<@decathorpe:fedora.im>
17:00:53
!startmeeting FESCo (2026-06-23)
<@meetbot:fedora.im>
17:00:54
Meeting started at 2026-06-23 17:00:53 UTC
<@meetbot:fedora.im>
17:00:54
The Meeting name is 'FESCo (2026-06-23)'
<@decathorpe:fedora.im>
17:00:58
!meetingname fesco
<@meetbot:fedora.im>
17:00:59
The Meeting Name is now fesco
<@decathorpe:fedora.im>
17:01:05
!group members fesco
<@zodbot:fedora.im>
17:01:07
Members of fesco: Fabio Valentini, Máirín Duffy, gotmax23 (@gotmax:matrix.org, @gotmax23:fedora.im), Jef Spaleta, Kevin Fenzi, ngompa (@conan_kudo:matrix.org, @ngompa:fedora.im, @pharaoh_atem:opensuse.org, @ngompa:kde.org, @ngompa:almalinux.im), salimma (@michel-slm:matrix.org, @salimma:fedora.im), Timothée Ravier, Simon de Vlieger, Zbigniew Jędrzejewski-Szmek
<@siosm:fedora.im>
17:01:09
!hi
<@decathorpe:fedora.im>
17:01:10
!topic Init Process
<@zodbot:fedora.im>
17:01:10
Timothée Ravier: Timothée Ravier (siosm) - he / him / his
<@nirik:matrix.scrye.com>
17:01:11
morning
<@zbyszek:fedora.im>
17:01:14
!hi
<@supakeen:fedora.im>
17:01:15
!hi
<@zodbot:fedora.im>
17:01:15
zbyszek: Zbigniew Jędrzejewski-Szmek (zbyszek)
<@zodbot:fedora.im>
17:01:16
Simon de Vlieger: Simon de Vlieger (supakeen) - he / him / his
<@zbyszek:fedora.im>
17:01:24
Simon de Vlieger: welcome
<@supakeen:fedora.im>
17:01:33
Thanks zbyszek!
<@decathorpe:fedora.im>
17:01:39
hey, no need to rush to say "!hi" before I finish pasting the boilerplate 😆
<@salimma:fedora.im>
17:01:40
!hi
<@zodbot:fedora.im>
17:01:41
Michel Lind ☘ UTC+1 📟: Michel Lind (salimma) - he / him / his
<@decathorpe:fedora.im>
17:01:51
!hi
<@zodbot:fedora.im>
17:01:52
Fabio Valentini 🌈: Fabio Valentini (decathorpe) - he / him / his
<@gotmax23:fedora.im>
17:01:53
!hi
<@zodbot:fedora.im>
17:01:54
gotmax23: Maxwell G (gotmax23) - he / him / his or they / them / theirs
<@decathorpe:fedora.im>
17:02:09
Simon de Vlieger, gotmax23: welcome!
<@gotmax23:fedora.im>
17:03:01
7/9 is pretty good
<@siosm:fedora.im>
17:03:11
Welcome to the new members!
<@zbyszek:fedora.im>
17:03:34
Do we want to chagne the meeting time? (Please say no.)
<@gotmax23:fedora.im>
17:03:46
I don't
<@conan_kudo:matrix.org>
17:03:50
!hi
<@zodbot:fedora.im>
17:03:52
Conan Kudo 😌: Neal Gompa (ngompa) - he / him / his
<@zbyszek:fedora.im>
17:04:01
Hi gotmax23
<@nirik:matrix.scrye.com>
17:04:05
yes, welcome to all new folks and many thanks to those who served before.
<@salimma:fedora.im>
17:04:06
I would not mind it earlier but that would be less practical for US folks
<@supakeen:fedora.im>
17:04:09
Theoretically an hour later would suit me better but if it incknvencies 8 others: no
<@decathorpe:fedora.im>
17:04:17
and then there were eight! almost enough to start an adventure to throw stuff into a volcano.
<@supakeen:fedora.im>
17:04:20
Inconveniences even
<@gotmax23:fedora.im>
17:04:31
Also, there's ELN and other meetings right before this one
<@decathorpe:fedora.im>
17:04:48
!topic New Members Init
<@decathorpe:fedora.im>
17:05:23
I think all the buttons have now been pushed in all the places - Simon de Vlieger gotmax23 can you confirm?
<@supakeen:fedora.im>
17:05:59
I think so but I’m not sure if I’m missing anything I saw FAS group, I have access to the issue tracker and ML
<@decathorpe:fedora.im>
17:06:20
I hope you also got the important thing: the badge!
<@supakeen:fedora.im>
17:06:45
I did!
<@decathorpe:fedora.im>
17:06:46
I see you have. *nods*
<@gotmax23:fedora.im>
17:07:01
nirik said:
<@gotmax23:fedora.im>
17:07:01
> That said, yes, we should add some more folks to list owners and fas group sponsors. I'm fine adding @amoloney to those if thats agreeable?
<@gotmax23:fedora.im>
17:07:01
<@gotmax23:fedora.im>
17:07:07
I think that's agreeable
<@nirik:matrix.scrye.com>
17:07:09
as a side note, we may want to add some more folks to list admins and fas sponsors.
<@nirik:matrix.scrye.com>
17:07:14
yeah
<@gotmax23:fedora.im>
17:07:18
:)
<@salimma:fedora.im>
17:07:43
should we all be sponsors? or at least those who want to volunteer for it?
<@decathorpe:fedora.im>
17:07:46
sure. so ... Proposal: Add Aoife as sponsor for the fesco FAS group
<@siosm:fedora.im>
17:07:47
+1
<@salimma:fedora.im>
17:07:54
+1
<@zbyszek:fedora.im>
17:08:09
FWIW, I'm 99% that we are confused with the awarding of the badge. It's labeled as "you _were_ a member of fesco", which strongly implies it should be awareded when leaving.
<@supakeen:fedora.im>
17:08:12
+1 (did she already volunteer or are we volunteering her?)
<@decathorpe:fedora.im>
17:08:16
+1
<@zbyszek:fedora.im>
17:08:21
+1
<@zbyszek:fedora.im>
17:08:26
We are volunteering here.
<@salimma:fedora.im>
17:08:28
voluntold is a word I think
<@zbyszek:fedora.im>
17:08:35
\* her
<@nirik:matrix.scrye.com>
17:08:40
yeah, the badge is completely confusing and always has been
<@gotmax23:fedora.im>
17:08:40
+1
<@zbyszek:fedora.im>
17:09:00
Pff, we are volunteeing here. I didn't want to edit because that messes up the log.
<@salimma:fedora.im>
17:09:02
wait till someone connects the dot and decided anyone with that badge automatically gets removed from FAS
<@zbyszek:fedora.im>
17:09:08
Pff, "her". Yikes.
<@nirik:matrix.scrye.com>
17:09:29
yeah, +1.. I can do that after the meeting.
<@zbyszek:fedora.im>
17:09:35
Just ask AI how to solve the discrepancy.
<@gotmax23:fedora.im>
17:09:55
and also as a list manager?
<@nirik:matrix.scrye.com>
17:10:17
yes.
<@decathorpe:fedora.im>
17:11:22
le sigh. do we need to re-vote for that amendment?
<@nirik:matrix.scrye.com>
17:11:45
I don't think it's particularly controversial...
<@duffy:fedora.im>
17:11:58
!hi
<@zodbot:fedora.im>
17:12:00
Máirín Duffy: Máirín Duffy (duffy) - she / her / hers
<@decathorpe:fedora.im>
17:12:18
hi!
