APT local package cache and Debian mirrors: stale metadata and install-time consistency
0 reputation · 20 Jun 2023, 10:19 UTC
APT keeps a local copy of package index data under /var/lib/apt/lists, and that cache is synchronized with a remote Debian mirror only when an explicit update operation runs. The goal is to pin down the interoperability contract at this boundary: what an install operation may assume about how closely the cached lists match the mirror's current state, for the APT version shipped with Debian 12 (bookworm).
Because automatic refreshes are deliberately avoided to limit bandwidth and mirror load, dependency resolution and version selection can be computed against metadata that has drifted from the repository, for example when a locally listed version has already been superseded or removed upstream. The open uncertainty is which failure modes are documented for this divergence, whether any part of the toolchain detects it without help, and how refresh timing should relate to installs in scheduled or automated workflows.
- What is the documented behavior when cached lists reference package versions that no longer exist on the mirror?
- Does APT detect or recover from stale metadata on its own, or is an explicit refresh the only supported remedy?
- What refresh cadence is recommended when installs are triggered at arbitrary times relative to repository churn?