Why gets unattended-upgrades installed after Debian jessie -> Debian stretch upgrade?

80 views
Skip to first unread message

Patrick Schleizer

unread,
Feb 6, 2017, 8:19:10 AM2/6/17
to debia...@lists.debian.org, Whonix-devel, qubes...@googlegroups.com
The unattended-upgrades was not installed on my Debian jessie system.
After upgrading to Debian stretch, the package unattended-upgrades got
installed. 'reverse-depends unattended-upgrades' [1] did not make me any
wiser. There must be a gap of my apt knowledge. Can anyone shed light on
this please?

Best regards,
Patrick

[1]
Reverse-Recommends
==================
* education-common
* python3-software-properties

Reverse-Depends
===============
* parl-desktop
* plinth

Packages without architectures listed are reverse-dependencies in:
amd64, arm64, armel, armhf, hurd-i386, i386, kfreebsd-amd64,
kfreebsd-i386, mips, mips64el, mipsel, powerpc, ppc64el, s390x

Unman

unread,
Feb 6, 2017, 9:25:13 PM2/6/17
to Patrick Schleizer, debia...@lists.debian.org, Whonix-devel, qubes...@googlegroups.com
I remember a thread last year saying that unattended-upgrades should be
installed by default, and enabled. I guess that is what you're seeing
here Patrick.
This was on debian-devel - I thought it related to d-i but it may be
brought in as default package on dist-upgrade.

have a look here:
https://lists.debian.org/debian-devel/2016/11/msg00262.html

Unman

unread,
Feb 7, 2017, 9:08:26 AM2/7/17
to Patrick Schleizer, debia...@lists.debian.org, Whonix-devel, qubes...@googlegroups.com
I was, as so often, wrong. It's pulled in as a recommend from
python3-software-properties which is being installed as part of upgrade.
Turn off Recommends and it isnt installed.

I think that follows from gnome-packagekit being installed, and pulling
in software-properties-gtk, which pulls software-properties-common and
so...

So turn off Recommends/Suggests or review installs before upgrading.

Chris Laprise

unread,
Feb 8, 2017, 12:39:04 PM2/8/17
to Unman, Patrick Schleizer, debia...@lists.debian.org, Whonix-devel, qubes...@googlegroups.com
Unfortunately it clashes with template usage patterns... and probably
not great for template-based VMs either.

Automatic updates would be better initiated from dom0, since the
templates don't run on a regular basis and there are VM maintenance
issues as well.

Chris

Unman

unread,
Feb 8, 2017, 9:45:06 PM2/8/17
to Chris Laprise, Patrick Schleizer, Whonix-devel, qubes...@googlegroups.com
See my later email on this - it's a package that users have chosen to
install, because it's pulled in as a recommend. It's not currently
installed and enabled by default in Stretch.

I'm not sure if it does clash with Template usage - if you can start the
Template and have it automatically pull in security fixes that may
become part of standard usage.
What's certainly true is that it would be disastrous in a
TemplateBasedVM, (and pointless).

But that's a generic problem with any Debian based system now, that many
services start automatically once installed. We don't have a sensible
way of controlling this in Qubes at the moment, although there is a long
standing issue on this.
Reply all
Reply to author
Forward
0 new messages