21:00:48 #startmeeting EPEL (2020-05-15) 21:00:48 Meeting started Fri May 15 21:00:48 2020 UTC. 21:00:48 This meeting is logged and archived in a public location. 21:00:48 The chair is tdawson. Information about MeetBot at http://wiki.debian.org/MeetBot. 21:00:48 Useful Commands: #action #agreed #halp #info #idea #link #topic. 21:00:48 The meeting name has been set to 'epel_(2020-05-15)' 21:00:49 #meetingname epel 21:00:49 The meeting name has been set to 'epel' 21:00:51 #chair nirik tdawson bstinson Evolution pgreco carlwgeorge 21:00:51 Current chairs: Evolution bstinson carlwgeorge nirik pgreco tdawson 21:00:52 #topic aloha 21:00:54 #info Meeting is run from https://board.net/p/epel 21:01:16 * nirik waves 21:01:28 Hi nirik 21:01:47 hey all 21:01:54 Hi bstinson 21:01:56 hi hi, sorry I'm a bit late :) 21:02:03 howdy y'all 21:02:22 Hi pgreco and carlwgeorge 21:03:17 * tdawson waits two more minutes for anyone else to show up. 21:05:22 #topic Old Business 21:05:23 #info What to do with epl8-playground, postponed until next week - 2020-05-22 21:05:37 I guess the title says it all 21:05:51 #info Retire zstd from epel8/epel8-playground - Done 21:05:53 .ticket 9442 21:06:01 tdawson: An error has occurred and has been logged. Please contact this bot's administrator for more information. 21:06:14 https://pagure.io/releng/issue/9442 21:06:27 I wanted to say thank you to those who did this. 21:06:37 I also wondered if the other packages were removed as well. 21:07:48 I think there were 6 packages that were now in RHEL8.2 21:08:06 probibly need to check and file bugz on it. ;( 21:08:17 But, I believe zstd was the only one where the EPEL version was higher than the RHEL version. 21:10:19 Looks like, as of last week, it was dwarves lmdb perl-Convert-ASN1 perl-LDAP python-psutil python3-pyxattr pyxattr whois zstd 21:10:31 python-psutil was also higher than the rhel version 21:11:36 Yep 21:11:52 And pyxattr was the exact same version. 21:12:03 is here now 21:12:07 I guess zstd got all the attention, because everyone has to have it. 21:12:09 Hi smooge 21:12:09 it might be worth trying to see where the internal process is not right around this. At one point when adding packages they were supposed to check for epel ones, etc 21:12:48 I believe for this list, they were in EPEL to begin with, and then RHEL 8.2 the packages were added. 21:13:01 pyxattr was newer too, 0.7.1 in epel before being retired, vs 0.5.3 in rhel 8.2 21:14:08 psutil was actually added in 8.1 and no one noticed 21:14:10 Ohh ... that's right. But it had a different name in EPEL, it's source was python3-pyxattr. 21:14:23 yeah, but it seems very haphazard if bugs are filed or versions / upgrade path is checked 21:15:22 lmdb was also an 8.1 addition 21:16:04 So, looks like we've missed this for a little bit. 21:17:41 huh, I don't see the rhel lbdb 21:17:52 only lmdb-libs is shipped 21:18:44 of course. 21:18:47 * nirik sighs 21:19:05 fun fact, pyxattr should have never been shipped, it's been in rhel8 from the beginning 21:20:19 huh, whats the source package there? 21:20:33 But python3-pyxattr wasn't there at the begining 21:20:57 there's no epel8 branch for pyxattr 21:21:18 EPEL8 branch is python3-pyxattr 21:21:24 rhel: source pyxattr, python3-pyxattr subpackage 21:21:33 epel: both python3-pyxattr 21:23:02 yeah, that one is already blocked in epel8 21:23:45 it went down here https://bugzilla.redhat.com/show_bug.cgi?id=1818713 21:26:27 OK, so that's two that were properly retired. 21:26:51 Anyone want to take the rest of the list? 21:27:56 OK, I'll take the list and make sure bugs and issues are filed for the retirement of them. 21:28:45 OK, I'll take the list and make sure bugs and issues are filed for the retirement of them. 21:29:24 #assign tdawson will follow up on the duplicate packages in EPEL8 / RHEL8 21:29:36 Moving on. 21:29:44 #info EPEL-6 is End of Life in 2020-11. It will be moved to archives in 2020-12 21:29:45 #info THIS IS NOT A DRILL. 