ivanpollak.com


pkgsrc

Overview

pkgsrc is the package management suite from NetBSD and just like NetBSD, it aims to be as portable as possible. This results in this software being available for many platforms beside NetBSD. The supported platforms include:

There are many more... Basically every Unix-like operating system is supported.

Unlike other package managers, pkgsrc provides both binary and source packages. This means that a package can be built from scratch if wanted, however there also are binary packages if the compilation is not wanted. Binary packages however are not provided for every mentioned platform. Official binary packages are only available for NetBSD. Binary packages for SmartOS, darwin (macOS) and Enterprise Linux (CentOS).

Components

As many other package managers, there is one tool to build the packages and one or multiple ones to install, update and remove the packages. In Arch Linux, these are makepkg and pacman, in Void Linux these are xbps-{install, update,remove} and xbps-src, in pkgsrc these are pkg_{add,delete,admin} and make (bmake on systems that are not NetBSD).

With pkgsrc, there is also pkgin, a wrapper around the various pkg_* comamnds that provides a more user-friendly way of installing packages.

Installation

This section focusses around building packages from source on darwin (macOS). If you have other needs, please consult another resource of information.

To get started, first make sure that the command line developer tools are installed. These official macOS package installs a c compiler, git and various other useful developer tools. They are required for pkgsrc to work. Install them using:

        
$ xcode-select --install
        
      

Next, clone the pkgsrc repository into a directory of your choice. In my case this is $HOME/Documents/. Note that we do clone from github, which is just a mirror of the CVS project so use it with care. In all of my cases, I've had no issues with it.

        
$ git clone https://github.com/NetBSD/pkgsrc
        
      

Lastly, it is required to bootstrap pkgsrc into a given location. It is recommended to put this into /opt, like in the example below:

        
$ cd pkgsrc/bootstrap
# ./bootstrap --prefix /opt/pkgsrc --prefer-pkgsrc yes --make-jobs 4
        
      

This installs bmake and all needed tools into /opt/pkgsrc. Make sure that the binary directory and man directory is in your path, so you do not have to type in the full path to run the binary:

        
$ export PATH="/opt/pkgsrc/bin:/opt/pkgsrc/sbin:${PATH}"
$ export MANPATH="/opt/pkgsrc/man:${MANPATH}"
        
      

Configuration

This section explains the different configuration options and settings for pkgsrc.

Global Configuration

pkgsrc's build process as well as many other things can be configured easily using the mk.conf file. By default, this is located in ${PREFIX}/etc/mk.conf, so in my case it is in /opt/pkgsrc/etc/mk.conf. There are many different variables that can be configured, however the (in my opinion) most important ones are:

Package Configuration

Some packages have build options. The build options may enable features or optional support for some dependencies. Not all packages have build options. To see if a package has some build options, use:

        
$ bmake show-options
Any of the following general options may be selected:
alsa     Enable ALSA support.
dbus     Enable dbus (desktop bus) support.
debug    Enable debugging facilities in the package.
debug-info       Enable debug info in generated binaries (e.g. for crash analysis), but not full scale debugging.
jack     Enable support for the JACK audio server.
mozilla-jemalloc        Enable building with Mozilla's jemalloc.
official-mozilla-branding       Use official Mozilla reg. trademarks and logos.
pulseaudio       Enable support for the PulseAudio sound server.
speechd  Enable Speech Dispatcher support.
sunaudio         Enable Sun audio support.
webrtc   Enable web realtime communications API.

These options are enabled by default:

These options are currently enabled:

You can select which build options to use by setting PKG_DEFAULT_OPTIONS
or PKG_OPTIONS.firefox.
        
      

To set an option, create a new variable in the mk.conf file: PKG_OPTIONS.firefox= alsa dbus -jack. Alternatively, options for all packages can be set using PKG_DEFAULT_OPTIONS= -atrs -dvdread -esound.

It should be noted, that suggested options that were suggested by the maintainer need to be explicitly disabled. This is because some package might break or behave weirdly if a given option is disabled.

Usage

This section describes how to use pkgsrc on macOS.

Installation

With all of this done, we now can start compiling. Find a package that you want to instal using:

        
$ cd $HOME/Documents/pkgsrc
$ find . -name "package-name"
        
      

This should return the path to the package's directory. Go into this directory and just run:

        
$ cd $HOME/Documents/pkgsrc
$ cd $(find . -name "package-name")
$ bmake install clean-depends clean
        
      

NetBSD's make will detect the dependencies automatically and build them first. If bmake needs root access, it will ask. It is recommended to build the packages as an user and not as root. Besides, root doesnt have the binary path in his PATH variable anyways. The command above will then clean the produced binary and things that are not needed anymore. This will result in less disk usage.

In most cases, the compilation will take some time, so sit back and relax.

Listing installed packages

To list all the installed packages, use:

        
$ sudo pkg_info
        
      

Note that we use sudo and not # (root shell) because if the root shell was used, we would not have the /opt/pkgsrc/{bin,sbin} in the PATH env variable.

Removal

To remove a package, it is recommended to use the pkg_delete command. This command is located in /opt/pkgsrc/sbin, so make sure that this directory is really in your PATH variable.

To uninstall a package, use:

        
$ sudo pkg_delete package-name
        
      

Checking security vulnerabilities

pkgsrc has a handy tool to check every installed package for known vulnerabilities (CVE's). To scan your system, use:

        
$ sudo pkg_admin fetch-pkg-vulnerabilities
$ sudo pkg_admin audit
        
      

This will first fetch the vulnerabilities from https://cdn.netbsd.org/pub/ NetBSD/packages/vulns/pkg-vulnerabilities and afterwards audit your system. Note that not every "vulnerability" is exploitable on every system. Some require special configurations and it is pretty common for a fully up-to-date system to list some vulnerabilities.

Packaging

If there is the need to share packages, these can be created by using:

        
$ bmake package
        
      

This will create a package into $HOME/Documents/pkgsrc/packages if the above guide was followed. These packages may be shared and installed using pkg_add on another system. This saves time and resources.

Terms

While each package manager has its own system, pkgsrc has some unique terms that are used to describe certain parts of the package management system. This section explains some of those.

Distfile

A distfile is the unmodified source code of a package. For example if firefox should be built, the distfile for firefox would be some sort of tar.gz archive of the source code. All distfiles have a directory where they are stored in. If the previous guide for macOS was followed, the files will be in $HOME/Documents/pkgsrc/distfiles.