andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
rajivr has joined #nixos-security
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
ris has quit [Ping timeout: 240 seconds]
tilpner_ has joined #nixos-security
cole-h has quit [Ping timeout: 256 seconds]
tilpner has quit [Ping timeout: 240 seconds]
tilpner_ is now known as tilpner
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
maljub01 has quit [Quit: maljub01]
maljub01 has joined #nixos-security
KREYREEN is now known as kreystorm
kreystorm is now known as KREYREEN
cole-h has joined #nixos-security
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
supersandro2000 has joined #nixos-security
kalbasit has quit [Ping timeout: 256 seconds]
FRidh has joined #nixos-security
justan0theruser has joined #nixos-security
justanotheruser has quit [Ping timeout: 272 seconds]
KREYREEN has quit [Remote host closed the connection]
KREYREEN has joined #nixos-security
cole-h has quit [Ping timeout: 240 seconds]
justan0theruser has quit [Ping timeout: 264 seconds]
lassulus has quit [Quit: WeeChat 2.9]
lassulus has joined #nixos-security
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
FRidh has quit [Quit: Konversation terminated!]
justanotheruser has joined #nixos-security
FRidh has joined #nixos-security
<hexa-> taking care of openssl
<hexa-> __red__: please look into #103552 again
<{^_^}> https://github.com/NixOS/nixpkgs/pull/103552 (by redvers, 3 weeks ago, open): xorg.xorgserver: 1.20.8 -> 1.20.9 [20.09]
kalbasit has joined #nixos-security
<hexa-> #106362
<{^_^}> https://github.com/NixOS/nixpkgs/pull/106362 (by mweinelt, 3 minutes ago, open): openssl: 1.1.1h -> 1.1.1i
cole-h has joined #nixos-security
FRidh has quit [Quit: Konversation terminated!]
lassulus has quit [Remote host closed the connection]
lassulus has joined #nixos-security
rajivr has quit [Quit: Connection closed for inactivity]
ris has joined #nixos-security
red[evilred] has joined #nixos-security
<red[evilred]> hexa- (IRC): will do - one moment caller...
<red[evilred]> Okay - hexa- (IRC) - I thought I was waiting on you. What am I missing?
<hexa-> > Starting nix-review process... brb
<{^_^}> error: syntax error, unexpected ELLIPSIS, expecting ')', at (string):443:28
<hexa-> how is that waiting on me?
<hexa-> also I'm not an xorg user, so I can't really test that change
<hexa-> you should be the one to request reviewers if nothing happens
<hexa-> not start a bunch of pull requests and let them go stale :(
<red[evilred]> Because the last thing I saw was a request for a change which I implemented
<red[evilred]> What we have here is me not being fully aware of what your expectations are
<red[evilred]> We can take this to PM if you want, but I'm pretty bothered by that last statement of yours
<hexa-> Are we both talking about https://github.com/NixOS/nixpkgs/pull/103552?
<{^_^}> #103552 (by redvers, 3 weeks ago, open): xorg.xorgserver: 1.20.8 -> 1.20.9 [20.09]
<red[evilred]> yes, but it's this:
<red[evilred]> "not start a bunch of pull requests and let them go stale :(" on irc that bothered me
<red[evilred]> if I'm missing something I need to be doing, please tell me - and I'll try to learn first time
<red[evilred]> your comment implies (unintentionally maybe) that I'm just dumping into the queue without caring about the quality of the work that I'm doing.
<hexa-> Let me address this when I'm back on my pc
<red[evilred]> no worries.
<hexa-> <red[evilred]> Because the last thing I saw was a request for a change which I implemented
<red[evilred]> How many people should a typical PR involve fort reviewsa?
<red[evilred]> so I can get started on this and make sure any others I have also have that done
<red[evilred]> because I want to do the right thing, I just plainly missed your expectation here.
<hexa-> so, back at my pc.
<red[evilred]> I guess the original author of the patch I cherry-picked?
<hexa-> the xorg backport is two weeks old, you say you were going to do a nixpkgs-review pr and "brb", nothing further happened
<hexa-> yes, or the reviewers of that pull request
<hexa-> also I feel the cassandra pull requests are going nowhere, and as I stated I'm not familiar with cassandra
<hexa-> sure, that might not be your fault per se
<hexa-> heh fault is a shitty topic in open source, and I don't mean "fault", english is not my first language
<red[evilred]> I reached out to the maintainer and they said they didn't use it anymore
<red[evilred]> so didn't have any way to help
<red[evilred]> Let's just look forward - I just want to help as best I can
<hexa-> for cassandra? check who else did commits related to cassandra recently
<hexa-> sure, let's do that
<hexa-> sorry for possible snark
<red[evilred]> and since I've ramped up working on packages that aren't mine - I'm hitting issues like this that I don't know how to address
<red[evilred]> before, I was excluisively working on modules that I wrote / maintaines
<red[evilred]> maintained
<red[evilred]> so I'm hitting new cultural issues
<red[evilred]> no worries <3
<hexa-> I'll request some reviewers
<red[evilred]> it happens
<red[evilred]> Thanks -
<red[evilred]> how useful is the "suggested reviewers" section?
