jdstrandalright, let's get started17:22
* sbeattie waves17:22
jdstrandThe meeting agenda can be found at:17:22
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting17:22
jdstrand[TOPIC] Review of any previous action items17:22
jdstrandI contacted xorg-security@ list and would be good if members of the ubuntu-security joined that list17:23
jdstrandI followed up and security@ubuntu.com should now be joined17:23
jdstrandI don't think there are any other action items17:24
jdstrand[TOPIC] Weekly stand-up report17:24
jdstrandkees is on holiday today. I am not sure everything he has planned, but he is triager for the week, and I noticed kernels are getting ready for publication17:25
jdstrandas for me, I'm in the happy place17:25
jdstrandI am working on several updates (libvirt, openldap and dbus-glib)17:25
jdstrandI've still not followed up on the bunch of little bugs I keep talking about, but need to do that (esp for ufw) before Thursday, which is the freeze for beta17:26
jdstrandI should be looking into Blackhat registration17:26
jdstrandas well as archive admin work for Beta17:27
jdstrandthat should be it for me17:27
jdstrandmdeslaur: you're up17:27
mdeslaurI'm on happy place this week, but since kees is triager and on holiday, I'll pick up the triager role17:27
mdeslaurI'm currently working on php5 and subversion, and will pick up a couple of more things to work on this week17:28
mdeslaurThat's it from me17:28
jdstrandmdeslaur: fyi, I think he'll be on at least Tue and Wed...17:28
jdstrandmdeslaur: thanks17:28
jdstrandsbeattie: you're next17:28
mdeslaurjdstrand: oh? ok...I'll triage whenever he's not here17:28
sbeattieI covered mdeslaur's triage last week, I guess I'm on community this week...17:29
* jdstrand nods17:29
jdstrandI think mdeslaur updated the /topic for that17:29
jdstrandsbeattie: btw, I uploaded the security fake sync for libcgroup this morning, so you don't have to worry about that17:30
sbeattiejdstrand: cool, thanks.17:30
mdeslaurI just put whatever I thought the next rotation was, but if that's not appropriate, we can change it17:30
jdstrandthat feels appropriate to me...17:30
sbeattieright, I'd thought this week was my regular triage week.17:30
sbeattiebut, whatever works.17:30
sbeattieanyway, published krb5 and the armel openjdk (huzzah, finally) last week.17:31
sbeattieI pushed up an apparmor 2.6.1 release candidate this morning, and want to release the final version this week (it's a small set of fixes over 2.6.0)17:32
sbeattieIn particular, mod_apparmor is broken in natty17:33
sbeattiewill also submit a merge to fix for natty before beta freeze17:33
jdstrandsbeattie: are you planning to package that for natty before beta?17:33
jjohansensmall but important fixes17:33
jdstrandsbeattie: I fixed via non-variable the multiarch stuff so natty wasn't broken, but we should make a decision on what to do there17:34
jdstrand(as upstream)17:34
jdstrandthen merge that into the update17:34
sbeattieright, I saw that, but haven't thought about it carefully.17:34
* jdstrand either17:34
sbeattieanyway, I'll probably try to pick up another update this week17:35
sbeattieand I think that's it for me.17:35
jdstrandmicahg: you're up17:36
micahgsorry, I apparently was thought I was here before, but wasn't17:36
micahggoing through webkit CVEs, then will prepare uploads for karmic-maverick17:37
micahgguessing there will be a chromium update we need later this week...17:37
micahgwe dodged 2 already :)17:38
micahgnext round of mozilla updates hopefully not until Apr 1917:38
* jdstrand nods17:39
micahgI'm worried about xulrunner-1.9.2 in natty since it will be unsupportable, so I might look and see what I can do there after webkit is done (probably not this week)17:39
micahgand I haven't piloted yet, so that will be sometime before the end of the month17:40
micahgI think that's it17:40
jdstrandmicahg: re xul> sounds reasonable-- please coordinate/share load with chrisccoulson17:40
micahgjdstrand: will do17:41
chrisccoulsonat this moment in time, i think that xul-2.0 is more unsupportable ;)17:41
micahgchrisccoulson: we need to chat about that in a bit :)17:41
chrisccoulsonfrom the ML discussion upstream, it is only going to be supported until ff-5.0 is released17:41
chrisccoulsonwhich will be 3 months ;)17:41
chrisccoulsonor 417:42
micahgchrisccoulson: and 1.9.2 will probably be dropped next month ;)17:42
jdstrandI'll let you two duke that out outside of this meeting17:42
chrisccoulsonkill it17:42
chrisccoulsoni'm wasting far too much time on a load of crappy applications i never use ;)17:42
jdstrandseriously, it is turning into an internal dependency these days...17:42
jdstrandwhy not just embrace it :)17:43
jdstrandmicahg: thanks17:43
jdstrand[TOPIC] Miscellaneous and Questions17:43
jdstrandfirst up, self-eval part of performance reviews are due by the 25th. I ask that you have them done by the 24th if possible so I can look at them17:44
jdstrand(I need to countersign them, etc, and would rather not be trying to fix problems on friday after HR went home)17:45
jdstrandalso, I wanted to mention oss-security@17:46
jdstrandI'm not sure how others are dealing with it, but I have personally not been looking at it extremely closely. I think that is wrong17:46
jdstrandesp with the demise of vsec17:46
jdstrandwrong because I noticed that mitre has been quite slow recently, and people are releasing things before CVEs are in our tracker17:47
jdstrands/people/other distros/17:47
jdstrandso, please keep oss-security@ in mind when triager17:47
jdstrandI don't have anything else17:48
jdstrandjjohansen: is there anything you'd like to bring up for us to help with?17:49
jdstrand(or anything else)17:49
jjohansenhrmm, nothing I can think of atm17:50
jdstrandI think that is a wrap then17:50
jdstrandthanks everyone!17:50
micahgthanks jdstrand17:50
