npx skills add ...
npx skills add iuliandita/skills --skill debian-ubuntu
Administer Debian, Ubuntu, Mint, and Pop!_OS: apt, dpkg, upgrades, boot, drivers, and desktop issues.
npx skills add iuliandita/skills --skill debian-ubuntu
Administer Debian, Ubuntu, Linux Mint, Pop!_OS, Devuan, and other Debian-derived systems, with partial coverage for Kali when the question is about base OS administration rather than security-distro workflow.
Focus on Debian stable and Ubuntu LTS first, then layer in derivative-specific behavior, PPA workflows, snap confinement, Ubuntu HWE, and explicit checks for derivatives that diverge on init, packaging defaults, or intended use.
Versions worth pinning (verified October 2026):
Only pin versions here when they materially affect compatibility or troubleshooting shape. For ordinary Debian and Ubuntu package work, prefer the live distro lane and package policy over a stale package-version table.
| Component | Version | Why it matters |
|---|---|---|
| Debian stable | 13 (trixie) | current stable baseline and repo behavior |
| Ubuntu LTS | 26.04 (Resolute Raccoon) | current LTS baseline for most Ubuntu guidance |
| Ubuntu interim lane | verify live (25.10 EOL July 2026; 26.10 "Stonking Stingray" due 2026-10-15) | interim releases move fast; check the active upgrade path instead of memorizing one short-lived codename |
| Ubuntu HWE lane | verify live | kernel metapackage and hardware-enablement behavior matter more than one exact kernel number |
| NVIDIA driver branch | verify live | proprietary branch choice affects Wayland, gaming, and DKMS behavior |
| Mesa stack | verify live | AMD and Intel graphics behavior tracks the shipped Mesa lane |
| Kernel security | verify live via USN tracker | patch high-severity privesc CVEs promptly; mid-2026 examples to confirm fixed: Copy Fail CVE-2026-31431 (CISA KEV, exploited), Dirty Frag CVE-2026-43284/43500, Fragnesia CVE-2026-46300 (ESP-in-TCP, public PoC, not in CISA KEV), ptrace CVE-2026-46333 |
Security recheck (2026-09-10): CVE-2026-53362
is a high-priority Linux IPv6 flaw that Canonical lists as CISA KEV. Ubuntu 26.04's
linux package is fixed in 7.0.0-31.31; Ubuntu 24.04's linux-hwe-7.0 is fixed in
7.0.0-31.31~24.04.1. The 24.04 linux lane remains marked vulnerable in that record.
Check the exact release and kernel package; these are not universal kernel version floors.
Security recheck (2026-10-02): CVE-2026-53266
(netfilter ebtables SNAT, high, CISA KEV 2026-09-18) has the same fixed versions: linux
7.0.0-31.31 on 26.04 and linux-hwe-7.0 7.0.0-31.31~24.04.1 on 24.04, while the 24.04
linux lane is still listed as vulnerable.
apt, apt-get, dpkg, apt-cache, pinning, or holdsadd-apt-repository, key handling)do-release-upgrade)fwupd, ubuntu-drivers, HWE stacks, backportsjournalctl, dmesg, lsblk, update-alternativesBefore returning Debian or Ubuntu commands, verify:
apt upgrade when apt full-upgrade or apt dist-upgrade is required for package transitions. Do not suggest apt dist-upgrade casually on Ubuntu without context.systemctl --user only when appropriate.pipewire-pulse, and WirePlumber are not fighting a leftover PulseAudio setup.bluetooth.service alone is not enough if audio routing, trust, pairing, or profile selection is broken.i386 graphics libraries.Software & Updates GUI are present by default.generic or hwe.2>/dev/null on commands whose error reason matters. Use 2>&1 || true to surface errors without aborting.fwupd and vendor tools (e.g., system76-firmware) are separate from apt upgrade.update-alternatives for that binary.references/agent-hygiene.mdThe steps are ordered. Copy this checklist and track progress:
| Distro | Default stance | What changes |
|---|---|---|
| Debian stable | Conservative, pin-oriented | stable repo only unless testing/unstable explicitly requested. Backports for select packages. |
| Debian testing | Rolling-ish, with freezes | Closer to Ubuntu but without Ubuntu-specific tooling. |
| Debian unstable (sid) | True rolling | No release, just sid. Higher breakage risk. |
| Ubuntu LTS | Default baseline | do-release-upgrade for release jumps. Treat Ubuntu 26.04 as the current baseline, but remember that 24.04 LTS upgraders also inherit 24.10, 25.04, and 25.10 changes. HWE kernel optional. Snap presence. |
| Ubuntu interim | Short-lived | Common stepping stone into the current LTS. Quick to EOL. |
| Linux Mint | Ubuntu LTS derivative | Cinnamon/XFCE focus. Mint-specific repos and update manager. PPAs from Ubuntu often work. |
| Pop!_OS | Ubuntu derivative with extras | System76 firmware, COSMIC desktop, Pop repos, system76-power. NVIDIA ISO available. |
| Devuan | Debian derivative with a major service-model split | Do not assume systemd, systemctl, or Ubuntu-style desktop/session plumbing. Verify init and service tooling first. |
| Kali | Debian-derived security distro | Fine for base apt, kernel, boot, or service administration, but use kali-linux for Kali-specific branches, images, metapackages, training-image workflow, and offensive-distro context. |
| Other Debian-based | Confirm repo model | Do not assume vanilla Debian or Ubuntu behavior. |
If the host is Ubuntu 24.04 LTS or the user is planning a 24.04 -> 26.04 move, load
references/derivatives-and-hwe.md early. That path bundles interim-release churn, desktop-session
changes, app swaps, and GUI-tool changes that do not show up if you treat 26.04 like a routine
point upgrade.
