=== freeflyi1g is now known as freeflying === noy_ is now known as noy === lag` is now known as lag === bdmurray_ is now known as bdmurray [17:22] \o [17:22] o/ [17:22] hellow! [17:22] \o [17:22] * sbeattie waves [17:22] sorry I was a little late. let's get started [17:22] #startmeeting [17:22] Meeting started at 12:22. The chair is jdstrand. [17:22] Commands Available: [TOPIC], [IDEA], [ACTION], [AGREED], [LINK], [VOTE] [17:23] The meeting agenda can be found at: [17:23] [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting [17:23] LINK received: https://wiki.ubuntu.com/SecurityTeam/Meeting [17:23] [TOPIC] Review of any previous action items [17:23] New Topic: Review of any previous action items [17:23] we don't have any formal ones from last week. jjohansen said he'd talk to me about dbus/apparmor, and did :) [17:23] [TOPIC] Weekly stand-up report [17:23] New Topic: Weekly stand-up report [17:23] I'll go first [17:24] I'm an triage this week [17:24] I have several updates I am working on [17:24] I am going to attempt to get a dbus/apparmor uploaded with just the stubs for the apparmor hooks, as after talking with skaet this should make things either [17:24] s/either/easier/ [17:25] I've also got a couple of apparmor profiles I'd like to get uploaded (related to work items) [17:25] I have more training [17:25] and apparently am the only active archive admin on duty for the week, due to debconf [17:25] it looks to be a busy week [17:25] kees: you're next [17:25] * Daviey hides RE: libvirt. [17:26] alright, I'm on community [17:26] Daviey: I may have to just upload :( we'll talk later [17:26] I'm trying to catch up on kernel CVEs -- it looks like mitre is very far behind, so I've got to go through oss-security to find stuff [17:26] bleck [17:26] mitre is always behind [17:26] bliss: this is much worse than usual [17:27] but regardless, yeah, they are, so I'm moving "review oss-security" up my priority list for each day :) [17:27] they really have been for quite a few months [17:27] at the same time, i'm working on getting a bug sync tool written to help the kernel team with bug statuses [17:27] that's it from me [17:28] proc commander out [17:28] lol [17:28] * kees threatens bliss ;) [17:28] sorry, don't mean to be disruptive :-) [17:29] hehe [17:29] nah, that was for 'proc commander' :) anyway, mdeslaur is up [17:29] * jdstrand loves 'proc commander', fwiw :) [17:29] this week, I'm in the happy place [17:29] I've just published freetype updates, and am currently working on libpng [17:29] am also working on an embargoed issue [17:30] and will further go down the list [17:30] friday, I'm on patch piloting [17:30] (different than being the proc commander) [17:30] that's it from me [17:30] sbeattie: you're up [17:30] I'm also in the happy place this week, after being on community last week. [17:31] I've got an icedtea-web/openjdk update I'm working on. [17:32] After that, I'm going to try to catch up on my apparmor work items. [17:32] that's it for me; micahg? [17:33] I'm working on webkit in various forms and associated CVE cleanup, chromium is a little late on their 6 week release train, so I expect a release relatively soon, but have no real idea about when, so if it comes, I'll take care of that, that's it for me [17:33] thanks guys [17:34] [TOPIC] Highlighted packages [17:34] New Topic: Highlighted packages [17:34] The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security on Freenode. The highlighted packages for this week are: [17:34] * http://people.canonical.com/~ubuntu-security/cve/pkg/smilutils.html [17:34] * http://people.canonical.com/~ubuntu-security/cve/pkg/ccid.html [17:34] * http://people.canonical.com/~ubuntu-security/cve/pkg/libglpng.html [17:34] * http://people.canonical.com/~ubuntu-security/cve/pkg/ntop.html [17:34] * http://people.canonical.com/~ubuntu-security/cve/pkg/ziproxy.html [17:34] [TOPIC] Miscellaneous and Questions [17:34] New Topic: Miscellaneous and Questions [17:34] I will be out of town for two weeks starting next monday (conference/holiday) [17:35] I know kees will also be out at least part of next week (conference) [17:35] Does anyone have any other questions or items to discuss? [17:35] jdstrand: I would like to discuss the openjdk update for a second. [17:36] wheee blackhat/defcon [17:36] would it be possible to devote time/effort to auditing packages identified by community members or the security team as needing a security overhaul? ideally packages that are widely used or commonly integrated into ubuntu [17:36] in a more coordinated way, i mean [17:37] it just strikes me that there are several widely used packages where everyone knows they're broken, but nobody has time or interest in fixing them [17:37] i would certain like to see something like that. do you want to do the coordination? [17:37] sure, i'd be happy to help in whatever way i can [17:38] anyone can get involved as well, doesn't need to just be security team [17:38] I think starting with wishlist bugs would be a good start. if there is a lot, it could be a wiki page [17:38] yeah [17:39] maybe for starters, a public list of "these packages could use some auditing/hardening" [17:39] I can incorporate into the 'Highlighted package' section, if there is an easy way to incorporate it [17:39] cool [17:39] we can brainstorm over the next few days/weeks, no need to draw out the meeting [17:39] just something that's been on my mind [17:40] google may want to get involved too [17:40] yeah, i'd imagine [17:40] examples: libavcodec/libavformat, libpoppler, libfreetype [17:40] bliss: thanks. maybe this could be discussed on the mailing list () [17:40] (the process, not necessarily which packages, but it could be [17:40] ) [17:41] sbeattie: you wanted to discuss openjdk? [17:41] alright, i'll flesh out some ideas and send an email [17:41] bliss: awesome, thanks :) [17:41] jdstrand: bascially, the patches that upstream shipped for icedtea 1.8.9 (used for armel/lucid,maverick) don't compile here. [17:42] sbeattie: awesome [17:42] jdstrand: the packages for the other arches and for icedtea-web built okay, I still need to test them. [17:42] jdstrand: so I thought I would approach upstream with the issue I have while releasing what I have (after testing). [17:43] and then if/when we get a fix for 1.8.9, release those as a -2 update. [17:43] does that sound reasonable? [17:44] yeah, sounds very reasonable. iirc, in the past we have published a -2 for openjdk for other things (building as I recall) [17:44] right. [17:44] okay thanks. [17:45] anything else? [17:46] ok. thanks everyone! :) [17:46] #endmeeting [17:46] Meeting finished at 12:46. [17:46] thanks jdstrand! [17:46] thanks jdstrand! [17:47] thanks jdstrand [17:47] jdstrand: thanks! === Ursinha is now known as Ursinha-lunch === maxforti_ is now known as maxforti === yofel_ is now known as yofel === Ursinha-lunch is now known as Ursinha === ^aL-ITAngel^ is now known as ^Zen-hoOb-bit