== Meeting information == * #ubuntu-meeting Meeting, 11 May at 16:38 — 17:05 UTC * Full logs at [[http://ubottu.com/meetingology/logs/ubuntu-meeting/2015/ubuntu-meeting.2015-05-11-16.38.log.html]] == Meeting summary == ''LINK:'' https://wiki.ubuntu.com/SecurityTeam/Meeting === Announcements === The discussion about "Announcements" started at 16:38. === Weekly stand-up report === The discussion about "Weekly stand-up report" started at 16:38. === Highlighted packages === The discussion about "Highlighted packages" started at 17:03. * ''LINK:'' http://people.canonical.com/~ubuntu-security/cve/pkg/pyrad.html * ''LINK:'' http://people.canonical.com/~ubuntu-security/cve/pkg/ircd-hybrid.html * ''LINK:'' http://people.canonical.com/~ubuntu-security/cve/pkg/ibm-3270.html * ''LINK:'' http://people.canonical.com/~ubuntu-security/cve/pkg/hostapd.html * ''LINK:'' http://people.canonical.com/~ubuntu-security/cve/pkg/gcc-4.8-powerpc-cross.html === Miscellaneous and Questions === The discussion about "Miscellaneous and Questions" started at 17:03. == Vote results == == Done items == * (none) == People present (lines said) == * tyhicks (39) * mdeslaur (16) * sarnold (12) * sbeattie (8) * chrisccoulson (6) * jdstrand (6) * jjohansen (6) * ubottu (3) * meetingology (3) == Full Log == 16:38 #startmeeting 16:38 Meeting started Mon May 11 16:38:08 2015 UTC. The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:38 16:38 Available commands: action commands idea info link nick 16:38 The meeting agenda can be found at: 16:38 [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:38 [TOPIC] Announcements 16:38 Thanks to Jonathan Riddell (Riddell) and Felix Geyer (debfx) for help on security updates for the community supported quassel (LP: #1448911) last week. Another thanks to Felix for unrar-nonfree (LP: 1451260). Your work is very much appreciated and will keep Ubuntu users secure. Great job! :) 16:38 Launchpad bug 1448911 in quassel (Ubuntu Wily) "Execute initDbSession() on DB reconnects" [Undecided,Fix released] https://launchpad.net/bugs/1448911 16:38 Launchpad bug 1451260 in unrar-nonfree (Ubuntu Utopic) "Directory traversal vulnerability" [Undecided,Fix released] https://launchpad.net/bugs/1451260 16:38 [TOPIC] Weekly stand-up report 16:38 jdstrand: you're up 16:39 this week I'm going to work with tyhicks on identifying and prioritizing our work backlog 16:39 hi 16:39 I'm also continuing to work on the review tools wrt snappy 16:40 and prodding the seccomp SRU along. related to that, will be discussing snappy stable updates with other teams 16:40 if I have time, I'll pick up the seccomp policy updates and mechanism for applying them on upgrades 16:41 that's it from me 16:41 mdeslaur: you're up 16:41 I'm on triage this week 16:41 and I'm working on some updates 16:41 I just released libtasn1 and icu updates 16:41 I also have an embargoed issue to work on 16:41 that's it from me, sbeattie? 16:42 I'm in the happy place this week. 16:42 I need to finish my wily apparmor upload after syncing up some changes from the debian packaging. 16:42 I also need to push my trusty apparmor SRU 16:43 (just need to do the SRU paperwork there) 16:43 great! 16:43 still need to push on gcc-pie stuff 16:44 that's pretty much it for this week 16:45 sbeattie: you mentioned an rsyslog SRU in last week's meeting - is that still needed? 16:45 the rsyslog SRU is done 16:45 It's been accepted, just needs verification. If one of the reporters doesn't do it, I'll knock it out. 16:46 it's verified 16:46 oh, I missed that email. 