17:23 #startmeeting 17:23 Meeting started Mon Nov 10 17:23:11 2014 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 17:23 17:23 Available commands: action commands idea info link nick 17:23 The meeting agenda can be found at: 17:23 [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 17:23 [TOPIC] Weekly stand-up report 17:23 I'll go first 17:23 I got pretty side-tracked last week with unplanned things 17:24 so, I'd like to finish the click-apparmor 0.3 for vivid and finish apparmor-easyprof-ubuntu for vivid 17:24 I'd also like to finish my update for click-reviewers-tools changes 17:25 once again, adjusting UCT for derivative branches 17:25 and then pending updates 17:25 that includes the sponsored konversation and kde-workspace that should go out today 17:25 mdeslaur: you'r up 17:25 mdeslaur: nm 17:25 sbeattie: you're up 17:26 oh, I'm here now 17:26 * sbeattie pauses 17:26 darn time zones 17:26 yes, my apologies 17:26 it is scheduled for ~ 1 hour ago 17:26 I'm on triage this week 17:26 maybe next week... 17:26 And have a few updates planned 17:27 and an embargoed issue I need to look at 17:27 and pending that, I'll be going down the list again 17:27 that's it from me 17:27 sbeattie: you're up 17:28 I'm working on the gcc pie-by-defaulton-x86-64 stuff; I have the patch applying cleanly again, and am currently hammering my laptop as it finishes building gcc locally. 17:29 Once that finishes, I'll start doing test builds of other packages against it. 17:29 I also need to do the usual apparmor stuff. 17:30 that's it for me; tyhicks? 17:30 I'm currently working a parser bug in trusty (LP: #1390592) 17:30 Launchpad bug 1390592 in linux (Ubuntu) "'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker" [High,Confirmed] https://launchpad.net/bugs/1390592 17:31 I've identified the bad patch and am in the process of testing a new package built with the correct upstream patch 17:32 after that, I need to revisit the dbus-daemon unrequested replies bug (LP: #1362469) 17:32 Launchpad bug 1362469 in dbus (Ubuntu) "AppArmor unrequested reply protection generates unallowable denials" [Medium,Triaged] https://launchpad.net/bugs/1362469 17:32 tyhicks: oh, it was the parser after all. and this is something for trusty sru? 17:32 tyhicks: oh, hunh, we have a different patch in ubuntu to add @{profile_name} from upstream? 17:32 jdstrand: it is something for a trusty sru - does someone have one in progress? 17:33 (I know we were talking about SRUing the python utils fixes) 17:33 I think sbeattie and mdeslaur were working to prepare one 17:33 * jdstrand isn't sure of the status 17:33 sbeattie: nope, the bad patch is one that attempted to fix and cleanup escape sequence handling 17:33 yeah, though I've mostly been doing prep work, I haven't got a tree in progress yep. 17:33 s/yep/yet/ 17:34 oh, hrm. 17:34 sbeattie: ubuntu patch add-decimal-interp.patch should be replaced with upstream rev 2456 17:34 I have a bit more testing to do, though 17:35 re dbus-daemon unrequested replies bug> folks are thinking that the newer dbus might fix an issue that dbus-daemon is hitting in rtm 17:36 so, bug #1390592 is pretty important to fix 17:36 bug 1390592 in apparmor (Ubuntu Trusty) "'ptrace peer=@{profile_name}' does not work on 14.04 (at least) with docker" [High,Triaged] https://launchpad.net/bugs/1390592 17:37 jdstrand: should we do an SRU just for it? 17:37 if we aren't planning to fix the python tools now, I think we should 17:37 ok 17:37 I should be able to prepare an SRU for that today 17:37 ok, thanks 17:37 np 17:37 okay, that's fine. 17:38 also, I'll continue work on turning the apparmor policy cache setup and loading code into a library 17:38 it has taken a little longer than expected but I finally feel like I'm making progress now 17:39 oh, I forgot-- I plan on finishing my upstream patch for docker so it can apply policy based on parser capabilities 17:39 (it is a little difficult to pull out the cache handling bits from the profile parser) 17:39 ok, that's it for me 17:39 chrisccoulson: I think it is your turn 17:40 skipping jjohansen and sarnold (time zone victims) 17:40 jj is off today 17:40 oh yes 17:40 this week, I'm hoping to finish off the header bar controls in oxide. I'm also going to be working on several bugs that affect single-process mode 17:40 I've just got chromium out (not for precise though) 17:41 and I've got one embargoed update to do 17:41 nice 17:41 I think that's me done 17:41 chrisccoulson: any news on precise? 17:41 what's wrong with precise? 17:41 oh, and reviewing updates to the mediahub branch when they arrive 17:42 chad's still working on building a compiler that can actually build it 17:42 good stuff 17:42 [TOPIC] Highlighted packages 17:43 http://people.canonical.com/~ubuntu-security/cve/pkg/stunnel4.html 17:43 http://people.canonical.com/~ubuntu-security/cve/pkg/lib3ds.html 17:43 http://people.canonical.com/~ubuntu-security/cve/pkg/qmail.html 17:43 http://people.canonical.com/~ubuntu-security/cve/pkg/c-icap.html 17:43 http://people.canonical.com/~ubuntu-security/cve/pkg/smokeping.html 17:43 The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 17:43 See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 17:43 [TOPIC] Miscellaneous and Questions 17:43 Does anyone have any other questions or items to discuss? 17:47 sarnold: hey, can you give a quick update? 17:48 I'm on community this week; I have some outstanding apparmor patches to review, and I'd like to keep working on programming scopes and applications for the touch environment 17:49 I found david planella's Ubuntu On Air video from last week really useful to understand the otherwise baffling ubuntu sdk environment, well worth watching that if you're new to it 17:50 there's two more videos in the series, and even though they are ridiculously long, I found the first one worth watching, so I'll try the other two as well 17:50 that's me; is it back to jdstrand or chrisccoulson? 17:51 me 17:52 but actually, that's it 17:52 sarnold: thanks :) 17:52 mdeslaur, sbeattie, tyhicks,chrisccoulson, sarnold: thanks! 17:52 #endmeeting