[BACK]Return to porting.html CVS log [TXT][DIR] Up to [local] / www

Annotation of www/porting.html, Revision 1.51

1.20      rohee       1: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 3.2 Final//EN">
1.1       marc        2: <html>
                      3:  <head>
                      4:   <meta http-equiv="Content-Type"
1.15      espie       5:         content="text/html; charset=iso-8859-1">
1.1       marc        6:   <meta name="resource-type"
1.15      espie       7:         content="document">
1.1       marc        8:   <meta name="description"
1.15      espie       9:         CONTENT="How to make an OpenBSD port">
1.1       marc       10:   <meta name="keywords"
1.15      espie      11:         content="openbsd,ports">
1.1       marc       12:   <meta name="distribution"
1.15      espie      13:         content="global">
1.1       marc       14:   <meta name="copyright"
1.47      nick       15:         content="This document copyright 1997-2004 by OpenBSD.">
1.1       marc       16:   <title>Building an OpenBSD port</title>
                     17:   <link rev="made" HREF="mailto:www@openbsd.org">
                     18:  </head>
                     19:  <body text="#000000" bgcolor="#FFFFFF" link="#23238E">
1.43      jsyn       20: <a href="index.html"><img alt="[OpenBSD]" height="30" width="141" src="images/smalltitle.gif" border="0"></a>
1.1       marc       21:
1.20      rohee      22:   <h2><font color="#e00000">Building an OpenBSD port</font></h2>
1.1       marc       23:
                     24:    So you've just compiled your favorite software package on your
                     25:    OpenBSD machine and you want to share your effort by turning
                     26:    it into a standard port.  What to do?
                     27:   <p>
1.25      espie      28:    The most important thing you can is to <strong>communicate</strong>.
                     29:    Ask people on <a href="mailto:ports@openbsd.org">ports@openbsd.org</a>
                     30:    if they are working on the same port. <em>Tell the original software
                     31:    author about it</em>, including problems you may find. If licensing
                     32:    information appears incorrect tell him.  If you had to jump through
                     33:    loops to make the port build, tell him what he can fix.  If they are
1.32      deraadt    34:    only developing on Linux and feel like ignoring the rest of the Unix
1.25      espie      35:    world, try to make them change their view.
                     36:   <p>
                     37:    <strong>COMMUNICATION</strong> makes the difference between a successful
1.34      jufi       38:    port and a port that will slowly be abandoned by everyone.
1.25      espie      39:   <p>
1.9       marc       40:    First look at the porting information on this page.  Then check
                     41:    out the referenced documents, especially the OpenBSD porting
1.26      espie      42:    <a href="checklist.html">checklist</a>.
1.1       marc       43:   <p>
1.9       marc       44:    Test, then re-test, and finally test again!
                     45:   <p>
                     46:    Submit the port.  Create a gzipped tarball of the port directory.
                     47:    You can then either place it on a public FTP or HTTP server, sending
1.20      rohee      48:    its address to <a href="mailto:ports@openbsd.org">ports@openbsd.org</a>
1.9       marc       49:    or send the port mime encoded to the same address.  Pick whichever
                     50:    method works best for you.
1.35      naddy      51:
                     52: <h3><font color="#0000e0">Index of Porting Documentation</font></h3>
                     53: <ul>
                     54: <li><a href="#Avail">Available Porting Information</a></li>
                     55: <li><a href="#Policy">OpenBSD Porting Policy</a></li>
                     56: <li><a href="#Security">Security Recommendations</a></li>
                     57: <li><a href="#Generic">Generic Porting Hints</a></li>
                     58: <li><a href="#Other">Other Helpful Hints</a></li>
                     59: </ul>
                     60:
                     61:   <h3><font color="#0000e0"><a name="Avail">Available Porting Information</a></font></h3>
1.1       marc       62:   <ul>
1.38      espie      63:    <li>OpenBSD porting <a href="checklist.html">checklist</a>.
                     64:    <li>The man page
1.41      rohee      65:    <a href="http://www.openbsd.org/cgi-bin/man.cgi?query=bsd.port.mk&amp;sektion=5">bsd.port.mk(5)</a>.
1.38      espie      66:        This documents the ports infrastructure makefile that is
                     67:        included at the end of each individual port makefile.
                     68:        There are still a few comments at the start of
1.39      horacio    69:        the file itself, but most of the useful information is now
1.38      espie      70:        documented.
                     71:    <li>Some differences from other BSD port systems, mostly a summary
                     72:    of <a href="porting/diffs.html">infrastructure differences</a>.
                     73:    <li><a href="porting/libraries.html">Using shared libraries
                     74:    in OpenBSD Ports</a>. The rules there are <strong>very
1.51    ! espie      75:    important</strong> as soon as you use shared libraries.
        !            76:    <li><a href="porting/autoconf.html">GNU autoconf specificities</a>,
        !            77:    how to deal with it in the context of OpenBSD ports.
        !            78:    <li><a href="porting/config.html">Configuration files</a>,
        !            79:    one frequent stumbling block for new developers, and the unique
        !            80:    tools the OpenBSD ports tree has to deal with these.
1.38      espie      81:    <li><a href="audio-port.html">Porting audio applications to OpenBSD</a>.
1.1       marc       82:    <li>The
1.13      art        83:        <a href="http://www.netbsd.org/Documentation/software/packages.html">
                     84:        NetBSD Package System</a> documentation.  This document describes
                     85:        NetBSD's version of the FreeBSD ports system and is quite helpful.
1.33      naddy      86:    <li>The
1.42      pvalchev   87:        <a href="http://www.freebsd.org/doc/en_US.ISO8859-1/books/porters-handbook/index.html">FreeBSD
1.33      naddy      88:        Porter's Handbook</a>.  This is the FreeBSD porting bible.
1.1       marc       89:    <li>The OpenBSD ports mailing list,
1.50      alek       90:        <a href="mailto:ports@openbsd.org">ports@openbsd.org</a>.
1.1       marc       91:   </ul>
1.35      naddy      92:   <h3><font color="#0000e0"><a name="Policy">OpenBSD Porting Policy</a></font></h3>
1.1       marc       93:   <ul>
1.24      rohee      94:    <li>OpenBSD does NOT use <code>/usr/local/etc/rc.d</code>.<br>
1.7       espie      95:        <code>/usr/local</code> is often shared between several machines
1.15      espie      96:          thanks to NFS.  For this reason, configuration files that are specific
                     97:          to a given machine can't be stored under <code>/usr/local</code>,
                     98:          <code>/etc</code> is the central repository for per machine
                     99:          configuration files.  Moreover, OpenBSD policy is to never update
                    100:          files under <code>/etc</code> automatically.  Ports that need some
                    101:          specific boot setup should advise the administrator about what to do
                    102:          instead of blindly installing files.
1.1       marc      103:    <li>OpenBSD does NOT compress man pages.
                    104:    <li>OpenBSD does NOT require <code>-lcrypt</code>.<br>
                    105:        DES encryption is part of the standard <code>libc</code>.
1.46      sturm     106:    <li>OpenBSD has a separate namespace for users and groups created by ports.
                    107:        See <code>/usr/ports/infrastructure/db/user.list</code> for details.
1.10      espie     108:    <li>OpenBSD is strongly security-oriented. You should read and understand
1.42      pvalchev  109:        this page's <a href="#Security">security section</a>.
1.24      rohee     110:    <li>Be sure to add the <code>&#36;OpenBSD&#36;</code> CVS tag to
1.10      espie     111:        the Makefile.  If importing a port from another system be sure to
1.48      xsa       112:        leave their tag in the Makefile, too.
1.10      espie     113:    <li>The goal is to get all ported applications to support OpenBSD.  To
                    114:        achieve this goal you <strong>must</strong> feed any OpenBSD patches
                    115:        back to the application maintainer.
                    116:   </ul>
1.35      naddy     117:   <h3><font color="#0000e0"><a name="Security">Security Recommendations</a></font></h3>
1.10      espie     118:   There are many security problems to worry about. If
1.2       marc      119:        you are not absolutely sure of what you are doing please request
1.1       marc      120:        help from the <a href="mailto:ports@openbsd.org">ports</a> mailing
                    121:        list.
1.10      espie     122:
                    123:   <ul>
1.20      rohee     124:    <li>Do <em>not</em> use alpha or beta code when preparing a port.  Use the
1.10      espie     125:        latest regular or patch release.
