No description
  • Perl 61.5%
  • Shell 32%
  • Python 6.5%
Find a file
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Daniel Baumann 6bcda17f3d
Releasing fastforward version 1.6.0-4~ffwd13+u1.
Signed-off-by: Daniel Baumann <daniel@debian.org>
2026-10-04 09:19:54 +02:00
debian Releasing fastforward version 1.6.0-4~ffwd13+u1. 2026-10-04 09:19:54 +02:00
examples/twb Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
hooks Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
tests Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
.gitignore Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
.mailmap Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
.perltidyrc Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
caching_proxy.py Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
CHANGELOG.md Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
coverage.py Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
coverage.sh Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
coverage.txt Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
gpgvnoexpkeysig Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
hurd-compare.py Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
hurd-profile.sh Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
hurd.sh Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
ldconfig.fakechroot Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
make_mirror.sh Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
mmdebstrap Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
mmdebstrap-autopkgtest-build-qemu Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
proxysolver Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
README.md Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
run_null.sh Adding upstream version 1.5.7. 2025-08-14 19:03:54 +02:00
run_qemu.sh Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00
tarfilter Merging upstream version 1.6.0. 2026-10-04 09:19:43 +02:00

mmdebstrap

An alternative to debootstrap which uses apt internally and is thus able to use more than one mirror and resolve more complex dependencies.

Usage

Use like debootstrap:

sudo mmdebstrap unstable ./unstable-chroot

Without superuser privileges:

mmdebstrap unstable unstable-chroot.tar

With complex apt options:

cat /etc/apt/sources.list | mmdebstrap > unstable-chroot.tar

For the full documentation use:

pod2man ./mmdebstrap | man -l -

Or read a HTML version of the man page in either of these locations:

The sales pitch in comparison to debootstrap

Summary:

  • more than one mirror possible
  • security and updates mirror included for Debian stable chroots
  • twice as fast
  • chroot with apt in 11 seconds
  • gzipped tarball with apt is 27M small
  • bit-by-bit reproducible output
  • unprivileged operation using Linux user namespaces or fakechroot
  • can operate on filesystems mounted with nodev
  • foreign architecture chroots with qemu-user
  • variant installing only Essential:yes packages and dependencies
  • temporary chroots by redirecting to /dev/null
  • chroots without apt inside (for chroot from buildinfo file with debootsnap)

The author believes that a chroot of a Debian stable release should include the latest packages including security fixes by default. This has been a wontfix with debootstrap since 2009 (See #543819 and #762222). Since mmdebstrap uses apt internally, support for multiple mirrors comes for free and stable or oldstable chroots will include security and updates mirrors.

A side-effect of using apt is being twice as fast as debootstrap. The timings were carried out on a laptop with an Intel Core i5-5200U, using a mirror on localhost and a tmpfs.

variant mmdebstrap debootstrap
essential 9.52 s n.a
apt 10.98 s n.a
minbase 13.54 s 26.37 s
buildd 21.31 s 34.85 s
- 23.01 s 48.83 s

Apt considers itself an Essential: yes package. This feature allows one to create a chroot containing just the Essential: yes packages and apt (and their hard dependencies) in just 11 seconds.

If desired, a most minimal chroot with just the Essential: yes packages and their hard dependencies can be created with a gzipped tarball size of just 34M. By using dpkg's --path-exclude option to exclude documentation, even smaller gzipped tarballs of 21M in size are possible. If apt is included, the result is a gzipped tarball of only 27M.

These small sizes are also achieved because apt caches and other cruft is stripped from the chroot. This also makes the result bit-by-bit reproducible if the $SOURCE_DATE_EPOCH environment variable is set.

The author believes, that it should not be necessary to have superuser privileges to create a file (the chroot tarball) in one's home directory. Thus, mmdebstrap provides multiple options to create a chroot tarball with the right permissions without superuser privileges. This avoids a whole class of bugs like #921815. Depending on what is available, it uses either Linux user namespaces or fakechroot. Debootstrap supports fakechroot but will not create a tarball with the right permissions by itself. Support for Linux user namespaces is missing (see #829134).

When creating a chroot tarball with debootstrap, the temporary chroot directory cannot be on a filesystem that has been mounted with nodev. In unprivileged mode, mknod is never used, which means that /tmp can be used as a temporary directory location even if if it's mounted with nodev as a security measure.

If the chroot architecture cannot be executed by the current machine, qemu-user is used to allow one to create a foreign architecture chroot.

Limitations in comparison to debootstrap

Debootstrap supports creating a Debian chroot on non-Debian systems but mmdebstrap requires apt and is thus limited to Debian and derivatives. This means that mmdebstrap can never fully replace debootstrap and debootstrap will continue to be relevant in situations where you want to create a Debian chroot from a platform without apt and dpkg.

There is no SCRIPT argument.

The following options, don't exist: --second-stage, --exclude, --resolve-deps, --force-check-gpg, --merged-usr and --no-merged-usr.

