/srv/irclogs.ubuntu.com/2022/10/18/#ubuntu-meeting.txt

=== JanC_ is now known as JanC
slyono/14:30
sarnoldgood morning14:30
slyonc_paelzer is busy, I'll be running the meeting today14:31
sarnoldthanks slyon14:31
slyon#startmeeting Weekly Main Inclusion Requests status14:31
meetingologyMeeting started at 14:31:27 UTC.  The chair is slyon.  Information about MeetBot at https://wiki.ubuntu.com/meetingology14:31
meetingologyAvailable commands: action, commands, idea, info, link, nick14:31
slyonPing for MIR meeting - didrocks joalif slyon sarnold c_paelzer jamespage14:31
joalifo/14:31
slyon#topic current component mismatches14:31
slyonMission: Identify required actions and spread the load among the teams14:31
slyon#link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg14:31
slyon#link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg14:31
slyonc-m is looking rather clean. except for nvidia-graphics-drivers-418-server14:32
slyonbut this is a binary update which has been in restricted before, so I guess there's nothing to do for us, and it just needs promotion14:33
sarnoldI can't recall one of these things coming up before14:33
didrockshey14:33
slyonI assume it got dropped & auto-demoted... now a new upload moved to multiverse instead of restricted. I'd leave this to the AAs to sort out14:34
sarnoldwill they automatically know it needs sorting out? or would a note in #ubuntu-release be appropriate?14:34
slyonIt shows up in the AAs reports, so they should be aware14:35
slyon(e.g. c-m, which is an AA report)14:35
slyon#topic New MIRs14:35
slyonMission: ensure to assign all incoming reviews for fast processing14:35
slyon#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir14:35
slyonnothing \o/ (we took it all last week :))14:36
slyon#topic Incomplete bugs / questions14:36
slyonMission: Identify required actions and spread the load among the teams14:36
slyon#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir14:36
slyonbug #1990655 : libgit2, http-parser14:36
-ubottu:#ubuntu-meeting- Bug 1990655 in http-parser (Ubuntu) "MIR: libgit2, http-parser" [High, Incomplete] https://launchpad.net/bugs/199065514:37
slyondidrocks: I feel like this should be status: New instead of Incomplete? ^14:37
slyonit is pending security review, but good from our POV14:37
didrockslibgit2 is for sure, I only changed the assignee, resetting to New14:38
slyonthanks14:38
slyonwhat do we still need for http-parser?14:38
sarnoldcomment #6 suggests just security review14:39
joalifi dont recall we wait for anything14:39
didrocksyeah, seems to be the same to me, joalif didn’t have any remaining concerns?14:39
slyonjoalif: if there's nothing else, could you change the status to "New" as well?14:39
joalifjust a really minor recommended todo14:40
joalifbut nothing else14:40
slyonjoalif: ok sounds good!14:40
joalifsure14:40
slyonbug #1990582 => waiting for feedback/action from the reporter, nothing to do right now for us14:40
-ubottu:#ubuntu-meeting- Bug 1990582 in thin (Ubuntu) "[MIR] Promote thin to main as a pcs dependency" [Undecided, Incomplete] https://launchpad.net/bugs/199058214:40
slyonthat's all updates for today.14:41
slyonI assume the MIR reviews we assigned last week are slowly progressing (I handled 2/5 already)14:41
slyon#topic MIR related Security Review Queue14:41
slyonMission: Check on progress, do deadlines seem doable?14:41
slyon#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir14:41
slyonInternal link:14:42
slyon#link https://warthogs.atlassian.net/jira/software/c/projects/SEC/boards/59414:42
slyonsarnold: can you give a brief update?14:42
sarnoldthere's been no progress on the security reviews, other tasks have sucked all the oxygen out of the room14:42
slyonwe're getting very close to the end-of-cycle. Do we have any misses that we need to notify people about?14:43
sarnoldI believe I did that last week14:43
slyonperfect, thanks!14:43
sarnoldwell, not *perfect*, but .. :)14:44
slyonindeed :p14:44
slyon#topic Any other business?14:44
joalifi have a  couple of questions14:44
sarnoldI'll miss next week's meeting, so I shall see you in prague :)14:44
joalifi'm reviewing ruby-ffi https://bugs.launchpad.net/ubuntu/+source/ruby-ffi/+bug/199057014:44
-ubottu:#ubuntu-meeting- Launchpad bug 1990570 in ruby-ffi (Ubuntu) "[MIR] Promote ruby-ffi to main a pcs indirect dependency" [Undecided, New]14:44
joalifi noticed that it makes a ffi_c.so , should there be a symbols file for this ?14:45
joalifalso security wise it's ok according to the list, this package provides a gem to programmatically load dynamic libraries14:46
didrocksit depends if there are external consumer14:46
joalifdo you think it would need a security review ?14:46
didrocks(for the symbols file)14:46
didrockslike, if the lib internal, only for the ruby binding?14:46
joalifi think it's for the ruby binding not external but i'll double check14:47
didrocksI would then check for the practice of python C bindings14:48
joalifok thanks!14:48
slyonI reviewed ruby-childprocess, which is making use of ruby-ffi for IPC. I requested security-review, because I feel passing random data between processes should be double checked, as it could crash/DoS those processes. sarnold what do you tihnk?14:48
slyonso I would lean towards requesting sec-review for ruby-ffi, too.14:49
sarnold$ apt-file search /usr/lib/x86_64-linux-gnu/ruby/vendor_ruby/ | grep '\.so$' | wc -l14:49
sarnold16714:49
joalifslyon: yes, I saw your review that's why i'm wondering for ruby-ffi at well, thanks14:50
sarnoldthere might other examples in the ruby world, though if we're looking at the pythons because we think they're more likely to be done right..14:50
