DEB package notes - dpkg, apt, aptitude, and friends

Jump to navigationJump to search

Notes on APT, apt-get, aptittude, dpkg, and friends

Apt-get or aptitude gets stuck trying to use IPv6 addresses

This seems stupid to me, but I have a thing against IPv6... At any rate, if apt-get seems to get stuck trying to connect to a repository and it is showing an IPv6 address for the address of the remote repository then you can add the following option to your command to make it stop doing this. This will force IPv4:

apt-get -o Acquire::ForceIPv4=true update
aptitude -o Acquire::ForceIPv4=true

Apt packages left stuck in queue -- clear the pending package actions

Having packages left in the queue can cause problems for the next admin to use the system. They might not notice the actions already in the queue and may inadvertently trigger them. This can have devastating consequences to the system. See Aptitude_safety_precautions for more information.

The first command will show a list of any packages in the queue waiting to be installed. The second command will clear everything from the queue.

aptitude -ysfD install
aptitude keep-all

Get a list of all packages last installed

awk '!/^Commandline:|^Start-Date:|^End-Date:|^Upgrade:|^Error:/ { gsub( /\([^()]*\)/ ,"" ); \
gsub(/ ,/," ");sub(/^Install:/,""); print}' /var/log/apt/history.log

Need to also check the gziped rotated historical logs (history.1.log.gz,

open and extract files from a DEB package without using Debian tools

You can use standard UNIX tools to work with a DEB file. Use the ar command to extract the data files from the DEB. These are stored in a tar.gz file. For this example, assume there is a file stored in /usr/bin/foo in the data file.

ar p foo.deb data.tar.xz > data.tar.xz
tar JxfO data.tar.xz ./usr/bin/foo >foo

open and extract files from a DEB package

This will create the destination directory that you give as the last argument. The filesystem contents of the deb package will be created. Note that this does not extract the control scripts and all the logic actually responsible for setting up the package. See the next example for that.

dpkg-deb --extract example-package-name.deb /tmp/example-package-name

Extract only the control files.

dpkg-deb --control example-package-name.deb /tmp/example-package-name

Extract both the filesystem tree and the control files.

dpkg-deb --raw-extract example-package-name.deb /tmp/example-package-name

download source package and extract the package source directory tree

This will download a source package and unpack its source tree.

apt-get source python-pexpect

This will download a source package but leave it unpacked.

apt-get --download-only source python-pexpect

download a specific DEB file from a repository

This will download the given PACKAGE_NAME. The file will be stored in /var/cache/apt/archives. Note that the exact name will be different than the package name. It will at least have a version number appended to it. This action may also download dependency DEB packages.

apt-get --download-only --force-yes -yy install --reinstall [PACKAGE_NAME]

This script will download into the current directory:

# deb-download

DESTINATION_DIR=$(readlink -f .)
[ -d ./partial/ ] && PARTIAL_EXISTS=1

if [ -z "${PARTIAL_EXISTS}" ]; then
    mkdir ${DESTINATION_DIR}/partial

apt-get -d --force-yes -y install --reinstall -o Dir::Cache::archives=${DESTINATION_DIR} ${PACKAGE_NAME}

if [ -z "${PARTIAL_EXISTS}" ]; then
    rmdir ${DESTINATION_DIR}/partial

You can also see the URL of where the package would be downloaded from:


Caching apt requests vs. maintaining a local mirror

Maintaining a local mirror takes more effort, storage, bandwidth, and maintenance. The main advantage of running a local mirror is that it isolates you from upstream updates to a repository. This is particularly important when working with Debian Sid. You can update the mirror on a staging server, point some test hosts at the stage repository, do a full update and upgrade on the test hosts, test and confirm that the hosts work as required; finally, push stage repository to the primary local mirror. A secondary advantage of a local mirror is much faster upgrade and updates of hosts.

Setting up a proxy cache is easy and quick. Hosts do need to be reconfigured to use the proxy, but this a one time setup. The main advantage of running a proxy cache is that subsequent upgrades and updates by other hosts using the cache will be much faster. The downside is that a proxy cache does not provide isolation from upstream changes.

This script will install the apt-cacher-ng package and then configure each host in the HOSTS list to use the MIRROR_HOST as a proxy.

export HOSTS="solute-1 solute-2 solute-3 solute-4 solute-5"
apt-get install -y apt-cacher-ng
# lynx http://localhost:3142/
for HOST in ${HOSTS}; do 
        ssh root@${HOST} 'echo "Acquire::http{Proxy \"http://'${MIRROR_HOST}':3142\";};" > /etc/apt/apt.conf.d/01proxy'

You can also use the proxy cache selectively by providing configuration through environment variables rather than updating /etc/apt/apt.conf.

apt-get install apt-cacher-ng
/etc/init.d/apt-cacher-ng start
export http_proxy=http://localhost:3142/

Running an Apt repository


  1. .Ubuntu Mirror of 14.04 LTS (trusty)
  2. .Local homemade packages
  3. .Staging repository on all packages, including Ubuntu Mirror
  4. .Production repository
  5. . Components: MirrorTrusty/main MirrorTrust/universe Staging/main Staging/universe Staging/local Production/main Production/universe Production/local

Install reprepro

Install the reprepro package.

aptitude install reprepro

Create a repository for it to manage.

mkdir -p /var/repo/conf
mkdir /var/repo/gpg

Create the following file, /var/repo/conf/distributions. If you do not want to use key signing with your repository then remove the last option line SignWith:"

Origin: custom
Label: Local Repository
Description: Local repository for 14.04 LTS (trusty) packages.
Codename: trusty
Components: main
Architectures: i386 amd64

Create the following file, /var/repo/conf/options.

outdir /var/repo
gnuphhome +b/gpg

Create a key options file for batch key creation, key.options:

Key-Type: default
Key-Length: 4096
Subkey-Length: 4096
Expire-Date: 0
Name-Real: Repo Robot
Name-Comment: repoman
%secring example.sec

Generate the GPG keys from the options batch file, or see next example to do it interactively.

GNUPGHOME=/var/repo/gpg gpg2 --batch --gen-key key.options

Generate GPG keys interactively. Press enter when asked for a password to disable encrypted keys.

GNUPGHOME=/var/repo/gpg gpg2 --gen-key

Set repository ownership.

chown -R www-data:www-data /var/repo

Configure Apache2 with something like the following in /etc/apache2/sites-enabled/000-default.conf:

ServerName localhost
<VirtualHost *:80>
        DocumentRoot /var/repo
        <Directory /var/repo/>
            Options Indexes FollowSymLinks
            AllowOverride None
            Require all granted
        # Possible values: debug, info, notice, warn, error, crit, alert, emerg
        LogLevel warn
        CustomLog ${APACHE_LOG_DIR}/access.log combined
        ErrorLog ${APACHE_LOG_DIR}/error.log
#        # Redirect http requests to https.
#        RewriteEngine On
#        RewriteCond %{HTTP:X-Forwarded-Proto} !https
#        RewriteRule !/server.html https://%{SERVER_NAME}%{REQUEST_URI} [L,R]

Download a few example debs from Silvenga Examples.


Use reprepro to add some example deb packages to our repository. This copies the debs to their proper locations under /var/repositories and rebuilds repository metadata files. Unfortunately, this does not update the directory structure to the ownership required by Apache, so we have to manually fix this.

reprepro --basedir /var/repo includedeb trusty example-helloworld_1.0.0.0_*
chown -R www-data:www-data /var/repo/

If you decide you don't want these files in your repository anymore use this command to remove them:

reprepro --basedir /var/repo remove trusty example-helloworld

Creating DEB packages

debian control directory

root name of a package control directory.
Convert an existing source package to your own package for modification.
aptitude -q -y install dh-make fakeroot pbuilder cdebootstrap

How To

  1. Put all source into a directory named package-version.
  2. Modify source directory as specified in
  3. When you are done cd above this directory: cd ..
  4. create package-version.tar.gz source tarball: `tar czf package-version.tar.gz package-version`.
  5. Create initial debian package environment: `cd package-version/;dh_make -e -f ../package-version.tar.gz`. This will create a new "debian" directory.
  6. Edit these files ./debian/control ./debian/copyright ./debian/license
  7. Run `dpkg-buildpackage -rfakeroot`

clean environment and workspace

This depends on `cdebootstrap`. This will take a while as it create an entire Debian chroot directory that looks like a fresh install.

sudo pbuilder create


Package is in a very bad inconsistent state - you should reinstall it before attempting a removal.

If an install or remove gets interrupted the package database might get left in an inconsistent state. This can cause errors like the one below:

dpkg: error processing xserver-xorg-video-s3virge (--remove):
Package is in a very bad inconsistent state - you should
reinstall it before attempting a removal.

The following may resolve the issue. This forces dpkg to remove the package despite the errors. This may break stuff!

dpkg --force-remove-reinstreq --remove xserver-xorg-video-s3virge