/srv/irclogs.ubuntu.com/2017/08/07/#ubuntu-meeting.txt

=== maclin1 is now known as maclin
=== fabo_ is now known as fabo
=== apw_ is now known as apw
=== fnordahl_ is now known as fnordahl
=== ogra_ is now known as ogra
=== marcoceppi_ is now known as marcoceppi
=== fginther` is now known as fginther
mdeslaur\o16:30
tyhicks#startmeeting16:30
meetingologyMeeting started Mon Aug  7 16:30:50 2017 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:30
meetingologyAvailable commands: action commands idea info link nick16:30
meetingology`Meeting started Mon Aug  7 16:30:50 2017 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:30
meetingology`Available commands: action commands idea info link nick16:30
* sbeattie waves16:30
chrisccoulsono/16:30
leosilvao/16:30
tyhicksThe meeting agenda can be found at:16:31
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:31
tyhicks[TOPIC] Announcements16:31
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
=== meetingology` changed the topic of #ubuntu-meeting to: Announcements
tyhicksheh, zero meeting bots last week and two meeting bots this week16:31
mdeslauroooh! bot fight!16:31
tyhicksJames Lu (tacocat) provided debdiffs for xenial-zesty for gnome-exe-thumbnailer (LP: #651610)16:31
ubottuLaunchpad bug 651610 in gnome-exe-thumbnailer (Ubuntu) "[CVE-2017-11421] Version number for .msi thumbnail is obtained from unreliable source" [Critical,Fix released] https://launchpad.net/bugs/65161016:31
tyhicksSimon Quigley (tsimonq2) provided debdiffs for trusty-xenial for lxterminal (LP: #1690416)16:31
ubottuLaunchpad bug 1690416 in lxterminal (Ubuntu Artful) "[CVE] socket can be blocked by another user" [Undecided,Fix released] https://launchpad.net/bugs/169041616:31
tyhicksSimon Quigley (tsimonq2) provided debdiffs for trusty-zesty for pcmanfm (LP: #1708542)16:31
ubottuLaunchpad bug 1708542 in pcmanfm (Ubuntu Zesty) "Fix potential access violation, use runtime user dir instead of tmp dir" [Undecided,Fix released] https://launchpad.net/bugs/170854216:31
tyhicksOtto Kekäläinen (otto) provided debdiffs for trusty for mariadb-5.5 (LP: #1705944)16:31
ubottuLaunchpad bug 1705944 in mariadb-5.5 (Ubuntu) "USN-3357-1: partially applies to MariaDB too" [Medium,Fix released] https://launchpad.net/bugs/170594416:31
tyhicksOtto Kekäläinen (otto) provided debdiffs for xenial for mariadb-10.0 (LP: #1698689)16:32
ubottuLaunchpad bug 1698689 in mariadb-10.1 (Ubuntu Artful) "USN-3269-1: partially applies to MariaDB too" [Undecided,New] https://launchpad.net/bugs/169868916:32
tyhicksOtto Kekäläinen (otto) provided debdiffs for zesty for mariadb-10.1 (LP: #1698689)16:32
tyhicksRoger Light (ral) provided debdiffs for trusty-zesty for mosquitto (LP: #1700490)16:32
ubottuLaunchpad bug 1700490 in mosquitto (Ubuntu) "Persistence file is world readable" [Undecided,Fix released] https://launchpad.net/bugs/170049016:32
tyhicksThank you for your assistance in keeping Ubuntu users secure! :)16:32
tyhicks[TOPIC] Weekly stand-up report16:32
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
=== meetingology` changed the topic of #ubuntu-meeting to: Weekly stand-up report
tyhicksjdstrand: you're up16:32
jdstrandhey16:33
jdstrandLast week I focused a lot on interface reviews (broadcom-asic-control, udev tagging,kvm, spi, avahi reimplementation. I also coordinated with the Desktop team wrt snaps on 17.10 desktop. I triaged the snapd-interface bugs and picked up the wayland work a bit.16:33
jdstrandThis week I plan to:16:33
jdstrand- finish going through the wayland interface (this has required quite a bit of investigation wrt interactions with snapd's setting of XDG_RUNTIME_DIR16:33
jdstrand- be responsive to various snappy PRs and feature discussions (eg, udev tagging, avahi, snapd user/groups, portals, etc)16:33
jdstrand- perform several PRs against snapd 2.27 for recent PRs that need to be in the next release16:34
jdstrand- pickup new 'desktop' interface for gnome-shell, plasma and sway as have time16:34
jdstrandthat's it from me16:34
jdstrandmdeslaur: you're up16:34
mdeslaurI'm on triage this week16:34
mdeslaurand I have a couple of updates to publish16:34
mdeslaurand after down, down the list, as usual16:34
mdeslaursbeattie: you're up16:34
sbeattieI'm in the happy place this week16:34
sbeattieI have a couple of kernel USNs to publish this morning16:35
sbeattieI have an embargoed issue on my plate16:35
sbeattieI'm stll waiting on openjdk-7 from td aitx, but might have that to publish this week16:36
sbeattieI'll  look at picking up other updates as well16:36
tsimonq2tyhicks: :D16:36
sbeattieI also have some apparmor bits and qrt bits to poke at.16:36
