dpkg Command in Linux: Install and Manage Debian Packages

By 

•

Updated on

•

11 min read

dpkg package management cards for installing, querying, and removing deb packages

When you install software on Ubuntu or Debian with apt , the package manager quietly calls dpkg in the background to do the actual work. dpkg is the low-level tool that unpacks and installs .deb files, maintains the package database, and handles removal and purging. Knowing how to use it directly is useful when you have a local .deb file that is not in a repository, when you need to query what files a package installed, or when you want to find which package owns a specific file on your system.

Syntax

txt
dpkg [OPTIONS] COMMAND [ARGUMENTS]

Install, remove, purge, and configure operations require sudo because they modify system directories and the package database. Query commands such as dpkg -l, dpkg -L, dpkg -S, and dpkg -s usually run without root privileges.

There is nothing to install before you start. dpkg is marked Essential: yes with Priority: required in every Debian-based distribution, which means it ships with the base system and apt will not let you remove it. If a command below is not found, you are almost certainly on a distribution that uses a different package manager, such as rpm or pacman.

Install a Package

To install a local .deb file:

Terminal
sudo dpkg -i package.deb

dpkg unpacks the archive, runs the maintainer scripts, and registers the package in its database. If the package has unmet dependencies, the install stops before configuration finishes, which the next section covers.

Pass several files at once when they depend on each other, since dpkg unpacks them all before configuring any of them:

Terminal
sudo dpkg -i *.deb

To unpack a package without running its configuration step, use sudo dpkg --unpack myapp.deb and configure it later with sudo dpkg --configure myapp.

For most local .deb installs, apt install ./package.deb is easier because it can resolve dependencies in the same step. Use dpkg -i when you specifically need the lower-level package operation.

Resolve Dependency Errors

dpkg installs exactly the file you hand it. It does not look at your repositories and it does not download anything, so a package with unmet dependencies stops partway through:

output
dpkg: dependency problems prevent configuration of myapp:
 myapp depends on libfoo1 (>= 1.2.0); however:
  Package libfoo1 is not installed.

dpkg: error processing package myapp (--install):
 dependency problems - leaving unconfigured
Errors were encountered while processing:
 myapp

Read that carefully, because the package is not gone. The files were unpacked and the package is registered, but the configuration step never ran. Until you finish it, apt refuses to work on anything else.

The fix is to let apt supply what dpkg could not:

Terminal
sudo apt install -f

apt reads the unconfigured package, pulls the missing dependencies from your repositories, and then runs the configuration step that failed. sudo apt --fix-broken install is the same command written out.

You can avoid the whole sequence by installing the file through apt in the first place, which resolves dependencies before it unpacks anything:

Terminal
sudo apt install ./myapp.deb

The ./ prefix matters. Without it, apt treats myapp.deb as a package name to look up in the repositories. For a wider look at repairing package state, see the guide on APT and dpkg lock errors .

Remove a Package

To uninstall a package while keeping its configuration files:

Terminal
sudo dpkg -r package-name

To uninstall a package and delete its configuration files at the same time (a full purge):

Terminal
sudo dpkg -P package-name

Use -P when you want a clean removal with no leftover config, or when you plan to reinstall with a fresh configuration. For the apt equivalents of these commands, see the guide on uninstalling software packages on Ubuntu .

Reinstall a Package

Reinstalling is useful when a binary was deleted by accident, a configuration file was mangled, or a package looks corrupted. dpkg does not have a dedicated reinstall flag, because it does not need one. Pointing -i at a package that is already installed unpacks it again over the existing files:

Terminal
sudo dpkg -i myapp.deb

That works when you still have the .deb on disk. For a package that came from a repository, let apt fetch the same version and hand it to dpkg:

Terminal
sudo apt install --reinstall nginx

Neither command restores a deleted package-managed conffile by default. dpkg treats the missing file as a deliberate choice and leaves it missing. To restore /etc/nginx/nginx.conf, reinstall the nginx-common package that owns it and add the confmiss force option:

Terminal
sudo apt install --reinstall -o Dpkg::Options::="--force-confmiss" nginx-common

List Installed Packages

To list the packages recorded in dpkg’s status database with their versions and states:

Terminal
dpkg -l

The output is wide. Each package line starts with three status columns: desired action, current package status, and error state. The list can include removed packages with leftover configuration files and packages in incomplete states, not only fully installed packages. The normal installed state appears as ii, followed by the package name, version, architecture, and description:

output
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name           Version              Architecture Description
+++-==============-====================-============-=================================
ii  curl           8.5.0-2ubuntu10.13   amd64        command line tool for transferring data
ii  nginx          1.24.0-2ubuntu7.18   amd64        small, powerful, scalable web/proxy server

