diff --git a/zh_TW.Big5/articles/Makefile b/zh_TW.Big5/articles/Makefile
index 252b5a8271..d999776b7f 100644
--- a/zh_TW.Big5/articles/Makefile
+++ b/zh_TW.Big5/articles/Makefile
@@ -1,8 +1,12 @@
# $FreeBSD$
SUBDIR =
SUBDIR+= contributing
SUBDIR+= cvs-freebsd
+SUBDIR+= hubs
+SUBDIR+= mailing-list-faq
+SUBDIR+= pr-guidelines
+SUBDIR+= problem-reports
DOC_PREFIX?= ${.CURDIR}/../..
.include "${DOC_PREFIX}/share/mk/doc.project.mk"
diff --git a/zh_TW.Big5/articles/hubs/Makefile b/zh_TW.Big5/articles/hubs/Makefile
new file mode 100644
index 0000000000..cded48ba4b
--- /dev/null
+++ b/zh_TW.Big5/articles/hubs/Makefile
@@ -0,0 +1,17 @@
+#
+# $FreeBSD$
+#
+# Article: Mirroring FreeBSD
+
+DOC?= article
+
+FORMATS?= html
+WITH_ARTICLE_TOC?= YES
+
+INSTALL_COMPRESSED?=gz
+INSTALL_ONLY_COMPRESSED?=
+
+SRCS= article.sgml
+
+DOC_PREFIX?= ${.CURDIR}/../../..
+.include "${DOC_PREFIX}/share/mk/doc.project.mk"
diff --git a/zh_TW.Big5/articles/hubs/article.sgml b/zh_TW.Big5/articles/hubs/article.sgml
new file mode 100644
index 0000000000..a2944f2994
--- /dev/null
+++ b/zh_TW.Big5/articles/hubs/article.sgml
@@ -0,0 +1,1081 @@
+
+
+
+
+
+
+
+%articles.ent;
+
+]>
+
+
+
+ Mirroring FreeBSD
+ $FreeBSD$
+
+
+ Jun
+ Kuriyama
+
+ kuriyama@FreeBSD.org
+
+
+
+ Valentino
+ Vaschetto
+
+ logo@FreeBSD.org
+
+
+
+ Daniel
+ Lang
+
+ dl@leo.org
+
+
+
+ Ken
+ Smith
+
+ kensmith@FreeBSD.org
+
+
+
+
+
+ &tm-attrib.freebsd;
+ &tm-attrib.cvsup;
+ &tm-attrib.general;
+
+
+
+ 這是份還在草稿中的文章,主要是(尤其是給各區網中心管理者的參考)介紹如何 mirror FreeBSD。
+
+
+
+
+ 聯繫方式
+
+ 若要找整個 Mirror 機制的協調者,可以 email 到 mirror-admin@FreeBSD.org。此外,這裡也有份
+ &a.hubs;。
+
+
+
+ 成為 FreeBSD mirrors 的必備條件
+
+ 硬碟空間
+
+ 硬碟空間是最重要的必備條件之一。
+ Depending on the set of releases, architectures,
+ and degree of completeness you want to mirror, a huge
+ amount of disk space may be consumed. Also keep in mind
+ that official mirrors are probably required to be
+ complete. The CVS repository and the web pages should
+ always be mirrored completely. Also note that the
+ numbers stated here are reflecting the current
+ state (at &rel2.current;-RELEASE/&rel.current;-RELEASE). Further development and
+ releases will only increase the required amount.
+ Also make sure to keep some (ca. 10-20%) extra space
+ around just to be sure.
+ Here are some approximate figures:
+
+
+ 完整 FTP Distribution: 126 GB
+ CVS repository: 2.7 GB
+ CTM deltas: 1.8 GB
+ Web pages: 300 MB
+
+
+
+ 網路頻寬
+
+ 當然,你一定要能連上 Internet。
+ 頻寬需求多少,這要看你所想要的 mirror 程度而定。
+ 若只想要 mirror 一部份的 FreeBSD 檔案以作為網站或 intranet 的局部用途,
+ 那麼頻寬需求會明顯比成為公共服務用途的小一些。
+ 若想成為 official mirror 之一的話,那麼頻寬就勢必得增加才夠用。以下,我們僅列出一些估計值以做為參考:
+
+
+ Local site, no public access: basically no minimum,
+ but < 2 Mbps could make syncing too slow.
+ Unofficial public site: 34 Mbps is probably a good start.
+ Official site: > 100 Mbps is recommended, and your host
+ should be connected as close as possible to your border router.
+
+
+
+ 系統需求、CPU、RAM
+
+ One thing this depends on the expected number of clients,
+ which is determined by the server's policy. It is
+ also affected by the types of services you want to offer.
+ Plain FTP or HTTP services may not require a huge
+ amount of resources. Watch out if you provide
+ CVSup, rsync or even AnonCVS. This can have a huge
+ impact on CPU and memory requirements. Especially
+ rsync is considered a memory hog, and CVSup does
+ indeed consume some CPU. For AnonCVS it might
+ be a nice idea to set up a memory resident file system (MFS) of at least
+ 300 MB, so you need to take this into account
+ for your memory requirements. The following
+ are just examples to give you a very rough hint.
+
+
+ For a moderately visited site that offers
+ Rsync, you might
+ consider a current CPU with around 800MHz - 1 GHz,
+ and at least 512MB RAM. This is probably the
+ minimum you want for an official
+ site.
+
+
+ For a frequently used site you definitely need
+ more RAM (consider 2GB as a good start)
+ and possibly more CPU, which could also mean
+ that you need to go for a SMP system.
+
+
+ You also want to consider a fast disk subsystem.
+ Operations on the CVS repository require a fast
+ disk subsystem (RAID is highly advised). A SCSI
+ controller that has a cache of its own can also
+ speed up things since most of these services incur a
+ large number of small modifications to the disk.
+
+
+
+ Services to offer
+
+ Every mirror site is required to have a set of core services
+ available. In addition to these required services, there are
+ a number of optional services that
+ server administrators may choose to offer. This section explains
+ which services you can provide and how to go about implementing them.
+
+
+ FTP (required for FTP fileset)
+
+ This is one of the most basic services, and
+ it is required for each mirror offering public
+ FTP distributions. FTP access must be
+ anonymous, and no upload/download ratios
+ are allowed (a ridiculous thing anyway).
+ Upload capability is not required (and must
+ never be allowed for the FreeBSD file space).
+ Also the FreeBSD archive should be available under
+ the path /pub/FreeBSD.
+
+
+ There is a lot of software available which
+ can be set up to allow anonymous FTP
+ (in alphabetical order).
+
+ /usr/libexec/ftpd: FreeBSD's own ftpd
+ can be used. Be sure to read &man.ftpd.8;.
+
+
+ ftp/ncftpd: A commercial package,
+ free for educational use.
+
+
+ ftp/oftpd: An ftpd designed with
+ security as a main focus.
+
+
+ ftp/proftpd: A modular and very flexible ftpd.
+
+
+ ftp/pure-ftpd: Another ftpd developed with
+ security in mind.
+
+ ftp/twoftpd: As above.
+ ftp/vsftpd: The very secure ftpd.
+
+ ftp/wu-ftpd: The ftpd from Washington
+ University. It has become infamous, because of the huge
+ amount of security issues that have been found in it.
+ If you do choose to use this software be sure to
+ keep it up to date.
+
+
+
+ FreeBSD's ftpd, proftpd,
+ wu-ftpd and maybe ncftpd
+ are among the most commonly used FTPds.
+ The others do not have a large userbase among mirror sites. One
+ thing to consider is that you may need flexibility in limiting
+ how many simultaneous connections are allowed, thus limiting how
+ much network bandwidth and system resources are consumed.
+
+
+
+ Rsync (optional for FTP fileset)
+
+ Rsync is often offered for access to the
+ contents of the FTP area of FreeBSD, so other mirror sites can use your system as their source. The
+ protocol is different from FTP in many ways.
+ It is much more
+ bandwidth friendly, as only differences between files
+ are transferred instead of whole files when they change.
+ Rsync does require a significant amount of memory for
+ each instance. The size depends on the size of
+ the synced module in terms of the number of directories and
+ files. Rsync can use rsh and
+ ssh (now default) as a transport,
+ or use its own protocol for stand-alone access
+ (this is the preferred method for public rsync servers).
+ Authentication, connection limits, and other restrictions
+ may be applied. There is just one software package
+ available:
+
+ net/rsync
+
+
+
+
+ HTTP (required for web pages, optional for FTP fileset)
+
+ If you want to offer the FreeBSD web pages, you will need
+ to install a web server.
+ You may optionally offer the FTP fileset via HTTP.
+ The choice of web server software is left up to the mirror administrator.
+ Some of the most popular choices are:
+
+
+
+ www/apache13:
+ Apache is the most widely
+ deployed web server on the Internet. It is used
+ extensively by the FreeBSD Project. You may also wish to
+ use the next generation of the
+ Apache web server, available
+ in the ports collection as www/apache22.
+
+
+
+ www/thttpd:
+ If you are going to be serving a large amount of static content
+ you may find that using an application such as thttpd is more
+ efficient than Apache. It is
+ optimized for excellent performance on FreeBSD.
+
+
+
+ www/boa:
+ Boa is another alternative to
+ thttpd and
+ Apache. It should provide
+ considerably better performance than
+ Apache for purely static
+ content. It does not, at the time of this writing,
+ contain the same set of optimizations for FreeBSD that
+ are found in thttpd.
+
+
+
+
+
+ CVSup (desired for CVS repository)
+
+ CVSup is a very efficient way of distributing files.
+ It works similar to rsync, but was specially designed for
+ use with CVS repositories. If you want to offer the
+ FreeBSD CVS repository, you really want to consider
+ offering it via CVSup. It is possible to offer
+ the CVS repository via AnonCVS, FTP,
+ rsync or HTTP, but
+ people would benefit much more from CVSup access.
+ CVSup was developed by &a.jdp;.
+ It is a bit tricky to install on non-FreeBSD platforms,
+ since it is written in Modula-3 and therefore requires
+ a Modula-3 environment. John Polstra has built a
+ stripped down version of M3 that is sufficient to
+ run CVSup, and can be installed much easier.
+ See Ezm3
+ for details. Related ports are:
+
+
+
+ net/cvsup: The native CVSup port (client and server)
+ which requires lang/ezm3 now.
+
+
+ net/cvsup-mirror: The CVSup mirror kit, which requires
+ net/cvsup-without-gui, and configures it mirror-ready. Some
+ site administrators may want a different setup though.
+
+
+
+
+ There are a few more like
+ net/cvsup-without-gui you might want to have
+ a look at. If you prefer a static binary package, take a look
+ here.
+ This page still refers to the S1G bug that was present
+ in CVSup. Maybe
+ John will set up a generic download-site to get
+ static binaries for various platforms.
+
+
+ It is possible to use CVSup to offer
+ any kind of fileset, not just CVS repositories,
+ but configuration can be complex.
+ CVSup is known to eat some CPU on both the server and the
+ client, since it needs to compare lots of files.
+
+
+
+ AnonCVS (optional for CVS repository)
+
+ If you have the CVS repository, you may want to offer
+ anonymous CVS access. A short warning first:
+ There is not much demand for it,
+ it requires some experience, and you need to know
+ what you are doing.
+
+
+ Generally there are two ways
+ to access a CVS repository remotely: via
+ pserver or via ssh
+ (we do not consider rsh).
+ For anonymous access, pserver is
+ very well suited, but some still offer ssh
+ access as well. There is a custom crafted
+ wrapper
+ in the CVS repository, to be used as a login-shell for the
+ anonymous ssh account. It does a chroot, and therefore
+ requires the CVS repository to be available under the
+ anonymous user's home-directory. This may not be possible
+ for all sites. If you just offer pserver
+ this restriction does not apply, but you may run with
+ more security risks. You do not need to install any special
+ software, since &man.cvs.1; comes with
+ FreeBSD. You need to enable access via inetd,
+ so add an entry into your /etc/inetd.conf
+ like this:
+
+cvspserver stream tcp nowait root /usr/bin/cvs cvs -f -l -R -T /anoncvstmp --allow-root=/home/ncvs pserver
+
+ See the manpage for details of the options. Also see the CVS info
+ page about additional ways to make sure access is read-only.
+ It is advised that you create an unprivileged account,
+ preferably called anoncvs.
+ Also you need to create a file passwd
+ in your /home/ncvs/CVSROOT and assign a
+ CVS password (empty or anoncvs) to that user.
+ The directory /anoncvstmp is a special
+ purpose memory based file system. It is not required but
+ advised since &man.cvs.1; creates a shadow directory
+ structure in your /tmp which is
+ not used after the operation but slows things
+ dramatically if real disk operations are required.
+ Here is an excerpt from /etc/fstab,
+ how to set up such a MFS:
+
+/dev/da0s1b /anoncvstmp mfs rw,-s=786432,-b=4096,-f=512,-i=560,-c=3,-m=0,nosuid,nodev 0 0
+
+ This is (of course) tuned a lot, and was suggested by &a.jdp;.
+
+
+
+
+
+ How to Mirror FreeBSD
+
+ Ok, now you know the requirements and how to offer
+ the services, but not how to get it. :-)
+ This section explains how to actually mirror
+ the various parts of FreeBSD, what tools to use,
+ and where to mirror from.
+
+
+ FTP
+
+ The FTP area is the largest amount of data that
+ needs to be mirrored. It includes the distribution
+ sets required for network installation, the
+ branches which are actually snapshots
+ of checked-out source trees, the ISO Images
+ to write CD-ROMs with the installation distribution,
+ a live file system, lots of packages, the ports tree,
+ distfiles, and a huge amount of packages. All of course
+ for various FreeBSD versions,
+ and various architectures.
+
+
+ With FTP mirror
+
+ You can use a FTP mirror
+ program to get the files. Some of the most commonly used are:
+
+ ftp/mirror
+ ftp/ftpmirror
+ ftp/emirror
+ ftp/spegla
+ ftp/omi
+ ftp/wget
+
+
+ ftp/mirror was very popular, but seemed
+ to have some drawbacks, as it is written in &man.perl.1;,
+ and had real problems with mirroring large
+ directories like a FreeBSD site. There are rumors that
+ the current version has fixed this by allowing
+ a different algorithm for comparing
+ the directory structure to be specified.
+
+
+ In general FTP is not really good for mirroring. It transfers
+ the whole file if it has changed, and does
+ not create a single data stream which would benefit from
+ a large TCP congestion window.
+
+
+
+ With rsync
+
+ A better way to mirror the FTP area is rsync.
+ You can install the port net/rsync and then use
+ rsync to sync with your upstream host.
+ rsync is already mentioned
+ in .
+ Since rsync access is not
+ required, your preferred upstream site may not allow it.
+ You may need to hunt around a little bit to find a site
+ that allows rsync access.
+
+
+ Since the number of rsync
+ clients will have a significant impact on the server
+ machine, most admins impose limitations on their
+ server. For a mirror, you should ask the site maintainer
+ you are syncing from about their policy, and maybe
+ an exception for your host (since you are a mirror).
+
+
+ A command line to mirror FreeBSD might look like:
+ &prompt.user; rsync -vaz --delete ftp4.de.FreeBSD.org::FreeBSD/ /pub/FreeBSD/
+
+ Consult the documentation for rsync,
+ which is also available at
+ http://rsync.samba.org/,
+ about the various options to be used with rsync.
+ If you sync the whole module (unlike subdirectories),
+ be aware that the module-directory (here "FreeBSD")
+ will not be created, so you cannot omit the target directory.
+ Also you might
+ want to set up a script framework that calls such a command
+ via &man.cron.8;.
+
+
+
+ With CVSup
+
+ A few sites, including the one-and-only ftp-master.FreeBSD.org
+ even offer CVSup to mirror the contents of
+ the FTP space. You need to install a CVSup
+ client, preferably from the port net/cvsup.
+ (Also reread .)
+ A sample supfile suitable for ftp-master.FreeBSD.org
+ looks like this:
+
+ #
+ # FreeBSD archive supfile from master server
+ #
+ *default host=ftp-master.FreeBSD.org
+ *default base=/usr
+ *default prefix=/pub
+ #*default release=all
+ *default delete use-rel-suffix
+ *default umask=002
+
+ # If your network link is a T1 or faster, comment out the following line.
+ #*default compress
+
+ FreeBSD-archive release=all preserve
+
+
+ It seems CVSup would be the best
+ way to mirror the archive in terms of efficiency, but
+ it is only available from few sites.
+
+
+ Please have look at the CVSup documentation
+ like &man.cvsup.1; and consider using the
+ option. This reduces I/O operations by assuming the
+ recorded information about each file is correct.
+
+
+
+
+
+ Mirroring the CVS repository
+ There are various ways to mirror the CVS repository.
+ CVSup is the most common method.
+
+
+ Using CVSup
+
+ CVSup is described in some
+ detail in and .
+
+ It is very easy to setup a
+ CVSup mirror. Installing
+ net/cvsup-mirror will
+ make sure all of the needed programs are installed and then
+ gather all the needed information to configure the mirror.
+
+
+ Please do not forget to consider the hint
+ mentioned in this note
+ above.
+
+
+
+
+ Using other methods
+
+ Using other methods than CVSup is
+ generally not recommended. We describe them in short here
+ anyway. Since most sites offer the CVS repository as
+ part of the FTP fileset under the path
+ /pub/FreeBSD/development/FreeBSD-CVS,
+ the following methods could be used.
+
+ FTP
+ Rsync
+ HTTP
+
+
+
+ AnonCVS cannot be used to mirror the CVS repository
+ since CVS does not allow you to access the repository
+ itself, only checked out versions of the modules.
+
+
+
+
+
+ Mirroring the WWW pages
+
+ The best way is to check out the www
+ distribution from CVS. If you have a local mirror of the
+ CVS repository, it is as easy as:
+ &prompt.user; cvs -d /home/ncvs co www
+ and a cronjob, that calls cvs up -d -P
+ on a regular basis, maybe just after your repository was updated.
+ Of course, the files need to remain in a directory available
+ for public WWW access. The installation and configuration of a
+ web server is not discussed here.
+
+
+
+ If you do not have a local repository, you can use
+ CVSup to maintain an up to date copy
+ of the www pages. A sample supfile can be found in
+ /usr/share/examples/cvsup/www-supfile and
+ could look like this:
+
+ #
+ # WWW module supfile for FreeBSD
+ #
+ *default host=cvsup3.de.FreeBSD.org
+ *default base=/usr
+ *default prefix=/usr/local
+ *default release=cvs tag=.
+ *default delete use-rel-suffix
+
+ # If your network link is a T1 or faster, comment out the following line.
+ *default compress
+
+ # This collection retrieves the www/ tree of the FreeBSD repository
+ www
+
+
+
+ Using ftp/wget or other web-mirror tools is
+ not recommended.
+
+
+ Mirroring the FreeBSD documentation
+
+ Since the documentation is referenced a lot from the
+ web pages, it is recommended that you mirror the
+ FreeBSD documentation as well. However, this is not
+ as trivial as the www-pages alone.
+
+
+ First of all, you should get the doc sources,
+ again preferably via CVSup.
+ Here is a corresponding sample supfile:
+
+ #
+ # FreeBSD documentation supfile
+ #
+ *default host=cvsup3.de.FreeBSD.org
+ *default base=/usr
+ *default prefix=/usr/share
+ *default release=cvs tag=.
+ *default delete use-rel-suffix
+
+ # If your network link is a T1 or faster, comment out the following line.
+ #*default compress
+
+ # This will retrieve the entire doc branch of the FreeBSD repository.
+ # This includes the handbook, FAQ, and translations thereof.
+ doc-all
+
+
+
+ Then you need to install a couple of ports.
+ You are lucky, there is a meta-port:
+ textproc/docproj to do the work
+ for you. You need to set up some
+ environment variables, like
+ SGML_CATALOG_FILES.
+ Also have a look at your /etc/make.conf
+ (copy /usr/share/examples/etc/make.conf if
+ you do not have one), and look at the
+ DOC_LANG variable.
+ Now you are probably ready to run make
+ in your doc directory (/usr/share/doc
+ by default) and build the documentation.
+ Again you need to make it accessible for your web server
+ and make sure the links point to the right location.
+
+
+ The building of the documentation, as well as lots
+ of side issues, is documented itself in the
+ &os; Documentation
+ Project Primer.
+ Please read this piece of documentation, especially if you
+ have problems building the documentation.
+
+
+
+
+
+
+ How often should I mirror?
+
+ Every mirror should be updated on a regular
+ basis. You will certainly need some script
+ framework for it that will be called by
+ &man.cron.8;. Since nearly every admin
+ does this his own way, we cannot give
+ specific instructions. It could work
+ like this:
+
+
+
+
+ Put the command to run your mirroring application
+ in a script. Use of a plain /bin/sh
+ script is recommended.
+
+
+
+
+ Add some output redirections so diagnostic
+ messages are logged to a file.
+
+
+
+
+ Test if your script works. Check the logs.
+
+
+
+
+ Use &man.crontab.1; to add the script to the
+ appropriate user's &man.crontab.5;. This should be a
+ different user than what your FTP daemon runs as so that
+ if file permissions inside your FTP area are not
+ world-readable those files can not be accessed by anonymous
+ FTP. This is used to stage releases —
+ making sure all of the official mirror sites have all of the
+ necessary release files on release day.
+
+
+
+
+ Here are some recommended schedules:
+
+ FTP fileset: daily
+ CVS repository: hourly
+ WWW pages: daily
+
+
+
+
+
+ Where to mirror from
+
+ This is an important issue. So this section will
+ spend some effort to explain the backgrounds. We will say this
+ several times: under no circumstances should you mirror from
+ ftp.FreeBSD.org.
+
+
+ A few words about the organization
+
+ Mirrors are organized by country. All
+ official mirrors have a DNS entry of the form
+ ftpN.CC.FreeBSD.org.
+ CC (i.e. country code) is the
+ top level domain (TLD)
+ of the country where this mirror is located.
+ N is a number,
+ telling that the host would be the Nth
+ mirror in that country.
+ (Same applies to cvsupN.CC.FreeBSD.org,
+ wwwN.CC.FreeBSD.org, etc.)
+ There are mirrors with no CC part.
+ These are the mirror sites that are very well connected and
+ allow a large number of concurrent users.
+ ftp.FreeBSD.org is actually two machines, one currently
+ located in Denmark and the other in the United States.
+ It is NOT a master site and should never be
+ used to mirror from. Lots of online documentation leads
+ interactiveusers to
+ ftp.FreeBSD.org so automated mirroring
+ systems should find a different machine to mirror from.
+
+
+ Additionally there exists a hierarchy of mirrors, which
+ is described in terms of tiers.
+ The master sites are not referred to but can be
+ described as Tier-0. Mirrors
+ that mirror from these sites can be considered
+ Tier-1, mirrors of Tier-1-mirrors,
+ are Tier-2, etc.
+ Official sites are encouraged to be of a low tier,
+ but the lower the tier the higher the requirements in
+ terms as described in .
+ Also access to low-tier-mirrors may be restricted, and
+ access to master sites is definitely restricted.
+ The tier-hierarchy is not reflected
+ by DNS and generally not documented anywhere except
+ for the master sites. However, official mirrors with low numbers
+ like 1-4, are usually Tier-1
+ (this is just a rough hint, and there is no rule).
+
+
+
+ Ok, but where should I get the stuff now?
+
+ Under no circumstances should you mirror from ftp.FreeBSD.org.
+ The short answer is: from the
+ site that is closest to you in Internet terms, or gives you
+ the fastest access.
+
+
+ I just want to mirror from somewhere!
+
+ If you have no special intentions or
+ requirements, the statement in
+ applies. This means:
+
+
+
+
+ Look at available mirrors in your country.
+ The FreeBSD
+ Mirror Database can help you with this.
+
+
+
+
+ Check for those which provide fastest access
+ (number of hops, round-trip-times)
+ and offer the services you intend to
+ use (like rsync
+ or CVSup).
+
+
+
+
+ Contact the administrators of your chosen site stating your
+ request, and asking about their terms and
+ policies.
+
+
+
+
+ Set up your mirror as described above.
+
+
+
+
+
+ I am an official mirror, what is the right site for me?
+
+ In general the description in
+ still applies. Of course you may want to put some
+ weight on the fact that your upstream should be of
+ a low tier.
+ There are some other considerations about official
+ mirrors that are described in .
+
+
+
+ I want to access the master sites!
+
+ If you have good reasons and good prerequisites,
+ you may want and get access to one of the
+ master sites. Access to these sites is
+ generally restricted, and there are special policies
+ for access. If you are already an official
+ mirror, this certainly helps you getting access.
+ In any other case make sure your country really needs another mirror.
+ If it already has three or more, ask the zone administrator (hostmaster@CC.FreeBSD.org) or &a.hubs; first.
+
+
+ Whoever helped you become, an official
+ should have helped you gain access to an appropriate upstream
+ host, either one of the master sites or a suitable Tier-1
+ site. If not, you can send email to
+ mirror-admin@FreeBSD.org to request help with
+ that.
+
+
+ There are three master sites for the FTP fileset and
+ one for the CVS repository (the web pages and docs are
+ obtained from CVS, so there is no need for master).
+
+
+ ftp-master.FreeBSD.org
+
+ This is the master site for the FTP fileset.
+
+
+ ftp-master.FreeBSD.org provides
+ rsync and CVSup
+ access, in addition to FTP.
+ Refer to and
+ how to access
+ via these protocols.
+
+
+ Mirrors are also encouraged to allow rsync
+ access for the FTP contents, since they are
+ Tier-1-mirrors.
+
+
+
+ cvsup-master.FreeBSD.org
+
+ This is the master site for the CVS repository.
+
+
+ cvsup-master.FreeBSD.org provides
+ CVSup access only.
+ See for details.
+
+
+ To get access, you need to contact the &a.cvsup-master;.
+ Make sure you read the
+ FreeBSD CVSup Access Policy
+ first!
+
+
+ Set up the required authentication by following
+ these
+ instructions. Make sure you specify the server as
+ freefall.FreeBSD.org on the cvpasswd
+ command line, as described in this document,
+ even when you are contacting
+ cvsup-master.FreeBSD.org
+
+
+
+
+
+
+ Official Mirrors
+
+ Official mirrors are mirrors that
+
+
+
+ a) have a FreeBSD.org DNS entry
+ (usually a CNAME).
+
+
+
+
+ b) are listed as an official mirror in the FreeBSD
+ documentation (like handbook).
+
+
+
+
+ So far to distinguish official mirrors.
+ Official mirrors are not necessarily Tier-1-mirrors.
+ However you probably will not find a Tier-1-mirror,
+ that is not also official.
+
+
+ Special Requirements for official (tier-1) mirrors
+
+ It is not so easy to state requirements for all
+ official mirrors, since the project is sort of
+ tolerant here. It is more easy to say,
+ what official tier-1 mirrors
+ are required to. All other official mirrors
+ can consider this a big should.
+
+
+ The following applies mainly to the FTP fileset,
+ since a CVS repository should always be mirrored
+ completely, and the web pages are a case of
+ its own.
+
+
+
+
+ Tier-1 mirrors are required to:
+
+ carry the complete fileset
+ allow access to other mirror sites
+ provide FTP and
+ rsync access
+
+
+ Furthermore, admins should be subscribed to the &a.hubs;.
+ See this link for details, how to subscribe.
+
+
+ It is very important for a hub administrator, especially
+ Tier-1 hub admins, to check the
+ release schedule
+ for the next FreeBSD release. This is important because it will tell you when the
+ next release is scheduled
+ to come out, and thus giving you time to prepare for the big spike of traffic which follows it.
+
+
+ It is also important that hub administrators try to keep their mirrors as up-to-date as
+ possible (again, even more crucial for Tier-1 mirrors). If Mirror1 does not update for a
+ while, lower tier mirrors will begin to mirror old data from Mirror1 and thus begins
+ a downward spiral... Keep your mirrors up to date!
+
+
+
+
+ How to become official then?
+
+ An interesting question, especially, since the state
+ of being official comes with some benefits, like a much
+ higher bill from your ISP as more people will be using
+ your site. Also it may be a key requirement to get access
+ to a master site.
+
+
+ Before applying, please consider (again) if
+ another official mirror is really needed for
+ your region. Check first with your zone administrator (hostmaster@CC.FreeBSD.org) or, if that fails, ask on the &a.hubs;.
+
+ Ok, here is how to do it:
+
+
+
+ Get the mirror running in first place (maybe not
+ using a master site, yet).
+
+
+
+
+ Subscribe to the &a.hubs;.
+
+
+
+
+ If everything works so far, contact the DNS administrator responsible
+ for your region/country, and ask for a DNS entry for your
+ site. The admin should able to be contacted via
+ hostmaster@CC.FreeBSD.org, where
+ CC is your country code/TLD.
+ Your DNS entry will be as described
+ in .
+
+
+ If there is no subdomain set up for your
+ country yet, you should contact
+ mirror-admin@FreeBSD.org,
+ or you can try the &a.hubs; first.
+
+
+
+
+ Whoever helps you get an official name should send email
+ to mirror-admin@FreeBSD.org so your site will be
+ added to the mirror list in the
+ FreeBSD
+ Handbook.
+
+
+
+ That is it.
+
+
+
+ Some statistics from mirror sites
+
+ Here are links to the stat pages of your favorite mirrors
+ (a.k.a. the only ones who feel like providing stats).
+
+
+ FTP site statistics
+
+
+ ftp.is.FreeBSD.org - hostmaster@is.FreeBSD.org -
+
+ (Bandwidth)(FTP
+ processes)(HTTP processes)
+
+
+
+
+ ftp.cz.FreeBSD.org - cejkar@fit.vutbr.cz -
+ (Bandwidth)
+ (FTP processes)
+ (rsync processes)
+
+
+
+ ftp2.ru.FreeBSD.org - mirror@macomnet.ru -
+ (Bandwidth)
+ (HTTP and FTP users)
+
+
+
+
+
+ CVSup site stats
+
+
+ cvsup[23456].jp.FreeBSD.org - kuriyama@FreeBSD.org - (CVSup processes)
+
+
+ cvsup.cz.FreeBSD.org - cejkar@fit.vutbr.cz -
+ (CVSup processes)
+
+
+
+
+
+
+
diff --git a/zh_TW.Big5/articles/mailing-list-faq/Makefile b/zh_TW.Big5/articles/mailing-list-faq/Makefile
new file mode 100644
index 0000000000..09f7ccb2f7
--- /dev/null
+++ b/zh_TW.Big5/articles/mailing-list-faq/Makefile
@@ -0,0 +1,26 @@
+#
+# $FreeBSD$
+#
+# Article: Frequently Asked Questions About The FreeBSD Mailing Lists
+
+DOC?= article
+
+FORMATS?= html
+
+INSTALL_COMPRESSED?=gz
+INSTALL_ONLY_COMPRESSED?=
+
+WITH_ARTICLE_TOC?=YES
+
+#
+# SRCS lists the individual SGML files that make up the document. Changes
+# to any of these files will force a rebuild
+#
+
+# SGML content
+SRCS= article.sgml
+
+URL_RELPREFIX?= ../../../..
+DOC_PREFIX?= ${.CURDIR}/../../..
+
+.include "${DOC_PREFIX}/share/mk/doc.project.mk"
diff --git a/zh_TW.Big5/articles/mailing-list-faq/article.sgml b/zh_TW.Big5/articles/mailing-list-faq/article.sgml
new file mode 100644
index 0000000000..7315385d33
--- /dev/null
+++ b/zh_TW.Big5/articles/mailing-list-faq/article.sgml
@@ -0,0 +1,430 @@
+
+
+
+
+
+
+
+%articles.ent;
+]>
+
+
+
+ &os; Mailing Lists 常見問答集
+
+
+
+ The &os; Documentation Project
+
+
+
+ $FreeBSD$
+
+
+ 2004
+ 2005
+ 2006
+ &os; 文件計畫
+
+
+
+ 這是有關 &os; mailing lists 的 FAQ。如果您對協助本文件/翻譯計畫
+ 的進行有興趣的話,請寄 e-mail 到
+ &a.doc;。此外,隨時可從
+ FreeBSD 網站 拿到這份文件的最新版本。
+ 也可以利用 HTTP 來下載 HTML
+ 文件,或是經由
+ FreeBSD FTP 站 下載純文字、&postscript;、或 PDF 版本的檔案。
+ 您也可以在這裡使用
+ 搜尋 FAQ 資料
+ 的功能。
+
+
+
+
+ 前言
+
+ 如同其他 FAQs 一樣,本文主要目的是希望涵蓋在 &os; mailing
+ lists 上面的常見問題(當然,包括答案)。
+ 雖然,原本構想是希望能降低這些重複問題的網路流量,但如今已被公認 FAQs 也是相當好用的資源之一。
+
+ 本文主要是描述社群之間所培養的一些禮儀(或默契),但本文本身並非『聖旨』般的權威。
+ 若發現本文內有任何技術瑕疵,或者是想建議可以增加哪些部分的話,請送 PR,或是 email 到 &a.doc;。謝囉!
+
+
+
+
+ &os; mailing lists 的目的為何?
+
+
+
+ &os; mailing lists 主要是提供 &os; 社群間的溝通管道,這裡有各式專題領域的探討,以及興趣交流。
+
+
+
+
+
+ &os; mailing lists 的參與者有哪些?
+
+
+
+ 這個問題,要看各個 list 的『版規(charter)』定位而有所不同。有些 lists 主要是 developers 在參與討論的;
+ 而有些則主要是幾乎整體 &os; 社群都可以隨意參與討論的。請看 這份清單 上面有目前所有 list 的摘要說明。
+
+
+
+
+
+ &os; mailing lists 對任何人都是開放參與的嗎?
+
+
+
+ 再重複一次,這要看各個 list 的『版規(charter)』定位而有所不同。
+ 請在發文前,先注意閱讀該 list 的『版規(charter)』,並遵守相關原則。
+ 如此一來,才會讓大家都能溝通更無礙。
+
+ 如果看了上一個問答內的清單之後,還是不清楚要到哪個 list 去發問的話,
+ 那麼可以試著把問題丟到 freebsd-questions 看看(但請先看下面講的補充)。
+
+ 請注意:習慣上所有 mailing lists 都是開放發表討論的,也不必得先成為訂閱會員才行。
+ 這是相當審慎的選擇,來讓參與 &os; 社群更輕鬆容易,並鼓勵互相分享彼此的想法。
+ 然而,由於過去有些人的濫用,有些 lists 現在開始限制參與討論的部分,以避免不必要的困擾。
+
+
+
+
+
+ 要怎麼訂閱呢?
+
+
+
+ 可以用
+ Mailman 網頁介面 來訂閱任何公開的 lists。
+
+
+
+
+
+ 要怎麼退訂?
+
+
+
+ 一樣請用剛上面說的網頁介面,或者 mailing list 上面每封信結尾處都會有相關 URL 連結的指示說明。
+
+ 千萬請不要直接寫信到這些公開的 mailing lists 說你要退訂。
+ 首先呢..因為本來就不是這樣退訂的,其次你會惹來眾怒而招來圍剿、筆戰。
+ 這是很典型的退訂錯誤示範,請不要這樣做。
+
+
+
+
+
+ 可以找到舊信的資料庫嗎?
+
+
+
+ 嗯,有!可以在 這邊
+ 找到相關的舊信資料庫(archive)。
+
+
+
+
+
+ mailing lists 可有摘要版呢?
+
+
+
+ 當然也有,請看
+ Mailman 網頁介面。
+
+
+
+
+
+
+ Mailing List 的參與禮儀
+
+ 在 mailing lists 上參與討論,就像在其他社群一樣,我們都需要一些溝通上的共識。
+ 發言請注重禮儀(或默契),切勿無的放矢。
+
+
+
+
+ 在發文之前,有什麼注意事項呢?
+
+
+
+ 最重要的是你已經看了這篇文章,然而,若您對 &os; 不熟的話,
+ 可能需要先廣泛閱讀
+ 相關書籍及文章
+ 來先熟悉這套作業系統和一些典故,尤其是其中的
+ &os; 常見問答集 (FAQ) 文件,
+
+ &os; 使用手冊(Handbook),
+ 以及相關文章:
+ How to get best results from the FreeBSD-questions mailing list、
+
+ Explaining BSD、以及
+ &os; First Steps。
+
+ 此外,對上述文件內已有解答的部份又提出來問的話,會被認為是相當不禮貌的。
+ 這並不是因為這群志工是相當吝於回答的,而是一再被相同的問題不斷疲勞轟炸之後,所產生的挫折感很重。
+ 尤其是現成答案明明就在眼前,卻仍同樣問題滿天飛,這實在是...。
+ 請注意:這些 &os; 相關文件幾乎都是由一群無薪志工的好心成果,而他們也是人。
+
+
+
+
+
+
+ 如何避免不當發文呢?
+
+
+
+
+
+ 發文時,請務必遵守該 mailing list 的遊戲規則。
+
+
+
+ 不要作人身攻擊。好的網路公民,應該要有更高的言行標準。
+
+
+
+ 請不要試圖作 Spam 行為(廣告、轉貼多處等不請自來行為)。
+ 所有 mailing lists 都會積極禁止這些違規者,一旦有的話,那麼後果請自行負責。
+
+
+
+
+
+
+
+ 發文時,有什麼該注意的嗎?
+
+
+
+
+
+ 發文時,請保持一行約 75 個字元就自動斷行,因為並不是每個看的人都有很炫的圖形介面(GUI)看信軟體。
+
+
+
+ 請注意:事實上,網路頻寬並不是無限的。
+ 並非每個讀者的頻寬都很大,所以若想貼一些像是 config.log
+ 之類的設定檔內容,或是大量的 stack trace 紀錄,那麼請把它放在自己網站上,然後貼出該網址 URL 就行了。
+ 還有一件事,請記住,這些信件都會被舊信資料庫保存下來,所以這樣作會造成保存的資料庫會很快被塞到很大,
+ 甚至可能塞爆 Server 的硬碟空間。
+
+
+
+ 文章是要讓人看得懂,所以請注意版面編排的可讀性,還有..
