ff /tmp/irc

/tmp/irc

stormycan people here me?12:02
LegNeato joined the channel12:02
jorgev joined the channel12:02
hrosikglazou, kev: I would prefer SIP though12:02
mj joined the channel12:03
kevI will see what I can do12:03
glazoustormy: is someone taking minutes?12:03
mjhi everybody12:03
kevme12:03
glazoukev: ok12:03
kevglazou: me12:03
Usul is now known as usul|phone12:03
kevI type better than I speak, it seems12:03
LegNeatoI'd like to add an agenda item about the releases we just did to give an overview12:03
JeremyDYoungTopic Suggestion: LTS Discussions on dev.planning12:05
LegNeatostormy: did you see my discussion item ^^12:05
JeremyDYoungI like the idea of delineating the costs of an LTS12:06
hrosikWes--: it would be enough if he would do more thinking before speaking12:07
Wes--Costs of LTS - first, who is going to *do* LTS - this /must/ cost moz-employee time AFAICS (which is why Asa is opposed)12:07
LegNeatoJeremyDYoung: It's not the costs12:07
LegNeatoAlso, FYI...a proposal doesn't mean we've committed to a LTS...it just means we need to have something to debate and tease out pros and cons12:08
JeremyDYoungLegNeato: Money is not the only cost factor. Stormy suggested we talk about what Enterprises can contribute.12:08
LegNeatoJeremyDYoung: Ok, great12:09
kevglazou: was that you?12:09
glazouyes12:09
kevkk12:09
kevsome mitigation strategies there12:09
Wes--(agenda item from glazou - third party private addons)12:09
glazou thinks we lost kev from IRC12:10
kevnope, I am here12:10
glazou s/french person/glazou12:10
usul|phoneI'll just add that Thunderbird did 3.1.14 and 6.0.2 for the same reasons12:11
hrosikand SeaMonkey 2.3.312:12
JeremyDYoungThey'll know that they care more.12:14
walickiewg-announce12:14
JeremyDYoungEnd Users will be at just as much risk, but just not know about it.12:15
mkaplyThere used to be a list like that12:15
mkaplya security announce release12:15
hrosikdon;t these security issues belong to security-announce?12:16
kev takes action item to post announce lists and relevant info sources on the meeting minutes12:16
bhearsumyeah, this doesn't sound enterprise-specific, it sounds like Enterprise people are one of many interested parties in this12:16
JeremyDYoungI agree that it's not directly an Enterprise concern. Security Related emergency releases should be announced to a special channel targetted at everyone.12:16
stormybhearsum, I agree12:16
kevthey exist, I belive, and I'll add it to the meeting minutes and Enterprise Wiki page for info sources12:17
glazou wonders if we're not diverging a bit from the main purpose of the EWG...12:17
JeremyDYoungMaybe the security blog with a "Release" tag?12:17
LegNeatomkaply: We have an announce list but it happens *after*12:18
LegNeatoglazou: I don't see that, this is seeing how enterprises get info and talking about an issue enterprises would care more about than an average end use12:18
LegNeator12:18
NikkiATypically monitor the minutes from https://wiki.mozilla.org/WeeklyUpdates and look for schedules to find out about when to expect a release12:18
hrosikgetting email pushed into mailbox is way easier than to pull blogs12:19
LegNeatohttp://blog.mozilla.com/channels/12:20
JeremyDYoungLegNeato: I agree this is EWG related, but maybe not the highest on everyone's concern list.12:20
LegNeatohttps://wiki.mozilla.org/Releases/12:20
stormyI think it is very much EWG related12:20
stormyWe are here partially because people were surprised by rapid release.12:21
stormyAnd didn't have a chance to give feedback and participate in the conversations.12:21
JeremyDYounghrosik: RSS readers are technology everyone in this group should be familiar with and using in my opinion.12:23
LegNeatohttps://wiki.mozilla.org/RapidRelease/Calendar12:24
walickithat wasn't me12:24
LegNeatoFYI, that page ^^ has release dates into the future12:24
glazou objects to what Christian said : people don't have the time to test a version every weeks anyway...12:25
glazou6 weeks12:25
kevbeta and aurora channel builds can be downloaded from http://www.mozilla.org/en-US/firefox/channel/12:25
JeremyDYoungWeb Developers can realistically be using Aurora, select users could be using Beta, (maybe non web developer and savvy IS users)12:26
LegNeatoglazou: We know it's hard, but with less changes, more documented, and predictable development schedules and steps we think it's doable (but still recognize it is hard)12:26
hrosikJeremyDYoung: email is still easier to work with - consider the legacy tools in some environments. it's a safe fallback12:26
