[16:33] hello [16:33] #startmeeting [16:33] Meeting started Mon Feb 26 16:33:39 2018 UTC. The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [16:33] Available commands: action commands idea info link nick [16:33] The meeting agenda can be found at: [16:33] [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting [16:33] [TOPIC] Announcements === meetingology changed the topic of #ubuntu-meeting to: Announcements [16:33] The generalist role rotation for this week as follows: [16:34] CVE Triage: mdeslaur, Bug Triage: leosilva, Community: sarnold, Happy Place: ratliff, sbeattie [16:34] An all new version of the USN website (usn.ubuntu.com) will be deployed today [16:34] \o [16:34] Please report a bug (https://github.com/canonical-websites/usn.ubuntu.com/issues/) for any issue that you discover [16:34] Simon Deziel (sdeziel) provided a debdiff for artful for unbound (LP: #1723900) [16:34] Launchpad bug 1723900 in unbound (Debian) "unbound systemctl (re)start fails due to Apparmor profile issue" [Unknown,New] https://launchpad.net/bugs/1723900 [16:34] Thank you for your assistance in keeping Ubuntu users secure! :) [16:34] [TOPIC] Weekly stand-up report === meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report [16:34] jdstrand: you're up [16:34] tyhicks, will the new website mine cryptocurrencies in javascript? [16:34] hi! [16:35] * xnox giggles [16:35] xnox: not yet but you never know what the future holds [16:35] completed: miscellaneous snappy conversations [16:35] completed: store reviews [16:35] completed: discuss/review PR 4741 - cmd/snap-update-ns: use recursive bind mounts for writable mimic (layouts) [16:35] completed: strict snaps on livecd implementation: PR 4714 (address review feedback) [16:35] progress: investigate more issues with minecraft and opening URLs [16:35] completed: ubuntu-security meeting [16:35] mdeslaur: you're up [16:35] hah [16:35] wait :P [16:35] xnox: it's our new autopkgtest infrastructure [16:35] * be responsive to snapd PRs [16:35] - portals (getting close) [16:35] - layouts (landed, needs a little hardening for 2.32) [16:35] - steam-support (blocked on upstream feedback) [16:35] * strict mode snaps on livecd (close to landing) [16:35] * miscellaneous policy investigations and updates [16:35] * prepare for sprint [16:35] * lxd snap regression wrt confinement as have time [16:35] * create screencast interface as have time [16:35] ok, now mdeslaur you're up :) [16:36] you sure your paste buffer is empty now? ;) [16:36] I'm on triage this week [16:36] my password is ready to paste [16:36] I just pushed out a sensible-utils update [16:36] and I'm going to work on something new off the list [16:36] I also may have an embargoed issue [16:36] that's it from me [16:36] sbeattie: you're up [16:37] I'm in the happy place this week [16:37] * xnox thinks there is a glitch in jdstrand AI today, and a reboot is required. [16:37] I'm double-checking gcc-7, gcc-6, and gcc-5 packages with retpoline enabled by default for x86 for sponsoring today. [16:38] I'm also examining a glibc built by said compilers [16:38] sbeattie, nice =) gcc-8 as well? it's not default, but is available. And some libraries are coming from gcc-8, and used in userspace. E.g. libitm1 -> opencryptoki, etc. [16:38] xnox: not yet, but yeah, I hsuld do that, too [16:38] cool [16:39] I need to add the documentation bits to a patch to hardening retpoline options to dpkg, to support hardening=[+-]retpoline and submit to debian [16:40] There's other bits and bobs related to retpoline to track down in prep for starting the rebuild [16:41] (documentation, double-checking upstream for bug fixes, etc) [16:41] I need to prep a bit for the sprint next week [16:41] that'll consume my week, surely. tyhicks, over to you [16:41] thanks [16:41] * xnox silently pings rbalint to read above status update. [16:41] I've got sprint prep [16:42] I'll be cleaning up any messes found with the switch to the new USN website today [16:42] I need to finalize an LSM stacking demo [16:43] I've got an embargoed issue [16:43] I'll also be involved in the retpoline by default discussions/uploads/etc [16:44] that's it for me [16:44] jjohansen: you're up [16:45] oh, he's not around right now [16:45] sarnold: go ahea [16:47] sorry, I missed this window entirely! :) [16:47] I'm on community, short week for me this weeke [16:48] I expect to review some apparmor patches, then return to brotli MIR, and responding to questions on the openjpeg2 bugs I opened [16:48] and I ought to try to rebuild my poor little pandaboard before the trip. I don't know how realistic that is :( [16:49] that's me, chrisccoulson? or ratliff_ if chrisccoulson is still out? (sorry, can't recall) [16:49] vacation day for chris_ccoulson :) [16:50] I'm in the happy place this week. [16:50] I have sprint prep. I need to nurse the kpis along and touch up the tutorial. I have some internal tasks that I'm working on. [16:50] leosilva: it's up to you [16:50] I'm bug triage this week. [16:51] I'm take a look in qpdf cves, some of them has just test as patch - weird. [16:51] besides that I'll to my hunting [16:51] tyhicks: it's back to you [16:51] thanks! [16:51] s/to/do/ [16:51] [TOPIC] Highlighted packages === meetingology changed the topic of #ubuntu-meeting to: Highlighted packages [16:51] The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security [16:51] updates. If you have any questions, feel free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. [16:52] [TOPIC] Miscellaneous and Questions === meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions [16:52] Does anyone have any other questions or items to discuss? [16:53] jdstrand, mdeslaur, sbeattie, sarnold, ratliff, leosilva: Thanks! [16:53] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [16:53] Meeting ended Mon Feb 26 16:53:30 2018 UTC. [16:53] Minutes: http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-02-26-16.33.moin.txt [16:53] thanks tyhicks! [16:53] tks tyhicks! [16:53] tyhicks: thanks! [16:53] thank you, tyhicks! [16:55] thanks tyhicks! [16:58] tyhicks: thanks! [18:59] o/ [18:59] o/ [19:00] o/ [19:01] Maybe dmb-ping? [19:05] sil2100: [19:05] grr [19:05] et al [19:05] Maybe take this to the ML? [19:06] what? [19:06] Oh hi, that's 3 [19:06] tsimonq2: grr? Didn't you just edit wiki page about your app today? [19:06] I guess we might have quorum for a meeting, right? [19:07] bdmurray: grr = I messed up mobile keyboard [19:08] I will have to run at any moment. [19:08] np [19:09] tsimonq2: okay [19:09] bdmurray: I'm perfectly fine, I knew it was tight timing anyways :) [19:09] I'm a bit torn apart today, bdmurray, cyphermox - could one of you chair the meeting? [19:10] ok [19:10] I'm here as well [19:10] #startmeeting Developer Membership Board [19:10] Meeting started Mon Feb 26 19:10:54 2018 UTC. The chair is cyphermox. Information about MeetBot at http://wiki.ubuntu.com/meetingology. [19:10] Available commands: action commands idea info link nick === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Developer Membership Board Meeting | Current topic: [19:11] #topic Review of previous action items === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Developer Membership Board Meeting | Current topic: Review of previous action items [19:11] sil2100: to add budgie-extras to fossfreedom's PPU set [19:11] ^ that's done, cool [19:11] bdmurray: to handle mapreri's PPU-addition request [19:12] I submitted a bug report to that special project, let me have a look at it. [19:12] bug 1747093 [19:12] bug 1747093 in ubuntu-community " [TB/DMB] Additional PPU for mapreri" [Undecided,New] https://launchpad.net/bugs/1747093 [19:12] I'll ping a TB member about it. [19:13] bad TB :> [19:13] heh [19:13] alrighty [19:13] #topic Package Set/Per Package Uploader Applications === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Developer Membership Board Meeting | Current topic: Package Set/Per Package Uploader Applications [19:14] tsimonq2: the one issue I see though is that typically we ask to have a week's lead time to be able to review the application before doing the DMB meeting [19:14] Yes, I understand. [19:14] to be fair, let's make sure that's written down somewhere [19:15] It is, but it's a "should" ;) [19:15] It's documented already at https://wiki.ubuntu.com/DeveloperMembershipBoard/ApplicationProcess [19:15] I don't think we need to have a strict policy on it, since we can vote with our...votes as needed. [19:16] any DMB members here opposing the review today? [19:16] I know there were some questions of viability of application by email already [19:16] I thought rbasak had asked a question about the application. [19:16] I don't oppose, but I may end up being -1 subject to more information or time. [19:16] If indeed I'm here to vote. [19:16] bdmurray: That was solved I believe. [19:17] I am still struggling to understand exactly what is blocking on you not being able to upload these packages. [19:17] tsimonq2: I think a response should have been sent to the original query even if it was addresed out of band. [19:17] I found three uploads. Are there any more? [19:17] There's four packages in main. [19:17] rbasak: Yes, there's quite a bit more. [19:18] bdmurray: Sure, apologies. [19:18] tsimonq2: your third table seems to have uploads that you performed without sponsorship. [19:18] Which is great for the DMB to review of course. [19:18] It's useful to have in the application. [19:18] But first I'd like to understand what you're being blocked in uploading. [19:19] I can't land the stack via the CI Train myself because four packages in the stack aree in main. [19:19] And the best way to demonstrate that is with a list of sponsored uploads, so we can see your work, what sorts of uploads they were, who sponsored them, etc. [19:19] Sure, I understand. [19:21] For uploads, mitya57 and LocutusOfBorg sponsor things for me nowadays. [19:21] (With