maintaining a freebsd install

These notes are almost certainly wrong, you’ve been warned.

First off you need to decide what version of FreeBSD your running. When I last did this I decided that 6.2 was the safe choice. 6.3 had a few release cantidates, but wasn’t actually released.

6.2 is a pain to install because after you install it you need to upgrade the X11 support and that involves hand work to get over a major transition in the X11 system. This is documented in the ports upgrading file. You’ll want to do that before you start installing too many ports that depend upon X11.  (Oddly I also must set ForwardX11Trusted).
Next up is the problem of getting the security patches installed, and that effects all the OS, the core utilities, and the ports; making for another reason to temper your enthusiasm for installing ports early. This step is eternal, particularly if the machine will be exposed on the open internet; and really one way and another – what isn’t?
There are tools to help, but they are in various states of current. In fact there are two many tools and something of a lack of guidance about which ones to use in which situations.

Freebsd-update is a help for the kernel. It’s a port, so you’ll need to install it. Then you need to wire it up so that it polls from crontab regularly for security patchs.

Portsnap, portupgrade and portinstall are a good. You may wish to wire portsnap into crontab so your informed of the freshest ports. (There seems to be something odd with my portupgrade, I have two /usr/ports/{ports-mgmt,sysutils}/portupgrade. I think happened early on as part of running portsnap. I believe I had to slam the one from ports-mgmt in over the one I’d installed earlier. Note that this happens in the middle of getting X11 upgraded.)
Portaudit, another port, needs to be installed so your informed when your ports have security issues.

Then you have to apply the patches freebsd-update is telling you about by hand, and you have to make thoughtful choices about how closely you track the latest and greatest ports. Of course upgrading to fix the problems portaudit points out can cascade into other ports.

All that that is hand work, which you have to do regularly; and you have to read your email from root. It’s a particular pain that portupgrade will occasionally decide it wants to interact with you personally to configure a package; when that happens it will want you to be on a traditional terminal.

I suspect that the approach outlined here doesn’t upgrade the core utilities should they have security issues uncovered. Similarly freebsd-upgrade is useless if you’ve compiled a custom kernel. I was pleased that I didn’t need to do that this time.

I suspect that I haven’t managed to fall into a “best practice” pattern with all this yet. It appears that there is a lot of variation seen through out the FreeBSD community for how to do this. The various tutorials and handbooks are interesting. Some are out of date. Most are confusing because they are full of too many choices! Some are confusing because the new better way hasn’t quite settle down and attracted a wide following, sometimes there appears to be more than one generation of new better way in that state.

Advice is welcome :).

2 thoughts on “maintaining a freebsd install

  1. Peter Keane

    I had a similar experience w/ FreeBSD recently and decided to give OpenBSD a try. I actually found it to be the easiest of any installs I’ve done recently (FreeBSD, ArchLinux, Gentoo). The package management system is a breeze (it is similar to FreeBSD there) and among other things, Firefox much faster on OpenBSD than on Linux (not sure why that is…). It’s a bit conservative in its packages (but they do an entire new release every 6 months), so I may go to “current” form the current “stable” & we’ll see how that goes….

    -peter keane

  2. ah

    i have managed a lot of freebsd server and i liked to work with it, but the upate-process was always a pain.
    before freebsd-update you had to rebuilt the whole system (make buildworld) …

    we mostly use debian or ubuntu server at work, because the update process is far more robust and faster.
    in my experience debian is as stable as freebsd and apt-get ist rock-solid if you keep using offical packages.

    compare the time to upgrade a freebsd and a debian system.

    debian mostly 10 minutes
    freebsd system and port mostly take a couple of hours

Leave a Reply

Your email address will not be published.