snap-confine-2.58.3-2.fc39 >t 6 6_! @ D6 z  3!92d LuZLd; uZLмBr4]j1Y(TB %AGL"7_p+˒fP-42۬L;mFC@`X,kAD\ Mi`A3a"OsoZbxⴙ?CΌ2HƸ5 vȷs@cnoO7v(+ \'9( xߖĠW^]Tڪ'ܰFpua#Av>+d4D<006)\Q;i0OcAFc?~[b PX 5n!XWB:)mZs<ى5xe"#USxu2{)? 6S]Q׭׾ui$S3v¡1TyΔ]V4g^ȳ@4ũRGL$] D67X_[R$4c݃'ēN1kܗן<ҏUee4 !@/"ɄOw|4pnf2f0f9dcfe0a330ca71636af211166512708ab01c1fdbb278493c1593c2142dbc119c0c8e9ba34c06931e9f0712f42d274462e9d030204388b603e00463044022069a585219db75ae53a8be63dd7565a84ae72b6eb04c977c7f1a33f2cab9d76a5022037a19a578ae0175806fdf39be8c0e3ba98f0568cd0d4841869096573db633235030204388b603e004730450220680294fca1d4df7900f6482cff6eedb25b23bdb76d0e972d329385506e6d9419022100e51b34571d994a7458e82b54e01a43917448efb8e24f02e4810205e5812af0c5030204388b603e004730450221008521a9235ab794a1bb1c621602a3744c8125aedc9b90952c09f09f90fc4a1d2e0220489e301344fb040b3c68e63e282fc487f118890773e7efef03b6d658fb1cb9d4030204388b603e00473045022100f34bfceae55599ee64e2fa78113b6fe04d4537d183cc20e6a4088cc56a3e124f02201b737658914708eb804149ef075345971d3382f877b302a1678824855a3cc1bb030204388b603e0046304402206275a6128106afe7fbe0467bc8e67977b8108b51e69e6f907e29cfcca69749bc02203322680f0269ca9a1a4dfd1ed291cd07d5e475d79bf41bec15770df49ffad6c9030204388b603e00473045022100945f0b86c36ffa00a9913d623ee96aaf11dcb3576fd11114a789ab5d390b175102204f2718cfac9b2e08ee9afb2d20cc900cbf41ecf20adb18b7452a73912576c4a6030204388b603e00473045022043633ef3fab68c7c0bcd485e41dbba31b3ce100af7cd73fea274493a8c3152c8022100c5b924a1fb0529b0083c6bcc1d4f439ae5898e08679fc99ec5d42541fa1266b8030204388b603e00483046022100b8ffb23a427268309e07ca96e1a47cd3bdcd1405f832fb9a0b0618e0c74a037002210084b58b079785983bb8f5f0d8524c1fe5cb0c5e032362fdb06edcb07db6512d65030204388b603e0048304602210090673c7daf9c32e7b84cb16077fc7aa6106e921eae844550693951dec90ebb81022100fca9e79514d28afcb3c4a5efe42f11a3f284da3de57b5be33bee0d682ce224d1030204388b603e0047304502204889173efd31fa35963b66d371a3a35e8e7a1e4b253b99435999e39255b4257d0221008d50ddb14eed98b63560c433041d19db237496bbf59b6eaf973be1b2b58a795b030204388b603e0046304402204e0e6a55e97a335a56038ee33f7046399c1451e357bc01361dcd44149589dfcd02205076b58a02acd622aa600529a1aa539e070410c030757239879fd284fff2906c030204388b603e004730450220190abbfccbb61018fe28329c6e359d164c78c9b1a67978b66aad3ee616499d18022100d788d8afaed79d3ce13956ab1c0751fe9ce4b9f3072fbf317f0fd0f056a403ac*3!92d LuZLd; uZL\+" c! BF E;MN5jKOd_9VK$B,!!~n9#KM㬲qC" <7 yCUᗊk1Vk`5ɹMC4CU Dٔh:F5z7Uf 4BWF2;'BmMMgk 2+۳",?8eӢT<0ǎ@eU' GI@|K.7Ax`JO12)-}˰!+셔* e;E6?@(Tsm˄52ODN b;LXjr}Z- J5sTم'Ml8ꜚcq/~ Q`ZRJECq\{߽K? nX@وw[cyBb~pR*-:z* Q\̞zg8&$ mLny0j%~VQ2Vn 73(>`A)?d  F  9?H!! ! P! ! ! !!! Z x!    (8 B9(B: BB .G <!H !I D!X hY pZ [ \ !]!^Pbdeflt!up!v wT!x!y\BdhCsnap-confine2.58.32.fc39Confinement system for snap applicationsThis package is used internally by snapd to apply confinement to the started snap applications.d:buildhw-x86-04.iad2.fedoraproject.orgJFedora ProjectFedora ProjectGPLv3Fedora ProjectUnspecifiedhttps://github.com/snapcore/snapdlinuxx86_640*1*-=,+Ooo/8/0%WHK AAAAAAAAAAA큤A큤@Idddddddddddddddddddddddddddcdcddd743d5624edb1fdd70064d9b55e7ad9c627f8612a31c0876068a23be1252014a358b4dde12431d5b21a9fdc8e8b4f4c356cc764e7daa7c31d68cb8c84e7eda821c22d4565fc4b6ede6c7d567fbdbb496796506f693a2ee1f914b2f6f36179bac6f512c19167639bb648037bd3592460f7e74cdeafc7e3239b458e43ecb259a2be9e8ee2cd3afa50919ea8159eb50da0a956e58d4109ebbf7c2b5b7ed6f4583decb0133bad28d893f485f5f15e7caee2932b703ba38a588ca2542c3c40e14870ed2e83955dc50cfe1d267f1b348e4d8bd5d0d8b47416ff881eee72b0e797822f671e94bc0c6693326da56a05ebca8ec052432aa332a44ff790775b7c0f133a81a7c589535706d9d3ac8ecdecc1919c86e823f29e0be3c33c61c4c94aa301643a618ceb4b9ee5adedde47b31e975c1d90c73ad27b6b165a1dcd80c7c545eb65b903c6444505333b0cc7086727c7657adb49fc4fa6dc20116b01462b035a86139e2be38e942a43f98b9bd12fb80bcdc662de62eea46cc2eef18632f0f2137424ebd5../../../../usr/libexec/snapd/snap-device-helper../../../../usr/libexec/snapd/snap-confine../../../../usr/libexec/snapd/snap-gdbserver-shim../../../../usr/libexec/snapd/snap-seccomp../../../../usr/libexec/snapd/snap-discard-ns../../../../usr/lib/systemd/system-generators/snapd-generator../../../../usr/libexec/snapd/snap-update-ns../../../../usr/libexec/snapd/snap-gdb-shimrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootrootsnapd-2.58.3-2.fc39.src.rpmsnap-confinesnap-confine(x86-64)@ @@@@@@@@@@@@@@@@@@@@@@@@@    @glibclibc.so.6()(64bit)libc.so.6(GLIBC_2.14)(64bit)libc.so.6(GLIBC_2.2.5)(64bit)libc.so.6(GLIBC_2.27)(64bit)libc.so.6(GLIBC_2.3)(64bit)libc.so.6(GLIBC_2.3.2)(64bit)libc.so.6(GLIBC_2.3.4)(64bit)libc.so.6(GLIBC_2.32)(64bit)libc.so.6(GLIBC_2.33)(64bit)libc.so.6(GLIBC_2.34)(64bit)libc.so.6(GLIBC_2.38)(64bit)libc.so.6(GLIBC_2.4)(64bit)libc.so.6(GLIBC_2.7)(64bit)libc.so.6(GLIBC_2.8)(64bit)libc.so.6(GLIBC_2.9)(64bit)libcap.so.2()(64bit)libgcc_s.so.1()(64bit)libgcc_s.so.1(GCC_3.0)(64bit)libgcc_s.so.1(GCC_3.3.1)(64bit)libresolv.so.2()(64bit)libseccomp.so.2()(64bit)libselinux.so.1()(64bit)libselinux.so.1(LIBSELINUX_1.0)(64bit)libudev.so.1()(64bit)libudev.so.1(LIBUDEV_183)(64bit)rpmlib(CompressedFileNames)rpmlib(FileDigests)rpmlib(PayloadFilesHavePrefix)rpmlib(PayloadIsZstd)rtld(GNU_HASH)2.37.9000-173.0.4-14.6.0-14.0-15.4.18-14.18.91dc@c@ccvcc]c@cEcs@cMCc5c#c@bbz@bb֜bγbʿ@bmbb@bbb1@b{@bm$bY^@bT@bP#bMb8hb8hb8hb+9b b8b a@aaaɪap@a{a@a@a@aaaKa(@a(@aqV@a\>@a\>@aTU@a2@a/k@a(aGaS@aa`@`@Fedora Release Engineering - 2.58.3-2Maciek Borzecki - 2.58.3-1Michael Vogt Michael Vogt Michael Vogt Fedora Release Engineering - 2.57.6-3Maciek Borzecki - 2.57.6-2Michael Vogt Maciek Borzecki - 2.57.6-1Michael Vogt Michael Vogt Michael Vogt Michael Vogt Michael Vogt Alberto Mardegan Michael Vogt Fedora Release Engineering - 2.56.2-5Maxwell G - 2.56.2-4Michael Vogt Maxwell G - 2.56.2-2Maxwell G - 2.56.2-2Maciek Borzecki - 2.56.2-1Robert-André Mauchin - 2.55.3-2Michael Vogt Michael Vogt Michael Vogt Michael Vogt Michael Vogt David King - 2.55.3-2Maciek Borzecki - 2.55.3-1Michael Vogt Maciek Borzecki - 2.55.2-1Ian Johnson Ian Johnson Ian Johnson Maciek Borzecki - 2.54.4-1Michael Vogt Maciek Borzecki - 2.54.3-1Michael Vogt Maciek Borzecki - 2.54.2-1Fedora Release Engineering - 2.54.1-2Ian Johnson Maciek Borzecki - 2.54.1-1Michael Vogt Michael Vogt Maciek Borzecki - 2.53.4-1Ian Johnson Ian Johnson Maciek Borzecki - 2.53.2-2Maciek Borzecki - 2.53.2-1Ian Johnson Maciek Borzecki - 2.53.1-2Maciek Borzecki - 2.53.1-1Ian Johnson Michael Vogt Michael Vogt Maciek Borzecki - 2.52-1Ian Johnson Maciek Borzecki - 2.51.7-1Ian Johnson Ian Johnson Ian Johnson Ian Johnson Maciek Borzecki - 2.51-4Maciek Borzecki - 2.51-3Fedora Release Engineering - 2.51-2- Rebuilt for https://fedoraproject.org/wiki/Fedora_39_Mass_Rebuild- Releate 2.58.3 to Fedora RHBZ#2173056- New upstream release 2.58.3 - interfaces/screen-inhibit-control: Add support for xfce-power- manager - interfaces/network-manager: do not show ptrace read denials - interfaces: relax rules for mount-control `what` for functionfs - cmd/snap-bootstrap: add support for snapd_system_disk - interfaces/modem-manager: add net_admin capability - interfaces/network-manager: add permission for OpenVPN - httputil: fix checking x509 certification error on go 1.20 - i/b/fwupd: allow reading host os-release - boot: on classic+modes `MarkBootSuccessfull` does not need a base - boot: do not include `base=` in modeenv for classic+modes installs - tests: add spread test that validates revert on boot for core does not happen on classic+modes - snapstate: only take boot participants into account in UpdateBootRevisions - snapstate: refactor UpdateBootRevisions() to make it easier to check for boot.SnapTypeParticipatesInBoot()- New upstream release 2.58.2 - bootloader: fix dirty build by hardcoding copyright year- New upstream release 2.58.1 - secboot: detect lockout mode in CheckTPMKeySealingSupported - cmd/snap-update-ns: prevent keeping unneeded mountpoints - o/snapstate: do not infinitely retry when an update fails during seeding - interfaces/modem-manager: add permissions for NETLINK_ROUTE - systemd/emulation.go: use `systemctl --root` to enable/disable - snap: provide more error context in `NotSnapError` - interfaces: add read access to /run for cryptsetup - boot: avoid reboot loop if there is a bad try kernel - devicestate: retry serial acquire on time based certificate errors - o/devicestate: run systemctl daemon-reload after install-device hook - cmd/snap,daemon: add 'held' to notes in 'snap list' - o/snapshotstate: check snapshots are self-contained on import - cmd/snap: show user+gating hold info in 'snap info' - daemon: expose user and gating holds at /v2/snaps/{name}- Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild- Fix for RHBZ#2152903- New upstream release 2.58 - many: Use /tmp/snap-private-tmp for per-snap private tmps - data: Add systemd-tmpfiles configuration to create private tmp dir - cmd/snap: test allowed and forbidden refresh hold values - cmd/snap: be more consistent in --hold help and err messages - cmd/snap: error on refresh holds that are negative or too short - o/homedirs: make sure we do not write to /var on build time - image: make sure file customizations happen also when we have defaultscause - tests/fde-on-classic: set ubuntu-seed label in seed partitions - gadget: system-seed-null should also have fs label ubuntu-seed - many: gadget.HasRole, ubuntu-seed can come also from system-seed- null - o/devicestate: fix paths for retrieving recovery key on classic - cmd/snap-confine: do not discard const qualifier - interfaces: allow python3.10+ in the default template - o/restart: fix PendingForSystemRestart - interfaces: allow wayland slot snaps to access shm files created by Firefox - o/assertstate: add Sequence() to val set tracking - o/assertstate: set val set 'Current' to pinned sequence - tests: tweak the libvirt interface test to work on 22.10 - tests: use system-seed-null role on classic with modes tests - boot: add directory for data on install - o/devicestate: change some names from esp to seed/seed-null - gadget: add system-seed-null role - o/devicestate: really add error to new error message - restart,snapstate: implement reboot-required notifications on classic - many: avoid automatic system restarts on classic through new overlord/restart logic - release: Fix WSL detection in LXD - o/state: introduce WaitStatus - interfaces: Fix desktop interface rules for document portal - client: remove classic check for `snap recovery --show- keys` - many: create snapd.mounts targets to schedule mount units - image: enable sysfs overlay for UC preseeding - i/b/network-control: add permissions for using AF_XDP - i/apparmor: move mocking of home and overlay conditions to osutil - tests/main/degraded: ignore man-db update failures in CentOS - cmd/snap: fix panic when running snap w/ flag but w/o subcommand - tests: save snaps generated during image preaparation - tests: skip building snapd based on new env var - client: remove misleading comments in ValidateApplyOptions - boot/seal: add debug traces for bootchains - bootloader/assets: fix grub.cfg when there are no labels - cmd/snap: improve refresh hold's output - packaging: enable BPF in RHEL9 - packaging: do not traverse filesystems in postrm script - tests: get microk8s from another branch - bootloader: do not specify Core version in grub entry - many: refresh --hold follow-up - many: support refresh hold/unhold to API and CLI - many: expand fully handling links mapping in all components, in the API and in snap info - snap/system_usernames,tests: Azure IoT Edge system usernames - interface: Allow access to org.freedesktop.DBus.ListActivatableNames via system-observe interface - o/devicestate,daemon: use the expiration date from the assertion in user-state and REST api (user-removal 4/n) - gadget: add unit tests for new install functions for FDE on classic - cmd/snap-seccomp: fix typo in AF_XDP value - tests/connected-after-reboot-revert: run also on UC16 - kvm: allow read of AMD-SEV parameters - data: tweak apt integration config var - o/c/configcore: add faillock configuration - tests: use dbus-daemon instead of dbus-launch - packaging: remove unclean debian-sid patch - asserts: add keyword 'user-presence' keyword in system-user assertion (auto-removal 3/n) - interfaces: steam-support allow pivot /run/media and /etc/nvidia mount - aspects: initial code - overlord: process auto-import assertion at first boot - release, snapd-apparmor, syscheck: distinguish WSL1 and WSL2 - tests: fix lxd-mount-units in ubuntu kinetic - tests: new variable used to configure the kernel command line in nested tests - go.mod: update to newer secboot/uc22 branch - autopkgtests: fix running autopkgtest on kinetic - tests: remove squashfs leftovers in fakeinstaller - tests: create partition table in fakeinstaller - o/ifacestate: introduce DebugAutoConnectCheck hook - tests: use test-snapd-swtpm instead of swtpm-mvo snap in nested helper - interfaces/polkit: do not require polkit directory if no file is needed - o/snapstate: be consistent not creating per-snap save dirs for classic models - inhibit: use hintFile() - tests: use `snap prepare-image` in fde-on-classic mk-image.sh - interfaces: add microceph interface - seccomp: allow opening XDP sockets - interfaces: allow access to icon subdirectories - tests: add minimal-smoke test for UC22 and increase minimal RAM - overlord: introduce hold levels in the snapstate.Hold* API - o/devicestate: support mounting ubuntu-save also on classic with modes - interfaces: steam-support allow additional mounts - fakeinstaller: format SystemDetails result with %+v - cmd/libsnap-confine-private: do not panic on chmod failure - tests: ensure that fakeinstaller put the seed into the right place - many: add stub services for prompting - tests: add libfwupd and libfwupdplugin5 to openSUSE dependencies - o/snapstate: fix snaps-hold pruning/reset in the presence of system holding - many: add support for setting up encryption from installer - many: support classic snaps in the context of classic and extended models - cmd/snap,daemon: allow zero values from client to daemon for journal rate limit - boot,o/devicestate: extend HasFDESetupHook to consider unrelated kernels - cmd/snap: validation set refresh-enforce CLI support + spread test - many: fix filenames written in modeenv for base/gadget plus drive- by TODO - seed: fix seed test to use a pseudo-random byte sequence - cmd/snap-confine: remove setuid calls from cgroup init code - boot,o/devicestate: introduce and use MakeRunnableStandaloneSystem - devicestate,boot,tests: make `fakeinstaller` test work - store: send Snap-Device-Location header with cloud information - overlord: fix unit tests after merging master in - o/auth: move HasUserExpired into UserState and name it HasExpired, and add unit tests for this - o/auth: rename NewUserData to NewUserParams - many: implementation of finish install step handlers - overlord: auto-resolve validation set enforcement constraints - i/backends,o/ifacestate: cleanup