16:32 <ratliff> #startmeeting
16:32 <meetingology> Meeting started Mon Apr 16 16:32:21 2018 UTC.  The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology.
16:32 <meetingology> 
16:32 <meetingology> Available commands: action commands idea info link nick
16:32 <ratliff> The meeting agenda can be found at:
16:32 <ratliff> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting
16:32 <ratliff> [TOPIC] Announcements
16:32 <ratliff> Thanks to James Cowgill (jcowgill) for providing a debdiff for xenial for ffmpeg (LP: #1697785)!
16:32 <ubottu> Launchpad bug 1697785 in ffmpeg (Ubuntu Xenial) "Update to 2.8.14 in Xenial" [Undecided,Fix released] https://launchpad.net/bugs/1697785
16:33 <ratliff> Thanks to Simon Quigley (tsimonq2) providing debdiffs for trusty-artful for calibre (LP: #1758699)!
16:33 <ubottu> Launchpad bug 1758699 in calibre (Ubuntu Artful) "[CVE] JavaScript in a book can access local files using XMLHttpRequest" [Medium,Fix released] https://launchpad.net/bugs/1758699
16:33 <ratliff> Your work is very much appreciated and will keep Ubuntu users secure. Thank you!
16:33 <ratliff> [TOPIC] Weekly stand-up report
16:33 <ratliff> Jamie's off today so, mdeslaur: you're up
16:33 <mdeslaur> I'm on community this week
16:33 <mdeslaur> I just published some tasty perl updates
16:34 <mdeslaur> and I'm trying to get some things migrated in bionic
16:34 <mdeslaur> that's about it, I need to pick something from the cve list
16:34 <mdeslaur> sbeattie: you're up
16:34 <sbeattie> I'm on bug triage this week
16:34 <sbeattie> I'm still working on my gcc-4.6 retpoline backport
16:34 <sbeattie> I have some kernel cve triage tasks to do
16:35 <sbeattie> And I need to pick something off the cve list
16:35 <sbeattie> That's probably the highlights for my week
16:35 <sbeattie> jjohansen: I think you're next?
16:35 <jjohansen> ah does that mean I don't get to jump in at the end again :)
16:36 <sbeattie> I'll figure out our team order eventually.
16:36 <jjohansen> so this week I am
16:36 <jjohansen> working with cboltz on finish up 2.13 bug fixes and problems he is having around packaging
16:36 <jjohansen> coordinate with cboltz on opensuse presentation proposals, and get those submitted
16:36 <jjohansen> merge rc1 into apparmor-next and then drop on the next set of patches targeted for 4.18
16:36 <jjohansen> do follow-up on on last weeks bugs 1750594, 1679704
16:36 <ubottu> bug 1750594 in AppArmor "Eventual OOM with profile reloads" [Undecided,Fix committed] https://launchpad.net/bugs/1750594
16:36 <ubottu> bug 1679704 in apparmor (Ubuntu) "libvirt profile is blocking global setrlimit despite having no rlimit rule" [Critical,In progress] https://launchpad.net/bugs/1679704
16:36 <jjohansen> do some revisions for policy hashing and policy versioning patching so I can get those up as wip: merge requests
16:36 <jjohansen> proper upstreamable fix for 1750594 to replace the single case fix being used as a short term work around
16:37 <jjohansen> finish up further rlimit fixes for bugs discovered while working on 1679704
16:37 <jjohansen> continue work on my LSM stacking review for Casey
16:37 <jjohansen> work on prompting prototype
16:37 <jjohansen> uhmm I think that is it for /me
16:37 <sbeattie> jjohansen: let me know if I can help on the packaging front
16:37 <ratliff> not sure that you left time to sleep, jjohansen
16:37 <jjohansen> sbeattie: ack
16:38 <jjohansen> ratliff: oh right, I need to add the critical item of track down time to sleep
16:38 <ratliff> I haven't seen sarnold yet this morning, so chrisccoulson you go next
16:39 <leosilva> he just say morning right now :)
16:39 <ratliff> yeah, I spoke to soon
16:39 <sarnold> :)
16:39 <ratliff> sarnold: you are up
16:39 <sarnold> I'm in the happy place this week, working down the mirs
16:39 <sarnold> I'm on socat now
16:39 <chrisccoulson> oh, I did start typing :)
16:39 <sarnold> sorry chrisccoulson :(
16:40 <sarnold> socat might finish today or tomorrow, if there's any others needing bumping up to the head of the queue let me know ..
16:40 <sarnold> that's it
16:40 <chrisccoulson> I'm still working on rust 1.25 updates. Currently 73 tests fail across armhf and arm64 because the tests appear to crash, so I'll be spending time trying to figure that out
16:41 <chrisccoulson> I'd like to pretend I'll have some time left over to do something useful, but I have a feeling this is going to end up wasting another week
16:41 <chrisccoulson> that's me done
16:41 <ratliff> I'll check around, but I haven't received any other requests so far, sarnold
16:41 <ratliff> good luck, chrisccoulson
16:41 <ratliff> I'm on CVE triage this week.
16:42 <ratliff> I have sprint prep and other internal work including starting a white paper.
16:42 <ratliff> I have a couple more kpi scripts to clean up and check in, but the dashboard is full again.
16:42 <ratliff> leosilva: on to you
16:42 <leosilva> I'm in the happy place this week :)
16:43 <leosilva> I'm did an USN for patch-esm this morning
16:43 <leosilva> I'm finally finished ruby updates and I'm publishing it right now *the crow says: yeahhhhh*
16:43 <leosilva> other than that I'll keep my hunting to get something from cve-list
16:43 <leosilva> it's back to you ratliff
16:44 <ratliff> [TOPIC] Highlighted packages
16:44 <ratliff> The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so.
16:44 <ratliff> See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.
16:44 <ratliff> [TOPIC] Miscellaneous and Questions
16:44 <ratliff> Does anyone have any other questions or items to discuss?
16:44 <tsimonq2> Thanks for the mention. :)
16:45 <ratliff> thanks for the debdiffs!
16:46 <ratliff> mdeslaur, sbeattie, jjohansen, sarnold, chrisccoulson, leosilva: Thanks!
16:46 <ratliff> #endmeeting