/srv/irclogs.ubuntu.com/2018/10/09/#ubuntu-devel.txt

=== cpaelzer_ is now known as cpaelzer
seb128wgrant, cjwatson, hey, is there a way to know who is tweaking the translation template sharing details on launchpad? or to lock those settings down? looks like the "sharing with main serie" has been enabled for most desktop packages again, but that points to buggy/outdated code import on launchpad and prevent source package templates/translations to be imported, which result in outdated/buggy ubuntu translations :/08:39
seb128I'm chasing down those manually now, which is tedious and leading to no change rebuilds08:40
didrocksseb128: speaking of which (and maybe related to your question), I guess you noted as well that GNOME Shell has some part of the UI in English, correct?08:41
seb128didrocks, yeah, that was discussed on the desktop channel some days ago and an upstream bug in gnome-shell, we need to get the .1 update08:42
didrocksok, great :)08:42
sbrazhi, can someone explain what the +esm1 stands for here? https://people.canonical.com/~ubuntu-security/cve/2016/CVE-2016-7099.html08:44
ubottuThe tls.checkServerIdentity function in Node.js 0.10.x before 0.10.47, 0.12.x before 0.12.16, 4.x before 4.6.0, and 6.x before 6.7.0 does not properly handle wildcards in name fields of X.509 certificates, which allows man-in-the-middle attackers to spoof servers via a crafted certificate. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-7099)08:44
sbrazmy currently installed version is "4.2.6~dfsg-1ubuntu4.2" without the +esm1 part, which makes pakiti think that my system is vulnerable08:45
sbrazExtended Security Maintenance i guess? still, why doesn't the installed version match the version in the advisory?08:46
cjwatsonseb128: I don't really know the details of this but AFAIK none of that kind of thing has a very useful audit log08:46
cjwatsonsorry08:47
seb128cjwatson, no worry, I was sort of expecting it was the case based on the previous cycles conversations with William when that sort of issues happen08:47
seb128I'm probably going to write a script that goes through the pages (or use the launchpad api if it works for that, I need to have a look) and dump the sharing status08:47
xnoxsbraz, hi. What's published in ubuntu can be seen here https://launchpad.net/ubuntu/+source/nodejs10:15
xnoxsbraz, i don't know how Extended Security Maintenance works, you'd need to contact ESM support if you have that, and something is missing.10:15
sbrazxnox: yes and this page doesn't list the version https://packages.ubuntu.com/xenial/nodejs doesn't either10:16
sbrazxnox: and https://people.canonical.com/%7Eubuntu-security/cve/2015/CVE-2015-8860.html says "released-esm" for ubuntu 16 which doesn't make sense, 16 is still fully supported, isn't it?10:17
ubottuThe tar package before 2.0.0 for Node.js allows remote attackers to write to arbitrary files via a symlink attack in an archive. (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2015-8860)10:17
xnoxsbraz, fully supported, but we only provide security support for main.10:18
xnoxsbraz, node-tar and nodejs are from universe.10:18
sbrazxnox: so that ESM feature can be useful for xenial too?10:20
xnoxsbraz, looks like it, it seems to cover more. you should contact canonical sales about ESM.10:20
xnoxsbraz, i.e. https://buy.ubuntu.com/ has a chat thing and phone numbers too.10:21
sbrazxnox: what bothers me is that those esm packages which are not free are listed in https://people.canonical.com/~ubuntu-security/oval/com.ubuntu.xenial.cve.oval.xml10:26
=== hyperair is now known as Guest50288
jdstrandsbraz: Ubuntu 16.04 is still officially supported by Canonical for main/restricted and community supported for universe/multiverse. UA customers may receive updates beyond what is officially supported13:06
jdstrandsbraz: can you clarify why their inclusion in the oval data bothers you?13:08
sbrazjdstrand: it's always a bit frustrating to see vulnerable packages on my servers, i didn't even know ESM was a thing until today13:16
sbrazi thought a vanilla up-to-date ubuntu to have no vulnerable packages13:16
sbrazi assume if i were to run bionic, this wouldn't be an issue?13:17
JamieBennettsbraz: right13:18
jdstrandsbraz: nodejs is in universe and thus community maintained. packages that are community supported are kept up to date to the level that the community has invested time in them13:18
jdstrandsbraz: you might be interested in https://wiki.ubuntu.com/SecurityTeam/FAQ#Official_Support13:19
jdstrandhow does that page not say anything about esm... /me adjusts13:20
sbrazjdstrand: i understand, it's just that i never had to think about all this before; it just worked as expected in the past, it's the first time i stumble on that kind of package/vulnerability13:24
