xref: /freebsd/usr.sbin/sysconf/sysconf.8 (revision a6deeaa2fb3b28a61ae56a85f2275f67fcf23262)
1.\" Copyright (c) 2013-2026 Devin Teske <dteske@FreeBSD.org>
2.\" Copyright (c) 2021-2026 Faraz Vahedi <kfv@FreeBSD.org>
3.\"
4.\" SPDX-License-Identifier: BSD-2-Clause
5.\"
6.Dd September 15, 2026
7.Dt SYSCONF 8
8.Os
9.Sh NAME
10.Nm sysconf
11.Nd read and modify system configuration files
12.Sh SYNOPSIS
13.Nm
14.Ar target
15.Op Fl AcDeFinNqsvVx
16.Op Fl j Ar jail | Fl R Ar dir
17.Op Fl f Ar file | Fl k Ar module
18.Ar name Ns Op Ns Oo +|- Oc Ns = Ns Ar value
19.Ar ...
20.Nm
21.Ar target
22.Op Fl ADeFnNqvV
23.Op Fl j Ar jail | Fl R Ar dir
24.Op Fl f Ar file | Fl k Ar module
25.Fl a
26.Nm
27.Ar target
28.Op Fl AaDinNq
29.Op Fl j Ar jail | Fl R Ar dir
30.Fl d
31.Op Ar name ...
32.Nm
33.Ar target
34.Op Fl E
35.Op Fl j Ar jail | Fl R Ar dir
36.Op Fl k Ar module
37.Fl l | L
38.Nm
39.Cm rc
40.Op Ar sysrc_argument ...
41.Sh DESCRIPTION
42The
43.Nm
44utility reads and modifies the system configuration files of the base
45system,
46completing the native configuration trinity alongside
47.Xr sysctl 8
48.Pq kernel state
49and
50.Xr sysrc 8
51.Pq Xr rc.conf 5 .
52The first positional argument selects a
53.Ar target
54keyword;
55options are equally accepted before it.
56Each target is documented on its own page
57.Pq see Sx TARGETS ;
58shared options and assignment syntax are documented here.
59.Ss Assignment syntax
60A
61.Ar name
62alone reads the current value of the directive,
63while
64.Ar name Ns = Ns Ar value
65atomically writes it.
66Writes echo
67.Ql name: old -> new
68when the stored value changes,
69or
70.Ql name: value (unchanged)
71when it is already set as requested
72.Pq the file is left untouched in that case .
73With
74.Fl e
75those echoes use
76.Ql name=...
77instead of
78.Ql name: ...
79.Pq matching read output .
80The echo is suppressed by
81.Fl q ;
82.Fl c
83writes nothing to stdout.
84A directive not previously set anywhere shows an empty old value.
85.Pp
86On the
87.Cm make
88and
89.Cm src
90targets, a
91.Ql WITH_*
92or
93.Ql WITHOUT_*
94build knob
95.Pq presence matters; Xr src.conf 5 ignores the value
96is shown as
97.Ql name (present)
98when defined
99.Po
100any value, including
101.Ql =
102or
103.Ql =t
104.Pc ,
105rather than printing the value after the colon;
106.Fl e
107prints the real assignment
108.Po
109e.g.
110.Ql name=
111or
112.Ql name=t
113.Pc ,
114and
115.Fl n
116prints that same value alone
117.Pq empty when the assignment is Ql name= .
118Setting such a knob with
119.Fl s
120echoes
121.Ql name: (not present) -> (present)
122.Po
123or
124.Ql (present) (unchanged)
125when it is already defined
126.Pc .
127An explicit
128.Ar name Ns =
129.Pq including empty
130always writes the requested value;
131a change of placeholder while the knob stays defined echoes
132.Ql name: old -> new
133like other assignments.
134A write of
135.Ql WITH_ Ns Ar foo Ns =no
136.Pq exact lowercase Ql no
137is still performed but warns to use
138.Ql WITHOUT_ Ns Ar foo Ns =1
139instead.
140That message matches
141.Pa share/mk/bsd.mkopt.mk
142and is emitted here as a precursor so a bad
143.Xr make.conf 5
144or
145.Xr src.conf 5
146assignment is caught at write time.
147The same advisory is printed on reads
148.Po
149named queries and
150.Fl a
151dump
152.Pc ,
153with
154.Ql file:line:
155when the authoritative statement is known, so an existing
156.Ql WITH_* Ns =no
157is not overlooked when presence display shows only
158.Ql (present) .
159.Fl q
160suppresses the read-time form.
161.Xr make 1
162itself typically warns later during a
163.Pa /usr/src
164build, when
165.Pa bsd.opts.mk
166.Pq or Pa src.opts.mk
167reloads
168.Pa bsd.mkopt.mk
169for recognized options such as
170.Va MANCOMPRESS .
