<@q5sys:matrix.org>
15:00:27
!startmeeting
<@q5sys:matrix.org>
15:00:29
!meetingname security-sig
<@meetbot:fedora.im>
15:00:31
Meeting started at 2026-03-26 15:00:27 UTC
<@meetbot:fedora.im>
15:00:31
The Meeting name is 'Fedora Meeting 3'
<@q5sys:matrix.org>
15:00:32
!link Issue Location : https://forge.fedoraproject.org/security/tickets
<@meetbot:fedora.im>
15:00:32
The Meeting Name is now security-sig
<@q5sys:matrix.org>
15:00:38
!link Discourse security tagged topics :https://discussion.fedoraproject.org/tag/security
<@q5sys:matrix.org>
15:00:43
!topic Open floor to discuss anything security related. (2026-03-26)
<@py0xc3:fedora.im>
15:00:43
!hi
<@zodbot:fedora.im>
15:00:44
Christopher Klooz (py0xc3) - he / him / his
<@q5sys:matrix.org>
15:00:47
!info Next meeting will be Apr 2nd.
<@q5sys:matrix.org>
15:01:07
There are 3 open tickets in the forge: https://forge.fedoraproject.org/security/tickets/issues?q=&type=all&state=open&labels=4216&milestone=0&assignee=0&poster=0
<@q5sys:matrix.org>
15:01:24
Support, collaborate or integrate "Fedora-downstream-hardening" project under the umbrella of Security SIG #1
<@q5sys:matrix.org>
15:01:24
if you have any input, please comment there.
<@q5sys:matrix.org>
15:01:24
<@q5sys:matrix.org>
15:01:24
Import Fedora Security Lab Repos to Forge #3
<@q5sys:matrix.org>
15:01:24
Migrate Documentation to docs.fp.o #2
<@py0xc3:fedora.im>
15:01:39
Two marked for meeting, but I think Daniel is not here. So not sure if there is anything to discuss about his one.
<@py0xc3:fedora.im>
15:01:58
Concerning the Fedora-downstream-hardening, it comes down to the three mentioned questions
<@q5sys:matrix.org>
15:02:08
Thanks for Chris for making the tickets.
<@py0xc3:fedora.im>
15:02:16
But I guess if its just us two we might not make a final decision or so
<@decathorpe:fedora.im>
15:02:36
!hi
<@zodbot:fedora.im>
15:02:38
Fabio Valentini (decathorpe) - he / him / his
<@q5sys:matrix.org>
15:04:46
3) I have no views on license. Whatever the overall Fedora project would prefer is fine with me.
<@q5sys:matrix.org>
15:04:46
As for that ticket... speaking for myself I'd say...
<@q5sys:matrix.org>
15:04:46
1) Yes.
<@q5sys:matrix.org>
15:04:46
2) I think having all the fedora stuff in the fedora locations instead of a github repo elsewhere would be beneficial.
<@py0xc3:fedora.im>
15:08:17
To mention an example, which is also one of the origins of the project:
<@py0xc3:fedora.im>
15:08:17
If new such decisions come up that enforce such compromises, and if FESCo has to make one towards UX (or if some developers do without a change proposal for whatever reason) to serve all involved interests in a "least common denominator by default" compromise, we can adjust the tool again to adjust itself correspondingly, and all would come through the normal updates.
<@py0xc3:fedora.im>
15:08:17
<@py0xc3:fedora.im>
15:08:17
With the recent decision of yama/ptrace_scope in mind (and the original decision of 10 years ago), if a user would had installed and activated this package, the engineering / FESCo decision would not have impacted them: the package would override a decision to disable such a security function, and if they would install gdb or strace, they could rely that they would become aware that something does not work rather than disabling a security function without them knowing. At the same time, it allows the majority - as we have it now - to deploy a UX first compromise the way it is now.
<@py0xc3:fedora.im>
15:08:17
<@py0xc3:fedora.im>
15:08:37
More details in the github README
<@q5sys:matrix.org>
15:23:01
Hopefully other people will chime in.
<@q5sys:matrix.org>
15:23:32
If you have a link or something to the Engineering/FESCO decsision that might be helpful to add to the ticket for context.
<@q5sys:matrix.org>
15:23:53
I dont know what decision you're referring to, so I suspect others might not know either.
<@decathorpe:fedora.im>
15:24:12
!fesco 3569
<@zodbot:fedora.im>
15:24:12
● **Closed: Accepted** a week ago by ngompa
<@zodbot:fedora.im>
15:24:12
**fesco #3569** (https://pagure.io/fesco/issue/3569):**Change: Restrict_ptrace_by_default**
<@zodbot:fedora.im>
15:24:12
<@zodbot:fedora.im>
15:24:12
● **Opened:** a month ago by alking
<@zodbot:fedora.im>
15:24:12
● **Last Updated:** a week ago
<@zodbot:fedora.im>
15:24:12
● **Assignee:** Not Assigned
<@py0xc3:fedora.im>
15:24:30
Yeah that's the most recent of several change proposals :-)
<@py0xc3:fedora.im>
15:26:01
This is already a compromise after several failed proposals. In the end, it was accepted as it was a compromise acceptable by everyone to some extent. But given the different interests it had to serve, no one really liked it I think
<@py0xc3:fedora.im>
15:28:19
It's just an example of how this tool can be used to mitigate issues that are more organizational than technical, and how it can evolve in parallel to the "major compromise" and users rely that both directions evolve considering each other
<@q5sys:matrix.org>
15:28:40
FYI, I've got another meeting starting in a few minutes (in meatspace) so I'm going to end this at the half hour mark. But you guys can keep talking here or continue it in the Security channel.
<@q5sys:matrix.org>
15:29:00
I dont think this channel is used again until the top of the hour.
<@py0xc3:fedora.im>
15:29:23
I think when the meeting is ended it makes sense to continue in the security channel or the ticket.
<@py0xc3:fedora.im>
15:30:49
I read I have a +1 of q5sys in the meeting, so I would wait for a second +1 and if then there is no -1 or so, I might implement the ticket if that is fine.
<@py0xc3:fedora.im>
15:31:33
I read q5sys gave a +1 in the meeting, so I would wait for a second +1 and if then there is no -1 or so, I might implement the ticket if that is fine.
<@q5sys:matrix.org>
15:31:55
fine with me... if anyone objects they need to speak up.
<@py0xc3:fedora.im>
15:32:10
Sure. Then shift it to the security channel and the ticket
<@q5sys:matrix.org>
15:32:19
its just creating a repo at this point... so even if they disagree with the practical implementation... that's a different issue.
<@py0xc3:fedora.im>
15:32:27
Indeed.
<@py0xc3:fedora.im>
15:32:57
I would then also start to try to get sponsorship to get the package forward
<@q5sys:matrix.org>
15:32:58
Thanks Chris (py0xc3) and Fabio Valentini
<@py0xc3:fedora.im>
15:33:13
But nothing of that is binding for security sig
<@q5sys:matrix.org>
15:33:44
!endmeeting