didrocks(that was my guess in getting inspired by python, because it’s not done for the other ruby projects I checked and I think it’s better to double cross)14:50
didrocksbut from the few python examples I found, it’s the same, no symbol file14:50
didrocksI think if they are tests importing the final product (python or ruby) module, and exercising it, it’s good enough to ensure about the ABI stability regarding the runtime?14:51
sarnoldslyon: good question; I'm more inclined to say it depends upon the type of software architecture the library encourages -- oftentimes ipc is used for things that are logically one program and this is just a detail of shuffling bytes around, so there's no boundaries being crossed. but others are intended to provide generic client-server or peers-on-a-bus architecture (like dbus) and that would be14:52
sarnoldmore important for a security review, I think14:52
joalifre symbols : it's not just tests in this case, in any case I look into it to see exactly how it's used and what happens with other rudy libs and python14:52
slyonsarnold: IIUC ruby-childprocess/-ffi is basically a module, which could be used to implement both types of architecture.14:53
sarnoldThis gem aims at being a simple and reliable solution for controlling14:54
sarnoldexternal programs running in the background on any Ruby / OS combination.14:54
sarnoldhah, yeah, that does feel like a security review would fit14:54
sarnoldif I had a dollar for every time I saw unsafe child process handling..14:54
slyonsarnold: haha, thanks for the confirmation!14:54
sarnoldthanks :D14:55
slyonjoalif: does that answer your questions?14:55
joalifyup all covered!14:55
joalifthank you all!14:55
slyondo we have anything else?14:55
joalifnothing from me14:55
slyonalright, thank you all!14:56
sarnoldthanks slyon, all :)14:56
slyonlooking forward to meeting you in prague!14:57
slyon#endmeeting14:57
meetingologyMeeting ended at 14:57:03 UTC.  Minutes at https://ubottu.com/meetingology/logs/ubuntu-meeting/2022/ubuntu-meeting.2022-10-18-14.31.moin.txt14:57
joalifthanks slyon, all :)14:57
didrocksthanks! See you in Prague14:59
nicozGood luck to all the candidates... each of you makes this community special18:14
* vorlon waves19:02
rbasako/19:02
vorlonhttps://wiki.ubuntu.com/TechnicalBoardAgenda hasn't been updated, still shows next meeting in August with sil2100 chairing19:03
vorlonwho I don't know whether is planning to make it, given that it's release week19:05
rbasakI don't have much to report.19:07
rbasakThird party repo requirements is making good progress, but it's all internal in the sense of the things Canonicalers need to do to get it all implemented.19:08
rbasakI hope to be able to report back in a few weeks with a more concrete plan in terms of progress.19:08
vorlonsounds good19:09
rbasakFor requirements B, F1 and F2 in particular.19:09
sil2100Eeek19:10
sil2100I think I'm late19:10
sil2100Sorry19:10
sil2100o/19:10
vorlonsil2100: hi, are you willing to chair? (wiki says you're on for it but I don't know if the wiki is just out of date)19:11
sarnoldsil2100: https://paste.debian.net/1257514/19:11
sil2100I could chair, I guess, just to go formally if we have any new possible action items19:13
vorlonlike you, my head is in release space this week of course19:13
sil2100Since I suppose the rest is just progress on the two issues19:14
sil2100#startmeeting Ubuntu Technical Board19:15
meetingologyMeeting started at 19:15:26 UTC.  The chair is sil2100.  Information about MeetBot at https://wiki.ubuntu.com/meetingology19:15
meetingologyAvailable commands: action, commands, idea, info, link, nick19:15
sil2100#topic Action review19:15
sil2100I suppose no sense to go through all of those, I think we already said those are still in progress19:15
sil2100Release makes it slower19:15
sil2100#topic Check up on community bugs (standing item)19:16
sil2100Okay, I see no new open bugs at least19:16
sil2100#topic Scan the mailing list archive for anything we missed (standing item)19:17
sil2100I suppose there's no new items19:17
vorlonI guess one minor thing there since you're the two other Canonicalers on the TB19:17
vorlondo either of you want to open an RT so I'm not a SPOF on the UES calendar?19:18
sil2100I think the TB elections are for next month19:18
rbasakOn the topic of the calendar, vorlon I wonder if it's easier for you to just delete the existing recurring event and we can create a fresh one that we all can edit?19:18
rbasakI don't mind filing an RT either, but I'm not clear on exactly what to ask for.19:18
vorlonI'm not sure if that's better or worse than the status quo, where I have granted you edit access to the recurring event19:18
vorlonrbasak: basically, edit access to the calendar that owns this event19:19
vorlonwhich I think is better than changing it to be an event I personally own19:19
rbasakAh I can edit it19:19
rbasakI just fixed the meeting location19:19
sil2100Can we edit the dates as well?19:20
vorlonas long as you do it in the context of this recurring event yes!19:20
rbasakDo we need anything further then?19:20
sil2100I think this is good enough to me19:21
sil2100Okay, I think that's it for the ML items19:21
sil2100#topic AOB19:21
sil2100Anything else to discuss?19:21
rbasakNothing from me. Thanks!19:21
vorlonthanks!19:23
sil2100#endmeeting19:28
meetingologyMeeting ended at 19:28:19 UTC.  Minutes at https://ubottu.com/meetingology/logs/ubuntu-meeting/2022/ubuntu-meeting.2022-10-18-19.15.moin.txt19:28
sil2100THank you! And sorry for being late, I try to finish up things at home here to get back to the releasey stuff19:28
Bashing-omCommunity Council Election: My vote completed - finally. Thanks to José's patience and guidance :D23:47

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!