> a modern OS should only need to be rebooted when the kernel is updated
You can still choose to reboot for every update.
The point though is that it is a choice.
sudo dnf offline-upgrade download -y && time sudo dnf offline-upgrade reboot
It doesn't nag me at all other than ask me for my sudo password.
It is perfect.
Here is what I understand about dnf offline-upgrade
> The process of restarting, applying updates, and then restarting again is called Offline Updates. Your computer boots into a special save-mode, where all other systems are disabled and where network access is unavailable. It then applies the updates and restarts.
https://fedoramagazine.org/offline-updates-and-fedora-35/
> With Windows, it's an almost-weekly, "Hey, update right now, because someone in another country is pwning all unpatched machines that aren't air-gapped from the internet."
I see.
I feel like I don't quite understand the extent of the problem.
In any case, I am not qualified to even attempt to propose a fix.
My mode of thinking was Google Chrome and derivatives are able to slowly walk along
with increasingly scarier visible warnings asking users to restart the web browsers
but they don't (as far as I know) reboot the web browser while the user is still using it.
Even Google Chrome OS didn't do that (well, it didn't back when I had my cr-48).
When I updated Mozilla Firefox on my Fedora machine, existing tabs continued to work.
New tabs would come with a warning for me to close Firefox and open it again.
This is the kind of warning I was getting rid of with offline-upgrade.
I agree with my parent comment though.
Updates are too bloated.
Windows updates should be very fast
with a modern processor (Intel eighth gen, AMD equivalent or greater), enough memory, and a fast SSD.
Even DNF which has a very renowned reputation (at least among Fedora users) of being slow, is pretty reliably fast.
I think the point that my parent comment was making was make people not dread rebooting their machine.
My thought was
1. educate the users why reboots are essential
2. allow the users to postpone reboots indefinitely
However, I don't know what to say if there is an active remote command exploitation in the wild.
It is important to get the update to the user before the exploit.
However, that goes against everything I've said so far.
I guess this leads us to the status quo.
Those who have the know-how to use group policy can opt out of certain Windows Update behavior.
The rest can either learn to do this:
and set up their own Windows Update server?
Periodically check CVE and gate update releases?
Not sure how it works...
The reason I hesitate and say automatic reboot should be OPT-IN
is sometimes I like to do some simple long running task
like stitch photos I took into a video using ffmpeg.
It can take hours on a slow laptop processor.
It would really suck to do something like that
and come back to see the computer rebooted itself.