+ 千 萬 不 要 大 聲 嚷 叫!!!!! 這點可不只 &os; mailing lists 才需如此注意,
+ 請勿低估文章『基本編排』的重要性、連鎖效應。
+ 信中的表達方式通常就代表著別人眼中的你,若文章讓人看了很吃力(霧煞煞)、拼字錯誤百出、
+ 充滿語意或邏輯錯誤、或是文內充滿一堆驚嘆號,這會讓人對你印象觀感極差。
+
+
+
+ 在一些特定的 list 場合,請用適當的語言來溝通。許多非英語系的mailing
+ lists 可以到
+
+ 這邊 查看看。
+
+ 對於許多母語不是英語的人,我們都能諒解他們的苦楚,並且試著儘量多多包涵。
+ 英文非母語的人,我們會儘量不惡意批評拼字或文法錯誤之處。
+ &os; 在這方面,一直有相當優秀的紀錄,請讓我們繼續保持這傳統吧。
+
+
+
+ 寫信時,請用相容標準的 Mail User Agent (MUA)程式。
+ 不良的(或設定錯誤的)寄信程式
+ 這裡列有許多信件格式的錯誤示範。以下是一些已知的寄信程式的不良示範:
+
+
+
+ cc:Mail
+
+
+
+ (舊版的)&eudora;
+
+
+
+ exmh
+
+
+
+ µsoft; Exchange
+
+
+
+ µsoft; Internet Mail
+
+
+
+ µsoft; &outlook;
+
+
+
+ (舊版的)&netscape;
+
+
+
+ 如同上述所見,Microsoft 出的一堆寄信程式通常都是不相容標準格式的。
+ 請儘量改用 &unix; 上的寄信程式。若必須在 Microsoft 環境下使用寄信程式的話,
+ 請記得確認設定是否正確。請儘量不要用 MIME 格式:
+ 因為有一堆人都在濫用 MIME 信件格式。
+
+
+
+ 請確認:時間與時區設定是否正確。
+ 這問題看起來有點蠢,因為你寄出的信還是會到達 mailing list 上,
+ 但是呢,每位 mailing lists 上的訂戶每天都會看數百封的信,
+ 他們通常會把信件以標題跟時間作為排序依據。
+ 若你的信沒有在第一篇正解之前就先出現的話,他們就會假設可能是漏收你這封信,
+ 然後就沒再去看你那封信了。
+
+
+
+ 請提供程式出現的相關訊息,像是 &man.dmesg.8; 或者 console
+ messages 也就是通常會出現在 /var/log/messages 出現的。
+ 請不要用手打,因為這不僅很苦,而且也可能打錯字或亂掉原有格式。請直接把相關的 log 檔丟出來,
+ 或是用編輯器來剪裁、或是用滑鼠複製/貼上來完成。舉個例子,如果是要把像是 dmesg
+ 的程式訊息倒入到某個檔案去的話,那麼作法如下:
+
+ &prompt.user; dmesg > /tmp/dmesg.out
+
+ 這樣子會把訊息送到 /tmp/dmesg.out 檔內。
+
+
+
+ 在用滑鼠剪貼時,請注意是否有犯一些細節的剪貼壞習慣。
+ 尤其是像貼 Makefiles 之類檔案時,由於 tab
+ 鍵所打出來的分格,是屬於特殊字元。因此,在
+ GNATS PR 資料庫 上很常看到這類很常見的惱人問題:
+ Makefiles 內的 tab 經過剪貼後,變成『空白(white space)』
+ 或是困擾的 =3B escape sequence,這些會讓 committers 們十分不爽。
+
+
+
+
+
+
+
+ 在 mailing lists 上回文的話,有什麼要特別注意的嗎?
+
+
+
+
+
+ 請適當調整文章引言長度。回文時,引言部份請引『有談到的』部分為主,但請不要過與不及。
+ 應該保留涉及討論範圍的原文,這樣子才能讓沒看過前面文章的人知道是在講什麼,而非一頭霧水。
+
+ 還有一點也很重要,原文若是幅度相當長的話,記得註明 "yes, I see this too"。
+
+
+
+ 善用技巧來確認原文與自己寫的部份:
+ 通常會在原文的每行前面加上 > 以作記號。
+ 請記得保留 > 符號後面的空白,並且在原文以及你所寫的段落之間加上空行,
+ 以便閱讀。
+
+
+
+ 請不要斷章取義、穿鑿附會:通常對原始文章『斷章取義』、『穿鑿附會』會讓大家很不爽,因為他們原意並非如此,卻被曲解。
+
+
+
+ 回文時,不要寫在原文上面(top post)。
+ 這個意思是:若要回文時,請寫在原文下方,不要寫在原文上面,以免讓人有時空錯置的錯亂混淆。
+
+
+
+ 答: Because it reverses the logical flow of
+ conversation.
+
+
+ 問: Why is top posting frowned upon?
+
+
+ (感謝 Randy Bush 提供笑話)
+
+
+
+
+
+
+
+
+ Mailing Lists 上的重複性問題
+
+ 在 mailing lists 上參與討論,就像在其他社群一樣,我們都需要一些溝通上的共識。
+ 許多 mailing lists 都會假設參與討論者都大致知道 FreeBSD 計劃的一些歷史淵源。
+ 尤其是社群的新手總是定期會不斷重複問類似問題。
+ 每個發文的人,都有責任來避免掉入這樣的惡性循環輪迴內。
+ 因此,應儘可能讓 mailing list 上能正常討論,而避免讓自己陷入筆戰泥沼。
+
+ 要怎麼避免呢?最好的方法就是善用這些
+ mailing list 舊信資料庫(archives),來瞭解相關背景。
+ 正由於這原因,所以
+ mailing list 搜尋介面 就顯得非常好用。
+ (若這方法仍無法找到有用的答案,那麼請改用自己愛用的搜尋引擎吧)
+
+ 透過這些舊信資料庫,不只可瞭解先前討論過哪些話題,也可以知道:是怎麼討論的、
+ 哪些人參與討論過、主要看的人又是哪些人。
+ 入境隨俗這些原則不只是 &os; mailing list 上才這樣,一樣可以適合其他地方。
+
+ archives 的內容無疑地相當廣泛,而且會有些問題不斷反覆出現,
+ 有時討論到後面總會離題。無論如何,在發問前的義務就是先做好功課,
+ 以避免這類的月經文惡性循環,尤其是令人反感的 bikeshed(打嘴砲)。
+
+
+
+ 什麼是 "Bikeshed" 呀?
+ 單就字面上意思解釋的話,bikeshed 是指專門給腳踏車、機車之類的兩輪交通工具使用的遮雨棚,
+ 然而呢,在 &os; 這邊的說法卻有其他意思(帶有貶抑)指的是:
+ 某些特定話題的重複討論,尤其是指在 &os; 社群內絕不會有共識,且有爭議的話題。
+ (這字彙的起源在
+ 這份文件 內有更多說明)。你只要在發信到任一 &os; mailing lists 之前,知道這個基本概念就行了。
+
+ 一般來講,『bikeshed』是很容易產生許多波的筆戰與額外討論的爭議話題,如果事先不知道這些背景的話。
+
+ 拜託,請幫個忙讓討論回歸正常,而不要只是到處打嘴砲而已。感恩!
+
+
+
+ 致謝
+
+
+
+ &a.grog;
+
+
+ How to get best results from the FreeBSD-questions mailing list 一文的原作者,
+ 我們從他這文內獲得許多 mailing list 上的禮儀(或默契)寫作題材。
+
+
+
+
+ &a.linimon;
+
+ 本 FAQ 雛形的原作
+
+
+
+
+
+
diff --git a/zh_TW.Big5/articles/pr-guidelines/Makefile b/zh_TW.Big5/articles/pr-guidelines/Makefile
new file mode 100644
index 0000000000..9aa329f736
--- /dev/null
+++ b/zh_TW.Big5/articles/pr-guidelines/Makefile
@@ -0,0 +1,19 @@
+#
+# $FreeBSD$
+#
+# Article: Problem Report Handling Guidelines
+
+DOC?= article
+
+FORMATS?= html
+WITH_ARTICLE_TOC?= YES
+
+INSTALL_COMPRESSED?=gz
+INSTALL_ONLY_COMPRESSED?=
+
+SRCS= article.sgml
+
+URL_RELPREFIX?= ../../../..
+DOC_PREFIX?= ${.CURDIR}/../../..
+
+.include "${DOC_PREFIX}/share/mk/doc.project.mk"
diff --git a/zh_TW.Big5/articles/pr-guidelines/article.sgml b/zh_TW.Big5/articles/pr-guidelines/article.sgml
new file mode 100644
index 0000000000..8df326229e
--- /dev/null
+++ b/zh_TW.Big5/articles/pr-guidelines/article.sgml
@@ -0,0 +1,881 @@
+
+
+
+
+
+
+
+%articles.ent;
+
+
+]>
+
+
+
+
+ 問題回報(PR)的處理原則
+
+ $FreeBSD$
+
+
+ &tm-attrib.freebsd;
+ &tm-attrib.opengroup;
+ &tm-attrib.general;
+
+
+
+ 這篇文章主要在講:由 FreeBSD PR 維護小組所提出的一些 FreeBSD 問題回報(PR)
+ 建議,希望大家在弄 PR 時都能遵守。
+
+
+
+
+ Dag-Erling
+ Smørgrav
+
+
+
+ Hiten
+ Pandya
+
+
+
+
+
+
+ 前言
+
+ GNATS 是 FReeBSD 計劃所採用的一套專門管理錯誤(回報bug) 系統。
+ 由於對 FreeBSD 品質保證而言,是否能準確掌握各項錯誤回報與進度是十分重要的,
+ 因此,如何正確有效使用 GNATS 也就必須注意。
+
+ Access to GNATS is available to FreeBSD developers, as well as
+ to the wider community. 為了讓 GNATS 資料庫使用上儘量一致,於是就產生了怎麼處理像是:followup(回文)、關閉PR等的參考原則。
+
+
+
+ 問題回報(PR)的生命週期
+
+
+
+ 首先,回報者(originator)以 &man.send-pr.1; 送出 PR,然後會收到一封確認信。
+
+
+
+ 然後,committer 們就會有人(假設叫做 Joe)發掘有興趣的 PR 並將該 PR 指派給自己來處理。
+ 或者 bugbuster 會有人(假設叫做 Jane) 就會下決定:她覺得 Joe 比較適合處理,就將該 PR 指派(assign)給他
+
+
+
+ Joe 會先與有問題的回報者作些意見交流(以確定這問題有進入 audit 追蹤流程內)
+ 以及判斷問題點。
+ 然後再確定問題點有寫入 audit 追蹤流程之後,然後把該 PR 狀態設為
+ analyzed(已分析)。
+
+
+
+ Joe 開始徹夜找出問題解法,然後將 patch 送到 follow-up(回文用),並請回報者協助測試是否正常。
+ 然後,他就會將 PR 狀態設為 feedback 囉。
+
+
+
+ 如此重複 analyzed、feedback 幾趟之後,直到 Joe 與回報者雙方都相當滿意 patch 結果,
+ 於是就會將 patch 給 commits 進入 -CURRENT (或者若 -CURRENT
+ 上面沒這問題的話,就直接送到 -STABLE),在 commit log 內要把相關 PR 寫上去
+ (同時回報者若有送完整或部分 patch 的話,就順便記載),然後,若沒什麼事的話,就開始準備 MFC 哩。
+ (譯註:MFC意指 Merged From CURRENT ,也就是把 -CURRENT 上的東西併入 -STABLE。
+
+
+
+ 若該 patch 不需要 MFC 的話,Joe 就會關掉(close)該 PR 了。
+
+
+
+ 若該 patch 需要 MFC 的話,Joe 會把 PR 狀態改為 patched(已修正),
+ 直到已經 MFC 完畢,才會 close(關掉)。
+
+
+
+
+ 很多送出來的 PR 都很少附上問題的相關訊息,而有些則是相當複雜難搞,
+ 或只是提到部分表面問題而已;
+ 遇到這種情況時,是非常需要得到所有相關訊息以便解決問題。
+ 若遇到這種無解的問題或再次發生的話,就必須要 re-open(重新開啟) 該 PR,以待解決。
+
+
+ PR 上所附的 email address 可能因某些原因而無法收信時,遇到這種狀況,通常就是
+ followup 該 PR ,並(在 followup 時)請回報者重新提供可正常收信的 email address。
+ 當系統上的 mail 系統關閉或沒裝的時候,這通常是在使用 &man.send-pr.1; 的替代方案。
+
+
+
+
+ 問題回報(PR)的狀態
+
+ 若 PR 有任何變化的話,請務必記得更新 PR 的『狀態(state)』。
+ 『狀態』應該要能正確反映該 PR 的目前進度才是。
+
+
+ 以下是更改 PR 狀態的小例子:
+
+ 當有可以修正問題的 PR 出現,而相關負責的 developer(s)
+ 也覺得這樣的修正可以接受,他們會 followup 該 PR,並將其狀態改為
+ feedback。同時,回報者應重新評估最終的修正結果,並回應:所回報的錯誤是否已成功修正。
+
+
+ 每份 PR 通常會有下面這幾種狀態之一:
+
+
+
+ open
+
+ PR 最初的狀態:這個問題被提出來,並在等待處理中。
+
+
+
+
+ analyzed
+
+ 已經開始處理這問題,並且有找到疑似解決的方法。
+
+
+
+
+ feedback
+
+ 需要回報者提供更詳細的相關資料,正如教學要因材施教,治病也要因人下藥,越多相關訊息,才能有最佳效果。
+
+
+
+
+ patched
+
+ 已經送相關 patch 了,但仍因某些原因(MFC,或來自回報者的確認結果異常)因此尚未完畢。
+
+
+
+
+ suspended(暫緩)
+
+ 因為沒附上相關訊息或參考資料,所以還沒辦法處理這問題。
+ This is a prime candidate for
+ somebody who is looking for a project to take on. If the
+ problem cannot be solved at all, it will be closed, rather
+ than suspended. The documentation project uses
+ suspended for wish-list
+ items that entail a significant amount of work which no one
+ currently has time for.
+
+
+
+
+ closed
+
+ A problem report is closed when any changes have been
+ integrated, documented, and tested, or when fixing the
+ problem is abandoned.
+
+
+
+
+
+ The patched state is directly related to
+ feedback, so you may go directly to closed state if
+ the originator cannot test the patch, and it works in your own testing.
+
+
+
+
+ 問題回報(PR)的種類
+
+ While handling problem reports, either as a developer who has
+ direct access to the GNATS database or as a contributor who
+ browses the database and submits followups with patches, comments,
+ suggestions or change requests, you will come across several
+ different types of PRs.
+
+
+
+ PRs not yet assigned to anyone.
+
+
+ PRs already assigned to someone.
+
+
+ 重複的 PR
+
+
+ Stale PRs
+
+
+ Misfiled PRs
+
+
+
+ The following sections describe what each different type of
+ PRs is used for, when a PR belongs to one of these types, and what
+ treatment each different type receives.
+
+
+ Unassigned PRs
+
+ When PRs arrive, they are initially assigned to a generic
+ (placeholder) assignee. These are always prepended with
+ freebsd-. The exact value for this default
+ depends on the category; in most cases, it corresponds to a
+ specific &os; mailing list. Here is the current list, with
+ the most common ones listed first:
+
+
+ Default Assignees — most common
+
+
+
+ Type
+ Categories
+ Default Assignee
+
+
+
+
+
+ base system
+ bin, conf, gnu, kern, misc
+ freebsd-bugs
+
+
+
+ architecture-specific
+ alpha, i386, ia64, powerpc, sparc64
+ freebsd-arch
+
+
+
+ ports collection
+ ports
+ freebsd-ports-bugs
+
+
+
+ documentation shipped with the system
+ docs
+ freebsd-doc
+
+
+
+ &os; web pages (not including docs)
+ www
+ freebsd-www
+
+
+
+
+ Do not be surprised to find that the submitter of the
+ PR has assigned it to the wrong category. If you fix the
+ category, do not forget to fix the assignment as well.
+ (In particular, our submitters seem to have a hard time
+ understanding that just because their problem manifested
+ on an i386 system, that it might be generic to all of &os;,
+ and thus be more appropriate for kern.
+ The converse is also true, of course.)
+
+ Certain PRs may be reassigned away from these generic
+ assignees by anyone. For assignees which are mailing lists,
+ please use the long form when making the assignment (e.g.,
+ freebsd-foo instead of foo);
+ this will avoid duplicate emails sent to the mailing list.
+
+
+ Here is a sample list of such entities; it is probably
+ not complete. In some cases, entries that have the short form are
+ aliases, not mailing lists.
+
+
+
+ Common Assignees — base system
+
+
+
+ Type
+ Suggested Category
+ Suggested Assignee
+
+
+
+
+
+ problem specific to the &arm; architecture
+ kern
+ freebsd-arm
+
+
+
+ problem specific to the &mips; architecture
+ kern
+ freebsd-mips
+
+
+
+ problem specific to the &powerpc; architecture
+ kern
+ freebsd-ppc
+
+
+
+ problem with Advanced Configuration and Power
+ Management (&man.acpi.4;)
+ kern
+ freebsd-acpi
+
+
+
+ problem with Asynchronous Transfer Mode (ATM)
+ drivers
+ kern
+ freebsd-atm
+
+
+
+ problem with &firewire; drivers
+ kern
+ freebsd-firewire
+
+
+
+ problem with the filesystem code
+ kern
+ freebsd-fs
+
+
+
+ problem with the &man.geom.4; subsystem
+ kern
+ freebsd-geom
+
+
+
+ problem with the &man.ipfw.4; subsystem
+ kern
+ freebsd-ipfw
+
+
+
+ problem with Integrated Services Digital Network
+ (ISDN) drivers
+ kern
+ freebsd-isdn
+
+
+
+ problem with &linux; or SVR4 emulation
+ kern
+ freebsd-emulation
+
+
+
+ problem with the networking stack
+ kern
+ freebsd-net
+
+
+
+ problem with PicoBSD
+ kern
+ freebsd-small
+
+
+
+ problem with the &man.pf.4; subsystem
+ kern
+ freebsd-pf
+
+
+
+ problem with the &man.scsi.4; subsystem
+ kern
+ freebsd-scsi
+
+
+
+ problem with the &man.sound.4; subsystem
+ kern
+ freebsd-multimedia
+
+
+
+ problem with &man.sysinstall.8;
+ bin
+ freebsd-qa
+
+
+
+ problem with the system startup scripts
+ (&man.rc.8;)
+ kern
+ freebsd-rc
+
+
+
+
+
+ Common Assignees — Ports Collection
+
+
+
+ Type
+ Suggested Category
+ Suggested Assignee
+
+
+
+
+
+ problem with the ports framework
+ (not with an individual port!)
+ ports
+ portmgr
+
+
+
+ port which is maintained by apache@FreeBSD.org
+ ports
+ apache
+
+
+
+ port which is maintained by eclipse@FreeBSD.org
+ ports
+ freebsd-eclipse
+
+
+
+ port which is maintained by gnome@FreeBSD.org
+ ports
+ gnome
+
+
+
+ port which is maintained by haskell@FreeBSD.org
+ ports
+ haskell
+
+
+
+ port which is maintained by java@FreeBSD.org
+ ports
+ freebsd-java
+
+
+
+ port which is maintained by kde@FreeBSD.org
+ ports
+ kde
+
+
+
+ port which is maintained by
+ openoffice@FreeBSD.org
+ ports
+ freebsd-openoffice
+
+
+
+ port which is maintained by perl@FreeBSD.org
+ ports
+ perl
+
+
+
+ port which is maintained by python@FreeBSD.org
+ ports
+ freebsd-python
+
+
+
+ port which is maintained by x11@FreeBSD.org
+ ports
+ freebsd-x11
+
+
+
"StackGuard detects and defeats stack
+ smashing attacks by protecting the return address on the stack
+ from being altered. StackGuard places a "canary" word next to
+ the return address when a function is called. If the canary
+ word has been altered when the function returns, then a stack
+ smashing attack has been attempted, and the program responds
+ by emitting an intruder alert into syslog, and then
+ halts."
+
+
"StackGuard is implemented as a small patch
+ to the gcc code generator, specifically the function_prolog()
+ and function_epilog() routines. function_prolog() has been
+ enhanced to lay down canaries on the stack when functions
+ start, and function_epilog() checks canary integrity when the
+ function exits. Any attempt at corrupting the return address
+ is thus detected before the function
+ returns."
+
+If successful, open() returns a non-negative
+integer, termed a file descriptor. It returns -1 on failure,
+and sets errno to indicate the error.
+
+
+
+
+The assembly language programmer new to &unix; and FreeBSD will
+immediately ask the puzzling question: Where is
+errno and how do I get to it?
+
+
+
+
+The information presented in the manual pages applies
+to C programs. The assembly language programmer needs additional
+information.
+
+
+
+
+
+
+Where Are the Return Values?
+
+
+Unfortunately, it depends... For most system calls it is
+in EAX, but not for all.
+A good rule of thumb,
+when working with a system call for
+the first time, is to look for
+the return value in EAX.
+If it is not there, you
+need further research.
+
+
+
+
+I am aware of one system call that returns the value in
+EDX: SYS_fork. All others
+I have worked with use EAX.
+But I have not worked with them all yet.
+
+
+
+
+
+If you cannot find the answer here or anywhere else,
+study libc source code and see how it
+interfaces with the kernel.
+
+
+
+
+
+Where Is errno?
+
+
+Actually, nowhere...
+
+
+
+errno is part of the C language, not the
+&unix; kernel. When accessing kernel services directly, the
+error code is returned in EAX,
+the same register the proper
+return value generally ends up in.
+
+
+
+This makes perfect sense. If there is no error, there is
+no error code. If there is an error, there is no return
+value. One register can contain either.
+
+
+
+
+
+Determining an Error Occurred
+
+
+When using the standard FreeBSD calling convention,
+the carry flag is cleared upon success,
+set upon failure.
+
+
+
+When using the Linux emulation mode, the signed
+value in EAX is non-negative upon success,
+and contains the return value. In case of an error, the value
+is negative, i.e., -errno.
+
+
+
+
+
+
+
+Creating Portable Code
+
+
+Portability is generally not one of the strengths of assembly language.
+Yet, writing assembly language programs for different platforms is
+possible, especially with nasm. I have written
+assembly language libraries that can be assembled for such different
+operating systems as &windows; and FreeBSD.
+
+
+
+It is all the more possible when you want your code to run
+on two platforms which, while different, are based on
+similar architectures.
+
+
+
+For example, FreeBSD is &unix;, Linux is &unix; like. I only
+mentioned three differences between them (from an assembly language
+programmer's perspective): The calling convention, the
+function numbers, and the way of returning values.
+
+
+Dealing with Function Numbers
+
+
+In many cases the function numbers are the same. However,
+even when they are not, the problem is easy to deal with:
+Instead of using numbers in your code, use constants which
+you have declared differently depending on the target
+architecture:
+
+
+
+%ifdef LINUX
+%define SYS_execve 11
+%else
+%define SYS_execve 59
+%endif
+
+
+Dealing with Conventions
+
+Both, the calling convention, and the return value (the
+errno problem) can be resolved with macros:
+
+
+
+%ifdef LINUX
+
+%macro system 0
+ call kernel
+%endmacro
+
+align 4
+kernel:
+ push ebx
+ push ecx
+ push edx
+ push esi
+ push edi
+ push ebp
+
+ mov ebx, [esp+32]
+ mov ecx, [esp+36]
+ mov edx, [esp+40]
+ mov esi, [esp+44]
+ mov ebp, [esp+48]
+ int 80h
+
+ pop ebp
+ pop edi
+ pop esi
+ pop edx
+ pop ecx
+ pop ebx
+
+ or eax, eax
+ js .errno
+ clc
+ ret
+
+.errno:
+ neg eax
+ stc
+ ret
+
+%else
+
+%macro system 0
+ int 80h
+%endmacro
+
+%endif
+
+
+
+
+Dealing with Other Portability Issues
+
+
+The above solutions can handle most cases of writing code
+portable between FreeBSD and Linux. Nevertheless, with some
+kernel services the differences are deeper.
+
+
+
+In that case, you need to write two different handlers
+for those particular system calls, and use conditional
+assembly. Luckily, most of your code does something other
+than calling the kernel, so usually you will only need
+a few such conditional sections in your code.
+
+
+
+
+Using a Library
+
+
+You can avoid portability issues in your main code altogether
+by writing a library of system calls. Create a separate library
+for FreeBSD, a different one for Linux, and yet other libraries
+for more operating systems.
+
+
+
+In your library, write a separate function (or procedure, if
+you prefer the traditional assembly language terminology) for each system
+call. Use the C calling convention of passing parameters.
+But still use EAX to pass the call number in.
+In that case, your FreeBSD library can be very simple, as
+many seemingly different functions can be just labels to
+the same code:
+
+
+
+sys.open:
+sys.close:
+[etc...]
+ int 80h
+ ret
+
+
+
+Your Linux library will require more different functions.
+But even here you can group system calls using the same
+number of parameters:
+
+
+
+sys.exit:
+sys.close:
+[etc... one-parameter functions]
+ push ebx
+ mov ebx, [esp+12]
+ int 80h
+ pop ebx
+ jmp sys.return
+
+...
+
+sys.return:
+ or eax, eax
+ js sys.err
+ clc
+ ret
+
+sys.err:
+ neg eax
+ stc
+ ret
+
+
+
+The library approach may seem inconvenient at first because
+it requires you to produce a separate file your code depends
+on. But it has many advantages: For one, you only need to
+write it once and can use it for all your programs. You can
+even let other assembly language programmers use it, or perhaps use
+one written by someone else. But perhaps the greatest
+advantage of the library is that your code can be ported
+to other systems, even by other programmers, by simply
+writing a new library without any changes to your code.
+
+
+
+If you do not like the idea of having a library, you can
+at least place all your system calls in a separate assembly language file
+and link it with your main program. Here, again, all porters
+have to do is create a new object file to link with your
+main program.
+
+
+
+
+
+Using an Include File
+
+
+If you are releasing your software as (or with)
+source code, you can use macros and place them
+in a separate file, which you include in your
+code.
+
+
+
+Porters of your software will simply write a new
+include file. No library or external object file
+is necessary, yet your code is portable without any
+need to edit the code.
+
+
+
+
+This is the approach we will use throughout this chapter.
+We will name our include file system.inc, and
+add to it whenever we deal with a new system call.
+
+
+
+
+We can start our system.inc by declaring the
+standard file descriptors:
+
+
+
+%define stdin 0
+%define stdout 1
+%define stderr 2
+
+
+
+Next, we create a symbolic name for each system call:
+
+
+
+%define SYS_nosys 0
+%define SYS_exit 1
+%define SYS_fork 2
+%define SYS_read 3
+%define SYS_write 4
+; [etc...]
+
+
+
+We add a short, non-global procedure with a long name,
+so we do not accidentally reuse the name in our code:
+
+
+
+section .text
+align 4
+access.the.bsd.kernel:
+ int 80h
+ ret
+
+
+
+We create a macro which takes one argument, the syscall number:
+
+
+
+%macro system 1
+ mov eax, %1
+ call access.the.bsd.kernel
+%endmacro
+
+
+
+Finally, we create macros for each syscall. These macros take
+no arguments.
+
+
+
+%macro sys.exit 0
+ system SYS_exit
+%endmacro
+
+%macro sys.fork 0
+ system SYS_fork
+%endmacro
+
+%macro sys.read 0
+ system SYS_read
+%endmacro
+
+%macro sys.write 0
+ system SYS_write
+%endmacro
+
+; [etc...]
+
+
+
+Go ahead, enter it into your editor and save it as
+system.inc. We will add more to it as we
+discuss more syscalls.
+
+
+
+
+
+
+
+Our First Program
+
+
+We are now ready for our first program, the mandatory
+Hello, World!
+
+
+
+ 1: %include 'system.inc'
+ 2:
+ 3: section .data
+ 4: hello db 'Hello, World!', 0Ah
+ 5: hbytes equ $-hello
+ 6:
+ 7: section .text
+ 8: global _start
+ 9: _start:
+10: push dword hbytes
+11: push dword hello
+12: push dword stdout
+13: sys.write
+14:
+15: push dword 0
+16: sys.exit
+
+
+
+Here is what it does: Line 1 includes the defines, the macros,
+and the code from system.inc.
+
+
+
+Lines 3-5 are the data: Line 3 starts the data section/segment.
+Line 4 contains the string "Hello, World!" followed by a new
+line (0Ah). Line 5 creates a constant that contains
+the length of the string from line 4 in bytes.
+
+
+
+Lines 7-16 contain the code. Note that FreeBSD uses the elf
+file format for its executables, which requires every
+program to start at the point labeled _start (or, more
+precisely, the linker expects that). This label has to be
+global.
+
+
+
+Lines 10-13 ask the system to write hbytes bytes
+of the hello string to stdout.
+
+
+
+Lines 15-16 ask the system to end the program with the return
+value of 0. The SYS_exit syscall never
+returns, so the code ends there.
+
+
+
+
+If you have come to &unix; from &ms-dos;
+assembly language background, you may be used to writing directly
+to the video hardware. You will never have to worry about
+this in FreeBSD, or any other flavor of &unix;. As far as
+you are concerned, you are writing to a file known as
+stdout. This can be the video screen, or
+a telnet terminal, or an actual file,
+or even the input of another program. Which one it is,
+is for the system to figure out.
+
+
+
+Assembling the Code
+
+
+Type the code (except the line numbers) in an editor, and save
+it in a file named hello.asm. You need
+nasm to assemble it.
+
+
+Installing nasm
+
+
+If you do not have nasm, type:
+
+
+&prompt.user; su
+Password:your root password
+&prompt.root; cd /usr/ports/devel/nasm
+&prompt.root; make install
+&prompt.root; exit
+&prompt.user;
+
+
+You may type make install clean instead of just
+make install if you do not want to keep
+nasm source code.
+
+
+
+Either way, FreeBSD will automatically download
+nasm from the Internet,
+compile it, and install it on your system.
+
+
+
+
+If your system is not FreeBSD, you need to get
+nasm from its
+home
+page. You can still use it to assemble FreeBSD code.
+
+
+
+
+Now you can assemble, link, and run the code:
+
+
+&prompt.user; nasm -f elf hello.asm
+&prompt.user; ld -s -o hello hello.o
+&prompt.user; ./hello
+Hello, World!
+&prompt.user;
+
+
+
+
+
+
+
+
+Writing &unix; Filters
+
+
+A common type of &unix; application is a filter—a program
+that reads data from the stdin, processes it
+somehow, then writes the result to stdout.
+
+
+
+In this chapter, we shall develop a simple filter, and
+learn how to read from stdin and write to
+stdout. This filter will convert each byte
+of its input into a hexadecimal number followed by a
+blank space.
+
+
+
+%include 'system.inc'
+
+section .data
+hex db '0123456789ABCDEF'
+buffer db 0, 0, ' '
+
+section .text
+global _start
+_start:
+ ; read a byte from stdin
+ push dword 1
+ push dword buffer
+ push dword stdin
+ sys.read
+ add esp, byte 12
+ or eax, eax
+ je .done
+
+ ; convert it to hex
+ movzx eax, byte [buffer]
+ mov edx, eax
+ shr dl, 4
+ mov dl, [hex+edx]
+ mov [buffer], dl
+ and al, 0Fh
+ mov al, [hex+eax]
+ mov [buffer+1], al
+
+ ; print it
+ push dword 3
+ push dword buffer
+ push dword stdout
+ sys.write
+ add esp, byte 12
+ jmp short _start
+
+.done:
+ push dword 0
+ sys.exit
+
+
+In the data section we create an array called hex.
+It contains the 16 hexadecimal digits in ascending order.
+The array is followed by a buffer which we will use for
+both input and output. The first two bytes of the buffer
+are initially set to 0. This is where we will write
+the two hexadecimal digits (the first byte also is
+where we will read the input). The third byte is a
+space.
+
+
+
+The code section consists of four parts: Reading the byte,
+converting it to a hexadecimal number, writing the result,
+and eventually exiting the program.
+
+
+
+To read the byte, we ask the system to read one byte
+from stdin, and store it in the first byte
+of the buffer. The system returns the number
+of bytes read in EAX. This will be 1
+while data is coming, or 0, when no more input
+data is available. Therefore, we check the value of
+EAX. If it is 0,
+we jump to .done, otherwise we continue.
+
+
+
+
+For simplicity sake, we are ignoring the possibility
+of an error condition at this time.
+
+
+
+
+The hexadecimal conversion reads the byte from the
+buffer into EAX, or actually just
+AL, while clearing the remaining bits of
+EAX to zeros. We also copy the byte to
+EDX because we need to convert the upper
+four bits (nibble) separately from the lower
+four bits. We store the result in the first two
+bytes of the buffer.
+
+
+
+Next, we ask the system to write the three bytes
+of the buffer, i.e., the two hexadecimal digits and
+the blank space, to stdout. We then
+jump back to the beginning of the program and
+process the next byte.
+
+
+
+Once there is no more input left, we ask the system
+to exit our program, returning a zero, which is
+the traditional value meaning the program was
+successful.
+
+
+
+Go ahead, and save the code in a file named hex.asm,
+then type the following (the ^D means press the
+control key and type D while holding the
+control key down):
+
+
+&prompt.user; nasm -f elf hex.asm
+&prompt.user; ld -s -o hex hex.o
+&prompt.user; ./hex
+Hello, World!
+48 65 6C 6C 6F 2C 20 57 6F 72 6C 64 21 0A Here I come!
+48 65 72 65 20 49 20 63 6F 6D 65 21 0A ^D &prompt.user;
+
+
+
+If you are migrating to &unix; from &ms-dos;,
+you may be wondering why each line ends with 0A
+instead of 0D 0A.
+This is because &unix; does not use the cr/lf convention, but
+a "new line" convention, which is 0A in hexadecimal.
+
+
+
+
+Can we improve this? Well, for one, it is a bit confusing because
+once we have converted a line of text, our input no longer
+starts at the beginning of the line. We can modify it to print
+a new line instead of a space after each 0A:
+
+
+
+%include 'system.inc'
+
+section .data
+hex db '0123456789ABCDEF'
+buffer db 0, 0, ' '
+
+section .text
+global _start
+_start:
+ mov cl, ' '
+
+.loop:
+ ; read a byte from stdin
+ push dword 1
+ push dword buffer
+ push dword stdin
+ sys.read
+ add esp, byte 12
+ or eax, eax
+ je .done
+
+ ; convert it to hex
+ movzx eax, byte [buffer]
+ mov [buffer+2], cl
+ cmp al, 0Ah
+ jne .hex
+ mov [buffer+2], al
+
+.hex:
+ mov edx, eax
+ shr dl, 4
+ mov dl, [hex+edx]
+ mov [buffer], dl
+ and al, 0Fh
+ mov al, [hex+eax]
+ mov [buffer+1], al
+
+ ; print it
+ push dword 3
+ push dword buffer
+ push dword stdout
+ sys.write
+ add esp, byte 12
+ jmp short .loop
+
+.done:
+ push dword 0
+ sys.exit
+
+
+We have stored the space in the CL register. We can
+do this safely because, unlike µsoft.windows;, &unix; system
+calls do not modify the value of any register they do not use
+to return a value in.
+
+
+
+That means we only need to set CL once. We have, therefore,
+added a new label .loop and jump to it for the next byte
+instead of jumping at _start. We have also added the
+.hex label so we can either have a blank space or a
+new line as the third byte of the buffer.
+
+
+
+Once you have changed hex.asm to reflect
+these changes, type:
+
+
+&prompt.user; nasm -f elf hex.asm
+&prompt.user; ld -s -o hex hex.o
+&prompt.user; ./hex
+Hello, World!
+48 65 6C 6C 6F 2C 20 57 6F 72 6C 64 21 0A
+Here I come!
+48 65 72 65 20 49 20 63 6F 6D 65 21 0A
+^D &prompt.user;
+
+
+That looks better. But this code is quite inefficient! We
+are making a system call for every single byte twice (once
+to read it, another time to write the output).
+
+
+
+
+
+Buffered Input and Output
+
+
+We can improve the efficiency of our code by buffering our
+input and output. We create an input buffer and read a whole
+sequence of bytes at one time. Then we fetch them one by one
+from the buffer.
+
+
+
+We also create an output buffer. We store our output in it until
+it is full. At that time we ask the kernel to write the contents
+of the buffer to stdout.
+
+
+
+The program ends when there is no more input. But we still need
+to ask the kernel to write the contents of our output buffer
+to stdout one last time, otherwise some of our output
+would make it to the output buffer, but never be sent out.
+Do not forget that, or you will be wondering why some of your
+output is missing.
+
+
+
+%include 'system.inc'
+
+%define BUFSIZE 2048
+
+section .data
+hex db '0123456789ABCDEF'
+
+section .bss
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+
+section .text
+global _start
+_start:
+ sub eax, eax
+ sub ebx, ebx
+ sub ecx, ecx
+ mov edi, obuffer
+
+.loop:
+ ; read a byte from stdin
+ call getchar
+
+ ; convert it to hex
+ mov dl, al
+ shr al, 4
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, dl
+ and al, 0Fh
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, ' '
+ cmp dl, 0Ah
+ jne .put
+ mov al, dl
+
+.put:
+ call putchar
+ jmp short .loop
+
+align 4
+getchar:
+ or ebx, ebx
+ jne .fetch
+
+ call read
+
+.fetch:
+ lodsb
+ dec ebx
+ ret
+
+read:
+ push dword BUFSIZE
+ mov esi, ibuffer
+ push esi
+ push dword stdin
+ sys.read
+ add esp, byte 12
+ mov ebx, eax
+ or eax, eax
+ je .done
+ sub eax, eax
+ ret
+
+align 4
+.done:
+ call write ; flush output buffer
+ push dword 0
+ sys.exit
+
+align 4
+putchar:
+ stosb
+ inc ecx
+ cmp ecx, BUFSIZE
+ je write
+ ret
+
+align 4
+write:
+ sub edi, ecx ; start of buffer
+ push ecx
+ push edi
+ push dword stdout
+ sys.write
+ add esp, byte 12
+ sub eax, eax
+ sub ecx, ecx ; buffer is empty now
+ ret
+
+
+We now have a third section in the source code, named
+.bss. This section is not included in our
+executable file, and, therefore, cannot be initialized. We use
+resb instead of db.
+It simply reserves the requested size of uninitialized memory
+for our use.
+
+
+
+We take advantage of the fact that the system does not modify the
+registers: We use registers for what, otherwise, would have to be
+global variables stored in the .data section. This is
+also why the &unix; convention of passing parameters to system calls
+on the stack is superior to the Microsoft convention of passing
+them in the registers: We can keep the registers for our own use.
+
+
+
+We use EDI and ESI as pointers to the next byte
+to be read from or written to. We use EBX and
+ECX to keep count of the number of bytes in the
+two buffers, so we know when to dump the output to, or read more
+input from, the system.
+
+
+
+Let us see how it works now:
+
+
+&prompt.user; nasm -f elf hex.asm
+&prompt.user; ld -s -o hex hex.o
+&prompt.user; ./hex
+Hello, World!
+Here I come!
+48 65 6C 6C 6F 2C 20 57 6F 72 6C 64 21 0A
+48 65 72 65 20 49 20 63 6F 6D 65 21 0A
+^D &prompt.user;
+
+
+Not what you expected? The program did not print the output
+until we pressed ^D. That is easy to fix by
+inserting three lines of code to write the output every time
+we have converted a new line to 0A. I have marked
+the three lines with > (do not copy the > in your
+hex.asm).
+
+
+
+%include 'system.inc'
+
+%define BUFSIZE 2048
+
+section .data
+hex db '0123456789ABCDEF'
+
+section .bss
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+
+section .text
+global _start
+_start:
+ sub eax, eax
+ sub ebx, ebx
+ sub ecx, ecx
+ mov edi, obuffer
+
+.loop:
+ ; read a byte from stdin
+ call getchar
+
+ ; convert it to hex
+ mov dl, al
+ shr al, 4
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, dl
+ and al, 0Fh
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, ' '
+ cmp dl, 0Ah
+ jne .put
+ mov al, dl
+
+.put:
+ call putchar
+> cmp al, 0Ah
+> jne .loop
+> call write
+ jmp short .loop
+
+align 4
+getchar:
+ or ebx, ebx
+ jne .fetch
+
+ call read
+
+.fetch:
+ lodsb
+ dec ebx
+ ret
+
+read:
+ push dword BUFSIZE
+ mov esi, ibuffer
+ push esi
+ push dword stdin
+ sys.read
+ add esp, byte 12
+ mov ebx, eax
+ or eax, eax
+ je .done
+ sub eax, eax
+ ret
+
+align 4
+.done:
+ call write ; flush output buffer
+ push dword 0
+ sys.exit
+
+align 4
+putchar:
+ stosb
+ inc ecx
+ cmp ecx, BUFSIZE
+ je write
+ ret
+
+align 4
+write:
+ sub edi, ecx ; start of buffer
+ push ecx
+ push edi
+ push dword stdout
+ sys.write
+ add esp, byte 12
+ sub eax, eax
+ sub ecx, ecx ; buffer is empty now
+ ret
+
+
+
+Now, let us see how it works:
+
+
+&prompt.user; nasm -f elf hex.asm
+&prompt.user; ld -s -o hex hex.o
+&prompt.user; ./hex
+Hello, World!