<@decathorpe:fedora.im>
17:12:35
ok then just ... spam that 👍️ reaction on nirik's message plz
<@salimma:fedora.im>
17:13:28
as long as counting is not involved
<@zbyszek:fedora.im>
17:13:47
The thumbs-up are not visible in the log. So please state that we observed 6 thumbs-up for the log.
<@siosm:fedora.im>
17:13:59
We have 6 thmbs up
<@gotmax23:fedora.im>
17:14:00
Now it's 7 thumbsup
<@duffy:fedora.im>
17:14:28
8 🙂
<@decathorpe:fedora.im>
17:14:32
!agreed The Fedora Operations Architect is added as a sponsor for the "fesco" group in FAS and as an admin of the mailing list. (with 8 👍️ and +8 votes for the initial proposal)
<@nirik:matrix.scrye.com>
17:14:32
whenever we get to it, I have a open floor item.
<@zbyszek:fedora.im>
17:14:54
I have something too.
<@decathorpe:fedora.im>
17:15:21
Does anybody have a strong objection to the current time slot for this meeting? If yes, speak now, or be forever silent.
<@decathorpe:fedora.im>
17:15:49
(/me watches clock until 1 minute passes.)
<@salimma:fedora.im>
17:16:47
I could make it work, I will just volunteer to chair less often
<@salimma:fedora.im>
17:17:10
if we move it back half an hour my stomach will be super happy but then again that means I have time to eat but will go home very late
<@decathorpe:fedora.im>
17:17:17
that doesn't sound like a strong objection :P
<@decathorpe:fedora.im>
17:17:27
!info The time slot for the weekly FESCo meeting remains at 18:00 Europe/London.
<@duffy:fedora.im>
17:17:38
it would be easier an hour later
<@duffy:fedora.im>
17:17:44
but it works ok for now
<@salimma:fedora.im>
17:17:49
if it's an hour later I will never chair :)
<@salimma:fedora.im>
17:17:55
and it will end at 10 pm for Zbyszek and Fabio
<@duffy:fedora.im>
17:17:58
er sorry an hour earlier
<@duffy:fedora.im>
17:18:04
i meant an hour earlier
<@salimma:fedora.im>
17:18:09
ah
<@duffy:fedora.im>
17:18:14
it would be easier an hour later^W earlier
<@salimma:fedora.im>
17:18:30
yeah, that would be ok with me, we'll need to get ELN to move
<@nirik:matrix.scrye.com>
17:18:51
riscv sig meeting would conflict every other week for me / this channel.
<@decathorpe:fedora.im>
17:18:54
none of these sound like strong objections so I'm going to continue ;)
<@decathorpe:fedora.im>
17:19:16
!topic Fedora Council Engineering Representative
<@decathorpe:fedora.im>
17:19:41
!info The nomination period for the next Fedora Council Engineering Representative is open until June 30.
<@gotmax23:fedora.im>
17:19:53
Have we decided what this person is actually supposed to do yet ;)?
<@decathorpe:fedora.im>
17:19:55
mostly just added that so it ends up included in the mailing list summary.
<@nirik:matrix.scrye.com>
17:20:04
where should we collect nominations? in a ticket?
<@decathorpe:fedora.im>
17:20:35
I would just comment on https://pagure.io/fesco/issue/3620
<@zbyszek:fedora.im>
17:20:42
Right. We also have the ticket open to clarify expectations for the job.
<@zbyszek:fedora.im>
17:21:10
It'd be great if we could create a short summary so that people who volunteer know what they are volunteering for.
<@decathorpe:fedora.im>
17:21:22
It's rather late for that
<@decathorpe:fedora.im>
17:21:43
and I don't particularly want to spend 2 hours of meeting time on this today
<@zbyszek:fedora.im>
17:21:43
We need to do it as *some* point.
<@gotmax23:fedora.im>
17:21:50
yeah, but it seems bad to ask people to volunteer for something with unclear expectations
<@siosm:fedora.im>
17:22:01
the wiki kind of has something about that
<@siosm:fedora.im>
17:22:10
but agree that it's a bit vagu
<@siosm:fedora.im>
17:22:12
e*
<@gotmax23:fedora.im>
17:22:13
we can discuss it async too
<@nirik:matrix.scrye.com>
17:22:23
stab at it -> "Represent the interests of fesco in council deliberations and communicate back items of interest to fesco. To serve as a communications conduit between the two bodies"
<@decathorpe:fedora.im>
17:22:28
People, could you have had that objection *before* I proposed the nomination period to start today? 😬
<@gotmax23:fedora.im>
17:22:30
but yes, I guess we can do nominations in the ticket for now?
<@zbyszek:fedora.im>
17:22:37
nirik: yep, this sounds good.
<@siosm:fedora.im>
17:22:59
This is basically what's written in https://docs.fedoraproject.org/en-US/fesco/Fedora_Council_Engineering_Rep/ ?
<@gotmax23:fedora.im>
17:23:07
I didn't realize that vote was closing before today's meeting, sorry :)
<@decathorpe:fedora.im>
17:24:06
I mean I don't think we would come up with responsibilities that are "extraordinarily unexpected" compared to what's already documented
<@gotmax23:fedora.im>
17:24:23
yeah, that's fair
<@decathorpe:fedora.im>
17:24:29
the issue right now is more that the current docs are rather vague
<@zbyszek:fedora.im>
17:24:43
Timothée Ravier: I think the text in the doc is more vague.
<@decathorpe:fedora.im>
17:25:17
> This person is responsible for representing engineering as a collective, and not as a single voice. They will be required to work with all of the various groups that collaborate with FESCo on technical things and act as a liasion between these groups and the Council itself.
<@decathorpe:fedora.im>
17:25:17
for reference:
<@decathorpe:fedora.im>
17:25:17
<@siosm:fedora.im>
17:25:19
OK, let's revise the text in a PR or async?
<@zbyszek:fedora.im>
17:25:33
In a PR.
<@decathorpe:fedora.im>
17:25:33
that sounds like a good idea
<@gotmax23:fedora.im>
17:25:40
ack
<@decathorpe:fedora.im>
17:26:23
!info We are looking at clarifying the documentation for the responsibilities of the Council Representative in followup pull requests.
<@decathorpe:fedora.im>
17:27:18
ok, getting to the actual meeting agenda now.
<@decathorpe:fedora.im>
17:27:25
!link Meeting Agenda: https://lists.fedoraproject.org/archives/list/devel@lists.fedoraproject.org/thread/HKQ332NLB7YKBY6AM35PXZ6NRWVAMUI6/
<@decathorpe:fedora.im>
17:27:36
!topic Migration of fesco tracker and fesco-docs projects to forge.fedoraproject.org
<@decathorpe:fedora.im>
17:27:42
!fesco 3492
<@zodbot:fedora.im>
17:27:43
<@zodbot:fedora.im>
17:27:43
● **Assignee:** Not Assigned
<@zodbot:fedora.im>
17:27:43
● **Last Updated:** 4 hours ago
<@zodbot:fedora.im>
17:27:43
**fesco #3492** (https://pagure.io/fesco/issue/3492):**Migration of fesco tracker and fesco-docs projects to forge.fedoraproject.org**
<@zodbot:fedora.im>
17:27:43
● **Opened:** 8 months ago by decathorpe
<@decathorpe:fedora.im>
17:28:41
Conan Kudo 😌: you are the only veto for now - maybe zbyszek can elaborate why he changed his mind after an in-person conversation?
<@zbyszek:fedora.im>
17:29:22
I learnt that pagure is more buggy than I was previously aware and that it would be prudent to migrate immediately.
