[15:00] <sil2100> o/
[15:00] <rbasak> o/
[15:00] <micahg`> o/
[15:00] <rbasak> handsome_feng: are you here?
[15:00] <bdmurray> o/
[15:00] <handsome_feng> rbasak: Yes :)
[15:02] <rbasak> We have quorum I think?
[15:02] <sil2100> I think we do, yes
[15:02] <rbasak> #startmeeting DMB
[15:02] <meetingology> Meeting started Mon Apr  9 15:02:28 2018 UTC.  The chair is rbasak. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
[15:02] <meetingology> Available commands: action commands idea info link nick
[15:02] <jbicha> o/
[15:02] <rbasak> #topic Review of previous action items
[15:02] <rbasak>     jbicha to add slahd to ubuntu-core-dev and send announcements (done)
[15:02] <rbasak> That's done then :)
[15:03] <rbasak> #topic Package Set/Per Package Uploader Applications
[15:03] <rbasak> #subtopic handsome_feng applying for ~ubuntukylin-dev
[15:03] <rbasak> handsome_feng: welcome! Please could you introduce your application?
[15:04] <handsome_feng> Hello,everyone, I'm handsome_feng, I've been an member of ubuntu kylin for more than 3 years,and I'm one of the administrators of that team, my main duties these days are develop/maintain UKUI and other kylin packages, and still sorry for my poor english,  I may reply you a bit slowly. Thanks! :) for reference: https://wiki.ubuntu.com/handsome_feng/UbuntuKylinDeveloperApplication
[15:06] <handsome_feng> Any questions? :)
[15:06]  * sil2100 is still reading the application
[15:10] <bdmurray> handsome_feng: Your application has nothing in the "What I like least in Ubuntu" section. Is there nothing you like least?
[15:10] <jbicha> handsome_feng: several UKUI packages are in Debian but they haven't been updated there recently. How would you get them updated in Debian?
[15:10] <cyphermox> handsome_feng: do you have examples of your work that are not ukui -- that are things you currently do not have access to upload yourself, not sponsored by Simon?
[15:12] <handsome_feng> bdmurray: Sorry, Maybe I missed that, but in fact, I have never thought that, I always notice the things I like
[15:14] <handsome_feng> jbicha: I will file a itp bug, but now we are focus on the update of UKUI and other kylin packages, when we finish the work in ubuntu , we will do that
[15:15] <jbicha> handsome_feng: ITP (Intent to Package) bugs are only for packages that are not yet in Debian. I'm curious if you know how to update packages that are in Debian
[15:16] <handsome_feng> cyphermox: In 17.10, the new ukui packages are uploaded by jbicha, does that counted?
[15:16] <cyphermox> handsome_feng: no, I mean things you upload that needed to be sponsored by someone
[15:18] <handsome_feng> jbicha: eee, sorry, I thought you mean the new ukui packages, to update an packages already in debian, we should upload it to mentors.debian.net and send RFS
[15:19] <jbicha> handsome_feng: thank you. That was the answer I was looking for :)
[15:20] <handsome_feng> cyphermox: When I have sometings that I need to be sponsored, I will file a bug, and subscribe ubuntu-sponrner team
[15:21] <jbicha> handsome_feng: I think you've only done one SRU. Is there a reason you haven't done more stable release updates?
[15:24] <handsome_feng> jbicha: We will do that when it need an sru, but the version before 17.10, we only have some applications in the iso, so we didn't need or we didn't find a bug in that applications
[15:25] <jbicha> ok
[15:31] <handsome_feng> cyphermox:  except UKUI, I also maintain kylin-greeter, ubuntukylin-default-settings
[15:32] <handsome_feng> ubuntu-kylin-docs and so on
[15:34] <handsome_feng> cyphermox: Do I understand your question correctly?
[15:35] <rbasak> handsome_feng: could you find some good examples of your sponsored uploads, please, that demonstrate the most complex type of work you've done on this packageset?
[15:41] <cyphermox> handsome_feng: yes, thanks
[15:42] <handsome_feng> rbasak: Maybe peony-extensions? I combine caja-extensions and engrampa.
[15:42] <rbasak> handsome_feng: which specific upload (including version) are you referring to please?
