Skip to content

Conversation

@Mic92
Copy link
Member

@Mic92 Mic92 commented Aug 17, 2025

Description of changes
Things done
  • Tested the changes in your own NixOS Configuration
  • Tested the changes end-to-end by using your fork of nixos-hardware and
    importing it via <nixos-hardware> or Flake input

@Mic92 Mic92 requested a review from fgaz as a code owner August 17, 2025 09:24
@Mic92 Mic92 force-pushed the private-flake branch 5 times, most recently from 6eb557c to 9cd60f4 Compare August 17, 2025 10:02
This makes `nix fmt` just works and we no longer have to override flake
inputs.
The broadcom-sta driver package is marked as insecure due to CVE-2019-9501
and CVE-2019-9502 (heap buffer overflow vulnerabilities allowing remote code
execution). The driver is also unmaintained and incompatible with modern
Linux kernel security mitigations.

Removed broadcom_sta from extraModulePackages and the corresponding "wl" kernel module.

This resolves test failures where Nixpkgs refuses to evaluate configurations
containing this insecure package.
@Mic92 Mic92 enabled auto-merge October 30, 2025 12:05
in ci, there is no cache, so it's just overhead and prints warnings.
@Mic92 Mic92 added this pull request to the merge queue Oct 30, 2025
@Mic92 Mic92 mentioned this pull request Oct 30, 2025
2 tasks
Merged via the queue into master with commit 43ffe9a Oct 30, 2025
2 checks passed
@Mic92 Mic92 deleted the private-flake branch October 30, 2025 12:40
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants