# Prevent from updating to 9.2

**URL:** <https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292>\
**Category:** Rocky Linux Help & Support\
**Created:** [June 15, 2023, 8:45am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292 "2023-06-15T08:45:02Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![ziemien](https://avatars.discourse-cdn.com/v4/letter/z/90db22/32.png) [@ziemien](https://forums.rockylinux.org/u/ziemien)\
**Post date:** [June 15, 2023, 8:45am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/1 "2023-06-15T08:45:02Z")

</div>

Hi

We are stuck at lest temporarily on 9.1 due to kernel support by third parties. Unfortunately I run today `sudo dnf update` and it upgraded our server to 9.2 which at the same time updated the kernel.

Is it possible to somehow restrict update in dnf (or freeze the minor version) to make sure nobody upgrades the OS to 9.2?

Best  
Bart

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [June 15, 2023, 9:30am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/2 "2023-06-15T09:30:30Z")

</div>

OS pinning is something supported by RHEL. It is not supported or possible for Rocky, Alma or whatever.

Theoretically, you can edit the /etc/yum.repos.d/\*.repo files and change the URL to use the Rocky vault url’s to stop it from being upgraded - assuming of course that they are then fixed to 9.1 and not eg: 9 - else when 9.2 gets moved to the vault, you’ll then end up being upgraded.

Obviously that isn’t recommended to do, so the responsibility for any issues later by using that method wouldn’t be the responsibility of Rocky. Updates are to ensure that a server is secure with the appropriate security patches applied etc.

It’s probably better if anything, just to fix the kernel so that it doesn’t upgrade by excluding it in /etc/dnf/dnf.conf - at least that way you won’t have the kernel upgrade issue, but at least the rest of the system will have updates applied and be more secure.

---

<div class="post-metadata">

**Author:** ![jlehtone](https://avatars.discourse-cdn.com/v4/letter/j/e9a140/32.png) [@jlehtone](https://forums.rockylinux.org/u/jlehtone)\
**Post date:** [June 15, 2023, 10:50am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/3 "2023-06-15T10:50:02Z")

</div>

> [@iwalker](#):
>
> OS pinning is something supported by RHEL.

But there is no pinning for RHEL 9.1, so _nobody_ supports 9.1 any more. Not even with money.

> [@ziemien](#):
>
> … kernel support by third parties.

Third parties seem to have a systemic issue.

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [June 15, 2023, 11:48am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/4 "2023-06-15T11:48:23Z")

</div>

> [@jlehtone](#):
>
> But there is no pinning for RHEL 9.1, so _nobody_ supports 9.1 any more. Not even with money.

I mentioned generally, since it’s something RHEL supports - obviously they have EUS versions that don’t apply to all versions. However, looks like it works for me:

```auto
[root@rhel9 ~]# subscription-manager release --show
Release not set

[root@rhel9 ~]# subscription-manager release --list
+-------------------------------------------+
          Available Releases       
+-------------------------------------------+
9
9.0
9.1
9.2

[root@rhel9 ~]# subscription-manager release --set=9.1
Release set to: 9.1

[root@rhel9 ~]# subscription-manager release --show
Release: 9.1

```

for EUS channels, then yes updates will be able to be applied. But I can still pin to a particular version, even if it’s not EUS, it just won’t get any extended updates if it’s not an EUS channel.

---

<div class="post-metadata">

**Author:** ![ziemien](https://avatars.discourse-cdn.com/v4/letter/z/90db22/32.png) [@ziemien](https://forums.rockylinux.org/u/ziemien)\
**Post date:** [June 15, 2023, 12:24pm UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/5 "2023-06-15T12:24:33Z")

</div>

I saw the old kernel indeed is still installed but the problem is with package kernel-devel - we require certain headers to be present and that package it’s not available for the 9.1 kernel. After the upgrade I can only see `5.14.0-284.11.1.el9_2.x86_64` headers available

---

<div class="post-metadata">

**Author:** ![Zabbix112](https://avatars.discourse-cdn.com/v4/letter/z/f6c823/32.png) [@Zabbix112](https://forums.rockylinux.org/u/Zabbix112)\
**Post date:** [June 15, 2023, 2:23pm UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/6 "2023-06-15T14:23:56Z")

</div>

Good day,

I have a question that relates to this topic, we went from 9.0 to 9.2 we are having issues with third party also. I need to downgrade to 9.1 I have not found a way that will roll everything back to 9.1. While we do a have a way to lock the version already this was a new build and we did not have the lock in place.