rbasakNothing has been taken away. You're just noticing more because Canonical are publishing more information for their customers and making some of that information public.13:26
jdstrandright13:28
xnoxsbraz, "in the past" you had vulnerable packages in universe installed and there were no updates for those available - neither gratis, nor paid. And well, was vulnerable to CVEs applicable to universe.13:29
sbrazxnox: i'm not saying it was better, just that i hadn't noticed :)13:36
xnox=))))))13:41
=== hypera1r is now known as hyperair
=== Sven_vB_ is now known as Sven_vB
sforsheeLocutusOfBorg: so I just got told about shared folders not working in Vagrant because of removing the vbox-guest-dkms modules from the kernel, bug 179664718:17
ubottubug 1796647 in cloud-images "Shared folders cannot be mounted in ubuntu/cosmic64 due to missing vbox modules" [High,Confirmed] https://launchpad.net/bugs/179664718:17
sforsheethe kernel packaging continues to say that it provides virtualbox-guest-modules, which it shouldn't18:17
LocutusOfBorgsforshee, the kernel should contain them... why did it drop them=18:18
LocutusOfBorg?18:18
LocutusOfBorgit has been using vboxvideo from the intree driver, and everything else from vbox modules18:18
LocutusOfBorgIIRC18:18
sforsheeLocutusOfBorg: we've talked about this several times ... we're using the upstream drivers now, you said you didn't want to seed vbox-guest18:19
sforsheethere should still be time to pull them back in though18:20
LocutusOfBorgok but only vboxvideo is upstream right now18:20
LocutusOfBorgI remember some of them being upstreamed IIRC18:20
sforsheewe must have gotten some wires crossed, I thought you said the others weren't important to ship in the kernel18:20
LocutusOfBorgvboxvideo is important if you want a good resolution18:21
LocutusOfBorgand yes, others are not fundamental, unless you want copy-paste from guest to host and such features18:21
Odd_Blokesforshee: As a sidenote, we do need these drivers in the official Ubuntu Vagrant image, which I think would preferably not rely on the DKMS modules.  (Not a hard requirement AFAIK, but would maybe nudge us more to retaining them.)18:23
sforsheeright ... I'm also now recalling that there was a conflict because the modules shipped upstream and in the dkms package have duplicated names18:23
sforsheeboth ship vboxguest.ko iirc18:23
sforsheeso probably we'll need to rename vboxguest that comes from the dkms package, is that going to cause issues?18:24
LocutusOfBorgwhy? is it causing problems?18:25
LocutusOfBorgthey have different directories, so there is no clash wrt apt side18:25
LocutusOfBorgand my vboxvideo has higher priority, something I want to have :)18:25
sforsheethe kernel build infrastructure does not expect modules with the same name when it is building, and does not handle it properly. I can't remember the specifics off the top of my head18:26
sforsheeI'm thinking it can't find symbols exported from one or the other18:26
LocutusOfBorgmmm so you are talking about the build farm...18:26
LocutusOfBorginteresting18:26
sforsheenot the build farm, all the makefiles and scripts which build the kernel18:27
sforsheeit may be some kind of namespacing thing, like I said I can't remember the exact details now18:28
LocutusOfBorgbut you don't have to copypaste my vboxvideo from vbox source tree, just the others18:28
sforsheebut I am thinking that something failed to link because it wanted exported symbols from one of the vboxgues modules but wasn't seeing them because they were masked by the other vboxguest module18:29
LocutusOfBorgI don't know...18:29
sforsheethe simple way to avoid it though is to rename one of them18:29
LocutusOfBorgwhat about providing "virtualbox-guest-video" kernel module?18:29
LocutusOfBorgand let the others come from my vbox source package?18:30
* LocutusOfBorg has to leave shortly18:30
sforsheethat doesn't fix it, we were already doing that18:31
sforsheeanyway, let me look into it18:31
LocutusOfBorgok18:32
* LocutusOfBorg leaves18:32
caravenaHello... What does it mean?: 'rls-cc-incoming'18:46
caravena^ Trevinho: Hello :-)18:46
caravena-> https://bugs.launchpad.net/bugs/1796422 You added the tag 'rls-cc-incoming'18:46
ubottuLaunchpad bug 1796422 in vte2.91 (Ubuntu) "Crash at encoding change" [Undecided,Confirmed]18:46
infinityvorlon, mdeslaur, kees, stgraber: Tee Bee.19:00
mdeslaurinfinity: ack19:00
jbichacaravena: it's used to suggest that that bug should be a priority for fixing for the CC (Cosmic) release19:04
jbichabugs with that tag will show up on http://reqorts.qa.ubuntu.com/reports/rls-mgr/rls-cc-incoming-bug-tasks.html19:05
jbichabugs can be fixed without that tag too19:05
caravenajbicha: Excellent! Thank you19:15

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!