=== IdleOne is now known as frenocha === frenocha is now known as IdleOne === cody-somerville_ is now known as cody-somerville === Logan_ is now known as log === medberry is now known as med_ [16:57] \o [16:57] \o [16:57] hello [16:58] hi! [16:58] #startmeeting [16:58] Meeting started Mon Aug 12 16:58:40 2013 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [16:58] Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired [16:58] The meeting agenda can be found at: [16:58] [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting [16:58] [TOPIC] Announcements === meetingology changed the topic of #ubuntu-meeting to: Announcements [16:58] Colin Watson (cjwatson) provided debdiffs for precise-raring for putty. Your work is very much appreciated and will keep Ubuntu users secure. Great job! :) [16:58] [TOPIC] Weekly stand-up report === meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report [16:58] I'll go first [16:59] I'm on triage this week [16:59] I've got openstack updates to do [16:59] I need to test the latest upstart-app-launch [16:59] I want to implement the xdg user dir support in apparmor [17:00] I need to sync up with sarnold on code audits and give some to him since he is actually pretty good at completing them :) [17:01] I have a number of follow-ups on application confinement discussions [17:01] and patch piloting [17:01] mdeslaur: you're up [17:01] I'm on community this week [17:01] I have a couple of updates that need testing [17:01] so I'll be doing that to try and get them released [17:01] I'll also try and get the list down a bit since I go on vacation next week [17:01] that's it for me [17:01] sbeattie: you're up [17:01] I'm on apparmor again this week [17:02] I'm currently trying to sort out what's going on after being gone on holiday and at black hat [17:02] I have a bug or two in click-apparmor to fix [17:02] sbeattie: we should sync up [17:03] I also have a couple of black hat related items (expenses, trip report) to do [17:03] jdstrand: yeah [17:03] so that's pretty much it for me. [17:03] tyhicks: you're up [17:03] sbeattie: I took the liberty of making a few small changes to click-apparmor in support of the MIR request that I filed last week [17:03] jdstrand: kewl [17:04] This morning, I'll be preparing debdiffs against apparmor and dbus for AppArmor D-Bus mediation [17:04] sbeattie: you might want to pull 0.1.0 from the archive into your branch and review (btw, is there an official home for it?) [17:04] * tyhicks pauses [17:04] jdstrand: not really outside of the +junk tree I have [17:04] we can move it to a more formal location under the security team [17:05] I think we may want to have it live somewhere, but we can talk somewhere else [17:05] yeah [17:05] yeah, sounds good [17:05] tyhicks: please proceed [17:05] help the homeless [17:05] * sbeattie presses play on tyhicks [17:05] :) [17:05] This morning, I'll be preparing debdiffs against apparmor and dbus for AppArmor D-Bus mediation [17:05] (yeah, yeah, you've heard that before but it is for real this time :) [17:05] hehe [17:05] jjohansen will be pushing a kernel patch out that enables it for all Saucy users - until then, the dbus-dev PPA kernel will still be needed for mediation to be enabled [17:05] tyhicks: you mean fr saucy upload? [17:06] jdstrand: yep [17:06] \o/ [17:06] jdstrand: don't celebrate yet, it's a trap :P [17:06] hehe [17:06] :) [17:06] Then I'll be working on my content-hub work items [17:06] you'll want to be prepared for everyone saying you broke everything :P [17:07] yeah, I'll probably need to plan in some support response time [17:07] probably a good idea [17:07] I imagine there will be questions [17:07] hopefully not too many bugs [17:07] After that, I'll work with jjohansen to add necessary APIs to libapparmor that allow trusted helpers to operate on AppArmor label sets [17:07] well, there may be no bugs-- doesn't mean you won't get blamed :P [17:07] true :) [17:08] Finally, I need to revise the dbus regression tests in the apparmor source tree for upstream approval and I also need to add tests for proper apparmor delegation when passing fds over dbus [17:08] * jdstrand was referring to that scenario in his initial comment :) [17:08] I think that's it for me [17:08] jjohansen: you're up [17:08] I'm on apparmor again as well, [17:08] I've got to finish fixing a bug in the replacedby logic that is causing crashes when we enable compound labels, [17:08] I need to: look into the 3.11 flink/linkat changes http://lwn.net/Articles/562488/, push the kernel patch for the label query that dbus needs, deal with bug 1202161, prepare for tuesdays apparmor meeting, and then perhaps get back to the current apparmor work items [17:08] bug 1202161 in linux (Ubuntu) "seccomp filter: execve(): Operation not permitted" [Medium,Incomplete] https://launchpad.net/bugs/1202161 [17:09] jjohansen: Good! I've been meaning to make sure you're aware of flink/linkat [17:10] I couldn't think of any potential problems for apparmor, but I'm sure that you can :) [17:10] tyhicks: well I remember seeing it, and making my self a note