GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    :umu: :umu: (a1ba@suya.place)'s status on Tuesday, 24-Jun-2025 23:39:55 JST :umu: :umu: :umu: :umu:
    @thesamesam lol cmake
    In conversation about a year ago from suya.place permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 24-Jun-2025 23:39:51 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • uis
      @a1ba @uis @thesamesam Well there's only one that's a (confirmed) vector for malware :D
      In conversation about a year ago permalink
    • Embed this notice
      :umu: :umu: (a1ba@suya.place)'s status on Tuesday, 24-Jun-2025 23:39:52 JST :umu: :umu: :umu: :umu:
      in reply to
      • uis
      @uis @thesamesam idk what's worse cmake or autotools
      In conversation about a year ago permalink
    • Embed this notice
      uis (uis@pone.social)'s status on Tuesday, 24-Jun-2025 23:39:53 JST uis uis
      in reply to

      @a1ba @thesamesam should have used KConfig?

      In conversation about a year ago permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 24-Jun-2025 23:51:11 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • uis
      @a1ba @uis @thesamesam Well so are GNU's numerous extensions and various abuses of m4 (such as loops).
      In conversation about a year ago permalink
    • Embed this notice
      :umu: :umu: (a1ba@suya.place)'s status on Tuesday, 24-Jun-2025 23:51:12 JST :umu: :umu: :umu: :umu:
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • uis
      @lanodan @uis @thesamesam cmake's language is a malware for brain
      In conversation about a year ago permalink
    • Embed this notice
      mittorn (mittorn@masturbated.one)'s status on Tuesday, 24-Jun-2025 23:51:58 JST mittorn mittorn
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • uis

      @lanodan @uis @thesamesam @a1ba or only one yet.
      autotools at least does not have FetchContent, while cmake may SILENTLY download something. This might be good for separate task, not during configure

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Tuesday, 24-Jun-2025 23:54:14 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • mittorn
      • uis
      @mittorn @uis @thesamesam @a1ba I think CMake FetchContent can be disabled at least?
      But well if fetches can be a threat, given all buildsystems allow to execute arbitrary commands during build you should use some kind of isolation (such as unshare or bwrap).
      In conversation about a year ago permalink
    • Embed this notice
      uis (uis@pone.social)'s status on Tuesday, 24-Jun-2025 23:58:44 JST uis uis
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • mittorn

      @mittorn @lanodan @thesamesam @a1ba last year I tried to package librosa for Gentoo. It kept triggering sandbox by trying to download test data from internet even if it was already downloaded. Ebuilds allow network access only during fetch phase.

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      mittorn (mittorn@masturbated.one)'s status on Wednesday, 25-Jun-2025 01:29:37 JST mittorn mittorn
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • uis

      @a1ba @uis @lanodan @thesamesam anyway, safe fetching should always include checksums and fetch should not be done in configuration stage, it must be separate stage. And FetchContent is worse than calling wget because it's standart feature (so cmake at some point advertise using it)

      In conversation about a year ago permalink
      Haelwenn /элвэн/ :triskell: likes this.
    • Embed this notice
      :umu: :umu: (a1ba@suya.place)'s status on Wednesday, 25-Jun-2025 01:29:38 JST :umu: :umu: :umu: :umu:
      in reply to
      • Haelwenn /элвэн/ :triskell:
      • mittorn
      • uis
      @mittorn @lanodan @uis @thesamesam btw I remember using it and while, yes, it can download and unpack stuff, it's weird that it's not verbose by default. Not arguing if it's an attack vector or something, just... why silent
      In conversation about a year ago permalink
    • Embed this notice
      Haelwenn /элвэн/ :triskell: (lanodan@queer.hacktivis.me)'s status on Wednesday, 25-Jun-2025 01:31:21 JST Haelwenn /элвэн/ :triskell: Haelwenn /элвэн/ :triskell:
      in reply to
      • mittorn
      • uis
      @mittorn @a1ba @uis @thesamesam I'd even say it shouldn't be done at all but I can already hear the whines from devs that have to support windows users.
      In conversation about a year ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.