nixbot

builds

clan/clan-infra build #574 failed

branch main · PR #3052 · commit 784d5c9c0f · · took 7m 57s

eval warnings 6 kinds · 14 occurrences
  • error ×1
  • error Refusing to evaluate package 'jitsi-meet-1.0.9365' in /nix/store/…-source/pkgs/by-name/ji/jitsi-meet/package.nix:61 because it is marked as insecure ×1
  • warn stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead ×3
  • warn stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead ×7
  • warn kanidm 1.10 is deprecated and will reach end-of-life on 2026-08-31 ×1
  • warn A legacy Nextcloud install (from before NixOS 26.11) may be installed. ×1

1 failed
failed attributes
status attribute duration
failed eval checks.x86_64-linux.nixos-jitsi01
error: … while evaluating a branch condition at «string»:25:5: 24| v: 25| if !builtins.isAttrs v || isDrv v then …
error:
       … while evaluating a branch condition
         at «string»:25:5:
           24|     v:
           25|     if !builtins.isAttrs v || isDrv v then
             |     ^
           26|       v

       … in the left operand of the OR (||) operator
         at «string»:25:28:
           24|     v:
           25|     if !builtins.isAttrs v || isDrv v then
             |                            ^
           26|       v

       … while evaluating definitions from `/nix/store/36jisy9766m1lxhs62ms3brnv575673p-source/modules/transposition.nix':

       … while evaluating definitions from `/nix/store/dgfxklpzbmg2qkld9n2h44x6f4dy4avb-source/checks/flake-module.nix, via option perSystem':

       … while evaluating the option `system.build.toplevel':

       … while evaluating definitions from `/nix/store/3ym565qsx3x29f0crw1ic2lhaxz59m08-source/nixos/modules/system/activation/top-level.nix':

       … while evaluating the option `systemd.services.nginx.serviceConfig':

       … while evaluating definitions from `/nix/store/3ym565qsx3x29f0crw1ic2lhaxz59m08-source/nixos/modules/system/boot/systemd.nix':

       … while evaluating the option `systemd.services.nginx.preStart':

       … while evaluating definitions from `/nix/store/3ym565qsx3x29f0crw1ic2lhaxz59m08-source/nixos/modules/services/web-servers/nginx/default.nix':

       … while evaluating the option `services.nginx.virtualHosts."jitsi.clan.lol".root':

       (stack trace truncated; use '--show-trace' to show the full, detailed trace)

       error: Refusing to evaluate package 'jitsi-meet-1.0.9365' in /nix/store/3ym565qsx3x29f0crw1ic2lhaxz59m08-source/pkgs/by-name/ji/jitsi-meet/package.nix:61 because it is marked as insecure

       Known issues:
        - The libolm end‐to‐end encryption library used in many Matrix
       clients and Jitsi Meet has been deprecated upstream, and relies
       on a cryptography library that has known side‐channel issues and
       disclaims that its implementations are not cryptographically secure
       and should not be used when cryptographic security is required.

       It is not known if the issues can be exploited over the network in
       practical conditions. Upstream does not believe such an attack is
       feasible, but has stated that the library should not be used going
       forward, and there are no plans to move to another cryptography
       implementation or otherwise further maintain the library at all.

       You should make an informed decision about whether to override this
       security warning, especially if you critically rely on end‐to‐end
       encryption. If you don’t care about that, or don’t use the Matrix
       functionality of a multi‐protocol client depending on libolm,
       then there should be no additional risk.

       Some clients are investigating migrating away from libolm to maintained
       libraries without known vulnerabilities.

       For further information, see:

       * The CVE records for the known vulnerabilities:

         * CVE-2024-45191
         * CVE-2024-45192
         * CVE-2024-45193

       * The libolm deprecation notice:
         <https://gitlab.matrix.org/matrix-org/olm/-/blob/6d4b5b07887821a95b144091c8497d09d377f985/README.md#important-libolm-is-now-deprecated>

       * The warning from the cryptography code used by libolm:
         <https://gitlab.matrix.org/matrix-org/olm/-/blob/6d4b5b07887821a95b144091c8497d09d377f985/lib/crypto-algorithms/README.md>

       * The blog post disclosing the details of the known vulnerabilities:
         <https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/>

       * The statement about the deprecation and vulnerabilities from the
         Matrix.org Foundation:
         <https://matrix.org/blog/2024/08/libolm-deprecation/>

       * A (likely incomplete) aggregation of client tracking issue links:
         <https://github.com/NixOS/nixpkgs/pull/334638#issuecomment-2289025802>


       You can install it anyway by allowing this package, using the
       following methods:

       a) To temporarily allow all insecure packages, you can use an environment
          variable for a single invocation of the nix tools:

            $ export NIXPKGS_ALLOW_INSECURE=1

          Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake,
                then pass `--impure` in order to allow use of environment variables.

       b) for `nixos-rebuild` you can add ‘jitsi-meet-1.0.9365’ to
          `nixpkgs.config.permittedInsecurePackages` in the configuration.nix,
          like so:

            {
              nixpkgs.config.permittedInsecurePackages = [
                "jitsi-meet-1.0.9365"
              ];
            }

       c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add
          ‘jitsi-meet-1.0.9365’ to `permittedInsecurePackages` in
          ~/.config/nixpkgs/config.nix, like so:

