[ubuntu/resolute-proposed] snapd 2.77.1+ubuntu26.04.2 (Accepted)

Ernest Lotter ernest.lotter at canonical.com
Wed Oct 7 13:15:30 UTC 2026


snapd (2.77.1+ubuntu26.04.2) resolute; urgency=medium

  * New upstream release, LP: #2158102
    - Fix undo of unlink-component after its snap revision was discarded
    - interfaces: power-control | allow reading all battery state files
    - fix 26.04+ snapd deb versioning

snapd (2.77+ubuntu26.04) resolute; urgency=medium

    - Account for differences in names of the binaries in the snapd FIPS
      build
    - Add code to calculate canonical subject name hash
    - Add commands for debugging or accessing snap mount namespaces
    - Add helpers for listing and iterating device mediation groups
    - Add package ebpf with helpers wrapping eBPF exposed objects with
      dependency on github.com/cilium/ebpf
    - Add secondary prerequisites task that acts as the synchronization
      point, which ensures that a snap's prerequisites are available
      before it's installed
    - Add support for shell conditional syntax in envs
    - Added /usr/share/{man,help,info} to system-packages-doc
    - asserts: add validation-sets confdb-schema builtin
    - asserts: ensure that compatibility labels are strings
    - asserts: extend on-classic constraints to accept "distro/variant",
      "distro/*", and "distro/" under a new snap-declaration format 7
    - asserts: validate serial in newDeviceIDFromString
    - Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for
      efivars probe
    - confdb: add validation-sets handler and fix data loss when writing
      to new schemas or accounts
    - confdb: fix bug on reading uneven lists
    - confdb: literal subkeys are sorted after placeholders
    - confdb: run observe-view-* hooks after commit
    - confdb: support Encode/Decode for builtins
    - confdb: support sign-only external keypair backends
    - core-initrd: add missing libbpf and systemd dlopen dependencies,
      and increase mount burst
    - Drop task logs for delayed effects
    - During snap removal, clear-snap task errors early if there are
      user mounts in snap data dirs
    - Enable reverts to trigger a seed refresh
    - Ensure profiles are setup before running prepare-{slot, plug}*
      hooks
    - Ensure that prereqs created by initial refresh run before create-
      recovery-system
    - Exclude Georgian from translation linting
    - experimental features: graduate layouts, classic-preserves-xdg-
      runtime-dir, refresh-app-awareness, and dbus-activation features
    - experimental features: warn when setting graduated or default-
      enabled experimental features and do not store settings for
      graduated features
    - Expose individual certs as well as c_rehash emulation
    - Extend autogen with explicit --sysconfdir
    - External keypair manager: add shared external key manager
      implementation
    - External keypair manager: refactor GPG and external keypair
      managers to use extKeypairMgrImpl
    - External keypair manager: support external OPENPGP signing in
      ExternalKeypairManager
    - FDE: add post install actions API
    - FDE: add reprovision API
    - FDE: add reprovision recovery key generation API
    - FDE: add reseal check after snapd refresh
    - FDE: allow reprovision without factory reset
    - FDE: change makebootable part of the boot package to not take
      install observers as parameters
    - FDE: extend storage-encrypted system information
    - FDE: make reprovision only seal
    - FDE: remove all tmp keyslots on error
    - FDE: remove check for unchanged authentication options
    - FDE: run post install checks during auto repair
    - Filter seed-refresh based on model and seed presence
    - Fix failing snap remove when there are snapctl created mounts
      under snap global data dirs
    - Fix postNotices to validate before locking state
    - Guard the ensure check from running on classic
    - Implement remodeling fully in terms of updates
    - Implement ShutDown for HookManager
    - Include variables SNAP_APP_NAME, and when applicable
      SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in
      snap application environments
    - interfaces: add xdg-portal-permission-store interface
    - interfaces: allow gtk css in subdirectories
    - interfaces: allow systemd networkd link property changes via D-Bus
