[{"data":1,"prerenderedAt":1413},["ShallowReactive",2],{"page-\u002Flinux\u002F08-package-management":3},{"id":4,"title":5,"body":6,"description":1406,"extension":1407,"meta":1408,"navigation":246,"path":1409,"seo":1410,"stem":1411,"__hash__":1412},"content\u002Flinux\u002F08-package-management.md","08 — Package Management",{"type":7,"value":8,"toc":1381},"minimark",[9,13,47,52,63,161,164,173,397,409,458,466,577,583,640,644,723,730,736,791,795,833,837,931,935,971,975,1013,1017,1113,1117,1217,1221,1224,1242,1253,1377],[10,11,5],"h1",{"id":12},"_08-package-management",[14,15,16,17,21,22,26,27,30,31,26,34,30,37,30,40,30,43,46],"p",{},"Linux distributions install, update, and remove software via ",[18,19,20],"strong",{},"package managers",". A package is an archive (files + metadata) that the manager installs into the system's standard directories. This chapter covers the major families (",[23,24,25],"code",{},"apt","\u002F",[23,28,29],{},"dpkg",", ",[23,32,33],{},"dnf",[23,35,36],{},"rpm",[23,38,39],{},"pacman",[23,41,42],{},"zypper",[23,44,45],{},"apk","), universal formats, and the pitfalls that break production systems.",[48,49,51],"h2",{"id":50},"the-two-layers","The Two Layers",[14,53,54,55,58,59,62],{},"Every family has a ",[18,56,57],{},"low-level"," tool (works with individual packages, no dependency resolution) and a ",[18,60,61],{},"high-level"," tool (resolves dependencies, downloads from repositories):",[64,65,66,85],"table",{},[67,68,69],"thead",{},[70,71,72,76,79,82],"tr",{},[73,74,75],"th",{},"Family",[73,77,78],{},"Low-Level",[73,80,81],{},"High-Level",[73,83,84],{},"Package Format",[86,87,88,107,125,143],"tbody",{},[70,89,90,94,98,102],{},[91,92,93],"td",{},"Debian\u002FUbuntu",[91,95,96],{},[23,97,29],{},[91,99,100],{},[23,101,25],{},[91,103,104],{},[23,105,106],{},".deb",[70,108,109,112,116,120],{},[91,110,111],{},"RHEL\u002FFedora\u002FRocky",[91,113,114],{},[23,115,36],{},[91,117,118],{},[23,119,33],{},[91,121,122],{},[23,123,124],{},".rpm",[70,126,127,130,134,138],{},[91,128,129],{},"Arch\u002FManjaro",[91,131,132],{},[23,133,39],{},[91,135,136],{},[23,137,39],{},[91,139,140],{},[23,141,142],{},".pkg.tar.zst",[70,144,145,148,152,156],{},[91,146,147],{},"Alpine",[91,149,150],{},[23,151,45],{},[91,153,154],{},[23,155,45],{},[91,157,158],{},[23,159,160],{},".apk",[14,162,163],{},"Use the high-level tool for normal operations. Drop to the low-level only for inspecting or repairing.",[48,165,167,168,170,171],{"id":166},"debianubuntu-apt-and-dpkg","Debian\u002FUbuntu — ",[23,169,25],{}," and ",[23,172,29],{},[174,175,177],"code-wrapper",{"language":176},"bash",[178,179,183],"pre",{"className":180,"code":181,"language":176,"meta":182,"style":182},"language-bash shiki shiki-themes github-light github-dark","# Complex Implementation: full system update + cleanup in production\nsudo apt update                  # refresh package index from repos\nsudo apt full-upgrade             # upgrade + remove\u002Fadd packages if needed\nsudo apt autoremove --purge       # remove unneeded deps + their config\n\n# Install a specific version:\nsudo apt install nginx=1.24.0-*\n\n# Find which package owns a file:\ndpkg -S \u002Fusr\u002Fbin\u002Fcurl\n\n# List files installed by a package:\ndpkg -L nginx\n\n# Fix interrupted installs:\nsudo dpkg --configure -a\nsudo apt --fix-broken install\n\n# Hold a package (prevent upgrade):\nsudo apt-mark hold nginx\napt-mark showhold\nsudo apt-mark unhold nginx\n","",[23,184,185,194,211,224,241,248,254,270,275,281,292,297,303,314,319,325,339,352,357,363,376,385],{"__ignoreMap":182},[186,187,190],"span",{"class":188,"line":189},"line",1,[186,191,193],{"class":192},"sdCPZ","# Complex Implementation: full system update + cleanup in