# \[GUIDE\] Debian unstable (sid) on the Framework Intel Laptop

**URL:** <https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539>\
**Category:** Linux\
**Created:** [November 27, 2021, 3:44pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539 "2021-11-27T15:44:33Z")\
**Posts on this page:** 20\
**Page:** 1

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [November 27, 2021, 3:44pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/1 "2021-11-27T15:44:33Z")

</div>

This thread is to manage the content on Debian unstable (sid) branch. For Debian’s 3 kind of branches: unstable (sid), testing and stable, you can see [Debian releases](https://www.debian.org/releases/) and [Debian#Branches - Wikipedia](https://en.wikipedia.org/wiki/Debian#Branches).

# Installation

As someone who has been daily-driving Debian `sid` for years at this point, it was only natural that I go with Debian `sid` on the Framework. Here was the process I followed (everything was pretty simple and straight-forward):

1. Install Debian using [this ISO](https://cdimage.debian.org/cdimage/daily-builds/daily/arch-latest/amd64/iso-cd/debian-testing-amd64-netinst.iso) (it’s the current weekly netinstall ISO build and includes nonfree firmware). Personally, when installing, I select the bare minimum to make the upgrade to `sid` easier in the next step.
2. Once booted into the new install, remove everything from `/etc/apt/sources.list` and put the following in `/etc/apt/sources.list.d/debian.sources` (you can select a different mirror if you wish, and you can find a list of mirrors [here](https://www.debian.org/mirror/list); if you do this, the `URIs` field will be the hostname + HTTP fields in the table and nothing else should change).

```auto
Types: deb deb-src
URIs: https://mirrors.wikimedia.org/debian/
Suites: unstable experimental
Components: main contrib non-free-firmware non-free

```

1. Once you’ve edited the sources, do `sudo apt update && sudo apt dist-upgrade`. If you did the minimal install (like I do), this should be fast and have few/no conflicts.
2. Now, you can install whatever desktop environments/window managers/etc you want (if you want to replicate the installer experience, you can do e.g. `sudo tasksel install <task>` and you can get a list of tasks by doing `tasksel --list-tasks`; for example, if you want to install Gnome the way the installer would, simply run `sudo tasksel install gnome-desktop`).

# Fingerprint authentication

To enable fingerprint authentication system-wide with a fallback to password authentication, you do the following:

1. Install `fprintd` and the `fprintd` PAM module: `sudo apt install fprintd libpam-fprintd`.
2. Enroll your fingerprint: `sudo fprintd-enroll $USER` and keep scanning your finger until it comes back with “Enrollment successful” (I think I had to do it 10 times?).
3. Enable fingerprint authentication: `sudo pam-auth-update` and check the “Fingerprint authentication” box (the spacebar will toggle whether something is enabled). **Don’t edit any of the other modules** — simply enable fingerprint authentication, hit the tab key to switch to the “OK” button, and hit the enter key to save.
4. You can test this out by doing `sudo -k && sudo -i`, which clears the `sudo` authentication cache and then opens a root shell (so it will prompt for authentication).

If you previously registered your fingerprints (either in Windows or another Linux install) and didn’t clear them before installing Debian, use [this](http://community.frame.work/t/fingerprint-scanner-compatibility-with-linux-ubuntu-fedora-etc/1501/214) to clear the fingerprint reader’s internal memory so that you can register your fingerprints again.

# Deep sleep

As with other Linux distros, you should add `mem_sleep_default=deep` to switch to deep sleep ( **different from hibernate** ) as the default.

1. Run `sudoedit /etc/default/grub` and add `mem_sleep_default=deep` at the end of the `GRUB_CMDLINE_LINUX_DEFAULT` parameter (inside the quotes). So for example, mine used to be `GRUB_CMDLINE_LINUX_DEFAULT="quiet splash"` and I changed it to `GRUB_CMDLINE_LINUX_DEFAULT="quiet splash mem_sleep_default=deep"`.
2. Run `sudo update-grub2` to update the bootloader configuration.
3. Reboot to use the new default.

# Hibernate

Out of the box, Framework enables secure boot. This is fine for booting Debian, but it puts the kernel in a restricted mode where hibernate is disabled. If you want to enable hibernation (_highly recommended_ for battery savings), you’ll want to disable Secure Boot in the UEFI settings. Once you do this, hibernate should just work.

# Display

I use Wayland with `sway` as my compositor. The default scaling is 2, which is a bit too large for my taste, so I set `output eDP-1 scale 1.5` in my `sway` config. As expected, Wayland-native programs are sharp, but Xwayland windows have slight blurring in the fonts. I’ve setup Firefox and Signal-Desktop to be Wayland-native (passing `MOZ_ENABLE_WAYLAND=1` as an environment variable when starting Firefox and passing the options `--enable-features=UseOzonePlatform --ozone-platform=wayland` when starting Signal-Desktop), so the only program I use regularly which is running on Xwayland is emacs, which should hopefully soon be fixed.

# UEFI Updates

I recently updated my UEFI from version 3.06 (the version my Batch 5 came with) to 3.07 (mainly for the charging limit feature). Until LVFS is setup, the easiest way to do this is to use the UEFI shell update method.

The releases are put up on [here](https://knowledgebase.frame.work/en_us/framework-laptop-bios-releases-S1dMQt6F), and I’ve linked to the 3.07 release in this post.

1. Run `sudo grub-install --removable` to make sure you’ll be able to boot without needing the ‘Debian’ boot entry (EFI boot variables are apparently cleared on upgrade). This **will** overwrite the `/efi/EFI/BOOT/BOOTX64.EFI` file if something else has written to it, so keep that in mind if you e.g. dual-boot. This is only needed once, so if you already have GRUB installed in that location, you can skip this step.
2. Download the [EFI shell updater](https://downloads.frame.work/bios/Framework_Laptop_BIOS_EFI_3.07.zip)
3. Format a flash drive as VFAT (e.g. `mkfs.vfat /dev/<whatever>`).
4. Mount the flash drive (e.g. `pmount /dev/<whatever>` or `sudo mount -t auto /dev/<whatever> /mnt/<whatever>`).
5. Copy the zip file to the flash drive.
6. Unzip the zip file. This should leave you with an `efi` directory and a few other files at the ‘root’ of the flash drive (`H2OFFT-Sx64.efi`, `hx20_capsule_dvt2_3.07.bin`, and `startup.nsh`).
7. Plug in the charger.
8. Reboot and boot from the flash drive (make sure Secure Boot is disabled and press F12 while booting to select the flash drive).
9. Follow the prompts and just wait for the update to finish.
10. After booting in Debian, run `sudo grub-install` to restore the EFI boot entry variables.

# Other things

If there are other things you want me to explain about my setup, I can add other posts to this thread (or possibly update this post depending on edit policy?), so just let me know! I’m more than happy to explain my setup and update with anything else I’ve tweaked. As far as I remember, these were the main “general” tweaks I had to do.

# See also

- [[TRACKING] Debian testing on the Framework Laptop](http://community.frame.work/t/debian-testing-on-the-framework-laptop/14448)
- [Debian 11 on the Framework Laptop](http://community.frame.work/t/debian-11-on-the-framework-laptop/10395)
- [Debian based Linux on the Framework Laptop](http://community.frame.work/t/debian-based-linux-on-the-framework-laptop/3347)

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 1, 2021, 9:26pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/2 "2021-12-01T21:26:19Z")

</div>

Tried and failed. Even with the non-free firmware included on the USB drive, the installer keeps requesting that I plug in a USB drive with the non-free firmware on it.

It cannot even figure out its own stuff.

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 1, 2021, 10:04pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/3 "2021-12-01T22:04:35Z")

</div>

You just hit enter and it should load the firmware.

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 1, 2021, 10:17pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/4 "2021-12-01T22:17:17Z")

</div>

> [@Chiraag\_Nataraj](#):
>
> You just hit enter and it should load the firmware.

Yeah, no, it doesn’t. As I said, it “keeps requesting”. In other words, I hit ENTER, it reads the USB drive, then the same screen pops up. I can hit ENTER all day long and go nowhere.

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 1, 2021, 10:18pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/5 "2021-12-01T22:18:56Z")

</div>

That’s really odd. How did you burn the image to the USB?

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 1, 2021, 10:49pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/6 "2021-12-01T22:49:59Z")

</div>

The USB formatting utility is irrelevant, but in the interest of full disclosure, I’m using Rufus v3.17.

