Minor Release Upgrades
Minor release upgrades (e.g., EL 9.3 to 9.4) are the most common maintenance operation. This guide covers the complete dnf update workflow including pre-checks, execution, verification, and rollback.
Checking Available Updates
Section titled “Checking Available Updates”Before performing an upgrade, review what packages have updates available.
List All Available Updates
Section titled “List All Available Updates”dnf check-updateThis command returns exit code 100 when updates are available, 0 when there are none, and 1 on error.
View Security Updates Only
Section titled “View Security Updates Only”dnf updateinfo list securityView Update Details
Section titled “View Update Details”dnf updateinfo info --advisories=ALSA-2025:1234View Update Summary
Section titled “View Update Summary”dnf updateinfo summaryPerforming the Minor Release Upgrade
Section titled “Performing the Minor Release Upgrade”Standard Full Update
Section titled “Standard Full Update”dnf update -yInstall Security Updates Only
Section titled “Install Security Updates Only”dnf update --security -yExclude Specific Packages
Section titled “Exclude Specific Packages”dnf update -y --exclude=kernel* --exclude=php*Dry Run (No Actual Installation)
Section titled “Dry Run (No Actual Installation)”dnf update --assumenoKernel Update Considerations
Section titled “Kernel Update Considerations”Kernel updates install alongside existing kernels rather than replacing them.
Check the Currently Running Kernel
Section titled “Check the Currently Running Kernel”uname -rList Installed Kernels
Section titled “List Installed Kernels”rpm -qa kernel-core | sort -VUpdate Only the Kernel
Section titled “Update Only the Kernel”dnf update kernel -yA reboot is required to use the new kernel after updating.
Using needs-restarting
Section titled “Using needs-restarting”The needs-restarting tool determines which services or the system itself need a restart after updates.
Install needs-restarting
Section titled “Install needs-restarting”dnf install -y dnf-plugins-coreCheck If a System Reboot Is Required
Section titled “Check If a System Reboot Is Required”needs-restarting -rExit code 0 means no reboot required; 1 means a reboot is needed.
List Services That Need Restarting
Section titled “List Services That Need Restarting”needs-restarting -sBatch Restart Affected Services
Section titled “Batch Restart Affected Services”needs-restarting -s | xargs -I {} systemctl restart {}Rollback Strategy
Section titled “Rollback Strategy”View dnf History
Section titled “View dnf History”dnf history listView Details of a Specific Transaction
Section titled “View Details of a Specific Transaction”dnf history info <transaction-ID>Undo a Specific Transaction
Section titled “Undo a Specific Transaction”dnf history undo <transaction-ID> -yRollback to a Point in Time
Section titled “Rollback to a Point in Time”dnf history rollback <transaction-ID> -yKernel Rollback
Section titled “Kernel Rollback”If a new kernel causes problems, select the old kernel from the GRUB menu at boot time.
grubby --set-default /boot/vmlinuz-<old-version>Scheduling Maintenance Windows
Section titled “Scheduling Maintenance Windows”Recommended Maintenance Workflow
Section titled “Recommended Maintenance Workflow”- Notify — Inform relevant teams at least 48 hours in advance
- Backup — Create system snapshots or back up critical data
- Pre-test — Validate updates in a test environment
- Execute — Perform updates within the maintenance window
- Verify — Check service status and functionality
- Rollback readiness — Confirm that the rollback plan is viable
Create a Pre-Update Snapshot (LVM)
Section titled “Create a Pre-Update Snapshot (LVM)”lvcreate -s -n pre-update-snap -L 10G /dev/vg0/rootAutomated Update Script
Section titled “Automated Update Script”#!/bin/bashset -e
echo "=== Maintenance update started: $(date) ==="
# 1. Record current staterpm -qa --qf '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort > /root/pkg-before.txt
# 2. Perform updatednf update -y
# 3. Record post-update staterpm -qa --qf '%{NAME}-%{VERSION}-%{RELEASE}.%{ARCH}\n' | sort > /root/pkg-after.txt
# 4. Show changesecho "=== Package changes ==="diff /root/pkg-before.txt /root/pkg-after.txt || true
# 5. Check if reboot is neededif ! needs-restarting -r &>/dev/null; then echo "*** System reboot required ***"fi
echo "=== Maintenance update completed: $(date) ==="Set Up Automatic Security Updates (Optional)
Section titled “Set Up Automatic Security Updates (Optional)”dnf install -y dnf-automatic
# Configure to only apply security updatessed -i 's/^upgrade_type.*/upgrade_type = security/' /etc/dnf/automatic.confsed -i 's/^apply_updates.*/apply_updates = yes/' /etc/dnf/automatic.conf
systemctl enable --now dnf-automatic.timerVerify the Automatic Update Timer
Section titled “Verify the Automatic Update Timer”systemctl status dnf-automatic.timer