+48 65 6C 6C 6F 2C 20 57 6F 72 6C 64 21 0A
+Here I come!
+48 65 72 65 20 49 20 63 6F 6D 65 21 0A
+^D &prompt.user;
+
+
+Not bad for a 644-byte executable, is it!
+
+
+
+
+This approach to buffered input/output still
+contains a hidden danger. I will discuss—and
+fix—it later, when I talk about the
+dark
+side of buffering.
+
+
+
+How to Unread a Character
+
+
+This may be a somewhat advanced topic, mostly of interest to
+programmers familiar with the theory of compilers. If you wish,
+you may skip to the next
+section, and perhaps read this later.
+
+
+
+While our sample program does not require it, more sophisticated
+filters often need to look ahead. In other words, they may need
+to see what the next character is (or even several characters).
+If the next character is of a certain value, it is part of the
+token currently being processed. Otherwise, it is not.
+
+
+
+For example, you may be parsing the input stream for a textual
+string (e.g., when implementing a language compiler): If a
+character is followed by another character, or perhaps a digit,
+it is part of the token you are processing. If it is followed by
+white space, or some other value, then it is not part of the
+current token.
+
+
+
+This presents an interesting problem: How to return the next
+character back to the input stream, so it can be read again
+later?
+
+
+
+One possible solution is to store it in a character variable,
+then set a flag. We can modify getchar to check the flag,
+and if it is set, fetch the byte from that variable instead of the
+input buffer, and reset the flag. But, of course, that slows us
+down.
+
+
+
+The C language has an ungetc() function, just for that
+purpose. Is there a quick way to implement it in our code?
+I would like you to scroll back up and take a look at the
+getchar procedure and see if you can find a nice and
+fast solution before reading the next paragraph. Then come back
+here and see my own solution.
+
+
+
+The key to returning a character back to the stream is in how
+we are getting the characters to start with:
+
+
+
+First we check if the buffer is empty by testing the value
+of EBX. If it is zero, we call the
+read procedure.
+
+
+
+If we do have a character available, we use lodsb, then
+decrease the value of EBX. The lodsb
+instruction is effectively identical to:
+
+
+
+ mov al, [esi]
+ inc esi
+
+
+
+The byte we have fetched remains in the buffer until the next
+time read is called. We do not know when that happens,
+but we do know it will not happen until the next call to
+getchar. Hence, to "return" the last-read byte back
+to the stream, all we have to do is decrease the value of
+ESI and increase the value of EBX:
+
+
+
+ungetc:
+ dec esi
+ inc ebx
+ ret
+
+
+
+But, be careful! We are perfectly safe doing this if our look-ahead
+is at most one character at a time. If we are examining more than
+one upcoming character and call ungetc several times
+in a row, it will work most of the time, but not all the time
+(and will be tough to debug). Why?
+
+
+
+Because as long as getchar does not have to call
+read, all of the pre-read bytes are still in the buffer,
+and our ungetc works without a glitch. But the moment
+getchar calls read,
+the contents of the buffer change.
+
+
+
+We can always rely on ungetc working properly on the last
+character we have read with getchar, but not on anything
+we have read before that.
+
+
+
+If your program reads more than one byte ahead, you have at least
+two choices:
+
+
+
+If possible, modify the program so it only reads one byte ahead.
+This is the simplest solution.
+
+
+
+If that option is not available, first of all determine the maximum
+number of characters your program needs to return to the input
+stream at one time. Increase that number slightly, just to be
+sure, preferably to a multiple of 16—so it aligns nicely.
+Then modify the .bss section of your code, and create
+a small "spare" buffer right before your input buffer,
+something like this:
+
+
+
+section .bss
+ resb 16 ; or whatever the value you came up with
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+
+
+
+You also need to modify your ungetc to pass the value
+of the byte to unget in AL:
+
+
+
+ungetc:
+ dec esi
+ inc ebx
+ mov [esi], al
+ ret
+
+
+
+With this modification, you can call ungetc
+up to 17 times in a row safely (the first call will still
+be within the buffer, the remaining 16 may be either within
+the buffer or within the "spare").
+
+
+
+
+
+
+Command Line Arguments
+
+
+Our hex program will be more useful if it can
+read the names of an input and output file from its command
+line, i.e., if it can process the command line arguments.
+But... Where are they?
+
+
+
+Before a &unix; system starts a program, it pushes some
+data on the stack, then jumps at the _start
+label of the program. Yes, I said jumps, not calls. That means the
+data can be accessed by reading [esp+offset],
+or by simply popping it.
+
+
+
+The value at the top of the stack contains the number of
+command line arguments. It is traditionally called
+argc, for "argument count."
+
+
+
+Command line arguments follow next, all argc of them.
+These are typically referred to as argv, for
+"argument value(s)." That is, we get argv[0],
+argv[1], ...,
+argv[argc-1]. These are not the actual
+arguments, but pointers to arguments, i.e., memory addresses of
+the actual arguments. The arguments themselves are
+NUL-terminated character strings.
+
+
+
+The argv list is followed by a NULL pointer,
+which is simply a 0. There is more, but this is
+enough for our purposes right now.
+
+
+
+
+If you have come from the &ms-dos; programming
+environment, the main difference is that each argument is in
+a separate string. The second difference is that there is no
+practical limit on how many arguments there can be.
+
+
+
+
+Armed with this knowledge, we are almost ready for the next
+version of hex.asm. First, however, we need to
+add a few lines to system.inc:
+
+
+
+First, we need to add two new entries to our list of system
+call numbers:
+
+
+
+%define SYS_open 5
+%define SYS_close 6
+
+
+
+Then we add two new macros at the end of the file:
+
+
+
+%macro sys.open 0
+ system SYS_open
+%endmacro
+
+%macro sys.close 0
+ system SYS_close
+%endmacro
+
+
+
+Here, then, is our modified source code:
+
+
+
+%include 'system.inc'
+
+%define BUFSIZE 2048
+
+section .data
+fd.in dd stdin
+fd.out dd stdout
+hex db '0123456789ABCDEF'
+
+section .bss
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+
+section .text
+align 4
+err:
+ push dword 1 ; return failure
+ sys.exit
+
+align 4
+global _start
+_start:
+ add esp, byte 8 ; discard argc and argv[0]
+
+ pop ecx
+ jecxz .init ; no more arguments
+
+ ; ECX contains the path to input file
+ push dword 0 ; O_RDONLY
+ push ecx
+ sys.open
+ jc err ; open failed
+
+ add esp, byte 8
+ mov [fd.in], eax
+
+ pop ecx
+ jecxz .init ; no more arguments
+
+ ; ECX contains the path to output file
+ push dword 420 ; file mode (644 octal)
+ push dword 0200h | 0400h | 01h
+ ; O_CREAT | O_TRUNC | O_WRONLY
+ push ecx
+ sys.open
+ jc err
+
+ add esp, byte 12
+ mov [fd.out], eax
+
+.init:
+ sub eax, eax
+ sub ebx, ebx
+ sub ecx, ecx
+ mov edi, obuffer
+
+.loop:
+ ; read a byte from input file or stdin
+ call getchar
+
+ ; convert it to hex
+ mov dl, al
+ shr al, 4
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, dl
+ and al, 0Fh
+ mov al, [hex+eax]
+ call putchar
+
+ mov al, ' '
+ cmp dl, 0Ah
+ jne .put
+ mov al, dl
+
+.put:
+ call putchar
+ cmp al, dl
+ jne .loop
+ call write
+ jmp short .loop
+
+align 4
+getchar:
+ or ebx, ebx
+ jne .fetch
+
+ call read
+
+.fetch:
+ lodsb
+ dec ebx
+ ret
+
+read:
+ push dword BUFSIZE
+ mov esi, ibuffer
+ push esi
+ push dword [fd.in]
+ sys.read
+ add esp, byte 12
+ mov ebx, eax
+ or eax, eax
+ je .done
+ sub eax, eax
+ ret
+
+align 4
+.done:
+ call write ; flush output buffer
+
+ ; close files
+ push dword [fd.in]
+ sys.close
+
+ push dword [fd.out]
+ sys.close
+
+ ; return success
+ push dword 0
+ sys.exit
+
+align 4
+putchar:
+ stosb
+ inc ecx
+ cmp ecx, BUFSIZE
+ je write
+ ret
+
+align 4
+write:
+ sub edi, ecx ; start of buffer
+ push ecx
+ push edi
+ push dword [fd.out]
+ sys.write
+ add esp, byte 12
+ sub eax, eax
+ sub ecx, ecx ; buffer is empty now
+ ret
+
+
+
+In our .data section we now have two new variables,
+fd.in and fd.out. We store the input and
+output file descriptors here.
+
+
+
+In the .text section we have replaced the references
+to stdin and stdout with
+[fd.in] and [fd.out].
+
+
+
+The .text section now starts with a simple error
+handler, which does nothing but exit the program with a return
+value of 1.
+The error handler is before _start so we are
+within a short distance from where the errors occur.
+
+
+
+Naturally, the program execution still begins at _start.
+First, we remove argc and argv[0] from the
+stack: They are of no interest to us (in this program, that is).
+
+
+
+We pop argv[1] to ECX. This
+register is particularly suited for pointers, as we can handle
+NULL pointers with jecxz. If argv[1]
+is not NULL, we try to open the file named in the first
+argument. Otherwise, we continue the program as before: Reading
+from stdin, writing to stdout.
+If we fail to open the input file (e.g., it does not exist),
+we jump to the error handler and quit.
+
+
+
+If all went well, we now check for the second argument. If
+it is there, we open the output file. Otherwise, we send
+the output to stdout. If we fail to open the output
+file (e.g., it exists and we do not have the write permission),
+we, again, jump to the error handler.
+
+
+
+The rest of the code is the same as before, except we close
+the input and output files before exiting, and, as mentioned,
+we use [fd.in] and [fd.out].
+
+
+
+Our executable is now a whopping 768 bytes long.
+
+
+
+Can we still improve it? Of course! Every program can be improved.
+Here are a few ideas of what we could do:
+
+
+
+
+
+Have our error handler print a message to
+stderr.
+
+
+
+
+
+Add error handlers to the read
+and write functions.
+
+
+
+
+
+Close stdin when we open an input file,
+stdout when we open an output file.
+
+
+
+
+
+Add command line switches, such as -i
+and -o, so we can list the input and
+output files in any order, or perhaps read from
+stdin and write to a file.
+
+
+
+
+
+Print a usage message if command line arguments are incorrect.
+
+
+
+
+
+I shall leave these enhancements as an exercise to the reader:
+You already know everything you need to know to implement them.
+
+
+
+
+
+&unix; Environment
+
+
+An important &unix; concept is the environment, which is defined by
+environment variables. Some are set by the system, others
+by you, yet others by the shell, or any program
+that loads another program.
+
+
+
+How to Find Environment Variables
+
+
+I said earlier that when a program starts executing, the stack
+contains argc followed by the NULL-terminated
+argv array, followed by something else. The
+"something else" is the environment, or,
+to be more precise, a NULL-terminated array of pointers to
+environment variables. This is often referred
+to as env.
+
+
+
+The structure of env is the same as that of
+argv, a list of memory addresses followed by a
+NULL (0). In this case, there is no
+"envc"—we figure out where the array ends
+by searching for the final NULL.
+
+
+
+The variables usually come in the name=value
+format, but sometimes the =value part
+may be missing. We need to account for that possibility.
+
+
+
+
+
+webvars
+
+
+I could just show you some code that prints the environment
+the same way the &unix; env command does. But
+I thought it would be more interesting to write a simple
+assembly language CGI utility.
+
+
+
+CGI: A Quick Overview
+
+
+I have a
+detailed
+CGI tutorial on my web site,
+but here is a very quick overview of CGI:
+
+
+
+
+
+The web server communicates with the CGI
+program by setting environment variables.
+
+
+
+
+
+The CGI program
+sends its output to stdout.
+The web server reads it from there.
+
+
+
+
+
+It must start with an HTTP
+header followed by two blank lines.
+
+
+
+
+
+It then prints the HTML
+code, or whatever other type of data it is producing.
+
+
+
+
+
+
+While certain environment variables use
+standard names, others vary, depending on the web server. That
+makes webvars
+quite a useful diagnostic tool.
+
+
+
+
+
+
+The Code
+
+
+Our webvars program, then, must send out
+the HTTP header followed by some
+HTML mark-up. It then must read
+the environment variables one by one
+and send them out as part of the
+HTML page.
+
+
+
+The code follows. I placed comments and explanations
+right inside the code:
+
+
+
+;;;;;;; webvars.asm ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; Copyright (c) 2000 G. Adam Stanislav
+; All rights reserved.
+;
+; Redistribution and use in source and binary forms, with or without
+; modification, are permitted provided that the following conditions
+; are met:
+; 1. Redistributions of source code must retain the above copyright
+; notice, this list of conditions and the following disclaimer.
+; 2. Redistributions in binary form must reproduce the above copyright
+; notice, this list of conditions and the following disclaimer in the
+; documentation and/or other materials provided with the distribution.
+;
+; THIS SOFTWARE IS PROVIDED BY THE AUTHOR AND CONTRIBUTORS ``AS IS'' AND
+; ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE
+; IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE
+; ARE DISCLAIMED. IN NO EVENT SHALL THE AUTHOR OR CONTRIBUTORS BE LIABLE
+; FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL
+; DAMAGES (INCLUDING, BUT NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS
+; OR SERVICES; LOSS OF USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION)
+; HOWEVER CAUSED AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
+; LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY
+; OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF
+; SUCH DAMAGE.
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; Version 1.0
+;
+; Started: 8-Dec-2000
+; Updated: 8-Dec-2000
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+%include 'system.inc'
+
+section .data
+http db 'Content-type: text/html', 0Ah, 0Ah
+ db '<?xml version="1.0" encoding="UTF-8"?>', 0Ah
+ db '<!DOCTYPE html PUBLIC "-//W3C/DTD XHTML Strict//EN" '
+ db '"DTD/xhtml1-strict.dtd">', 0Ah
+ db '<html xmlns="http://www.w3.org/1999/xhtml" '
+ db 'xml.lang="en" lang="en">', 0Ah
+ db '<head>', 0Ah
+ db '<title>Web Environment</title>', 0Ah
+ db '<meta name="author" content="G. Adam Stanislav" />', 0Ah
+ db '</head>', 0Ah, 0Ah
+ db '<body bgcolor="#ffffff" text="#000000" link="#0000ff" '
+ db 'vlink="#840084" alink="#0000ff">', 0Ah
+ db '<div class="webvars">', 0Ah
+ db '<h1>Web Environment</h1>', 0Ah
+ db '<p>The following <b>environment variables</b> are defined '
+ db 'on this web server:</p>', 0Ah, 0Ah
+ db '<table align="center" width="80" border="0" cellpadding="10" '
+ db 'cellspacing="0" class="webvars">', 0Ah
+httplen equ $-http
+left db '<tr>', 0Ah
+ db '<td class="name"><tt>'
+leftlen equ $-left
+middle db '</tt></td>', 0Ah
+ db '<td class="value"><tt><b>'
+midlen equ $-middle
+undef db '<i>(undefined)</i>'
+undeflen equ $-undef
+right db '</b></tt></td>', 0Ah
+ db '</tr>', 0Ah
+rightlen equ $-right
+wrap db '</table>', 0Ah
+ db '</div>', 0Ah
+ db '</body>', 0Ah
+ db '</html>', 0Ah, 0Ah
+wraplen equ $-wrap
+
+section .text
+global _start
+_start:
+ ; First, send out all the http and xhtml stuff that is
+ ; needed before we start showing the environment
+ push dword httplen
+ push dword http
+ push dword stdout
+ sys.write
+
+ ; Now find how far on the stack the environment pointers
+ ; are. We have 12 bytes we have pushed before "argc"
+ mov eax, [esp+12]
+
+ ; We need to remove the following from the stack:
+ ;
+ ; The 12 bytes we pushed for sys.write
+ ; The 4 bytes of argc
+ ; The EAX*4 bytes of argv
+ ; The 4 bytes of the NULL after argv
+ ;
+ ; Total:
+ ; 20 + eax * 4
+ ;
+ ; Because stack grows down, we need to ADD that many bytes
+ ; to ESP.
+ lea esp, [esp+20+eax*4]
+ cld ; This should already be the case, but let's be sure.
+
+ ; Loop through the environment, printing it out
+.loop:
+ pop edi
+ or edi, edi ; Done yet?
+ je near .wrap
+
+ ; Print the left part of HTML
+ push dword leftlen
+ push dword left
+ push dword stdout
+ sys.write
+
+ ; It may be tempting to search for the '=' in the env string next.
+ ; But it is possible there is no '=', so we search for the
+ ; terminating NUL first.
+ mov esi, edi ; Save start of string
+ sub ecx, ecx
+ not ecx ; ECX = FFFFFFFF
+ sub eax, eax
+repne scasb
+ not ecx ; ECX = string length + 1
+ mov ebx, ecx ; Save it in EBX
+
+ ; Now is the time to find '='
+ mov edi, esi ; Start of string
+ mov al, '='
+repne scasb
+ not ecx
+ add ecx, ebx ; Length of name
+
+ push ecx
+ push esi
+ push dword stdout
+ sys.write
+
+ ; Print the middle part of HTML table code
+ push dword midlen
+ push dword middle
+ push dword stdout
+ sys.write
+
+ ; Find the length of the value
+ not ecx
+ lea ebx, [ebx+ecx-1]
+
+ ; Print "undefined" if 0
+ or ebx, ebx
+ jne .value
+
+ mov ebx, undeflen
+ mov edi, undef
+
+.value:
+ push ebx
+ push edi
+ push dword stdout
+ sys.write
+
+ ; Print the right part of the table row
+ push dword rightlen
+ push dword right
+ push dword stdout
+ sys.write
+
+ ; Get rid of the 60 bytes we have pushed
+ add esp, byte 60
+
+ ; Get the next variable
+ jmp .loop
+
+.wrap:
+ ; Print the rest of HTML
+ push dword wraplen
+ push dword wrap
+ push dword stdout
+ sys.write
+
+ ; Return success
+ push dword 0
+ sys.exit
+
+
+
+This code produces a 1,396-byte executable. Most of it is data,
+i.e., the HTML mark-up we need to send out.
+
+
+
+Assemble and link it as usual:
+
+
+&prompt.user; nasm -f elf webvars.asm
+&prompt.user; ld -s -o webvars webvars.o
+
+
+To use it, you need to upload webvars to your
+web server. Depending on how your web server is set up, you
+may have to store it in a special cgi-bin directory,
+or perhaps rename it with a .cgi extension.
+
+
+
+Then you need to use your browser to view its output.
+To see its output on my web server, please go to
+http://www.int80h.org/webvars/.
+If curious about the additional environment variables
+present in a password protected web directory, go to
+http://www.int80h.org/private/,
+using the name asm and password
+programmer.
+
+
+
+
+
+
+
+
+
+Working with Files
+
+
+We have already done some basic file work: We know how
+to open and close them, how to read and write them using
+buffers. But &unix; offers much more functionality when it
+comes to files. We will examine some of it in this section,
+and end up with a nice file conversion utility.
+
+
+
+Indeed, let us start at the end, that is, with the file
+conversion utility. It always makes programming easier
+when we know from the start what the end product is
+supposed to do.
+
+
+
+One of the first programs I wrote for &unix; was
+tuc,
+a text-to-&unix; file converter. It converts a text
+file from other operating systems to a &unix; text file.
+In other words, it changes from different kind of line endings
+to the newline convention of &unix;. It saves the output
+in a different file. Optionally, it converts a &unix; text
+file to a DOS text file.
+
+
+
+I have used tuc extensively, but always
+only to convert from some other OS
+to &unix;, never the other way. I have always wished
+it would just overwrite the file instead of me having
+to send the output to a different file. Most of the time,
+I end up using it like this:
+
+
+&prompt.user; tuc myfile tempfile
+&prompt.user; mv tempfile myfile
+
+
+It would be nice to have a ftuc,
+i.e., fast tuc, and use it like this:
+
+
+&prompt.user; ftuc myfile
+
+
+In this chapter, then, we will write
+ftuc in assembly language
+(the original tuc
+is in C), and study various
+file-oriented kernel services in the process.
+
+
+
+At first sight, such a file conversion is very
+simple: All you have to do is strip the carriage
+returns, right?
+
+
+
+If you answered yes, think again: That approach will
+work most of the time (at least with MS
+DOS text files), but will fail occasionally.
+
+
+
+The problem is that not all non &unix; text files end their
+line with the carriage return / line feed sequence. Some
+use carriage returns without line feeds. Others combine several
+blank lines into a single carriage return followed by several
+line feeds. And so on.
+
+
+
+A text file converter, then, must be able to handle
+any possible line endings:
+
+
+
+
+
+carriage return / line feed
+
+
+
+
+
+carriage return
+
+
+
+
+
+line feed / carriage return
+
+
+
+
+
+line feed
+
+
+
+
+
+It should also handle files that use some kind of a
+combination of the above (e.g., carriage return followed
+by several line feeds).
+
+
+
+Finite State Machine
+
+
+The problem is easily solved by the use of a technique
+called finite state machine, originally developed
+by the designers of digital electronic circuits. A
+finite state machine is a digital circuit
+whose output is dependent not only on its input but on
+its previous input, i.e., on its state. The microprocessor
+is an example of a finite state machine: Our
+assembly language code is assembled to machine language in which
+some assembly language code produces a single byte
+of machine language, while others produce several bytes.
+As the microprocessor fetches the bytes from the memory
+one by one, some of them simply change its state rather than
+produce some output. When all the bytes of the op code are
+fetched, the microprocessor produces some output, or changes
+the value of a register, etc.
+
+
+
+Because of that, all software is essentially a sequence of state
+instructions for the microprocessor. Nevertheless, the concept
+of finite state machine is useful in software design as well.
+
+
+
+Our text file converter can be designed as a finite state machine with three
+possible states. We could call them states 0-2,
+but it will make our life easier if we give them symbolic names:
+
+
+
+
+
+ordinary
+
+
+
+
+
+cr
+
+
+
+
+
+lf
+
+
+
+
+
+Our program will start in the ordinary
+state. During this state, the program action depends on
+its input as follows:
+
+
+
+
+
+If the input is anything other than a carriage return
+or line feed, the input is simply passed on to the output. The
+state remains unchanged.
+
+
+
+
+
+If the input is a carriage return, the state is changed
+to cr. The input is then discarded, i.e.,
+no output is made.
+
+
+
+
+
+If the input is a line feed, the state is changed to
+lf. The input is then discarded.
+
+
+
+
+
+Whenever we are in the cr state, it is
+because the last input was a carriage return, which was
+unprocessed. What our software does in this state again
+depends on the current input:
+
+
+
+
+
+If the input is anything other than a carriage return
+or line feed, output a line feed, then output the input, then
+change the state to ordinary.
+
+
+
+
+
+If the input is a carriage return, we have received
+two (or more) carriage returns in a row. We discard the
+input, we output a line feed, and leave the state unchanged.
+
+
+
+
+
+If the input is a line feed, we output the line feed
+and change the state to ordinary. Note that
+this is not the same as the first case above – if we tried
+to combine them, we would be outputting two line feeds
+instead of one.
+
+
+
+
+
+Finally, we are in the lf state after
+we have received a line feed that was not preceded by a
+carriage return. This will happen when our file already is
+in &unix; format, or whenever several lines in a row are
+expressed by a single carriage return followed by several
+line feeds, or when line ends with a line feed /
+carriage return sequence. Here is how we need to handle
+our input in this state:
+
+
+
+
+
+If the input is anything other than a carriage return or
+line feed, we output a line feed, then output the input, then
+change the state to ordinary. This is exactly
+the same action as in the cr state upon
+receiving the same kind of input.
+
+
+
+
+
+If the input is a carriage return, we discard the input,
+we output a line feed, then change the state to ordinary.
+
+
+
+
+
+If the input is a line feed, we output the line feed,
+and leave the state unchanged.
+
+
+
+
+
+The Final State
+
+
+The above finite state machine works for the entire file, but leaves
+the possibility that the final line end will be ignored. That will
+happen whenever the file ends with a single carriage return or
+a single line feed. I did not think of it when I wrote
+tuc, just to discover that
+occasionally it strips the last line ending.
+
+
+
+This problem is easily fixed by checking the state after the
+entire file was processed. If the state is not
+ordinary, we simply
+need to output one last line feed.
+
+
+
+
+Now that we have expressed our algorithm as a finite state machine,
+we could easily design a dedicated digital electronic
+circuit (a "chip") to do the conversion for us. Of course,
+doing so would be considerably more expensive than writing
+an assembly language program.
+
+
+
+
+
+
+The Output Counter
+
+
+Because our file conversion program may be combining two
+characters into one, we need to use an output counter. We
+initialize it to 0, and increase it
+every time we send a character to the output. At the end of
+the program, the counter will tell us what size we need
+to set the file to.
+
+
+
+
+
+
+
+Implementing FSM in Software
+
+
+The hardest part of working with a finite state machine
+is analyzing the problem and expressing it as a
+finite state machine. That accomplished,
+the software almost writes itself.
+
+
+
+In a high-level language, such as C, there are several main
+approaches. One is to use a switch statement
+which chooses what function should be run. For example,
+
+
+
+ switch (state) {
+ default:
+ case REGULAR:
+ regular(inputchar);
+ break;
+ case CR:
+ cr(inputchar);
+ break;
+ case LF:
+ lf(inputchar);
+ break;
+ }
+
+
+
+Another approach is by using an array of function pointers,
+something like this:
+
+
+
+ (output[state])(inputchar);
+
+
+
+Yet another is to have state be a
+function pointer, set to point at the appropriate function:
+
+
+
+ (*state)(inputchar);
+
+
+This is the approach we will use in our program because it is very easy to do in assembly language, and very fast, too. We will simply keep the address of the right procedure in EBX, and then just issue:
+
+
+ call ebx
+
+
+
+This is possibly faster than hardcoding the address in the code
+because the microprocessor does not have to fetch the address from
+the memory—it is already stored in one of its registers. I said
+possibly because with the caching modern
+microprocessors do, either way may be equally fast.
+
+
+
+
+
+Memory Mapped Files
+
+
+Because our program works on a single file, we cannot use the
+approach that worked for us before, i.e., to read from an input
+file and to write to an output file.
+
+
+
+&unix; allows us to map a file, or a section of a file,
+into memory. To do that, we first need to open the file with the
+appropriate read/write flags. Then we use the mmap
+system call to map it into the memory. One nice thing about
+mmap is that it automatically works with
+virtual memory: We can map more of the file into the memory than
+we have physical memory available, yet still access it through
+regular memory op codes, such as mov,
+lods, and stos.
+Whatever changes we make to the memory image of the file will be
+written to the file by the system. We do not even have to keep
+the file open: As long as it stays mapped, we can
+read from it and write to it.
+
+
+
+The 32-bit Intel microprocessors can access up to four
+gigabytes of memory – physical or virtual. The FreeBSD system
+allows us to use up to a half of it for file mapping.
+
+
+
+For simplicity sake, in this tutorial we will only convert files
+that can be mapped into the memory in their entirety. There are
+probably not too many text files that exceed two gigabytes in size.
+If our program encounters one, it will simply display a message
+suggesting we use the original
+tuc instead.
+
+
+
+If you examine your copy of syscalls.master,
+you will find two separate syscalls named mmap.
+This is because of evolution of &unix;: There was the traditional
+BSD mmap,
+syscall 71. That one was superseded by the &posix; mmap,
+syscall 197. The FreeBSD system supports both because
+older programs were written by using the original BSD
+version. But new software uses the &posix; version,
+which is what we will use.
+
+
+
+The syscalls.master file lists
+the &posix; version like this:
+
+
+
+197 STD BSD { caddr_t mmap(caddr_t addr, size_t len, int prot, \
+ int flags, int fd, long pad, off_t pos); }
+
+
+
+This differs slightly from what
+mmap2
+says. That is because
+mmap2
+describes the C version.
+
+
+
+The difference is in the long pad argument, which is not present in the C version. However, the FreeBSD syscalls add a 32-bit pad after pushing a 64-bit argument. In this case, off_t is a 64-bit value.
+
+
+When we are finished working with a memory-mapped file,
+we unmap it with the munmap syscall:
+
+
+
+
+For an in-depth treatment of mmap, see
+W. Richard Stevens'
+Unix
+Network Programming, Volume 2, Chapter 12.
+
+
+
+
+
+
+Determining File Size
+
+
+Because we need to tell mmap how many bytes
+of the file to map into the memory, and because we want to map
+the entire file, we need to determine the size of the file.
+
+
+
+We can use the fstat syscall to get all
+the information about an open file that the system can give us.
+That includes the file size.
+
+
+
+Again, syscalls.master lists two versions
+of fstat, a traditional one
+(syscall 62), and a &posix; one
+(syscall 189). Naturally, we will use the
+&posix; version:
+
+
+
+189 STD POSIX { int fstat(int fd, struct stat *sb); }
+
+
+
+This is a very straightforward call: We pass to it the address
+of a stat structure and the descriptor
+of an open file. It will fill out the contents of the
+stat structure.
+
+
+
+I do, however, have to say that I tried to declare the
+stat structure in the
+.bss section, and
+fstat did not like it: It set the carry
+flag indicating an error. After I changed the code to allocate
+the structure on the stack, everything was working fine.
+
+
+
+
+
+Changing the File Size
+
+
+Because our program may combine carriage return / line feed
+sequences into straight line feeds, our output may be smaller
+than our input. However, since we are placing our output into
+the same file we read the input from, we may have to change the
+size of the file.
+
+
+
+The ftruncate system call allows us to do
+just that. Despite its somewhat misleading name, the
+ftruncate system call can be used to both
+truncate the file (make it smaller) and to grow it.
+
+
+
+And yes, we will find two versions of ftruncate
+in syscalls.master, an older one
+(130), and a newer one (201). We will use
+the newer one:
+
+
+
+201 STD BSD { int ftruncate(int fd, int pad, off_t length); }
+
+
+
+Please note that this one contains a int pad again.
+
+
+
+
+
+ftuc
+
+
+We now know everything we need to write ftuc.
+We start by adding some new lines in system.inc.
+First, we define some constants and structures, somewhere at
+or near the beginning of the file:
+
+
+
+;;;;;;; open flags
+%define O_RDONLY 0
+%define O_WRONLY 1
+%define O_RDWR 2
+
+;;;;;;; mmap flags
+%define PROT_NONE 0
+%define PROT_READ 1
+%define PROT_WRITE 2
+%define PROT_EXEC 4
+;;
+%define MAP_SHARED 0001h
+%define MAP_PRIVATE 0002h
+
+;;;;;;; stat structure
+struc stat
+st_dev resd 1 ; = 0
+st_ino resd 1 ; = 4
+st_mode resw 1 ; = 8, size is 16 bits
+st_nlink resw 1 ; = 10, ditto
+st_uid resd 1 ; = 12
+st_gid resd 1 ; = 16
+st_rdev resd 1 ; = 20
+st_atime resd 1 ; = 24
+st_atimensec resd 1 ; = 28
+st_mtime resd 1 ; = 32
+st_mtimensec resd 1 ; = 36
+st_ctime resd 1 ; = 40
+st_ctimensec resd 1 ; = 44
+st_size resd 2 ; = 48, size is 64 bits
+st_blocks resd 2 ; = 56, ditto
+st_blksize resd 1 ; = 64
+st_flags resd 1 ; = 68
+st_gen resd 1 ; = 72
+st_lspare resd 1 ; = 76
+st_qspare resd 4 ; = 80
+endstruc
+
+
+
+We define the new syscalls:
+
+
+
+%define SYS_mmap 197
+%define SYS_munmap 73
+%define SYS_fstat 189
+%define SYS_ftruncate 201
+
+
+
+We add the macros for their use:
+
+
+
+%macro sys.mmap 0
+ system SYS_mmap
+%endmacro
+
+%macro sys.munmap 0
+ system SYS_munmap
+%endmacro
+
+%macro sys.ftruncate 0
+ system SYS_ftruncate
+%endmacro
+
+%macro sys.fstat 0
+ system SYS_fstat
+%endmacro
+
+
+
+And here is our code:
+
+
+
+;;;;;;; Fast Text-to-Unix Conversion (ftuc.asm) ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;;
+;; Started: 21-Dec-2000
+;; Updated: 22-Dec-2000
+;;
+;; Copyright 2000 G. Adam Stanislav.
+;; All rights reserved.
+;;
+;;;;;;; v.1 ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+%include 'system.inc'
+
+section .data
+ db 'Copyright 2000 G. Adam Stanislav.', 0Ah
+ db 'All rights reserved.', 0Ah
+usg db 'Usage: ftuc filename', 0Ah
+usglen equ $-usg
+co db "ftuc: Can't open file.", 0Ah
+colen equ $-co
+fae db 'ftuc: File access error.', 0Ah
+faelen equ $-fae
+ftl db 'ftuc: File too long, use regular tuc instead.', 0Ah
+ftllen equ $-ftl
+mae db 'ftuc: Memory allocation error.', 0Ah
+maelen equ $-mae
+
+section .text
+
+align 4
+memerr:
+ push dword maelen
+ push dword mae
+ jmp short error
+
+align 4
+toolong:
+ push dword ftllen
+ push dword ftl
+ jmp short error
+
+align 4
+facerr:
+ push dword faelen
+ push dword fae
+ jmp short error
+
+align 4
+cantopen:
+ push dword colen
+ push dword co
+ jmp short error
+
+align 4
+usage:
+ push dword usglen
+ push dword usg
+
+error:
+ push dword stderr
+ sys.write
+
+ push dword 1
+ sys.exit
+
+align 4
+global _start
+_start:
+ pop eax ; argc
+ pop eax ; program name
+ pop ecx ; file to convert
+ jecxz usage
+
+ pop eax
+ or eax, eax ; Too many arguments?
+ jne usage
+
+ ; Open the file
+ push dword O_RDWR
+ push ecx
+ sys.open
+ jc cantopen
+
+ mov ebp, eax ; Save fd
+
+ sub esp, byte stat_size
+ mov ebx, esp
+
+ ; Find file size
+ push ebx
+ push ebp ; fd
+ sys.fstat
+ jc facerr
+
+ mov edx, [ebx + st_size + 4]
+
+ ; File is too long if EDX != 0 ...
+ or edx, edx
+ jne near toolong
+ mov ecx, [ebx + st_size]
+ ; ... or if it is above 2 GB
+ or ecx, ecx
+ js near toolong
+
+ ; Do nothing if the file is 0 bytes in size
+ jecxz .quit
+
+ ; Map the entire file in memory
+ push edx
+ push edx ; starting at offset 0
+ push edx ; pad
+ push ebp ; fd
+ push dword MAP_SHARED
+ push dword PROT_READ | PROT_WRITE
+ push ecx ; entire file size
+ push edx ; let system decide on the address
+ sys.mmap
+ jc near memerr
+
+ mov edi, eax
+ mov esi, eax
+ push ecx ; for SYS_munmap
+ push edi
+
+ ; Use EBX for state machine
+ mov ebx, ordinary
+ mov ah, 0Ah
+ cld
+
+.loop:
+ lodsb
+ call ebx
+ loop .loop
+
+ cmp ebx, ordinary
+ je .filesize
+
+ ; Output final lf
+ mov al, ah
+ stosb
+ inc edx
+
+.filesize:
+ ; truncate file to new size
+ push dword 0 ; high dword
+ push edx ; low dword
+ push eax ; pad
+ push ebp
+ sys.ftruncate
+
+ ; close it (ebp still pushed)
+ sys.close
+
+ add esp, byte 16
+ sys.munmap
+
+.quit:
+ push dword 0
+ sys.exit
+
+align 4
+ordinary:
+ cmp al, 0Dh
+ je .cr
+
+ cmp al, ah
+ je .lf
+
+ stosb
+ inc edx
+ ret
+
+align 4
+.cr:
+ mov ebx, cr
+ ret
+
+align 4
+.lf:
+ mov ebx, lf
+ ret
+
+align 4
+cr:
+ cmp al, 0Dh
+ je .cr
+
+ cmp al, ah
+ je .lf
+
+ xchg al, ah
+ stosb
+ inc edx
+
+ xchg al, ah
+ ; fall through
+
+.lf:
+ stosb
+ inc edx
+ mov ebx, ordinary
+ ret
+
+align 4
+.cr:
+ mov al, ah
+ stosb
+ inc edx
+ ret
+
+align 4
+lf:
+ cmp al, ah
+ je .lf
+
+ cmp al, 0Dh
+ je .cr
+
+ xchg al, ah
+ stosb
+ inc edx
+
+ xchg al, ah
+ stosb
+ inc edx
+ mov ebx, ordinary
+ ret
+
+align 4
+.cr:
+ mov ebx, ordinary
+ mov al, ah
+ ; fall through
+
+.lf:
+ stosb
+ inc edx
+ ret
+
+
+
+Do not use this program on files stored on a disk formated
+by &ms-dos; or &windows;. There seems to be a
+subtle bug in the FreeBSD code when using mmap
+on these drives mounted under FreeBSD: If the file is over
+a certain size, mmap will just fill the memory
+with zeros, and then copy them to the file overwriting
+its contents.
+
+
+
+
+
+
+
+One-Pointed Mind
+
+
+As a student of Zen, I like the idea of a one-pointed mind:
+Do one thing at a time, and do it well.
+
+
+
+This, indeed, is very much how &unix; works as well. While
+a typical &windows; application is attempting to do everything
+imaginable (and is, therefore, riddled with bugs), a
+typical &unix; program does only one thing, and it does it
+well.
+
+
+
+The typical &unix; user then essentially assembles his own
+applications by writing a shell script which combines the
+various existing programs by piping the output of one
+program to the input of another.
+
+
+
+When writing your own &unix; software, it is generally a
+good idea to see what parts of the problem you need to
+solve can be handled by existing programs, and only
+write your own programs for that part of the problem
+that you do not have an existing solution for.
+
+
+CSV
+
+
+I will illustrate this principle with a specific real-life
+example I was faced with recently:
+
+
+
+I needed to extract the 11th field of each record from a
+database I downloaded from a web site. The database was a
+CSV file, i.e., a list of
+comma-separated values. That is quite
+a standard format for sharing data among people who may be
+using different database software.
+
+
+
+The first line of the file contains the list of various fields
+separated by commas. The rest of the file contains the data
+listed line by line, with values separated by commas.
+
+
+
+I tried awk, using the comma as a separator.
+But because several lines contained a quoted comma,
+awk was extracting the wrong field
+from those lines.
+
+
+
+Therefore, I needed to write my own software to extract the 11th
+field from the CSV file. However, going with the &unix;
+spirit, I only needed to write a simple filter that would do the
+following:
+
+
+
+
+
+Remove the first line from the file;
+
+
+
+
+
+Change all unquoted commas to a different character;
+
+
+
+
+
+Remove all quotation marks.
+
+
+
+
+
+Strictly speaking, I could use sed to remove
+the first line from the file, but doing so in my own program
+was very easy, so I decided to do it and reduce the size of
+the pipeline.
+
+
+
+At any rate, writing a program like this took me about
+20 minutes. Writing a program that extracts the 11th field
+from the CSV file would take a lot longer,
+and I could not reuse it to extract some other field from some
+other database.
+
+
+
+This time I decided to let it do a little more work than
+a typical tutorial program would:
+
+
+
+
+
+It parses its command line for options;
+
+
+
+
+
+It displays proper usage if it finds wrong arguments;
+
+
+
+
+
+It produces meaningful error messages.
+
+
+
+
+
+Here is its usage message:
+
+
+Usage: csv [-t<delim>] [-c<comma>] [-p] [-o <outfile>] [-i <infile>]
+
+
+All parameters are optional, and can appear in any order.
+
+
+
+The -t parameter declares what to replace
+the commas with. The tab is the default here.