    - interfaces: allow the systemd networkctl command
    - interfaces: allow Wine to execute files accessed via the Document
      Portal
    - interfaces: apparmor-observe | add interface
    - interfaces: attempt to fix content with parallel installs
    - interfaces: devlxd | fix access for LXD containers
    - interfaces: docker | allow connecting to system-wide docker on
      classic
    - interfaces: grant default access to memory.high in a snap's cgroup
    - interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes
    - interfaces: kernel-sched-ext-control | add the kernel sched-ext
      control interface implementation
    - interfaces: make polkit and upower implicit on Core systems only
    - interfaces: open-iscsi | add missing state paths
    - interfaces: opengl | expose wsl libraries
    - interfaces: u2f-devices | add atkey PID and relative VID support
    - List dir contents on failure to remove snap base data dir
    - List non-snapctl mounts in snap data dirs
    - LP: #2072331 Validate map keys in JSON config values
    - LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup
    - LP: #2143934 Interfaces: network-control, network-manager | allow
      missing resolve1 link setters
    - LP: #2160691 Security logging: strip trailing whitespace from
      audit netlink message payload
    - LP: #2161982 Interfaces: vsock | add interface for VM guest
      services
    - Make arguments of debug mount-namespace consistent with other
      debug commands
    - Make bootloader logging less verbose
    - Make cert manager garbage check run after symlink migration
    - Make secondary prerequisite synchronization task handle same-
      change retries
    - mkversion.sh: do describe in worktrees too
    - multi-entry snapd: merge snap and snapd binaries
    - multi-entry snapd: move debug device-cgroup implementation file
      under cmd/snapd/cli
    - multi-entry snapd: move snap-gpio-helper sources around before
      transitioning to multi-entry dispatch
    - multi-entry snapd: move snapd-apparmor sources to a dedicated tool
      location
    - multi-entry snapd: move source files around in preparation for
      snapd/snap merge
    - multi-entry snapd: move the snap-preseed sources around in
      preparation
    - multi-entry snapd: move the sources of snapctl and snap-exec in
      preparation for the multi-entry dispatch
    - Never create seed refresh tasks during a remodel
    - packaging: assign a default label for /tmp/snap-private-tmp and
      set it during installation
    - packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for
      focal
    - packaging: drop SNAP_TAGS
    - packaging: drop symlinks for opensuse 15.5/15.6 packaging
    - packaging: fix service startup during install and session-agent
      socket handling on Ubuntu 26.04+
    - packaging: fix stderr redirection
    - packaging: restore gbp.conf output directory for Ubuntu 26.04
      builds
    - packaging: switch to apparmor 5.x with 5 ABI
    - packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI
      when running as deb
    - packaging: use a relative symlink for snapctl and update steam-
      support udev rules
    - Preserve component in hook security tags
    - Prevent removal of seed-refresh snaps when seed-refresh is enabled
    - Refactor base-declaration into 1st class builtin assertion
    - Refactor how the is-originating-from-snap-command advisory check
      works
    - Refactor prerequisites task handler to enable proper seed-refresh
      integration
    - Reintroduce fdstore helpers
    - remote device management: add task to validate request messages
    - remote device management: apply management messages, queue
      response messages, and improve sequencing and redelivery handling
    - Remove osutil unused AtomicWriteFollow flag
    - Remove xerrors dependency
    - Reuse existing seed-refresh implementation for free during single-
      path installation
    - Rework how SnapSetup.SnapPath is used
    - seccomp: allow rseq_slice_yield
    - security logging: add seclog API for administrative actions and
      token create/remove events
    - security logging: add security logging for adding, updating and
      removing a snapd user
    - Set target hostname from install-mode
    - snap-confine: improve loading of BPF programs, retry on failures
      to collect verifier logs
    - snap-confine: use profile and flags= in snap-confine and snap-
      update-ns' AppArmor profiles
    - snap-confine: work around kernel mnt_ns_loop() ordering bug on
      6.18.x
    - snap: add debug command for listing currently mediated devices for
      a given snap
    - snap: fix self-managed cgroup support checks
    - snap: report hidden file access for paths allowed by home when
      prompting is active
    - snap: report read-only file access for paths allowed by system-
      package-doc
    - snapctl async support: add --format json to snap tasks to be
      consistent with snapctl
    - snapctl async support: add snapctl tasks command
    - snapctl async support: async feature negotiation between snap
      client and daemon
    - snapctl async support: fix snapctl is-ready exit codes
    - snapctl async support: re-enable snapctl async functionality
    - snapshots: restore preserves snapctl created mounts
    - snapshots: save excludes all mount points
    - Support ca-certificate.crt only systems like core26
    - Turn on quota-groups by default
    - Use 0755 for certificate generation directories
    - Use CreateTemp for NewAtomicFile tmp file creation
    - Verify cached downloads in the do path and detect obvious
      corruption

Date: Wed, 02 Sep 2026 14:39:12 +0200
Changed-By: Ernest Lotter <ernest.lotter at canonical.com>
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Signed-By: Graham Inggs <graham.inggs at canonical.com>
https://launchpad.net/ubuntu/+source/snapd/2.77.1+ubuntu26.04.2
-------------- next part --------------
Format: 1.8
Date: Wed, 02 Sep 2026 14:39:12 +0200
Source: snapd
Built-For-Profiles: noudeb
Architecture: source
Version: 2.77.1+ubuntu26.04.2
Distribution: resolute
Urgency: medium
Maintainer: Ubuntu Developers <ubuntu-devel-discuss at lists.ubuntu.com>
Changed-By: Ernest Lotter <ernest.lotter at canonical.com>
Launchpad-Bugs-Fixed: 2072331 2110510 2143934 2158102 2160691 2161982
Changes:
 snapd (2.77.1+ubuntu26.04.2) resolute; urgency=medium
 .
   * New upstream release, LP: #2158102
     - Fix undo of unlink-component after its snap revision was discarded
     - interfaces: power-control | allow reading all battery state files
     - fix 26.04+ snapd deb versioning
 .
 snapd (2.77+ubuntu26.04) resolute; urgency=medium
 .
     - Account for differences in names of the binaries in the snapd FIPS
       build
     - Add code to calculate canonical subject name hash
     - Add commands for debugging or accessing snap mount namespaces
     - Add helpers for listing and iterating device mediation groups
     - Add package ebpf with helpers wrapping eBPF exposed objects with
       dependency on github.com/cilium/ebpf
     - Add secondary prerequisites task that acts as the synchronization
       point, which ensures that a snap's prerequisites are available
       before it's installed
     - Add support for shell conditional syntax in envs
     - Added /usr/share/{man,help,info} to system-packages-doc
     - asserts: add validation-sets confdb-schema builtin
     - asserts: ensure that compatibility labels are strings
     - asserts: extend on-classic constraints to accept "distro/variant",
       "distro/*", and "distro/" under a new snap-declaration format 7
     - asserts: validate serial in newDeviceIDFromString
     - Bump github.com/canonical/go-efilib to v1.8.0 to include fixes for
       efivars probe
     - confdb: add validation-sets handler and fix data loss when writing
       to new schemas or accounts
     - confdb: fix bug on reading uneven lists
     - confdb: literal subkeys are sorted after placeholders
     - confdb: run observe-view-* hooks after commit
     - confdb: support Encode/Decode for builtins
     - confdb: support sign-only external keypair backends
     - core-initrd: add missing libbpf and systemd dlopen dependencies,
       and increase mount burst
     - Drop task logs for delayed effects
     - During snap removal, clear-snap task errors early if there are
       user mounts in snap data dirs
     - Enable reverts to trigger a seed refresh
     - Ensure profiles are setup before running prepare-{slot, plug}*
       hooks
     - Ensure that prereqs created by initial refresh run before create-
       recovery-system
     - Exclude Georgian from translation linting
