Request: Auto-connect log-observe for canonical-livepatch

To make the review of your request easier, please use the following template to provide all the required details and also include any other information that may be relevant.


  • name: canonical-livepatch

  • description: Canonical Livepatch patches high and critical linux kernel vulnerabilities removing the immediate need to reboot to upgrade the kernel, instead allowing the downtime to be scheduled. It is a part of the Ubuntu Pro offering.

    The Canonical Livepatch Client is an application that runs on your machine and periodically checks for patches.

    See our docs at https://ubuntu.com/security/livepatch/docs/livepatch

  • snapcraft: N/A

  • upstream: PRIVATE

  • upstream-relation: The livepatch team in Comsys.

  • interfaces:

    • log-observe:
      • request-type: auto-connection
      • reasoning: The livepatch team are implementing a new procedure for monitoring system health after a patch is loaded into the kernel. We need to stream kernel logs from /dev/kmsg to look for errors, bug, and success logs after patch insertion. To read from this character device, we need the log-observe interface. This will allow the client to detect patch application issues with a higher grade of accuracy and improve observability for patch health. Because users of livepatch enable the client as a background process, possibly on many machines, we need this interface to be auto-connected as it cannot be realistically connected manually.

This request has been added to the queue for review by the @reviewers team.

Hello @haydntamura!

Given the functionality of the snap and the justification provided, this is a +1 (#voteFor) for auto-connecting the log-observe interface to the canonical-livepatch snap.

Hello! This is a +1 (#voteFor) from me as well for granting auto-connect for the log-observe interface for the canonical-livepatch snap given the context and reasoning for the request. Thanks!

Hey @haydntamura

+2 for, 0 against granting canonical-livepatch auto-connection to the log-observe interface. Publisher is vetted.

Please let us know when a new revision using log-observe interface is uploaded to the store, so that we can effectively grant this permission

Hello,

We have now published a new revision (revision 392) of canonical-livepatch with the log-observe-interface.

Voting period has ended. This request is approved with 2 votes for and 0 votes against.