/srv/irclogs.ubuntu.com/2015/07/13/#ubuntu-meeting.txt

rdarwmajor00:49
=== ubott2 is now known as ubottu
jdstrandhi!16:32
mdeslaur\o16:32
tyhicks#startmeeting16:32
tyhicksThe meeting agenda can be found at:16:33
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:33
tyhicks[TOPIC] Announcements16:33
* tyhicks kicks the meeting bot16:33
tewardtyhicks: possible it's down with all the other bots?16:34
tewardif you'd like i'll drop Archangel (my bot) in here, then provide a publicly accessible copy of the logs for you for the meeting.16:35
tewardor pull it from my raw logs here on my client16:35
tyhicksteward: possibly - I'm not aware of any others being down16:35
tyhicksteward: thanks but I've got a logger going16:35
tewardack16:35
tyhicksI guess I'll just proceed16:36
* teward lurks16:36
tyhicks[TOPIC] Announcements16:36
tyhicksThanks to Otto Kekäläinen (otto) for providing a debdiff to update mariadb-10.0 in vivid (LP: #1451677)16:36
ubottuLaunchpad bug 1451677 in mariadb-10.0 (Ubuntu) "USN-2575-1: MySQL vulnerabilities partially also applies to MariaDB" [Medium,Fix released] https://launchpad.net/bugs/145167716:36
jdstrandfyi, in the past when the bot was down I just pasted the irc into the wiki page rather than pointing it somewhere else16:36
tyhicksok16:36
jdstrand(at the end of the meeting)16:36
tyhicks[TOPIC] Weekly stand-up report16:36
tyhicksjdstrand: you're up16:36
jdstrandtoday we had the oobe meeting with design. it went well, there are followups and discussions that need to be had that we'll capture in trello16:37
jdstrandI need to continue going over the IoM summaries and takeaways16:37
jdstrandI've got an embargoed item I am working on16:37
jdstrandI'd like to finish up the ubuntu-personal-security policy bits16:38
jdstrandthen pick up a card as have time16:38
jdstrandmdeslaur: you're up16:38
mdeslaurI'm on bug triage this week16:39
mdeslaurit's a short week for me as I'm on holiday friday and monday16:39
mdeslaurI'm working on a certificate issue in the ca-certificates package which I hope will be fixed soon16:39
mdeslaurand I'm going down the CVE list16:39
mdeslaurI'll probably be stealing the in-progress nbd updates from sbeattie16:40
mdeslaurthat's about it, sbeattie, you're up16:40
sbeattieI'm on cve triage this week16:40
sbeattieI'm trying to finish up the last patch reviews needed for an apparmor 2.10 release that we can pull into wily16:40
sbeattieI need to look at doko's gcc-5 plans16:41
sbeattieand that will probably consume my week16:41
sbeattietyhicks: you're up16:41
tyhicksI'm in the happy place this week16:42
tyhicksI had a little bit of community sponsoring work left over from last week that I did this morning (smoke test and publish mariadb-10.0)16:42
tyhicksI will review the kdbus LSM hook patch set this week16:42
tyhicksI need to determine the best way to fix an auditing bug in the phone images (I've already sent a patch that will fix the issue in new kernels)16:43
tyhicksI want to get back to my UCT-to-trello bridge16:43
tyhicksand I have several embargoed issues16:43
tyhicksI think that's it for me16:44
tyhickssarnold: skipping to you as I don't see jj16:44
sarnoldI'm on community this week, if someone wants to tackle updates for http://people.canonical.com/~ubuntu-security/cve/pkg/proftpd-dfsg.html I know a few users would appreciate the fixes; I'll also be working on the ppc64-diag "follow-on" package auditing; upstream suggested that we audit git instead, which makes some sense, I hope they can be repackaged for our 14.04.3 release quickly enough.16:45
sarnoldthat's it for me, chrisccoulson?16:45
chrisccoulsonAfter last week, I was hoping to get through some Oxide reviews this week and carry on with https://launchpad.net/oxide/+milestone/branch-1.916:46
chrisccoulsonBut Firefox has something to say about that16:46
tyhicks:/16:47
chrisccoulsonI've got 1 embargoed update to do, and I also need to do the thunderbird update16:47
chrisccoulsonthat's me done16:47
sarnoldwould it make sense at some point to revert precise back to a firefox ESR release?16:47
jdstrandchrisccoulson: I asked in the other channel. is there something I/we can do to help with firefox?16:47
chrisccoulsonI'm not sure atm. I'd like to be able to reproduce this crash, but I can't16:48
tyhicksthe 14.04 crash?16:48
chrisccoulsonYeah16:48
tyhicksI can try in a VM16:49
chrisccoulsonThat's what I'm doing at the moment too16:49
dokosbeattie, please delay any config changes until the GCC 5 transition is done16:49
dokoit's already ugly enough16:49
sbeattiedoko: okay16:49
tyhickschrisccoulson: ok, I'll get my trusty-amd64 vm updated and let you know what happens16:50
chrisccoulsonthanks16:50
tyhickssbeattie: I guess that means you should have full focus on aa 2.10 and getting it uploaded to wily this week16:50
tyhickssbeattie: if that goes quickly, picking up a MIR would be a good idea16:51
sbeattietyhicks: I forgot I had another thing on my plate, finishing up fixing QART issues on arm6416:52
tyhicksah, ok16:52
tyhickssbeattie: those are seccomp test failures, right?16:52
tyhicks(due to symbol craziness)16:53
tyhicksyou can tell me later16:54
sbeattieno, this is the test-kernel-security.py stuff, dealing with and testing for different configs16:54
tyhicksoh16:54
tyhicksok16:54
tyhicksmoving on16:54
tyhicks[TOPIC] Highlighted packages16:54
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:54
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:54
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/boost1.48.html16:54
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/jython.html16:54
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/dhcpcd5.html16:54
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/charybdis.html16:54
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/texmacs.html16:54
tyhicks[TOPIC] Miscellaneous and Questions16:54
tyhicksDoes anyone have any other questions or items to discuss?16:54
tyhicksjdstrand, mdeslaur, sbeattie, sarnold, ChrisCoulson (and teward): Thanks!16:56
mdeslaurthanks tyhicks!16:56
tyhicks#endmeeting16:56
sbeattietyhicks: thanks16:57
sarnoldthanks tyhicks!16:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!