- 
    Tue Nov 02 2021 Maciek Borzecki <maciek.borzecki@gmail.com> - 2.53.1-2
    
- Disable BPF support on systems that are too old
   
  
  - 
    Tue Nov 02 2021 Maciek Borzecki <maciek.borzecki@gmail.com> - 2.53.1-1
    
- Release 2.53.1 to Fedora
   
  
  - 
    Thu Oct 21 2021 Ian Johnson <ian.johnson@canonical.com>
    
- New upstream release 2.53.1
 - spread: run lxd tests with version from latest/stable
 - secboot: use latest secboot with tpm legacy platform and v2 fully
   optional (#10946)
 - cmd/snap-confine: die when snap process is outside of snap
   specific cgroup (2.53)
 - interfaces/u2f-devices: add Nitrokey 3
 - Update the ubuntu-image channel to candidate
 - Allow hostnames up to 253 characters, with dot-delimited elements
   (as suggested by man 7 hostname).
 - Disable i386 until it is possible to build snapd using lxd
 - o/snapstate, hookstate: print remaining hold time on snapctl
   --hold
 - tests/snapd-sigterm: be more robust against service restart
 - tests: add a regression test for snapd hanging on SIGTERM
 - daemon: use the syscall connection to get the socket
   credentials
 - interfaces/builtin/hardware-observer: add /proc/bus/input/devices
   too
 - cmd/snap-confine/snap-confine.apparmor.in: update ld rule for
   s390x impish
 - interface/modem-manager: add accept for MBIM/QMI proxy clients
 - secboot: revert move to new version
   
