Computing and the Command Line

Keeping the System Updated

What updates itself and what doesn't. unattended-upgrades installs security fixes daily, its settings and logs, and when it reboots; phased updates and packages kept back; needrestart and /var/run/reboot-required; snaps refreshing themselves and Flatpaks updated by hand; a weekly update routine as an alias in your dotfiles; and moving to a new LTS every two years with do-release-upgrade, after the first point release, with backups and third-party repositories in mind. Ubuntu Pro for ten years of updates.

  • 7 min
  • 7 steps
  • 3 questions
  • Lesson 49 of 80

In this lesson

  1. What updates itself
  2. How unattended-upgrades works
  3. Kept back, and reboots
  4. A weekly routine
  5. A new release every two years
  6. Your turn
  7. So

What updates itself

Three kinds of software, three update stories:

  • Security fixes for debs install themselves. The unattended-upgrades package, installed by default, runs once a day and applies security updates without asking 1 2.
  • Snaps refresh themselves, checking four times a day 3.
  • Everything else waits for you: non-security deb updates, and Flatpaks 2 4.

On the desktop, the Software Updater app pops up when updates are waiting and installs them with a click. From the terminal, it’s the pair you know:

me@garden-laptop:~$ sudo apt update
me@garden-laptop:~$ sudo apt upgrade
Five rows. deb security fixes: unattended-upgrades, daily, automatic. All other deb updates: sudo apt update and sudo apt upgrade, weekly, by you. Snaps: snapd checks four times a day, automatic. Flatpaks: flatpak update, weekly, by you. A new LTS release: sudo do-release-upgrade, every two years. Note: packages kept back by phased updates arrive within days; if /var/run/reboot-required exists, restart. Bottom, a weekly routine: an update-all function in your dotfiles that runs apt update and upgrade, snap refresh, and flatpak update, then checks for /var/run/reboot-required.
Security fixes install themselves daily; the rest is a weekly habit; a new LTS every two years. Credit: StudyCorner diagram · CC BY 4.0 · Source

Quick check

With Ubuntu’s default settings, which updates install themselves without you doing anything?

How unattended-upgrades works

It does the equivalent of apt update and apt upgrade, limited to the sources it’s allowed to use 1. The pieces 1:

  • /etc/apt/apt.conf.d/20auto-upgrades turns it on and sets how often, in days:

    APT::Periodic::Update-Package-Lists "1";
    APT::Periodic::Unattended-Upgrade "1";
    

    Setting both to "0" turns it off.

  • /etc/apt/apt.conf.d/50unattended-upgrades says what to install. Its Allowed-Origins list includes the release and its -security pocket (and Ubuntu Pro’s security pockets if you have them); the -updates line is commented out with //. Uncomment it to have all regular updates installed automatically too.

  • Two systemd timers, apt-daily.timer and apt-daily-upgrade.timer, run it at a random time each day. If the computer was off then, it runs soon after the next start, which is why apt is sometimes busy just after you log in. (Timers are next module.)
  • Logs go in /var/log/unattended-upgrades/.

Adding a third-party repository does not make unattended-upgrades install from it; it needs to be added to Allowed-Origins by name 1.

It won’t restart the computer on its own unless you set Unattended-Upgrade::Automatic-Reboot "true"; in 50unattended-upgrades; the default is false 1. For a desktop that’s right. For a home server that should keep itself patched, it’s worth turning on, with a time set for the reboot.

Kept back, and reboots

Two messages you’ll meet:

“Packages have been kept back.” Ubuntu releases many updates in phases: a random subset of machines gets an update first, and only if no problems turn up does it go to everyone 5. Until your machine’s turn, apt upgrade holds that package back. You don’t need to do anything; it arrives within days 5. (apt policy package shows the details.)