production\n",[186,195,197,201,205,208],{"class":188,"line":196},2,[186,198,200],{"class":199},"sIsaT","sudo",[186,202,204],{"class":203},"sJ6F3"," apt",[186,206,207],{"class":203}," update",[186,209,210],{"class":192},"                  # refresh package index from repos\n",[186,212,214,216,218,221],{"class":188,"line":213},3,[186,215,200],{"class":199},[186,217,204],{"class":203},[186,219,220],{"class":203}," full-upgrade",[186,222,223],{"class":192},"             # upgrade + remove\u002Fadd packages if needed\n",[186,225,227,229,231,234,238],{"class":188,"line":226},4,[186,228,200],{"class":199},[186,230,204],{"class":203},[186,232,233],{"class":203}," autoremove",[186,235,237],{"class":236},"snvgF"," --purge",[186,239,240],{"class":192},"       # remove unneeded deps + their config\n",[186,242,244],{"class":188,"line":243},5,[186,245,247],{"emptyLinePlaceholder":246},true,"\n",[186,249,251],{"class":188,"line":250},6,[186,252,253],{"class":192},"# Install a specific version:\n",[186,255,257,259,261,264,267],{"class":188,"line":256},7,[186,258,200],{"class":199},[186,260,204],{"class":203},[186,262,263],{"class":203}," install",[186,265,266],{"class":203}," nginx=1.24.0-",[186,268,269],{"class":236},"*\n",[186,271,273],{"class":188,"line":272},8,[186,274,247],{"emptyLinePlaceholder":246},[186,276,278],{"class":188,"line":277},9,[186,279,280],{"class":192},"# Find which package owns a file:\n",[186,282,284,286,289],{"class":188,"line":283},10,[186,285,29],{"class":199},[186,287,288],{"class":236}," -S",[186,290,291],{"class":203}," \u002Fusr\u002Fbin\u002Fcurl\n",[186,293,295],{"class":188,"line":294},11,[186,296,247],{"emptyLinePlaceholder":246},[186,298,300],{"class":188,"line":299},12,[186,301,302],{"class":192},"# List files installed by a package:\n",[186,304,306,308,311],{"class":188,"line":305},13,[186,307,29],{"class":199},[186,309,310],{"class":236}," -L",[186,312,313],{"class":203}," nginx\n",[186,315,317],{"class":188,"line":316},14,[186,318,247],{"emptyLinePlaceholder":246},[186,320,322],{"class":188,"line":321},15,[186,323,324],{"class":192},"# Fix interrupted installs:\n",[186,326,328,330,333,336],{"class":188,"line":327},16,[186,329,200],{"class":199},[186,331,332],{"class":203}," dpkg",[186,334,335],{"class":236}," --configure",[186,337,338],{"class":236}," -a\n",[186,340,342,344,346,349],{"class":188,"line":341},17,[186,343,200],{"class":199},[186,345,204],{"class":203},[186,347,348],{"class":236}," --fix-broken",[186,350,351],{"class":203}," install\n",[186,353,355],{"class":188,"line":354},18,[186,356,247],{"emptyLinePlaceholder":246},[186,358,360],{"class":188,"line":359},19,[186,361,362],{"class":192},"# Hold a package (prevent upgrade):\n",[186,364,366,368,371,374],{"class":188,"line":365},20,[186,367,200],{"class":199},[186,369,370],{"class":203}," apt-mark",[186,372,373],{"class":203}," hold",[186,375,313],{"class":203},[186,377,379,382],{"class":188,"line":378},21,[186,380,381],{"class":199},"apt-mark",[186,383,384],{"class":203}," showhold\n",[186,386,388,390,392,395],{"class":188,"line":387},22,[186,389,200],{"class":199},[186,391,370],{"class":203},[186,393,394],{"class":203}," unhold",[186,396,313],{"class":203},[398,399,401,402,405,406],"h3",{"id":400},"caveat-anti-pattern-apt-upgrade-vs-full-upgrade","Caveat & Anti-Pattern: ",[23,403,404],{},"apt upgrade"," vs ",[23,407,408],{},"full-upgrade",[174,410,411],{"language":176},[178,412,414],{"className":180,"code":413,"language":176,"meta":182,"style":182},"# NAIVE: apt upgrade holds back packages with changed dependencies\n# — kernel updates sometimes \"don't happen\" with plain upgrade\nsudo apt upgrade\n\n# PRODUCTION: full-upgrade can remove\u002Fadd packages to resolve dependencies\n# — needed for kernel updates and major version bumps\nsudo apt full-upgrade\n",[23,415,416,421,426,435,439,444,449],{"__ignoreMap":182},[186,417,418],{"class":188,"line":189},[186,419,420],{"class":192},"# NAIVE: apt upgrade holds back packages with changed dependencies\n",[186,422,423],{"class":188,"line":196},[186,424,425],{"class":192},"# — kernel updates sometimes \"don't happen\" with plain upgrade\n",[186,427,428,430,432],{"class":188,"line":213},[186,429,200],{"class":199},[186,431,204],{"class":203},[186,433,434],{"class":203}," upgrade\n",[186,436,437],{"class":188,"line":226},[186,438,247],{"emptyLinePlaceholder":246},[186,440,441],{"class":188,"line":243},[186,442,443],{"class":192},"# PRODUCTION: full-upgrade can remove\u002Fadd packages to resolve dependencies\n",[186,445,446],{"class":188,"line":250},[186,447,448],{"class":192},"# — needed for kernel updates and major version bumps\n",[186,450,451,453,455],{"class":188,"line":256},[186,452,200],{"class":199},[186,454,204],{"class":203},[186,456,457],{"class":203}," full-upgrade\n",[48,459,461,462,170,464],{"id":460},"rhelfedorarocky-dnf-and-rpm","RHEL\u002FFedora\u002FRocky — ",[23,463,33],{},[23,465,36],{},[174,467,468],{"language":176},[178,469,471],{"className":180,"code":470,"language":176,"meta":182,"style":182},"sudo dnf install nginx             # install\nsudo dnf upgrade                   # upgrade all\ndnf provides \u002Fusr\u002Fbin\u002Fcurl         # which package provides a file\ndnf repoquery --requires nginx     # dependencies\ndnf repoquery --whatrequires libcurl  # reverse deps\nrpm -qa                           # all installed packages\nrpm -qf \u002Fusr\u002Fbin\u002Fcurl             # which package owns this file?\nrpm -V nginx                       # verify (check file changes against manifest)\n",[23,472,473,488,500,513,528,543,553,565],{"__ignoreMap":182},[186,474,475,477,480,482,485],{"class":188,"line":189},[186,476,200],{"class":199},[186,478,479],{"class":203}," dnf",[186,481,263],{"class":203},[186,483,484],{"class":203}," nginx",[186,486,487],{"class":192},"             # install\n",[186,489,490,492,494,497],{"class":188,"line":196},[186,491,200],{"class":199},[186,493,479],{"class":203},[186,495,496],{"class":203}," upgrade",[186,498,499],{"class":192},"                   # upgrade all\n",[186,501,502,504,507,510],{"class":188,"line":213},[186,503,33],{"class":199},[186,505,506],{"class":203}," provides",[186,508,509],{"class":203}," \u002Fusr\u002Fbin\u002Fcurl",[186,511,512],{"class":192},"         # which package provides a file\n",[186,514,515,517,520,523,525],{"class":188,"line":226},[186,516,33],{"class":199},[186,518,519],{"class":203}," repoquery",[186,521,522],{"class":236}," --requires",[186,524,484],{"class":203},[186,526,527],{"class":192},"     # dependencies\n",[186,529,530,532,534,537,540],{"class":188,"line":243},[186,531,33],{"class":199},[186,533,519],{"class":203},[186,535,536],{"class":236}," --whatrequires",[186,538,539],{"class":203}," libcurl",[186,541,542],{"class":192},"  # reverse deps\n",[186,544,545,547,550],{"class":188,"line":250},[186,546,36],{"class":199},[186,548,549],{"class":236}," -qa",[186,551,552],{"class":192},"                           # all installed packages\n",[186,554,555,557,560,562],{"class":188,"line":256},[186,556,36],{"class":199},[186,558,559],{"class":236}," -qf",[186,561,509],{"class":203},[186,563,564],{"class":192},"             # which package owns this file?\n",[186,566,567,569,572,574],{"class":188,"line":272},[186,568,36],{"class":199},[186,570,571],{"class":236}," -V",[186,573,484],{"class":203},[186,575,576],{"class":192},"                       # verify (check file changes against manifest)\n",[48,578,580,581],{"id":579},"arch-linux-pacman","Arch Linux — ",[23,582,39],{},[174,584,585],{"language":176},[178,586,588],{"className":180,"code":587,"language":176,"meta":182,"style":182},"sudo pacman -Syu                  # sync repos + upgrade everything (ALWAYS together!)\nsudo pacman -S nginx              # install\nsudo pacman -Rs nginx             # remove + unneeded deps\npacman -Qdt                       # orphaned packages (deps no longer needed)\n",[23,589,590,603,616,630],{"__ignoreMap":182},[186,591,592,594,597,600],{"class":188,"line":189},[186,593,200],{"class":199},[186,595,596],{"class":203}," pacman",[186,598,599],{"class":236}," -Syu",[186,601,602],{"class":192},"                  # sync repos + upgrade everything (ALWAYS together!)\n",[186,604,605,607,609,611,613],{"class":188,"line":196},[186,606,200],{"class":199},[186,608,596],{"class":203},[186,610,288],{"class":236},[186,612,484],{"class":203},[186,614,615],{"class":192},"              # install\n",[186,617,618,620,622,625,627],{"class":188,"line":213},[186,619,200],{"class":199},[186,621,596],{"class":203},[186,623,624],{"class":236}," -Rs",[186,626,484],{"class":203},[186,628,629],{"class":192},"             # remove + unneeded deps\n",[186,631,632,634,637],{"class":188,"line":226},[186,633,39],{"class":199},[186,635,636],{"class":236}," -Qdt",[186,638,639],{"class":192},"                       # orphaned packages (deps no longer needed)\n",[398,641,643],{"id":642},"edge-case-partial-upgrades-break-arch","Edge Case: Partial Upgrades Break Arch",[174,645,646],{"language":176},[178,647,649],{"className":180,"code":648,"language":176,"meta":182,"style":182},"# NAIVE: sync index without upgrading (partial upgrade)\nsudo pacman -Sy nginx\n# The new nginx is built against NEWER libraries than you have → broken\n\n# PRODUCTION: always full-upgrade first (or in one command)\nsudo pacman -Syu\nsudo pacman -Syu nginx            # sync + upgrade + install in one\n\n# If already broken (missing .so files):\nsudo pacman -Syu                  # finish the partial upgrade\n",[23,650,651,656,667,672,676,681,690,703,707,712],{"__ignoreMap":182},[186,652,653],{"class":188,"line":189},[186,654,655],{"class":192},"# NAIVE: sync index without upgrading (partial upgrade)\n",[186,657,658,660,662,665],{"class":188,"line":196},[186,659,200],{"class":199},[186,661,596],{"class":203},[186,663,664],{"class":236}," -Sy",[186,666,313],{"class":203},[186,668,669],{"class":188,"line":213},[186,670,671],{"class":192},"# The new nginx is built against NEWER libraries than you have → broken\n",[186,673,674],{"class":188,"line":226},[186,675,247],{"emptyLinePlaceholder":246},[186,677,678],{"class":188,"line":243},[186,679,680],{"class":192},"# PRODUCTION: always full-upgrade first (or in one command)\n",[186,682,683,685,687],{"class":188,"line":250},[186,684,200],{"class":199},[186,686,596],{"class":203},[186,688,689],{"class":236}," -Syu\n",[186,691,692,694,696,698,700],{"class":188,"line":256},[186,693,200],{"class":199},[186,695,596],{"class":203},[186,697,599],{"class":236},[186,699,484],{"class":203},[186,701,702],{"class":192},"            # sync + upgrade + install in one\n",[186,704,705],{"class":188,"line":272},[186,706,247],{"emptyLinePlaceholder":246},[186,708,709],{"class":188,"line":277},[186,710,711],{"class":192},"# If already broken (missing .so files):\n",[186,713,714,716,718,720],{"class":188,"line":283},[186,715,200],{"class":199},[186,717,596],{"class":203},[186,719,599],{"class":236},[186,721,722],{"class":192},"                  # finish the partial upgrade\n",[14,724,725,726,729],{},"On rolling-release distros: ",[18,727,728],{},"never partial-upgrade."," On point-release distros (Debian, Ubuntu, Fedora), this isn't an issue because versions are pinned per release.",[48,731,733,734],{"id":732},"alpine-apk","Alpine — ",[23,735,45],{},[174,737,738],{"language":176},[178,739,741],{"className":180,"code":740,"language":176,"meta":182,"style":182},"# Complex Implementation: Docker-optimized install (no cache = smaller image)\nsudo apk add --no-cache nginx\napk info -L nginx                  # files installed\napk info --who-owns \u002Fusr\u002Fbin\u002Fcurl  # who owns this file?