/srv/irclogs.ubuntu.com/2012/07/23/#ubuntu-meeting.txt

=== shadeslayer is now known as shadeslayer_
=== shadeslayer_ is now known as shadeslayer
=== raju is now known as genupulas
=== yofel_ is now known as yofel
=== shadeslayer is now known as shadeslayer_
=== shadeslayer_ is now known as shadeslayer
=== noy_ is now known as noy
jdstrandhi!18:02
mdeslaur\o18:02
mdeslauro/18:02
mdeslaur\o18:02
mdeslauro/18:02
jdstrand#startmeeting18:02
meetingologyMeeting started Mon Jul 23 18:02:29 2012 UTC.  The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology.18:02
meetingologyAvailable commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired18:02
jdstrandThe meeting agenda can be found at:18:02
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting18:02
jdstrand[TOPIC] Weekly stand-up report18:02
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
jdstrandI'll go first18:02
jdstrandI will actually not have a short week this week :)18:03
jdstrandI'm on communuity18:03
jdstrandam patch piloting today18:03
jdstrandhave some pending updates18:03
jdstrandand will be reviewing webkit maintenance a bit18:03
jdstrandmdeslaur: you're up18:03
mdeslaurI'm in the happy place this week18:04
mdeslaurI've got a libexif update coming out in a few minutes18:04
mdeslaurand have an embargoed issue (or two) that I need to work on this week18:04
mdeslaurand I've worked on "uvt", the python replacement for vmtools18:04
sbeattie\o/18:04
mdeslaurI still have a couple of commands to implement before marking off the work item18:04
mdeslaurI should be done with them today or tomorrow18:05
mdeslaurand after that, I'll pick some CVEs in the list18:05
mdeslaurwe have a _lot_ of open CVEs, so we need to be picking stuff up18:05
mdeslaurthat's it from me18:05
mdeslaursbeattie: you're up18:05
sbeattieI'm in the happy place this week18:05
sbeattieI've currently working on an embargoed issue18:06
sbeattieI'm also poking at a possible regression from the openjdk backports I did around JNI in lucid (LP: #1027122)18:06
sbeattiejjohansen handed me what he had for dbus/apparmor, so I'll be poking at that as well18:07
sbeattieotherwise, I'll try to pick up a CVE or two as well18:07
sbeattiethat's all I've got; micahg, you're up18:08
micahgThis week I'm starting the staged rollout of webkit updates to the stable releases, tomorrow, precise-proposed will get 1.8.1 and if there aren't any significant increases in crashes, I'll push that to everyone late Thursday (or Monday if people think that's better)18:09
jdstrand\o/18:09
micahgwith the rest of the releases hopefully getting to their respective -proposed repo by the end of next week18:09
* jdstrand guesses monday would be best. it is already late so don't cause potential extra work over the weekend18:10
micahgok18:10
micahgthat's basically it aside from watching for any issues with the Mozilla updates (have been skimming the bugmail to notify tyhicks if need be), all seems fine18:12
jdstrandtyhicks: you're up18:12
micahgoh, right, and trying to process all the mail about thunderbird's future, I hope to have something drafted over the next week or 218:13
micahgjdstrand: he's off today :)18:13
jdstrandah18:13
jdstrandjjohansen: you're up18:13
jdstrandtyhicks: nm18:13
jdstrandbzr diff18:13
jdstrandmeh18:13
jjohansenso I need to finish getting dbus stuff to sbeattie, I actually didn't give him the kernel bits yet, and the parser bits don't apply (though I may let him have a crack at fixing that)18:14
jjohansenI have some more kernel QRT fallout to look at this week, not sure what it is yet just saw the request (/me is suspecting more arm failures)18:15
* jjohansen needs to finish up on the rcu locking rework to fix deadlocking issues in the current apparmor patchset so I can push those out to the list18:16
jdstrandjjohansen: is that due to upstream churn?18:17
* jdstrand assumes so18:18