                    126:
1.1       marc      127:    <li>Any software to be installed as a server should be scanned
                    128:        for buffer overflows, especially unsafe use of
                    129:        <code>strcat/strcpy/strcmp/sprintf</code>.  In general,
                    130:        <code>sprintf</code> should be replaced with <code>snprintf</code>.
1.10      espie     131:
1.17      espie     132:    <li>Never use filenames instead of true security. There are numerous race
1.10      espie     133:        conditions where you don't have proper control. For instance, an attacker
                    134:        who already has user privileges on your machines may replace files in
                    135:        <code>/tmp</code> with symbolic links to more strategic files, such as
1.19      rohee     136:        <code>/etc/master.passwd</code>.
1.16      espie     137:
                    138:    <li>For instance, both <code>fopen</code> and <code>freopen</code>
                    139:        <strong>create a new file or open an existing file</strong> for
                    140:        writing. An attacker may create a symbolic link from
1.19      rohee     141:        <code>/etc/master.passwd</code> to <code>/tmp/addrpool_dump</code>. The
1.16      espie     142:        instant you open it, your password file is hosed. Yes, even with
                    143:        an <code>unlink</code> right before. You only narrow the window
                    144:        of opportunity.  Use <code>open</code> with
1.22      rohee     145:        <code>O_CREAT|O_EXCL</code> and <code>fdopen</code> instead.
1.15      espie     146:
1.16      espie     147:    <li>Another very common problem is the <code>mktemp</code>
1.17      espie     148:        function. Heed the warnings of the bsd linker about its uses.
1.15      espie     149:        <strong>These must be fixed</strong>.
                    150:        This is not quite as simple as <code>s/mktemp/mkstemp/g</code>.  <br>
                    151:        Refer to the <code>mktemp(3)</code> man page of OpenBSD current
                    152:        for more indications.
                    153:        Correct code using <code>mkstemp</code> includes the source to
                    154:        <code>ed</code> or <code>mail</code>.
                    155:        A rare instance of code that uses <code>mktemp</code> correctly
                    156:        can be found in the <code>rsync</code> port.
1.10      espie     157:
                    158:    <li>Just because you can read it doesn't mean you should. A well-known hole
                    159:        of this nature was the <code>startx</code> problem.  As a setuid program,
                    160:        you could launch startx with any file as a script. If the file was not
                    161:        a valid shell script, a syntax error message would follow, along with the
                    162:        first line of the offending file, without any further permission check.
                    163:        Pretty handy to grab the first line of a shadow passwd file, considering
1.12      deraadt   164:        these often start with root entry.   Do not open your file, and then do
                    165:        an <code>fstat</code> on the open descriptor to check if you should have
1.15      espie     166:        been able to open it (or the attacker will play with /dev/rst0 and rewind
1.12      deraadt   167:        your tape) -- open it with the correct uid/gid/grouplist set.
1.10      espie     168:
                    169:    <li>Don't use anything that forks a shell in setuid programs before dropping
1.15      espie     170:        your privileges. This includes <code>popen</code> and
                    171:        <code>system</code>.
1.10      espie     172:        Use <code>fork</code>, <code>pipe</code> and <code>execve</code> instead.
                    173:
1.15      espie     174:    <li>Pass open descriptors instead of filenames to other programs to
                    175:        avoid race conditions.  Even if a program does not accept file
                    176:        descriptors, you can still use <code>/dev/fd/0</code>.
1.10      espie     177:
1.15      espie     178:    <li>Access rights are attached to file descriptors. If you need setuid rights
1.10      espie     179:        to open a file, open that file, then drop your privileges. You can still
                    180:        access the open descriptor, but you have less to worry about. This is
                    181:        double-edged: even after dropping privileges, you should still watch out
                    182:        for those descriptors.
                    183:
                    184:    <li>Avoid root setuid as much as you can. Basically, root can do anything,
1.15      espie     185:        but root rights are very rarely needed, except maybe to create
                    186:        socket ports with a number under 1024.  It is arguably better to
                    187:        keep that under <code>inetd</code>
1.10      espie     188:        control and just add the relevant entries to <code>inetd.conf</code>.
                    189:        You must know the appropriate magic for writing daemons to achieve that.
1.15      espie     190:        It could be argued that you have no business writing setuid programs
                    191:        if you don't know how to do that.
1.10      espie     192:
1.15      espie     193:    <li>Use setgid instead of setuid.  Apart from those specific files needed
                    194:        by setgid programs, most files are not group-writable. Hence, a
                    195:        security problem in a setgid program won't compromise your system as
                    196:        much: with only group rights, the worst an intruder will be able to
                    197:        do is hack a games score table or some such.
1.10      espie     198:        See the <code>xkobo</code> port for an instance of such a change.
                    199:
1.15      espie     200:    <li>Don't trust group-writable files.  Even though they are audited,
                    201:        setgid programs are not perceived as important potential security
                    202:        holes. Hence stuff they can tamper with shouldn't be considered
                    203:        sensitive information.
                    204:
                    205:    <li>Don't trust your environment ! This involves simple things such as
                    206:        your <code>PATH</code> (never use <code>system</code> with an
                    207:        unqualified name, avoid <code>execvp</code>), but also more subtle
                    208:        items such as your locale, timezone, termcap, and so on.
                    209:        Be aware of transitivity: even though you're taking full precautions,
                    210:        programs you call directly won't necessarily. <strong>Never</strong>
                    211:        use <code>system</code> in privileged programs, build your command
                    212:        line, a controlled environment, and call <code>execve</code> directly.
                    213:        The <code>perlsec</code> man page is a good tutorial on such problems.
                    214:
1.31      jufi      215:    <li>Never use setuid shell-scripts.  These are inherently insecure.
1.15      espie     216:        Wrap them into some C code that ensures a proper environment.
                    217:        On the other hand, OpenBSD features secure perl scripts.
                    218:
                    219:    <li>Beware the dynamic loader. If you are running setuid, it will only
                    220:        use trusted libraries that were scanned with ldconfig.
                    221:        Setgid is not enough.
                    222:
                    223:    <li>Dynamic libraries are tricky. C++ code sets a similar problem.
                    224:        Basically, libraries may take some action based upon your environment
                    225:        before your main program even gets to check its setuid status.
                    226:        OpenBSD <code>issetugid</code> addresses this problem, from the
                    227:        library writer point of view.  Don't try to port libraries unless you
                    228:        understand this issue thoroughly.
1.10      espie     229:   </ul>
1.35      naddy     230:   <h3><font color="#0000e0"><a name="Generic">Generic Porting Hints</a></font></h3>
1.10      espie     231:   <ul>
                    232:    <li><code>__OpenBSD__</code> should be used sparingly, if at all.
                    233:        Constructs that look like
                    234:        <pre>
                    235:             #if defined(__NetBSD__) || defined(__FreeBSD__)
                    236:        </pre>
                    237:        are often inappropriate. Don't add blindly <code>__OpenBSD__</code>
                    238:        to it. Instead, try to figure out what's going on, and what actual
                    239:        feature is needed.   Manual pages are often useful, as they include
                    240:        historic comments, stating when a particular feature was incorporated
                    241:        into BSD.  Checking the numeric value of <code>BSD</code> against known
                    242:        releases is often the right way. See
1.17      espie     243:        <a href="ftp://ftp.netbsd.org/pub/NetBSD/packages/pkgsrc/Packages.txt">the NetBSD package guide</a>
1.10      espie     244:        for more information.
                    245:    <li>Defining <code>BSD</code> is a bad idea. Try to include <code>sys/param.h</code>.
                    246:        This not only defines <code>BSD</code>, it also gives it a proper value.
                    247:        The right code fragment should look like:
                    248:        <pre>
1.23      rohee     249:            #if (defined(__unix__) || defined(unix)) &amp;&amp; !defined(USG)
1.10      espie     250:            #include &lt;sys/param.h&gt;
                    251:            #endif
                    252:        </pre>
                    253:    <li>Test for features, not for specific OSes. In the long run, it is much
1.15      espie     254:        better to test whether <code>tcgetattr</code> works than whether
                    255:        you're running under BSD 4.3 or later, or SystemVR4.  These kind of
                    256:        tests just confuse the issue. The way to go about it is, for instance,
                    257:        to test for one particular system, set up a slew of
                    258:        <code>HAVE_TCGETATTR</code> defines, then proceed to the next system.
                    259:        This technique separates features tests from specific OSes.
                    260:        In a hurry, another porter can just add the whole set of
                    261:        <code>-DHAVE_XXX</code> defines to the Makefile.  One may also write
                    262:        or add to a configure script to check for that feature and add it
                    263:        automatically.  As an example not to follow, check nethack 3.2.2
                    264:        source: it assumes loads of things based on the system type.  Most
                    265:        of these assumptions are obsolete and no longer reflect reality:
                    266:        POSIX functions are more useful than older BSD versus SystemV
                    267:        differences, to the point that some traditional bsd functions are
1.10      espie     268:        now only supported through compatibility libraries.
                    269:
                    270:    <li>Avoid include files that include other includes that... First, because
1.15      espie     271:        this is inefficient. Your project will end up including a file that
                    272:        includes everything.  Also, because it makes some problems difficult
                    273:        to fix. It becomes harder to <em>not</em> include one particular file
                    274:        at a given point.
1.10      espie     275:
                    276:    <li>Avoid bizarre macro tricks.  Undefining a macro that was defined by a
                    277:        header file is a bad idea.  Defining macros to get some specific behavior
1.15      espie     278:        from an include file is also a bad idea: compilation modes should be
                    279:        global.  If you want POSIX behavior, say so, and
                    280:        <code>#define POSIX_C_SOURCE</code>
1.10      espie     281:        throughout the whole project, not when you feel like it.
                    282:
                    283:    <li>Don't ever write system function prototypes.  All modern systems,
                    284:        OpenBSD included, have a standard location for these prototypes. Likely
1.15      espie     285:        places include <code>unistd.h</code>, <code>fcntl.h</code> or
                    286:        <code>termios.h</code>.
                    287:        The man page frequently states where the prototype can be found.
                    288:        You might need another slew of <code>HAVE_XXX</code> macros to
                    289:        procure the right file.  Don't worry about including the same file
                    290:        twice, include files have guards that prevent all kinds of nastiness.<br>
1.10      espie     291:        If some broken system needs you to write the prototype, don't impose
1.15      espie     292:        on all other systems. Roll-your-own prototypes will break because they
                    293:        may use types that are equivalent on your system, but are not portable
                    294:        to other systems (<code>unsigned long</code> instead of
                    295:        <code>size_t</code>), or get some <code>const</code> status wrong.
                    296:        Also, some compilers, such as OpenBSD's own gcc,
1.10      espie     297:        are able to do a better job with some very frequent functions such as
                    298:        <code>strlen</code> if you include the right header file.
                    299:
                    300:    <li>Don't use the name of a standard system function for anything else.
1.15      espie     301:        If you want to write your own function, give it its own name, and
                    302:        call that function everywhere.  If you wish to revert to the
                    303:        default system function, you just need to comment your code out,
                    304:        and define your own name to the system function. Don't do it the
                    305:        other way round. Code should look like this
1.10      espie     306: <pre>
                    307:        /* prototype part */
                    308:        #ifdef USE_OWN_GCVT
                    309:        char *foo_gcvt(double number, size_t ndigit, char *buf);
                    310:        #else
                    311:        /* include correct file */
                    312:        #include &lt;stdlib.h&gt;
                    313:        /* use system function */
                    314:        #define foo_gcvt  gcvt
                    315:        #endif
                    316:
                    317:        /* definition part */
                    318:        #ifdef USE_OWN_GCVT
                    319:        char *foo_gcvt(double number, size_t ndigit, char *buf)
                    320:           {
1.15      espie     321:           /* proper definition */
                    322:           }
1.10      espie     323:
                    324:        /* typical use */
                    325:        s = foo_gcvt(n, 15, b);
                    326:        </pre>
1.1       marc      327:   </ul>
1.35      naddy     328:   <h3><font color="#0000e0"><a name="Other">Other Helpful Hints</a></font></h3>
1.1       marc      329:   <ul>
1.15      espie     330:    <li>Recent versions of <code>bsd.port.mk</code> set the installers
                    331:        path. Specifically, they set <code>/usr/bin</code> and
                    332:        <code>/bin</code> to be searched <em>before</em>
                    333:        <code>/usr/local/bin</code> and <code>/usr/X11R6/bin</code>.
