18:00:21 #startmeeting FESCO (2015-11-25) 18:00:21 #meetingname fesco 18:00:21 Meeting started Wed Nov 25 18:00:21 2015 UTC. The chair is thozza. Information about MeetBot at http://wiki.debian.org/MeetBot. 18:00:21 Useful Commands: #action #agreed #halp #info #idea #link #topic. 18:00:21 The meeting name has been set to 'fesco_(2015-11-25)' 18:00:21 The meeting name has been set to 'fesco' 18:00:21 #chair ajax dgilmore hguemar jwb nirik paragan rishi thozza sgallagh 18:00:21 #topic init process 18:00:21 Current chairs: ajax dgilmore hguemar jwb nirik paragan rishi sgallagh thozza 18:00:33 morning 18:00:39 hi all :) 18:00:49 Hi 18:00:59 o/ 18:01:44 .hello rishi 18:01:45 rishi`: rishi 'Debarshi Ray' 18:01:56 .hello hguemar 18:01:57 number80: hguemar 'Haïkel Guémar' 18:02:21 that's 5 of us.... I'll give the rest a minute and start 18:02:32 ok 18:03:40 #topic #1500 Deactivate accounts that infra could not contact for 7 days. 18:03:40 .fesco 1500 18:03:42 thozza: #1500 (Deactivate accounts that infra could not contact for 7 days.) – FESCo - https://fedorahosted.org/fesco/ticket/1500 18:04:19 nirik: so my question is, if it would make sense not to run the script every hour? 18:04:37 every hour is too often IMHO - for the emails 18:04:56 sure, but then people will complain that they don't have the privs they should have quickly enough. 18:05:02 yes every hour looks too ofter 18:05:40 I'm not expert on spam filters, but I'm afraid that after 2nd or 3rd email, it would fall info SPAM 18:05:40 I'm not sure it's as important as it once was. 18:06:02 personally I don't know spam filters that do that, although it's not implausable. 18:06:36 it used to be people needed the privs to set fedora-cvs on their package review, since they no longer need that I guess we could move it to once a day or something. 18:08:30 Proposal: Request from ticket #1500 is approved, however please consider longer period than 1 hour between the emails. 18:08:52 +1 18:09:01 +1 18:09:04 sure, like I said we can move it up. +1 18:09:19 I think jwb's vote can be counted for this as well 18:09:27 I'm +1 for the record 18:09:44 +1 18:10:13 #agreed Request from ticket #1500 is approved, however please consider longer period than 1 hour between the emails. (+6, 0, -0) 18:10:25 #topic #1501 F24 System Wide Change: Systemd package split 18:10:25 .fesco 1501 18:10:26 thozza: #1501 (F24 System Wide Change: Systemd package split) – FESCo - https://fedorahosted.org/fesco/ticket/1501 18:10:58 +1 18:11:01 +1 18:11:02 I'm ok with the change. Does anyone has any questions/objections? 18:11:09 +1 for the record 18:11:19 * zbyszek is here, just in case 18:11:28 This one was discussed on the devel list and systemd list so it's fine 18:11:32 zbyszek++ 18:11:32 number80: Karma for zbyszek changed to 1 (for the f23 release cycle): https://badges.fedoraproject.org/tags/cookie/any 18:11:39 +1 from jwb in the ticket 18:11:42 I guess I am +1 18:12:09 Sorry, I'm here now. 18:12:22 +1 18:12:27 sgallagh: np, we are discussing the .fesco 1501 18:12:36 https://fedorahosted.org/fesco/ticket/1501 18:12:48 Right, I have no problems with this. 18:12:57 +1 18:13:15 * thozza counting 18:13:39 7 18:13:39 #agreed F24 System Wide Change: Systemd package split is approved (+7, 0, -0) 18:13:43 right :) 18:13:59 #topic #1502 F24 System Wide Change: Systemd file triggers 18:13:59 .fesco 1502 18:14:00 thozza: #1502 (F24 System Wide Change: Systemd file triggers) – FESCo - https://fedorahosted.org/fesco/ticket/1502 18:14:54 sure, +1 triggers are nice. 18:15:00 I haven't followed this discussion too closely 18:15:01 zbyszek: I saw sgallagh's comment on the devel list about synchronization with other changes that need the mass rebuild. I think it would be good to use that opportunity, what do you think? 18:15:24 zbyszek: I assume you're working with FPC to help them build guidelines for triggers? 18:15:28 because from what I saw you don't plan to do one, just let the packages be rebuilt when needed 18:15:44 thozza: it's more or less implemented already, so yeah, any rebuild will be good enough. 18:15:54 zbyszek: great 18:16:04 +1 from me 18:16:25 +1 from jwb in the ticket 18:16:26 +1 18:16:38 +1 18:17:10 +1 18:18:07 +1 18:18:31 #agreed F24 System Wide Change: Systemd file triggers is approved (+7, 0, -0) 18:18:47 #topic #1503 F24 System Wide Change: GHC 7.10 18:18:48 .fesco 1503 18:18:49 thozza: #1503 (F24 System Wide Change: GHC 7.10) – FESCo - https://fedorahosted.org/fesco/ticket/1503 18:19:01 +1 from me 18:19:08 +1 from jwb in the ticket 18:19:21 +1 18:19:25 +1 18:19:28 +1 18:19:45 +1 rubber stamp 18:20:30 rishi`: ? 18:20:53 * rishi` reads 18:20:57 +1 18:21:15 #agreed F24 System Wide Change: GHC 7.10 is approved (+7, 0, -0) 18:21:28 #topic Next week's chair 18:21:33 that was fast :) 18:22:09 I can chair next week 18:22:17 paragan: thanks! 18:22:28 thanks guys :) 18:22:33 Thanks thozza ! 18:22:36 #info paragan to chair next week 18:22:48 #topic Open Floor 18:22:55 There was no plan for mass-rebuild during F24 cycle. However reading through the Changes, it looks like I need to plan one. 18:23:08 ... just a note 18:23:12 it just depends on if one is needed, yeah 18:24:54 If there is not anything else, I'll end the meeting in 2 minutes 18:25:02 One more note: Elections - we have new nominees to FESCo: https://fedoraproject.org/w/index.php?title=Development/SteeringCommittee/Nominations 18:25:05 I have something 18:25:14 sgallagh: go on 18:25:28 This is somewhat directed towards zbyszek 18:25:48 I was just made aware of https://bugzilla.redhat.com/show_bug.cgi?id=1284325 18:26:15 sgallagh: yeah? 18:26:19 Which also implies that the systemd package unilaterally added a %post script in Rawhide (and F23?) to add the nss_mymachines to /etc/nsswitch.conf 18:26:37 This is completely unacceptable behavior without first coming to FESCo. 