[Bug 2124239] Re: [SRU] 2.72

Launchpad Bug Tracker 2124239 at bugs.launchpad.net
Wed Nov 12 14:10:35 UTC 2025


This bug was fixed in the package snapd - 2.72+ubuntu25.10.2

---------------
snapd (2.72+ubuntu25.10.2) questing; urgency=medium

  * New upstream release, LP: #2124239
    - FDE: support replacing TPM protected keys at runtime via the
      /v2/system-volumes endpoint
    - FDE: support secboot preinstall check fix actions for 25.10+
      hybrid installs via the /v2/system/{label} endpoint
    - FDE: tweak polkit message to remove jargon
    - FDE: ensure proper sealing with kernel command line defaults
    - FDE: provide generic reseal function
    - FDE: support using OPTEE for protecting keys, as an alternative to
      existing fde-setup hooks (Ubuntu Core only)
    - Confdb: 'snapctl get --view' supports passing default values
    - Confdb: content sub-rules in confdb-schemas inherit their parent
      rule's "access"
    - Confdb: make confdb error kinds used in API more generic
    - Confdb: fully support lists and indexed paths (including unset)
    - Prompting: add notice backend for prompting types (unused for now)
    - Prompting: include request cgroup in prompt
    - Prompting: handle unsupported xattrs
    - Prompting: add permission mapping for the camera interface
    - Notices: read notices from state without state lock
    - Notices: add methods to get notice fields and create, reoccur, and
      deepcopy notice
    - Notices: add notice manager to coordinate separate notice backends
    - Notices: support draining notices from state when notice backend
      registered as producer of a particular notice type
    - Notices: query notice manager from daemon instead of querying
      state for notices directly
    - Packaging: Ubuntu | ignore .git directory
    - Packaging: FIPS | bump deb Go FIPS to 1.23
    - Packaging: snap | bump FIPS toolchain to 1.23
    - Packaging: debian | sync most upstream changes
    - Packaging: debian-sid | depends on libcap2-bin for postint
    - Packaging: Fedora | drop fakeroot
    - Packaging: snap | modify snapd.mk to pass build tags when running
      unit tests
    - Packaging: snap | modify snapd.mk to pass nooptee build tag
    - Packaging: modify Makefile.am to fix snap-confine install profile
      with 'make hack'
    - Packaging: modify Makefile.am to fix out-of-tree use of 'make
      hack'
    - LP: #2122054 Snap installation: skip snap icon download when
      running in a cloud or using a proxy store
    - Snap installation: add timeout to http client when downloading
      snap icon
    - Snap installation: use http(s) proxy for icon downloads
    - LP: #2117558 snap-confine: fix error message with /root/snap not
      accessible
    - snap-confine: fix non-suid limitation by switching to root:root to
      operate v1 freezer
    - core-initrd: do not use writable-paths when not available
    - core-initrd: remove debian folder
    - LP: #1916244 Interfaces: gpio-chardev | re-enable the gpio-chardev
      interface now with the more robust gpio-aggregator configfs kernel
      interface
    - Interfaces: gpio-chardev | exclusive snap connections, raise a
      conflict when both gpio-chardev and gpio are connected
    - Interfaces: gpio-chardev | fix gpio-aggregator module load order
    - Interfaces: ros-snapd-support | grant access to /v2/changes
    - Interfaces: uda-driver-libs, egl-driver-libs, gbm-driver-libs,
      opengl-driver-libs, opengles-driver-libs | new interfaces to
      support nvidia driver components
    - Interfaces: microstack-support | allow DPDK (hugepage related
      permissions)
    - Interfaces: system-observe | allow reading additional files in
      /proc, needed by node-exporter
    - Interfaces: u2f | add Cano Key, Thesis FIDO2 BioFP+ Security Key
      and Kensington VeriMark DT Fingerprint Key to device list
    - Interfaces: snap-interfaces-requests-control | allow shell API
      control
    - Interfaces: fwupd | allow access to Intel CVS sysfs
    - Interfaces: hardware-observe | allow read access to Kernel
      Samepage Merging (KSM)
    - Interfaces: xilinx-dma | support Multi Queue DMA (QDMA) IP
    - Interfaces: spi | relax sysfs permission rules to allow access to
      SPI device node attributes
    - Interfaces: content | introduce compatibility label
    - LP: #2121238 Interfaces: do not expose Kerberos tickets for
      classic snaps
    - Interfaces: ssh-public-keys | allow ro access to public host keys
      with ssh-key
    - Interfaces: Modify AppArmor template to allow listing systemd
      credentials and invoking systemd-creds
    - Interfaces: modify AppArmor template with workarounds for Go 1.35
      cgroup aware GOMAXPROCS
    - Interfaces: modify seccomp template to allow landlock_*
    - Prevent snap hooks from running while relevant snaps are unlinked
    - Make refreshes wait before unlinking snaps if running hooks can be
      affected
    - Fix systemd unit generation by moving "WantedBy=" from section
      "unit" to "install"
    - Add opt-in logging support for snap-update-ns
    - Unhide 'snap help' sign and export-key under Development category
    - LP: #2117121 Cleanly support socket activation for classic snap
    - Add architecture to 'snap version' output
    - Add 'snap debug api' option to disable authentication through
      auth.json
    - Show grade in notes for 'snap info --verbose'
    - Fix preseeding failure due to scan-disk issue on RPi
    - Support 'snap debug api' queries to user session agents
    - LP: #2112626 Improve progress reporting for snap install/refresh
    - Drop legacy BAMF_DESKTOP_FILE_HINT in desktop files
    - Fix /v2/apps error for root user when user services are present
    - LP: #2114704 Extend output to indicate when snap data snapshot was
      created during remove
    - Improve how we handle emmc volumes
    - Improve handling of system-user extra assertions