<@decathorpe:fedora.im>
17:29:28
(I've also heard that if we don't migrate *now* we'd get migrated to a *new* pagure instance, and then would have to migrate a *second* time to forgejo.?)
<@conan_kudo:matrix.org>
17:30:04
then to me that makes the lack of priority on resolving gaps with forgejo worse
<@nirik:matrix.scrye.com>
17:30:05
huh?
<@conan_kudo:matrix.org>
17:30:05
not better
<@zbyszek:fedora.im>
17:30:12
I can provide more info in a non-public chat.
<@salimma:fedora.im>
17:30:55
do they just mean the public codeberg.org ?
<@salimma:fedora.im>
17:31:09
because surely it's not something Fedora is hosting
<@decathorpe:fedora.im>
17:31:11
?
<@nirik:matrix.scrye.com>
17:31:17
I don't think there's any priority issues... if you mean private tickets, folks are working on them.
<@salimma:fedora.im>
17:31:24
this new pagure instance
<@salimma:fedora.im>
17:31:39
oh wait, pagure not forgejo... ok this is super weird then
<@gotmax23:fedora.im>
17:32:01
Yeah, I heard at Flock that there were some plans to create a tmp.pagure.io instance and make pagure.io readonly
<@supakeen:fedora.im>
17:32:07
Is private tickets the last blocker, I thought I had read about a workaround with migrating them to a separate repository that’s restricted?
<@gotmax23:fedora.im>
17:32:11
this was secondhand info, so 🤷
<@gotmax23:fedora.im>
17:32:25
I unfortunately missed the Forge talk due to flight delays :(
<@decathorpe:fedora.im>
17:32:39
yes, that is what Council did, and what I proposed we do too. Conan Kudo 😌 vetoed the proposal in-ticket vote, so ... here we are!
<@nirik:matrix.scrye.com>
17:32:41
I can ask around, I don't recall hearing anything about that.
<@nirik:matrix.scrye.com>
17:32:52
and I think it's not a good idea.
<@conan_kudo:matrix.org>
17:33:08
I really want a concrete status report on private tickets
<@gotmax23:fedora.im>
17:33:15
Me too
<@conan_kudo:matrix.org>
17:33:26
I don't want us pulling the trigger on anything without that timeline
<@conan_kudo:matrix.org>
17:33:44
"people are working on it" isn't enough when we're being pushed into doing haphazard migrations
<@siosm:fedora.im>
17:34:10
I don't think that's the right way to look at this
<@supakeen:fedora.im>
17:34:14
Isn’t that difficult if work is done upstream?
<@conan_kudo:matrix.org>
17:34:15
I'm tracking the upstream forgejo tickets from codeberg and I haven't seen material progress either
<@decathorpe:fedora.im>
17:34:21
Conan Kudo 😌: I know you aren't happy with anything right now, but can we look at this pragmatically please?
<@conan_kudo:matrix.org>
17:34:25
so I have no idea what the heck is going on
<@nirik:matrix.scrye.com>
17:34:29
sure, a status report would be nice, although it's hard to estimate things like that
<@nirik:matrix.scrye.com>
17:34:39
https://forge.fedoraproject.org/forge/forge/issues?state=open&type=all&labels=&milestone=0&project=0&assignee=0&poster=0&sort=relevance&q=private
<@siosm:fedora.im>
17:34:47
https://codeberg.org/forgejo/design/issues/2
<@salimma:fedora.im>
17:35:01
if we have to use a temporary tracker for private issues for now I think that's better than just blocking progress and making people maintain two forges
<@conan_kudo:matrix.org>
17:35:17
well we have to basically stop taking private tickets
<@salimma:fedora.im>
17:35:18
it's not like we have private issues *that* often
<@conan_kudo:matrix.org>
17:35:27
because there is no sane way to merge them back into one later
<@gotmax23:fedora.im>
17:35:28
I'm kind of starting to look at this as I'm not super happy about this Forge migration flag date thing and lack of features, but it already happened and hopefully we can do this better for distgit (hence the other ticket I opened)
<@decathorpe:fedora.im>
17:35:34
I kind of regret having them *in general*
<@zbyszek:fedora.im>
17:35:52
OK, I think I can provide a status report, second-hand: it's being worked on, but the current work is a proposal. Upstream needs to review and accept the changes and make a release. ETA is a few months, but not promises are made about the schedule. Downstream does not want to provide the feature as a patch, because of the potential risk if anything is wrong with the patches and/or the patches are changes. The patches touch the db schema so it's not good if they get heavily revised before being merged upstream.
<@zbyszek:fedora.im>
17:36:12
The fesco tracker has 8 private issues, with only 2 in the last few years.
<@salimma:fedora.im>
17:36:21
right. we should not have them more than once in a blue moon, so the work involved in duplicating an issue is not so bad. and we can probably look into automating copying the issue -- does forgejo's API support this?
<@siosm:fedora.im>
17:36:26
Yes, it's a difficult feature, and with a lot of implications if things go wrong
<@siosm:fedora.im>
17:36:34
I understand that things are not done in a hurry
<@salimma:fedora.im>
17:36:36
so you can recreate an issue with all the comments attributed to the right users
<@conan_kudo:matrix.org>
17:36:45
zbyszek: the other piece I need to know is if a process to merge the private tickets back into the main ticket repo once it's all worked out is sketched out
<@nirik:matrix.scrye.com>
17:36:55
there's at least two folks working on it.
<@salimma:fedora.im>
17:36:56
or we can just provide a summary of the private issue when we publish it
<@gotmax23:fedora.im>
17:36:57
Can we at least define a way for people to contact us privately that doesn't involve tickets then?
<@conan_kudo:matrix.org>
17:36:58
because we're basically going to temporarily say no to private tickets entirely
<@siosm:fedora.im>
17:37:04
We are not here to demand anything from Forgejo upstrea
<@siosm:fedora.im>
17:37:06
m*
<@gotmax23:fedora.im>
17:37:21
The mailing list is moderated and the fesco-members@fp.o alias doesn't work right because of SPF issues
<@zbyszek:fedora.im>
17:37:24
I heard that would not be possible. The tickets that are private would remain in the second repo forever and not be migrated again.
<@decathorpe:fedora.im>
17:37:40
Honestly, encrypted matrix chat would be the safest choice for something that's supposed to be "private" 🤷
<@siosm:fedora.im>
17:37:46
I explcitly think we should not do that
<@conan_kudo:matrix.org>
17:37:57
that doesn't sound right... it's a database thing, so it should be possible to do it, especially since the numbers are skipped and "reserved"
<@siosm:fedora.im>
17:38:00
we should move away from private issues as much as possible
<@gotmax23:fedora.im>
17:38:07
If we can merge them back and keep that private status, I don't see why we wouldn't want to do that
<@conan_kudo:matrix.org>
17:38:26
we need to be able to handle sensitive reports, that is part of our remit
<@nirik:matrix.scrye.com>
17:38:31
last I heard the answer to merging back was "it depends, will know more once we have the implementation"
<@decathorpe:fedora.im>
17:38:54
I mean all is possible if you SQL hard enough
<@conan_kudo:matrix.org>
17:38:56
right now we are intentionally skipping private issue numbers on record, so I'm hoping someone can commit to a plan to merge them back in
<@zbyszek:fedora.im>
17:38:58
gotmax23: I thought about this and also discussed this during Flock. I think we should publish the mails of a few fesco members and ask people to write a mail to those addresess. As fesco members, we'll take care of using reply-to-all to cover all the members and the non-fesco sender.
