<!-- llms-explorer concept facts · https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/ · pack 2026-09-08 · ~7075 tokens -->

# Linux Package Management & Software Building — apt/dpkg, dnf/rpm, pacman, from-source & kernel build

> A Linux package is an archive of files plus metadata (name, version, dependencies, scripts,

Parent: [DevOps, Infrastructure & Observability](https://llms-explorer.com/tree/devops-infrastructure-observability/) · 16 facets · 84 facts · page: https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/

## Overview

- A Linux package is an archive of files plus metadata (name, version, dependencies, scripts, signature). A package manager resolves dependencies, fetches packages from repositories, verifies their signatures, and applies the change as a transaction recorded in a local database. There are two layers in every native stack: — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#overview)
  - Low-level tool - operates on a single local package file and the package DB. No dependency resolution, no network: dpkg (.deb), rpm (.rpm), pacman -U (.pkg.tar.zst). — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#overview)
  - High-level tool - resolves dependencies and talks to repositories: apt, dnf, pacman -S. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#overview)
- Use the high-level tool for normal work; drop to the low-level tool only to install a downloaded file or to inspect/repair the database. The three native ecosystems map cleanly onto each other, so once you know the model you mostly translate verbs. Above the native layer sit the universal formats (Flatpak, Snap, Nix) which bundle dependencies and are cross-distro. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#overview)

## Core Concepts (the shared branch)

- These ideas are identical across apt, dnf, and pacman - learn them once. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Package + metadata. Files + a manifest declaring Depends/Requires/depends, Conflicts, Provides (virtual packages, e.g. mail-transport-agent), version constraints, and pre/post install scripts. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Dependency resolution. Given a request, the solver computes a consistent set of installs, upgrades, and removals. Modern solvers are SAT/backtracking-based (APT's solver3, dnf's libsolv, pacman's internal resolver). When no consistent set exists you get a conflict the solver explains. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Repositories. Signed collections of packages + an index (Debian Release/Packages, RPM repodata/repomd.xml, Arch *.db). The client downloads the index, then packages. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Metadata cache vs installed DB. Two distinct things: the downloaded repo index (refreshed by apt update, dnf makecache, pacman -Sy) and the local installed-package DB (/var/lib/dpkg, the rpmdb in /var/lib/rpm or /usr/lib/sysimage/rpm, /var/lib/pacman/local). — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Transaction. An all-or-nothing batch. dnf records every transaction with full undo/rollback; dpkg/apt and pacman keep logs (/var/log/dpkg.log, /var/log/pacman.log) but weaker rollback. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Trust/signing. Repos sign their index; clients verify against a trusted keyring before trusting any package hash. This is the security boundary - never disable it casually. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)
  - Explicit vs dependency (orphan tracking). Managers mark whether you asked for a package or it came in as a dependency, so orphans can be auto-removed (apt autoremove, dnf autoremove, pacman -Qtdq). — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#core-concepts-the-shared-branch)

## apt / dpkg (Debian, Ubuntu, Mint, Pop!_OS)

- APT 3.0+ (Debian 13 "trixie", Ubuntu 25.04+) ships a colorized UI and solver3, a backtracking, SAT-solver-inspired resolver with unit propagation - faster, more predictable, better at preserving the order of alternatives and explaining conflicts than the classic solver. 3.1 added per-repo package excludes; 3.3.1 continued solver tuning. Signature verification moved to Sequoia-PGP (sqv) instead of GnuPG. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#apt-dpkg-debian-ubuntu-mint-pop_os)
- Repository config: /etc/apt/sources.list (legacy one-line) or .list / modern deb822 .sources files in /etc/apt/sources.list.d/. Each repo's signing key goes in /usr/share/keyrings/*.gpg (or .pgp) and is bound with Signed-By: (deb822) or [signed-by=…] (one-line). apt-key is deprecated - never add keys to the global keyring. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#apt-dpkg-debian-ubuntu-mint-pop_os)
- apt is the human-facing CLI; apt-get/apt-cache are the stable scripting interfaces. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#apt-dpkg-debian-ubuntu-mint-pop_os)