+For example, -t; will replace all unquoted
+commas with semicolons.
+
+
+
+I did not need the -c option, but it may
+come in handy in the future. It lets me declare that I want a
+character other than a comma replaced with something else.
+For example, -c@ will replace all at signs
+(useful if you want to split a list of email addresses
+to their user names and domains).
+
+
+
+The -p option preserves the first line, i.e.,
+it does not delete it. By default, we delete the first
+line because in a CSV file it contains the field
+names rather than data.
+
+
+
+The -i and -o
+options let me specify the input and the output files. Defaults
+are stdin and stdout,
+so this is a regular &unix; filter.
+
+
+
+I made sure that both -i filename and
+-ifilename are accepted. I also made
+sure that only one input and one output files may be
+specified.
+
+
+
+To get the 11th field of each record, I can now do:
+
+
+&prompt.user; csv '-t;' data.csv | awk '-F;' '{print $11}'
+
+
+The code stores the options (except for the file descriptors)
+in EDX: The comma in DH, the new
+separator in DL, and the flag for
+the -p option in the highest bit of
+EDX, so a check for its sign will give us a
+quick decision what to do.
+
+
+
+Here is the code:
+
+
+
+;;;;;;; csv.asm ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; Convert a comma-separated file to a something-else separated file.
+;
+; Started: 31-May-2001
+; Updated: 1-Jun-2001
+;
+; Copyright (c) 2001 G. Adam Stanislav
+; All rights reserved.
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+%include 'system.inc'
+
+%define BUFSIZE 2048
+
+section .data
+fd.in dd stdin
+fd.out dd stdout
+usg db 'Usage: csv [-t<delim>] [-c<comma>] [-p] [-o <outfile>] [-i <infile>]', 0Ah
+usglen equ $-usg
+iemsg db "csv: Can't open input file", 0Ah
+iemlen equ $-iemsg
+oemsg db "csv: Can't create output file", 0Ah
+oemlen equ $-oemsg
+
+section .bss
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+
+section .text
+align 4
+ierr:
+ push dword iemlen
+ push dword iemsg
+ push dword stderr
+ sys.write
+ push dword 1 ; return failure
+ sys.exit
+
+align 4
+oerr:
+ push dword oemlen
+ push dword oemsg
+ push dword stderr
+ sys.write
+ push dword 2
+ sys.exit
+
+align 4
+usage:
+ push dword usglen
+ push dword usg
+ push dword stderr
+ sys.write
+ push dword 3
+ sys.exit
+
+align 4
+global _start
+_start:
+ add esp, byte 8 ; discard argc and argv[0]
+ mov edx, (',' << 8) | 9
+
+.arg:
+ pop ecx
+ or ecx, ecx
+ je near .init ; no more arguments
+
+ ; ECX contains the pointer to an argument
+ cmp byte [ecx], '-'
+ jne usage
+
+ inc ecx
+ mov ax, [ecx]
+
+.o:
+ cmp al, 'o'
+ jne .i
+
+ ; Make sure we are not asked for the output file twice
+ cmp dword [fd.out], stdout
+ jne usage
+
+ ; Find the path to output file - it is either at [ECX+1],
+ ; i.e., -ofile --
+ ; or in the next argument,
+ ; i.e., -o file
+
+ inc ecx
+ or ah, ah
+ jne .openoutput
+ pop ecx
+ jecxz usage
+
+.openoutput:
+ push dword 420 ; file mode (644 octal)
+ push dword 0200h | 0400h | 01h
+ ; O_CREAT | O_TRUNC | O_WRONLY
+ push ecx
+ sys.open
+ jc near oerr
+
+ add esp, byte 12
+ mov [fd.out], eax
+ jmp short .arg
+
+.i:
+ cmp al, 'i'
+ jne .p
+
+ ; Make sure we are not asked twice
+ cmp dword [fd.in], stdin
+ jne near usage
+
+ ; Find the path to the input file
+ inc ecx
+ or ah, ah
+ jne .openinput
+ pop ecx
+ or ecx, ecx
+ je near usage
+
+.openinput:
+ push dword 0 ; O_RDONLY
+ push ecx
+ sys.open
+ jc near ierr ; open failed
+
+ add esp, byte 8
+ mov [fd.in], eax
+ jmp .arg
+
+.p:
+ cmp al, 'p'
+ jne .t
+ or ah, ah
+ jne near usage
+ or edx, 1 << 31
+ jmp .arg
+
+.t:
+ cmp al, 't' ; redefine output delimiter
+ jne .c
+ or ah, ah
+ je near usage
+ mov dl, ah
+ jmp .arg
+
+.c:
+ cmp al, 'c'
+ jne near usage
+ or ah, ah
+ je near usage
+ mov dh, ah
+ jmp .arg
+
+align 4
+.init:
+ sub eax, eax
+ sub ebx, ebx
+ sub ecx, ecx
+ mov edi, obuffer
+
+ ; See if we are to preserve the first line
+ or edx, edx
+ js .loop
+
+.firstline:
+ ; get rid of the first line
+ call getchar
+ cmp al, 0Ah
+ jne .firstline
+
+.loop:
+ ; read a byte from stdin
+ call getchar
+
+ ; is it a comma (or whatever the user asked for)?
+ cmp al, dh
+ jne .quote
+
+ ; Replace the comma with a tab (or whatever the user wants)
+ mov al, dl
+
+.put:
+ call putchar
+ jmp short .loop
+
+.quote:
+ cmp al, '"'
+ jne .put
+
+ ; Print everything until you get another quote or EOL. If it
+ ; is a quote, skip it. If it is EOL, print it.
+.qloop:
+ call getchar
+ cmp al, '"'
+ je .loop
+
+ cmp al, 0Ah
+ je .put
+
+ call putchar
+ jmp short .qloop
+
+align 4
+getchar:
+ or ebx, ebx
+ jne .fetch
+
+ call read
+
+.fetch:
+ lodsb
+ dec ebx
+ ret
+
+read:
+ jecxz .read
+ call write
+
+.read:
+ push dword BUFSIZE
+ mov esi, ibuffer
+ push esi
+ push dword [fd.in]
+ sys.read
+ add esp, byte 12
+ mov ebx, eax
+ or eax, eax
+ je .done
+ sub eax, eax
+ ret
+
+align 4
+.done:
+ call write ; flush output buffer
+
+ ; close files
+ push dword [fd.in]
+ sys.close
+
+ push dword [fd.out]
+ sys.close
+
+ ; return success
+ push dword 0
+ sys.exit
+
+align 4
+putchar:
+ stosb
+ inc ecx
+ cmp ecx, BUFSIZE
+ je write
+ ret
+
+align 4
+write:
+ jecxz .ret ; nothing to write
+ sub edi, ecx ; start of buffer
+ push ecx
+ push edi
+ push dword [fd.out]
+ sys.write
+ add esp, byte 12
+ sub eax, eax
+ sub ecx, ecx ; buffer is empty now
+.ret:
+ ret
+
+
+
+Much of it is taken from hex.asm above. But there
+is one important difference: I no longer call write
+whenever I am outputting a line feed. Yet, the code can be
+used interactively.
+
+
+
+I have found a better solution for the interactive problem
+since I first started writing this chapter. I wanted to
+make sure each line is printed out separately only when needed.
+After all, there is no need to flush out every line when used
+non-interactively.
+
+
+
+The new solution I use now is to call write every
+time I find the input buffer empty. That way, when running in
+the interactive mode, the program reads one line from the user's
+keyboard, processes it, and sees its input buffer is empty. It
+flushes its output and reads the next line.
+
+
+
+The Dark Side of Buffering
+
+This change prevents a mysterious lockup
+in a very specific case. I refer to it as the
+dark side of buffering, mostly
+because it presents a danger that is not
+quite obvious.
+
+
+
+It is unlikely to happen with a program like the
+csv above, so let us consider yet
+another filter: In this case we expect our input
+to be raw data representing color values, such as
+the red, green, and
+blue intensities of a pixel. Our
+output will be the negative of our input.
+
+
+
+Such a filter would be very simple to write.
+Most of it would look just like all the other
+filters we have written so far, so I am only
+going to show you its inner loop:
+
+
+
+.loop:
+ call getchar
+ not al ; Create a negative
+ call putchar
+ jmp short .loop
+
+
+Because this filter works with raw data,
+it is unlikely to be used interactively.
+
+
+
+But it could be called by image manipulation software.
+And, unless it calls write before each call
+to read, chances are it will lock up.
+
+
+
+Here is what might happen:
+
+
+
+The image editor will load our filter using the
+C function popen().
+
+
+
+It will read the first row of pixels from
+a bitmap or pixmap.
+
+
+
+It will write the first row of pixels to
+the pipe leading to
+the fd.in of our filter.
+
+
+
+Our filter will read each pixel
+from its input, turn it to a negative,
+and write it to its output buffer.
+
+
+
+Our filter will call getchar
+to fetch the next pixel.
+
+
+
+getchar will find an empty
+input buffer, so it will call
+read.
+
+
+
+read will call the
+SYS_read system call.
+
+
+
+The kernel will suspend
+our filter until the image editor
+sends more data to the pipe.
+
+
+
+The image editor will read from the
+other pipe, connected to the
+fd.out of our filter so it can set the first row of the
+output image before
+it sends us the second row of the input.
+
+
+
+The kernel suspends
+the image editor until it receives
+some output from our filter, so it
+can pass it on to the image editor.
+
+
+
+
+At this point our filter waits for the image
+editor to send it more data to process, while
+the image editor is waiting for our filter
+to send it the result of the processing
+of the first row. But the result sits in
+our output buffer.
+
+
+
+The filter and the image editor will continue
+waiting for each other forever (or, at least,
+until they are killed). Our software has just
+entered a
+race condition.
+
+
+
+This problem does not exist if our filter flushes
+its output buffer before asking the
+kernel for more input data.
+
+
+
+
+
+
+
+
+
+Using the FPU
+
+Strangely enough, most of assembly language literature does not
+even mention the existence of the FPU,
+or floating point unit, let alone discuss
+programming it.
+
+
+
+Yet, never does assembly language shine more than when
+we create highly optimized FPU
+code by doing things that can be done only in assembly language.
+
+Organization of the FPU
+
+The FPU consists of 8 80–bit floating–point registers.
+These are organized in a stack fashion—you can
+push a value on TOS
+(top of stack) and you can
+pop it.
+
+
+
+That said, the assembly language op codes are not push
+and pop because those are already taken.
+
+
+You can push a value on TOS
+by using fld, fild,
+and fbld. Several other op codes
+let you push many common
+constants—such as pi—on
+the TOS.
+
+
+
+Similarly, you can pop a value by
+using fst, fstp,
+fist, fistp, and
+fbstp. Actually, only the op
+codes that end with a p will
+literally pop the value,
+the rest will store it
+somewhere else without removing it from
+the TOS.
+
+
+
+We can transfer the data between the
+TOS and the computer memory either as
+a 32–bit, 64–bit, or 80–bit real,
+a 16–bit, 32–bit, or 64–bit integer,
+or an 80–bit packed decimal.
+
+
+
+The 80–bit packed decimal is
+a special case of binary coded
+decimal which is very convenient when
+converting between the ASCII
+representation of data and the internal
+data of the FPU. It allows us to use
+18 significant digits.
+
+
+
+No matter how we represent data in the memory,
+the FPU always stores it in the 80–bit
+real format in its registers.
+
+
+
+Its internal precision is at least 19 decimal
+digits, so even if we choose to display results
+as ASCII in the full
+18–digit precision, we are still showing
+correct results.
+
+
+
+We can perform mathematical operations on the
+TOS: We can calculate its
+sine, we can scale it
+(i.e., we can multiply or divide it by a power
+of 2), we can calculate its base–2
+logarithm, and many other things.
+
+
+
+We can also multiply or
+divide it by, add
+it to, or subtract it from,
+any of the FPU registers (including
+itself).
+
+
+
+The official Intel op code for the
+TOS is st, and
+for the registers
+st(0)–st(7).
+st and st(0), then,
+refer to the same register.
+
+
+
+For whatever reasons, the original author of
+nasm has decided to use
+different op codes, namely
+st0–st7.
+In other words, there are no parentheses,
+and the TOS is always
+st0, never just st.
+
+
+
+The Packed Decimal Format
+
+The packed decimal format
+uses 10 bytes (80 bits) of
+memory to represent 18 digits. The
+number represented there is always an
+integer.
+
+
+
+
+You can use it to get decimal places
+by multiplying the TOS
+by a power of 10 first.
+
+
+
+
+The highest bit of the highest byte
+(byte 9) is the sign bit:
+If it is set, the number is negative,
+otherwise, it is positive.
+The rest of the bits of this byte are unused/ignored.
+
+
+
+The remaining 9 bytes store the 18 digits
+of the number: 2 digits per byte.
+
+
+The more significant digit is
+stored in the high nibble
+(4 bits), the less significant
+digit in the low nibble.
+
+
+
+That said, you might think that -1234567
+would be stored in the memory like this (using
+hexadecimal notation):
+
+
+
+80 00 00 00 00 00 01 23 45 67
+
+
+Alas it is not! As with everything else of Intel make,
+even the packed decimal is
+little–endian.
+
+
+That means our -1234567
+is stored like this:
+
+
+
+67 45 23 01 00 00 00 00 00 80
+
+
+Remember that, or you will be pulling your hair out
+in desperation!
+
+
+
+
+The book to read—if you can find it—is Richard Startz'
+8087/80287/80387
+for the IBM PC & Compatibles.
+Though it does seem to take the fact about the
+little–endian storage of the packed
+decimal for granted. I kid you not about the
+desperation of trying to figure out what was wrong
+with the filter I show below before
+it occurred to me I should try the
+little–endian order even for this type of data.
+
+
+
+
+
+
+
+
+Excursion to Pinhole Photography
+
+To write meaningful software, we must not only
+understand our programming tools, but also the
+field we are creating software for.
+
+
+
+Our next filter will help us whenever we want
+to build a pinhole camera,
+so, we need some background in pinhole
+photography before we can continue.
+
+
+
+The Camera
+
+The easiest way to describe any camera ever built
+is as some empty space enclosed in some
+lightproof material, with a small hole in the
+enclosure.
+
+
+
+The enclosure is usually sturdy (e.g., a box),
+though sometimes it is flexible (the bellows).
+It is quite dark inside the camera. However, the
+hole lets light rays in through a single point
+(though in some cases there may be several).
+These light rays form an image, a representation
+of whatever is outside the camera, in front of the
+hole.
+
+
+
+If some light sensitive material (such as film)
+is placed inside the camera, it can capture the
+image.
+
+
+The hole often contains a lens, or
+a lens assembly, often called the objective.
+
+
+
+
+
+The Pinhole
+
+But, strictly speaking, the lens is not necessary:
+The original cameras did not use a lens but a
+pinhole. Even today, pinholes
+are used, both as a tool to study how cameras
+work, and to achieve a special kind of image.
+
+
+
+The image produced by the pinhole
+is all equally sharp. Or blurred.
+There is an ideal size for a pinhole: If it is
+either larger or smaller, the image loses its
+sharpness.
+
+
+
+
+Focal Length
+
+This ideal pinhole diameter is a function
+of the square root of focal
+length, which is the distance of the
+pinhole from the film.
+
+
+
+ D = PC * sqrt(FL)
+
+
+In here, D is the
+ideal diameter of the pinhole,
+FL is the focal length,
+and PC is a pinhole
+constant. According to Jay Bender,
+its value is 0.04, while
+Kenneth Connors has determined it to
+be 0.037. Others have
+proposed other values. Plus, this
+value is for the daylight only: Other types
+of light will require a different constant,
+whose value can only be determined by
+experimentation.
+
+
+
+
+
+The F–Number
+
+The f–number is a very useful measure of
+how much light reaches the film. A light
+meter can determine that, for example,
+to expose a film of specific sensitivity
+with f5.6 may require the exposure to last
+1/1000 sec.
+
+
+It does not matter whether it is a 35–mm
+camera, or a 6x9cm camera, etc.
+As long as we know the f–number, we can determine
+the proper exposure.
+
+
+
+The f–number is easy to calculate:
+
+
+
+ F = FL / D
+
+
+In other words, the f–number equals the focal
+length divided by the diameter of the pinhole.
+It also means a higher f–number either implies
+a smaller pinhole or a larger focal distance,
+or both. That, in turn, implies, the higher
+the f–number, the longer the exposure has to be.
+
+
+
+Furthermore, while pinhole diameter and focal
+distance are one–dimensional measurements,
+both, the film and the pinhole, are two–dimensional.
+That means that
+if you have measured the exposure at f–number
+A as t, then the exposure
+at f–number B is:
+
+
+ t * (B / A)²
+
+
+
+
+Normalized F–Number
+
+While many modern cameras can change the diameter
+of their pinhole, and thus their f–number, quite
+smoothly and gradually, such was not always the case.
+
+
+
+To allow for different f–numbers, cameras typically
+contained a metal plate with several holes of
+different sizes drilled to them.
+
+
+
+Their sizes were chosen according to the above
+formula in such a way that the resultant f–number
+was one of standard f–numbers used on all cameras
+everywhere. For example, a very old Kodak Duaflex IV
+camera in my possession has three such holes for
+f–numbers 8, 11, and 16.
+
+
+
+A more recently made camera may offer f–numbers of
+2.8, 4, 5.6, 8, 11,
+16, 22, and 32 (as well as others).
+These numbers were not chosen arbitrarily: They all are
+powers of the square root of 2, though they may
+be rounded somewhat.
+
+
+
+
+
+The F–Stop
+
+A typical camera is designed in such a way that setting
+any of the normalized f–numbers changes the feel of the
+dial. It will naturally stop in that
+position. Because of that, these positions of the dial
+are called f–stops.
+
+
+Since the f–numbers at each stop are powers of the
+square root of 2, moving the dial by 1
+stop will double the amount of light required for
+proper exposure. Moving it by 2 stops will
+quadruple the required exposure. Moving the dial by
+3 stops will require the increase in exposure
+8 times, etc.
+
+
+
+
+
+
+
+Designing the Pinhole Software
+
+We are now ready to decide what exactly we want our
+pinhole software to do.
+
+
+
+Processing Program Input
+
+Since its main purpose is to help us design a working
+pinhole camera, we will use the focal
+length as the input to the program. This is something
+we can determine without software: Proper focal length
+is determined by the size of the film and by the need
+to shoot "regular" pictures, wide angle pictures, or
+telephoto pictures.
+
+
+
+Most of the programs we have written so far worked with
+individual characters, or bytes, as their input: The
+hex program converted individual bytes
+into a hexadecimal number, the csv
+program either let a character through, or deleted it,
+or changed it to a different character, etc.
+
+
+
+One program, ftuc used the state machine
+to consider at most two input bytes at a time.
+
+
+
+But our pinhole program cannot just
+work with individual characters, it has to deal with
+larger syntactic units.
+
+
+
+For example, if we want the program to calculate the
+pinhole diameter (and other values we will discuss
+later) at the focal lengths of 100 mm,
+150 mm, and 210 mm, we may want
+to enter something like this:
+
+100, 150, 210
+
+Our program needs to consider more than a single byte of
+input at a time. When it sees the first 1,
+it must understand it is seeing the first digit of a
+decimal number. When it sees the 0 and
+the other 0, it must know it is seeing
+more digits of the same number.
+
+
+
+When it encounters the first comma, it must know it is
+no longer receiving the digits of the first number.
+It must be able to convert the digits of the first number
+into the value of 100. And the digits of the
+second number into the value of 150. And,
+of course, the digits of the third number into the
+numeric value of 210.
+
+
+
+We need to decide what delimiters to accept: Do the
+input numbers have to be separated by a comma? If so,
+how do we treat two numbers separated by something else?
+
+
+
+Personally, I like to keep it simple. Something either
+is a number, so I process it. Or it is not a number,
+so I discard it. I do not like the computer complaining
+about me typing in an extra character when it is
+obvious that it is an extra character. Duh!
+
+
+
+Plus, it allows me to break up the monotony of computing
+and type in a query instead of just a number:
+
+
+What is the best pinhole diameter for the focal length of 150?
+
+There is no reason for the computer to spit out
+a number of complaints:
+
+
+Syntax error: What
+Syntax error: is
+Syntax error: the
+Syntax error: best
+
+Et cetera, et cetera, et cetera.
+
+
+Secondly, I like the # character to denote
+the start of a comment which extends to the end of the
+line. This does not take too much effort to code, and
+lets me treat input files for my software as executable
+scripts.
+
+
+
+In our case, we also need to decide what units the
+input should come in: We choose millimeters
+because that is how most photographers measure
+the focus length.
+
+
+
+Finally, we need to decide whether to allow the use
+of the decimal point (in which case we must also
+consider the fact that much of the world uses a
+decimal comma).
+
+
+In our case allowing for the decimal point/comma
+would offer a false sense of precision: There is
+little if any noticeable difference between the
+focus lengths of 50 and 51,
+so allowing the user to input something like
+50.5 is not a good idea. This is
+my opinion, mind you, but I am the one writing
+this program. You can make other choices in yours,
+of course.
+
+
+
+
+
+Offering Options
+
+The most important thing we need to know when building
+a pinhole camera is the diameter of the pinhole. Since
+we want to shoot sharp images, we will use the above
+formula to calculate the pinhole diameter from focal length.
+As experts are offering several different values for the
+PC constant, we will need to have the choice.
+
+
+
+It is traditional in &unix; programming to have two main ways
+of choosing program parameters, plus to have a default for
+the time the user does not make a choice.
+
+
+
+Why have two ways of choosing?
+
+
+One is to allow a (relatively) permanent
+choice that applies automatically each time the
+software is run without us having to tell it over and
+over what we want it to do.
+
+
+
+The permanent choices may be stored in a configuration
+file, typically found in the user's home directory.
+The file usually has the same name as the application
+but is started with a dot. Often "rc"
+is added to the file name. So, ours could be
+~/.pinhole or ~/.pinholerc.
+(The ~/ means current user's
+home directory.)
+
+
+
+The configuration file is used mostly by programs
+that have many configurable parameters. Those
+that have only one (or a few) often use a different
+method: They expect to find the parameter in an
+environment variable. In our case,
+we might look at an environment variable named
+PINHOLE.
+
+
+
+Usually, a program uses one or the other of the
+above methods. Otherwise, if a configuration
+file said one thing, but an environment variable
+another, the program might get confused (or just
+too complicated).
+
+
+
+Because we only need to choose one
+such parameter, we will go with the second method
+and search the environment for a variable named
+PINHOLE.
+
+
+The other way allows us to make ad hoc
+decisions: "Though I usually want
+you to use 0.039, this time I want 0.03872."
+In other words, it allows us to override
+the permanent choice.
+
+
+
+This type of choice is usually done with command
+line parameters.
+
+
+
+Finally, a program always needs a
+default. The user may not make
+any choices. Perhaps he does not know what
+to choose. Perhaps he is "just browsing."
+Preferably, the default will be the value
+most users would choose anyway. That way
+they do not need to choose. Or, rather, they
+can choose the default without an additional
+effort.
+
+
+
+Given this system, the program may find conflicting
+options, and handle them this way:
+
+
+
+If it finds an ad hoc choice
+(e.g., command line parameter), it should
+accept that choice. It must ignore any permanent
+choice and any default.
+
+
+
+Otherwise, if it finds
+a permanent option (e.g., an environment
+variable), it should accept it, and ignore
+the default.
+
+
+Otherwise, it should use
+the default.
+
+
+
+
+We also need to decide what format
+our PC option should have.
+
+
+
+At first site, it seems obvious to use the
+PINHOLE=0.04 format for the
+environment variable, and -p0.04
+for the command line.
+
+
+
+Allowing that is actually a security risk.
+The PC constant is a very small
+number. Naturally, we will test our software
+using various small values of PC.
+But what will happen if someone runs the program
+choosing a huge value?
+
+
+
+It may crash the program because we have not
+designed it to handle huge numbers.
+
+
+
+Or, we may spend more time on the program so
+it can handle huge numbers. We might do that
+if we were writing commercial software for
+computer illiterate audience.
+
+
+
+Or, we might say, "Tough!
+The user should know better.""
+
+
+
+Or, we just may make it impossible for the user
+to enter a huge number. This is the approach we
+will take: We will use an implied 0.
+prefix.
+
+
+
+In other words, if the user wants 0.04,
+we will expect him to type -p04,
+or set PINHOLE=04 in his environment.
+So, if he says -p9999999, we will
+interpret it as 0.9999999—still
+ridiculous but at least safer.
+
+
+
+Secondly, many users will just want to go with either
+Bender's constant or Connors' constant.
+To make it easier on them, we will interpret
+-b as identical to -p04,
+and -c as identical to -p037.
+
+
+
+
+
+The Output
+
+We need to decide what we want our software to
+send to the output, and in what format.
+
+
+
+Since our input allows for an unspecified number
+of focal length entries, it makes sense to use
+a traditional database–style output of showing
+the result of the calculation for each
+focal length on a separate line, while
+separating all values on one line by a
+tab character.
+
+
+
+Optionally, we should also allow the user
+to specify the use of the CSV
+format we have studied earlier. In this case,
+we will print out a line of comma–separated
+names describing each field of every line,
+then show our results as before, but substituting
+a comma for the tab.
+
+
+We need a command line option for the CSV
+format. We cannot use -c because
+that already means use Connors' constant.
+For some strange reason, many web sites refer to
+CSV files as "Excel
+spreadsheet" (though the CSV
+format predates Excel). We will, therefore, use
+the -e switch to inform our software
+we want the output in the CSV format.
+
+
+
+We will start each line of the output with the
+focal length. This may sound repetitious at first,
+especially in the interactive mode: The user
+types in the focal length, and we are repeating it.
+
+
+
+But the user can type several focal lengths on one
+line. The input can also come in from a file or
+from the output of another program. In that case
+the user does not see the input at all.
+
+
+
+By the same token, the output can go to a file
+which we will want to examine later, or it could
+go to the printer, or become the input of another
+program.
+
+
+
+So, it makes perfect sense to start each line with
+the focal length as entered by the user.
+
+
+
+No, wait! Not as entered by the user. What if the user
+types in something like this:
+
+00000000150
+
+Clearly, we need to strip those leading zeros.
+
+
+So, we might consider reading the user input as is,
+converting it to binary inside the FPU,
+and printing it out from there.
+
+
+
+But...
+
+
+What if the user types something like this:
+
+
+17459765723452353453534535353530530534563507309676764423
+
+Ha! The packed decimal FPU format
+lets us input 18–digit numbers. But the
+user has entered more than 18 digits. How
+do we handle that?
+
+
+
+Well, we could modify our code to read
+the first 18 digits, enter it to the FPU,
+then read more, multiply what we already have on the
+TOS by 10 raised to the number
+of additional digits, then add to it.
+
+
+
+Yes, we could do that. But in this
+program it would be ridiculous (in a different one it may be just the thing to do): Even the circumference of the Earth expressed in
+millimeters only takes 11 digits. Clearly,
+we cannot build a camera that large (not yet,
+anyway).
+
+
+
+So, if the user enters such a huge number, he is
+either bored, or testing us, or trying to break
+into the system, or playing games—doing
+anything but designing a pinhole camera.
+
+
+
+What will we do?
+
+
+We will slap him in the face, in a manner of speaking:
+
+17459765723452353453534535353530530534563507309676764423 ??? ??? ??? ??? ???
+
+To achieve that, we will simply ignore any leading zeros.
+Once we find a non–zero digit, we will initialize a
+counter to 0 and start taking three steps:
+
+
+
+
+Send the digit to the output.
+
+
+
+Append the digit to a buffer we will use later to
+produce the packed decimal we can send to the
+FPU.
+
+
+
+Increase the counter.
+
+
+
+
+Now, while we are taking these three steps,
+we also need to watch out for one of two
+conditions:
+
+
+
+
+If the counter grows above 18,
+we stop appending to the buffer. We
+continue reading the digits and sending
+them to the output.
+
+
+
+
+
+If, or rather when,
+the next input character is not
+a digit, we are done inputting
+for now.
+
+
+
+Incidentally, we can simply
+discard the non–digit, unless it
+is a #, which we must
+return to the input stream. It
+starts a comment, so we must see it
+after we are done producing output
+and start looking for more input.
+
+
+
+
+
+That still leaves one possibility
+uncovered: If all the user enters
+is a zero (or several zeros), we
+will never find a non–zero to
+display.
+
+
+We can determine this has happened
+whenever our counter stays at 0.
+In that case we need to send 0
+to the output, and perform another
+"slap in the face":
+
+
+0 ??? ??? ??? ??? ???
+
+Once we have displayed the focal
+length and determined it is valid
+(greater than 0
+but not exceeding 18 digits),
+we can calculate the pinhole diameter.
+
+
+
+It is not by coincidence that pinhole
+contains the word pin. Indeed,
+many a pinhole literally is a pin
+hole, a hole carefully punched with the
+tip of a pin.
+
+
+
+That is because a typical pinhole is very
+small. Our formula gets the result in
+millimeters. We will multiply it by 1000,
+so we can output the result in microns.
+
+
+
+At this point we have yet another trap to face:
+Too much precision.
+
+
+
+Yes, the FPU was designed
+for high precision mathematics. But we
+are not dealing with high precision
+mathematics. We are dealing with physics
+(optics, specifically).
+
+
+
+Suppose we want to convert a truck into
+a pinhole camera (we would not be the
+first ones to do that!). Suppose its box is
+12
+meters long, so we have the focal length
+of 12000. Well, using Bender's constant, it gives us square root of
+12000 multiplied by 0.04,
+which is 4.381780460 millimeters,
+or 4381.780460 microns.
+
+
+
+Put either way, the result is absurdly precise.
+Our truck is not exactly12000
+millimeters long. We did not measure its length
+with such a precision, so stating we need a pinhole
+with the diameter of 4.381780460
+millimeters is, well, deceiving. 4.4
+millimeters would do just fine.
+
+
+
+
+I "only" used ten digits in the above example.
+Imagine the absurdity of going for all 18!
+
+
+
+
+We need to limit the number of significant
+digits of our result. One way of doing it
+is by using an integer representing microns.
+So, our truck would need a pinhole with the diameter
+of 4382 microns. Looking at that number, we still decide that 4400 microns,
+or 4.4 millimeters is close enough.
+
+
+
+Additionally, we can decide that no matter how
+big a result we get, we only want to display four
+significant digits (or any other number
+of them, of course). Alas, the FPU
+does not offer rounding to a specific number
+of digits (after all, it does not view the
+numbers as decimal but as binary).
+
+
+
+We, therefore, must devise an algorithm to reduce
+the number of significant digits.
+
+
+
+Here is mine (I think it is awkward—if
+you know a better one, please, let me know):
+
+
+
+Initialize a counter to 0.
+
+
+
+While the number is greater than or equal to
+10000, divide it by
+10 and increase the counter.
+
+
+
+Output the result.
+
+
+While the counter is greater than 0,
+output 0 and decrease the counter.
+
+
+
+
+
+The 10000 is only good if you want
+four significant digits. For any other
+number of significant digits, replace
+10000 with 10
+raised to the number of significant digits.
+
+
+
+
+We will, then, output the pinhole diameter
+in microns, rounded off to four significant
+digits.
+
+
+
+At this point, we know the focal
+length and the pinhole
+diameter. That means we have enough
+information to also calculate the
+f–number.
+
+
+
+We will display the f–number, rounded to
+four significant digits. Chances are the
+f–number will tell us very little. To make
+it more meaningful, we can find the nearest
+normalized f–number, i.e.,
+the nearest power of the square root
+of 2.
+
+
+
+We do that by multiplying the actual f–number
+by itself, which, of course, will give us
+its square. We will then calculate
+its base–2 logarithm, which is much
+easier to do than calculating the
+base–square–root–of–2 logarithm!
+We will round the result to the nearest integer.
+Next, we will raise 2 to the result. Actually,
+the FPU gives us a good shortcut
+to do that: We can use the fscale
+op code to "scale" 1, which is
+analogous to shifting an
+integer left. Finally, we calculate the square
+root of it all, and we have the nearest
+normalized f–number.
+
+
+
+If all that sounds overwhelming—or too much
+work, perhaps—it may become much clearer
+if you see the code. It takes 9 op
+codes altogether:
+
+
+ fmul st0, st0
+ fld1
+ fld st1
+ fyl2x
+ frndint
+ fld1
+ fscale
+ fsqrt
+ fstp st1
+
+
+The first line, fmul st0, st0, squares
+the contents of the TOS
+(top of the stack, same as st,
+called st0 by nasm).
+The fld1 pushes 1
+on the TOS.
+
+
+The next line, fld st1, pushes
+the square back to the TOS.
+At this point the square is both in st
+and st(2) (it will become
+clear why we leave a second copy on the stack
+in a moment). st(1) contains
+1.
+
+
+
+Next, fyl2x calculates base–2
+logarithm of st multiplied by
+st(1). That is why we placed 1 on st(1) before.
+
+
+At this point, st contains
+the logarithm we have just calculated,
+st(1) contains the square
+of the actual f–number we saved for later.
+
+
+
+frndint rounds the TOS
+to the nearest integer. fld1 pushes
+a 1. fscale shifts the
+1 we have on the TOS
+by the value in st(1),
+effectively raising 2 to st(1).
+
+
+
+Finally, fsqrt calculates
+the square root of the result, i.e.,
+the nearest normalized f–number.
+
+
+
+We now have the nearest normalized
+f–number on the TOS,
+the base–2 logarithm rounded to the
+nearest integer in st(1),
+and the square of the actual f–number
+in st(2). We are saving
+the value in st(2) for later.
+
+
+
+But we do not need the contents of
+st(1) anymore. The last
+line, fstp st1, places the
+contents of st to
+st(1), and pops. As a
+result, what was st(1)
+is now st, what was st(2)
+is now st(1), etc.
+The new st contains the
+normalized f–number. The new
+st(1) contains the square
+of the actual f–number we have
+stored there for posterity.
+
+
+
+At this point, we are ready to output
+the normalized f–number. Because it is
+normalized, we will not round it off to
+four significant digits, but will
+send it out in its full precision.
+
+
+
+The normalized f-number is useful as long
+as it is reasonably small and can be found
+on our light meter. Otherwise we need a
+different method of determining proper
+exposure.
+
+
+
+Earlier we have figured out the formula
+of calculating proper exposure at an arbitrary
+f–number from that measured at a different
+f–number.
+
+
+
+Every light meter I have ever seen can determine
+proper exposure at f5.6. We will, therefore,
+calculate an "f5.6 multiplier,"
+i.e., by how much we need to multiply the exposure measured
+at f5.6 to determine the proper exposure
+for our pinhole camera.
+
+
+
+From the above formula we know this factor can be
+calculated by dividing our f–number (the
+actual one, not the normalized one) by
+5.6, and squaring the result.
+
+
+
+Mathematically, dividing the square of our
+f–number by the square of 5.6
+will give us the same result.
+
+
+
+Computationally, we do not want to square
+two numbers when we can only square one.
+So, the first solution seems better at first.
+
+
+
+But...
+
+
+5.6 is a constant.
+We do not have to have our FPU
+waste precious cycles. We can just tell it
+to divide the square of the f–number by
+whatever 5.6² equals to.
+Or we can divide the f–number by 5.6,
+and then square the result. The two ways
+now seem equal.
+
+
+
+But, they are not!
+
+
+Having studied the principles of photography
+above, we remember that the 5.6
+is actually square root of 2 raised to
+the fifth power. An irrational
+number. The square of this number is
+exactly32.
+
+
+
+Not only is 32 an integer,
+it is a power of 2. We do not need
+to divide the square of the f–number by
+32. We only need to use
+fscale to shift it right by
+five positions. In the FPU
+lingo it means we will fscale it
+with st(1) equal to
+-5. That is much
+faster than a division.
+
+
+
+So, now it has become clear why we have
+saved the square of the f–number on the
+top of the FPU stack.
+The calculation of the f5.6 multiplier
+is the easiest calculation of this
+entire program! We will output it rounded
+to four significant digits.
+
+
+
+There is one more useful number we can calculate:
+The number of stops our f–number is from f5.6.
+This may help us if our f–number is just outside
+the range of our light meter, but we have
+a shutter which lets us set various speeds,
+and this shutter uses stops.
+
+
+
+Say, our f–number is 5 stops from
+f5.6, and the light meter says
+we should use 1/1000 sec.
+Then we can set our shutter speed to 1/1000
+first, then move the dial by 5 stops.
+
+
+
+This calculation is quite easy as well. All
+we have to do is to calculate the base-2
+logarithm of the f5.6 multiplier
+we had just calculated (though we need its
+value from before we rounded it off). We then
+output the result rounded to the nearest integer.
+We do not need to worry about having more than
+four significant digits in this one: The result
+is most likely to have only one or two digits
+anyway.
+
+
+
+
+
+
+FPU Optimizations
+
+In assembly language we can optimize the FPU
+code in ways impossible in high languages,
+including C.
+
+
+
+Whenever a C function needs to calculate
+a floating–point value, it loads all necessary
+variables and constants into FPU
+registers. It then does whatever calculation is
+required to get the correct result. Good C
+compilers can optimize that part of the code really
+well.
+
+
+
+It "returns" the value by leaving
+the result on the TOS.
+However, before it returns, it cleans up.
+Any variables and constants it used in its
+calculation are now gone from the FPU.
+
+
+
+It cannot do what we just did above: We calculated
+the square of the f–number and kept it on the
+stack for later use by another function.
+
+
+
+We knew we would need that value
+later on. We also knew we had enough room on the
+stack (which only has room for 8 numbers)
+to store it there.
+
+
+
+A C compiler has no way of knowing
+that a value it has on the stack will be
+required again in the very near future.
+
+
+
+Of course, the C programmer may know it.
+But the only recourse he has is to store the
+value in a memory variable.
+
+
+
+That means, for one, the value will be changed
+from the 80-bit precision used internally
+by the FPU to a C double
+(64 bits) or even single (32
+bits).
+
+
+
+That also means that the value must be moved
+from the TOS into the memory,
+and then back again. Alas, of all FPU
+operations, the ones that access the computer
+memory are the slowest.
+
+
+
+So, whenever programming the FPU
+in assembly language, look for the ways of keeping
+intermediate results on the FPU
+stack.
+
+
+
+We can take that idea even further! In our
+program we are using a constant
+(the one we named PC).
+
+
+
+It does not matter how many pinhole diameters
+we are calculating: 1, 10, 20,
+1000, we are always using the same constant.
+Therefore, we can optimize our program by keeping
+the constant on the stack all the time.
+
+
+
+Early on in our program, we are calculating the
+value of the above constant. We need to divide
+our input by 10 for every digit in the
+constant.
+
+
+
+It is much faster to multiply than to divide.
+So, at the start of our program, we divide 10
+into 1 to obtain 0.1, which we
+then keep on the stack: Instead of dividing the
+input by 10 for every digit,
+we multiply it by 0.1.
+
+
+
+By the way, we do not input 0.1 directly,
+even though we could. We have a reason for that:
+While 0.1 can be expressed with just one
+decimal place, we do not know how many binary
+places it takes. We, therefore, let the FPU
+calculate its binary value to its own high precision.
+
+
+
+We are using other constants: We multiply the pinhole
+diameter by 1000 to convert it from
+millimeters to microns. We compare numbers to
+10000 when we are rounding them off to
+four significant digits. So, we keep both, 1000
+and 10000, on the stack. And, of course,
+we reuse the 0.1 when rounding off numbers
+to four digits.
+
+
+
+Last but not least, we keep -5 on the stack.
+We need it to scale the square of the f–number,
+instead of dividing it by 32. It is not
+by coincidence we load this constant last. That makes
+it the top of the stack when only the constants
+are on it. So, when the square of the f–number is
+being scaled, the -5 is at st(1),
+precisely where fscale expects it to be.
