diff --git a/doc/manual/rl-next/failed-cve-mitigation.md b/doc/manual/rl-next/failed-cve-mitigation.md deleted file mode 100644 index 553c06ae6..000000000 --- a/doc/manual/rl-next/failed-cve-mitigation.md +++ /dev/null @@ -1,35 +0,0 @@ ---- -synopsis: "Revert CVE-2025-52992 failed mitigation" -issues: [fj#883, fj#887] -cls: [3432, 3525, 3526, 3527] -category: "Fixes" -credits: ["raito", "horrors"] ---- - -Following the initial mitigation of **CVE-2025-52992** in `cl/3432`, we -received reports of **unexpected deletion of in-use store paths**. - -Upon investigation, we found that the patch did **not correctly cancel all -automatic deleters**, resulting in potentially critical path loss during normal -operation. - -Given the severity and time-sensitive nature of the situation ([see incident -report](https://lix.systems/blog/2025-06-27-lix-critical-bug/)), we evaluated -possible options to repair the behavior safely. However, we concluded that a -rushed fix would either - -* **Overdelete**, i.e. breaking running systems, or, -* **Underdelete**, effectively **reopening CVE-2025-52992** while leaving - orphaned paths behind. - -As **CVE-2025-52992 has no known exploit vector**, and correctness is critical -in the Lix project, we have **fully reverted the previous mitigations**. - -The affected patches (`cl/3432`) have been rolled back for the time being. - -Moving forward, the Lix team will rework this code path in a **long-term, -correctness-first fix** on the main branch. We will explore backporting it to -stable channels once its safety is assured. - -We are deeply sorry for the stability incident and the Lix team remain -available for assisting you in recovering your systems. diff --git a/doc/manual/rl-next/infallible-build-dirs.md b/doc/manual/rl-next/infallible-build-dirs.md deleted file mode 100644 index e5ffb4a61..000000000 --- a/doc/manual/rl-next/infallible-build-dirs.md +++ /dev/null @@ -1,25 +0,0 @@ ---- -synopsis: "Fallback to safe temp dir when build-dir is unwritable" -issues: [fj#876] -cls: [3503] -category: "Fixes" -credits: ["raito", "horrors"] ---- - -Non-daemon builds started failing with a permission error after introducing the `build-dir` option: - -``` -$ nix build --store ~/scratch nixpkgs#hello --rebuild -error: creating directory '/nix/var/nix/builds/nix-build-hello-2.12.2.drv-0': Permission denied -``` - -This happens because: - -1. These builds are not run via the daemon, which owns `/nix/var/nix/builds`. -2. The user lacks permissions for that path. - -We considered making `build-dir` a store-level option and defaulting it to `/nix/var/nix/builds` for chroot stores, but opted instead for a fallback: if the default fails, Nix now creates a safe build directory under `/tmp`. - -To avoid CVE-2025-52991, the fallback uses an extra path component between `/tmp` and the build dir. - -**Note**: this fallback clutters `/tmp` with build directories that are not cleaned up. To prevent this, explicitly set `build-dir` to a path managed by Lix, even for local workloads. diff --git a/doc/manual/src/release-notes/rl-2.92.md b/doc/manual/src/release-notes/rl-2.92.md index eef8fdadc..7f0d35fa2 100644 --- a/doc/manual/src/release-notes/rl-2.92.md +++ b/doc/manual/src/release-notes/rl-2.92.md @@ -1,4 +1,61 @@ # Lix 2.92 "Bombe glacée" (2025-01-18) +# Lix 2.92.3 (2025-06-30) + +## Fixes +- Revert CVE-2025-52992 failed mitigation [fj#883](https://git.lix.systems/lix-project/lix/issues/883) [fj#887](https://git.lix.systems/lix-project/lix/issues/887) [cl/3432](https://gerrit.lix.systems/c/lix/+/3432) [cl/3525](https://gerrit.lix.systems/c/lix/+/3525) [cl/3526](https://gerrit.lix.systems/c/lix/+/3526) [cl/3527](https://gerrit.lix.systems/c/lix/+/3527) + + Following the initial mitigation of **CVE-2025-52992** in `cl/3432`, we + received reports of **unexpected deletion of in-use store paths**. + + Upon investigation, we found that the patch did **not correctly cancel all + automatic deleters**, resulting in potentially critical path loss during normal + operation. + + Given the severity and time-sensitive nature of the situation ([see incident + report](https://lix.systems/blog/2025-06-27-lix-critical-bug/)), we evaluated + possible options to repair the behavior safely. However, we concluded that a + rushed fix would either + + * **Overdelete**, i.e. breaking running systems, or, + * **Underdelete**, effectively **reopening CVE-2025-52992** while leaving + orphaned paths behind. + + As **CVE-2025-52992 has no known exploit vector**, and correctness is critical + in the Lix project, we have **fully reverted the previous mitigations**. + + The affected patches (`cl/3432`) have been rolled back for the time being. + + Moving forward, the Lix team will rework this code path in a **long-term, + correctness-first fix** on the main branch. We will explore backporting it to + stable channels once its safety is assured. + + We are deeply sorry for the stability incident and the Lix team remain + available for assisting you in recovering your systems. + + Many thanks to [Raito Bezarius](https://git.lix.systems/raito) and [eldritch horrors](https://git.lix.systems/pennae) for this. +- Fallback to safe temp dir when build-dir is unwritable [fj#876](https://git.lix.systems/lix-project/lix/issues/876) [cl/3503](https://gerrit.lix.systems/c/lix/+/3503) + + Non-daemon builds started failing with a permission error after introducing the `build-dir` option: + + ``` + $ nix build --store ~/scratch nixpkgs#hello --rebuild + error: creating directory '/nix/var/nix/builds/nix-build-hello-2.12.2.drv-0': Permission denied + ``` + + This happens because: + + 1. These builds are not run via the daemon, which owns `/nix/var/nix/builds`. + 2. The user lacks permissions for that path. + + We considered making `build-dir` a store-level option and defaulting it to `/nix/var/nix/builds` for chroot stores, but opted instead for a fallback: if the default fails, Nix now creates a safe build directory under `/tmp`. + + To avoid CVE-2025-52991, the fallback uses an extra path component between `/tmp` and the build dir. + + **Note**: this fallback clutters `/tmp` with build directories that are not cleaned up. To prevent this, explicitly set `build-dir` to a path managed by Lix, even for local workloads. + + Many thanks to [Raito Bezarius](https://git.lix.systems/raito) and [eldritch horrors](https://git.lix.systems/pennae) for this. + + # Lix 2.92.2 (2025-06-23) ## Breaking Changes