Home / Alt manpages / debconf-set-selections(1)

  • debconf-set-selections(1)
  • User command
  • linux

Pre-seed Debian package answers safely with debconf-set-selections

You will prepare a debconf answer file, check its format without changing the database, then apply it before installing or reconfiguring a package. Allow about fifteen minutes for a small preseed file and one verification pass. You need a shell, the debconf package, and a package whose questions you intend to answer.

The examples use debconf 1.5.86ubuntu1, installed on this machine. The local manual documents --verbose and --checkonly; the installed command also reports --unseen. Treat that extra option as version-specific and confirm it with debconf-set-selections --help on another system.

Safety boundary

This command writes to the debconf database. Only seed questions for packages that are installed or are about to be installed. Invented answers for unrelated packages can remain in the database and can interfere with shared questions.

1. Write a small answer file

Each active line has four parts: the owning package, the question name, its type, and the answer. A comment starts with #; blank lines are ignored. The answer is everything after the third whitespace-separated field, so values containing spaces can stay on the same line.

$ install -m 600 /dev/null /tmp/my-package-preseed
$ editor /tmp/my-package-preseed
# Example questions. Replace these with names documented by the package.
my-package my-package/feature boolean true
my-package my-package/mode select standard

The package and question names above are placeholders, not guaranteed questions. Replace them with real templates from the package documentation or from a matching system. Do not paste this file into a production run unchanged.

Values normally mark their questions as seen, which prevents debconf from asking them interactively later. To set only the seen state, use seen as the third field and put true or false after it:

my-package my-package/feature seen false

If you need to change a value without marking the question seen, use two lines: set the value, then explicitly set its seen state to false. A line can continue onto the next line by ending with a backslash.

Checkpoint: inspect before applying

Read the file back and check that every non-comment line names the package you expect. This catches the most distracting failure mode: editing a copy in one directory and applying a different file.

$ sed -n '1,120p' /tmp/my-package-preseed
# Example questions. Replace these with names documented by the package.
my-package my-package/feature boolean true
my-package my-package/mode select standard

2. Validate the format without saving changes

Run --checkonly before the real operation. It checks the input file format and does not save changes to the debconf database. This is an ordinary, unprivileged check when the file is readable.

$ debconf-set-selections --checkonly /tmp/my-package-preseed
$ printf '%s\n' "$?"
0

A zero status means the file passed this parser check. It does not prove that the question exists, that the value is suitable for the package version, or that the package will behave as you expect. Fix any diagnostic and rerun the check before continuing.

3. Apply the answers deliberately

Once the file is checked, apply it by naming the file. Writing the system database commonly requires elevated privileges, so use sudo only for this state-changing step:

$ sudo debconf-set-selections /tmp/my-package-preseed

The normal command is quiet. Add --verbose when you need a record of what it is processing:

$ sudo debconf-set-selections --verbose /tmp/my-package-preseed
info: Trying to set 'my-package/feature' [boolean] to 'true'

Verbose output is useful for finding a misspelled question name or a value that the package does not accept. Do not treat it as a substitute for checking the package's templates.

4. Keep answers unseen when the next install must ask

The installed command advertises --unseen, abbreviated as -u. It applies preseeding without setting the seen flag. This is useful when you want a default available to the package but still want the frontend to present the question:

$ sudo debconf-set-selections --unseen /tmp/my-package-preseed

This option is not listed in the local manual page, although the installed program accepts it. Check the local help output before using it in a portable script. If you require exact seen-state control, an explicit seen false line is easier to audit in the input file.

5. Verify the consumer, not just the seed command

A successful seed command only says that debconf accepted the input. Install or reconfigure the intended package, then observe whether it uses the answers. Use the package's normal operation, for example:

$ sudo apt-get install my-package
$ sudo dpkg-reconfigure my-package

Replace my-package with a real package. These commands may change installed software and may ask questions, so review the transaction before confirming it. A preseed does not grant permission to install software, skip package-maintainer scripts, or bypass an administrator's review.

For a portable migration, the documented pipeline is to obtain selections with debconf-get-selections and feed them to the command on another host. That utility is supplied by debconf-utils, not by the base command's package:

$ debconf-get-selections > host-a-selections
$ ssh newhost debconf-set-selections < host-a-selections

Review a dump before transferring it. It can contain passwords or host-specific values, and the manual recommends using this approach only between machines with an identical installation. Protect the file and delete it through your normal secure-data process after confirming it is no longer needed.

Common traps and recovery

  • Wrong package or question: the line can parse successfully while having no useful effect. Compare the question name and type with the target package's templates.
  • Unexpected prompts: check whether the value was marked seen, whether the package asks a different question in this release, and whether the selected frontend is displaying it.
  • Unwanted database state: do not edit debconf's database files by hand. Remove or change the specific answer through the package's debconf tools, or use debconf-communicate only after reviewing its documentation and the package's recovery procedure.
  • Interrupted installation: keep the original preseed file, inspect the package manager's reported state, and complete recovery with the package manager's normal repair commands. Do not repeatedly apply a guessed answer file.

Done means

  • The answer file contains only questions for the package being installed or configured.
  • debconf-set-selections --checkonly returned status 0 before any database change.
  • The applied values and seen states match the intended installation workflow.
  • Elevated privileges were used only for the database write and package operation.
  • Any exported selections file was reviewed and protected because it may contain secrets or host-specific settings.