/srv/irclogs.ubuntu.com/2014/04/07/#ubuntu-meeting.txt

=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== zequence_ is now known as zequence
=== cjwatson_ is now known as cjwatson
=== s1aden is now known as sladen
=== Quintasan is now known as Doktorant_R4k
=== Doktorant_R4k is now known as Quintasan
=== brendand_ is now known as brendand
=== shuduo is now known as shuduo_afk
* bdmurray looks around15:00
bdmurrayI believe I'm that chair today, do we take attendance first or anything?15:01
Laneyhi15:02
stgraberbdmurray: I think we've got quorum so it's fine to just start the meeting15:02
* xnox O/15:02
LaneyDo you mind chairing in your first meeting?15:02
LaneyThe agenda from the last meeting hasn't been cleared yet, unfortunately15:02
bdmurrayI think I can sort it out15:02
ScottK\o15:03
Laneyok15:03
bdmurray#startmeeting Ubuntu DMB15:03
meetingologyMeeting started Mon Apr  7 15:03:16 2014 UTC.  The chair is bdmurray. Information about MeetBot at http://wiki.ubuntu.com/meetingology.15:03
meetingologyAvailable commands: action commands idea info link nick15:03
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic:
bdmurray#topic Review of previous action items15:03
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic: Review of previous action items
bdmurrayIt doesn't look like there were any previous action items, as the one on the agenda seems to be a holdover, correct?15:04
=== Darkwing_ is now known as Darkwing
ScottKNo.  I think at least some of that needed to be done after the last meeting.15:04
ScottKstgraber would know if it's all done, in any case.15:04
stgraberI think everything was done15:05
bdmurrayokay, great.15:05
bdmurraymoving on then15:06
bdmurray#topic Per Package Uploader Application: Benjamin Kerensa15:07
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic: Per Package Uploader Application: Benjamin Kerensa
bdmurrayI don't see bkerensa here, but I've pinged him.15:08
LaneyCould swap to stokachu & come back15:08
bdmurrayokay, let's do that then15:09
bdmurray#topic Ubuntu Core dev application: Adam Stokes15:09
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic: Ubuntu Core dev application: Adam Stokes
bdmurraystokachu: Are you ready?15:09
LaneyHmm15:11
xnoxutc/summer-time hiatus?15:12
stgraberwell, if that was the case, they'd have been here an hour ago15:13
stgraberso probably not15:13
* xnox ponders australia... two hours late or something like that?!15:13
ScottKMakes it a short meeting.15:13
xnoxthey are not in southern hemispheres though, i think.15:13
bdmurrayMaybe we should email candidates a reminder?15:13
ScottKI think if they can't manage to remember, they've earned the result they get.15:14
ScottKWe can roll them over to two weeks from now.15:14
ScottKThe agenda for that meeting is empty ATM anyway.15:14
bdmurrayMaybe they should be 2nd in case anybody else applies15:15
LaneyBit unfortunate if anyone wants to apply today for the next meeting15:15
LaneyHo hum15:15
bdmurray#topic AOB15:15
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic: AOB
LaneyThat's what happens, I guess15:15
bdmurrayOkay, is there anything else?15:16
xnoxwell if people show up in 1 hour maybe we could still reconvene...15:16
bdmurrayI'm actually not working / on holiday today15:16
bdmurrayand I still made it to the meeting on time ;-)15:17
bdmurraySince there's nothing else then let's wrap up the meeting.15:18
bdmurray#endmeeting15:18
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Apr  7 15:18:49 2014 UTC.15:18
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2014/ubuntu-meeting.2014-04-07-15.03.moin.txt15:18
LaneyIntense meeting15:19
xnoxbdmurray: excellent chairing =)15:21
stokachubdmurray: sorry im here15:22
stokachuprobably to late15:22
stokachudamnit15:22
xnoxbdmurray: Laney: ScottK: micahg: ping ^15:23
ScottKStill here.15:23
LaneyCool15:23
LaneyJust settled down for a nap too15:23
xnoxwe are still within normal 1h slot for the meeting =)15:24
xnoxbdrung: around? =)15:24
bdmurrayI'm still here15:25
xnoxbdmurray: restart the meeting? =)15:26
* bdmurray looks for restart command15:26
Laneystart it again15:26
bdmurraythat was a joke ;-)15:26
bdmurray#startmeeting Ubuntu DMB15:26
meetingologyMeeting started Mon Apr  7 15:26:47 2014 UTC.  The chair is bdmurray. Information about MeetBot at http://wiki.ubuntu.com/meetingology.15:26
meetingologyAvailable commands: action commands idea info link nick15:26
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic:
bdmurray#topic Ubuntu Core dev application: Adam Stokes15:26
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Ubuntu DMB Meeting | Current topic: Ubuntu Core dev application: Adam Stokes
xnoxFrom service manpage restart is stop, start =))))))))) </joke>15:26
stokachuhi, thanks guys for restarting for me15:27
bdmurraystokachu: Could you introduce yourself, your work, and your application?15:27
stokachuHi, I've been working for Canonical doing a Sustaining Engineering role and recently moving into Solutions Engineer concentrating on juju, maas, and our most recent project cloud installer15:28
stokachuone sec lemme get the app link15:28
stokachuhttps://wiki.ubuntu.com/AdamStokes/CoreDevApplication15:28
ScottKFor those of us that don't work at Canonical, sustaining/solutions engineering doesn't mean much.15:29
stokachuas stated in the application ive been using Ubuntu for roughly 3 years and Fedora prior to that for 7 years15:29
stokachuSusstaining engineering revolved around maintaining the quality and stability of the existing product lines15:29
stokachuinlucding Base OS, Kernel maintenance, and Cloud technologies such as Juju15:30
xnoxstokachu: mostly on LTS releases only?15:30
stokachuSustaining rarely did new feature enhancements or new package appication15:30
stokachuYea our main focus was LTS releases15:30
stokachuhowever when we sent a patch we did it for all supported Relesaes15:30
stokachureleases*15:30
stokachuIn solutions engineering we are kind of a R&D department15:31
stokachuwhere we work on upstream enhancements with focus in maas, juju, and hpc15:31
ScottKUsually, people apply for MOTU, before core-dev.  How it's somewhat unusual to see someone going for core-dev as their first entry point into ubuntu-dev.15:32
stokachuas for outside of the canonical realm i've successfully submitted the package sosreport in the Debian archive via the mentors program15:32
stokachuwhich was handled from scratch until upload15:32
stokachuI am currently a Ubuntu contributing developer15:32
stokachuScottK: ^15:33
stokachuwhen time permits ive done package merges from debian into X ubuntu release15:33
stokachuparticipated in +1 maintenance15:33
ScottKRight, but that's not part of ubuntu-dev (that's people with upload rights)15:34
LaneyWhat do you imagine you'll be mainly working on in the Ubuntu archive?15:34
xnoxScottK: however, I went straight from contributing developer -> core dev. So there have been cases like that before. Also looking at stokachu's upload history most of the uploads that got sponsored for him are for "main" packages.15:34
stokachuMy main focus will be our cloud products such as Maas, Juju, and Cloud installer15:34
* Laney doesn't think going straight for core-dev is a problem in itself if there's experience and that's where the interests/intention to contribute is15:34
stokachucurtin15:34
stokachuWhere main package contributions come into play will be against those that are depending on by the stated cloud products15:35
stokachudhcp, bind, etc15:35
ScottKxnox: I know it's happened, it's just not usual.15:35
stokachuive worked with xnox and bdmurray on a few occasions related to packaging and userspace maintenance work15:36
bdmurraystokachu: with your change in teams and responsibilities has your focus shifted from SRUs to the development release?15:36
stokachubdmurray: yea my focus won't be SRU at this time15:37
stokachuprimarily due to team sizes/resources etc15:37
stokachuCTS would still handle the SRU's for products i will directly work on15:37
ScottKCTS?15:37
stokachucanonical technical services15:37
stokachuthe department where Sustaining Engineering resides15:37
stokachuScottK: sorry i dont intentially mean to automatically assume everyone knows canonical15:38
ScottKLet's try and make it through the rest of the meeting without any references to the Canonical org chart.15:38
stokachusure15:38
ScottKWhat do you think of the process for landing maas/juju development efforts into Ubuntu?15:39
stokachuThey aren't in line with the rest of development processes15:39
bdmurraystokachu: your application seems to be missing the "Things I could do better" section.  Is that deliberate?15:40
stokachuAs in feature freezes tend to not apply to them, however, I feel they should15:40
stokachubdmurray: there is a one liner which states Increase my productivity by stream lining my work items for the different projects I am involved in.15:40
stokachuand by increasing productivity I mean adhearing to the processes defined by Ubuntu15:40
ScottKstokachu: Feature freeze does apply.  They just ignore it and ask for an FFe every time.15:41
stokachureduce back and forth15:41
xnoxstokachu: MAAS & juju testing is loosely integrated with ubuntu release cycle. Past three releases co-incided with Openstack summits and there was nobody available (and had hardware) to execute end-to-end MAAS testing, and it hasn't been tested regularly during the development cycle. In your opinion, how can this be improved?15:41
xnox(thus critical bugs were discovered more-or-less during release weeks)15:41
stokachuxnox: So CI is definitely a big issue in my eyes15:41
stokachuwe shouldnt be releasing products that do not 100% pass tests and have a huge percentage of coverage15:42
ScottKHaving a release schedule that's aligned to Ubuntu's would help.15:42
stokachuFor juju in particular it would be beneficial to stick to not making breaking changes in minor releases15:42
stokachuAlso maas release 1.5 which is way to close to the 14.04 release15:42
stokachuto be audited and signed off on15:43
stokachureleased*15:43
stokachuMaking sure codebases are green before doing releases is a pet peeve of mine15:43
stokachuBut, maas and juju teams do realize the pitfalls15:44
stokachuand are actively changing their processes and increasing testing15:44
stokachuThey are in the right direction so I strongly believe those aligned processes with Ubuntu will be seen in the near future15:44
xnoxstokachu: ok. Slightly different question: What should one do when updating a library, that removes one function from its ABI?15:45
stokachuxnox: ifa function is removed the symbol tables would need to be updated to reflect that15:46
stokachuamong a version bump and possible rebuilds of affected packages15:47
* bdrung_work arrives15:48
xnoxstokachu: how would you find out list of affected packages?15:48
stokachuxnox: running a rdepends to see which version of the library is used15:50
stokachuusing ldd will also give you the library version used15:50
xnoxstokachu: ok. There is also "reverse-depends" command, that I find is often faster (it uses pregenerated caches)15:50
xnoxno more questions from me.15:50
bdmurrayDoes anybody else have any questions?15:51
stokachuxnox: is that different than the rdepends argument?15:51
stokachuapt-rdepends?15:52
stokachuor that may be recursive15:52
ScottKIf you have a library that needs a version bump, what packaging changes are needed?15:52
xnoxstokachu: one is local, the other one uses remote cache. Otherwise basic functionality is about the same. But each has extra features lacking in the other tool.15:53
stokachuah ok good t oknow15:53
ScottKAlso reverse-depends -b will give you the reverse build-deps.15:53
stokachuScottK: changing the SONAME and corresponding name for the binary package15:54
stokachucall ldconfig within postinst15:54
stokachuhm.. what else15:54
stokachui think those are the main things15:55
ScottKOther than sosreport and the things related to your work, what interests in Ubuntu development do you have?15:55
