/srv/irclogs.ubuntu.com/2011/07/25/#ubuntu-meeting.txt

=== freeflyi1g is now known as freeflying
=== noy_ is now known as noy
=== lag` is now known as lag
=== bdmurray_ is now known as bdmurray
kees\o17:22
jdstrando/17:22
mdeslaurhellow!17:22
jjohansen\o17:22
* sbeattie waves17:22
jdstrandsorry I was a little late. let's get started17:22
jdstrand#startmeeting17:22
MootBotMeeting started at 12:22. The chair is jdstrand.17:22
MootBotCommands Available: [TOPIC], [IDEA], [ACTION], [AGREED], [LINK], [VOTE]17:22
jdstrandThe meeting agenda can be found at:17:23
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting17:23
MootBotLINK received:  https://wiki.ubuntu.com/SecurityTeam/Meeting17:23
jdstrand[TOPIC] Review of any previous action items17:23
MootBotNew Topic:  Review of any previous action items17:23
jdstrandwe don't have any formal ones from last week. jjohansen said he'd talk to me about dbus/apparmor, and did :)17:23
jdstrand[TOPIC] Weekly stand-up report17:23
MootBotNew Topic:  Weekly stand-up report17:23
jdstrandI'll go first17:23
jdstrandI'm an triage this week17:24
jdstrandI have several updates I am working on17:24
jdstrandI am going to attempt to get a dbus/apparmor uploaded with just the stubs for the apparmor hooks, as after talking with skaet this should make things either17:24
jdstrands/either/easier/17:24
jdstrandI've also got a couple of apparmor profiles I'd like to get uploaded (related to work items)17:25
jdstrandI have more training17:25
jdstrandand apparently am the only active archive admin on duty for the week, due to debconf17:25
jdstrandit looks to be a busy week17:25
jdstrandkees: you're next17:25
* Daviey hides RE: libvirt.17:25
keesalright, I'm on community17:26
jdstrandDaviey: I may have to just upload :( we'll talk later17:26
keesI'm trying to catch up on kernel CVEs -- it looks like mitre is very far behind, so I've got to go through oss-security to find stuff17:26
jdstrandbleck17:26
blissmitre is always behind17:26
keesbliss: this is much worse than usual17:26
keesbut regardless, yeah, they are, so I'm moving "review oss-security" up my priority list for each day :)17:27
jdstrandthey really have been for quite a few months17:27
keesat the same time, i'm working on getting a bug sync tool written to help the kernel team with bug statuses17:27
keesthat's it from me17:27
blissproc commander out17:28
mdeslaurlol17:28
* kees threatens bliss ;)17:28
blisssorry, don't mean to be disruptive :-)17:28
jdstrandhehe17:29
keesnah, that was for 'proc commander' :) anyway, mdeslaur is up17:29
* jdstrand loves 'proc commander', fwiw :)17:29
mdeslaurthis week, I'm in the happy place17:29
mdeslaurI've just published freetype updates, and am currently working on libpng17:29
mdeslauram also working on an embargoed issue17:29
mdeslaurand will further go down the list17:30
mdeslaurfriday, I'm on patch piloting17:30
mdeslaur(different than being the proc commander)17:30
mdeslaurthat's it from me17:30
mdeslaursbeattie: you're up17:30
sbeattieI'm also in the happy place this week, after being on community last week.17:30
sbeattieI've got an icedtea-web/openjdk update I'm working on.17:31
sbeattieAfter that, I'm going to try to catch up on my apparmor work items.17:32
sbeattiethat's it for me; micahg?17:32
micahgI'm working on webkit in various forms and associated CVE cleanup, chromium is a little late on their 6 week release train, so I expect a release relatively soon, but have no real idea about when, so if it comes, I'll take care of that, that's it for me17:33
jdstrandthanks guys17:33
jdstrand[TOPIC] Highlighted packages17:34
MootBotNew Topic:  Highlighted packages17:34
jdstrandThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security on Freenode. The highlighted packages for this week are:17:34
