[16:30] <tyhicks> hello
[16:30] <tyhicks> #startmeeting
[16:30] <meetingology> Meeting started Mon Jun 19 16:30:45 2017 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
[16:30] <meetingology> Available commands: action commands idea info link nick
[16:30] <mdeslaur> \o
[16:30] <tyhicks> The meeting agenda can be found at:
[16:30] <tyhicks> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting
[16:31] <tyhicks> [TOPIC] Weekly stand-up report
[16:31] <tyhicks> jdstrand: you're up
[16:31] <jdstrand> hi!
[16:32] <jdstrand> in terms of what I planned to work on last week, I spent a lot of time on the bpf caching PR. I also did a lot of miscellaneous snappy PR and store reviews and I helped with an embargoed issue (unplanned)
[16:32] <jdstrand> the greengrass-support interface is now merged. Once I'm given a working devmode snap
[16:32] <jdstrand>  I will test it in strict mode and make any necessary policy adjustments
[16:32] <jdstrand> this week I plan to:
[16:32] <jdstrand> - continue to be response to the racy profile generation fixes PRs (ie, bpf caching and system-key). The bpf caching PR is pretty close to merging and shouldn't take too much more of my time
[16:32] <jdstrand> - pickup the password-manager-service interface work
[16:32] <jdstrand> - work on the overlayfs/apparmor/snaps investigation by filing various bugs
[16:32] <jdstrand> - finish the snappy-debug work to work with journald as have time
[16:33] <jdstrand> - miscellaneous snappy policy updates as have time as have time
[16:33] <jdstrand> that's it from me
[16:33] <jdstrand> mdeslaur: you're up
[16:33] <mdeslaur> I'm in the happy place this week, and it's a short week for me, I'm off on friday
[16:33] <mdeslaur> I'm currently releasing glibc and exim4 updates
[16:33] <mdeslaur> I'm working on ruby updates too
[16:34] <mdeslaur> I have a bunch of stuff to test this week
[16:34] <mdeslaur> that's about it
[16:34] <mdeslaur> hrm, steve's not here...who's next?
[16:34] <tyhicks> me
[16:34] <tyhicks> I'm on bug triage this week
[16:34] <tyhicks> I'm currently working on evaluating fscrypt for home dir encryption
[16:35] <tyhicks> still need to finalize a final design aspect of the seccomp logging patches
[16:35] <tyhicks> book upcoming travel
[16:35] <tyhicks> I have a remaining ecryptfs kernel patch to review
[16:36] <tyhicks> I will also help leosilva with the update publishing process and possibly with bug triage duties
[16:36] <tyhicks> jjohansen: you're up
[16:36] <jjohansen> urk
[16:36] <jjohansen> so I am working on publishing some USNs
[16:36] <tyhicks> jjohansen: I know you're busy with other things so just a few quick words is fine
[16:37] <jjohansen> I have some LSS stuff to take care of working on the schedule, book hotel and flight
[16:37] <jjohansen> I have some more upstream review, and investigation to finish
[16:38] <jjohansen> I have the namespacing patch set to push out an RFC for
[16:38] <jjohansen> and I need to get working on the networking/unix socket patchset so I can get an RFC up for it soon, as its the going to be the largest and most picked at of the outstanding work
[16:38] <jjohansen> I think that is it for me
[16:39] <jjohansen> I don't see sarnold yet, so back to you tyhicks
[16:39] <tyhicks> chrisccoulson_: you're up
[16:39] <chrisccoulson_> I've got a thunderbird update to do this week
[16:40] <chrisccoulson_> I'll also be spending some time trying to figure out how maintainable spidermonkey is
[16:40] <chrisccoulson_> also an embargoed issue
[16:40] <chrisccoulson_> That's me done
[16:40] <ratliff> I'm in the happy place this week
[16:40] <ratliff> I will continue working through updates for UC15
[16:41] <ratliff> Any remaining time will be spent on technical content and reporting.
