FreeBSD Ports Collection¶
- ID
ports- Links
- Upstream stars
⭐ 1,208
- Last commit
2026-09-29
- Platforms
🅱️ BSD (FreeBSD only)
- Operations
installed·outdated·install·upgrade·upgrade_all·remove·sync·cleanup- purl types
pkg:ports/- CLI name
make- Forced environment
BATCH=yes- Issues and PRs
- Source
FreeBSD ports tree: the source-build workflow rooted at /usr/ports.
Note
Coexists with PKG on the same system: both share the install
database maintained by pkg. Ports builds and tracks ports compiled
from source under /usr/ports, while PKG handles binary packages
from the FreeBSD repository. Listing operations may overlap because pkg
does not distinguish ports-built from binary-installed packages once they
are registered.
Note
installed and outdated delegate to the sibling pkg binary,
since the ports tree keeps no registry of its own. Builds drive FreeBSD’s
make directly with BATCH=yes to accept default build options
without prompting. Upgrades shell out to the third-party portmaster:
the ports tree ships no batch upgrader. sync refreshes the tree with
git (portsnap was removed after FreeBSD 13).
Caution
Mutating operations require root privileges and a populated ports tree at
/usr/ports. The manager flags itself unavailable when the tree is
missing.
Caution
Mutating operations compile from source, so their duration is set by the
port rather than by the network. A small library finishes well inside the
500 second ceiling mpm puts on a state-changing command (expat takes
about a minute), where a compiler or a browser runs for hours and reports
Timed out after 500s. Raise the ceiling for this manager alone, in the
configuration file:
[mpm.overrides.ports]
timeout = 14400
No single value fits, a build scaling with the port, its dependency tree
and the machine. sync and installed are unaffected, delegating to
git and pkg rather than building.
What mpm adds to ports¶
mpm reaches across every manager at once, not ports alone: mpm installed and mpm outdated cover ports alongside every other manager you run in one table, mpm upgrade --all updates them together, and mpm sbom exports the whole machine as one bill of materials.
Every mpm command also gains --dry-run and --plan previews, cross-scheme version comparison and purl identifiers. See manager augmentations for how each one is built.
Your ports commands, in mpm¶
You already know ports: each operation maps one-to-one onto mpm, in an interface shared by every manager.
To… |
With |
With |
|---|---|---|
List what’s installed |
|
|
List outdated packages |
|
|
Upgrade everything |
|
|
Clear caches |
|
|
Prefix any command above with --dry-run to simulate the underlying manager calls without touching the system: the safe way to watch what mpm would do before trusting it.
Operations¶
Operation |
Supported |
|---|---|
|
✅ |
|
✅ |
|
|
|
|
|
✅ |
|
✅ |
|
✅ |
|
✅ |
|
✅ |
|
✅ |
|
Configuration¶
Ignore
portson thempmCLI by passing the--no-portsoption.Ignore it for every run in your configuration:
[mpm] ports = false
Raise the timeout of all
portscalls:[mpm.overrides.ports] timeout = 900
Run
mpm config-template portsto print all overridable settings for your configuration file:[mpm.overrides.ports] cli_names = [ "make", ] cli_search_path = [] dry_run = false ignore_auto_updates = true plan = false post_args = [] pre_args = [] pre_cmds = [] stop_on_error = false unmaintained = false version_cli_options = [ "-V", "MAKE_VERSION", ] version_regexes = [ "(?P<version>\\d{8,})", ] [mpm.overrides.ports.extra_env] BATCH = "yes"
The arguments and environment variables listed in the box atop this page are forced on every ports call, so runs stay quiet, non-interactive and reproducible: the defaults you would set in CI anyway.
Recipes¶
A few jobs you would otherwise script around ports, one mpm command each:
Snapshot and clone a machine:
mpm --ports dump ports.toml, thenmpm restore ports.tomlon the next one.Export a compliance SBOM:
mpm --ports sbom(CycloneDX by default,--spdxfor SPDX).
Privilege escalation¶
System-wide manager: mpm wraps its privileged operations in sudo out of the box. Instead of letting the tool prompt mid-run, mpm primes the credential cache up-front, with a single branded password prompt at most. Turn escalation off for rootless setups with --no-sudo or the per-manager sudo override.
Its privileged operations are cleanup, install, remove, sync, upgrade, upgrade_all.
See privilege escalation for the full policy.
Concurrency¶
mpm never runs ports at the same time as pkg: ports keeps no registry of its own and registers what it builds through pkg, whose advisory lock on that shared install database refuses a second writer. Each mutating operation waits for the previous one, even with a higher --jobs, while managers outside this group keep running in parallel.
Only mutations are held back. The read-only queries (installed, outdated, search) take no backend lock and stay fully concurrent.
Cooldown¶
State of FreeBSD Ports Collection’s release-age gating, from the cooldown support table:
Status: ❌ None (FreeBSD ports)
A cooldown only pays off where a compromised release can be withdrawn while the clock runs, and can only be emulated where the registry dates its releases. From the retraction table:
Registry: Source-based recipe trees
Retraction: Index revert of the recipe tree
Publish date: ❌ a recipe carries no publication date
With --cooldown set, mpm skips this manager’s install and upgrade operations rather than run them unguarded (fail-closed); --cooldown best-effort opts back in.
Reference traces¶
A collection of raw native outputs captured from the manager’s own CLI and recorded in the manager source. If you know FreeBSD Ports Collection well and a transcript below looks wrong, or a newer release changed its output format, report it.
$ pkg query "%n %v %o %c"
curl 8.7.1 ftp/curl Non-interactive tool to get files from FTP/HTTP servers
python311 3.11.9 lang/python311 Interpreted object-oriented programming language
$ pkg version -vPL=
expat-2.8.2 < needs updating (port has 2.8.3)
git-2.54.0 < needs updating (port has 2.55.0)
libffi-3.6.0 < needs updating (port has 3.8.0)
FreeBSD-acct-15.1 ? orphaned: base/FreeBSD-acct
Version check¶
The version is extracted from the output of make -V MAKE_VERSION with:
r"(?P<version>\d{8,})"
Upstream project¶
Metrics |
|
|---|---|
Activity |
|
Popularity |
|
Metadata |
|
Changelog¶
8.0.0(2026-09-20)Stop running
portsconcurrently withpkg, which holds the advisory lock on the install database both register into.Fix
--planfor the operations that query before they act: they reported every package as missing instead of printing the command.Fix the FreeBSD ports manager, which reported no version and so never activated, and repair
installed,outdated,installandupgrade, the last of which hung on the port options dialog until it timed out.
6.4.0(2026-04-27)Add FreeBSD ports tree manager with
installed,outdated,install,upgrade,upgrade_all,remove,sync, andcleanupsupport. Drivesmake-based source builds out of/usr/ports, delegates registry queries topkg, and usesgitfor tree updates.