The first i means the package is selected for installation, and the second i means it is installed and configured. Filter by name to narrow the output:

Terminal
dpkg -l 'nginx*'
output
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Inst/Conf-files/Unpacked/halF-conf/Half-inst/trig-aWait/Trig-pend
|/ Err?=(none)/Reinst-required (Status,Err: uppercase=bad)
||/ Name           Version              Architecture Description
+++-==============-====================-============-=================================
ii  nginx          1.24.0-2ubuntu7.18   amd64        small, powerful, scalable web/proxy server
ii  nginx-common   1.24.0-2ubuntu7.18   all          small, powerful, scalable web/proxy server - common files

For more ways to filter, sort, and export that list, see the guide on listing installed packages on Debian .

List Files Installed by a Package

To see every file a package placed on your system:

Terminal
dpkg -L nginx
output
/.
/usr
/usr/sbin
/usr/sbin/nginx
/usr/share
/usr/share/doc
/usr/share/doc/nginx
/usr/share/doc/nginx/changelog.Debian.gz
/usr/share/doc/nginx/copyright
/usr/share/man
/usr/share/man/man8
/usr/share/man/man8/nginx.8.gz

Notice that the list contains the binary, the changelog, and the man page, but no configuration files. Debian packages are often split, and the nginx package ships only the server itself. The configuration lives in a separate package. The following filter shows several main configuration files from nginx-common:

Terminal
dpkg -L nginx-common | grep -E '^/etc/nginx/(fastcgi\.conf|mime\.types|nginx\.conf|sites-available/default)$'
output
/etc/nginx/fastcgi.conf
/etc/nginx/mime.types
/etc/nginx/nginx.conf
/etc/nginx/sites-available/default

This split is the reason dpkg -L is worth reaching for. When you expect a file and the package does not list it, a -common, -data, or -doc companion package usually owns it.

Find Which Package Owns a File

To identify which package installed a particular file:

Terminal
dpkg -S /usr/sbin/nginx
output
nginx: /usr/sbin/nginx

You can also search by pattern:

Terminal
dpkg -S '*/bin/curl'
output
curl: /usr/bin/curl

Show Package Details

To print the full metadata for an installed package including version, dependencies, and description:

Terminal
dpkg -s nginx
output
Package: nginx
Status: install ok installed
Priority: optional
Section: httpd
Installed-Size: 1323
Maintainer: Ubuntu Developers <ubuntu-devel-discuss@lists.ubuntu.com>
Architecture: amd64
Version: 1.24.0-2ubuntu7.18
Depends: libc6 (>= 2.34), libssl3t64 (>= 3.0.0), nginx-common (= 1.24.0-2ubuntu7.18)
...

The Status line is the field to read first. install ok installed means the package is fully installed and configured. A package you removed without purging shows deinstall ok config-files instead, which tells you the configuration files are still on disk. Installed-Size is reported in kilobytes.

Inspect a .deb File Without Installing

To read the metadata of a .deb file before installing it:

Terminal
dpkg --info package.deb
output
 new Debian package, version 2.0.
 size 1234567 bytes: control archive=2048 bytes.
     ...
 Package: myapp
 Version: 2.1.0
 Architecture: amd64
 ...

To list the files the package would install without actually installing it:

Terminal
dpkg --contents package.deb

Extract a Package Without Installing

To unpack the contents of a .deb file into a directory for inspection:

Terminal
dpkg -x package.deb /tmp/extracted

The directory structure mirrors where files would be installed on the real system.

Export and Restore Package Selections

To export dpkg’s package selection states (useful for replicating a system):

Terminal
dpkg --get-selections > installed-packages.txt

The file can contain install, hold, deinstall, and purge states. Before restoring it on another machine, copy APT’s package metadata into dpkg’s available-package database so that --set-selections recognizes packages that are not already installed:

Terminal
apt-cache dumpavail | sudo dpkg --merge-avail
sudo dpkg --set-selections < installed-packages.txt

Preview the resulting package changes before applying them:

Terminal
sudo apt-get --simulate dselect-upgrade

If the proposed changes are correct, apply them:

Terminal
sudo apt-get dselect-upgrade

Reconfigure an Installed Package

Some packages run interactive setup at install time. To run that setup again:

Terminal
sudo dpkg-reconfigure package-name

This is commonly used to reconfigure tzdata for timezone changes, keyboard-configuration, or locales.

