Fedora DNF¶
Note
DNF 4 is superseded by dnf5 (Fedora’s default since Fedora 41) but stays maintained for the RHEL 8/9 family; mpm wraps dnf5 as a separate manager.
- ID
dnf- Home page
- Upstream stars
⭐ 1,380
- Last commit
2026-08-07
- Version requirement
>= 4, < 5
- Platforms
🅱️ BSD · 🐧 Linux · ⨂ Unix
- Operations
installed·outdated·orphans·search·install·upgrade·upgrade_all·remove·sync·cleanup·doctor- purl types
pkg:dnf·pkg:rpm- CLI names (lookup order)
dnf·dnf4- Every call
dnf --color=never --quiet <command>- Issues and PRs
- Source
Fedora’s RPM package manager.
mpm reads the inventory through repoquery rather than the human-facing
listing: --userinstalled for packages installed on request (dependencies
pulled in automatically are skipped), --upgrades for pending updates and
--unneeded for the orphans, each with a --queryformat that joins the
fields on a private ___MPM___ delimiter so summaries containing spaces stay
splittable. Every call is forced --color=never and --quiet for parseable
output.
Note
outdated is the one operation that runs two of those queries. --upgrades
answers for available packages, so it describes the upgrade candidate and
never the package installed, and repoquery offers no tag for the latter.
The installed set is therefore read separately and joined on name and
architecture. It is also the one place versions are reported as %{evr},
epoch and release included, since an upgrade may move only the release.
Note
remove runs autoremove, so removing a package also drops the
dependencies it leaves orphaned. search matches names only, with no
exact or extended mode.
The DNF5 and YUM subclasses reuse everything here, differing only in
the binary and forced arguments.
Documentation:
What mpm adds to dnf¶
Through mpm, dnf gains --exact and --extended search, to narrow to exact names or match descriptions.
Bigger still, mpm reaches across every manager at once: mpm installed and mpm outdated cover dnf alongside dnf5, yum, zypper and any other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your dnf commands, in mpm¶
You already know dnf: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Search for a package |
|
|
Install a package |
|
|
Upgrade one package |
|
|
Upgrade everything |
|
|
Remove a package |
|
|
List orphaned dependencies |
|
|
Clear caches |
|
|
Run health checks |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
Notes |
|---|---|---|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
exact and extended search backfilled by |
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
|
|
✓ |
Selecting and configuring dnf¶
Deselect dnf for a single run with --no-dnf, or persist the choice in your configuration:
[mpm]
dnf = false
The arguments and environment variables listed in the box atop this page are forced on every dnf call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Keep it enabled but tune how mpm drives it with a per-manager override:
[mpm.overrides.dnf]
timeout = 900
mpm config-template dnf prints every overridable attribute as a ready-to-paste block.
Recipes¶
A few jobs you would otherwise script around dnf, one mpm command each:
Snapshot and clone a machine:
mpm --dnf dump dnf.toml, thenmpm restore dnf.tomlon the next one.Export a compliance SBOM:
mpm --dnf sbom(CycloneDX by default,--spdxfor SPDX).Gate CI on health:
mpm --dnf doctorrelays Fedora DNF’s own diagnosis and exits non-zero on trouble.
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs dnf at the same time as dnf5, urpmi, yum or zypper: they all reach the RPM database, and a second writer waits on its lock for as long as the first one holds it, rather than failing. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of Fedora DNF’s release-age gating, from the cooldown support table:
Status: ❌ None (effort focused on dnf5)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Distro binary archives (
pkg:deb,pkg:rpm,pkg:alpm,pkg:apk)Retraction: Index revert: removal is an archive operation and the mirror is rebuilt without the package. Debian, for one, requires filing an
RM:bug againstftp.debian.org(developers-reference)Publish date: ❌ the version string is the distro maintainer’s build, carrying no upstream publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Version probe¶
The version is extracted from the output of dnf --version with the first of these regular expressions to match:
r"dnf5\s+version\s+(?P<version>\S+)"
r"(?P<version>\S+)"
Reference traces¶
Raw native outputs captured in the manager source: the reference mpm’s parsers were written against. If you know Fedora DNF well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ dnf --color=never --quiet repoquery --userinstalled --qf {format}
NetworkManager-bluetooth___MPM___1.56.1___MPM___Bluetooth device plugin for NetworkManager___MPM___aarch64
NetworkManager-team___MPM___1.56.1___MPM___Team device plugin for NetworkManager___MPM___aarch64
NetworkManager-wifi___MPM___1.56.1___MPM___Wifi plugin for NetworkManager___MPM___aarch64
$ dnf --color=never --quiet repoquery --installed --qf {format}
librepo___MPM___1.21.0-1.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.13-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.05.30-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --upgrades --qf {format}
librepo___MPM___1.21.0-2.fc44___MPM___Repodata downloading library___MPM___aarch64
openldap___MPM___2.6.14-1.fc44___MPM___LDAP support libraries___MPM___aarch64
wireless-regdb___MPM___2026.09.03-1.fc44___MPM___Regulatory database for 802.11 wireless networking___MPM___noarch
$ dnf --color=never --quiet repoquery --unneeded
bc-0:1.08.2-4.fc44.aarch64
dos2unix-0:7.5.6-1.fc44.aarch64
tree-0:2.2.1-4.fc44.aarch64
Feed any of these through mpm and the raw output becomes one uniform table, the same shape for every manager: filter it, project columns, or export it (mpm --dnf installed --output json, or csv, toml, yaml), each package carrying a purl and a version comparable across managers.
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0.dev0(unreleased)Fix version detection against
dnf5, whose banner was read as the versiondnf5, dropping every RPM front-end from the pool on Fedora 41 and later.Fix
searchondnf5, which returned no results at all, and keep whole package descriptions instead of their first word.Decline a
dnf5binary reached through thednfname, leaving it to thednf5manager instead of reporting the same RPM database twice.Fix
outdated, which reported the upgrade candidate’s own version as the installed one, and now names the epoch and release both sides differ by.Correct the
searchcommands shown on each manager’s page, which named fewer options thanmpmactually runs.Correct the inventory and outdated commands shown on each manager’s page, which named fewer options than
mpmactually runs.
7.4.0(2026-07-25)Plain
cleanupno longer removes orphaned packages: their native sweeps moved behindcleanup --orphans. This also stopsemerge’s cleanup from triggering its pre-depclean world upgrade unless--orphansis given.removeno longer cascades to orphaned dependencies by default: a plain removal keeps them. Use the newremove --orphansto restore the previous behavior.cleanup --cachenow escalates throughsudo:dnf clean allclears the root-owned package cache.
7.1.0(2026-07-07)upgradeandupgrade --allnow pass--assumeyes, as the other dnf operations already did, so upgrades no longer hang on an interactive confirmation prompt.
6.2.0(2026-03-25)Add
--quietoption to all invocations to reduce log verbosity.
5.19.0(2024-11-14)Implement
removeoperation.Use query template instead of regex parsing to retrieve package data.
4.12.0(2022-04-04)