            {
              permittedInsecurePackages = [
                "jitsi-meet-1.0.9365"
              ];
            }
68 succeeded ⚠ 10
succeeded attributes
status attribute duration
succeeded checks.aarch64-darwin.nix-darwin-build02
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
6m 19s
succeeded checks.aarch64-darwin.nix-darwin-build04
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
7m 28s
succeeded checks.aarch64-darwin.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
3m 24s
succeeded checks.aarch64-linux.nixos-build01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
5m 49s
succeeded checks.aarch64-linux.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
3m 14s
succeeded checks.x86_64-linux.nixos-build-x86-01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
14s
succeeded checks.x86_64-linux.nixos-storinator01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
7s
succeeded checks.x86_64-linux.nixos-web01
  • A legacy Nextcloud install (from before NixOS 26.11) may be installed. After nextcloud33 is installed successfully, you can safely upgrade to 34. The latest version available is Nextcloud34. Please note that Nextcloud doesn't support upgrades across multiple major versions (i.e. an upgrade from 16 is possible to 17, but not 16 to 18). The package can be upgraded by explicitly declaring the service-option `services.nextcloud.package`.
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
4m 20s
succeeded checks.x86_64-linux.nixos-web02
  • kanidm 1.10 is deprecated and will reach end-of-life on 2026-08-31 Please upgrade by verifying `kanidmd domain upgrade-check` and choosing the next version with `services.kanidm.package = pkgs.kanidm_1_x;` See upgrade guide at https://kanidm.github.io/kanidm/master/server_updates.html
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
14s
succeeded checks.x86_64-linux.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
1s
succeeded checks.aarch64-darwin.devShell-cache-new 7m 33s
succeeded checks.aarch64-darwin.devShell-default 6m 2s
succeeded checks.aarch64-darwin.devShell-dns 7m 48s
succeeded checks.aarch64-darwin.devShell-terraform 7m 39s
succeeded checks.aarch64-darwin.package-action-create-pr 2m 41s
succeeded checks.aarch64-darwin.package-action-ensure-tea-login 2m 56s
succeeded checks.aarch64-darwin.package-action-flake-update 5m 26s
succeeded checks.aarch64-darwin.package-action-flake-update-pr-clan 0s
succeeded checks.aarch64-darwin.package-action-flake-update-pr-clan-individual 14s
succeeded checks.aarch64-darwin.package-cache-new 6m 28s
succeeded checks.aarch64-darwin.package-dns 6m 25s
succeeded checks.aarch64-darwin.package-gitea 3m 54s
succeeded checks.aarch64-darwin.package-job-flake-update-clan-core 14s
succeeded checks.aarch64-darwin.package-job-flake-update-clan-core-individual 5s
succeeded checks.aarch64-darwin.package-job-flake-update-clan-homepage 5m 46s
succeeded checks.aarch64-darwin.package-job-flake-update-clan-infra 14s
succeeded checks.aarch64-darwin.package-job-flake-update-data-mesher 10s
succeeded checks.aarch64-darwin.package-terraform 6m 13s
succeeded checks.aarch64-linux.devShell-cache-new 4m 19s
succeeded checks.aarch64-linux.devShell-default 4m 5s
succeeded checks.aarch64-linux.devShell-dns 4m 30s
succeeded checks.aarch64-linux.devShell-terraform 4m 39s
succeeded checks.aarch64-linux.package-action-create-pr 1m 44s
succeeded checks.aarch64-linux.package-action-ensure-tea-login 1m 44s
succeeded checks.aarch64-linux.package-action-flake-update 1m 44s
succeeded checks.aarch64-linux.package-action-flake-update-pr-clan 33s
succeeded checks.aarch64-linux.package-action-flake-update-pr-clan-individual 1m 12s
succeeded checks.aarch64-linux.package-cache-new 4m 3s
succeeded checks.aarch64-linux.package-dns 4m 4s
succeeded checks.aarch64-linux.package-gitea 3m 43s
succeeded checks.aarch64-linux.package-job-flake-update-clan-core 37s
succeeded checks.aarch64-linux.package-job-flake-update-clan-core-individual 9s
succeeded checks.aarch64-linux.package-job-flake-update-clan-homepage 31s
succeeded checks.aarch64-linux.package-job-flake-update-clan-infra 37s
succeeded checks.aarch64-linux.package-job-flake-update-data-mesher 20s
succeeded checks.aarch64-linux.package-terraform 3m 46s
succeeded checks.aarch64-linux.secrets 3m 48s
succeeded checks.aarch64-linux.vars 4m 3s
succeeded checks.x86_64-linux.devShell-cache-new 38s
succeeded checks.x86_64-linux.devShell-default 29s
succeeded checks.x86_64-linux.devShell-dns 35s
succeeded checks.x86_64-linux.devShell-terraform 36s
succeeded checks.x86_64-linux.package-action-create-pr 5s
succeeded checks.x86_64-linux.package-action-ensure-tea-login 4s
succeeded checks.x86_64-linux.package-action-flake-update 4s
succeeded checks.x86_64-linux.package-action-flake-update-pr-clan 2s
succeeded checks.x86_64-linux.package-action-flake-update-pr-clan-individual 1s
succeeded checks.x86_64-linux.package-cache-new 22s
succeeded checks.x86_64-linux.package-dns 23s
succeeded checks.x86_64-linux.package-gitea 1m 8s
succeeded checks.x86_64-linux.package-job-flake-update-clan-core 3s
succeeded checks.x86_64-linux.package-job-flake-update-clan-core-individual 0s
succeeded checks.x86_64-linux.package-job-flake-update-clan-homepage 3s
succeeded checks.x86_64-linux.package-job-flake-update-clan-infra 3s
succeeded checks.x86_64-linux.package-job-flake-update-data-mesher 2s
succeeded checks.x86_64-linux.package-terraform 24s
succeeded checks.x86_64-linux.secrets 38s
succeeded checks.x86_64-linux.vars 47s
3 already built
skipped attributes
status attribute duration
loading…