17:00:56 #startmeeting RELENG (2019-02-14) 17:00:56 Meeting started Thu Feb 14 17:00:56 2019 UTC. 17:00:56 This meeting is logged and archived in a public location. 17:00:56 The chair is mboddu. Information about MeetBot at http://wiki.debian.org/MeetBot. 17:00:56 Useful Commands: #action #agreed #halp #info #idea #link #topic. 17:00:56 The meeting name has been set to 'releng_(2019-02-14)' 17:00:56 #meetingname releng 17:00:56 #chair nirik tyll sharkcz masta pbrobinson pingou puiterwijk maxamillion mboddu Kellin dustymabe 17:00:56 The meeting name has been set to 'releng' 17:00:56 Current chairs: Kellin dustymabe masta maxamillion mboddu nirik pbrobinson pingou puiterwijk sharkcz tyll 17:00:56 #topic init process 17:01:23 hi, /me is here 17:02:17 morning 17:02:19 * dustymabe waves 17:03:09 * relrod waves 17:03:16 Hello Everyone 17:03:25 Lets get started 17:03:39 #topic #7793 Implement new Fedora Security policy for retiring packages with security bugs 17:03:45 #link https://pagure.io/releng/issue/7793 17:04:19 * cverna waves 17:04:29 So, FESCo asked us to do this work 17:04:56 yeah. Which doesn't magically mean we have cycles to do so. ;) 17:05:15 Yeah, but now we have Tomas for doing these sort of automation work 17:05:25 Although he is on PTO this week :) 17:06:10 cool. Is this something he is willing to work on? 17:06:21 note that we can possibly reuse some of the FTBFS scripting 17:06:32 nirik: Yes and yes 17:07:19 excellent 17:07:44 nirik: But, I want to understand the proposal here a bit more 17:08:09 it's been a long time since I looked at it. ;) 17:08:47 nirik: Okay, I am not able to understand the time related information 17:10:39 re-reading it, I am not sure why we tied it to branching. 17:11:28 As I understand it, we start looking at security issue bugs opened against a pkg for 6 months 4 weeks before mass branching, and then file ftbfs (which I dont know why, since they might be buildable) and send weekly notification for 8 weeks and orphan them? 17:11:55 basically we want to file bugs against everything with those critera like a FTBFS bug.... but instead a "Outstanding security bug" and then nag for 8 weeks one per week, and retire if the bug isn't fixed at the end 17:12:16 "like" FTBFS. 17:12:29 So, its a continuous thing? not 4 weeks before branching? 17:12:34 nirik: Okay 17:12:43 well, the timing seems odd. 17:13:03 perhaps we should ask for clarification from fesco 17:13:47 Yeah, that was the other question, since 8 weeks of notifications starting 4 weeks before branching means, we will be branched by the end of 8 weeks and we orphan/retire them both on branched and rawhide? 17:14:08 yeah, that seems less than ideal. 17:14:44 It would make more sense to me to do right after branching (but rawhide only), and orphan, then retire before the next branch 17:15:27 But that would be a lot of weeks of nagging :) (if sent every week) 17:15:51 well, nag for N weeks, then orphan, then N weeks and retire? 17:16:14 but I am not sure why 8 is the number there... I guess to allow for people being on vaacation or something. 17:16:49 and the orphan and retire can be done as part of the retire orphans process... 17:17:16 it would be nice to leverage some of pagure in all of this automation, ie try to see if we can had some the branch info in pagure 17:17:43 nirik: Okay +1 17:17:51 all this stuff is pretty manual... it would be nice to automate it 17:17:56 cverna: I didnt get you 17:17:59 and the state of a package, for example we could have archived repo in pagure for retired 17:18:07 * nirik points to cverna's releng automation page. ;) 17:18:36 mboddu: I mean a lot of of the info you need might already be available in pagure's db 17:18:49 so, shall we ask fesco for clarification? if we do, we should propose something more clear at the start. 17:18:59 just not displayed or available via an api 17:19:23 cverna: Yeah, my plan is to automate this stuff totally, I dont want RelEng to sit down and do it manually :) 17:19:31 nirik: good point 17:19:52 nirik: Yup, I will file a ticket with FESCo and also ping Miro on the ticket 17:20:50 ok. I'd suggest proposing we change it to start after branching in rawhide only and confirm 8 weeks is the nagging time before orphaning. 