=== emma is now known as em === JanC_ is now known as JanC === Quintasan_ is now known as Quintasan === yofel_ is now known as yofel === Avishek12 is now known as 92AABBCCG [14:58] balloons: http://sdrv.ms/ROS6Cz === Riddelll is now known as Riddell [17:54] beuno: hello [18:13] \o [18:13] o/ [18:13] hi! [18:13] #startmeeting [18:13] Meeting started Mon Aug 6 18:13:28 2012 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [18:13] Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired [18:13] The meeting agenda can be found at: [18:13] [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting [18:13] [TOPIC] Announcements === meetingology changed the topic of #ubuntu-meeting to: Announcements [18:14] Thanks to the following individuals: [18:14] Felix Geyer (debfx) provided debdiffs for oneiric-precise for ruby-actionpack-2.3 (LP: #1030984) [18:14] Mike !McClurg (mike-mcclurg) provided a debdiff for precise for xen-api (LP: #1031375) [18:14] Your work is very much appreciated and will keep Ubuntu users secure. Great job! :) [18:14] [TOPIC] Weekly stand-up report === meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report [18:14] I'll go first [18:15] so, I spent a *lot* of time on webkit and kde/archive admin stuff last week [18:15] the former is mostly done, but I need to follow up with some discussions, etc [18:16] the latter is done for now. There is more that can be done, but I don't have the stamina to do it atm [18:16] :-) [18:16] I'm in the happy place [18:17] I have a couple of MIR audits left, then after that, recruiting and back to pending updates [18:17] mdeslaur: you're up [18:17] I'm on community this week [18:17] just published the nvidia driver updates [18:17] and now I'm looking at koffice and uhm... [18:18] what's it called [18:18] calligra? [18:18] tomorrow, I'll be working on openoffice and libreoffice [18:18] and will try and get to libxml too [18:18] that's it for me [18:18] tyhicks: you're up [18:18] mdeslaur: thanks again for working on that mvidia issue [18:18] nvidia [18:19] * micahg wonders where he went [18:19] np [18:19] micahg: go ahead [18:19] hehe, I wasn't sure who was usually after steve [18:19] sorry for aggravating your OCD :) [18:19] * jdstrand allows goes with longevity on team [18:19] I'm still working on webkit, hopefully will see the light at the end of the tunnel soon, I'm also SRUing a regression fix from the icedtea-web in natty/oneiric for sbeattie [18:19] that is the only way I can keep it straight :) [18:20] as well as the standard mozilla pretesting of the week [18:20] I think that's it for me [18:20] I'm covering triage this week for steve [18:21] My focus will be on updates and working a new eCryptfs data corruption bug [18:22] :\ how widespread is that? [18:22] It is intermittent and only happens when downloading really large files, so it will be a fun one :/ [18:22] How large is really large? [18:22] ScottK: I've only reproduced it with > 3G files [18:22] OK. [18:22] jdstrand: Not too widespread. I've only seen one report on it. [18:23] The concerned eCryptfs user sits back down. [18:23] It is very subtle, too. Only one or two bytes changed in the corrupted file. [18:23] (at least in the couple times that I was able to reproduce it) [18:23] tyhicks: what bug # is that? [18:23] * tyhicks looks [18:23] tyhicks: let's talk outside of the meeting on how you are reproducing [18:24] bug 1027450 [18:24] Launchpad bug 1027450 in eCryptfs "File corruption in ecryptfs folder" [High,Incomplete] https://launchpad.net/bugs/1027450 [18:24] jdstrand: ack [18:24] That's it for me [18:25] jjohansen: you're up [18:25] I guess I'm up [18:25] I've got a couple of apparmor bugs to look into, cboltz's profile cache failing reported on the ml, and a no new privs issue from hallyn, [18:25] While I am at the no new privs issue, I'll also look into how to deal with that in stacking, it may require us to carry some information in the stack [18:25] I've got a qrt kernel security failure to finishing looking into [18:25] beyond that I'll be pushing out the 3rd iteration of the current patchset with the locking rework, and might include some of the perm remapping, profile hashing and stacking patches with it [18:26] jdstrand: back to you [18:27] [TOPIC] Highlighted packages === meetingology changed the topic of #ubuntu-meeting to: Highlighted packages [18:27] http://people.canonical.com/~ubuntu-security/cve/pkg/syscp.html [18:27] http://people.canonical.com/~ubuntu-security/cve/pkg/libhtml-template-pro-perl.html [18:27] http://people.canonical.com/~ubuntu-security/cve/pkg/network-manager-openvpn.html [18:27] http://people.canonical.com/~ubuntu-security/cve/pkg/gridengine.html [18:27] http://people.canonical.com/~ubuntu-security/cve/pkg/ncpfs.html [18:27] The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. [18:28] See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. [18:28] I pasted the highlighted packages above [18:28] [TOPIC] Miscellaneous and Questions === meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions [18:28] There are a lot of merge opportunities for packages listed in http://people.canonical.com/~ubuntu-security/d2u/. Performing these updates is a great way to help Ubuntu and bolster your developer application. [18:28] Does anyone have any other questions or items to