+
+
+
+It is common to create certain constants from
+scratch instead of loading them from the memory.
+That is what we are doing with -5:
+
+
+
+ fld1 ; TOS = 1
+ fadd st0, st0 ; TOS = 2
+ fadd st0, st0 ; TOS = 4
+ fld1 ; TOS = 1
+ faddp st1, st0 ; TOS = 5
+ fchs ; TOS = -5
+
+
+We can generalize all these optimizations into one rule:
+Keep repeat values on the stack!
+
+
+
+
+&postscript; is a stack–oriented
+programming language. There are many more books
+available about &postscript; than about the
+FPU assembly language: Mastering
+&postscript; will help you master the FPU.
+
+
+
+
+
+
+pinhole—The Code
+
+;;;;;;; pinhole.asm ;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+;
+; Find various parameters of a pinhole camera construction and use
+;
+; Started: 9-Jun-2001
+; Updated: 10-Jun-2001
+;
+; Copyright (c) 2001 G. Adam Stanislav
+; All rights reserved.
+;
+;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;;
+
+%include 'system.inc'
+
+%define BUFSIZE 2048
+
+section .data
+align 4
+ten dd 10
+thousand dd 1000
+tthou dd 10000
+fd.in dd stdin
+fd.out dd stdout
+envar db 'PINHOLE=' ; Exactly 8 bytes, or 2 dwords long
+pinhole db '04,', ; Bender's constant (0.04)
+connors db '037', 0Ah ; Connors' constant
+usg db 'Usage: pinhole [-b] [-c] [-e] [-p <value>] [-o <outfile>] [-i <infile>]', 0Ah
+usglen equ $-usg
+iemsg db "pinhole: Can't open input file", 0Ah
+iemlen equ $-iemsg
+oemsg db "pinhole: Can't create output file", 0Ah
+oemlen equ $-oemsg
+pinmsg db "pinhole: The PINHOLE constant must not be 0", 0Ah
+pinlen equ $-pinmsg
+toobig db "pinhole: The PINHOLE constant may not exceed 18 decimal places", 0Ah
+biglen equ $-toobig
+huhmsg db 9, '???'
+separ db 9, '???'
+sep2 db 9, '???'
+sep3 db 9, '???'
+sep4 db 9, '???', 0Ah
+huhlen equ $-huhmsg
+header db 'focal length in millimeters,pinhole diameter in microns,'
+ db 'F-number,normalized F-number,F-5.6 multiplier,stops '
+ db 'from F-5.6', 0Ah
+headlen equ $-header
+
+section .bss
+ibuffer resb BUFSIZE
+obuffer resb BUFSIZE
+dbuffer resb 20 ; decimal input buffer
+bbuffer resb 10 ; BCD buffer
+
+section .text
+align 4
+huh:
+ call write
+ push dword huhlen
+ push dword huhmsg
+ push dword [fd.out]
+ sys.write
+ add esp, byte 12
+ ret
+
+align 4
+perr:
+ push dword pinlen
+ push dword pinmsg
+ push dword stderr
+ sys.write
+ push dword 4 ; return failure
+ sys.exit
+
+align 4
+consttoobig:
+ push dword biglen
+ push dword toobig
+ push dword stderr
+ sys.write
+ push dword 5 ; return failure
+ sys.exit
+
+align 4
+ierr:
+ push dword iemlen
+ push dword iemsg
+ push dword stderr
+ sys.write
+ push dword 1 ; return failure
+ sys.exit
+
+align 4
+oerr:
+ push dword oemlen
+ push dword oemsg
+ push dword stderr
+ sys.write
+ push dword 2
+ sys.exit
+
+align 4
+usage:
+ push dword usglen
+ push dword usg
+ push dword stderr
+ sys.write
+ push dword 3
+ sys.exit
+
+align 4
+global _start
+_start:
+ add esp, byte 8 ; discard argc and argv[0]
+ sub esi, esi
+
+.arg:
+ pop ecx
+ or ecx, ecx
+ je near .getenv ; no more arguments
+
+ ; ECX contains the pointer to an argument
+ cmp byte [ecx], '-'
+ jne usage
+
+ inc ecx
+ mov ax, [ecx]
+ inc ecx
+
+.o:
+ cmp al, 'o'
+ jne .i
+
+ ; Make sure we are not asked for the output file twice
+ cmp dword [fd.out], stdout
+ jne usage
+
+ ; Find the path to output file - it is either at [ECX+1],
+ ; i.e., -ofile --
+ ; or in the next argument,
+ ; i.e., -o file
+
+ or ah, ah
+ jne .openoutput
+ pop ecx
+ jecxz usage
+
+.openoutput:
+ push dword 420 ; file mode (644 octal)
+ push dword 0200h | 0400h | 01h
+ ; O_CREAT | O_TRUNC | O_WRONLY
+ push ecx
+ sys.open
+ jc near oerr
+
+ add esp, byte 12
+ mov [fd.out], eax
+ jmp short .arg
+
+.i:
+ cmp al, 'i'
+ jne .p
+
+ ; Make sure we are not asked twice
+ cmp dword [fd.in], stdin
+ jne near usage
+
+ ; Find the path to the input file
+ or ah, ah
+ jne .openinput
+ pop ecx
+ or ecx, ecx
+ je near usage
+
+.openinput:
+ push dword 0 ; O_RDONLY
+ push ecx
+ sys.open
+ jc near ierr ; open failed
+
+ add esp, byte 8
+ mov [fd.in], eax
+ jmp .arg
+
+.p:
+ cmp al, 'p'
+ jne .c
+ or ah, ah
+ jne .pcheck
+
+ pop ecx
+ or ecx, ecx
+ je near usage
+
+ mov ah, [ecx]
+
+.pcheck:
+ cmp ah, '0'
+ jl near usage
+ cmp ah, '9'
+ ja near usage
+ mov esi, ecx
+ jmp .arg
+
+.c:
+ cmp al, 'c'
+ jne .b
+ or ah, ah
+ jne near usage
+ mov esi, connors
+ jmp .arg
+
+.b:
+ cmp al, 'b'
+ jne .e
+ or ah, ah
+ jne near usage
+ mov esi, pinhole
+ jmp .arg
+
+.e:
+ cmp al, 'e'
+ jne near usage
+ or ah, ah
+ jne near usage
+ mov al, ','
+ mov [huhmsg], al
+ mov [separ], al
+ mov [sep2], al
+ mov [sep3], al
+ mov [sep4], al
+ jmp .arg
+
+align 4
+.getenv:
+ ; If ESI = 0, we did not have a -p argument,
+ ; and need to check the environment for "PINHOLE="
+ or esi, esi
+ jne .init
+
+ sub ecx, ecx
+
+.nextenv:
+ pop esi
+ or esi, esi
+ je .default ; no PINHOLE envar found
+
+ ; check if this envar starts with 'PINHOLE='
+ mov edi, envar
+ mov cl, 2 ; 'PINHOLE=' is 2 dwords long
+rep cmpsd
+ jne .nextenv
+
+ ; Check if it is followed by a digit
+ mov al, [esi]
+ cmp al, '0'
+ jl .default
+ cmp al, '9'
+ jbe .init
+ ; fall through
+
+align 4
+.default:
+ ; We got here because we had no -p argument,
+ ; and did not find the PINHOLE envar.
+ mov esi, pinhole
+ ; fall through
+
+align 4
+.init:
+ sub eax, eax
+ sub ebx, ebx
+ sub ecx, ecx
+ sub edx, edx
+ mov edi, dbuffer+1
+ mov byte [dbuffer], '0'
+
+ ; Convert the pinhole constant to real
+.constloop:
+ lodsb
+ cmp al, '9'
+ ja .setconst
+ cmp al, '0'
+ je .processconst
+ jb .setconst
+
+ inc dl
+
+.processconst:
+ inc cl
+ cmp cl, 18
+ ja near consttoobig
+ stosb
+ jmp short .constloop
+
+align 4
+.setconst:
+ or dl, dl
+ je near perr
+
+ finit
+ fild dword [tthou]
+
+ fld1
+ fild dword [ten]
+ fdivp st1, st0
+
+ fild dword [thousand]
+ mov edi, obuffer
+
+ mov ebp, ecx
+ call bcdload
+
+.constdiv:
+ fmul st0, st2
+ loop .constdiv
+
+ fld1
+ fadd st0, st0
+ fadd st0, st0
+ fld1
+ faddp st1, st0
+ fchs
+
+ ; If we are creating a CSV file,
+ ; print header
+ cmp byte [separ], ','
+ jne .bigloop
+
+ push dword headlen
+ push dword header
+ push dword [fd.out]
+ sys.write
+
+.bigloop:
+ call getchar
+ jc near done
+
+ ; Skip to the end of the line if you got '#'
+ cmp al, '#'
+ jne .num
+ call skiptoeol
+ jmp short .bigloop
+
+.num:
+ ; See if you got a number
+ cmp al, '0'
+ jl .bigloop
+ cmp al, '9'
+ ja .bigloop
+
+ ; Yes, we have a number
+ sub ebp, ebp
+ sub edx, edx
+
+.number:
+ cmp al, '0'
+ je .number0
+ mov dl, 1
+
+.number0:
+ or dl, dl ; Skip leading 0's
+ je .nextnumber
+ push eax
+ call putchar
+ pop eax
+ inc ebp
+ cmp ebp, 19
+ jae .nextnumber
+ mov [dbuffer+ebp], al
+
+.nextnumber:
+ call getchar
+ jc .work
+ cmp al, '#'
+ je .ungetc
+ cmp al, '0'
+ jl .work
+ cmp al, '9'
+ ja .work
+ jmp short .number
+
+.ungetc:
+ dec esi
+ inc ebx
+
+.work:
+ ; Now, do all the work
+ or dl, dl
+ je near .work0
+
+ cmp ebp, 19
+ jae near .toobig
+
+ call bcdload
+
+ ; Calculate pinhole diameter
+
+ fld st0 ; save it
+ fsqrt
+ fmul st0, st3
+ fld st0
+ fmul st5
+ sub ebp, ebp
+
+ ; Round off to 4 significant digits
+.diameter:
+ fcom st0, st7
+ fstsw ax
+ sahf
+ jb .printdiameter
+ fmul st0, st6
+ inc ebp
+ jmp short .diameter
+
+.printdiameter:
+ call printnumber ; pinhole diameter
+
+ ; Calculate F-number
+
+ fdivp st1, st0
+ fld st0
+
+ sub ebp, ebp
+
+.fnumber:
+ fcom st0, st6
+ fstsw ax
+ sahf
+ jb .printfnumber
+ fmul st0, st5
+ inc ebp
+ jmp short .fnumber
+
+.printfnumber:
+ call printnumber ; F number
+
+ ; Calculate normalized F-number
+ fmul st0, st0
+ fld1
+ fld st1
+ fyl2x
+ frndint
+ fld1
+ fscale
+ fsqrt
+ fstp st1
+
+ sub ebp, ebp
+ call printnumber
+
+ ; Calculate time multiplier from F-5.6
+
+ fscale
+ fld st0
+
+ ; Round off to 4 significant digits
+.fmul:
+ fcom st0, st6
+ fstsw ax
+ sahf
+
+ jb .printfmul
+ inc ebp
+ fmul st0, st5
+ jmp short .fmul
+
+.printfmul:
+ call printnumber ; F multiplier
+
+ ; Calculate F-stops from 5.6
+
+ fld1
+ fxch st1
+ fyl2x
+
+ sub ebp, ebp
+ call printnumber
+
+ mov al, 0Ah
+ call putchar
+ jmp .bigloop
+
+.work0:
+ mov al, '0'
+ call putchar
+
+align 4
+.toobig:
+ call huh
+ jmp .bigloop
+
+align 4
+done:
+ call write ; flush output buffer
+
+ ; close files
+ push dword [fd.in]
+ sys.close
+
+ push dword [fd.out]
+ sys.close
+
+ finit
+
+ ; return success
+ push dword 0
+ sys.exit
+
+align 4
+skiptoeol:
+ ; Keep reading until you come to cr, lf, or eof
+ call getchar
+ jc done
+ cmp al, 0Ah
+ jne .cr
+ ret
+
+.cr:
+ cmp al, 0Dh
+ jne skiptoeol
+ ret
+
+align 4
+getchar:
+ or ebx, ebx
+ jne .fetch
+
+ call read
+
+.fetch:
+ lodsb
+ dec ebx
+ clc
+ ret
+
+read:
+ jecxz .read
+ call write
+
+.read:
+ push dword BUFSIZE
+ mov esi, ibuffer
+ push esi
+ push dword [fd.in]
+ sys.read
+ add esp, byte 12
+ mov ebx, eax
+ or eax, eax
+ je .empty
+ sub eax, eax
+ ret
+
+align 4
+.empty:
+ add esp, byte 4
+ stc
+ ret
+
+align 4
+putchar:
+ stosb
+ inc ecx
+ cmp ecx, BUFSIZE
+ je write
+ ret
+
+align 4
+write:
+ jecxz .ret ; nothing to write
+ sub edi, ecx ; start of buffer
+ push ecx
+ push edi
+ push dword [fd.out]
+ sys.write
+ add esp, byte 12
+ sub eax, eax
+ sub ecx, ecx ; buffer is empty now
+.ret:
+ ret
+
+align 4
+bcdload:
+ ; EBP contains the number of chars in dbuffer
+ push ecx
+ push esi
+ push edi
+
+ lea ecx, [ebp+1]
+ lea esi, [dbuffer+ebp-1]
+ shr ecx, 1
+
+ std
+
+ mov edi, bbuffer
+ sub eax, eax
+ mov [edi], eax
+ mov [edi+4], eax
+ mov [edi+2], ax
+
+.loop:
+ lodsw
+ sub ax, 3030h
+ shl al, 4
+ or al, ah
+ mov [edi], al
+ inc edi
+ loop .loop
+
+ fbld [bbuffer]
+
+ cld
+ pop edi
+ pop esi
+ pop ecx
+ sub eax, eax
+ ret
+
+align 4
+printnumber:
+ push ebp
+ mov al, [separ]
+ call putchar
+
+ ; Print the integer at the TOS
+ mov ebp, bbuffer+9
+ fbstp [bbuffer]
+
+ ; Check the sign
+ mov al, [ebp]
+ dec ebp
+ or al, al
+ jns .leading
+
+ ; We got a negative number (should never happen)
+ mov al, '-'
+ call putchar
+
+.leading:
+ ; Skip leading zeros
+ mov al, [ebp]
+ dec ebp
+ or al, al
+ jne .first
+ cmp ebp, bbuffer
+ jae .leading
+
+ ; We are here because the result was 0.
+ ; Print '0' and return
+ mov al, '0'
+ jmp putchar
+
+.first:
+ ; We have found the first non-zero.
+ ; But it is still packed
+ test al, 0F0h
+ jz .second
+ push eax
+ shr al, 4
+ add al, '0'
+ call putchar
+ pop eax
+ and al, 0Fh
+
+.second:
+ add al, '0'
+ call putchar
+
+.next:
+ cmp ebp, bbuffer
+ jb .done
+
+ mov al, [ebp]
+ push eax
+ shr al, 4
+ add al, '0'
+ call putchar
+ pop eax
+ and al, 0Fh
+ add al, '0'
+ call putchar
+
+ dec ebp
+ jmp short .next
+
+.done:
+ pop ebp
+ or ebp, ebp
+ je .ret
+
+.zeros:
+ mov al, '0'
+ call putchar
+ dec ebp
+ jne .zeros
+
+.ret:
+ ret
+
+
+The code follows the same format as all the other
+filters we have seen before, with one subtle
+exception:
+
+
+
+
+We are no longer assuming that the end of input
+implies the end of things to do, something we
+took for granted in the character–oriented
+filters.
+
+
+
+This filter does not process characters. It
+processes a language
+(albeit a very simple
+one, consisting only of numbers).
+
+
+
+When we have no more input, it can mean one
+of two things:
+
+
+
+We are done and can quit. This is the
+same as before.
+
+
+
+
+
+The last character we have read was a digit.
+We have stored it at the end of our
+ASCII–to–float conversion
+buffer. We now need to convert
+the contents of that buffer into a
+number and write the last line of our
+output.
+
+
+
+
+
+For that reason, we have modified our getchar
+and our read routines to return with
+the carry flagclear whenever we are
+fetching another character from the input, or the
+carry flagset whenever there is no more
+input.
+
+
+
+Of course, we are still using assembly language magic
+to do that! Take a good look at getchar.
+It always returns with the
+carry flagclear.
+
+
+
+Yet, our main code relies on the carry
+flag to tell it when to quit—and it works.
+
+
+
+The magic is in read. Whenever it
+receives more input from the system, it just
+returns to getchar, which
+fetches a character from the input buffer,
+clears the carry flag
+and returns.
+
+
+
+But when read receives no more
+input from the system, it does not
+return to getchar at all.
+Instead, the add esp, byte 4
+op code adds 4 to ESP,
+sets the carry
+flag, and returns.
+
+
+
+So, where does it return to? Whenever a
+program uses the call op code,
+the microprocessor pushes the
+return address, i.e., it stores it on
+the top of the stack (not the FPU
+stack, the system stack, which is in the memory).
+When a program uses the ret
+op code, the microprocessor pops
+the return value from the stack, and jumps
+to the address that was stored there.
+
+
+
+But since we added 4 to
+ESP (which is the stack
+pointer register), we have effectively
+given the microprocessor a minor case
+of amnesia: It no longer
+remembers it was getchar
+that called read.
+
+
+
+And since getchar never
+pushed anything before
+calling read,
+the top of the stack now contains the
+return address to whatever or whoever
+called getchar.
+As far as that caller is concerned,
+he called getchar,
+which returned with the
+carry flag set!
+
+
+
When the fs block size is 4K, triple indirect blocks work
and everything should be limited by the maximum fs block number
that can be represented using triple indirect blocks (approx.
1K^3 + 1K^2 + 1K), but everything is limited by a (wrong) limit
of 1G-1 on fs block numbers. The limit on fs block numbers
should be 2G-1. There are some bugs for fs block numbers near
2G-1, but such block numbers are unreachable when the fs block
size is 4K.block 大小如果是 8K 或更大,檔案系統 block 數目會被限制在 2G-1
,但實際上應該說限制是 1G-1 才對,因為採用 2G-1 block 的檔案系統會導致一些問題。
為何在啟動新的 kernel 時,看到
archsw.readin.failed 錯誤訊息?原因出在你的 world 以及 kernel 並不同步,舉例:kernel 用 4.11,
而 world 卻是 4.8,這樣是會有問題的。
請再次確認,是否有以 make buildworld 及
make buildkernel 來正常更新 kernel。在啟動 loader 之前,會看到 "|" 這個符號在轉動,這時可以按任何鍵中斷,
然後再指定要載入哪個 kernel 來開機。security profiles 是指什麼?A security profile is a set of configuration
options that attempts to achieve the desired ratio of security
to convenience by enabling and disabling certain programs and
other settings. For full details, see the Security
Profile section of the Handbook's post-install
chapter.在開機時,選擇使用 ACPI 則在安裝過程就掛了,該怎麼辦?試試看關閉 ACPI support。 當在載入 bootloader時,按下空白鍵。
系統會顯示 OK 這時輸入
unset acpi_load 接著打
boot
以繼續開機,這樣子應該就可以了。硬體支援方面一般問題我想組裝自己的 FreeBSD 機器,有哪些型號、品牌、規格是支援程度最好的呢?有關這點,在 FreeBSD 討論區上時常有人討論。雖然硬體汰換速度很快,
可能隨時有新規格、新產品出現,然而這些都在我們意料之中,
我們 仍然 強烈建議:在詢問有關最新規格硬體的支援問題之前,
請先參閱 &os
&rel.current;
或
&rel2.current;的支援硬體列表,
或是搜尋討論區的舊文章,
也許,上週才剛恰巧有人討論過你所要問的硬體。如果要找有關筆記型電腦方面,請到 FreeBSD-mobile 筆記型電腦討論區。
不然,就到 FreeBSD-questions 討論區,或是特定硬體規格(比如 pc98, Alpha)的專屬討論區吧。
硬體架構及 CPUFreeBSD 有支援 x86 之外的硬體架構平台嗎?有的,FreeBSD 目前可以在 Intel x86 and DEC
(現在的 HP-Compaq) Alpha 架構上面運作。自 FreeBSD 5.0 之後的版本,則
可支援 AMD64 及 Intel EM64T, IA-64 以及 &sparc64; 架構。
未來平台支援上還會有 &mips; 及
&powerpc;,細節請分別參閱 &a.mips; 或 &a.ppc;。
一般而言,新的硬體架構平台方面,都是到 &a.platforms; 討論。若你機器不是以上架構或是比較奇特的,而想立刻試試看 BSD 的魔力,
我們建議你可以考慮使用 NetBSD 或 OpenBSD。FreeBSD 支援 CPU 對稱多工處理(SMP, Symmetric Multiprocessing)嗎?有的。 SMP 在 &os; 5.2 預設的 kernel(GENERIC)已有啟動。
在 &os; 5.3 要 release 時,SMP相關設定也是預設就有啟動。
然而,在一些較新型的機器(像是 emt64)上卻又有些問題,
所以還是決定在相關問題、安全議題未獲解決前,先關閉 SMP 的相關啟動。
這點,正是 &os; 5.4 所優先考慮的方向。&os; 4.X 的話,預設的 kernel 並沒有啟動 SMP,
因此,必須要把 options SMP 加入 kernel 設定檔並重新編譯才能啟動。
至於還有哪些相關設定要放入 kernel 設定檔,請參閱/sys/i386/conf/LINT。
硬碟、磁帶機以及光碟、DVD、燒錄機FreeBSD 可支援哪些種類的硬碟呢?FreeBSD 都支援 EIDE 及 SCSI 介面的硬碟(以及 SCSI 卡,請看下一節說明)
以及 Western Digital 介面的硬碟 (MFM、 RLL、
ESDI,當然包含 IDE),不過有一些少數的 ESDI 晶片組的(型號:WD1002/3/6/7)
可能無法正常運作。支援哪些 SCSI 卡、設備呢?請參閱 &os; 的硬體支援表(
&rel.current; 或
&rel2.current;)支援哪些磁帶機呢?FreeBSD 支援 SCSI 及 QIC-36 (QIC-02 介面) 規格的磁帶機。
同時包含了 8-mm (也就是 Exabyte) 及 DAT 磁帶機。有些早期版本的 8-mm 磁帶機並不是完全相容於 SCSI-2 規格,
所以可能在 FreeBSD 上表現不是很好。FreeBSD 支援磁帶自動換帶機嗎?FreeBSD 可以用 &man.ch.4; 上面所列的機種,搭配 &man.chio.1; 指令,
來使用 SCSI 種類的自動換帶機,細節部分請參閱 &man.chio.1; 說明。If you are not using AMANDA
or some other product that already understands changers,
remember that they only know how to move a tape from one
point to another, so you need to keep track of which slot a
tape is in, and which slot the tape currently in the drive
needs to go back to.FreeBSD 可支援哪些種類的光碟機呢?只要是有支援的 SCSI 卡上所接的任一 SCSI 光碟機都有支援。此外,也支援下列的光碟機:Mitsumi LU002 (8bit), LU005 (16bit) 及 FX001D
(16bit 2x Speed)Sony CDU 31/33ASound Blaster 非 SCSI 介面的光碟機Matsushita/Panasonic 光碟機相容 ATAPI 規格的 IDE CDROMs相對於 SCSI 機種而言,其他非 SCSI 的光碟機都是比較慢,
此外,有些 ATAPI 種類的光碟機可能無法順利運作Daemon News 以及 FreeBSD Mall 所發行的正式 FreeBSD 光碟以及燒錄用的影像檔(ISO),
都可以直接用於開機光碟使用。FreeBSD 支援哪些光碟燒錄機的驅動程式呢?FreeBSD 支援任何相容 ATAPI 標準的 IDE CD-R 或 CD-RW 光碟燒錄機,
細節請參閱 &man.burncd.8; 說明。FreeBSD 也支援任何 SCSI CD-R 或 CD-RW 光碟燒錄機。
請用 port 或 packag 機制來安裝、使用 cdrecord ,
並確定您的 kernel 內有將 pass設備一併編譯在內。
(預設的 kernel.GENERIC 都會有 device pass 這段)FreeBSD 支援 Iomega &iomegazip; 嗎?FreeBSD 支援外接式的 SCSI 及 ATAPI(IDE) 介面的 Iomega &iomegazip;。
不過 SCSI ZIP 只能被設為 SCSI ID 5 或是 6 才可以運作,但如果
SCSI 卡上的 BIOS 支援它,你甚至可以用它來開機。
我們不曉得哪一塊卡可以把卡的 ID 設在除了 0 或 1 以外的地方而開機成功,
因此,如果想改 SCSI ID 的話,請務必參閱該型號的說明手冊。FreeBSD 同時也支援 Parallel Port Zip磁碟機。請檢查 kernel
設定檔是否有:
scbus0、
da0、
ppbus0,以及
vp0 這些驅動程式 (預設的 GENERIC kernel
除了 vp0 沒包進去,其他三者都會有)。
加了這幾個驅動程式之後,Parallel Port Zip 就會成為
/dev/da0s4。這時,就可以用像是 mount /dev/da0s4 /mnt 或
(DOS 檔案系統)mount_msdos /dev/da0s4 /mnt
之類的指令來掛載、讀寫。也可以參閱下面有關隨身磁片
部分,以及抽取碟、隨身碟的『格式化』討論
的部分FreeBSD 有支援 &jaz;、EZ 及其他類似的隨身磁片嗎?可以啊,除了 IDE 的 EZ drive 外,其他的應該都是 SCSI 介面,
所以在 FreeBSD 上都會以 SCSI 硬碟來處理。當然,你必須確定在開機時,這些設備的電源是打開的,
以便讓 FreeBSD 可以偵測到。如果在磁碟運中狀態中,要更換磁片的話,
記得先看一下 &man.mount.8;、&man.umount.8;、
以及(SCSI的話)&man.camcontrol.8; 或 &man.atacontrol.8; 還有 FAQ 後面有關
使用抽取碟、隨身碟的討論
。鍵盤、滑鼠FreeBSD 有支援 USB 鍵盤嗎?FreeBSD (尤其是有支援 USB keyboards。 Enable USB support in
/etc/rc.conf.若有開 USB 鍵盤支援而且同時接上 AT 跟 USB 鍵盤的話,那麼 AT 鍵盤會變成
/dev/kbd0,而 USB 鍵盤則是
/dev/kbd1。如果只接 USB 鍵盤,那麼它就是
/dev/ukbd0 囉。如果想在 console 上使用 USB 鍵盤的話,那麼必須設定 console 指定用 USB 鍵盤。
可以在系統開機程序時,加上下列指令:&prompt.root; kbdcontrol -k /dev/kbd1 < /dev/ttyv0 > /dev/null注意:若只有 USB 鍵盤的話,也就是 /dev/ukbd0,
那麼請改用下列指令:&prompt.root; kbdcontrol -k /dev/ukbd0 < /dev/ttyv0 > /dev/null建議:可以把上述指令放入 /etc/rc.i386 。設定成功之後,USB 鍵盤不用作任何特別設定,就可以在 X 視窗環境上正常運作囉。USB 鍵盤的熱插拔(Hot-plugging and unplugging)在 &os; 可能還無法完全正常運作,
建議:在系統開機前就先接上鍵盤,直到關機為止,以避免不必要的困擾。相關細節請參閱 &man.ukbd.4; 的說明。古早的 bus 滑鼠,要怎麼設定呢?FreeBSD 支援一些廠商(像是:Microsoft、Logitech、ATI)所做的 bus 及 InPort bus 介面的滑鼠。
然而,預設的 kernel(GENERIC)已經不內含它們的驅動程式。
因此,要加入下列到 kernel 設定檔並重新編譯、安裝,才能啟用:device mse0 at isa? port 0x23c irq5Bus 滑鼠通常要搭配專用的介面卡才能使用。
這些卡可以設定 port address 及 IRQ 值,這些細節請參閱你的滑鼠說明手冊及
&man.mse.4; 說明。PS/2 (mouse port 或
keyboard)的滑鼠要怎麼設定才好呢?PS/2 滑鼠都有支援,所需要用到的驅動程式 psm
在預設的 kernel(GENERIC)已有內含了。若你自訂的 kernel 內漏了 psm 的話,那麼就再把下列內容加到 kernel
設定檔並重新編譯、安裝:device psm0 at atkbdc? irq 12當開機時 kernel 有正確偵測到 psm0
,請務必確認在 /dev 內有
psm0 。
如果沒有的話,那麼就用 root 來打下列指令來建立吧:&prompt.root; cd /dev; sh MAKEDEV psm0如果是 &os; 5.0-RELEASE(含之後版本)的話,因為採用 &man.devfs.5; 機制的因素,
所以會自動在 /dev 下建立相關設備的節點,因此就可以略過上面這一步。如果不用 X Window 環境的話,也可以用滑鼠嗎?若使用 console 的預設驅動程式(也就是 &man.syscons.4;),
那麼就可以在文字介面的 console 上面用滑鼠來剪貼文字了。
那麼要啟動 &man.moused.8; 並開啟游標顯示,
請打下列指令:&prompt.root; moused -p /dev/xxxx -t yyyy
&prompt.root; vidcontrol -m on其中『xxxx』是滑鼠的設備名稱,而
『yyyy』則是滑鼠所使用的 protocol 種類。
目前的 moused 可以自動偵測(除了舊式的 serial
滑鼠之外)大多數滑鼠所使用的 protocol 種類,而不用刻意去指定。
『protocol 種類』設定用
auto 就會自動偵測了。若自動偵測失敗的話,請參閱 &man.moused.8;
裡面的 type 那段說明。如果用的是 PS/2 滑鼠,只要把
moused_enable="YES" 加到
/etc/rc.conf ,這樣每次開機就會自動啟動了。
此外,如果要在所有 virtual terminals 上也能使用滑鼠,
而不限定只有 console 的話,那麼請再把
allscreens_flags="-m on" 加到 /etc/rc.conf 裡面即可。moused 在執行中的時候,如果要使用滑鼠相關功能,都必須透過 moused
或其他程式像是 X 視窗來進行。請參閱 FAQ 中有關『為什麼不能在 X 視窗裡使用滑鼠?』以瞭解相關細節。在文字模式的 console 環境要怎麼用滑鼠來剪貼文字呢?當執行 moused 後,(參閱前一節)
按住左鍵,接著移動滑鼠來選擇一個區域之後放開,這樣就完成『複製』。
要『貼上』的話,按滑鼠中鍵就可以了。
要『延伸選取區』的話,按滑鼠右鍵如果你的滑鼠沒有中鍵,你可以用模擬的方式,或是重新定義滑鼠按鍵的方式,
來達成「延伸」的功能。詳情請參閱 &man.moused.8; 說明。我滑鼠上面的滾輪、滾輪按鈕,可以在 console 上使用嗎?這個答案嘛...,很不幸地,在大多數的情況下不行。
這些有滾輪的滑鼠需要用特殊驅動程式才行,
除非,滑鼠驅動程式或使用者自己的應用程式有支援,
不然,這些滑鼠只能夠當成是普通的兩鍵或三鍵的滑鼠來用而已。
如果要在 X 視窗環境上使用滾輪的話,請參閱
X 視窗上的滾輪使用
說明。要怎麼在筆記型電腦上使用滑鼠、軌跡球、觸控板呢?請參閱前面的 PS/2 滑鼠的問答
。網路跟 serial 設備FreeBSD 支援哪些網路卡呢?請參考 &os; 各版本的硬體支援列表。為什麼 FreeBSD 找不到 PnP(隨插隨用,Plug & Play)規格的 modem?原因在於:需要把 modem 的 PnP ID 加到 serial 驅動程式的 PnP ID 表,作法如下:
首先,在 kernel 設定檔內加入 controller pnp0,
並重新編譯、安裝 kernel,最後重開機就會啟動 PnP 支援。然後,kernel 會把偵測到所有設備上的 PnP ID 都列出。
這時,修改 /usr/src/sys/isa/sio.c(大約第752行左右的地方),
可以搜尋 SUP1310 當關鍵字(位於 sio_ids[] 表內),
請將剛才 kernel 顯示的 modem 的 PnP ID 複製到相關位置。這時,再重新編譯、安裝 kernel,最後重開機應該就會正確偵測到 modem 了。此外,也可以在開機時以 pnp 指令來手動設定 PnP 設備,
來讓 kernel 得以正確偵測,舉例:pnp 1 0 enable os irq0 3 drq0 0 port0 0x2f8FreeBSD 支援像是 Winmodems 之類的軟體 modem 嗎?FreeBSD 可以安裝額外的軟體來支援軟體 modem。
像是 comms/ltmdm 可支援常見的 Lucent LT 晶片,
comms/mwavem 則可支援 IBM Thinkpad 600 及 700
筆記型電腦上面的 modem。然而,並不能用軟體 modem 來安裝 FreeBSD,
因為:這類軟體必須在作業系統安裝完畢之後,才能安裝。有 Broadcom 43xx 無線網卡的原生驅動程式(Native driver)嗎?沒有,而且也不太可能會有。Broadcom 拒絕公開有關無線網卡晶片的驅動程式相關說明,
主因大概是他們用軟體來控制無線傳輸方式。
事實上,因為要能通過美國聯邦電信委員會(FCC)檢磁安規的話,
必須確保產品不能讓使用者不能隨意更動相關設定,比如:電磁波頻率、相關模組參數、輸出電源等。
但是,如果我們不知道如何去控制晶片的話,那麼撰寫驅動程式之路恐怕不太可行。FreeBSD 支援哪些 multi-port serial卡呢?請參閱使用手冊上的 安裝篇—其他硬體
列表。雖然有些卡是沒牌的(尤其是有標明:相容 AST 規格)但也可以正常使用。至於卡的設定方面,請參閱 &man.sio.4; 的說明。在 serial console 上要如何才會出現 boot: 提示呢?kernel 設定檔加入
options COMCONSOLE建立 /boot.config 檔,並且該檔裡面內容只填上 把鍵盤從機器上拔掉細節請看
/usr/src/sys/i386/boot/biosboot/README.serial音效卡FreeBSD 支援哪些音效卡?&os; 支援各種音效卡,包括了 &soundblaster;、
&soundblaster; Pro、&soundblaster; 16、Pro Audio Spectrum 16、
AdLib、及 Gravis UltraSound sound cards (細節請參閱
&os; 發行情報
以及 &man.snd.4; 的說明)。
此外,對 MPU-401 及 MIDI 相容規格的也有一定程度的支援,而
µsoft; Sound System 規格也有支援。驅動程式僅適用於『音效』部分! 除了 &soundblaster; 之外,
目前音效驅動程式並不支援這些音效卡上的光碟機, SCSI設備或搖桿。
&soundblaster; 的 SCSI 介面及某些非 SCSI 的光碟機是有支援,但無法用來開機。
&man.pcm.4; 所支援的音效卡沒有聲音,有什麼暫時解決方式嗎?因為有些像是 es1370 晶片的音效卡會在每次開機時把音量調為零。
暫時解法是在每次開機時執行下面指令,或是加到 /etc/rc.local 內:&prompt.root; mixer pcm 100 vol 100 cd 100
- 其他硬體
+ 其他怪異問題(ACPI、重開機後掛了..等)FreeBSD 還支援其他哪些硬體呢?請參閱使用手冊上的 安裝篇—其他硬體
。FreeBSD 支援筆記型電腦的省電管理功能嗎?FreeBSD 4.X(含之後版本)在某些機種上都有支援 APM。
細節請參閱 &man.apm.4; 的說明。FreeBSD 5.X(含之後版本)支援在目前大部分機種上都有的
ACPI 功能。
細節請參閱 &man.acpi.4; 的說明。若機器上同時都有 APM
及 ACPI 功能的話,我們建議你可以兩者都試試看,
看看哪一種比較符合你的需求。該如何關閉 ACPI?把 hint.acpi.0.disabled="1"
這段加到 /boot/device.hints 即可。Micron 電腦總是在 &os; 啟動時就掛掉,該怎麼辦呢?有些 Micron 主機板上的 BIOS 在 PCI 方面會有問題,
這會導致 PCI 設備會被 BIOS 偵測為不正確設定,而進入 FreeBSD 就掛掉。暫時解決方式:關閉 BIOS 內 Plug and Play Operating System
的設定。&tm.3com; PCI 介面網路卡無法在 Micron 電腦上使用,該怎麼辦?這問題跟前面的問題因素一樣,總之,就是關閉 BIOS 中有關 OS PnP 的設定。暫時解決方式:關閉 BIOS 內 Plug and Play Operating System
的設定。主機板是用華碩(ASUS) K7V,可是用開機片開到一半就當了,怎麼辦呢?進入 BIOS 設定,並關閉 boot virus protection 設定即可。PCMCIA 卡無法使用,並出現錯誤訊息
cbb0: unsupported card type detected.
該怎麼辦?可以試試看改用舊的方式,請先修改 kernel 設定檔,拿掉下面這幾行:
device cbb
device pccard
device cardbus
然後加上:
device pcic
device card 1
最後請參閱 Handbook 中
調整 FreeBSD Kernel
章節,以重新編譯、安裝新的 kernel。為什麼 &dell; &poweredge; 2850 裝完 FreeBSD 之後,重開機接著鍵盤就掛了?(本題由 cdsheen 提供)嚐試在 &dell; &poweredge; 2850 上面安裝 &os; 6.0,
不過安裝完成、並重新開機之後,發現 console 的鍵盤不能動了,
同樣的情況似乎也存在於 &os; 5.3 及 &os; 5.4,
經過一番搜尋,發覺是因為這台機器上面有一個 Dell Remote Access Controller (DRAC),
這個裝置會被系統辨識成一個 USB Keyboard,所以導致開完機之後,正常的 PS/2 鍵盤反而不能動了!暫時解決方式如下:先以 Single User Mode 進入系統在命令列模式下,先執行下列命令:&prompt.root; fsck -y /&prompt.root; mount -u /然後編輯 /etc/devd.conf,把對於 USB Keyboard 的支援暫時拿掉,
也就是把下面幾行開頭加上 #
# When a USB keyboard arrives, attach it as the console keyboard.
#attach 100 {
# device-name "ukbd0";
# action "kbdcontrol -k /dev/ukbd0 < /dev/console && /etc/rc.d/syscons restart";
#};
#detach 100 {
# device-name "ukbd0";
# action "kbdcontrol -k /dev/kbd0 < /dev/console";
#};
然後輸入 exit離開 Single User Mode 之後,
就可以順利進入系統、而且鍵盤也可以正常運作,下次開機也不會有問題!另外,&dell; 的 DRAC/BMC 看起來有蠻多不錯的遠端存取功能,有興趣的人可以玩玩看...WilliamLiaochliao@tpts4.seed.net.tw常見問題解決
+
+
+ Why is &os; finding the wrong amount of memory?
+
+
+
+ The reason is the difference between physical memory addresses
+ and virtual addresses.
+
+ The convention for most PC hardware is to use the memory area
+ between 3.5G and 4G for a special purpose (usually for PCI). This
+ address space is used to access PCI hardware. As a result real,
+ physical memory can not appear in that address space.
+
+ What happens to the memory that should appear in that location
+ is dependent on your hardware. Unfortunately, some hardware does
+ nothing and the ability to use that last 500M of RAM is entirely
+ lost.
+
+ Luckily, most hardware remaps the memory to a higher location
+ so that it can still be used. However, this can cause some
+ confusion if you watch the boot messages.
+
+ On a 32 bit version of &os;, the memory appears lost, since it
+ will be remapped above 4G, which a 32 bit kernel is unable to
+ access. In this case, the solution is to build a PAE enabled
+ kernel. See this FAQ entry
+ for more information.
