cpaelzer#startmeeting Weekly Main Inclusion Requests status14:31
cpaelzerPing for MIR meeting - didrocks joalif slyon sarnold cpaelzer jamespage ( eslerm dviererbe )14:31
cpaelzer#topic current component mismatches14:31
cpaelzerMission: Identify required actions and spread the load among the teams14:31
cpaelzer#link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg14:31
cpaelzer#link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg14:31
cpaelzer3 new sets14:31
cpaelzerand a bunch of known ones14:31
cpaelzerusidks2 -> exfatprogs14:32
cpaelzerDesktop needs to think about what they want14:32
cpaelzerjbicha: are you around and could make that happen?14:32
cpaelzerrustc-1.76 -> fonts-open-sand/highlight.js14:32
cpaelzeryou might say it is foundations14:32
cpaelzerbut this smells14:32
cpaelzerlike a -doc package14:33
cpaelzerthat was forgotten to be added to auto-exclude14:33
-ubottu:#ubuntu-meeting- Commit b278dfb in ~ubuntu-core-dev/ubuntu-seeds/+git/ubuntu "Extra-Exclude: exclude rust-1.76-doc HEAD oracular"14:33
didrocksnot the first time from rustc IIRC, and yes, that was the -doc package14:33
cpaelzerhehe :-) like this14:33
slyonwe might need to demote rust-1.76-doc, though14:33
slyonnot sure if the seed change is enough14:33
cpaelzerIIRC if nothing holds it it would be auto-demoted14:33
slyonok. let's wait and see14:33
cpaelzerotherwise let me know14:34
cpaelzernext is curl -> nghttp3 / ngtcp214:34
slyonwe are dropping this.14:34
cpaelzerwow - did we reach http3, I'm so outdated14:34
cpaelzerok, already resolved14:34
slyonI discussed it with foundations this morning. We might re-enable http3 at some point in the future (once it lands in OpenSSL)14:34
cpaelzergoing on14:34
cpaelzer#topic New MIRs14:34
cpaelzerMission: ensure to assign all incoming reviews for fast processing14:35
cpaelzer#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir14:35
didrocksweird at this point of the cycle14:35
didrocksI’m fearing August now :)14:35
sarnoldso weird14:35
cpaelzerSome reviews of last week have been handed out last week14:35
cpaelzersome concluded, some still ongogin AFAICS14:35
cpaelzerso it isn't that there is nothing going on14:35
cpaelzer#topic Incomplete bugs / questions14:35
cpaelzerMission: Identify required actions and spread the load among the teams14:35
cpaelzer#link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir14:35
slyonjbicha: FYI bug #2071396 is looking mostly good, but we'd want to have the most recent version v0.2.014:35
-ubottu:#ubuntu-meeting- Bug 2071396 in libdisplay-info (Ubuntu) "[MIR] libdisplay-info" [Undecided, Incomplete] https://launchpad.net/bugs/207139614:36
cpaelzerthanks jbicha, waiting for you to call it ready14:36
slyonsarnold: I wasn't sure if we need security review on this ^14:36
cpaelzeralso https://bugs.launchpad.net/ubuntu/+source/highway/+bug/2070807 is known but not yet ready14:36
slyonsee comment #014:36
-ubottu:#ubuntu-meeting- Launchpad bug 2070807 in highway (Ubuntu) "[MIR] highway" [Undecided, Incomplete]14:36
cpaelzersarnold: it parses media files, that needs security14:37
slyonI decieded we don't need security update, as they are mostly parsing EDID data from trusted sources (kernel)14:37
cpaelzeroh is that all they do ...14:37
cpaelzerreading more ...14:37
sarnoldslyon: yeah, I'm also not sure .. I think I'd expect the kernel to just hand over raw blobs without inspection.. but if they've already got fuzzing in place, that's very impressive, and our capacity issues this cycle suggests that we ought to try to steer things away from us where it makes sense14:37
slyonyeah mostly sysfs data14:37
didrocksyeah, I would say from the comment as it’s only sysfs info, it shouldn’t need?14:38
didrocksand yeah fuzzing <314:38
cpaelzeroh you are on libdisplay-info still14:38
didrocksyeah, sorry cpaelzer :)14:38
sarnoldyeah, I type so slow, heh14:38
cpaelzerI was on the src:highway already14:38
slyonRight, they have fuzzing in place for their parser. Seems solid overall.14:38
slyonI think we can stay with no security review14:39
didrocksthat’s why you are managing people, ahead of us :p14:39
cpaelzerthat src:highway I expect needing a security review once it is ready in general14:39
sarnoldyes, highway feels like it needs security review, jpegs are reachable via more than "plug in a device" :)14:39
cpaelzeralthough, it is just "Efficient and performance-portable SIMD wrapper "14:39
cpaelzerso it does not know it deals with image files14:39
cpaelzerup to you to decide once it is ready14:40
cpaelzerbut still, uncontrolled source usually means better have a look to be safe14:40
cpaelzergoing on here ...14:40
cpaelzer#topic Process/Documentation improvements14:40
cpaelzerMission: Review pending process/documentation pull-requests or issues14:40
cpaelzer#link https://github.com/canonical/ubuntu-mir/pulls14:40
cpaelzer#link https://github.com/canonical/ubuntu-mir/issues14:40
cpaelzercleaned of all but the long waiting cases14:40
cpaelzerand those got an update why they are stuck14:40
cpaelzer#topic MIR related Security Review Queue14:41
cpaelzerMission: Check on progress, do deadlines seem doable?14:41
cpaelzerSome clients can only work with one, some with the other escaping - the URLs point to the same place.14:41
cpaelzer#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir14:41
cpaelzer#link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=[MIR]&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir14:41
cpaelzerInternal link14:41
cpaelzer- ensure your teams items are prioritized among each other as you'd expect14:41
cpaelzer- ensure community requests do not get stomped by teams calling for favors too much14:41
cpaelzer#link https://warthogs.atlassian.net/jira/software/c/projects/SEC/boards/59414:41
sarnold"restart to keep using firefox" sheesh14:41
sarnoldalas, no progress in the last week, and given my interview schedule this week, unlikely any progress this week, either :(14:42
sarnoldour director is keenly aware of our capacity problems14:42
sarnoldhiring and onboarding new people takes immense time .. so .. this might be a repeating story for a while.14:43
cpaelzer"our director is keenly aware of our capacity problems" is what we wanted to hear14:43
cpaelzer#topic Any other business?14:43
sarnoldhis advice was to get in the most important pieces early14:44
didrocksnothing for me14:44
slyonnothing here14:44
sarnoldnothing here14:44
cpaelzerI know there will be a big MIR not yet in the queue soon14:44
cpaelzerto satisfy sarnold missing more activity14:44
didrockslucky him :)14:45
sarnoldoh boy oh boy! just like old times :)14:45
jbichaexcept for highway needing an autopkgtest, I consider it ready for review. Sorry I didn't get to that last week14:45
cpaelzerabout a package new to the archive and aiming to go to main in all releases soon14:45
cpaelzersomething hwlib from the cert team, but it was not yet ready for review today14:45
cpaelzerbut FYI for now14:45
sarnoldnew toys!14:46
cpaelzerok, all looks good14:46
cpaelzerand jbicha, no need to excuse. You know it is needed and you prep it right away - that is good and nothing to excuse :-)14:47
cpaelzerok, with that I think we can close for today14:47
slyonthanks cpaelzer, all!14:47
sarnoldthanks cpaelzer, all :)14:47
didrocksthanks you all!14:47
