[Bug 2124239] Re: [SRU] 2.72
Launchpad Bug Tracker
2124239 at bugs.launchpad.net
Wed Nov 12 14:10:35 UTC 2025
This bug was fixed in the package snapd - 2.72+ubuntu25.10.2
---------------
snapd (2.72+ubuntu25.10.2) questing; urgency=medium
* New upstream release, LP: #2124239
- FDE: support replacing TPM protected keys at runtime via the
/v2/system-volumes endpoint
- FDE: support secboot preinstall check fix actions for 25.10+
hybrid installs via the /v2/system/{label} endpoint
- FDE: tweak polkit message to remove jargon
- FDE: ensure proper sealing with kernel command line defaults
- FDE: provide generic reseal function
- FDE: support using OPTEE for protecting keys, as an alternative to
existing fde-setup hooks (Ubuntu Core only)
- Confdb: 'snapctl get --view' supports passing default values
- Confdb: content sub-rules in confdb-schemas inherit their parent
rule's "access"
- Confdb: make confdb error kinds used in API more generic
- Confdb: fully support lists and indexed paths (including unset)
- Prompting: add notice backend for prompting types (unused for now)
- Prompting: include request cgroup in prompt
- Prompting: handle unsupported xattrs
- Prompting: add permission mapping for the camera interface
- Notices: read notices from state without state lock
- Notices: add methods to get notice fields and create, reoccur, and
deepcopy notice
- Notices: add notice manager to coordinate separate notice backends
- Notices: support draining notices from state when notice backend
registered as producer of a particular notice type
- Notices: query notice manager from daemon instead of querying
state for notices directly
- Packaging: Ubuntu | ignore .git directory
- Packaging: FIPS | bump deb Go FIPS to 1.23
- Packaging: snap | bump FIPS toolchain to 1.23
- Packaging: debian | sync most upstream changes
- Packaging: debian-sid | depends on libcap2-bin for postint
- Packaging: Fedora | drop fakeroot
- Packaging: snap | modify snapd.mk to pass build tags when running
unit tests
- Packaging: snap | modify snapd.mk to pass nooptee build tag
- Packaging: modify Makefile.am to fix snap-confine install profile
with 'make hack'
- Packaging: modify Makefile.am to fix out-of-tree use of 'make
hack'
- LP: #2122054 Snap installation: skip snap icon download when
running in a cloud or using a proxy store
- Snap installation: add timeout to http client when downloading
snap icon
- Snap installation: use http(s) proxy for icon downloads
- LP: #2117558 snap-confine: fix error message with /root/snap not
accessible
- snap-confine: fix non-suid limitation by switching to root:root to
operate v1 freezer
- core-initrd: do not use writable-paths when not available
- core-initrd: remove debian folder
- LP: #1916244 Interfaces: gpio-chardev | re-enable the gpio-chardev
interface now with the more robust gpio-aggregator configfs kernel
interface
- Interfaces: gpio-chardev | exclusive snap connections, raise a
conflict when both gpio-chardev and gpio are connected
- Interfaces: gpio-chardev | fix gpio-aggregator module load order
- Interfaces: ros-snapd-support | grant access to /v2/changes
- Interfaces: uda-driver-libs, egl-driver-libs, gbm-driver-libs,
opengl-driver-libs, opengles-driver-libs | new interfaces to
support nvidia driver components
- Interfaces: microstack-support | allow DPDK (hugepage related
permissions)
- Interfaces: system-observe | allow reading additional files in
/proc, needed by node-exporter
- Interfaces: u2f | add Cano Key, Thesis FIDO2 BioFP+ Security Key
and Kensington VeriMark DT Fingerprint Key to device list
- Interfaces: snap-interfaces-requests-control | allow shell API
control
- Interfaces: fwupd | allow access to Intel CVS sysfs
- Interfaces: hardware-observe | allow read access to Kernel
Samepage Merging (KSM)
- Interfaces: xilinx-dma | support Multi Queue DMA (QDMA) IP
- Interfaces: spi | relax sysfs permission rules to allow access to
SPI device node attributes
- Interfaces: content | introduce compatibility label
- LP: #2121238 Interfaces: do not expose Kerberos tickets for
classic snaps
- Interfaces: ssh-public-keys | allow ro access to public host keys
with ssh-key
- Interfaces: Modify AppArmor template to allow listing systemd
credentials and invoking systemd-creds
- Interfaces: modify AppArmor template with workarounds for Go 1.35
cgroup aware GOMAXPROCS
- Interfaces: modify seccomp template to allow landlock_*
