/srv/irclogs.ubuntu.com/2018/01/04/#launchpad.txt

tsimonq2So is it intentional that I can't clone bzr branches from https but I can from http?01:53
wgranttsimonq2: Yes. It's recommended to use bzr+ssh.01:54
wgrantHTTPS is supported for git, but the only secure option for bzr is bzr+ssh01:54
tsimonq2Alright.01:54
tsimonq2wgrant: See the discussion in #ubuntu-release for why I ask, interesting case :)01:55
=== ePierre__ is now known as ePierre
rbasakcjwatson: we're downloading Sources files to work out what source packages exist and what component they're in for mass import purposes (allowing us to ramp up, etc). But these are plain HTTP downloads. Do you have any opinion on whether and how we should validate the downloads? Eg. if we verify gpg signatures, then what keyrings can we use, given we are also pulling historical series?13:39
rbasakAt the moment I think we're only looking at active Ubuntu series and sid, but eventually we'll need to expand that.13:39
rbasakOr is this overkill? If we're just getting source package names and component names and then hitting Launchpad securely, then we can only be DoS'd I think maybe.13:40
cjwatsonrbasak: The two "Ubuntu Archive Automatic Signing Key" keys in /usr/share/keyrings/ubuntu-archive-keyring.gpg are the only ones that have ever been used to sign the archive.13:40
cjwatsonI'd verify using those.13:41
rbasakThanks. Do you happen to know about Debian?13:41
cjwatsonA much larger set.  A current debian-archive-keyring package goes back a fair way at least13:42
cjwatsonYou might have to basically union all the debian-archive-keyring versions you can find13:42
rbasakOK. Is there any tooling we could use to help with the validation?13:42
rbasakSomething easier than setting up chdist would be nice :)13:42
cjwatson/usr/share/keyrings/debian-archive-removed-keys.gpg goes back to 200413:42
cjwatsonNot sure, sorry13:43
rbasakOK. Thanks!13:43
ricotzcjwatson, hi, is it possible to treat the pending firefox 58 beta builds like the 57.0.4 security builds? they also target "spectre" -- https://launchpad.net/%7Emozillateam/+archive/ubuntu/firefox-next/+packages15:17
Merlijn_SFYI: I came here to ask if the build farm is disabled. The topic answered my question but are you aware that `launchpad.net/builders` reports 0 disabled, 198 available?15:41
teward"198 available build machines, 0 disabled and 81 building of a total of 198 registered."15:41
tewardMerlijn_S: i fail to see what's wrong here?15:41
Merlijn_STopic is15:42
Merlijn_S> Build farm disabled for maintenance; no ETA yet15:42
=== teward changed the topic of #launchpad to: Launchpad is an open source project: https://dev.launchpad.net/ | This channel is logged: http://irclogs.ubuntu.com/ | User Guide: https://help.launchpad.net/ | Support: https://answers.launchpad.net/launchpad
tewardthey can put that back to the way it was, but it *looks* like it's 'up'?15:42
Merlijn_SAll my builds are estimated to complete in 1 hour. If I schedule a build, the estimated complete time just keeps incrementing every x minutes15:43
Merlijn_SEx: https://code.launchpad.net/~communitheme/+archive/ubuntu/ppa/+recipebuild/151302615:44
tewardbuild priority impacts this15:44
Merlijn_Sand https://code.launchpad.net/~communitheme/+archive/ubuntu/ppa/+recipebuild/151308015:44
acheronuksysadmin said yesterday they were putting the builders on 'manual'15:45
tewardacheronuk: are they still on manual?15:45
acheronukif you look at what is building, it's archive test rebuild backlog, and security team builds15:45
acheronukso I would guess they ahve been judged to be safe15:46
acheronukother stuff still seems on hold15:46
=== teward changed the topic of #launchpad to: Build farm disabled for maintenance; no ETA yet | Launchpad is an open source project: https://dev.launchpad.net/ | This channel is logged: http://irclogs.ubuntu.com/ | User Guide: https://help.launchpad.net/ | Support: https://answers.launchpad.net/launchpad
acheronukcjwatson wgrant: correct?15:47
acheronukI could be wrong :P15:51
acheronukweird that the test rebuilds now have a priority of > 100,00015:51
acheronuknormally they are tiny or -ve15:51
acheronukmaybe giving the canonical stuff stupidly high scores was the best way to selectively re-enable?15:53
* acheronuk shrugs15:53
dobeyi think only trusted things are allowed to build right now15:59
acheronukyes. whatever way that is being done, I would say so15:59
dobeyie PPAs are untrusted15:59
Merlijn_Sok, thanks for the explanation16:00
Merlijn_SIs there any place where I can receive updates on the state?16:01