jjohansenjdstrand: no, its due to us doing more and being forced to do GFP_KERNEL allocations indirectly in places where locks are held.  This can cause sleeping at those points but with the way our locking works and the LSM hooks this effectively blocks all execs and several other operations causing system deadlocks18:18
jdstrandjjohansen: oh, so this affects current kernels?18:19
jjohansenjdstrand: no just the dev stuff18:19
jdstrandjjohansen: part of getting rid of the compat work?18:19
jjohansenjdstrand: not just the compat, its needed for stacking and labeling too18:20
jdstrandok18:20
jdstrandjjohansen: anything else?18:20
jjohansenbasically an extra prereq18:20
jjohansenhrmm well I plan to review the R stuff floated on the list18:21
jjohansenoh and I have some 3.5 testing18:21
* jjohansen pushed the compat patches for 3.5 but hasn't actually built or tested against upstream 3.518:22
jjohansenbut that is minor18:22
jjohansenjdstrand: thats it back to you18:22
jdstrandthanks18:22
jdstrand[TOPIC] Highlighted packages18:22
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
jdstrandThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.18:22
jdstrandSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.18:22
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/nusoap.html18:22
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/phppgadmin.html18:23
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/libfile-temp-perl.html18:23
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/mplayer2.html18:23
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/tangerine.html18:23
jdstrand[TOPIC] Miscellaneous and Questions18:24
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
jdstrandThere are a lot of merge opportunities for packages listed in http://people.canonical.com/~ubuntu-security/d2u/. Performing these updates is a great way to help Ubuntu and bolster your developer application.18:24
jdstrandDoes anyone have any other questions or items to discuss?18:24
jdstrandmdeslaur, sbeattie, micahg, jjohansen: thanks18:32
jdstrand#endmeeting18:32
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Jul 23 18:32:58 2012 UTC.18:32
meetingologyMinutes (wiki):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-07-23-18.02.moin.txt18:32
meetingologyMinutes (html):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-07-23-18.02.html18:32
jjohansenthanks jdstrand18:33
mdeslaurthanks jdstrand18:33
micahgthanks jdstrand18:33
sbeattiethanks18:33
* kees waves20:59
* stgraber waves20:59
* kees looks around for mdz21:11
mdzsorry, I thought I was in -meeting but I was only in -devel21:13
mdzwho's here for TB?21:13
keeso/21:13
* stgraber waves21:13
mdz#startmeeting21:14
meetingologyMeeting started Mon Jul 23 21:14:27 2012 UTC.  The chair is mdz. Information about MeetBot at http://wiki.ubuntu.com/meetingology.21:14
meetingologyAvailable commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired21:14
mdz#link https://wiki.ubuntu.com/TechnicalBoardAgenda21:14
mdzhttps://wiki.ubuntu.com/TechnicalBoardAgenda21:14
mdz#topic Action review21:14
=== meetingology changed the topic of #ubuntu-meeting to: Action review
mdzsoren to continue brainstorm review21:14
mdzI have no idea about this and soren doesn't seem to be around. anyone know?21:15
mdzkees to ping LP advocate about LP: #25236821:15
keessoren's task: I haven't seen any email about it, so I assume it's continuing21:15
keesI've asked, and it's in limbo.21:15
keesthere doesn't seem to be a sensible way to unlimbo it, either.21:15
keesalready advocated bugs aren't seeing any attention, so it's unlikely this one will either.21:15
mdzso you asked the advocate about it, and they said there's nothing they can do?21:16
keesbasically, yes.21:16
mdzthat sounds...less than ideal21:16
mdzis there an escalation path?21:17
keesthe LP team says that to fix bugs, people should do it themselves.21:17
keesthat's not clear.21:17
keesI'll continue the discussion.21:17
