/srv/irclogs.ubuntu.com/2017/11/27/#ubuntu-meeting.txt

tyhickshello!16:31
leosilvao/16:31
chrisccoulsonwhoop16:31
* sbeattie waves16:31
tyhicks#startmeeting16:31
meetingologyMeeting started Mon Nov 27 16:31:45 2017 UTC.  The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:31
meetingologyAvailable commands: action commands idea info link nick16:31
tyhicksThe meeting agenda can be found at:16:31
tyhicks[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:31
tyhicks[TOPIC] Announcements16:31
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
mdeslaur\o16:32
tyhicksSimon Quigley (tsimonq2) provided debdiffs for trusty-artful for konversation (LP: #1731797)16:32
ubottuLaunchpad bug 1731797 in Kubuntu PPA "[CVE] Crash in IRC message parsing" [High,In progress] https://launchpad.net/bugs/173179716:32
tyhicksThank you for your assistance in keeping Ubuntu users secure! :)16:32
tyhicks[TOPIC] Weekly stand-up report16:32
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
tyhicksjdstrand: you're up16:32
tyhicksmdeslaur: go ahead16:34
mdeslaurI'm in the happy place this week16:34
mdeslaurI have three updates I'm about to release, including the remote code execution issue found in exim this weekend16:35
mdeslaurwe have exim compiled with PIE, so I don't think we have code execution16:35
mdeslaurbut updates are ready anyway16:35
mdeslaurafter that, I'll pick something up from the list, if leosilva left me any16:35
mdeslaurthat's about it16:35
mdeslaursbeattie: you're up16:35
leosilvahehe16:35
sbeattieI'm also in the happy place this week16:35
sbeattieMy primary focus is on CVE notifications for snap owners16:36
sbeattieI have an openjdk-7 update from td daitx to test and publish16:36
sbeattieI have some upstream apparmor tasks open16:36
* jdstrand is here (sorry)16:37
sbeattieand I have the usual bits of kernel cve triage to watch over.16:37
sbeattiethat's probably my week.16:37
sbeattiejdstrand: you want to jump in?16:37
tyhicksjdstrand: go ahead16:37
jdstrandyeah16:37
jdstrandThis week I am focusing on:16:37
jdstrand* email catchup from short week last week16:37
jdstrand* fix a review tools/store bug16:37
jdstrand* snapd PR reviews16:37
jdstrand* pickup the ssh/gpg interfaces PR16:37
jdstrand* investigate/implement proper fix for hotplugged devices not being added to device cgroup (mir input forum issue)16:37
jdstrand* investigate tun/tap intermittent spread failure as have time16:37
jdstrand* add kmod spread test as have time16:37
jdstrand* uid/gid privilege dropping as have time16:37
jdstrand* everything from ssh/gpg and after might change depending on an embargoed issue I might be asked to help with16:37
jdstrandthat's it from me. back to you tyhicks :)16:37
tyhicksI'm on community this week16:39
tyhicksI'll be catching up on email from being off all last week16:39
tyhicksI have several things that I need to nudge along this week but shouldn't require any real work on my side (snapd seccomp logging PR, libseccomp xenial SRU, audit SRUs, libseccomp-golang upstream PR)16:40
tyhicksI plan to focus on reproducable squashfs images16:41
tyhicksthere are two more ecryptfs kernel fixes that need to go into a 4.15 -rc release so I'll get to them as I have time16:41
tyhicksthat's it for me16:41
tyhicksjj is out16:41
tyhickssarnold: you're up16:41
sarnoldI'm on cve triage this week, and getting caught up on whatever I missed while enjoying a nice long weekend16:44
sarnoldapparmor patch reviews as I can, and finishing the embargoed review, starting on the next MIR on the list16:44
sarnoldthat should cover me, chrisccoulson?16:44
chrisccoulson I've got a thunderbird update to do this week (started already), and a firefox publication to finish off16:45
chrisccoulsonAnd then rust and cargo updates. I'm reasonably optimistic this one will go better than the last, and it shouldn't be too difficult16:46
chrisccoulsonI also need to figure out how hard it is to backport python versions for the firefox build16:46
tyhickshow many weeks before that's needed?16:47
chrisccoulsontyhicks, python or rust?16:47
tyhickschrisccoulson: python'16:47
chrisccoulsontyhicks, march for the actual release16:47
chrisccoulsonbut anytime now for trunk16:48
tyhicksack, glad you're thinking about it this early16:48
chrisccoulsonAnd then hopefully I'll have some time left to look at other things, finally16:48
chrisccoulsonthat's me done16:48
tyhicksratliff: your turn16:48
ratliffI'm on bug triage this week16:49
ratliffAfter that I will continue to be focused on internal tasks.16:49
ratliffon to you leosilva16:49
leosilvaI`m the happy place this week16:49
leosilvaI also will have  a short week (Tuesday is my Friday)16:49
leosilvaI have a postgresql-common to work and USN and some python that I'm waiting to push to ppas.16:50
leosilvaI also want to hunt some pkg and push in my list of TODO.16:50
leosilvathat ` all, tyhicks it is back to you16:50
tyhicksthanks16:51
tyhicks[TOPIC] Highlighted packages16:51
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
tyhicksThe Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.16:51
tyhicksSee https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:51
tyhickshttps://people.canonical.com/~ubuntu-security/cve/pkg/python-rsa.html16:51
tyhickshttps://people.canonical.com/~ubuntu-security/cve/pkg/percona-xtrabackup.html16:51
tyhickshttps://people.canonical.com/~ubuntu-security/cve/pkg/libpgf.html16:51
tyhicks[TOPIC] Miscellaneous and Questions16:51
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
tyhickshttps://people.canonical.com/~ubuntu-security/cve/pkg/python3.7.html16:51
tyhicksDoes anyone have any other questions or items to discuss?16:51
tyhickshttps://people.canonical.com/~ubuntu-security/cve/pkg/xine-ui.html16:51
tyhicksjdstrand, mdeslaur, sbeattie, sarnold, ChrisCoulson, ratliff, leosilva: Thanks!16:53
tyhicks#endmeeting16:53
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology
meetingologyMeeting ended Mon Nov 27 16:53:07 2017 UTC.16:53
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2017/ubuntu-meeting.2017-11-27-16.31.moin.txt16:53
mdeslaurthanks tyhicks!16:53
leosilvatks tyhicks!16:53
sarnoldthanks tyhicks!16:53
sbeattietyhicks: thanks!16:53
ratliffthanks, tyhicks!16:54
jdstrandtyhicks: thanks!16:55

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!