1.\" Copyright (c) 2013-2026 Devin Teske <dteske@FreeBSD.org> 2.\" Copyright (c) 2021-2026 Faraz Vahedi <kfv@FreeBSD.org> 3.\" 4.\" SPDX-License-Identifier: BSD-2-Clause 5.\" 6.Dd September 15, 2026 7.Dt SYSCONF 8 8.Os 9.Sh NAME 10.Nm sysconf 11.Nd read and modify system configuration files 12.Sh SYNOPSIS 13.Nm 14.Ar target 15.Op Fl AcDeFinNqsvVx 16.Op Fl j Ar jail | Fl R Ar dir 17.Op Fl f Ar file | Fl k Ar module 18.Ar name Ns Op Ns Oo +|- Oc Ns = Ns Ar value 19.Ar ... 20.Nm 21.Ar target 22.Op Fl ADeFnNqvV 23.Op Fl j Ar jail | Fl R Ar dir 24.Op Fl f Ar file | Fl k Ar module 25.Fl a 26.Nm 27.Ar target 28.Op Fl AaDinNq 29.Op Fl j Ar jail | Fl R Ar dir 30.Fl d 31.Op Ar name ... 32.Nm 33.Ar target 34.Op Fl E 35.Op Fl j Ar jail | Fl R Ar dir 36.Op Fl k Ar module 37.Fl l | L 38.Nm 39.Cm rc 40.Op Ar sysrc_argument ... 41.Sh DESCRIPTION 42The 43.Nm 44utility reads and modifies the system configuration files of the base 45system, 46completing the native configuration trinity alongside 47.Xr sysctl 8 48.Pq kernel state 49and 50.Xr sysrc 8 51.Pq Xr rc.conf 5 . 52The first positional argument selects a 53.Ar target 54keyword; 55options are equally accepted before it. 56Each target is documented on its own page 57.Pq see Sx TARGETS ; 58shared options and assignment syntax are documented here. 59.Ss Assignment syntax 60A 61.Ar name 62alone reads the current value of the directive, 63while 64.Ar name Ns = Ns Ar value 65atomically writes it. 66Writes echo 67.Ql name: old -> new 68when the stored value changes, 69or 70.Ql name: value (unchanged) 71when it is already set as requested 72.Pq the file is left untouched in that case . 73With 74.Fl e 75those echoes use 76.Ql name=... 77instead of 78.Ql name: ... 79.Pq matching read output . 80The echo is suppressed by 81.Fl q ; 82.Fl c 83writes nothing to stdout. 84A directive not previously set anywhere shows an empty old value. 85.Pp 86On the 87.Cm make 88and 89.Cm src 90targets, a 91.Ql WITH_* 92or 93.Ql WITHOUT_* 94build knob 95.Pq presence matters; Xr src.conf 5 ignores the value 96is shown as 97.Ql name (present) 98when defined 99.Po 100any value, including 101.Ql = 102or 103.Ql =t 104.Pc , 105rather than printing the value after the colon; 106.Fl e 107prints the real assignment 108.Po 109e.g. 110.Ql name= 111or 112.Ql name=t 113.Pc , 114and 115.Fl n 116prints that same value alone 117.Pq empty when the assignment is Ql name= . 118Setting such a knob with 119.Fl s 120echoes 121.Ql name: (not present) -> (present) 122.Po 123or 124.Ql (present) (unchanged) 125when it is already defined 126.Pc . 127An explicit 128.Ar name Ns = 129.Pq including empty 130always writes the requested value; 131a change of placeholder while the knob stays defined echoes 132.Ql name: old -> new 133like other assignments. 134A write of 135.Ql WITH_ Ns Ar foo Ns =no 136.Pq exact lowercase Ql no 137is still performed but warns to use 138.Ql WITHOUT_ Ns Ar foo Ns =1 139instead. 140That message matches 141.Pa share/mk/bsd.mkopt.mk 142and is emitted here as a precursor so a bad 143.Xr make.conf 5 144or 145.Xr src.conf 5 146assignment is caught at write time. 147The same advisory is printed on reads 148.Po 149named queries and 150.Fl a 151dump 152.Pc , 153with 154.Ql file:line: 155when the authoritative statement is known, so an existing 156.Ql WITH_* Ns =no 157is not overlooked when presence display shows only 158.Ql (present) . 159.Fl q 160suppresses the read-time form. 161.Xr make 1 162itself typically warns later during a 163.Pa /usr/src 164build, when 165.Pa bsd.opts.mk 166.Pq or Pa src.opts.mk 167reloads 168.Pa bsd.mkopt.mk 169for recognized options such as 170.Va MANCOMPRESS . 171The same 172.Xr make.conf 5 173line stays silent for a bare 174.Xr make 1 175.Pq e.g. Fl C Pa /tmp 176or for ports, which do not run that option pass. 177.Ql WITHOUT_* Ns =no , 178.Ql WITH_* Ns =NO , 179and other values do not warn here or there. 180.Va WITHOUT_MODULES 181is not a presence knob 182.Pq its value is a module list 183and is excluded from 184.Fl s 185and presence display. 