Stable Linux mainline builds for Ubuntu
stgraber.org
stgraber.org
Here's an intro to his project Incus (TIL, fork of LXC):
Be aware that upgrading kernel usually mess with graphics driver, especially for Nvidia. In the best case you'll have to unload and reload the Nvidia driver, in the worst case your driver just stops working.
Intel and AMD don't have significant breakage when upgrading the Linux kernel.
I find modern Windows and macOS updates to be frustratingly opaque and slow. Linux distro updates, on the popular/common distros like debian and arch, are one of my favorite parts of using the system. It'll just install updates for like 200 separate packages (libraries, tools, etc) bang, bang, bang, less than a minute, done. And with the absurdly high speed of todays CPUs and storage, why should it take longer? What are Windows and macOS even doing? I will accept linux has some drawbacks and disadvantages, but the system package managers have been fantastic, for about 2 decades now.
Yeah. I've never heard of reinstalling the OS just to get a newer kernel.
> is there a good guide for how to do that
I think it's best to continue to use your distro's package manager to handle actually installing that kernel, so the instructions would all be distro-specific. Some distros make working with a custom kernel easier than others.
> for a homelabber would that be a good idea to avoid security bugs?
Depends on your distro. I would expect major ones and enterprise-oriented ones to do a good job of backporting security fixes to the older kernels they run. If they do a really good job of this, it might even be more secure on the whole.
But yeah, just using the latest stable kernel is probably the simplest way to ensure that you have the latest security fixes. (It'll also ensure you have the latest undiscovered security bugs. ;)
Also, you can have many kernels installed concurrently and select which one to boot from at the GRUB boot screen. This is mostly used when you update the kernel and suddenly find on rebooting that something has gone wrong (e.g. necessary drivers not included in the initial ram disk - initrd), so you can reboot and select the previous working kernel to boot the system and resolve whatever issue you had.
Ubuntu Pro is free for five machines and includes live-patches for security updates. Non-security updates still require a reboot.
For example when people talk about phones or tablets having mainline support, they mean that Linus's tree has all the drivers etc for that hardware and using the hardware vendor's arbitrary kernel drop isn't needed. They don't necessarily mean that the support is only in master and not in a stable branch. Eg https://mainline.space/ https://not.mainline.space/
I run the stable kernel, which I build myself. There is still the occasional regression. About a year ago it had a regression in the Intel graphics driver which broke graphics for my Haswell chip. A patch was available but this wasn't merged for months. Luckily Gentoo makes it super easy to apply custom patches so I did. IMO if you want to run a stable or mainline kernel yourself you might as well build it yourself too.
What we really need is simple tooling that handles just the case of "I want to sign kernels for my own machine(s)".
Of course, some tools do exist for this case, but I'm not aware of one that is totally generic. Lanzaboote for NixOS seems interesting (disclaimer: have not tried.)
Please, people, if you release software that overlaps or competes with another existing in the space, take the 3 minutes to write a comparison note or "why this exists". Please.
Unfortunately, unlike many of their projects, they don't seem to have a blog post yet for it.
It seems like a natural conclusion to spend a fraction of the energy to author, to detail it's reason to exist.
Anyway, no one owes me anything but I trust that Determinate Systems has a grander vision than I can see, I just want to be clued in, to be honest ;).
https://wiki.archlinux.org/title/Unified_kernel_image#Prepar...
> Ideally signing and enrolling in the UEFI the key to a signed Unified Kernel Image (UKI) makes more sense
(It's much more useful to have a link to it, so thank you!)
It gives you the "here, run these commands" version if that's what you want.
[1] https://wiki.debian.org/SecureBoot#MOK_-_Machine_Owner_Key
Step 0: deploy your own PKI, install certificates on your motherboard firmware, sign your kernel, sign your modules.
Step 0.5: Sign your DKMSs from Broadcom, Nvidia, and Intel.
Step 0.75: Re-sign everything because you missed a step.
Maybe I need to write it a little more clearly, but perhaps that will get you there.
My hacky script has more lines to fetch the signer name from the kernel (once it's been signed) than to just sign the vmlinuz image.
I just put some niceties like irqbalance and add a few lines to sysctl.conf for better latency at a cost of throughput (doesn't matter if you're just using the system as a desktop and not as a server). And that gives me a very nice experience overall.
Edit: Please, be careful. This is under a very well performing machine, take a look at replies for more information.
https://www.quakeworld.nu/wiki/Smooth_Quake_in_Linux
Best of luck!