Hydra | 374 Members | |
| 108 Servers |
| Sender | Message | Time |
|---|---|---|
| 17 Apr 2024 | ||
| 17:16:44 | ||
| 17:21:55 | ||
| 17:21:55 | ||
| 18 Apr 2024 | ||
I'm trying to determine the duration of a build for a single package. However, when parsing the JSON with start and stop times, curl -H 'Accept: application/json' <https://hydra.nixos.org/build/255062383> | jq '.starttime, .stoptime', it shows the same start and stop time while the build duration at https://hydra.nixos.org/build/255062383#tabs-summary shows it took 45 seconds. | 06:59:38 | |
| 19 Apr 2024 | ||
| the key part there is that the build was cached from another build. you'll need to grab the build info from that original build. | 15:54:32 | |
| 19:53:58 | ||
| 21 Apr 2024 | ||
In reply to @casey:hubns.netOoh I see, thanks | 07:51:39 | |
| 15:47:35 | ||
| 23:46:03 | ||
| 22 Apr 2024 | ||
| 08:33:54 | ||
| @room You Hydra might have a XSS vulnerability, please check if you need to update: https://github.com/NixOS/hydra/security/advisories/GHSA-2p75-6g9f-pqgx | 15:25:58 | |
| Hm, that's not really a helpful reproducer since the fix doesn't prevent the alert from happening? | 15:27:30 | |
| (or at least as far as I understand the fix, it shouldn't) | 15:28:17 | |
In reply to @linus:schreibt.jetztThat's a reasonable point :/ | 15:28:41 | |
| I can just drop it, it's not like the issue or anyone's vulnerability to it is debatable | 15:29:14 | |
In reply to @janne.hess:helsinki-systems.deDoes that in any way affect nixos users who use the distro-provided cache? | 16:46:55 | |
In reply to @janne.hess:helsinki-systems.de* Does that in any way affect nixos users who use the distro-provided cache? e.g. malicious cache? | 16:49:44 | |
In reply to @5m5z3q888q5prxkg:chat.lightnovel-dungeon.deIt doesn't affect the cache, it's only an issue when looking at html files from the Hydra web interface | 16:51:49 | |
| Merged the fixes in nixpkgs, doesn't seem like it'll hurt | 17:03:29 | |
| 24 Apr 2024 | ||
| 08:59:22 | ||
| I had wanted to use I guess there's a good reason why Hydra uses restricted mode and I better don't just patch | 15:57:34 | |
| there is probably a good reason, but back when i used hydra, i also patched that out for... reasons. | 16:01:28 | |
In reply to @os:matrix.flyingcircus.ioI think the main reason was that h.n.o. is effectively evaluating untrusted Nix code and the devs wanted to have certain restrictions for that (e.g. being unable to fetch stuff from random URLs). I've seen it a few times that people patched it out in their overlays. | 16:01:49 | |
| The last time I looked (~1year ago), the effects of restricted mode weren't that greatly documented, neither in Nix nor what they cause in Hydra. So I'm always a bit wary about it. | 16:03:21 | |
| not sure if much has changed about that... But tests/functional/restricted.sh from the nix repo has a few test cases that may give a rough idea of what it does | 16:08:05 | |
| * The last time I looked (~1year ago), the effects of restricted mode weren't that greatly documented, neither in Nix nor what they cause in Hydra. So I'm always a bit weary about it. | 16:08:15 | |
| 25 Apr 2024 | ||
| 03:33:20 | ||
| 14:43:29 | ||
| 21:11:58 | ||
| 23:19:14 | ||