/srv/irclogs.ubuntu.com/2010/10/04/#ubuntu-meeting.txt

=== yfoel is now known as yofel
=== elky` is now known as elky
=== Ursinha is now known as Ursinha-afk
=== inetpro_ is now known as inetpro
=== noy_ is now known as noy
=== rgreening_ is now known as rgreening
=== xfaf is now known as zul
=== kenvandine_ is now known as kenvandine
=== Mohan_chml is now known as IAmNotThatGuy
=== serfus is now known as shpongle
=== nixternal is now known as Guest8628
=== nixternal_ is now known as nixternal
=== jjohansen is now known as jj-afk
=== IAmNotThatGuy is now known as Mohan_chml
=== Ursinha-afk is now known as Ursinha
=== Mohan_chml is now known as IAmNotThatGuy
mdeslaurkees, jdstrand, sbeattie: meeting?18:02
keesmdeslaur: \o18:03
sbeattiemdeslaur: sure.18:05
jdstrando/18:08
* kees starts18:09
keesdid a couple security fake-syncs.18:10
keescouchdb exploded due to autoconf-hate, so I've skipped it for now on jaunty18:10
keesbeen trying to keep up with kernel CVE triage; there have been a lot lately18:10
keesthis week I'll likely spend time rebasing yama and nx-emut o natty's kernel18:11
keess/ut o/u to/18:11
keesI've got 2 things unembargoed this week as well18:11
keesand I'll be poking at maverick final testing. might even update the colo to RC18:12
keesthat's it from me18:12
mdeslaurok, my turn18:12
mdeslaurSo I'm trying to figure out a way of testing the lvm2 cluster daemon18:13
mdeslaurso I can test my lvm2 updates18:13
mdeslaurand am on triage18:13
mdeslaurI'll pick something from the list if I have time18:13
mdeslaurThat's it from me18:14
* sbeattie facepalms as he clearly can't read topic messages and thought he was on triage this week.18:14
mdeslaurlol18:15
sbeattieanyway, last week I spent some time on apparmor build issues and coping with copious gpg key changes.18:16
sbeattieI'm hoping to push out some patches to the apparmor list for review later today.18:16
sbeattiesince I'm *not* triaging, I'll try to pick up some open issues this week.18:17
sbeattieI think that's it for me, jdstrand?18:17
jdstrandI'm on community18:19
jdstrandlast week I did quite a bit of install auditing for maverick, and will continue that this week18:19
jdstrandthe rng tests are still churning away18:19
jdstrandI got back into my libvirt update and am continuing to work on it18:20
jdstrandthere is some upstream feedback that I need to tend to on libvirt not related to that update18:20
jdstrandI plan to start looking at moodle once libvirt is out the door18:20
keesoh, that reminds me, I'm happy with the dieharder results. it's got a few sensitive tests, but other than that, it looks good.18:20
jdstrandI'm not sure that will be this week or next, but that is the plan18:20
jdstrandkees: were you able to update the qrt test to be less sensitive? I saw some commits go by, but didn't look at them closely18:21
keesjdstrand: basically it came down to two specific tests complaining, so I set them to XFAIL. I didn't create anything more complex, as that seemed like overkill.18:22
jdstrandkees: sounds fine18:22
jdstrandwrt the rng tests, I'm doing collision testing and the kernel passed for both /dev/random and /dev/urandom18:23
jdstrandit is in the gnupg tests now18:23
keesexcellent18:23
jdstrandI have one item for the end of the meeting, and stefanlsd may also have something (or may not, it is up to him)18:24
jdstrandthat is it from me (until later)18:24
jdstrandwe could mention that we've all done our gpg migration18:25
keesindeed!18:25
jdstrandhttps://wiki.ubuntu.com/SecurityTeam/GPGMigration18:25
jdstrandfor those listening at home, we've tested various applications and how they deal with the new secure defaults from upstream gnupg18:26
jdstrandfor lucid and maverick18:26
jdstrandwe determined it was ok to migrate, and have instructions on what to do to migrate keys in that wiki link18:27
jdstrand(the wiki has the results of the investigations)18:27
* jdstrand is really done, until the end18:27
stefanlsdI wanted to speak about community uploaded rights to -security for unseeded, but wanted to chat to a few more people, so i'll postpone till i have more info.18:28
keessbeattie: oh, btw, can you update your reviews of mutt and gmail to use the review template?18:29