Qt.) [19:21] It's a bit hard to see who pressed the button on Bileto but it's been one of them. [19:22] I found three uploads> FTR, I think three is fine for an experienced uploader helping with transitions etc. [19:23] I haven't decided how you fit with that for myself yet though, because I'm not sure I understand (yet) your existing contributions. [19:23] OK; ftr I helped with the 5.7.1, 5.9.0, 5.9.1, 5.9.2 transitions in Debian and Ubuntu and 5.9.3 and 5.9.4 in Ubuntu only. [19:24] I did 5.9.3 and 5.9.4 myself, with 5.9.2 being mostly me [19:24] 5.9.0 was a joint effort. [19:24] OK, but what specifically did that involve for you in Ubuntu? [19:25] 5.9.2+ was merging from Debian or doing Ubuntu-specific uploads. [19:26] 5.9.2 was mostly syncs while 5.9.3+ is Ubuntu-only with the whole stack. [19:26] This also involved the normal transition stuff like no-change rebuilds, etc. [19:27] I did some work with 5.7 but that was *mostly* Mirv and mitya57, both of which have eendorsed my application. [19:27] Does that answer your questions? [19:28] For the record, this is 5.9.4: https://bileto.ubuntu.com/#/ticket/311 [19:28] er [19:28] https://bileto.ubuntu.com/#/ticket/3113 [19:28] With the exception of one qttools upload, that was all me. [19:30] I'm not done yet either, qtwebengine is building and should be ready to land tobnight, as well as qtwebview. [19:30] *tonight [19:31] Is that all for questions? :) [19:33] (Hello?) [19:33] Can I see some diffs of what you actually uploaded to Ubuntu with sponsorship? I'm not sure how to get that. [19:33] (apart from the three I found) [19:34] https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.9.3+dfsg-0ubuntu1 [19:35] https://launchpad.net/ubuntu/+source/qtsvg-opensource-src/5.9.3-0ubuntu1 [19:36] I'm on mobile so it's taking me a bit, but the 5.9.3 transition was sponsored via Bil [19:36] *Bileto [19:37] I believe LocutusOfBorg did the review and pressed the button. [19:37] 5.9.2 should be similar [19:38] https://launchpad.net/ubuntu/+source/qtbase-opensource-src/5.9.2+dfsg-4ubuntu1 [19:38] etc. [19:38] Would you like me to find additional uploads? [19:39] I personally need some more time to review specifically the diffs rbasak is requesting. [19:39] Sure, no problem. [19:39] * LocutusOfBorg is here in case you want some answer [19:40] You can also find a lot on the ubuntu+1 branches of the packages here: https://salsa.debian.org/qt-kde-team/qt// [19:40] To be clear I mean more time than I think we have in this meeting. [19:40] Alright, no problem at all. [19:41] Does the rest of the DMB concur? [19:41] I agree with bdmurray [19:41] Could you update your application so that we have a link to sponsored Ubuntu diffs please? [19:42] Alright. Can we continue this on the mailing list then? Thd d [19:42] Yeah [19:42] Continue on the ML, and we'll schedule another meeting when we're ready. [19:42] Sure. [19:42] Thanks everyone, [19:42] That diff is one of the three I had found :) [19:43] OK ;) [19:44] bdmurray: alright [19:44] tsimonq2: So to ease the process I think you could provide us specific links to diffs showing your work. [19:44] there's a core dev app for next month, yikes [19:45] let's go the rest of this review on the ML, though [19:45] bdmurray: Sure. [19:45] #topic AOB? === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | Developer Membership Board Meeting | Current topic: AOB? [19:45] Going back in time - I goofed about the PPU request and didn't email the TB. [19:45] I'll fix that today. [19:46] put an #action to review my ppu bug next time again? [19:46] mapreri: alrady there. [19:46] #action bdmurray to email the TB about mapreri's PPU. [19:46] ACTION: bdmurray to email the TB about mapreri's PPU. [19:46] anything else? [19:46] ta :) [19:47] I don't think so. [19:47] * rbasak has to run [19:47] ok, let's wrap this up [19:47] who's next chair? [19:47] I can [19:47] ack [19:47] #endmeeting === meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology [19:47] Meeting ended Mon Feb 26 19:47:53 2018 UTC. [19:47] Minutes: http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-02-26-19.10.moin.txt [19:47] thanks everyone! [19:48] cyphermox: thank you for chairing [19:48] Thanks! [19:48] bdmurray: can't you just add ~techboard to the bug subscribers? [19:48] bdmurray: Er, so uploads that I have upload access to and were sponsored + stuff in main, or just stuff in main? [19:48] cyphermox: thanks for chairing :) [19:48] Thanks everyone! Much appreciated :) [19:48] mapreri: That's not what our documentation regarding the process says. [19:49] bdmurray: ok (just to me it feels weird to file a bug the target people won't receive and then manually mail *shrug*) [19:50] tsimonq2: uploads which you have had sponsored for the four additional packages for which you are requesting upload rights [19:50] bdmurray: Sure, will do, thanks! [22:18] bdmurray, mapreri: it's not in the process because we can't actually do it (ACL restriction).