16:46 it's just waiting the required waiting period 16:46 good 16:46 I'm in the community role this week 16:47 I'm still catching up on email and IRC from my vacation last week 16:47 good luck :) 16:47 :) 16:47 ctrl-a, del 16:47 I'll be working with jdstrand to get our backlog in order for the W cycle 16:48 heck, that's what I do, and I didn't go on vacation 16:48 I want to revive my patch updates 16:48 I'll be adding support to apparmor_parser for kernel keyring mediation 16:49 I think that's it for me 16:49 jjohansen: your turn 16:50 I have to spend a few minutes preparing for the apparmor meeting tomorrow 16:50 and I have to sit down with the kt and verify the 4.1-RC3 port and make sure we are ready for that new kernel to drop in W 16:51 other than that its planning and back to apparmor cleanups for upstreaming 16:51 jjohansen: I see that we're are 4.1-rc3 - will you be able to push any patches up for 4.2? 16:51 s/are/at/ 16:52 tyhicks: yes, sorry that is the other thing todo. /me will make it top priority this week to get a pull request together and get it out 16:52 jjohansen: that's great to hear :) 16:52 its not going to be huge but 8 or 10 patches can go up 16:53 that's a start 16:53 that is it for me sarnold you are up 16:53 I'm on bug triage this week; I have a reproducer working for horizon's cve, at least on trusty, so I am feeling much closer to releasing an update; the quick way to do the update is just for trusty and probably newer, since that's what's charmed up and working.. precise might still require the testingopenstack VM image. 16:54 sarnold: trusty and higher just got brand spanking new horizon packages 16:54 sarnold: are you sure they still need the CVE fix? 16:55 mdeslaur: dunno if that's encouragement to drink or sob or ... 16:55 oh maybe not trusty 16:55 mdeslaur: they may; how recent? friday afternoon I reproduced the problem 16:55 utopic and vivid have a new package in -proposed that got uploaded last week. Sorry, trusty still has an old package 16:56 aha 16:56 might be worth checking to make sure it's not getting an update soon though 16:56 thanks mdeslaur 16:56 sarnold: please be sure to document the serverstack deployment and testing process 16:56 (otherwise, you'll become the openstack testing guy :) 16:57 tyhicks: heh, did you bring along "how to motivate employees" on your vacation? :) 16:57 hehe 16:57 lol 16:58 tyhicks: just a note for the backlog review, it may not show up easily, but there's some omre work oustanding for the ppc64-diag MIR, there's some more dependant packages that we ignored in favor of other packages in the last cycle... 16:58 sarnold: thanks for the headsup - I noticed the comment in the MIR bug while reading email this morning 16:58 tyhicks: 1417608 16:59 oh cool! an update for ppc64-diag :) nice. 17:00 anyway, I suppose that doesn't have to happenh right away, but they'll want it SRUd to 14.04 LTS 17:00 that's it for me, chrisccoulson? 17:00 It's Mozilla update this week, so I'll be handling that 17:00 I've also got an embargoed update 17:01 other than that, I'm just about to merge https://code.launchpad.net/~chrisccoulson/oxide/media-permissions and then I'll be working on bug 1428754 again 17:01 bug 1428754 in Oxide "Persist permission request decisions for a session" [High,In progress] https://launchpad.net/bugs/1428754 17:02 I'll also be continuing to work through code reviews. I got some done last week, but the list is still growing 17:02 I think that's me done 17:02 thanks 17:03 [TOPIC] Highlighted packages 17:03 The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 17:03 See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 17:03 http://people.canonical.com/~ubuntu-security/cve/pkg/pyrad.html 17:03 http://people.canonical.com/~ubuntu-security/cve/pkg/ircd-hybrid.html 17:03 http://people.canonical.com/~ubuntu-security/cve/pkg/ibm-3270.html 17:03 http://people.canonical.com/~ubuntu-security/cve/pkg/hostapd.html 17:03 Does anyone have any other questions or items to discuss? 17:03 http://people.canonical.com/~ubuntu-security/cve/pkg/gcc-4.8-powerpc-cross.html 17:03 [TOPIC] Miscellaneous and Questions 17:05 jdstrand, mdeslaur, sbeattie, jjohansen, sarnold, ChrisCoulson: Thanks! 17:05 #endmeeting Generated by MeetBot 0.1.5 (http://wiki.ubuntu.com/meetingology)