Restarts. Most updates take effect without a reboot. When a shared library is updated, programs already running keep the old copy in memory until they restart; Ubuntu’s needrestart restarts the affected services automatically, apart from a few it leaves alone, such as the login screen 1. A new kernel needs a full reboot. Updates that need one create the file /var/run/reboot-required 1:

me@garden-laptop:~$ [ -f /var/run/reboot-required ] && echo "restart needed"

Quick check

apt upgrade says some packages have been kept back. What should you do?

A weekly routine

Put it in your dotfiles (Git course, module 7), so every machine has it. In bash_aliases:

# Update debs, then snaps and Flatpaks if present, then say if a restart is needed
update-all() {
    sudo apt update && sudo apt upgrade || return
    if command -v snap >/dev/null; then sudo snap refresh; fi
    if command -v flatpak >/dev/null; then flatpak update; fi
    if [ -f /var/run/reboot-required ]; then echo "Restart needed."; fi
}

A function rather than an alias, since it’s several steps (Shell course, module 8). || return stops if apt fails, and command -v skips snap or flatpak on a machine without them, such as WSL, so the same dotfiles work everywhere. Run update-all once a week, read what apt proposes before saying yes, and restart if asked. Commit it and pull it on your other machines.

A new release every two years

Your updates stay within your release: 26.04 stays 26.04. Every two years there’s a new LTS, and moving to it is a release upgrade 6:

  • LTS to LTS, one at a time. From 24.04 you go to 26.04; from 22.04 you’d stop at 24.04 first 6.
  • Offered after the first point release, like 26.04.1, usually several months after the April release, once early problems are fixed 6.
  • It takes up to an hour and is interactive 6.

To prepare: plug in a laptop, check there’s several gigabytes of free space, back up your files, and install all current updates and restart 6. Then either the Software Updater offers the new release, or 6:

me@garden-laptop:~$ sudo do-release-upgrade

It shows what it will install and remove, and warns if you have packages from PPAs or third-party repositories; those are a common cause of trouble, and they may be disabled during the upgrade, so check them afterward in Software & Updates, Other Software 6 7. At the end it offers to remove obsolete packages, then restarts.

There’s no hurry: 24.04 LTS has security updates until May 2029, and 26.04 until May 2031 8.

Ubuntu Pro, free for personal use on up to five machines, adds Expanded Security Maintenance: ten years of security updates instead of five, covering the community universe packages too 8. On the desktop, turn it on in the Security Center app 2. It’s worth having on any machine you’ll keep for years.

Quick check

When can an Ubuntu 24.04 LTS desktop upgrade to 26.04 LTS through the Software Updater?

Your turn

Exercises

  1. cat /etc/apt/apt.conf.d/20auto-upgrades. Are automatic updates on?
  2. Look at the Allowed-Origins section of /etc/apt/apt.conf.d/50unattended-upgrades. Which pockets are allowed?
  3. ls /var/log/unattended-upgrades/ and read the newest log. What did it install recently?
  4. Add the update-all function to your dotfiles’ bash_aliases, commit, push, and run it.
  5. snap refresh --time and apt policy on one package from apt list --upgradable.
  6. Find your WSL Ubuntu’s release with lsb_release -a, and look up when its standard updates end.
Answers
  1. Both lines "1": daily package list updates and daily unattended upgrades.
  2. The release itself and -security (plus the ESM pockets); -updates, -proposed, and -backports commented out with //.
  3. Lines like Packages that will be upgraded: followed by package names, and All upgrades installed.
  4. Under WSL, the command -v tests skip snap or flatpak if they aren’t installed, so the function still runs apt.
  5. apt policy shows the installed version, the candidate, and where each comes from; a phased update shows a phasing percentage.

So

Security updates for debs install themselves daily through unattended-upgrades (settings in 20auto-upgrades and 50unattended-upgrades, logs in /var/log/unattended-upgrades/), and snaps refresh themselves; other deb updates and Flatpaks are yours to run, weekly, with apt update, apt upgrade, snap refresh, and flatpak update, which fit nicely in a dotfiles function. “Kept back” packages are phased updates and arrive on their own; /var/run/reboot-required says when to restart. Every two years, after the first point release, do-release-upgrade moves you to the next LTS, one at a time, after a backup.

