From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mp12.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by ms0.migadu.com with LMTPS id ILZ2IfFFVWIGEAAAgWs5BA (envelope-from ) for ; Tue, 12 Apr 2022 11:27:13 +0200 Received: from aspmx1.migadu.com ([2001:41d0:2:bcc0::]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits)) by mp12.migadu.com with LMTPS id uBFFHvFFVWL1KwAAauVa8A (envelope-from ) for ; Tue, 12 Apr 2022 11:27:13 +0200 Received: from lists.gnu.org (lists.gnu.org [209.51.188.17]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by aspmx1.migadu.com (Postfix) with ESMTPS id 73ED93D238 for ; Tue, 12 Apr 2022 11:27:12 +0200 (CEST) Received: from localhost ([::1]:54190 helo=lists1p.gnu.org) by lists.gnu.org with esmtp (Exim 4.90_1) (envelope-from ) id 1neCnm-0005bz-KR for larch@yhetil.org; Tue, 12 Apr 2022 05:27:10 -0400 Received: from eggs.gnu.org ([2001:470:142:3::10]:60194) by lists.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.90_1) (envelope-from ) id 1neCne-0005Zf-E6 for guix-patches@gnu.org; Tue, 12 Apr 2022 05:27:02 -0400 Received: from debbugs.gnu.org ([209.51.188.43]:53633) by eggs.gnu.org with esmtps (TLS1.2:ECDHE_RSA_AES_128_GCM_SHA256:128) (Exim 4.90_1) (envelope-from ) id 1neCne-0005fN-1i for guix-patches@gnu.org; Tue, 12 Apr 2022 05:27:02 -0400 Received: from Debian-debbugs by debbugs.gnu.org with local (Exim 4.84_2) (envelope-from ) id 1neCnd-0006Az-TN for guix-patches@gnu.org; Tue, 12 Apr 2022 05:27:01 -0400 X-Loop: help-debbugs@gnu.org Subject: [bug#54723] [PATCH] Check URI when verifying narinfo validity. Resent-From: Guillaume Le Vaillant Original-Sender: "Debbugs-submit" Resent-CC: guix-patches@gnu.org Resent-Date: Tue, 12 Apr 2022 09:27:01 +0000 Resent-Message-ID: Resent-Sender: help-debbugs@gnu.org X-GNU-PR-Message: followup 54723 X-GNU-PR-Package: guix-patches X-GNU-PR-Keywords: patch To: Ludovic =?UTF-8?Q?Court=C3=A8s?= Cc: Simon Streit , 54723@debbugs.gnu.org, Maxim Cournoyer Received: via spool by 54723-submit@debbugs.gnu.org id=B54723.164975560523708 (code B ref 54723); Tue, 12 Apr 2022 09:27:01 +0000 Received: (at 54723) by debbugs.gnu.org; 12 Apr 2022 09:26:45 +0000 Received: from localhost ([127.0.0.1]:47530 helo=debbugs.gnu.org) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1neCnN-0006AJ-Gj for submit@debbugs.gnu.org; Tue, 12 Apr 2022 05:26:45 -0400 Received: from mout02.posteo.de ([185.67.36.66]:46459) by debbugs.gnu.org with esmtp (Exim 4.84_2) (envelope-from ) id 1neCnM-0006A3-Ir for 54723@debbugs.gnu.org; Tue, 12 Apr 2022 05:26:45 -0400 Received: from submission (posteo.de [185.67.36.169]) by mout02.posteo.de (Postfix) with ESMTPS id 0041F240109 for <54723@debbugs.gnu.org>; Tue, 12 Apr 2022 11:26:38 +0200 (CEST) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=posteo.net; s=2017; t=1649755599; bh=wiJqAhSBHt6+H3zg89vT9ZTGWehPgtATd0RwtXC4ZDY=; h=From:To:Cc:Subject:Date:From; b=Sy9qwMV2FJrPy8junQ6DHbZwgBT7+YKuce+koJu0b2CuePd4R+w+Gri4FXJQK2CEL 8Gd/JdjkVGf9yiZh7KzJ3RQYBlyDy/dCaV+DPgeaJihFxAMCew2yFdRZUXobyqJIfI htYsZCsh3DxAVJ+V0/vA/hTgGO2/GVPiNi3dqCe02WrYobRV/n0C38/QVVYVrk8CSf mLhhBFo7yqg492jE9WGStWJcJSkJ4iq/kvPXx1G2K9xPiqJX4cX4+TqmVnpk8twLPw arqspWg7x9ivGwBg9hQxVQJTT4hd9uDfRYGB2M0dUtkMm8XYIT5mKgDr6TtyGOzGQ4 2icR8W9+aT+xQ== Received: from customer (localhost [127.0.0.1]) by submission (posteo.de) with ESMTPSA id 4Kd0j91GCbz6tqJ; Tue, 12 Apr 2022 11:26:37 +0200 (CEST) References: <87a6czbzvh.fsf@kitej> <877d83lapv.fsf@gnu.org> <875ynnbe65.fsf@kitej> <87pmlq6lqx.fsf_-_@gnu.org> <877d7ydjwk.fsf@kitej> <87wnfv90cl.fsf@kitej> <871qy2g2v3.fsf@gnu.org> From: Guillaume Le Vaillant Date: Tue, 12 Apr 2022 08:54:00 +0000 In-reply-to: <871qy2g2v3.fsf@gnu.org> Message-ID: <87o816wt36.fsf@kitej> MIME-Version: 1.0 Content-Type: multipart/signed; boundary="=-=-="; micalg=pgp-sha512; protocol="application/pgp-signature" X-BeenThere: debbugs-submit@debbugs.gnu.org X-Mailman-Version: 2.1.18 Precedence: list X-BeenThere: guix-patches@gnu.org List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: guix-patches-bounces+larch=yhetil.org@gnu.org Sender: "Guix-patches" X-Migadu-Flow: FLOW_IN X-Migadu-To: larch@yhetil.org X-Migadu-Country: US ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=yhetil.org; s=key1; t=1649755633; h=from:from:sender:sender:reply-to:subject:subject:date:date: message-id:message-id:to:to:cc:cc:mime-version:mime-version: content-type:content-type:resent-cc:resent-from:resent-sender: resent-message-id:in-reply-to:in-reply-to:references:references: list-id:list-help:list-unsubscribe:list-subscribe:list-post: dkim-signature; bh=zkssA9KEET7b9e/iJ7IJbAd9Pht50MPqXIi6uJQy2vM=; b=sevQsWZ4Wp0TuskB/7Kg70fUWcctq61XEd8JkR0lCiH0VA/j3StQSZM9I8mnKJnLoGr61C FFgfIlIRVUyv8YQx/STv9h44eRFdLxXYHLb4z8QLs0RQDNfkeoCgS+8a6CIYivoVd9m5od U3RomVySQnvAw0LDZjtya8zSdkpbdE4qT6q+mcithucbnuPDUuA7sOZHZ74kHcwgsF+OgY hHnhFCQwh0Tt3tluZxH08T6ejs38pl75WVlx+KU2G8vV+K3XNL0JYFAvFOCX2Fk2grwj6Q YF4ia/+rmfrFi8GQdMc3JKF6BAA+RpOk6LLdWxS6CohbGyIyaSjI3CMg/D02pQ== ARC-Seal: i=1; s=key1; d=yhetil.org; t=1649755633; a=rsa-sha256; cv=none; b=Xt9R+SdxKn8SAIebVczsxzXMrn+V5GX6uUQm01y4dI5pElKO/3wGJ7hQ4AeAQmeQz3xMfh JH2KHc5WAVJEU/BiyBO2yHWDh07pONlncytj19QvKJLSTd11Qq7h8Du82hNWpbxRaudEA9 /q4fjJ5L2aHy4U+KGsvkyp1qC2awMruxWBCUv06D73nr6F52XAKn0g7os0RmYoxuq1/7hO TnD95P6bF/kde7knC0L3hcKi3DXR78yCAqSMFdePkcUA7ibcOlFTAEN8yIc4yIYpadLT/w eefkgdNV4Nv7loNCdzkLtOes664D4LNuTQ4ERdUTUw1xnFPrE2IFRgwObXkIjw== ARC-Authentication-Results: i=1; aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=posteo.net header.s=2017 header.b=Sy9qwMV2; dmarc=fail reason="SPF not aligned (strict)" header.from=posteo.net (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Spam-Score: 5.14 Authentication-Results: aspmx1.migadu.com; dkim=fail ("headers rsa verify failed") header.d=posteo.net header.s=2017 header.b=Sy9qwMV2; dmarc=fail reason="SPF not aligned (strict)" header.from=posteo.net (policy=none); spf=pass (aspmx1.migadu.com: domain of "guix-patches-bounces+larch=yhetil.org@gnu.org" designates 209.51.188.17 as permitted sender) smtp.mailfrom="guix-patches-bounces+larch=yhetil.org@gnu.org" X-Migadu-Queue-Id: 73ED93D238 X-Spam-Score: 5.14 X-Migadu-Scanner: scn0.migadu.com X-TUID: BfNJZ8+2G0Q6 --=-=-= Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: quoted-printable Ludovic Court=C3=A8s skribis: > Woow. How do you build and run =E2=80=98guix publish=E2=80=99? Is it a = distro package > or is it coming straight from Guix? What command-line options are you > passing? > > I=E2=80=99ve never seen this, although we have it running on several serv= ers, > notably ci.guix. I wonder what could cause this. > > Thanks, > Ludo=E2=80=99. I'm using guix-publish-service-type in the operating-system definition to manage the "guix publish" server, using the on-the-fly mode and fast Zstandard compression: =2D-8<---------------cut here---------------start------------->8--- (service guix-publish-service-type (guix-publish-configuration (host "0.0.0.0") (port 8080) (compression '(("zstd" 3))) (advertise? #t))) =2D-8<---------------cut here---------------end--------------->8--- When booting the machine, shepherd starts the server with the following command-line options: =2D-8<---------------cut here---------------start------------->8--- /gnu/store/059svbd32i4s0l9s5i7z0krcnl666bjy-guix-1.3.0-24.2fb4304/libexec/g= uix/guile \ /gnu/store/059svbd32i4s0l9s5i7z0krcnl666bjy-guix-1.3.0-24.2fb43= 04/bin/guix publish -u guix-publish -p 8080 -C zstd:3 --nar-path=3Dnar --li= sten=3D0.0.0.0 --advertise =2D-8<---------------cut here---------------end--------------->8--- There's another report about this at I had forgotten about, where Simon Streit and Maxim Cournoyer indicate that they have seen this issue too. --=-=-= Content-Type: application/pgp-signature; name="signature.asc" -----BEGIN PGP SIGNATURE----- iIUEAREKAC0WIQTLxZxm7Ce5cXlAaz5r6CCK3yH+PwUCYlVFvQ8cZ2x2QHBvc3Rl by5uZXQACgkQa+ggit8h/j91WgD/XqYz6LtKogKSNZerrXAqJZUhPG2SPgR3E9Wv rS/EZtAA/REc9W+O8OPtNRWtOkjnA060LMut97drfk89Yzc6O8f+ =JDIe -----END PGP SIGNATURE----- --=-=-=--