- Prevent snap hooks from running while relevant snaps are unlinked
- Make refreshes wait before unlinking snaps if running hooks can be
affected
- Fix systemd unit generation by moving "WantedBy=" from section
"unit" to "install"
- Add opt-in logging support for snap-update-ns
- Unhide 'snap help' sign and export-key under Development category
- LP: #2117121 Cleanly support socket activation for classic snap
- Add architecture to 'snap version' output
- Add 'snap debug api' option to disable authentication through
auth.json
- Show grade in notes for 'snap info --verbose'
- Fix preseeding failure due to scan-disk issue on RPi
- Support 'snap debug api' queries to user session agents
- LP: #2112626 Improve progress reporting for snap install/refresh
- Drop legacy BAMF_DESKTOP_FILE_HINT in desktop files
- Fix /v2/apps error for root user when user services are present
- LP: #2114704 Extend output to indicate when snap data snapshot was
created during remove
- Improve how we handle emmc volumes
- Improve handling of system-user extra assertions
-- Ernest Lotter <ernest.lotter at canonical.com> Thu, 18 Sep 2025
10:00:54 +0200
** Changed in: snapd (Ubuntu Questing)
Status: Fix Committed => Fix Released
--
You received this bug notification because you are a member of Ubuntu
Sponsors, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/2124239
Title:
[SRU] 2.72
Status in snapd package in Ubuntu:
Fix Released
Status in snapd source package in Jammy:
Fix Released
Status in snapd source package in Noble:
Fix Released
Status in snapd source package in Plucky:
Fix Released
Status in snapd source package in Questing:
Fix Released
Status in snapd source package in Resolute:
Fix Released
Bug description:
New Snapd release 2.72 is required for Jammy, Noble, Plucky and
Questing.
Snapd 2.72 is the latest upstream release. It follows the the previous
Ubuntu release snapd 2.71.
The Snapd package deviates from the standard SRU process. The
following special SRU process was followed:
https://documentation.ubuntu.com/sru/en/latest/reference/exception-
Snapd-Updates/. We are in the process of updating to refreshed
documentation:
https://docs.google.com/document/d/e/2PACX-1vTE088Am4f5SWhf3vIzA1vAIPLNrQ7JYWRO185SWmHED_e0msSahJSozArisSXezd1D8CugstKN27jx/pub
(draft)
Release preparation: https://github.com/canonical/snapd/pull/16000
Release preparation test results: https://github.com/canonical/snapd/actions/runs/17822196539/job/50712254868
Failure analysis: https://github.com/canonical/snapd/pull/16000#issuecomment-3311044430
Release notes:
https://github.com/canonical/snapd/pull/16000/files#diff-51920e95310ebfbc1ae31709f3b95f89afffbf4f1a6e38e8b2b406e2fb6197ea
Please refer to snapd release notes documentation to understand how
this is put together:
https://docs.google.com/document/d/1do2TFwRIAzuOjLmteVuD0CRoJNO5vVcdUIwTHo4bYO4/edit?tab=t.0#heading=h.ablpjof536fg
Launchpad bugs addressed: https://launchpad.net/snapd/+milestone/2.72
Content overview:
- Full Disk Encryption (FDE)
- Confdb
- AppArmor Prompting
- Notices
- Many interface extensions including:
- GPIO chardev interface as replacement for sysfs based GPIO
- Multiple interfaces for different Nvidia driver components
- Various LP bug fixes
- Various packaging changes, only one minor change for Ubuntu
Areas of potential regressions:
- FDE just because it's complex, but risk is low given the level of integration tests in place
Source packages on `ppa:snappy-dev/image` for upload to -proposed:
- Resolute | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17749185/+listing-archive-extra
- Questing | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17749183/+listing-archive-extra
- Plucky | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598894/+listing-archive-extra
- Noble | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598895/+listing-archive-extra
- Jammy | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598896/+listing-archive-extra
Validation already completed:
- Release preparation test results: https://github.com/canonical/snapd/actions/runs/17822196539/job/50712254868
- QA Beta validation https://warthogs.atlassian.net/browse/SNAPDENG-34861
- Certification validation: https://test-observer.canonical.com/#/snaps/239942 (need VPN)
To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/2124239/+subscriptions
More information about the Ubuntu-sponsors
mailing list