\n",[23,742,743,748,763,777],{"__ignoreMap":182},[186,744,745],{"class":188,"line":189},[186,746,747],{"class":192},"# Complex Implementation: Docker-optimized install (no cache = smaller image)\n",[186,749,750,752,755,758,761],{"class":188,"line":196},[186,751,200],{"class":199},[186,753,754],{"class":203}," apk",[186,756,757],{"class":203}," add",[186,759,760],{"class":236}," --no-cache",[186,762,313],{"class":203},[186,764,765,767,770,772,774],{"class":188,"line":213},[186,766,45],{"class":199},[186,768,769],{"class":203}," info",[186,771,310],{"class":236},[186,773,484],{"class":203},[186,775,776],{"class":192},"                  # files installed\n",[186,778,779,781,783,786,788],{"class":188,"line":226},[186,780,45],{"class":199},[186,782,769],{"class":203},[186,784,785],{"class":236}," --who-owns",[186,787,509],{"class":203},[186,789,790],{"class":192},"  # who owns this file?\n",[398,792,794],{"id":793},"edge-case-alpine-uses-musl-not-glibc","Edge Case: Alpine Uses musl, Not glibc",[174,796,797],{"language":176},[178,798,800],{"className":180,"code":799,"language":176,"meta":182,"style":182},"# Prebuilt binaries compiled against glibc (most Linux software) won't run on Alpine\n# Error: \"Error loading shared library ld-linux-x86-64.so.2: No such file or directory\"\n# Fix: install gcompat (glibc compatibility layer) or use a musl build\nsudo apk add gcompat\n# Or use debian-slim\u002Fubuntu as the base image instead of Alpine\n",[23,801,802,807,812,817,828],{"__ignoreMap":182},[186,803,804],{"class":188,"line":189},[186,805,806],{"class":192},"# Prebuilt binaries compiled against glibc (most Linux software) won't run on Alpine\n",[186,808,809],{"class":188,"line":196},[186,810,811],{"class":192},"# Error: \"Error loading shared library ld-linux-x86-64.so.2: No such file or directory\"\n",[186,813,814],{"class":188,"line":213},[186,815,816],{"class":192},"# Fix: install gcompat (glibc compatibility layer) or use a musl build\n",[186,818,819,821,823,825],{"class":188,"line":226},[186,820,200],{"class":199},[186,822,754],{"class":203},[186,824,757],{"class":203},[186,826,827],{"class":203}," gcompat\n",[186,829,830],{"class":188,"line":243},[186,831,832],{"class":192},"# Or use debian-slim\u002Fubuntu as the base image instead of Alpine\n",[48,834,836],{"id":835},"universal-package-formats","Universal Package Formats",[64,838,839,861],{},[67,840,841],{},[70,842,843,846,849,852,855,858],{},[73,844,845],{},"Format",[73,847,848],{},"Sandbox",[73,850,851],{},"Auto-update",[73,853,854],{},"Store",[73,856,857],{},"Desktop",[73,859,860],{},"Server",[86,862,863,882,899,915],{},[70,864,865,868,871,874,877,880],{},[91,866,867],{},"Native (apt\u002Fdnf)",[91,869,870],{},"No",[91,872,873],{},"Via package manager",[91,875,876],{},"Distro repos",[91,878,879],{},"✅",[91,881,879],{},[70,883,884,887,890,892,895,897],{},[91,885,886],{},"Flatpak",[91,888,889],{},"Yes",[91,891,889],{},[91,893,894],{},"Flathub",[91,896,879],{},[91,898,870],{},[70,900,901,904,906,908,911,913],{},[91,902,903],{},"Snap",[91,905,889],{},[91,907,889],{},[91,909,910],{},"Snap Store",[91,912,879],{},[91,914,879],{},[70,916,917,920,922,924,927,929],{},[91,918,919],{},"AppImage",[91,921,870],{},[91,923,870],{},[91,925,926],{},"Manual",[91,928,879],{},[91,930,870],{},[398,932,934],{"id":933},"caveat-snap-auto-updates-can-break-things","Caveat: Snap Auto-Updates Can Break Things",[174,936,937],{"language":176},[178,938,940],{"className":180,"code":939,"language":176,"meta":182,"style":182},"# Snaps update automatically — you can't easily pin a version\n# If a snap's new version has a bug, it breaks your workflow with no easy rollback\nsnap refresh --hold               # hold updates (recent snapd)\n# Or avoid snaps for critical tools — use native