  
  - 
    Tue Oct 05 2021 Michael Vogt <michael.vogt@ubuntu.com>
    
- New upstream release 2.53
 - overlord: fix generated snap-revision assertions in remodel unit
   tests
 - snap-bootstrap: wait in `mountNonDataPartitionMatchingKernelDisk`
 - interfaces/modem-manager: add access to PCIe modems
 - overlord/devicestate: record recovery capable system on a
   successful remodel
 - o/snapstate: use device ctx in prerequisite install/update
 - osutil/disks: support filtering by mount opts in
   MountPointsForPartitionRoot
 - many: support an API flag system-restart-immediate to make snap
   ops proceed immediately with system restarts
 - osutil/disks: add RootMountPointsForPartition
 - overlord/devicestate, tests: enable UC20 remodel, add spread tests
 - cmd/snap: improve snap run help message
 - o/snapstate: support ignore validation flag on install/update
 - osutil/disks: add Disk.FindMatchingPartitionWith{Fs,Part}Label
 - desktop: implement gtk notification backend and provide minimal
   notification api
 - tests: use the latest cpu family for nested tests execution
 - osutil/disks: add Partition struct and Disks.Partitions()
 - o/snapstate: prevent install hang if prereq install fails
 - osutil/disks: add Disk.KernelDevice{Node,Path} methods
 - disks: add `Size(path)` helper
 - tests: reset some mount units failing on ubuntu impish
 - osutil/disks: add DiskFromDevicePath, other misc changes
 - interfaces/apparmor: do not fail during initialization when there
   is no AppArmor profile for snap-confine
 - daemon: implement access checkers for themes API
 - interfaces/seccomp: add clone3 to default template
 - interfaces/u2f-devices: add GoTrust Idem Key
 - o/snapstate: validation sets enforcing on update
 - o/ifacestate: don't fail remove if disconnect hook fails
 - tests: fix error trying to create the extra-snaps dir which
   already exists
 - devicestate: use EncryptionType
 - cmd/libsnap-confine-private: workaround BPF memory accounting,
   update apparmor profile
 - tests: skip system-usernames-microk8s when TRUST_TEST_KEYS is
   false
 - interfaces/dsp: add a usb rule to the ambarella flavor
 - interfaces/apparmor/template.go: allow inspection of dbus
   mediation level
 - tests/main/security-device-cgroups: fix when both variants run on
   the same host
 - cmd/snap-confine: update s-c apparmor profile to allow versioned
   ld.so
 - many: rename systemd.Kind to Backend for a bit more clarity
 - cmd/libsnap-confine-private: fix set but unused variable in the
   unit tests
 - tests: fix netplan test on i386 architecture
 - tests: fix lxd-mount-units test which is based on core20 in ubuntu
   focal system
 - osutil/disks: add new `CreateLinearMapperDevice` helper
 - cmd/snap: wait while inhibition file is present
 - tests: cleanup the job workspace as first step of the actions
   workflow
 - tests: use our own image for ubuntu impish
 - o/snapstate: update default provider if missing required content
 - o/assertstate, api: update validation set assertions only when
   updating all snaps
 - fde: add HasDeviceUnlock() helper
 - secboot: move to new version
 - o/ifacestate: don't lose connections if snaps are broken
 - spread: display information about current device cgroup in debug
   dump
 - sysconfig: set TMPDIR in tests to avoid cluttering the real /tmp
 - tests, interfaces/builtin: introduce 21.10 cgroupv2 variant, tweak
   tests for cgroupv2, update builtin interfaces
 - sysconfig/cloud-init: filter MAAS c-i config from ubuntu-seed on
   grade signed
 - usersession/client: refactor doMany() method
 - interfaces/builtin/opengl.go: add libOpenGL.so* too
 - o/assertstate: check installed snaps when refreshing validation
   set assertions
 - osutil: helper for injecting run time faults in snapd
 - tests: update test nested tool part 2
 - libsnap-confine: use the pid parameter
 - gadget/gadget.go: LaidOutSystemVolumeFromGadget ->
   LaidOutVolumesFromGadget
 - tests: update the time tolerance to fix the snapd-state test
 - .github/workflows/test.yaml: revert #10809
 - tests: rename interfaces-hooks-misbehaving spread test to install-
   hook-misbehaving
 - data/selinux: update the policy to allow s-c to manipulate BPF map
   and programs
 - overlord/devicestate: make settle wait longer in remodel tests
 - kernel/fde: mock systemd-run in unit test
 - o/ifacestate: do not create stray task in batchConnectTasks if
   there are no connections
 - gadget: add VolumeName to Volume and VolumeStructure
 - cmd/libsnap-confine-private: use root when necessary for BPF
   related operations
 - .github/workflows/test.yaml: bump action-build to 1.0.9
 - o/snapstate: enforce validation sets/enforce on InstallMany
 - asserts, snapstate: return full validation set keys from
   CheckPresenceRequired and CheckPresenceInvalid
 - cmd/snap: only log translation warnings in debug/testing
 - tests/main/preseed: update for new base snap of the lxd snap
 - tests/nested/manual: use loop for checking for initialize-system
   task done
 - tests: add a local snap variant to testing prepare-image gating
   support
 - tests/main/security-device-cgroups-strict-enforced: demonstrate
   device cgroup being enforced
 - store: one more tweak for the test action timeout
 - github: do not fail when codecov upload fails
 - o/devicestate: fix flaky test remodel clash
 - o/snapstate: add ChangeID to conflict error
 - tests: fix regex of TestSnapActionTimeout test
 - tests: fix tests for 21.10
 - tests: add test for store.SnapAction() request timeout
 - tests: print user sessions info on debug-each
 - packaging: backports of golang-go 1.13 are good enough
 - sysconfig/cloudinit: add cloudDatasourcesInUseForDir
 - cmd: build gdb shims as static binaries
 - packaging/ubuntu: pass GO111MODULE to dh_auto_test
 - cmd/libsnap-confine-private, tests, sandbox: remove warnings about
   cgroup v2, drop forced devmode
 - tests: increase memory quota in quota-groups-systemd-accounting
 - tests: be more robust against a new day stepping in
 - usersession/xdgopenproxy: move PortalLauncher class to own package
 - interfaces/builtin: fix microstack unit tests on distros using
   /usr/libexec
 - cmd/snap-confine: handle CURRENT_TAGS on systems that support it
 - cmd/libsnap-confine-private: device cgroup v2 support
 - o/servicestate: Update task summary for restart action
 - packaging, tests/lib/prepare-restore: build packages without
   network access, fix building debs with go modules
 - systemd: add AtLeast() method, add mocking in systemdtest
 - systemd: use text.template to generate mount unit
 - o/hookstate/ctlcmd: Implement snapctl refresh --show-lock command
 - o/snapstate: optimize conflicts around snaps stored on
   conditional-auto-refresh task
 - tests/lib/prepare.sh: download core20 for UC20 runs via
   BASE_CHANNEL
 - mount-control: step 1
 - go: update go.mod dependencies
 - o/snapstate: enforce validation sets on snap install
 - tests: revert revert manual lxd removal
 - tests: pre-cache snaps in classic and core systems
 - tests/lib/nested.sh: split out additional helper for adding files
   to VM imgs
 - tests: update nested tool - part1
 - image/image_linux.go: add newline
 - interfaces/block-devices: support to access the state of block
   devices
 - o/hookstate: require snap-refresh-control interface for snapctl
   refresh --proceed
 - build-aux: stage libgcc1 library into snapd snap
 - configcore: add read-only netplan support
 - tests: fix fakedevicesvc service already exists
 - tests: fix interfaces-libvirt test
 - tests: remove travis leftovers
 - spread: bump delta ref to 2.52
 - packaging: ship the `snapd.apparmor.service` unit in debian
 - packaging: remove duplicated `golang-go` build-dependency
 - boot: record recovery capable systems in recovery bootenv
 - tests: skip overlord tests on riscv64 due to timeouts.
 - overlord/ifacestate: fix arguments in unit tests
 - ifacestate: undo repository connection if doConnect fails
 - many: remove unused parameters
 - tests: failure of prereqs on content interface doesn't prevent
   install
 - tests/nested/manual/refresh-revert-fundamentals: fix variable use
 - strutil: add Intersection()
 - o/ifacestate: special-case system-files and force refreshing its
   static attributes
 - interface/builtin: add qualcomm-ipc-router interface for
   AF_QIPCRTR socket protocol
 - tests:  new snapd-state tool
 - codecov: fix files pathnames
 - systemd: add mock systemd helper
 - tests/nested/core/extra-snaps-assertions: fix the match pattern
 - image,c/snap,tests: support enforcing validations in prepare-image
   via --customize JSON validation enforce(|ignore)
 - o/snapstate: enforce validation sets assertions when removing
   snaps
 - many: update deps
 - interfaces/network-control: additional ethernet rule
 - tests: use host-scaled settle timeout for hookstate tests
 - many: move to go modules
 - interfaces: no need for snapRefreshControlInterface struct
 - interfaces: introduce snap-refresh-control interface
 - tests: move interfaces-libvirt test back to 16.04
 - tests: bump the number of retries when waiting for /dev/nbd0p1
 - tests: add more space on ubuntu xenial
 - spread: add 21.10 to qemu, remove 20.10 (EOL)
 - packaging: add libfuse3-dev build dependency
 - interfaces: add microstack-support interface
 - wrappers: fix a bunch of duplicated service definitions in tests
 - tests: use host-scaled timeout to avoid riscv64 test failure
 - many: fix run-checks gofmt check
 - tests: spread test for snapctl refresh --pending/--proceed from
   the snap
 - o/assertstate,daemon: refresh validation sets assertions with snap
   declarations
 - tests: migrate tests that are only executed on xenial to bionic
 - tests: remove opensuse-15.1 and add opensuse-15.3 from spread runs
 - packaging: update master changelog for 2.51.7
 - sysconfig/cloudinit: fix bug around error state of cloud-init
 - interfaces, o/snapstate: introduce AffectsPlugOnRefresh flag
 - interfaces/interfaces/ion-memory-control: add: add interface for
   ion buf
 - interfaces/dsp: add /dev/ambad into dsp interface
 - tests: new spread log parser
 - tests: check files and dirs are cleaned for each test
 - o/hookstate/ctlcmd: unify the error message when context is
   missing
 - o/hookstate: support snapctl refresh --pending from snap
 - many: remove unused/dead code
 - cmd/libsnap-confine-private: add BPF support helpers
 - interfaces/hardware-observe: add some dmi properties
 - snapstate: abort kernel refresh if no gadget update can be found
 - many: shellcheck fixes
 - cmd/snap: add Size column to refresh --list
 - packaging: build without dwarf debugging data
 - snapstate: fix misleading `assumes` error message
 - tests: fix restore in snapfuse spread tests
 - o/assertstate: fix missing 'scheduled' header when auto refreshing
   assertions
 - o/snapstate: fail remove with invalid snap names
 - o/hookstate/ctlcmd: correct err message if missing root
 - .github/workflows/test.yaml: fix logic
