/srv/irclogs.ubuntu.com/2018/10/01/#ubuntu-meeting.txt

=== PeterRabbit1 is now known as Guest34489
jdstrandhi!16:31
* sbeattie waves hello16:32
jdstrand#startmeeting16:32
jdstrandThe meeting agenda can be found at:16:32
jdstrand[LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting16:32
meetingologyMeeting started Mon Oct  1 16:32:11 2018 UTC.  The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology.16:32
meetingologyAvailable commands: action commands idea info link nick16:32
jdstrand[TOPIC] Announcements16:32
=== meetingology changed the topic of #ubuntu-meeting to: Announcements
jdstrandFirst off, I'd like to warmly welcome joemcmanus to the team as our new security team manager. Glad to have you Joe! :)16:32
sbeattiewelcome, joemcmanus!16:32
jdstrandThe generalist role rotation for this week as follows:16:33
mdeslaur\o16:33
jdstrandCVE Triage: msalvatore (ebarretto), Bug Triage: sarnold, Community: sbeattie, Happy Place: amurray, mdeslaur, leosilva, ebarretto16:33
jdstrand[TOPIC] Weekly stand-up report16:33
=== meetingology changed the topic of #ubuntu-meeting to: Weekly stand-up report
jdstrandoh, I forgot one announcement16:34
jdstrandThe Ubuntu Security Team is hiring!16:34
jdstrandUbuntu Security engineer: https://boards.greenhouse.io/canonical/jobs/1158266?t=8c0a6c1f116:34
jdstrandok, I'll go first for standup16:34
jdstrandThis week I plan to:16:34
jdstrand* continue brand store snap declarations16:34
jdstrand* continue kubernetes-support interfaces16:34
jdstrand* various snapd PR reviews16:34
jdstrand* iterate on docker PRs16:34
jdstrand* embargoed issue16:34
jdstrandmdeslaur: you're up16:35
mdeslaurI'm in the happy place this week16:35
mdeslaurI just finished publishing a whole new ghostscript version to the stable releases to fix a bunch of security issues that don't have CVE numbers16:35
mdeslaurhopefully it won't cause any major regressions16:36
mdeslaurI have an embargoed issue to publish later on once upstream makes the issue public16:36
mdeslaurand I'll be continuing more CVE work after that16:36
mdeslaurthat's about it, sbeattie, you're up16:36
sbeattieI'm on community this week16:36
jdstrandmdeslaur: do you think it warrants a call for testing?16:37
mdeslaurwhat, ghostscript?16:37
sarnoldit's already out the door :)16:37
mdeslaurI already published it16:37
mdeslaurI tested the heck out of it16:37
jdstrandmdeslaur: yes, and, ok :)16:37
mdeslaurand judging by the number of open bugs against the old version, this one can only be better16:37
jdstrandmdeslaur: it was the 'hopefully' that threw me:)16:38
mdeslaurI will keep a look out for regression bugs16:38
* jdstrand nods16:38
jdstrandmdeslaur: thanks for taking that on. ghostscript can be challenging16:38
jdstrandsorry sbeattie, go ahead :)16:39
sbeattiekernel updates are being published now, will start the USNs for them after the meeting.16:39
sbeattieI have imagemagick packages in the ubuntu-security-proposed ppa that disable pdf/ps support, to avoid ghostscript (for all the reasons above) that I'll be testing and publishing.16:40
mdeslaur\o/16:40
sbeattieAfter that, I need to spend some time looking at possible addiitonal toolchain hardening for cosmic+1.16:40
sbeattieThat will probably take up my week.16:41
sbeattiejjohansen: over to you.16:41
jjohansenIts a short week for me, I am off Wednesday, Thursday, and maybe Friday.16:41
jjohansenI am still trying to finish up last weeks items, apparmor items for the 4.20 pull request: mjg secmark patch, kernel_t label for kernel network tasks, and the nonewprivs work.  LSM stacking patches, and the 2.10.4, 2.11.2, 2.12.1, 2.13.1 stable releases for apparmor16:41
jjohansenthats it for me, sarnold you're up16:42
sarnoldI'm on bug triage this week; I'm going to finish the xdg-desktop-portal-gtk MIR 1750069 this week, hopefully by tomorrow; then I'll run down the list of MIRs in trello. I'll do apparmor patch reviews as needed.16:43
