Before you install a Debian package, apt-extracttemplates lets you pull out its debconf questions and configuration script and read them first. It writes both files to a directory you choose, prints their paths, and touches nothing else on the system. The whole check takes about ten minutes and never installs, removes or configures anything.
.deb file and a shell./tmp normally needs none.apt-utils package, 2.8.3, on amd64.$ command -v apt-extracttemplates
/usr/bin/apt-extracttemplates
$ apt-extracttemplates --version
apt 2.8.3 (amd64)
Checkpoint: if command -v prints nothing, install or repair apt-utils through your normal system administration process before continuing. Do not work around a missing binary by copying one from another host.
out_dir=$(mktemp -d)
printf 'extraction directory: %s\n' "$out_dir"
package.template.random and package.config.random, with trailing characters generated to avoid a fixed filename.--tempdir at a directory containing files you care about; treating a shared directory as disposable makes later cleanup and review harder even though the output names look temporary.deb_file=/path/to/package.deb
apt-extracttemplates --tempdir "$out_dir" "$deb_file"
status=$?
printf 'exit status: %s\n' "$status"
For every input package containing both kinds of debconf data, the output line has this shape:
package version template-file config-script
Extracting the Ubuntu tzdata package with this installed command produced:
tzdata 2026c-0ubuntu0.24.04.1 /tmp/apt-extracttemplates-fixture-Oi9zz3/out/tzdata.template.EvoOfn /tmp/apt-extracttemplates-fixture-Oi9zz3/out/tzdata.config.yu3m8K
0 means the operation completed normally; the program uses decimal status 100 for an error.find "$out_dir" -maxdepth 1 -type f -printf '%f %s bytes\n' | sort
file "$out_dir"/*
Checkpoint: the paths printed by apt-extracttemplates should point inside $out_dir, and the corresponding files should exist:
test -d "$out_dir" && find "$out_dir" -maxdepth 1 -type f -print
A package without associated config scripts and templates may produce no data line and leave the output directory empty. That is different from a failed extraction, so check the exit status as well as the file list.
first_deb=/path/to/first-package.deb
second_deb=/path/to/second-package.deb
apt-extracttemplates --tempdir "$out_dir" "$first_deb" "$second_deb"
printf 'exit status: %s\n' "$?"
apt-extracttemplates \
-o APT::ExtractTemplates::TempDir="$out_dir" \
"$deb_file"
--tempdir corresponds to APT::ExtractTemplates::TempDir, and for a one-off check the option is easier to audit.--config-file deliberately. Reach for it when a complete APT configuration file is part of a controlled test; the program reads the default configuration before that named file.APT_CONFIG runs earlier still. It applies settings before default configuration files are parsed. Do not put secrets or unrelated production settings into a temporary test file.rm -rf -- "$out_dir"
Warning: this deletion is irreversible. Check the variable before running it, especially if you opened another shell or copied commands between terminals:
printf 'about to remove: %s\n' "$out_dir"
test -n "$out_dir" && test -d "$out_dir" && rm -rf -- "$out_dir"
If you need an audit record, copy the extracted files to a deliberately named, access-controlled directory before cleanup. Do not retain a config script in a shared location merely because it is convenient.
apt-extracttemplates --version reports the installed APT version you intended to test.