backends.All - cmd/snap-confine: move bind-mount setup into separate function - tests/main/mount-ns: update namespace for 18.04 - o/state: Hold pseudo-error for explicit holding, concept of pending changes in prune logic - many: support extended classic models that omit kernel/gadget - data/selinux: allow snapd to detect WSL - overlord: add code to remove users that has an expiration date set - wrappers,snap/quota: clear LogsDirectory= in the service unit for journal namespaces - daemon: move user add, remove operations to overlord device state - gadget: implement write content from gadget information - {device,snap}state: fix ineffectual assignments - daemon: support validation set refresh+enforce in API - many: rename AddAffected* to RegisterAffected*, add Change|State.Has, fix a comment - many: reset store session when setting proxy.store - overlord/ifacestate: fix conflict detection of auto-connection - interfaces: added read/write access to /proc/self/coredump_filter for process-control - interfaces: add read access to /proc/cgroups and /proc/sys/vm/swappiness to system-observe - fde: run fde-reveal-key with `DefaultDependencies=no` - many: don't concatenate non-constant format strings - o/devicestate: fix non-compiling test - release, snapd-apparmor: fixed outdated WSL detection - many: add todos discussed in the review in tests/nested/manual/fde-on-classic, snapstate cleanups - overlord: run install-device hook during factory reset - i/b/mount-control: add optional `/` to umount rules - gadget/install: split Run in several functions - o/devicestate: refactor some methods as preparation for install steps implementation - tests: fix how snaps are cached in uc22 - tests/main/cgroup-tracking-failure: fix rare failure in Xenial and Bionic - many: make {Install,Initramfs}{{,Host},Writable}Dir a function - tests/nested/manual/core20: fix manual test after changes to 'tests.nested exec' - tests: move the unit tests system to 22.04 in github actions workflow - tests: fix nested errors uc20 - boot: rewrite switch in SnapTypeParticipatesInBoot() - gadget: refactor to allow usage from the installer - overlord/devicestate: support for mounting ubuntu-save before the install-device hook - many: allow to install/update kernels/gadgets on classic with modes - tests: fix issues related to dbus session and localtime in uc18 - many: support home dirs located deeper under /home - many: refactor tests to use explicit strings instead of boot.Install{Initramfs,Host}{Writable,FDEData}Dir - boot: add factory-reset cases for boot-flags - tests: disable quota tests on arm devices using ubuntu core - tests: fix unbound SPREAD_PATH variable on nested debug session - overlord: start turning restart into a full state manager - boot: apply boot logic also for classic with modes boot snaps - tests: fix snap-env test on debug section when no var files were created - overlord,daemon: allow returning errors when requesting a restart - interfaces: login-session-control: add further D-Bus interfaces - snapdenv: added wsl to userAgent - o/snapstate: support running multiple ops transactionally - store: use typed valset keys in store package - daemon: add `ensureStateSoon()` when calling systems POST api - gadget: add rules for validating classic with modes gadget.yaml files - wrappers: journal namespaces did not honor journal.persistent - many: stub devicestate.Install{Finish,SetupStorageEncryption}() - sandbox/cgroup: don't check V1 cgroup if V2 is active - seed: add support to load auto import assertion - tests: fix preseed tests for arm systems - include/lk: update LK recovery environment definition to include device lock state used by bootloader - daemon: return `storage-encryption` in /systems/