/srv/irclogs.ubuntu.com/2021/06/29/#ubuntu-meeting.txt

=== not_phunyguy is now known as phunyguy
=== genii is now known as genii-core
=== not_phunyguy is now known as phunyguy
cpaelzerpre-ping for MIR ddstreet doko sarnold didrocks jamespage14:29
* cpaelzer lights a multi-dimensional campfire (for those with flooding it is warm and dry, for those with heat issues it is a cooling fire, for everyone else it is whatever they need)14:29
cpaelzer#startmeeting Weekly Main Inclusion Requests status14:30
meetingologyMeeting started at 14:30:25 UTC.  The chair is cpaelzer.  Information about MeetBot at https://wiki.ubuntu.com/meetingology14:30
meetingologyAvailable commands: action, commands, idea, info, link, nick14:30
cpaelzerno old actions to look at14:30
cpaelzer#topic current component mismatches14:30
didrockshey14:30
cpaelzer#link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg14:30
cpaelzer#link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg14:30
sarnoldgood morning14:31
cpaelzerhiho14:31
sarnoldI like this multidimensional fire idea14:31
cpaelzerthese seem to contain the same as recently14:31
cpaelzerlet us check the status14:31
cpaelzerfence-agents still on security via https://bugs.launchpad.net/ubuntu/+source/fence-agents/+bug/192700414:31
ubottuLaunchpad bug 1927004 in fence-agents (Ubuntu) "[MIR] fence-agents" [Undecided, New]14:31
cpaelzercherrypy on jamespage14:32
cpaelzeroh this one14:32
cpaelzerscreen-resolution-extra -> policykit-1-gnome14:32
didrocksthis is an alternative, I remember we used to have already c-m picking the wrong one and we had to workaroudn it, but did anyone of you remember what we did exactly?14:32
cpaelzerdidrocks: you said last week you wanted to take a loolk14:32
didrockshttp://launchpadlibrarian.net/544364041/screen-resolution-extra_0.18build2_0.18.1.diff.gz14:32
cpaelzerlook14:32
didrocksit’s fullfiled by gnome-shell already14:32
cpaelzerok so we consider this done and it will vanish from this view in some time14:33
cpaelzerthanks didrocks14:33
didrockscpaelzer: no no14:33
didrocksit’s not done14:33
cpaelzeroh14:33
didrocksthe issue is triggered by this diff14:33
cpaelzerthen I misinerpreted "fulfilled"14:33
cpaelzeroh I see14:33
cpaelzerthanks14:33
didrocksand this diff is for every flavor not picking up gnome-shell14:33
didrocksso, the issue is in component-mismatch14:33
didrocksand I don’t remember how we workarounded it in other cases in the past…14:34
sarnoldI think "oh that's a holdovre from..."14:34
sarnold(like terminator, esmtp, etc)14:34
didrocksyeah14:35
cpaelzeryes14:35
cpaelzer+ policykit-1-gnome | gnome-shell | polkit-1-auth-agent,14:35
cpaelzerok I'll try to remember this is part of that group14:35
cpaelzerthanks for checking didrocks14:35
didrocksyw14:35
cpaelzer#topic New MIRs14:35
cpaelzer#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir14:35
cpaelzerstill no action by doko on flashrom/libftdi :-/14:35
cpaelzerI'll contact him and matt offline via a mail14:36
* didrocks is surprised on busybox not being in main…14:36
cpaelzeras I'd love to get it out of this stage in some way (continue or abort it)14:36
cpaelzerdidrocks: lets us talk about busybox14:36
cpaelzerI guess we can agree and promite it right away14:36
cpaelzerTL;DR busyboy is in main, this is about an extra binary from the src package to be promoted14:36
cpaelzerUsually people ask that on the old MIR bugs14:37
cpaelzerbut this one is so old, it has no MIR bug14:37
sarnoldI wouldn't be surprised if there's outstanding cves in busybox that we've ignored, something like their tools for downloading files don't check tls certificates..14:37
didrocksah ack only one binary missing, I was wondering for a while with what I was playing after happy testing in casper :p14:37
cpaelzersarnold: why would those have been ignroed?14:38
cpaelzeras far as I ahve looked it seems to be a differnt build from the same source14:38
cpaelzerso no "new code" to be promoted14:38
