andi- changed the topic of #nixos-security to: Vulnerability Roundup Issues: https://github.com/NixOS/nixpkgs/issues?utf8=%E2%9C%93&q=is%3Aissue+is%3Aopen+Vulnerability+roundup + https://broken.sh | Currently supported releases: unstable (master), 20.09, 20.03 (until 27th of November)
eyJhb has quit [Ping timeout: 246 seconds]
eyJhb has joined #nixos-security
eyJhb has joined #nixos-security
eyJhb has quit [Changing host]
eyJhbV2 has joined #nixos-security
eyJhb has quit [Ping timeout: 240 seconds]
eyJhbV2 is now known as eyJhb
eyJhb has joined #nixos-security
eyJhb has quit [Changing host]
supersandro2000 has quit [Disconnected by services]
supersandro2000 has joined #nixos-security
rajivr has joined #nixos-security
Raito_Bezarius has quit [Remote host closed the connection]
Raito_Bezarius has joined #nixos-security
<hexa-> no takers? :D
<{^_^}> #115310 (by mweinelt, 2 weeks ago, open): grub: 2.0.4 -> 2.0.6-rc1
<cole-h> sad how a part of the critical boot chain is unmaintained...
<hexa-> yep
<cole-h> (well, unmaintained in nixpkgs)
<hexa-> at least no pseudomaintainers in that package :)
<hexa-> I've been rolling with that since 10 days on my desktop
<cole-h> I'd say merge it tbh, considering it seems to be relatively tested
<hexa-> but no secure boot here
<hexa-> > The error message about missing "share/locale" is still visible when the bootloader gets installed. I have the impression that --enable-nls was already implied before it got set explicitely, so the new commit probably has no effect at all.
<{^_^}> error: syntax error, unexpected ',', expecting ')', at (string):492:190
<hexa-> ther e is this review message
<cole-h> well, it'll hit unstable and then you'll get more (unwitting) volunteers :)
<hexa-> lmao :)
<cole-h> my verdict is: merge it when you're happy with it
<hexa-> fair enough
<cole-h> but I'm also not a part of the security team :P
<gchristensen> are you happy about with it hexa-?
<hexa-> gchristensen: I'm not happy about that nls stuff
<hexa-> I'm dropping the latest commit as it doesn't seem to have an affect according to the reviewer
<hexa-> fwiw: I couldn't see the warning anymore
<hexa-> but I'm by no means a grub expert :3
<gchristensen> I'll press the button and take the heat
<cole-h> well, if you couldn't see it with the latest, chances are they messed something up locally?
<hexa-> *shrug*
<hexa-> I don't expect there to be much heat
<hexa-> so let's go ahead
<gchristensen> 1s
<cole-h> alternatively
<cole-h> we could check the sources to validate the claim that nls is enabled implicitly
<cole-h> :P
<hexa-> yep, I'm doing that rn
<hexa-> I kinda expected nls to have been enabled, since gettext was already in the inputs
<hexa-> include/grub/i18n.h
<hexa-> 25:/* NLS can be disabled through the configure --disable-nls option. */
<hexa-> the only reference I could quickly find
<gchristensen> I'm deploying to AWS as a check
<cole-h> gchristensen++
<{^_^}> gchristensen's karma got increased to 0b110110111
<gchristensen> those machines are particularly annoying to rescue
<hexa-> nice
<cole-h> yeah, looks like nls is enabled by default
<cole-h> so I'd drop that commit
<hexa-> do you have a reference?
<hexa-> fwiw: result/share/locale is missing either way
<hexa-> commit removed
<cole-h> sorry, maybe not by default, but for us it's enabled by default :p
<hexa-> *shrug* :)
<cole-h> `nix-build -A grub2 --check 2>| rg -i nls` on master shows `checking whether NLS is requested...` and `checking whether to use NLS...` as yes
<gchristensen> someone ping me when it is green?
<cole-h> gchristensen: any chance you could see if that locale error is present prior to this PR as well?
<gchristensen> uhm
<cole-h> (if not, no sweat)
<hexa-> there is no result/share/locale before that either
<cole-h> maybe it's because LOCALE / LANG isn't set in the ssh connection?
<cole-h> idk; I guess if it doesn't affect functionality it isn't *too* important...