sbeattiethat's it for me. tyhicks, over to you...16:37
tyhicksI'm in the happy place this week16:37
tyhicksI will finish making changes to seccomp v6 kernel patch set, test, and submit upstream16:37
tyhicksneed to do fscrypt pam module review and packaging16:37
tyhicksstill need to familiarize myself with the latest LSM stacking patch set16:37
tyhicksI also still need to review jdstrand's snapd users/groups writeup16:37
tyhicksjjohansen: you're up16:38
jjohansenI am still working on upstreaming apparmor, specifically the type splitting needed to fixed the stored path issue in our unix domain sockets.16:38
jjohansenI will be doing some more testing of the LSM stacking kernel, and getting my feedback to Casey16:38
jjohansenI have some Ralley prep to take care of this week.16:38
jjohansenand if there is time some misc apparmor test suite issues to poke at16:39
jdstrandtyhicks: fyi, niemeyer ack'd that the users/groups write-up is accurate which I think is a precursor to his full review/comment16:39
jjohansenthats it for me sarnold you're up16:40
sarnoldI'm on community this week; also setting up rally travel, and working down the MIRs. Maybe review a patch or two from jjohansen if he think it'd be helpful.16:40
sarnoldthat's it for me, chrisccoulson?16:40
chrisccoulsonI've got firefox and chromium updates this week16:40
jjohansensarnold: oh yes16:41
chrisccoulsonI'm also in the process of updating rust to 1.19, but I've got an issue with 1.18 first. I imagine this will take up most of my week16:41
chrisccoulsonThat's me done16:41
ratliffI'm in the happy place this week16:41
ratliffI will be focusing on KPIs for the foreseeable future16:42
ratliffleosilva: you are up16:42
leosilvaI worked in a couple of update/finished the publishment today morning16:43
leosilvathis week I'm bug triage and also finish triage hope to get some updates too16:43
leosilvathat's it for me16:43
leosilvatyhicks: it's back to you16:43
leosilvaduh, I mean, soon finish triage*16:44
* tyhicks is catching up16:44
tyhicks[TOPIC] Highlighted packages16:45
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
=== meetingology` changed the topic of #ubuntu-meeting to: Highlighted packages
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:45
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:45
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/unrar-nonfree.html16:45
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/yaml-cpp.html16:45
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/qpid-proton.html16:45
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/freeciv.html16:45
tyhickshttp://people.canonical.com/~ubuntu-security/cve/pkg/inspircd.html16:45
tyhicks[TOPIC] Miscellaneous and Questions16:45
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
=== meetingology` changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
tyhicksDoes anyone have any other questions or items to discuss?16:45
sarnoldprobably it's worth adding http://people.canonical.com/~ubuntu-security/cve/pkg/varnish.html to that list, four or so community folks filed bugs but I don't recall seeing any debdiffs http://people.canonical.com/~ubuntu-security/cve/pkg/varnish.html16:47
tyhicksgood thought16:47
tyhicksI think varnish updates would be more useful than any of the ones I listed16:48
tsimonq2I can provide debdiffs within the next hour if someone can help me test them.16:50
tsimonq2Because it's a Universe package right?16:50
tsimonq2(yes, answered my own question)16:50
tyhickstsimonq2: you could post debdiffs, sarnold could sponsor them to the ubuntu-security-proposed PPA, and then we could ask for testing in the bug16:51
tsimonq2tyhicks: Works for me.16:51
tyhickstsimonq2: thanks!16:51
tyhicksjdstrand, mdeslaur, sbeattie, jjohansen, sarnold, ChrisCoulson, ratliff, leosilva: thank you!16:51
tyhicks#endmeeting16:51
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Aug  7 16:51:50 2017 UTC.16:51
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-08-07-16.30.moin.txt16:51
=== meetingology` changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingology`Meeting ended Mon Aug  7 16:51:50 2017 UTC.16:51
meetingology`Minutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-08-07-16.30.moin.txt16:51
tsimonq2tyhicks: np, let's follow up in #ubuntu-hardened :)16:51
mdeslaurthanks tyhicks16:51
jdstrandthanks tyhicks :)16:51
jjohansenthanks tyhicks16:51
leosilvathanks tyhicks!16:51
sarnoldthanks tyhicks!16:52
=== meetingology` is now known as meetingology
=== JanC__ is now known as JanC
=== meetingology` is now known as meetingology
=== meetingology` is now known as meetingology

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!