dobeyyou can follow the launchpad status account on twitter, or check the topic in here i guess16:01
dobeyhttps://twitter.com/launchpadstatus/status/94868823302988185616:02
Merlijn_Sthanks, didn't know about that :)16:03
acheronukmight not be quick to sort: https://wiki.ubuntu.com/SecurityTeam/KnowledgeBase/SpectreAndMeltdown16:03
acheronukthat early disclosure 'bites'16:03
tewarddobey: that's problematic for me, I have an nginx merge I need to build test.16:04
tewardand i usually spin the multiarch build tests via PPA.  I presume it's nontrivial to permit a single thing to build then :/16:05
dobeyteward: well i guess you can build locally with sbuild, or try to hunt down someone with privileges to maybe allow the build. but i'd suggest the people in that latter category would be better spending their time on the task at hand to get things back up and running16:06
tewarddobey: the problem is the oddball archs16:06
tewardsbuild isn't nice with some of the non-arm oddball archs, at least on my system16:06
tewardi'll test locally and hope things don't explode when uploaded to -proposed16:07
tewardi presume also that the proposed uploads (for, say, merges) are also on hold?16:07
dobeyi think so16:07
acheronukI would guess so16:07
dobeyall i know is the world exploded16:07
acheronukmy last uploads to bionic are going no-where16:08
cjwatsonricotz: I think I'd need to consult on that, since they're non-Canonical uploaders16:26
cjwatsonMerlijn_S: We basically put emergency measures in place so the UI isn't everything it could be16:27
cjwatsonacheronuk: Manually scoring those up as a way to get them to build, yes; it's not that they're urgent, but they're low-risk and we might as well drain the queue while not much else is happening16:28
acheronukmakes sense :)16:28
ricotzcjwatson, i think you could consult chrisccoulson16:28
tewardcjwatson: is there details on what exploded?16:28
cjwatsonricotz: Yeah, just did, will enable in a bit16:29
cjwatsonteward: Well uhhhh you could consult pretty much any of the tech press16:29
ricotzcjwatson, thank you, firefox-trunk is basically the same if there are free cycles16:29
tewardi'm more or less hunting context (if you mean Spectre and Meltdown, well, that's its own little beast)16:29
tewardcjwatson: i'm a little late to catching up on things ;)16:30
cjwatsonricotz: I'd like to keep it to a minimum in terms of PPAs; firefox-trunk doesn't seem super-urgent for getting fixes out to users16:30
ricotzcjwatson, yeah, that is fine, the beta is far more used16:31
dobeyteward: yeah, being able to exfiltate the signing keys from launchpad would not be a good thing16:31
cjwatsondobey: signing keys are not at risk16:31
cjwatson(but I'm not going to go into more detail)16:32
cjwatsonricotz: firefox-next should be building now/soon16:33
ricotzcjwatson, thank you16:34
tsimonq2cjwatson: Are livefses for e.g. Lubuntu dailies whitelisted?18:02
tsimonq2cjwatson: If not, would it be possible to do so, or should we consider dailies no-go for now?18:04
cjwatsontsimonq2: No-go for now, sorry.18:56
tsimonq2cjwatson: Alright, understandable, thanks19:09
nacccjwatson: hey, so I finally heard back from the keyring folks re: https://github.com/jaraco/keyrings.alt/issues/23, which I think I was triggering with git-ubuntu's launchpadlib and the file keyring. It seems like the keyring backends, at least with Python3, are expecting a unicode string, not a base64 encoded string (a la credentials.py::KeyringCredentialStore.do_save(). Do you want a bug for that?19:49
cjwatsonnacc: Didn't you already file one?  https://bugs.launchpad.net/launchpadlib/+bug/168596220:24
ubot5Launchpad bug 1685962 in launchpadlib "keyring file-backend reports backtrace with oauth" [Undecided,New]20:24
nacccjwatson: ah so i did! :)20:26
nacccjwatson: sorry for the noise!20:26
cjwatsona cross-reference in that bug would be good though20:26
nacccjwatson: yep, doing so now20:27
cjwatsonI have the obvious patch in my working tree so can chase that up20:27
nacccjwatson: thanks!20:27
mitya57nacc, cjwatson: there is also bug 1685547, maybe one of them should be marked as duplicate?20:57
ubot5bug 1685547 in python-launchpadlib (Ubuntu) "Crash in python3 with the 'file' backend" [Undecided,Confirmed] https://launchpad.net/bugs/168554720:57
naccmitya57: thanks, definitely a dupe one way or the other21:16
naccmitya57: sorry i did't see that one when i filed21:16
mitya57It is filed against a different project (Ubuntu vs launchpadlib) so no need to be sorry :)22:21

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!