[15:44] <rbasak> handsome_feng: for me, a key part of assessing your application is to examine your work. Specifically your uploads for which you required sponsorship that you will no longer require sponsorship if your application is successful.
[15:44] <rbasak> handsome_feng: right now I'm struggling to find this work.
[15:47] <handsome_feng> rbasak: The initial version of peony-extensions, I update the rules and compat to fit the new debian policy, and check the license, fix the lintian warrings
[15:48] <rbasak> handsome_feng: OK. Do you have other examples please?
[15:48] <micahg`> right, but that's also something you maintain compared to other things in the UbuntuKylin packageset that aren't created by you
[15:49] <micahg`> s/maintain/created/
[15:54] <handsome_feng> micahg`: During the test of ubuntu kylin 18.04 beta, we find a bug in mate-terminal, we will file a bug about that , and support an patch. If a package in not maintain by me, I will not upload it directly, I will ping the owner.
[15:55] <micahg`> my point was, I think rbasak is looking for stuff that you've worked with in the UbuntuKylin flavour packageset that's outside of the packages that UbuntuKylin itself created
[15:55] <rbasak> Right.
[15:55] <handsome_feng> rbasak: Before upload an package, I always do that work(check the diff, build, and test)
[15:56] <rbasak> handsome_feng: I cannot assess an application without seeing examples of sponsored uploads.
[15:56] <rbasak> handsome_feng: I think you should update your application wiki to add links to them
[15:57] <rbasak> handsome_feng: they should be examples your work that required sponsorship and are in the packageset to which you're requesting direct upload access.
[15:59] <rbasak> handsome_feng: that's my personal opinion. Until I have this list and have reviewed it, I am not in favour of progressing your application.
[15:59] <rbasak> This isn't a rejection your application - I just feel that it is incomplete at the moment.
[16:00] <sil2100> I think most of handsome_feng's recent uploads are in the kylin packageset, so in theory those should fit your description
[16:00] <sil2100> Even though those were NEW uploads, I assume those will not stay in the initial versions forever
[16:01] <rbasak> How should we proceed?
[16:02] <bdmurray> I also would like to have the examples rbasak has requested.
[16:03] <handsome_feng> rbasak: Sorry, give me a litter more time, I'm looking up the dictionary..
[16:04] <micahg`> +1
[16:04] <micahg`> to the information :)
[16:07] <handsome_feng> Do you mean things like this?  https://bugs.launchpad.net/ubuntu/+source/ukui-settings-daemon/+bug/1760557 ?
[16:11] <handsome_feng> https://bugs.launchpad.net/ubuntu/+source/ukui-panel/+bug/1760789
[16:12] <sil2100> handsome_feng: ok, so we're discussing this now, and this is what we would like to get from you:
[16:13] <sil2100> handsome_feng: could you provide a list of your sponsored uploads that were not NEW packages but updates to existing packages in ubuntukylin?
[16:14] <rbasak> Please link directly to the upload. Example: https://launchpad.net/ubuntu/+source/ukui-session-manager/1.1.1-0ubuntu1
[16:14] <rbasak> We can find any relevant bugs from there.
[16:14] <sil2100> handsome_feng: you have recently published a lot of NEW packages, but we'd like to see a list of your uploads that were existing package updates
[16:15] <handsome_feng> sil2100, rbasak: Ok , I got you, sorry for my poor english...
[16:16] <rbasak> handsome_feng: no problem. We will look into improving the documentation for the application process.
[16:16] <rbasak> We are already over time. Shall we defer your application to the next meeting so that you have a chance to do that?
[16:17] <handsome_feng> rbasak: Fine, and sorry for the trouble, I will update my wiki page.
[16:19] <rbasak> #topic Expiring DMB seats
[16:19] <rbasak> I stuck this topic in to make sure it gets addressed.
[16:19] <rbasak> jbicha: I believe you're looking in to this? Mind if we give you an action for it please?
[16:20] <sil2100> Would be nice if we had the call for nominations ASAP, so that we have a DMB for the next meeting
[16:21] <jbicha> yes, does this look fine but bumping the number from "three valid nominations" to six? http://paste.debian.net/hidden/5ae4128b
[16:21] <micahg`> jbicha: can we say their membership is expiring please?