mdzI could raise it with debian-derivatives21:18
keesthat might work too21:18
mdzI'm not sure what the barrier to entry is like these days for LP development21:18
mdzbut this sounds pretty non-trivial to implement21:18
keesyeah21:18
keessounds like LP development has stopped?21:18
keeseven the stakeholders don't know where to escalate to.21:19
mdzI'll send an email about it21:19
mdzbut it sounds like there's no next action for this particular bug21:19
stgraberyeah, LP is in maintenance-only mode... any feature work should be done outside of the LP team, though one LP squad is usually available for code reviews and helping people contribute21:19
DavieyIs this really a pressing matter ?21:19
mdzkees, can you put a comment on the bug with the latest update?21:20
keessure21:20
mdzDaviey, it is pressing enough to warrant some action within 4 years :-)21:20
mdzits 4th anniversary is coming up21:20
DavieyIt seems to me that the barrier of creating a LP account is so low, that the bother to implement this is crazy use of resources.21:20
mdzDaviey, that would be a reasonable position for the Launchpad project to take21:21
mdzand if they took that position, I think we would probably accept it21:21
mdzbut that's a different thing from just letting the request sit21:21
mdzanyway, moving on21:22
Davieyright21:22
mdz#topic Mythbuntu LTS21:22
=== meetingology changed the topic of #ubuntu-meeting to: Mythbuntu LTS
mdzit looks like this got three +1s on the mailing list21:22
mdzand no opposition21:22
Davieyflacoste,mrevell or cztab is probably the escalation path,21:22
mdzso I think it's done21:22
mdzI'm not sure who put it on the agenda21:23
mdzI think it just needs a rubber stamp21:23
czajkowskiDaviey: sup21:23
mdzunless anyone disagrees, I'll follow up to the mailing list and stamp it21:23
mdzczajkowski, do you have a highlight for cztab? :-)21:23
mdzkees, stgraber, you OK with that?21:23
czajkowskimdz: oddly enough I do :)21:24
stgrabermdz: I'm fine with that21:24
mdzok21:24
mdz#topic MRE request for VLC (bdrung)21:24
=== meetingology changed the topic of #ubuntu-meeting to: MRE request for VLC (bdrung)
mdzbdrung, hi21:25
kees(/me is fine too)21:25
ScottKDaviey: When it's come up, it was important to a number of DD's.  It's socially important in our relationships with our primary upstream.  Technically less so.21:25
ScottK(sorry, missed the discussion earlier)21:25
mdzbdrung, are you there?21:26
mdzwe'll skip ahead21:26
mdz#topic Mesa provisional MRE21:26
=== meetingology changed the topic of #ubuntu-meeting to: Mesa provisional MRE
mdz#link https://lists.ubuntu.com/archives/technical-board/2012-July/001352.html21:26
mdzthis is from RAOF21:27
bdrungmdz: hi21:27
mdzbdrung, hi, we'll come back to your topic in a moment21:27
mdzkees, stgraber, thoughts on the Mesa request?21:28
keesif piglet can get run on several HW types, I'd be happy with the MRE21:28
kees(run and pass, that is)21:28
stgraberquickly reading the e-mail again, I remember thinking it was a reasonable testing plan21:28
mdzyes, I think the important thing is that the regression test suite passes, and running it in the proper environment (where that's not the buildd) is a no-brainer21:29
mdzOK, I'll follow up and ack it21:29
mdz#topic  MRE request for VLC (bdrung)21:30
=== meetingology changed the topic of #ubuntu-meeting to: MRE request for VLC (bdrung)
stgraberright, +1 from me with the plan that the regression test runs on all the hardware combination in the lab21:30
mdzbdrung, go ahead21:30
bdrungVLC has a maintenance branch (currently 2.0.x) where they mainly apply bug fixes21:30
bdrungi like to get a MRE that allows getting new 2.0.x versions into precise21:31
mdzbdrung, what's the regression testing story?21:32
bdrungthe 2.0.2 release closes 9 Launchpad bugs and many more bugs that were not reported on Launchpad21:32
keeswow, 9.21:32
bdrungkees: IIRC the 1.1.0 release held the record21:33
keesI bet :)21:33
