/srv/irclogs.ubuntu.com/2015/04/27/#ubuntu-meeting.txt

=== wolsen_ is now known as wolsen
=== bladernr_ is now known as bladernr-malta
mdeslaur\o16:32
tyhickshello16:33
tyhicks#startmeeting16:33
meetingologyMeeting started Mon Apr 27 16:33:24 2015 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:33
meetingologyAvailable commands: action commands idea info link nick16:33
tyhicksThe meeting agenda can be found at:16:33
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:33
tyhicks[TOPIC] Announcements16:33
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
tyhicksThanks to Rhonda D'Vine (rhonda) for help on security updates for the community supported wesnoth-1.10 last week. Your work is very much appreciated and will keep Ubuntu users secure. Great job! :)16:34
tyhicks(LP: #1445688)16:34
ubottuLaunchpad bug 1445688 in wesnoth-1.10 (Ubuntu Utopic) "private file disclosure issue (CVE-2015-0844)" [Undecided,Fix released] https://launchpad.net/bugs/144568816:34
tyhicks[TOPIC] Weekly stand-up report16:34
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
tyhicksjdstrand is busy atm so we'll skip him for now16:35
tyhickshe can jump in if he frees up16:35
tyhicksmdeslaur: go ahead16:35
mdeslaurI'm on community this week16:35
mdeslaurIm currently sponsoring ffmpeg16:35
mdeslaurtomorrow I have patch piloting duties16:35
mdeslaurI just published a few updates, and I have a couple more to test16:35
mdeslaurand I completely forgot about the openssl precise update that I started, which I'll look into again16:36
mdeslaurthat's about it form me, sbeattie?16:36
essembeI'm on bug triage this week16:36
mdeslauressembe: INTRUDER!16:36
tyhickswho's this guy16:36
essembeoh bah16:36
sarnoldhe looks shifty16:36
=== essembe is now known as sbeattie
sbeattieI'm on bug triage this week16:36
sbeattieI'm finishing up preparing the trusty apparmor SRU, I just have a couple of snags I hit to smooth out.16:37
sbeattieAnd then I'll switch to focusing on the gcc-pie work16:38
sbeattieI need to look at tyhicks patchset to support systemd, so we can land that work when W opens16:38
sbeattiethat's pretty much it for me. tyhicks?16:38
tyhicksmdeslaur: back to your openssl precise update - is that to enable tlsv1.2 by default for clients?16:39
tyhicksI'm on CVE triage this week16:41
tyhicksI have a short week and will be off Thursday and Friday16:41
tyhicksI need to circle back to a number of things that were ignored during the ramp up to the Vivid release16:41
tyhicksand I want to finish the kernel patches for AppArmor kernel keyring mediation16:42
tyhicksit would be nice if I could get those patches out for review before Thursday but I'm not sure16:42
tyhicksjjohansen: you're up16:42
mdeslaurtyhicks: yes, that's it16:42
tyhicksthanks16:42
jjohansenI have a short week this week, I will be off Friday16:42
jjohansenI have a couple backported CVE kernel fixes to look at and discuss with the kernel team16:43
jjohansenI also have a couple more apparmor patches to get out to the kernel team, so we can get the fixes into the next round of kernels16:44
jjohansenbug #143054616:44
ubottubug 1430546 in linux (Ubuntu) "apparmor kernel BUG kills firefox" [Medium,Triaged] https://launchpad.net/bugs/143054616:44
jjohansenbeing one of them (sorry I seem to have lost my browser tabs)16:45
tyhicksno problem16:46
jjohansenand then its back to the apparmor upstream cleanup. I plan to finish up with the domain transition cleanup/fixes this week (not that I didn't plan on finishing that bit last week :/)16:46
jjohansenI think that is it from me sarnold you're up16:47
tyhicksjjohansen: I noticed that a new AA kernel bug came in (LP: #1448912)16:47
ubottuLaunchpad bug 1448912 in AppArmor "BUG: unable to handle kernel NULL pointer dereference" [Undecided,New] https://launchpad.net/bugs/144891216:47
jjohansentyhicks: oh I hadn't noticed that one, yet. I'll poke at that one too, this week16:48
tyhicksthanks16:48
tyhickssarnold: go ahead :)16:49
sarnoldI'm in the happy place this week; I will be working more on openstack updates, and getting the hang of how the different openstack services work, etc.16:49
mdeslaursarnold: FYI, I think the updates in the ppa are now out of date, more CVEs came out in the meantime16:50
sarnoldI think I'll poke at the horizon service this week, and try to reproduce one of the issues on serverstack and try to find out if th e issue affects precise or not, and I'd love love love to get an update out the door, but .. thursdays always come so quickly16:50
sarnoldmdeslaur: yes, I think most of those updates are now stale :(16:51
tyhicksgetting an update out this week would be great since you're in the happy place16:51
tyhicksit is always a little more difficult on cve triage weeks16:51
sarnoldyes16:51
sarnoldso very much yes :)16:51
tyhickssarnold: do you plan on updating the packages with the new fixes?16:51
sarnoldtyhicks: I can give it  ashot, I haven't actually looked into the details of any of the fixed packages in the ppa, excepting the one horizon issue16:52
sarnold.. nor the details of the subsequently discovered CVEs16:52
tyhickssarnold: ok, we'll discuss it more in a little bit16:52
sarnoldI may also do some apparmor patch reviews for distraction along the way16:53
sarnoldthat's me, chrisccoulson?16:53
chrisccoulsonThis week, I need to get chromium out16:53
chrisccoulsonI'll also be working through code reviews (my queue is quite large now)16:53
chrisccoulsonAnd I'm currently looking at a browser crash on the phone16:54
chrisccoulsonOther than that, it's business as usual (hopefully)16:54
tyhicksthanks16:55
tyhicks[TOPIC] Highlighted packages16:55
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:56
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:56
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/mednafen.html16:56
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/prewikka.html16:56
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/rt-authen-externalauth.html16:56
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/forked-daapd.html16:56
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/mc.html16:56
tyhicks[TOPIC] Miscellaneous and Questions16:56
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
tyhicksDoes anyone have any other questions or items to discuss?16:56
tyhicksmdeslaur, sbeattie, jjohansen, sarnold, ChrisCoulson: Thanks!16:58
tyhicks#endmeeting16:58
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendar | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Apr 27 16:58:17 2015 UTC.16:58
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2015/ubuntu-meeting.2015-04-27-16.33.moin.txt16:58
sbeattietych0: thanks!16:58
jjohansenthanks tyhicks16:58
mdeslaurthanks tyhicks!16:58
sbeattiedouble bah.16:58
sbeattietyhicks: thanks!16:58
sbeattietych0: sorry.16:58
sarnoldthanks tyhicks16:58
micahganyone here to discuss anything at the DMB meeting, if not, we'l reconvene in two weeks since there's nothing on the agenda for today19:01
bdmurraymicahg: have the previous action items been taken care of?19:02
micahgwell, the first one is still out there, the second is done, I just need to send a follow-up message, but my E-Mail client wasn't being helpful before the meeting, I'll send that today19:03

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!