How dnf Differs From apt
In one line
The decisive difference of dnf is that every install is recorded as a transaction and can be undone. apt has no feature that corresponds to this.
Why this exists
This is the first thing that surprises people who come over from Ubuntu.
dnf history # 지금까지의 모든 트랜잭션 목록
dnf history info 42 # 42번 트랜잭션에서 무엇이 바뀌었나
dnf history undo 42 # 42번을 되돌린다
dnf history rollback 41 # 41번 시점의 상태로 되돌린다
apt has a record called /var/log/apt/history.log, but no command to undo. This difference changes the way you operate. In the RHEL family, "install it to see, and undo it if it isn't right" becomes possible.
But the limits are clear. If the previous version of the package is not in the repository, the downgrade fails. And Red Hat states that it does not support downgrading system packages (selinux, selinux-policy, kernel, glibc, and gcc and others that depend on glibc). Rollback is not a cure-all.
How it works
Command correspondence table
| Task | apt | dnf |
|---|---|---|
| Refresh the index | apt-get update |
(automatic; dnf makecache if needed) |
| Install | apt-get install X |
dnf install X |
| Remove | apt-get remove X |
dnf remove X |
| Search | apt-cache search X |
dnf search X |
| Information | apt-cache show X |
dnf info X |
| File → package | dpkg -S /path |
dnf provides /path (including not installed) |
| List of installed files | dpkg -L X |
rpm -ql X |
| Upgrade | apt-get upgrade |
dnf upgrade |
| Pin a version | apt-mark hold |
dnf versionlock add |
| Rollback | None | dnf history undo |
dnf provides is especially powerful. apt's dpkg -S finds only files that are already installed, but dnf provides digs through the repository metadata and finds even packages that are not yet installed.
dnf provides '*/nginx.conf'
dnf provides 'libnl-3.so.200()(64bit)'
The second example is important. In RPM, the unit of a dependency is not a package name but a capability. The soname of a shared library, a file path, and even a symbol version can become a dependency target.
dnf repoquery --requires httpd
dnf repoquery --requires --resolve --recursive httpd | sort -u | wc -l
--requires is the capabilities it requires, --resolve substitutes the packages that provide those capabilities, and --recursive keeps descending recursively. It is a key tool when building an import list for an air-gapped network.
The repository file
# /etc/yum.repos.d/labhub-local.repo
[labhub-local]
name=LabHub local (snapshot 2026-08-20)
baseurl=file:///srv/repo/labhub
enabled=1
gpgcheck=1
gpgkey=file:///etc/pki/rpm-gpg/RPM-GPG-KEY-labhub
metadata_expire=-1
It is important to know the default of each key.
enableddefault Truegpgcheckdefault False — you have to turn it on explicitlyrepo_gpgcheck(metadata signature verification) default Falseprioritydefault 99metadata_expiredefault 48 hours. For a local repository on an air-gapped network, it is better to set it to-1(never expires)module_hotfixesdefault False
If you put the snapshot date in the repository display name, six months later one dnf repolist -v line tells you as of what point in time that server's content was installed.
Cache
The report that comes in most often on an air-gapped network is "I put a package in the repository but it doesn't show". The cause is one of two.
# 저장소 쪽: 메타데이터를 다시 만들었는가 (이걸 빼먹는 경우가 정말 많다)
createrepo_c --update /srv/repo/labhub
# 클라이언트 쪽: 캐시를 만료 표시 (가장 가벼움)
dnf clean expire-cache
# 그래도 안 되면
dnf clean metadata
# 최후의 수단
dnf clean all
dnf makecache
The definitions of each: expire-cache only marks the metadata as expired, metadata removes the metadata, packages removes cached packages, and all removes everything.
What it looks like in the field
When dnf update --security quietly ends with "nothing to do". That happens when the repository has no security advisory (updateinfo) metadata. createrepo_c can make only primary/filelists/other from rpm files, and the advisory information is not inside the rpm. The danger is that it quietly does nothing. You need the habit of checking with dnf updateinfo --summary.
What you will do in the next lab
You check the repository with dnf, install, trace back with provides, roll back with history, and pin a version.