You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Ubuntu 18.04 Pro订阅环境下unattended-upgrades无法处理ESM安全更新的问题求助

Ubuntu 18.04 Pro订阅环境下unattended-upgrades无法处理ESM安全更新的问题求助

大家好,我遇到一个棘手的问题,想请教下各位:

我有一台Ubuntu 18.04的机器,已经绑定了Ubuntu Pro订阅令牌,通过sudo pro security-status可以看到系统有不少待处理的ESM安全更新,具体输出如下:

763 packages installed:

680 packages from Ubuntu Main/Restricted repository

57 packages from Ubuntu Universe/Multiverse repository

26 packages from third parties

To get more information about the packages, run

pro security-status --help

for a list of available options.

The system apt cache may be outdated. Make sure to run

sudo apt-get update

to get the latest package information from apt.

This machine is attached to an Ubuntu Pro subscription.

Main/Restricted packages are receiving security updates from

Ubuntu Pro with 'esm-infra' enabled until 2028. There are 72 pending security updates.

Universe/Multiverse packages are receiving security updates from

Ubuntu Pro with 'esm-apps' enabled until 2028. There are 10 pending security updates.

但奇怪的是,当我运行sudo unattended-upgrade -v尝试自动处理这些更新时,结果显示找不到可升级的包,输出如下:

Initial blacklisted packages:

Initial whitelisted packages:

Starting unattended upgrades script

Allowed origins are: o=Ubuntu,a=bionic, o=Ubuntu,a=bionic-security, o=UbuntuESM,a=bionic

No packages found that can be upgraded unattended and no pending auto-removals

我们的需求是通过unattended-upgrades自动处理这些ESM安全更新,而不想直接执行全量的sudo apt upgrade。我已经检查过unattended-upgrades的配置文件,里面的Allowed-Origins配置看起来是正确的:

Unattended-Upgrade::Allowed-Origins {
    "${distro_id}:${distro_codename}";
    "${distro_id}:${distro_codename}-security";
    // Extended Security Maintenance; doesn't necessarily exist for
    // every release and this system may not have it installed, but if
    // available, the policy for updates is such that unattended-upgrades
    // should also install from here by default.
    "${distro_id}ESM:${distro_codename}";
    //      "${distro_id}:${distro_codename}-updates";
    //      "${distro_id}:${distro_codename}-proposed";
    //      "${distro_id}:${distro_codename}-backports";
};

我实在搞不清楚哪里出问题了,请问各位我是不是遗漏了什么配置或者步骤,才导致unattended-upgrades无法识别这些ESM的安全更新呢?

备注:内容来源于stack exchange,提问作者yi1

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 12:34:39