stokachuim a big fan of KDE so I'd like to be more active in that area15:56
stokachumaybe not so much the DE portion but its applications15:56
stokachuI also enjoy blogging and talking about products/projects in a way that can benefit small businesses15:57
stokachuwrt juju I have a interest in the "scaling down" part of the environment15:58
bdmurrayAlright, is that all the questions?15:59
bdmurray#vote Adamd Stokes for Ubuntu Core Developer16:01
meetingologyPlease vote on: Adamd Stokes for Ubuntu Core Developer16:01
meetingologyPublic votes can be registered by saying +1, +0 or -1 in channel, (for private voting, private message me with 'vote +1/-1/+0 #channelname)16:01
xnox+116:02
meetingology+1 received from xnox16:02
ScottK+0 #clearly knows a lot, but straight to core-dev is a big jump - I would be more comfortable starting with PPU or maybe server dev.16:02
meetingology+0 #clearly knows a lot, but straight to core-dev is a big jump - I would be more comfortable starting with PPU or maybe server dev. received from ScottK16:02
Laney+116:02
meetingology+1 received from Laney16:02
stgraber+116:02
meetingology+1 received from stgraber16:02
bdmurray+116:02
meetingology+1 received from bdmurray16:02
Laneymicahg: bdrung16:02
bdrung_worki still have to catch up.16:03
Laneyok, well no need anyway :-)16:03
xnoxmicahg had tentative +016:04
bdmurray#endvote16:05
meetingologyVoting ended on: Adamd Stokes for Ubuntu Core Developer16:05
meetingologyVotes for:4 Votes against:0 Abstentions:116:05
meetingologyMotion carried16:05
stokachusweet!16:05
stokachubdmurray: just noticed Adamd Stokes :)16:05
Laneywell done ;-)16:05
argescongrats16:06
bdmurraystokachu: sorry about that typo16:06
stokachubdmurray: its cool man16:07
stokachumicahg: ScottK, promise not to let you down :)16:07
xnoxstokachu: =) congrats.16:07
stokachuthanks everyone :)16:07
bdmurrayOkay, we already handled AOB in the previous meeting ;-) so I guess that's a wrap.16:07
stokachuthanks again for your time and restarting the meeting16:08
stgraberstokachu: congrats!16:08
ScottKstokachu: The main thing is to ask when you're not sure.  Core-dev means you have more ability to break things, it doesn't mean you're expected to know it all.16:08
stokachuScottK: i will definitely do that16:08
stokachustgraber: thanks!16:08
ScottKThe breaking part or the asking part?16:08
bdmurray#endmeeting16:08
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Apr  7 16:08:42 2014 UTC.16:08
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2014/ubuntu-meeting.2014-04-07-15.26.moin.txt16:08
ScottK;-)16:08
Laneystokachu: https://wiki.ubuntu.com/MOTU/New16:08
Laneymight be useful, please add new tips that you come up with16:09
Laneybdmurray: now the joy of post meeting tasks16:10
josejdstrand: ping, mind a quick PM?16:30
jdstrandjose: I am about to step into a meeting. feel free to privmsg me, I read backscroll16:31
josethanks16:31
mdeslaur\o16:35
chrisccoulsono/16:35
tyhickshello16:35
jdstrandhi!16:36
jdstrand#startmeeting16:36
meetingologyMeeting started Mon Apr  7 16:36:06 2014 UTC.  The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:36
meetingologyAvailable commands: action commands idea info link nick16:36
jdstrandThe meeting agenda can be found at:16:36
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:36
jdstrand[TOPIC] Announcements16:36
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
jdstrandapparmor ptrace and signal mediation has landed on desktop and server. Touch images have the userspace and should have kernel updates next week. For anyone seeing apparmor denials in distro/click policy, please file bugs16:36
jdstrandoxide is now in main and in use on the touch images16:36
jdstrand[TOPIC] Weekly stand-up report16:37
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
jdstrandI'll go first16:37
jdstrandI'm in the happy place this week16:37
jdstrandI will be publishing the openjdk-6 update today16:37
jdstrandI'm also working with phonedations on the media-hub landing (apparmor policy updates)16:37