Lesson complete

Nice work.

1day streak
0/1today's goal
–correct

Up next · 7 min

systemd and systemctl

Next lesson
Sources for this lesson
  1. 1
    Automatic updates (Ubuntu Server documentation). Canonical. verifiedunattended-upgrades, installed by default, applies security updates automatically, once a day by default. /etc/apt/apt.conf.d/20auto-upgrades (Update-Package-Lists and Unattended-Upgrade, in days; 0 disables), /etc/apt/apt.conf.d/50unattended-upgrades (Allowed-Origins: release and -security plus ESM; -updates commented out; added repositories aren't included automatically; Automatic-Reboot default false), logs in /var/log/unattended-upgrades; triggered by apt-daily.timer and apt-daily-upgrade.timer, catching up after boot if missed; /var/run/reboot-required; needrestart restarts affected services automatically since 24.04, except a list such as the display manager.
  2. 2
    Snap and deb packages (Ubuntu Desktop documentation). Canonical. verifiedThe App Center shows snaps by default. Snaps: sandboxed (classic snaps aren't, reviewed manually), versions independent of the Ubuntu release, updated automatically, permissions in Settings > Apps, a base snap such as core26 plus bundled libraries, so larger. Debs: tied to the release, security updates installed automatically, other updates via Software Updater, full access, many small dependencies, smaller. If an app is available both ways, Ubuntu generally recommends the snap, especially from third-party developers. Ubuntu Pro can be enabled in the Security Center, free on up to 5 machines.
  3. 3
    Manage updates (snap documentation). Canonical. verifiedSnaps update automatically; snapd checks for updates four times a day by default (snap refresh --time shows timer, last, next). snap refresh --hold[=duration] postpones updates for some or all snaps; --unhold removes it; system options refresh.timer, refresh.hold (up to 90 days), refresh.metered, refresh.retain.
  4. 4
    Using Flatpak (Flatpak documentation). Flatpak. verifiedThree-part IDs like org.gimp.GIMP; system-wide by default, --user per user; flatpak remotes, remote-add, search, install flathub ID, run, update (apps and runtimes), list --app, uninstall, uninstall --unused for runtimes no longer used, repair, permission-reset, history. Apps may need a runtime, installed first.
  5. 5
    About apt upgrade and phased updates (Ubuntu Server documentation). Canonical. verifiedapt upgrade may report packages kept back because of phased updates: an update first goes to a random subset of machines (decided on the client from the machine ID, package, and version) and to everyone once no problems are found; it's safe to ignore and the update arrives automatically; apt policy shows phasing details.
  6. 6
    Upgrade Ubuntu Desktop (Ubuntu Desktop documentation). Canonical. verifiedSequential upgrades only, LTS to next LTS; upgrades to a new LTS become available after its first point release (such as 26.04.1), several months after release; up to an hour and interactive. Prepare: power, free disk space, back up, fully update and restart. Start from Software Updater or sudo do-release-upgrade; PPAs and third-party packages trigger a Foreign Packages prompt and may be disabled; remove obsolete packages; restart; re-check third-party repositories in Software & Updates > Other Software.
  7. 7
    Third party repository usage (Ubuntu Server documentation). Canonical. verifiedUbuntu doesn't recommend third-party software: APT repositories run code that isn't sandboxed and give no security boundary between publishers, so the system is only as secure as the weakest publisher; third-party packages can conflict with official ones, and are the most common cause of release-upgrade failures.
  8. 8
    Ubuntu release cycle. Canonical. verifiedA new Ubuntu every six months, versioned by year and month; interim releases get 9 months of updates; LTS releases every two years get 5 years of standard security maintenance (26.04 LTS: released April 2026, to May 2031; 24.04 LTS to May 2029). Ubuntu Pro, free for personal use on up to five machines, adds Expanded Security Maintenance to 10 years including Universe; a paid Legacy add-on reaches 15.