+
+ On a 64 bit version of &os;, or when running a PAE-enabled
+ kernel, &os; will correctly detect and remap the memory so it is
+ usable. During boot, however, it may seem as if &os; is detecting
+ more memory than the system really has. This is normal and the
+ available memory will be corrected as the boot process
+ completes.
+
+
+
硬碟有壞軌時該怎麼辦?若是 SCSI 硬碟的話,那麼磁碟機應該有能力自動作 re-mapping
的動作。然而,因為一些未知的因素,在出廠時,很多硬碟的這項
功能是關閉的...要將其重新開啟,您需要編輯裝置的第一個 page 模式
(first device page mode),在 FreeBSD 上可以用下面的指令辦到
(以 root身分執行)&prompt.root; scsi -f /dev/rsd0c -m 1 -e -P 3然後將 AWRE 和 ARRE 的數值從 0 變成 1:-AWRE(Auto Write Reallocation Enbld): 1
ARRE(Auto Read Reallocation Enbld): 1以下這段是由 Ted Mittelstaedt
tedm@toybox.placo.com所提供:若為 IDE 硬碟,任何的壞軌通常都是麻煩的預兆。目前所有較新的
IDE 硬碟,內部都有自動 remapping 壞軌的能力。目前所有 IDE 硬碟
製造商,都提供了更久的保證,而且會幫您更換出現壞軌的硬碟。如果您仍想要修復產生壞軌的 IDE 硬碟,您仍可以試著去下載 IDE
硬碟製造商所提供的檢測程式,並用它來檢查您的硬碟。有時這些軟體可
以強迫重新檢查硬碟的壞軌,並將它們標示出來。對 ESDI,RLL 及 MFM 的硬碟來說,通常壞軌是正常現象,也不是什
麼麻煩的前兆。在 PC 上,磁碟控制卡和 BIOS 負責標示壞軌的任務。這
對一些使用 BIOS來存取磁碟的作業環境(如 DOS)是沒有問題的。然而,
FreeBSD 的磁碟驅動程式並不經過 BIOS 來存取磁碟,所以,有個 bad144
的機制用來取代這項功能。bad144 只能用在 wd 這個磁碟驅動程式上(這
個代表了 FreeBSD 4.0 並不支援它),它也無法用在 SCSI 硬碟上。
bad144的工作方法是將所有找到的壞軌資料存到一個特別的檔案�堙C使用 bad144 的警告 - 存著壞軌資料的特別檔案是放在硬碟的最後
一軌上。因為這個檔案儲存的壞軌資料中,有可能有些資料是指向硬碟最
前端所發生的壞軌情形,就是可能儲存 /kernel 這個檔的地方,所以它
一定要能被開機程式所讀取,而開機程式是透過 BIOS 來讀取 kernel
檔。這表示了使用 bad144 的硬碟絕不能擁有超過 1024 個 cylinder,
16 個 head 及 63 個 sector。而這使得欲使用 bad144 的硬碟的大小不
能大於 500 MB。要使用 bad144 很簡單,只要在開始安裝時,在 FreeBSD fdisk 畫面
把Bad Block 掃瞄設為 ON 即可。在 FreeBSD 2.2.7 以
後都可以使用此方法。但這個硬碟的 cylinder 一定要在 1024 以下。使
用前,我們建議這個硬碟要至少先使用四個小時,以便熱膨脹與磁軌偏移
達一般狀態。如果這個硬碟擁有超過 1024 個 cylinder(像大容量的 ESDI 硬碟)
,ESDI 控制卡利用一個特別的轉換模式使它能在 DOS 下工作。而如果您
在 fdisk �堛� set geometry 中輸入
轉換過 的 geometry,wd 這個驅動程式能了解這些轉換
模式。您也絕對不能使用 dangerously dedicated 模式來建立 FreeBSD
的分割區,因為它會忽略 geometry 這個參數。此外,就算 fdisk 使用
您所輸入的 geometry 參數,它依然會去讀取這硬碟的真正資料,而會嘗
試去建立一個過大的 FreeBSD 分割區。如果磁碟的 geometry 已經被
轉換 過了,那麼 這個分割區 必須
以手動輸入 block 數目的方法來建立。一個快速的小技巧是利用 ESDI 控制卡來設定大容量的 ESDI 硬碟,
用 DOS 開機片開機,再將它 format 為 DOS 的分割區。然後重開機進入
FreeBSD 安裝程序,在 fdisk 畫面,把DOS 分割區的 blocksize 和
block number 抄下來。然後重新設定 geometry 使其跟 DOS 使用的一樣。
刪除 DOS 分割區,然後使用您剛剛抄下的 blocksize 來建立一個
cooperative FreeBSD 分割區。然後設定這個分割區為可
開機,再打開壞軌掃瞄。在真正的安裝過程中,bad144 會在任何檔案系統
被建立前先被執行。(您可以按 Alt-F2 來監看這一切)如果在建立壞軌資
料檔時發生了問題,您會需要設定一個較大的磁碟 geometry - 這表示您
需要重開機,然後全部再重新開始(包括重新分割以及在 DOS 下重新
format)。如果 remapping 的功能已經啟動了,而您依然一直看到壞軌產生,
那麼考慮換一台硬碟吧。壞軌的情形只會隨時間增加而更為嚴重。為什麼 FreeBSD 抓不到 HP Netserver 的 SCSI 控制卡?基本上這個是一個已知的問題。在 HP Netserver 機器上的 on-board
EISA 介面 SCSI 控制卡占據了定址為第 11 的 EISA 槽,因此所有的
真實 EISA 槽都在它之前。可是,在 EISA 定址空間
>= 10 時,會與指定給 PCI 用的定址空間相衝突,且 FreeBSD 的
auto-configuration 無法正確的處理這個情形。因此,現在你能做的最好事情就是在 kernel �堻]定
EISA_SLOTS 這個選項為 12 ,然後當作沒有這個
問題 :)。請依照
Handbook 中有關 kernel 的設定 �堜珨〞漱隤k來設定與編譯
您的 kernel。當然,在安裝 FreeBSD 到這種機器上時,這是一個雞生蛋蛋生雞的
問題。為了解決這個問題,在 UserConfig 中有
一個特別的方法,安裝時不要進入 visual 介面,相反
的,在命令列模式中,鍵入eisa 12
quit然後就如以往一樣安裝您的系統。不過我們建議您編譯與安裝一個
屬於自己的 kernel,但希望在未來的版本中能對這個問題有一個好的解決方法。您無法在 HP Netserver 上使用
dangerously dedicated 磁碟模式。您可以參考
這份註解 以獲得更多資訊。一直看到類似
ed1: timeout 的訊息。它們是什麼意思呢?
- 這個通常是由於中斷衝突(interrupt conflict)所造成的(例如,
- 兩塊卡使用到了相同的 IRQ)。 FreeBSD 在 2.0.5 版以前都容許這個
- 情形,就算有 IRQ 衝突情形,網路卡也應該仍可正常運作。然而,在
- 2.0.5 版及其以後,已不再容許有 IRQ 衝突的情形了。請於開機時使
- 用 -c 這個選項,然後更改 ed0/de0/..。等的設定,使其和您網路卡
- 本身的設定一致。
+ 這個通常是由於中斷衝突(interrupt conflict)所造成的
+ (例如:兩塊卡使用到了相同的 IRQ)。 FreeBSD 在 2.0.5 版以前都容許這個情形,
+ 就算有 IRQ 衝突情形,網路卡也應該仍可正常運作。然而,在 2.0.5 版及其以後,
+ 已不再容許有 IRQ 衝突的情形了。請於開機時使用 -c 這個選項,
+ 然後更改 ed0/de0/..等的設定,使其和您網路卡本身的設定一致。
- 如果您是使用您網路卡上的 BNC 接頭,您或許也會因不良的終端電
- 阻設定,而發生裝置 (device) timeout 的情形。要檢查是否有這種情
- 形,您可以在網路卡上直接接上終端電阻(不要接網路線),然後看看這
- 個錯誤訊息是不是就消失了。
+ 如果您是使用您網路卡上的 BNC 接頭,您或許也會因不良的終端電阻設定,
+ 而發生裝置(device) timeout 的情形。要檢查是否有這種情形,
+ 您可以在網路卡上直接接上終端電阻(不要接網路線),
+ 然後,看看這個錯誤訊息是不是就消失了。
- 有些 NE2000 的相容卡,如果它的 UTP 埠沒有接網路線,或是該網
- 路線並沒被使用的話,也會出現這個錯誤訊息。
+ 有些 NE2000 的相容卡,如果它的 UTP 埠沒有接網路線,
+ 或是該網路線並沒被使用的話,也會出現這個錯誤訊息。
- &tm.3com; 3C509 網路卡在沒有任何明顯原因下停止工作
- 了呢?
+ &tm.3com; 3C509 網路卡莫名其妙罷工?這塊卡有個不好的地方在於它常常會遺失本身的設定資料。請使用該
卡的 DOS 工具 3c5x9.exe 來更新卡上設定。
- 平行埠印表速度破天荒的慢,我該怎麼做?
+ 平行埠印表速度破天荒的慢,該怎麼辦?如果唯一的問題就是速度很慢的話,試著改變您的
印表機連接埠設定 這個在手冊中的
印表機設定
這個章節有加以討論。
- 程式有時會因
- Signal 11 這個錯誤而停止?
+ 程式有時會因 Signal 11 錯誤而停止?Signal 11 這個錯誤是因為你的 process 嘗試要存取一塊記憶體,
而你的作業系統並不允許它做這個動作而發生的。如果這種情形常常不
定時發生,那麼你應該要開始看看是不是哪裡出問題了。這些問題可能是與下列情形有關:如果這個問題只在某一個您自己寫的某個特定程式發生,那
麼很有可能是您的程式碼有問題。如果這個問題是在 FreeBSD 的某些系統檔案發生,有可能是
因為程式有問題,但通常在我們這群讀 FAQ 的使用者去跑這些有
問題的程式碼前,它們早就就已經被解決了(這是 -current 在做
的事)。尤其如果你在編譯一個程式,但是每次編譯器跑出來的結果都不一樣
- 的話,這是一個無解的問題,而不是
- FreeBSD 臭蟲。
+ 的話,這是一個無解的問題,而不是 FreeBSD 臭蟲。
舉例來說,假設您正在跑 make buildworld,
而 compiler 在將 ls.c 編譯成
ls.o 時發生錯誤,這時請再跑一次
make buildworld,如果 compiler 依然在同樣的地方發
生問題,那麼就是程式碼有問題--請更新原始碼然後再試試看。而如果
compiler 是在其他的地方發生錯誤,那麼幾乎可以確定是硬體的問題了。
您這時應該做什麼:如果是第一種情形,可以使用一些 debugger,如:gdb,來找出程式
是在那兒會去嘗試存取錯誤的記憶體位址,然後再修正它。如果是第二種情形,就需要檢查看看是不是硬體的問題了。一些造成硬體不穩的原因包括:可能是硬碟過熱:請檢查機殼內的風扇是否運作正常,因為您
的硬碟(或者還有其他的硬體裝置)過熱了。處理器過熱:這個有可能是因為超頻,或者是處理器的風扇掛了。
不論是哪種原因,您都需要將所有的元件回復到它們原先設定的工作狀
態,這樣才能解決這個問題。舉個例子來說:將處理器調回原先的工作
頻率。如果您還是堅持要超頻的話,請謹記,與其燒壞而需要換新的一台
主機,不如將速度調慢一點!除此之外,不管你覺得它安不安全,一般
人對於您因為超頻而發生的問題,是不會有什麼同情心的。不穩定的記憶體:如果主機上有安裝數根 SIMM/DIMM 記憶體,
試著把它們全拆下來,然後一根一根插上去做測試,藉此縮小範圍,
以便找出有問題的某根記憶體或是某種記憶體組合。最佳化過頭的主機板設定:在 BIOS �堜峎O有些主機板的 jumper
上,有時可以更改一些 timing,但在大多數的情形�堙A使用預設值就
已經足夠了。況且有時候把 RAM 的 wait states 設太小,或是在
BIOS �堙A把 RAM Speed: Turbo 這個或是其他類似
的選項打開都有可能會造成一些不正常的現象。一個解決的方法是把
BIOS 設回預設值,不過在這之前記得先記下目前的設定!供給主機板的電力不乾淨或是不足。試著把系統內沒有用到的
I/O 卡.硬碟或是 CDROM 暫時拆掉或是拔掉電源線,看看你的電源
供應器是不是能夠在小一點的負荷下正常工作。不然就是換上另一
個新的電源供應器,最好是瓦數高一點的(打個比方來說,如果原
先的電源供應器是 250 瓦的,那麼就換上 300 瓦的試試)。請順便參閱 SIG11 FAQ(連結在下面),雖然它是站在 Linux 的角
度寫的,可是裡面對這些問題有許多很棒的解說。它裡面也有討論為什麼
有問題的記憶體能通過軟體或硬體的測試的原因。最後,如果上面這些原因都排除了,那麼有可能是遇到了 FreeBSD
�堛漱@隻臭蟲,請參閱指示做一個問題回報。這兒有一個更詳細的 FAQ -
the SIG11 problem FAQ
- 當機時出現:Fatal
- trap 12: page fault in kernel mode,或是
- panic:再加上一堆錯誤訊息,
- 該怎麼辦?
+ 當機時出現:Fatal trap 12: page fault in kernel mode
+ ,或是 panic: 以及一堆錯誤訊息,該怎麼辦?FreeBSD 的開發者對於這些錯誤訊息相當的有興趣,但是他們需要
更詳細的一些細節。請把您的當機的訊息全部複製下來,接著查閱 FAQ
�� kernel
panics 這節,依說明編譯一個含除錯碼的 kernel,以取得函式
呼叫順序(backtrace)。這個聽起來很難,但實際上並不需要任何程式
設計的能力,您只需要依照指示做即可。為什麼當我開機時,螢幕變黑,且不停閃動?這個問題,已知是由 ATI Mach 64 顯示卡所引起的。因為這塊卡
使用到 2e8 這個位址,而這與第四個序列埠
(serial port)所使用的位址相同。而在 &man.sio.4; 這個驅動
程式�堙A不知道是 bug 或是功能(feature),就算您沒有第四個序
列埠,或是已經將 sio3(第四個序列埠)取消了,它
依然會去嘗試驅動它。直到這個問題被解決以前,您可以使用這個方法:在看到開機提示時輸入
(這會讓 kernel 進入設定模式)。取消 sio0 ,
sio1 ,
sio2 和
sio3(全部)。
這可以讓 sio 驅動程式不動作 -> 於是問題解決。輸入 exit 以繼續啟動程序。如果您想要使用您的序列埠,您需要修改
/usr/src/sys/i386/isa/sio.c,在該檔中找出
0x2e8 這個字串,移除這個字串及它前面的逗號
(保留後面的),然後重新編譯一個新的 kernel。就算使用了上面這些方法,X Window 仍然有可能無法順利執行。
如果發生了這種情形,請確定你用的 XFree86 的版本是最新的 XFree86
3.3.3 或是其後的版本。它們有內建支援 Mach 64 這張卡,甚至為了這
些卡還附有一個特別的 X Server為什麼我的系統裝有 128 MB 的 RAM,而 FreeBSD 只用了其中的
64MB?因為 FreeBSD 是使用呼叫 BIOS 來取得記憶體大小的方法,因此它
只能偵測到 16 bits 位元長度的 KByte 大小(65535 KBytes = 64MB)
(或者更少..。有些 BIOS 將最高記憶體大小限為只有 16MB)
如果您擁有 64MB 以上的 RAM,FreeBSD 會嘗試去偵測出它,但是有可能
會失敗。要解決這個問題,您需要使用下面所提的 kernel 設定選項。雖然有
方法可以從 BIOS 中取得記憶體的完整資訊,但是目前我們在開機區中並
沒有多餘的空間來做這件事。當某天開機區空間不足的情形獲得解決時,
我們將會使用 BIOS 的延伸功能來取得記憶體的完整資訊...但現在我們
將它放在 kernel 設定選項中。options "MAXMEM=n"n 是指您的記憶體大小,以 KB
為單位。以一台有 128MB RAM 的機器來說,您可使用
131072這個數字。機器上的 RAM 有 1GB 以上,可是為何卻收到 kmem_map too small
的 panic 錯誤訊息?
通常 FreeBSD 會依據機器狀況來自動調整 kernel 相關參數設定,比如:
根據機器所裝的 RAM 大小來決定同時可開啟的檔案數量多寡。
然而,在 1GB RAM(含以上) 的機器上,這個『自動調整』的機制可能有時會高估:
比方說..開機時,kernel 會先配置各種不同用途的表格及其他架構放到記憶體上,
然後,當整個作業系統都開始運作之後,kernel 就會開始不夠空間來做記憶體配置的動態調整,
於是就 panic 掛了。解法是:把 加到 kernel 設定檔內,
並重新編譯 kernel,比如:
這樣會設定 400 MB 來給 kernel 使用,而且採用 400 MB 的話,
目前在 6GB RAM 的機器上都可被有效運用。機器上 RAM 不到 1GB ,但仍會出現
kmem_map too small! 的 panic 錯誤訊息
之所以 panic 的原因在於系統用光了給 network buffer 用途的 virtual memory
(尤其是 mbuf clusters)。解法是增加給 mbuf clusters 用的 virtual memory
數量,這步驟請參閱 FreeBSD 使用手冊的
網路限制篇
。為什麼我一直看到 /kernel: proc: table
is full 這個錯誤訊息?FreeBSD kernel 只允許一定數量的 process 在同一時間裡同
時運作。而這個數目是根據 kernel 設定檔裡面的
MAXUSERS 值來決定的。MAXUSERS
這個值也會影響其他的 kernel 內定值,比如說 network buffer
(請參閱這個之前討
論過的問題)。如果機器負荷(load)很重,您可能需要增加
MAXUSERS 這個值。這麼作會一併提高系統的其他內
定值,包括最大可擁有的 process 數等。若要調整 MAXUSERS,請參閱 FreeBSD 使用手冊中的
檔案/Process的限制 章節。
(雖然該處指的是『檔案的開啟數量限制』,但也適用於 process部分。)在 FreeBSD 4.4 之後,MAXUSERS 已經變成可
以靠著更改 /boot/loader.conf �堛�
kern.maxusers 這個值而調整的變數了。而在之前
的 FreeBSD 版本中,這個值只能在 kernel 設定檔�婼桴耤C如果機器負荷並不重,而您只是需要同時跑很多很多 process,
那麼也可以直接用 sysctl 調整 kern.maxproc 值。
假如這些 process 都是屬於某個使用者的,那麼您還需要另
外調整 kern.maxprocperuid 這個值,使它比新
的 kern.maxproc 這個值少 1 (一定要少 1 ,
因為 &man.init.8; 這個系統程式絕對要保持在運作狀態)。如果想在每次開機都要更改 sysctl 的值,而且您的 FreeBSD 是
最近的版本的話,請在 /etc/sysctl.conf 這
個檔中設定,而如果是舊的版本,可以在
/etc/rc.local 中作設定。為什麼用新 kernel 開機時,出現 CMAP
busy 這個錯誤訊息?
- 用來偵測過時
- /var/db/kvm_*.db 檔案的機制偶爾會
- 發生問題,而使用到了一個不協調(mismatch)的檔案有時就會導致
- panic。
+ 用來偵測 /var/db/kvm_*.db 過時檔案的機制偶爾會發生問題,而使用到了一個不協調
+ (mismatch)的檔案有時就會導致 panic。
- 如果發生了這個問題,請重新開機,進入單使用者模式,然後執
- 行:
+ 如果發生了這個問題,請重新開機,進入 single 使用者模式,然後執行:&prompt.root; rm /var/db/kvm_*.db
- 請問這個訊息:ahc0: brkadrint,
- Illegal Host Access at seqaddr 0x0
+ 請問這個訊息:ahc0: brkadrint, Illegal Host Access at seqaddr 0x0
是什麼意思?這是一個和 Ultrastor SCSI 控制卡有關的衝突(conflict)。在開機時,進入 kernel 設定選單取消
uha0,它是造成這個問題的原因。
- 在開機時,我看到這個錯誤訊息
- ahc0: illegal cable configuration。
+ 開機時,看到這個錯誤訊息 ahc0: illegal cable configuration。
我的排線確定有接對。 是出了什麼問題呢?您的主機板可能不支援自動終端電阻設定。請進到 SCSI 的 BIOS
- 裡面手動指定正確的終端電阻順序,而不要使用自動設定。AIC7XXX 的
- 驅動程式並無法知道有沒有這些排線偵測(以及自動終端電阻設定)的
- 電路(external logic)存在。如果 EEPROM 裡面的設定是
- "automatic termination" 時,它只會單純假定這些電路當然是存在的。
- 若缺少了這個電路,驅動程式在設定終端電阻時就常常出問題。
+ 裡面手動指定正確的終端電阻順序,而不要使用自動設定。
+ AIC7XXX 的驅動程式並無法知道有沒有這些排線偵測(以及自動終端電阻設定)的電路(external logic)
+ 存在。如果 EEPROM 裡面的設定是 "automatic termination" 時,它只會單純假定這些電路當然是存在的。
+ 若缺少了這個電路,驅動程式在設定終端電阻時就常常出問題。
而這種問題將導致 SCSI 匯流排的可靠性降低。為什麼 Sendmail 一直出現
mail loops back to myself
這個錯誤訊息?這個問題在 sendmail 的 FAQ 中是這樣回答的:- * 我一直收到有關 "Local configuration error" 的信件,例如:
553 relay.domain.net config error: mail loops back to myself
554 <user@domain.net>... Local configuration error
我要如何解決這個問題?
您利用 MX 設定,讓要寄到某 domain(如: domain.net)的信件,
寄到您所指定的機器(在這個例子中為 relay.domain.net),但是這
部機器並未被設定接受 domain.net 的信件。請把 domain.net 加到
/etc/sendmail.cw 中(如果您有使用 FEATURE(use_cw_file)) 或是
在 sendmail.cf 中加入 "Cw domain.net"
最新版本的 sendmail
FAQ 現在已不再隨著 sendmail 出貨。
它目前是被定期的發表在 comp.mail.sendmail,
comp.mail.misc,comp.mail.smail,comp.answers,和 news.answers. 您也可以寄一封
Email 到 mail-server@rtfm.mit.edu,然後在信件內文
中寫上
send usenet/news.answers/mail/sendmail-faq
以取得這份 FAQ 文件。為什麼執行遠端機器(remote machine)的全螢幕的軟體時,
有不正常的情形?或許遠端機器並非將您的終端機模式設為 FreeBSD console 所用的
cons25,而是設為其它模式。這兒有幾個解決這個問題的方法:在 logging 進遠端機器後,更改您的 shell 變數 TERM 為
ansi 或是 sco
﹙如果遠端機器支援這些模式的話)。使用支援 VT100 的模擬軟體,如 FreeBSD console 下的
screen 軟體。
screen 提供您在一個 terminal
�埵P時跑好幾個 session 的能力,而且它本身也是一個相當好
的軟體。每個 screen 都像是一個
VT100 的終端機,所以遠端機器的 TERM 變數應該設為
vt100。在遠端機器的終端機資料庫(terminal database)中加入
cons25 的資料。加入的方法視遠端機器的
作業系統不同而有所差異。請參閱遠端機器給系統管理員的說明
書,應該會有所幫助。啟動 FreeBSD 的 X 伺服器,然後使用一些 X Window 下的
終端機模擬器來登入遠端機器,例如 xterm
或 rxvt。而遠端機器的 TERM 變數應該要
設為 xterm 或 vt100。
為什麼我的機器一直顯示
calcru: negative time...?跟中斷(interrupt)有關的不同硬體 與/或 軟體的搭配都有可能造成
這個問題。這有可能是 bug 或是某個裝置本身的問題。在平行埠上使用
大的 MTU 來作 TCP/IP 傳輸可以重現這個問題。若是圖形加速卡造成這個
問題的話,您應該先檢查卡的中斷設定。這個問題的邊際效應是會造成有些 process 出現
SIGXCPU exceeded cpu time limit 的訊息,而不正常
停止。若是 FreeBSD 3.0 或是 1998 年 11 月 29 日以後其他版本,萬一
這個問題一直無法以其他方法解決,就只能設定 sysctl 變數:&prompt.root; sysctl -w kern.timecounter.method=1這樣會對效能有些影響,但是若考慮到這個問題帶來的後果,這樣做
是值得的。如果這個問題還是存在的話,讓 sysctl 那個值依然設為 1,
然後增加 kernel 設定檔中 NTIMECOUNTER 這個選
項的數值。如果您將 NTIMECOUNTER 增加到 20 依
然無法解決這個問題,那麼您機器上的中斷已經多到無法讓計數器維持在
可靠的狀態了。出現 pcm0 not found 這個訊息,或者是
我的音效卡變成了 pcm1,但在 kernel 設定
檔�塈甯O設 device pcm0 啊。這是怎麼回事呢?
如果您在 FreeBSD 3.x 上使用 PCI 音效卡就會發生這種問題。
因為pcm0 這個 device 是內定保留給 ISA
的音效卡的,所以如果您有一張 PCI 的音效卡,您就會遇到這個問題,
而您的卡會變成 pcm1。如果您只把 kernel 設定檔中的設定改成
device pcm1 是無法除去這個警告訊息的,
這樣會造成 pcm1 被保留給 ISA 音效卡,
而 PCI 音效卡則會變成 pcm2
(外加 pcm1 not found 的警告訊息)。
如果您有一張 PCI 的音效卡,您需要 make
snd1 這個 device,而不是
snd0:&prompt.root; cd /dev
&prompt.root; ./MAKEDEV snd1這個問題在 FreeBSD 4.x 上並不會發生,因為很多人投下了許多心
力讓它更PnP 導向,而且
pcm0 這個 device 也不再是只保留給 ISA
的音效卡了。為什麼在更新到 FreeBSD 4.X 後會抓不到我的 PnP 卡
(或者是抓成 unknown)?FreeBSD 4.X 現在已經更 PnP 導向了,
而邊際效應就是會發生有些在 FreeBSD 3.X 可以用的 PnP 裝置
(如音效卡或是內插式數據機)變成無法使用。這個原因可以用一封由 Peter Wemm 發到 freebsd-questions
這個 mailing list 上的信來解釋,它原本是解釋為什麼有一個內
插式數據機,在系統升級到 FreeBSD 4.x 後,就沒法被抓到了
(在 [] �堛漪O另外加的註解,讓內容更易懂)。
The PNP bios preconfigured it [the modem] and left it
laying around in port space,so [in 3.x] the old-style ISA
probes found it there.Under 4.0,the ISA code is much more PnP-centric. It was
possible [in 3.x] for an ISA probe to find a
stray device and then for the PNP device id to
match and then fail due to resource conflicts. So,it
disables the programmable cards first so this double probing
cannot happen. It also means that it needs to know the PnP
id's for supported PnP hardware. Making this more user
tweakable is on the TODO list.
如果要讓裝置能再度運作,我們需要找出它的 PnP id,然後再將它
加入一份在偵測 ISA 裝置時會使用的表中。可以執行 &man.pnpinfo.8;
來偵測這個裝置,舉例來說,下面是 &man.pnpinfo.8; 抓到的一個內插
式數據機的資料:&prompt.root; pnpinfo
Checking for Plug-n-Play devices...
Card assigned CSN #1
Vendor ID PMC2430 (0x3024a341),Serial Number 0xffffffff
PnP Version 1.0,Vendor Version 0
Device Description: Pace 56 Voice Internal Plug & Play Modem
Logical Device ID: PMC2430 0x3024a341 #0
Device supports I/O Range Check
TAG Start DF
I/O Range 0x3f8 .. 0x3f8,alignment 0x8,len 0x8
[16-bit addr]
IRQ: 4 - only one type (true/edge)[more TAG lines elided]TAG End DF
End Tag
Successfully got 31 resources,1 logical fdevs
-- card select # 0x0001
CSN PMC2430 (0x3024a341),Serial Number 0xffffffff
Logical device #0
IO: 0x03e8 0x03e8 0x03e8 0x03e8 0x03e8 0x03e8 0x03e8 0x03e8
IRQ 5 0
DMA 4 0
IO range check 0x00 activate 0x01您所需要的資訊是一開始看到的 Vendor ID
這一行。括號中的十六位元碼(這個例子中是 0x3024a341)就是
PnP id,而在這之前的字串(PMC2430)則是一個獨一無二的 ASCII id。
而這些資料需要被加到 /usr/src/sys/isa/sio.c
這個檔案�堙C為了防止任何東西出錯,您應該要先備份目前的
sio.c。而且您要 submit PR 時也需要這個
原始檔案來做出 patch(您應該會將它 submit PR 吧..:)..)。
接著就編輯 sio.c 找尋下面這行static struct isa_pnp_id sio_ids[] = {接著往下捲動,找個正確的位置來插入您的裝置資訊。您看到的就
下面這個樣子,它們是照右邊註解裡面的 ASCII 這個 Vender ID 做排
序的,或是 &man.pnpinfo.8; 所找到的一部分
裝置描述:{0x0f804f3f,NULL}, /* OZO800f - Zoom 2812 (56k Modem) */
{0x39804f3f,NULL}, /* OZO8039 - Zoom 56k flex */
{0x3024a341,NULL}, /* PMC2430 - Pace 56 Voice Internal Modem */
{0x1000eb49,NULL}, /* ROK0010 - Rockwell ? */
{0x5002734a,NULL}, /* RSS0250 - 5614Jx3(G) Internal Modem */把您這個裝置的十六進位的 Vender ID 加到正確的地方,存檔,
然後重新編一個 kernel,再重開機。之後這個裝置應該就會像在
FreeBSD 3.X 下,被偵測為 sio 裝置了。為什麼我常常在跑一些程式(例如 top 或
systat)的時候出現
nlist failed 這個錯誤訊息?這個問題是因為您跑的程式需要一個特別的 kernel symbol,可是
不知道什麼原因而找不到﹔而會發生這個問題可能是因為下面兩個原因:
您的 kernel 和 userland 的檔案版本並不一致(例如說,您
編了一個新的 kernel,但是並沒有執行對應的
installworld,或是其他類似情形),
因此 symbol table 的內容就和應用程式編譯時的不太一樣了。如
果是這種情形,請執行完整的升級步驟(請參閱
/usr/src/UPDATING 以得知正確的流
程)。您沒有用 /boot/loader 來載入您的
kernel,而是直接由 boot2 開機(請參閱 &man.boot.8;)。
雖然說跳過 /boot/loader 並沒有什麼錯,
但是它在 kernel symbols 跟應用程式的溝通方面佔了很重的份量。
為什麼我用 ssh 或 telnet
連到我的電腦時,會等待很長的一段時間才能連上?症狀:TCP 連線建立之後和詢問密碼之前(如果是在說 &man.telnet.1;
的話,則是 login 提示符號跳出來之前),要等待很長的一段時
間。問題所在:這種延遲情形常常是因為伺服軟體(server software)
嘗試要將客戶端(client)的 IP 位址轉換成主機名稱。因為很多伺服
軟體,包括 FreeBSD 內建的 Telnet 和 SSH,為了將主機名稱寫入紀
錄檔中以供管理者作參考,而會做這項動作。解決方法:如果這個問題在您連接不同的伺服器時都會發生,那麼
問題是在您客戶端這一方﹔同樣的,如果別人只有在連到您的伺服器上
才會發生這個情形,那麼問題就是在伺服器這邊了。如果是客戶端這方有問題,唯一的方法就是將 DNS 伺服器修好,
這樣對方伺服器才能正確的轉換名稱。如果問題是在內部區域網路發
生的,這應該是伺服器有問題,請詳細檢查一下﹔相反的,如果是您
在上 Internet 時發生的,那麼您需要跟您的 ISP 聯絡,請他們解決
這個問題。如果是伺服器這邊的問題,而且是發生在內部區域網路,那麼您需
要設定這個伺服器,使它能正確將內部網路的 IP 位址轉換為主機名稱。
請參閱 &man.hosts.5; 和 &man.named.8; 的說明以獲得更多資訊。如
果是在 Internet 上的伺服器發生這個問題,那麼有可能是您伺服器的
轉換功能出問題。您可以試試查詢另一個主機名稱,比如:
www.yahoo.com。如果查不到,那麼可以確定是您這
邊出問題了。stray IRQ 這個錯誤訊息是什麼意思?Stray IRQs 是硬體 IRQ 有點小問題的現象,大多是因為硬體本身
在發出中斷需求後,又取消了它自己的中斷要求。有三個方法可以應付這個問題:不理會這個警告。反正一個 irq 出現五次警告後系統就不會
再顯示了。把 isa_strayintr() �堛滬�,由 5
改成 0,這樣所有的警告訊息都不會出現。安裝使用 irq 7 的平行埠硬體設備,以及它的 PPP 驅動程式
(這個大部分系統都有做),接著安裝 ide 硬碟或是其他會使用
irq 15 的硬體設備以及它的驅動程式。為什麼 file: table is full 這個訊息
一直在 dmesg �堶娃ぁX現?這個錯誤訊息代表了您系統的 file descriptors 已經使用光了。
請參閱手冊內
Tuning Kernel Limits 裡面的
kern.maxfiles 這個章節,裡面有一些討論及解決方法。為什麼我筆記型電腦上的時鐘一直顯示錯誤的時間?您的筆記型電腦裡有兩個以上的時鐘,而 FreeBSD 選到了錯的
那個。執行 &man.dmesg.8;,檢查一下有 Timecounter
字串的那幾行。最後一行是 FreeBSD 選用的,通常是
TSC。&prompt.root; dmesg | grep Timecounter
Timecounter "i8254" frequency 1193182 Hz
Timecounter "TSC" frequency 595573479 Hz您可以執行 &man.sysctl.3; 看一下
kern.timecounter.hardware 這個值做確認。&prompt.root; sysctl kern.timecounter.hardware
kern.timecounter.hardware: TSCBIOS 可能在一些情形下會更改 TSC 的時脈—有時候是因為
在使用電池工作時會更改處理器的速度,另外也有可能是進入了省電模
式,可是 FreeBSD 並不會察覺到這些調整,而會發生時間增加或是減
少的情形。在上面的例子當中,我們看到還有 i8254
這個時鐘可以選擇,執行 &man.sysctl.3; 用手動的方式將這個值寫入
kern.timecounter.hardware 中。&prompt.root; sysctl -w kern.timecounter.hardware=i8254
kern.timecounter.hardware: TSC -> i8254這樣您的筆記型電腦應該就可以保持正確的時間了。如果要讓這個更改的動作再每次開機時自動執行,在
/etc/sysctl.conf �堨[入下面這行。kern.timecounter.hardware=i8254為什麼我的筆記型電腦無法正確的偵測到 PC card ?這個問題常常發生在灌了多個作業系統的筆記型電腦上。有些非
BSD 的作業系統會讓 PC card 的硬體裝置處在一個不一致的狀態下
(inconsistent state)。使得 pccardd 在偵
測這片卡時,無法抓到正確的型號,而是
"(null)""(null)"。您需要移除 PC card 插槽的電源以重置這個硬體裝置。一個方法是
將您的筆記型電腦關機(不是休眠模式,也不是待命模式﹔要完全的關
機)。等個幾秒鐘再重開機。這樣您的 PC card 應該就正常了。有時有些筆記型電腦雖然看起來已經關機了,但實際上並沒有。
如果您發現上面那個方法沒有用,請關機,移除電池,等個幾秒鐘,
把電池裝上去然後重開機。為什麼在 BIOS 畫面之後,FreeBSD 的 boot loader 顯示
Read error 然後就停止不動了?這是因為FreeBSD 的 boot loader 無法正確的找出硬碟的
geometry。這樣的話,就需要在用 fdisk 分割或是修改 FreeBSD
的 slice 時,手動將正確的值輸入進去了。正確的硬碟 geometry 值在 BIOS 裡面可以查的到。注意該硬碟的
cylinders,heads 以及 sectors 這些數值。在執行 &man.sysinstall.8;的 fdisk 時,按下 G
以便手動設定硬碟的 geometry。這時會有一個對話框跳出來,詢問您有關 cylinders,heads 以及
sectors 這些東西的值。請將剛剛在 BIOS 查到的數字,以 / 作分隔輸
入進去。舉例來說,如果是 5000 cylinders,250 sectors 和 60 sectors
就輸入 5000/250/60輸入完後請按 enter 鍵確認,最後按下 W 鍵把
新的分割區表寫入硬碟當中。另一個作業系統摧毀了我的 Boot Manager。我要怎麼樣才能把它還
原回來?執行 &man.sysinstall.8; 接著選 Configure,然後選 Fdisk。
再來用空白鍵選擇原先 Boot Manager 所在的硬碟。
按下 W 鍵來作寫入的動作。這時會跳出一個提示
訊息,詢問您要安裝哪一個 boot loader。請選擇 Boot Manager,
這樣就可以將它還原了。這個錯誤訊息:swap_pager: indefinite
wait buffer: 是什麼意思呢?這個訊息是說有一個執行程序正在嘗試將分頁記憶體(page memory)
寫入硬碟中,而這個動作嘗試了 20 秒鐘仍然無法成功。這個有可能是因為
硬碟有壞軌、電路或排線有問題、以及其他跟硬碟讀出寫入有關的硬體設備。
如果真的是硬碟壞軌的問題,您應該會在
/var/log/messages這個檔案中,或是在執行
dmesg這個指令後,看到有關磁碟錯誤的訊息。
如果沒有,那麼請檢查您的排線還有接頭連接是否良好。為何在 buildworld/installworld 時,會趴在
touch: not found 的錯誤訊息?這錯誤訊息並不是指 &man.touch.1; 程式不見了,事實上可能是該檔檔案時間被設為未來的時間。
若機器上的 CMOS-clock 時鐘設定為當地時間
(非格林威治時間,比如台灣時間為 GMT +08:00 ,也就是 CST 中原標準時間),
那麼請在開機時,先選 single user 模式進入,然後打
adjkerntz -i
來調整 kernel clock 與機器上的 CMOS-clock 來同步。VanillaShuvanilla@FreeBSD.org商業軟體這一節的內容還是相當少,不過我們當然希望各個公司能為它加點內容 :)
FreeBSD 組織和列在這裡的任何一家公司都沒有金錢上的利害關係,列出來純粹只是對大眾公開介紹(同時也認為在 FreeBSD
上的商機若興旺,會對 FreeBSD 可長可久有極正面的效益)。我們鼓勵商業軟體的廠商把他們的產品包括在下面的名單中,在
Vendors page 可以看到更長的列表。在哪邊找到給 FreeBSD 用的 Office 套件呢?OpenOffice 這套 open-source 性質的 office
可以在 FreeBSD 上正常運用自如,而 &linux; 版的
StarOffice,
這套 closed-source 的 OpenOffice 加值版,也可以在 FreeBSD 上正常使用。FreeBSD 上還有許多編排軟體、試算表(Spreadsheet)以及繪圖軟體都可用 Ports
Collection 來安裝喔。在哪邊可找到給 FreeBSD 用的 Motif?Open Group 釋出了 Motif 2.1.30 的原始碼,可以透過
open-motif package 安裝,或是由 ports 自行
編譯。相關的資訊,請參考 handbook 中的 ports 章節。
Open Motif 只能在同樣也是 open source
的作業系統或計劃中使用。另外,也是有商業版本的 Motif 存在。也許這種版本的 Motif
不是免費的,但是絕對允許用在 closed-source 的環境下。
Apps2go 提供了最便宜的 FreeBSD
(包括 i386 跟 alpha)版本的 ELF Motif 2.1.20 套件。
目前提供兩種不同環境的版本, 發展用版本 及
runtime 版本 。這兩種套件都包括:OSF/Motif manager, xmbind, panner, wsm.Development kit with uil, mrm, xm, xmcxx, include
and Imake files.Static and dynamic ELF libraries (for use with
FreeBSD 3.0 and above).Demonstration applets.因為 Apps2go 也有提供 NetBSD 和 OpenBSD
的版本,所以在訂購時請特別指定是要 FreeBSD 版本的 Motif!
