RAWNIX(7) Miscellaneous Information Manual RAWNIX(7)

rawnix — what rawnix is, and what it is not

rawnix is a source-based Linux system built around musl, Clang/LLVM, LibreSSL and runit. There is no glibc, no systemd, no OpenSSL and no X server. Packages are built from recipes with mkpkg(8) and installed with pkg(8), and the whole system is meant to be read: every tool is small enough to follow, and the configuration is files you edit.

What follows is the shape of the system. To install it, see installation(7); for what to do afterwards, see post-install(7).

rawnix boots with Limine from an EFI system partition. There is no BIOS or CSM support: no limine-bios.sys, no limine bios-install, and limine-sync assumes an ESP at /boot/efi. A machine whose firmware offers only legacy boot cannot run rawnix as it is shipped.

This is a deliberate choice, not an omission. Supporting both means two boot paths to test and maintain, and every machine made in the last decade boots UEFI. Check before buying a server or a virtual machine:

$ ls /sys/firmware/efi
On a UEFI system that directory exists.

There is no X server in the ports tree. The compositors are sway(1) and labwc(1), both on wlroots, and the terminal is foot(1). X11 applications run under xwayland if the compositor is built with it.

The X11 stack was retired when rawnix moved to Wayland. The ports still exist, unmaintained, and can be fetched from https://git.rawnix.org/attic/xorg/: the libraries, the server, the input and video drivers, and the small utilities that go with them. They are kept as a reference, not as a supported path: nothing in the live tree depends on them, and they are not built for the binary repository.

Process supervision is runit, in its original layout. A service is a directory holding a run script, and a service is enabled by linking it into /service:

# ln -s /etc/sv/nginx /service/nginx      # enable
# rm /service/nginx                       # disable
# sv status /service/*                    # what is running
# sv restart nginx                        # restart one

/service is a real directory on the root file system, not /var/service, not /run/runit/service, and not a symbolic link to either. Documentation written for other distributions often says otherwise; on rawnix the path is the one above.

A package that ships a service declares it in its recipe, and addpkg(8) makes the link at install time, so a newly installed daemon starts by itself.

The C library is musl. Glibc-only interfaces are absent, so some software needs patching, and some needs the small compatibility ports musl-fts, argp-standalone and libucontext. Binaries from other distributions do not run: they ask for /lib/ld-linux-x86-64.so.2, which does not exist here.

There is no ldd; revdep(8) reports what is missing instead, reading the package database rather than running the program.

Everything is built with clang, and the LLVM package is the toolchain: compiler, linker (lld), C++ library (libc++), and the usual tools. There is no GCC; gcc-compat exists only for configure scripts that insist on the name.

LLVM is built for the targets a desktop needs and no more:

-DLLVM_TARGETS_TO_BUILD="X86;AMDGPU"

X86 is the machine itself. AMDGPU is there for Mesa's shader compiler on AMD graphics, and for ROCm. On a machine with other graphics, change it:

AMD
, the default.
Intel
alone: Mesa's Intel drivers use their own compiler and need no LLVM target.
NVIDIA
for nouveau, whose Gallium driver can use it.
a virtual machine
alone.

Leaving out AMDGPU makes the package markedly smaller and the build markedly shorter; adding a target you do not have costs both for nothing. The setting is in the llvm port's MAKEPKG; changing it means rebuilding llvm and then Mesa.

The kernel is built with everything a machine needs to boot, mount its disks and reach the network compiled in, not as modules: no initramfs guesswork, nothing to load before the root file system appears.

Two kinds of driver are modules, because which one is needed cannot be known when the kernel is built: wireless and graphics. They are loaded at boot from /etc/rc.modules; see post-install(7), KERNEL MODULES.

Every port is signed with signify(1), and mkpkg(8) verifies the signature against a key in /etc/ports/keys/ before it builds anything. bulk(8) fetches prebuilt packages for the same ports, so a machine without a compiler can still be kept up to date; see pkg(8) -b.

mkpkg(8)
builds a package from a MAKEPKG(5) recipe
pkg(8)
installs, upgrades and removes, with dependencies
addpkg(8), delpkg(8), infopkg(8)
the package database itself
ports(8)
syncs the ports tree
bulk(8)
fetches prebuilt packages
revdep(8)
finds broken library dependencies
stik(8)
mounts removable devices as an ordinary user

Their source is at https://git.rawnix.org/, their manual pages at https://man.rawnix.org/, and https://audit.rawnix.org/ shows which ports are outdated and which carry open CVEs.

/service/
Enabled services, linked from /etc/sv/.
/etc/rc.modules
Wireless and graphics modules, loaded at boot.
/etc/pkg.conf
Where the ports are; see pkg.conf(5).
/etc/ports/
Collection configuration and trusted keys; see ports(8).
/etc/mkpkg.conf
Build settings; see mkpkg.conf(5).

installation(7), post-install(7), mkpkg(8), pkg(8), ports(8), revdep(8)

zorz <zorz@rawnix.org>

October 1, 2026 setup 1.4