bdrungmdz: the good story: we have a daily PPA for the upstream maintenance branch21:34
bdrungthe bad story: the package has a test suite that is currently not run on compile time (it succeeds locally, but one test fails in the chroot)21:34
bdrungthe test suite is very small and does not cover much of the program21:35
keescan that test be removed from the suite for the builds? it would be nice to have those tests work in the build21:35
keesoh21:35
mdzis the failure a regression, or has it failed before?21:35
mdzah21:35
mdzso the test suite is not very relevant21:35
mdzbdrung, you mentioned the branch includes "mainly" bug fixes...how "mainly"? :-)21:36
mdzan MRE would usually imply that their policy is at least as strict as ours21:36
bdrungupstream makes sure that they keep their ABI stable in their maintenance branch21:37
bdrungthey apply bug fixes, update translations, add new translations21:38
keesthat seems fine21:39
mdzyes21:39
bdrungtheir NEWS files only states fixes21:39
mdzbdrung, has it been SRUd many times before?21:39
bdrungthe updated libraries and Mac OS changes are irrelevant for us21:40
bdrungmdz: at least once21:40
mdzwhat's the rationale for a standing exception, as opposed to just doing an SRU for 2.0.2?21:40
bdrungthe maintenance branch get security fixes too and it will fix more bugs21:41
keesseems like a win to me. have there been reports of regressions in past SRUs?21:42
bdrungi like to get all 2.0.x releases into precise to have a version with no security hole and less bugs21:42
bdrungkees: i can't remember a regression21:43
mdzwithout a regression testing plan/suite, there is certainly a higher risk of regressions21:43
mdzbut the impact of a regression in vlc is smaller than in many other packages21:43
mdzsuch as, say, Mesa :-)21:43
keesright21:43
bdrungoh wait. there was a pulseaudio output plugin change that causes some trouble21:43
bdrungthis change revealed some pulseaudio/driver bugs IIRC21:44
mdzwere we able to fix the regression promptly?21:44
mdzor did we have to roll back the whole thing?21:45
bdrungi think it was bug #80580721:46
ubottuLaunchpad bug 805807 in vlc (Ubuntu Natty) "Sound is not synchronised with the video" [Undecided,Confirmed] https://launchpad.net/bugs/80580721:46
mdzthat looks like it's...still open in natty?21:48
mdzdid we regress it and then not fix  the regression?21:48
bdrungno, it was an upstream regression from one release to another.21:49
mdzI don't follow21:50
bdrungthe initial problem was bug #74332321:51
ubottuLaunchpad bug 743323 in vlc (Ubuntu Natty) "vlc memory leak" [High,Fix released] https://launchpad.net/bugs/74332321:51
mdzthe bug reads like a regression in a stable update21:51
mdzso far it seems like in favor we have: relatively low impact package, bugfix-only branch21:52
bdrungyes, seems so21:52
mdzand against: not much in the way of regression testing21:53
mdzstgraber, kees, thoughts?21:53
keesI would be happy to grant a provisional MRE21:53
bdrungthe pulseaudio plugin was rewritten to fix the memory leak, introduces a regression and was later fixed21:53
keesif the regression stuff repeats, then I'm not sure we can safely do MREs on VLC, even though it fixes so much stuff21:53
keesand if regressions do get fixed, that's a good sign.21:54
stgraberprovisional sounds reasonable, we can see how ti goes after we get one or two upstream point release in. If we get any regression, we might have to consider more QA before pushing something to updates21:54
mdzif I were considering whether it makes sense to SRU 2.0.2, I would probably say yes, go for it, and if it regresses, we can just roll it back21:54
mdzbut since I'm supposed to consider whether it should get a standing exception, I'm not so sure21:54
bdrung1.1.10 contained the fix and 1.1.12 fixes the regressions21:55
Davieywow. push something out, and roll back if it regresses? O_o21:55
DavieyAs an emergency, great.. but as a /plan/?21:55