[16:22] <jbicha> s/will be expiring shortly/are expiring  ? sure, I guess
[16:22] <micahg`> or have reached the end of their terms?
[16:23] <rbasak> +1 to your pastebin and amendement
[16:24] <rbasak> #action jbicha to arrange call for nominations and election if required
[16:24] <meetingology> ACTION: jbicha to arrange call for nominations and election if required
[16:24] <rbasak> #topic AOB
[16:24] <rbasak> #subtopic Ubuntu GNOME packageset update
[16:24] <rbasak> I'm not sure what this means. Is someone organising an update?
[16:25] <jbicha> no real news about Ubuntu GNOME except there was a La_ney email today
[16:25] <jbicha> we're waiting on darkxst to update the seed
[16:26] <rbasak> #info We're waiting on darkxst to update the seed
[16:26] <rbasak> Thanks
[16:26] <rbasak> That's the end of the agenda.
[16:26] <rbasak> AO AOB/
[16:26] <rbasak> ?
[16:26] <rbasak> Thanks all!
[16:26] <rbasak> #endmeeting
[16:26] <meetingology> Meeting ended Mon Apr  9 16:26:53 2018 UTC.
[16:26] <meetingology> Minutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-04-09-15.02.moin.txt
[16:26] <micahg`> I think we should request a 1 month extension from the TB for the terms that are ending
[16:27] <micahg`> sorry I wasn't fast enough
[16:27] <rbasak> +1
[16:27] <rbasak> micahg`: would you be OK to take the action for that please?
[16:27] <micahg`> sure
[16:27] <jbicha> I can request that extension too
[16:27] <rbasak> I see no reason we need quorum to agree that or anything.
[16:28] <rbasak> Since it'll be a TB decision and anyone can obviously opt out.
[16:30] <sil2100> rbasak: thanks for chairing!
[16:31] <sil2100> As a side-note, as already mentioned on the ML I have refreshed the packagesets today
[16:31] <sil2100> So if anyone notices anything fishy, please poke
[16:33]  * ratliff looks around to see if the room is cleared and ready for the security team meeting :)
[16:34] <ratliff> #startmeeting
[16:34] <meetingology> Meeting started Mon Apr  9 16:34:25 2018 UTC.  The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
[16:34] <meetingology> Available commands: action commands idea info link nick
[16:34] <ratliff> The meeting agenda can be found at:
[16:34] <ratliff> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting
[16:34] <ratliff> [TOPIC] Announcements
[16:35] <ratliff> We have no announcements this week.
[16:35] <ratliff> [TOPIC] Weekly stand-up report
[16:35] <ratliff> jdstrand: you're up
[16:36] <mdeslaur> \o
[16:37] <ratliff> mdeslaur: why don't you go ahead. it looks like jdstrand is still wrapping up from a previous discussion
[16:37] <mdeslaur> I'm on bug triage this week
[16:37] <mdeslaur> I'm working on publishing some updates
[16:37] <mdeslaur> at the moment
[16:37] <jdstrand> sorry, I'm here. I'll go after mdeslaur
[16:37] <mdeslaur> and I have a couple of embargoed issues to look at
[16:37] <mdeslaur> if I have time, I'll pick something else off the list
[16:37] <mdeslaur> that's about it, jdstrand, you're up
[16:37] <jdstrand> https://github.com/ubuntu
[16:38] <jdstrand> let me try that again
[16:38] <jdstrand> This week I plan to work on:
[16:38] <jdstrand> - finish up miscellaneous updates branches for snapd (should be done this morning)
[16:38] <jdstrand> - enabling resquashfs enforcement in the review tools
[16:38] <jdstrand> - snap/usn notification (will start today)
[16:38] <jdstrand> - attend to high priority snapd reviews
[16:38] <jdstrand> - address conntrack deprecation issues in ufw for 18.04 SRU as have time
[16:38] <jdstrand> ratliff: note on the last point, I'm going to fix in SRU rather than release
[16:39] <ratliff> jdstrand: ack
[16:39] <jdstrand> ratliff: it requires a bit of work to do correctly and I got pulled aside in different ways last week
[16:39] <jdstrand> I worked on it, but not enough to have it ready for release
[16:39] <jdstrand> sbeattie: you're up
[16:39] <sbeattie> I'm on cve triage this week
[16:40] <sbeattie> I also have a bunch of kernel cve triage and signoffs to look at
[16:40] <sbeattie> I'm still working on the gcc-4.6 retpoline backport.