packages\n",[23,941,942,947,952,966],{"__ignoreMap":182},[186,943,944],{"class":188,"line":189},[186,945,946],{"class":192},"# Snaps update automatically — you can't easily pin a version\n",[186,948,949],{"class":188,"line":196},[186,950,951],{"class":192},"# If a snap's new version has a bug, it breaks your workflow with no easy rollback\n",[186,953,954,957,960,963],{"class":188,"line":213},[186,955,956],{"class":199},"snap",[186,958,959],{"class":203}," refresh",[186,961,962],{"class":236}," --hold",[186,964,965],{"class":192},"               # hold updates (recent snapd)\n",[186,967,968],{"class":188,"line":226},[186,969,970],{"class":192},"# Or avoid snaps for critical tools — use native packages\n",[48,972,974],{"id":973},"verifying-packages","Verifying Packages",[174,976,977],{"language":176},[178,978,980],{"className":180,"code":979,"language":176,"meta":182,"style":182},"# RPM file integrity check\nrpm -V nginx               # check all files against the package manifest\n# Output codes: S=size, M=mode, 5=md5, L=symlink, D=device, U=user, G=group, T=mtime\n# . = ok\n# If a config file was edited, you'll see \"5\" for it (expected)\n",[23,981,982,987,998,1003,1008],{"__ignoreMap":182},[186,983,984],{"class":188,"line":189},[186,985,986],{"class":192},"# RPM file integrity check\n",[186,988,989,991,993,995],{"class":188,"line":196},[186,990,36],{"class":199},[186,992,571],{"class":236},[186,994,484],{"class":203},[186,996,997],{"class":192},"               # check all files against the package manifest\n",[186,999,1000],{"class":188,"line":213},[186,1001,1002],{"class":192},"# Output codes: S=size, M=mode, 5=md5, L=symlink, D=device, U=user, G=group, T=mtime\n",[186,1004,1005],{"class":188,"line":226},[186,1006,1007],{"class":192},"# . = ok\n",[186,1009,1010],{"class":188,"line":243},[186,1011,1012],{"class":192},"# If a config file was edited, you'll see \"5\" for it (expected)\n",[48,1014,1016],{"id":1015},"tips-tricks","💡 Tips & Tricks",[1018,1019,1020,1037,1050,1065,1076,1089,1101],"ul",{},[1021,1022,1023,1026,1027,1030,1031,1033,1034,1036],"li",{},[18,1024,1025],{},"Idiom",": use ",[23,1028,1029],{},"apt full-upgrade"," (not ",[23,1032,404],{},") on Debian\u002FUbuntu — ",[23,1035,408],{}," can remove\u002Fadd packages to resolve dependencies (needed for kernel updates).",[1021,1038,1039,1041,1042,1045,1046,1049],{},[18,1040,1025],{},": run ",[23,1043,1044],{},"sudo apt autoremove --purge"," periodically — after removing packages, their dependencies linger. ",[23,1047,1048],{},"autoremove --purge"," cleans them and their config.",[1021,1051,1052,1026,1054,1057,1058,1057,1061,1064],{},[18,1053,1025],{},[23,1055,1056],{},"dpkg -S"," \u002F ",[23,1059,1060],{},"rpm -qf",[23,1062,1063],{},"pacman -Qo"," to find which package owns a file — essential when a file is broken and you want to reinstall its package.",[1021,1066,1067,1026,1069,1057,1072,1075],{},[18,1068,1025],{},[23,1070,1071],{},"apt-mark hold",[23,1073,1074],{},"dnf versionlock"," to pin a version — if an upgrade would break a critical package, hold it. Just don't forget you held it.",[1021,1077,1078,1080,1081,1084,1085,1088],{},[18,1079,1025],{},": on Arch, always ",[23,1082,1083],{},"pacman -Syu"," (never ",[23,1086,1087],{},"-Sy"," alone) — partial upgrades break the system.",[1021,1090,1091,1026,1094,1057,1097,1100],{},[18,1092,1093],{},"Debug",[23,1095,1096],{},"apt depends \u003Cpkg>",[23,1098,1099],{},"dnf repoquery --requires"," to trace dependency chains.",[1021,1102,1103,1026,1105,1108,1109,1112],{},[18,1104,1093],{},[23,1106,1107],{},"dpkg --configure -a"," to fix a broken apt state — if ",[23,1110,1111],{},"apt install"," is interrupted, the package manager is left half-configured.",[48,1114,1116],{"id":1115},"️-edge-cases-gotchas","⚠️ Edge Cases & Gotchas",[1018,1118,1119,1140,1162,1168,1181,1187,1199,1205],{},[1021,1120,1121,1127,1128,1131,1132,1135,1136,1139],{},[18,1122,1123,1126],{},[23,1124,1125],{},"dpkg -i package.deb"," doesn't resolve dependencies",": it installs only that file. If deps are missing, it fails. Use ",[23,1129,1130],{},"sudo apt install .\u002Fpackage.deb"," (note the ",[23,1133,1134],{},".\u002F",") or ",[23,1137,1138],{},"sudo apt-get install -f"," after.",[1021,1141,1142,1150,1151,1154,1155,1158,1159,1161],{},[18,1143,1144,405,1147],{},[23,1145,1146],{},"rpm -ivh",[23,1148,1149],{},"-Uvh",": ",[23,1152,1153],{},"-i"," installs (fails if already installed). ",[23,1156,1157],{},"-U"," upgrades (installs if not present, upgrades if present). For updates, use ",[23,1160,1157],{},".",[1021,1163,1164,1167],{},[18,1165,1166],{},"Third-party repos can conflict",": adding Docker's repo and a distro's docker.io package can cause version conflicts. Pick one source and stick with it.",[1021,1169,1170,1176,1177,1180],{},[18,1171,1172,1175],{},[23,1173,1174],{},"apt autoremove"," can remove things you need",": if you installed a package manually then removed the thing that depended on it, ",[23,1178,1179],{},"autoremove"," might remove the manual package if it was marked as auto-installed. Review the list before confirming.",[1021,1182,1183,1186],{},[18,1184,1185],{},"PPAs and third-party repos don't get security updates automatically",": if a PPA is abandoned, you get no updates. Remove unused repos.",[1021,1188,1189,1150,1192,1195,1196,1198],{},[18,1190,1191],{},"Holding a package too long causes dependency hell",[23,1193,1194],{},"apt-mark hold nginx"," keeps nginx at 1.24, but other packages move to 1.26 APIs. Eventually ",[23,1197,404],{}," fails with broken deps.",[1021,1200,1201,1204],{},[18,1202,1203],{},"Alpine uses musl, not glibc",": prebuilt binaries built against glibc won't run on Alpine. This is the #1 Docker Alpine gotcha.",[1021,1206,1207,1150,1210,1213,1214,1161],{},[18,1208,1209],{},"Removing a package doesn't always stop its service",[23,1211,1212],{},"apt remove nginx"," may leave the service running until reboot. Stop it first: ",[23,1215,1216],{},"sudo systemctl stop nginx && sudo apt remove nginx",[48,1218,1220],{"id":1219},"spot-the-bug","🧠 Spot the Bug",[14,1222,1223],{},"On an Arch system, a user installs a package:",[174,1225,1226],{"language":176},[178,1227,1229],{"className":180,"code":1228,"language":176,"meta":182,"style":182},"sudo pacman -S firefox\n",[23,1230,1231],{"__ignoreMap":182},[186,1232,1233,1235,1237,1239],{"class":188,"line":189},[186,1234,200],{"class":199},[186,1236,596],{"class":203},[186,1238,288],{"class":236},[186,1240,1241],{"class":203}," firefox\n",[14,1243,1244,1245,1248,1249,1252],{},"Then a few days later, they run ",[23,1246,1247],{},"sudo pacman -Syu"," and get errors about missing shared libraries (",[23,1250,1251],{},".so"," not found) for several programs. What happened?",[1254,1255,1256,1260,1287,1293,1298,1345,1354,1372],"details",{},[1257,1258,1259],"summary",{},"Answer",[14,1261,1262,1263,1266,1267,1270,1271,1270,1274,1277,1278,1281,1282,1286],{},"On Arch (rolling release), the system must be ",[18,1264,1265],{},"fully upgraded"," before installing new packages. The user ran ",[23,1268,1269],{},"pacman -S firefox"," ",[18,1272,1273],{},"without",[23,1275,1276],{},"-Syu"," first. This installed a ",[23,1279,1280],{},"firefox"," built against the ",[1283,1284,1285],"em",{},"latest"," libraries, while their installed packages (glibc, etc.) were still at older versions.",[14,1288,1289,1290,1292],{},"When they later ran ",[23,1291,1083],{},", the upgrade tried to update libraries, but the mismatched state caused failures.",[14,1294,1295],{},[18,1296,1297],{},"Fix — always full-upgrade first:",[174,1299,1300],{"language":176},[178,1301,1303],{"className":180,"code":1302,"language":176,"meta":182,"style":182},"sudo