     - experimental features: graduate layouts, classic-preserves-xdg-
       runtime-dir, refresh-app-awareness, and dbus-activation features
     - experimental features: warn when setting graduated or default-
       enabled experimental features and do not store settings for
       graduated features
     - Expose individual certs as well as c_rehash emulation
     - Extend autogen with explicit --sysconfdir
     - External keypair manager: add shared external key manager
       implementation
     - External keypair manager: refactor GPG and external keypair
       managers to use extKeypairMgrImpl
     - External keypair manager: support external OPENPGP signing in
       ExternalKeypairManager
     - FDE: add post install actions API
     - FDE: add reprovision API
     - FDE: add reprovision recovery key generation API
     - FDE: add reseal check after snapd refresh
     - FDE: allow reprovision without factory reset
     - FDE: change makebootable part of the boot package to not take
       install observers as parameters
     - FDE: extend storage-encrypted system information
     - FDE: make reprovision only seal
     - FDE: remove all tmp keyslots on error
     - FDE: remove check for unchanged authentication options
     - FDE: run post install checks during auto repair
     - Filter seed-refresh based on model and seed presence
     - Fix failing snap remove when there are snapctl created mounts
       under snap global data dirs
     - Fix postNotices to validate before locking state
     - Guard the ensure check from running on classic
     - Implement remodeling fully in terms of updates
     - Implement ShutDown for HookManager
     - Include variables SNAP_APP_NAME, and when applicable
       SNAP_APP_COMMON_ID, SNAP_APP_DESKTOP_FILE and SNAP_APP_BUS_NAME in
       snap application environments
     - interfaces: add xdg-portal-permission-store interface
     - interfaces: allow gtk css in subdirectories
     - interfaces: allow systemd networkd link property changes via D-Bus
     - interfaces: allow the systemd networkctl command
     - interfaces: allow Wine to execute files accessed via the Document
       Portal
     - interfaces: apparmor-observe | add interface
     - interfaces: attempt to fix content with parallel installs
     - interfaces: devlxd | fix access for LXD containers
     - interfaces: docker | allow connecting to system-wide docker on
       classic
     - interfaces: grant default access to memory.high in a snap's cgroup
     - interfaces: iscsi-initiator | allow access to /var/lib/iscsi/nodes
     - interfaces: kernel-sched-ext-control | add the kernel sched-ext
       control interface implementation
     - interfaces: make polkit and upower implicit on Core systems only
     - interfaces: open-iscsi | add missing state paths
     - interfaces: opengl | expose wsl libraries
     - interfaces: u2f-devices | add atkey PID and relative VID support
     - List dir contents on failure to remove snap base data dir
     - List non-snapctl mounts in snap data dirs
     - LP: #2072331 Validate map keys in JSON config values
     - LP: #2110510 Interfaces: allow reading of /proc/self/smaps_rollup
     - LP: #2143934 Interfaces: network-control, network-manager | allow
       missing resolve1 link setters
     - LP: #2160691 Security logging: strip trailing whitespace from
       audit netlink message payload
     - LP: #2161982 Interfaces: vsock | add interface for VM guest
       services
     - Make arguments of debug mount-namespace consistent with other
       debug commands
     - Make bootloader logging less verbose
     - Make cert manager garbage check run after symlink migration
     - Make secondary prerequisite synchronization task handle same-
       change retries
     - mkversion.sh: do describe in worktrees too
     - multi-entry snapd: merge snap and snapd binaries
     - multi-entry snapd: move debug device-cgroup implementation file
       under cmd/snapd/cli
     - multi-entry snapd: move snap-gpio-helper sources around before
       transitioning to multi-entry dispatch
     - multi-entry snapd: move snapd-apparmor sources to a dedicated tool
       location
     - multi-entry snapd: move source files around in preparation for
       snapd/snap merge
     - multi-entry snapd: move the snap-preseed sources around in
       preparation
     - multi-entry snapd: move the sources of snapctl and snap-exec in