discuss? [18:28] \o [18:28] ScottK: go ahead [18:29] The Calligra/KOffice issue is in an embedded copy of wv2. [18:29] We also have a packaged wv2 that's significantly older. [18:29] The code in the area of the fix is superficially similar, but the package doesn't build with the patch. [18:30] I was wondering if when you're looking at Calligra/KOffice you might have a glance at wv2 and see if you think it's also relevant to it. [18:30] .. [18:30] it did look relevant at first glance === Zic_ is now known as Guest89846 [18:30] (I was in a rush on saturday and heaved an updated wv2 at quantal. [18:31] It FTBFS. [18:31] scottK: that looks like a gcc-4.7 failure [18:31] OK. [18:31] Thanks. [18:31] I'll see if I can find someone to help me with it. [18:32] (that or remove the package, there aren't any users for the lib and it's dead upstream other than the embedded on in Calligra. === Guest89846 is now known as Zic [18:33] ScottK: thanks [18:34] any other questions or items to discuss? [18:38] mdeslaur, micahg, tyhicks, jjohansen, ScottK: thanks! [18:38] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [18:38] Meeting ended Mon Aug 6 18:38:06 2012 UTC. [18:38] Minutes (wiki): http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-08-06-18.13.moin.txt [18:38] Minutes (html): http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-08-06-18.13.html [18:38] thanks jdstrand [18:38] thanks jdstrand! === funkyHat_ is now known as funkyHat [18:39] thanks jdstrand === pleia2_ is now known as pleia2 === YoBoY` is now known as YoBoY [20:55] \o [20:58] * stgraber waves [20:59] o/ [21:00] #startmeeting [21:00] Meeting started Mon Aug 6 21:00:27 2012 UTC. The chair is soren. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [21:00] Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired [21:00] Short agenda today: [21:00] #link https://wiki.ubuntu.com/TechnicalBoardAgenda [21:01] pitti seems to be on holiday [21:01] here [21:01] boring agenda [21:01] I haven't seen apologies from anyone else. [21:01] #topic Action review === meetingology changed the topic of #ubuntu-meeting to: Action review [21:02] Soren: Brainstorm review [21:02] No progress. Vacation and conferences and whatnot. :( [21:02] #action Soren to finish brainstorm review [21:02] ACTION: Soren to finish brainstorm review [21:02] Anything else? Meetbot isn't very helpful from last meeting. [21:03] Guess not. [21:03] Gah, laggy connection. Crappy timing. [21:03] anything in IRC logs? [21:03] Sorry guys. [21:04] * cjwatson has a quick look [21:04] There's the thing abut gut 252368 [21:04] gut? bug! [21:04] bug 252368 [21:04] Launchpad bug 252368 in Launchpad itself "Automatically associate DD and DM accounts with GPG keys in keyring packages to allow DDs to use the Launchpad Email interface" [Low,Triaged] https://launchpad.net/bugs/252368 [21:04] It seems mdz was to follow up to the mailing list. [21:05] IMO this is low priority and we should stop caring [21:05] I didn't [21:05] OK with me [21:05] I can't understand why we're continuing to worry about it; there are many other more important things to do on LP [21:05] Alright. Officially intentionally not going to carry this over. [21:06] I know we've been asked about it and there is some social importance to it [21:06] But there are lots of other things in a similar position [21:06] * cjwatson skim-reading last fortnight's logs [21:06] I see no other action items [21:07] Moving on [21:07] I don't see anything else carried over either [21:07] #topic MRE for point release mythtv in LTS === meetingology changed the topic of #ubuntu-meeting to: MRE for point release mythtv in LTS [21:07] https://lists.ubuntu.com/archives/technical-board/2012-August/001357.html [21:07] It wasn't added to the agenda, but I guess we can still discuss it. [21:08] Is anyone here to represent this topic? [21:08] I've been pretty happy with the process (I use MythTV myself). [21:08] yeah, would be good to have this approved or rejected soon as they want to update mythtv for the 12.04.1 point release which is getting really close [21:08] I've found upstream to be good about doing fixes only. [21:09] I would be happy to approve a provisional MRE; though it would be nice if they had some kind of test suite. [21:09] superm1: Just in time :) [21:09] hey superm1 [21:09] hi folks [21:09] superm1: we're discussing your MRE request at the moment [21:10] do you know what kind of testing is done upstream for their stable release? do they have any kind of automated testing or strong manual testing prior to release? [21:10] (/msg'ed relevant scrollback) [21:10] stgraber: yeah soren just shared with the scrollback, thanks soren [21:10] np [21:10] stgraber: they have automated build testing, but other than that it's strong manual testing prior to point releases [21:11] they heavily push the community to use their stable branch at all times when a problem comes up [21:11] Do they have multiple branches, so this is a maintenance branch while there's another one where the dev focus is? [21:12] yes [21:12] they have a fixes branch for every major release [21:12] and a master branch for development [21:12] no new features come to the fixes branch for any of the releases for any reason, it's solely bug fixes [21:13] How long are these branches usually maintained? [21:13] up until the