关于Unattended Upgrades未使用Mozilla新Firefox apt repository的技术咨询
Hey there, let's figure out why Unattended Upgrades isn't pulling updates from Mozilla's new official Firefox apt repository.
First off, the core issue here is that Unattended Upgrades only checks repositories listed in its allowed origins by default—and Mozilla's new repo isn't part of that default list. Here's how to fix it step by step:
1. Verify Mozilla's repository is properly added
First, confirm you've actually added the repo to your system. Check the /etc/apt/sources.list.d/ directory for a file like mozilla-firefox.list (the exact name might vary). You can run this command to check:
ls /etc/apt/sources.list.d/ | grep mozilla
If the file exists, peek at its content to make sure it's formatted correctly (it should include a deb line with the repo URL and a signed-by key path).
2. Update Unattended Upgrades' allowed origins
Next, you need to tell Unattended Upgrades to include Mozilla's repo in its update checks. Open the main config file with your preferred editor:
sudo nano /etc/apt/apt.conf.d/50unattended-upgrades
Look for the Unattended-Upgrade::Allowed-Origins section. By default, it includes entries like ${distro_id}:${distro_codename} (your base Ubuntu repo) and security updates.
To find the exact origin string for Mozilla's repo, run this command:
apt-cache policy firefox
In the output, look for the line starting with Origin: under the Mozilla repo entry (it might look like LP-PPA-mozilla-team-firefox-next). Then add a new line to the allowed origins list using that origin and your Ubuntu codename (e.g., jammy, noble):
Unattended-Upgrade::Allowed-Origins { "${distro_id}:${distro_codename}"; "${distro_id}:${distro_codename}-security"; // Keep other default entries here... "LP-PPA-mozilla-team-firefox-next:jammy"; // Replace with your Origin and codename };
Save and close the file when you're done.
3. Test the configuration
To make sure everything works as expected, run a dry run of Unattended Upgrades:
sudo unattended-upgrade --dry-run
Check the output—if you see references to Firefox updates from Mozilla's repo, you're good to go.
A couple of quick notes
- Make sure you've installed Mozilla's GPG key correctly! If the key is missing, Unattended Upgrades will skip the repo entirely due to signature verification failures.
- When you upgrade your Ubuntu version (e.g., from Jammy to Noble), don't forget to update the codename in the allowed origins entry to match your new OS version.
备注:内容来源于stack exchange,提问作者tardis

