/srv/irclogs.ubuntu.com/2023/09/12/#ubuntu-meeting.txt

=== JanC_ is now known as JanC
didrockscpaelzer_: hey, as a FYI, I will again not be available today for the team meeting. I have a free slot for review if needed and will catch up at the time the meeting end12:34
=== cpaelzer_ is now known as cpaelzer
cpaelzerarr, I'll liekly miss the meeting as well due to ongoing conflicts14:08
sarnoldgood morning14:30
dviererbehello o/14:30
liushuyumorning14:31
sarnold#startmeeting Weekly Main Inclusion Requests status14:32
meetingologyMeeting started at 14:32:01 UTC.  The chair is sarnold.  Information about MeetBot at https://wiki.ubuntu.com/meetingology14:32
meetingologyAvailable commands: action, commands, idea, info, link, nick14:32
sarnoldPing for MIR meeting - didrocks joalif slyon sarnold cpaelzer jamespage ( eslerm dviererbe )14:32
joalifo/14:32
sarnold#topic current component mismatches14:32
sarnoldMission: Identify required actions and spread the load among the teams14:32
sarnold#link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg14:32
sarnold#link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg14:32
sarnoldthe pydantic mir is an old-style multiple package in one bug ..14:33
sarnoldaha, it looks like that's stalled on jamespage's crew to solve some required TODOs before it'll be assigned to security team14:34
sarnoldI think nothing else here needs investigation?14:35
eslermo/14:35
sarnold#topic New MIRs14:35
sarnoldMission: ensure to assign all incoming reviews for fast processing14:35
sarnold#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir14:35
sarnoldhttps://bugs.launchpad.net/ubuntu/+source/rustc/+bug/195793214:36
-ubottu:#ubuntu-meeting- Launchpad bug 1957932 in rustc (Ubuntu) "[MIR] rustc, cargo, dh-cargo" [Critical, New]14:36
sarnoldI think I agree with the conclusion, that rustc is ready for promotion. I believe it just needs an AA to tend to it,14:37
eslermAA?14:37
sarnoldarchive admin14:37
eslermty14:37
liushuyuHowever Cargo requires http-parser and libgit2 to be promoted as well14:38
sarnoldhrmph.14:38
sarnoldyou're right.14:38
sarnoldI had a long conversation with eslerm about that yesterday, even.14:38
eslermI have been relaying our conversation with liushuyu14:38
liushuyuRE: patch development: Foundations can take on the task of developing non-complicated patches. For non-trivial patches, we will need to annoy the libgit2 upstream to switch to a better alternative14:39
liushuyuOr you know, pressure the Cargo upstream to drop libgit2 altogether14:39
sarnoldif you're positive you can be annoying enough to encourage them to switch to an alternative in such a fashion that we can backport the solution to all the releases that require a rust compiler...14:40
liushuyugitoxide has a very high MSRV (Minimum Supported Rust Version), so that will be a disaster I could see14:41
liushuyuMaking libgit2 to switch to llhttp might be a easier version of the outcome for us14:42
sarnoldmy guess is that'll be impossible: libgit2 is a pure C library. llhttp is a typescript package. *someone* would need to write a shim layer to let you call nodejs from within C, like Lua. that sounds like the least fun project I can imagine this early in the morning.14:44
liushuyusarnold: llhttp is C. The TypeScript part is the binding14:45
liushuyuIf you look at the npmjs.com files, llhttp contains a WASM module produced by Emscripten14:46
sarnoldlol that's hilarious14:46
sarnold68% binding ..14:46
liushuyusarnold: That is the normal per modern JavaScript ecosystem14:46
sarnoldliushuyu: alright, well, if you're convinced that it'd be easier to replace http-parse with llhttp when we need to do a security update, that's also an option. probably one that we'd want to run through the SRU process, so that'd require building it in a ppa with only -security configured14:47
liushuyuI mean, you can also upload Rust projects this way to npmjs.com14:47
liushuyusarnold: well at least that's what I think. Because switching to gitoxide means backporting a very new Rust compiler to older series (more error-prone)14:48
sarnoldalright, I added a quick summary of this to the bug, I think we can move on with the assumption that rust ought to be promoted by an AA14:50
sarnoldhttps://bugs.launchpad.net/ubuntu/+source/libde265/+bug/200444914:51
-ubottu:#ubuntu-meeting- Launchpad bug 2004449 in libde265 (Ubuntu) "[MIR] libde265 (dependency of libheif)" [Undecided, New]14:51
eslerm\o/ thanks sarnold and liushuyu14:52
sarnoldlibde265 appears to have some outstanding required TODOs; vpa1977, can you track down the work still needed for https://bugs.launchpad.net/ubuntu/+source/libde265/+bug/2004449 ? or someone else on foundations?14:53
-ubottu:#ubuntu-meeting- Launchpad bug 2004449 in libde265 (Ubuntu) "[MIR] libde265 (dependency of libheif)" [Undecided, New]14:53
sarnold#topic Incomplete bugs / questions14:54
sarnoldMission: Identify required actions and spread the load among the teams14:54
sarnold#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir14:54
sarnoldhttp-parser change was me added notes14:54