[16:40] <sbeattie> I also have a kernel qrt issue for bionic's kernel to sort out.
[16:41] <sbeattie> if I have time, I'll pick up an update.
[16:41] <sbeattie> that's it for me. sarnold, I think you're next?
[16:42] <sarnold> I'm in the happy place this week, running down the MIRs
[16:42] <sarnold> pv at the moment, I think socat up next
[16:42] <sarnold> that's it for me, chrisccoulson I think?
[16:43] <chrisccoulson> I'm expecting to have to do another thunderbird update this week
[16:43] <chrisccoulson> I've also got a couple of embargoed issues
[16:44] <chrisccoulson> I also plan to go through and triage all of the spidermonkey CVEs
[16:44] <chrisccoulson> I need to get python3.5 backported to trusty, as well as work on rust 1.25 updates, so I'm not too hopeful about being able to do anything fun this week
[16:45] <chrisccoulson> I think that's me done
[16:45] <ratliff> I'm in the happy place this week.
[16:45] <ratliff> I need to load the CVE triage data since January into Influx for the kpis.
[16:45] <ratliff> I have some internal work to do.
[16:46] <ratliff> I have sprint prep work.
[16:46] <ratliff> leosilva: you are up
[16:46] <leosilva> I'm community this week.
[16:46] <leosilva> I have a patch update to work
[16:46] <leosilva> Also a ruby cve triage/research before follow with ruby`s rounds 2 update
[16:46] <leosilva> other than that I'll hunting and grab new pkgs to udpate
[16:47] <leosilva> ratliff: it's back to you
[16:47] <jjohansen> I guess I'll squeeze in last
[16:47] <jjohansen> this week I am working on
[16:47] <jjohansen> - finishing up with LSM stacking work for bionic
[16:47] <jjohansen> - backporting all existing apparmor bug fixes for bionic
[16:47] <jjohansen> - the 4.17 apparmor pull request
[16:47] <jjohansen> - working on bug 1679704
[16:47] <jjohansen> - finishing up with the 2.13 changes for suse
[16:47] <jjohansen> - once that is done maybe I can start poking at the prompt mode work
[16:47] <jjohansen> ratliff: back to you
[16:47] <ratliff> thanks, jjohansen!
[16:47] <ratliff> [TOPIC] Highlighted packages
[16:48] <ratliff> The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so.
[16:48] <ratliff> See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.
[16:48] <ratliff> [TOPIC] Miscellaneous and Questions
[16:48] <ratliff> Does anyone have any other questions or items to discuss?
[16:51] <jbicha> y'all decided against doing a bionic archive-rebuild for spectre mitigation, right?
[16:51] <ratliff> jbicha: yes
[16:51] <ratliff> the performance regression was too high for a questionable security return
[16:52] <jbicha> performance regression? are only certain whitelisted packages using repotline?
[16:52] <jbicha> anyway, I don't want to hold up your meeting
[16:53] <ratliff> jbicha: we can discuss in #ubuntu-hardened
[16:53] <ratliff> jdstrand, mdeslaur, sbeattie, jjohansen, sarnold, chrisccoulson, leosilva: Thanks!
[16:53] <jbicha> sure, thanks
[16:53] <ratliff> #endmeeting
[16:53] <meetingology> Meeting ended Mon Apr  9 16:53:29 2018 UTC.
[16:53] <meetingology> Minutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-04-09-16.34.moin.txt
[16:53] <sbeattie> ratliff: thanks!
[16:53] <jdstrand> thanks ratliff! :)
[16:53] <jjohansen> thanks ratliff
[16:54] <doko> chrisccoulson: python3.5 for mozilla?
[16:54] <chrisccoulson> doko, yeah :(
[16:59] <sarnold> thanks ratliff!