pacman -Syu          # sync + upgrade ALL packages, always together\nsudo pacman -S firefox    # now safe (system is consistent)\n# Or in one command:\nsudo pacman -Syu firefox\n",[23,1304,1305,1316,1330,1335],{"__ignoreMap":182},[186,1306,1307,1309,1311,1313],{"class":188,"line":189},[186,1308,200],{"class":199},[186,1310,596],{"class":203},[186,1312,599],{"class":236},[186,1314,1315],{"class":192},"          # sync + upgrade ALL packages, always together\n",[186,1317,1318,1320,1322,1324,1327],{"class":188,"line":196},[186,1319,200],{"class":199},[186,1321,596],{"class":203},[186,1323,288],{"class":236},[186,1325,1326],{"class":203}," firefox",[186,1328,1329],{"class":192},"    # now safe (system is consistent)\n",[186,1331,1332],{"class":188,"line":213},[186,1333,1334],{"class":192},"# Or in one command:\n",[186,1336,1337,1339,1341,1343],{"class":188,"line":226},[186,1338,200],{"class":199},[186,1340,596],{"class":203},[186,1342,599],{"class":236},[186,1344,1241],{"class":203},[14,1346,1347,1350,1351,1353],{},[18,1348,1349],{},"If already broken"," (missing ",[23,1352,1251],{}," files), boot to a fallback initramfs or chroot from a live USB and complete the upgrade:",[174,1355,1356],{"language":176},[178,1357,1359],{"className":180,"code":1358,"language":176,"meta":182,"style":182},"sudo pacman -Syu          # finish the partial upgrade\n",[23,1360,1361],{"__ignoreMap":182},[186,1362,1363,1365,1367,1369],{"class":188,"line":189},[186,1364,200],{"class":199},[186,1366,596],{"class":203},[186,1368,599],{"class":236},[186,1370,1371],{"class":192},"          # finish the partial upgrade\n",[14,1373,1374,1375],{},"The rule on rolling-release distros: ",[18,1376,728],{},[1378,1379,1380],"style",{},"html pre.shiki code .sdCPZ, html code.shiki .sdCPZ{--shiki-default:#6A737D;--shiki-github-dark:#6A737D}html pre.shiki code .sIsaT, html code.shiki .sIsaT{--shiki-default:#6F42C1;--shiki-github-dark:#B392F0}html pre.shiki code .sJ6F3, html code.shiki .sJ6F3{--shiki-default:#032F62;--shiki-github-dark:#9ECBFF}html pre.shiki code .snvgF, html code.shiki .snvgF{--shiki-default:#005CC5;--shiki-github-dark:#79B8FF}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}html.github-dark .shiki span {color: var(--shiki-github-dark);background: var(--shiki-github-dark-bg);font-style: var(--shiki-github-dark-font-style);font-weight: var(--shiki-github-dark-font-weight);text-decoration: var(--shiki-github-dark-text-decoration);}",{"title":182,"searchDepth":196,"depth":196,"links":1382},[1383,1384,1389,1391,1395,1399,1402,1403,1404,1405],{"id":50,"depth":196,"text":51},{"id":166,"depth":196,"text":1385,"children":1386},"Debian\u002FUbuntu — apt and dpkg",[1387],{"id":400,"depth":213,"text":1388},"Caveat & Anti-Pattern: apt upgrade vs full-upgrade",{"id":460,"depth":196,"text":1390},"RHEL\u002FFedora\u002FRocky — dnf and rpm",{"id":579,"depth":196,"text":1392,"children":1393},"Arch Linux — pacman",[1394],{"id":642,"depth":213,"text":643},{"id":732,"depth":196,"text":1396,"children":1397},"Alpine — apk",[1398],{"id":793,"depth":213,"text":794},{"id":835,"depth":196,"text":836,"children":1400},[1401],{"id":933,"depth":213,"text":934},{"id":973,"depth":196,"text":974},{"id":1015,"depth":196,"text":1016},{"id":1115,"depth":196,"text":1116},{"id":1219,"depth":196,"text":1220},"Linux distributions install, update, and remove software via package managers. A package is an archive (files + metadata) that the manager installs into the system's standard directories. This chapter covers the major families (apt\u002Fdpkg, dnf\u002Frpm, pacman, zypper, apk), universal formats, and the pitfalls that break production systems.","md",{},"\u002Flinux\u002F08-package-management",{"title":5,"description":1406},"linux\u002F08-package-management","0tgsCuTpr6N3j5xpoyoJUYTxXBtH41aTQmIsJjR6TGk",1789924649982]