Nixpkgs: Please update to systemd-232!

Created on 4 Nov 2016  路  11Comments  路  Source: NixOS/nixpkgs

Changelog

Systemd-232 brings a whole heap of features which can fix many security-related issues, such as #14645 #11908

enhancement blocker mass-rebuild security nixos changelog community feedback documentation package (update)

Most helpful comment

I updated nixos patches to v232, built it, and running some tests locally now.

All 11 comments

DynamicUser option is interesting. That way we do not have to allocate users for services without persistent data.

@grahamc security, update, possibly mass-rebuild

@spacekitteh is there a security issue the update does address beside hardening?

I updated nixos patches to v232, built it, and running some tests locally now.

Sweet. I'll create a ticket to take advantage of the new features.

The simple nixpkgs part of the WIP: 0d3981941e6b8. I don't think I can really finish it anytime soon.

Many tests are failing with systemd-journald complaining Failed to create notify socket: Protocol not supported, maybe due to https://github.com/systemd/systemd/issues/4575. It's well possible some other problems are there as well, but some tests did succeed for me.

For now it might be best to find and apply security-only patches – we probably don't want systemd-232 in 16.09 anyway.

From 64-bit ones, tests.simple times out, for example, repeatedly spitting

node2# Error retrieving list of active machines: googleapi: Error 503: fleet server unable to communicate with etcd

This is pushed to staging btw. (a38f1911d34f2a72e15d5e98d76bece6cb8042a8)

Was this page helpful?
0 / 5 - 0 ratings