 - o/snapstate: don't hold some snaps if not all snaps can be held by
   the given gating snap
 - c-vendor.c: new c-vendor subdir
 - store: make sure expectedZeroFields in tests gets updated
 - overlord: add manager test for "assumes" checking
 - store: deal correctly with "assumes" from the store raw yaml
 - sysconfig/cloudinit.go: add functions for filtering cloud-init
   config
 - cgroup-support: allow to hide cgroupv2 warning via ENV
 - gadget: Export mkfs functions for use in ubuntu-image
 - tests: set to 10 minutes the kill timeout for tests failing on
   slow boards
 - .github/workflows/test.yaml: test github.events key
 - i18n/xgettext-go: preserve already escaped quotes
 - cmd/snap-seccomp/syscalls: update syscalls list to libseccomp
   v2.2.0-428-g5c22d4b
 - github: do not try to upload coverage when working with cached run
 - tests/main/services-install-hook-can-run-svcs: shellcheck issue
   fix
 - interfaces/u2f-devices: add Nitrokey FIDO2
 - testutil: add DeepUnsortedMatches Checker
 - cmd, packaging: import BPF headers from kernel, detect whether
   host headers are usable
 - tests: fix services-refresh-mode test
 - tests: clean snaps.sh helper
 - tests: fix timing issue on security-dev-input-event-denied test
 - tests: update systems for sru validation
 - .github/workflows: add codedov again
 - secboot: remove duplicate import
 - tests: stop the service when is active in test interfaces-
   firewall-control test
 - packaging: remove TEST_GITHUB_AUTOPKGTEST support
 - packaging: merge 2.51.6 changelog back to master
 - secboot: use half the mem for KDF in AddRecoveryKey
 - secboot: switch main key KDF memory cost to 32KB
 - tests: remove the test user just when it was installed on create-
   user-2 test
 - spread: temporarily fix the ownership of /home/ubuntu/.ssh on
   21.10
 - daemon, o/snapstate: handle IgnoreValidation flag on install (2/3)
 - usersession/agent: refactor common JSON validation into own
   function
 - o/hookstate: allow snapctl refresh --proceed from snaps
 - cmd/libsnap-confine-private: fix issues identified by coverity
 - cmd/snap: print logs in local timezone
 - packaging: changelog for 2.51.5 to master
 - build-aux: build with go-1.13 in the snapcraft build too
 - config: rename "virtual" config to "external" config
 - devicestate: add `snap debug timings --ensure=install-system`
 - interfaces/builtin/raw_usb: fix platform typo, fix access to usb
   devices accessible through platform
 - o/snapstate: remove commented out code
 - cmd/snap-device-helper: reimplement snap-device-helper
 - cmd/libsnap-confine-private: fix coverity issues in tests, tweak
   uses of g_assert()
 - o/devicestate/handlers_install.go: add workaround to create dirs
   for install
 - o/assertstate: implement ValidationSetAssertionForEnforce helper
 - clang-format: stop breaking my includes
 - o/snapstate: allow auto-refresh limited to snaps affected by a
   specific gating snap
 - tests: fix core-early-config test to use tests.nested tool
 - sysconfig/cloudinit.go: measure (but don't use) gadget cloud-init
   datasource
 - c/snap,o/hookstate/ctlcmd: add JSON/string strict processing flags
   to snap/snapctl
 - corecfg: add "system.hostname" setting to the system settings
 - wrappers: measure time to enable services in StartServices()
 - configcore: fix early config timezone handling
 - tests/nested/manual: enable serial assertions on testkeys nested
   VM's
 - configcore: fix a bunch of incorrect error returns
 - .github/workflows/test.yaml: use snapcraft 4.x to build the snapd
   snap
 - packaging: merge 2.51.4 changelog back to master
 - {device,snap}state: skip kernel extraction in seeding
 - vendor: move to snapshot-4c814e1 branch and set fixed KDF options
 - tests: use bigger storage on ubuntu 21.10
 - snap: support links map in snap.yaml (and later from the store
   API)
 - o/snapstate: add AffectedByRefreshCandidates helper
 - configcore: register virtual config for timezone reading
 - cmd/libsnap-confine-private: move device cgroup files, add helper
   to deny a device
 - tests: fix cached-results condition in github actions workflow
 - interfaces/tee: add support for Qualcomm qseecom device node
 - packaging: fix build failure on bionic and simplify rules
 - o/snapstate: affectedByRefresh tweaks
 - tests: update nested wait for snapd command
 - interfaces/builtin: allow access to per-user GTK CSS overrides
 - tests/main/snapd-snap: install 4.x snapcraft to build the snapd
   snap
 - snap/squashfs: handle squashfs-tools 4.5+
 - asserts/snapasserts: CheckPresenceInvalid and
   CheckPresenceRequired methods
 - cmd/snap-confine: refactor device cgroup handling to enable easier
   v2 integration
 - tests: skip udp protocol on latest ubuntus
 - cmd/libsnap-confine-private: g_spawn_check_exit_status is
   deprecated since glib 2.69
 - interfaces: s/specifc/specific/
 - github: enable gofmt for Go 1.13 jobs
 - overlord/devicestate: UC20 specific set-model, managers tests
 - o/devicestate, sysconfig: refactor cloud-init config permission
   handling
 - config: add "virtual" config via config.RegisterVirtualConfig
 - packaging: switch ubuntu to use golang-1.13
 - snap: change `snap login --help` to not mention "buy"
 - tests: removing Ubuntu 20.10, adding 21.04 nested in spread
 - tests/many: remove lxd systemd unit to prevent unexpected
   leftovers
 - tests/main/services-install-hook-can-run-svcs: make variants more
   obvious
 - tests: force snapd-session-agent.socket to be re-generated
   
  
  - 
    Tue Oct 05 2021 Michael Vogt <michael.vogt@ubuntu.com>
    
- New upstream release 2.52.1
 - snap-bootstrap: wait in `mountNonDataPartitionMatchingKernelDisk`
   for the disk (if not present already)
 - many: support an API flag system-restart-immediate to make snap
   ops proceed immediately with system restarts
 - cmd/libsnap-confine-private: g_spawn_check_exit_status is
   deprecated since glib 2.69
 - interfaces/seccomp: add clone3 to default template
 - interfaces/apparmor/template.go: allow inspection of dbus
   mediation level
 - interfaces/dsp: add a usb rule to the ambarella flavor
 - cmd/snap-confine: update s-c apparmor profile to allow versioned
   ld.so
 - o/ifacestate: don't lose connections if snaps are broken
 - interfaces/builtin/opengl.go: add libOpenGL.so* too
 - interfaces/hardware-observe: add some dmi properties
 - build-aux: stage libgcc1 library into snapd snap
 - interfaces/block-devices: support to access the state of block
   devices
 - packaging: ship the `snapd.apparmor.service` unit in debian
   
  
  - 
    Wed Sep 29 2021 Maciek Borzecki <maciek.borzecki@gmail.com> - 2.52-1
    
- Update to 2.52
- Drop squashfs 4.5+ patch as it's part of 2.52 release
- Cherry pick clone3 seccom patch (RHBZ#2008737)
   
