/srv/irclogs.ubuntu.com/2014/06/23/#ubuntu-meeting.txt

=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== shadeslayer_ is now known as shadeslayer
=== vladk is now known as vladk|offline
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline
jdstrandhi!16:30
tyhickshello16:30
mdeslaurhi!16:30
jdstrand#startmeeting16:31
jdstrandhuh, the bot seems dead16:31
jdstrandThe meeting agenda can be found at:16:31
chrisccoulsonhi!16:31
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:31
jdstrand[TOPIC] Announcements16:31
jdstrandRohan Garg (rohangarg) provided debdiffs for saucy and trusty for kde4libs (LP: #1332064). Your work is very much appreciated and will keep Ubuntu users secure. Great job!16:32
ubottuLaunchpad bug 1332064 in kde4libs (Ubuntu Trusty) "[CVE-2014-3494] KMail/KIO POP3 SSL MITM Flaw" [Undecided,New] https://launchpad.net/bugs/133206416:32
jdstrand[TOPIC] Weekly stand-up report16:32
jdstrandI'll go first16:32
jdstrandfyi, I'm off all next week16:32
jdstrandI'm on triage this week16:32
jdstrandI'm helping test/coordinate the apparmor landing with mdeslaur today. I expect it to be pushed to the archive in a little while16:33
mdeslaur\o/16:33
tyhicksnice16:33
jdstrandI will be working on the ofono profiles bug this week, and any other June work items I can get to16:33
jdstrandI have a pending update I will hopefully get out later today16:33
jdstrandthat's it from me16:33
jdstrandmdeslaur: you're up16:33
mdeslaurI'm on community this week16:34
mdeslaurI just pushed out a few updates16:34
mdeslaurand am currently testing the apparmor and other packages that will get published16:34
mdeslaurI plan on taking a bite out of the long list of accumulating CVEs16:34
mdeslaurtomorrow, I'm on national holiday16:34
mdeslaurand I also have to write a wiki page about click store package signing16:35
mdeslaurthat's it from me16:35
mdeslaursbeattie: you're up16:35
tyhicksso you're planning on uploading the new apparmor and then splitting for day?? ;)16:35
mdeslaurtyhicks: SUCKS TO BE YOU!16:35
mdeslaur:)16:35
sbeattieI'm still working on pie by default for gcc/amd64.16:36
tyhicksheh :)16:36
sbeattie(mdeslaur: heh)16:36
jjohansen1tyhicks: don't be surprised if he is sick tomorrow16:36
mdeslaursbeattie: any progress there?16:36
sbeattieOne thing I discovered is that if an otherwise dynamically linked binary includes a libxxx.a, the object files in that .a file need to be compiled with -fPIE as well, which isn't a big deal when they're in the same package, but could introduce an ordering issue for situations where they're in different source packages.16:37
sarnoldinteresting, I hadn't heard that before.16:38
sbeattie(the apparmor parser does this, but since it's just internal to the source, it's not a big deal)16:38
sbeattiesarnold: yeah. I get a link time failure if they're not.16:38
sbeattieanyway. Other things for this week: I need to look at a mod_apparmor issue — I missed a note in the 2.2 -> 2.4 transition about the authentication hooks changing, which is causing some of people's problems with the HANDLING_UNTRUSTED_INPUT hat, I think16:40
sbeattieand other misc apparmor stuff.16:40
sbeattiethat's pretty much it for my week. tyhicks?16:41
tyhicksI'm wanting to wrap up my rtm work items this week16:41
tyhicks"review trust session and lp:trust-store for pid/APP_ID/apparmor/etc" has turned into a design discussion16:41
tyhicksand "verify kernel security features in phablet image (besides ufw and apparmor)" just needs a little bit of testing today before I send out the kernel config patches16:42
tyhicksI had done one swoop at verifying the kernel security features and enabled everything that we test for in QRT, but there's other things that we don't test for16:43
tyhicksthings that we're interested in but are not enabled in all of the touch kernels16:43
tyhicks(like ecryptfs)16:43
tyhicksso I'll add those config tests to QRT after I send out the patches16:43
sbeattietyhicks: thanks for that.16:44
tyhicksnp16:44
tyhicksthat's it for me16:44
tyhicksjjohansen1: you're up16:44
jdstrandtyhicks: design discussion?16:44
jjohansen1I'm working on my rtm WIs this week16:44
jdstrandtyhicks: does that mean you are blocked?16:44
