Release of Debian 13

After two years of development, Debian 13 "Trixie" was released, available for eight officially supported architectures: Intel IA-32/x86 (i686), AMD64/x86-64, ARM EABI (armel), ARM64, ARMv7 (armhf), RISC-V, PowerPC 64 (ppc64el), and IBM System z (s390x). Updates for Debian 13 will be released over a period of 5 years.

Installation images are available for download via HTTP, jigdo, or BitTorrent. For the amd64 architecture, LiveUSBs have been developed, available in GNOME, KDE, LXDE, Xfce, Cinnamon, and MATE variants, as well as a multi-architecture DVD combining packages for the amd64 platform with additional packages for the i386 architecture. Before the migration procedure from Debian 12, please refer to the following document.

The repository features 69,830 binary packages, which is 5,411 packages more than what was offered in Debian 12. Compared to Debian 12, 14,116 new binary packages have been added, 8,844 (12%) outdated or abandoned packages have been removed, and 44,326 (63%) packages have been updated. The total size of all source texts proposed in the distribution is 1,463,291,186 lines of code. The total size of all packages is 403 GB.

Reproducible builds are supported for 96.9% of packages, allowing verification that the executable was built exactly from the declared source texts and contains no unauthorized changes, which could potentially be introduced through attacks on the build infrastructure or backdoors in the compiler.

Key changes in Debian 13.0:

  • An official port of the distribution for 64-bit RISC-V architecture systems has been added.
  • A "loong64" port has been added for systems based on the LoongArch instruction set architecture, used in Loongson 3 5000 processors, which implements an ISA similar to MIPS and RISC-V. This port is not included among the officially supported ones.
  • The "mipsel" and "mips64el" ports for MIPS architecture systems have been removed. The "mipsel" port was one of the oldest supported Debian ports, with only the i386 port being older. The reason for removal was technical issues, such as a memory size limitation in user space of 2GB and build problems.
  • The formation of official installation images and packages with a kernel for 32-bit x86 systems has been discontinued, but the presence of an officially supported package repository and a multi-arch repository has been maintained, along with the ability to deploy 32-bit environments in isolated containers and tools for building 32-bit applications. The i386 architecture in Debian is now limited to supporting the execution of 32-bit applications in a 64-bit x86_64 environment (SSE2 instructions, which are unavailable in most 32-bit processors supported in Debian 12, are used during building).
  • The year 2038 problem has been fully resolved. All packages have been transitioned to use the 64-bit time_t type in the distribution ports for 32-bit architectures, where the 32-bit time_t type was still used (this cannot handle time beyond January 19, 2038, due to the overflow of the second counter since January 1, 1970).
  • The installer has updated the EFI partition management logic and added a recovery mode for systems installed in a Btrfs subsection. Unneeded firmware that cannot operate without non-free packages or is useless under current kernel settings has been excluded. Support for grub-legacy and win32-loader has been discontinued. The use of non-ASCII characters in full usernames has been restored. Support has been added for the following boards and devices: Pine64 Pinebook, MNT Reform 2, AM64x HummingBoard-T, Pine64 Star64, Wandboard rev D1, as well as laptops and tablets based on the ARM SoC Snapdragon X Elite.
  • The installer and Live builds now include a remote boot mode called ‘HTTP Boot’, where boot images are delivered using the HTTP protocol (the URL of the ISO image is entered in the UEFI firmware or U-Boot interface).
  • The directory for temporary files /tmp now uses the tmpfs file system, which employs a RAM disk stored in memory and can be swapped to a swap partition when there is insufficient free memory. Using tmpfs reduces the number of write operations on physical storage, lowers hard drive power consumption, extends the lifespan of SSDs, and enhances performance when working with temporary files. To revert the storage of /tmp to a regular file system, the command ‘systemctl mask tmp.mount’ can be used.
  • The commands last, lastb, and lastlog have been excluded, which were tied to the files /var/log/wtmp, /var/log/btmp, /var/run/utmp, and /var/log/lastlog, using a 32-bit time_t type that cannot be replaced with a 64-bit without modifying the Glibc ABI and breaking application compatibility. Instead of these utilities, it is recommended to use the utilities wtmpdb, lastlog2, and lslogins.
  • The systemd-cryptsetup package has been used for detecting and mounting encrypted filesystems.
  • On AMD64 and ARM64 architecture systems, Intel CET (Control-flow Enforcement Technology), ARM PAC (Pointer Authentication), and BTI (Branch Target Identification) extensions are utilized to protect against exploits that use return-oriented programming (ROP) techniques. In a ROP attack, the attacker does not attempt to place their code into memory but operates with pieces of machine instructions already available in loaded libraries that end with a return address instruction (typically the end of library functions). The exploit works by creating a chain of calls to similar blocks ('gadgets') to achieve the desired functionality. The essence of the protection is that after control is transferred to a function, return addresses are saved by the processor not only in the usual stack but also in a separate shadow stack that cannot be modified directly.
  • Support for the run0 utility, included in systemd for running processes under the identifiers of other users, has been added. This utility is implemented as an add-on to the systemd-run command and is presented as a more secure alternative to the sudo program.
  • The APT package manager branch 3.0 has been used, in which the user interface has been revamped, the dependency resolution engine Solver3 has been activated, snapshot support has been added, the apt-key utility has been deprecated, a cryptographic backend for the OpenSSL library has been added, and the 'dist-clean' command has been implemented.
  • The debian-repro-status command has been added to check the state of reproducible builds for packages installed in the current system.
  • The migration of the distribution from using a separate /usr partition to a layout where the /bin, /sbin, and /lib* directories are implemented as symbolic links to the corresponding directories within /usr has been completed.
  • The Linux kernel has been updated to version 6.12. New releases of systemd 257, bash 5.2.37, Glibc 2.41, and OpenSSL 3.5 have been utilized.
  • The release includes desktop environments GNOME 48, KDE Plasma 6.3, LXDE 13, LXQt 2.1.0, and Xfce 4.20. The graphics stack has been updated.
  • User applications have been updated, including LibreOffice 25.2, GIMP 3.0.2, Inkscape 1.4, and Vim 9.1.
  • Server applications have been updated, including BIND 9.20, Postfix 3.10, Exim 4.98, PostgreSQL 17, MariaDB 11.8, nginx 1.26, OpenJDK 21, OpenSSH 10.0, Samba 4.22, QEMU 10.0, Docker 26.1.5, and Xen 4.20.
  • Development tools have been updated, such as GCC 14.2, LLVM/Clang 19, Perl 5.40, PHP 8.4, Python 3.13, Rust 1.85, and Go 1.24.
Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster