Debian Package Tracker
Register | Log in
Subscribe

snapd

Daemon and tooling that enable snap packages

Choose email to subscribe with

general
  • source: snapd (main)
  • version: 2.48.2-3
  • maintainer: Michael Hudson-Doyle (DMD)
  • uploaders: Luke Faraone [DMD] – Steve Langasek [DMD] – Zygmunt Krynicki [DMD] [DM]
  • arch: all any
  • std-ver: 3.9.8
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • oldstable: 2.21-2
  • old-sec: 2.21-2+deb9u1
  • stable: 2.37.4-1
  • testing: 2.45.2-1
  • unstable: 2.48.2-3
versioned links
  • 2.21-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.21-2+deb9u1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.37.4-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.45.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2.48.2-3: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • golang-github-snapcore-snapd-dev
  • golang-github-ubuntu-core-snappy-dev
  • snap-confine (1 bugs: 0, 0, 1, 0)
  • snapd (21 bugs: 1, 19, 1, 0)
  • ubuntu-core-launcher
action needed
Debci reports failed tests high
  • unstable: neutral (log)
    The tests ran in 0:01:21
    Last run: 2020-07-09 01:53:02 UTC
    Previous status: neutral

  • testing: neutral (log)
    The tests ran in 0:00:22
    Last run: 2021-01-20 12:36:12 UTC
    Previous status: neutral

  • stable: fail (log)
    The tests ran in 0:00:40
    Last run: 2019-04-24 07:15:23 UTC
    Previous status: fail