sarnoldhttps://bugs.launchpad.net/ubuntu/+source/aom/+bug/2004442 -- changed roughly a week ago, "integration of the test suite" link on salsa14:55
-ubottu:#ubuntu-meeting- Launchpad bug 2004442 in aom (Ubuntu) "[MIR] aom (dependency of libheif)" [Undecided, Incomplete]14:55
sarnoldhttps://bugs.launchpad.net/ubuntu/+source/pappl-retrofit/+bug/2031814 -- has some outstanding TODOs for Till, he's at a conference and unlikely to have made progress -- I think I saw conversation elsewhere suggesting this might be stalled for the release?14:56
-ubottu:#ubuntu-meeting- Launchpad bug 2031814 in pappl-retrofit (Ubuntu) "[MIR] pappl-retrofit" [Undecided, Incomplete]14:56
sarnoldeverything else is later still14:56
sarnold#topic Process/Documentation improvements14:56
sarnoldMission: Review pending process/documentation pull-requests or issues14:56
sarnold#link https://github.com/canonical/ubuntu-mir/pulls14:56
sarnold#link https://github.com/canonical/ubuntu-mir/issues14:56
eslermfrom the last section, we may need to ping for a dotnet6 status update14:57
sarnolddviererbe: any thoughts on dotnet6? you're the last one on the bug :) https://bugs.launchpad.net/ubuntu/+source/dotnet6/+bug/202353114:58
-ubottu:#ubuntu-meeting- Launchpad bug 2023531 in dotnet6 (Ubuntu) "[MIR] dotnet6" [Undecided, Incomplete]14:58
dviererbethere is unfortunately no change :/14:58
sarnoldre: github issues, it looks like there hasn't been much feedback on the new pull request; thanks for giving it a look eslerm. I propose we only mention that we ought to read and give feedback.14:58
sarnoldalright, I annoyed a bunch of people on the bug :)15:00
sarnold#topic MIR related Security Review Queue15:00
sarnoldMission: Check on progress, do deadlines seem doable?15:00
sarnoldSome clients can only work with one, some with the other escaping - the URLs point to the same place.15:00
sarnold#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir15:00
sarnold#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=[MIR]&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir15:00
sarnoldInternal link15:00
sarnold- ensure your teams items are prioritized among each other as you'd expect15:00
sarnold- ensure community requests do not get stomped by teams calling for favors too much15:00
sarnold#link https://warthogs.atlassian.net/jira/software/c/projects/SEC/boards/59415:01
sarnoldwe've got some conversations in flight with libmysofa upstream, I understand it's been Very Quiet upstream for a few months, no replies to our earlier emails. I'd like us to consider a future with libmysofa not being ACKd15:01
eslerms390-tools is no longer in the security queue https://bugs.launchpad.net/ubuntu/+source/s390-tools/+bug/203048215:01
-ubottu:#ubuntu-meeting- Launchpad bug 2030482 in s390-tools (Ubuntu) "[MIR] s390-tools Rust dependencies (vendored)" [Undecided, Incomplete]15:01
sarnoldheh, I wonder why vor_lon assigned it to schopin? we can still try to get someone on the security team to start in on reviewing it, but there's no denying that between 360s and sprints we're unable to take on large new undertakings15:03
eslermit wasn't ever officially in Security's queue*15:03
sarnoldyeah, that makes sense15:03
sarnoldno notes on the jira ticket about it being reassigned15:04
schopinmight be a procedural mixup, IIRC we mentioned the bug a couple of weeks ago in our triage meeting.15:04
eslermthis might be a case where missing beta freeze is o-k, since the package has been in main before15:04
sarnoldyeah15:04
eslermyeah, iirc Christian asked that I look for security volunteers last week15:05
sarnoldand you did :) but .. 360s. sprint. $otherobligations.15:05
sarnoldschopin: heh, that sounds pretty plausible. could you investigate and assign that to security when you've done whatever needs to be done? :)15:05
sarnold#topic Any other business?15:06
sarnold(there's no denying that christian runs a tighter meeting, heh)15:06
schopinsarnold: will do. It's not yet in a full MIR review state, but the security-relevant bits are already there, hence my initial ask for starting that in parallel.15:06
sarnoldschopin: aha, cool, thanks15:07
eslermI will find a volunteer to review this at next weeks sprint :)15:07
didrockso/ (seeing no hilight, so assuming no tasks? \o/)15:07
sarnoldmy only other business is that the security team is sprinting next week, I may not make that one; and then I have some PTO and won't make the next few meetings. eslerm should be well-positioned to handle security team requests :)15:07
sarnoldhey didrocks :) only to review the new pull request15:08
didrocksack15:08
sarnoldalright, if that's it..15:09
eslermthanks Seth, all o/15:09
sarnoldthanks eslerm, liushuyu, dviererbe, schopin, didrocks, joalif :)15:09
didrocksthanks sarnold, all! :)15:09
sarnold(I hope that's it)15:09
sarnold#endmeeting15:09
meetingologyMeeting ended at 15:09:39 UTC.  Minutes at https://ubottu.com/meetingology/logs/ubuntu-meeting/2023/ubuntu-meeting.2023-09-12-14.32.moin.txt15:09
liushuyusarnold: thank you!15:09
dviererbethanks everyone! o/15:09
joalifthanks all :)15:09

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!