Skip to content

102.4 Use Debian package management

Weight: 3

Candidates should be able to perform package management using the Debian package tools.

Objectives

  • Install, upgrade and uninstall Debian binary packages
  • Find packages containing specific files or libraries which may or may not be installed
  • Obtain package information like version, content, dependencies, package integrity and installation status (whether or not the package is installed)
  • Awareness of apt

Terms

/etc/apt/sources.list, dpkg, dpkg-reconfigure, apt-get, apt-cache

Concept of the package management system

Long ago, software for Linux came as a compressed .tar.gz file of source code, and you compiled it yourself. As software grew, that became too slow: not everyone has the time or computing power to compile something like the Linux kernel. So package managers were born.

Today you almost never compile software by hand. Every major distribution keeps huge archives of pre-compiled software called repositories, and a package manager that searches them, installs software, finds and installs dependencies, resolves conflicts, and updates the system. Linux had this long before phones had an "app store".

Debian, and its derivatives like Ubuntu, use .deb packages. They are named like NAME_VERSION-RELEASE_ARCHITECTURE.deb, for example:

tmux_3.2a-4build1_amd64.deb
 |    |    |       |
name  |    release architecture
      version

There are two levels of tools:

Package management layers:

  apt-get / apt-cache / apt       (high-level: repositories, dependencies, updates)
  apt-file                        (high-level: find files inside packages)
        |
        v
  dpkg                            (low-level: install/remove individual .deb files)
        |
        v
  .deb files on disk

dpkg works on single .deb files and cannot resolve dependencies. APT (Advanced Package Tool) is not a replacement for dpkg: it is a front end that uses dpkg and fills its gaps, like downloading packages and resolving dependencies automatically. Think of dpkg as the engine and apt as the driver.

dpkg: installing and upgrading a .deb

dpkg -i installs a .deb file. Upgrading is the same command: if an older version is installed, dpkg upgrades it, otherwise it installs a fresh copy.

# dpkg -i tmux_3.2a-4build1_amd64.deb

Packages often need other packages to work, for example an image editor needs a library to open JPEG files. dpkg checks these dependencies and refuses to configure the package if they are missing. It tells you what is missing, but it does not install them. That is your job:

# dpkg -i openshot-qt_2.4.3+dfsg1-1_all.deb
(Reading database ... 269630 files and directories currently installed.)
Preparing to unpack openshot-qt_2.4.3+dfsg1-1_all.deb ...
Unpacking openshot-qt (2.4.3+dfsg1-1) over (2.4.3+dfsg1-1) ...
dpkg: dependency problems prevent configuration of openshot-qt:
 openshot-qt depends on fonts-cantarell; however:
  Package fonts-cantarell is not installed.
 openshot-qt depends on python3-openshot; however:
  Package python3-openshot is not installed.
...
dpkg: error processing package openshot-qt (--install):
 dependency problems - leaving unconfigured
Errors were encountered while processing:
 openshot-qt

The easy fix is apt-get install -f, which installs the missing dependencies (see below).

dpkg: removing and purging

dpkg -r removes a package but keeps its configuration files. dpkg -P (purge) removes the package and its configuration files. You can give several package names at once.

# dpkg -r unrar
(Reading database ... 269630 files and directories currently installed.)
Removing unrar (1:5.6.6-2) ...

Removal also checks dependencies. You cannot remove a package while other installed packages need it:

# dpkg -r p7zip
dpkg: dependency problems prevent removal of p7zip:
 winetricks depends on p7zip; however:
  Package p7zip is to be removed.
 p7zip-full depends on p7zip (= 16.02+dfsg-6).
dpkg: error processing package p7zip (--remove):
 dependency problems - not removing

--force (as in dpkg -i --force PACKAGE) installs or removes even when dependencies are not met. It will most likely leave the package, or the whole system, broken. Do not use it unless you are absolutely sure.

dpkg: getting package information

The general format is dpkg [OPTIONS] ACTION PACKAGE.

