[ubuntu/resolute-proposed] snapd 2.77.1+ubuntu26.04.2 (Accepted)
Ernest Lotter
ernest.lotter at canonical.com
Wed Oct 7 13:15:30 UTC 2026
snapd (2.77.1+ubuntu26.04.2) resolute; urgency=medium
* New upstream release, LP: #2158102
- Fix undo of unlink-component after its snap revision was discarded
- interfaces: power-control | allow reading all battery state files
- fix 26.04+ snapd deb versioning
snapd (2.77+ubuntu26.04) resolute; urgency=medium
- Account for differences in names of the binaries in the snapd FIPS
build
- Add code to calculate canonical subject name hash
- Add commands for debugging or accessing snap mount namespaces
- Add helpers for listing and iterating device mediation groups
- Add package ebpf with helpers wrapping eBPF exposed objects with
dependency on github.com/cilium/ebpf
- Add secondary prerequisites task that acts as the synchronization
point, which ensures that a snap's prerequisites are available
before it's installed
- Add support for shell conditional syntax in envs
- Added /usr/share/{man,help,info} to system-packages-doc
- asserts: add validation-sets confdb-schema builtin
- asserts: ensure that compatibility labels are strings
- asserts: extend on-classic constraints to accept "distro/variant",
"distro/*", and "distro/" under a new snap-declaration format 7
- asserts: validate serial in newDeviceIDFromString
- Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for
efivars probe
- confdb: add validation-sets handler and fix data loss when writing
to new schemas or accounts
- confdb: fix bug on reading uneven lists
- confdb: literal subkeys are sorted after placeholders
- confdb: run observe-view-* hooks after commit
- confdb: support Encode/Decode for builtins
- confdb: support sign-only external keypair backends
- core-initrd: add missing libbpf and systemd dlopen dependencies,
and increase mount burst
- Drop task logs for delayed effects
- During snap removal, clear-snap task errors early if there are
user mounts in snap data dirs
- Enable reverts to trigger a seed refresh
- Ensure profiles are setup before running prepare-{slot, plug}*
hooks
- Ensure that prereqs created by initial refresh run before create-
recovery-system
- Exclude Georgian from translation linting
- experimental features: graduate layouts, classic-preserves-xdg-
runtime-dir, refresh-app-awareness, and dbus-activation features
- experimental features: warn when setting graduated or default-
enabled experimental features and do not store settings for
graduated features
- Expose individual certs as well as c_rehash emulation
- Extend autogen with explicit --sysconfdir
- External keypair manager: add shared external key manager
implementation
- External keypair manager: refactor GPG and external keypair
managers to use extKeypairMgrImpl
- External keypair manager: support external OPENPGP signing in
ExternalKeypairManager
- FDE: add post install actions API
- FDE: add reprovision API
- FDE: add reprovision recovery key generation API
- FDE: add reseal check after snapd refresh
- FDE: allow reprovision without factory reset
- FDE: change makebootable part of the boot package to not take
install observers as parameters
- FDE: extend storage-encrypted system information
- FDE: make reprovision only seal
- FDE: remove all tmp keyslots on error
- FDE: remove check for unchanged authentication options
- FDE: run post install checks during auto repair
- Filter seed-refresh based on model and seed presence
- Fix failing snap remove when there are snapctl created mounts
under snap global data dirs
- Fix postNotices to validate before locking state
- Guard the ensure check from running on classic
- Implement remodeling fully in terms of updates
- Implement ShutDown for HookManager
- Include variables SNAP_APP_NAME, and when applicable
SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in
snap application environments
- interfaces: add xdg-portal-permission-store interface
- interfaces: allow gtk css in subdirectories
- interfaces: allow systemd networkd link property changes via D-Bus
- interfaces: allow the systemd networkctl command
- interfaces: allow Wine to execute files accessed via the Document
Portal
- interfaces: apparmor-observe | add interface
- interfaces: attempt to fix content with parallel installs
- interfaces: devlxd | fix access for LXD containers
- interfaces: docker | allow connecting to system-wide docker on
classic
- interfaces: grant default access to memory.high in a snap's cgroup
- interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes
- interfaces: kernel-sched-ext-control | add the kernel sched-ext
control interface implementation
- interfaces: make polkit and upower implicit on Core systems only
- interfaces: open-iscsi | add missing state paths
- interfaces: opengl | expose wsl libraries
- interfaces: u2f-devices | add atkey PID and relative VID support
- List dir contents on failure to remove snap base data dir
- List non-snapctl mounts in snap data dirs
- LP: #2072331 Validate map keys in JSON config values
- LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup
- LP: #2143934 Interfaces: network-control, network-manager | allow
missing resolve1 link setters
- LP: #2160691 Security logging: strip trailing whitespace from
audit netlink message payload
- LP: #2161982 Interfaces: vsock | add interface for VM guest
services
- Make arguments of debug mount-namespace consistent with other
debug commands
- Make bootloader logging less verbose
- Make cert manager garbage check run after symlink migration
- Make secondary prerequisite synchronization task handle same-
change retries
- mkversion.sh: do describe in worktrees too
- multi-entry snapd: merge snap and snapd binaries
- multi-entry snapd: move debug device-cgroup implementation file
under cmd/snapd/cli
- multi-entry snapd: move snap-gpio-helper sources around before
transitioning to multi-entry dispatch
- multi-entry snapd: move snapd-apparmor sources to a dedicated tool
location
- multi-entry snapd: move source files around in preparation for
snapd/snap merge
- multi-entry snapd: move the snap-preseed sources around in
preparation
- multi-entry snapd: move the sources of snapctl and snap-exec in
preparation for the multi-entry dispatch
- Never create seed refresh tasks during a remodel
- packaging: assign a default label for /tmp/snap-private-tmp and
set it during installation
- packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for
focal
- packaging: drop SNAP_TAGS
- packaging: drop symlinks for opensuse 15.5/15.6 packaging
- packaging: fix service startup during install and session-agent
socket handling on Ubuntu 26.04+
- packaging: fix stderr redirection
- packaging: restore gbp.conf output directory for Ubuntu 26.04
builds
- packaging: switch to apparmor 5.x with 5 ABI
- packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI
when running as deb
- packaging: use a relative symlink for snapctl and update steam-
support udev rules
- Preserve component in hook security tags
- Prevent removal of seed-refresh snaps when seed-refresh is enabled
- Refactor base-declaration into 1st class builtin assertion
- Refactor how the is-originating-from-snap-command advisory check
works
- Refactor prerequisites task handler to enable proper seed-refresh
integration
- Reintroduce fdstore helpers
- remote device management: add task to validate request messages
- remote device management: apply management messages, queue
response messages, and improve sequencing and redelivery handling
- Remove osutil unused AtomicWriteFollow flag
- Remove xerrors dependency
- Reuse existing seed-refresh implementation for free during single-
path installation
- Rework how SnapSetup.SnapPath is used
- seccomp: allow rseq_slice_yield
- security logging: add seclog API for administrative actions and
token create/remove events
- security logging: add security logging for adding, updating and
removing a snapd user
- Set target hostname from install-mode
- snap-confine: improve loading of BPF programs, retry on failures
to collect verifier logs
- snap-confine: use profile and flags= in snap-confine and snap-
update-ns' AppArmor profiles
- snap-confine: work around kernel mnt_ns_loop() ordering bug on
6.18.x
- snap: add debug command for listing currently mediated devices for
a given snap
- snap: fix self-managed cgroup support checks
- snap: report hidden file access for paths allowed by home when
prompting is active
- snap: report read-only file access for paths allowed by system-
package-doc
- snapctl async support: add --format json to snap tasks to be
consistent with snapctl
- snapctl async support: add snapctl tasks command
- snapctl async support: async feature negotiation between snap
client and daemon
- snapctl async support: fix snapctl is-ready exit codes
- snapctl async support: re-enable snapctl async functionality
- snapshots: restore preserves snapctl created mounts
- snapshots: save excludes all mount points
- Support ca-certificate.crt only systems like core26
- Turn on quota-groups by default
- Use 0755 for certificate generation directories
- Use CreateTemp for NewAtomicFile tmp file creation
- Verify cached downloads in the do path and detect obvious
corruption
Date: Wed, 02 Sep 2026 14:39:12 +0200
Changed-By: Ernest Lotter <ernest.lotter at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Graham Inggs <graham.inggs at canonical.com>
https://launchpad.net/ubuntu/+source/snapd/2.77.1+ubuntu26.04.2
-------------- next part --------------
Format: 1.8
Date: Wed, 02 Sep 2026 14:39:12 +0200
Source: snapd
Built-For-Profiles: noudeb
Architecture: source
Version: 2.77.1+ubuntu26.04.2
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Ernest Lotter <ernest.lotter at canonical.com>
Launchpad-Bugs-Fixed: 2072331 2110510 2143934 2158102 2160691 2161982
Changes:
snapd (2.77.1+ubuntu26.04.2) resolute; urgency=medium
.
* New upstream release, LP: #2158102
- Fix undo of unlink-component after its snap revision was discarded
- interfaces: power-control | allow reading all battery state files
- fix 26.04+ snapd deb versioning
.
snapd (2.77+ubuntu26.04) resolute; urgency=medium
.
- Account for differences in names of the binaries in the snapd FIPS
build
- Add code to calculate canonical subject name hash
- Add commands for debugging or accessing snap mount namespaces
- Add helpers for listing and iterating device mediation groups
- Add package ebpf with helpers wrapping eBPF exposed objects with
dependency on github.com/cilium/ebpf
- Add secondary prerequisites task that acts as the synchronization
point, which ensures that a snap's prerequisites are available
before it's installed
- Add support for shell conditional syntax in envs
- Added /usr/share/{man,help,info} to system-packages-doc
- asserts: add validation-sets confdb-schema builtin
- asserts: ensure that compatibility labels are strings
- asserts: extend on-classic constraints to accept "distro/variant",
"distro/*", and "distro/" under a new snap-declaration format 7
- asserts: validate serial in newDeviceIDFromString
- Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for
efivars probe
- confdb: add validation-sets handler and fix data loss when writing
to new schemas or accounts
- confdb: fix bug on reading uneven lists
- confdb: literal subkeys are sorted after placeholders
- confdb: run observe-view-* hooks after commit
- confdb: support Encode/Decode for builtins
- confdb: support sign-only external keypair backends
- core-initrd: add missing libbpf and systemd dlopen dependencies,
and increase mount burst
- Drop task logs for delayed effects
- During snap removal, clear-snap task errors early if there are
user mounts in snap data dirs
- Enable reverts to trigger a seed refresh
- Ensure profiles are setup before running prepare-{slot, plug}*
hooks
- Ensure that prereqs created by initial refresh run before create-
recovery-system
- Exclude Georgian from translation linting
- experimental features: graduate layouts, classic-preserves-xdg-
runtime-dir, refresh-app-awareness, and dbus-activation features
- experimental features: warn when setting graduated or default-
enabled experimental features and do not store settings for
graduated features
- Expose individual certs as well as c_rehash emulation
- Extend autogen with explicit --sysconfdir
- External keypair manager: add shared external key manager
implementation
- External keypair manager: refactor GPG and external keypair
managers to use extKeypairMgrImpl
- External keypair manager: support external OPENPGP signing in
ExternalKeypairManager
- FDE: add post install actions API
- FDE: add reprovision API
- FDE: add reprovision recovery key generation API
- FDE: add reseal check after snapd refresh
- FDE: allow reprovision without factory reset
- FDE: change makebootable part of the boot package to not take
install observers as parameters
- FDE: extend storage-encrypted system information
- FDE: make reprovision only seal
- FDE: remove all tmp keyslots on error
- FDE: remove check for unchanged authentication options
- FDE: run post install checks during auto repair
- Filter seed-refresh based on model and seed presence
- Fix failing snap remove when there are snapctl created mounts
under snap global data dirs
- Fix postNotices to validate before locking state
- Guard the ensure check from running on classic
- Implement remodeling fully in terms of updates
- Implement ShutDown for HookManager
- Include variables SNAP_APP_NAME, and when applicable
SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in
snap application environments
- interfaces: add xdg-portal-permission-store interface
- interfaces: allow gtk css in subdirectories
- interfaces: allow systemd networkd link property changes via D-Bus
- interfaces: allow the systemd networkctl command
- interfaces: allow Wine to execute files accessed via the Document
Portal
- interfaces: apparmor-observe | add interface
- interfaces: attempt to fix content with parallel installs
- interfaces: devlxd | fix access for LXD containers
- interfaces: docker | allow connecting to system-wide docker on
classic
- interfaces: grant default access to memory.high in a snap's cgroup
- interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes
- interfaces: kernel-sched-ext-control | add the kernel sched-ext
control interface implementation
- interfaces: make polkit and upower implicit on Core systems only
- interfaces: open-iscsi | add missing state paths
- interfaces: opengl | expose wsl libraries
- interfaces: u2f-devices | add atkey PID and relative VID support
- List dir contents on failure to remove snap base data dir
- List non-snapctl mounts in snap data dirs
- LP: #2072331 Validate map keys in JSON config values
- LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup
- LP: #2143934 Interfaces: network-control, network-manager | allow
missing resolve1 link setters
- LP: #2160691 Security logging: strip trailing whitespace from
audit netlink message payload
- LP: #2161982 Interfaces: vsock | add interface for VM guest
services
- Make arguments of debug mount-namespace consistent with other
debug commands
- Make bootloader logging less verbose
- Make cert manager garbage check run after symlink migration
- Make secondary prerequisite synchronization task handle same-
change retries
- mkversion.sh: do describe in worktrees too
- multi-entry snapd: merge snap and snapd binaries
- multi-entry snapd: move debug device-cgroup implementation file
under cmd/snapd/cli
- multi-entry snapd: move snap-gpio-helper sources around before
transitioning to multi-entry dispatch
- multi-entry snapd: move snapd-apparmor sources to a dedicated tool
location
- multi-entry snapd: move source files around in preparation for
snapd/snap merge
- multi-entry snapd: move the snap-preseed sources around in
preparation
- multi-entry snapd: move the sources of snapctl and snap-exec in
preparation for the multi-entry dispatch
- Never create seed refresh tasks during a remodel
- packaging: assign a default label for /tmp/snap-private-tmp and
set it during installation
- packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for
focal
- packaging: drop SNAP_TAGS
- packaging: drop symlinks for opensuse 15.5/15.6 packaging
- packaging: fix service startup during install and session-agent
socket handling on Ubuntu 26.04+
- packaging: fix stderr redirection
- packaging: restore gbp.conf output directory for Ubuntu 26.04
builds
- packaging: switch to apparmor 5.x with 5 ABI
- packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI
when running as deb
- packaging: use a relative symlink for snapctl and update steam-
support udev rules
- Preserve component in hook security tags
- Prevent removal of seed-refresh snaps when seed-refresh is enabled
- Refactor base-declaration into 1st class builtin assertion
- Refactor how the is-originating-from-snap-command advisory check
works
- Refactor prerequisites task handler to enable proper seed-refresh
integration
- Reintroduce fdstore helpers
- remote device management: add task to validate request messages
- remote device management: apply management messages, queue
response messages, and improve sequencing and redelivery handling
- Remove osutil unused AtomicWriteFollow flag
- Remove xerrors dependency
- Reuse existing seed-refresh implementation for free during single-
path installation
- Rework how SnapSetup.SnapPath is used
- seccomp: allow rseq_slice_yield
- security logging: add seclog API for administrative actions and
token create/remove events
- security logging: add security logging for adding, updating and
removing a snapd user
- Set target hostname from install-mode
- snap-confine: improve loading of BPF programs, retry on failures
to collect verifier logs
- snap-confine: use profile and flags= in snap-confine and snap-
update-ns' AppArmor profiles
- snap-confine: work around kernel mnt_ns_loop() ordering bug on
6.18.x
- snap: add debug command for listing currently mediated devices for
a given snap
- snap: fix self-managed cgroup support checks
- snap: report hidden file access for paths allowed by home when
prompting is active
- snap: report read-only file access for paths allowed by system-
package-doc
- snapctl async support: add --format json to snap tasks to be
consistent with snapctl
- snapctl async support: add snapctl tasks command
- snapctl async support: async feature negotiation between snap
client and daemon
- snapctl async support: fix snapctl is-ready exit codes
- snapctl async support: re-enable snapctl async functionality
- snapshots: restore preserves snapctl created mounts
- snapshots: save excludes all mount points
- Support ca-certificate.crt only systems like core26
- Turn on quota-groups by default
- Use 0755 for certificate generation directories
- Use CreateTemp for NewAtomicFile tmp file creation
- Verify cached downloads in the do path and detect obvious
corruption
Checksums-Sha1:
d81f5783d2f9055ca45f1d4fbfa25a6266ff452a 2378 snapd_2.77.1+ubuntu26.04.2.dsc
a4b03f8264ec53ade76c4ad3dcb4fdb382c240ff 11352640 snapd_2.77.1+ubuntu26.04.2.tar.xz
765cc8e60347e1a2f656cf2d55f42b2f33796b4b 10678 snapd_2.77.1+ubuntu26.04.2_source.buildinfo
Checksums-Sha256:
030f51020b334b1c891d9748c15d44f213a856df7d0b6e00753c5150303ea1a6 2378 snapd_2.77.1+ubuntu26.04.2.dsc
ac79e1fe832b763295721ed4a1e3cd8669b5c67cbd98f95c06703ac95257bb54 11352640 snapd_2.77.1+ubuntu26.04.2.tar.xz
ebce374cfeb113cee19dfed2f6c7cdf1354cd609936e4c0ff94a539add561af7 10678 snapd_2.77.1+ubuntu26.04.2_source.buildinfo
Files:
468f1cf1949222aec976a3f0c857fa98 2378 devel optional snapd_2.77.1+ubuntu26.04.2.dsc
822d06522c5deee99462e797921058e6 11352640 devel optional snapd_2.77.1+ubuntu26.04.2.tar.xz
cd47bc3019d4008fe7d22eab0fcf5869 10678 devel optional snapd_2.77.1+ubuntu26.04.2_source.buildinfo
More information about the Resolute-changes
mailing list