Obviously your mileage may vary, but the 8 upgrades of Debian 10 to 11 I did were exactly that for me.
Edit: realized I lied and the Canon driver wasn't ready for Debian 11 so rolled my print server back. You'll have to decide for yourself whether this is a Debian problem or not
I have written an article on this, unfortunately in Czech, but you can try Google Translate: https://www-abclinuxu-cz.translate.goog/blog/jenda/2020/12/2...
TL;DR:
- perform apt-get dist-upgrade, apt-get autoremove, apt-get clean
- migrate postgresql database to a new version, if installed
- run `aptitude search "?narrow(?installed,?not(?archive(stable)))"` to find leftover packages from older releases. Install alternatives and remove these old packages.
- once in a while, run
for p in `dpkg -l | grep ^ii | cut -d " " -f 3 | grep -E "^lib"`; do echo "if [ \`apt-get -s purge $p | grep -E \"^(Purg|Inst|Conf)\" | wc -l\` -eq 1 ]; then echo $p; fi" done | parallel
to find libraries that nothing depends on
- when taking over a system from a previous sysadmin, run debsums -c and maybe also a complete audit of all files that are not managed by a package manager (though this has lots of false-positives, so it needs an expert judgement)
# locate * | grep -vE "^/(home|tmp|mnt|boot|opt|root|srv|usr/local|var/cache|var/lib|var/log|var/tmp|var/mail|var/www)/" | sort -u > /tmp/allfiles
# sort -u /var/lib/dpkg/info/*.list > /tmp/allfiles2
# comm -23 /tmp/allfiles /tmp/allfiles2 |less
Building and installing stuff yourself using the default directory prefix is potentially dangerous. It can turn your installation into a mess, and there's no way to undo it (unless you're using a filesystem that supports snapshots, but even then it is tricky if the problems appear much later).
However, I suspect this issue also exists with macOS.
I've been using old Ubuntu distros which still get security patches with flatpaks. This gives me a good balance of stability and modern user space software.
As an experiment, I'm keeping a Debian 11 in which I installed flatpak and GNU Guix. I can use very recent GCC versions and still have a very stable system. I still plan to install homebrew on it to watch how the different parts will interact.
I still haven't tried it, but my next step will be to try homebrew.
Also, how would you install Python wheels in a system-wide manner?
This is the output of "tree /usr/local" on my non-experimental system:
marco@marco-Inspiron-3421:~$ tree /usr/local/
/usr/local/
├── bin
├── etc
├── games
├── include
├── lib
│ ├── python2.7
│ │ ├── dist-packages
│ │ └── site-packages
│ └── python3.8
│ └── dist-packages
├── man -> share/man
├── sbin
├── share
│ ├── ca-certificates
│ ├── fonts
│ ├── man
│ ├── sgml
│ │ ├── declaration
│ │ ├── dtd
│ │ ├── entities
│ │ ├── misc
│ │ └── stylesheet
│ ├── texmf
│ └── xml
│ ├── declaration
│ ├── entities
│ ├── misc
│ └── schema
└── src
29 directories, 0 files
It has a lot of packages installed but, as you can see, the package manager never wrote a file in /usr/local. So I think it is safe to assume things installed to /usr/local will not interfere with the package manager.> Also, how would you install Python wheels in a system-wide manner?
No sure, but I think it can be done with guix.
Every so often I run into very odd plists and remnants of long obsolete programs. I’ve used the migration assistant each time I moved from Mac to Mac. All the PPC only apps went away when Rosetta was removed and the 32bit Carbon apps were similarly discarded. Support files sometimes stick around but the transfer agent is generally pretty tidy.
It is good to run this once a while even for non-security reasons: you can detect hardware problems (notoriously failing SD cards in Raspberry Pis) and mistakes, like installing a custom program to /usr instead of /opt and accidentally overwriting system files.
(Granted, those are unlikely to survive for many years without breaking or otherwise getting caught)
Yeah, backdooring configuration/bashrc is a problem, unfortunately, you will probably copy the configuration after the reinstall, thus copying the backdoor too.
https://changelog.complete.org/archives/9969-goodbye-to-a-15...