<@nirik:matrix.scrye.com>
17:39:34
we could allow list posts to non subscribers and just moderate them... will just be a bunch of spam
<@gotmax23:fedora.im>
17:39:45
That's kinda terrible and also there's no archive or record there
<@decathorpe:fedora.im>
17:39:47
I don't think the mailing list is a good solution
<@zbyszek:fedora.im>
17:39:51
What nirik says sounds good too.
<@gotmax23:fedora.im>
17:39:59
I guess that's better than nothing
<@salimma:fedora.im>
17:40:08
yeah I don't want to deal with people directly messaging me
<@conan_kudo:matrix.org>
17:40:20
definitely
<@salimma:fedora.im>
17:40:22
mailing list is better though agreed that the spam will be bad
<@nirik:matrix.scrye.com>
17:40:28
we might be able to do something on discussion? would need to investigate... but you can have topics that are locked to groups I am pretty sure.
<@salimma:fedora.im>
17:40:36
I alreayd get people DM ing me on Matrix for things that should not be 1:1 and I push back
<@salimma:fedora.im>
17:40:45
not naming names but everyone knows this person
<@siosm:fedora.im>
17:40:56
Another option would be to keep a fesco repo in pagure just for the private tickets for now
<@siosm:fedora.im>
17:41:01
move the public things to the new forge
<@siosm:fedora.im>
17:41:07
keep the private tickets in pagure
<@salimma:fedora.im>
17:41:09
but we can't if pagure is getting decommissioned right?
<@gotmax23:fedora.im>
17:41:17
yeah, I don't know if that's even an option
<@salimma:fedora.im>
17:41:24
I'd suggest a private repo in gitlab or github (horror) as a short term fix
<@decathorpe:fedora.im>
17:41:35
‼️ we have spent 15 minutes on this topic ‼️
<@salimma:fedora.im>
17:41:38
also timecheck.. how long... ah
<@salimma:fedora.im>
17:41:40
jinx
<@decathorpe:fedora.im>
17:41:47
let me make a proposal
<@nirik:matrix.scrye.com>
17:42:00
given how infrequent this is, I would say just do the list thing... it's easy and we can do it now.
<@decathorpe:fedora.im>
17:42:47
Proposal: We ask the people working on the forge deployment for a status update for next week, and - if possible - for one of them to join next week's meeting, so we can have a more informed discussion.
<@siosm:fedora.im>
17:42:59
-1
<@zbyszek:fedora.im>
17:43:03
-1
<@siosm:fedora.im>
17:43:29
I think we should move now. We can discuss what form private issues will take
<@decathorpe:fedora.im>
17:43:34
ah well. it was worth a try
<@zbyszek:fedora.im>
17:43:41
What siosm said.
<@salimma:fedora.im>
17:43:48
yeah, I think it looks bad if we keep delaying
<@siosm:fedora.im>
17:43:50
Gitlab, github, I don't care, it should only be for a short time
<@decathorpe:fedora.im>
17:44:16
does GitLab even have confidential issues? (does GitHub?)
<@siosm:fedora.im>
17:44:17
If we can make it work on Gitlab.com Fedora org that would be nice
<@siosm:fedora.im>
17:44:22
I don't know
<@salimma:fedora.im>
17:44:30
at some point there needs to be a good place for private discussion, not just for us (our needs should be rare) but for ... fedora security SIG, which we hope to have back
<@nirik:matrix.scrye.com>
17:44:36
Why not just do the list for now? another repo is... anoying
<@salimma:fedora.im>
17:44:46
issues on private repos are private, right?
<@decathorpe:fedora.im>
17:44:51
alright, previous proposal withdrawn, new proposal incoming
<@siosm:fedora.im>
17:44:53
I'm OK with the ML option as well
<@salimma:fedora.im>
17:44:57
but yeah I'd lean towards doing list first until we decide it does not work
<@gotmax23:fedora.im>
17:44:58
I'd like to invite people from the Forge effort next week anyways to discuss https://pagure.io/fesco/issue/3623, so we could also discuss this subject
<@gotmax23:fedora.im>
17:45:03
Gitlab does support private issues
<@gotmax23:fedora.im>
17:45:09
And can do FAS auth
<@zbyszek:fedora.im>
17:45:11
Proposal: Migrate public issues to the forge. Migrate private issues to a separate repo on the forge, for archival purposes only. Open up the mailing list for non-subscribers as nirik suggested.
<@gotmax23:fedora.im>
17:45:19
But I'd prefer not to use Gitlab here...
<@nirik:matrix.scrye.com>
17:45:23
+1
<@salimma:fedora.im>
17:45:35
yeah, I want a status update too, I just don't want it blocking
<@siosm:fedora.im>
17:45:42
+1
<@supakeen:fedora.im>
17:46:00
I’m +1 on zbyszek s idea but would still want this to be implemented and status updates
<@zbyszek:fedora.im>
17:46:05
(If we later *can* migrate private issues to the existing repo, great. We can always consider that later .We can also figure out how to handle private issues in the public repo if the situation changes. Hopefully that'll happen in a few months.)
<@decathorpe:fedora.im>
17:46:18
for reference, the initial proposal that caused this topic to be on the agenda is https://pagure.io/fesco/issue/3492#comment-1018737
<@zbyszek:fedora.im>
17:47:41
Fabio Valentini 🌈: ah, yes. That is pretty close, except for the mailing list stuff.
<@siosm:fedora.im>
17:47:47
I think that mixing private an public issues is a recipe for disaster
<@conan_kudo:matrix.org>
17:48:06
that is a weird take, since that's _normal_ across almost every project
<@decathorpe:fedora.im>
17:48:30
it's not though. GitHub hasn't supported private issues for like a decade
<@salimma:fedora.im>
17:48:39
yeah, if you have a public project surely you don't want another repo just to take private issues
<@gotmax23:fedora.im>
17:48:43
Github has the private security reports thing though
<@siosm:fedora.im>
17:48:48
But we are an open source project. I expect things to be open by default
<@gotmax23:fedora.im>
17:48:49
but I digress
<@decathorpe:fedora.im>
17:48:53
yes, but that's relatively recent.
<@salimma:fedora.im>
17:49:01
open by default, yes, but not everything can be open
<@nirik:matrix.scrye.com>
17:49:09
we should be open by default, but there's exceptions....
<@zbyszek:fedora.im>
17:49:12
Fabio Valentini 🌈: so you +1 in the ticket. Why not ack the latest proposal?
<@siosm:fedora.im>
17:49:19
anyway, lease vote on this one
<@salimma:fedora.im>
17:49:22
we probably don't want to... keep hashing this out. can we follow up elsewhere?
<@decathorpe:fedora.im>
17:49:53
fine, it's basically the same thing I proposed, just in different words (plus the ML thing). +1
<@conan_kudo:matrix.org>
17:50:51
I'm more angry about the fact my question was ignored each time I brought this up over the past year
<@salimma:fedora.im>
17:50:52
+1
<@conan_kudo:matrix.org>
17:50:58
but whatever
<@conan_kudo:matrix.org>
17:50:59
+0
<@salimma:fedora.im>
17:51:24
yeah... I have been asking about issue migration for a while too and have always been told it's not a big deal (for dist-git)
<@salimma:fedora.im>
17:51:45
so at this point I'd say well you break it you own it. since there are claims that "oh bugzilla is confusing and that's why we don't have new contributors"
<@decathorpe:fedora.im>
17:51:48
see also https://pagure.io/fesco/issue/3623
<@conan_kudo:matrix.org>
17:51:48
there is no point in providing feedback if there is no loop
<@gotmax23:fedora.im>
17:52:12
I was hoping that someone would have responsed to https://pagure.io/fesco/issue/3492
<@conan_kudo:matrix.org>
17:52:24
I've generally learned nobody will now
<@gotmax23:fedora.im>
17:52:26
It was stalled on getting feedback from the Forge team for four weeks and then there was no feedback
<@conan_kudo:matrix.org>
17:52:29
until everything is super on fire
<@zbyszek:fedora.im>
17:52:37
Máirín Duffy vote?
