4 ms·
You only need to restart when there is a kernel update, and the frequency of kernel updates depend heavily on the distro used. Debian stable, for example, altho
by hyperknot 11y ago
You only need to restart when there is a kernel update, and the frequency of kernel updates depend heavily on the distro used. Debian stable, for example, although using ancient versions of the packages, is a great OS for such a use case, as kernel upgrades are really infrequent. Have a look at the changelog frequency of Squeeze [1] or Wheezy [2].
[1] http://metadata.ftp-master.debian.org/changelogs/main/l/linux-latest-2.6/linux-latest-2.6_29_changelog http://metadata.ftp-master.debian.org/changelogs/main/l/linu...
[2] http://metadata.ftp-master.debian.org/changelogs/main/l/linux-latest/linux-latest_46_changelog http://metadata.ftp-master.debian.org/changelogs/main/l/linu...
- aroch 11y agoIf you update a central library (e.g. openssl), you'll have to restart in order to deal with in-memory copies being used by other programs. If you're running a Debian server one of the packages to include in your base install is debian-goodies or needrestart because the former bundles a very helpful little script called "checkrestart" and the latter is an updated systemd-compatible version, both of which use `lsof` under the hood to determine when and why package updates require a restart for full effect.
- bgray 11y agoBut do you? You really only need to restart the processes using those packages. Technically, a kernel update (specifically security update, bug fixes may not be important) would only require a reboot.
- jerf 11y agoYes, you can restart all processes using SSL. However, I've often been in situations where I reboot anyhow, because rebooting means I'm 100% confident the old code is gone, whereas if I try to get clever and avoid the restart, I'm significantly less confident. Depending on how hard it is to validate the security bug, that can be a problem. Plus, for much of the past 20 years for many computers, if you're going to restart all services, adding in the last step for rebooting doesn't add all that significantly to the downtime. Server-class hardware often have things that make that not true (stupid RAID cards), but for everything else you were often only adding, say, 25% for the actual reboot.
- ultramancool 11y agoYou don't need to be 100% confident the old code is gone - just 100% confident the old code is no longer exposed to the network - check your sockstat/netstat and call it a day.
- hs86 11y agoIt gets complicated when central libraries like glibc have to be updated. I did this once with checkrestart on Debian Wheezy and I had to restart nearly everything except for the init process. So in this case just restarting the system would have been faster and easier.
- NoGravitas 11y agoFor lots of core stuff, you don't technically need to reboot, but you probably do need to go down to single user mode and come back up (consider upgrading glibc or openssl), and at that point you might as well reboot.
- niutech 11y agoRebooting also closes unused sockets, closes opened descriptors, fixes memory leaks, cleans /tmp and performs fsck if needed. So it is good to reboot.
- Xorlev 11y agoKSplice helps you avoid the need to reboot even with many kernel changes. KSplice is the delta layer that gets you from security patch to maintenance window for a real reboot.
- Kesty 11y agoSince a lot of updates will require for you to stop or the service anyhow, adding a reboot at the end before bringing everything back up it's not that bad of an idea.
- marcosdumay 11y agoWell, the server is there to host some service. If you'd need to restart the service deamon, why not restart the machine for once, and make everything simpler? Also, boot time bugs are a huge issue. They can creep during the entire time your system is up, and only show up during a reboot. Thus, if your server only has unplanned restarts, you'll only discover those bugs when you have yet another pressing issue to deal with, and also, likely at 3 in the morning on a Sunday. So, make things better for you, and restart those servers once in a while, when things are quiet.
- Joeri 11y agoI once had a debian stable desktop and home server reach two years of uptime using that strategy of upgrading everything except the kernel. Some upgrades, like a newer glibc, were quite tricky to accomplish without a reboot as you had to restart nearly every process. It was a fun game so i didn't mind the effort. Eventually a power outage wiped away my uptime.
- ultramancool 11y agoNot only that but you only reboot when there's a kernel update that you care about. If it's not a security update or it's not a security update that affects you. I don't reboot for remote exploits in kernel services I don't use or single service VMs with local privilege escalation vulns.
- ptman 11y agoIsn't modern dbus something that you can't restart without rebooting the computer? I think...