186.Pp 187For directives whose value is a space-separated list 188.Po 189.Va kld_list Ns -style ; 190see for example 191.Va kernels 192in 193.Xr loader.conf 5 194.Pc , 195.Ar name Ns += Ns Ar word 196appends each given word not already present and 197.Ar name Ns -= Ns Ar word 198strikes each given word, 199after the fashion of 200.Xr sysrc 8 . 201Striking words from a directive set nowhere is reported like any other 202unknown directive. 203.Pp 204For 205.Xr make 1 Ns -syntax 206targets 207.Po 208.Cm make 209and 210.Cm src ; 211see 212.Xr sysconf-make 8 213and 214.Xr sysconf-src 8 215.Pc , 216.Ql += 217is instead the 218.Xr make 1 219append operator and 220.Ql -= 221strikes words from the last matching assignment fragment. 222.Pp 223Files are never modified in place: 224updates are streamed to a temporary file which is flushed to stable storage 225and atomically renamed over the target 226.Pq see Xr bsdconf_put 3 . 227How multi-file targets choose the file to read or rewrite is documented in 228.Xr sysconf-targets 8 . 229.Sh TARGETS 230The following target keywords are supported: 231.Bl -tag -width indent 232.It Cm loader 233Boot loader configuration 234.Pq Xr loader.conf 5 . 235See 236.Xr sysconf-loader 8 . 237.It Cm sysctl 238Kernel state set at boot 239.Pq Xr sysctl.conf 5 . 240See 241.Xr sysconf-sysctl 8 . 242.It Cm make 243System-wide 244.Xr make 1 245settings 246.Pq Pa /etc/make.conf . 247See 248.Xr sysconf-make 8 . 249.It Cm src 250The 251.Pa /usr/src 252build triad 253.Pq Pa src-env.conf , make.conf , src.conf . 254See 255.Xr sysconf-src 8 . 256.It Cm rc 257Pass-through to 258.Xr sysrc 8 . 259See 260.Xr sysconf-rc 8 . 261.It Cm generic 262Foreign or unknown format; 263requires 264.Fl f . 265See 266.Xr sysconf-generic 8 . 267.El 268.Pp 269Cross-cutting rules for multi-file sourcing, 270defaults, 271and where writes versus removals land are in 272.Xr sysconf-targets 8 . 273Built-in format descriptors and file-list discovery are in 274.Xr bsdconf_format 3 . 275.Sh OPTIONS 276The options are as follows: 277.Bl -tag -width indent 278.It Fl A 279Widen dump scope to include directives still at their system default 280.Po 281named reads always reflect the defaults; 282see 283.Xr sysconf-targets 8 284.Pc . 285With no 286.Ar name 287arguments, 288dumps everything 289.Po 290as 291.Fl a , 292defaults included 293.Pc . 294.Pp 295Combined with 296.Fl D , 297the scoping of 298.Fl D 299wins and 300.Fl A 301retains only its dump-implying role, 302so 303.Ql -ADd 304describes all defaults and only defaults, 305as in 306.Xr sysrc 8 . 307Only valid for targets with a defaults file 308.Pq see Xr sysconf-loader 8 . 309.It Fl a 310Dump all configured directives from the target: 311the union of the target's files, 312wherein directives in later files override earlier ones. 313Directives whose value still comes from the defaults file alone are out 314of scope 315.Pq widen with Fl A . 316.It Fl c 317Check mode. 318For each 319.Ar name Ns = Ns Ar value 320argument, 321compare the effective value against 322.Ar value 323without modifying any file 324.Po 325with 326.Fl x , 327check that 328.Ar name 329is absent 330.Pc . 331Exit with success if no changes would be required, 332else error. 333.It Fl D 334Consult only the target's defaults file, 335reporting the system default value of each 336.Ar name 337.Po 338or, with 339.Fl a , 340dumping every default 341.Pc . 342Defaults are read-only; 343combining 344.Fl D 345with an assignment is an error. 346Only valid for targets with a defaults file 347.Pq see Xr sysconf-loader 8 . 348.It Fl d 349Show the description of each 350.Ar name 351instead of its value. 352.Pp 353For targets with a defaults file, 354the description is the inline comment trailing the directive's default 355assignment, 356continued across subsequent lines of whitespace followed by a comment 357character. 358A commented-out default 359.Pq e.g., Ql #comconsole_speed=\(dq115200\(dq # Set the ... 