jdstrand  * http://people.canonical.com/~ubuntu-security/cve/pkg/smilutils.html17:34
jdstrand  * http://people.canonical.com/~ubuntu-security/cve/pkg/ccid.html17:34
jdstrand  * http://people.canonical.com/~ubuntu-security/cve/pkg/libglpng.html17:34
jdstrand  * http://people.canonical.com/~ubuntu-security/cve/pkg/ntop.html17:34
jdstrand  * http://people.canonical.com/~ubuntu-security/cve/pkg/ziproxy.html17:34
jdstrand[TOPIC] Miscellaneous and Questions17:34
MootBotNew Topic:  Miscellaneous and Questions17:34
jdstrandI will be out of town for two weeks starting next monday (conference/holiday)17:34
jdstrandI know kees will also be out at least part of next week (conference)17:35
jdstrandDoes anyone have any other questions or items to discuss?17:35
sbeattiejdstrand: I would like to discuss the openjdk update for a second.17:35
keeswheee blackhat/defcon17:36
blisswould it be possible to devote time/effort to auditing packages identified by community members or the security team as needing a security overhaul?  ideally packages that are widely used or commonly integrated into ubuntu17:36
blissin a more coordinated way, i mean17:36
blissit just strikes me that there are several widely used packages where everyone knows they're broken, but nobody has time or interest in fixing them17:37
keesi would certain like to see something like that. do you want to do the coordination?17:37
blisssure, i'd be happy to help in whatever way i can17:37
blissanyone can get involved as well, doesn't need to just be security team17:38
jdstrandI think starting with wishlist bugs would be a good start. if there is a lot, it could be a wiki page17:38
blissyeah17:38
blissmaybe for starters, a public list of "these packages could use some auditing/hardening"17:39
jdstrandI can incorporate into the 'Highlighted package' section, if there is an easy way to incorporate it17:39
blisscool17:39
blisswe can brainstorm over the next few days/weeks, no need to draw out the meeting17:39
blissjust something that's been on my mind17:39
keesgoogle may want to get involved too17:40
blissyeah, i'd imagine17:40
blissexamples: libavcodec/libavformat, libpoppler, libfreetype17:40
jdstrandbliss: thanks. maybe this could be discussed on the mailing list (<ubuntu-hardened@lists.ubuntu.com>)17:40
jdstrand(the process, not necessarily which packages, but it could be17:40
jdstrand)17:40
jdstrandsbeattie: you wanted to discuss openjdk?17:41
blissalright, i'll flesh out some ideas and send an email17:41
jdstrandbliss: awesome, thanks :)17:41
sbeattiejdstrand: bascially, the patches that upstream shipped for icedtea 1.8.9 (used for armel/lucid,maverick) don't compile here.17:41
mdeslaursbeattie: awesome17:42
sbeattiejdstrand: the packages for the other arches and for icedtea-web built okay, I still need to test them.17:42
sbeattiejdstrand: so I thought I would approach upstream with the issue I have while releasing what I have (after testing).17:42
sbeattieand then if/when we get a fix for 1.8.9, release those as a -2 update.17:43
sbeattiedoes that sound reasonable?17:43
jdstrandyeah, sounds very reasonable. iirc, in the past we have published a -2 for openjdk for other things (building as I recall)17:44
sbeattieright.17:44
sbeattieokay thanks.17:44
jdstrandanything else?17:45
jdstrandok. thanks everyone! :)17:46
jdstrand#endmeeting17:46
MootBotMeeting finished at 12:46.17:46
keesthanks jdstrand!17:46
mdeslaurthanks jdstrand!17:46
micahgthanks jdstrand17:47
sbeattiejdstrand: thanks!17:47
=== Ursinha is now known as Ursinha-lunch
=== maxforti_ is now known as maxforti
=== yofel_ is now known as yofel
=== Ursinha-lunch is now known as Ursinha
=== ^aL-ITAngel^ is now known as ^Zen-hoOb-bit

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!