that got lost in all the other notes [17:10] yes it is going to rework some work around our link rules [17:11] but, I need to trace the security hooks because I don't think they are sufficient to mediate it [17:12] or more correctly currently only the inode hook is, mediating it [17:12] ah [17:13] anyways that it from me sarnold your up [17:13] sarnold: hold on a sec [17:14] jjohansen: I didn't recognize the IPC work items in your list this week-- would it be helpful/possible to shuffle some work around to free up some time? [17:15] jdstrand: sorry that is the "current apparmor work items" bit [17:15] jjohansen: related: flink/linkat is for 3.11-- are we going to ship 3.11 in 13.10 and if not, is that something we can/should put on the backburner for a bit? [17:15] jdstrand: saucy will be 3.11 [17:15] ok [17:16] that isn't to say I won't go only as far as getting the info to file a bug on this item for this week, and deal with it later [17:16] oh, why was I thinking we had 3.10 still [17:17] I think the switch just happened [17:17] oh, hah, cause it happened today :) [17:18] jdstrand: no the switch happened last week when tim rebased to -rc4 [17:19] we had issues in the 3.11 kernel where I couldn't even get the machine to boot in -rc2, and the kt was shaking out a couple issues in -rc3 [17:19] maybe-- but I see 3.10.0-6.17 was only superceded a little while ago [17:19] (in saucy release) [17:19] anyhoo, doesn't matter [17:20] superseded [17:21] jjohansen: so, aiui, you've got the stuff you listed and you don't think it will take an inordinate amount of time (something that will take longer will be planned/done later) and you plan to work on ipc still? [17:22] is that accurate? [17:22] jdstrand: yes [17:22] ok, cool, thanks. sorry if I was being dense :) [17:22] sarnold: you're up [17:24] I'm in the happy place the week; I've got (at least one) MIR audit (click-apparmor), and I've grabbed an update for maas to do. I may steal some of jdstrand's MIR audits as needed. [17:24] and of course, if there are apparmor patches posted, reviewing them will be my top priority. [17:24] I believe that's me [17:25] chrisccoulson: you're up [17:25] hi [17:25] last week, i got firefox and thunderbird out. everything's been pretty quiet since then, which I'll assume is a good thing :) [17:25] \o/ [17:25] chrisccoulson: did you see my critical firefox bug? [17:26] \o/ [17:26] also, i added support for multiple browser contexts to oxide, which hopefully means that it's possible to have webviews with different profile folders now :) [17:26] neat :) [17:26] \o/ [17:26] \o/ [17:26] chrisccoulson: that reminds me, I owe you and ubuntu-devel@ an email regarding oxide [17:26] very cool :) [17:27] (that was one of the things I was planning to follow-up on this week) [17:27] i'm still working on the user script support, which i plan to continue this week. i wanted to get the browser context stuff out of the way first, as i'm making user scripts per-context rather than per-webview, and i didn't want to have to refactor everything later on :) [17:27] i'm not sure if anyone has been following https://code.launchpad.net/~chrisccoulson/oxide/oxide.trunk ? [17:28] sorry, no [17:28] that's ok ;) [17:28] i think that's me done [17:28] chrisccoulson: wow, a lot of work in there [17:28] mdeslaur, yeah, it's slowly getting there :) [17:30] [TOPIC] Highlighted packages === meetingology changed the topic of #ubuntu-meeting to: Highlighted packages [17:30] The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. [17:30] See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. [17:30] http://people.canonical.com/~ubuntu-security/cve/pkg/ngircd.html [17:30] http://people.canonical.com/~ubuntu-security/cve/pkg/glusterfs.html [17:30] http://people.canonical.com/~ubuntu-security/cve/pkg/shibboleth-sp2.html [17:30] http://people.canonical.com/~ubuntu-security/cve/pkg/qpid-python.html [17:30] http://people.canonical.com/~ubuntu-security/cve/pkg/darktable.html [17:30] [TOPIC] Miscellaneous and Questions === meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions [17:30] sarnold pointed out that the community supported drupal7 packages could use some attention on earlier released (particularly 12.04). See http://people.canonical.com/~ubuntu-security/cve/pkg/drupal7.html for details. [17:31] Does anyone have any other questions or items to discuss? [17:37] mdeslaur, sbeattie, tyhicks, jjohansen, sarnold, ChrisCoulson: thanks! [17:37] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [17:37] Meeting ended Mon Aug 12 17:37:21 2013 UTC. [17:37] Minutes (wiki): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-08-12-16.58.moin.txt [17:37] Minutes (html): http://ubottu.com/meetingology/logs/ubuntu-meeting/2013/ubuntu-meeting.2013-08-12-16.58.html [17:37] thanks [17:37] thanks jdstrand [17:37] thanks jdstrand [17:37] * pinky is away: Away [17:37] thanks jdstrand! [19:21] !dmb-ping [19:21] bdrung, ScottK, Laney, micahg, barry, tumbleweed, stgraber: DMB ping [19:22] was any non-DMB member here for the DMB meeting? [19:26] \0 === Ursinha-afk is now known as Ursinha