这个系列是什么「Linux 实战」按线上真正会撞上的事情排:认清系统和装软件(本篇)、端口不通、服务起不来、磁盘满了、网络和 SSH、日志与性能……每一篇都做两件事:①所有命令在真机上跑过、贴原始输出;②同一件事在三个系统上各跑一遍—— CentOS 7 还大量在线上跑着,新机器多半是 Rocky 9 或 Ubuntu,而这三个系统在装软件、换源这件事上几乎处处不一样,照着一个系统的教程去弄另一个,常常是命令敲对了却不生效。实测环境机器版本内核说明CentOS 7CentOS Linux release 7.9.2009 (Core)3.10.0-1160.71.1.el7VMware 虚拟机,firewalld 开、SELinux EnforcingRocky 9Rocky Linux release 9.8 (Blue Onyx)5.14.0-687.49.1.el9_8KVM 虚拟机,最小化镜像后补装了 firewalld、SELinux 切到 EnforcingUbuntu 24.04Ubuntu 24.04.5 LTS6.8.0-139-genericKVM 虚拟机,最小化镜像后补装了 ufw(未启用)、AppArmor⚠️ 后两台是最小化镜像,下文凡是写「这台机器上没有 X」,只代表这台机器,你那台标准安装的服务器可能装了。1. 先认清是什么系统 ✅装软件、改源、开端口的命令都跟系统走,所以第一步永远是确认自己在哪台什么系统上。1.1/etc/os-release:三个系统都有,最该先看# cat /etc/os-release (CentOS 7,截取前 6 行) NAMECentOS Linux VERSION7 (Core) IDcentos ID_LIKErhel fedora VERSION_ID7 PRETTY_NAMECentOS Linux 7 (Core)# cat /etc/os-release (Rocky 9,截取) NAMERocky Linux VERSION9.8 (Blue Onyx) IDrocky ID_LIKErhel centos fedora VERSION_ID9.8 PLATFORM_IDplatform:el9 PRETTY_NAMERocky Linux 9.8 (Blue Onyx) SUPPORT_END2032-05-31# cat /etc/os-release (Ubuntu 24.04,截取) PRETTY_NAMEUbuntu 24.04.5 LTS NAMEUbuntu VERSION_ID24.04 VERSION24.04.5 LTS (Noble Numbat) VERSION_CODENAMEnoble IDubuntu ID_LIKEdebian最有用的是ID_LIKE:它说的是「这个系统像谁」。含rhel→ 按 yum/dnf 那一套走;含debian→ 按 apt 那一套走。写脚本时只取一个值:# . /etc/os-release echo $ID rocky # grep ^ID /etc/os-release | cut -d -f2 | tr -d rocky⚠️. /etc/os-release会把文件里的变量灌进当前 shell。实测(三台结果一致,这里贴 CentOS 7):# VERSIONmine; . /etc/os-release; echo VERSION 被覆盖成: $VERSION VERSION 被覆盖成: 7 (Core) # VERSIONmine; ( . /etc/os-release; echo 子shell里: $ID ); echo 外面 VERSION 仍是: $VERSION 子shell里: centos 外面 VERSION 仍是: mine脚本里自己有VERSION、NAME这类变量的,要么放进( )子 shell,要么用grep那种写法。1.2 其他几个文件,各有各的坑命令CentOS 7Rocky 9Ubuntu 24.04cat /etc/redhat-releaseCentOS Linux release 7.9.2009 (Core)Rocky Linux release 9.8 (Blue Onyx)No such file or directorycat /etc/debian_versionNo such file or directoryNo such file or directorytrixie/sidcat /etc/issue\S/Kernel \r on an \m\S/Kernel \r on \mUbuntu 24.04.5 LTS \n \lcommand -v lsb_release没有没有/usr/bin/lsb_release三个要注意的地方:Ubuntu 的/etc/debian_version给的是trixie/sid,不是 24.04。判 Ubuntu 版本别看它。RHEL 系的/etc/issue里是\S、\r这样的转义符,登录提示时才被替换,cat出来看不到版本号。lsb_release两台 RHEL 系机器上都没有,Ubuntu 上有:# lsb_release -a (Ubuntu 24.04) Distributor ID: Ubuntu Description: Ubuntu 24.04.5 LTS Release: 24.04 Codename: noble # lsb_release -a (Rocky 9) bash: line 1: lsb_release: command not found所以脚本里判系统用/etc/os-release,别依赖lsb_release。另外,不知道有哪些 release 文件时ls /etc/*release /etc/*version能列全,但在 RHEL 系上它的退出码是 2(/etc/*version一个都匹配不到),写进脚本别拿退出码判断成败:# ls /etc/*release /etc/*version 2/dev/null (Rocky 9,退出码 2) /etc/os-release /etc/redhat-release /etc/rocky-release /etc/system-release1.3 内核、架构、是不是虚拟机# uname -r; uname -m 3.10.0-1160.71.1.el7.x86_64 ← CentOS 7 5.14.0-687.49.1.el9_8.x86_64 ← Rocky 9 6.8.0-139-generic ← Ubuntu 24.04 x86_64内核里的el7/el9能反推 RHEL 大版本,但只能当线索:最终以/etc/os-release为准。