/srv/irclogs.ubuntu.com/2017/01/23/#ubuntu-meeting.txt

=== JanC_ is now known as JanC
=== JanC_ is now known as JanC
=== JanC_ is now known as JanC
tyhickshello16:30
tyhicks#startmeeting16:30
meetingologyMeeting started Mon Jan 23 16:30:14 2017 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:30
meetingologyAvailable commands: action commands idea info link nick16:30
tyhicksThe meeting agenda can be found at:16:30
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:30
tyhicks[TOPIC] Announcements16:30
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
tyhicksAhmed Farag provided notifications for false positive virus identification for files in the archive (pnsnap, ettercap-common, dbacl, and libmail-deliverystatus-bounceparser-perl).16:30
tyhicksScott Kitterman (ScottK) provided a debdiff for trusty for pdns-recursor (LP: #1656931)16:30
ubottuLaunchpad bug 1656931 in pdns-recursor (Ubuntu Trusty) "Security update for pdns-recursor on trusty" [High,Fix released] https://launchpad.net/bugs/165693116:30
tyhicksClive Johnston (clivejo) provided a debdiff for xenial for ark (LP: #1655507)16:30
ubottuLaunchpad bug 1655507 in ark (Ubuntu Yakkety) "CVE-2017-5330 - Ark: unintended execution of scripts and executable files" [High,Fix released] https://launchpad.net/bugs/165550716:30
mdeslaur\o16:30
tyhicksVishnu Vardhan Reddy Naini (visred) provided a debdiff for yakkety for ark (LP: #1655507)16:30
tyhicksThank you for your assistance in keeping Ubuntu users secure! :)16:30
tyhicks[TOPIC] Weekly stand-up report16:30
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
tyhicksjdstrand: you're up16:31
jdstrandThis week I plan to work on:16:31
jdstrand- various PR reviews (8 new ones since friday)16:31
jdstrand- miscellaneous apparmor policy updates16:31
jdstrand- prepare snap for testing security policy16:31
jdstrand- seccomp arg filtering policy16:31
jdstrandthat's it from me. mdeslaur, you're up16:31
mdeslaurI'm on community this week, so i'll be sponsoring a bunch of stuff16:31
mdeslaurI have a short week, I'm off on friday16:32
mdeslaurI plan on publishing a couple of usns this afternoon, and if I have time I'll be picking something from the list16:32
mdeslaurthat's it from me, sbeattie, you're up16:32
sbeattieI'm on bug triage this week16:32
sbeattieI'll have openjdk-8 packages from tdaitx to test and publish16:33
sbeattieI need to push some packages to the security pocket that recent linux-raspi2 kernels depend on.16:34
sbeattieafter that, I'll be going through the list looking for updates as well16:34
sbeattiethat's it for me, tyhicks?16:34
tyhicksI'm on cve triage this week16:34
tyhicksI will finish and submit the second revision of seccomp/libseccomp patches to upstream16:35
tyhicksI am also working on uploading AppArmor 2.11.0 to zesty but have hit some test failures that need to be sorted out first16:35
tyhicksI have an embargoed issue16:35
tyhicksany free time will go towards a security update16:35
tyhicksthat's it for me16:35
tyhicksjjohansen: go ahead16:35
jjohansenI will be looking into some outstanding bugs 1658219, and 165612116:36
ubottubug 1658219 in AppArmor "flock not mediated by 'k'" [Undecided,New] https://launchpad.net/bugs/165821916:36
jjohansenand probably a couple more16:36
jjohansenI have a nice stack of patches for the xenial/yakketty kernels that I need to cleanup and send up to the kteam16:37
jjohansenI will be doing some work on revising the dconf/gsetting patches and synching with will on them16:38
jjohansenand if I have any time I will be working on the next steps in upstreaming, likely the securityfs modification RFC16:39
jjohansenthats it for me, sarnold? you're up16:40
sarnoldI'm in the happy place this week; I expect to finish the uvp-monitor sorta-mir today, I'll file some bugs with upstream project for things i've found so far. I'm having trouble seeing the point of the thing compared to e.g. collectd or other popular tools...16:41
sarnoldso tyhicks, another suggestion for the next thing to undertake soon, but not immediately :)16:41
sarnoldalso I'm losing verbs at an astounding rate. good luck.16:42
tyhickssarnold: what's the suggestion?16:42
sarnoldtyhicks: hehe, the missing bit, "I need another suggestion" :) if it's another MIR or reactive or whatever16:42
ratliffI would vote for libapache2-mod-auth-mellon16:43
tyhicksI think there are some new MIRs that I need to add to the list16:43
tyhicksI bet ratliff's suggestion is the right one to take next16:44
sarnoldworks for me, thanks :)16:44
sarnoldthat's it for me, chrisccoulson?16:44
chrisccoulsonIt's firefox update week this week16:44
chrisccoulsonIn addition to that, I need to fix some issues in the ubufox extension caused by breaking changes in firefox 53 (removal of the non-standard 'for each' syntax)16:45
chrisccoulsonI'll also be spending time trying to get rust backported, but I need to talk to foundations first to agree how to split the work16:46
chrisccoulsonOther than that, I'll be working on oxide stuff, particularly work around JS dialogs16:46
chrisccoulsonthat's me done16:47
ratliffI'm in the happy place this week16:47
ratliffI will spend time working on updates for snappy-prev16:47
ratliffback to you tyhicks16:47
tyhicksthanks!16:48
tyhicks[TOPIC] Highlighted packages16:48
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:48
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:48
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/pxz.html16:48
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/ckeditor.html16:48
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/radicale.html16:48
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/elog.html16:48
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/gksu.html16:48
tyhicks[TOPIC] Miscellaneous and Questions16:48
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
tyhicksDoes anyone have any other questions or items to discuss?16:48
tyhickschrisccoulson: I wanted to ask what sort of deadline are we looking at for having rustc available in the archive in old stable releases that don't already include it?16:49
chrisccoulsontyhicks, I'm not entirely sure yet. Mozilla said firefox will depend on it in "early 2017", but that will give us between 12-18 weeks before it reaches stable16:52
tyhickschrisccoulson: ok, thanks16:52
chrisccoulsonSo we've still got 3 months, at least16:52
* tyhicks nods16:52
tyhicksjdstrand, mdeslaur, sbeattie, jjohansen, sarnold, ChrisCoulson, ratliff: Thanks!16:53
tyhicks#endmeeting16:53
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Jan 23 16:53:05 2017 UTC.16:53
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-01-23-16.30.moin.txt16:53
ratliffthank you, tyhicks!16:53
mdeslaurthanks tyhicks!16:53
jjohansenthanks tyhicks16:53
sarnoldthanks tyhicks!16:53
chrisccoulsontyhicks, in fact, it's better than that. Because it's release week this week, we've got 18 weeks (unless they sneak a hard rust dependency in today)16:56
chrisccoulsonAnd one of the release cycles is 8 weeks (over the easter holiday), which pushes that out to 20 weeks16:56
chrisccoulsonhttps://wiki.mozilla.org/RapidRelease/Calendar16:57
chrisccoulson(firefox 55 would be the earliest release with a hard rust dependency)16:57
tyhickschrisccoulson: that helps a lot - thanks16:59
tyhicksratliff: ^16:59
chrisccoulsontyhicks, I mean firefox 54 btw, but that's still 20 weeks (june 13th)17:02
tyhicksack17:05

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!