Skip to content
Merged
Changes from 3 commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
48 changes: 45 additions & 3 deletions RELEASE.md
Original file line number Diff line number Diff line change
Expand Up @@ -106,7 +106,7 @@ flowchart LR
### Release output artifacts

The release process produces the following:
- The snapd snap https://snapcraft.io/snapd
- The snapd snap https://snapcraft.io/snapd (a regular build and a FIPS one)
- snapd debs https://launchpad.net/ubuntu/+source/snapd/
- GitHub release https://github.com/canonical/snapd/releases
- Cross-distro artifacts https://snapcraft.io/docs/reference/administration/distribution-support/
Expand All @@ -123,6 +123,8 @@ The complete set of prerequisites for all release process steps is as follows:
- ability to promote snapd via snapcraft (you can check if you have permission by running `snapcraft status snapd`)
- permission to run autopkgtests in Launchpad (autopkgtest-requesters group membership; request via debcrafters)
- permission to re-trigger failing autopkgtests running on -proposed (request via debcrafters)
- you are a member of [Ubuntu Core/Snapd FIPS team](https://launchpad.net/~uc-snapd-fips) (ask for an invite if needed)
- you have access to a FIPS enabled Ubuntu 24.04 or 22.04 system (an LXD VM which you can set up by running `pro attach <my-token> && pro enable fips-updates` is sufficient)

# Full Release Process

Expand Down Expand Up @@ -324,10 +326,14 @@ Push the version tag to the canonical/snapd repo by following the steps:
2. You should use a regular merge commit to merge it (not squash and merge, not rebase and merge)
4. Once merged, the tag's commit should be found on the master branch `git branch --contains <tag/tag-commit>`

#### 4. Create snapd snap builds for `beta/<version>` on Launchpad
#### 4. Create snapd snap builds on Launchpad

**IMPORTANT: Only trigger the snapd snap builds once you see the tag has been imported to Launchpad. The version is derived from the tag, so its absence will incorrectly produce `<version>+git`**

##### 4.1 Regular builds (`latest/beta/<version>`)

The following steps document how to build a snapd snap artifact which will be published to `latest/beta/<version>` branch.

1. Go to https://code.launchpad.net/~snappy-dev/snapd/+git/snapd
Comment thread
ernestl marked this conversation as resolved.
2. Click "import now" to import the codebase
3. Click on https://code.launchpad.net/~snappy-dev/snapd/+git/snapd/+ref/release/2.XX and attempt to browse the code. It will probably not work, but if it does work, then you can confirm the presence of the git tag.
Expand All @@ -336,7 +342,38 @@ Push the version tag to the canonical/snapd repo by following the steps:
6. Once you are done setting it up, save, click on the package (https://launchpad.net/~snappy-dev/+snap/snapd-2.XX), and request builds.
7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep beta/<version>`

#### 5. Release to latest/beta
##### 4.2 FIPS builds (`fips-updates/beta/<version>`)

The following steps document how to build the FIPS-enabled snapd artifact which will be published to `fips-updates/beta/<version>` branch.

Prerequisites:
- You are a member of [Ubuntu Core/Snapd FIPS team](https://launchpad.net/~uc-snapd-fips) - if not, ask for an invite.
- You have access to a FIPS enabled Ubuntu 24.04 or 22.04 system. An LXD VM which you can set up by running `pro attach <my-token> && pro enable fips-updates` is sufficient.
Comment thread
bboozzoo marked this conversation as resolved.

Repeat steps 1-4 from section 4.1, then:
5. In yet another window open the [snapd-fips package edit page](https://launchpad.net/~ubuntu-advantage/fips-cc-stig/+snap/snapd-fips/+edit) for reference.
6. Set `snapd-fips-<2.XX>` as the recipe name. The recipe **MUST** be owned by `ubuntu-advantage` and associated with `fips-cc-stig` project. The build **MUST** be done using `~ubuntu-advantage/ubuntu/pro-fips-updates` PPA for FIPS modules to be automatically located at build time. Use the same branch as for the non-FIPS build. Configure automatic store upload to `fips-updates/beta/<version>` branch. Only select `amd64` and `arm64` architectures. Save the package and request builds, double check that the right PPA is used for the builds.
7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep fips-updates/beta/<version>`. The snap version should be `2.XX+fips`.

**IMPORTANT: the `+fips` suffix is added automatically at build time once the relevant FIPS modules were found. If the suffix is missing, ensure that a correct PPA was enabled during the build.**

Post-build verification steps:
8. In a FIPS enabled VM (confirm by `/proc/sys/crypto/fips_enabled` contains `1`), install snapd snap from the build branch.
9. Confirm snapd snap version. Confirm the FIPS provider module is used at runtime by running: `pmap -p $(pidof snapd) |grep fips.so`.
Example:
```
root@vu3-2404-pro-fips:~# pmap -p $(pidof snapd) |grep fips.so
0000791b7697f000 100K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
0000791b76998000 1068K r-x-- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
0000791b76aa3000 236K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
0000791b76ade000 4K ----- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
0000791b76adf000 88K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
0000791b76af5000 4K rw--- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so
```

#### 5. Release to beta

##### 5.1 Release to `latest/beta`

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Again perhaps explicit 5.1 for non-fips and 5.2 for fips?

Prerequisites:

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Prerequisites seems to be common, so should probable move to 5. ?

- You have the necessary snapcraft permissions to promote the snapd snap
Expand All @@ -350,6 +387,11 @@ Steps:
4. Update internal roadmap tracking, for example by marking Jira epics and releases as completed.
5. Update GitHub milestones to close the released milestone

##### 5.2 Release to `fips-updates/beta` (FIPS)

1. Find the revisions for the snap in `fips-updates/beta/<version>` branch.
2. For each architecture build (`amd64` and `arm64`), release it to `fips-updates` track by running `snapcraft release snapd <revision-number> fips-updates/beta`.

#### 6. Post-beta steps

1. Let snapd QA know that snapd was promoted to beta so they can verify that testing has started.
Expand Down
Loading