  
  - 
    Fri Sep 03 2021 Ian Johnson <ian.johnson@canonical.com>
    
- New upstream release 2.52
 - interface/builtin: add qualcomm-ipc-router interface for
   AF_QIPCRTR socket protocol
 - o/ifacestate: special-case system-files and force refreshing its
   static attributes
 - interfaces/network-control: additional ethernet rule
 - packaging: update 2.52 changelog with 2.51.7
 - interfaces/interfaces/ion-memory-control: add: add interface for
   ion buf
 - packaging: merge 2.51.6 changelog back to 2.52
 - secboot: use half the mem for KDF in AddRecoveryKey
 - secboot: switch main key KDF memory cost to 32KB
 - many: merge release/2.51 change to release/2.52
 - .github/workflows/test.yaml: use snapcraft 4.x to build the snapd
   snap
 - o/servicestate: use snap app names for ExplicitServices of
   ServiceAction
 - tests/main/services-install-hook-can-run-svcs: add variant w/o
   --enable
 - o/servicestate: revert only start enabled services
 - tests: adding Ubuntu 21.10 to spread test suite
 - interface/modem-manager: add support for MBIM/QMI proxy clients
 - cmd/snap/model: support storage-safety and snaps headers too
 - o/assertstate: Implement EnforcedValidationSets helper
 - tests: using retry tool for nested tests
 - gadget: check for system-save with multi volumes if encrypting
   correctly
 - interfaces: make the service naming entirely internal to systemd
   BE
 - tests/lib/reset.sh: fix removing disabled snaps
 - store/store_download.go: use system snap provided xdelta3 priority
   + fallback
 - packaging: merge changelog from 2.51.3 back to master
 - overlord: only start enabled services
 - interfaces/builtin: add sd-control interface
 - tests/nested/cloud-init-{never-used,nocloud}-not-vuln: fix tests,
   use 2.45
 - tests/lib/reset.sh: add workaround from refresh-vs-services tests
   for all tests
 - o/assertstate: check for conflicts when refreshing and committing
   validation set asserts
 - devicestate: add support to save timings from install mode
 - tests: new tests.nested commands copy and wait-for
 - install: add a bunch of nested timings
 - tests: drop any-python wrapper
 - store: set ResponseHeaderTimeout on the default transport
 - tests: fix test-snapd-user-service-sockets test removing snap
 - tests: moving nested_exec to nested.tests exec
 - tests: add tests about services vs snapd refreshes
 - client, cmd/snap, daemon: refactor REST API for quotas to match
   CLI org
 - c/snap,asserts: create/delete-key external keypair manager
   interaction
 - tests: revert disable of the delta download tests
 - tests/main/system-usernames-microk8s: disable on centos 7 too
 - boot: support device change
 - o/snapstate: remove unused refreshSchedule argument for
   isRefreshHeld helper
 - daemon/api_quotas.go: handle conflicts, returning conflict
   response
 - tests: test for gate-auto-refresh hook error resulting in hold
 - release: 2.51.2
 - snapstate/check_snap: add snap_microk8s to shared system-
   usernames
 - snapstate: remove temporary snap file for local revisions early
 - interface: allows reading sd cards internal info from block-
   devices interface
 - tests: Renaming tool nested-state to tests.nested
 - testutil: fix typo in json checker unit tests
 - tests: ack assertions by default, add --noack option
 - overlord/devicestate: try to pick alternative recovery labels
   during remodel
 - bootloader/assets: update recovery grub to allow system labels
   generated by snapd
 - tests: print serial log just once for nested tests
 - tests: remove xenial 32 bits
 - sandbox/cgroup: do not be so eager to fail when paths do not exist
 - tests: run spread tests in ubuntu bionic 32bits
 - c/snap,asserts: start supporting ExternalKeypairManager in the
   snap key-related commands
 - tests: refresh control spread test
 - cmd/libsnap-confine-private: do not fail on ENOENT, better getline
   error handling
 - tests: disable delta download tests for now until the store is
   fixed
 - tests/nested/manual/preseed: fix for cloud images that ship
   without core18
 - boot: properly handle tried system model
 - tests/lib/store.sh: revert #10470
 - boot, seed/seedtest: tweak test helpers
 - o/servicestate: TODO and fix preexisting typo
 - o/servicestate: detect conflicts for quota group operations
 - cmd/snap/quotas: adjust help texts for quota commands
 - many/quotas: little adjustments
 - tests: add spread test for classic snaps content slots
 - o/snapstate: fix check-rerefresh task summary when refresh control
   is used
 - many: use changes + tasks for quota group operations
 - tests: fix test snap-quota-groups when checking file
   cgroupProcsFile
 - asserts: introduce ExternalKeypairManager
 - o/ifacestate: do not visit same halt tasks in waitChainSearch to
   avoid cycles
 - tests/lib/store.sh: fix make_snap_installable_with_id()
 - overlord/devicestate, overlord/assertstate: use a temporary DB
   when creating recovery systems
 - corecfg: allow using `# snapd-edit: no` header to disable pi-
   config# snapd-edit: no
 - tests/main/interfaces-ssh-keys: tweak checks for openSUSE
   Tumbleweed
 - cmd/snap: prevent cycles in waitChainSearch with snap debug state
 - o/snapstate: fix populating of affectedSnapInfo.AffectingSnaps for
   marking self as affecting
 - tests: new parameter used by retry tool to set env vars