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 1, 2021, 10:59pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/7 "2021-12-01T22:59:56Z")

</div>

> [@Christopher\_McGee](#):
>
> The USB formatting utility is irrelevant, but in the interest of full disclosure, I’m using Rufus v3.17.

This is absolutely not true. Sometimes the formatting utility can mess things up.

I really don’t know, since I usually use `dd` to format my USB sticks and it’s never failed. Once you boot into the installer and get to the firmware step, can you change to a different TTY (e.g. type Ctrl+Alt+F2), press enter to activate the console, and run `dmesg` to see if there are any errors. Further, you can try `dpkg -i /firmware/firmware-iwlwifi_20210818-1_all.deb` to manually load it.

I want to emphasize that something is wrong here, since I absolutely did not have to do any of this and it all worked seamlessly during install. Maybe it’s Rufus. Maybe your ISO download is corrupted (you can finding the sha256 or sha512 checksums and comparing against the ones on the website).

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 2, 2021, 12:33am UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/8 "2021-12-02T00:33:17Z")

</div>

> [@Chiraag\_Nataraj](#):
>
> I usually use `dd` to format my USB sticks and it’s never failed.

I recommend you amend your original post to inform users that they should write the image to the USB drive in “DD Image mode.”

In Rufus, after loading up the ISO image and clicking `START`, one of the popups that will appear right before it begins to write data to the drive is “ISOHybrid image detected”. It allows the user to select if they want to write the image in “ISO Image (file copy) mode” (which they recommend) or in “DD Image (disk image) mode.” The ISO Image mode allows for full access to the drive after writing to it whereas the DD Image mode does not.

I honestly did not think this choice would make any difference whatsoever until you mentioned that you use something called `dd` to format your USB drives.

My apologies if I came across as rude. It’s been a long day.

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 2, 2021, 1:13am UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/9 "2021-12-02T01:13:47Z")

</div>

Also, I’m getting the same problem as I did with Ubuntu when attempting to register a fingerprint.

In Gnome: “Failed to claim fingerprint device Goodix MOC Fingerprint Sensor: the device is already claimed by another process.”

In the terminal: “failed to claim device: GDBud.Error:net.reactivated.Fprint.Error.AlreadyInUse: Device was already claimed”

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 2, 2021, 12:34pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/10 "2021-12-02T12:34:10Z")

</div>

> [@Christopher\_McGee](#):
>
> In the terminal: “failed to claim device: GDBud.Error:net.reactivated.Fprint.Error.AlreadyInUse: Device was already claimed”

Hmm, the only reference I found to that error is [here](https://bbs.archlinux.org/viewtopic.php?id=262476), but it makes me wonder if you tried setting up fingerprint authentication on Windows before installing Linux?

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 2, 2021, 1:07pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/11 "2021-12-02T13:07:40Z")

</div>

> [@Chiraag\_Nataraj](#):
>
> tried setting up fingerprint authentication on Windows before installing Linux?

Nope. My very first attempts with this Framework laptop were with Ubuntu. Regardless, you also own a Framework laptop, so you can verify that there is no “Predesktop Authentication” setting in BIOS.

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 2, 2021, 1:37pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/12 "2021-12-02T13:37:01Z")

</div>

> [@Christopher\_McGee](#):
>
> Regardless, you also own a Framework laptop, so you can verify that there is no “Predesktop Authentication” setting in BIOS.

I know, but people have reported issues with registering fingerprints under Windows and then installing Linux, hence I asked.

Further, [this](http://community.frame.work/t/solved-fingerprint-reader-no-longer-working-on-fedora-after-windows-to-go-boot/10949) thread mentions that setting up the fingerprint reader in Windows (even just installing the driver) might have locked the device to Windows, and there’s a link to another post on there that explains how to fix it. Specifically, try [this](http://community.frame.work/t/fingerprint-scanner-compatibility-with-linux-ubuntu-fedora-etc/1501/214) appimage.

In the other thread, you mentioned that you were going to setup Windows, so I’m wondering if you actually followed through on that. Regardless, something here has to do with the fact that you’ve reinstalled the OS multiple times (and maybe setup your fingerprints on a previous install).