171The same
172.Xr make.conf 5
173line stays silent for a bare
174.Xr make 1
175.Pq e.g. Fl C Pa /tmp
176or for ports, which do not run that option pass.
177.Ql WITHOUT_* Ns =no ,
178.Ql WITH_* Ns =NO ,
179and other values do not warn here or there.
180.Va WITHOUT_MODULES
181is not a presence knob
182.Pq its value is a module list
183and is excluded from
184.Fl s
185and presence display.
186.Pp
187For directives whose value is a space-separated list
188.Po
189.Va kld_list Ns -style ;
190see for example
191.Va kernels
192in
193.Xr loader.conf 5
194.Pc ,
195.Ar name Ns += Ns Ar word
196appends each given word not already present and
197.Ar name Ns -= Ns Ar word
198strikes each given word,
199after the fashion of
200.Xr sysrc 8 .
201Striking words from a directive set nowhere is reported like any other
202unknown directive.
203.Pp
204For
205.Xr make 1 Ns -syntax
206targets
207.Po
208.Cm make
209and
210.Cm src ;
211see
212.Xr sysconf-make 8
213and
214.Xr sysconf-src 8
215.Pc ,
216.Ql +=
217is instead the
218.Xr make 1
219append operator and
220.Ql -=
221strikes words from the last matching assignment fragment.
222.Pp
223Files are never modified in place:
224updates are streamed to a temporary file which is flushed to stable storage
225and atomically renamed over the target
226.Pq see Xr bsdconf_put 3 .
227How multi-file targets choose the file to read or rewrite is documented in
228.Xr sysconf-targets 8 .
229.Sh TARGETS
230The following target keywords are supported:
231.Bl -tag -width indent
232.It Cm loader
233Boot loader configuration
234.Pq Xr loader.conf 5 .
235See
236.Xr sysconf-loader 8 .
237.It Cm sysctl
238Kernel state set at boot
239.Pq Xr sysctl.conf 5 .
240See
241.Xr sysconf-sysctl 8 .
242.It Cm make
243System-wide
244.Xr make 1
245settings
246.Pq Pa /etc/make.conf .
247See
248.Xr sysconf-make 8 .
249.It Cm src
250The
251.Pa /usr/src
252build triad
253.Pq Pa src-env.conf , make.conf , src.conf .
254See
255.Xr sysconf-src 8 .
256.It Cm rc
257Pass-through to
258.Xr sysrc 8 .
259See
260.Xr sysconf-rc 8 .
261.It Cm generic
262Foreign or unknown format;
263requires
264.Fl f .
265See
266.Xr sysconf-generic 8 .
267.El
268.Pp
269Cross-cutting rules for multi-file sourcing,
270defaults,
271and where writes versus removals land are in
272.Xr sysconf-targets 8 .
273Built-in format descriptors and file-list discovery are in
274.Xr bsdconf_format 3 .
275.Sh OPTIONS
276The options are as follows:
277.Bl -tag -width indent
278.It Fl A
279Widen dump scope to include directives still at their system default
280.Po
281named reads always reflect the defaults;
282see
283.Xr sysconf-targets 8
284.Pc .
285With no
286.Ar name
287arguments,
288dumps everything
289.Po
290as
291.Fl a ,
292defaults included
293.Pc .
294.Pp
295Combined with
296.Fl D ,
297the scoping of
298.Fl D
299wins and
300.Fl A
301retains only its dump-implying role,
302so
303.Ql -ADd
304describes all defaults and only defaults,
305as in
306.Xr sysrc 8 .
307Only valid for targets with a defaults file
308.Pq see Xr sysconf-loader 8 .
309.It Fl a
310Dump all configured directives from the target:
311the union of the target's files,
312wherein directives in later files override earlier ones.
313Directives whose value still comes from the defaults file alone are out
314of scope
315.Pq widen with Fl A .
316.It Fl c
317Check mode.
318For each
319.Ar name Ns = Ns Ar value
320argument,
321compare the effective value against
322.Ar value
323without modifying any file
324.Po
325with
326.Fl x ,
327check that
328.Ar name
329is absent
330.Pc .
331Exit with success if no changes would be required,
332else error.
333.It Fl D
334Consult only the target's defaults file,
335reporting the system default value of each
336.Ar name
337.Po
338or, with
339.Fl a ,
340dumping every default
341.Pc .
342Defaults are read-only;
343combining
344.Fl D
345with an assignment is an error.
346Only valid for targets with a defaults file
347.Pq see Xr sysconf-loader 8 .
348.It Fl d
349Show the description of each
350.Ar name
351instead of its value.
352.Pp
353For targets with a defaults file,
354the description is the inline comment trailing the directive's default
355assignment,
356continued across subsequent lines of whitespace followed by a comment
357character.