360still yields its description. 361For the 362.Ql sysctl 363target, 364descriptions come from the running kernel 365.Po 366as with 367.Xr sysctl 8 368.Fl d ; 369see 370.Xr sysconf-sysctl 8 371.Pc . 372.Pp 373Combined with 374.Fl a , 375.Fl A , 376or 377.Fl D , 378dumps the description of every directive in scope 379.Po 380of the configured directives, 381of everything defaults included, 382or of the defaults alone, 383respectively 384.Pc , 385after the fashion of 386.Xr sysrc 8 387.Fl \&Ad . 388A directive the defaults never mention prints an empty description. 389.It Fl E 390With 391.Fl l 392or 393.Fl L , 394list only files that exist on disk. 395.It Fl e 396Print values in 397.Ar name Ns = Ns Ar value 398format, 399suitable for feeding back into the configuration file. 400Applies to both reads and the informational echo from assignments 401.Po 402replacing the default 403.Ql name: value 404form; 405changed writes use 406.Ql name=old # -> new , 407matching 408.Xr sysrc 8 409.Pc . 410For the 411.Ql loader 412target the value is quoted. 413.It Fl F 414Show the pathname of the file holding each directive's effective 415.Pq authoritative 416value instead of the value itself. 417For a directive still at its system default, 418this truthfully names the defaults file. 419.It Fl f Ar file 420Operate on 421.Ar file , 422in the format of the 423.Ar target 424keyword, 425instead of the target's standard files; 426mutually exclusive with 427.Fl k . 428For read operations 429.Ar file 430may be a non-seekable stream 431.Po 432a fifo or 433.Pa /dev/stdin , 434for example, 435spooled to a temporary automatically 436.Pc ; 437write operations require a regular file. 438A 439.Ar file 440of 441.Ql - 442means standard input 443.Pq a synonym for Pa /dev/stdin , 444exempt from 445.Fl R . 446See 447.Xr sysconf-targets 8 448and 449.Xr sysconf-generic 8 . 450.It Fl h , Fl Fl help 451Print a short usage statement 452.Pq or, for the long form, the full option summary 453to stderr and exit. 454.It Fl Fl version 455Print 456.Nm 457and linked 458.Xr bsdconf 3 459versions and exit. 460.It Fl i 461Ignore unknown names 462.Pq and suppress the warning when writing an unknown sysctl OID . 463.It Fl j Ar jail 464Operate within the jail 465.Ar jail 466.Pq name or numeric id ; 467mutually exclusive with 468.Fl R . 469.It Fl k Ar module 470Include the kernel module drop-in file for 471.Ar module 472in the target's file list 473.Pq e.g., Pa /etc/sysctl.kld.d/ Ns Ar module Ns Pa .conf . 474Only valid for targets with a module drop-in directory 475.Pq see Xr sysconf-sysctl 8 . 476.It Fl l 477List the pathnames of the files backing the target, 478in sourcing order, 479and exit. 480The read-only defaults file is never listed 481.Po 482.Fl l 483enumerates only files 484.Nm sysconf 485may modify; 486see 487.Xr sysconf-targets 8 488.Pc . 489.It Fl L 490Like 491.Fl l , 492but additionally list every drop-in candidate: 493for targets with a module drop-in directory, 494one candidate per loaded kernel module 495.Pq whether or not the file exists yet 496plus any drop-in already on disk. 497The read-only defaults file is likewise never listed. 498.It Fl n 499Show only directive values, 500not their names. 501.It Fl N 502Show only directive names, 503not their values. 504.It Fl q 505Quiet. 506Suppress warnings about unknown directives and the 507.Ql old -> new 508echo of write operations. 509.It Fl R Ar dir 510Operate within the root directory 511.Ar dir 512rather than 513.Pa / ; 514mutually exclusive with 515.Fl j . 516.It Fl s 517Set empty 518.Ql WITH_* 519and 520.Ql WITHOUT_* 521build knobs on the 522.Cm make 523and 524.Cm src 525targets 526.Po 527equivalent to 528.Ar name Ns = 529with no value; 530see 531.Xr sysconf-make 8 532and 533.Xr sysconf-src 8 534.Pc . 535Each bare 536.Ar name 537must begin with 538.Ql WITH_ 539or 540.Ql WITHOUT_ . 541An already-present knob 542.Pq any value 543is left unchanged by 544.Fl s . 