For some reason, a lot of people ignore the warnings
https://wiki.debian.org/DebianUnstable
about unstable and testing and are complaining that Debian is broken.
For some reason, a lot of people ignore the warnings
https://wiki.debian.org/DebianUnstable
about unstable and testing and are complaining that Debian is broken.
I have never (yet!) gotten myself into any trouble, by following a very simple principle: if aptitude (dselect back in the day) wants to remove or hold more than a handful of packages, STOP. Undo what you just did, and instead of a bulk upgrade go through marking one package at a time for upgrade. When you hit one that needs major changes, if you can't find an upgrade alternative that is sensible, leave it un-upgraded and try again in a few days.
This time upgrade has been one of the more challenging ones to track in unstable, but patience and actually reading the reasons that dpkg reports for why it wants to do something has gotten me through it.
So I wrote a lighthearted theme song for `unstable` updates. I don't recall most of it offhand, but it was to the tune of "Cat's in the Cradle":
o/~ What I'd really like now
is to update your libc.
See you later,
can you apt-get please?
At some point, Linux software stopped improving so quickly, and Debian Stable seemed better. And I've been very happy with it, for most all startup and personal purposes.Testing and unstable requires a bit more experience to drive daily, but neither of them just collapses into a pile of smoking ash with an update. They're pretty stable and usable. I didn't reinstall any testing systems since I started using them.
The only thing about Testing and unstable is: "None of them receives security updates. They are not intended for internet facing production systems".
Hope that changes until the packets move to stable.
Stable will iron out all of them.
Yes, the probability of being attacked is less but it is a false sense of security. Nowadays, you download loads of code from the internet just by navigating to a website using the web browser. Are you 100% sure there is no bug in the sandbox? How about all the other protocols on your computer, or all the other computers on the same "internal" network. Are you sure, those are 100% resistant too?
Firefox follows upstream from 24-48h behind, unless something big like t64 transition is happening (which happens once every 5 years or so). Unstable currently provides 125.0.3. If you wish, you can use Mozilla's official Firefox builds updates which arrive as soon as new versions are released. However, Debian hardens Firefox to its own standards.
Other libraries and everything follows pretty close to upstream when the distro is not frozen for release.
Also, Stable has the "Patches in 24h even if upstream doesn't provide" guarantee (which we have seen during Bash's RCE bug). This is what testing and unstable lacks.
So, it's no FUD. It's nuanced. As I said before. Using testing and unstable needs some experience and understanding how a distribution works. Stable is install and forget.
> or all the other computers on the same "internal" network.
Considering we manage all the other computers in the same internal network, I'm sure they're fine. They all run prod-ready software. Some BSD, rest is Linux.
Debian Testing and Unstable are mostly fine if you know what you are doing - you seem to have a clue. Security guidance is usually for people that need it - those that might not understand the full implications. Even for professionals it can be a useful reminder.
Oh, OK. My bad, sorry. Thanks for the clarification.