18:04:51 <jdstrand> #startmeeting 18:04:52 <meetingology> Meeting started Mon Jun 18 18:04:51 2012 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 18:04:52 <meetingology> 18:04:52 <meetingology> Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired 18:04:58 <jdstrand> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 18:05:16 <jdstrand> #link https://wiki.ubuntu.com/SecurityTeam/Meeting 18:05:25 <jdstrand> *shrug* 18:05:32 <jdstrand> [TOPIC] Weekly stand-up report 18:05:38 <jdstrand> I'll go first 18:06:17 <jdstrand> I'm on triage this week 18:06:43 <jdstrand> I'm working on libreoffice and oo.o this week 18:07:12 <jdstrand> I had a short week last week and got distracted by the apt updates, so not much was done there (though I did manage to get the related raprot update out this morning) 18:07:24 <jdstrand> I also have a short week next week 18:07:28 <jdstrand> mdeslaur: you're up 18:08:01 <mdeslaur> I'm in the happy place this week 18:08:06 <mdeslaur> I just published libav/ffmpeg updates 18:08:13 <mdeslaur> and have php5 and clamav updates to test 18:08:18 <mdeslaur> which I should be publishing this week 18:08:25 <mdeslaur> after that, I have some merges to do 18:08:30 <mdeslaur> and that's about it for me 18:08:32 <mdeslaur> sbeattie: you're up 18:08:48 <sbeattie> I'm on community this week. 18:09:06 <sbeattie> My focus for the week is the openjdk-6 update + backports 18:09:29 <sbeattie> I'll try to pick up something else in the backgroud. 18:09:52 <sbeattie> I think that's it for me (besides trying to shake the remnants of this cold) 18:09:59 <sbeattie> micahg: tag 18:10:30 <micahg> I've got patch piloting, Firefox/Thunderbird 13.0.1, then webkit, if sbeattie gets the openjdk stuff ready for testing, I'll be helping him with the browser plugin testing 18:10:40 <micahg> that's it for me 18:10:56 <tyhicks> I'm in the happy place this week 18:11:21 <tyhicks> I got all of my eCryptfs fixes out last week. I only have a patch review pending for this week. 18:11:38 <tyhicks> I'll get through that today and then will focus on updates 18:11:58 <tyhicks> I also have some merges to do that I'll try to fit in later in the week 18:12:02 <tyhicks> That's it for me 18:12:06 <tyhicks> jjohansen: you're up 18:12:15 <jjohansen> I need to poke at the bugs that were reported on the ml some more. I expect the genprof problems are actually related to audit dropping messages, but need to confirm that. 18:12:58 <jjohansen> I also need to finish dealing with debian Bug#676515 so that they can have a working apparmor in wheezy 18:13:40 <jjohansen> Other than that I am trying to finish up enough of the stacking work to get an alpha1 out before I take off on vacation next week 18:14:11 <xnox> http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=676515 18:14:13 <ubottu> Debian bug 676515 in linux-2.6 "linux-2.6: AppArmor totally broken" [Normal,Open] 18:14:52 <jjohansen> yeah, its pretty bad :/ 18:15:21 <jjohansen> I think that is it from /me jdstrand back to you 18:15:51 <jdstrand> [TOPIC] Highlighted packages 18:15:56 <jdstrand> The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 18:16:02 <jdstrand> See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 18:16:17 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/alien-arena.html 18:16:20 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/weechat.html 18:16:23 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/smsclient.html 18:16:27 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/slurm-llnl.html 18:16:31 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/xmlsec1.html 18:16:58 <jdstrand> [TOPIC] Miscellaneous and Questions 18:17:04 * xnox 0/ 18:17:06 <jdstrand> Does anyone have any other questions or items to discuss? 18:17:12 <jdstrand> xnox: go ahead 18:17:28 <xnox> Is anyone going to do a review of python3 port? https://code.launchpad.net/~dmitrij.ledkov/apparmor/py3/+merge/109682 18:17:34 <xnox> is there anything left to do? 18:17:48 <xnox> which version of apparmor will ship with quantal (such that I can prepare packaging changes) 18:17:58 <xnox> unless security team will take that responsibility 18:17:59 <xnox> .. 18:18:15 <jdstrand> xnox: I will take that responsibility (review, packaging, etc) 18:18:30 <xnox> jdstrand: any ETA? =) e.g. quantal milestone? 18:18:39 <jdstrand> xnox: sorry I haven't gotten to the review yet. thank you for the porting-- I was planning on ding it myself :) 18:19:05 * xnox jdstrand to review apparmor python3 port 18:19:18 * xnox or maybe the chair needs to do that 18:19:24 <xnox> ok, thanks. sorted then =) 18:19:25 <xnox> .. 18:19:26 <jdstrand> xnox: soonish? feel free to take it off your list 18:19:34 * xnox ok 18:20:02 * sbeattie had also meant to review it as well, sorry 18:20:24 <sbeattie> jdstrand: FYI, last week I punted on triaging the md5crypt cve 18:20:36 <jdstrand> xnox: as you can imagine, we get sidetracked fairly often with security updates, but we'll get to it 18:21:06 <jdstrand> xnox: thanks again for your work on it :) 18:21:21 <xnox> I do know how much great work you lot do. I am subscribed to security announces 18:21:32 <jdstrand> :) 18:21:43 <sbeattie> jdstrand: we don't have it in the archive, but I wasn't sure whether we wanted to mark it as ignored, or have a full not-affected cve entry where we could put references to how we've transitioned away from md5. 18:21:44 <xnox> well done you all =) especially keeping it cool with "I'm in a happy place this week" 18:22:40 <xnox> jdstrand: I have marked my workitem as done, and added one for you on https://blueprints.launchpad.net/ubuntu/+spec/foundations-q-python-versions 18:23:27 <jdstrand> xnox: ok. I already had one in another bp, but that's cool 18:23:47 <jdstrand> sbeattie: noted 18:24:05 <jdstrand> any other items to discuss? 18:24:28 <xnox> jdstrand: barry uses that one to track the progress as he is driving python3 migration 18:25:29 * jdstrand nods 18:26:23 <jdstrand> mdeslaur, sbeattie, micahg, tyhicks, jjohansen, xnox: thanks! 18:26:26 <jdstrand> #endmeeting