-
Notifications
You must be signed in to change notification settings - Fork 680
release: add notes of FIPS build and release #17002
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
bboozzoo
merged 4 commits into
canonical:master
from
bboozzoo:bboozzoo/fips-release-notes
May 20, 2026
+45
−3
Merged
Changes from 1 commit
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
833d706
release: add notes of FIPS build and release
bboozzoo 0b9d9e9
fixup! release: add notes of FIPS build and release
bboozzoo 738ddc3
fixup! release: add notes of FIPS build and release
bboozzoo 58fc6d2
fixup! release: add notes of FIPS build and release
bboozzoo File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Some comments aren't visible on the classic Files Changed page.
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
|
|
@@ -336,6 +336,33 @@ Push the version tag to the canonical/snapd repo by following the steps: | |
| 6. Once you are done setting it up, save, click on the package (https://launchpad.net/~snappy-dev/+snap/snapd-2.XX), and request builds. | ||
| 7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep beta/<version>` | ||
|
|
||
| ##### 4.1 Create snapd FIPS builds for `fips-updates/beta/<version>` on Launchpad | ||
|
|
||
| Prerequisites: | ||
| - You are a member of [Ubuntu Core/Snapd FIPS team](https://launchpad.net/~uc-snapd-fips) - if not, ask for an invite. | ||
| - You have access to a FIPS enabled Ubuntu 24.04 or 22.04 system. An LXD VM which you can set up by running `pro attach <my-token> && pro enable fips-updates` is sufficient. | ||
|
|
||
| Repeat steps 1-4 from section 4, then: | ||
| 5. In yet another window open the [snapd-fips package edit page](https://launchpad.net/~ubuntu-advantage/fips-cc-stig/+snap/snapd-fips/+edit) for reference. | ||
| 6. Set `snapd-fips-<2.XX>` as the recipe name. The recipe **MUST** be owned by `ubuntu-advantage` and associated with `fips-cc-stig` project. The build **MUST** be done using `~ubuntu-advantage/ubuntu/pro-fips-updates` PPA for FIPS modules to be automatically located at build time. Use the same branch as for the non-FIPS build. Configure automatic store upload to `fips-updates/beta/<version>` branch. Only select `amd64` and `arm64` architectures. Save the package and request builds, double check that the right PPA is used for the builds. | ||
| 7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep fips-updates/beta/<version>`. The snap version should be `2.XX+fips`. | ||
|
|
||
| **IMPORTANT: the `+fips` suffix is added automatically at build time once the relevant FIPS modules were found. If the suffix is missing, ensure that a correct PPA was enabled during the build.** | ||
|
|
||
| Post-build verification steps; | ||
| 8. In a FIPS enabled VM (confirm by `/proc/sys/crypto/fips_enabled` contains `1`), install snapd snap from the build branch. | ||
| 9. Confirm snapd snap version. Confirm the FIPS provider module is used at runtime by running: `pmap -p $(pidof snapd) |grep fips.so`. | ||
| Example: | ||
| ``` | ||
| root@vu3-2404-pro-fips:~# pmap -p $(pidof snapd) |grep fips.so | ||
| 0000791b7697f000 100K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| 0000791b76998000 1068K r-x-- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| 0000791b76aa3000 236K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| 0000791b76ade000 4K ----- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| 0000791b76adf000 88K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| 0000791b76af5000 4K rw--- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so | ||
| ``` | ||
|
|
||
| #### 5. Release to latest/beta | ||
|
|
||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Again perhaps explicit 5.1 for non-fips and 5.2 for fips? |
||
| Prerequisites: | ||
|
Member
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more.
|
||
|
|
@@ -350,6 +377,11 @@ Steps: | |
| 4. Update internal roadmap tracking, for example by marking Jira epics and releases as completed. | ||
| 5. Update GitHub milestones to close the released milestone | ||
|
|
||
| ##### 5.1 Release of FIPS artifact to fips-updates/beta | ||
|
|
||
| 1. Find the revisions for the snap in `fips-updates/beta/<version>` branch. | ||
| 2. For each architecture build (`amd64` and `arm64`), release it to `fips-updates` track by running `snapcraft release snapd <revision-number> fips-updates/beta`. | ||
|
|
||
| #### 6. Post-beta steps | ||
|
|
||
| 1. Let snapd QA know that snapd was promoted to beta so they can verify that testing has started. | ||
|
|
||
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.