---
tags:
- linux
- l1
- flashcard-deck
- dnf
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [DNF Package Manager](../../../../library/portal/topics.md) | **Domain:** Linux
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
dnf/a1b2c3d4e5f6	dnf	easy	dnf, yum, basics	What is the relationship between yum and dnf on RHEL 8+?	On RHEL 8+, yum is a symlink to dnf. Yum4 is dnf under the hood. The yum command still works but actually runs dnf.\n\nName origin: DNF stands for 'Dandified YUM' — a rewrite of YUM (Yellowdog Updater Modified, originally for Yellow Dog Linux on PowerPC Macs).\n\nTimeline: yum (2003) -> yum3 (Python, slow solver) -> dnf/yum4 (2015, libsolv C-based SAT solver, faster and more correct).\n\nGotcha: scripts that check `which yum` still work on RHEL 8+ because yum is a symlink, but best practice is to use `dnf` explicitly in new automation.	training/library/topics/dnf/primer.md
dnf/b2c3d4e5f6a7	dnf	easy	dnf, repos	Where do dnf repository configuration files live?	/etc/yum.repos.d/*.repo — each .repo file can define one or more [repo-id] sections with baseurl, gpgcheck, priority, etc.\n\nGotcha: the directory is still named yum.repos.d even on dnf systems — a legacy naming artifact. Do not rename it.\n\nExample: a minimal .repo file: [myrepo]\\nname=My Repo\\nbaseurl=https://repo.example.com/el9/\\ngpgcheck=1\\nenabled=1	training/library/topics/dnf/primer.md
dnf/c3d4e5f6a7b8	dnf	easy	dnf, search	How do you find which package provides a specific file?	dnf provides '*/filename' — searches all repos for packages that own files matching the glob pattern.\n\nExample: dnf provides '*/dig' finds bind-utils. dnf provides '*/libssl.so*' finds openssl-libs.\n\nRemember: 'provides' searches repo metadata, not just installed packages. For installed-only, use rpm -qf /full/path/to/file.	training/library/topics/dnf/primer.md
dnf/d4e5f6a7b8c9	dnf	easy	dnf, cache	What does `dnf clean all` do?	Wipes all cached metadata and downloaded packages from /var/cache/dnf/. Forces a fresh download of repo metadata on the next operation.\n\nGotcha: `dnf clean all` does NOT clean the RPM database (/var/lib/rpm). For that, use rpm --rebuilddb.\n\nDebug clue: if dnf complains about stale or corrupt metadata, `dnf clean all && dnf makecache` is the standard first fix.	training/library/topics/dnf/primer.md
dnf/e5f6a7b8c9d0	dnf	easy	dnf, check-update	What exit code does `dnf check-update` return when updates are available?	Exit code 100 means updates are available. Exit code 0 means no updates. This is useful in scripts to conditionally trigger patching.\n\nRemember: exit 100 is unusual — most tools use 0=success, non-zero=error. dnf check-update is an exception: 100=updates available (not an error).\n\nExample: dnf check-update -q; rc=$?; if [ $rc -eq 100 ]; then echo 'Updates available'; fi	training/library/topics/dnf/primer.md
dnf/f6a7b8c9d0e1	dnf	easy	dnf, groups	How do you install a package group with dnf?	dnf group install "Development Tools" — installs mandatory and default packages in the group. Use --setopt=group_package_types=mandatory,default to control which tiers.\n\nExample: 'Development Tools' includes gcc, make, autoconf, automake — essential for compiling C/C++ software from source.\n\nRemember: dnf group list shows available groups. dnf group info "Group Name" shows which packages are mandatory, default, and optional.	training/library/topics/dnf/primer.md
dnf/a7b8c9d0e1f2	dnf	easy	dnf, install, local	How do you install a local RPM file so dnf tracks it properly?	dnf install ./package.rpm — the ./ prefix tells dnf it's a local file. This ensures dnf records it as user-installed and tracks dependencies, unlike rpm -i.\n\nGotcha: without the ./ prefix, dnf searches repos for a package named 'package.rpm' (a package name, not a file). The ./ makes it a file path.\n\nX vs Y: dnf install ./pkg.rpm records in dnf history and resolves deps from repos. rpm -i pkg.rpm bypasses dnf entirely — no dep resolution, no history tracking.	training/library/topics/dnf/footguns.md
dnf/b8c9d0e1f2a3	dnf	easy	dnf, list	How do you list all installed packages?	dnf list installed — shows every installed package with version and source repo.\n\nExample: dnf list installed | grep httpd shows if Apache is installed. The @repo column tells you which repo it came from (@anaconda = initial install, @appstream = updates).\n\nRemember: for detailed info on one package: dnf info httpd. For all files in a package: rpm -ql httpd.	training/library/topics/dnf/primer.md
dnf/c9d0e1f2a3b4	dnf	easy	dnf, repolist	How do you show all configured repos and their status?	dnf repolist --all — shows enabled and disabled repos. Add -v for verbose output including baseurl and expiration.\n\nExample: dnf repolist -v shows baseurl, metalink, expiration date, and package count for each repo.\n\nDebug clue: if a package you expect is missing, check dnf repolist to verify the correct repo is enabled.	training/library/topics/dnf/primer.md
