!UNVBThoJtlIiVwiDjU:nixos.org

Staging

337 Members
Staging merges | Running staging cycles: https://github.com/NixOS/nixpkgs/pulls?q=is%3Apr+is%3Aopen+head%3Astaging-next+head%3Astaging-next-25.05 | Review Reports: https://malob.github.io/nix-review-tools-reports/111 Servers

Load older messages


SenderMessageTime
16 Jan 2026
@emilazy:matrix.orgemilyfor an integer overflow issue in a memory allocation function? no22:31:59
@emilazy:matrix.orgemilyanything letting untrusted parties pass huge values there is doomed already22:32:15
@emilazy:matrix.orgemilyhttps://matrix.to/#/!ZRgXNaHrdpGqwUnGnj:nixos.org/$_nFYUuPwe8sGpb2iv1WyH1FKc7L_JM6CRRCF9fhPlKg?via=nixos.org&via=matrix.org&via=nixos.dev22:32:30
@emilazy:matrix.orgemilyalso, this involves allocating an object whose size can't fit in ptrdiff_t?22:33:28
@emilazy:matrix.orgemilythat's UB in both LLVM and GCC22:33:34
@emilazy:matrix.orgemilyso a security bug in any code that allows user input to trigger it both before and after remediation22:33:56
@emilazy:matrix.orgemilyor well, maybe the alignment part makes it subtler here22:34:40
@emilazy:matrix.orgemilygiving untrusted input control over alignment is pretty wild already though. unless I'm missing something this feels like nothing22:35:14
@fabianhjr:matrix.orgFabián HerediaThere are two, that is the first one and the second one is stack leak to a dns resolver22:37:35
@emilazy:matrix.orgemilyah ok I missed that one22:37:49
@emilazy:matrix.orgemilythat one is also nothing :)22:38:28
@fabianhjr:matrix.orgFabián HerediaThough I would say I don't think those are critical enough to require and inmediate rebuild22:38:31
@ma27:nicht-so.sexyma27fwiw no objections from my side on targeting staging instead of -next. Can retarget the PR tomorrow, I'll go to sleep now.22:39:24
@k900:0upti.meK900 The second one is nothing 22:39:41
@k900:0upti.meK900The first one I may have misread22:39:47
@k900:0upti.meK900It's almost 2AM22:39:51
@emilazy:matrix.orgemilyyeah heap overflow in a case that is maybe compiler UB regardless and I'm any case involves giving attackers crazy levels of control of memory allocation, plus uncommon calls leaking small amounts of stack to DNS server = I sleep22:40:41
@emilazy:matrix.orgemilyI'd expect -next contains juicier fixes already22:41:40
17 Jan 2026
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)There's a slight include messup with cppnix 2.33 and glibc 2.42. I should send that to staging-next now? https://github.com/NixOS/nix/pull/1501118:45:42
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)Or just master and the regular merge will do the thing?18:46:54
@k900:0upti.meK900master is fine18:48:17
@emilazy:matrix.orgemilystaging-nixos, no?18:53:29
@emilazy:matrix.orgemilygiven the test rebuilds?18:53:37
@emilazy:matrix.orgemilyor is it not default yet?18:53:43
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)Not the default18:54:59
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)Going to also grab aarch64-darwin patches to fix darwin19:00:11
@xokdvium:matrix.orgSergei Zimmerman (xokdvium)* Going to also grab aarch64-darwin patches to fix darwin sandbox shenanigans19:00:25
18 Jan 2026
@reckenrode:matrix.orgRandy Eckenrodepython3Packages.setproctitle is failing to build on 25.11. It happened to build on unstable, but that may have been a happy accident, so I’m going to fix the failure on staging first. When I do the backport, should it still target staging-25.11, or can it be retargeted to release-25.11 since it’s not technically causing rebuilds (but it will cause a bunch of builds)?19:53:52
@leona:leona.isleonaRedacted or Malformed Event19:54:15
@leona:leona.isleonaRedacted or Malformed Event19:54:22

There are no newer messages yet.


Back to Room ListRoom Version: 6