[Bug 2037567] Re: mantic kernel 6.5.0.1006 Adds io_uring apparmor feature
Launchpad Bug Tracker
2037567 at bugs.launchpad.net
Wed Jan 17 11:44:47 UTC 2024
This bug was fixed in the package livecd-rootfs - 2.765.34
---------------
livecd-rootfs (2.765.34) jammy; urgency=medium
* Remove comments in the debian/control dependencies as it was causing the
package build to fail.
livecd-rootfs (2.765.33) jammy; urgency=medium
[ Steve Langasek ]
* Use losetup instead of kpartx to resolve race conditions in riscv64
image builds. LP: #2045797.
[ Utkarsh Gupta ]
* unminimize: Use lxd-installer to install LXD itself (LP: #2036725)
livecd-rootfs (2.765.32) jammy; urgency=medium
[ Heinrich Schuchardt ]
* arm: fix console parameter for ARM cloud-images (LP: #2036730)
livecd-rootfs (2.765.31) jammy; urgency=medium
[ John Chittum ]
* fix: add 6.5 kernel apparmor features to livecd-rootfs based on
features of 6.5 in ubuntu/mantic. This will roll as HWE. (LP: #2037567)
livecd-rootfs (2.765.30) jammy; urgency=medium
* Enable snap preseeding with ppc64el images where /boot/vmlinux is used
instead of /boot/vmlinuz. (LP: #2038957)
livecd-rootfs (2.765.29) jammy; urgency=medium
[ Steve Langasek ]
* The chroot tmpfs mount should only be /var/lib/apt/lists, not
/var/lib/apt; the latter breaks changes to /var/lib/apt/extended_states.
(LP: #2036195).
livecd-rootfs (2.765.28) jammy; urgency=medium
* Fix unminimize to correctly list packages. (LP: #1996489)
* Install LXD snap from stable/ubuntu-<version> channel. (LP: #2036725)
livecd-rootfs (2.765.27) jammy; urgency=medium
[ Thomas Bechtold ]
* Do not modify /etc/ssh/sshd_config for ubuntu-cpc
project builds (LP: #1968873)
-- Ćukasz 'sil2100' Zemczak <lukasz.zemczak at ubuntu.com> Mon, 15 Jan
2024 16:41:18 +0100
** Changed in: livecd-rootfs (Ubuntu Jammy)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Foundations Bugs, which is subscribed to livecd-rootfs in Ubuntu.
https://bugs.launchpad.net/bugs/2037567
Title:
mantic kernel 6.5.0.1006 Adds io_uring apparmor feature
Status in livecd-rootfs package in Ubuntu:
Fix Released
Status in livecd-rootfs source package in Jammy:
Fix Released
Bug description:
starting with kernel package(s) 6.5.0.1006, currently in mantic-
proposed, `io_uring` is added as a apparmor feature. This change
results in preseeded snaps being unoptimized, as the mounted apparmor
features in the chroot do not match the 6.5.0.1006 kernels. On a
system running with the kernel
cat /sys/kernel/security/apparmor/features/io_uring/mask
sqpoll override_creds
1. ensure that this is correct with kernel and security teams
2. ~~ensure that this is the default going forward~~ : Create a 6.5 feature directory as it was pointed out by xnox that Mantic has more than 6.5 kernels at this time.
if 1 and 2, then set the default in `livecd-rootfs` for mounted
apparmor features to include io_uring
SRU [Jammy]
====
[ Impact ]
* Users of the 6.5 kernel will have un-optimized first boot
experiences due to snaps not preseeding with the correct apparmor
setup. This directly affects clouds, leading to boot speed degradation
of anywhere from 10-30s (depending on snaps installed)
[ Test Plan ]
* Create images with livecd-rootfs:ubuntu/jammy with the SRU'd change (the 6.5 directory in live-build/apparmor)
* image must use an "edge" kernel or another forward pointing kernel as the HWE and cloud kernels have not rolled yet.
* boot image(s)
* check `snap debug seeding`. This should show successful seeding
* if a long json output is observed, check the restart-key to see what features are missing. compare to 6.5 in ubuntu/master. check with security, apparmor, and kernel teams
[ Where problems could occur ]
* If there is a difference in rules of 6.5 in mantic and 6.5 being released to Jammy
*
[ Other Info ]
* testing may be difficult, as we're trying to catch this before it lands. the codepath selecting kernel version is stable, so adding the configuration area should be safe, even if testing is not easily possible.
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/2037567/+subscriptions
More information about the foundations-bugs
mailing list