# systemd-detect-virt vmware ← CentOS 7(VMware 虚拟机) kvm ← Rocky 9 / Ubuntu 24.04(KVM 虚拟机) # systemd-detect-virt -c; echo 退出码$? none 退出码1⚠️-c只判容器:不是容器时输出none、退出码是 1。脚本里if systemd-detect-virt -c这样写,在物理机和虚拟机上都会走 else 分支,这是对的,但别把退出码 1 当成「命令出错」。dmidecode能看到虚拟化厂商:CentOS 7 是VMware, Inc./VMware Virtual Platform,Rocky 9 是QEMU/Standard PC (Q35 ICH9, 2009)。这台 Ubuntu 最小化镜像上没有dmidecode命令(command not found)。1.4 一段脚本拿全景(三台都实跑过)echo 系统 (./etc/os-release2/dev/nullecho$PRETTY_NAME(ID$IDLIKE$ID_LIKE))\||cat/etc/redhat-release2/dev/null\||cat/etc/issueecho 内核/架构 uname-srmecho 虚拟化 systemd-detect-virt2/dev/null||echo(无 systemd-detect-virt)echo 包管理器 forpindnf yumaptzypperapk pacman;docommand-v$p/dev/null21echo有:$pdoneecho 防火墙 forpinfirewall-cmd ufw nft iptables;docommand-v$p/dev/null21echo有:$pdoneecho init ps-p1-ocomm三台的输出: 系统 CentOS Linux 7 (Core) (IDcentos LIKErhel fedora) 内核/架构 Linux 3.10.0-1160.71.1.el7.x86_64 x86_64 虚拟化 vmware 包管理器 有:yum 防火墙 有:firewall-cmd 有:iptables init systemd 系统 Rocky Linux 9.8 (Blue Onyx) (IDrocky LIKErhel centos fedora) 内核/架构 Linux 5.14.0-687.49.1.el9_8.x86_64 x86_64 虚拟化 kvm 包管理器 有:dnf 有:yum 防火墙 有:firewall-cmd 有:nft 有:iptables init systemd 系统 Ubuntu 24.04.5 LTS (IDubuntu LIKEdebian) 内核/架构 Linux 6.8.0-139-generic x86_64 虚拟化 kvm 包管理器 有:apt 防火墙 有:ufw 有:nft 有:iptables init systemd2. 装软件:yum、dnf、apt 的差别 ✅2.1 Rocky 9 上的yum其实就是dnf# ls -l $(command -v yum); yum --version | head -1 (Rocky 9) lrwxrwxrwx. 1 root root 5 May 19 22:37 /usr/bin/yum - dnf-3 4.14.0 # ls -l $(command -v yum); yum --version | head -1 (CentOS 7) -rwxr-xr-x. 1 root root 801 Oct 2 2020 /usr/bin/yum 3.4.3所以 Rocky 9 上敲yum和dnf结果一样;CentOS 7 上只有 yum,没有dnf,也没有模块流:# yum module list (CentOS 7) No such command: module. Please use /usr/bin/yum --help2.2 装、卸、撤销(Rocky 9 实测)# dnf install -y nginx (截取末尾) nginx-2:1.20.1-28.el9_8.6.rocky.0.1.x86_64 nginx-core-2:1.20.1-28.el9_8.6.rocky.0.1.x86_64 nginx-filesystem-2:1.20.1-28.el9_8.6.rocky.0.1.noarch rocky-logos-httpd-90.17-1.el9.noarch Complete!dnf history undo是后悔药:每次装卸都有一条带编号的记录,可以按编号撤销。# dnf history | head -5 ID | Command line | Date and time | Action(s) | Altered ------------------------------------------------------------------------------- 7 | remove -y nginx | 2026-09-21 14:49 | Removed | 4 6 | install -y nginx | 2026-09-21 14:49 | Install | 4 5 | -y -q install firewalld | 2026-09-21 14:29 | Install | 21 EE # dnf history undo -y 7 (撤销第 7 次的卸载 装回来) ... Complete! # rpm -q nginx nginx-1.20.1-28.el9_8.6.rocky.0.1.x86_64CentOS 7 的yum history undo同样可用(下文 §3 测完后就是用它把装的包逐次撤掉的)。