358A commented-out default
359.Pq e.g., Ql #comconsole_speed=\(dq115200\(dq # Set the ...
360still yields its description.
361For the
362.Ql sysctl
363target,
364descriptions come from the running kernel
365.Po
366as with
367.Xr sysctl 8
368.Fl d ;
369see
370.Xr sysconf-sysctl 8
371.Pc .
372.Pp
373Combined with
374.Fl a ,
375.Fl A ,
376or
377.Fl D ,
378dumps the description of every directive in scope
379.Po
380of the configured directives,
381of everything defaults included,
382or of the defaults alone,
383respectively
384.Pc ,
385after the fashion of
386.Xr sysrc 8
387.Fl \&Ad .
388A directive the defaults never mention prints an empty description.
389.It Fl E
390With
391.Fl l
392or
393.Fl L ,
394list only files that exist on disk.
395.It Fl e
396Print values in
397.Ar name Ns = Ns Ar value
398format,
399suitable for feeding back into the configuration file.
400Applies to both reads and the informational echo from assignments
401.Po
402replacing the default
403.Ql name: value
404form;
405changed writes use
406.Ql name=old # -> new ,
407matching
408.Xr sysrc 8
409.Pc .
410For the
411.Ql loader
412target the value is quoted.
413.It Fl F
414Show the pathname of the file holding each directive's effective
415.Pq authoritative
416value instead of the value itself.
417For a directive still at its system default,
418this truthfully names the defaults file.
419.It Fl f Ar file
420Operate on
421.Ar file ,
422in the format of the
423.Ar target
424keyword,
425instead of the target's standard files;
426mutually exclusive with
427.Fl k .
428For read operations
429.Ar file
430may be a non-seekable stream
431.Po
432a fifo or
433.Pa /dev/stdin ,
434for example,
435spooled to a temporary automatically
436.Pc ;
437write operations require a regular file.
438A
439.Ar file
440of
441.Ql -
442means standard input
443.Pq a synonym for Pa /dev/stdin ,
444exempt from
445.Fl R .
446See
447.Xr sysconf-targets 8
448and
449.Xr sysconf-generic 8 .
450.It Fl h , Fl Fl help
451Print a short usage statement
452.Pq or, for the long form, the full option summary
453to stderr and exit.
454.It Fl Fl version
455Print
456.Nm
457and linked
458.Xr bsdconf 3
459versions and exit.
460.It Fl i
461Ignore unknown names
462.Pq and suppress the warning when writing an unknown sysctl OID .
463.It Fl j Ar jail
464Operate within the jail
465.Ar jail
466.Pq name or numeric id ;
467mutually exclusive with
468.Fl R .
469.It Fl k Ar module
470Include the kernel module drop-in file for
471.Ar module
472in the target's file list
473.Pq e.g., Pa /etc/sysctl.kld.d/ Ns Ar module Ns Pa .conf .
474Only valid for targets with a module drop-in directory
475.Pq see Xr sysconf-sysctl 8 .
476.It Fl l
477List the pathnames of the files backing the target,
478in sourcing order,
479and exit.
480The read-only defaults file is never listed
481.Po
482.Fl l
483enumerates only files
484.Nm sysconf
485may modify;
486see
487.Xr sysconf-targets 8
488.Pc .
489.It Fl L
490Like
491.Fl l ,
492but additionally list every drop-in candidate:
493for targets with a module drop-in directory,
494one candidate per loaded kernel module
495.Pq whether or not the file exists yet
496plus any drop-in already on disk.
497The read-only defaults file is likewise never listed.
498.It Fl n
499Show only directive values,
500not their names.
501.It Fl N
502Show only directive names,
503not their values.
504.It Fl q
505Quiet.
506Suppress warnings about unknown directives and the
507.Ql old -> new
508echo of write operations.
509.It Fl R Ar dir
510Operate within the root directory
511.Ar dir
512rather than
513.Pa / ;
514mutually exclusive with
515.Fl j .
516.It Fl s
517Set empty
518.Ql WITH_*
519and
520.Ql WITHOUT_*
521build knobs on the
522.Cm make
523and
524.Cm src
525targets
526.Po
527equivalent to
528.Ar name Ns =
529with no value;
530see
531.Xr sysconf-make 8
532and
533.Xr sysconf-src 8
534.Pc .
535Each bare
536.Ar name
537must begin with
538.Ql WITH_
539or
540.Ql WITHOUT_ .
541An already-present knob
542.Pq any value
543is left unchanged by
544.Fl s .
545An explicit
546.Ar name Ns =
547including empty always writes.
548Mutually exclusive with
549.Fl x .
550.It Fl v
551Verbose.
552Print the pathname of the configuration file holding the final effective
553value
554.Pq the last file in sourcing order that assigned the directive .
555.It Fl V
556Trail.
