"What's the long-term play for Canonical here?"

Presumably it's rewriting critical parsing code in APT to a memory-safe language.