他們目前只提供以 FTP 的方式取得這份套件。更多資訊
Apps2go WWW page或sales@apps2go.com 或
support@apps2go.com或phone (817) 431 8775 or +1 817 431-8775也可以聯絡 Xi Graphics,他們提供了一個
FreeBSD a.out 格式的 Motif 2.0 套件。在這套件中包括了:OSF/Motif manager, xmbind, panner, wsm.Development kit with uil, mrm, xm, xmcxx, include
and Imake files.Static and dynamic libraries (for use with FreeBSD
2.2.8 and earlier).Demonstration applets.Preformatted man pages.在你跟他們訂購 Motif 時,請一定註明你要的是 FreeBSD 的版本!
因為 Xi Graphics 也同時提供了 BSDI 跟 Linux
版本的 Motif。目前發行的版本是放在四塊磁片中,將來他們會將所有的
東西都放到光碟裡,就像他們所發行的 CDE 一樣。在哪邊可找到給 FreeBSD 用的 CDE?Xi Graphics 以前有賣 FreeBSD 用的
CDE,不過現已停止發售了。就許多方面而言,KDE 這個 open
source 的桌面環境與 CDE 相當類似。此外,你可能會喜歡使用 xfce。KDE 及 xfce 都可由 ports
機制來安裝。有沒有要錢,但是高效率的 X servers?有, Xi Graphics
有提供給 FreeBSD(或其他 Intel 平台上)用的 X 視窗加速產品。Xi Graphics 所提供的高效能 X Server 有非常簡單的設定方式,
並且支援了目前市面上當紅的各大廠牌的顯示卡。它只給你 Binary 檔案,
是用磁片的方式發行,FreeBSD 跟 Linux 版本都相同。Xi Graphics 同時
也提供了專門給筆記型電腦用的高效能 X Server。5.0 版有提供免費的相容 demo 版本Xi Graphics 也有在賣 FreeBSD 用的 Motif 跟 CDE(往上面看看)。
更多的資訊
Xi Graphics WWW page或sales@xig.com
或 support@xig.com或phone (800) 946 7433 or +1 303 298-7478.在 FreeBSD 上有任何的資料庫嗎?有! 請看 FreeBSD 網站上
商業軟體公司 這一部份。還有請參考 ports 中
Databases 相關的收集。可以在 FreeBSD 上執行 Oracle 嗎?可以,下面這個網頁會說明如何在 FreeBSD 上執行 Linux
版的 Oracle:
http://www.scc.nl/~marcel/howto-oracle.html
http://www.lf.net/lf/pi/oracle/install-linux-oracle-on-freebsdKang-minLiugugod@gugod.org一般應用程式嗯..我要在哪找到我要的程式呢?請看看 ports
目錄 吧。這邊有份已經 port 到 FreeBSD 的軟體列表。
目前有超過 &os.numports; 個軟體已經被port 到 FreeBSD 上,並且每天
都在增加中。所以有空就多看看這份列表,不然你也可以訂閱
freebsd-announce
- 這份 mailing list,會有人將每個星期最新的軟體列表貼在
- 上面。
+ 這份 mailing list,會有人將每個星期最新的軟體列表貼在上面。
- 大部份的 ports 應該都可以在 2.2,3.0 跟 4.0 的系統上使
- 用,並且還有部份的 ports 可以在 2.1.x 的系統上運作。每次
- 當 FreeBSD release 時,都會有一份 ports tree 被放在這一個
+ 大部份的 ports 應該都可以在 4.X、5.X 跟 6.X 的系統上使用。
+ 每次當 FreeBSD release 新版時,都會有一份 ports tree 被放在這一個
release cd 裡面的 ports/ 目錄裡。我們也支援一種叫 package 的概念,基本上
就是 gzip 壓縮、可用來發行的 binary 檔案,但是裡面藏了一
些相當有用的資訊,可以給各種自訂安裝來使用。使用者不必知
道某個 package 裡究竟有包括哪些檔案,就可`以很方便地重複將
它安裝/反安裝。
- 你可以執行 /stand/sysinstall 後,
+ 你可以執行 sysinstall(&os; 5.2 之前版本則是 /stand/sysinstall) 後,
在 post-configuration 選單下選擇 package 這個安裝選項;或
是對某個有興趣的 package 檔案執行 &man.pkg.add.1;
- 把它裝起來。Package 檔案通常以 .tgz
- 作為延伸檔名,手上有 FreeBSD CDROM 的人可以在
- packages/All 這個目錄下找到這類檔案。
+ 把它裝起來。Package 檔案通常以 .tgz 或 .tbz
+ 為副檔名,手上有 FreeBSD CDROM 的人可以在 packages/All 這個目錄下找到這類檔案。
對不同的 FreeBSD 版本,也可以從下列位址由網路上取得:
-
- 給 2.2.8-release/2.2.8-stable 用的
-
-
- ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-2.2.8/
-
-
+
+ 給 4.X-RELEASE/4-STABLE 用的
+
+
+ ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-stable/
+
+
- 給 3.2-release/3.2-stable 用的
-
+ 給 5.X-RELEASE/5-STABLE 用的
+
- ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-3-stable/
-
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-stable/">
+ ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-stable
-
- 給 4.X-RELEASE/4-STABLE 用的
+
+ 給 6.X-RELEASE/6-STABLE 用的
- ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-4-current/
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-6-stable/">
+ ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-6-stable
-
- 給 5.X-CURRENT 用的
+
+ 給 7-CURRENT 用的
- ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-5-current
+ url="ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-7-current/">
+ ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/i386/packages-7-current
-
+
或是離你最近的 mirror 站。要注意的是,因為新的 port 一直在增加中,所以並不是所有 port
都有相對應的 package。最好定時檢查ftp.FreeBSD.org
,看看有哪些 package 可以用。
+
+
+ 該怎麼設定 INN(Internet News) 來當 news server?
+
+
+
+ 以 package 或 port 方式來裝好 news/inn 之後,Dave
+ Barr's INN Page 是個非常好的 INN 入門處,你可以在那邊找到 INN 的 FAQ。
+
+
+
+
+
+ FreeBSD 有支援 &java; 嗎?
+
+
+
+ 有啊,請看
+ http://www.FreeBSD.org/java/
+
+
+
我可以在哪邊找到 libc.so.3.0?你可能在一台 2.1.x 的機器上,跑著給 2.2/3.x/4.0 的軟體。
請再往上面一個章節看,正確的取得給你機器用的 port/package。為何我得到了這個訊息 ?Error: can't find
libc.so.4.0?你不小心抓了給 4.X 及 5.X 系統用的 package,並且嘗試著
去裝在你的 2.X 或 3.X 的系統上面。請下載正確版本的 package。 ghostscript 在我的 386/486SX 上有點問題呢!你沒有浮點運算器,對吧?你必須在你的 kernel 中加入數學
運算模擬器,你可以跟著下面的步驟做,並在更改過你的 kernel 設定
檔後,重新編譯過一次。options GPL_MATH_EMULATE當你加入上一行的同時,你必須將
MATH_EMULATE 移除掉。為什麼當我執行 SCO/iBCS2 的程式時,它在
socksys 這個地方出了問題?
(FreeBSD 3.0 以及更早的版本才有此問題。)你必須先修改 /etc/sysconfig (或是
/etc/rc.conf, 請讀 &man.rc.conf.5;)
這檔案最後一個章節,將下面所講到的變數設成
YES:# Set to YES if you want ibcs2 (SCO) emulation
loaded at startup ibcs2=NO這會在開機時將 ibcs2 這一個 kernel 模組載入。你還要將你的 /compat/ibcs2/dev 改成下面這樣:lrwxr-xr-x 1 root wheel 9 Oct 15 22:20 X0R@ -> /dev/null
lrwxr-xr-x 1 root wheel 7 Oct 15 22:20 nfsd@ -> socksys
-rw-rw-r-- 1 root wheel 0 Oct 28 12:02 null
lrwxr-xr-x 1 root wheel 9 Oct 15 22:20 socksys@ -> /dev/null
crw-rw-rw- 1 root wheel 41, 1 Oct 15 22:14 spx你只需要將 socksys 轉向到 /dev/null
(請讀 &man.null.4;) 去騙過 open & close 的動作。在 -current
裡面的 ibcs2 相關程式碼將會處理其餘的部份,這種作法比以前的方式
乾淨太多了。假如你想要使用 spx 方面的
程式,在你的 kernel 設定檔裡面 加上SPX_HACK。
-
-
-
- 我要如何在我的機器上設定 INN (Internet News)?
-
-
-
- 在你使用 package 或者是 port 安裝完 inn 之後,Dave Barr's
- INN Page 是個非常好的開始,你可以在那邊找到INN 的 FAQ。
-
-
-
-
+
我該使用那個版本的 Microsoft FrontPage?Use the Port, Luke!在 ports tree 中已經有一個包含 FrontPage
的 Apache 版本了。
-
-
-
- FreeBSD 支援 Java 嗎?
-
-
-
- 有,請看
- http://www.FreeBSD.org/java.
-
-
-
+
為什麼我無法在 3.X-STABLE 機器上順利編好這個 port?如果你的 FreeBSD 版本相較 -CURRENT 或 -STABLE 之下是很古
早的話,或許你會需要一個升級 ports 的工具,在
http://www.FreeBSD.org/ports/。如果你以將其更新卻仍無用,
那麼一定是某人更動之後造成 -CURRENT 才能用,-STABLE 無法用的情況。
由於 ports 內所收集的軟體在 -CURRENT 或是 -STABLE 上都要能用,
所以請儘速送出關於此問題的蟲報告;請使用 &man.send-pr.1; 這個指
令來送蟲報告。那裡可以找得到 ld.so?有些 a.out 格式的應用程式會需要 a.out 格式的函式庫,
Netscape Navigator 就是一個例子。不過用 ELF 函式庫編起來
的 FreeBSD 預設並不會安裝舊的 a.out 函式庫,所以您可能會得
到類似找不到 /usr/libexec/ld.so 的抱怨訊
息。如果說您的系統有這安裝 a.out 函式庫的必要,這些函式庫
(compat22) 也能夠利用 &man.sysinstall.8; 來安裝。或者利用
FreeBSD 原始碼來安裝:&prompt.root; cd /usr/src/lib/compat/compat22&prompt.root; make install clean如果你希望每次 make world 時會自動更新
compat22 函式庫,那麼修改 /etc/make.conf,
加入 COMPAT22=YES。這些相容於古老版本的函式庫
已經沒什麼在更新了,所以一般說來是不需要這樣的。同時也請您看一下 3.1-RELEASE 和 3.2-RELEASE 的勘誤表(ERRATA)。我更新了系統原始碼,現在我要怎樣升級某個已經安裝上
的 ports ?FreeBSD 本身並沒有自動升級 ports 的工具,但有一些可以讓升級
簡化一些的小程式。你也可以自己裝上額外的工具來處理。&man.pkg.version.1; 指令可以自動產生用來達到自動升級到
ports tree 最新版本的 script。&prompt.root; pkg_version > /tmp/myscript一定要在手動修改一下產生出來的 script。
目前的 &man.pkg.version.1; 在 script 最前面加入 &man.exit.1; 強
迫你去修改它。你應將執行 script 所產生的輸出記錄下來,因為裡面會有記載某些
尚未升級但已經更新的 ports。不過你不一定要去升級它們。通常是因為
有某個共用的函式庫已經改變版本號了,才要去重編一次那些使用到該函
式庫的 ports。如果你的硬碟空間很夠,那麼可以用 portupgrade
這個工具來做全自動處裡。portupgrade 裡面也有
一些小程式來簡化 package 升級,它在
sysutils/portupgrade。
這個工具是用 Ruby 這個語言寫的,所以並不適合加入到 FreeBSD 的原
始碼中,不過並不會因此讓某些人不用它。如果你的系統一直都處於開機狀態,可利用 &man.periodic.8; 系統,
每個星期產生一張需要升級的清單。只要在
/etc/periodic.conf 加入
weekly_status_pkg_enable="YES" 就可以了。為什麼 /bin/sh這麼的小?為什麼 FreeBSD
不改用 bash 或者是其他比較強悍的 shell?因為 POSIX 說,該要有這麼樣的一個 shell 在才行。比較繁瑣的答案:許多人需要寫可以跨很多平台的 shell script 。
這也是為何 POSIX 將 shell 以及工具命稱都定義的非常詳細的緣故。
大部份的 script 都適用於 Bourne shell,又因為有幾個重要的
寫程式所用到的程式或者函式 (&man.make.1; , &man.system.3;,
&man.popen.3;, 還有在 Perl 或者 Tcl 裡面呼叫系統程式的地方)
都指定用 Bourne shell 。那麼因為 Bourne Shell 如此的廣泛常用,
那麼它的執行效率便很重要,快速是它決定性的要點之一,還要不佔太多
記憶體。目前的 /bin/sh 已是我們嘔心瀝血之作,它已
經盡量地符合標準規定。為了讓它非常小,我們拿掉了一些其他 shell
有的方便功能。這也是為什麼 ports 裡面還有很多強悍的 shell ,像是
bash, scsh, tcsh 以及 zsh 。 (你可以自己比較一下這些 shell 執行
時所佔的記憶體大小,去看看 ps -u 列出來的
VSZ 和 RSS 這兩個欄位就知道了。)
為什麼 Netscape 和 Opera 要花好久的時間才能啟動?通常是因為你的 DNS 沒有設定好。 Netscape 跟 Opera 在啟動的時候
都會去檢查一下 DNS。直到 DNS 有回應,或者是斷定網路目前是斷線之後,
它們才會顯示畫面出來。
-
+
+
+
+
+
+ Yi-Feng
+ Tzeng
+
+ yftzeng@iis.sinica.edu.tw
+
+
+
+
+ Ports and Packages 常見問題
+
+
+
+
+ 如何只抓取 tarball?
+
+
+
+ 如果只希望抓取 tarball 下來的話,僅需打下面指令即可:
+ &prompt.root; make fetch
+ 如果是要抓取單一的 port,以 editors/joe 為例的話,則:
+ &prompt.root; cd /usr/ports/editors/joe
+&prompt.root; make fetch
+ 那麼,預設會將 editors/joe 的 tarball 下載至 /usr/ports/distfiles 目錄下。
+
+ 如果是希望抓取安裝此 ports 所有相關相依 ports 的 tarball,以 systuils/portupgrade 為例的話,則:
+ &prompt.root; cd /usr/ports/systuils/portupgrade
+&prompt.root; make fetch-recursive
+ 預設會將此 port 與所有需要的其他 port 的 tarball,都下載至 /usr/ports/distfiles 目錄下。
+
+ 如果是希望抓取 ftp 分類下所有 ports 的 tarball ,則:
+ &prompt.root; cd /usr/ports/ftp
+&prompt.root; make fetch-recursive
+ 則會所將 ftp 分類下所有 ports 的 tarball 都下載至 /usr/ports/distfiles 目錄下。
+
+
+
+
+
+ 如何僅做到解開 tarball的步驟?
+
+
+
+ 有時候習慣自己 patch 原始碼的時候,會很常用到這個功能。以 editors/joe 為例的話,則:
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make extract
+
+ 那麼就會將 tarball解開至 /usr/ports/editors/joe/work 目錄下。
+
+
+
+
+
+ 如何僅做到解開 tarball 並補上官方提供的 patch ?
+
+
+
+ 此法與上面方式有一些類似,不同於是先補上官方提供的 patch ,再行 patch 自己的修正。有時候習慣自己 patch 原始碼的時候,會很常用到這個功能。
+ 以 editors/joe 為例的話,則:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make patch
+
+ 那麼就會將 tarball解開至 /usr/ports/editors/joe/work 目錄下
+ ,並補上官方提供的 patch。
+
+
+
+
+
+ 如何安裝一個新的 port?
+
+
+
+ 如果系統上未安裝此軟體,則可以選擇安裝一個新的 port。
+ 以 editors/joe 為例的話,則:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make install
+
+ 如此會在系統上安裝一個新的 joe 軟體。
+ 如果需要在安裝完成後,也一併清除編輯時期所留下來的暫存目錄,則可配合 make clean
+ 方法一起使用,如:
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make clean
+
+
+
+
+
+ 如何安裝一個新的 port,並打包(package)起來?
+
+
+
+ 將安裝完成的軟體打包起來,有許多便利性:包括在叢集系統中,可供其它機器使用,
+ 或將未來此軟體出問題可重新利用此 package 重新快速安裝。
+ 以 editors/joe 為例的話,則:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make package
+
+ 如此會在系統上安裝一個新的 joe 軟體,並將此軟體打包(package)起來。
+ package 預設會在 /usr/ports/editors/joe 目錄下,如果希望集中管理的話,建議做如下的步驟:
+
+ &prompt.root; mkdir -p /usr/ports/packages/All
+
+ 以後打包的 packages 都會存放在此目錄下,並且系統會自動做分類,以方便管理。
+ 如果需要在安裝完成後,一併清除編輯時期所留下來的暫存目錄,則可加上 make clean 一起使用,比如:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make package clean
+
+
+
+
+
+ 如何打包一個 port,並將其所有相依的 ports 也打包起來?
+
+
+
+ 因為上面剛說的 make package 方式只有打包單一套件,
+ 中間依賴的 ports 並沒有一起打包,這會出現一個常遇到的問題:
+ 就是如果一個 port 需要依賴其它的 ports,那麼必須將其它 ports 也一起打包,否則安裝 packages 會有相依的問題。
+ 以 sysutils/portupgrade 為例:
+
+ &prompt.root; cd /usr/ports/sysutils/portupgrade
+ &prompt.root; make DEPENDS_TARGET=package package
+
+ 如此一來,就會對所有 portupgrade 所相依賴的 ports 都一併打包,也包括自己本身。
+
+
+
+
+
+ 如何對一個已經安裝的 port 打包?
+
+
+
+ 如果安裝好一個套軟,事前並未打包,事後想打包的話,
+ 以 editors/joe 為例:
+
+ &prompt.root; cd /var/db/pkg
+ &prompt.root; pkg_create -b joe-{版本號}
+
+ 如此一來,就會將已安裝的 port 打包起來,放在 /var/db/pkg 目錄下。
+
+
+
+
+
+ 如何清理 ports 編輯期間所產生的暫存資料?
+
+
+
+ 在安裝 port 的時候,通常會有編譯期間所需要的工作目錄(work),因此通常安裝好一個套件後,會清除此暫存目錄,以節省硬碟空間。
+ 以 editors/joe 為例:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make clean
+
+ 而如果是希望清除所有 ports 的暫存目錄,則:
+ &prompt.root; cd /usr/ports
+ &prompt.root; make clean
+
+ 而如果是希望清除所有 ftp 分類的暫存目錄,則:
+ &prompt.root; cd /usr/ports/ftp
+ &prompt.root; make clean
+
+
+
+
+
+ 如何清理 ports 編輯期間所產生的暫存資料,以及 tarball 檔?
+
+
+
+ 上面所講的 make clean 僅只是清除編輯期間所需要的工作目錄(work),並沒有將編譯
+ ports 時一併下載的 tarball 刪除(相對應之 tarball 預設會存放在 /usr/ports/distfiles)
+ 如果打算把 tarball 也一併清除的話,以 editors/joe 為例:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make distclean
+
+ make distclean 的步驟包含了 make clean
+ 的功能,也就是說除了會刪除 tarball 外,還會一併清除編譯時的暫存 work 目錄。
+
+ 如果是希望清除所有 ports 的暫存 work 目錄及 tarball,則:
+ &prompt.root; cd /usr/ports
+ &prompt.root; make distclean
+
+ 而如果是希望清除所有 ftp 分類的暫存目錄以及 tarball,則:
+ &prompt.root; cd /usr/ports/ftp
+ &prompt.root; make distclean
+
+
+
+
+
+ 如何在安裝 ports 前查詢所依賴的相關套件?
+
+
+
+ 在安裝 ports 前,可以查詢所需依賴/相關的套件。
+ 以 mail/p5-Mail-SpamAssassin 為例:
+
+ &prompt.root; cd /usr/ports/mail/p5-Mail-SpamAssassin
+ &prompt.root; make all-depends-list
+ make all-depends-list 顯示此套件所有相依的套件。
+
+ &prompt.root; cd /usr/ports/mail/p5-Mail-SpamAssassin
+ &prompt.root; make pretty-print-build-depends-list
+ make all-depends-list 顯示此套件在編譯期間所需要的套件。
+
+ &prompt.root; cd /usr/ports/mail/p5-Mail-SpamAssassin
+ &prompt.root; make pretty-print-run-depends-list
+ make all-depends-list 顯示此套件要執行時所需要的套件。
+
+
+
+
+
+ 如何移除已安裝的 ports?
+
+
+
+ 以 editors/joe 為例:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make deinstall
+
+ 或是使用 pkg_delete:
+ &prompt.root; pkg_delete joe-{version}
+
+ 有時候套件之間的相依性會導致無法直接移除,如果要強制移除的話,則:
+ &prompt.root; pkg_delete -f joe-{version}
+ 但請注意:很有可能會導致其它相依到這軟體的套件執行起來出現問題。
+
+
+
+
+
+ 如何一併移除所相依的 ports?
+
+
+
+ 以 sysutils/portupgrade 為例:
+
+ &prompt.root; cd /usr/ports/sysutils/portupgrade
+ &prompt.root; make deinstall-depends
+
+ 執行此步驟前,請注意是否會移除其他套件也有共同相依的部分。建議先參考
+ 上面所講的 make-depends-list 的方法來檢查。
+ &prompt.root; pkg_delete joe-{version}
+
+ 或者建議用:pkg_delete,這樣若仍有相依該套件的話,會先警告而不會移除。
+ 除非有另外加了 -f 參數來強制移除...。
+ &prompt.root; pkg_delete -r joe-{version}
+
+
+
+
+
+ 如何重新安裝已安裝過的 ports?
+
+
+
+ 重新安裝的前提是:之前有安裝過或目前已安裝。以 editors/joe 為例:
+
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make deinstall clean install
+
+ 或是
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make reinstall
+
+ 或是
+ &prompt.root; portupgrade -f joe
+
+
+
+
+
+ 如何以關鍵字搜尋所要找的 ports?
+
+
+
+ 如果要從全部的 ports collection 中找尋與關鍵字 "ldap" 有關的 ports,則:
+
+ &prompt.root; cd /usr/ports
+ &prompt.root; make search key=ldap
+
+ 如果只要從與 ftp 相關的 ports 下找尋與關鍵字 "ldap" 有關的 ports,則:
+ &prompt.root; cd /usr/ports/ftp
+ &prompt.root; make search key=ldap
+
+ 另外,還有另一個用法,方法只是將 key 換成 name。如果已經知道要搜尋 ports 的名稱,或只想找名稱相關的關鍵字 "ldap", 則:
+ &prompt.root; cd /usr/ports
+ &prompt.root; make search name=ldap
+
+
+
+
+
+ 如何升級已安裝的 ports?
+
+
+
+ 如果已經安裝套件,事後欲升級的話,必須先移除舊版的 port。以 editors/joe 為例:
+
+ &prompt.root; portupgrade joe
+
+ 或是
+ &prompt.root; cd /usr/ports/editors/joe
+ &prompt.root; make clean reinstall
+
+ 或是
+ &prompt.root; portupgrade -f joe
+
+
+
+
+
+ 如何查詢目前系統安裝了哪些套件?
+
+
+
+ 查詢目前系統已安裝的全部套件:
+
+ &prompt.root; pkg_info
+
+
+
+
+
+ 如何查詢目前系統有沒有安裝這個關鍵字的套件?
+
+
+
+ 假設要找的關鍵字是 joe 的話:
+ &prompt.root; pkg_info | grep joe
+
+
+
+
+
+ 如何查詢某個檔案是屬於哪些套件?
+
+
+
+ 如果想查詢 /usr/local/bin/joe 是屬於哪個套件的話,則:
+ &prompt.root; pkg_info -W /usr/local/bin/joe
+ 如果沒有回傳任何資訊的話,代表著這個檔案是由 FreeBSD 內建的。
+
+
+
+
+
+ 如何查詢某個套件安裝了哪些檔案?
+
+
+
+ 如果想查詢目前系統所安裝的 joe 包含了哪些檔案,則:
+ &prompt.root; pkg_info -L /var/db/pkg/joe-{version}
+
+
+
+
+
+ 如何安裝舊版的 ports?
+
+
+
+ 有時候會因為相依性,或是新版有問題,而會想裝舊版本的套件。
+ 這裡介紹的方法是利用 CVS 的好處,回歸到以前舊版本存在的日子,以安裝舊版本的套件。
+
+ 首先,若我們要回復到某一個套件的版本時,需要去查詢 FreeBSD ports CVS repository。
+ 最常見的就是 Freshports 網站、 FreeBSD 的
+ Mailing FreeBSD cvs 或是 FreeBSD
+ ports cvsweb。
+
+ 查到該套件版本所依存的日子後,就修改 CVS tag。一般預設 ports 的 CVS tag 會寫在 /usr/share/examples/cvsup/ports-supfile
+ ,如要回溯到 2002/10/05 號的話,則:
+ &prompt.root; vi /usr/share/examples/cvsup/ports-supfile
+ default date=2002.10.05.00.00.00 #將 date 改成當日
+
+ 然後按照一般 CVSup 或 csup 的時候一樣,執行 CVSup 或 csup (make update),此時的
+ ports collections 就會回到當時的情形,那麼該套件的舊版也會出現在 ports collections 中,只要安裝即可。
+
+ 如果僅是想回溯某部份的 ports,則必須加上額外的資訊,如僅希望把 lang/perl5.8 回溯,
+ 而我們得知此屬於 lang 中的一支,則:
+ &prompt.root; vi /usr/share/examples/cvsup/ports-supfile
+ #ports-all #將 ports-all 標示起來
+ ports-lang #加入這行
+
+ 最後,執行 CVSup 或 csup ,並安裝即可。目前若希望單獨回溯單一的 port,則比較麻煩。
+
+
+
+
+
+
+
Kang-minLiugugod@gugod.orgkernel 設定我想自訂 kernel,這會很困難嗎?不會!請查閱
使用手冊中的 kernel 設定一節。我會建議你在你讓核心能正常工作後,做一個
kernel.YYMMDD 日期形式的備份,同時也備份
/module這個目錄至
/modules.YYMMDD。這樣下次如果你很不幸的玩
壞了設定,至少可以不需要使用最原始的
kernel.GENERIC。如你正從一個 GENERIC
kernel 裡面不支援的控制器裡啟動時,這就顯得特別重要。我的核心因為 _hw_float遺失而編譯失敗。
該怎麼修正呢?讓我猜看看,你把 npx0
(詳見 &man.npx.4;) 從你的 kernel 設定檔移除了,因為你沒有數學運算器,
對嗎?錯了!:-) 這個 npx0是
必須要有的。就算你沒有數學運算器,你還是
必須 引入 npx0 裝置。
為什麼造出來的 kernel 這麼大 (10MB 以上) ?這很有可能是因為,你把 kernel 編成 偵錯模式
了。偵錯模式之下的 kernel 裡面會存著偵錯用的許多符號,因此會大幅
增加 kernel 的大小。如果說你的 FreeBSD 是 3.0 以後的版本,這對於
效能來說影響並不大,幾乎是沒有。而在系統會因某些原因 panic 時,
有個偵錯模式的 kernel 在也挺有用的。不過呢,如果你的磁碟空間很小,或者你就是不想用偵錯模式的
kernel 的話,請確認以下事情:kernel 設定檔裡面沒有這一行:makeoptions DEBUGS=-g 執行 &man.config.8; 時沒有加上
這個選項。以上兩件事情都會讓你編出一個偵錯模式的 kernel。但只要避免之,
就可以編出一個正常的 kernel,而你也會注意到,kernel 明顯的變小了;
大部份的 kernel 都差不多在 1.5MB 到 2MB 之間。為何出現了 multi-port serial code 的中斷衝突?當我編譯一個 multi-port serial code 的核心時,它告訴我只有
第一個被偵測到,其他的則因中斷衝突而跳過了,我該怎麼修正它?這個問題是因為 FreeBSD 使用內建程式碼避免因為硬體或軟體衝突
導致 kernel 過於肥大或無用。要修正這種情形的方法是除了一個 port
外把其他所有的 IRQ 設定都做保留。這裡有一個範例:#
# Multiport high-speed serial line - 16550 UARTS
#
device sio2 at isa? port 0x2a0 tty irq 5 flags 0x501 vector siointr
device sio3 at isa? port 0x2a8 tty flags 0x501 vector siointr
device sio4 at isa? port 0x2b0 tty flags 0x501 vector siointr
device sio5 at isa? port 0x2b8 tty flags 0x501 vector siointr為什麼我一個 kernel 都編不起來?甚至 GENERIC 也不行?這有很多種可能的原因:你沒有用新的 make buildkernel 與
make installkernel 這兩個方法來編,而正好
你的系統原始碼的版本和正在執行的系統核心版本不一樣 (像是,
在跑 4.0-RELEASE 的系統上嘗試著編 4.3-RELEASE)。如果說你要升
級系統的話,請務必去看看 /usr/src/UPDATING
這個檔案,特別注意最後面的 COMMON ITEMS
這個小節。你已經用上 make buildkernel 以及
make installkernel 了,但是在
make buildworld 時失敗了。可惜的是,
make buildkernel 要成功,需要依賴
make buildworld 後造出來的一些檔案。
- 就算是你在編 FreeBSD-STABLE,
+ 就算是你在編 &os.stable;,
還是有可能你抓到了正在修改中,或著因為某些緣故而根本還沒改好
- 的原始碼;雖然說 FreeBSD-STABLE
+ 的原始碼;雖然說 &os.stable;
大部份的時候都是可以編的,但只有 RELEASE 才是保證可以編的。碰
到這個問題時,再次更新原始碼並且再試試看。也有可能是放原始碼的
伺服器出現某些問題,所以更新原始碼時也試試從不同伺服器來更新看
看。硬碟、檔案系統、Boot Loader如何在 FreeBSD 內把新硬碟掛上去用呢?請參閱
磁碟格式化教學。How do I move my system over to my huge new disk?理想的方式是先在新硬碟上重裝好作業系統,然後把使用者相關程式、資料搬過去就好。
This is highly
recommended if you have been tracking -STABLE for more
than one release, or have updated a release instead of
installing a new one. You can install booteasy on both
disks with &man.boot0cfg.8;, and dual boot them until
you are happy with the new configuration. Skip the
next paragraph to find out how to move the data after
doing this.Should you decide not to do a fresh install, you
need to partition and label the new disk with either
- /stand/sysinstall, or &man.fdisk.8;
+ sysinstall(&os; 5.2 之前版本則是 /stand/sysinstall), or &man.fdisk.8;
and &man.disklabel.8;. You should also install booteasy
on both disks with &man.boot0cfg.8;, so that you can
dual boot to the old or new system after the copying
is done. See the
formatting-media article for details on this
process.Now you have the new disk set up, and are ready
to move the data. Unfortunately, you cannot just blindly
copy the data. Things like device files (in
/dev), flags, and links tend to
screw that up. You need to use tools that understand
these things, which means &man.dump.8;.
Although it is suggested that you move the data in single user
mode, it is not required.You should never use anything but &man.dump.8; and
&man.restore.8; to move the root filesystem. The
&man.tar.1; command may work - then again, it may not.
You should also use &man.dump.8; and &man.restore.8;
if you are moving a single partition to another empty
partition. The sequence of steps to use dump to move
a partitions data to a new partition is:newfs the new partition.mount it on a temporary mount point.cd to that directory.dump the old partition, piping output to the
new one.For example, if you are going to move root to
/dev/ad1s1a, with
/mnt as the temporary mount point,
it is:&prompt.root; newfs /dev/ad1s1a
&prompt.root; mount /dev/ad1s1a /mnt
&prompt.root; cd /mnt
&prompt.root; dump 0af - / | restore xf -Rearranging your partitions with dump takes a bit more
work. To merge a partition like /var
into its parent, create the new partition large enough
for both, move the parent partition as described above,
then move the child partition into the empty directory
that the first move created:&prompt.root; newfs /dev/ad1s1a
&prompt.root; mount /dev/ad1s1a /mnt
&prompt.root; cd /mnt
&prompt.root; dump 0af - / | restore xf -
&prompt.root; cd var
&prompt.root; dump 0af - /var | restore xf -To split a directory from its parent, say putting
/var on its own partition when it was not
before, create both partitions, then mount the child partition
on the appropriate directory in the temporary mount point, then
move the old single partition:&prompt.root; newfs /dev/ad1s1a
&prompt.root; newfs /dev/ad1s1d
&prompt.root; mount /dev/ad1s1a /mnt
&prompt.root; mkdir /mnt/var
&prompt.root; mount /dev/ad1s1d /mnt/var
&prompt.root; cd /mnt
&prompt.root; dump 0af - / | restore xf -You might prefer &man.cpio.1;, &man.pax.1;,
&man.tar.1; to &man.dump.8; for user data. At the time of
this writing, these are known to lose file flag information,
so use them with caution.Will a dangerously dedicated disk endanger
my health?The installation procedure allows
you to chose two different methods in partitioning your
hard disk(s). The default way makes it compatible with other
operating systems on the same machine, by using fdisk table
entries (called slices in FreeBSD), with a
FreeBSD slice that employs partitions of its own. Optionally,
one can chose to install a boot-selector to switch between the
possible operating systems on the disk(s). The alternative uses
the entire disk for FreeBSD, and makes no attempt to be
compatible with other operating systems.So why it is called dangerous? A disk
in this mode does not contain what normal PC utilities
would consider a valid fdisk table. Depending on how well
they have been designed, they might complain at you once
they are getting in contact with such a disk, or even
worse, they might damage the BSD bootstrap without even
asking or notifying you. In addition, the
dangerously dedicated disk's layout is
known to confuse many BIOSes, including those from AWARD
(e.g. as found in HP Netserver and Micronics systems as
well as many others) and Symbios/NCR (for the popular
53C8xx range of SCSI controllers). This is not a complete
list, there are more. Symptoms of this confusion include
the read error message printed by
the FreeBSD bootstrap when it cannot find itself, as well
as system lockups when booting.Why have this mode at all then? It only saves a few kbytes
of disk space, and it can cause real problems for a new
installation. Dangerously dedicated mode's
origins lie in a desire to avoid one of the most common
problems plaguing new FreeBSD installers - matching the BIOS
geometry numbers for a disk to the disk
itself.Geometry is an outdated concept, but one
still at the heart of the PC's BIOS and its interaction with
disks. When the FreeBSD installer creates slices, it has to
record the location of these slices on the disk in a fashion
that corresponds with the way the BIOS expects to find them. If
it gets it wrong, you will not be able to boot.Dangerously dedicated mode tries to work
around this by making the problem simpler. In some cases, it
gets it right. But it is meant to be used as a last-ditch
alternative - there are better ways to solve the problem 99
times out of 100.So, how do you avoid the need for DD mode
when you are installing? Start by making a note of the geometry
that your BIOS claims to be using for your disks. You can
arrange to have the kernel print this as it boots by specifying
at the boot: prompt, or
using boot -v in the loader. Just before the
installer starts, the kernel will print a list of BIOS
geometries. Do not panic - wait for the installer to start and
then use scrollback to read the numbers. Typically the BIOS
disk units will be in the same order that FreeBSD lists your
disks, first IDE, then SCSI.When you are slicing up your disk, check that the disk
geometry displayed in the FDISK screen is correct (ie. it
matches the BIOS numbers); if it is wrong, use the
g key to fix it. You may have to do this if
there is absolutely nothing on the disk, or if the disk has been
moved from another system. Note that this is only an issue with
the disk that you are going to boot from; FreeBSD will sort
itself out just fine with any other disks you may have.Once you have got the BIOS and FreeBSD agreeing about the
geometry of the disk, your problems are almost guaranteed to be
over, and with no need for DD mode at all. If,
however, you are still greeted with the dreaded read
error message when you try to boot, it is time to cross
your fingers and go for it - there is nothing left to
lose.To return a dangerously dedicated disk
for normal PC use, there are basically two options. The first
is, you write enough NULL bytes over the MBR to make any
subsequent installation believe this to be a blank disk. You
can do this for example with&prompt.root; dd if=/dev/zero of=/dev/rda0 count=15Alternatively, the undocumented DOS
featureC:\>fdisk /mbrwill to install a new master boot record as well, thus
clobbering the BSD bootstrap.Which partitions can safely use Soft Updates? I have
heard that Soft Updates on / can cause
problems.Short answer: you can usually use Soft Updates safely
on all partitions.Long answer: There used to be some concern over using
Soft Updates on the root partition. Soft Updates has two
characteristics that caused this. First, a Soft Updates
partition has a small chance of losing data during a
system crash. (The partition will not be corrupted; the
data will simply be lost.) Also, Soft Updates can cause
temporary space shortages.When using Soft Updates, the kernel can take up to
thirty seconds to actually write changes to the physical
disk. If you delete a large file, the file still resides
on disk until the kernel actually performs the deletion.
This can cause a very simple race condition. Suppose you
delete one large file and immediately create another large
file. The first large file is not yet actually removed
from the physical disk, so the disk might not have enough
room for the second large file. You get an error that the
partition does not have enough space, although you know
perfectly well that you just released a large chunk of
space! When you try again mere seconds later, the file
creation works as you expect. This has left more than one
user scratching his head and doubting his sanity, the
FreeBSD filesystem, or both.If a system should crash after the kernel accepts a
chunk of data for writing to disk, but before that data is
actually written out, data could be lost or corrupted.
This risk is extremely small, but generally manageable.
Use of IDE write caching greatly increases this risk; it
is strongly recommended that you disable IDE write caching
when using Soft Updates.These issues affect all partitions using Soft Updates.
So, what does this mean for the root partition?Vital information on the root partition changes very
rarely. Files such as /kernel and
the contents of /etc only change
during system maintenance, or when users change their
passwords. If the system crashed during the
thirty-second window after such a change is made, it is
possible that data could be lost. This risk is negligible
for most applications, but you should be aware that it
exists. If your system cannot tolerate this much risk,
do not use Soft Updates on the root filesystem!/ is traditionally one of the
smallest partitions. By default, FreeBSD puts the
/tmp directory on
/. If you have a busy
/tmp, you might see intermittent
space problems. Symlinking /tmp to
/var/tmp will solve this
problem.What is inappropriate about my ccd?The symptom of this is:&prompt.root; ccdconfig -C
ccdconfig: ioctl (CCDIOCSET): /dev/ccd0c: Inappropriate file type or formatThis usually happens when you are trying to concatenate
the c partitions, which default to type
unused. The ccd driver requires the
underlying partition type to be FS_BSDFFS. Edit the disklabel
of the disks you are trying to concatenate and change the types
of partitions to 4.2BSD.Why can I not edit the disklabel on my ccd?The symptom of this is:&prompt.root; disklabel ccd0
(it prints something sensible here, so let us try to edit it)
&prompt.root; disklabel -e ccd0
(edit, save, quit)
disklabel: ioctl DIOCWDINFO: No disk label on disk;
use "disklabel -r" to install initial labelThis is because the disklabel returned by ccd is actually
a fake one that is not really on the disk.
You can solve this problem by writing it back explicitly,
as in:&prompt.root; disklabel ccd0 > /tmp/disklabel.tmp
&prompt.root; disklabel -Rr ccd0 /tmp/disklabel.tmp
&prompt.root; disklabel -e ccd0
(this will work now)Can I mount other foreign filesystems under FreeBSD?FreeBSD supports a variety of other
filesystems.Digital UNIXUFS CDROMs can be mounted directly on FreeBSD.