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 2, 2021, 8:17pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/13 "2021-12-02T20:17:36Z")

</div>

Does the fingerprint device itself have its own, separate non-volatile memory where it stores the fingerprints that have been scanned? If so, I wonder if the times when I was able to successfully scan fingerprints (way back during my first Ubuntu installation) have taken up those spots in its memory and now I need to run the scripts or whatever in the other thread to erase them from memory and start from a blank slate.

---

<div class="post-metadata">

**Author:** ![lbkNhubert](https://avatars.discourse-cdn.com/v4/letter/l/e19b73/32.png) [@lbkNhubert](https://community.frame.work/u/lbkNhubert)\
**Post date:** [December 2, 2021, 9:53pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/14 "2021-12-02T21:53:13Z")

</div>

Yes, it does. I believe that you’re on the right track regarding running the python script to clear out any existing prints, then trying again to enroll a new one. Best of luck!

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [December 3, 2021, 1:38pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/15 "2021-12-03T13:38:32Z")

</div>

By the way, I made this a wiki post so that others can edit with their experience (or clarify things). @Christopher_McGee, feel free to add parts specific to your experience if you wish 🙂

---

<div class="post-metadata">

**Author:** ![Christopher\_McGee](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/christopher_mcgee/32/5175_2.png) [@Christopher\_McGee](https://community.frame.work/u/Christopher_McGee)\
**Post date:** [December 3, 2021, 2:28pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/16 "2021-12-03T14:28:52Z")

</div>

Sounds good. I’ve [posted my experiences in the main thread](http://community.frame.work/t/fingerprint-scanner-compatibility-with-linux-ubuntu-fedora-etc/1501/285). Feel free to paraphrase it here if you like.

---

<div class="post-metadata">

**Author:** ![junaruga](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/junaruga/32/5342_2.png) [@junaruga](https://community.frame.work/u/junaruga)\
**Post date:** [January 29, 2022, 2:22pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/17 "2022-01-29T14:22:31Z")

</div>

I renamed “Setting up Debian sid on the Framework” to “Debian unstable (sid) on the Framework Laptop” aligning other distro threads on “Linux” category. I also wanted to emphasize this thread is for unstable (sid) branch but not for testing branch for now. Though it might be this thread could include testing branch in the future.

As a reference, to know 3 kind of branches: unstable (sid), testing, stable branches, the following documents are useful.

- [https://www.debian.org/releases/](https://www.debian.org/releases/)
- [https://en.wikipedia.org/wiki/Debian#Branches](https://en.wikipedia.org/wiki/Debian#Branches)

---

<div class="post-metadata">

**Author:** ![junaruga](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/junaruga/32/5342_2.png) [@junaruga](https://community.frame.work/u/junaruga)\
**Post date:** [January 29, 2022, 2:40pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/18 "2022-01-29T14:40:54Z")

</div>

I updated this thread’s wiki adding “See also” section to add links to Debian testing and stable branches, and Debian based Linux threads for convenience.

---

<div class="post-metadata">

**Author:** ![khimaros](https://sea1.discourse-cdn.com/flex001/user_avatar/community.frame.work/khimaros/32/6257_2.png) [@khimaros](https://community.frame.work/u/khimaros)\
**Post date:** [January 29, 2022, 4:10pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/19 "2022-01-29T16:10:14Z")

</div>

> [@Christopher\_McGee](#):
>
> BIOS

any ideas on how to prevent BIOS updates from screwing with EFI boot? how does ubuntu work around this?

---

<div class="post-metadata">

**Author:** ![Chiraag\_Nataraj](https://avatars.discourse-cdn.com/v4/letter/c/97f17d/32.png) [@Chiraag\_Nataraj](https://community.frame.work/u/Chiraag_Nataraj)\
**Post date:** [January 29, 2022, 10:04pm UTC](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539/20 "2022-01-29T22:04:35Z")

</div>

> [@khimaros](#):
>
> any ideas on how to prevent BIOS updates from screwing with EFI boot? how does ubuntu work around this?

Run `sudo grub-install --removable` and you should always be able to boot back up even if the EFI boot entries have been removed.

[Next page](https://community.frame.work/t/guide-debian-unstable-sid-on-the-framework-intel-laptop/11539.md?page=2)
