| 13 Dec 2024 |
Christian Theune | but yeah | 08:08:39 |
vcunat | Though hydra.nixos.org is now blocked by loading jobs from DB. Probably the steps that check what's in S3 already. (it's overseas unfortunately so higher latency) | 08:08:54 |
Christian Theune | yeah i've read that. that part of the code/architecture i haven't looked at before and it's two steps further down the road on our map. | 08:10:14 |
Christian Theune | (our s3 is local and we have a much lower number of jobs anyway) | 08:10:40 |
Christian Theune | but yeah, happy to help in general, but need to be careful with my commitments ... | 08:11:01 |
vcunat | Sure. I appreciate any kind of progress 🙂 | 08:11:52 |
Christian Theune | the martian is always right. one problem at a time. | 08:13:57 |
7c6f434c | If the builder sends just the hash to sign, this is not that far from having the signing key on the builder? | 08:15:32 |
7c6f434c | (A key that has signed something weird will probably be rotated even if it was not disclosed) | 08:16:09 |
vcunat | Corrupting builds chosen by someone else feels somewhat safer than ability to steal the key. | 08:18:49 |
7c6f434c | Ah right the store path still comes from evaluation on master | 08:22:10 |
vcunat | Though I'm not sure if the builder could inject arbitrary runtime dependencies. | 08:22:48 |
7c6f434c | Well, just forcing the deps to be in the store doesn't sound that much more than just including the payload in all he binaries | 08:23:53 |
Christian Theune | yeah, that's the weakest point imho, so theorizing about any higher layer injections is a bit moot. | 08:29:04 |
| 16 Dec 2024 |
| @ole6edev:matrix.org left the room. | 02:55:03 |
| 18 Dec 2024 |
| @dmiskovic:matrix.org joined the room. | 19:37:43 |
| 21 Dec 2024 |
| @stablejoy:matrix.org left the room. | 05:08:22 |
| @dmiskovic:matrix.org left the room. | 05:14:06 |
| @stablejoy:matrix.org joined the room. | 06:43:00 |
| Dimitar joined the room. | 19:44:49 |
| 22 Dec 2024 |
| @stablejoy:matrix.org left the room. | 13:25:34 |
| allrealmsoflife joined the room. | 15:55:04 |
| 26 Dec 2024 |
| elikoga changed their display name from elikoga to elikoga (@38c3 📞448{0,1}. | 15:21:46 |
| elikoga changed their display name from elikoga (@38c3 📞448{0,1} to elikoga (@38c3 📞448{0,1}). | 15:26:01 |
| elikoga changed their display name from elikoga (@38c3 📞448{0,1}) to elikoga (@38c3 📞488{0,1}). | 15:26:44 |
| phaer changed their display name from phaer to phaer (8650 at 38c3). | 17:41:54 |
| stigo changed their display name from stigo to stigo 5716. | 22:15:41 |
| 27 Dec 2024 |
| raitobezarius changed their display name from raitobezarius to raitobezarius (DECT: 3538 / EPVPN 2681). | 07:33:17 |
| tilpner changed their display name from tilpner to tilpner (38c3 3209). | 09:41:14 |
| Dimitar set a profile picture. | 11:41:20 |