Switch Long form What it does
-i --install install or upgrade a .deb file. Does not install dependencies
-r --remove remove a package, keep its configuration files
-P --purge remove a package and its configuration files
-I --info show information about a .deb file: version, architecture, dependencies
-c --contents list the files inside a .deb file
-s --status show the status of a package: installed or not, version, dependencies
-l --list list installed packages (matching a pattern)
-L --listfiles list the files an installed package put on the system
-S --search find which installed package owns a file
-C --audit search for broken installed packages and suggest fixes
--configure configure (or reconfigure) an installed package
--get-selections list every installed package

Look inside a .deb before you install it. -I shows its control information:

# dpkg -I google-chrome-stable_current_amd64.deb
 new Debian package, version 2.0.
 size 59477810 bytes: control archive=10394 bytes.
 Package: google-chrome-stable
 Version: 76.0.3809.100-1
 Architecture: amd64
 Maintainer: Chrome Linux Team <chromium-dev@chromium.org>
 Installed-Size: 205436
 Pre-Depends: dpkg (>= 1.14.0)
 Depends: ca-certificates, fonts-liberation, libappindicator3-1, libasound2 (>= 1.0.16), ...
 Recommends: libu2f-udev
 Provides: www-browser
 Section: web
 Description: The web browser from Google

and -c lists the files it contains:

$ dpkg --contents bzr_2.7.0+bzr6622+brz_all.deb
drwxr-xr-x root/root         0 2019-09-19 18:25 ./
drwxr-xr-x root/root         0 2019-09-19 18:25 ./usr/
drwxr-xr-x root/root         0 2019-09-19 18:25 ./usr/share/doc/bzr/
-rw-r--r-- root/root      1769 2019-09-19 18:25 ./usr/share/doc/bzr/copyright

Is it installed? -s shows the status. deinstall ok config-files means the package was removed but its configuration files are still there:

$ dpkg -s bzr
Package: bzr
Status: deinstall ok config-files
Section: vcs
Architecture: all
Version: 2.6.0+bzr6595-1ubuntu1
Depends: python-bzrlib (<= 2.6.0+bzr6595-1ubuntu1.1~), python-bzrlib (>= 2.6.0+bzr6595-1ubuntu1), python:any
Recommends: python-gpgme
Conffiles:
 /etc/bash_completion.d/bzr b8d9ca95521a7c5f14860e205a854da2
Description: easy to use distributed version control system

What did it install? -L lists the files of an installed package:

# dpkg -L unrar
/.
/usr
/usr/bin
/usr/bin/unrar-nonfree
/usr/share/doc/unrar/copyright
/usr/share/man/man1/unrar-nonfree.1.gz

Who owns this file? dpkg -S, or dpkg-query -S, gives the installed package that owns a file:

# dpkg-query -S /usr/bin/unrar-nonfree
unrar: /usr/bin/unrar-nonfree
$ dpkg -S /var/lib/mplayer/prefs/mirrors
mplayer: /var/lib/mplayer/prefs/mirrors

Quick examples:

dpkg --contents tmux_3.2a-4build1_amd64.deb    # peek inside a .deb without installing
dpkg -i tmux_3.2a-4build1_amd64.deb            # install from a local .deb file
dpkg -s tmux                                   # is tmux installed? what version?
dpkg -L tmux                                   # what files did tmux install?
dpkg -S /usr/bin/tmux                          # which package owns /usr/bin/tmux?
dpkg -P tmux                                   # remove tmux AND its config files

Key difference: -r vs -P

  • -r (remove): deletes the program but leaves config files behind. If you reinstall later, your old settings are still there
  • -P (purge): deletes everything, program and configs. Clean slate

Key difference: -i vs apt-get install

  • dpkg -i installs one .deb file, does NOT resolve dependencies (fails if they're missing)
  • apt-get install fetches from repositories AND resolves all dependencies automatically

dpkg-reconfigure

When a package is installed, a post-install script sets things up: permissions, configuration files, and sometimes questions for you (this is done with debconf). tzdata, for example, asks for your timezone.

If a configuration file is broken, or you want to change your earlier answers, run dpkg-reconfigure. It backs up the old configuration files, unpacks fresh ones and runs the post-install script again, as if the package had just been installed:

# dpkg-reconfigure tzdata

APT and its tools

APT works with repositories: a local or remote server, or (rarely) a CD-ROM. Distributions keep their own repositories, and developers or user groups can offer extra ones. APT may need a network connection to download packages and package lists.

Tool Used for
apt-get download, install, upgrade and remove packages
apt-cache search and show information in the package index
apt-file find files inside packages, even packages that are not installed
apt a newer, friendlier tool that combines the most used options of apt-get and apt-cache

Most apt commands are the same as apt-get:

Task apt-get / apt-cache apt
update the package index apt-get update apt update
install a package apt-get install tmux apt install tmux
remove a package apt-get remove tmux apt remove tmux
upgrade all packages apt-get upgrade apt upgrade
search for a package apt-cache search tmux apt search tmux
show package info apt-cache show tmux apt show tmux
fix broken packages apt-get install -f apt install -f
empty the cache apt-get clean apt clean

Why learn apt-get if apt exists? apt may not be installed on every system, while apt-get and apt-cache always are. On minimal or older systems, apt-get is guaranteed to be there; apt might not be. Also, apt-get is more stable for use in scripts, while apt adds features like a progress bar that are designed for interactive (human) use. So learn apt-get and apt-cache first.

Repositories: /etc/apt/sources.list

APT reads its list of sources from /etc/apt/sources.list. Edit it with any text editor or with graphical tools like synaptic. A typical line:

deb http://us.archive.ubuntu.com/ubuntu/ jammy main restricted universe multiverse

The format is archive type, URL, distribution, components, or archive-type URL distribution component(s):

Field Meaning
archive type deb for binary (ready to run) packages, deb-src for source code
URL the address of the repository
distribution the release name or codename, like jammy (Ubuntu 22.04) or disco (Ubuntu 19.04). One repository can serve several releases
components one or more sets of packages

The components on Ubuntu:

Component Contains
main officially supported, open source
restricted officially supported, closed source, like graphics card drivers
universe open source, maintained by the community
multiverse unsupported, closed source or patent-encumbered

The components on Debian:

Component Contains
main packages that follow the Debian Free Software Guidelines (DFSG) and need nothing outside main
contrib DFSG-compliant packages that depend on packages outside main
non-free packages that do not follow the DFSG
security security updates
backports newer versions of packages in main. Debian stable releases come about every two years, so this gives users newer software

Lines starting with # are comments. To add a repository, add its line (the maintainer usually gives it to you), save, and run apt-get update.

Instead of editing the main file, you can drop extra .list files with the same format into /etc/apt/sources.list.d/:

$ cat /etc/apt/sources.list.d/buster-backports.list
deb http://deb.debian.org/debian buster-backports main contrib non-free
deb-src http://deb.debian.org/debian buster-backports main contrib non-free

The general APT settings are in /etc/apt/apt.conf, and the apt-config program works with them.

Updating the package index

Before installing or upgrading, refresh the package index, the list of packages available in every repository:

# apt-get update
Hit:1 http://us.archive.ubuntu.com/ubuntu disco InRelease
Hit:2 http://us.archive.ubuntu.com/ubuntu disco-security InRelease
Hit:3 http://us.archive.ubuntu.com/ubuntu disco-updates InRelease
Hit:4 http://us.archive.ubuntu.com/ubuntu disco-backports InRelease
Reading package lists... Done

update does not upgrade any software. It only updates the information about packages.

Installing packages

$ tmux
The program 'tmux' is currently not installed. You can install it by typing:
sudo apt-get install tmux
# apt-get install tmux

apt-get install asks for confirmation and resolves dependencies: anything the package needs is installed too. APT always shows what it will install or remove before it asks:

# apt-get install xournal
Reading package lists... Done
Building dependency tree
Reading state information... Done
The following NEW packages will be installed:
  xournal
0 upgraded, 1 newly installed, 0 to remove and 75 not upgraded.
Need to get 285 kB of archives.
After this operation, 1041 kB of additional disk space will be used.

Useful variants:

# apt-get install -s tmux                       # simulation (dry run), changes nothing
# apt-get install --download-only tmux          # only download into the cache
$ apt-get download tmux                         # download the .deb into the current directory

Removing packages

apt-get remove removes a package and keeps its configuration files. To remove the configuration files as well, use purge, or remove --purge:

# apt-get remove xournal
# apt-get purge p7zip
# apt-get remove --purge p7zip

Dependency resolution works both ways. Packages that depend on the one you remove are removed too, and APT lists them first:

# apt-get remove p7zip
The following packages will be REMOVED:
  android-libbacktrace android-libunwind android-libutils
  android-libziparchive android-sdk-platform-tools fastboot p7zip p7zip-full
0 upgraded, 0 newly installed, 8 to remove and 75 not upgraded.
Do you want to continue? [Y/n]

Removing a package does not remove the dependencies that were installed automatically with it. autoremove cleans those up:

# apt-get autoremove tmux                       # remove tmux and its unused dependencies
# apt-get autoremove                            # remove every dependency nothing needs anymore
The following packages will be REMOVED:
  linux-image-3.16.0-25-generic linux-image-extra-3.16.0-25-generic
0 upgraded, 0 newly installed, 2 to remove, and 0 not upgraded.
After this operation, 203 MB of disk space will be freed.

Note on "removing 100%": dpkg -P tmux (purge) removes tmux and its config files, but leaves its dependencies behind. apt autoremove tmux removes tmux and its unused dependencies, but leaves the config files behind. Neither one alone does both jobs. sudo apt autoremove --purge tmux does both in one line, but only checks tmux's own dependencies at that moment. For a full clean-up, including leftovers from older removals, run sudo apt purge tmux and then sudo apt autoremove.

Fixing broken dependencies

Broken dependencies mean an installed package needs packages that are not installed or no longer exist. This happens after an APT error, an interrupted installation, or a manual dpkg -i. Fix it with:

# apt-get install -f                            # -f = fix broken

It installs the missing dependencies, so all packages are consistent again.

Upgrading

apt-get upgrade upgrades every installed package to the newest version in the repositories. Always run apt-get update first, or you upgrade based on old information:

# apt-get update
# apt-get upgrade
Calculating upgrade... Done
The following packages have been kept back:
  gnome-control-center
The following packages will be upgraded:
  cups cups-bsd cups-client cups-common cups-core-drivers cups-daemon (...)
74 upgraded, 0 newly installed, 0 to remove and 1 not upgraded.
Need to get 243 MB of archives.
Do you want to continue? [Y/n]

The last lines tell you how many packages will be upgraded, installed, removed or kept back, and how much will be downloaded.

# apt-get upgrade tzdata                        # upgrade (or install) one package
# apt-get install tzdata                        # install also upgrades an installed package
# apt-get dist-upgrade                          # move to a new distribution release, a major upgrade

Do not confuse them: update refreshes the list of what is available (like checking what is new in the store), and upgrade actually installs the newer versions (like buying them and bringing them home).

The local cache

Every .deb that APT installs is first downloaded to /var/cache/apt/archives/. Partial downloads go to /var/cache/apt/archives/partial/. The cache grows over time, and apt-get clean empties both directories.

Searching for packages: apt-cache

apt-cache search searches package names and descriptions:

$ apt-cache search "tiny window"               # search package names and descriptions
$ apt search grub2                             # same thing using the newer apt command
# apt-cache search p7zip
liblzma-dev - XZ-format compression library - development files
liblzma5 - XZ-format compression library
p7zip - 7zr file archiver with high compression ratio
p7zip-full - 7z and 7za file archivers with high compression ratio
p7zip-rar - non-free rar module for p7zip

liblzma5 does not seem to match, but apt-cache show reveals the word in its full description. show also gives the version, dependencies, size and checksums (MD5, SHA1, SHA256) used to check the package's integrity:

# apt-cache show liblzma5
Package: liblzma5
Architecture: amd64
Version: 5.2.4-1
Priority: required
Section: libs
Depends: libc6 (>= 2.17)
Filename: pool/main/x/xz-utils/liblzma5_5.2.4-1_amd64.deb
Size: 92352
MD5sum: 223533a347dc76a8cc9445cfc6146ec3
SHA256: 01020b5a0515dbc9a7c00b464a65450f788b0258c3fbb733ecad0438f5124800
Description-en: XZ-format compression library
  ...
  format, use the p7zip package instead.)

The search pattern can also be a regular expression.

apt-cache command Use
search search names and descriptions
show full information about a package
showpkg detailed information about a package
depends the dependencies of a package
unmet unmet dependencies
pkgnames list all package names
stats statistics about the package index

Finding files in packages: apt-file

dpkg -S and dpkg -L only know installed packages. To ask about packages that are not installed, use apt-file. It may not be installed by default, and it needs its own cache:

# apt-get install apt-file
# apt-file update
# apt-file list unrar
unrar: /usr/bin/unrar-nonfree
unrar: /usr/share/doc/unrar/changelog.Debian.gz
unrar: /usr/share/doc/unrar/copyright
unrar: /usr/share/man/man1/unrar-nonfree.1.gz
# apt-file search libSDL2.so
libsdl2-dev: /usr/lib/x86_64-linux-gnu/libSDL2.so

So if you need the library libSDL2.so, install libsdl2-dev. Remember the exam difference: apt-file search also searches packages that are not installed, while dpkg-query -S only knows installed ones.

Common apt-get commands

Command Use
update refresh the package index from the repositories (does not upgrade)
upgrade upgrade all installed packages to latest versions (won't remove anything)
dist-upgrade major upgrade to a new release, can add or remove packages to satisfy new dependencies
install install or upgrade packages (-f fixes broken dependencies)
remove remove a package, keep its configuration
purge remove a package and its configuration
autoremove remove automatically installed dependencies that are no longer needed
source download the source code of a package
download download a .deb into the current directory
clean delete all cached .deb files from /var/cache/apt/archives/ to free disk space
autoclean remove cached packages that can no longer be downloaded
check check the package database for consistency issues

There are other front ends too: text tools like aptitude (a text-based interactive package manager), and graphical tools like synaptic and the software centers of GNOME and KDE.

Summary

I have a Debian-based Linux system where software is distributed as .deb packages, and there are two layers of tools. dpkg at the bottom works directly with individual .deb files, but it cannot resolve dependencies on its own: -i installs or upgrades but stops on missing dependencies, -r removes and keeps configuration while -P purges it too, -I and -c inspect a .deb file, and -s, -L, -S (or dpkg-query -S) and --get-selections query what is installed. If a package has post-install configuration prompts I need to change later, dpkg-reconfigure re-runs them.

Above it, APT (apt-get and apt-cache) works with the online repositories listed in /etc/apt/sources.list and /etc/apt/sources.list.d/*.list (lines of type, URL, distribution and components such as main, contrib, non-free or universe), automatically downloading packages and their dependencies. The workflow I use most often is apt-get update to refresh the package list, then apt-get install to install, apt-get upgrade to upgrade all packages, and apt-get remove, purge or autoremove to clean up. If a dpkg -i leaves a package in a broken state with missing dependencies, apt-get install -f fixes it, and apt-get clean empties /var/cache/apt/archives/. To find things, apt-cache search and show cover names, descriptions, versions, dependencies and checksums, and apt-file search finds which package holds a file even when it is not installed. apt combines the common commands, but I learn apt-get and apt-cache because they are always there.

The one naming trap to watch for is update vs upgrade: apt-get update only refreshes the list of available packages (like checking what's new at the store), while apt-get upgrade actually installs the newer versions (like buying and bringing them home). Running upgrade without update first means you're upgrading based on stale information.