| 22 Apr 2024 |
@linus:schreibt.jetzt | Hm, that's not really a helpful reproducer since the fix doesn't prevent the alert from happening? | 15:27:30 |
@linus:schreibt.jetzt | (or at least as far as I understand the fix, it shouldn't) | 15:28:17 |
@janne.hess:helsinki-systems.de | In reply to @linus:schreibt.jetzt Hm, that's not really a helpful reproducer since the fix doesn't prevent the alert from happening? That's a reasonable point :/ | 15:28:41 |
@janne.hess:helsinki-systems.de | I can just drop it, it's not like the issue or anyone's vulnerability to it is debatable | 15:29:14 |
@5m5z3q888q5prxkg:chat.lightnovel-dungeon.de | In reply to @janne.hess:helsinki-systems.de @room You Hydra might have a XSS vulnerability, please check if you need to update: https://github.com/NixOS/hydra/security/advisories/GHSA-2p75-6g9f-pqgx Does that in any way affect nixos users who use the distro-provided cache? | 16:46:55 |
@5m5z3q888q5prxkg:chat.lightnovel-dungeon.de | In reply to @janne.hess:helsinki-systems.de @room You Hydra might have a XSS vulnerability, please check if you need to update: https://github.com/NixOS/hydra/security/advisories/GHSA-2p75-6g9f-pqgx * Does that in any way affect nixos users who use the distro-provided cache? e.g. malicious cache? | 16:49:44 |
@janne.hess:helsinki-systems.de | In reply to @5m5z3q888q5prxkg:chat.lightnovel-dungeon.de Does that in any way affect nixos users who use the distro-provided cache? e.g. malicious cache? It doesn't affect the cache, it's only an issue when looking at html files from the Hydra web interface | 16:51:49 |
@rick:matrix.ciphernetics.nl | Merged the fixes in nixpkgs, doesn't seem like it'll hurt | 17:03:29 |
| 24 Apr 2024 |
| @stablejoy:matrix.org changed their profile picture. | 08:59:22 |
osnyx (he/him) | I had wanted to use replaceRuntimeDependencies in a system config to hotfix the latest glibc CVE, but unfortunately Hydra fails to evaluate it due to
error: access to absolute path '/nix/store/anlf335xlh41yjhm114swi87406mq5pw-glibc-2.38-44' is forbidden in restricted mode.
I guess there's a good reason why Hydra uses restricted mode and I better don't just patch evalSettings.restrictEval = false;?
| 15:57:34 |
@casey:hubns.net | there is probably a good reason, but back when i used hydra, i also patched that out for... reasons. | 16:01:28 |
ma27 | In reply to @os:matrix.flyingcircus.io
I had wanted to use replaceRuntimeDependencies in a system config to hotfix the latest glibc CVE, but unfortunately Hydra fails to evaluate it due to
error: access to absolute path '/nix/store/anlf335xlh41yjhm114swi87406mq5pw-glibc-2.38-44' is forbidden in restricted mode.
I guess there's a good reason why Hydra uses restricted mode and I better don't just patch evalSettings.restrictEval = false;?
I think the main reason was that h.n.o. is effectively evaluating untrusted Nix code and the devs wanted to have certain restrictions for that (e.g. being unable to fetch stuff from random URLs). I've seen it a few times that people patched it out in their overlays. | 16:01:49 |
osnyx (he/him) | The last time I looked (~1year ago), the effects of restricted mode weren't that greatly documented, neither in Nix nor what they cause in Hydra. So I'm always a bit wary about it. | 16:03:21 |
ma27 | not sure if much has changed about that...
But tests/functional/restricted.sh from the nix repo has a few test cases that may give a rough idea of what it does | 16:08:05 |
osnyx (he/him) | * The last time I looked (~1year ago), the effects of restricted mode weren't that greatly documented, neither in Nix nor what they cause in Hydra. So I'm always a bit weary about it. | 16:08:15 |
| 25 Apr 2024 |
| @me:indeednotjames.com left the room. | 03:33:20 |
| @delroth:delroth.net left the room. | 14:43:29 |
| NixOS Moderation Bot banned @jonringer:matrix.org (Banned until 2024/06/10 after deliberation of the Moderation team). | 21:11:58 |
| David Mell (zraexy) joined the room. | 23:19:14 |
| David Mell (zraexy) changed their display name from David Mell to David Mell (zraexy). | 23:51:58 |
| 26 Apr 2024 |
| @stablejoy:matrix.org changed their profile picture. | 14:03:43 |
| @patka_123:matrix.org left the room. | 19:33:34 |
| 29 Apr 2024 |
| stigo left the room. | 12:03:45 |
| NixOS Moderation Botchanged room power levels. | 15:29:48 |
| 30 Apr 2024 |
| ondt joined the room. | 22:21:41 |
| 1 May 2024 |
| NixOS Moderation Botchanged room power levels. | 15:06:26 |
| 3 May 2024 |
John Ericson | https://hydra.ngi0.nixos.org/build/3992#tabs-summary I was trying to figure out why this stuff is stuck in queue | 18:03:13 |
John Ericson | anyone know where to look? | 18:03:16 |
| 4 May 2024 |
| @theophane:hufschmitt.net left the room. | 15:55:58 |
| 6 May 2024 |
| tracteur joined the room. | 21:58:35 |