tyhicksThe meeting agenda can be found at:16:31
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:31
tyhicks[TOPIC] Announcements16:31
tyhicksStefan Bader (smb) provided a debdiff for precise for xen16:31
tyhicksAndreas Cadhalpun provided a debdiff for wily for ffmpeg16:31
tyhicksThank you for your assistance in keeping Ubuntu users secure! :)16:31
tyhicks[TOPIC] Weekly stand-up report16:31
tyhicksjdstrand: since you'll be in and out, let us know when you're "in"16:32
tyhicksmdeslaur: go ahead16:32
mdeslaurI'm on community this week16:32
mdeslaurI have a gnutls26 update to test and push out16:32
mdeslaurand I'm trying to reproduce an nss issue in xenial16:32
mdeslaurto do that, I'm trying to fix uvt to work properly with xenial16:32
mdeslaurand after that, I may work on some sudo updates that rebase xenial's version for older releases to finally fix the clock issue16:33
mdeslaurthat's pretty much it...sbeattie, you're up16:33
sbeattieI'm on bug triage this week.16:33
sbeattieOn the pie gcc front, I'm hip deep in kernel build process stuff, trying to figure out all the locations where to disable it.16:34
sbeattieI have an openjdk-6 update to test and push out, along with another package16:35
mdeslaursbeattie: I saw a gcc-5 upload with some peculiar changelog entries...did it get enabled?16:35
sbeattiemdeslaur: oh, I'm pulling the latest upload down right now, I haven't looked at the changelog.16:36
sbeattiedo ko sent me an email asking about stuff.16:36
tyhicks  * Add --enable-default-pie option to GCC configure, taken from the trunk.16:37
sbeattieah, woot!16:37
tyhicksnice :)16:37
mdeslaurdoes that mean it's on, or just that the option is added?16:38
mdeslaurbecause that's in the debian changelog part16:38
mdeslaurthen there's "* Configure with --enable-default-pie on s390x."16:38
sbeattieyeah, it looks like it just got turned on for s390x. interesting16:40
jjohansenno chance for regressions there16:41
sbeattieanyway, I'll still need to deal with fallout from that, so, along with a shortish week (friday off), that + usual email and kernel triage will probably consume my week16:41
sbeattietyhicks: you're up16:41
tyhicksI'm on cve triage16:42
tyhicksI need to send off my findings from my mapplauncherd review as well as the code and profile generation bits for confining the generic booster process16:42
jdstrandI'm in16:42
tyhicksjdstrand: go ahead16:42
jdstrandok, I'm catching up from holiday16:43
jdstrandpreparing for a sprint next week16:43
jdstrandhave an embargoed item16:43
jdstrandand finishing up some policy work on touch and snappy that I started before the holiday16:43
jdstrandthat's it from me16:43
tyhicksI also need to do snappy sprint prep16:45
tyhicksI have a review to do for the snapd socket access checks so that non-root processes can connect16:45
tyhicksand I'm still trying to get to unprivileged AppArmor policy loads inside of a user namespace16:45
tyhicksjjohansen: you're up16:45
jjohansenso I am primarily working on apparmor stacking this week16:46
jjohansenI have some ml followup to do, and some bug follow-up that could eat some time depending on testing16:46
jjohansenprimarily bug 1446906, that I am following16:47
ubottubug 1446906 in lxc (Ubuntu) "lxc container with postfix, permission denied on mailq" [Medium,Confirmed] https://launchpad.net/bugs/144690616:47
tyhicksjjohansen: could you send that fix to sarnold and myself for review?16:47
jjohansenthe kt also has an apparmor related bug in 4.3 that they are looking at, they think it might be test related16:47
sarnoldis that the caching timestamp bug?16:48
jjohansentyhicks: yeah, I want to clean it up a bit first, but I will send it out. Note that its on top of the larger 25 patch series16:48
jjohansensarnold: no, it is to due with mediation of a file based unix domain socket that has been shutdown16:49
sarnoldjjohansen: heh, sorry, I meant the one the KT reported that they think is test relatede16:49
jjohansensarnold: not sure, I have just seen the mention of it and that brad is looking into it16:50
jjohansenso its on my radar but I don't have details yet16:50
jjohansenoh, I should also get ahead of the curve and do the 4.4 rebase, and point tim and and andy at it16:50
sarnoldaha. I took a quick look at what they were talking about last week, and I couldn't figure out how on earth that test goes wrong. it feels like it'd be worth taking apparmor out of the equation on that one and try to write a reproduer that does't rely upon upstart ..16:50
jjohansenoh fun, looks like sarnold has volunteered to take that one off my hands :)16:51
tyhicksjjohansen: ISTR you and Tim talking at the sprint about how the 4.4 rebase required no changes from the 4.3 rebase so Tim was just going to handle it himself?16:51
jjohansentyhicks: that was the 4.3 rebase at the sprint, I haven't looked at 4.4 at all16:52
jjohansenthough I expect it is similar16:52
tyhickssarnold: you're up16:52
sarnoldi'm in the happy place this week16:52
sarnoldI'd like to take a short week this week (thinking friday off)16:53
sarnoldi will finish the libmicrohttpd mir, will start (and probably finish) the dpdk mir, catch up from holiday email, and hopefully review an apparmor patch or two16:53
sarnoldtyhicks feels like he's drowning this week, so perhaps steal a day of cve triage16:54
sarnoldthat's it for me, chrisccoulson?16:54
tyhicksI'll let you know16:54
chrisccoulsonSo, last week I got the camera working in the browser on the phone. I'm still ironing out some bugs with that (orientation is still messed up, and I'm seeing the device reset frequently as well)16:55
sarnoldwoo :)16:55
chrisccoulsonI also need to get someone to review my changes to libhybris, but I'm not sure who's responsible for that now16:55
chrisccoulsonOther than that, I plan to tackle the stuff I wanted to do last week but never got around to :) (bug 1447345), as well as the usual code review stuff16:56
ubottubug 1447345 in Oxide "Support the unprivileged namespace sandbox" [High,Triaged] https://launchpad.net/bugs/144734516:56
chrisccoulson(short week too - I'm out on wednesday)16:56
chrisccoulsonThat's me done16:56
tyhickschrisccoulson: nice to hear that the camera work is progressing :)16:57
tyhicks[TOPIC] Highlighted packages16:57
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:57
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:57
tyhicks[TOPIC] Miscellaneous and Questions16:58
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
tyhicksDoes anyone have any other questions or items to discuss?16:58
tyhicksjdstrand, mdeslaur, sbeattie, jjohansen, sarnold, ChrisCoulson: Thanks!16:59
jjohansenthanks jdstrand16:59
jjohansenthanks tyhicks16:59
sarnoldthanks tyhicks :)16:59
sbeattietyhicks: thanks!17:01
jdstrandtyhicks: thanks! :)17:07
