=== baba is now known as hack === hack is now known as megha === tvoss is now known as tvoss|test === tvoss|test is now known as tvoss === doko_ is now known as doko === security is now known as megha === billy_ is now known as wickedpuppy [16:30] hi! [16:30] hey [16:30] \o [16:31] hello [16:31] #startmeeting [16:31] Meeting started Mon Apr 15 16:31:25 2013 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [16:31] Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired === beuno_ is now known as beuno [16:31] The meeting agenda can be found at: [16:31] [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting [16:31] [TOPIC] Announcements === meetingology changed the topic of #ubuntu-meeting to: Announcements [16:32] (none this week) [16:32] [TOPIC] Weekly stand-up report === meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report [16:32] I'll go first [16:32] I'm on community this week [16:33] I have more requirements gathering, planning and communications of our plans to do [16:33] I also have to finish up performance reviews [16:33] there are a couple audits to finish [16:33] and I will be working on two embargoed updates [16:34] that's it for me [16:34] mdeslaur: you're up [16:35] I'm in the happy place this week [16:35] you bet you are! :P [16:35] hehe [16:35] and I only have two days...wednesday I'm on vacation [16:35] jdstrand: hehe :) [16:35] (on vac until the 29th [16:35] I'm currently writing a test script for haproxy, which I'll likely release this afternoon or tomorrow [16:36] and am working on an embargoed issue to hand off to one of the non-vacationing suckers [16:36] and, that's it from me. [16:36] sbeattie: you're up [16:36] fyi, I forgot one-- hope to do install audits this week too [16:36] ah cool [16:36] I'm working on apparmor work items again this week. [16:37] I'm continuing to write some example clients for confinement, wrote a couple of qml demos last week. [16:37] will need to put some automation around them as well. [16:37] sbeattie: could you stick those in a bzr tree somewhere? [16:38] sbeattie: re automation, what are you thinking, for automatic testing? [16:38] jdstrand: yeah, for automatic testing, as much as possible. [16:38] drag-n-drop stuff may be harder to automate. [16:39] mdeslaur: https://code.launchpad.net/~sbeattie/+junk/apparmor-examples [16:39] sbeattie: cool-- though aiui, having automatic testing is not in scope for this month per se. [16:39] sbeattie: ah! cool [16:39] sbeattie: obviously we want it-- what are you thinking about in terms of scheduling that work? [16:40] jdstrand: uhh, hadn't really decided on anything concrete for schedule. [16:40] ok [16:40] jdstrand: was expecting to coordinate that with you/the team [16:41] sbeattie: basically my questons are coming from the palce of 'let's focus on what we said we would focus on, but if we have to adjust, let's talk about it' [16:41] okay [16:41] so yeah, talking later is fine [16:41] anyway, that's pretty much it for me. [16:41] tyhicks: you're up [16:42] I'm working on https://blueprints.launchpad.net/ubuntu/+spec/security-1304-appisolation-dbus this week [16:42] Still wrapping up the dbus parser tests item [16:42] Last week while writing parser tests, I ran across some parser bugs [16:42] Those are fixed now and I'm back to improving the tests [16:43] then I'll move on to "dbus daemon - regression tests" and then to "dbus daemon, pass labeling info on messages so security context can be queried by recipient" [16:43] eCryptfs prep work for the kernel merge window stole some time from me last week but that is now all done [16:44] so my sole focus will be on aa work items this week [16:44] tyhicks: did you push your tests anywhere? [16:44] * jdstrand is happy to hear that we are finding and fixing bugs when writing our tests :) [16:44] indeed! [16:44] sbeattie: not yet, when I fully complete that work item the tests will live in the apparmor package of the dbus-dev ppa [16:45] tyhicks: okay, just wondered if you wanted any feedback/review of them... [16:45] I also did a lot of work (still pending upload) on fixing up the patches in the dbus-dev apparmor package so that the patches will be easier to send upstream [16:45] sbeattie: I will want some feedback for sure. I'll send them to the list. [16:46] that's it for me [16:46] jjohansen: you're up [16:46] tyhicks: thanks [16:46] I'll be continuing to work on https://blueprints.launchpad.net/ubuntu/+spec/security-1304-appisolation-signals-ipc-ptrace [16:46] Mostly it should be work around sockets (labeling, passing them, etc) [16:46] I will also need to spend some time pushing some patches to the upstream security tree so they are there for when the merge window opens [16:46] tyhicks: regarding upstreamifying-- is that DBus upstreaming, apparmor, kernel, or some combination? [16:47] jdstrand: kernel - ecryptfs work [16:47] jdstrand: apparmor [16:47] tyhicks: oh? [16:48] the patches against the apparmor package were piling up and it was going to be a pain to get them all in order and broken down for upstreaming [16:48] tyhicks: as in, making them easily digestible for the list? [16:48] jdstrand: exactly [16:48] just a little tidying up before things got too ugly [16:48] ah [16:49] jjohansen: curious-- what are you snding to the upstream security tree? [16:50] jdstrand: about the first 20 patches from the queue that have been reviewed. Its all the base code cleanups and bug fixes [16:50] neat [16:51] sarnold: your up [16:51] I'm on triage this week [16:51] I'm finishing up curl publication today, and I'm liable to ask jdstrand if I can take one of his MIR audits [16:52] I'd like to get around to fixing up my juju charms, but that might take a back burner again to doing another update [16:52] sarnold: if you're up to a challenge, you can try and take the bouncycastle update [16:52] sarnold: actually one is a MIR audit (ie, not security audit) and the other I'm putting in that category-- it is about the scopes privacy [16:52] sarnold: java backporting fun [16:52] mdeslaur: that -is- a challenge :) [16:53] sarnold: actually, it might not be a bad idea to get some help there [16:53] .. with all the goodness of inexplicable crypto goo :) [16:53] sarnold: but we'll talk later [16:53] cool :) [16:54] chrisccoulson: your turn :) [16:54] yoyoyo [16:54] i got a flash update out last week [16:54] also fixed an arm crash in chromium (waiting on testing feedback from the ufa guys, but it works here) [16:55] fixed https://bugzilla.mozilla.org/show_bug.cgi?id=858670, which appeared in the ff20 update [16:55] Mozilla bug 858670 in Extension Compatibility "crash in uGlobalMenuObject::ShouldShowIcon with GlobalMenu on Ubuntu" [Critical,New] [16:55] https://bugzilla.mozilla.org/show_bug.cgi?id=858782 also appeared, but i've no idea what is happening there. if any of you use google docs and can recreate it, please let me know ;) [16:55] Mozilla bug 858782 in Extension Compatibility "crash in uGlobalMenuDocListener::DoHandleMutations with GlobalMenu on Ubuntu" [Critical,New] [16:56] did a bit more with chromium automated testing. discovered that gtest can already produce junit formatted test results, which is a great help [16:57] i'll hopefully be done with updates / chromium etc this week, so i can start on other things i'm meant to be looking at :) [16:57] nice [16:57] (junit) [16:57] well all of it, but you know, that goes for everyone :) [16:58] yeah, unfortunately, i discovered it created junit results after i started writing code to parse the results and convert them ;) [16:58] (like we're doing for firefox already) [16:59] heh [16:59] chrisccoulson: did you have more? [16:59] no, that's me done i think [16:59] chrisccoulson: (fyi, since you're last, you can say 'back to you jdstrand or something :) [17:00] sure, no problem [17:00] [TOPIC] Highlighted packages === meetingology changed the topic of #ubuntu-meeting to: Highlighted packages [17:00] The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. [17:00] See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. [17:00] http://people.canonical.com/~ubuntu-security/cve/pkg/gpw.html [17:00] http://people.canonical.com/~ubuntu-security/cve/pkg/jenkins-winstone.html [17:00] http://people.canonical.com/~ubuntu-security/cve/pkg/policycoreutils.html [17:00] http://people.canonical.com/~ubuntu-security/cve/pkg/spice-gtk.html [17:00] http://people.canonical.com/~ubuntu-security/cve/pkg/openjpeg.html [17:00] [TOPIC] Miscellaneous and Questions === meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions [17:01] I have one for several of you [17:01] based on what was said in this meeting, I have a good feeling about progress for the month [17:01] however, if I look at http://status.ubuntu.com/ubuntu-raring/canonical-security-ubuntu-13.04-month-6.html I have a less good feeling [17:02] so, I guess, now that we are 2 weeks in to this month, how are the work items going? Are we 50% done? are there problems? [17:02] jjohansen: ^ we talked about this a bit last week, so afaik, we are slightly behind but aren't worried on our timeline for this month. is that accurate? [17:03] yes [17:03] jjohansen: (talking about your work items specifically) [17:03] I'm not 50% done, but I also haven't been able to spend 100% of my time on the work items [17:03] I will be able to for the remainder of the month [17:03] and I'm confident that I can knock off all of my work items by