1.19      rohee     334:    <li>Do <em>NOT</em> generate shared libraries if
1.49      espie     335:        <code>${NO_SHARED_LIBS}</code> is set to yes (beware, it can be defined
1.21      rohee     336:        only after inclusion of <code>bsd.port.mk</code>). If your port has
                    337:        a GNU configure simply add the line
                    338:        <code>CONFIGURE_ARGS += ${CONFIGURE_SHARED}</code> to the Makefile.
1.44      pvalchev  339:    <li>It is OK to rely on a feature that appeared in a recent version of
                    340:        <code>bsd.port.mk</code>, as people are supposed to update their
                    341:        whole ports tree, including <code>bsd.port.mk</code>.
                    342:        NEED_VERSION is now obsolete.
1.49      espie     343:    <li>Prefer using <code>update-plist</code> to generate and update
                    344:        packing-lists instead of doing things manually.
                    345:        You can comment unwanted lines out.
                    346:        <code>update-plist</code> can detect most file types and copy most
                    347:        extra annotations correctly.
1.1       marc      348:    <li>In OpenBSD <code>curses.h/libcurses/libtermlib</code> are the
                    349:        ``new curses''.  Change:<br>
1.15      espie     350:        <code>ncurses.h ==&gt; curses.h</code><br>
                    351:        ``old (BSD) curses'' is available by defining
                    352:        <code>_USE_OLD_CURSES_</code>
1.11      millert   353:        before including <code>curses.h</code> (usually in a Makefile) and
1.15      espie     354:        linking with <code>-locurses</code>.
1.11      millert   355:    <li>In OpenBSD, terminal discipline has been upgraded from the older BSD
                    356:        <code>sgtty</code> to the newer POSIX <code>tcgetattr</code> family.
1.15      espie     357:        Avoid the older style in new code.  Some code may define
                    358:        <code>tcgetattr</code> to be a synonym for the older
                    359:        <code>sgtty</code>, but this is at best a stopgap measure on OpenBSD.
                    360:        The <code>xterm</code> source code is a very good example of
                    361:        what not to do.  Try to get your system functionality right: you
                    362:        want a type that remembers the state of your terminal
                    363:        (possible typedef), you want a function that extracts the current
                    364:        state, and a function that sets the new state.
                    365:        Functions that modify this state are more difficult, as they tend
                    366:        to vary depending upon the system.  Also, don't forget that you will
                    367:        have to handle cases where you are not connected to a terminal,
                    368:        and that you need to handle signals: not only termination, but
                    369:        also background (<code>SIGTSTP</code>). You should always leave
                    370:        the terminal in a sane state.  Do your tests under an older shell,
                    371:        such as sh, which does not reset the terminal in any way at
1.10      espie     372:        program's termination.
1.15      espie     373:    <li>The newer termcap/terminfo and curses, as included with OpenBSD,
                    374:        include standard sequences for controlling color terminals.  You
                    375:        should use these if possible, reverting to standard ANSI color
                    376:        sequences on other systems.  However, some terminal descriptions
                    377:        have not been updated yet, and you may need to be able to specify
                    378:        these sequences manually.  This is the way vim handles it.  This is
                    379:        not strictly necessary. Except for privileged programs, it is
                    380:        generally possible to override a termcap definition through the
1.10      espie     381:        <code>TERMCAP</code> variable and get it to work properly.
1.15      espie     382:    <li>Signal semantics are tricky, and vary from one system to another.
                    383:        Use <code>sigaction</code> to ensure a specific semantics, along
                    384:        with other system calls referenced in the corresponding  manpage.
1.1       marc      385:   </ul>
                    386:   <hr>
1.6       pauls     387:   <a href="index.html"><img height=24 width=24 src=back.gif border=0 alt=OpenBSD></a>
1.20      rohee     388:   <a href="mailto:www@openbsd.org">www@openbsd.org</a>
1.51    ! espie     389: <br><small>$OpenBSD: porting.html,v 1.50 2004/11/26 15:26:10 alek Exp $</small>
1.1       marc      390:  </body>
                    391: </html>