09:00:01 #startmeeting CIP IRC weekly meeting 09:00:01 Meeting started Thu Aug 6 09:00:01 2020 UTC and is due to finish in 60 minutes. The chair is masashi910. Information about MeetBot at http://wiki.debian.org/MeetBot. 09:00:01 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 09:00:01 The meeting name has been set to 'cip_irc_weekly_meeting' 09:00:09 masashi910: Error: Can't start another meeting, one is in progress. Use #endmeeting first. 09:00:23 #topic rollcall 09:00:27 hi 09:00:29 please say hi if you're around 09:00:30 hi 09:00:33 hi 09:00:33 hi 09:00:34 hi 09:00:49 #topic AI review 09:00:55 hi 09:00:58 1. Combine root filesystem with kselftest binary - iwamatsu 09:01:11 masashi910: no update 09:01:25 iwamatsu: Noted. 09:01:32 2. Post LTP results to KernelCI - patersonc 09:01:53 patersonc: are you around? 09:02:13 Let's revisit if he joins. 09:02:20 Hi sorry 09:02:24 No updated :) 09:02:32 patersonc: Hi 09:02:42 patersonc: Noted. 09:02:57 Then, let's move to next. 09:03:03 #topic Kernel maintenance updates 09:03:21 Fix for CVE-2020-14331 from last week is in linux-next, but not in Linus's tree. 09:03:28 I have reviewed patches for 4.19.136 and 137. 09:03:39 New issues this week: CVE-2020-0255 (fixed), CVE-2020-16166 (fixed) 09:03:48 I reviewed 4.4.233-rc. 09:05:06 wens: So, this week, there are no pending CVEs. Is it correct? 09:05:18 correct. 09:05:31 wens: Thanks for your confirmation. 09:05:52 for an old CVE, Debian reports that the fix was not completely backported to 4.19 09:06:10 CVE-2019-3874 09:06:47 this is DoS due to SCTP usage, classified as minor issue. 09:07:31 that's all 09:08:50 wens: according to cip-kernel-sec, CVE-2019-3874 has two rows. One is ignored and one is fixed. 09:09:20 Do you mean the fixed one? 9a84bb13816f 09:09:48 https://security-tracker.debian.org/tracker/CVE-2019-3874 09:10:21 looks like they are ignoring the issue as well. 09:10:40 Not two rows, but one row says "fixed by 9a84bb13816f" 09:10:57 Anyway, thanks for your report. 09:11:17 wens, pavel1, iwamatsu: Thanks for your works. 09:11:18 4.19 is missing 9dde27de3e5efa0d032f3c891a0ca833a0d31911 , the other half of the fix 09:11:50 wens: I see. Thanks for your explanation. 09:12:21 Any other topics? 09:12:26 nope 09:12:46 Ok, then let's move on. 09:12:59 #topic Kernel testing 09:13:05 patersonc: the floor is yours. 09:14:16 patersonc: are you there? 09:14:49 hi 09:14:50 sorry 09:14:53 Let's revisit when he comes back. 09:15:00 I've set up a specific lava master for the security working group to test/investigate multi-node support. Login details have been shared with Venkata. 09:15:00 I've conencted a lava lab running at home to this master, with 2x qemu and 1x g2m board. 09:15:16 I'll try and find time to activly try multi-node as well 09:15:23 I think that's it from me this week 09:16:17 patersonc: Does KernelCI run LTP with CIP kernel now, or still in progress? 09:16:50 I've submitted for them to boot test CIP Kernels 09:17:07 But KCI doesn't support LTP yet 09:17:28 patersonc: I see. Thanks for your updates. 09:17:45 any other topics? 09:17:54 3 09:17:59 2 09:18:03 1 09:18:05 #topic Software update 09:18:13 Quote from Suzuki-san "SW Updates WG don't have any updates this week." 09:18:21 Let's move on. 09:18:30 #topic CIP Security 09:19:12 no major update this week, and we are trying to draft documents for the assessment w/ Exida. 09:19:13 Yoshida-san or Dinesh-san, any updates? 09:19:26 That's is from me this week. Thanks. 09:19:35 OK plz wait 09:19:46 Investigation of IEC-62443-4-1 is completed 09:19:58 Investigation report of IEC-62443-4-1 is shared for exida review 09:20:07 Debugging of multi-node LAVA test failure is in progress 09:20:20 Verification of security packages in CIP tiny profile is in progress 09:20:26 Next IEC-62443-4-x gap assessment meeting with exida is planned on 24/Aug 09:20:35 These are some minor updates this week 09:20:52 yoshidak[m], dinesh[m]: Thanks for your updates. 09:21:00 Any queries? 09:21:13 3 09:21:18 2 09:21:21 1 09:21:24 #topic AOB 09:21:32 I have one query to IRC meeting members. 09:21:44 Next week is so called OBON in Japan and most Japanese people will be off. 09:21:51 Can we skip next IRC meeting? Any objections? 09:22:02 No objection from me 09:22:03 no objection 09:22:04 I'd like to talk with Patersonc after the meeting. 09:22:15 No objections. 09:22:26 No objection 09:22:40 Thanks. Then, the next meeting will be skipped. 09:22:57 Any other topics? 09:23:08 3 09:23:13 2 09:23:14 1 09:23:17 #endmeeting