升级前记一下history的当前编号,出事时有救。2.3rpm -ivh/dpkg -i不解依赖手上只有一个包文件时,别直接rpm -ivh:# rpm -ivh nginx-1*.rpm nginx-core-*.rpm; echo rpm 退出码$? (Rocky 9) error: Failed dependencies: nginx-filesystem 2:1.20.1-28.el9_8.6.rocky.0.1 is needed by nginx-2:1.20.1-28.el9_8.6.rocky.0.1.x86_64 system-logos-httpd is needed by nginx-2:1.20.1-28.el9_8.6.rocky.0.1.x86_64 nginx-filesystem is needed by nginx-core-2:1.20.1-28.el9_8.6.rocky.0.1.x86_64 rpm 退出码2换成dnf install ./文件名,缺的依赖会从仓库自动补:# dnf install -y ./nginx-1*.rpm ./nginx-core-*.rpm (截取) Installing: Installing dependencies: nginx-filesystem noarch 2:1.20.1-28.el9_8.6.rocky.0.1 appstream 11 kCentOS 7 同理,rpm -ivh httpd报缺httpd-tools、libapr-1.so.0等 4 项(退出码 1),yum install -y ./httpd-*.rpm自动补上apr、apr-util、httpd-tools、mailcap。Ubuntu 上的对应情况:# dpkg -i nginx_*.deb; echo dpkg 退出码$? (Ubuntu 24.04) Selecting previously unselected package nginx. ... dpkg: dependency problems prevent configuration of nginx: nginx depends on nginx-common ( 1.24.0-2ubuntu7.18); however: Package nginx-common is not installed. dpkg: error processing package nginx (--install): dependency problems - leaving unconfigured Errors were encountered while processing: nginx dpkg 退出码1 # dpkg -l | grep -E ^.. nginx iU nginx 1.24.0-2ubuntu7.18 amd64 small, powerful, scalable web/proxy server⚠️iU 已解包、未配置—— 包「装了一半」挂在那里。补救:# apt --fix-broken install -y (截取) Correcting dependencies... Done The following additional packages will be installed: nginx-common ... # dpkg -l | grep -E ^.. nginx ii nginx 1.24.0-2ubuntu7.18 amd64 small, powerful, scalable web/proxy server ii nginx-common 1.24.0-2ubuntu7.18 all small, powerful, scalable web/proxy server - common files2.4 apt remove nginx之后,/etc/nginx还在# apt remove -y nginx ... Removing nginx (1.24.0-2ubuntu7.18) ... # dpkg -l | grep -E ^.. nginx ii nginx-common 1.24.0-2ubuntu7.18 all small, powerful, scalable web/proxy server - common files # ls /etc/nginx | head -5 conf.d fastcgi.conf fastcgi_params koi-utf koi-win配置文件属于nginx-common,不属于nginx。想把配置改坏了「彻底重来」,要连它一起 purge:# apt purge -y nginx nginx-common ... # ls /etc/nginx ls: cannot access /etc/nginx: No such file or directory很多教程写「apt purge nginx连配置一起删」—— 只 purgenginx这一个包是删不掉/etc/nginx的。2.5 「命令找不到,该装哪个包」以semanage(SELinux 常用命令)为例:# dnf provides */semanage (Rocky 9,截取) policycoreutils-python-utils-3.6-5.el9.noarch : SELinux policy core python utilities Repo : appstream Matched from: Filename : /usr/sbin/semanage # yum provides */semanage (CentOS 7,截取) policycoreutils-python-2.5-34.el7.x86_64 : SELinux policy core python utilities Repo : base Matched from: Filename : /usr/sbin/semanage注意两个版本的包名不一样:CentOS 7 是policycoreutils-python,Rocky 9 是policycoreutils-python-utils。