16:32 <ratliff> #startmeeting 16:32 <meetingology> Meeting started Mon Apr 23 16:32:34 2018 UTC. The chair is ratliff. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:32 <meetingology> 16:32 <meetingology> Available commands: action commands idea info link nick 16:32 <ratliff> The meeting agenda can be found at: 16:32 <ratliff> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:32 <ratliff> [TOPIC] Announcements 16:33 <mdeslaur> \o 16:33 <ratliff> 18.04 gets released this week! 16:33 <leosilva> oww, nice! 16:33 <ratliff> [TOPIC] Weekly stand-up report 16:33 <ratliff> jdstrand: you are up! 16:35 <ratliff> we'll circle back around to jdstrand later, mdeslaur do you want to go ahead? 16:35 <mdeslaur> sure! 16:35 <mdeslaur> I'm in the happy place this week 16:35 <mdeslaur> I'm going to publish some mysql updates soon once I'm done with testing 16:35 <mdeslaur> I also have an embargoed issue 16:36 <mdeslaur> and I'll go down the list after that 16:36 <mdeslaur> that's it from me, sbeattie? 16:36 <sbeattie> I'm on community this week 16:36 <sbeattie> I need to check over the release notes and security features wiki pages for 18.04 things. 16:37 <sbeattie> I have the usual kernel cve triage things to do 16:37 <sbeattie> Still working on the precise gcc retpoline backport :/ 16:37 * jdstrand is here 16:38 <sbeattie> I'm also helping jjohansen track down why the apparmor parser userspace tests are failing in some environments. 16:38 <sbeattie> and have some misc review work to do there. 16:38 <sbeattie> Tht's probably the major highlights for my week. 16:39 <sbeattie> jdstrand: you want to go next, and then hand of to jjohansen? 16:39 <jdstrand> sure 16:39 <jdstrand> This week I plan to work on: 16:39 <jdstrand> - focusing on snap usns 16:39 <jdstrand> - critical priority snapd PR reviews (none atm) 16:39 <jdstrand> - sprint prep 16:39 <jdstrand> - will investigate resquashfs wrt electron-builder as have time 16:39 <jdstrand> that's it from me. jjohansen, you're up 16:39 <jjohansen> I have several new 2.13 bugs to start chasing down, and now an issue with expr-simplify as well 16:39 <jjohansen> Mount changes from David Howells to review 16:39 <jjohansen> do some revisions for policy hashing and policy versioning patching so I can get those up as wip: merge requests 16:39 <jjohansen> proper upstreamable fix for 1750594 to replace the single case fix being used as a short term work around 16:39 <jjohansen> finish up further rlimit fixes for bugs discovered while working on 1679704 16:39 <jjohansen> continue work on my LSM stacking review for Casey 16:39 <jjohansen> work on prompting prototype 16:40 <jjohansen> thats it for me sarnold you are up 16:40 <sarnold> I'm on CVE duty this week 16:40 <sarnold> I'll probably hold off on starting that to try to finish up xe-guest-utilities .. the bits I haven't seen yet are all in go, so I'm hoping they're cleaner than the shell stuff I've seen so far.. 16:41 <sarnold> I'll keep on rolling down the MIR list and reading apparmor patches as needed 16:41 <sarnold> that's it for me, chrisccoulson? 16:41 <chrisccoulson> I'm expecting chromium updates this week 16:42 <chrisccoulson> I've got work arounds for the 2 rust issues I'm looking at, although one of those is just "fingers in ears, there are no test failures, lalalala" 16:43 <chrisccoulson> I don't know whether to spend any more time this week on that, it feels a bit pointless 16:43 <chrisccoulson> I've still got to work on backports to all the other releases, so there could be new issues there anyway 16:43 <chrisccoulson> I need to try to find time for the python3.5 backport too 16:44 <chrisccoulson> And I also need to get the thunderbird-next packaging in shape too, for the next major release (which is soon). We ship a thunderbird extension by default, which has historically been low maintenance. But the context behind https://mail.mozilla.org/pipermail/tb-planning/2018-April/005977.html means it will stop being low maintenance now :( 16:45 <chrisccoulson> Given that's my extension, and the low probability of finding anyone else to hand it off to, 3 guesses who will end up with that ;) 16:45 <chrisccoulson> Another fun week. I think that's me done 16:46 <ratliff> I'm on bug triage this week. 16:46 <ratliff> I will be at the product roadmap sprint next week, so the weekly meeting for next week has been cancelled and I have some more sprint prep work to do. 16:46 <ratliff> I am working an embargoed issue and have internal work to do. 16:47 <ratliff> leosilva: you are up 16:47 <leosilva> I'm in the happy place this week :) 16:47 <leosilva> I have a ghostscript update to work. I want to revisit ruby cves/triage too and I'll keep the hunting 16:47 <leosilva> that is me done. 16:47 <leosilva> ratliff: it's back to you 16:48 <ratliff> thanks! 16:48 <ratliff> [TOPIC] Highlighted packages 16:48 <ratliff> The Ubuntu Security team suggests that contributors look into merging Debian security updates in community-supported packages. If you would like to help Ubuntu but are not sure where to start, this is a great way to do so. 16:48 <ratliff> See http://people.canonical.com/~ubuntu-security/d2u/ for available merges and https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details on preparing Ubuntu security updates. If you have any questions, feel free to ask in #ubuntu-hardened. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:48 <ratliff> [TOPIC] Miscellaneous and Questions 16:48 <ratliff> Does anyone have any other questions or items to discuss? 16:53 <ratliff> jdstrand, mdeslaur, sbeattie, jjohansen, sarnold, chrisccoulson, leosilva: Thanks! 16:53 <sarnold> thanks ratliff! 16:53 <ratliff> #endmeeting