glazouLegNeato: I don't call potential breakage of binary compat for add-ons every 6 weeks "doable", sorry ; my customers don't call that doable either12:27
LegNeatoglazou: For example, when we told the AV vendors about this they said no way, their dev cycles were 6-8 months. They have pivoted and have been tracking the 6 week releases (not 100% but close and getting better)12:27
Wes--EWG is good, but not wide enough -- sysadmins etc are not on EWG because they don't see themselves as part of the "working group"12:27
mkaplyglazou: potential breakage? you mean breakage. It will break.12:27
glazouLegNeato: AV?12:27
JeremyDYoungStormy: Getting notices on the EWG would be beneficial, but a Security Related Advanced release notification channel would be ideal.12:27
LegNeatoglazou: antivirus vendors12:27
glazouLegNeato: they are in the computer industry !!!! think outside !12:28
LegNeatomkaply, glazou: The only add-ons that will for sure break are binary addons, and usually it is just a recompile12:28
walickiThat is a different John.12:28
glazouLegNeato: my customers for add-ons are car manufacturer, telcom companies12:28
LegNeatoglazou: If they rely on js-ctypes or strictly js add-ons there should generally be no problem12:28
stormywalicki, John O'Duinn12:28
mkaplyLegNeato: Understand, but glazou was talking about binary compat.12:29
LegNeatoglazou: Do you use binary components? (I know you are well versed in mozilla stuff :-) )12:29
glazouno they all really on xpcom-based binary add-ons over proprietary dlls; js-ctypes are not enough for them12:29
glazouLegNeato: yes12:29
LegNeatoah12:29
walickiright - I was trying identifying voices12:29
glazouLegNeato: we all said it multiple time ; js-ctypes are not enough...12:29
stormywalicki, I agree. I've been thinking about typing "<so and so> speaking" every time a new person speaks ...12:30
mkaplyglazou: part of that issue is I don't think anyone has a good sense of how many companies are depending on mozilla technology internally.12:30
LegNeatoglazou: We've been talking about a stable binary api...notice plugins have no issues because the NPAPI is stable...12:30
mkaplyThe killing of remote XUL showed how important this is12:30
glazoumkaply: agreed ; but we tried to say it multiple times...12:30
kev will post his12:30
LegNeatomkaply: Yeah, that showed us that many people who rely on our technologies don't follow our development12:31
kev(calendar)12:31
mkaplyAs Mozilla moves farther away from considering Firefox/Mozilla as a development platform and more as just a web browser, that will keep happening12:31
glazouand that will kill the ecosystem12:31
Wes--speaker++12:31
mkaplyLegNeato: No, it showed that Mozilla doesn't have a sense of how people use their technology12:31
dabHow do we report possible infected Mozilla Firefox distribution sites - mozilla.petsads.us/firefox/releases/3.6.22/update/win32/en-us was blocked by Sophos AV yesterday.12:31
JeremyDYoungmkaply: I agree, Enterprises consider the browser an application deployment platform.12:32
Wes--speaker, closer to mic12:32
joduinn-mtgkev: super hard to hear you12:32
usul|phoneI've lost sound12:32
kevthat may be my lovely pbx12:32
glazouhey, xulrunner exists too.. it's not only the browser ; a LOT of companies build upon it12:32
rsdab: a bug report would be the best way12:32
LegNeatomkaply: Also, deprecations and removals were generally "random" and people shoehorned them in because they didn't want to be stuck another year with the tech12:32
mkaplyLegNeato: Well, it's more that people created solutions that depended on Mozilla technology and then that technology went away.12:33
Wes--and spidermonkey! ;)12:34
LegNeatomkaply: The new process they are more deliberate and we're coming up with guidelines such as "must throw a warning for 2 releases, must be messaged in x ways, must take y proactive steps to get impact data, etc"12:34
JoelGB joined the channel12:34
JeremyDYoung<redacted> can barely get a new version deployed to all Stores in a 6 week period.12:34
LegNeatoJeremyDYoung: I'm really curious why....validation? the actual rollout?12:35
mj joined the channel12:35
LegNeato can imagine but wants to hear directly with actual current times and what you think is the best case you could roll out12:36
glazouJeremyDYoung: my <redacted> customer is in same situation ; very heavy-weight app based on gecko, deployed to all <redacted>12:36
usul|phoneI think community can help with :12:36
usul|phone1) testing12:36
usul|phone2) feedback12:36
