15:04:33 <gagehugo> #startmeeting security
15:04:33 <opendevmeet> Meeting started Thu Sep  2 15:04:33 2021 UTC and is due to finish in 60 minutes.  The chair is gagehugo. Information about MeetBot at http://wiki.debian.org/MeetBot.
15:04:33 <opendevmeet> Useful Commands: #action #agreed #help #info #idea #link #topic #startvote.
15:04:33 <opendevmeet> The meeting name has been set to 'security'
15:04:37 <fungi> ohai
15:04:47 <gagehugo> apologies for the late start
15:04:51 <gagehugo> #link https://etherpad.opendev.org/p/security-agenda agenda
15:04:56 <fungi> no apology needed
15:07:10 <gagehugo> Nothing on the agenda so
15:07:14 <gagehugo> #topic open discussion
15:08:10 <fungi> we published ossa-2021-005 earlier this week
15:08:35 <fungi> the patches met with some testing problems once pushed to public review
15:09:21 <fungi> #link https://review.opendev.org/806746 has merged to the master branch of neutron now
15:09:36 <fungi> thankfully it did not need any alterations, just some rechecking
15:09:56 <fungi> so the patches we sent everyone under embargo should still be what we ended up merging in master, at least
15:10:08 <gagehugo> cool
15:10:45 <fungi> the stable/wallaby change also just merged moments ago
15:11:31 <fungi> others backports are passing in check and have +2 reviews but no approvals yet
15:12:14 <fungi> also after the publication of the ossa, backports got added in review for em branches as far back as stable/queens and those are passing check now too
15:12:50 <fungi> in other news, ossa-2021-002 is going to need an update (errata publication), since the first fix for it was incomplete
15:12:57 <gagehugo> ok
15:13:12 <fungi> we're waiting on the stable/ussuri backport of the second fix to merge, i think, and then we'll be set to publish that
15:13:20 * fungi checks in on it real quick
15:15:15 <gagehugo> sure
15:15:18 <fungi> #link https://review.opendev.org/803094 stable/ussuri errata for ossa-2021-002
15:15:26 <fungi> looks like it's not passing in check yet
15:15:51 <fungi> we may actually want to get a stable/train backport of the second fix too before we do the errata, since the original advisory included a patch for it as well
15:17:48 <gagehugo> ok
15:17:53 <gagehugo> yeah that makes sense
15:18:56 <gagehugo> Also I made an etherpad for the PTG
15:18:59 <gagehugo> #link https://etherpad.opendev.org/p/security-sig-ptg-yoga
15:19:17 <fungi> thanks!
15:25:40 <gagehugo> fungi: Anything else for today? I have been a bit absent with the job move, thanks for keeping things running!
15:27:46 <fungi> no worries, and no i don't have anything new just yet, but we're overdue for another unresolved public reports reminder to the ml, i think
15:32:18 <gagehugo> ok cool
15:32:36 <gagehugo> thanks fungi! Have a good rest of the week
15:32:39 <gagehugo> #endmeeting