照抄 7 的教程在 9 上装会找不到包。Ubuntu 上「命令找不到时提示你装哪个包」这个功能依赖command-not-found包。这台最小化镜像一开始没有,敲semanage只有一句command not found;装上之后:# apt install -y command-not-found apt update # semanage Command semanage not found, but can be installed with: apt install policycoreutils-python-utils没这个提示时用apt-file(要先装、先apt-file update):# apt-file search /usr/sbin/semanage policycoreutils-python-utils: /usr/sbin/semanage2.6 两个写脚本时会咬人的细节①check-update有更新时退出码是 100,不是 1:# yum check-update /dev/null 21; echo yum check-update 退出码$? (CentOS 7) yum check-update 退出码100 # dnf check-update /dev/null 21; echo dnf check-update 退出码$? (Rocky 9,当时无更新) dnf check-update 退出码0脚本里set -e或if yum check-update会把「有可用更新」当成失败。② 脚本里用apt-get,别用apt:apt的输出一被管道接走,就会先打一行警告:# apt show nginx 21 | head -3 WARNING: apt does not have a stable CLI interface. Use with caution in scripts.2.7 锁住某个包不让升级(Ubuntu)# apt-mark hold nginx; apt-mark showhold nginx set on hold. nginx # apt-mark unhold nginx Canceled hold on nginx.排查「这个包为什么一直没升级」时,先看一眼apt-mark showhold。3. CentOS 7 源失效:照教程切 vault,实测 403 ✅这是本篇的重点。下面的测试把 CentOS 7 的仓库配置换回了centos-release包里自带的原版(从 rpm 包里解出来的,不是手写的),复现一台「从没改过源」的 CentOS 7 现在会遇到什么。3.1 症状:Cannot find a valid baseurl原版配置用的是 mirrorlist:[base] nameCentOS-$releasever - Base mirrorlisthttp://mirrorlist.centos.org/?release$releaseverarch$basearchrepoosinfra$infra gpgcheck1 gpgkeyfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7# yum makecache (截取末尾) 5. Configure the failing repository to be skipped, if it is unavailable. Note that yum will try to contact the repo. when it runs most commands, so will have to try and fail each time (and thus. yum will be be much slower). If it is a very temporary problem though, this is often a nice compromise: yum-config-manager --save --setoptrepoid.skip_if_unavailabletrue Cannot find a valid baseurl for repo: base/7/x86_64yum install任何包都是同一句。原因不是网络,是源下线了:# getent hosts mirrorlist.centos.org || echo mirrorlist.centos.org 解析不到 mirrorlist.centos.org 解析不到 # curl -sS -m 10 -o /dev/null -w %{http_code}\n http://mirror.centos.org/centos/7/os/x86_64/repodata/repomd.xml 4043.2 教程里的第一选择 vault.centos.org:实测 403大多数教程让你把baseurl指向官方归档vault.centos.org。在我这条国内宽带上直连,它返回 403:# curl -sS -m 15 -I https://vault.centos.org/7.9.2009/os/x86_64/repodata/repomd.xml (截取) HTTP/1.1 403 Forbidden Server: CloudFront X-Cache: Error from cloudfront加浏览器 User-Agent 也还是 403。yum 里的表现:failure: repodata/repomd.xml from base: [Errno 256] No more mirrors to try. https://vault.centos.org/7.9.2009/os/x86_64/repodata/repomd.xml: [Errno 14] HTTPS Error 403 - Forbidden⚠️ 这是 2026-09-21 在一条国内宽带上的读数;同一时刻从一个走代理出口的网络访问是 200。所以它跟你的网络出口有关,不代表 vault 关了。切 vault 之前先curl -I看一眼能不能拿到 200,拿不到就直接用下面的镜像。