16:32 <jdstrand> #startmeeting
16:32 <jdstrand> The meeting agenda can be found at:
16:33 <jdstrand> [LINK] https://wiki.ubuntu.com/SecurityTeam/Meeting
16:33 <jdstrand> [TOPIC] Announcements
16:33 <jdstrand> Stefan Bader (smb) provided debdiffs for precise-raring for xen. Your work is very much appreciated and will keep Ubuntu users secure. Thanks!
16:33 <jdstrand> [TOPIC] Weekly stand-up report
16:33 <chrisccoulson> hi
16:33 <jdstrand> I'll go first
16:34 <jdstrand> I'm on triage this week
16:34 <jdstrand> I will finish the preliminary install audit of the phablet image this week
16:34 <jdstrand> I have some pending updates
16:35 <jdstrand> and need to review sbeattie's deliverables for the month and plan for getting them finished since he is on holiday
16:35 <jdstrand> mdeslaur: you're up
16:35 <mdeslaur> I'm on community this week
16:35 <mdeslaur> am currently testing an embargoed issue
16:35 <mdeslaur> and will write a test for libraw
16:36 <mdeslaur> will go down the list of updates after that
16:36 <mdeslaur> that's pretty much it
16:36 <mdeslaur> uh...who's usually after steve... tyhicks?
16:36 <tyhicks> yep
16:37 <tyhicks> I'm currently drafting an email to the apparmor list to push the dbus syntax discussions along
16:37 <tyhicks> I hope that we can come to a decision on that and I can make the parser changes for that this week
16:38 * sarnold dons asbestos ..
16:39 <jdstrand> so
16:39 <jdstrand> with sbeattie out, I wonder if we can actually take a decision
16:39 <tyhicks> I'll also be going through my todo list of trivial things that needs to be fixed/improved in the dbus and apparmor packages as we get closer to upstreaming those and sticking them in the archive
16:39 <tyhicks> jdstrand: I expected more people to chime into your question on proposal 3 vs 4
16:40 <jdstrand> me too :\
16:40 <tyhicks> jdstrand: but, I feel like there's still a lean towards 3
16:40 <tyhicks> which is sbeattie's proposal
16:41 <tyhicks> That's it for me
16:41 <tyhicks> jjohansen: you're up
16:41 <jdstrand> because that didn't happen and steve is on vacation, I don't think we can take a decision and complete that work item
16:41 <jdstrand> wait
16:41 <tyhicks> ah
16:41 <tyhicks> sorry
16:41 <jdstrand> before we get to jjohansen
16:41 <jdstrand> jjohansen: opinion? ^
16:42 <jjohansen> jdstrand: well likely not, but we will see how things go. I don't think steve cares so much about 3 vs 4
16:42 <jdstrand> huh, 4 seems so radically different I would think there would be an opinion
16:43 <jjohansen> but if we are leaning towards 3 and since it is his proposal modified, maybe
16:43 <jdstrand> but I don't want to stall out for weeks either
16:43 <jdstrand> my feeling is that as upstream, we shouldn't take the decision
16:43 <jjohansen> jdstrand: don't worry I can throw enough fuel on the fire
16:43 <jdstrand> jjohansen: I'm afraid of said fuel :P
16:44 <jdstrand> my feeling is that as upstream, we shouldn't take the decision without steve
16:44 <jdstrand> but, for Ubuntu I think we should revise our stance on pushing a syntax that may change
16:45 <jjohansen> I think that we will just have to push something that may change
16:45 <jjohansen> but lets get it to where it likely won't
16:45 <jdstrand> in others words, let's get as far as we can on the syntax as we can without steve (like tyhicks said), then push that into the archive (or at least the ppa) so that these code bits are in before feature freeze and getting some testing
16:46 <tyhicks> I think that makes sense
16:46 <jdstrand> then when he gets back, we can see what he objects to (if anything), then adjust before committing upstream. then after committing to upstream, do another upload to ubuntu
16:47 <tyhicks> that's reasonable
16:47 <jdstrand> mdeslaur, jjohansen: what do you think?
16:48 <jjohansen> jdstrand: I think its the only thing we can reasonable do given the circumstance
16:48 <mdeslaur> I didn't follow what the issue was, so I have no current opinion
16:48 <jdstrand> ok, then let's plan on that
16:48 <jdstrand> tyhicks: thanks
16:48 <jdstrand> jjohansen: you're up
16:48 <jjohansen> I'll be working on backporting apparmor for the phablet kernels, an email to push the syntax discussion along (or at least ignite the arguing again), hopefully release 2.8.2 and then back to working ipc
16:49 <jjohansen> s/working/working on/
16:49 * jjohansen just wishes it was all working
16:51 <mdeslaur> \o/ phablet kernels
16:52 <jjohansen> thats it for me sarnold your up
16:53 <sarnold> I'm in my happy place this week, though I've got some leftover packages from community to finish: stunnel4 (I want another two manual tests before shipping) and ruby-openid (no idea how to test, asking ckuerst for ideas..)
16:54 <sarnold> the patch for ruby-openid looked simpled enough, it's probably fine even without a test, but just 'it loads' is a little unsatisfying.
16:55 <sarnold> I'm looking forward t othrowing rocks at hornets's nests^W^W^W^W the upcoming dbus responses... I'm mostly happy with #3 but want to make sure that we're not missing something better.
16:55 <sarnold> I'm hopeful for some patch review from jjohansen or tyhicks this week, but if not, I'll pick up an update
16:56 <sarnold> I think that's it for me; chrisccoulson, you're up :)
16:56 <chrisccoulson> w00t
16:57 <chrisccoulson> so, last week we got a flash update, and i did some more work on our chromium API
16:57 <chrisccoulson> i've scheduled a meeting tomorrow afternoon to discuss that btw :)
16:57 <chrisccoulson> i shall be doing more work on that this week, and we'll likely get chromium published too (yay!)
16:57 <jdstrand> sarnold: regarding options against #3-- not to worry, I'll be happy to shoot those down too
16:57 <jdstrand> sarnold: :P (j/k ;)
16:57 <sarnold> jdstrand: woo :)
16:58 * jdstrand hugs sarnold
16:58 <sarnold> chrisccoulson: oh man, that's awesome. :)
16:58 <mdeslaur> chrisccoulson: chromium updates! /me rubs his eyes
16:58 <chrisccoulson> also, i'll get builds for next weeks firefox update before the end of the week
16:58 * jdstrand hugs chrisccoulson too :)
16:58 <chrisccoulson> so it's going to be a fun end to the week ;)
16:58 <chrisccoulson> thanks :)
16:58 <chrisccoulson> i think that's me done
16:59 <jdstrand> [TOPIC] Highlighted packages
16:59 <jdstrand> The Ubuntu Security team will highlight some community-supported packages that might be good candidates for updating and or triaging. If you would like to help Ubuntu and not sure where to start, this is a great way to do so.
16:59 <jdstrand> See https://wiki.ubuntu.com/SecurityTeam/UpdateProcedures for details and if you have any questions, feel free to ask in #ubuntu-security. To find out other ways of helping out, please see https://wiki.ubuntu.com/SecurityTeam/GettingInvolved.
16:59 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/lib3ds.html
16:59 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/tryton-server.html
16:59 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/libphp-jpgraph.html
16:59 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/osc.html
17:00 <jdstrand> http://people.canonical.com/~ubuntu-security/cve/pkg/magics++.html
17:00 <jdstrand> [TOPIC] Miscellaneous and Questions
17:00 <jdstrand> Does anyone have any other questions or items to discuss?
17:05 <jdstrand> mdeslaur, tyhicks, jjohansen, sarnold, chrisccoulson: thanks!
17:05 <jdstrand> #endmeeting