---

<div class="post-metadata">

**Author:** ![ziemien](https://avatars.discourse-cdn.com/v4/letter/z/90db22/32.png) [@ziemien](https://forums.rockylinux.org/u/ziemien)\
**Post date:** [June 16, 2023, 4:00am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/7 "2023-06-16T04:00:42Z")

</div>

Could you share how did you achieve the version lock?

Best  
Bart

---

<div class="post-metadata">

**Author:** ![iwalker](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/iwalker/32/2599_2.png) [@iwalker](https://forums.rockylinux.org/u/iwalker)\
**Post date:** [June 16, 2023, 6:26am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/8 "2023-06-16T06:26:39Z")

</div>

The version lock is on RHEL - it doesn’t work on Rocky/Alma or any other EL derivatives.

You have to edit the /etc/yum.repos.d/\*.repo files manually and change the URL’s to use the Rocky Vault URL’s for where the archived versions of Rocky exist to be able to pin it to 9.1 or whatever. But it’s not recommended to do that as previously mentioned but you have the choice if you so wish 🙂

The vault URL: [Index of /vault/rocky/](https://download.rockylinux.org/vault/rocky/)

---

<div class="post-metadata">

**Author:** ![nouvo09](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/nouvo09/32/2920_2.png) [@nouvo09](https://forums.rockylinux.org/u/nouvo09)\
**Post date:** [June 16, 2023, 9:50am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/9 "2023-06-16T09:50:00Z")

</div>

If you want to prevent dnf from updating the kernel, add in the file /etc/dnf/dnf.conf this line:

exclude=kernel\*

Be aware that the kernel will NEVER be updated until you drop this line.

---

<div class="post-metadata">

**Author:** ![Cphusion](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/cphusion/32/3235_2.png) [@Cphusion](https://forums.rockylinux.org/u/Cphusion)\
**Post date:** [June 16, 2023, 10:26am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/10 "2023-06-16T10:26:39Z")

</div>

Or if you use the dnf option --disableexcludes==[all|main|]

---

<div class="post-metadata">

**Author:** ![anthyve](https://avatars.discourse-cdn.com/v4/letter/a/b2d939/32.png) [@anthyve](https://forums.rockylinux.org/u/anthyve)\
**Post date:** [June 16, 2023, 11:58am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/11 "2023-06-16T11:58:23Z")

</div>

To prevent updates to certain packages, you could use `dnf versionlock`.

Install `dnf install python3-dnf-plugin-versionlock`, then lock packages that you want to avoid upgrading, e.g. kernel `dnf versionlock kernel-*`. See [DNF versionlock Plugin — dnf-plugins-core 4.4.1-1 documentation](https://dnf-plugins-core.readthedocs.io/en/latest/versionlock.html) .

---

<div class="post-metadata">

**Author:** ![Zabbix112](https://avatars.discourse-cdn.com/v4/letter/z/f6c823/32.png) [@Zabbix112](https://forums.rockylinux.org/u/Zabbix112)\
**Post date:** [June 16, 2023, 9:17pm UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/12 "2023-06-16T21:17:44Z")

</div>

[Index of /vault/rocky/9.1/](https://dl.rockylinux.org/vault/rocky/9.1/) if you go into rocky.repo you will see everything has a variable. osversion release all this stuff you just need to change the baseurl not mirror to this static site url for baseOS, extras, appstream

---

<div class="post-metadata">

**Author:** ![nyue](https://avatars.discourse-cdn.com/v4/letter/n/94ad74/32.png) [@nyue](https://forums.rockylinux.org/u/nyue)\
**Post date:** [June 21, 2023, 3:03am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/13 "2023-06-21T03:03:42Z")

</div>

About a month ago, there was this CIQ [webinar](https://www.youtube.com/watch?v=t0aJ4RkRRQE) which mention version pinning. Maybe there is some information from that webinar that might help you.

Cheers

---

<div class="post-metadata">

**Author:** ![brian](https://sea2.discourse-cdn.com/flex020/user_avatar/forums.rockylinux.org/brian/32/5777_2.png) [@brian](https://forums.rockylinux.org/u/brian)\
**Post date:** [August 25, 2023, 2:59am UTC](https://forums.rockylinux.org/t/prevent-from-updating-to-9-2/10292/14 "2023-08-25T02:59:55Z")

</div>


