Re: Search alerts and Watch issue on mumi

2025-04-04 Thread Arun Isaac
> Or, subscribe to all issues in which you participated > in—submitter:"Arun Isaac" (replace my name with yours, of course)—and > never worry about people not Ccing you correctly. Small correction. This query should be author:"Arun Isaac". submitter:"Arun Isaac" only gives you issues which you c

Re: bug#76428: [GCD PATCH] 003-set-search-paths-without-program-wrappers: Submit.

2025-04-04 Thread 宋文武
Ludovic Courtès writes: > 宋文武 skribis: > >> ld.so.cache >> search-paths.d >> GUIX_XDG_DATA_DIRS >> GUIX_GIO_EXTRA_MODULES >> GUIX_GTK4_PATH > > I don’t think the “GUIX_” prefix is really justified in the proposal. Sure. There are 2 reasons, one is to avoid broke foreign systems

Re: GNU & Guix

2025-04-04 Thread Tobias Geerinckx-Rice
Yo, On 2 April 2025 15:34:36 UTC, Caleb Herbert wrote: >Hi, signer of Document! Wat. I attached no signature/document/whatsoever. What was it? (Whenever I *want* K-9 and GPG to play nicely, they won't!) Anyway, it meant nothing and I presume you were able to read my message just fine. >Par

Re: Applying Patches for Review

2025-04-04 Thread Cayetano Santos
>sam. 29 mars 2025 at 16:10, Noé Lopez wrote: > Gabriel Santos writes: > Another way I know of is to download the mailbox from the issue’s > debbugs page and apply it with “git am”. As an alternative, you have https://yhetil.org/guix-patches/ From here, you can download the full thread a

How is security managed in Guix? Should there be a team?

2025-04-04 Thread Nicolas Graves
Hi Guix! I think one of the things where Guix could be better is security / ensuring CVEs are fixed quickly. In 76819 I developped some missing functionality in the CVE linter, so that it will be easier to get proper missing libraries. A few ideas/questions to advance on that : - there are still

Re: How is security managed in Guix? Should there be a team?

2025-04-04 Thread Development of GNU Guix and the GNU System distribution.
Nicolas Graves writes: > Hi Guix! > > I think one of the things where Guix could be better is security / > ensuring CVEs are fixed quickly. > > In 76819 I developped some missing functionality in the CVE linter, so > that it will be easier to get proper missing libraries. > > A few ideas/question

Re: Slow guix pull? (was Re: Please don't leave GNU)

2025-04-04 Thread 45mg
45mg <45mg.wri...@gmail.com> writes: > The initial `git pull` part can be surprisingly slow, though. And it's > not always a network thing. For example, every single time I run `guix > pull` it appears to do nothing for like 2 minutes, and then the progress > bars display as it pulls the entire re

Re: How is security managed in Guix? Should there be a team?

2025-04-04 Thread Development of GNU Guix and the GNU System distribution.
Hello, (CCing some more security people) On Fri, Apr 04, 2025 at 05:51 PM, Simon Josefsson via \"Development of GNU Guix and the GNU System distribution.\" wrote: > Nicolas Graves writes: > >> Hi Guix! >> >> I think one of the things where Guix could be better is security / >> ensuring CVEs ar

Re: How is security managed in Guix? Should there be a team?

2025-04-04 Thread Leo Famulari
The guix-security mailing list is meant to be a private messaging system for embargoed (i.e. secret) security reports. Everything else should be handled in public. Leo On Fri, Apr 4, 2025, at 12:21, John Kehayias wrote: > Hello, > > (CCing some more security people) > > On Fri, Apr 04, 2025 at

Re: “Build daemon drops its privileges” 👈 blog post

2025-04-04 Thread Ludovic Courtès
Simon Josefsson skribis: > Not invalidating my questions, but maybe some additional insight: > Reading the guix-install.sh make me believe that one part of my issues > could be due to: > > [ FAIL ] Init system could not be detected. > > Several things from guix-install.sh are not run properly in

Re: Next period? (was Re: [GCD] Set search paths without program wrappers)

2025-04-04 Thread 宋文武
Simon Tournier writes: > Almost one month is over. For the record, the discussion happens here: > > [bug#76428] [GCD PATCH] > 003-set-search-paths-without-program-wrappers: Submit. > iyzsong--- via Guix-patches via > Thu, 20 Feb 2025 12:08:23 +0800 > id:20250220

Re: Search alerts and Watch issue on mumi

2025-04-04 Thread Gabriel Santos
>PS: I would appreciate if some CSS-proficient person helped out with >https://issues.guix.gnu.org/77513 > I gave it a quick look and removing this line: mumi.css 1970:2 > line-height: var(--line-height); Brought "Projects" to the same height as "Search Alert". -- Gabriel Santos

Re: Search alerts and Watch issue on mumi

2025-04-04 Thread Cayetano Santos
>ven. 04 avril 2025 at 20:07, Arun Isaac wrote: > Hi all, > > mumi has two exciting new features—search alerts and watch issue. Now, > you can subscribe to any issue or search query using your feed reader. Love it. Really. Thanks a lot for all those improvements to mumi, which is getting more a

Re: How is security managed in Guix? Should there be a team?

2025-04-04 Thread Development of GNU Guix and the GNU System distribution.
John Kehayias via "Development of GNU Guix and the GNU System distribution." writes: >> Yes, most distributions have a special security point of contact that is >> not publicly archived, to discuss ways to resolve responsible disclosure >> vulnerabilities for example. Seeing some progress on thi

Search alerts and Watch issue on mumi

2025-04-04 Thread Arun Isaac
Hi all, mumi has two exciting new features—search alerts and watch issue. Now, you can subscribe to any issue or search query using your feed reader. # Watch issues Subscribe to a specific issue. Look for a "Watch Issue" link in the top-right corner on the navbar of issue pages. You will get s

Re: bug#76428: [GCD PATCH] 003-set-search-paths-without-program-wrappers: Submit.

2025-04-04 Thread Ludovic Courtès
Hi 宋文武, First of all, apologies for not really contributing to the discussion before. My sentiment could be summarized as: I agree with the rationale, I like the idea of storing search path metadata in package outputs, but I’m concerned about the maintainability and viability of some aspects of t

Daemon in Docker/GitLab-CI and Buildah

2025-04-04 Thread Ludovic Courtès
Hi Simon, I guess you’re ahead on me on these issues :-) so I’m glad you’re testing it and reporting back! Simon Josefsson skribis: > I get the following error: > > guix pull: error: cloning builder process: Operation not permitted > > If I add --cap-add and instead run: > > time buildah build