then [17:03] tyhicks: right.. [17:03] ah, ok [17:04] sbeattie: how about you? ^ [17:04] sorry, I'm notorious for not updating my workitem entries. === jasoncwarner__ is now known as jasoncwarner [17:04] well, I was going to end with 'Please update your work items' :) [17:04] heh [17:05] but yeah, feeling pretty confident about where things are at. [17:05] sbeattie: but in a less burndown chart way: are you on track for your work items for the month? [17:05] forgetting to update the entries is better than not having any updates to make ;) [17:05] tyhicks: yes!! :) [17:05] sbeattie: awesome [17:05] hehe [17:06] jjohansen, tyhicks, sbeattie: if you could update this month work items sometime today, that would be great [17:06] okay [17:06] * tyhicks nods [17:06] Does anyone have any other questions or items to discuss? === Ursinha is now known as Ursinha-afk === Ursinha-afk is now known as Ursinha === security is now known as megha [17:17] mdeslaur, sbeattie, tyhicks, jjohansen, sarnold, chrisccoulson: thanks! [17:17] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [17:17] Meeting ended Mon Apr 15 17:17:49 2013 UTC. [17:17] Minutes (wiki): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-04-15-16.31.moin.txt [17:17] Minutes (html): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-04-15-16.31.html [17:17] thanks jdstrand :) [17:17] thanks jdstrand! [17:17] thanks jdstrand [17:18] jdstrand: thanks [19:56] bonsoir [19:57] bonsoir pitti [19:59] hi [20:00] #startmeeting Technical Board meeting [20:00] Meeting started Mon Apr 15 20:00:27 2013 UTC. The chair is stgraber. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [20:00] Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: [20:00] hey everyone, so from what I'm seeing on the ML, it's just the three of us tonight [20:01] we also appear to have an empty agenda [20:01] * pitti hasn't caught up with the over-weekend mail flood yet, sorry [20:01] oh, good [20:01] anyway, let's quickly go through the usual points, but I expect this to be a very short meeting [20:01] #topic Action review === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: Action review [20:02] TBH I didn't properly catch up on the last meeting to see if we got through all the outstanding business then [20:02] I didn't see minutes on -devel-announce [20:02] unfortunately it doesn't look like soren got around to doing the post-meeting paperwork, so I'm assuming we didn't have any action [20:02] If we did I guess we'll find out in two weeks? :) [20:02] IIRC we granted a MRE for xorg and discussed Mark's proposal some more [20:03] mdz was supposed to process the MRE and update the wiki, but IIRC he was waiting for the meeting minutes to link to them [20:04] so hopefully this is enough highlights for both of them to have this sorted out ;) [20:04] #topic Scan the mailing list archive for anything we missed (standing item) === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: Scan the mailing list archive for anything we missed (standing item) [20:05] I just did a quick scan, we had a few things but they were resolved by e-mail or were just notifications [20:05] I can't see anything in my ML for TB [20:05] #topic Check up on community bugs === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: Check up on community bugs [20:05] " [20:05] There are currently no open bugs. [20:05] " [20:05] #topic Select a chair for the next meeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: Select a chair for the next meeting [20:06] I think the next chair is cjwatson. However this will be during the client sprint, so we should probably make sure we don't have conflicting meetings [20:06] stgraber: well, hopefully the sprint won't be tightly packed with meetings [20:07] I think we can make a point of carving out time [20:07] It's on our calendars so we should notice, right? [20:07] I don't think I have the TB meeting on my Canonical calendar, but I can fix that ;) [20:07] I do, at least [20:08] 12.30-13.30 - Lunch [20:08] so the meeting will be during lunch [20:08] no risk of conflicts then ;) [20:08] * cjwatson will pack military rations [20:09] one hand typing, the other munching on a sandwich [20:09] sounds like a plan [20:09] #topic AOB === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Technical Board meeting Meeting | Current topic: AOB [20:10] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [20:10] Meeting ended Mon Apr 15 20:10:20 2013 UTC. [20:10] Minutes (wiki): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-04-15-20.00.moin.txt [20:10] Minutes (html): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-04-15-20.00.html [20:10] thanks; good night everyone! [20:10] pitti: good night!