| Task type | Reference |
|---|---|
apt, dpkg, pinning, PPAs, snaps, .deb handling | references/packages-and-repos.md |
| systemd units, timers, journal, overrides | references/systemd-and-journal.md |
| GRUB, kernel, initramfs, EFI, recovery | references/boot-kernel-and-recovery.md |
| Ubuntu HWE, release upgrades, Debian lanes, Mint/Pop/Devuan/Kali specifics | references/derivatives-and-hwe.md |
| Wayland, X11, GNOME, KDE, Cinnamon, COSMIC, PipeWire | references/desktop-audio-and-bluetooth.md |
| Display managers, session startup, suspend/resume, power, hybrid graphics | references/session-display-and-mobile.md |
| GPU drivers, Vulkan, Steam, Proton, gaming | references/graphics-and-gaming.md |
| OBS, WebRTC, screen sharing, virtual cameras | references/capture-and-sharing.md |
| ext4, Btrfs, LUKS, LVM, TRIM, hibernation | references/storage-and-rollback.md |
| AppArmor, unattended-upgrades, debian-security | references/security-and-updates.md |
| Remote gaming, controllers, input | references/remote-gaming-input-and-tooling.md |
| Core Linux ops commands and Debian tools | references/base-linux-and-cli.md |
| Recurring Debian/Ubuntu failure patterns | references/gotchas-and-special-situations.md |
Do not load every reference by default. Pick the one that matches the failure mode, then widen only if the first layer is clean.
apt-mark, saved configs.Consequential changes (release upgrades, full-upgrade with removals, kernel removal, GRUB
reinstall, PPA purge, LUKS or LVM changes): show the exact command and what it will do (simulated
transaction with apt-get -s, removal list, or target device), get explicit confirmation, run it,
then go to Step 5. In unattended runs, stop at the plan. Exact commands live in
references/derivatives-and-hwe.md (release upgrades), references/boot-kernel-and-recovery.md
(kernels, GRUB, live-media chroot), and references/storage-and-rollback.md (LUKS, LVM).
If kernel or boot files changed, first confirm every kernel above has an initrd and run
sudo update-initramfs -u -k <version> for any that are missing. Then run sudo update-grub only
when GRUB is the confirmed loader (command -v update-grub), and confirm the entries with
grep -E "menuentry|initrd" /boot/grub/grub.cfg. If a check fails, fix the layer it points to and
return to Step 4. Reboot only when the boot path is understood and at least one known-good entry remains.