18:26:53 (Via a Change Proposal) 18:27:17 This bypassed the glibc people, the identity management people, etc. 18:28:16 What I'm hearing from those groups is that this results in unpredictable and broken user/group lookups, particularly when nscd is in play. 18:28:37 sgallagh: Yes, this wasn't the right way to do it. I hope to clarify the situation / resolve the bugs / fix things as appropriate. 18:29:03 zbyszek: Until the bugs are addressed, I think you need to push out a systemd update that reverts the nsswitch.conf immediately 18:29:52 sgallagh: that seems reasonable 18:30:17 zbyszek: Also, such changes need to coordinate with authconfig as well, since things like ipa-client-install, realmd, etc. will use that to make changes to nsswitch.conf 18:30:23 And would overwrite any changes you might make 18:30:46 I'm not sure if we need to vote on this. I guess that zbyszek can do it without explicit request from FESCo, right? 18:31:03 but we can if you sgallagh want to ;) 18:31:12 thozza: If zbyszek is willing to make the change, no vote is needed. 18:31:15 Removing the %post script is reasoanble. Removing changes from installed systems can be tricky... I didn't have time today to look at the nscd bug yet. 18:33:08 sgallagh: do you insist on changing the nsswitch.conf also on existing installations? 18:33:24 So yeah, I'll remove the %post script. I'd prefer to discuss other changes in the bug. 18:34:34 thozza: not at this time, though that may change 18:34:52 sgallagh: so you are OK with such outcome, right? 18:34:56 There is some ongoing discussion as to whether there may be a security issue involved. 18:35:48 #info zbyszek will remove the %post script from systemd package that modifies the nsswitch.conf 18:36:08 anything else? 18:36:13 Just a sec 18:36:18 sure 18:36:48 simo, one of the IDM guys, wants to chime in 18:36:57 I just sent him the backscroll 18:37:24 np 18:37:34 simo: the floor is your :) 18:38:21 I would remove it but it forcibly if it were f23 18:38:59 on rawhide .. I mean if you remove it then you may remove it also for someone that put it there intentionally 18:39:44 although given the problems this module has for user/group perhaps systemd should retire it for user/group purposes sompletely hence just always remove it if there on poasswd/grpup lines 18:39:46 zbyszek: What is the purpose of nss_mymachines when used with users and groups, exactly? 18:39:55 and propose a dedicated module 18:40:12 my_machines doesn't exacly make a lot of sense for an identity module as a name ... 18:40:34 To resolve names like vu-- for user namespace containers. 18:41:17 I do not know of any standard that uses names like that, sounds like some more baking should be done before polluting the user/group namespaces 18:41:24 simo: yes, removing the user/group part to a separate module might be the best approach. 18:42:09 This part is not in F23, only in rawhide. 18:42:31 zbyszek: Was the hosts: line handled by glibc or systemd in F23? 18:42:37 That, at least, really should be glibc 18:43:16 (and, again, authconfig) 18:43:42 that is something that may also warrant discussion if we start having a local resolver by default 18:43:49 sgallagh: What do you mean by "handled"? 'mymachines' was added to the end of hosts: line in F23 by systemd %post. 18:43:53 because you could simply have a zone in the resolver and add names there 18:44:27 but that's an entirely different discussion, and should be deferred until we do have a resolver by default 18:45:06 zbyszek: That's what I meant. That *should* just be in the default nsswitch.conf and understood by authconfig 18:45:32 But the user/group stuff definitely needs a rethink, so please remove it with prejudice. 18:45:44 And let people know they have to add it back manually if they are testing it 18:46:20 simo: just a note that tomorrow we will have a discussion with GNOME and NM devels about the default resolver and plan to submit the change proposal to wrangler this week or early next week ;) 18:46:36 I'm fine with removing it temporarily, but in the long run I want to discuss this this upstream. 18:47:14 zbyszek: Please do. This isn't meant to be a permanent answer 18:49:13 OK, so are we agreed here? 18:49:40 As far as having %post remove my_machines from passwd and group? 18:49:54 it sounds so... sgallagh you may want to state #info on the rest of what you agreed on 18:50:10 thozza: tomorrow is thanksgiving, not a great day if you want participation :) 18:51:32 simo: given the 8PM local time for me... sounds like a great combination :) 18:52:19 zbyszek: can you please confirm the assumption that you are in agreement with sgallagh? :) 18:52:47 #action zbyszek to modify systemd %post to remove my_machines from the passwd: and group: lines in nsswitch.conf while the interaction is sorted out between glibc, IDM and systemd upstreams. 18:53:26 good.... so unless there is anything else to discuss, I'll close the meeting in 2 minutes 18:53:42 Yes, I'm ok with '#action zbyszek'. 18:53:49 zbyszek: Thanks 18:56:03 #endmeeting