       preparation for the multi-entry dispatch
     - Never create seed refresh tasks during a remodel
     - packaging: assign a default label for /tmp/snap-private-tmp and
       set it during installation
     - packaging: build deb with Go 1.23 for noble and jammy, Go 1.22 for
       focal
     - packaging: drop SNAP_TAGS
     - packaging: drop symlinks for opensuse 15.5/15.6 packaging
     - packaging: fix service startup during install and session-agent
       socket handling on Ubuntu 26.04+
     - packaging: fix stderr redirection
     - packaging: restore gbp.conf output directory for Ubuntu 26.04
       builds
     - packaging: switch to apparmor 5.x with 5 ABI
     - packaging: update bundled AppArmor to 5.0.2 and accept the 5.0 ABI
       when running as deb
     - packaging: use a relative symlink for snapctl and update steam-
       support udev rules
     - Preserve component in hook security tags
     - Prevent removal of seed-refresh snaps when seed-refresh is enabled
     - Refactor base-declaration into 1st class builtin assertion
     - Refactor how the is-originating-from-snap-command advisory check
       works
     - Refactor prerequisites task handler to enable proper seed-refresh
       integration
     - Reintroduce fdstore helpers
     - remote device management: add task to validate request messages
     - remote device management: apply management messages, queue
       response messages, and improve sequencing and redelivery handling
     - Remove osutil unused AtomicWriteFollow flag
     - Remove xerrors dependency
     - Reuse existing seed-refresh implementation for free during single-
       path installation
     - Rework how SnapSetup.SnapPath is used
     - seccomp: allow rseq_slice_yield
     - security logging: add seclog API for administrative actions and
       token create/remove events
     - security logging: add security logging for adding, updating and
       removing a snapd user
     - Set target hostname from install-mode
     - snap-confine: improve loading of BPF programs, retry on failures
       to collect verifier logs
     - snap-confine: use profile and flags= in snap-confine and snap-
       update-ns' AppArmor profiles
     - snap-confine: work around kernel mnt_ns_loop() ordering bug on
       6.18.x
     - snap: add debug command for listing currently mediated devices for
       a given snap
     - snap: fix self-managed cgroup support checks
     - snap: report hidden file access for paths allowed by home when
       prompting is active
     - snap: report read-only file access for paths allowed by system-
       package-doc
     - snapctl async support: add --format json to snap tasks to be
       consistent with snapctl
     - snapctl async support: add snapctl tasks command
     - snapctl async support: async feature negotiation between snap
       client and daemon
     - snapctl async support: fix snapctl is-ready exit codes
     - snapctl async support: re-enable snapctl async functionality
     - snapshots: restore preserves snapctl created mounts
     - snapshots: save excludes all mount points
     - Support ca-certificate.crt only systems like core26
     - Turn on quota-groups by default
     - Use 0755 for certificate generation directories
     - Use CreateTemp for NewAtomicFile tmp file creation
     - Verify cached downloads in the do path and detect obvious
       corruption
Checksums-Sha1:
 d81f5783d2f9055ca45f1d4fbfa25a6266ff452a 2378 snapd_2.77.1+ubuntu26.04.2.dsc
 a4b03f8264ec53ade76c4ad3dcb4fdb382c240ff 11352640 snapd_2.77.1+ubuntu26.04.2.tar.xz
 765cc8e60347e1a2f656cf2d55f42b2f33796b4b 10678 snapd_2.77.1+ubuntu26.04.2_source.buildinfo
Checksums-Sha256:
 030f51020b334b1c891d9748c15d44f213a856df7d0b6e00753c5150303ea1a6 2378 snapd_2.77.1+ubuntu26.04.2.dsc
 ac79e1fe832b763295721ed4a1e3cd8669b5c67cbd98f95c06703ac95257bb54 11352640 snapd_2.77.1+ubuntu26.04.2.tar.xz
 ebce374cfeb113cee19dfed2f6c7cdf1354cd609936e4c0ff94a539add561af7 10678 snapd_2.77.1+ubuntu26.04.2_source.buildinfo
Files:
 468f1cf1949222aec976a3f0c857fa98 2378 devel optional snapd_2.77.1+ubuntu26.04.2.dsc
 822d06522c5deee99462e797921058e6 11352640 devel optional snapd_2.77.1+ubuntu26.04.2.tar.xz
 cd47bc3019d4008fe7d22eab0fcf5869 10678 devel optional snapd_2.77.1+ubuntu26.04.2_source.buildinfo


More information about the Resolute-changes mailing list