=== starcraft is now known as starcraftman === asac_ is now known as asac === swoody_ is now known as swoody === ogra_ is now known as ogra === ogra_ is now known as ogra === highvolt1ge is now known as highvoltage === fader|away is now known as fader_ === yofel_ is now known as yofel === Yos_ is now known as Yos === KatieKitty is now known as KatieOffline === KatieOffline is now known as KatieKitty [18:04] kees, robbiew: meeting? [18:04] * robbiew is here ;) [18:04] \o [18:04] is mdeslaur back? [18:05] * jjohansen waves [18:05] kees: I don't think so [18:05] he said he expected to have to miss today [18:06] ah, ok. let's go ahead with the meeting anyway and we can catch him up tomorrow? [18:06] sounds good [18:07] alrighty [18:07] I'm playing a bit with "dieharder" for testing RNGs, and will probably create a q-r-t script for it. [18:07] it's a long-running test, but it's pretty exhaustive. [18:07] RNGs? [18:08] Random Number Generator [18:08] kees: perhaps add it to test-rng.py? [18:08] I'd done limited RNG testing with the "rngtest" tool but that only covers FIPS-140-2 [18:08] jdstrand: yeah [18:09] test-rng.py allows you to run specific tests if you want, or all, of which dieharder could be one [18:09] kees: that is cool-- I hadn't heard of dieharder :) [18:09] kees: is rngtest part of test-rng.py now too? or did you not bother cause of dieharder? [18:10] I may not bother given how robust dieharder is. [18:10] on the other hand, it's super-fast. [18:10] might be fun-- you've already learned the tool [18:11] * kees nods [18:11] going to try to hit some more low-hanging fruit on the updates tree, and if I have any time left, I'm going to start working on the fscaps implementation for dpkg. [18:12] that's it from me. [18:12] I am triager and I am continuing the transmission update this week. [18:13] it looks like I won't get to the getent/passwd apparmor stuff before alpha-2 [18:13] s'okay, the infrastructure to support it is done, which is great [18:13] I plan to work on apparmor dev work for lucid, which includes alias support and the libvirt 0.7.5 merge from Debian [18:14] beyond that, I will probably pick up an update [18:14] kees: yeah-- we are looking very good wrt to tunables these days [18:15] there is a debconf question, apparmor now uses tunables/home.d and likewise-open drops a file in tunables/home.d [18:15] already that is a good improvement over previous releases [18:15] I have the method I am going to use for the passwd stuff, just need to think about whether to break it out into a separate tool, etc [18:16] that will be discussed when I get back to it [18:16] that is it from me for this week, but I have a separate item to discuss regarding our blueprints [18:17] we can come back to it later, or discuss now) [18:17] s/)// [18:17] let's do it now. :) [18:17] ok, so an essential item (catchall-essential iirc) has "switch apparmor Firefox profile on for Lucid dev cycle" [18:17] (fine) [18:18] (well, maybe not, but anyhoo...) [18:18] whats not fine? [18:18] * kees is confused too [18:19] that is a problem atm because a) I know that java is busted and audit doesn't show it as being broke because of profiling) and b) we can't do it until some lower priority blueprints are implemented [18:19] kick it down to "high", I'd say. [18:19] which blueprints? [18:20] specifically: it requires parts of security-lucid-apparmor-usability and security-lucid-apparmor-abstractions, both 'high' [18:20] jjohansen: it's all my stuff [18:20] jjohansen: though I look forward to the ptrace fix ;) [18:20] just curious [18:20] right, that won't hit alpha2 [18:20] (that isn't blueprinted-- I'm just teasing) [18:20] well, maybe you bp'd it-- I didn't [18:21] erm, I think its a kernel work item [18:21] kees: so, yeah, marking it to high would be an option, but it is essential based on the person who suggested it [18:22] so I feel kinda stuck [18:22] (Mark said turn it on during UDS) [18:22] that came out wrong [18:23] during UDS, Mark suggested we turn the profile to enforcing [18:24] well it would be nice to have it on during alpha2 [18:24] so I wasn't sure to shuffle stuff around to essential, or to bump it down to high. the java bug is a problem though [18:24] jjohansen: I haven't had time to look at the java bug at all, but I confirmed java breaks with the profile on, but there are no denials [18:24] right, we need to look at that, is it serious enough that its not worth doing for alpha2 [18:25] jjohansen: have you seen that bug? [18:25] Anything that takes a Java upload is clearly too late for Alpha 2. [18:25] ScottK: no, not a java upload [18:25] just profile [18:25] the java plugin breaks and hangs firefox when the firefox profile is in enforcing mode [18:26] * robbiew is confused...why must we bump it down to high? is it b/c it won't make alpha2? [18:26] jdstrand: hrm [18:26] robbiew: I think the issue is that non-essential bps are blocking an essential bp [18:26] robbiew: an essential item depends on two items that are only high to be feasible [18:26] ah [18:26] ack [18:27] makes sense to lower to high then [18:27] regardless of who requested it ;) [18:27] the only other option is get the blocking bps raised [18:27] agreeded I think its to late to figure out the Java bug and get a fix in [18:27] it probably has a kernel component [18:28] I mean, I can turn it on right now, but it breaks the java plugin, and regular people won't know what is happening with other profile bugs cause there isn't good gui reporting [18:28] jjohansen: fyi, java bug is bug #484148 [18:28] Launchpad bug 484148 in firefox-3.5 "apparmor-profiles freezes Firefox when using Java applets (Sun JRE)" [Undecided,Confirmed] https://launchpad.net/bugs/484148 [18:28] I confirned it with openjdk [18:29] thanks [18:29] I'll take a look at it tomorrow [18:29] robbiew: the problem with rasing others to essential is that the the profile (excepting java) works well with Ubuntu [18:29] jdstrand: right...then I guess we have our answer ;) [18:29] lower it [18:30] lol [18:30] robbiew: but, it is known to have problem in Kubuntu, and is untested in Xubuntu [18:30] alright [18:30] can we get the QA team to do some testing? [18:31] jdstrand: I would like to have the firefox maintainer own this profile. [18:32] sure that would be nice [18:32] kees: yeah-- but, tbh, he is gone and there the replacement isn't here yet [18:32] * kees nods [18:32] just wanted to mention it. :) [18:32] kees: and, if you consider the whole of the distro, it isn't fully baked-- it works for Ubuntu, but untested in other places [18:33] there is quite a bit more that needs to be done development-wise [18:33] I mean, if someone said "hey, assign me that bp" I'd be happy to. no on ei is doing that ;) [18:34] well that is why I asked if we could get QA to do some browser testing [18:34] that would be excellent [18:35] Unfortunately this doesn't seem to be the sort of thing they do. [18:35] (not endorsing that, just saying) [18:35] yeah...but it won't hurt to ask :) [18:36] Agreed. [18:36] They might be more willing if we could automate it [18:37] I'd love an automated test for firefox-- I don't have one though (requires the time to learn the tools) [18:37] yeah [18:38] anyway, the rest of the discussion can be done outside of this meeting [18:39] I just wanted to indicate a problem with the priorities and the problems with that item in general [18:39] that is it from me [18:39] kees, robbiew: ^ [18:39] ack [18:41] anyone have any other questions for the security team? [18:42] Probably ought to think about clamav 0.94 ->0.95 soon [18:42] yeah [18:42] AFAIK all the packages in backports are in good shap. [18:42] They just need to be rebuilt against -security (clamav first and then the rdepends) [18:43] ScottK: so are you saying we are good to go with moving forward on that? [18:43] Yes [18:43] ScottK: ok-- I'll take that on [18:43] Great. [18:43] not a question, but dfa.minimization won't hit alpha2, its currently buggy [18:43] ScottK: I'll contact you soonish-- I am thinking within the next week or so I get into it fully [18:44] jdstrand: OK. I'll be around. [18:44] ScottK: thanks again for all your hard work on it :) [18:44] jjohansen: ack [18:44] Thanks. [18:44] jjohansen: that's fine. cool that it's seeing progress. :) [18:44] yeah, totally [18:45] jdstrand: BTW, cemc (who has been doing most of the testing and some of the rdepends packaging) in planning on going for Ubuntu membership soon. I hope you will endorse him. [18:45] it should hit this week, just not by tomorrow [18:45] ScottK: I'd be happy to endorse him too (worked with him on pdns-recursor) [18:45] kees: Great. [18:45] ScottK: sure, feel free to have him contact me, and I'll be sure to get him involved in this update [18:46] jdstrand: OK. Will do. [18:46] (visiably involved with me) [18:46] visibly [18:46] anything else? [18:47] Not from me. [18:47] alright then, let's adjourn [18:47] kees: ^ [18:48] agreed, thanks everyone [18:48] o/ [18:49] bye === fader_ is now known as fader|lunch === fader|lunch is now known as fader_ === starcraft is now known as starcraftman === fader_ is now known as fader|away === robbiew is now known as robbiew_