** Changed in: livecd-rootfs (Ubuntu Noble)
       Status: New => In Progress

** Changed in: livecd-rootfs (Ubuntu)
       Status: New => Invalid

** Summary changed:

- Apparmor feature mismatch for the 7.0 kernel in noble
+ SRU] Apparmor feature mismatch for the 7.0 kernel in noble

** Description changed:

  Preseeding with the 7.0 kernel (currently in edge) fails due to apparmor
  feature mismatch
+ 
+ [Why are we not adding this change to `ubuntu/master` (stonking) as
+ well?]
+ 
+ The 7.0 kernel `apparmor` preseeding support already exists in
+ `ubuntu/master` via the `live-build/apparmor/7.0/` feature tree (added
+ in 6d331d4d and bd01492).
+ 
+ This commit doesn't contain any code/logic changes, it only adds
+ `apparmor` feature files which were gathered from noble's HWE 7.0 kernel
+ (currently in `linux-gcp-edge`). `ubuntu/master`'s 7.0 tree was captured
+ from its own 7.0 kernel, and the `apparmor` feature set must match the
+ kernel it targets. I did check the diff of the two 7.0 directories and
+ confirmed they are distinct and diverge both ways (e.g. noble adds
+ `policy/compressed_load` and `policy/diff_encode` whereas
+ `ubuntu/master` has `ipc/posix_mqueue`'s label, `policy/notify/user`'s
+ tags and `policy/unconfined_restrictions/io_uring=1` which noble doesn't
+ have)
  
  [ Impact ]
  
  When building noble images with the 7.0 kernel from edge (e.g. `linux-
  gcp-edge`), snap preseeding fails as there's a mismatch between the
  kernel's apparmor capabilities and the capabilities listed in `livecd-
  rootfs`. So these images have slower boot times as the snaps are being
  seeded at first boot instead
  
  [ Test Plan ]
  
  * Build an image
  * Register the image on the relevant cloud
  * Boot into the image and check that `snap debug seeding` doesn't contain the 
`seed-restart-system-key` key
  
  [ Where problems could occur ]
  
  The risk of regressions is pretty small (we do this for every kernel
  roll and new release) and there shouldn't be any runtime changes. One
  potential problem is if the proposed changes do not properly rectify the
  mismatch in the apparmor features, but in that case we just go through
  the process again with a new MP.
  
  [ Other Info ]
  
  * This bug just affects Noble 24.04

** Description changed:

- Preseeding with the 7.0 kernel (currently in edge) fails due to apparmor
- feature mismatch
+ Preseeding with the 7.0 kernel (currently in edge) fails due to an
+ `apparmor` feature mismatch
  
  [Why are we not adding this change to `ubuntu/master` (stonking) as
  well?]
  
  The 7.0 kernel `apparmor` preseeding support already exists in
  `ubuntu/master` via the `live-build/apparmor/7.0/` feature tree (added
  in 6d331d4d and bd01492).
  
  This commit doesn't contain any code/logic changes, it only adds
  `apparmor` feature files which were gathered from noble's HWE 7.0 kernel
  (currently in `linux-gcp-edge`). `ubuntu/master`'s 7.0 tree was captured
  from its own 7.0 kernel, and the `apparmor` feature set must match the
  kernel it targets. I did check the diff of the two 7.0 directories and
  confirmed they are distinct and diverge both ways (e.g. noble adds
  `policy/compressed_load` and `policy/diff_encode` whereas
  `ubuntu/master` has `ipc/posix_mqueue`'s label, `policy/notify/user`'s
  tags and `policy/unconfined_restrictions/io_uring=1` which noble doesn't
  have)
  
  [ Impact ]
  
  When building noble images with the 7.0 kernel from edge (e.g. `linux-
  gcp-edge`), snap preseeding fails as there's a mismatch between the
  kernel's apparmor capabilities and the capabilities listed in `livecd-
  rootfs`. So these images have slower boot times as the snaps are being
  seeded at first boot instead
  
  [ Test Plan ]
  
  * Build an image
  * Register the image on the relevant cloud
  * Boot into the image and check that `snap debug seeding` doesn't contain the 
`seed-restart-system-key` key
  
  [ Where problems could occur ]
  
  The risk of regressions is pretty small (we do this for every kernel
  roll and new release) and there shouldn't be any runtime changes. One
  potential problem is if the proposed changes do not properly rectify the
  mismatch in the apparmor features, but in that case we just go through
  the process again with a new MP.
  
  [ Other Info ]
  
  * This bug just affects Noble 24.04

** Summary changed:

- SRU] Apparmor feature mismatch for the 7.0 kernel in noble
+ [SRU] Apparmor feature mismatch for the 7.0 kernel in noble

-- 
You received this bug notification because you are a member of Ubuntu
Bugs, which is subscribed to Ubuntu.
https://bugs.launchpad.net/bugs/2161121

Title:
  [SRU] Apparmor feature mismatch for the 7.0 kernel in noble

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/livecd-rootfs/+bug/2161121/+subscriptions


-- 
ubuntu-bugs mailing list
[email protected]
https://lists.ubuntu.com/mailman/listinfo/ubuntu-bugs

Reply via email to