## dnf / rpm (Fedora, RHEL, Rocky, Alma, openSUSE uses zypper)

- dnf5 (default in Fedora 41+; the C++ rewrite) is faster and replaces dnf/microdnf. Note partial parity gaps: some users hit Unknown argument 'undo' and rollback edge cases on dnf5 - verify history subcommands on your version. dnf 5.4 improved transaction history precision. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#dnf-rpm-fedora-rhel-rocky-alma-opensuse-uses-zypper)
- RHEL caveat: dnf history undo/rollback is not supported for downgrading core packages (kernel, glibc, selinux-policy-*); downgrading to a prior minor version can leave the system inconsistent. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#dnf-rpm-fedora-rhel-rocky-alma-opensuse-uses-zypper)
- Verification: repos set gpgcheck=1 and gpgkey= in their .repo. Verify with rpm --checksig pkg.rpm; rpm -V audits an installed package against the DB (size, mode, digest, ownership drift). rpmdb may live at /usr/lib/sysimage/rpm on newer systems. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#dnf-rpm-fedora-rhel-rocky-alma-opensuse-uses-zypper)

## pacman (Arch, Manjaro, EndeavourOS)

- Flag grammar: operations are -S sync, -R remove, -Q query, -U upgrade(local); modifiers stack (y refresh DB, u upgrade, s search, i info, c clean). So -Syu = refresh + upgrade. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#pacman-arch-manjaro-endeavouros)
- AUR (Arch User Repository): user-submitted PKGBUILD recipes, not binaries. Workflow: git clone the AUR repo → review the PKGBUILD → makepkg -si (build + install with deps). AUR helpers (paru, yay) automate this but you own the security review. Popular PKGBUILDs graduate to the extra repo as binaries. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#pacman-arch-manjaro-endeavouros)
- Signing: pacman verifies via the archlinux-keyring (pacman-key). A stale keyring causes "invalid or corrupted package (PGP signature)" - fix with sudo pacman -Sy archlinux-keyring then retry the upgrade, or sudo pacman-key --refresh-keys. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#pacman-arch-manjaro-endeavouros)

## Universal formats (cross-distro, dependency-bundled)

- Flatpak - sandboxed desktop apps, community-governed via Flathub, shared runtimes to cut duplication, fine-grained portal permissions. flatpak install flathub <app-id>, flatpak update, flatpak run <app-id>. Best security/disk profile of the three. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#universal-formats-cross-distro-dependency-bundled)
- Snap - Canonical's compressed read-only SquashFS images mounted by snapd; auto-updating; centralized Snap Store. snap install <name>, snap refresh. Slower cold start (mount cost), single-vendor store. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#universal-formats-cross-distro-dependency-bundled)
- Nix - declarative, immutable, content-addressed /nix/store; reproducible and rollback-able; 122k+ packages (largest, most current repo as of 2025). Not a distro-native verb - it's a different model (see the immutable-atomic-linux reference for NixOS-as-OS). nix profile install, flakes. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#universal-formats-cross-distro-dependency-bundled)

## Building from source

- When no package exists, the version is too old, or you need custom build flags. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#building-from-source)

## The three build systems you'll meet

- Autotools (./configure && make && sudo make install): configure probes the host for toolchain/libraries and generates the Makefile; make compiles; make install copies into the prefix. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#the-three-build-systems-youll-meet)
- CMake: cmake -S . -B build -DCMAKE_INSTALL_PREFIX=/usr/local && cmake --build build -j$(nproc) && sudo cmake --install build. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#the-three-build-systems-youll-meet)
- Meson + Ninja: meson setup build --prefix=/usr/local && meson compile -C build && sudo meson install -C build. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#the-three-build-systems-youll-meet)

## Source-build hygiene (the patterns that keep it maintainable)

- Get the deps first. sudo apt build-dep <pkg> / sudo dnf builddep <spec> / pull makedepends via the PKGBUILD. Read the project README/INSTALL - honor its recommendation over generic advice. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
- Verify the tarball. Download from a trusted origin; check the GPG signature or checksum before extracting. Supply-chain risk lives here. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
- Never build or run make as root. Build as your user; only make install (the copy step) needs privilege. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
- Isolate the prefix for easy removal. Default /usr/local collides nothing with the package manager (which owns /usr), but an explicit versioned prefix like /opt/foo-1.2.3 or --prefix=$HOME/.local is cleaner and trivially removable. There is usually no make uninstall, so isolation matters. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
- Make it removable / trackable. Prefer one of: — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
  - checkinstall - wraps make install to produce a real .deb/.rpm/.tgz so the package manager tracks and can cleanly remove it. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
  - GNU Stow - make install into /usr/local/stow/foo-1.2.3, then stow symlinks it into /usr/local; stow -D removes it atomically. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
  - Building a proper native package (.deb via debuild, .rpm via rpmbuild/.spec, .pkg.tar.zst via PKGBUILD) for anything you'll ship. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)
- Run ldconfig after installing shared libraries to a new path; add the dir to /etc/ld.so.conf.d/ if outside the default search path. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#source-build-hygiene-the-patterns-that-keep-it-maintainable)

