automatic installation of security upgrades

Release: bionic (18.04)
Level: proposed
Repository: main


base main 1.1ubuntu1
updates main 1.1ubuntu1.18.04.14


Version: 1.1ubuntu1.18.04.13 2019-11-25 19:06:21 UTC

  unattended-upgrades (1.1ubuntu1.18.04.13) bionic; urgency=medium

  * Fix non-minimal upgrades (LP: #1853861)
    - Mark packages for performing non-minimal upgrades
    - Clear cache after checking upgrades against the blacklist again.
      This fixes the issue when the dirty cache caused all packages to be
      upgraded in the first "minimal" step.
      Thanks to Paul Wise
    - Leave the cache clean when returning from calculate_upgradable_pkgs()
      When collecting upgradable packages the upgradable ones stayed in the
      cache and they were upgraded together even when unattended-upgrades
      was configured to perform upgrades in minimal steps.
      Thanks to Paul Wise
    - Clear cache after downloading packages

 -- Balint Reczey <email address hidden> Mon, 25 Nov 2019 16:23:06 +0100

1853861 [SRU] Unattended-upgrades silently does not apply updates when MinimalSteps is disabled and there are autoremovable kernels

Version: 1.1ubuntu1.18.04.12 2019-10-24 22:07:03 UTC

  unattended-upgrades (1.1ubuntu1.18.04.12) bionic; urgency=medium

  * Report packages kept back by origin (LP: #1821376)
  * Store list of kept packages and report the number of them in motd
    (LP: #1823070)
  * Default to "/" as rootdir to fix saving list of kept packages.
    Thanks to Paul Wise (Closes: #932160)
  * debian/tests/control: Mark upgrade-between-snapshots as flaky
    (Closes: #941752) (LP: #1848354)

 -- Balint Reczey <email address hidden> Fri, 18 Oct 2019 13:24:28 +0200

1821376 Report packages kept back by origins
1823070 unattended-upgrades should tell the user (via motd) when security updates are held back
1848354 upgrade-between-snapshots autopkgtest is flaky
932160 unattended-upgrades: regression: path to the kept-back file is not correctly determined - Debian Bug report logs
941752 unattended-upgrades: flaky autopkgtest: upgrade-between-snapshots - Debian Bug report logs

Version: 1.1ubuntu1.18.04.11 2019-04-30 11:06:25 UTC

  unattended-upgrades (1.1ubuntu1.18.04.11) bionic; urgency=medium

  * Detect changes to moved conffiles (LP: #1823872)
    - Add tests for checking conffile moves.
      Build depend on and use equivs to generate new test packages
    - Split() conffile data to set of names only once
    - Don't parse dpkg conffile db when there are no conffiles in the package
  * Detect unchanged moved conffiles.
    When a package moves a conffile properly without any change no conffile
    prompt needs to be shown thus the package can be upgraded unattended.
    (LP: #1823872)
  * Skip sending email when no package had to be installed, upgraded or removed
    (LP: #1821103) (Closes: #924554)
  * Make sure autoremovals don't start with a dirty cache and remove other
    packages (LP: #1824341)
  * Continue applying minimal sets when one set can't be marked for upgrade.
    Thanks to Anderson Luiz Alves for the patch, it needed minor modifications
    (LP: #1824341)
  * Stop raising NoAllowedOriginError when marking packages to upgrade/install
    fails (LP: #1824876)
  * Adjust only transitive dependencies in the fallback when a package from an
    allowed origin can't be marked to install/upgrade.
    This is a much lighter approach than marking every upgradable package
    because the full fallback was triggered on packages held back as well,
    using an excessive amount of CPU time.
    Also it crashed with packages not having any version in allowed origins.
    (LP: #1824804, #1824949)
  * Skip trying to upgrade held packages in call_adjusted() (LP: #1824804)
  * Follow all kinds of transitive dependencies when adjusting dependencies
  * Don't crash collecting transitive dependencies when package has no candidate
    (LP: #1825886)
  * Use mark_install_adjusted() in rewind_cache()
    The original cache had packages marked with adjustments thus rewinding
    should also do adjustments to reach the same state.
    Also not using mark_install_adjusted() crashes when apt raises error on
    held packages. (LP: #1826157)
    - test_rewind: Update test to check if adjustend rewinding took place

 -- Balint Reczey <email address hidden> Mon, 29 Apr 2019 12:13:14 +0200

1823872 Fixing fsfreeze-hook can break unattended upgrades
1821103 [SRU] Skip sending email when no package had to be installed, upgraded or removed
1824341 NoAllowedOrigin cause package removal
1824876 unattended-upgrades: call_adjusted() raises NoAllowedOriginError when marking packages to upgrade/install fails
1824804 Unattended upgrades falls back to adjust all upgradable packages in attempt to install held packages
1825886 Unattended-upgrades may crash when a package does not have a candidate
1826157 unattended-upgrades: rewind_cache() may crash due to not adjusting package candidates
924554 SUCCESS messages: significant behaviour change - Debian Bug report logs

