Roll back a package update two ways, and tell users what is happening
Task
Treat a package update on lin-b as the cause of a fault and roll it back twice: first precisely, by reverting the package with the package manager's history, then broadly, by reverting the VM to its pre-patch snapshot. Record what each method restores and what each loses, and write the outage messages users would receive while it happened.
Steps
- Take the
before-patchsnapshot. Choose a package with an available update and save its installed version tolab/rollback/v-before.txt. - Create a file
/srv/after-patch-data.txt(standing in for data written after patching), then update the package and save its version tolab/rollback/v-updated.txt. - Roll back with the package manager and save the version to
lab/rollback/v-pkg-rollback.txt, and whether the data file still exists tolab/rollback/data-after-pkg.txt, aspresentormissing. - Update the package again, then revert the VM to
before-patch. Save the version tolab/rollback/v-snapshot.txtand whether the data file exists tolab/rollback/data-after-snapshot.txt, aspresentormissing. - Write
lab/rollback/messages.txtwith three short outage messages: the first acknowledgement, an update at thirty minutes, and the resolution.
Verify
These checks run in a POSIX shell: Terminal on macOS or Linux, and on Windows Git Bash (it comes with Git for Windows) or WSL. A stock Windows PowerShell or Command Prompt has no awk or grep, so there the first line fails.
cat lab/rollback/v-before.txt lab/rollback/v-updated.txt
diff lab/rollback/v-before.txt lab/rollback/v-pkg-rollback.txt && echo package rollback restored the old version
diff lab/rollback/v-before.txt lab/rollback/v-snapshot.txt && echo snapshot restored the old version
grep -Eic 'yes|exists|present' lab/rollback/data-after-pkg.txt
grep -Eic 'missing|gone|absent|does not exist' lab/rollback/data-after-snapshot.txt
grep -c . lab/rollback/messages.txt
Both rollbacks restored the old version, but only the package rollback kept the data written after patching; the snapshot discarded it. That is the trade-off the lesson describes: a snapshot is fast and complete, and it takes everything since, including work that had nothing to do with the patch.
Notes
After rolling back, the vulnerability the update fixed is open again. Block the update from reinstalling -- apt-mark hold or dnf's exclude -- and apply a mitigation until a fixed version is available.
This is an independent study companion for CompTIA Server+ SK0-005 and is not produced by or endorsed by CompTIA.