jdstrandand will be working on scopes apparmor policy this week16:38
jdstrandI have other updates assigned to me that I plan on picking up again16:38
jdstrandmdeslaur: you're up16:38
mdeslaurI'm on triage this week16:38
mdeslaurjust published a couple of updates, and have some more in the PPA to test and release16:39
mdeslaurthe cve list is growing, so I'll be poking at that too16:39
mdeslaurand I'm off on friday16:39
mdeslaurthat's it for me, sbeattie, you're up16:39
sbeattieI'm on apparmor again this week16:39
sbeattieI'm finishing up reviewing the user spaces patches for ptrace signals, to get them landed upstream.16:40
sbeattieAs well as writing additional test cases for them.16:40
sbeattieI know jj made a couple of commits over the weekend, which caused the jenkins builds to fail, so I need to see what's up with that (I suspect a couple of files got missed being added in a commit)16:41
sbeattieand I also need to finish making travel arrangements for the upcoming sprint.16:41
sbeattiethat's it for me16:41
sbeattietyhicks: you're up16:42
tyhicksI'm currently working on fixing up some lightdm guest session denials16:42
tyhicksone is a new denial from the signals/ptrace ffe and the rest are pre-existing denials16:42
tyhicksI also need to do a small followup patch, at cboltz's request, around the aa.py test cases that I added16:43
tyhicksthen I'm going to get caught up on what's been happening around kdbus LSM integration16:43
tyhicksI also need to book sprint travel16:43
tyhicksthat's it for me16:43
tyhicksjj is out today16:44
tyhickssarnold: that means you're up16:44
sarnoldI'm on community this week16:44
sarnoldI believe there is only one outstanding MIR left, glusterfs, to finish up this week16:44
sarnoldI want to upgrade to trusty before release, it'd be nice to participate in a pre-release circus :)16:45
sarnoldthere's plenty of apparmor patches outstanding, I'd like to review some of those and get them checked in16:45
tyhicks+116:45
sarnoldand I haven't yet bookde sprint travel, so that'll be this week :)16:46
sarnoldI think that's me this week, chrisccoulson? :)16:46
jdstrandtyhicks: re pre-existing-- I'm not sure you have to fix everything up. I think there are several things that may have been left out on purpose16:46
chrisccoulsonhi :)16:47
tyhicksjdstrand: I'll be sure to pass everything by you16:47
mdeslaursarnold: geez, might as well wait an extra couple of weeks and directly upgrade to U :P16:47
chrisccoulsonright now, i'm fixing bug 130134116:47
ubottubug 1301341 in webbrowser-app "grooveshark playback has stopped functioning" [Undecided,Confirmed] https://launchpad.net/bugs/130134116:47
chrisccoulsoni'm going to do another upload of oxide later with some other stuff in (file picker support)16:47
sarnoldmdeslaur :)16:48
chrisccoulsonbut other than that, i shall be mostly working on https://bugs.launchpad.net/oxide/ ;)16:48
jdstrandchrisccoulson: fyi, oxide got promoted this morning16:48
chrisccoulsoni've got another update to do this week as well16:49
chrisccoulsonjdstrand, thanks16:49
chrisccoulsoni think that's me done16:49
jdstrand[TOPIC] Highlighted packages16:49
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
jdstrandThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:49
jdstrandSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:49
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/gallery2.html16:50
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/libjboss-cache3-java.html16:50
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/jplayer.html16:50
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/djbdns.html16:50
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/pen.html16:50
jdstrand[TOPIC] Miscellaneous and Questions16:50
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
jdstrandI had one question16:50