sarnoldthat's it for me.. leosilva?16:43
leosilvaI'm in the happy place this week16:43
leosilvaI pushed a USN for bind9 for precise16:43
leosilvaI spent some time in a glib2.0 regression, but it eends as a no sec regression16:43
leosilvaI'll do the hunting pkg and find something to update - right now I'm digging on liblouis16:44
leosilvathat is it for me16:44
mdeslaurlibleo16:44
leosilvamsalvatore: I think it's up to you now16:44
leosilvahehe.16:44
msalvatoreHi all. I'm on CVE triage this week, but It's a super short week for me (I'm out oct2-oct12)16:45
msalvatoreebarretto will fill in for CVE triage16:45
msalvatoreI published fixes for uwsgi this morning16:45
msalvatoreI'm focusing on CVE triage and re-triage of older CVEs for today.16:45
msalvatoreebarretto: you're up16:45
ebarrettoI'm in the happy place/cve triage this week:16:46
ebarretto- Released today new opencv update for bionic16:46
ebarretto- Also released a new version of monit for xenial because of a regression in the last update (LP: #Bug:1786910)16:46
ebarretto- I am working on updating libav for trusty, right now I am testing the security fixes that were backported16:46
ebarretto- I will be doing CVE triage starting tomorrow to cover msalvatore16:46
ebarretto- If anyone finds any problem in uwsgi update from msalvatore, feel free to ping me and add me to bugs16:46
ebarrettothat's it for me ... joemcmanus you're up16:47
ebarrettojdstrand, did we skip chrisccoulson ?16:49
chrisccoulsonyep ;)16:49
chrisccoulsonshall I go now?16:49
jdstrandebarretto: he was skipped. I thought it was me now knowing who was out :)16:49
mdeslaurman, we keep forgetting chrisccoulson16:49
mdeslaurhe's too quiet16:49
chrisccoulsonlol16:49
jdstrandchrisccoulson: yes please :)16:49
jdstrandhey, I can't prove it, but I was thinking about it :)16:49
mdeslaurhehe16:49
ebarrettohehe16:50
chrisccoulsonI'm expecting a firefox release to test and publish this week, although the release hasn't happened yet16:50
chrisccoulsonI've got an embargoed update too16:50
chrisccoulsonand I'll be working on the libssh2 MIR16:50
chrisccoulsonthat shouldn't take all week, so I'll have time for something else (something else on the review queue?)16:51
chrisccoulsonthat's me done16:51
jdstrandchrisccoulson: I think so, yes, we getting to the end :)16:51
jdstrand[TOPIC] Highlighted packages16:51
=== meetingology changed the topic of #ubuntu-meeting to: Highlighted packages
jdstrandThe Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security16:52
jdstrandupdates. If you have any questions, feel free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.16:52
jdstrand[TOPIC] Miscellaneous and Questions16:52
=== meetingology changed the topic of #ubuntu-meeting to: Miscellaneous and Questions
jdstrandDoes anyone have any other questions or items to discuss?16:52
jdstrandmdeslaur, sbeattie, jjohansen, sarnold, chrisccoulson (see, I didn't forget!), leosilva, msalvatore, ebarretto, joemcmanus: thanks!16:54
jdstrand#endmeeting16:54
=== meetingology changed the topic of #ubuntu-meeting to: Ubuntu Meeting Grounds: Please leave swords by the door | Calendar/Scheduled meetings: http://fridge.ubuntu.com/calendars | Logs: https://wiki.ubuntu.com/MeetingLogs | Meetingology documentation: https://wiki.ubuntu.com/meetingology | <wxl> be nice
meetingologyMeeting ended Mon Oct  1 16:54:40 2018 UTC.16:54
meetingologyMinutes:        http://ubottu.com/meetingology/logs/ubuntu-meeting/2018/ubuntu-meeting.2018-10-01-16.32.moin.txt16:54
sarnoldthanks jdstrand!16:54
jjohansenthanks jdstrand16:54
ebarrettothanks jdstrand16:54
sbeattiejdstrand: thanks!16:55
leosilvatks jdstrand !16:55
chrisccoulson:)16:55
mdeslaurthanks jdstrand16:56

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!