cpaelzerI'd like to understand why in this scenario CVEs would have been ignored, to get a feeling if this needs only MIR ack or also security re-review14:38
didrocksyeah, it’s only the dynamic linking (the static is in main) if I read the MIR correctly14:38
cpaelzeryes didrocks - that should be it14:39
sarnoldcpaelzer: because busybox is often used in environments where 'the usual things' are broken / missing / intentionally unavailable14:39
cpaelzerah but now you could use it in "others environments"14:39
sarnoldyeah14:39
cpaelzerand that might change the attack surface14:39
cpaelzerok thanks14:39
cpaelzerI think this is a trivial review from the MIR POV (nt a full one), but a more coplex one from the security side then14:40
didrockslooks like it14:40
sarnoldheh, alas yes..14:40
cpaelzerbut since this is a server case I'd want to ask if someone else could do the MIR-check on this14:40
cpaelzerto not look like special-case-self-signed-off14:40
cpaelzersince no one but the three of us seem available, would you didrocks be able to do that MIR check there?14:40
cpaelzerand then probably assign it to security to get thie rre-eval?14:41
didrockscpaelzer: will do14:41
cpaelzeroh btw #action cpaelzer to clarify libftdi with matt/doko14:41
cpaelzer#action cpaelzer to clarify libftdi with matt/doko14:41
meetingologyACTION: cpaelzer to clarify libftdi with matt/doko14:41
cpaelzerthanks didrocks14:41
cpaelzerthat gets us to the next agenda item14:41
didrocksyw!14:41
cpaelzer#topic Incomplete bugs / questions14:42
cpaelzer#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir14:42
cpaelzersdl is me, that will soon be ready for promotion14:42
cpaelzerno action needed14:42
dokoo/14:42
cpaelzerflatpack ...14:42
cpaelzerreading14:42
cpaelzeroh we marked it incomplete last week14:42
cpaelzerok nothing new14:42
cpaelzerwelcome doko14:42
cpaelzerbefore I send you a mail doko, would you this week have time to resolve flashrom/libftdi ?14:43
cpaelzerI have asked a few weeks in a row and some way it should get off our incoming list14:43
dokoright, it should be updated, fwupd needs a dependency14:43
cpaelzerI've outlined it a few times already, it is about a non MIR-team evaluation wihch seems "approved" by you14:43
dokoyes, but I don't want to see it. fwupd needs to build with that support. waiting for an upload now14:44
cpaelzeran upload of fwupd to pull it in?14:45
dokoyes14:45
dokojawn-smith working on it14:46
cpaelzerso this was an approval by you then back on 2021-03-1114:46
cpaelzerif you could confirm this now that would be helpful, then I could do an update and set the bug to the right states14:47
jawn-smitho/ I can do upload a change with a dependency14:48
jawn-smiths/do//14:49
cpaelzerjawn-smith: I was mostly concerned because the bug looked like needing a review still14:49
cpaelzerthis is now clarified and I have updated the bug14:49
cpaelzeryou can do the upload now and then promotion to main can happen14:49
cpaelzerand it is by now gone from the MIR-team incoming queue14:49
cpaelzerThanks for all the clarifications, we look good again now ...14:50
cpaelzer#topic Any other business?14:50
jawn-smithexcellent, thanks!14:50
cpaelzernothing from me14:50
sarnold\o/14:50
sarnoldnothing from me14:50
didrocksnothing either14:50
cpaelzerok timeout :-)14:55
cpaelzersee you all next week then14:55
sarnoldwoot, thanks cpaelzer, all :)14:55
cpaelzerthanks14:55
cpaelzer#endmeeting14:55
meetingologyMeeting ended at 14:55:43 UTC.  Minutes at https://new.ubottu.com/meetingology/logs/ubuntu-meeting/2021/ubuntu-meeting.2021-06-29-14.30.moin.txt14:55
didrockssee you o/14:55
=== genii-core is now known as genii
cyphermoxo/18:57
rbasako/18:57
rbasakmdeslaur: around?19:04
rbasakvorlon?19:04
* rbasak doesn't see sil2100 here19:04
* rbasak goes back to his evening19:19
=== genii is now known as genii-core
=== JanC_ is now known as JanC

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!