[16:41] <ratliff> leosilva: your turn
[16:41] <leosilva> I've finished testing a libnl3 update for 12.04 ESM and I'll be publishing it soon
[16:41] <leosilva> I'll pick up another security update
[16:41] <leosilva> I'm also planning to try to train on one of the generalist's rotational roles.
[16:42] <leosilva> it's for me
[16:42] <leosilva> tyhicks: it's back to you
[16:42] <tyhicks> thanks
[16:43] <tyhicks> I don't see sarnold so we'll move on
[16:43] <tyhicks> he's on CVE triage duty this week and is working on MIRs
[16:43] <tyhicks> [TOPIC] Highlighted packages
[16:43] <tyhicks> The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.
[16:43] <tyhicks> See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.
[16:43] <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/gradle.html
[16:43] <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/python-tablib.html
[16:43] <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/batmand.html
[16:43] <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/nagvis.html
[16:43] <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/k4dirstat.html
[16:43] <tyhicks> [TOPIC] Miscellaneous and Questions
[16:43] <tyhicks> Does anyone have any other questions or items to discuss?
[16:45] <tyhicks> jdstrand, mdeslaur, jjohansen, sarnold, ChrisCoulson, ratliff, leosilva: Thanks!
[16:45] <tyhicks> #endmeeting
[16:45] <meetingology> Meeting ended Mon Jun 19 16:45:16 2017 UTC.
[16:45] <meetingology> Minutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-06-19-16.30.moin.txt
[16:45] <jjohansen> thanks tyhicks
[16:45] <ratliff> thanks, tyhicks!
[16:46] <jdstrand> tyhicks: thanks!
[16:46] <leosilva> tks tyhicks !
[16:46] <mdeslaur> thanks tyhicks
[19:00] <rbasak> o/
[19:00] <sil2100> o/
[19:00] <bdmurray> o/
[19:03] <sil2100> bdmurray: did we get any nominations for cyphermox's place?
[19:03] <cyphermox> o/
[19:04] <rbasak> Quorum!
[19:04]  * rbasak falls out of his chair
[19:04] <bdmurray> Its not quorum because cyphermox isn't on the dmb.
[19:05] <rbasak> Oh :-(
[19:05] <bdmurray> Who wants to be the meeting runner?
[19:06] <sil2100> I could
[19:06] <sil2100> Should be a quick meeting
[19:06] <sil2100> #startmeeting DMB
[19:06] <meetingology> Meeting started Mon Jun 19 19:06:18 2017 UTC.  The chair is sil2100. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
[19:06] <meetingology> Available commands: action commands idea info link nick
[19:06] <sil2100> #topic Review of previous action items
[19:07] <sil2100> I don't think we have too many of those, on the agenda I only see the one action from rbasak regarding Aron's request
[19:07] <sil2100> rbasak: did that get resolved in the end?
[19:07] <rbasak> I just followed up. I propose that we consider my action item done now, unless happyaron replies?
[19:07] <rbasak> (in which case we can pick it up as new work again)
[19:08] <sil2100> Ok
[19:08] <sil2100> Since we don't have anything else, let's move on
[19:08] <bdmurray> Works fo me
[19:09] <sil2100> #topic Board business
[19:09] <sil2100> A separate topic for that, I guess we're currently officially missing one person in the DMB
[19:09] <sil2100> Like, from the required 7-people
[19:10] <sil2100> + some others stopped attending
[19:10] <bdmurray> That's true we never received nominations when I sent the 2nd call out.
[19:10] <sil2100> cyphermox: did you want to re-apply?
[19:10] <cyphermox> yes
[19:10] <sil2100> ...you're in! DONE, let's go home
[19:11] <sil2100> Kidding, but yeah, in this case we only have one candidate, so I guess no voting here is needed?
[19:11] <bdmurray> rbasak: One idea we discussed at our sprint was reducing the number of members.
[19:11] <bdmurray> sil2100: but Adam's membership expires shortly
[19:12] <sil2100> We're anyway operating usually with 4-5 people
[19:12] <rbasak> bdmurray: wouldn't that make our lack of average attendance worse? Or is it really to reduce quorum?