Keep triage cross-layer and boring:
Core log sweep:
Broad pattern sweeps when you need correlation, not first-pass precision:
When a bug looks desktop-only, compare one clean baseline:
testing or sid packages on stable without a transition plan.Software & Updates GUI is no longer installed by default on new installs. GUI-first troubleshooting advice from 24.04-era blog posts may be wrong on fresh 26.04 systems.systemctl, journalctl, timedatectl, and localectl before distro wrappers.apt-cache policy, apt list --upgradable, and targeted installs before broad reinstall attempts. For slow upgrades, identify held packages and phased updates before forcing resolver choices. Keep package index updates scoped; repeated apt update in scripts wastes time and load.update-initramfs, update-grub, and EFI fallback all have to agree.i386 userspace, absent firmware, or broken Proton path is more common than "Linux gaming is bad."aa-status and journal denials when a service or binary mysteriously fails.fwupd and vendor tools update hardware firmware. Do not expect apt upgrade to fix BIOS or SSD firmware.| Symptom | First checks |
|---|---|
| Package weirdness after install | apt update first. Broken dependencies? apt -f install. Held packages? apt-mark showhold. Mixed releases? apt-cache policy |
| Service fails after update | Config merge needed? ucf or dpkg --configure -a. Check unit overrides and journalctl -b |
| Won't boot after kernel work | GRUB menu, fallback kernel, initramfs. From live media, mount root and the ESP, then bind-mount /dev, /proc, /sys, and /run before chroot; use the boot recovery reference instead of a one-line chroot recipe. |
| PPA broke the system | ppa-purge if available, or manual downgrade + remove after checking package origin with apt-cache policy |
| Snap app misbehaves | snap connections, snap info, confinement level, interfaces |
| Desktop weirdness after update | XDG_SESSION_TYPE, portal, Xwayland, user services. On Ubuntu 26.04, verify the user is not expecting the old Ubuntu Xorg session to exist by default. |
| Bluetooth audio issues | BlueZ pairing, PipeWire nodes, card profile |
| Game blackscreen/crash | GPU driver (proprietary vs Mesa), Vulkan, Steam i386 libs, Gamescope/MangoHud |
| Screen share broken | Wayland vs X11, portal backend, PipeWire user units |
| Suspend/resume breaks desktop | Sleep state, GPU logs, lock-screen, display manager |
| NVIDIA/module vanished after kernel change | DKMS drift: dkms status, confirm module built for uname -r, check HWE transition |
| Nothing makes sense | Check gotchas reference - mixed repos, stale PPAs, DKMS drift, AppArmor denials, HWE metapackage mismatch |
references/packages-and-repos.md - apt workflow, dpkg, pinning, PPAs, snaps, flatpaks, .deb handlingreferences/systemd-and-journal.md - systemd service debugging, unit overrides, user units, journal triagereferences/boot-kernel-and-recovery.md - GRUB, kernel metapackages, initramfs, EFI, recovery, and live-ISO chrootreferences/derivatives-and-hwe.md - Ubuntu HWE, release upgrades, Debian lane differences, Mint, Pop!_OS, Devuan, and Kali scope notesreferences/desktop-audio-and-bluetooth.md - X11 vs Wayland, GNOME, KDE, Cinnamon, COSMIC, portals, PipeWire, Bluetoothreferences/session-display-and-mobile.md - GDM, SDDM, LightDM, session env, suspend/resume, power profiles, hybrid graphicsreferences/graphics-and-gaming.md - NVIDIA, AMD, Intel, Vulkan, Steam, Proton, Gamescope, MangoHudreferences/capture-and-sharing.md - OBS, WebRTC screen sharing, Discord/Teams, hardware encoding, virtual camerasreferences/storage-and-rollback.md - ext4, Btrfs, LUKS, LVM, TRIM, hibernation, resumereferences/security-and-updates.md - AppArmor, unattended-upgrades, debian-security, needrestartreferences/remote-gaming-input-and-tooling.md - Moonlight, Sunshine, controllers, Steam Remote Playreferences/base-linux-and-cli.md - core Linux inspection commands and Debian tools such as update-alternativesreferences/gotchas-and-special-situations.md - recurring Debian/Ubuntu failure patterns and edge casesSee references/output-contract.md for the full contract.
auditsreferences/output-contract.md and write the deliverable to docs/local/audits/debian-ubuntu/<YYYY-MM-DD>-<slug>.md. When invoked to answer a question, teach a concept, build a new artifact, or generate content, respond freely without the contract.P0 | P1 | P2 | P3 | info (see shared contract; only used in audit/review mode).full-upgrade first.apt-cache policy package_name
systemctl status unit_name
journalctl -u unit_name -b
ls -l /boot/vmlinuz-* /boot/initrd.img-*journalctl -b -p warning..alert
journalctl --user -b
dmesg --level=err,warn
journalctl -u unit_name -b
journalctl --user -u pipewire -u wireplumber -u xdg-desktop-portal -bjournalctl -b | grep -Ei 'nvrm|nvidia|amdgpu|i915|xe|drm' 2>&1 || true
journalctl --user -b | grep -Ei 'portal|pipewire|webrtc|obs' 2>&1 || true