Skip to Content

Permission Prompting

Ubuntu 26.04 introduces a new permission prompting system that displays a prompt window requesting user authorization when an app attempts to access sensitive resources. This mechanism significantly improves desktop security by giving users fine-grained control over each app’s permissions.

How It Works

Core Concepts

The permission prompting system is built on AppArmor 4.0’s prompting interface. When a confined app (primarily Snap apps) attempts an operation requiring specific permissions, the system intercepts the request and displays a dialog for the user to decide whether to authorize it.

The workflow is as follows:

  1. An app attempts to access a protected resource (such as files, camera, network, etc.)
  2. AppArmor intercepts the access request
  3. The system displays a permission prompt dialog
  4. The user chooses “Allow” or “Deny”
  5. The user can choose “Just this once” or “Always allow/deny”
  6. The system remembers the user’s choice and applies it to future requests

Protected Resource Types

Resource TypeDescriptionExample
FilesystemAccess user filesReading files in ~/Documents
CameraUse camera devicesVideo calling apps
MicrophoneUse recording devicesVoice recording apps
LocationObtain geographic locationMap apps
NetworkNetwork accessAccess to specific ports or addresses
NotificationsSend desktop notificationsMessaging apps
AutostartRun on bootBackground services

Permission Prompt Interface

When a permission prompt is triggered, a system-level dialog appears containing the following information:

  • Name and icon of the requesting app
  • Type of permission requested
  • Specific resource path (such as a file path)
  • Action options:
    • Allow once
    • Always allow
    • Deny once
    • Always deny

Advanced Options

For filesystem permissions, users can further choose:

  • Allow access to a specific file
  • Allow access to an entire directory
  • Allow read-only access
  • Allow read-write access

Managing Permissions

Via Security Center

Open the “App Permissions” section of Security Center to:

  • View all granted permissions
  • Modify or revoke permissions
  • Browse by app or by permission type

Via Command Line

# View snap app connections (permissions) snap connections firefox # View all snap connections snap connections --all # Manually grant a connection sudo snap connect firefox:camera # Disconnect (revoke permission) sudo snap disconnect firefox:camera # View available interfaces snap interface camera

Viewing Permission Rules

Permission prompting rules are managed by snapd (not hand-written files). You can view and manage them through the graphical “Security Center”, or query them via snapd’s Prompting API.

# Query the current prompting rules via the snapd REST API sudo snap interface snap-interfaces-requests-control # Call the Prompting API over the local socket to list rules sudo curl -s --unix-socket /run/snapd.socket \ http://localhost/v2/interfaces/requests/rules

Resetting Permissions

# Recommended: clear an app's permission decisions via the Security Center GUI # Or call the Prompting API to delete a rule (requires the rule ID) # Reset a specific snap interface connection sudo snap disconnect firefox:home

Snap Interfaces Explained

The permission prompting system primarily operates around Snap interfaces. Common interfaces include:

File Access Interfaces

# home - access user home directory snap connections firefox | grep home # removable-media - access removable storage sudo snap connect myapp:removable-media # personal-files - access specific personal files # system-files - access specific system files

Hardware Interfaces

# camera - camera snap interface camera # audio-record - microphone snap interface audio-record # bluetooth-control - Bluetooth snap interface bluetooth-control # joystick - game controller snap interface joystick

Network Interfaces

# network - network access # network-bind - listen on ports # network-observe - network monitoring # firewall-control - firewall control snap connections --all | grep network

Configuring Permission Prompt Behavior

Global Settings

# Permission prompting is still experimental in 26.04; enable/disable it via the snapd experimental option sudo snap set system experimental.apparmor-prompting=true # Check whether it is currently enabled snap get system experimental.apparmor-prompting # You can also toggle it in the graphical Security Center

Per-App Configuration

# View an app's snap declaration snap info firefox # View all interfaces requested by an app snap connections firefox # Example output: # Interface Plug Slot Notes # camera firefox:camera :camera - # home firefox:home :home - # network firefox:network :network - # audio-playback firefox:audio-playback :audio-playback -

Persistent Authorization Rules

Permission prompting rules are managed uniformly by snapd and are not configured through hand-written files. When you choose “Always Allow” in a prompt dialog, snapd automatically creates a persistent rule.

To manage rules programmatically, use snapd’s Prompting API (/v2/interfaces/requests/rules), initiated by a client that holds the snap-interfaces-requests-control interface; querying, creating, and deleting rules are all handled by snapd rather than by directly editing JSON files on disk.

# List the current persistent rules sudo curl -s --unix-socket /run/snapd.socket \ http://localhost/v2/interfaces/requests/rules

Impact on Traditional deb Apps

The permission prompting system primarily targets Snap apps. Traditional apps installed via APT still use the conventional Linux permission model:

  • deb apps have all user-level permissions by default
  • AppArmor can be manually configured to restrict deb apps
  • For sensitive applications, prefer the Snap version for better permission isolation
# Check AppArmor status sudo aa-status # View loaded AppArmor profiles sudo aa-status | grep profiles

Developer Guide

Declaring Interfaces for Snap Apps

Declare the interfaces your app needs in snapcraft.yaml:

apps: myapp: command: myapp plugs: - home - network - camera - audio-playback plugs: home: read: all write: all camera: null audio-playback: null

Best Practices

  1. Request only necessary permissions - Follow the principle of least privilege
  2. Request on demand - Only request permissions when the user triggers a related feature
  3. Provide a fallback - Offer alternative functionality when a permission is denied
  4. Explain the purpose - Clearly inform the user why a permission is needed

Troubleshooting

Permission Prompt Not Appearing

# Check if the AppArmor prompting service is running systemctl --user status snap.snapd-desktop-integration.snapd-desktop-integration.service # Check snapd version (requires 2.66 or higher) snap version # Check if the kernel supports AppArmor prompting cat /sys/kernel/security/apparmor/features/prompting/supported

App Not Working Due to Denied Permissions

# View denied permission requests journalctl --user | grep -i "permission\|denied\|apparmor" # Manually grant necessary interfaces sudo snap connect myapp:home sudo snap connect myapp:network # Or reset all permission decisions rm ~/.local/share/apparmor/prompting/snap.myapp.json
Last updated on