 -- Ernest Lotter <ernest.lotter at canonical.com>  Thu, 18 Sep 2025
10:00:54 +0200

** Changed in: snapd (Ubuntu Questing)
       Status: Fix Committed => Fix Released

-- 
You received this bug notification because you are a member of Ubuntu
Sponsors, which is subscribed to the bug report.
https://bugs.launchpad.net/bugs/2124239

Title:
  [SRU] 2.72

Status in snapd package in Ubuntu:
  Fix Released
Status in snapd source package in Jammy:
  Fix Released
Status in snapd source package in Noble:
  Fix Released
Status in snapd source package in Plucky:
  Fix Released
Status in snapd source package in Questing:
  Fix Released
Status in snapd source package in Resolute:
  Fix Released

Bug description:
  New Snapd release 2.72 is required for Jammy, Noble, Plucky and
  Questing.

  Snapd 2.72 is the latest upstream release. It follows the the previous
  Ubuntu release snapd 2.71.

  The Snapd package deviates from the standard SRU process. The
  following special SRU process was followed:
  https://documentation.ubuntu.com/sru/en/latest/reference/exception-
  Snapd-Updates/. We are in the process of updating to refreshed
  documentation:
  https://docs.google.com/document/d/e/2PACX-1vTE088Am4f5SWhf3vIzA1vAIPLNrQ7JYWRO185SWmHED_e0msSahJSozArisSXezd1D8CugstKN27jx/pub
  (draft)

  Release preparation: https://github.com/canonical/snapd/pull/16000
  Release preparation test results: https://github.com/canonical/snapd/actions/runs/17822196539/job/50712254868
  Failure analysis: https://github.com/canonical/snapd/pull/16000#issuecomment-3311044430

  Release notes:
  https://github.com/canonical/snapd/pull/16000/files#diff-51920e95310ebfbc1ae31709f3b95f89afffbf4f1a6e38e8b2b406e2fb6197ea

  Please refer to snapd release notes documentation to understand how
  this is put together:
  https://docs.google.com/document/d/1do2TFwRIAzuOjLmteVuD0CRoJNO5vVcdUIwTHo4bYO4/edit?tab=t.0#heading=h.ablpjof536fg

  Launchpad bugs addressed: https://launchpad.net/snapd/+milestone/2.72

  Content overview:
   - Full Disk Encryption (FDE)
   - Confdb
   - AppArmor Prompting
   - Notices
   - Many interface extensions including:
     - GPIO chardev interface as replacement for sysfs based GPIO
     - Multiple interfaces for different Nvidia driver components
   - Various LP bug fixes
   - Various packaging changes, only one minor change for Ubuntu

  Areas of potential regressions:
  - FDE just because it's complex, but risk is low given the level of integration tests in place

  Source packages on `ppa:snappy-dev/image` for upload to -proposed:
  - Resolute | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17749185/+listing-archive-extra
  - Questing | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17749183/+listing-archive-extra
  - Plucky   | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598894/+listing-archive-extra
  - Noble    | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598895/+listing-archive-extra
  - Jammy    | https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/17598896/+listing-archive-extra

  Validation already completed:

  - Release preparation test results: https://github.com/canonical/snapd/actions/runs/17822196539/job/50712254868
  - QA Beta validation        https://warthogs.atlassian.net/browse/SNAPDENG-34861
  - Certification validation: https://test-observer.canonical.com/#/snaps/239942 (need VPN)

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/2124239/+subscriptions





More information about the Ubuntu-sponsors mailing list