<hexa-> depends
<cole-h> Basically just suggests people who touched the files you touched last
<red[evilred]> what is the etiquite for requesting - do I just add them?
<red[evilred]> or do I try and contact them first?
<hexa-> I'd rather log at `git log` for a certain file and see who did actual changes to the package/module
<cole-h> ^
<hexa-> just do imo
<red[evilred]> okay
<hexa-> don't be spammy with requests, should be fine as long as there is a relationship
<red[evilred]> So, since I know that the previous maintainer is now disengaged - should I try and find a new maintainer?
<hexa-> especially when there is no maintainer, like in this case
<hexa-> uh no
<red[evilred]> it seems a waste of knowledge to just throw away that fact that I know that the maintainer is no longer current
<hexa-> maintainers should probably step up themselves, you could make users aware of the lack of maintainership though.
<red[evilred]> should they raise a PR changing the maintainer field to [] ?
<red[evilred]> or should I encorage them to do so?
<hexa-> pretty sure cransom did that already
<hexa-> see f6e974e701fba2de89e24637d6478aee69de0546
<red[evilred]> ah yes - in master - now I see it
<red[evilred]> I really should be writing down each of these things as I come across them and put them in some kind of FAQ
<red[evilred]> being a new developer can sometimes feel like a thousand paper-cuts
<hexa-> yep
<red[evilred]> and I'm sure you guys get sick and tired of asking the same questions
<red[evilred]> or having to reject PRs for the exact same thing every single time
supersandro2000 has quit [Read error: Connection reset by peer]
<hexa-> re #103552, please pick #105631, then try to find a test that uses xorg.xorgserver and run it, then look up the reviewers in 105631.
<{^_^}> https://github.com/NixOS/nixpkgs/pull/103552 (by redvers, 3 weeks ago, open): xorg.xorgserver: 1.20.8 -> 1.20.9 [20.09]
<{^_^}> https://github.com/NixOS/nixpkgs/pull/105631 (by TredwellGit, 6 days ago, merged): xorg.xorgserver: 1.20.9 -> 1.20.10 (CVE-2020-14360 CVE-2020-25712)
<red[evilred]> the first PR I raised I raised against the master branch on my fork
<hexa-> we are learning :p
supersandro2000 has joined #nixos-security
<red[evilred]> that's how new I was
<hexa-> hehe
<red[evilred]> Okay - I'm going to paste that into the ticket so I don't lose it - brb
<red[evilred]> hexa- (IRC): I shouldn't squash these right?
<red[evilred]> since they are two cherry-picked pacthes
<red[evilred]> patches
supersandro2000 has quit [Ping timeout: 265 seconds]
<hexa-> cherry-picks should always keep their references from where they originated
<hexa-> hence no cherry-picking please
<hexa-> they are self-contained changes
<red[evilred]> umm
<red[evilred]> so is what I've done what you expected?
supersandro2000 has joined #nixos-security
<hexa-> sorry, currently my firefox is broken
<red[evilred]> no worries
<red[evilred]> looks like this:
<red[evilred]> so still has that master ref smell
<hexa-> lgtm from the image
<hexa-> red[evilred]: there was a gnome test I ran in the master pull request
<red[evilred]> cool -
<hexa-> please look it up and run it on 20.09 as well
<red[evilred]> I'm running a nixpkgs-review which is going to eat all the CPUs
<hexa-> not sure how big a rebuild that is going to be
<hexa-> if this is aiming for staging-20.09 you probably shouldn't
<red[evilred]> how do I "please look it up and run it on 20.09 as well"
<hexa-> In #105631 i requested ofborg to run a test
<{^_^}> https://github.com/NixOS/nixpkgs/pull/105631 (by TredwellGit, 6 days ago, merged): xorg.xorgserver: 1.20.9 -> 1.20.10 (CVE-2020-14360 CVE-2020-25712)
<red[evilred]> Okay - kick that off on my PR?
<red[evilred]> or on something else
<red[evilred]> Okay - done
<hexa-> well, it's using xorg, which is somewhat related. so yeah, on your pr :)
<red[evilred]> I went to make sure that you hadn't merged it into a bunch of otehr changes to test a bunch at once
star_cloud has quit [Remote host closed the connection]
star_cloud has joined #nixos-security
star_cloud has quit [Excess Flood]
star_cloud has joined #nixos-security
<hexa-> red[evilred]: request reviewers :)
<red[evilred]> will do
<red[evilred]> looing for where the tests live
<red[evilred]> I'm in lib/tests/modules - doesn't seem like the right place
<red[evilred]> found them
<red[evilred]> nixos/tests
Raito_Bezarius has quit [Ping timeout: 272 seconds]
<red[evilred]> interesting that there are no maintainers in xorg at all
<red[evilred]> but there is a maintainer group for gnome
<red[evilred]> which is xorg ajacent? ;-)
Raito_Bezarius has joined #nixos-security
<red[evilred]> Okay - invited gnome.members :-P
KREYREEN has quit [Remote host closed the connection]
KREYREEN has joined #nixos-security