Conversation
Notices
-
Embed this notice
Oneesan succubus (lain@pleroma.soykaf.com)'s status on Saturday, 05-Aug-2023 21:09:41 JST Oneesan succubus Another Pleroma issue has been found, similar to yesterday's but this one also affects single user instances. Please update your servers once more, akkoma also has the same patch.
https://pleroma.social/announcements/2023/08/05/pleroma-security-release-2.5.4/
Thanks again to everyone involved in reporting and fixing this!-
Embed this notice
on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ (lain@lain.com)'s status on Sunday, 06-Aug-2023 00:31:49 JST on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ @hakui @benis @lain @shpuld why not update then... It's two commands... In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:31:50 JST 御園はくい @shpuld @benis @lain i'm on otp.. In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:31:51 JST 御園はくい @benis @lain any way to patch it without updating In conversation permalink -
Embed this notice
御shp :blobshp: (shpuld@shpposter.club)'s status on Sunday, 06-Aug-2023 00:31:51 JST 御shp :blobshp: @hakui @benis @lain just check the commits and apply yourself In conversation permalink -
Embed this notice
Generational Wealth (benis@cawfee.club)'s status on Sunday, 06-Aug-2023 00:31:53 JST Generational Wealth @lain oh no, now @hakui will have to upgrade In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:36:29 JST 御園はくい @lain @benis @lain @shpuld anyway, what's this new exploit about In conversation permalink -
Embed this notice
on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ (lain@lain.com)'s status on Sunday, 06-Aug-2023 00:36:29 JST on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ @hakui @benis @lain @shpuld reading your config files with XML fun In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:36:30 JST 御園はくい @lain @benis @lain @shpuld i suspect updates are a cause of sudden db catastrophical failure In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:45:43 JST 御園はくい @lain @benis @lain @shpuld what does secret_key_base and signing_salt do again In conversation permalink -
Embed this notice
on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ (lain@lain.com)'s status on Sunday, 06-Aug-2023 00:45:43 JST on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ @hakui @benis @lain @shpuld secure your cookies In conversation permalink -
Embed this notice
on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ (lain@lain.com)'s status on Sunday, 06-Aug-2023 00:54:24 JST on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ @hakui @benis @lain @shpuld yes In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:54:25 JST 御園はくい @lain @benis @lain @shpuld and what does an attacker get by getting those
make fake cookies of their own?In conversation permalink -
Embed this notice
on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ (lain@lain.com)'s status on Sunday, 06-Aug-2023 00:55:32 JST on-lain ✔ᵛᵉʳᶦᶠᶦᵉᵈ @hakui @benis @lain @eal @rin @shpuld I can help you with the update if you want, but not today In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:55:33 JST 御園はくい @shpuld @benis @lain @lain
@eal @rin how did y'all's instances die againIn conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Sunday, 06-Aug-2023 00:55:34 JST 御園はくい @shpuld @benis @lain @lain >my problems with upgrade went away by upgrading more
survivorship biasIn conversation permalink -
Embed this notice
御shp :blobshp: (shpuld@shpposter.club)'s status on Sunday, 06-Aug-2023 00:55:34 JST 御shp :blobshp: @hakui @benis @lain @lain no it was unbearable at 2.4.9 or so, I was afraid 2.5.0 would make it worse but no it fixed perf regressions In conversation permalink -
Embed this notice
御shp :blobshp: (shpuld@shpposter.club)'s status on Sunday, 06-Aug-2023 00:55:35 JST 御shp :blobshp: @hakui @benis @lain @lain are you on pg9.6 or something
anyway my problems with upgrade went away by upgrading more, latest versions work just about as smooth as when I started
backup anywayIn conversation permalink -
Embed this notice
「セル」cell (سل) (cell@pl.ebin.zone)'s status on Sunday, 06-Aug-2023 08:08:57 JST 「セル」cell (سل) @shpuld @benis @lain @lain @hakui 2.4.x nearly killed my instance, but luckily 2.5 fixed the performance regressions In conversation permalink -
Embed this notice
ロミンちゃん (romin@shitposter.club)'s status on Monday, 07-Aug-2023 09:38:04 JST ロミンちゃん @hakui @dcc @benis @lain @lain @shpuld @m0xee RIP In conversation permalink -
Embed this notice
御園はくい (hakui@tuusin.misono-ya.info)'s status on Monday, 07-Aug-2023 09:38:05 JST 御園はくい @dcc @m0xee @benis @lain @lain @shpuld yeah but i haven't updated in three years lad In conversation permalink -
Embed this notice
✙ dcc :pedomustdie: :phear_slackware: (dcc@annihilation.social)'s status on Monday, 07-Aug-2023 09:38:06 JST ✙ dcc :pedomustdie: :phear_slackware: @m0xee @hakui @benis @lain @lain @shpuld These two updates dont change your db at all In conversation permalink -
Embed this notice
m0xEE (m0xee@social.librem.one)'s status on Monday, 07-Aug-2023 09:38:07 JST m0xEE @hakui
I don't think these minor updates do a thing to the db, the whole ecto.migrate takes less than a second even on my severely underpowered hardware on which db VACUUM takes minutes (and that's a single-user instance) as it appear to be to changes to the db schema 🤷
@benis @lain @lain @shpuldIn conversation permalink
-
Embed this notice