<hexa-> same
<hexa-> guess we'll let it sit for a while before backporting it
<cole-h> warning is probably from util/grub-install-common.c @ 660
<hexa-> uh, so … do we need to mkdir $out/share/locale? :o
<hexa-> uh, but yeah, it seems to read LC_MESSAGES ig?
<hexa-> so I'm not exactly sure what nls get us at this point
<gchristensen> so I am trying to do a test deploy but wouldn't you know it I'm out of disk space
<gchristensen> so ... waiting for DC
<cole-h> lol
<hexa-> lol
<gchristensen> GC*
<gchristensen> I'm still just deleting .lock files
<gchristensen> idk maybe I should gc more than, uh, literally no idea
<cole-h> hehe
<cole-h> reading ABOUT-NLS, it seems like it relies on LANG. so if the environment running `grub-install` doesn't have LANG set, it'll whine about that?
<cole-h> maybe?
<gchristensen> it is so silly that nix-collect-garbage onl ytakes bytes deleting '/nix/store/x27wqxpy0d41mxgl6yvsg5n9h9c81mhr-linux-4.19.116.tar.xz'
<gchristensen> deleted or invalidated more than 40000000 bytes; stopping
supersandro2000 has quit [Quit: The Lounge - https://thelounge.chat]
<gchristensen> hexa-, cole-h I'm going to merge
<gchristensen> sgty?
<cole-h> SGTM.
<cole-h> gchristensen++
<{^_^}> gchristensen's karma got increased to 440
<gchristensen> g'night
supersandro2000 has joined #nixos-security
<cole-h> o/
cjb has quit []
cole-h has quit [Ping timeout: 246 seconds]
FRidh has joined #nixos-security
Raito_Bezarius has quit [Ping timeout: 260 seconds]
FRidh has quit [Quit: Konversation terminated!]
adisbladis has quit [Remote host closed the connection]
Yakulu[m] has quit [Ping timeout: 246 seconds]
cemguresci[m] has quit [Ping timeout: 246 seconds]
colemickens has quit [Ping timeout: 246 seconds]
supersandro2000 has quit [Ping timeout: 245 seconds]
Ox4A6F has quit [Ping timeout: 240 seconds]
supersandro2000 has joined #nixos-security
adisbladis has joined #nixos-security
aanderse has quit [Ping timeout: 240 seconds]
JJJollyjim has quit [Ping timeout: 240 seconds]
thefloweringash has quit [Ping timeout: 258 seconds]
flx has quit [Remote host closed the connection]
bbigras has quit [Ping timeout: 240 seconds]
JrgKtemeier[m] has quit [Ping timeout: 244 seconds]
danielrf[m] has quit [Ping timeout: 244 seconds]
immae has quit [Ping timeout: 240 seconds]
julianst[m] has quit [Ping timeout: 240 seconds]
nh2[m] has quit [Ping timeout: 240 seconds]
jdnixx-M has quit [Ping timeout: 268 seconds]
SushiDude[m] has quit [Ping timeout: 244 seconds]
Guest57260 has quit [Ping timeout: 244 seconds]
kalbasit[m] has quit [Ping timeout: 244 seconds]
cwprobablydead[m has quit [Ping timeout: 268 seconds]
flx has joined #nixos-security
Yakulu[m] has joined #nixos-security
colemickens has joined #nixos-security
jdnixx-M has joined #nixos-security
cemguresci[m] has joined #nixos-security
JJJollyjim has joined #nixos-security
thefloweringash has joined #nixos-security
aanderse has joined #nixos-security
JrgKtemeier[m] has joined #nixos-security
Ox4A6F has joined #nixos-security
nh2[m] has joined #nixos-security
danielrf[m] has joined #nixos-security
julianst[m] has joined #nixos-security
Guest57260 has joined #nixos-security
kalbasit[m] has joined #nixos-security
SushiDude[m] has joined #nixos-security
bbigras has joined #nixos-security
cwprobablydead[m has joined #nixos-security
immae has joined #nixos-security
cole-h has joined #nixos-security
justanotheruser has joined #nixos-security
justan0theruser has quit [Ping timeout: 260 seconds]
rajivr has quit [Quit: Connection closed for inactivity]
cole-h has quit [Quit: Goodbye]
cole-h has joined #nixos-security
tokudan has quit [Remote host closed the connection]
tokudan has joined #nixos-security
Raito_Bezarius has joined #nixos-security