dnf/d0e1f2a3b4c5	dnf	medium	dnf, modules, streams	What is a module stream in dnf and why does it matter?	A module stream is a version track for a software component (e.g., postgresql:15 vs postgresql:16). Only one stream per module can be active. Streams filter which packages are visible to the solver, preventing accidental version mixing.\n\nAnalogy: module streams are like TV channels — you can only watch one channel per module at a time. Switching requires explicitly resetting and enabling the new stream.\n\nGotcha: enabling a stream is sticky and persists. If you enable postgresql:15, packages from postgresql:16 become invisible until you reset and switch.	training/library/topics/dnf/primer.md
dnf/e1f2a3b4c5d6	dnf	medium	dnf, modules, profiles	What is the difference between a module stream and a module profile?	A stream selects the version track (e.g., postgresql:15). A profile selects a package subset within that stream (e.g., server, client, devel). You choose a stream first, then a profile.\n\nAnalogy: stream = which version of the software, profile = which components. Like choosing PostgreSQL 15 (stream) and then 'server' vs 'client-only' (profile).\n\nExample: dnf module install postgresql:15/server installs the server profile from the PostgreSQL 15 stream.	training/library/topics/dnf/primer.md
dnf/f2a3b4c5d6e7	dnf	medium	dnf, modules, enable	What happens when you enable a module stream?	dnf module enable postgresql:15 marks that stream as active. Packages from other streams become invisible to the resolver. This is sticky — it persists across operations and requires a reset to change.	training/library/topics/dnf/primer.md
dnf/a3b4c5d6e7f8	dnf	medium	dnf, history, undo	What is the difference between `dnf history undo` and `dnf history rollback`?	undo N reverses only transaction N's changes. rollback N reverses ALL transactions after N, restoring the system to the state immediately after transaction N completed.\n\nExample: if transactions are 10, 11, 12: undo 11 reverses only #11. rollback 10 reverses both #11 and #12.\n\nGotcha: neither command restores config files modified by package scriptlets. You may end up with old packages and new configs — test in staging first.	training/library/topics/dnf/primer.md
dnf/b4c5d6e7f8a9	dnf	medium	dnf, security	How do you apply only security updates with dnf?	dnf update --security — installs only packages that have security advisories. Add --sec-severity=Critical to further filter by severity.\n\nExample: dnf updateinfo list security shows pending security advisories. dnf updateinfo info RHSA-2026:1234 shows details about a specific advisory.\n\nInterview tip: knowing how to apply security-only updates shows you understand production patching discipline — not just 'yum update everything.'	training/library/topics/dnf/street_ops.md
dnf/c5d6e7f8a9b0	dnf	medium	dnf, versionlock	How do you pin a package to its current version with dnf?	Install dnf-plugin-versionlock, then run dnf versionlock add <package>. The lock is stored in /etc/dnf/plugins/versionlock.list and prevents dnf update from changing that package.\n\nGotcha: versionlock prevents ALL updates to the package, including security patches. Review locks regularly with dnf versionlock list.\n\nExample: dnf versionlock add kernel — prevents kernel upgrades until you explicitly remove the lock with dnf versionlock delete kernel.	training/library/topics/dnf/street_ops.md
dnf/d6e7f8a9b0c1	dnf	medium	dnf, automatic	What are the three timer profiles for dnf-automatic?	dnf-automatic-download.timer (download only), dnf-automatic-install.timer (download + install), dnf-automatic-notifyonly.timer (just notify). Each runs daily by default.\n\nRemember: DIN — Download, Install, Notify. Three profiles for three levels of automation.\n\nGotcha: dnf-automatic-install applies updates without human review — safe for security patches, risky for major version bumps. Config: /etc/dnf/automatic.conf.	training/library/topics/dnf/street_ops.md
dnf/e7f8a9b0c1d2	dnf	medium	dnf, repoquery	How do you find what packages depend on a specific installed package?	dnf repoquery --whatrequires <package> --installed — shows all installed packages that have a dependency on the specified package.\n\nExample: dnf repoquery --whatrequires openssl-libs --installed shows everything depending on OpenSSL — useful before major version upgrades.\n\nRemember: without --installed, repoquery searches all repos. Add --installed to limit to what's on this system.	training/library/topics/dnf/street_ops.md
dnf/f8a9b0c1d2e3	dnf	medium	dnf, reposync	How do you create an offline mirror of a dnf repository?	dnf reposync --repoid=baseos --download-metadata -p /srv/repos/ — mirrors the repo to local disk. Then run createrepo_c to regenerate metadata if needed.\n\nExample: use --newest-only to save disk by only mirroring the latest version of each package.\n\nWar story: air-gapped environments (government, secure facilities) depend on reposync mirrors. Without them, no patching is possible.	training/library/topics/dnf/street_ops.md
dnf/a9b0c1d2e3f4	dnf	medium	dnf, priority	How do repo priorities work in dnf and what is the default?	Lower priority number = higher preference. Default is 99. Set priority=10 on internal repos to ensure they win over EPEL (priority=90). Requires the priorities plugin.	training/library/topics/dnf/primer.md
dnf/b0c1d2e3f4a5	dnf	medium	dnf, variables	How do you create and use custom dnf variables?	Create a file in /etc/dnf/vars/ (e.g., echo "production" > /etc/dnf/vars/environment). Reference it in repo configs as $environment. Useful for pointing dev/staging/prod at different repo paths.	training/library/topics/dnf/primer.md
dnf/c1d2e3f4a5b6	dnf	medium	dnf, downloadonly	How do you pre-download updates without installing them?	dnf update --downloadonly -y — downloads packages to /var/cache/dnf/. During the maintenance window, run dnf update -y -C to install from cache with no network access.\n\nRemember: -C (cacheonly) means 'use only cached data, no network.' Perfect for maintenance windows where you want deterministic updates.\n\nWar story: downloading during business hours and installing during the maintenance window avoids surprise download failures at 2 AM.	training/library/topics/dnf/street_ops.md
dnf/d2e3f4a5b6c7	dnf	medium	dnf, best	What does the --best flag do in dnf and what happens without it?	--best (default on RHEL \n9) makes dnf fail if the latest version can't be installed due to dep issues. Without it (--nobest), dnf silently installs an older version that satisfies deps.	training/library/topics/dnf/footguns.md
dnf/e3f4a5b6c7d8	dnf	medium	dnf, gpgcheck	Why should gpgcheck always be enabled in production repo configs?	gpgcheck=1 verifies package signatures against trusted GPG keys. Without it, a compromised mirror or MITM attack could serve tampered packages. It's a basic supply chain security control.	training/library/topics/dnf/primer.md
dnf/f4a5b6c7d8e9	dnf	medium	dnf, exclude	Why is using exclude= in repo configs risky for security patching?	exclude= makes matching packages invisible to dnf, including security updates. If someone added exclude=kernel* to prevent kernel updates, dnf update --security silently skips kernel CVE fixes.	training/library/topics/dnf/footguns.md
dnf/a5b6c7d8e9f0	dnf	hard	dnf, modules, reset	What is the risk of running `dnf module reset` on a production system?	Module reset clears the enabled stream state. If packages from that module are installed, they become "unmanaged" — updates may stop or the system may see conflicting packages. On a running database server, this can lead to package removal or version conflicts.	training/library/topics/dnf/footguns.md
dnf/b6c7d8e9f0a1	dnf	hard	dnf, module_hotfixes	What does module_hotfixes=1 do in a repo config and when is it needed?	It allows the repo to provide packages that override module stream filtering. Needed when a third-party repo provides updated versions of module-managed packages (e.g., a vendor's newer PHP build that should override the AppStream module).	training/library/topics/dnf/primer.md
dnf/c7d8e9f0a1b2	dnf	hard	dnf, history, rollback	Why doesn't `dnf history rollback` restore config files?	Rollback reinstalls/downgrades/removes packages but does not track or restore config file changes made by %post scriptlets or admin edits. You may have an old package version with a new config format, causing service failures.	training/library/topics/dnf/footguns.md
dnf/d8e9f0a1b2c3	dnf	hard	dnf, rpm, database	How do you recover from a corrupted RPM database?	Back up /var/lib/rpm, then run rpm --rebuilddb. Verify with rpm -qa. Corruption typically happens when a transaction is interrupted (killed process, disk full). RHEL 9+ uses SQLite which is more resilient than the old Berkeley DB format.	training/library/topics/dnf/footguns.md
dnf/e9f0a1b2c3d4	dnf	hard	dnf, fleet, staging	Describe the snapshot repo pattern for fleet package management.	Mirror repos at a point in time using dnf reposync. Point dev servers at the snapshot first, promote to staging after validation, then production. Every environment gets identical packages, eliminating "works in staging" drift caused by repo contents changing.	training/library/topics/dnf/street_ops.md
dnf/f0a1b2c3d4e5	dnf	hard	dnf, autoremove, risk	Why can `dnf autoremove` break applications installed via `rpm -i`?	rpm -i doesn't register the package as user-installed in dnf's database. Its dependencies appear as orphaned autoremove candidates. Running dnf autoremove removes them, breaking the rpm-installed application. Fix: use dnf install ./pkg.rpm or dnf mark install <deps>.	training/library/topics/dnf/footguns.md
dnf/a0b1c2d3e4f5	dnf	hard	dnf, solver, libsolv	What dependency solver does dnf use and how does it differ from yum3?	dnf uses libsolv (via hawkey), a C-based SAT solver. Yum3 used a custom Python solver that was slow and sometimes produced incorrect solutions. libsolv is faster, deterministic, and handles complex dependency graphs correctly.	training/library/topics/dnf/primer.md

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [DNF Package Manager](../../../../library/topics/dnf/index.md) (Topic Pack, L2) — DNF Package Manager

<!-- wiki:related:end -->