jjohansen1I also have the latest revision for the touch kernels to land this week, as soon as the new userspace lands16:45
jjohansen1and I am off tuesday16:45
jdstrandjjohansen1: that should land today. does that mean as soon as it lands you can do the pull request?16:46
jjohansen1rtm WIs == apparmor extended mediation of unix sockets16:46
jjohansen1jdstrand: yes16:46
jdstrandcool16:46
jdstrandre your rtm work items-- would it help if tyhicks or sbeattie helped you if they put aside non-rtm work items?16:47
jdstrandif so, we can take that offline (just putting it out there)16:48
tyhicksjdstrand: no, I'm not blocked - my WI was to review the code and I guess that is technically done16:49
tyhicksjdstrand: now it has turned into a discussion on how to improve things16:49
jdstrandtyhicks: I see. update the work item as you see fit and continue guiding them as necessary :) thanks for taking that on16:50
jjohansen1that is it for me sarnold you are up16:50
jdstrandjjohansen1: did you see my question about help?16:50
jjohansen1jdstrand: not yet but soon, I'll poke them later in the week, wednesday, thursday,16:52
sarnoldI'm in the happy place this week, there's an openssl098 community update I'm still working on from last week, I'm still working on the qrt test-django script, and I'm hopeful for some apparmor patch reviews to distract me from the test-django work :)16:52
jjohansen1jdstrand: don't worry I'll poke you to join the party too16:52
jdstrandjjohansen1: ok, thanks16:53
sarnoldI think that's it for me, chrisccoulson?16:53
chrisccoulsonso, bug 1312082 is finished. I'm just waiting on something olivier is finishing before I merge it, so that I don't break his work16:54
ubottubug 1312082 in Oxide "Stop using deprecated compositing paths" [High,In progress] https://launchpad.net/bugs/131208216:54
chrisccoulsoni've got through some of my review queue :)16:54
chrisccoulsontoday, I started on bug 1332754, which should hopefully improve our memory usage a bit16:55
ubottubug 1332754 in Oxide "Evict frames for hidden webviews" [High,In progress] https://launchpad.net/bugs/133275416:55
chrisccoulsonother than that, it's business as usual :)16:55
chrisccoulsoni think that's me done16:56
jdstrandsarnold: there were some other reviews that are listed as work items that we talked about last week-- did you work on those, where are they prioritized for you?16:58
jdstrandchrisccoulson: re 1312082> nice!16:58
jdstrandchrisccoulson: seems like the media-hub/oxide integration is progressing well (which is part of your reviews I think)16:59
mdeslaurjdstrand, tyhicks, jjohansen1, chrisccoulson, sarnold, sbeattie: we're nearing the end of june. Please look at your assigned work items, and if anything is marked may or june and you won't be done in the next week, please let me know16:59
tyhicksack16:59
sbeattiemdeslaur: okay16:59
sarnoldjdstrand: I'd really like to be out from underneath this test-django script, so I was hoping to get it done. I'm sick of it. :)16:59
jdstrandsarnold: sure. how close are you?17:00
sarnoldjdstrand: it feels like another day or two17:00
sarnoldmdeslaur: ack17:01
jdstrandok, cool17:01
jdstrandI'm going to proceed-- chrisccoulson feel free to interrupt to answer my question whenever17:03
jdstrand[TOPIC] Highlighted packages17:03
jdstrandThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.17:03
jdstrandSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.17:03
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/merkaartor.html17:03
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/libipc-pubsub-perl.html17:03
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/gridengine.html17:03
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/autotrace.html17:03
jdstrandhttp://people.canonical.com/~ubuntu-security/cve/pkg/gajim.html17:03
jdstrand[TOPIC] Miscellaneous and Questions17:03
jdstrandDoes anyone have any other questions or items to discuss?17:03
jdstrand#endmeeting17:07
jdstrandmdeslaur, sbeattie, tyhicks, jjohansen, sarnold, ChrisCoulson: thanks!17:07
tyhicksthanks17:07
mdeslaurthanks jdstrand17:07
sbeattiethanks, jdstrand17:07
sarnoldthanks jdstrand17:08
jjohansen1thanks jdstrand17:11
=== vladk|offline is now known as vladk
=== vladk is now known as vladk|offline

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!