mdzDaviey, I'm open to other opinions21:56
mdzbut I don't think it makes sense to apply a blanket approach to all packages21:56
mdzthe fallout from regressions is very severe in some cases, and very little in others21:57
mdzif the sound in VLC is out of sync for a few days, that's a pretty limited impact21:57
mdzcompared to, say, a graphics driver hang21:57
bdrungi got two bug reports against the daily-stable PPA package that i could fix (otherwise these bugs could have entered the archive later)21:57
mdzmy only other idea would be to come up with a manual regression testing plan21:58
mdzwhich covers the most common/important functionality21:58
mdzplay some streams in various formats, check that it works as expected, that sort of thing21:58
bdrungi do test the package with some video files, but that do not cover much of vlc21:59
mdzinteresting that it didn't catch the audio sync issue21:59
bdrungit was connected to the underlying hardware21:59
mdzah21:59
bdrungonly some soundcards triggered it22:00
mdzthe policy is that a provisional MRE can be approved by any TB member22:01
mdzand two have expressed support, so I think there's nothing more to discuss on this specific request22:01
bdrungwhat should be done if a new upstream release fixes security bugs?22:01
mdzI defer to the security team on that22:02
mdzanything else on this topic before we move on? we're out of time22:02
bdrungget it SRUed and then copied to -security or a separate fix for -security?22:02
ScottKbdrung: IME ask the security team and they'll tell you.22:02
bdrungk22:02
mdz#topic stable updates exception policy22:02
=== meetingology changed the topic of #ubuntu-meeting to: stable updates exception policy
LordOfTimebdrung:  you can ask security questions to the security team in #ubuntu-hardened if you want, they might be able to answer22:02
LordOfTime(sorry for butting in )22:02
mdzbased in part on the discussions in this meeting, I'd like to propose a small clarification22:03
mdzreplace:22:03
mdz  * regression tests are enabled in the package's build22:03
mdzwith:22:03
mdz  * regression tests are always run on the update before it is released (e.g. by being enabled in the package's build)22:03
mdzkees, stgraber, OK with that?22:03
ScottKThat's not always feasible.22:03
ScottKThere are packages that have tests that require a network.22:03
mdzScottK, it's a noop for that case22:04
mdzthis is only broadening the criteria, not restricting them further22:04
stgrabermdz: +122:04
* kees nods22:04
ScottKOK.22:04
kees+122:04
mdzdone22:04
mdz#topic closing business22:04
=== meetingology changed the topic of #ubuntu-meeting to: closing business
mdzwho's next for chair? soren?22:05
ScottKmdz: I understand now.  I read it backwards.  Thanks.22:05
=== LordOfTime is now known as TheLordOfTime
keesI think so, yes. can you email him to remind him?22:05
kees(since he's not here?)22:05
mdzwill do22:05
mdzthanks all22:05
mdz#endmeeting22:05
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Jul 23 22:05:30 2012 UTC.22:05
meetingologyMinutes (wiki):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-07-23-21.14.moin.txt22:05
meetingologyMinutes (html):        http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-07-23-21.14.html22:05
keesthanks mdz!22:05
stgraberthanks mdz!22:05
ScottKIsn't that how you always get volunteered for stuff (by missing the meeting)?22:05
TheLordOfTimemdz:  ScottK:  sorry for butting in right at the end with pointing bdrung to the security team's channel, i assumed he wanted fast answers, so i directed him there :)22:06
ScottKTheLordOfTime: Most Ubuntu developers know about that already, but he's sure to now.22:07
TheLordOfTimeScottK:  indeed, just wanted to affirm :)22:07
TheLordOfTime(in case some didnt :P)22:07
* TheLordOfTime returns to what he was originally doing, figuring out why Launchpad doesn't like him today22:08

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!