sbeattiekees: sure thing.18:29
keesjdstrand: the stuff you added about removing your old key...18:30
keesjdstrand: why not just specify a numerical id instead of email?18:30
keese.g. debsign can use an id18:30
jdstrandkees: that is indeed the recommended and first method under the NOTE18:31
keesjdstrand: right, I guess I mean, why should the other method ever be used?18:32
jdstrandkees: they only (potential) problem with that is if you have several applications to change. you might want to instead change the order of your secret keyring so they all just get the default18:32
jdstrandkees: ie, what you suggest is for every application. the 2nd method will affect all applications but is a little trickier18:33
keesjdstrand: okidoky. I found one place in umt where it was using email instead of id, and fixed that. otherwise, everything else I found uses id18:33
keesright18:33
jdstrandthe third is weird, and could be removed, but is listed for completeness18:33
keesokidoky. sounds fine; was just curious how it even came up as a need. :) sorry to derail!18:34
jdstrandI had to change quite a few things, but won't list them18:34
keesI changed it in 3 places. .devscripts .ubuntu-security-tools.conf .muttrc18:35
jdstrandkees: it came up because I kept finding stuff and wanted it to be changed in one spot rather than many18:35
* kees nods18:35
jdstrandkees: it was rather evolutionary18:35
kees4, .gnupg/gpg.conf18:35
keesanyway... you had another topic?18:35
jdstrandyes, it was for what to include in the lucid apparmor sru18:35
jdstrandI plan to perform the sru, but wanted to coordinate with jj-afk and sbeattie18:36
jdstrandjj-afk is still out, so maybe we'll discuss it in #ubuntu-hardened when he is online18:36
jdstrand(he mentioned he might pop in for the discussion)18:37
sbeattieokay.18:37
jdstrandso, that is it from me18:38
keeswill we SRU 2.5.1 final to maverick first?18:38
jdstrandkees: that is part of the discuss I think18:40
jdstranddiscussion18:40
jdstrandright now, we know we want 2.5.1, but there are also some attractive testsuite fixes in 2.5.218:40
jdstrandmaverick has most of 2.5.1 anyway, so... there is a lot to talk about :)18:41
keesheh18:41
keeswell, getting lucid onto 2.5.1 will fix the kernel instabilities too, iirc.18:42
* sbeattie was hoping someone would ack the rest of the 2.5 testsuite nominations he made. :-)18:42
jdstrandkees: but iiuc, you want to make sure that lucid isn't ahead of maverick. it won't be-- we will do a maverick SRU first, then lucid, depending on what we want18:42
keescool18:43
jdstrandkees: actually, lucid should be solid now with just the kernel updates18:43
keesjdstrand: did the kernel updates actually make it into lucid?18:43
jdstrandkees: but the userspace will still generate some invalid cache entries, but the kernel dtrt18:43
keesbug 581525 seems to indicate lucid's kernel updates never happened.18:43
ubottuLaunchpad bug 581525 in linux (Ubuntu Lucid) "Lucid: system becomes unstable randomly, seems related with apparmor" [Undecided,In progress] https://launchpad.net/bugs/58152518:43
jdstrandkees: that is a good question. I thought so... we need to follow up with jj-afk18:44
jdstrandoh, indeed18:44
jdstrandhrm18:44
keesthat's why I was hoping to get the lucid SRU sooner rather than later; that problem has been languishing18:44
jdstrandwell, we need that in lucid regardless. the apparmor userspace would help avoid it, but we really want the kernel side18:44
keessure, yeah18:45
keesokay, anyone have anything else for the security team?18:45
jdstrandkees: I was not suggesting 2.5.2 for lucid. I was wanting to identify what we want from 2.5.2 if anything, pull it in and then push18:45
jdstrandsorry if I was unclear18:45
jdstrandI would like to see the sru done by the end of the month18:46
keescool18:46
jdstrandshall we call it a meeting?18:49
keesyawp, all done. thanks everyone!19:01
jdstrandthanks kees! :)19:09
=== txwikinger is now known as txwikinger_on_gn
=== txwikinger_on_gn is now known as txwikinger
=== Claudinux_ is now known as Claudinux
=== yofel_ is now known as yofel

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!