<@conan_kudo:matrix.org>
17:52:45
that's why I was trying to force a relatively safe fire
<@siosm:fedora.im>
17:52:54
Did anyone bring that ticket to the attention of the forge team?
<@nirik:matrix.scrye.com>
17:52:56
well, I would ping jednorozec to answer... he may well not be watching fesco tickets ?
<@conan_kudo:matrix.org>
17:52:58
yes
<@conan_kudo:matrix.org>
17:53:02
yes
<@conan_kudo:matrix.org>
17:53:08
three times
<@conan_kudo:matrix.org>
17:53:24
it even came up in FRCL
<@gotmax23:fedora.im>
17:53:49
FWIW, I did ping people last week, but maybe it was missed because of conference travel, etc.
<@gotmax23:fedora.im>
17:54:03
But I would really like for there to be some open line of communication here
<@gotmax23:fedora.im>
17:54:12
Especially for the distgit migration
<@salimma:fedora.im>
17:54:16
airing of grievances can be cathartic if done sparingly like during Festivus but if it's too often and nothing happens..
<@conan_kudo:matrix.org>
17:54:29
and I'm waiting for jednorozec to eat a hat as he promised for this
<@salimma:fedora.im>
17:54:39
straw hat or felt fedora/
<@conan_kudo:matrix.org>
17:54:43
since a bunch of things were missed
<@salimma:fedora.im>
17:54:46
straw hat or felt fedora?
<@conan_kudo:matrix.org>
17:54:56
I'm good with either :P
<@nirik:matrix.scrye.com>
17:55:00
I can try and ask them to answer those things... I'm not sure what else I can do...
<@siosm:fedora.im>
17:55:00
We are at 5,1,0 if I count zbyszek as +1
<@gotmax23:fedora.im>
17:55:12
I don't want this to become a thing, but it would be nice to not have to be making decisions based on second and third hand information
<@zbyszek:fedora.im>
17:55:14
Timothée Ravier: I made the proposal, so I automatically count as +1
<@decathorpe:fedora.im>
17:55:16
I was just going to ask, I lost track of the votes.
<@salimma:fedora.im>
17:55:52
wait till you see change proposals that nobody understand after reading and asking questions for weeks
<@conan_kudo:matrix.org>
17:55:57
one day that will happen, it'll be a glorious world
<@decathorpe:fedora.im>
17:56:00
zbyszek: can you write the !agreed line?
<@siosm:fedora.im>
17:56:18
6,1,0 as I had missed Fabio's vote
<@zbyszek:fedora.im>
17:57:41
draft: Migrate FESCo public issues to the forge. Migrate private issues to a separate repo on the forge, for archival purposes only. Open up the mailing list for non-subscribers as a temporary measure until private tickets can be handled at the forge. (+6, 1, 0)
<@decathorpe:fedora.im>
17:57:58
ack
<@supakeen:fedora.im>
17:58:05
Ack but not super happy 🙂
<@gotmax23:fedora.im>
17:58:19
Meh, you can add me to abstentions. **+0**
<@zbyszek:fedora.im>
17:58:24
!agreed Migrate FESCo public issues to the forge. Migrate private issues to a separate repo on the forge, for archival purposes only. Open up the mailing list for non-subscribers as a temporary measure until private tickets can be handled at the forge. (+6, 2, 0)
<@decathorpe:fedora.im>
17:58:35
zbyszek: thanks
<@decathorpe:fedora.im>
17:58:42
*exhales*
<@nirik:matrix.scrye.com>
17:58:50
note that we need: someone to do the migrating, and someone to update the docs to mail the list about private issues.
<@decathorpe:fedora.im>
17:59:14
I can do that
<@decathorpe:fedora.im>
17:59:28
!action decathorpe to do the migratening
<@siosm:fedora.im>
17:59:39
We can sync together if you want as I've migrated some repos already
<@siosm:fedora.im>
17:59:45
(up to you)
<@decathorpe:fedora.im>
18:00:05
yeah I have migrated some too, it should be fine
<@gotmax23:fedora.im>
18:00:23
Just please don't run that script that leaves a comment on every Pagure issue; it creates a huge amount of spam
<@decathorpe:fedora.im>
18:00:29
yup yup
<@gotmax23:fedora.im>
18:00:33
But thanks for doing the migration :)
<@decathorpe:fedora.im>
18:00:35
!topic Should we require 2FA for provenpackagers?
<@decathorpe:fedora.im>
18:00:40
!fesco 3618
<@zodbot:fedora.im>
18:00:41
● **Assignee:** Not Assigned
<@zodbot:fedora.im>
18:00:41
**fesco #3618** (https://pagure.io/fesco/issue/3618):**Should we require 2FA for provenpackagers?**
<@zodbot:fedora.im>
18:00:41
<@zodbot:fedora.im>
18:00:41
● **Opened:** a week ago by gotmax23
<@zodbot:fedora.im>
18:00:41
● **Last Updated:** 4 hours ago
<@nirik:matrix.scrye.com>
18:00:47
another easy topic! :)
<@decathorpe:fedora.im>
18:00:47
even more uncontroversial things
<@gotmax23:fedora.im>
18:00:54
Technically, this was already approved based on votes
<@salimma:fedora.im>
18:00:56
after the security incident I'm leaning to +1
<@supakeen:fedora.im>
18:00:57
So this topic it was unclear to me if technically possible or only soft possible.
<@conan_kudo:matrix.org>
18:01:02
in principle, I don't hate the idea
<@salimma:fedora.im>
18:01:09
but the recovery option used to be scary with our account system
<@gotmax23:fedora.im>
18:01:11
Technically, this was already approved based on ticket votes
<@conan_kudo:matrix.org>
18:01:12
I just really wish we had a self-service recovery mechanism
<@supakeen:fedora.im>
18:01:14
Even if it has already been approved I wonder about the enforcement part of it.
<@salimma:fedora.im>
18:01:27
iirc in the past it sometimes goes wrong and we just say "contact an admin and beg to get it disabled"
<@supakeen:fedora.im>
18:01:36
And the concern of infra/releng having to deal with users losing stuff.
<@salimma:fedora.im>
18:01:37
but we don't require pgp or anything to prove someone's credentials
<@nirik:matrix.scrye.com>
18:01:44
you can avoid that by making sure you enroll several otps and keep one 'safe' somewhere.
<@gotmax23:fedora.im>
18:01:45
What would that look like? Backup tokens like other services or something different?
<@decathorpe:fedora.im>
18:01:47
you can add multiple second factors, as long as *one* of them works you should be good
<@salimma:fedora.im>
18:01:48
right
<@salimma:fedora.im>
18:01:59
do we at least have backup recovery codes?
<@conan_kudo:matrix.org>
18:01:59
if I had 2FA three years ago after my luggage was lost, I would have been unable to execute _any_ of the "supported" reocvery methods
<@conan_kudo:matrix.org>
18:02:07
because I lost all of my MFA token devices
<@conan_kudo:matrix.org>
18:02:15
no, that's what I want us to have
<@supakeen:fedora.im>
18:02:15
We don't have backup recovery codes.
<@salimma:fedora.im>
18:02:35
so this is why I don't have it turned on for fedora. even though I am a provenpackager, and I have this turned on everywhere else
<@nirik:matrix.scrye.com>
18:02:35
this has all been discussed on the list. ;) I can recap for folks... I don't know if we want to rehash everything we already discussed there?
<@conan_kudo:matrix.org>
18:02:41
since our system is built on FreeIPA, it never really occurred to anyone to have this, since it assumes an ever-present central admin
<@decathorpe:fedora.im>
18:02:41
please no
<@salimma:fedora.im>
18:02:45
github, gitlab, pypi...
<@supakeen:fedora.im>
18:03:00
Not everything, I'm just wondering if it'd be a hard requirement or a soft requirement @nirik:matrix.scrye.com :)
<@conan_kudo:matrix.org>
18:03:14
yeah, I have MFA on for everything _except_ fedora for precisely this reason
<@zbyszek:fedora.im>
18:03:19
!info The stack for nitrokeys (python-pynitrokey and dependecies) has been packaged by Daniel Milnes. It'll be available soon™ in Rawhide and other releases a bit later. This makes TOPT generation using Nitrokeys work nicely.
<@salimma:fedora.im>
18:03:21
so yeah I just want a documented recovery flow in case things go pear shaped
<@nirik:matrix.scrye.com>
18:03:28
The proposal in the ticket is to change the 'provenpackages SHOULD' to provenpackagers MUST
<@conan_kudo:matrix.org>
18:03:39
almost all of us in here are provenpackagers
<@conan_kudo:matrix.org>
18:03:45
so this affects us significantly
<@gotmax23:fedora.im>
18:04:00
Yeah, I deliberately left out any enforcement mechanism for the initial proposal
<@nirik:matrix.scrye.com>
18:04:10
recovery flow: use your backup otp... if all of those are also somehow broken, mail admin@fp.o
<@gotmax23:fedora.im>
18:04:13
This is documented in the Infra SOPs I believe
<@supakeen:fedora.im>
18:04:22
Ah, if that's left out on purpose then I understand :)
<@supakeen:fedora.im>
18:04:37
But I thought we'd want to chat about implementation here.
<@thebeanogamer:fedora.im>
18:04:41
Security SIG is also working on docs for NitroKey and Yubikeys, as well as support in fkinit
<@zbyszek:fedora.im>
18:04:47
I have turned on 2FA recently and it seems to mostly work fine. I need to input the OTP token every few days, but that's acceptable.
<@nirik:matrix.scrye.com>
18:04:48
well, we should decide what to do about the folks who currently don't meet that requirement.
<@siosm:fedora.im>
18:04:59
nirik Could you link to your recap? (here or in the ticket)
<@zbyszek:fedora.im>
18:05:01
Hmm, I thought fkinit already works. What is missing?
<@nirik:matrix.scrye.com>
18:05:13
I don't have one, I could try and write one up?
<@thebeanogamer:fedora.im>
18:05:36
It works, I just think it can be nicer (automatically poke the key rather than you generating the code in one terminal and pasting into another)
<@siosm:fedora.im>
18:05:43
Ah ok nevermind, I missunderstood
<@thebeanogamer:fedora.im>
18:05:43
It’s a nice to have
<@supakeen:fedora.im>
18:05:45
Does announcement on devel@, then a follow-up direct email x time later work?
<@gotmax23:fedora.im>
18:05:49
yeah, pretty much the only thing we can technically do now is remove people from provenpackager who don't have 2FA enabled after a certain date
<@zbyszek:fedora.im>
18:05:53
Ah, OK, yeah, fkinit doing this automatically would be nice.
<@gotmax23:fedora.im>
18:05:59
but that's terrible :(
<@supakeen:fedora.im>
18:06:16
Then *after* that it'd mean removal however horrible that is, perhaps with the 'you get it back once you enable it'.
<@decathorpe:fedora.im>
18:06:21
eh 🤷 having fewer provenpackagers would be a good thing IMO
<@nirik:matrix.scrye.com>
18:06:44
zbyszek You can pass the TOTP in a env var.
<@gotmax23:fedora.im>
18:06:47
something like that sounds reasonable
<@siosm:fedora.im>
18:06:48
yes, it's not an issue removing the proven packager status until the person sets up 2FA
<@zbyszek:fedora.im>
18:06:55
agreed
<@siosm:fedora.im>
18:06:56
they can always get it back
<@gotmax23:fedora.im>
18:07:09
we can say that they can get it back without any process other than an infra ticket
<@gotmax23:fedora.im>
18:07:23
(i.e., fesco doesn't need to vote on it like it usually would)
<@gotmax23:fedora.im>
18:07:38
yeah, me too :(
<@salimma:fedora.im>
18:07:44
we can't disable their login while not changing their FAS group memberships?
<@decathorpe:fedora.im>
18:07:46
In the interest of not making this meeting very long: Can you post the gist and proposals to the ticket?
<@salimma:fedora.im>
18:07:52
that seems easier to fix than removing the group membership
<@gotmax23:fedora.im>
18:07:54
but making changes to the auth system itself is probably more work
<@siosm:fedora.im>
18:08:01
1. Announce on devel & discussion
<@siosm:fedora.im>
18:08:01
2. Timeline is: new proven packagers right now, 3 months for existing ones
<@siosm:fedora.im>
18:08:01
3. Demote pp without 2FA in 3 months
<@salimma:fedora.im>
18:08:04
but that might be worse, losing all access
<@nirik:matrix.scrye.com>
18:08:23
we can disable accounts, but that completely disables them. They cannot login or use there account
<@zbyszek:fedora.im>
18:08:30
Do we really need 3 months? Maybe 1 month?
<@supakeen:fedora.im>
18:08:33
I think removing `provenpackager` is the better evil as it removes the gate that we want 2fa for while allowing someone to continue other tasks that don't require that gate.
<@salimma:fedora.im>
18:08:40
I'd suggest encouraging adding one's GPG key in FAS so you can authenticate who you are by sending a signed email. but our GPG usage is so low that might not help many people
<@decathorpe:fedora.im>
18:08:55
FWIW dropping group memberships won't do anything *immediately*, only after they force a logout/login flow
<@zbyszek:fedora.im>
18:09:05
I mean, even if you want to acquire a yubikey, this is doable in a week. Extra 10 weeks doesn't change anything except enable procrastination.
<@supakeen:fedora.im>
18:09:08
@zbyszek:fedora.im I'd say 3 if it's announce soon as we're going into summer vacation time.
<@gotmax23:fedora.im>
18:09:14
1. Announce on devel & discussion
<@gotmax23:fedora.im>
18:09:14
1. Demote pp without 2FA in 3 months
<@gotmax23:fedora.im>
18:09:14
1. Timeline is: new proven packagers right now, 3 months for existing ones
<@gotmax23:fedora.im>
18:09:14
1. Directly email affected provenpackagers
<@gotmax23:fedora.im>
18:09:14
1. Provenpackagers can file an infra ticket to be readded once 2FA is enabled
<@supakeen:fedora.im>
18:09:18
(or 2, but not 1)
<@nirik:matrix.scrye.com>
18:09:21
There's a toddler that is supposed to sync group memberships on src.fp.o
<@salimma:fedora.im>
18:09:53
I'm happy to dogfood by waiting to get that email before enabling 2FA :)
<@gotmax23:fedora.im>
18:10:00
I don't know if it works for provenpackager, though
<@gotmax23:fedora.im>
18:10:17
I'd have to look at the toddler code again...
<@nirik:matrix.scrye.com>
18:10:23
yeah, it should
<@gotmax23:fedora.im>
18:10:28
okay
<@decathorpe:fedora.im>
18:10:31
gotmax23: eh, +1. that 5 step plan sounds ok
<@zbyszek:fedora.im>
18:10:37
OK, I'd prefer sooner mut but if everybody thinks 3 months is appropriate, I won't argue.
<@siosm:fedora.im>
18:10:39
+1 to gotù
<@siosm:fedora.im>
18:10:43
gotmax's
<@zbyszek:fedora.im>
18:10:44
+1 to gotmax23
<@nirik:matrix.scrye.com>
18:10:48
also note that there's options like keepassxc and bitwarden... hardware shouldn't be a blocker
<@gotmax23:fedora.im>
18:10:59
I don't care that much, but 3 months didn't seem unreasonable
<@nirik:matrix.scrye.com>
18:10:59
+1
<@gotmax23:fedora.im>
18:11:02
+1 to my proposal
<@supakeen:fedora.im>
18:11:15
+1
<@salimma:fedora.im>
18:11:19
+1
<@nirik:matrix.scrye.com>
18:11:23
as a side note the amazing abbra proposed some passkey support pr's for noggin. ;)
<@zbyszek:fedora.im>
18:11:34
gotmax23: you don't need to vote. Since you made the proposal, you're +1 implicitly. You only need to say something if you vote 0 or -1.
<@siosm:fedora.im>
18:12:00
Neal Gompa (Fedora)Máirín Duffy
<@siosm:fedora.im>
18:12:14
Conan Kudo 😌
<@conan_kudo:matrix.org>
18:12:14
+0
<@conan_kudo:matrix.org>
18:12:30
I don't hate it, but I don't like it as-is
<@conan_kudo:matrix.org>
18:12:39
I wish I could be more supportive of it
<@conan_kudo:matrix.org>
18:12:46
but I feel we're setting people up for failure
<@gotmax23:fedora.im>
18:13:16
I just think the blast radius of a compromised provenpackager is so large that accepting this is better than nothing
<@decathorpe:fedora.im>
18:13:20
proposed !agreed Two-factor authentication will be required for members of the provenpackager group. There will be 3 month grace period for existing group members, after which users that don't have 2FA set up will be removed from the group. (+7, 1, -0)
<@gotmax23:fedora.im>
18:13:46
(and yes, I understand that 2fa is not foolproof, but it makes compromising an account significantly harder)
<@supakeen:fedora.im>
18:13:50
Do we want docs and suggestions to be part of the proposal/before the email?
<@zbyszek:fedora.im>
18:14:11
Let's just !info that.
<@supakeen:fedora.im>
18:14:15
+
<@nirik:matrix.scrye.com>
18:14:22
who is sending the email? do you want me to?
<@gotmax23:fedora.im>
18:14:49
Shortened version is fine, but can we paste the version with the notifications and infra ticket recovery steps into the ticket?
<@gotmax23:fedora.im>
18:14:53
I think those things are important
<@conan_kudo:matrix.org>
18:15:26
yes, and that's why I'm not -1
<@decathorpe:fedora.im>
18:15:40
I'll include the whole thing in an !info after the !agreed, and paste the original 5 point proposal into the ticket - does that work for you?
<@conan_kudo:matrix.org>
18:15:48
but I really do think not having a recovery code solution that is self-service is a bad idea
<@conan_kudo:matrix.org>
18:15:57
and we need to ask the IPA Noggin folks to look into it
<@salimma:fedora.im>
18:16:05
we should at least file an issue with freeipa and track it
<@conan_kudo:matrix.org>
18:16:27
I have been through an event like that before, and it's really bad if you have to do individual proofs instead of instant automated resets
<@abbra:matrix.org>
18:16:35
For use of passkeys we need to migrate from ipsilon
<@conan_kudo:matrix.org>
18:16:46
I am not going to use passkeys, FYI
<@conan_kudo:matrix.org>
18:16:58
machine bound logins are just not something I will do
<@supakeen:fedora.im>
18:16:59
I think it's best if it comes from infrastructure, but perhaps we can write the text all togehter through some etherpad or something?
<@supakeen:fedora.im>
18:17:15
Or with a few people :)
<@decathorpe:fedora.im>
18:17:15
!agreed Two-factor authentication will be required for members of the provenpackager group. There will be 3 month grace period for existing group members, after which users that don't have 2FA set up will be removed from the group. (+7, 1, -0)
<@nirik:matrix.scrye.com>
18:17:20
sure, I can draft something and ask for reviews?
<@supakeen:fedora.im>
18:17:26
Yes please.
<@decathorpe:fedora.im>
18:17:59
!info The agreed-upon steps are: 1. Announce on devel & discussion; 2. Directly email affected provenpackagers; 3. Timeline is: new proven packagers right now, 3 months for existing ones; 4. Demote pp without 2FA in 3 months; 5. Provenpackagers can file an infra ticket to be readded once 2FA is enabled
<@abbra:matrix.org>
18:18:30
Current options in kerberos are: smart cards, FIDO2 passkeys, OTP tokens, external IdP, and passwords
<@siosm:fedora.im>
18:18:43
passkeys don't have to be machine bound
<@decathorpe:fedora.im>
18:19:08
I have some passkeys on my yubikey ...
<@conan_kudo:matrix.org>
18:19:09
they have to be bound to _something_
<@nirik:matrix.scrye.com>
18:19:10
shall we move that discussion over to #devel:fedoraproject.org and continue meeting?
<@decathorpe:fedora.im>
18:19:19
also some in BitWarden
<@gotmax23:fedora.im>
18:19:21
Supporting FIDO2 is nice, but I don't want to require that since it requires volunteers to by special hardware
<@gotmax23:fedora.im>
18:19:27
+1 to continuing discussion async
<@conan_kudo:matrix.org>
18:19:40
I'm just saying my red line is requiring FIDO2 passkeys
<@conan_kudo:matrix.org>
18:19:44
not going to do it
<@gotmax23:fedora.im>
18:19:55
Supporting FIDO2 is nice, but I don't want to require that since it requires volunteers to buy special hardware
<@conan_kudo:matrix.org>
18:20:11
especially with how bad our recovery story is, I wouldn't want to even if I liked passkeys
<@siosm:fedora.im>
18:20:29
I don't about any service that requires FIDO2 passkeys
<@siosm:fedora.im>
18:20:38
let's move on?
<@decathorpe:fedora.im>
18:20:40
!topic Next Week's Chair
<@decathorpe:fedora.im>
18:20:49
any volunteers?
<@conan_kudo:matrix.org>
18:21:12
I will be dead from my flight home next week, so not me
<@siosm:fedora.im>
18:21:22
Meeting process is in https://fedoraproject.org/wiki/FESCo_meeting_process for the new members :)
<@decathorpe:fedora.im>
18:21:23
I can help guide new members through the process if needed
<@decathorpe:fedora.im>
18:21:36
but yes mostly just that wiki page
<@decathorpe:fedora.im>
18:21:54
great. nothing like jumping in the deep end
<@siosm:fedora.im>
18:21:57
It's reasonably easy to do, take a bit of time on monday
<@gotmax23:fedora.im>
18:22:01
Side note, step 6 in that wiki has a broken link
<@decathorpe:fedora.im>
18:22:05
!action gotmax23 to chair next week's meeting
<@siosm:fedora.im>
18:22:34
Hum, it works for me
<@gotmax23:fedora.im>
18:22:52
Oh, it does, hmm
<@decathorpe:fedora.im>
18:22:54
!topic Open Floor
<@zodbot:fedora.im>
18:24:19
salimma gave a cookie to gotmax23. They now have 66 cookies, 8 of which were obtained in the Fedora 44 release cycle
<@nirik:matrix.scrye.com>
18:24:22
I had a hopefully quick item... bugzilla.redhat.com admins approached me and said that they have a process that sets closed and inactive more than 90 days bugs such that it requires privs to do anything with them (this would be fedorabugs, ie, the priv that packagers and qa has). Does anyone see any problem with me telling them to go ahead and do this? It would cut down on spam that hits popular old closed tickets and thus save them work.
