I Built Linux from Scratch
thesloth.me
thesloth.me
Nowadays, I am a devops/infrastructure engineer, and I can say LFS is a core foundational experience that has let me be better at my job. I know deeper inner workings of a Linux distro and that strong foundation helps. Yes there is so much more to learn but having LFS in your back pocket of lifetime experiences is great.
I also think its a 1 and done kind of thing. I don't see a huge benefit of doing it again. Maybe for fun, in a VM while waiting for other things to finish. It is also much faster nowadays. Back when I did it, I had a 1ghz, 256gb ram machine, it took me days. I could probably go through it in a day casually with modern computing, and especially since I have a threadripper machine, sending 64 threads at the make commands im sure will get my 1 BU to be a very small number.
If you have a child that is interested in computers, tech, programming, etc. I highly encourage this activity. Could be a fun bonding activity too.
So I had to try and break the LFS build into one hour chunks. Though I got through quite a bit, unfortunately, there were some multihour build steps and I never got lucky enough with multihour electricity, till I finally lost interest.
I did learn quite a bit from reading the manual though.
From there I moved to Gentoo, and then eventually to Ubuntu and other batteries-included distros. But the knowledge I gained from LFS is still a foundational part of my skillset, even though my roles have been more dev-focused than ops/infra.
It did teach me how subtle a running stable OS is underneath though, as, after my first standalone boot, I could enjoy a partially working TCP stack: elinks could browser, curl couldn't, irssi sometimes, all of this with random terminal display codes being inserted.
I’ve tried to return a few times but it’s a bit different now and I’m happy enough with FreeBSD that I don’t have much place for it. I do wish more embedded distros would have started with Gentoo (specifically ARM SBCs).
Bare bones hardened kernel + shim init + target application are all you need, and will be your highest security/reliability systems.
And yeah, threadrippers are a must.
In security focused orgs though you review all code yourself with the exception of things with extensive third party signed review such as the Linux kernel itself. Even then I review codepaths in the kernel critical for my use case such as random.c
From there, if I -alone- compile containers, kernels, or binaries, someone could coerce me to tamper with them to compromise all downstream users. Same if there was a central build system I can access. To mitigate this I ensure my artifact builds are deterministic, sign my changes, and have team members review my changes, reproduce my artifacts bit for bit, then counter-sign the results.
It is never wise to be in a position where there is possibility of you yourself tampering with things that control anything of value, or else someone will coerce you to help them steal said value.
As a security engineer it is my job to ensure no one ever has to trust anyone, including me.
Interesting thread!
Sure, compromised binaries are nasty but personally I do place quite a lot of trust with the distribution repos.
(PS, if you are reading this and contribute packages to distribution repos: Thank you!)
Security comes down to reducing attack surface, ideally to an infinitesimal degree.
I mean, they give a wonderfully higher quality of life for compiling but they are $2,500-6,000 just for the CPU. Of course this can be done on much lower-cost CPUs! A 12-core Ryzen is already at the "I have lots of money to spend" end of what I'd suggest for something like this.
You had a 256gb ram machine???
It's been so long that thinking of ram in anything other than GB is weird.
The LFS book is quite thorough, so you technically only need to copy/paste commands, but you learn _a lot_ about Linux in the process. I highly recommend it to anyone interested in Linux. I did it once in college, and parts of BLFS IIRC, and it's one of the few memorable projects I got from my degree.
Sort of like launching a spaceship in factorio.
I would definitely recommend going through LFS to anyone maintaining Linux systems, it really helps you understand how things work.
I had a lot of fun doing this. You really get a feel for the evolution of build systems -- from older software that uses automake/make to newer programs that use meson/ninja/cmake etc. It was also cool to learn how to bootstrap a bespoke set of development tools tuned for your hardware.
