[14:32] good morning [14:33] hey sarnold! [14:33] o/ [14:33] hiho [14:34] hey didrocks, joalif, cpaelzer :) [14:34] I guess we should get started :-) [14:34] #startmeeting Weekly Main Inclusion Requests status [14:34] Meeting started at 14:34:24 UTC. The chair is cpaelzer. Information about MeetBot at https://wiki.ubuntu.com/meetingology [14:34] Available commands: action, commands, idea, info, link, nick [14:34] Ping for MIR meeting - didrocks joalif slyon sarnold cpaelzer jamespage [14:34] #topic current component mismatches [14:34] Mission: Identify required actions and spread the load among the teams [14:34] #link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg [14:34] #link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg [14:34] nothing new AFAICS [14:35] \o/ [14:35] yeah, the list looks really clean for once! [14:35] at least one thing that all the freezes make easier :-) [14:35] hehe yeah :) [14:35] heh :) [14:35] #topic New MIRs [14:35] Mission: ensure to assign all incoming reviews for fast processing [14:35] #link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir [14:35] we have https://bugs.launchpad.net/ubuntu/+source/libgit2/+bug/1990655 [14:35] Launchpad bug 1990655 in http-parser (Ubuntu) "MIR: libgit2, http-parser" [High, New] [14:35] by schopin [14:36] dependencies for cargo [14:36] nice bug description [14:36] needs a reviewer each [14:36] yeah this looks well prepared [14:37] I can take libgit2 [14:37] thanks didrocks [14:37] I would, but currently my life and work is more insane than usual, so I'd prefer to skip this time :-/ [14:37] joalif: could I convince you to take http-parser? [14:38] code-wise http-parser is simpler, but there are ecosystem issues with it. [14:38] yup looking [14:38] hmm, unmaintained by upstream [14:38] I see schopin [14:39] do you happen to know if cargo plans to move elsewhere sooner or later? [14:39] htanks joalif [14:39] the dep chain is cargo -> libgit2 -> http-parser [14:39] cargo might move to a rust implem of Git at some point but that's still a way off. [14:40] thanks for the background info! [14:40] libgit2 is aware of http-parser being unmaintained, and is vaguely considering lhttp [14:41] which isn't packaged at all atm :-/ [14:41] so this might end up in a circle [14:41] well, let us look at all of the rest [14:41] and then dsicuss to what extend that is a no-go and/or what options we have [14:41] going on here ... [14:41] #topic Incomplete bugs / questions [14:41] Mission: Identify required actions and spread the load among the teams [14:41] #link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir [14:41] just tuned which didrocks put back on the reporter [14:42] as there was just too much required the ask is to complete all that [14:42] before e.g. entering security review [14:42] anything else is older [14:42] #topic MIR related Security Review Queue [14:42] Mission: Check on progress, do deadlines seem doable? [14:42] #link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir [14:42] Internal link [14:42] - ensure your teams items are prioritized among each other as you'd expect [14:42] - ensure community requests do not get stomped by teams calling for favors too much [14:42] #link https://warthogs.atlassian.net/jira/software/c/projects/SEC/boards/594 [14:42] well, obviously I ask sarnold about mdevctl now [14:43] this is the week you promised - will I be happy in 30 seconds or not? [14:43] unfortunately I left yesterday without having succesfully done a fake update :( [14:43] not seeing a but update ... *drumroll* ... [14:43] given how far in the cycle we are, we can't really go without [14:43] do you have any new ETA? [14:43] so that it can migrate after beta freeze is lifted maybe [14:44] I'm leaning towards waving this through on the grounds that it's replacing a shell script.. [14:44] but I really don't like being in the position of saying I don't have a clue how to do a rust update [14:44] so as long as we are replacing worse code we are kind of ok [14:44] I can go on like that for now [14:45] yay, athos has replied to my email :) [14:45] he usually is super-quick [14:45] :D [14:45] We avoid stealing any of the "oh this is delayed because of me" feeling :-P [14:45] this is detailed enough it'll be easy for me to validate them by the end of my day :D [14:45] \o/ [14:45] you gotta teach me that trick [14:45] from next week -> EOD [14:46] ok nothing else in that list that concerns me for this cycle [14:46] no one else has spken [14:46] so ... [14:46] #topic Any other business? [14:46] none! [14:46] none here [14:46] nothing [14:46] nothing else from me, other than enjoy the time - once LL opens there will be a lot (I'm sure) [14:46] hehe [14:46] never ending story… :) [14:47] ok then, not making this longer than needed [14:47] don't worry, I'll have a new MIR for y'all shortly [14:47] thank you all! [14:47] thanks! [14:47] schopin: woot :) [14:47] thanks cpaelzer, all :) [14:47] cargo has quite a few deps... [14:47] thanks cpaelzer, all :) [14:47] * cpaelzer knows about a nice two digit MIRs coming from sevrer team too [14:47] #endmeeting [14:47] Meeting ended at 14:47:33 UTC. Minutes at https://ubottu.com/meetingology/logs/ubuntu-meeting/2022/ubuntu-meeting.2022-09-27-14.34.moin.txt [14:47] (lalalalala, not hearing anything) [14:47] lalalalalalalala can't hear you [14:47] lala land or what? [14:47] ahah [14:47] schopin: thanks for getting started early on them :) [14:48] actually I'm quite late :'( [14:48] uhoh :( [14:48] that was a 22.10 item :-) [14:48] Yeah, I hadn't anticipated the libgit2/http-parser mess because it was bundled in. [14:49] and libssh2 was also missed in our initial review for sizing (as in *not* from openssl) [14:49] s/ssl/ssh [15:02] heh, last time we looked at libssh2 chrisccoulson was an absolute reviewing machine :) https://github.com/libssh2/libssh2/pull/315 https://github.com/libssh2/libssh2/pull/316 [15:02] Pull 315 in libssh2/libssh2 "Security fixes" [Merged] [15:02] Pull 316 in libssh2/libssh2 "More 1.8.0 security fixes" [Merged] [19:00] o/ === dbungert1 is now known as dbungert