<@conan_kudo:matrix.org>
18:24:50
that would be great
<@nirik:matrix.scrye.com>
18:24:53
I can't see really any downside, but promised to bring it up here.
<@zbyszek:fedora.im>
18:24:54
Seems reasonable.
<@salimma:fedora.im>
18:24:59
sounds good
<@conan_kudo:matrix.org>
18:25:02
spam based necromancy sucks
<@siosm:fedora.im>
18:25:22
Can we do this only on closed bugs (just to confirm)?
<@nirik:matrix.scrye.com>
18:25:25
yeah. I see them pretty often... they try and pick 'popular' old tickets.
<@salimma:fedora.im>
18:25:26
people can always just clone them if the same issue persists, no reason keeping old bugs alive
<@salimma:fedora.im>
18:25:38
'closed and inactive' right?
<@nirik:matrix.scrye.com>
18:25:41
yes, it's only closed and nothing has been done to them in 90 days
<@zbyszek:fedora.im>
18:25:43
Please don't clone. Resubmit fresh.
<@decathorpe:fedora.im>
18:25:58
sounds good to me.
<@nirik:matrix.scrye.com>
18:26:01
clone bad. Just make a new bug and refer back
<@siosm:fedora.im>
18:26:17
+1
<@salimma:fedora.im>
18:26:26
ah ... ok one more thing then
<@salimma:fedora.im>
18:26:31
can cloning be disabled for such bugs?
<@salimma:fedora.im>
18:26:39
bonus if it can, if it can't that is ok too
<@decathorpe:fedora.im>
18:27:00
(I don't even know *how* to clone a bug. is there UI for it or do you need XMLRPC API calls?)
<@salimma:fedora.im>
18:27:05
and is there a comment or something added to the bug explaining why it'slocked?
<@salimma:fedora.im>
18:27:10
there are two clone buttons in the UI
<@salimma:fedora.im>
18:27:20
they are tiny and easy to miss - on top of the summary header, above save changes
<@salimma:fedora.im>
18:27:30
full clone and lightweight clone. I don't recommend using them much
<@decathorpe:fedora.im>
18:27:39
oh! the teeny tiny buttons. I see.
<@salimma:fedora.im>
18:27:48
I'm sorry that now you know ;)
<@zbyszek:fedora.im>
18:27:55
I have something for open floor too.
<@decathorpe:fedora.im>
18:28:10
adding a comment that explains the "locked" status upon locking would be great yeah
<@decathorpe:fedora.im>
18:28:25
but in favor with or without this
<@nirik:matrix.scrye.com>
18:28:26
no
<@nirik:matrix.scrye.com>
18:28:41
we don't want to comment on 10000000000900000 bugsx.
<@nirik:matrix.scrye.com>
18:28:47
thats insane
<@supakeen:fedora.im>
18:28:54
Comments would send emails too
<@gotmax23:fedora.im>
18:29:12
We could make them the kind of comments that don't send emails
<@nirik:matrix.scrye.com>
18:29:16
users without privs would just not be able to do things and would file a new bug...
<@salimma:fedora.im>
18:29:23
not if you say 'minor update'
<@gotmax23:fedora.im>
18:29:32
right
<@nirik:matrix.scrye.com>
18:29:37
I am pretty sure that bugzilla admins would say nevermind if we asked them to update all fedora bugs over all time
<@salimma:fedora.im>
18:29:50
but this are minor suggestions and we generally approve this right
<@gotmax23:fedora.im>
18:30:10
fair enough
<@decathorpe:fedora.im>
18:30:19
skip the first large batch, do it for *new* locked bugs?
<@decathorpe:fedora.im>
18:30:46
or maybe that's too much effort for a service that's being shut down at some point anyway.
<@nirik:matrix.scrye.com>
18:30:55
they will have to do it in batches anyhow, but I don't see why we should spam all the bugs.
<@nirik:matrix.scrye.com>
18:31:10
even if it doesn't send email
<@nirik:matrix.scrye.com>
18:31:33
there's 814563 fedora bugs
<@salimma:fedora.im>
18:31:42
fair
<@gotmax23:fedora.im>
18:31:52
was there another thing for open floor?
<@nirik:matrix.scrye.com>
18:32:06
zbyszek had something?
<@zbyszek:fedora.im>
18:32:12
I think it'd nice to acknowledge that.
<@zbyszek:fedora.im>
18:32:12
Fabio L. graciously filled in the gap during the last month of previous FESCo.
<@zbyszek:fedora.im>
18:32:27
Proposal: FESCo thanks @Fale for stepping up to be a FESCO member in the previous term.
<@gotmax23:fedora.im>
18:32:33
+1
<@supakeen:fedora.im>
18:32:45
+1, ack.
<@decathorpe:fedora.im>
18:32:45
+1
<@salimma:fedora.im>
18:32:52
+1
<@siosm:fedora.im>
18:32:55
+1
<@decathorpe:fedora.im>
18:33:13
I tried to add something to that effect in https://pagure.io/fesco/issue/3619 too :)
<@nirik:matrix.scrye.com>
18:33:24
+10
<@decathorpe:fedora.im>
18:33:40
all the upvotes.
<@decathorpe:fedora.im>
18:33:50
anything else for open floor?
<@gotmax23:fedora.im>
18:35:06
this problem is kind of intractable :(. we have the power to orphan/retire packages that contain pre-built binaries, but not much else
<@decathorpe:fedora.im>
18:35:08
ah yes 😬 the ghost.js that keeps haunting us
<@gotmax23:fedora.im>
18:36:12
and also, I'd like to discuss https://pagure.io/fesco/issue/3623 at some point. not sure how to best go about inviting representatives from the Forge team to meeting
<@nirik:matrix.scrye.com>
18:36:43
also, we were supposed to get a report back about v3 recompiles?
<@gotmax23:fedora.im>
18:36:50
yeah, that too
<@gotmax23:fedora.im>
18:37:36
https://pagure.io/fesco/issue/3599 ftr
<@decathorpe:fedora.im>
18:37:41
it's marked as "stalled" so I didn't poke the ticket, but yes, it was supposed to be three weeks. it's now been 2 months
<@conan_kudo:matrix.org>
18:38:03
owen: FYI ^
<@conan_kudo:matrix.org>
18:38:23
I talked to them a bit about this at Flock and they were just starting on this effort
<@conan_kudo:matrix.org>
18:38:32
but I don't know much more beyond that
<@decathorpe:fedora.im>
18:38:59
ok, good to know that it's still on their radar.
<@decathorpe:fedora.im>
18:39:26
unless there's anything else for open floor, I'm going to !endmeeting in a minute or two.
<@conan_kudo:matrix.org>
18:39:53
note hangry at the beginning of this meeting
<@zbyszek:fedora.im>
18:40:52
Fabio Valentini 🌈: thanks for chairing
<@zodbot:fedora.im>
18:41:05
salimma gave a cookie to decathorpe. They now have 174 cookies, 12 of which were obtained in the Fedora 44 release cycle
<@gotmax23:fedora.im>
18:41:16
decathorpe++
<@zodbot:fedora.im>
18:41:18
gotmax23 has already given cookies to decathorpe during the F44 timeframe
<@decathorpe:fedora.im>
18:41:48
hey I got four week's worth of chairing duty for the price of one, I'd call that a bargain
<@decathorpe:fedora.im>
18:42:08
!endmeeting