Created: 2019-10-12 Last update: 2021-01-23 04:07
Standards version of the package is outdated. high
The package is severely out of date with respect to the Debian Policy. The package should be updated to follow the last version of Debian Policy (Standards-Version 4.5.1 instead of 3.9.8).
Created: 2017-08-14 Last update: 2021-01-22 19:05
The VCS repository is not up to date, push the missing commits. high
vcswatch reports that the current version of the package is not in its VCS.
Either you need to push your commits and/or your tags, or the information about the package's VCS are out of date. A common cause of the latter issue when using the Git VCS is not specifying the correct branch when the packaging is not in the default one (remote HEAD branch), which is usually "master" but can be modified in salsa.debian.org in the project's general settings with the "Default Branch" field). Alternatively the Vcs-Git field in debian/control can contain a "-b <branch-name>" suffix to indicate what branch is used for the Debian packaging.
Created: 2019-02-19 Last update: 2021-01-22 16:05
lintian reports 1 error and 12 warnings high
Lintian reports 1 error and 12 warnings about this package. You should make the package lintian clean getting rid of them.
Created: 2020-07-29 Last update: 2020-09-21 06:04
Fails to build during reproducibility testing normal
A package building reproducibly enables third parties to verify that the source matches the distributed binaries. It has been identified that this source package produced different results, failed to build or had other issues in a test environment. Please read about how to improve the situation!
Created: 2018-07-29 Last update: 2021-01-23 03:35
Multiarch hinter reports 2 issue(s) normal
There are issues with the multiarch metadata for this package.
  • golang-github-snapcore-snapd-dev could be marked Multi-Arch: foreign
  • ubuntu-core-launcher could be marked Multi-Arch: same
Created: 2016-09-14 Last update: 2021-01-23 02:35
3 ignored security issues in stretch low
There are 3 open security issues in stretch.
3 issues skipped by the security teams:
  • CVE-2019-11502: snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
  • CVE-2019-11503: snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
  • CVE-2019-7303: A vulnerability in the seccomp filters of Canonical snapd before version 2.37.4 allows a strict mode snap to insert characters into a terminal on a 64-bit host. The seccomp rules were generated to match 64-bit ioctl(2) commands on a 64-bit platform; however, the Linux kernel only uses the lower 32 bits to determine which ioctl(2) commands to run. This issue affects: Canonical snapd versions prior to 2.37.4.
Please fix them.
Created: 2019-04-25 Last update: 2021-01-22 17:00
3 ignored security issues in buster low
There are 3 open security issues in buster.
3 issues skipped by the security teams:
  • CVE-2019-11502: snap-confine in snapd before 2.38 incorrectly set the ownership of a snap application to the uid and gid of the first calling user. Consequently, that user had unintended access to a private /tmp directory.
  • CVE-2019-11503: snap-confine as included in snapd before 2.39 did not guard against symlink races when performing the chdir() to the current working directory of the calling user, aka a "cwd restore permission bypass."
  • CVE-2020-11934: It was discovered that snapctl user-open allowed altering the $XDG_DATA_DIRS environment variable when calling the system xdg-open. OpenURL() in usersession/userd/launcher.go would alter $XDG_DATA_DIRS to append a path to a directory controlled by the calling snap. A malicious snap could exploit this to bypass intended access restrictions to control how the host system xdg-open script opens the URL and, for example, execute a script shipped with the snap without confinement. This issue did not affect Ubuntu Core systems. Fixed in snapd versions 2.45.1ubuntu0.2, 2.45.1+18.04.2 and 2.45.1+20.04.2.
Please fix them.
Created: 2019-04-25 Last update: 2021-01-22 17:00
testing migrations
  • excuses:
    • Migration status for snapd (2.45.2-1 to 2.48.2-3): Waiting for test results, another package or too young (no action required now - check later)
    • Issues preventing migration:
    • autopkgtest for snapd/2.48.2-3: amd64: No test results, arm64: No test results, armhf: No test results, i386: No test results, ppc64el: Test in progress
    • Too young, only 1 of 5 days old
    • Additional info:
    • Piuparts tested OK - https://piuparts.debian.org/sid/source/s/snapd.html
    • Not considered
news
[rss feed]
  • [2021-01-22] Accepted snapd 2.48.2-3 (source) into unstable (Michael Vogt)
  • [2021-01-15] Accepted snapd 2.21-2+deb9u1 (source all amd64) into oldstable (Brian May)
  • [2021-01-15] Accepted snapd 2.48.2-2 (source) into unstable (Michael Vogt)
  • [2021-01-15] Accepted snapd 2.48.2-1 (source) into unstable (Michael Vogt)
  • [2020-07-18] snapd 2.45.2-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-15] Accepted snapd 2.45.2-1 (source) into unstable (Michael Vogt)
  • [2020-04-11] snapd 2.44.1-2 MIGRATED to testing (Debian testing watch)
  • [2020-04-06] Accepted snapd 2.44.1-2 (source) into unstable (Michael Vogt)
  • [2020-03-24] Accepted snapd 2.44.1-1 (source) into unstable (Michael Vogt)
  • [2019-11-11] snapd 2.42.1-1 MIGRATED to testing (Debian testing watch)
  • [2019-11-06] Accepted snapd 2.42.1-1 (source) into unstable (Michael Vogt)
  • [2019-07-24] Accepted snapd 2.40-1 (source all amd64) into unstable (Michael Vogt)
  • [2019-03-11] snapd 2.37.4-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-28] Accepted snapd 2.37.4-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2019-02-19] Accepted snapd 2.37.3-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2019-02-12] snapd 2.37.2-1 MIGRATED to testing (Debian testing watch)
  • [2019-02-07] Accepted snapd 2.37.2-1 (source) into unstable (Michael Hudson-Doyle)
  • [2019-01-29] Accepted snapd 2.37.1-1 (source) into unstable (Zygmunt Krynicki) (signed by: Zygmunt Bazyli Krynicki)
  • [2019-01-29] snapd 2.37-3 MIGRATED to testing (Debian testing watch)
  • [2019-01-24] Accepted snapd 2.37-3 (source) into unstable (Michael Hudson-Doyle)
  • [2019-01-23] Accepted snapd 2.37-2 (source) into unstable (Michael Hudson-Doyle)
  • [2018-02-16] snapd 2.30-5 MIGRATED to testing (Debian testing watch)
  • [2018-02-10] Accepted snapd 2.30-5 (source) into unstable (Michael Stapelberg)
  • [2018-01-21] snapd 2.30-4 MIGRATED to testing (Debian testing watch)
  • [2018-01-16] Accepted snapd 2.30-4 (source) into unstable (Michael Hudson-Doyle)
  • [2018-01-09] Accepted snapd 2.30-3 (source) into unstable (Michael Hudson-Doyle)
  • [2018-01-08] Accepted snapd 2.30-2 (source) into unstable (Michael Hudson-Doyle)
  • [2018-01-04] Accepted snapd 2.30-1 (source) into unstable (Michael Hudson-Doyle)
  • [2017-10-02] snapd 2.27.6-2 MIGRATED to testing (Debian testing watch)
  • [2017-09-26] Accepted snapd 2.27.6-2 (source) into unstable (Michael Hudson-Doyle)
  • 1
  • 2
bugs [bug history graph]
  • all: 26
  • RC: 1
  • I&N: 22
  • M&W: 3
  • F&P: 0
  • patch: 0
  • NC: 1
links
  • homepage
  • lintian (1, 12)
  • buildd: logs, clang, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
  • screenshots
  • l10n (-, 26)
  • debci
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.48+21.04
  • 231 bugs (2 patches)

Debian Package Tracker — Copyright 2013-2018 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing