whisper: built with -no-pie (prebuilt libraries)#457358
Merged
philiptaron merged 1 commit intoNixOS:masterfrom Nov 1, 2025
Merged
whisper: built with -no-pie (prebuilt libraries)#457358philiptaron merged 1 commit intoNixOS:masterfrom
-no-pie (prebuilt libraries)#457358philiptaron merged 1 commit intoNixOS:masterfrom
Conversation
13 tasks
Contributor
Author
|
LunNova
approved these changes
Oct 31, 2025
Member
|
The vendored precompiled libraries are 8 years old so it seems likely they're vulnerable and this package should be marked insecure, eg zlib version would be impacted by CVE-2022-37434. |
jbedo
approved these changes
Nov 1, 2025
Without the change the build fails as https://hydra.nixos.org/build/310775846: ld: libs/libz.a(deflate.o): relocation R_X86_64_32S against `.rodata' can not be used when making a PIE object; recompile with -fPIE ld: failed to set dynamic section sizes: bad value It happens because `libs/libz.a` comes from a "source" tarball. As some libraries are not packaged in `nixpkgs` let's fall back to `-no-pie`. Co-authored-by: Justin Bedő <[email protected]>
87d7812 to
4f59e2f
Compare
philiptaron
approved these changes
Nov 1, 2025
Contributor
philiptaron
left a comment
There was a problem hiding this comment.
Support the "mark broken" line of argumentation, merging this to unbreak in the interim.
Member
|
Setting knownVulnerabilities in #457885 |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Without the change the build fails as https://hydra.nixos.org/build/310775846:
It happens because
libs/libz.acomes from a"source" tarball. As some libraries are not packaged in
nixpkgslet's fall back to-no-pie.Things done
passthru.tests.nixpkgs-reviewon this PR. See nixpkgs-review usage../result/bin/.Add a 👍 reaction to pull requests you find important.