3.3 实测能用的:阿里云 centos-vault先确认路径能拿到 200(这一步别省,路径写错的表现和源失效一模一样):200 0.377s https://mirrors.aliyun.com/centos-vault/7.9.2009/os/x86_64/repodata/repomd.xml然后:mkdir-p/etc/yum.repos.d/bakmv/etc/yum.repos.d/CentOS-Base.repo /etc/yum.repos.d/bak/新建/etc/yum.repos.d/CentOS-Vault.repo:[base] nameCentOS-7 - Base baseurlhttps://mirrors.aliyun.com/centos-vault/7.9.2009/os/$basearch/ gpgcheck1 enabled1 gpgkeyfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 [updates] nameCentOS-7 - Updates baseurlhttps://mirrors.aliyun.com/centos-vault/7.9.2009/updates/$basearch/ gpgcheck1 enabled1 gpgkeyfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7 [extras] nameCentOS-7 - Extras baseurlhttps://mirrors.aliyun.com/centos-vault/7.9.2009/extras/$basearch/ gpgcheck1 enabled1 gpgkeyfile:///etc/pki/rpm-gpg/RPM-GPG-KEY-CentOS-7# yum clean all; time yum makecache (截取末尾) Loaded plugins: fastestmirror Determining fastest mirrors Metadata Cache Created real 3m7.691s 两个要点:baseurl写死7.9.2009,别用$releasever:它展开成7,而归档站只有按小版本分的目录(7.0.1406/…7.9.2009/),没有7/(下面两行是在另一台机器上用 curl 查的):404 https://mirrors.aliyun.com/centos-vault/7/os/x86_64/repodata/repomd.xml 200 https://mirrors.aliyun.com/centos-vault/7.9.2009/os/x86_64/repodata/repomd.xml换完先yum clean all再yum makecache,让 yum 丢掉旧的元数据。⚠️ 切到归档只是让 yum 重新能用,归档里不会再有新的安全更新。长期看还是要迁到仍在维护的系统。3.4 如果 mirrorlist 那一行没删掉,会怎样很多教程说「mirrorlist不删,yum 还会去问已经下线的 mirrorlist,所以一定要删」。实测:在baseurl已经指向阿里云的前提下,把 mirrorlist 行加回去:# yum --disablerepo* --enablerepobase makecache (截取末尾) Loaded plugins: fastestmirror Determining fastest mirrors Could not retrieve mirrorlist http://mirrorlist.centos.org/?release7archx86_64repoosinfrastock error was 14: curl#6 - Could not resolve host: mirrorlist.centos.org; Unknown error Metadata Cache Created退出码是 0 ——yum 先问 mirrorlist、报一行错,然后回落到baseurl,最后是成功的。所以留着它不会让换源失败,但每次都会多一行报错、多一次解析等待。还是删掉,只是别把「换源没成功」归咎到它身上。3.5 EPEL 7 也下线了:metalink 卡满 3 分钟CentOS 7 上很多常用软件(比如 nginx)不在 base 源里,要先装 EPEL。epel-release本身能从 extras 装上,但它写进去的是 metalink:# grep -E ^(metalink|#baseurl) /etc/yum.repos.d/epel.repo | head -2 #baseurlhttp://download.fedoraproject.org/pub/epel/7/$basearch metalinkhttps://mirrors.fedoraproject.org/metalink?repoepel-7arch$basearch之后任何 yum 命令都会卡住。我给它设了 180 秒上限:# timeout 180 yum makecache Loaded plugins: fastestmirror Loading mirror speeds from cached hostfile * epel: d2lzkl7pfhq30w.cloudfront.net 退出码124 用时180s退出码 124 被timeout杀掉,除了开头三行,180 秒里没有任何输出。