545An explicit 546.Ar name Ns = 547including empty always writes. 548Mutually exclusive with 549.Fl x . 550.It Fl v 551Verbose. 552Print the pathname of the configuration file holding the final effective 553value 554.Pq the last file in sourcing order that assigned the directive . 555.It Fl V 556Trail. 557For each named read 558.Pq and for Fl a , 559print every assignment step that contributed to the effective value: 560.Ql file:line: nameopfragment , 561and when the running effective value differs from the fragment, 562.Ql -> effective . 563.Pp 564For writes, print the same 565.Ql file:line: 566shape for the change: 567.Ql file:line: name=old -> name=new , 568.Ql name=value (unchanged) , 569.Ql name=value (added) 570when a new statement is created, 571or 572.Ql nameopfragment (removed) 573when a statement is deleted, 574using the statement operator 575.Ql = / += / ... 576as appropriate . 577.Pp 578Uses the same accumulation model as ordinary reads 579.Pq make(1) `+=' et al. , 580so the last effective value matches 581.Fl v 582and, 583for linear conf files without 584.Ql .if , 585.Nm make Fl V 586.Pq see Xr sysconf-make 8 and Xr sysconf-src 8 . 587.It Fl x 588Remove the named directive(s) from every file of the target listing them 589.Pq see Xr sysconf-targets 8 . 590With 591.Fl v 592or 593.Fl V , 594a successful removal echoes 595.Ql name (removed) 596.Pq or a trail form with Fl V . 597.El 598.Sh ENVIRONMENT 599.Bl -tag -width "LOADER_DEFAULTS" 600.It Ev LOADER_DEFAULTS 601Defaults file for the 602.Ql loader 603target; 604see 605.Xr sysconf-loader 8 . 606.It Ev SRC_ENV_CONF , Ev __MAKE_CONF , Ev SRCCONF 607Paths for the 608.Cm src 609triad; 610see 611.Xr sysconf-src 8 . 612.El 613.Sh FILES 614See the per-target manuals 615.Pq Xr sysconf-loader 8 , Xr sysconf-sysctl 8 , Xr sysconf-make 8 , Xr sysconf-src 8 616for the files each keyword consults. 617Common paths include 618.Pa /boot/loader.conf , 619.Pa /etc/sysctl.conf , 620.Pa /etc/make.conf , 621and 622.Pa /etc/src.conf . 623.Sh EXIT STATUS 624.Ex -std 625In check mode 626.Pq Fl c , 627an exit status of zero means no changes are required. 628.Sh EXAMPLES 629Read and set a boot loader directive: 630.Pp 631.Dl sysconf loader zfs_load 632.Dl sysconf loader zfs_load=\(dqYES\(dq 633.Pp 634Raise a sysctl applied at boot: 635.Pp 636.Dl sysconf sysctl kern.maxfiles=65536 637.Pp 638List files backing the loader target: 639.Pp 640.Dl sysconf loader -l 641.Pp 642Append to a space-separated list: 643.Pp 644.Dl sysconf loader kernels+=kernel_test 645.Pp 646Append a 647.Xr make 1 648flag and set a 649.Pa src.conf 650knob: 651.Pp 652.Dl sysconf make CFLAGS+=-DDEBUG 653.Dl sysconf src -s WITHOUT_LLDB 654.Dl sysconf src WITHOUT_LLDB= 655.Pp 656Further examples for each target appear in 657.Xr sysconf-loader 8 , 658.Xr sysconf-sysctl 8 , 659.Xr sysconf-make 8 , 660.Xr sysconf-src 8 , 661.Xr sysconf-rc 8 , 662and 663.Xr sysconf-generic 8 . 664.Sh SEE ALSO 665.Xr bsdconf 3 , 666.Xr bsdconf_format 3 , 667.Xr bsdconf_put 3 , 668.Xr loader.conf 5 , 669.Xr src.conf 5 , 670.Xr sysctl.conf 5 , 671.Xr jail 8 , 672.Xr sysconf-generic 8 , 673.Xr sysconf-loader 8 , 674.Xr sysconf-make 8 , 675.Xr sysconf-rc 8 , 676.Xr sysconf-src 8 , 677.Xr sysconf-sysctl 8 , 678.Xr sysconf-targets 8 , 679.Xr sysctl 8 , 680.Xr sysrc 8 681.Sh HISTORY 682The 683.Nm 684utility first appeared in 685.Fx 16.0 . 686.Sh AUTHORS 687.An Devin Teske Aq Mt dteske@FreeBSD.org 688.An Faraz Vahedi Aq Mt kfv@FreeBSD.org 689.Sh SECURITY CONSIDERATIONS 690Read-only invocations 691.Po 692including 693.Fl c 694checks, which never modify files 695.Pc 696run inside a 697.Xr capsicum 4 698sandbox: 699the backing files are opened first and the process then relinquishes all 700other capabilities before any file content is parsed. 701.Pp 702Write operations replace files atomically and never in place; 703see the 704.Sx SECURITY CONSIDERATIONS 705section of 706.Xr bsdconf_put 3 707for the properties of the write transaction. 708