/srv/irclogs.ubuntu.com/2022/05/03/#ubuntu-meeting.txt

sarnoldgood morning14:30
slyono/14:31
didrockshey o/14:31
slyonChristian is at the sprint in copenhagen, so I will run the meeting, today.14:31
slyonjoalif: are you around? I guess all others are at the sprint14:32
slyon#startmeeting Weekly Main Inclusion Requests status14:32
meetingologyMeeting started at 14:32:17 UTC.  The chair is slyon.  Information about MeetBot at https://wiki.ubuntu.com/meetingology14:32
meetingologyAvailable commands: action, commands, idea, info, link, nick14:32
sarnoldwoo, thanks slyon14:32
joalifyup I'm at sprint, but I'm around14:32
slyon#topic Review of previous action items14:32
slyonjoalif: did you already have a chance to review bug #1965115 from last week's meeting?14:33
ubottuBug 1965115 in nullboot (Ubuntu) "[MIR] nullboot" [Undecided, New] https://launchpad.net/bugs/196511514:33
joalifI'm working on it14:33
slyonok, thanks. I think we had no other action items14:33
slyon#topic current component mismatches14:33
slyonMission: Identify required actions and spread the load among the teams14:33
slyon#link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg14:33
slyon#link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg14:33
slyonthere are quite some mismatches, especially in -proposed, but let's start with the release pocket14:34
slyonllvm-toolchain-13 vs z3 is in foundation's backlog, we're still investigating if we can drop one recommends, or if we actually need to do a z3 MIR14:34
sarnoldlibnotify -> sugar -> { python-gwebsockets, sugar-toolkit-gtk3} looks new to me14:35
didrocksyeah, I can take libnotify14:35
slyonlibnotify looks new to me, too14:35
slyonthanks didrocks14:35
slyonlooking at -proposed mismatches, there is gvfs -> libsoup3 -> sysprof – that is a desktop package too14:35
didrocksindeed, taking as well14:35
slyondidrocks: do you have capacity to ivestigate what's happening there, too?14:36
slyonthanks!14:36
slyonok, next here are plenty of foundations packages, that I will have a look at:14:36
slyonlicensecheck, sphinx, twisted, mutt, requests14:36
slyonI will at least try to do an investigation on those.14:36
didrocks(enjoy :))14:37
slyonfinally we have jaraco.text -> jaraco.context which is an openstack package, so for jamespage to have a look at (after the sprint I suppose)14:37
slyondid I miss anything?14:38
sarnoldI think that's it14:38
slyon#topic New MIRs14:38
slyonMission: ensure to assign all incoming reviews for fast processing14:38
slyon#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir14:38
slyon<none> :)14:38
sarnold\o/14:38
slyon#topic Incomplete bugs / questions14:38
didrocksyeah!14:38
slyonMission: Identify required actions and spread the load among the teams14:38
slyon#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir14:38
slyonwe have bug #1963707 that was updated since last week14:39
ubottuBug 1963707 in libqrtr-glib (Ubuntu) "[MIR] libqrtr-glib" [Low, Incomplete] https://launchpad.net/bugs/196370714:39
slyonseb created this... do you know anything about it didrocks ?14:39
slyonit's still in "Incomplete" status, is that accurate?14:39
didrocksI don’t. I can check on this, but this might wait for the sprint to be over14:39
didrocksI can chat with Jeremy too14:40
slyonthat should be fine, i guess. As priority is set to "Low"14:40
didrocksyeah14:40
slyonThanks that'd be great14:40
slyon#topic MIR related Security Review Queue14:40
slyonMission: Check on progress, do deadlines seem doable?14:40
slyon#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir14:40
slyonsarnold: any updates?14:40
sarnoldwe haven't worked on MIRs this last week14:41
slyonthat's sad :( but we're still early in the cycle! :)14:41
slyonthanks for the update14:41
slyon#topic Any other business?14:41
sarnoldyeah, I had hoped to start in on one..14:41
joalifjuliank: re lp 1965115 (nullboot) any reason why it vendorizes go libraries ?14:41
sarnoldwe do have one question on https://bugs.launchpad.net/ubuntu/+source/networkd-dispatcher/+bug/176436214:41
ubottuLaunchpad bug 1965115 in nullboot (Ubuntu) "[MIR] nullboot" [Undecided, New] https://launchpad.net/bugs/196511514:41
ubottuLaunchpad bug 1764362 in networkd-dispatcher (Ubuntu) "[MIR] networkd-dispatcher" [Undecided, Fix Released]14:41
slyonok. let's go with nullboot first14:42
slyonjoalif: are those go-dependencies available as individual packages in the archive?14:42
slyonIIRC we have some rules that allow vendoring of go libraries14:43
didrockswith a correct rationale and ensuring that the maintainance will follow, this is allowed14:43
joalifslyon: need to check this, but still iiuc it is required by the process to be justified why librearies are vendorized14:43
slyonlike those: "Go Package that follows the Debian Go packaging guidelines" "vendoring is used, but the reasoning is sufficiently explained" "golang: static builds are used, the team confirmed their commitment to the additional responsibilities implied by static builds."14:43
slyonyes, if the justification and maintenance commitment is missing, you should ask about it in the LP bug14:44
joalifok thanks14:44
slyonOK. netwirkd-dispatcher next, what was the question there sarnold?14:45
sarnoldwe're curious why networkd-dispatcher wasn't forwarded to the security team for security review -- the checklist suggests to me that it should have been forwarded to us for review, based on the "Package does install services, timers or recurring jobs" rule https://wiki.ubuntu.com/MainInclusionProcess14:46
sarnold(the context is https://www.microsoft.com/security/blog/2022/04/26/microsoft-finds-new-elevation-of-privilege-linux-vulnerability-nimbuspwn/ )14:47
slyonthat MIR is 4 years old... I haven't been involved at that time, does anybody have context about this?14:47
slyonI don't know how our rules MIR evolved in the past 4 year...14:47
didrocksyeah, at the time, security review was more depending on how the reviewed felt it14:47
sarnoldquite a lot, I think :)14:47
slyonsarnold: do you think it makes sense to do a security-review retro-actively for networkd-dispatcher?14:48
didrockswe have stricter and defined rules now14:48
sarnoldslyon: probably not, I expect our friends at microsoft probably gave it a pretty thorough look14:48
slyonOK. I need to read up on that microsoft link. But other than that, I think we can leave it as is for now?14:49
sarnoldI'm more curious if future similar cases of privileged dbus services would be seen differently today or not14:49
slyonsarnold: yes, thanks for bringing this up. IMO according to our new rules anything that runs a system service with escalated privilegs should go through security review.14:50
sarnoldcool cool :)14:50
slyonso, yes. I think this would be seen differently today.14:50
slyondidrocks: do you agree? (you've been around longer than me)14:51
didrocksoh sure, today, we have way more rigorous rules and this will definitively go through security14:51
slyonAlright folks, that's all for today then.14:51
didrocksthanks slyon for hosting the meeting :)14:52
slyonif there isnt any thing else?14:52
sarnoldnothing else, thanks :)14:52
joalifnope14:52
slyon#endmeeting14:52
meetingologyMeeting ended at 14:52:28 UTC.  Minutes at https://ubottu.com/meetingology/logs/ubuntu-meeting/2022/ubuntu-meeting.2022-05-03-14.32.moin.txt14:52
joalifthanks slyon, all14:52
slyonthank you all!14:52
didrocksthanks!14:52
sarnoldthanks slyon, didrocks, joalif14:52
slyonenjoy your 10 min back :)14:52
didrocks:)14:53
juliankjoalif: because that's the the policy and it's been explained at length in the maintenance section15:12
nicozo/*20:02
DD3my_ei nicoz20:03
nicozCan you accept "Daniele De Michele" on Ubuntu Wiki Editors to complete his application?20:03
nicozon Launchpad20:03
nicoz@madhens ;)20:05
nicozthis is his post https://discourse.ubuntu.com/t/dd3my-membership-application/28146/920:06
Eickmeyernicoz: Probably the best person to tag for that would be kenvandine , but warning: this is a bad week as there's a bunch of people away at a developer summit this week.20:24
nicoz;) ok ok thanks Eickmeyer20:24
DD3my_thanks Eickmeyer :)20:25
Eickmeyernicoz, DD3my_ : Also, this is definitely not the best channel for that, but I'm not sure what the best channel would be, tbh. :)20:26

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!