17:21:10 #info mboddu will file a ticket with FESCo on more clarification about the timing of this process 17:21:26 it's hard to keep in mind all these things... it would be nice to have a page/doc/thing describing them and when 17:21:36 #info suggestion is - proposing we change it to start after branching in rawhide only and confirm 8 weeks is the notification time before orphaning. 17:22:09 nirik: +1, once I get the information, either Tomas or I will create a wiki page 17:22:23 so, is this stuff in the FPM schedules? 17:22:37 And the process will be documented in docs.pagure.org/releng 17:22:45 nirik: Not that I know of 17:22:54 As far as I remember 17:22:57 * mboddu checks 17:23:23 https://fedorapeople.org/groups/schedule/f-30/f-30-releng-tasks.html 17:23:24 it is 17:23:35 Retirement process for packages with open security issues Tue 2019-01-22 Mon 2019-03-18 17:23:46 Retire Orphaned and Long-Time FTBFS Rawhide Packages Tue 2019-02-19 Tue 2019-02-19 17:24:47 nirik: Yeah, right 17:25:03 so I guess another thing to ask is: since we haven't done this this cycle, should we try, or should we punt to f31? 17:25:24 Yes, I will ask it in the ticket 17:25:56 #info PGM schedule already has this scheduled, mboddu will ask if we should try it or punt it to f31 17:26:56 cool 17:27:03 Anything else? 17:28:15 not on this I don't think 17:29:58 Okay, there is only 1 other thing I wanted to discuss 17:30:04 #topic Change Meeting time 17:30:33 https://framadate.org/fedorarelengmeeting 17:31:11 cverna, dustymabe, relrod : Since you are here, can you please add your vote ^, if you can 17:31:22 on it 17:31:50 So, far it looks like Tue 16:00 UTC or Fri 16:00 UTC is the best time 17:32:25 If that seems to be the case, I want to propose Tue as sometimes Fri is a long weekend or people want to take PTO for extended weekend 17:32:26 * relrod looks 17:33:04 Tue 16:00 is when the CPE program call happens so that might not be the best 17:33:13 or I messed up my UTC time 17:33:34 one problem with tuesday...ok, second problem with tuesday: often we have releng things on tue... mass branching, freeze starts, etc. 17:33:47 * nirik filled this out before we had that call I think 17:33:49 yep 1600 is cpe time 17:34:15 nirik: Yeah, right, I haven't thought about it at all 17:34:26 I guess we could just keep this time... 17:34:27 cverna: Ahhh, you are okay with all the times? 17:34:38 no I messed up editing now :P 17:35:14 nirik: Its not working out for me, hence I wanted to propose a new time and couple of people also requested it earlier 17:35:37 oh right, reading that an hour eariler would work better for you? 17:36:13 * cverna likes Thursday 1600 so it is just after the infra meeting 17:37:41 cverna: I would like to avoid back to back to meetings since most of the people will attend both of the meetings, but we will see 17:38:00 we could do 16:30 and confuse everyone! :) 17:38:12 mboddu: I voted for times that work(-ish) with my class schedule, but I'm not too active in releng yet, so don't weigh my vote too heavily. 17:38:34 relrod: Thanks 17:38:38 nirik: Haha :) 17:39:54 How about Mon or Wed 16:00 UTC? 17:40:05 cverna: Didn't say no to them, so he can attend ;) 17:40:09 monday I have fesco. ;( 17:40:14 wed is fine for me 17:40:49 * cverna double check his calendar 17:41:31 monday would work 17:41:51 cverna: Wed? Since nirik got FESCo on Monday 17:42:25 Wed 16:00 UTC seems to be perfect if cverna can make it 17:42:38 Lot of pressure on cverna :P 17:43:00 I would be ok but every other week I have a call at this time 17:43:11 but I can follow on IRC :) 17:43:19 cverna: Okay, that is awesome 17:43:27 So, wed 16:00 UTC it is 17:43:45 Scheduling is hard :( 17:43:51 yep 17:43:59 almost as much as naming 17:44:12 next up we need to name our new schedule 17:44:23 #info Fedora RelEng meeting will be moved to every Wednesday 16:00 UTC 17:44:38 #info mboddu will send an email to releng list and update the calendar 17:44:42 oh, I suppose we can do #fedora-meeting then 17:44:42 ? 