[19:12] <rbasak> In which case, perhaps we should reduce quorum while keeping the membership size the same?
[19:12] <rbasak> (we might have to ask the TB for that)
[19:13] <sil2100> We could, but as said we anyway basically have 4-5 active board members
[19:14] <sil2100> And there doesn't seem to be much interest from other people to join the DMB
[19:14] <bdmurray> I guess its really to reduce quorum but we also have a few members who don't make meetings often.
[19:14] <sil2100> At least from the recent call for nominations
[19:14] <bdmurray> Is it worth keeping them on?
[19:15] <rbasak> Perhaps we should ask them. I appreciate the effort to try to sort this out, but I'm not sure that reducing the size of the DMB will help, as in the long term that just means that we have a smaller pool to try to find quorum from.
[19:15] <rbasak> OTOH, as you point out, we may not have much choice.
[19:16] <rbasak> But in that case, perhaps we can just leave some seats vacant, with a reduced quorum?
[19:16] <bdmurray> Leave them vacant with a permanent "help wanted" sign?
[19:17] <rbasak> Perhaps, yes. I haven't thought through possible consequences of this mind.
[19:18] <rbasak> And we could also ask the absent members if they want to step down, which would reduce our quorum (depending on its exact definition, but I think all would consider not counting vacant seats reasonable).
[19:18] <bdmurray> Okay, so we don't have quorum now in this meeting so I think the first bit of work should be getting cyphermox re-added for some period of time.
[19:18] <sil2100> Should we write down an action item for that?
[19:18] <rbasak> https://launchpad.net/~developer-membership-board/+members says he's current, until 4 August?
[19:19] <sil2100> Oh, indeed, wait, but we saw him being expired right?
[19:19] <bdmurray> Oh somebody sync'ed up him with Adam.
[19:19] <sil2100> I guess that's sorted out then..?
[19:20] <sil2100> I wonder who though
[19:20] <bdmurray> Not for long...
[19:20] <bdmurray> So which members should we reach out to?
[19:20] <rbasak> All those not here, IMHO.
[19:21] <sil2100> +1
[19:21] <rbasak> (which would then cover everyone)
[19:21] <sil2100> Who would like to get this action item?
[19:21] <bdmurray> If there are 3 people then 3 people can take it.
[19:22] <bdmurray> Rather than giving 1 person all the work lets divy it up.
[19:22] <sil2100> #action rbasak, bdmurray and sil2100 to ask absent DMB members if they want to continue being part of the DMB
[19:22] <meetingology> ACTION: rbasak, bdmurray and sil2100 to ask absent DMB members if they want to continue being part of the DMB
[19:22] <rbasak> ack
[19:23] <sil2100> Should I go and ask infinity maybe? Although I think I already can guess his answer
[19:26] <cyphermox> sil2100: bdmurray: infinity synced my expiration to his.
[19:26] <sil2100> Even with this covered we really need to discuss what next - maybe there will be more interest in a wider call for nominations? Maybe we should announce that somewhere else as well? bdmurray did you send it to the devel ML too?
[19:26] <sil2100> cyphermox: ah, ok
[19:26] <bdmurray> It made it to the fridge and stuff
[19:29] <bdmurray> rbasak: Could you draft an argument for why we should reduce quorum and keep the member count at 7?
[19:30] <rbasak> OK
[19:30] <bdmurray> At one point in time I thought someone mentioned you didn't *need* to be a core-dev to be on the dmb.
[19:30] <rbasak> I do recall that. Though I am dubious at the proposition TBH.
[19:31] <bdmurray> rbasak: The TB just reduced their member count IIRC - so maybe there's a reson for that.
[19:31] <rbasak> IIRC the TB reduced to become odd without sabdfl for draw-breaking purposes.
[19:32] <bdmurray> cyphermox, sil2100: Do you have an opinion on non core-devs in the DMB? My thought was if its okay we might get more applicants.
[19:33] <bdmurray> I'm not saying I'm in favor of it though.