EPEL 7 的正式地址已经 404,归档还在:200 https://archives.fedoraproject.org/pub/archive/epel/7/x86_64/repodata/repomd.xml 200 https://mirrors.aliyun.com/epel-archive/7/x86_64/repodata/repomd.xml 404 https://dl.fedoraproject.org/pub/epel/7/x86_64/repodata/repomd.xml把/etc/yum.repos.d/epel.repo的[epel]段改成:[epel] nameExtra Packages for Enterprise Linux 7 - $basearch baseurlhttps://mirrors.aliyun.com/epel-archive/7/$basearch #metalinkhttps://mirrors.fedoraproject.org/metalink?repoepel-7arch$basearch failovermethodpriority enabled1 gpgcheck1# yum clean all; yum makecache ... Metadata Cache Created 退出码0 用时100s # yum install -y nginx (截取末尾) nginx-filesystem.noarch 1:1.20.1-10.el7 openssl11-libs.x86_64 1:1.1.1k-7.el7 Complete! # rpm -q nginx nginx-1.20.1-10.el7.x86_644. Rocky 9:powertools 改名 crb、模块流要先 reset ✅4.1powertools在 9 上叫crb照着 Rocky 8 的教程开powertools仓库:# dnf config-manager --set-enabled powertools; echo 退出码$? Error: No matching repo to modify: powertools. 退出码1 # dnf config-manager --set-enabled crb; echo 退出码$? 退出码0⚠️ 在这台最小化的 Rocky 9 上,dnf config-manager一开始根本不存在,报的是另一句:No such command: config-manager. Please use /usr/bin/dnf --help It could be a DNF plugin command, try: dnf install dnf-command(config-manager)要先dnf install -y dnf-plugins-core。所以同一条命令可能撞上两种报错,先看清是哪一句。装 EPEL 在 9 上是正常的:# dnf install -y epel-release; dnf repolist | grep -i epel epel Extra Packages for Enterprise Linux 9 - x86_64 epel-cisco-openh264 Extra Packages for Enterprise Linux 9 openh264 (From Cisco) - x86_644.2 模块流:换版本前要reset装特定大版本的 Node.js / PHP 这类软件,Rocky 9 用模块流:# dnf module list nodejs (截取) Name Stream Profiles Summary nodejs 18 common [d], development, minimal, s2i Javascript runtime nodejs 20 common [d], development, minimal, s2i Javascript runtime nodejs 22 common [d], development, minimal, s2i Javascript runtime nodejs 24 common [d], development, minimal, s2i Javascript runtime先启用了 20,再想换成 22:# dnf module enable -y nodejs:22 ... The operation would result in switching of module nodejs stream 20 to stream 22 Error: It is not possible to switch enabled streams of a module unless explicitly enabled via configuration option module_stream_switch. It is recommended to rather remove all installed content from the module, and reset the module using dnf module reset module_name command. After you reset the module, you can install the other stream.先reset再启用就行:# dnf module reset -y nodejs; dnf module enable -y nodejs:22 # dnf module list nodejs | grep -E ^nodejs nodejs 18 common [d], development, minimal, s2i Javascript runtime nodejs 20 common [d], development, minimal, s2i Javascript runtime nodejs 22 [e] common [d], development, minimal, s2i Javascript runtime nodejs 24 common [d], development, minimal, s2i Javascript runtime4.3 Rocky 9 换国内源Rocky 默认用 mirrorlist(dnf repoinfo里能看到它挑中的镜像)。