!ZRgXNaHrdpGqwUnGnj:nixos.org

NixOS Security Triage

761 Members
Coordination and triage of security issues in nixpkgs233 Servers

Load older messages


SenderMessageTime
20 Jul 2021
@qyliss:fairydust.spaceAlyssa Rossthey're in today's stable releases16:01:00
@janne.hess:helsinki-systems.dedas_jah great16:01:06
@qyliss:fairydust.spaceAlyssa Rossso it's just a stable kernel update as usual16:01:14
@qyliss:fairydust.spaceAlyssa Rossjanne.hess: https://github.com/NixOS/nixpkgs/pull/13080716:05:33
@hexa:lossy.networkhexait's usually not worth looking into kernel vulns, because we bump them often enough and they will be released sooner or later16:09:43
@qyliss:fairydust.spaceAlyssa Rossthis seems to be a particularly serious one16:10:09
@hexa:lossy.networkhexawhich is why it was coordinated and promtly released on a schedule16:10:27
@hexa:lossy.networkhexa * which is why it was coordinated and promptly released on a schedule16:10:35
@andreas.schraegle:helsinki-systems.deajs124
In reply to @hexa:lossy.network
it's usually not worth looking into kernel vulns, because we bump them often enough and they will be released sooner or later
also, you need to reboot to apply them. our reboot schedule for a bunch of systems is every half year for the release upgrade.
16:12:05
@hexa:lossy.networkhexayeah rebooting is messy :D16:12:28
@philipp:xndr.dephilippBut the absolutely best feeling is to reboot a compelx system and it just coming back up without any issues.16:13:18
@sumner:sumnerevans.comsumner left the room.21:42:19
21 Jul 2021
@genevino:matrix.orgArminio Genevino joined the room.20:25:46
@noch3:matrix.orgElliot joined the room.20:25:46
@genevino:matrix.orgArminio Genevinoo/20:25:50
@noch3:matrix.orgElliotIs there a detailed writeup of how NixOS stacks up against other distros wrt to security? 20:26:10
@nixinator:nixos.devnixinator
In reply to @noch3:matrix.org
Is there a detailed writeup of how NixOS stacks up against other distros wrt to security?
i can't think of one of the top of my braincase, but do you have a specific questions?
21:20:27
@noch3:matrix.orgElliot set a profile picture.21:45:49
22 Jul 2021
@js:ukvly.orgjuliansthey! the steps to verify the Nix download as they are documented on the homepage seem to be broken: https://nixos.org/download.html#nix-verify-installation08:35:56
@js:ukvly.orgjulianst

specifically:

gpg2 --recv-keys B541D55301270E0BCF15CA5D8170B4726D7198DE
gpg: keyserver receive failed: No name
08:36:05
@js:ukvly.orgjulianst I can download edolstra's key manually, but I assume the --recv-keys should also work given that it's what's people try first 08:36:48
@andi:kack.itandi-
In reply to @js:ukvly.org
I can download edolstra's key manually, but I assume the --recv-keys should also work given that it's what's people try first
Try now. I think the default keyserver that is used in NixOS (or upstream GnuPG by now?) has changed and it didn't have that key.
08:43:26
@js:ukvly.orgjulianstimage.png
Download image.png
08:49:56
@js:ukvly.orgjulianstsuper weird08:50:41
@js:ukvly.orgjulianstthis is from my colleague. I still get the error above. boy, this gpg infrastructure is horrible :)08:51:23
@js:ukvly.orgjulianstlet me try from another box...08:52:06
@js:ukvly.orgjulianst

my other box says:

❯  gpg2 --recv-keys B541D55301270E0BCF15CA5D8170B4726D7198DE
gpg: keyserver receive failed: Server indicated a failure

08:53:58
@js:ukvly.orgjulianst🤷08:54:13
@js:ukvly.orgjulianstI guess the best way is to just change the description to download the key from nixos.org 08:55:14
@js:ukvly.orgjulianstah, someone is already on it: https://github.com/NixOS/nixos-homepage/pull/72408:57:56

Show newer messages


Back to Room ListRoom Version: 6