## Kernel build basics

- Compiling a custom kernel from kernel.org source (or your distro's source) - for new hardware, debugging, custom config, or learning. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Get source + deps. Extract the tarball; install build deps (build-essential/gcc make, bison flex libssl-dev libelf-dev bc, ncurses for menuconfig). — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Configure - produce a .config: — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
    - make menuconfig - ncurses menu editor (also nconfig, xconfig, gconfig). — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
    - make localmodconfig - the practical shortcut: reads lsmod and disables every module not currently loaded, producing a lean, fast-building config tailored to this machine. (Pass a captured lsmod via LSMOD=file to target another machine.) — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
    - make olddefconfig - carry an existing .config forward, defaulting new symbols. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
    - Common base: cp /boot/config-$(uname -r) .config then make olddefconfig. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Build. make -j$(nproc) - uses all cores; still typically 1–2+ hours for a full config, minutes for a localmodconfig-trimmed one. Produces arch/x86/boot/bzImage (the compressed kernel image) and the built modules. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Install modules. sudo make modules_install → copies into /lib/modules/<version>/. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Install kernel. sudo make install (distro-friendly: copies bzImage to /boot, generates the initramfs, and updates the bootloader on most distros) - or manually copy bzImage to /boot/vmlinuz-<ver>, build the initramfs (dracut/update-initramfs), and regenerate GRUB (grub-mkconfig -o /boot/grub/grub.cfg or grub2-mkconfig). See linux-boot-init for the initramfs + bootloader chain and linux-kernel-architecture for module/ABI internals. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)
  - Reboot and pick the entry; verify with uname -r. Keep the old kernel as a fallback boot entry - never delete the working kernel until the new one boots clean. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#kernel-build-basics)

## Anti-patterns

- pacman -Sy <pkg> (partial upgrade). The single most dangerous Arch mistake. It refreshes the DB and installs/upgrades one package (pulling new library deps) without upgrading the rest of the system. Because Arch is rolling and keeps no old library versions, this breaks other packages linked against the now-removed library. Always pacman -Syu - and refusing the upgrade prompt after -Sy is just as bad. Never -Sy then -S. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- apt-key add / dropping keys in the global keyring. Deprecated and insecure (one bad repo can sign anything). Use a per-repo keyring + Signed-By:. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- sudo make install of an untracked source build into /usr or /. Collides with the package manager and is near-impossible to remove. Use /usr/local, an isolated prefix, checkinstall, or stow. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- Mixing repos / "Frankendebian". Pinning packages from a newer release (e.g. Debian testing/unstable on stable, or random third-party repos) without proper apt pinning causes dependency hell. Use apt-pinning deliberately or not at all. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- Disabling GPG checks (--allow-unauthenticated, gpgcheck=0, --nosignature) to "fix" a key error. Fix the key, don't disable the trust boundary. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- rm-ing files instead of removing the package. Leaves the DB believing the package is present. Always go through the manager. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- dnf history rollback on RHEL core packages (kernel/glibc/selinux) - unsupported; can brick the system. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)
- Running a full menuconfig from scratch. Thousands of symbols; you'll misconfigure something. Start from the running config or localmodconfig. — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#anti-patterns)

