Permission Prompting
Ubuntu 26.04 introduces a new permission prompting system that displays a prompt window requesting user authorization when an app attempts to access sensitive resources. This mechanism significantly improves desktop security by giving users fine-grained control over each app’s permissions.
How It Works
Core Concepts
The permission prompting system is built on AppArmor 4.0’s prompting interface. When a confined app (primarily Snap apps) attempts an operation requiring specific permissions, the system intercepts the request and displays a dialog for the user to decide whether to authorize it.
The workflow is as follows:
- An app attempts to access a protected resource (such as files, camera, network, etc.)
- AppArmor intercepts the access request
- The system displays a permission prompt dialog
- The user chooses “Allow” or “Deny”
- The user can choose “Just this once” or “Always allow/deny”
- The system remembers the user’s choice and applies it to future requests
Protected Resource Types
| Resource Type | Description | Example |
|---|---|---|
| Filesystem | Access user files | Reading files in ~/Documents |
| Camera | Use camera devices | Video calling apps |
| Microphone | Use recording devices | Voice recording apps |
| Location | Obtain geographic location | Map apps |
| Network | Network access | Access to specific ports or addresses |
| Notifications | Send desktop notifications | Messaging apps |
| Autostart | Run on boot | Background services |
Permission Prompt Interface
When a permission prompt is triggered, a system-level dialog appears containing the following information:
- Name and icon of the requesting app
- Type of permission requested
- Specific resource path (such as a file path)
- Action options:
- Allow once
- Always allow
- Deny once
- Always deny
Advanced Options
For filesystem permissions, users can further choose:
- Allow access to a specific file
- Allow access to an entire directory
- Allow read-only access
- Allow read-write access
Managing Permissions
Via Security Center
Open the “App Permissions” section of Security Center to:
- View all granted permissions
- Modify or revoke permissions
- Browse by app or by permission type
Via Command Line
# View snap app connections (permissions)
snap connections firefox
# View all snap connections
snap connections --all
# Manually grant a connection
sudo snap connect firefox:camera
# Disconnect (revoke permission)
sudo snap disconnect firefox:camera
# View available interfaces
snap interface cameraViewing Permission Rules
Permission prompting rules are managed by snapd (not hand-written files). You can view and manage them through the graphical “Security Center”, or query them via snapd’s Prompting API.
# Query the current prompting rules via the snapd REST API
sudo snap interface snap-interfaces-requests-control
# Call the Prompting API over the local socket to list rules
sudo curl -s --unix-socket /run/snapd.socket \
http://localhost/v2/interfaces/requests/rulesResetting Permissions
# Recommended: clear an app's permission decisions via the Security Center GUI
# Or call the Prompting API to delete a rule (requires the rule ID)
# Reset a specific snap interface connection
sudo snap disconnect firefox:homeSnap Interfaces Explained
The permission prompting system primarily operates around Snap interfaces. Common interfaces include:
File Access Interfaces
# home - access user home directory
snap connections firefox | grep home
# removable-media - access removable storage
sudo snap connect myapp:removable-media
# personal-files - access specific personal files
# system-files - access specific system filesHardware Interfaces
# camera - camera
snap interface camera
# audio-record - microphone
snap interface audio-record
# bluetooth-control - Bluetooth
snap interface bluetooth-control
# joystick - game controller
snap interface joystickNetwork Interfaces
# network - network access
# network-bind - listen on ports
# network-observe - network monitoring
# firewall-control - firewall control
snap connections --all | grep networkConfiguring Permission Prompt Behavior
Global Settings
# Permission prompting is still experimental in 26.04; enable/disable it via the snapd experimental option
sudo snap set system experimental.apparmor-prompting=true
# Check whether it is currently enabled
snap get system experimental.apparmor-prompting
# You can also toggle it in the graphical Security CenterPer-App Configuration
# View an app's snap declaration
snap info firefox
# View all interfaces requested by an app
snap connections firefox
# Example output:
# Interface Plug Slot Notes
# camera firefox:camera :camera -
# home firefox:home :home -
# network firefox:network :network -
# audio-playback firefox:audio-playback :audio-playback -Persistent Authorization Rules
Permission prompting rules are managed uniformly by snapd and are not configured through hand-written files. When you choose “Always Allow” in a prompt dialog, snapd automatically creates a persistent rule.
To manage rules programmatically, use snapd’s Prompting API (/v2/interfaces/requests/rules), initiated by a client that holds the snap-interfaces-requests-control interface; querying, creating, and deleting rules are all handled by snapd rather than by directly editing JSON files on disk.
# List the current persistent rules
sudo curl -s --unix-socket /run/snapd.socket \
http://localhost/v2/interfaces/requests/rulesImpact on Traditional deb Apps
The permission prompting system primarily targets Snap apps. Traditional apps installed via APT still use the conventional Linux permission model:
- deb apps have all user-level permissions by default
- AppArmor can be manually configured to restrict deb apps
- For sensitive applications, prefer the Snap version for better permission isolation
# Check AppArmor status
sudo aa-status
# View loaded AppArmor profiles
sudo aa-status | grep profilesDeveloper Guide
Declaring Interfaces for Snap Apps
Declare the interfaces your app needs in snapcraft.yaml:
apps:
myapp:
command: myapp
plugs:
- home
- network
- camera
- audio-playback
plugs:
home:
read: all
write: all
camera: null
audio-playback: nullBest Practices
- Request only necessary permissions - Follow the principle of least privilege
- Request on demand - Only request permissions when the user triggers a related feature
- Provide a fallback - Offer alternative functionality when a permission is denied
- Explain the purpose - Clearly inform the user why a permission is needed
Troubleshooting
Permission Prompt Not Appearing
# Check if the AppArmor prompting service is running
systemctl --user status snap.snapd-desktop-integration.snapd-desktop-integration.service
# Check snapd version (requires 2.66 or higher)
snap version
# Check if the kernel supports AppArmor prompting
cat /sys/kernel/security/apparmor/features/prompting/supportedApp Not Working Due to Denied Permissions
# View denied permission requests
journalctl --user | grep -i "permission\|denied\|apparmor"
# Manually grant necessary interfaces
sudo snap connect myapp:home
sudo snap connect myapp:network
# Or reset all permission decisions
rm ~/.local/share/apparmor/prompting/snap.myapp.json