[19:33] <sil2100> hm, wasn't it like that?
[19:33] <cyphermox> well the usual point was that not being a core-dev, you weren't as much in a position to evaluate on things you haven't necessarily done before
[19:33] <sil2100> I remember someone mentioning being part of the DMB while being MOTU
[19:33] <cyphermox> but I'm not sure even opening it to all developers will necessarily improve the response to calls for nominations
[19:34] <cyphermox> I think we've already been working with MOTUs and core-devs in the DMB in the past, it was never "just core-devs"
[19:35] <sil2100> I have no strong opinion here, but I would like someone to have at least MOTU privilages personally
[19:36] <sil2100> Although core-devs seem to be the best fit for board members, especially as per what cyphermox said
[19:36] <bdmurray> That's enough of a consensus for me then.
[19:37] <cyphermox> there's nothing wrong with not being in the core-dev or MOTU teams and being on the DMB per se
[19:37] <cyphermox> the idea is that those who evaluate applicants should be trusted, contributing members of the developer community (and that's why we submit DMB applicants to vote by the developer community at large)
[19:38] <rbasak> It's possibly not up to us anyway, but the TB.
[19:38] <cyphermox> the "knowing what you're talking about part" is kind of a side-effect of being able to get the votes to be elected.
[19:39] <rbasak> ...except when we can't get enough nominations for the seats available.
[19:39] <jbicha> I wasn't here earlier in the meeting, have you gotten any nominations yet?
[19:39] <cyphermox> in that context, we don't have much choice but to reduce numbers, or do away with the DMB altogether and let the TB deal with the applications
[19:39] <bdmurray> jbicha: No, we didn't really.
[19:40] <sil2100> jbicha: are you interested in nominating yourself?
[19:40] <jbicha> I was thinking about applying; I guess my biggest hesitation was the 2 year committment
[19:41] <bdmurray> That's only 52 meetings if that
[19:41] <jbicha> lol
[19:41] <bdmurray> We won't expect you on holidays
[19:42] <jbicha> ok, I'll go ahead and put my self-nomination in, probably later today
[19:43] <rbasak> Thanks!
[19:43] <sil2100> jbicha: thanks!
[19:43] <sil2100> Ok, I guess there's not much more we can discuss here, right?
[19:43] <bdmurray> sil2100: we should clarify who is following up with the inactive members. you have infinity?
[19:44] <sil2100> bdmurray: yeah, I'll take infinity
[19:44] <bdmurray> I can talk to ben, that leaves micah.
[19:45] <rbasak> That means me I think?
[19:46] <sil2100> Once we know how many 'free seats' we'll be having we can resume our discussion on what to do next
[19:47] <sil2100> Since from expirations we'll have 2 seats free but we already have 2 candidates, so that's settled - now depending if the inactive members want to still continue or not
[19:48] <bdmurray> rbasak: you or cyphermox
[19:51] <sil2100> rbasak: will you take care of micah?
[19:52] <rbasak> ack
[19:52] <bdmurray> sil2100: cyphermox should officially nominate himself too
[19:53] <cyphermox> I did send an email weeks ago
[19:53] <cyphermox> I will send it again
[19:53] <sil2100> You did? I probably missed it, a re-send would be welcome
[19:53] <bdmurray> Was it during the 1st call or the 2nd call?
[19:53] <sil2100> We'll re-visit the situation next week
[19:53] <sil2100> I mean, next meeting
[19:53] <sil2100> Anything else for board business?
[19:54] <bdmurray> That's all I can think of.
[19:54] <sil2100> #topic Any other business
[19:55] <sil2100> I guess no other business as well?
[19:55] <sil2100> Let's call it a day then
[19:55] <sil2100> #endmeeting
[19:55] <meetingology> Meeting ended Mon Jun 19 19:55:24 2017 UTC.
[19:55] <meetingology> Minutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-06-19-19.06.moin.txt
[19:55] <sil2100> Thanks everyone o/
[19:57] <rbasak> Thanks sil2100!