diff --git a/RELEASE.md b/RELEASE.md index 4a9be32a337..c4c8e3cc265 100644 --- a/RELEASE.md +++ b/RELEASE.md @@ -106,7 +106,7 @@ flowchart LR ### Release output artifacts The release process produces the following: -- The snapd snap https://snapcraft.io/snapd +- The snapd snap https://snapcraft.io/snapd (a regular build and a FIPS one) - snapd debs https://launchpad.net/ubuntu/+source/snapd/ - GitHub release https://github.com/canonical/snapd/releases - Cross-distro artifacts https://snapcraft.io/docs/reference/administration/distribution-support/ @@ -123,6 +123,8 @@ The complete set of prerequisites for all release process steps is as follows: - ability to promote snapd via snapcraft (you can check if you have permission by running `snapcraft status snapd`) - permission to run autopkgtests in Launchpad (autopkgtest-requesters group membership; request via debcrafters) - permission to re-trigger failing autopkgtests running on -proposed (request via debcrafters) +- you are a member of [Ubuntu Core/Snapd FIPS team](https://launchpad.net/~uc-snapd-fips) (ask for an invite if needed) +- you have access to a FIPS enabled Ubuntu 24.04 or 22.04 system (an LXD VM which you can set up by running `pro attach && pro enable fips-updates` is sufficient) # Full Release Process @@ -324,10 +326,14 @@ Push the version tag to the canonical/snapd repo by following the steps: 2. You should use a regular merge commit to merge it (not squash and merge, not rebase and merge) 4. Once merged, the tag's commit should be found on the master branch `git branch --contains ` -#### 4. Create snapd snap builds for `beta/` on Launchpad +#### 4. Create snapd snap builds on Launchpad **IMPORTANT: Only trigger the snapd snap builds once you see the tag has been imported to Launchpad. The version is derived from the tag, so its absence will incorrectly produce `+git`** +##### 4.1 Regular builds (`latest/beta/`) + +The following steps document how to build a snapd snap artifact which will be published to `latest/beta/` branch. + 1. Go to https://code.launchpad.net/~snappy-dev/snapd/+git/snapd 2. Click "import now" to import the codebase 3. Click on https://code.launchpad.net/~snappy-dev/snapd/+git/snapd/+ref/release/2.XX and attempt to browse the code. It will probably not work, but if it does work, then you can confirm the presence of the git tag. @@ -336,13 +342,44 @@ Push the version tag to the canonical/snapd repo by following the steps: 6. Once you are done setting it up, save, click on the package (https://launchpad.net/~snappy-dev/+snap/snapd-2.XX), and request builds. 7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep beta/` -#### 5. Release to latest/beta +##### 4.2 FIPS builds (`fips-updates/beta/`) + +The following steps document how to build the FIPS-enabled snapd artifact which will be published to `fips-updates/beta/` branch. + +Prerequisites: +- You are a member of [Ubuntu Core/Snapd FIPS team](https://launchpad.net/~uc-snapd-fips) - if not, ask for an invite. +- You have access to a FIPS enabled Ubuntu 24.04 or 22.04 system. An LXD VM which you can set up by running `pro attach && pro enable fips-updates` is sufficient. + +Repeat steps 1-4 from section 4.1, then: +5. In yet another window open the [snapd-fips package edit page](https://launchpad.net/~ubuntu-advantage/fips-cc-stig/+snap/snapd-fips/+edit) for reference. +6. Set `snapd-fips-<2.XX>` as the recipe name. The recipe **MUST** be owned by `ubuntu-advantage` and associated with `fips-cc-stig` project. The build **MUST** be done using `~ubuntu-advantage/ubuntu/pro-fips-updates` PPA for FIPS modules to be automatically located at build time. Use the same branch as for the non-FIPS build. Configure automatic store upload to `fips-updates/beta/` branch. Only select `amd64` and `arm64` architectures. Save the package and request builds, double check that the right PPA is used for the builds. +7. Once the builds have completed, ensure the versions are correct by checking `snapcraft status snapd | grep fips-updates/beta/`. The snap version should be `2.XX+fips`. + +**IMPORTANT: the `+fips` suffix is added automatically at build time once the relevant FIPS modules were found. If the suffix is missing, ensure that a correct PPA was enabled during the build.** + +Post-build verification steps: +8. In a FIPS enabled VM (confirm by `/proc/sys/crypto/fips_enabled` contains `1`), install snapd snap from the build branch. +9. Confirm snapd snap version. Confirm the FIPS provider module is used at runtime by running: `pmap -p $(pidof snapd) |grep fips.so`. + Example: + ``` + root@vu3-2404-pro-fips:~# pmap -p $(pidof snapd) |grep fips.so + 0000791b7697f000 100K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + 0000791b76998000 1068K r-x-- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + 0000791b76aa3000 236K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + 0000791b76ade000 4K ----- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + 0000791b76adf000 88K r---- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + 0000791b76af5000 4K rw--- /snap/snapd/26976/usr/lib/x86_64-linux-gnu/ossl-modules-3/fips.so + ``` + +#### 5. Release to beta Prerequisites: - You have the necessary snapcraft permissions to promote the snapd snap - You have permission from the snapd manager to promote to latest/beta - Builds on all architectures have succeeded +##### 5.1 Release to `latest/beta` + Steps: 1. Sync with the QA person on the team in charge of beta testing to make sure we can go to beta. For example, if a previous release has not yet made it to candidate, we would need to hold off on promoting. 2. Find the revisions for the snap you just pushed. It will be `beta/`. You can find the revisions by running `snapcraft status snapd` @@ -350,6 +387,11 @@ Steps: 4. Update internal roadmap tracking, for example by marking Jira epics and releases as completed. 5. Update GitHub milestones to close the released milestone +##### 5.2 Release to `fips-updates/beta` (FIPS) + +1. Find the revisions for the snap in `fips-updates/beta/` branch. +2. For each architecture build (`amd64` and `arm64`), release it to `fips-updates` track by running `snapcraft release snapd fips-updates/beta`. + #### 6. Post-beta steps 1. Let snapd QA know that snapd was promoted to beta so they can verify that testing has started.