15:32 #startmeeting Weekly Main Inclusion Requests status 15:32 Meeting started at 15:32:47 UTC. The chair is cpaelzer. Information about MeetBot at https://wiki.ubuntu.com/meetingology 15:32 just in time after my IRC timed out o/ 15:32 Available commands: action, commands, idea, info, link, nick 15:32 #topic Review of previous action items 15:33 no items other than the reviews assigned to MIR and security team 15:33 #topic current component mismatches 15:33 Mission: Identify required actions and spread the load among the teams 15:33 #link https://people.canonical.com/~ubuntu-archive/component-mismatches-proposed.svg 15:33 #link https://people.canonical.com/~ubuntu-archive/component-mismatches.svg 15:33 let us start with the -release report 15:33 I see updates (two weeks ago) on https://bugs.launchpad.net/ubuntu/+source/glade/+bug/1961023 15:33 Launchpad bug 1961023 in glade (Ubuntu) "[MIR] glade" [Undecided, Incomplete] 15:34 didrocks: seb128: does that need further action by you? 15:34 libhandy-1 -> glade: seb128 told me he was going to look at it (false positive, but let’s ensure) 15:34 ok, let us know if we need to memorize another false positive 15:34 nothing else new in this list 15:34 yeah, I want us to be sure before claiming this 15:34 going to -proposed now 15:34 python-consul looks new to me 15:34 on https://bugs.launchpad.net/ubuntu/+source/python-cheroot/+bug/1930111 15:34 Launchpad bug 1930111 in cherrypy3 (Ubuntu) "[MIR] new dependencies of cherrypy3: jaraco.collections, jaraco.classes, jaraco.text, python-cheroot, python-jaraco.functools, python-tempora, python-portend, zc.lockfile" [Undecided, In Progress] 15:35 there was an update 15:35 IMHO this is in wrong state, needs to go back to openstack Team 15:35 jamespage: I'll assign you and set incomplete for your awareness 15:36 another update: libqmi -> libqtrglib. The dep will be dropped soon rather than MIRing, it’s an optional dep that we don’t really need now 15:36 yay :) 15:36 thanks didrocks, I think I have read about this somewhere 15:36 so let us ignore libqmi 15:36 and gnome-shell -> libhandy1, I started it but I will need more time to finish it and too much urgent things right now (still aiming before EOW) 15:37 but I hear this is on you and we should not bother about it atm 15:37 indeed 15:37 python-xmlschema - I have the feeling we had this for a while ... 15:37 another false positive 15:37 ? 15:38 no no alternative 15:38 python-pysaml2 -> python3-xmlschema seems legit, and by the uploader names on openstack 15:38 jamespage: ^^ 15:39 bug exists and is 15:39 https://bugs.launchpad.net/ubuntu/+source/python-xmlschema/+bug/1953363 15:39 Launchpad bug 1953363 in python-xmlschema (Ubuntu) "[MIR] python-xmlschema, elementpath, importlib-resources" [High, New] 15:39 ok so right now this one is actually on security AFAICS 15:39 ok for me 15:39 it is flagged as 22.04 material 15:39 sarnold: can you check if this is on your list/queue ? 15:39 your teams list I should say? 15:39 cpaelzer: it is 15:39 good 15:40 next case then ... 15:40 https://bugs.launchpad.net/ubuntu/+source/libadwaita-1/+bug/1962568 is new but already assigned 15:40 Launchpad bug 1962568 in libadwaita-1 (Ubuntu) "[MIR] libadwaita-1" [Undecided, New] 15:40 didrocks: is busy these days 15:40 :) 15:40 but this one us openstack and not handled yet 15:40 consider it in a perfect world not be in the list next week :) 15:40 https://launchpad.net/ubuntu/+source/masakari-monitors -> python-consul 15:41 jamespage: ^^ 15:41 we see the new upload held back by this 15:41 https://launchpad.net/ubuntu/+source/masakari-monitors/12.0.0+git2022030313.a89511e-0ubuntu1 15:41 coreycb: ^^ your upload 15:41 the rest in this list looks known to me 15:41 cpaelzer: thanks, I'll take a look 15:41 didrocks: final check on libreoffice -> epiphany? 15:42 IIRC that dep was meant to be dropped 15:42 is that task assigned to someone? 15:42 cpaelzer: definitively false positive 15:42 the alternative has firefox as first 15:42 which is seeded 15:42 oh ok - then just keep reminding me until I have learned 15:42 thanks in advance 15:42 so another one for the list :/ 15:42 #topic New MIRs 15:42 Mission: ensure to assign all incoming reviews for fast processing 15:42 we should have a deny-list at some point.. 15:42 #link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=NEW&field.status%3Alist=CONFIRMED&assignee_option=none&field.assignee=&field.subscriber=ubuntu-mir 15:42 slyon: yeah we all agree 15:43 the first to get to code one has is allowed to skip one review 15:43 new MIRs list is empty 15:43 one only? :) 15:43 \o/ 15:43 :) 15:43 #topic Incomplete bugs / questions 15:43 Mission: Identify required actions and spread the load among the teams 15:43 #link https://bugs.launchpad.net/ubuntu/?field.searchtext=&orderby=-date_last_updated&field.status%3Alist=INCOMPLETE_WITH_RESPONSE&field.status%3Alist=INCOMPLETE_WITHOUT_RESPONSE&field.subscriber=ubuntu-mir 15:44 sarnold: I have to go by the market, only if no one implements it for one the price increases 15:44 HODL HODL HODL! 15:44 we have four updates since last week in the list of incompletes 15:44 checking them one by one 15:45 https://bugs.launchpad.net/ubuntu/+source/tcmu/+bug/1854362 15:45 Launchpad bug 1854362 in ceph-iscsi (Ubuntu) "[MIR] ceph-iscsi, tcmu, python-configshell-fb, python-rtslib-fb, urwid, targetcli-fb" [Undecided, In Progress] 15:45 that is ok, openstack can use this now 15:45 I found it forgotten and updated the case, they are aware 15:45 to be extra sure coreycb jamespage ^^ FYI 15:45 https://bugs.launchpad.net/ubuntu/+source/libqrtr-glib/+bug/1963707 15:45 Launchpad bug 1963707 in libqrtr-glib (Ubuntu) "[MIR] libqrtr-glib" [Low, Incomplete] 15:45 filed by desktop, related to qmi, which we were told the dependency will be dropped 15:45 discussed above, the dep will be dropped as soon as seb128 has a sec 15:45 so action 15:46 https://bugs.launchpad.net/ubuntu/+source/rustc/+bug/1957932 15:46 Launchpad bug 1957932 in rustc (Ubuntu) "[MIR] rustc, cargo" [Critical, Incomplete] 15:46 that is documentation of what was discussed at the sprint 15:46 no action yet 15:46 https://bugs.launchpad.net/ubuntu/+source/python-cheroot/+bug/1930111 15:46 Launchpad bug 1930111 in cherrypy3 (Ubuntu) "[MIR] new dependencies of cherrypy3: jaraco.collections, jaraco.classes, jaraco.text, python-cheroot, python-jaraco.functools, python-tempora, python-portend, zc.lockfile" [Undecided, In Progress] 15:47 that was unblocked by security (thanks) and is back on openstack 15:47 jamespage: ^^ FYI 15:47 I have already updated the case to reflect that 15:47 #topic MIR related Security Review Queue 15:47 Mission: Check on progress, do deadlines seem doable? 15:47 #link https://bugs.launchpad.net/~ubuntu-security/+bugs?field.searchtext=%5BMIR%5D&assignee_option=choose&field.assignee=ubuntu-security&field.bug_reporter=&field.bug_commenter=&field.subscriber=ubuntu-mir 15:48 we recently finished plocate https://bugs.launchpad.net/ubuntu/+source/plocate/+bug/1960864 -- and glusterfs is in progress https://bugs.launchpad.net/ubuntu/+source/glusterfs/+bug/1950321 -- swtpm is also in-progress of a sort, no progress in the last few days https://bugs.launchpad.net/ubuntu/+source/swtpm/+bug/1948748 15:48 a few are left 15:48 Launchpad bug 1960864 in Release Notes for Ubuntu "[MIR] plocate" [Undecided, New] 15:48 Launchpad bug 1950321 in glusterfs (Ubuntu) "[MIR] glusterfs" [Critical, Confirmed] 15:48 Launchpad bug 1948748 in swtpm (Ubuntu) "[MIR] swtpm" [High, New] 15:48 yes sarnold I've seen and updated the bug 15:48 thank you 15:48 glusterfs sounds like it's still pretty gronky code 15:48 why isn't gluster in this list anymore ? 15:48 'assigned to sbeat tie' 15:49 oh reassigned 15:49 ok 15:49 the list still shringks every week 15:49 * sbeattie is trying to get through it, but it'd help if people'd stop finding security issues in other software. 15:49 it == glusterfs 15:49 yespls 15:49 so again thank you sarnold and sbeattie and all the reviewer you train up 15:49 sbeattie: can we stop other people finding other issues somehow? 15:50 we can beg people to run coverity and cppcheck and .. :) 15:50 hehe 15:50 so to sum it up, progress is made on the security reviews, that makes people happy, we still might be able to complete all 22.04 material in time 15:50 #topic Any other business? 15:50 https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/1887187 15:50 Launchpad bug 1887187 in nftables (Ubuntu) "[MIR] nftables" [Critical, New] 15:51 right that is recent as well slyon 15:51 joalif and myself finished the MIR review on that one today 15:51 not sure why it didn't show up in the new MIRs queue 15:51 sweet 15:51 thanks slyon again! 15:51 basically it is back to the security team for security review and a small packaging change (missing .symbols file) 15:51 slyon: does it have required todos? 15:51 yes it has some 15:52 so I'll set incomplete 15:52 cpaelzer: yes it does have two small required TODOs 15:52 then it would have shown 15:52 thank you 15:52 And this is on security twice now - for review and for driving the case (IIUC) 15:52 exactly 15:52 *very* secure 15:52 hehe 15:53 https://github.com/cpaelzer/ubuntu-mir/pull/9 15:53 Pull 9 in cpaelzer/ubuntu-mir "RFC: ensure package built in most recent archive test rebuild" [Open] 15:53 I updated https://bugs.launchpad.net/ubuntu/+source/nftables/+bug/1887187 15:53 Launchpad bug 1887187 in nftables (Ubuntu) "[MIR] nftables" [Critical, Incomplete] 15:53 let us look at the PR 15:53 sorry for bug handling not being present sbeattie 15:53 reading the case 15:53 no problem 15:54 I'd plus one this suggestion 15:55 could we vote on this please, if we are overall +1 I can add it right away 15:55 +1 15:55 +1 15:55 +1, maybe we could suggest doing a local build, too? 15:55 I'd like to avoid the issue found in the python-cheroot security review, feel free to wordsmith, bikeshed, etc. 15:55 +1 as well 15:55 +1 15:56 like running sbuild on the package locally. This would be even newer than the latest archive rebuild 15:56 slyon: I can add that as C 15:56 that or a proposed PPA rebuild 15:56 this suggestion is better than nothing, wordsmithing can happen if this ever is a pain to someone 15:56 I'd add it right now 15:56 cpaelzer: that'd be nice 15:56 that seems to be all we have 15:57 thanks! 15:57 ok closing then 15:57 #endmeeting