usul|phoneI don't see how the community could maintain patches and a branch without mozilla employee following things12:37
JeremyDYoungLegNeato: A large combination of things. 1) QA testing for a week or so 2) bundling and queueing of the actual deployment 3) deployment to a small subset of stores12:37
mkaplyglazou: but do they even need to upgrade? Near as I can tall, Lowe's is in the same situation. When I look at their machines, they are running an old old Mozilla release (preseamonkey).12:37
glazouyes they do, they rely on web services and then security does matter12:37
hrosikwell, I don;t think, we could release beta version to our enterprise customers12:37
NikkiALegNeato we have the same issue with deployment as <redacted> as Firefox is not the only application being deployed within our company.12:37
LegNeatousul|phone: we're not talking abut 100% community12:37
LegNeatohrosik: So you are saying you need to wait for a release and *then* qualify?12:38
hrosikLegNeato: mostly12:38
hrosikwe coould probably start our QA with a late beta12:38
hrosikLegNeato: but releasing beta is a no-go even from marketing POV12:38
JeremyDYoungLegNeato: Then we tier out the deployment to larger numbers of <redacted> in a few more phases. Bandwidth is a concern for the speed of that deployment inside our private network.12:38
mkaplyhrosik: But you can't qualify. Typically you have to qualify on an official release.Because you never know why might change in the end.12:38
LegNeatoJeremyDYoung: Ok, this is great feedback12:39
bhearsummkaply: haven't we committed to _not_ changing at that stage?12:39
hrosikmkaply: yes, but betas are reasonably stable12:39
bhearsumwe will *not* ship a release rather than change it in that way, as i understand it12:39
LegNeatomkaply, hrosik: You are thinking about the old process...new process is more like RCs12:39
glazouq+12:39
JeremyDYounghrosik / LegNeato: Actually, we wait for the version that SLES 10 puts out first, and then we can start our testing process.12:39
glazouwe need a question queue here12:39
glazoulike Zakim on irc.w3.org12:40
mkaplyLegNeato: I understand the new process, but if you find a show stopper 1 day before, you'll fix it. And it might break something else. It's software12:40
LegNeatomkaply: The process is structured for that to not happen. If it does, we plug the hole and it never happens that way again12:40
bhearsumLegNeato: and we're not going to make changes that we know break things at that late stage, right?12:41
LegNeatoglazou: Good idea12:41
LegNeatobhearsum: Correct12:41
kev takes note to add qq12:41
kevdoes anyone have any concerns with posting the channel log to the minutes? I can anonymize nicks if needed12:42
JoelGBno problem12:42
LegNeatothe changes in the beta are *more* restricted than changes between 3.6.13 adn 3.6.14 (for example)12:42
glazoukev: np12:43
mkaplyre: irc log - no prob from me12:43
NikkiAkev More concerned about making sure company name is anonymized than nicks12:44
kevkk12:44
mkaplyyeah, I was thinking the same thing. Remove the intros at the beginning.12:44
glazoukev: do you my changes to your minutes of my own prose?12:45
glazoudo you see12:45
JeremyDYoungkev: Any company names removed, yes, please.12:45
JeremyDYoungStormy: Yes, I'd like to discuss the possibility of reducing the time of LTS "lives" over multiple releases.12:46
JoelGBi seriously doubt my company will ever want rapid release12:46
mkaplyPlus 3.6 still has extension compatibility12:46
glazouI have never seen a large company validate a new browser version in less than 4 months...12:47
Wes--JoelGB: Question, why would your company want to tie itself to a single vendor's browser?12:47
mkaplyI can't picture why any company would want rapid release. Noone wants to deploy a new browser in their company every six weeks. They might have to, but they don't want to.12:47
mkaplyHeck, I'm already tired of getting new browsers at home.12:47
glazouWes--: because of intranet apps12:47
JeremyDYoungWes-- : It's an application development platform. IE has plenty of examples of why we wouldn't want to make internal applications work across multiple browsers.12:47
Wes--glazou: intranet apps can't use web standards?12:47
JeremyDYoungWes--: That's rather trite.12:48
glazouWes--: intranet apps VERY rarely use _only_ web standards...12:48
JoelGBWes--: we aren't tied to one browser. but we do have a default/supported browser.12:48
Wes--JeremyDYoung: IE is exactly the example why you want internal apps running on multiple browesrs12:48
glazou reminds Wes-- he is co-chair of a W3C WG12:48
