nixbot

builds

clan/clan-infra build #592 failed

branch main · PR #3052 · commit 741ec84764 · · took 59s

eval warnings 6 kinds · 15 occurrences
  • error ×1
  • error Refusing to evaluate package 'jitsi-meet-1.0.9365' in /nix/store/…-source/pkgs/by-name/ji/jitsi-meet/package.nix:61 because it is marked as insecure ×1
  • warn stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead ×3
  • warn stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead ×8
  • warn kanidm 1.10 is deprecated and will reach end-of-life on 2026-08-31 ×1
  • warn A legacy Nextcloud install (from before NixOS 26.11) may be installed. ×1

1 failed
failed attributes
status attribute duration
failed eval checks.x86_64-linux.nixos-jitsi01
error: … while evaluating a branch condition at «string»:25:5: 24| v: 25| if !builtins.isAttrs v || isDrv v then …
error:
       … while evaluating a branch condition
         at «string»:25:5:
           24|     v:
           25|     if !builtins.isAttrs v || isDrv v then
             |     ^
           26|       v

       … in the left operand of the OR (||) operator
         at «string»:25:28:
           24|     v:
           25|     if !builtins.isAttrs v || isDrv v then
             |                            ^
           26|       v

       … while evaluating definitions from `/nix/store/36jisy9766m1lxhs62ms3brnv575673p-source/modules/transposition.nix':

       … while evaluating definitions from `/nix/store/7g2k5vfw5qsx2zcl5zay3iqg9sj5blwn-source/checks/flake-module.nix, via option perSystem':

       … while evaluating the option `system.build.toplevel':

       … while evaluating definitions from `/nix/store/3jimg4nwv1acgkf0xjj55vxs004qfs0j-source/nixos/modules/system/activation/top-level.nix':

       … while evaluating the option `systemd.services.nginx.serviceConfig':

       … while evaluating definitions from `/nix/store/3jimg4nwv1acgkf0xjj55vxs004qfs0j-source/nixos/modules/system/boot/systemd.nix':

       … while evaluating the option `systemd.services.nginx.preStart':

       … while evaluating definitions from `/nix/store/3jimg4nwv1acgkf0xjj55vxs004qfs0j-source/nixos/modules/services/web-servers/nginx/default.nix':

       … while evaluating the option `services.nginx.virtualHosts."jitsi.clan.lol".root':

       (stack trace truncated; use '--show-trace' to show the full, detailed trace)

       error: Refusing to evaluate package 'jitsi-meet-1.0.9365' in /nix/store/3jimg4nwv1acgkf0xjj55vxs004qfs0j-source/pkgs/by-name/ji/jitsi-meet/package.nix:61 because it is marked as insecure

       Known issues:
        - The libolm end‐to‐end encryption library used in many Matrix
       clients and Jitsi Meet has been deprecated upstream, and relies
       on a cryptography library that has known side‐channel issues and
       disclaims that its implementations are not cryptographically secure
       and should not be used when cryptographic security is required.

       It is not known if the issues can be exploited over the network in
       practical conditions. Upstream does not believe such an attack is
       feasible, but has stated that the library should not be used going
       forward, and there are no plans to move to another cryptography
       implementation or otherwise further maintain the library at all.

       You should make an informed decision about whether to override this
       security warning, especially if you critically rely on end‐to‐end
       encryption. If you don’t care about that, or don’t use the Matrix
       functionality of a multi‐protocol client depending on libolm,
       then there should be no additional risk.

       Some clients are investigating migrating away from libolm to maintained
       libraries without known vulnerabilities.

       For further information, see:

       * The CVE records for the known vulnerabilities:

         * CVE-2024-45191
         * CVE-2024-45192
         * CVE-2024-45193

       * The libolm deprecation notice:
         <https://gitlab.matrix.org/matrix-org/olm/-/blob/6d4b5b07887821a95b144091c8497d09d377f985/README.md#important-libolm-is-now-deprecated>

       * The warning from the cryptography code used by libolm:
         <https://gitlab.matrix.org/matrix-org/olm/-/blob/6d4b5b07887821a95b144091c8497d09d377f985/lib/crypto-algorithms/README.md>

       * The blog post disclosing the details of the known vulnerabilities:
         <https://soatok.blog/2024/08/14/security-issues-in-matrixs-olm-library/>

       * The statement about the deprecation and vulnerabilities from the
         Matrix.org Foundation:
         <https://matrix.org/blog/2024/08/libolm-deprecation/>

       * A (likely incomplete) aggregation of client tracking issue links:
         <https://github.com/NixOS/nixpkgs/pull/334638#issuecomment-2289025802>


       You can install it anyway by allowing this package, using the
       following methods:

       a) To temporarily allow all insecure packages, you can use an environment
          variable for a single invocation of the nix tools:

            $ export NIXPKGS_ALLOW_INSECURE=1

          Note: When using `nix shell`, `nix build`, `nix develop`, etc with a flake,
                then pass `--impure` in order to allow use of environment variables.

       b) for `nixos-rebuild` you can add ‘jitsi-meet-1.0.9365’ to
          `nixpkgs.config.permittedInsecurePackages` in the configuration.nix,
          like so:

            {
              nixpkgs.config.permittedInsecurePackages = [
                "jitsi-meet-1.0.9365"
              ];
            }

       c) For `nix-env`, `nix-build`, `nix-shell` or any other Nix command you can add
          ‘jitsi-meet-1.0.9365’ to `permittedInsecurePackages` in
          ~/.config/nixpkgs/config.nix, like so:

            {
              permittedInsecurePackages = [
                "jitsi-meet-1.0.9365"
              ];
            }
15 succeeded ⚠ 11
succeeded attributes
status attribute duration
succeeded checks.aarch64-darwin.nix-darwin-build02
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
34s
succeeded checks.aarch64-darwin.nix-darwin-build04
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
45s
succeeded checks.aarch64-darwin.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
39s
succeeded checks.aarch64-linux.nixos-build01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
20s
succeeded checks.aarch64-linux.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
3s
succeeded checks.x86_64-linux.nixos-build-x86-01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
6s
succeeded checks.x86_64-linux.nixos-monitoring01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
13s
succeeded checks.x86_64-linux.nixos-storinator01
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
14s
succeeded checks.x86_64-linux.nixos-web01
  • A legacy Nextcloud install (from before NixOS 26.11) may be installed. After nextcloud33 is installed successfully, you can safely upgrade to 34. The latest version available is Nextcloud34. Please note that Nextcloud doesn't support upgrades across multiple major versions (i.e. an upgrade from 16 is possible to 17, but not 16 to 18). The package can be upgraded by explicitly declaring the service-option `services.nextcloud.package`.
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
13s
succeeded checks.x86_64-linux.nixos-web02
  • kanidm 1.10 is deprecated and will reach end-of-life on 2026-08-31 Please upgrade by verifying `kanidmd domain upgrade-check` and choosing the next version with `services.kanidm.package = pkgs.kanidm_1_x;` See upgrade guide at https://kanidm.github.io/kanidm/master/server_updates.html
  • stdenv.isLinux is deprecated, use stdenv.hostPlatform.isLinux instead
13s
succeeded checks.x86_64-linux.treefmt
  • stdenv.isDarwin is deprecated, use stdenv.hostPlatform.isDarwin instead
2s
succeeded checks.aarch64-linux.secrets 24s
succeeded checks.aarch64-linux.vars 36s
succeeded checks.x86_64-linux.secrets 19s
succeeded checks.x86_64-linux.vars 25s
57 already built
skipped attributes
status attribute duration
loading…