16:36 <tyhicks> #startmeeting 16:36 <meetingology> Meeting started Mon Nov 9 16:36:28 2015 UTC. The chair is tyhicks. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:36 <meetingology> 16:36 <meetingology> Available commands: action commands idea info link nick 16:36 <tyhicks> The meeting agenda can be found at: 16:36 <tyhicks> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:36 <tyhicks> [TOPIC] Announcements 16:36 <tyhicks> Klas Mattsson (klas-mattsson) provided a debdiff for precise for openafs (LP: #1513461) 16:36 <ubottu> Launchpad bug 1513461 in openafs (Ubuntu) "OPENAFS-SA-2015-007 "Tattletale"" [High,Fix released] https://launchpad.net/bugs/1513461 16:36 <tyhicks> Otto Kekäläinen (otto) provided debdiffs for trusty-wily for mysqldb (LP: #1512241) 16:37 <ubottu> Launchpad bug 1512241 in mariadb-10.0 (Ubuntu Xenial) "USN-2781-1: MySQL vulnerabilities partially also applies to MariaDB" [Medium,Fix released] https://launchpad.net/bugs/1512241 16:37 <tyhicks> Many thanks for your contributions and assistance in keeping Ubuntu users secure! :) 16:37 <tyhicks> [TOPIC] Weekly stand-up report 16:37 <tyhicks> jdstrand: you're up 16:37 <jdstrand> hey 16:38 <jdstrand> so, I need to arrange travel for an upcoming sprint 16:38 <jdstrand> I'm also helping interview candidates for FIPS/CC lead (https://ldd.tbe.taleo.net/ldd03/ats/careers/requisition.jsp?org=CANONICAL&cws=1&rid=1049) 16:39 <jdstrand> I will be picking up the snappy security policy generation work (reviewing merges to me branch, finishing up the branch) 16:40 <jdstrand> I have a number of sprint followups too 16:40 <jdstrand> mdeslaur: you're up 16:40 <mdeslaur> I'm in the happy place this week 16:40 <mdeslaur> I just released an unzip regression fix 16:40 <mdeslaur> and I have a number of embargoed issues I'm working on 16:40 <mdeslaur> tomorrow I get to do patch piloting 16:40 <mdeslaur> and if I have time, I'll pluck something off the list 16:40 <mdeslaur> that's about it, sbeattie, you're up 16:41 <sbeattie> I'm on community this week. 16:41 <sbeattie> I have an embargoed issue and an openjdk-7 regression fix to do. 16:42 <sbeattie> I need to contact people to get a test archive rebuild going for the pie work 16:43 <sbeattie> and that will probably consume most of my week, which will be a bit short (holiday weds, need to swap friday off) 16:43 <sbeattie> tyhicks: you're up 16:43 <tyhicks> I'm on bug triage this week 16:44 <tyhicks> I need to book upcoming sprint travel 16:44 <tyhicks> I have Ubuntu Core Sprint followups from last week 16:44 <tyhicks> still getting to the mapplauncherd review and profile development 16:45 <tyhicks> and then I'll start working on making it easier to create AppArmor policy namespaces and to load AppArmor policy inside of user namespaces 16:45 <tyhicks> that's it for me 16:45 <tyhicks> jjohansen: you're up 16:45 <jjohansen> I am mostly working on apparmor stacking/namespaces 16:46 <jjohansen> I need to finish up the experiment with the latest of the smack ns patches, and refresh to the set that was just put up 16:47 <jjohansen> I also have bug 1511791 to finish chasing down 16:47 <ubottu> bug 1511791 in apparmor (Ubuntu) "dbus rule regression with wpa supplicant profile" [Undecided,New] https://launchpad.net/bugs/1511791 16:47 <tyhicks> jjohansen: that feels like a bug that I should chase down while you work on stacking 16:47 <tyhicks> jjohansen: well, unless you feel like it is a kernel issue 16:48 <jjohansen> tyhicks: feel free, specifically I am just looking at whether it is related to the signal issue I started chasing last week and haven't filed a bug on 16:48 <jjohansen> I wasn't planning on chasing it into dbus 16:49 <tyhicks> jjohansen: ok, only do as much on it as determining if it is the same bug as the signal issue 16:49 <tyhicks> jjohansen: if not, punt it to me 16:49 <jjohansen> ack 16:49 <tyhicks> thanks 16:49 <jjohansen> oh, and that means I should also finish getting together to post the code I put together for testing the signal issue 16:50 <jjohansen> that is it for /me sarnold_ you are up? 16:50 <tyhicks> haven't seen him yet 16:50 <jjohansen> yeah 16:51 <tyhicks> probably due to DST timing confusion 16:51 <jjohansen> yep 16:51 <tyhicks> chrisccoulson: go ahead 16:51 <chrisccoulson> This week, I've got an embargoed update to do. And possibly also Thunderbird 16:53 <chrisccoulson> I'll also be working on camera support in the browser for the phone, tidying up the Flash support in Oxide (it works pretty well now) and getting a fork of Chromium in git up and running 16:53 <chrisccoulson> I think that's me done 16:54 <tyhicks> thanks! 16:54 <tyhicks> [TOPIC] Highlighted packages 16:54 <tyhicks> The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 16:54 <tyhicks> See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:54 <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/parcimonie.html 16:54 <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/libguac.html 16:55 <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/xbindkeys-config.html 16:55 <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/gcc-4.8-ppc64el-cross.html 16:55 <tyhicks> http://people.canonical.com/~ubuntu-security/cve/pkg/netty.html 16:55 <tyhicks> [TOPIC] Miscellaneous and Questions 16:55 <tyhicks> Does anyone have any other questions or items to discuss? 16:57 <tyhicks> jdstrand, mdeslaur, sbeattie, jjohansen, ChrisCoulson: Thanks! 16:57 <tyhicks> #endmeeting