改成阿里云:cp-a/etc/yum.repos.d /root/yum.repos.d.baksed-es|^mirrorlist|#mirrorlist|g\-es|^#baseurlhttp://dl.rockylinux.org/$contentdir|baseurlhttps://mirrors.aliyun.com/rockylinux|g\-i.bak/etc/yum.repos.d/rocky*.repo# grep -E ^(baseurl|#mirrorlist) /etc/yum.repos.d/rocky.repo | head -2 #mirrorlisthttps://mirrors.rockylinux.org/mirrorlist?arch$basearchrepoBaseOS-$releasever$rltype baseurlhttps://mirrors.aliyun.com/rockylinux/$releasever/BaseOS/$basearch/os/ # dnf clean all; time dnf makecache (截取末尾) Metadata cache created. real 0m23.952s # dnf repoinfo baseos | grep Repo-baseurl Repo-baseurl : https://mirrors.aliyun.com/rockylinux/9/BaseOS/x86_64/os/5. Ubuntu 24.04:改sources.list不生效 ✅5.1 源已经不在sources.list里了# cat /etc/apt/sources.list # Ubuntu sources have moved to the /etc/apt/sources.list.d/ubuntu.sources # file, which uses the deb822 format. Use deb822-formatted .sources files # to manage package sources in the /etc/apt/sources.list.d/ directory. # See the sources.list(5) manual page for details.真正的源在/etc/apt/sources.list.d/ubuntu.sources,而且是多行格式:Types: deb URIs: http://archive.ubuntu.com/ubuntu Suites: noble noble-updates noble-backports Components: main universe restricted multiverse Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg Types: deb URIs: http://security.ubuntu.com/ubuntu Suites: noble-security Components: main universe restricted multiverse Signed-By: /usr/share/keyrings/ubuntu-archive-keyring.gpg5.2 老教程的 sed,一个字节都没改到# sed -i s|//archive.ubuntu.com|//mirrors.aliyun.com|g /etc/apt/sources.list # sed -i s|//security.ubuntu.com|//mirrors.aliyun.com|g /etc/apt/sources.list # cmp /tmp/sources.list.before /etc/apt/sources.list echo sources.list 一个字节都没变 sources.list 一个字节都没变 # apt-get update 21 | grep -oE http://[a-z.] | sort | uniq -c 3 http://archive.ubuntu.com 1 http://security.ubuntu.com命令不报错,apt update也正常,只是还在走官方源—— 这是最难发现的那种「没生效」。5.3 改ubuntu.sources,而且两个地址都要改只改 archive 的话:# sed -i s|//archive.ubuntu.com|//mirrors.aliyun.com|g /etc/apt/sources.list.d/ubuntu.sources # grep ^URIs /etc/apt/sources.list.d/ubuntu.sources URIs: http://mirrors.aliyun.com/ubuntu URIs: http://security.ubuntu.com/ubuntu # apt-get update 21 | grep -oE http://[a-z.] | sort | uniq -c 36 http://mirrors.aliyun.com 1 http://security.ubuntu.comsecurity 那一段还在走官方。完整写法:cp/etc/apt/sources.list.d/ubuntu.sources /etc/apt/sources.list.d/ubuntu.sources.baksed-is|//archive.ubuntu.com|//mirrors.aliyun.com|g/etc/apt/sources.list.d/ubuntu.sourcessed-is|//security.ubuntu.com|//mirrors.aliyun.com|g/etc/apt/sources.list.d/ubuntu.sourcesaptupdate# grep ^URIs /etc/apt/sources.list.d/ubuntu.sources URIs: http://mirrors.aliyun.com/ubuntu URIs: http://mirrors.aliyun.com/ubuntu # apt-get update 21 | grep -oE http://[a-z.] | sort | uniq -c 16 http://mirrors.aliyun.com备份放在sources.list.d/里、叫ubuntu.sources.bak的话,实测不会被当成源读进去:上面只改了 archive 那一次,.bak里还是archive.ubuntu.com,而apt update里一次都没出现它。