## References

- APT 3.0 / solver3 - LWN, "What's new in APT 3.0": https://lwn.net/Articles/1017315/ — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Ubuntu Community Hub, "Evaluating the new APT solver in 25.04": https://discourse.ubuntu.com/t/evaluating-the-new-apt-solver-in-25-04/55618 — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Debian Wiki - SecureApt & UseThirdParty (repo signing, deb822, Signed-By): https://wiki.debian.org/SecureApt , https://wiki.debian.org/DebianRepository/UseThirdParty — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Red Hat docs, "Handling package management history" (dnf history undo/rollback): https://docs.redhat.com/en/documentation/red_hat_enterprise_linux/9/html/managing_software_with_the_dnf_tool/assembly_handling-package-management-history_managing-software-with-the-dnf-tool — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Baeldung, "DNF: history rollback vs. undo": https://www.baeldung.com/linux/dnf-dnf-history-rollback-vs-undo — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- ArchWiki - pacman, PKGBUILD, Arch User Repository, System maintenance: https://wiki.archlinux.org/title/Pacman , https://wiki.archlinux.org/title/PKGBUILD , https://wiki.archlinux.org/title/Arch_User_Repository , https://wiki.archlinux.org/title/System_maintenance — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Arch Forums, "Why is pacman -Sy bad?" (partial upgrade hazard): https://bbs.archlinux.org/viewtopic.php?id=241092 — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- unixwiz, "Good practices for building packages from source": http://www.unixwiz.net/techtips/building-source.html — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- kernel.org admin-guide README (kernel build): https://www.kernel.org/doc/Documentation/admin-guide/README.rst — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- ArchWiki - Kernel/Traditional compilation (menuconfig, localmodconfig, modules_install): https://wiki.archlinux.org/title/Kernel/Traditional_compilation — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- Linux Magazine, "Universal Package Formats" (Flatpak/Snap/Nix): https://www.linux-magazine.com/Issues/2025/298/Universal-Package-Formats — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)
- NixOS package count / model (2025): https://nixos.org — [source](https://llms-explorer.com/sources/mdb-context-hub/linux-package-management/#references)

## Where this helps

- Diagnosing a broken package database or invalid-signature error by knowing whether the problem is the repo index cache, the trust keyring, or the installed-package database itself. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Deciding when to build from source instead of using a package — a version too new or too old for the distro repo, or a custom build flag the packaged binary does not expose. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Compiling a custom kernel for new hardware, a debugging config, or a stripped-down localmodconfig build tailored to one machine. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Choosing the right cross-distro format (Flatpak, Snap, Nix) when an app needs to run identically across distros or needs stronger sandboxing than the native package gives it. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Project ideas

- Build and package a small utility three ways — a native .deb via debuild, a .rpm via rpmbuild, and a .pkg.tar.zst via PKGBUILD — to see how the same source maps onto each ecosystem's metadata model. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Compile a custom kernel from kernel.org source using make localmodconfig, boot into it, and confirm hardware/module parity with uname -r and lsmod against the stock kernel. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Write a PKGBUILD for a small open-source tool not yet in the AUR, build it with makepkg -si, and submit it for AUR review. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Set up an isolated source-build workflow using GNU Stow or checkinstall so every from-source install into /usr/local stays trackable and removable. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Common mistakes

- Running pacman -Sy <pkg> (a partial upgrade) instead of a full pacman -Syu — because Arch is rolling and keeps no old library versions, this can leave other packages linked against a library version that no longer exists. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- sudo make install-ing an untracked source build straight into /usr or / instead of an isolated prefix — it collides with the package manager's ownership of /usr and is nearly impossible to cleanly remove afterward. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Disabling GPG verification (--allow-unauthenticated, gpgcheck=0, --nosignature) to work around a key error instead of fixing the key — this removes the actual security boundary rather than repairing it. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- rm-ing files that belong to an installed package instead of removing it through the package manager, which leaves the local database believing the package is still present. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Known issues

- dnf5's history subcommands still have partial parity gaps with classic dnf (some users hit an "Unknown argument undo" error), so rollback behavior should be verified on the actual installed version rather than assumed. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- dnf history undo/rollback is explicitly unsupported for RHEL's core packages (kernel, glibc, selinux-policy-*) — attempting it on those can leave the system in an inconsistent state. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- Mixing repositories across release channels (Debian testing on stable, third-party repos without pinning), sometimes called Frankendebian, produces dependency conflicts that apt pinning is specifically designed to prevent but that most people skip. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*
- A full kernel make menuconfig from a blank slate covers thousands of symbols and is easy to misconfigure; starting from the running kernel's config (cp /boot/config-$(uname -r) .config && make olddefconfig) is the practical, lower-risk baseline. — [source](https://llms-explorer.com/tree/linux-package-management-software-building-apt-dpkg-dnf-rpm-pacman-from-source-kernel-build/) *(AI-suggested, synthesized from this pack's existing facts — not extracted from a source document.)*

## Context files

- [Linux Package Management & Software Building — apt/dpkg, dnf/rpm, pacman, from-source & kernel build](https://llms-explorer.com/downloads/sources/mdb-context-hub/linux-package-management.md)