jdstrandsomeone reported this denial to me in #ubuntu-devel: [13395.573516] type=1400 audit(1396873920.517:120): apparmor="DENIED" operation="file_inherit" profile="/usr/lib/NetworkManager/nm-dhcp-client.action" name="/var/lib/NetworkManager/dhclient-9a71cfcd-ec48-4ea2-9a72-928b504f7429-usb0.lease" pid=1168 comm="nm-dhcp-client." requested_mask="r" denied_mask="r" fsuid=0 ouid=016:51
jdstrandthis requred /usr/lib/NetworkManager/nm-dhcp-client.action {} to need a new rule:16:51
jdstrand/var/lib/NetworkManager/*lease r,16:51
jdstrandsomeone in the #apparmor channel over the weekend saw something similar16:52
jdstrandand then I saw it this morning with my chromium-browser profile16:52
jdstrandit is my understanding that this was intentional, related to file delegation and that maybe at some point we want to make this configurable16:53
jdstrandI have some concerns that this is turned on atm. I didn't see it in any of the rather significant testing we did over the past weeks16:54
jdstrandis this from a new patch to the kernel?16:54
sbeattieah, hrm, I hadn't seen that before either.16:54
sbeattieI'm not aware of it being a new patch, but jj is the one to answer that for sure.16:54
tyhicksa quick git blame points at "apparmor: revalidate open files at exec time"16:55
tyhicksit is one of the last few patches in jj's patch set16:55
jdstrandso that is in the kernels we tested16:55
jdstrandhmm16:56
jdstrandI find it really odd that I didn't see the nm one16:56
tyhicksI never saw it, either16:56
sarnoldiirc this revalidation should only occur when a confined profile hands a fd across an exec to a different domain16:56
tyhicksit is due to fd's not being closed (or intentionally being passed) across exec16:56
tyhicksso there may be some paths in nm that close the fds and some that don't??16:57
sarnoldI believe unconfined -> exec -> confined is probably still not validated16:57
jdstrandsarnold: right that was my understanding too. nm ships 3 different profiles16:57
jdstrandsarnold: that is consistent with what I've seen and what was reported in #apparmor16:58
sarnoldjdstrand: I -think- the revalidation used to occur at read() time (perhaps 'back in the day') -- this might have moved it forward to exec time to better label fds16:59
jdstrandI guess sanitized helper won't be affected cause if its wide file access (/** rwkl,)16:59
jdstrandbut I worry about evince17:00
jdstrandI guess we can just keep an eye on it17:00
jdstrandwhat do other people think?17:00
tyhicksjdstrand: I did a `dmesg -C && sudo ./test-evince.py -v && dmesg | grep DENIED` and didn't see any denials17:00
jdstrandtyhicks: right, but I think if this occurs it will be less direct than that. eg, firefox opening evince, eveince opening firefox, etc17:01
tyhicksjdstrand: firefox opening evince does happen in test-evince.py, but I'm not sure about evince opening firefox17:02
jdstrandtyhicks: right, but in that test, firefox isn't confined, is it17:02
jdstrand?17:02
tyhicksah17:02
tyhicksprobably not17:02
tyhicksgood point17:02
jdstrandwell, possibly good point. I don't know if it is a problem or now-- I was just surprised by these denials17:03
jdstrands/now/not/17:03
tyhicksyeah, I wasn't looking for delegation denials during my testing17:04
jdstrandme either-- I wasn't aware the patchset changed things17:05
jdstrandwrt delegation17:05
jdstrandwell, anyway, I guess we can just keep an eye on it17:06
jdstrandDoes anyone have any other questions or items to discuss?17:06
* sbeattie takes a note to make sure delegation is exercised in the regression tests17:07
jdstrandsbeattie: thanks17:08
jdstrandmdeslaur, sbeattie, tyhicks, sarnold, chrisccoulson: thanks!17:14
jdstrand#endmeeting17:14
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Apr  7 17:14:12 2014 UTC.17:14
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2014/ubuntu-meeting.2014-04-07-16.36.moin.txt17:14
mdeslaurthanks jdstrand!17:14
sbeattiejdstrand: thank you!17:14
sarnoldthanks jdstrand17:15
=== vladk is now known as vladk|offline
=== ubott2 is now known as ubottu
=== Ursinha_ is now known as Ursinha
=== zoktar_ is now known as zoktar

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!