16:33 #startmeeting 16:33 Meeting started Mon Jun 10 16:33:03 2013 UTC. The chair is jdstrand. Information about MeetBot at http://wiki.ubuntu.com/meetingology. 16:33 16:33 Available commands: #accept #accepted #action #agree #agreed #chair #commands #endmeeting #endvote #halp #help #idea #info #link #lurk #meetingname #meetingtopic #nick #progress #rejected #replay #restrictlogs #save #startmeeting #subtopic #topic #unchair #undo #unlurk #vote #voters #votesrequired 16:33 The meeting agenda can be found at: 16:33 [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting 16:33 [TOPIC] Announcements 16:33 Christian Kuersteiner (ckuerste) provided debdiffs for lucid-precise for xml-light (LP: #1186860). Your work is very much appreciated and will keep Ubuntu users secure. Great job! :) 16:33 Launchpad bug 1186860 in xml-light (Ubuntu Precise) "Hash collision vulnerability in xml-light" [Undecided,Fix released] https://launchpad.net/bugs/1186860 16:33 hi! 16:34 [TOPIC] Weekly stand-up report 16:34 I'll go first 16:34 apparently I am in the happy place this week, which I am grateful for :) 16:34 :) 16:34 I'm catching up from being off last week 16:34 I've got patch piloting to do 16:35 an embargoed update 16:35 various reviews and coordination surrounding application isolation, scopes and click packages 16:35 and I plan to do a preliminary install audit of the phablet image 16:35 mdeslaur: you're up 16:35 I have an openchrome update I'll be releasing this afternoon 16:36 and after that, I've got a bunch of stuff ready for testing in the secppa 16:36 I'm also on triage duty this week 16:36 that's pretty much it...updates as usual :) 16:36 sbeattie: you're up 16:36 I'm again on apparmor this week 16:37 I'm currently working on the apparmor/sdk work in the https://blueprints.launchpad.net/ubuntu/+spec/security-s-appisolation-sdk 16:38 sbeattie: how is that going? 16:38 I've uploaded some of the easyprof policy group stuff to the dbus-dev ppa, along with versions of the calculator and calendar app that make use of them 16:38 ah, cool 16:38 oh, cool 16:38 * jdstrand makes note to play with that this week 16:38 I'm still working on getting json input to easyprof going and am continuing to look at what the click package emits 16:39 I think there's an apparmor upstream meeting this week that I need to prep for 16:39 oh, I should note that after this week, I'm off for two weeks 16:39 That's it for me. 16:40 sbeattie: wrt click> maybe ask beuno/cjwatson? 16:40 jdstrand: sure, I've been playing around with the source a bit 16:40 tyhicks: you're up 16:41 sbeattie: also, for clarity (since I've been off a week and still catching up), you're still going to work with debhelper correct? 16:41 I'm (finally) finishing my email to the apparmor list to compare the various dbus syntax proposals 16:41 jdstrand: yes. I didn't do that in the bits I uploaded. 16:41 I got sidetracked last week while chasing down some odd things I came across while preparing a profile for that email 16:42 sbeattie: ok, thanks. I think that shouldn't be too bad. we (you, me, mdeslaur) can talk more if anything is unclear 16:42 tyhicks: please continue (sorry to interrupt) 16:42 oh! forgot to mention I also plan on installing ubuntu on my nexus 4 this week 16:42 later today, I'll start prepping for my work items in https://blueprints.launchpad.net/ubuntu/+spec/client-1305-content-mgmt-picking 16:43 I'll begin work on that blueprint this week 16:43 and will continue working on the parser changes in the background 16:43 that's it for me 16:43 jjohansen: you're up 16:44 tyhicks: fyi, tvoss mentioned possibly having a command line first draft of that api this week 16:44 mdeslaur: ok, that would be good 16:44 tyhicks: also note, that the meeting is early tomorrow 16:44 tyhicks: did anything happen with rescheduling that 16:44 I guess we'll find out more at tomorrow's meeting 16:44 jdstrand: no, I'm going to give it a shot for a week or two 16:45 if it kills me, I'll push for a reschedule 16:45 I think I'll be fine 16:45 tyhicks: sorry about that, but I appreciate it 16:45 no problem 16:45 I think jjohansen is afk atm 16:45 oh, yes 16:45 tyhicks: please don't die 16:45 sarnold: you're up 16:45 :) 16:46 I'm on community this week; I'll also be reviewing some patches I expect from jjohansen soon. I'd like jdstrand or mdeslaur's help in pushing the openssl zlib environment variable to a -proposed for wider testing before pushing to the archive 16:46 sarnold: ah! yes, cool 16:46 sarnold: can I try and push what's in the ppa now? 16:46 my bouncycastle test suite is starting to feel like there's something to it :) I've got symmetric ciphers and their modes of operations working; I can see adding assymetric ciphers and then finally some high level TLS servers/clients 16:46 sarnold: just put it in the ubuntu-security-proposed ppa and ping me to push it to -proposed when ready 16:46 mdeslaur: yes 16:47 jdstrand: it's already in the security ppa; would it need to be rebuilt in ubuntu-security-proposed before it could be pushed? 16:47 sarnold: nope 16:47 sarnold: no, I can do it from there too 16:48 jdstrand: let me try first 16:48 ah, cool :) 16:48 * jdstrand defers to mdeslaur 16:48 okay, I think that's me, chrisccoulson, you're up :) 16:49 thanks sarnold 16:50 so, last week, i pretty much finished off fleshing out the architecture for our chromium embedding api (tentatively named "oxide", thanks to mdeslaur) ;) 16:50 i have a pretty good idea of how much work is involved now 16:50 tyhicks: (fyi, please feel free to poke me if I don't respond to your apparmor policy email-- I'd like to get those discussions moving and completed) 16:50 jdstrand: ack - same here 16:50 and i've actually created a project branch locally to start some hacking on it :) 16:50 chrisccoulson: nice! 16:50 chrisccoulson: oh, cool...looking forward to discussion that with you 16:51 this week, i've got an embargoed update to do 16:52 i think that's me (other than that update, i'll be continuing work on https://blueprints.launchpad.net/ubuntu/+spec/client-1303-webkit-maintenance/) 16:52 [TOPIC] Highlighted packages 16:52 The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so. 16:53 See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved. 16:53 http://people.canonical.com/~ubuntu-security/cve/pkg/boinc.html 16:53 http://people.canonical.com/~ubuntu-security/cve/pkg/iscsitarget.html 16:53 http://people.canonical.com/~ubuntu-security/cve/pkg/ruby-openid.html 16:53 http://people.canonical.com/~ubuntu-security/cve/pkg/charybdis.html 16:53 http://people.canonical.com/~ubuntu-security/cve/pkg/bcron.html 16:53 [TOPIC] Miscellaneous and Questions 16:53 Does anyone have any other questions or items to discuss? 16:57 mdeslaur, sbeattie, tyhicks, jjohansen, sarnold, ChrisCoulson: thanks! 16:57 #endmeeting