Hi,

sorry for the late reply.

On Sun, 27 Jul 2025 21:15:30 -0500
Kurt Kremitzki <kurt@kwk.systems> wrote:

> root@guix-test:~# guix repl -- abstract-socket-vuln-check.scm
> [some error]
> Is this happening to anyone else?

I had a similar issue with CVE-2024-2797: with Trisquel, if I run
apt install guix, I've Guix 1.3.0 which is affected by this CVE, but
1.3.0 cannot run the test.

So I simply use 'guix time-machine \
--commit=8e2f32cee982d42a79e53fc1e9aa7b8ff0514714  -- [...]' to test.

I ended it putting these tests in a git repository[1] but it would be
better to have that into Guix proper somehow (easier to get, better
trust than some random git repository, etc).

References:
-----------
[1]https://git.sr.ht/~gnutoo/guix-security-tests

Denis.

Attachment: pgps_JPMEW9nY.pgp
Description: OpenPGP digital signature

Reply via email to