13:02:48 #startmeeting CIP IRC weekly meeting 13:02:48 Meeting started Thu May 23 13:02:48 2024 UTC and is due to finish in 60 minutes. The chair is jki. Information about MeetBot at http://wiki.debian.org/MeetBot. 13:02:48 Useful Commands: #action #agreed #help #info #idea #link #topic #startvote. 13:02:48 The meeting name has been set to 'cip_irc_weekly_meeting' 13:02:55 #topic AI review 13:03:07 - prepare blog entry on SLTS kernel state and challenges [Jan] 13:03:34 down in the prio list again, was struggling (and still are) with cip-core 13:03:51 no other AIs recorded 13:03:57 5 13:03:58 4 13:04:00 3 13:04:01 2 13:04:02 1 13:04:05 #topic Kernel maintenance updates 13:04:23 I was reviewing 6.1.91. 13:04:24 i'm back from vacation, nothing substantial to report yet 13:04:25 This week reported 685 new CVEs and 8 updated CVEs. 13:04:29 I am reviewing 6.1.91 13:05:20 685 is a new record - any particular reason for that peak visible? 13:06:07 not sure.. 13:07:16 just curious, not that it would change the overall situation 13:07:21 Shal we do anything with the CVEs? 13:08:05 I went through some, and signal-to-noise is not quite usefu 13:08:11 useful. 13:08:27 well, we can only do automated stuff with them, given the amount 13:08:57 We are automatically putting them into database noone reads 13:09:13 can we filter out anything that we already got or that is not affecting older kernels? 13:09:30 to have stats of potentially open issues, at least on the CVE paper? 13:10:42 I believe we have similar information in better form already 13:11:32 cves are just git dumps. Not sure what kind of paper would be useful to generate from that. 13:11:39 pave1: what are you referring to? 13:12:26 arisut -- greg is copy-pasting git logs into cves. 13:13:02 Investigating issues where the commit introducing the bug is not documented. Perhaps we should focus on such bugs? 13:14:33 Masami -- commit introducing not known will be common. 13:14:55 well, anything that is fix in X, affecting Y and possibly not even affecting CIP is not interesting, sure 13:15:18 digging into details is likely not helpful beyond examples 13:15:23 but maybe we could filter by commit fixing not listed, because those are not spam? 13:15:25 having stats could be 13:15:52 jki -- i have some stats. 13:16:22 on very small sample 50% is simply not security related. 13:16:42 40% may be relevant in some crazy config. 13:17:05 well, config correlation is another area of interest, if automatable 13:17:05 10% could be a real issue. 13:17:32 you may have seen https://ciq.com/blog/why-a-frozen-linux-kernel-isnt-the-safest-choice-for-security/ 13:17:52 and the fact that they didn't look at the configs 13:18:21 I can take a look. I believe that's more broken than that. 13:18:22 jki: I guess we don't know _every_ config a SLTS user will be using though? Unless there are some options that can _never_ be used? 13:18:37 we have defined supported configs 13:18:44 we are not supporting random ones 13:19:20 those can be debated in details, but if we exclude drivers or complete subsystems, that are easy takes (or non-takes) 13:19:50 What happens if a new member joins and adds more configs? We would have to go back and work out which CVEs are now relevant, which we couldn't do if they weren't in our database to start with? 13:20:16 Anyway, this topic is probably worth a proper call/F2F about at some point? 13:20:34 that is a valid point, and it would at least take some impact analysis, automated 13:21:22 if we exclude CVE-0815 today, will adding CONFIG_Y bring it plus hundreds more in? 13:21:35 so far, we cannot tell that 13:21:53 and no one is able to do manual analysis 13:21:56 Well, we pretend we support any config on supported architectures. 13:22:06 nope, we surely don't 13:22:14 we never 13:22:49 CIP is not a distro kernel, and even distros have certain exclusion areas, starting with CONFIG_STAGING 13:23:06 ok, sure, staging is out. 13:25:15 and more, just look at an long-living enterprise kernel 13:25:54 do not state that CIP is generic, please, that is neither true nor what we communicated all the time 13:26:24 we may patch left and right, but only on best effort basis, if at all 13:26:52 I guess we should create a list of 'definitely out' options at some point. 13:27:18 how to maintain that? 13:27:34 it would not be a technically executable something 13:27:44 we have a whitelist, and members can expand it 13:28:00 we need to take measure to assess expansion requests better 13:30:15 likely a topic for next TSC as well... 13:30:29 anything else about this or beyond on maintenance? 13:31:10 5 13:31:12 4 13:31:13 3 13:31:14 2 13:31:16 1 13:31:19 #topic Kernel release status 13:31:32 I saw 4.19-rt is out 13:31:40 6.1 is scheduled? 13:31:43 I am working for 6.1.y-cip 13:32:02 perfect 13:32:07 anything else? 13:32:26 5 13:32:28 4 13:32:29 3 13:32:31 2 13:32:32 1 13:32:34 #topic Kernel testing 13:33:02 We had some gitlab runner token issues, resolved now. Sorry for the interruption Pavel 13:33:28 no news from me 13:33:34 I've been looking into some cip core testing bits & bobs. 13:33:39 That's about it 13:33:57 no problem, it works now 13:34:26 Siemens lab bring-back is delayed due to connectivity issues 13:34:34 I've been trying to push internally for more time/resources to work on CIP testing - the project is well behind where it should be. We need to get a lot more in place before more LTS kernels go EOL and everyone jumps to SLTS... 13:34:39 Thanks jki 13:34:41 discussed with Quirin today, we have a resolution strategy now 13:35:12 patersonc: thanks for bringing this up! so true 13:37:27 I guess there's nothing else for testing this week... 13:38:27 ok, then moving on... 13:38:33 5 13:38:35 4 13:38:37 3 13:38:39 2 13:38:41 1 13:38:44 #topic AOB 13:39:22 iwamatsu__: there are quite a few open MRs on the config repo - already had time to check? 13:39:44 specifically the x86 generic one would help to also move forward with isar-cip-core 13:40:15 I am reviewing now, so I think I can merge it tomorrow. 13:41:03 great, TIA! 13:41:23 other topics? 13:41:45 just checking: next week is public holiday again for me 13:42:00 I may not be available 13:42:58 I have something just before.... 13:43:31 ...but there's good chance it ends in time. 13:43:42 I can takeover. 13:43:44 I won't be here next Thursday, apologies 13:44:18 ok, if the round becomes too small, make it short or skip directly 13:44:38 but thanks for your offer, iwamatsu-san 13:44:52 :) 13:45:47 So cancel or keep? 13:48:08 If there are few participants, I think it is okay to cancel. 13:48:16 looks like 13:48:27 ok for me too 13:48:35 i'm ok either way 13:48:39 use email for anything urgent to discuss 13:48:46 yeah me too 13:48:50 ok 13:49:56 Ok, so next one is cancelled. See you in 14 days. 13:50:22 good 13:50:23 see you pave1 13:50:30 then closing for today... 13:50:40 5 13:50:42 4 13:50:43 3 13:50:44 2 13:50:46 1 13:50:48 #endmeeting