It took me a solid weekend to get everything built. I was able to get a basic LFS system built on a Saturday, and on Sunday I did the "Beyond Linux From Scratch" edition. At one point I got stuck trying to debug a weird interaction between systemd and PAM that took me a while to unravel. That was humbling, I thought I knew just about everything about Linux, but turns out there are large areas where I just don't have a clue.
The docs are well written and maintained, so there wasn't a lot of frustration there. Even if you're not an old hand at Linux you can likely get pretty far by just diligently following the instructions.
I struggled a lot more trying to make a decent desktop environment than I did getting the OS setup. I spent so much time trying to get a nice-looking toolbar (polybar) and basic stuff (like how patched fonts work) took me an embarrasingly long time to sort out. I also didn't know what a compositor was, or why you might want one. I enjoyed figuring out the basics of compton, which allowed me to get cool transparent backgrounds on windows[0], although I never did quite figure out how to get rounded corners.
The "package manager" is just a shell script. The installation process[1] is entirely manual, so you control every step as you bootstrap up to building your own kernel and installing each subsystem, all the way up to compiling and running Firefox. It's pretty neat.
[0] https://www.reddit.com/r/linux/comments/m4pwix/what_happened...
Though these days I would probably recommend to go with Yocto [2] for the sake of stability and updates.
Use the advanced install feature and only select the packages you need. Build the other software yourself. You can choose your own difficulty this way. You can also follow the distro's way of packaging up software (build scripts), or build it the software developer's way. The main advantages of building software yourself are:
1. You are a developer who wants to customize the software.
2. You want to practice.
3. You want to contribute to a project.
4. You want to have a better understanding of what the code does.
Slackware 15 is a modern platform to build upon.
Slackware doesn't try to hide anything from you, it takes the long way around, but it does so in order to do the correct thing, and in a way where it's clear to you why things function the way they do.
In some ways Slackware is hard to use, but it's also less frustrating and you don't hit exceedingly hard problems where you feel like the OS is fighting you.
IceWM gang anyone ?
Slackware was underdeveloped PITA back then and it is now
But the "proper" way includes million scripts and checks that make sure your .dpkg is "distribution grade" and it can be quite complex
Ipcop was a pretty good router. It could be booted off a 1.44MB floppy disk. It was built using LFS, so it took a while to install on a home-grade machine (like, a day!). This was ages ago; apparently they're still going.
I didn't learn anything from installing it, except that it's possible, as a user, to build the whole toolchain, the OS, and the application, starting from assembly language. And that using LFS, you can make a really tiny Linux. Making a router was a good application of LFS; I'm surprised the search engines have forgotten it.
It's important that we can always do that.
I ended up using the system for a few months until it collected enough cruft that I started over with some other distro.
> Slackware and LFS are the Haskells of the Linux distribution world. People jump to the extreme end of the spectrum, and either get burnt or remain unproductive for life, when they should have just used OCaml or F# instead.
https://blog.nawaz.org/posts/2023/May/20-years-of-gentoo/
I've done both LFS and Gentoo. While LFS is certainly fun, in practice I don't think you really learn that much more than with Gentoo. The benefit of the latter is it's easy to stick to for life.
At the time I made it a 32-bit system since LFS didn't (doesn't?) support multilib and I knew I would need some 32-bit libraries.
I used that as my main system for quite a long time, upgrading software or installing based on BLFS or my own intuition as necessary. It worked pretty well! It was an invaluable experience in the development of my Linux expertise.
After about 5 years I got frustrated with the 32-bit system so I did an in-place upgrade to 64-bit. It was thrilling to come out the other end of that, to say the least (seriously). The training wheels were definitely off, but LFS had educated me enough to be confident in doing it. Also I kept around all the 32-bit stuff of course, so I could incrementally upgrade things.
After a few more years (maybe 2018ish?) I grew weary and changed to Arch (now I use void) :)
All that being said, I highly recommend LFS!
I highly recommend this to anyone interested in 'computers'.
