** Description changed:

  New Snapd release 2.76.3 is required for Jammy, Noble, Resolute and
  Stonking
  
- Snapd 2.76.3 is the latest upstream minor release. It follows the previous 
Ubuntu release snapd 2.76.
- Note: 2.76.1 was a security release. 2.76.2 was a snap-only release.
+ Snapd 2.76.3 is the latest upstream minor release. It directly follows
+ the previous Ubuntu release snapd 2.76, because release attempt 2.76.1
+ was a security release and 2.76.2 was a snap-only release.
  
  The Snapd package deviates from the standard SRU process. The following
- special SRU process was followed: <link to relevant SRU process doc>
+ special SRU process was followed: https://github.com/ubuntu/ubuntu-
+ project-docs/pull/542.
  
- Release preparation: occurred in a private repo
- Release preparation test results: All failures analyzed and accounted for
+ Release preparation: 
https://github.com/canonical/snapd-security-release/pull/36  (private repo)
+ Note: We decided to use the private repo even though this is not a security 
release, purely to enable us to base it on the security release which at the 
time was not yet publicly available - thereby saving time which was required 
because we are behind schedule.
+ 
+ Release preparation test results: https://github.com/canonical/snapd-
+ security-release/actions/runs/28926525907/job/85900215317 (private repo)
+ 
+ Failure analysis: https://github.com/canonical/snapd-security-
+ release/pull/36#issuecomment-4925314121 (private repo).
  
  Release notes:
+ https://github.com/canonical/snapd/blob/master/NEWS.md#new-in-snapd-2763
  
  Please refer to snapd release notes documentation
  (https://github.com/canonical/snapd/blob/master/RELEASE.md) for details
  on how this is assembled.
  
- Launchpad bugs addressed: https://launchpad.net/snapd/+milestone/2.76.3
+ Launchpad bugs addressed: NONE
  
  Content overview:
-  - TPM/FDE: Updated secboot to allow preinstall check to proceeding without 
HW root of trust
-  - TPM/FDE: Re-enable setting PIN/Passphrase during install
-  - TPM/FDE: Support keyboard configuration at install-time for first-boot
-  - selinux: Use init_named_socket_activation() for allowing systemd to start 
snapd through socket activation
+ 
+ TPM/FDE: 
+   - Updated secboot to allow preinstall check to proceeding without HW root 
of trust
+   - Re-enable setting PIN/Passphrase during install
+   - Support keyboard configuration at install-time for first-boot
+ 
+ - selinux: Use init_named_socket_activation() for allowing systemd to start 
snapd through socket activation
  - packaging: make sure that usr/bin/snap is built with correct build tags on 
debian sid
  
  Areas of potential regressions:
  The changes are focused mostly around very specific functionality the works 
together to allow TPM/FDE
  without HW root of trust. The PIN/Passphrase functionality was removed and 
now added again, so not completely new. The secboot changes is very specific 
and was thoroughly tested on the relevant HW.
  Keyboard configuration is important for a subset keyboards that is not that 
common, and regardless it was also thoroughly tested. Selinux change is not 
applicable to Ubuntu.
  
  So overall the risk is low, and limited to a small TPM/FDE installation
  and and firstboot.
  
  Source packages on `ppa:snappy-dev/image` for upload to -proposed:
  jammy 
https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/18631710/+listing-archive-extra
  noble 
https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/18631711/+listing-archive-extra
  resolute 
https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/18631726/+listing-archive-extra
  stonking 
https://launchpad.net/~snappy-dev/+archive/ubuntu/image/+sourcepub/18631731/+listing-archive-extra
  
  Validation already completed:
  
- - Release preparation test results: <link to release PR run results>
- - QA Beta validation <link to beta validation Jira ticket>
- - Certification validation: <link to test observer results> (need VPN)
+ - Release preparation test results: 
https://github.com/canonical/snapd-security-release/pull/36  (private repo)
+ - QA Beta validation https://warthogs.atlassian.net/browse/SNAPDENG-37281
+ - Certification validation: 
https://test-observer.canonical.com/#/snaps/411197 (requires login)
  
  Verification required:
  
- - Verify LP bugs for <list of short name target releases>
- - Perform release upgrades from <short name of earliest supported target 
release> to <short name of latest supported release>
+ - Verify LP bugs: N/A
+ - Perform release upgrades from jammy to stonking: This is covered by 
automated testing during release preparation.

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2158301

Title:
  [SRU] 2.76.3

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/snapd/+bug/2158301/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to