17:44:43 smooge: Noooooooo 17:44:51 maybe we should look at merging the infra and releng meeting 17:45:12 * mboddu is thinking about cverna's idea 17:45:13 that would be one less thing in the calendar :P 17:45:33 cverna: Well, we have to extend the meeting time though 17:46:00 nirik: +1 on #fedora-meeting 17:46:15 mboddu: yes 17:46:30 we could... some people might not be interested in one or the other tho 17:46:57 if we were going that way we would need an agenda and respect timing 17:47:15 Yup and 2 hours continuous meeting is also hectic 17:47:21 true 17:47:29 * nirik isn't sure what he thinks of that... would want to ponder on it more 17:47:37 although the infra meeting is often done in 30 min 17:47:42 Anyway, we can push it for later 17:48:02 sure it was just me thinking out loud 17:48:09 We will think about it in future if needed 17:48:34 Okay, moving on 17:48:39 #topic Open Floor 17:49:01 I have a question to nirik but I can go last 17:49:31 I was just going to mention branching is next week, so we should make sure we are all ready for it. 17:50:40 #info Mass Branching is next week, Feb 19th 17:50:52 nirik: That means, new key and signing the rawhide 17:50:58 yep. 17:51:07 perhaps we should make those today/tomorrow? 17:51:15 and start signing nowish 17:51:16 nirik: That is one thing we need before mass branching 17:51:21 nirik: +1 17:52:14 Oh, I forgot about mass building modules 17:52:18 you want to make the key? (we should also send it to msuchy to add to mock) 17:52:44 I can add it to autosign (except I may need puiterwijk to do initial setup) 17:52:48 #info Finally I started running mass rebuild on modules but it failed due to some missing permissions on what the token can do 17:52:59 #info Patrick is working on fixing it 17:53:01 nirik: for what? What do you need me to do? 17:53:19 nirik: Sure, I can create the key 17:53:21 fedora-31 key added to autosign... it has to be bound? or can I do that with the info you provided the other day? 17:53:37 Oh, right. 17:53:45 I think you can do that with what I provided, yes. 17:54:05 can give it a go and yell for help if I get stuck 17:54:16 Sure 17:54:43 #info mboddu will create the key and nirik/puiterwijk will work on adding fedora-31 key to autosign 17:54:51 hum, so how can we ask it to sign... we need tags created first 17:55:34 nirik: No, we sign f30 tag with f31 key as well and when branched, they will all be signed with f31 key 17:55:37 if I add another f30 to f30 section with the f31 key will it work right? 17:55:41 At least thats what I thought we have been doing 17:55:55 yes, but I am talking about robosign config. 17:56:25 nirik: I thought you can add two keys within f30 section 17:56:41 Thats what I remember seeing, but I might be wrong 17:57:24 well, if that works it will help for new builds, but it won't help for existing ones. 17:58:56 nirik: no, two keys for the same source tag won't work. So what we did before was one for the pending tags, and the other just in the destination as best effort 17:59:40 that seems non ideal. ;( 18:01:29 not sure what else to do tho... you don't want sigul_sign_unsigned to be run anymore. ;) 18:01:34 nirik: I thought you were using sigulsign_unsigned.py to sign the existing builds 18:01:53 Yeah, that is true :) 18:01:55 it would be cool if robosign had a 'sign everything in this existing tag, don't worry about fedmsgs' 18:03:10 We have past the meeting time, can we take this to a regular channel? 18:04:04 yeah, move on. 18:04:26 nirik: depending on when it is needed, and how much background knowledge is needed, maybe I could take a look at adding that option as an entry into releng stuff? 18:04:26 Anybody has any other quick updates? 18:04:51 relrod: sure, if you like... 18:04:57 Thanks relrod 18:05:23 I'll likely need some handholding for it at first thoguh 18:05:33 *though 18:06:07 relrod: Understandable :) 18:06:16 Anyway, thanks for joining everyone 18:06:29 Lets take it to #fedora-releng 18:06:34 I suppose I could also stop the hub and run a loop... but that will stop regular stuff... might be ok on weekend nights tho 18:07:06 nirik: Not a big fan of it, but if its the only thing we can do... 18:07:17 #endmeeting