Re: [fr] Moment de convivialité Guix@Paris en avril

2024-04-11 Thread Tanguy LE CARROUR
(Warning: this email is in french because the meeting is supposed to be held in French.) Bonjour Guix, Merci à toutes celles et ceux qui ont bravé… la promiscuité pour venir discuter de Guix et d’autres sujets hier soir ! Je vais sérieusement envisager de repasser côté April, histoire que nous pu

Re: backdoor injection via release tarballs combined with binary artifacts (was Re: Backdoor in upstream xz-utils)

2024-04-11 Thread Ekaitz Zarraga
Hi, and everybody is reading. This is a steep claim! I agree that nobody reads generated files in a release tarball, but I am not sure how many other files are actually read. Yea, it is. I'd also love to know how effective is the reading in a release tarball vs a VCS repo. Quality of the re

Re: backdoor injection via release tarballs combined with binary artifacts (was Re: Backdoor in upstream xz-utils)

2024-04-11 Thread Andreas Enge
Am Thu, Apr 11, 2024 at 02:56:24PM +0200 schrieb Ekaitz Zarraga: > I think it's just better to > obtain the exact same code that is easy to find The exact same code as what? Actually I often wonder when looking for a project and end up with a Github repository how I could distinguish the "original

Re: backdoor injection via release tarballs combined with binary artifacts (was Re: Backdoor in upstream xz-utils)

2024-04-11 Thread Ekaitz Zarraga
Hi, On 2024-04-11 14:43, Andreas Enge wrote: Hello, Am Wed, Apr 10, 2024 at 03:57:20PM +0200 schrieb Ludovic Courtès: I think we should gradually move to building everything from source—i.e., fetching code from VCS and adding Autoconf & co. as inputs. the big drawback of this approach is tha

Re: backdoor injection via release tarballs combined with binary artifacts (was Re: Backdoor in upstream xz-utils)

2024-04-11 Thread Andreas Enge
Hello, Am Wed, Apr 10, 2024 at 03:57:20PM +0200 schrieb Ludovic Courtès: > I think we should gradually move to building everything from > source—i.e., fetching code from VCS and adding Autoconf & co. as inputs. the big drawback of this approach is that we would lose maintainers' signatures, right

Re: Security-Enhancement: Fine Control for guix pull --allow-downgrades

2024-04-11 Thread pelzflorian (Florian Pelz)
"pelzflorian (Florian Pelz)" writes: > And use ‘guix style --whole-file’ for formatting code, This was bad advice in this case, sorry. Regards, Florian

Re: Security-Enhancement: Fine Control for guix pull --allow-downgrades

2024-04-11 Thread pelzflorian (Florian Pelz)
Hello Rostislav. This is a good idea in my opinion, but please send the patch as a mail to guix-patc...@gnu.org. Also do not use [] for parentheses; always use (), which is Guix policy. And use ‘guix style --whole-file’ for formatting code, see the manual by running the command “info "(guix)Form

[Nicolas Graves] [PATCH v6 01/10] rde: emacs: Start emacs in --daemon mode, with shepherd and pid-file

2024-04-11 Thread Development of GNU Guix and the GNU System distribution.
Hi Guix, Emacs, As promised to Stefan a few months ago, here's a use case of Shepherd/Emacs implementation that we developped in RDE. We're using the --daemon option on the Shepherd side to launch the server in the background, include code in Emacs configuration to make it create a pid-file as s

Re: Status of ‘core-updates’

2024-04-11 Thread Steve George
On 10 Apr, Ludovic Courtès wrote: > Hello! > > Josselin Poiret skribis: > > > Disclaimer: I've been quite busy with work recently and haven't been > > able to work on core-updates that much (having to build the world > > locally doesn't help). > > No problem. We should find someone willing to