbound federation traffic that is affected. Confirming with the synapse devs22:59:32
@sumner:nevarro.spaceSumner EvansRedacted or Malformed Event23:00:24
@sumner:nevarro.spaceSumner EvansRedacted or Malformed Event23:03:46
@sumner:nevarro.spaceSumner Evans

from the maintainers:

Inbound traffic can cause outbound traffic to fail across all rooms

Personally, I think this is serious enough to bump the channels.

23:04:41
@sumner:nevarro.spaceSumner EvansRedacted or Malformed Event23:04:48
@f0x:pixie.townf0x
In reply to @sumner:nevarro.space
from what I understand, it's only outbound federation traffic that is affected. Confirming with the synapse devs. I think that if it's only possible for users on your own homeserver to cause this problem, then we don't have to bump the channel
https://github.com/element-hq/synapse/security/advisories/GHSA-v56r-hwv5-mxg6 states "a malicious server" so pretty sure this is exploitable over federation
23:05:21
@sumner:nevarro.spaceSumner EvansRedacted or Malformed Event23:05:45
@emilazy:matrix.orgemily I'd suggest asking for a bump in #infra:nixos.org. I have the technical permissions but I don't feel confident in using them unilaterally here 23:08:07
@emilazy:matrix.orgemily e.g., it would delay the security fixes currently building on staging-next-24.11 23:08:18
@emma:rory.gayEmma [it/its]no its caused by remote users in particular23:08:44
@emma:rory.gayEmma [it/its]
@ndzA8wy:mittens.jumpingcrab.com
@ZQqejO:mittens.jumpingcrab.com
@2cwBli9fJY:mittens.jumpingcrab.com
@hIuTKmCQjQ:mittens.jumpingcrab.com
@byJbUSec:optane.twilightparadox.com
@0dIr0JN:optane.twilightparadox.com
@q2PXjFrjI:optane.twilightparadox.com
@LfnjbI:optane.twilightparadox.com
@B8OWSs:optane.twilightparadox.com
@04zkgFxWPw:optane.twilightparadox.com
@eHvmaxWj:optane.twilightparadox.com
@yb4jUx:optane.twilightparadox.com
@VEloRu:vengeance.ignorelist.com
@BVbuVa:vengeance.ignorelist.com
@zYSwMcf25:vengeance.ignorelist.com
@Du6J9zkG:vengeance.ignorelist.com
@UkbIyOUyNL:vengeance.ignorelist.com
23:10:23
@emma:rory.gayEmma [it/its]here's the 3 homeservers that caused it23:10:33
27 Mar 2025
@hexa:lossy.networkhexanext time raise this earlier00:52:15

Show newer messages


Back to Room ListRoom Version: 4