 - tests: support parameters for match-log on journal-state tool
 - configcore: ignore system.pi-config.* setting on measured kernels
 - sandbox/cgroup: support freezing groups with unified
   hierarchy
 - tests: fix preseed test to used core20 snap on latest systems
 - testutil: introduce a checker which compares the type after having
   passed them through a JSON marshaller
 - store: tweak error message when store.Sections() download fails
 - o/servicestate: stop setting DoneStatus prematurely for quota-
   control
 - cmd/libsnap-confine-private: bump max depth of groups hierarchy to
   32
 - many: turn Contact into an accessor
 - store: make the log with download size a debug one
 - cmd/snap-update-ns: Revert "cmd/snap-update-ns: add SRCDIR to
   include search path"
 - o/devicestate: move SystemMode method before first usage
 - tests: skip tests when the sections cannot be retrieved
 - boot: support resealing with a try model
 - o/hookstate: dedicated handler for gate-auto-refresh hook
 - tests: make sure the /root/snap dir is backed up on test snap-
   user-dir-perms-fixed
 - cmd/snap-confine: make mount ns use check cgroup v2 compatible
 - snap: fix TestInstallNoPATH unit test failure when SUDO_UID is set
 - cmd/libsnap-confine-private/cgroup-support.c: Fix typo
 - cmd/snap-confine, cmd/snapd-generator: fix issues identified by
   sparse
 - o/snapstate: make conditional-auto-refresh conflict with other
   tasks via affected snaps
 - many: pass device/model info to configcore via sysconfig.Device
   interface
 - o/hookstate: return bool flag from Error function of hook handler
   to ignore hook errors
 - cmd/snap-update-ns: add SRCDIR to include search path
 - tests: fix for tests/main/lxd-mount-units test and enable
   ubuntu-21.04
 - overlord, o/devicestate: use a single test helper for resetting to
   a post boot state
 - HACKING.md: update instructions for go1.16+
 - tests: fix restore for security-dev-input-event-denied test
 - o/servicestate: move SetStatus to doQuotaControl
 - tests: fix classic-prepare-image test
 - o/snapstate: prune gating information and refresh-candidates on
   snap removal
 - o/svcstate/svcstatetest, daemon/api_quotas: fix some tests, add
   mock helper
 - cmd: a bunch of tweaks and updates
 - o/servicestate: refactor meter handling, eliminate some common
   parameters
 - o/hookstate/ctlcmd: allow snapctl refresh --pending --proceed
   syntax.
 - o/snapstate: prune refresh candidates in check-rerefresh
 - osutil: pass --extrausers option to groupdel
 - o/snapstate: remove refreshed snap from snaps-hold in
   snapstate.doInstall
 - tests/nested: add spread test for uc20 cloud.conf from gadgets
 - boot: drop model from resealing and boostate
 - o/servicestate, snap/quota: eliminate workaround for buggy
   systemds, add spread test
 - o/servicestate: introduce internal and servicestatetest
 - o/servicestate/quota_control.go: enforce minimum of 4K for quota
   groups
 - overlord/servicestate: avoid unnecessary computation of disabled
   services
 - o/hookstate/ctlcmd: do not call ProceedWithRefresh immediately
   from snapctl
 - o/snapstate: prune hold state during autoRefreshPhase1
 - wrappers/services.go: do not restart disabled or inactive
   services
 - sysconfig/cloudinit.go: allow installing both gadget + ubuntu-seed
   config
 - spread: switch LXD back to latest/candidate channel
 - interfaces/opengl: add support for Imagination PowerVR
 - boot: decouple model from seal/reseal handling via an auxiliary
   type
 - spread, tests/main/lxd: no longer manual, switch to latest/stable
 - github: try out golangci-lint
 - tests: set lxd test to manual until failures are fixed
 - tests: connect 30% of the interfaces on test interfaces-many-core-
   provided
 - packaging/debian-sid: update snap-seccomp patches for latest
   master
 - many: fix imports order (according to gci)
 - o/snapstate: consider held snaps in autoRefreshPhase2
 - o/snapstate: unlock the state before calling backend in
   undoStartSnapServices
 - tests: replace "not MATCH" by NOMATCH in tests
 - README.md: refer to new IRC server
 - cmd/snap-preseed: provide more error info if snap-preseed fails
   early on mount
 - daemon: add a Daemon argument to AccessChecker.CheckAccess
 - c/snap-bootstrap: add bind option with tests
 - interfaces/builtin/netlink_driver_test.go: add test snippet
 - overlord/devicestate: set up recovery system tasks when attempting
   a remodel
 - osutil,strutil,testutil: fix imports order (according to gci)
 - release: merge 2.51.1 changelog
 - cmd: fix imports order (according to gci)
 - tests/lib/snaps/test-snapd-policy-app-consumer: remove dsp-control
   interface
 - o/servicestate: move handlers tests to quota_handlers_test.go file
   instead
 - interfaces: add netlink-driver interface
 - interfaces: remove leftover debug print
 - systemd: refactor property parsers for int values in
   CurrentTasksCount, etc.
 - tests: fix debug section for postrm-purge test
 - tests/many: change all cloud-init passwords for ubuntu to use
   plain_test_passwd
 - asserts,interfaces,snap: fix imports order (according to gci)
 - o/servicestate/quota_control_test.go: test the handlers directly
 - tests: fix issue when checking the udev tag on test security-
   device-cgroups
 - many: introduce Store.SnapExists and use it in
   /v2/accessories/themes