next major release [21:13] Is that time-based? [21:13] they're moving to time based now i believe [21:13] they were previously feature based (it'll be done when it's done) [21:14] but they're pushing features out for later releases if they're not going to be ready in time, and doing development in topic branches to merge [21:14] Cool. [21:15] I don't have any other questions. [21:15] Anyone else? [21:15] and to be clear, this is just for asking for the micro releases of the 0.25 release (which only one is expected), i don't think it will be appropriate to push to 0.26 ever to -updates, only maybe -backports [21:16] Oh, one more thing: [21:17] Is this just a single source package or do we need a list somewhere? [21:17] It sounds reasonable enough to me [21:17] single source package [21:17] it used to be multiple source packages, but was a mess to sync up with archive skew [21:18] Cool. [21:18] Alright. [21:18] #vote Approve MRE for MythTV [21:18] Please vote on: Approve MRE for MythTV [21:18] Public votes can be registered by saying +1, +0 or -1 in channel, (private votes don't work yet, but when they do it will be by messaging the channel followed by +1/-1/+0 to me) [21:18] +1 [21:18] +1 received from soren [21:18] +1 [21:18] +1 received from stgraber [21:19] mdz, kees: [21:19] +1 [21:19] +1 received from mdz [21:19] Going once.. [21:19] Going twice [21:20] #endvote [21:20] Voting ended on: Approve MRE for MythTV [21:20] Votes for:3 Votes against:0 Abstentions:0 [21:20] Motion carried [21:20] great, thanks guys [21:20] superm1: FWIW I'm also granting you a 12.04.1 exception, so if you want it in the point release, please make sure it's uploaded ASAP [21:20] stgraber: it's in the queue, just needs accepting [21:20] Lovely. [21:20] Moving on. [21:21] #topic check up on community bugs === meetingology changed the topic of #ubuntu-meeting to: check up on community bugs [21:21] So, given our discussion earlier, I'm going to go ahead an unassing us from https://bugs.launchpad.net/ubuntu-community/+bug/252368 [21:21] Launchpad bug 252368 in Launchpad itself "Automatically associate DD and DM accounts with GPG keys in keyring packages to allow DDs to use the Launchpad Email interface" [Low,Triaged] [21:22] As for https://bugs.launchpad.net/ubuntu-community/+bug/174375 [21:22] Launchpad bug 174375 in Launchpad itself "Distribution drivers permissions may need redesign" [Low,Triaged] [21:22] I'm having network issues right now [21:22] lagging a lot [21:23] I'm not sure what we need to discuss here still. [21:24] I guess I'm not the only one. [21:24] We still need to get ubuntu-release-nominators out of ubuntu-release somehow; that team is a hack [21:25] To some extent we've just moved the problem (albeit to somewhere less damaging) [21:26] I guess I'm not actually clear on what *we* are meant to do here. [21:26] Specify what should be done on behalf of Ubuntu [21:26] I think I might be able to take an action to progress this [21:27] Since I think I understand both the security model we want and the relevant bits of LP code [21:27] Perfect! [21:28] Given that the individual stakeholders are who they are, it seems a bit awkward for us to have to drive it. [21:28] But I currently have a toddler sitting on my lap so not so much right now [21:28] Well, this too has been sitting in LP for years. [21:29] Another day won't matter much. [21:29] Great. [21:29] #action cjwatson to look into https://bugs.launchpad.net/ubuntu-community/+bug/174375 [21:29] ACTION: cjwatson to look into https://bugs.launchpad.net/ubuntu-community/+bug/174375 [21:29] Launchpad bug 174375 in Launchpad itself "Distribution drivers permissions may need redesign" [Low,Triaged] [21:29] We can't in general assume that the LP team understands what Ubuntu wants to get out of their security model - we have to tell them [21:30] And the TB is the owner of the Ubuntu object in LP [21:30] cjwatson: Understood. I was rather thinking it would be delegated to the stakeholders on the Ubuntu side. [21:30] Please no [21:30] ..but if you're doing it, we're covered for sure. [21:30] We understand it better :) [21:31] Very well. [21:31] The stakeholders are liaisons, not necessarily decision-makers [21:31] (With that hat on, anyway) [21:31] (Or at least that's how I understand it) [21:32] Well, we'd certainly have final say in it, but it's hard for us as a group to actually drive this issue forward. [21:32] But this is all academic since you've accepted the action item :) [21:32] Yes; but nobody else really can either :) [21:32] Yeah [21:32] #topic Any other business? === meetingology changed the topic of #ubuntu-meeting to: Any other business? [21:32] We made excellent progress on it a while back in an in-person TB meeting, actually - we just haven't finished the job [21:33] Nothing else from me [21:33] none here [21:33] Who's the next chair? stgraber? [21:33] sounds right [21:33] #info Next meeting is set for Aug 20th, 2100 UTC. Chair is stgraber [21:34] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [21:34] Meeting ended Mon Aug 6 21:34:04 2012 UTC. [21:34] Minutes (wiki): http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-08-06-21.00.moin.txt [21:34] Minutes (html): http://ubottu.com/meetingology/logs/ubuntu-meeting/2012/ubuntu-meeting.2012-08-06-21.00.html [21:34] Thanks everyone.