mkaplyWes--: They could going forward, but we're dealing with the past here.12:48
hrosikhalf of the anti-rapid release feelings is because of the vast perceived changes in numbers. it's just scary for anyone who doesn't see that it is more like 4.2 4.3 4.5...12:48
Wes--glazou: Didn't know that, but point stands -- are MOST enterprises running non-web-standards apps because they have no choice, or because they are only testing on one platform?12:48
JeremyDYoungWes--: Intranet applications live for many years with no modifications. Web Standards change.12:48
glazouWes--: because they have no choice, usually12:48
mkaplyWes--: Especially as it relates to third party software.12:49
glazouthey contract a service company to write an app12:49
Wes--JeremyDYoung: web standards tend to evolve non-breakingly, and that is more and more true now than ever12:49
glazouthat company focuses on a single browser12:49
JeremyDYoungWes--: Just getting CSS to work across Firefox and IE is usually uselessly expensive.12:49
glazouand they use ALL of it12:49
glazouincluding what's non-standard12:49
JeremyDYoungWes--: So we just told users to use Firefox.12:49
Wes--glazou: "that company focuses on single browser" -- this is the problem, we need to change this as a community on a go-forward basis12:49
glazounon software companies don't understand web standards12:49
Wes--JeremyDYoung: We pick multiple standards-compliant browsers. Chrome, Opera, Safari, Firefox. If IE doesn't work, there's lots to chose from.12:50
JoelGBWes--: also, my company doesn't want to pay me every 6 weeks to test and deploy a full released version12:50
kevstormy: 10 minute warning12:50
glazouWes--: you just can't tell real industry companies how they work… a second of software error can cause millions of dollars of loss12:50
JeremyDYoungWes--: Yes, but we can't just jump from where we are to fully web standard supported in any reasonable time frame.12:50
joduinn-mtgglazou: 100% agreed12:50
Wes--JoelGB: That's the whole point: you don't test that it works with browser X, you develop to conform to standard Y and choose browser Z which supports it12:50
glazouWes--: no12:50
glazouWes--: they need a feature12:51
mkaplyWes--: And that sounds great in a world where someone is developing all their products from scratch tomorrow.12:51
glazouthe conformance to open standards is a luxury12:51
glazouand they don't care12:51
JeremyDYoungWes--: Web standards are a nice theory, but it has to look exactly right in the browsers that we use.12:51
glazouthey run a business, not a conformance bureau12:51
dabIf the EWG requested Windows MSI based installers under the rapid release program, what is the soonest version/date when this would be ready?12:51
NikkiAWhile it seems all well and nice to hope for all web apps to be up to web standards but its just not reality.12:51
JoelGBWes--: I don't devolope anything. I install and maintain software for my company. All the higher ups care about is that the software we have works. They don't care what standards it's developed with.12:52
Wes--JoelGB: do the developers care?12:52
JeremyDYoungStormy: Enterprises expect their software developers to guarantee that those security updates don't break their company's desktops.12:53
JoelGBWes--: I don't know, I don't talk to most of them, as a small company, we purchase most of our internal applications12:53
mkaplyIf you have a company that has their entire line of business app in Excel (which exist), you stay on the version of Office that works. You don't upgrade.12:53
LegNeatodab: Not sure12:53
dabI think the MS Office example is incorrect, Microsoft releases security patches 2nd Tue, other non security updates 4th tuesday if needed (1x per quarter).12:53
usul|phoneDaniel you are forgetting windows : one release a month - but in the enterprise admins decide when they do it.12:54
JeremyDYoungspeaker: Major may not be the right word -- It's just whether there are new features present.12:54
glazouusul|phone: msft issues fixes, not major versions of windows...12:54
LegNeatoJeremyDYoung: The idea of the new release is we're not sure what is in it until it is done on the Aurora channel12:54
Rami joined the channel12:54
NikkiAdab Office example does apply as you would still apply security updates but wouldn't update its version (example 2003 to 2007 or 2010)12:55
KristiBThank you for supporting FF 3.6 in near term - very helpful as a stop gap - I would prefer to move everyone to latest FF and sunset it as you suggest when it makes sense for us - let us know where to respond on LTS idea12:55