 - o/snapstate: update LastRefreshTime in doLinkSnap handler
 - o/hookstate: handle snapctl refresh --proceed and --hold
 - boot: fix model inconsistency check in modeenv, extend unit tests
 - overlord/servicestate: improve test robustness with locking
 - tests: first part of the cleanup
 - tests: new note in HACKING file to clarify about
   yamlordereddictloader dependency
 - daemon: make CheckAccess return an apiError
 - overlord: fix imports ordering (according to gci)
 - o/servicestate: add quotastate handlers
 - boot: track model's sign key ID, prepare infra for tracking
   candidate model
 - daemon: have apiBaseSuite.errorReq return *apiError directly
 - o/servicestate/service_control.go: add comment about
   ExplicitServices
 - interfaces: builtin: add dm-crypt interface to support external
   storage encryption
 - daemon: split out error response code from response*.go to
   errors*.go
 - interfaces/dsp: fix typo in udev rule
 - daemon,o/devicestate: have DeviceManager.SystemMode take an
   expectation on the system
 - o/snapstate: add helpers for setting and querying holding time for
   snaps
 - many: fix quota groups for centos 7, amazon linux 2 w/ workaround
   for buggy systemd
 - overlord/servicestate: mv ensureSnapServicesForGroup to new file
 - overlord/snapstate: lock the mutex before returning from stop snap
   services undo
 - daemon: drop resp completely in favor of using respJSON
   consistently
 - overlord/devicestate: support for snap downloads in recovery
   system handlers
 - daemon: introduce a separate findResponse, simplify SyncRespone
   and drop Meta
 - overlord/snapstate, overlord/devicestate: exclusive change
   conflict check
 - wrappers, packaging, snap-mgmt: handle removing slices on purge
   too
 - services: remember if acting on the entire snap
 - store: extend context and action objects of SnapAction with
   validation-sets
 - o/snapstate: refresh control - autorefresh phase2
 - cmd/snap/quota: refactor quota CLI as per new design
 - interfaces: opengl: change path for Xilinx zocl driver
 - tests: update spread images for ubuntu-core-20 and ubuntu-21.04
 - o/servicestate/quota_control_test.go: change helper escaping
 - o/configstate/configcore: support snap set system swap.size=...
 - o/devicestate: require serial assertion before remodeling can be
   started
 - systemd: improve systemctl error reporting
 - tests/core/remodel: use model assertions signed with valid keys
 - daemon: use apiError for more of the code
 - store: fix typo in snapActionResult struct json tag
 - userd: mock `systemd --version` in privilegedDesktopLauncherSuite
 - packaging/fedora: sync with downstream packaging
 - daemon/api_quotas.go: include current memory usage information in
   results
 - daemon: introduce StructuredResponse and apiError
 - o/patch: check if we have snapd snap with correct snap type
   already in snapstate
 - tests/main/snapd-snap: build the snapd snap on all platforms with
   lxd
 - tests: new commands for snaps-state tool
 - tests/main/snap-quota-groups: add functional spread test for quota
   groups
 - interfaces/dsp: add /dev/cavalry into dsp interface
 - cmd/snap/cmd_info_test.go: make test robust against TZ changes
 - tests: moving to tests directories snaps built locally - part 2
 - usersession/userd: fix unit tests on systems using /var/lib/snapd
 - sandbox/cgroup: wait for pid to be moved to the desired cgroup
 - tests: fix snap-user-dir-perms-fixed vs format checks
 - interfaces/desktop-launch: support confined snaps launching other
   snaps
 - features: enable dbus-activation by default
 - usersession/autostart: change ~/snap perms to 0700 on startup
 - cmd/snap-bootstrap/initramfs-mounts: mount ubuntu-data nosuid
 - tests: new test static checker
 - release-tool/changelog.py: misc fixes from real world usage
 - release-tools/changelog.py: add function to generate github
   release template
 - spread, tests: Fedora 32 is EOL, drop it
 - o/snapstate: bump max postponement from 60 to 95 days
 - interfaces/apparmor: limit the number of jobs when running with a
   single CPU
 - packaging/fedora/snapd.spec: correct date format in changelog
 - packaging: merge 2.51 changelog back to master
 - packaging/ubuntu-16.04/changelog: add 2.50 and 2.50.1 changelogs,
   placeholder for 2.51
 - interfaces: allow read access to /proc/tty/drivers to modem-
   manager and ppp/dev/tty
   
  
  - 
    Wed Sep 01 2021 Maciek Borzecki <maciek.borzecki@gmail.com> - 2.51.7-1
    
- New upstream release 2.51.7 (RHBZ#1972558)
- Include an upstream fix for squashfs 4.5+ compatibility (RHBZ#1999998)
   
  
  - 
    Fri Aug 27 2021 Ian Johnson <ian.johnson@canonical.com>
    
- New upstream release 2.51.7
 - cmd/snap-seccomp/syscalls: update syscalls list to libseccomp
   v2.2.0-428-g5c22d4b1
 - tests: cherry-pick shellcheck fix `bd730fd4`
 - interfaces/dsp: add /dev/ambad into dsp interface
 - many: shellcheck fixes
 - snapstate: abort kernel refresh if no gadget update can be found
 - overlord: add manager test for "assumes" checking
 - store: deal correctly with "assumes" from the store raw yaml
   
  
  - 
    Thu Aug 19 2021 Ian Johnson <ian.johnson@canonical.com>
    
- New upstream release 2.51.6
 - secboot: use half the mem for KDF in AddRecoveryKey
 - secboot: switch main key KDF memory cost to 32KB