Fix Broken Package State

To see which packages are in a bad state before you repair anything, run an audit:

Terminal
dpkg -C
output
The following packages are only half configured, probably due to problems
configuring them the first time. The configuration should be retried using
dpkg --configure <package> or the configure menu option in dselect:
 myapp   My application

Silence means nothing is broken.

If a system update or manual operation leaves packages in a half-installed or unconfigured state, run:

Terminal
sudo dpkg --configure -a

This processes any pending package configuration steps. Follow it with sudo apt install -f if dependency issues remain.

Troubleshooting

dpkg reports dependency problems
dpkg installs the package file you give it, but it does not download missing dependencies. Run sudo apt install -f to install the required packages and finish the pending configuration.

A package operation was interrupted
If an update or install stopped before configuration finished, run sudo dpkg --configure -a. This resumes pending package configuration scripts.

dpkg reports an error exit status 1
A maintainer script failed, not dpkg itself. The line above the error names the package and the script, usually post-installation script subprocess returned error exit status 1. Run sudo dpkg --configure -a to retry it, and read the output directly above the failure for the real cause, which is often a service that could not start or a missing dependency.

dpkg cannot get a lock
Another package operation holds the database lock. Wait for it to finish rather than deleting the lock file. See the guide on fixing APT and dpkg lock errors .

dpkg cannot find a package
Use the installed package name, not the .deb filename. Run dpkg -l 'pattern*' to find matching installed packages, then use that package name with commands such as dpkg -L, dpkg -s, or sudo dpkg -r.

Quick Reference

For a printable quick reference, see the dpkg cheatsheet .

CommandDescription
dpkg -i pkg.debInstall a local .deb file
dpkg -r packageRemove a package, keep config
dpkg -P packagePurge a package and its config
dpkg --unpack pkg.debUnpack without configuring
dpkg -lList package status records
dpkg -l 'pattern*'Filter package status records
dpkg -L packageList files installed by a package
dpkg -S /path/to/fileFind which package owns a file
dpkg -s packageShow package status and details
dpkg --info pkg.debInspect a .deb file
dpkg --contents pkg.debList files in a .deb
dpkg -x pkg.deb /dirExtract a .deb without installing
dpkg --get-selectionsExport package selection states
dpkg-reconfigure packageRe-run package configuration
dpkg -CAudit packages in a broken state
dpkg --configure -aFix incomplete installations

FAQ

What is the difference between dpkg and apt?
dpkg works on local .deb files and the local package database. It does not know about repositories and it does not resolve dependencies. apt is a front end that talks to repositories, works out the dependency tree, downloads what is needed, and then calls dpkg to do the actual installation.

Do I need to install dpkg first?
No. dpkg is an essential package in every Debian-based distribution, so it is already on the system and apt refuses to remove it. Run dpkg --version to confirm which release you have.

Does dpkg -i upgrade a package or install a second copy?
It replaces the installed version in place. Debian packaging allows only one version of a package per architecture, so dpkg unpacks the supplied version over the existing one and runs the package maintainer scripts. If the file contains an older version, dpkg prints a downgrade warning and proceeds by default, but it does not check whether the downgrade breaks another package’s dependencies. APT can also downgrade a package when you specify the older version explicitly, for example with sudo apt install package-name=version.

What does ii mean in the dpkg -l output?
The first letter is the state you asked for and the second is the state the package is actually in, so ii means you asked for it to be installed and it is installed and configured. rc is the other common pair: the package was removed but its configuration files are still on disk. An uppercase second letter such as iU or iF means the package is unpacked or half-configured and needs sudo dpkg --configure -a.

Conclusion

dpkg is the foundation of package management on Debian-based systems. For everyday installs and updates from repositories, apt is the better tool because it resolves dependencies automatically. Reach for dpkg directly when you need to install a .deb file from disk, audit what a package installed, or diagnose a broken package state.

Linuxize Weekly Newsletter

A quick weekly roundup of new tutorials, news, and tips.

About the authors

Dejan Panovski

Dejan Panovski

Dejan Panovski is the founder of Linuxize, an RHCSA-certified Linux system administrator and DevOps engineer based in Skopje, Macedonia. Author of 1000+ Linux tutorials with 20+ years of experience turning complex Linux tasks into clear, reliable guides.

View author page