5.4 加第三方源:apt-key还能用,但换成signed-by以 nginx 官方源为例。老写法apt-key add在 24.04 上还能执行成功,但会打弃用警告:# apt-key add /tmp/nginx_signing.key; echo apt-key 退出码$? OK apt-key 退出码0 Warning: apt-key is deprecated. Manage keyring files in trusted.gpg.d instead (see apt-key(8)).现在的写法:把 key 转成二进制放进/etc/apt/keyrings/,在源里用signed-by指定它:install-d-m0755 /etc/apt/keyringscurl-fsSLhttps://nginx.org/keys/nginx_signing.key-o/tmp/nginx_signing.key gpg--dearmor-o/etc/apt/keyrings/nginx.gpg/tmp/nginx_signing.keyechodeb [signed-by/etc/apt/keyrings/nginx.gpg] http://nginx.org/packages/ubuntu noble nginx\|tee/etc/apt/sources.list.d/nginx.listaptupdate# apt-get update 21 | grep -iE nginx.org|W:|E: Get:5 http://nginx.org/packages/ubuntu noble InRelease [3278 B] Get:6 http://nginx.org/packages/ubuntu noble/nginx amd64 Packages [45.3 kB] # apt policy nginx | head -6 nginx: Installed: 1.24.0-2ubuntu7.18 Candidate: 1.30.5-1~noble Version table: 1.30.5-1~noble 500 500 http://nginx.org/packages/ubuntu noble/nginx amd64 Packagesapt policy 包名能看到候选版本来自哪个源—— 排查「怎么装到的不是我想要的版本」就看它。5.5 「Could not get lock」另一个进程拿着 dpkg 的锁时(下面是我用一个脚本故意占住锁来复现的):# apt-get install -y tree; echo 退出码$? E: Could not get lock /var/lib/dpkg/lock-frontend. It is held by process 2879 (python3) E: Unable to acquire the dpkg frontend lock (/var/lib/dpkg/lock-frontend), is another process using it? 退出码100apt-get不会等,直接退出(退出码 100);报错里直接写了是哪个进程占着(process 2879 (python3))—— 先看它是谁,等它结束。真实环境里最常见的是后台自动更新,这台机器上unattended-upgrades默认是enabled的。别一上来就删锁文件,先看报错里写的是哪个进程、等它结束。锁释放后同一条命令直接成功:# apt-get install -y tree (截取末尾) Setting up tree (2.1.1-2ubuntu3.24.04.2) ...6. 本篇速查(三台实测过的写法)想做的事CentOS 7Rocky 9Ubuntu 24.04判系统cat /etc/os-release同左同左更新索引yum makecachednf makecacheapt update装本地包(自动解依赖)yum install ./x.rpmdnf install ./x.rpmapt install ./x.deb文件属于哪个包(未安装)yum provides */名字dnf provides */名字apt-file search 路径撤销上一次装卸yum history undo IDdnf history undo ID—连配置一起删——apt purge 包 及其 -common 包源配置在哪/etc/yum.repos.d/*.repo同左/etc/apt/sources.list.d/ubuntu.sources换源后必做yum clean all yum makecachednf clean all dnf makecacheapt update实测能用的国内源mirrors.aliyun.com/centos-vault/7.9.2009epel-archive/7mirrors.aliyun.com/rockylinuxmirrors.aliyun.com/ubuntu这一篇最容易踩的坑: CentOS 7 源失效,切vault.centos.org前先curl -I—— 国内直连实测 403。 EPEL 7 的 metalink 会让 yum 卡死,改成epel-archive的 baseurl。 Ubuntu 24.04 改sources.list不生效;改ubuntu.sources要连 security 一起改。apt remove nginx删不掉/etc/nginx,要 purgenginx-common。 Rocky 9 上powertools叫crb;config-manager可能要先装dnf-plugins-core。 同一个命令,CentOS 7 和 Rocky 9 的包名可能不同(policycoreutils-pythonvspolicycoreutils-python-utils)。⚠️check-update有更新时退出码是 100;apt-get撞锁退出码也是 100。下一篇(二)端口不通:firewalld / ufw / iptables / nftables / SELinux,同样三台机器实测。