21:29:51 #topic EPEL-7 21:29:58 i already filed bugs for the rest of them last week 21:30:29 #info carlwgeorge already filed bugs for the duplicate packages. 21:30:33 carlwgeorge ++ 21:30:35 cool. thanks carlwgeorge 21:30:58 I'd give you a cookie if I could. :) 21:31:14 it's the thought that counts i guess? :D 21:31:37 Any EPEL7 issues or things to discuss? 21:31:42 i've got an epel7 thing. oniguruma has lots of outstanding cves, and i've proposed an incompatible upgrade on the mailing list. 21:31:48 https://bugzilla.redhat.com/show_bug.cgi?id=1777660 21:33:04 sounds good. 21:33:20 not much of a choice, imo 21:33:48 I mean, we don't want open cves 21:34:08 there's just over 1000 cves in new or assigned on Fedora EPEL components. 21:34:18 1018 21:34:20 Youch 21:34:21 ssssh 21:34:34 you aren't allowed to break a board member so quickly 21:34:56 selfishly i actually want that to ship php74 in ius, but the cves also matter of course 21:35:02 he needs to gaze into the horror of Bugzilla and have it stare back into him 21:35:28 * tdawson wakes up in a daze ... 21:35:40 huhh ... what ... sure ... carlwgeorge ... go for it. 21:36:18 carlwgeorge: just make sure it builds on armhfp ;) 21:36:19 according to the process page, after a week on the list we can vote on it here, so just a heads up for now 21:36:33 perhaps we could try and poke the top ones when we have time. (whenever that is) 21:36:43 41 podofo 21:36:43 37 xpdf 21:36:43 33 asterisk 21:36:43 27 matio 21:36:43 26 nodejs 21:37:12 * smooge saw jamielinux orphaned a lot of nodejs so I think that is going to get cleaned out 21:37:22 oh wait, thats not right 21:37:42 carlwgeorge: OK, I've put it on next weeks agenda. 21:37:50 thats total bugs. 21:38:08 CVES: 37 xpdf 26 nodejs 26 matio 26 LibRaw 25 hdf5 21:39:13 nirik: Do we know of the breakdown by with EPEL? Or is that all of them together? 21:39:15 nirik, is that in general? or epel* versions? 21:39:23 thats all. 21:40:26 all packages, all active epel versions 21:40:58 i'm curious, where are you pulling that from? 21:41:10 just playing with bugzilla command line... :) 21:41:21 bugzilla query -p "Fedora EPEL" -s NEW,ASSIGNED -t CVE --outputformat "%{component}" | sort | uniq -c | sort -nr | less 21:42:06 hehe, the sequence " sort | uniq -c | sort -nr" is too damn useful... :) 21:42:06 neat 21:43:21 I guess that could be sort -unr ? anyhow... 21:43:38 fine to move on, my brain is already on the weekend 21:43:49 OK 21:43:55 one thing to note is that some bugs have more than one cve on them, so that's a bug count, not cve count 21:43:55 #topic EPEL-8 21:44:34 Any new EPEL8 things? 21:44:39 true. 21:45:39 rhel 8 ships non-modular haproxy 1.8, and the maintainer declined to ship a 2.0 module. i'm considering if i want to wade into those waters. 21:45:51 as an epel8 module that is 21:46:13 Well, we've opened the gate for that. 21:46:30 I know someone else wants to do a module for cmake 21:46:43 at a minimum i'll need to be a co-maintainer on the fedora package, correct? 21:47:04 yep. 21:47:26 you could also do a non modular haproxy2 or something (but that could be tricky in other ways) 21:47:46 that may be a fight, i haven't been able to get prs merged for that 21:47:59 .whoowns xpdf 21:48:00 smooge: owner: spot 21:48:24 yeah, definitely not interested in messing with a parallel package, i do enough of that elsewhere 21:48:37 fair 21:49:08 Anything else for EPEL8? 21:49:42 #topic General Issues / Open Floor 21:51:01 Anything before nirik completely succombs to the weekend? 21:51:34 b-rrrr--aaaaaa--innnssss 21:51:50 mmm, not here, I need my weekend now! 21:52:00 OK, thanks everyone for coming. 21:52:06 We'll talk to you next week. 21:52:16 thanks tdawson 21:52:19 #endmeeting