557For each named read
558.Pq and for Fl a ,
559print every assignment step that contributed to the effective value:
560.Ql file:line: nameopfragment ,
561and when the running effective value differs from the fragment,
562.Ql -> effective .
563.Pp
564For writes, print the same
565.Ql file:line:
566shape for the change:
567.Ql file:line: name=old -> name=new ,
568.Ql name=value (unchanged) ,
569.Ql name=value (added)
570when a new statement is created,
571or
572.Ql nameopfragment (removed)
573when a statement is deleted,
574using the statement operator
575.Ql = / += / ...
576as appropriate .
577.Pp
578Uses the same accumulation model as ordinary reads
579.Pq make(1) `+=' et al. ,
580so the last effective value matches
581.Fl v
582and,
583for linear conf files without
584.Ql .if ,
585.Nm make Fl V
586.Pq see Xr sysconf-make 8 and Xr sysconf-src 8 .
587.It Fl x
588Remove the named directive(s) from every file of the target listing them
589.Pq see Xr sysconf-targets 8 .
590With
591.Fl v
592or
593.Fl V ,
594a successful removal echoes
595.Ql name (removed)
596.Pq or a trail form with Fl V .
597.El
598.Sh ENVIRONMENT
599.Bl -tag -width "LOADER_DEFAULTS"
600.It Ev LOADER_DEFAULTS
601Defaults file for the
602.Ql loader
603target;
604see
605.Xr sysconf-loader 8 .
606.It Ev SRC_ENV_CONF , Ev __MAKE_CONF , Ev SRCCONF
607Paths for the
608.Cm src
609triad;
610see
611.Xr sysconf-src 8 .
612.El
613.Sh FILES
614See the per-target manuals
615.Pq Xr sysconf-loader 8 , Xr sysconf-sysctl 8 , Xr sysconf-make 8 , Xr sysconf-src 8
616for the files each keyword consults.
617Common paths include
618.Pa /boot/loader.conf ,
619.Pa /etc/sysctl.conf ,
620.Pa /etc/make.conf ,
621and
622.Pa /etc/src.conf .
623.Sh EXIT STATUS
624.Ex -std
625In check mode
626.Pq Fl c ,
627an exit status of zero means no changes are required.
628.Sh EXAMPLES
629Read and set a boot loader directive:
630.Pp
631.Dl sysconf loader zfs_load
632.Dl sysconf loader zfs_load=\(dqYES\(dq
633.Pp
634Raise a sysctl applied at boot:
635.Pp
636.Dl sysconf sysctl kern.maxfiles=65536
637.Pp
638List files backing the loader target:
639.Pp
640.Dl sysconf loader -l
641.Pp
642Append to a space-separated list:
643.Pp
644.Dl sysconf loader kernels+=kernel_test
645.Pp
646Append a
647.Xr make 1
648flag and set a
649.Pa src.conf
650knob:
651.Pp
652.Dl sysconf make CFLAGS+=-DDEBUG
653.Dl sysconf src -s WITHOUT_LLDB
654.Dl sysconf src WITHOUT_LLDB=
655.Pp
656Further examples for each target appear in
657.Xr sysconf-loader 8 ,
658.Xr sysconf-sysctl 8 ,
659.Xr sysconf-make 8 ,
660.Xr sysconf-src 8 ,
661.Xr sysconf-rc 8 ,
662and
663.Xr sysconf-generic 8 .
664.Sh SEE ALSO
665.Xr bsdconf 3 ,
666.Xr bsdconf_format 3 ,
667.Xr bsdconf_put 3 ,
668.Xr loader.conf 5 ,
669.Xr src.conf 5 ,
670.Xr sysctl.conf 5 ,
671.Xr jail 8 ,
672.Xr sysconf-generic 8 ,
673.Xr sysconf-loader 8 ,
674.Xr sysconf-make 8 ,
675.Xr sysconf-rc 8 ,
676.Xr sysconf-src 8 ,
677.Xr sysconf-sysctl 8 ,
678.Xr sysconf-targets 8 ,
679.Xr sysctl 8 ,
680.Xr sysrc 8
681.Sh HISTORY
682The
683.Nm
684utility first appeared in
685.Fx 16.0 .
686.Sh AUTHORS
687.An Devin Teske Aq Mt dteske@FreeBSD.org
688.An Faraz Vahedi Aq Mt kfv@FreeBSD.org
689.Sh SECURITY CONSIDERATIONS
690Read-only invocations
691.Po
692including
693.Fl c
694checks, which never modify files
695.Pc
696run inside a
697.Xr capsicum 4
698sandbox:
699the backing files are opened first and the process then relinquishes all
700other capabilities before any file content is parsed.
701.Pp
702Write operations replace files atomically and never in place;
703see the
704.Sx SECURITY CONSIDERATIONS
705section of
706.Xr bsdconf_put 3
707for the properties of the write transaction.
708