The quirks from debootstrap are needed to create chroots of Debian unstable from snapshot.d.o before timestamp 20141107T220431Z or Debian 8 (Jessie) or later.

Tests

On Debian, the following packages are required to run the testsuite:

sudo apt install --no-install-recommends debvm debootstrap dctrl-tools \
    perltidy libperl-critic-perl black shellcheck shfmt python3-debian \
    debvm

The script coverage.sh runs mmdebstrap in all kind of scenarios to execute all code paths of the script. It verifies its output in each scenario and displays the results gathered with Devel::Cover. It also compares the output of mmdebstrap with debootstrap in several scenarios. To run the testsuite, run:

./make_mirror.sh
CMD=./mmdebstrap ./coverage.sh

To also generate perl Devel::Cover data, omit the CMD environment variable. But that will also take a lot longer.

The make_mirror.sh script will be a no-op if nothing changed in Debian unstable. You don't need to run make_mirror.sh before every invocation of coverage.sh. When you make changes to make_mirror.sh and want to regenerate the cache, run:

FORCE_UPDATE=yes ./make_mirror.sh

The script coverage.sh does not need an active internet connection by default. An online connection is only needed by the make_mirror.sh script which fills a local cache with a few minimal Debian mirror copies.

By default, coverage.sh will skip running a single test which tries creating a Ubuntu Focal chroot. To not skip that test, run coverage.sh with the environment variable ONLINE=yes.

If a test fails you can run individual tests by executing coverage.py with the test name and optionally limit it to a specific distribution like so:

CMD=./mmdebstrap ./coverage.py --dist unstable check-against-debootstrap-dist

Bugs

mmdebstrap has bugs. Report them here: https://gitlab.mister-muffin.de/josch/mmdebstrap/issues

Contributors

  • Johannes Schauer Marin Rodrigues (main author)
  • Jochen Sprickerhof
  • Helmut Grohne
  • Gioele Barabucci
  • Benjamin Drung
  • Josh Triplett
  • Konstantin Demin
  • Charles Short
  • Chris Hofstaedtler
  • Colin Watson
  • David Kalnischkies
  • Emilio Pozuelo Monfort
  • Francesco Poli
  • Jakub Wilk
  • Joe Groocock
  • Max-Julian Pogner
  • Nicolas Vigier
  • Raul Tambre
  • Steve Dodd
  • Trent W. Buck
  • Vagrant Cascadian

Above list of contributors only contains humans. This project will never accept contributions from LLMs, (generative) AI or any other tool destroying our community, free software, small websites, people's livelihood (especially in the global south) and (last but not least) this planet's climate. This decision can only be revisited once the cost of LLMs or similar machinery no longer outweighs their benefits (yes, the benefit i.e. making mmdebstrap better, is not important in comparison). This means that if your contribution was not produced by your brain but by some piece of software, that software must meet the following requirements:

  1. Did not require non-consensual scraping of the free internet, destroying the small servers of those without the time or funds to combat the scraper hordes from hard-to-block residential proxies and requires internet users to waste time and energy on solving proof-of-work riddles
  2. Did not require a supercomputer (especially not those powered by fossil fuels) which no normal person can ever afford for training, making common hardware more expensive and even less affordable for those with less financial freedom
  3. Did not rely on data with unclear or non-free copyright status
  4. Does not make fascist billionaires even richer than they already are
  5. If a bug is found in your tool, that bug can be fixed by a human

Yes, even Apertus fails points 2 and 5. You can use a proprietary operating system and editor to create your contribution. The above is about the tool which generated the code, not about your favourite editor. For example, the top of the mmdebstrap script contains the array @hurdfiles with over 1.2k entries. This is tiresome for a human to edit, so you can resort to tools like awk or sed to produce changes automatically with the help of a computer (that's what they are for). This is because awk or sed do not violate any of the rules above. If you do this, it'd be nice to put the command you used into the commit message so that others can benefit as well and learn from your method.

You are not allowed to use the mmdebstrap codebase for any sort of machine learning input (though this ship likely has sailed a long time ago as the codebase has been scraped and integrated into countless non-free LLMs without my consent). If you think your use-case is of ethical nature, write me an email and make your case.

If you go against my wishes and analyze mmdebstrap with an LLM to find bugs, I will be angry and upset but probably still fix the bugs your stupid "tool" found but only if you wrote the bug report in your own words, understand the bug and can discuss it with me. Use your brain to talk to me. Do not put a machine between us.

Bug reports written by an LLM without a human who can meaningfully discuss the problem will be ignored and/or directly closed.

Please don't use an LLM to translate your bug from your native language to English or to "improve" the wording of your bug report. I'm not a native speaker either but I can promise you that you only get better with writing if you write. You cannot get better at something without doing it and we all start off being bad at something before we get better. Write bad English, write bad software but then lets get together and talk about it so that we can both grow and get better at it. We don't need climate-destroying fascist software between us.

I put the above LLM policy for mmdebstrap into the public domain and you can do whatever you want with it without mentioning my name or mmdebstrap.