But yes... building Linux from scratch can be very educational. It's probably a right of passage for jedi geeks: LFS, designing and spinning your own SBC, using wireshark/ethereal to debug a borked Cisco router. Sadly, I still remember much more about LILO than I ever learned about Grub.
I learned a bit of rust and wrote a minimal init system perfect for my use case: https://github.com/distrust-foundation/EnclaveOS/blob/master...
The init system is statically compiled into the kernel as a CPIO.
This is about as bare bones as you can get with linux, and may help others understand the essentials.
I was only able to do this because of years of running gentoo and building linux for various embedded projects. It pays off!
You could swap out my init binary for busybox init and have built a full interactive linux distro from scratch in under an hour.
I have some precedent for that kind of thing, back in 1987 I made a deal with a prof that as an independent study course a friend and I were going to build a pair of voice synthesizers on IBM PC Prototype boards using the synth chips available at Radio Shack and he'd give us the grade my computer verbally asked him for at the end of the semester. I had no backup plan and it was a crazy risk, but we got A's and the teacher regretted not having us make one for him as well.
I recommend using embedded Linux instead, e.g. with Buildroot. You get an understanding of the fundamentals of the hardware, kernel, and build toolchain. And you can create small hardware systems that do fun things.
I ran Gentoo for a few years, and enjoyed it. Doing the install from stage1 gives you a similar understanding of how the pieces fit together and enables you to fix low level system problems, e.g. with disk failures. The community is also smart, as it self-selects for people who have skills and good attitude. Unfortunately Gentoo is too slow to install and quirky to deploy on servers.
Back then I ran into the same issue as everyone else, it basically felt like Slackware, or FreeBSD with the ports but sans all the handy patches.
I'd love it if their docs[1] actually mentioned how to install an existing package manager software on your LFS, that would basically make it a distro.
1. https://www.linuxfromscratch.org/lfs/view/stable/chapter08/p...
<insert joke about the similarities between making sandwiches (bistro) and building a linux (distro)>
Yes definitely! If you want to roll a new distro, I would dare say LFS is an essential step. Now that said, if your new "distro" is just going to be Ubuntu with a couple tweaked settings, you won't get nearly as much from it. But any non-trivial distro rolling you can absolutely benefit.
Thanks, and yeah if I were to roll a new distro it’d be substantially different from anything currently out there.
Even if you try and argue it is educational. Learning how to build programs does not require LFS. LFS is inefficient as a learning tool
So I developed my own build system, which probably looked somewhat like Nix for building the distribution and managing updates.
LFS was great place to start with
It was a miss calculation on my part, I underestimate how long it would take me to complete the whole LFS thing. Still on my todo list though
Its certainly a learning experience, but I'm happy with Gentoo thanks.
What do you mean? Did you replace the login shell with a NodeJS interpreter or did you use a terminal emulator that ran on NodeJS?
In retrospect it was insanity layered upon insanity.
No need to click on the link.
If you're asking about the hashes for required packages in 'Chapter 3. Packages and Patched', the hashes should match if you're downloading from the provided mirror - https://www.linuxfromscratch.org/lfs/mirrors.html#files
Downloading from these mirrors ensures that you have the exact version needed for the build, in any other cases you run the risk of the system not working as expected / documented in the book.
- 0 - 6 preschool
- 7 - 15 basic school (mandatory)
- 16 - 19 middle school
- 20+ university or polytechnique
And middle school generally divides into: a) 3 year of craft school, workforce after; or b) 4 years of general learning school, no craft knowledge after, expected to go to university after or be clerk, or ..., unspecified; or c) ~4 years technical school in specific craft with "qualified technik" diploma quasi low level "engineer" (have some knowledge to be responsible for things), maybe polytechnique after or uni
At unis typical degrees: master, phd, professor.
So where in such schema collage is located ?
What you call middle school they call high school.
I had the same experience with college. I'd been using Linux for years and learned nothing new about Linux in college. It was nice because the class moved fast and a lot of people who had never Linuxed or CLIed in their lives really struggled to get through it and keep up.