kevjoduinn-mtg: big issue is difference between a point release and major release12:55
glazoujoduinn-mtg: I can remain on IRC to discuss that12:55
kevour versioning makes it difficult there12:55
kevstormy: nothing from me12:55
JeremyDYoungLegNeato: It may be possible for Enterprises to trust the testing channels that Mozilla uses in the future, but there's no way to jump into that level of trust without some sort of easing into it over time.12:55
glazoukev: I still don't know if you caught my changes to the minutes12:56
JeremyDYoungLegNeato: Not to mention, 3rd party software vendors have to be on board with the rapid release process as well.12:56
mkaplyThe choice of the term "Beta" might not have been the best choice either. You're basically saying your betas are release candidate, which I understand, but I doubt most people do12:56
kevI did! they were orange12:56
kevand were appreciated12:56
glazoucool12:56
glazounp12:56
JeremyDYoungThank you Stormy.12:56
NikkiA3rd party add-on and plugins getting on board really are what holds things back12:56
joduinn-mtgthanks stormy12:56
Wes--kev: LTS versioning could work like Firefox 7 Enterprise Edition, Service Release 2011 09 1612:56
LegNeatoJeremyDYoung: If we bumped you up to Fx8 or whatever with an undefined later plan (like we are now but not 3.6-based) would you move to Fx8?12:57
glazoujoduinn-mtg: let's stay here to discuss?12:57
Wes--or12:57
LegNeatoor would you sit back and wait until the "real" plan12:57
joduinn-mtgglazou: sure12:57
joduinn-mtg has a few mins before next meeting, but yes, please12:57
glazouwhat do you want to know (re. my experience at electricté de france)12:57
kevWes--: yeah, I was more pointing out that one of the problems is how we version software, and what it means for support given policies12:58
JeremyDYoungLegNeato: Yes, if you said to us "Mozilla is going to now treat Firefox 8.0.x the same way as 3.6.x and release security updates until there is a new option." We would change to 8.012:58
joduinn-mtgglazou: 1) thanks, I knew as I was speaking that I was getting the organization-name wrong. Sorry about that.12:58
glazouJeremyDYoung: no, we would consider changing to 8.0, and that's entirely different12:58
kevok, I am cutting log... here12:58
glazoujoduinn-mtg: aaaah those froggies :-)12:58
hrosikLegNeato: linux distributions are likely to stick to a LTS version as well12:58
dabI agree, if 8.0 would be the next interm successor to 3.6 I would consider upgrading as well.12:58
LegNeatoJeremyDYoung: That is interesting feedback. I expected most people to not want to (as there is likely effort to move from 3.6 -> Fx8 or whatever) and depending on the future plan the effort may be wasted12:59
LegNeatodab: good to know as well12:59
nashibq quit IRC (Quit: CGI:IRC (Ping timeout))12:59
mj left the channel ()12:59
JoelGBJeremyDYoung: and correct me if I am wrong, but wouldn't your company then spend 1-2 weeks testing/validating/rolling out 8.0 ?12:59
JeremyDYoungWe probably wouldn't go to 8.0 the day that it moved from the Beta channel :)12:59
joduinn-mtg2) apart from firefox browser, what other software does your enterprise have to support - other browsers? other software like MSOffice? desktop OS?12:59
LegNeatoglazou: Would you move your clients up to Fx 8 or whatever if we said it was the new "stogap" release ?12:59
JeremyDYoungJoelGB, yes, probably 4-6 weeks for everything.12:59
dabAny suggestion on how much notice will be given before 3.6 is declared EOL?12:59
[1:00] <LegNeato> JeremyDYoung: Would the 6 weeks in aurora and the 6 weeks in beta allow you to move to Fx8 or whatever in time?
[1:00] <glazou> LegNeato: as I said, I would consider it ; BUT it would still require testing/qualification of the final 8.0...
[1:00] <JoelGB> JeremyDYoung: just verifying that. We are in that same boat.
[1:00] <JeremyDYoung> glazou: Yes, we would be certifying 8.0.0 RELEASE version, not Beta at this point.
[1:00] <glazou> JeremyDYoung: the question is not 8 or 7 or 9, the question is how many times per year...
[1:00] <joduinn-mtg> ...and for those software vendors, how do you deal with them sending updates? Do you have to reverify each update from each vendor?
[1:01] <joduinn-mtg> glazou: make sense?
[1:01] <LegNeato> yes, I am really curious how a 3.6 stopgap -> 6+ stopgap cutover would be handled by everyone
[1:01] <glazou> joduinn-mtg: OS, all productivity (office, etc.), control command SW (proprietary), access to all intranet apps

Generated by irclog2html.py 2.9.2 by Marius Gedminas - find it at mg.pov.lt!