Mounting disk partitions from Digital UNIX and other
systems that support UFS may be more complex, depending
on the details of the disk partitioning for the operating
system in question.&linux;FreeBSD supports ext2fs
partitions. See &man.mount.ext2fs.8; for more
information.&windowsnt;FreeBSD includes a read-only NTFS driver. For
more information, see &man.mount.ntfs.8;.
FATFreeBSD includes a read-write FAT driver. For
more information, see &man.mount.msdosfs.8;.FreeBSD also supports network filesystems such as NFS
(see &man.mount.nfs.8;), NetWare (see &man.mount.nwfs.8;),
and Microsoft-style SMB filesystems (see
&man.mount.smbfs.8;).
How do I mount a secondary DOS partition?The secondary DOS partitions are found after ALL the
primary partitions. For example, if you have an
E partition as the second DOS partition on
the second SCSI drive, you need to create the special files
for slice 5 in /dev,
then mount /dev/da1s5:&prompt.root; cd /dev
&prompt.root; sh MAKEDEV da1s5
&prompt.root; mount -t msdos /dev/da1s5 /dos/eYou can omit this step if you are running FreeBSD
5.0-RELEASE or newer with &man.devfs.5;
enabled.
- Is there a cryptographic filesystem for &os;?
+ &os; 有檔案加密系統嗎?
- Yes. If you are running FreeBSD 5.0 or later, see
- &man.gbde.8;. For earlier releases, see the security/cfs port.
+ 有啊! FreeBSD 5.0 起內建 &man.gbde.8;,而 FreeBSD 6.0
+ 又加上 &man.geli.8;。 而較早期的版本,請多利用 security/cfs port,謝謝。How can I use the &windowsnt; loader to boot FreeBSD?The general idea is that you copy the first sector of your
native root FreeBSD partition into a file in the DOS/&windowsnt;
partition. Assuming you name that file something like
c:\bootsect.bsd (inspired by
c:\bootsect.dos), you can then edit the
c:\boot.ini file to come up with something
like this:[boot loader]
timeout=30
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Windows NT"
C:\BOOTSECT.BSD="FreeBSD"
C:\="DOS"If FreeBSD is installed on the same disk as the &windowsnt; boot
partition simply copy /boot/boot1 to
C:\BOOTSECT.BSD. However, if FreeBSD is
installed on a different disk /boot/boot1
will not work, /boot/boot0 is needed./boot/boot0 needs to be installed
- using sysinstall by selecting the FreeBSD boot manager on
+ using sysinstall(&os; 5.2 之前版本則是 /stand/sysinstall) by selecting the FreeBSD boot manager on
the screen which asks if you wish to use a boot
manager. This is because /boot/boot0
has the partition table area filled with NULL characters
but sysinstall copies the partition table before copying
/boot/boot0 to the MBR.Do not simply copy /boot/boot0
instead of /boot/boot1; you will
overwrite your partition table and render your computer
un-bootable!When the FreeBSD boot manager runs it records the last
OS booted by setting the active flag on the partition table
entry for that OS and then writes the whole 512-bytes of itself
back to the MBR so if you just copy
/boot/boot0 to
C:\BOOTSECT.BSD then it writes an empty
partition table, with the active flag set on one entry, to the
MBR.How do I boot FreeBSD and &linux; from LILO?If you have FreeBSD and &linux; on the same disk, just follow
LILO's installation instructions for booting a non-&linux;
operating system. Very briefly, these are:Boot &linux;, and add the following lines to
/etc/lilo.conf:other=/dev/hda2
table=/dev/hda
label=FreeBSD(the above assumes that your FreeBSD slice is known to
&linux; as /dev/hda2; tailor to
suit your setup). Then, run lilo as
root and you should be done.If FreeBSD resides on another disk, you need to add
loader=/boot/chain.b to the LILO entry.
For example:other=/dev/dab4
table=/dev/dab
loader=/boot/chain.b
label=FreeBSDIn some cases you may need to specify the BIOS drive number
to the FreeBSD boot loader to successfully boot off the second
disk. For example, if your FreeBSD SCSI disk is probed by BIOS
as BIOS disk 1, at the FreeBSD boot loader prompt you need to
specify:Boot: 1:da(0,a)/kernel
- On FreeBSD 2.2.5 and later, you can configure
+ You can configure
&man.boot.8;
to automatically do this for you at boot time.The
&linux;+FreeBSD mini-HOWTO is a good reference for
FreeBSD and &linux; interoperability issues.How do I boot FreeBSD and &linux; using BootEasy?Install LILO at the start of your &linux; boot partition
instead of in the Master Boot Record. You can then boot LILO
from BootEasy.If you are running &windows; 95 and &linux; this is recommended
anyway, to make it simpler to get &linux; booting again if you
should need to reinstall &windows; 95 (which is a Jealous
Operating System, and will bear no other Operating Systems in
the Master Boot Record).How do I change the boot prompt from ??? to
something more meaningful?You can not do that with the standard boot manager without
rewriting it. There are a number of other boot managers
in the sysutils ports category that
provide this functionality.I have a new removable drive, how do I use it?Whether it is a removable drive like a &iomegazip; or an EZ drive
(or even a floppy, if you want to use it that way), or a new
hard disk, once it is installed and recognized by the system,
and you have your cartridge/floppy/whatever slotted in, things
are pretty much the same for all devices.(this section is based on
Mark Mayo's ZIP FAQ)If it is a ZIP drive or a floppy, you have already got a DOS
filesystem on it, you can use a command like this:&prompt.root; mount -t msdos /dev/fd0c /floppyif it is a floppy, or this:&prompt.root; mount -t msdos /dev/da2s4 /zipfor a ZIP disk with the factory configuration.For other disks, see how they are laid out using
&man.fdisk.8; or
&man.sysinstall.8;.The rest of the examples will be for a ZIP drive on da2,
the third SCSI disk.Unless it is a floppy, or a removable you plan on sharing
with other people, it is probably a better idea to stick a BSD
filesystem on it. You will get long filename support, at least a
2X improvement in performance, and a lot more stability. First,
you need to redo the DOS-level partitions/filesystems. You can
either use &man.fdisk.8; or
- /stand/sysinstall, or for a small drive
+ sysinstall(&os; 5.2 之前版本則是 /stand/sysinstall), or for a small drive
that you do not want to bother with multiple operating system
support on, just blow away the whole FAT partition table
(slices) and just use the BSD partitioning:&prompt.root; dd if=/dev/zero of=/dev/rda2 count=2
&prompt.root; disklabel -Brw da2 autoYou can use disklabel or
- /stand/sysinstall to create multiple BSD
+ sysinstall to create multiple BSD
partitions. You will certainly want to do this if you are adding
swap space on a fixed disk, but it is probably irrelevant on a
removable drive like a ZIP.Finally, create a new filesystem, this one is on our ZIP
drive using the whole disk:&prompt.root; newfs /dev/rda2cand mount it:&prompt.root; mount /dev/da2c /zipand it is probably a good idea to add a line like this
to /etc/fstab (see &man.fstab.5;) so
you can just type mount /zip in the
future:/dev/da2c /zip ffs rw,noauto 0 0Why do I get Incorrect super block when
mounting a CDROM?You have to tell &man.mount.8; the type of the device
that you want to mount. This is described in the Handbook section on
optical media, specifically the section Using Data
CDs.Why do I get Device not
configured when mounting a CDROM?This generally means that there is no CDROM in the
CDROM drive, or the drive is not visible on the
bus. Please see the Using Data
CDs section of the Handbook for a detailed
discussion of this issue.Why do all non-English characters in filenames show up as
? on my CDs when mounted in FreeBSD?Your CDROM probably uses the Joliet
extension for storing information about files and
directories. This is discussed in the Handbook chapter on
creating and
using CDROMs, specifically the section on Using Data
CDROMs.I burned a CD under FreeBSD and now I can not read it
under any other operating system. Why?You most likely burned a raw file to your CD, rather
than creating an ISO 9660 filesystem. Take a look at the
Handbook
chapter on creating CDROMs, particularly the
section on burning raw
data CDs.How can I create an image of a data CD?This is discussed in the Handbook section on duplicating
data CDs. For more on working with CDROMs, see the
Creating CDs
Section in the Storage chapter in the
Handbook.Why can I not mount an audio
CD?If you try to mount an audio CD, you will get an error
like cd9660: /dev/acd0c: Invalid
argument. This is because
mount only works on filesystems. Audio
CDs do not have filesystems; they just have data. You
need a program that reads audio CDs, such as the
audio/xmcd port.How do I mount a multi-session CD?By default, &man.mount.8; will attempt to mount the
last data track (session) of a CD. If you would like to
load an earlier session, you must use the
command line argument. Please see
&man.mount.cd9660.8; for specific examples.How do I let ordinary users mount floppies, CDROMs and
other removable media?Ordinary users can be permitted to mount devices. Here is
how:As root set the sysctl variable
vfs.usermount to
1.&prompt.root; sysctl -w vfs.usermount=1As root assign the appropriate
permissions to the block device associated with the
removable media.For example, to allow users to mount the first floppy
drive, use:&prompt.root; chmod 666 /dev/fd0To allow users in the group
operator to mount the CDROM drive,
use:&prompt.root; chgrp operator /dev/acd0c
&prompt.root; chmod 640 /dev/acd0cIf you are running &os; 5.X or later, you will need to alter
/etc/devfs.conf to make these changes
permanent across reboots.As root, add the necessary lines to
/etc/devfs.conf. For example, to allow
users to mount the first floppy drive add:# Allow all users to mount the floppy disk.
own /dev/fd0 root:operator
perm /dev/fd0 0666To allow users in the group operator
to mount the CD-ROM drive add:# Allow members of the group operator to mount CD-ROMs.
own /dev/acd0 root:operator
perm /dev/acd0 0660Finally, add the line
vfs.usermount=1
to the file /etc/sysctl.conf so
that it is reset at system boot time.All users can now mount the floppy
/dev/fd0 onto a directory that they
own:&prompt.user; mkdir ~/my-mount-point
&prompt.user; mount -t msdos /dev/fd0 ~/my-mount-pointUsers in group operator can now
mount the CDROM /dev/acd0c onto a
directory that they own:&prompt.user; mkdir ~/my-mount-point
&prompt.user; mount -t cd9660 /dev/acd0c ~/my-mount-pointUnmounting the device is simple:&prompt.user; umount ~/my-mount-pointEnabling vfs.usermount, however,
has negative security implications. A better way to
access &ms-dos; formatted media is to use the
emulators/mtools
package in the ports collection.The device name used in the previous examples must be
changed according to your configuration.The du and df
commands show different amounts of disk space available.
What is going on?You need to understand what du and
df really do. du
goes through the directory tree, measures how large each
file is, and presents the totals. df
just asks the filesystem how much space it has left. They
seem to be the same thing, but a file without a directory
entry will affect df but not
du.When a program is using a file, and you delete the
file, the file is not really removed from the filesystem
until the program stops using it. The file is immediately
deleted from the directory listing, however. You can see
this easily enough with a program such as
more. Assume you have a file large
enough that its presence affects the output of
du and df. (Since
disks can be so large today, this might be a
very large file!) If you delete this
file while using more on it,
more does not immediately choke and
complain that it cannot view the file. The entry is
simply removed from the directory so no other program or
user can access it. du shows that it
is gone — it has walked the directory tree and the file
is not listed. df shows that it is
still there, as the filesystem knows that
more is still using that space. Once
you end the more session,
du and df will
agree.Note that Soft Updates can delay the freeing of disk
space; you might need to wait up to 30 seconds for the
change to be visible!This situation is common on web servers. Many people
set up a FreeBSD web server and forget to rotate the log
files. The access log fills up /var.
The new administrator deletes the file, but the system
still complains that the partition is full. Stopping and
restarting the web server program would free the file,
allowing the system to release the disk space. To prevent
this from happening, set up &man.newsyslog.8;.How can I add more swap space?In the Configuration and
Tuning section of the Handbook, you will find a
section
describing how to do this.Why does &os; see my disk as smaller than the
manufacturer says it is?Disk manufacturers calculate gigabytes as a billion bytes
each, whereas &os; calculates them as 1,073,741,824 bytes
each. This explains why, for example, &os;'s boot messages
will report a disk that supposedly has 80GB as holding
76319MB.Also note that &os; will (by default)
reserve 8% of the disk
space.How is it possible for a partition to be more than 100%
full?A portion of each UFS partition (8%, by default) is
reserved for use by the operating system and the
root user.
&man.df.1; does not count that space when
calculating the Capacity column, so it can
exceed 100%. Also, you will notice that the
Blocks column is always greater than the
sum of the Used and
Avail columns, usually by a factor of
8%.For more details, look up the option
in &man.tunefs.8;.Wei-HonChenplasmaball@pchome.com.tw系統管理系統起始設定檔在哪?從 2.0.5R 到 2.2.1R,主要的設定檔是
/etc/sysconfig。所有的選項都被指定在這個檔,
而其他像 /etc/rc (參見 &man.rc.8;)
和 /etc/netstart 只是引用它。觀察 /etc/sysconfig 這個檔並修正其值以
適合你的系統。這個檔用註解填滿以表示何處該放置什麼設定。在 post-2.2.1 以後及 3.0,/etc/sysconfig
亦更名為一個更容易描述的檔名叫 &man.rc.conf.5; ,並且語法簡化了些。
/etc/netstart 亦更名為
/etc/rc.network 因此所有的檔案都可以用
cp /usr/src/etc/rc* /etc 來拷貝。在 3.1 以及,/etc/rc.conf 被移到
/etc/defaults/rc.conf。
千萬不要編輯這個檔! 如果
/etc/defaults/rc.conf 內有想要更動的項目,
你應該將那一行的內容拷貝到 /etc/rc.conf,
然後再修改它。例如 FreeBSD 3.1 及以後的版本內,有一個 DNS 伺服器 named,
而你想要啟動它。你所需要作的事就是:&prompt.root; echo named_enable="YES" >> /etc/rc.conf想要在 FreeBSD 3.1 及以後的版本中,啟動本地端服務的話,將
shell script 置於 /usr/local/etc/rc.d 目錄
下。這些 shell script 應該設定成可執行,並且檔名以 .sh 結束。
在 FreeBSD 3.0 及更早的版本中,你應該直接編輯
/etc/rc.local 檔。/etc/rc.serial用來初始化序列埠
(像是鎖定埠的特性等)。/etc/rc.i386 是 Intel 專用設定,
像是 iBCS2 模擬或是 PC 系統主控台設定。
- 我該如何簡單地加入使用者?
+ 該如何簡單地新增帳號?使用 &man.adduser.8; 指令。如果需要更複雜的使用方式,
請用 &man.pw.8; 這個指令。要再次移除使用者,使用 &man.rmuser.8; 指令。還有,
&man.pw.8; 也可以使用。
- 在我編輯 crontab 檔案之後,為什麼我老是收到這樣的訊息:
+ 在改完 crontab 檔案後,為什麼老是收到這樣的訊息:
root: not found?通常都是因為編輯了系統的 crontab
(/etc/crontab) 然後就用 &man.crontab.1;
去安裝它:&prompt.root; crontab /etc/crontab這樣作是不對的。系統的 crontab 和 &man.crontab.1;
所更新的使用者的 crontab 格式並不一樣 (&man.crontab.5;
說明文件針對差異處有詳細的說明)。如果你已經用這種方法,額外多出的 crontab 只就是
/etc/crontab 的拷貝,只是格式是錯誤的。
可用以下的命令刪除:&prompt.root; crontab -r下次你編輯 /etc/crontab 檔案的時候,
你不用作任何動作去通知 &man.cron.8; ,它自動會去偵測是否有更動。
如果你想要每天、每週、或是每月固定執行某些動作一次,也許加個
shell script 在 /usr/local/etc/periodic
目錄下會更好,系統的 cron 會固定執行 &man.periodic.8; 命令,
它可將你的程式和其它的系統週期性工作一起執行。這個錯誤的真正原因,是因為系統的 crontab 有一個額外的欄位,
說明該命令要以什麼使用者身份執行。在 FreeBSD 的預設系統 crontab
中,所有的項目都是 root。 當這個 crontab
被當作是 root 的使用者 crontab (它和系統的
crontab 是 不 一樣的),&man.cron.8; 會以為
root 字串是欲執行的命令的第一個字,但是實際上
並沒有這樣的命令存在。為什麼我想要用 su 成為 root 時,會得到
you are not in the correct group to su root
的錯誤訊息?這是一個安全特性。想要利用 su 成為 root
(或其它有 superuser 權限的帳號),你一定要在
wheel 群組內。如果沒有這個特性的話,
任何人只要在系統裡有帳號,並且恰巧知道 root
的密碼,就可以取得 superuser 等級的權限以存取系統。有了這個特性,
這樣的情況就不會發生;如果使用者不在 wheel
群組內的話,&man.su.1; 會讓他們連試著鍵入密碼的機會都沒有。要讓某人可以利用 su 成為 root 的話,
只要把他們放入 wheel 群組內即可。我在 rc.conf 還是某個起動檔案裡犯了錯誤,
因為檔案系統變成唯讀的,我無法去編輯它。我該怎麼辦?當電腦問你 shell 完整路徑名時,只要按 ENTER
,然後執行 mount / 以讀寫模式
重新掛載根檔案系統。你也許需要執行 mount -a -t ufs
,將你慣用的文字編輯器所在的檔案系統掛載上來。如果
你慣用的文字編輯器在網路檔案系統上的話,你必須先手動將網路設定
起來,以便將網路檔案系統掛載上來,或是使用本地端檔案系統上的
編輯器,例如 &man.ed.1;。如果你想要使用像 &man.vi.1; 或是 &man.emacs.1; 等的全螢幕
文字編輯器的話,你也需要執行
export TERM=cons25 ,以便讓這些編輯器能夠從
&man.termcap.5; 資料庫裡讀取正確的資料。當你已經完成了這些步驟後,你可以照你平常修改文法錯誤的方式
去編輯 /etc/rc.conf 檔案。在核心 (kernel)
啟動時所顯示的錯誤訊息,能夠告訴你檔案中哪一行有錯誤。為什麼我沒辦法設定我的印表機?請參考一下 Handbook 中,有關列印的部份。它應該能夠解決
你大部份的問題。請參考
Handbook 中的列印部份。有些印表機需要主機支援的驅動程式 (host-based driver) 才能
執行任何列印功能。FreeBSD 本身並不支援這些所謂的
WinPrinters。 如果你的印表機無法在 DOS 或
Windows NT 4.0 下執行,那它大概就是一台 WinPrinter。你唯一能使用
這樣的印表機的希望,就是試試
print/pnm2ppa 支不支援它了。我要怎麼樣修正我的系統所使用的鍵盤對映 (keyboard mapping)?
請參考 Handbook 中的 using localization
章節,尤其是 console
setup 章節。為什麼我在系統啟動時,得到 unknown: <PNP0303>
can't assign resources 的訊息?
- 以下是從 freebsd-current 通信論壇的一篇文章中節錄出來的。
+ 以下是從 &os.current; 通信論壇的一篇文章中節錄出來的。
Network cards based on the DEC PCI chipsetVendorModelASUSPCI-L101-TBAcctonENI1203CogentEM960PCICompexENET32-PCID-LinkDE-530DaynaDP1203, DP2100DECDE435, DE450DanpexEN-9400P3JCISCondor JC1260LinksysEtherPCIMylexLNP101SMCEtherPower 10/100 (Model 9332)SMCEtherPower (Model 8432)TopWareTE-3500PZnyx (2.2.x)ZX312, ZX314, ZX342, ZX345, ZX346, ZX348Znyx (3.x)ZX345Q, ZX346Q, ZX348Q, ZX412Q, ZX414, ZX442, ZX444,
ZX474, ZX478, ZX212, ZX214 (10mbps/hd)
為什麼要用 FQDN 才能連到其他機器?你也許會發現要連的機器其實是在另一個網域。舉個例子,假設你是在
foo.bar.edu 這個網域中,想要連到在一台叫 mumble
的主機,他在 example.org 網域下,
你必須用 Fully-Qualified Domain Name mumble.example.org,而不是只用
mumble。傳統的 BSD BIND resolver 允許用這種方式解出機器的位址,但是
FreeBSD 內附 bind (see &man.named.8;)
版本內定方式,則是除了你所在的網域以外,不支援其他非 FQDN 的縮寫。
所以如 mumble 必須在 mumble.foo.example.org,否則就會從網域的最底
層開始找。這和先前的做法不同,也就是不用
mumble.example.org,和
mumble.edu 繼續搜尋。
看一下 RFC 1535,裡面有提到為什麼之前的做法不好,甚至算是個安全
漏洞。這裡有個不錯的解法, 你可以加入一行search foo.example.org example.orginstead of the previousdomain foo.example.org在你的 /etc/resolv.conf 檔案中 (請參考
&man.resolv.conf.5;)。但是要確定搜尋順序不會違反 RFC 1535 所謂的
boundary between local and public administration。
為什麼我在連線時一直出現
Permission denied 的錯誤訊息? 如果在編譯 kernel 時加入 IPFIREWALL 選項,
請注意 2.1.7R 內定是拒絕所有未經核准的網路封包(但在開發
2.1-STABLE 時改掉了)。I如果不小心弄錯了 firewall 的設定,你可以以
root 執行以下命令網路功能就會恢復正常:&prompt.root; ipfw add 65534 allow all from any to any也可以在 /etc/rc.conf 加入
firewall_type="open" 的選項。如果想知道如何設定 FreeBSD firewall,請參考 手冊中相關章節。IPFW 會造成多大的網路延遲?請參考手冊中 Firewalls 章節,特別是
IPFW
Overhead & Optimization 這一段。為什麼我的 ipfwfwd
redirect 規則將服務轉向其他機器時無法正常運作?可能是你除了轉送封包以外還額外想進行位址轉譯
(network address translation, NAT),fwd 規則所進
行的動作就如同字面所示;僅轉送封包,它並不會去修改封包中的資料。
假設我們有如下的規則:01000 fwd 10.0.0.1 from any to foo 21當一個通往特定目標位址 foo 的封包
送達主機時,根據這條規則,封包將被轉送至
10.0.0.1,但是它的目標位址卻仍然是
foo!封包的目標位址並
沒有 更改為
10.0.0.1。大部分的主機會將封包丟棄,
因為他們並不是這個目標位址。因此,使用 fwd 規則
時往往不如使用者所預期的那般順利。這種行為是系統特性,而非錯誤。
參考 關於服務轉向的常見問
答集, &man.natd.8; 手冊,或者是使用 ports collection 中許
多服務轉向的工具來正確的完成你想進行的工作。要如何把對某台機器的網路服務要求(service request)轉向到另一台?
在 ports 目錄的sysutils分類中有個叫
socket 的套件,可以幫你轉向 FTP 或其他類似的
網路服務。只要把該網路服務的命令改成呼叫 socket 即可,如下所示:
ftp stream tcp nowait nobody /usr/local/bin/socket socket ftp.example.comftp其中 ftp.example.com 與
ftp 分別是被轉到的機器和 port 名稱。
那裡可以找到管理頻寬的工具?FreeBSD 上有三套頻寬管理工具: &man.dummynet.4; 已經整合進入
FreeBSD 系統(更詳細的用途, &man.ipfw.4;); ALTQ
可以免費使用,Emerging Technologies
推出的 Bandwidth Manager 則是商用軟體。怎麼會跑出
/dev/bpf0: device not configured這個訊息?
你執行了一個需要柏克萊封包過濾器 (Berkeley Packet Filter) 的
程式 (&man.bpf.4;),但是你在 kernel 中沒有啟動它。把下面這一行加
入 kernel 設定檔中,編譯一個新的 kernel:pseudo-device bpf # Berkeley Packet Filter在重新開機之後,還要做出 device node,在
/dev 下執行:&prompt.root; sh MAKEDEV bpf0如果想要更進一步知道如何做出各種 device node,請參閱 Handbook 關於週邊節點的說明
。我要怎樣才能將 Windows 機器中的磁碟掛入系統, 就像 Linux 提供
的 smbmount 那樣?使用 SMBFS 工具組。這套工具組中
包含了一系列的 kernel 修改還有使用者的工具程式(userland programs)。
這些程式和資訊在 ports 收藏中
net/smbfs 下可以找到。在
4.5-RELEASE 之後的版本則是系統中內建。我在系統日誌中發現以下訊息:
icmp-response bandwidth limit 300/200 pps,這是
蝦米碗糕?這是系統核心告訴你有某些活動引發它送出比它所認為應該送出更
多的 ICMP 或 TCP 重置訊息 (RST)。ICMP 回應訊息常常是因為有人嘗
試連接未被使用的 UDP 通訊埠。TCP 重置訊息則是有人嘗試連接未開
放 TCP 通訊埠造成的結果。以下這些活動可能就是造成這些訊息的原因:
暴力法的服務組絕攻擊(DoS)方式
(相較於針對特殊弱點使用單一封包的攻擊方式)。大量的通訊埠掃描(相較於僅嘗試少數的常見服務通訊埠)。出現的數字中第一個代表根據這些流量 kernel 應該送出的封包數,
第二個數字則是 kernel 目前限制最大發送數。你可以利用 sysctl 修改
net.inet.icmp.icmplim 變數值來更改最大值。舉
例來說,如果希望修改限制為 300 packets per
second:&prompt.root; sysctl -w net.inet.icmp.icmplim=300如果你不想在系統紀錄中看到這些訊息,但是仍然希望保持回應的限
制的話,你可以利用 sysctl 修改
net.inet.icmp.icmplim_output 變數來取消這些訊
息:&prompt.root; sysctl -w net.inet.icmp.icmplim_output=0最後,如果你想取消這些限制的話,你可以設定
net.inet.icmp.icmplim (如上例所示) 為
0。基於上述理由,我們不建議你取消這些限制。
這個錯誤訊息
arp: unknown hardware address format
是什麼意思?這代表你的區域網路連線上有一些設備使用 FreeBSD 看不懂得 MAC
格式。這通常是代表有人在你的區域網路上進行實驗,最常見的就是
cable modem 的連線。這訊息無害,而且應該不至於影響到 FreeBSD 主
機的效能。我剛剛裝好 CVSup 套件,但是在嘗試執行時發生了錯誤,要怎麼辦?
首先,看看錯誤的訊息是否如下:/usr/libexec/ld-elf.so.1: Shared object "libXaw.so.6" not found這種錯誤訊息代表你主機上安裝的
net/cvsup 沒有包含
XFree86 套件。如果你想要使用
CVSup 內建的圖形介面
GUI 的話,你需要安裝
XFree86。此外,如果你只想以命令列方
式使用 CVSup 的話,你應該先移除之前
安裝的套件。並安裝
net/cvsup-without-gui 這套
軟體。在 FreeBSD 手冊中 CVSup
段落中有更詳細的說明。Biing JongLinbjlin@stic.gov.tw系統安全篇什麼是 sandbox?Sandbox 是系統安全用的術語,有兩個意義:放在某些虛擬防護牆裡的執行程序,這些防護牆是用來阻止
某些人侵入這道程序,進而出入於更大的系統中。這道程序可以完全在防護牆裡 動作。也就
是說,它所執行的任何程式不可能會滲透到牆的外面。所以如果
您對它有安全上的顧慮,並不需要特別去監聽它的一舉一動,反
正它只能在牆內活動。舉例來說,可以用 userid 來做這道防護牆,這正是 security
和 named 說明文件中的定義。現在就用 ntalk 這個服務作說明(見
/etc/inetd.conf)。這個服務以前的 userid 是
root,現在執行時則是用
tty。tty
這個使用者就是一個 sandbox,如果有人能夠順利用 ntalk
侵入系統,現在他就算進得來也只能用這個 userid。放在某個模擬機器裡的程式,這比上述來得更嚴密。基本上
這表示能侵入該程式的人相信他能再進入所屬的機器,但事實上
只會進入模擬出來的機器,無法進一步修改任何真實的資料。達到這個目的最常用的方法,就是在某個子目錄下做出模擬的
環境,然後用 chroot 執行該程式,這樣該程式的根目錄便是這個
子目錄,而非系統真正的根目錄。另一個常見作法是將某個檔案系統 mount 成唯讀,但在它
上面另外製造出程式以為可以寫入的檔案系統。這個程式會相信
它可以對其他檔案讀寫,但只有它看不到這個唯讀效應 - 系統
執行的一般程式都看得到。我們試圖將這類 sandbox 盡量透明化,讓使用者或侵入者
無法看到他是否在某個 sandbox 裡面。UNIX 實作兩種 sandbox,一個在程式層面,另一個則是由 userid
來達成。每個 UNIX 執行程序會用防火牆將它和所有其他程序隔開,某個程序
不可以隨意修改其他程序位址的資料。這和 Windows 中,程式可以輕易
修改其他位址資料,結果導致當機的情形大不相同。每個 UNIX 程序都屬於某個特定的 userid。如果該 userid 不是
root,就會將它和其他使用者的程序隔開。
Userid 同時也用於硬碟資料的存取權上。什麼是 securelevel?securelevel 是核心中所實作的一個安全機制。基本上當
securelevel 是正值時,核心會限制某些工作;即使是 superuser
(也就是 root) 也無法完成那些工作。在撰寫
本文時,securelevel 機制在一般的限制外,還能夠限制以下的功能:
清除某些特定的檔案旗標,例如 schg
(系統唯讀標旗, the system immutable flag)經由 /dev/mem 與
/dev/kmem, 將資料寫入至核心記憶體中
載入核心模組更動 &man.ipfirewall.4; 規則。想要檢查在某個運作中的系統的 securelevel 狀態,只要執行以下
命令即可:&prompt.root; sysctl kern.securelevel輸出的結果會包含一個 &man.sysctl.8; 變數名稱 (在這個例子中,
它是 kern.securelevel) 以及一個數字。後者即是
目前的 securelevel 值。如果它是一個正值 (也就是大於 0),表示至少
有一些 securelevel 的保護機制已經開啟了。你沒有辦法降低一個運作中的系統的 securelevel;如果可以的話,
就失去了這個機制的意義了。如果你要作一些需要 securelevel 為
非正值才可以的動作的話 (例如 installworld
或更動日期),你需要修改 /etc/rc.conf 內的
securelevel 設定 (找找 kern_securelevel 和
kern_securelevel_enable 變數),然後重新開機。
想要知道更多有關於 securelevel 與各個不同等級影響的細節,
請參考 &man.init.8; 說明文件。securelevel 可不是萬靈丹;它有許多已知的缺陷,往往造成
一種安全的假象。它一個最大的問題,就是要讓這個功能完全有效的話,在
securelevel 發揮作用前的啟動過程中,所有使用到的檔案都
必須被保護起來。如果一個攻擊者在 securelevel 有效前 (由於
有些系統在啟動中所作的事情,無法在較高的 securelevel 中
正常運作,所以這會在啟動過程中後期才會運作),能讓他們的程式
被執行的話,securelevel 的保護就完全無效了。保護啟動程序
中所有的檔案在技術上是可行的,但是如果真的這樣作的話,系統
維護將會變成一場夢魘。即使只是修改一個設定檔,也必須將整個
系統關閉,至少也得到單人模式。除了這點,還有許多其它的東西都在通信論壇上討論,尤其是
freebsd-security。請到 這裡 搜尋以前的
討論。有些人希望 securelevel 能夠儘快消失,由另一個更優秀的
機制取代,不過機會有點渺茫。風險自行承擔。BIND (named) 除了在通訊埠 53 以外也在
其他高編號通訊埠 (high-numbered port) 聆聽 (Listen)。
這是怎麼回事?FreeBSD 3.0 後的版本使用一個特殊的 BIND 版本,這個版本會使
用隨機的高編號通訊埠來回應外部的查詢。如果你因為要適合防火牆的
設定或是單純的想讓自己看來舒服一點而想用 53 通訊埠回應外部查詢,
那麼你可以嘗試更改以下檔案相關內容
/etc/namedb/named.conf:options {
query-source address * port 53;
};你也可以將 * 更改為特定 IP address,
藉以加強控制條件。順便恭喜你。能夠讀取你系統上的 &man.sockstat.1; 報告並且注意
不正常狀況是一件好事!Sendmail 除了在標準的通訊埠 25 外也在通訊埠 587 聆聽!這是怎
麼回事?較新版本的 Sendmail 支援 mail submission 這項功能,並且使
用通訊埠 587。這項功能還沒有被廣泛支援但是支援的數目正在增長
中。我發現了這個 UID 0 toor 帳號,這是什麼
碗糕?我被黑掉了嗎?放心。toor 是一個
alternative 管理者帳號 (toor 是 root 的轉向拼法)。
以往是跟隨 &man.bash.1; 安裝而建制的,後來則成為系統內定建制的一
個帳號。這個帳號將伴隨一個非標準的 shell 測試使用, 讓你不需要去
更改到 root 的內建 shell。因為這些其他的 shell
並沒有跟隨系統預設值安裝 (舉例來說,某些由 ports 安裝的
shell package),而被內定安裝在 /usr/local/bin
目錄下,有可能存在不同的檔案系統中。 倘若 root
的 shell 被放在 /usr/local/bin,且
/usr (或是其他包含著
/usr/local/bin 這個子目錄的檔案系統)
因為某些原因並沒有被正常的 mount 起來的話,root
將無法正常的登入系統進行維修 (雖然說你重開機成單人模式就會問你要
載入哪個 shell)。有些人使用 toor 帳號進行每日的
root 維護工作,如此可以使用非標準的
shell,而 root 可以保留標準 shell,
以因應單一使用者模式 (single user mode) 或緊急狀況處理。
依照系統內定值,你將無法使用 toor 登入,
因為這個帳號尚未更改密碼設定。因此你如果你想啟動這個帳號,你需要
使用 root 登入系統並且修改
toor 的密碼。為什麼 suidperl 無法正常運作?因為某些安全的考,suidperl 內定的安裝
並沒有設定 suid bit。系統管理者可以依照以下命令啟動 suid 設定。
&prompt.root; chmod u+s /usr/bin/suidperl如果你想要在由 source 升級時 suidperl 內定
啟動 suid 功能的話,編輯 /etc/make.conf 加入
ENABLE_SUIDPERL=true 然後執行
make buildworld。PPPI cannot make &man.ppp.8; work. What am I doing wrong?You should first read the
&man.ppp.8;
man page and the
PPP section of the handbook. Enable logging with
the commandset log Phase Chat Connect Carrier lcp ipcp ccp commandThis command may be typed at the
&man.ppp.8; command prompt or it may be
entered in the /etc/ppp/ppp.conf
configuration file (the start of the
default section is the best
place to put it). Make sure that
/etc/syslog.conf (see &man.syslog.conf.5;) contains the lines!ppp
*.* /var/log/ppp.logand that the file /var/log/ppp.log
exists. You can now find out a lot about what is going on
from the log file. Do not worry if it does not all make sense.
If you need to get help from someone, it may make sense to
them.If your version of &man.ppp.8; does not understand the
set log command, you should download the
latest version. It will build on FreeBSD version
2.1.5 and higher.Why does &man.ppp.8; hang when I run it?This is usually because your hostname will not resolve.
The best way to fix this is to make sure that
/etc/hosts is consulted by your
resolver first by editing /etc/host.conf
and putting the hosts line first. Then,
simply put an entry in /etc/hosts for
your local machine. If you have no local network, change your
localhost line:127.0.0.1 foo.bar.com foo localhostOtherwise, simply add another entry for your host.
Consult the relevant man pages for more details.You should be able to successfully
ping -c1 `hostname` when you are done.Why will &man.ppp.8; not dial in -auto
mode?First, check that you have got a default route. By running
netstat -rn (see &man.netstat.1;), you should see two entries like this:Destination Gateway Flags Refs Use Netif Expire
default 10.0.0.2 UGSc 0 0 tun0
10.0.0.2 10.0.0.1 UH 0 0 tun0This is assuming that you have used the addresses from the
handbook, the man page or from the ppp.conf.sample file.
If you do not have a default route, it may be because you are
running an old version of &man.ppp.8;
that does not understand the word HISADDR
in the ppp.conf file. If your version of
&man.ppp.8; is from before FreeBSD
2.2.5, change theadd 0 0 HISADDRline to one sayingadd 0 0 10.0.0.2Another reason for the default route line being missing
is that you have mistakenly set up a default router in your
/etc/rc.conf (see &man.rc.conf.5;) file (this file was called
/etc/sysconfig prior to release 2.2.2),
and you have omitted the line sayingdelete ALLfrom ppp.conf. If this is the case,
go back to the
Final system configuration section of the
handbook.What does No route to host mean?This error is usually due to a missingMYADDR:
delete ALL
add 0 0 HISADDRsection in your /etc/ppp/ppp.linkup
file. This is only necessary if you have a dynamic IP address
or do not know the address of your gateway. If you are using
interactive mode, you can type the following after entering
packet mode (packet mode is
indicated by the capitalized PPP in the
prompt):delete ALL
add 0 0 HISADDRRefer to the
PPP and Dynamic IP addresses section of the handbook
for further details.Why does my connection drop after about 3 minutes?The default PPP timeout is 3 minutes. This can be
adjusted with the lineset timeout NNNwhere NNN is the number of
seconds of inactivity before the connection is closed. If
NNN is zero, the connection is never
closed due to a timeout. It is possible to put this command in
the ppp.conf file, or to type it at the
prompt in interactive mode. It is also possible to adjust it on
the fly while the line is active by connecting to
ppps server socket using
&man.telnet.1; or &man.pppctl.8;.
Refer to the
&man.ppp.8; man
page for further details.Why does my connection drop under heavy load?If you have Link Quality Reporting (LQR) configured,
it is possible that too many LQR packets are lost between
your machine and the peer. Ppp deduces that the line must
therefore be bad, and disconnects. Prior to FreeBSD version
2.2.5, LQR was enabled by default. It is now disabled by
default. LQR can be disabled with the linedisable lqrWhy does my connection drop after a random amount of
time?Sometimes, on a noisy phone line or even on a line with
call waiting enabled, your modem may hang up because it
thinks (incorrectly) that it lost carrier.There is a setting on most modems for determining how
tolerant it should be to temporary losses of carrier. On a
USR Sportster for example, this is measured by the S10
register in tenths of a second. To make your modem more
forgiving, you could add the following send-expect sequence
to your dial string:set dial "...... ATS10=10 OK ......"Refer to your modem manual for details.Why does my connection hang after a random amount of
time?Many people experience hung connections with no apparent
explanation. The first thing to establish is which side of
the link is hung.If you are using an external modem, you can simply try
using &man.ping.8; to see if the
TD light is flashing when you transmit data.
If it flashes (and the RD light does not),
the problem is with the remote end. If TD
does not flash, the problem is local. With an internal modem,
you will need to use the set server command in
your ppp.conf file. When the hang occurs,
connect to &man.ppp.8; using &man.pppctl.8;. If your network connection
suddenly revives (PPP was revived due to the activity on the
diagnostic socket) or if you cannot connect (assuming the
set socket command succeeded at startup
time), the problem is local. If you can connect and things are
still hung, enable local async logging with set log
local async and use &man.ping.8; from
another window or terminal to make use of the link. The async
logging will show you the data being transmitted and received
on the link. If data is going out and not coming back, the
problem is remote.Having established whether the problem is local or remote,
you now have two possibilities:The remote end is not responding. What can I do?There is very little you can do about this. Most ISPs
will refuse to help if you are not running a Microsoft OS.
You can enable lqr in your
ppp.conf file, allowing &man.ppp.8; to detect
the remote failure and hang up, but this detection is
relatively slow and therefore not that useful. You may want to
avoid telling your ISP that you are running user-PPP...First, try disabling all local compression by adding the
following to your configuration:disable pred1 deflate deflate24 protocomp acfcomp shortseq vj
deny pred1 deflate deflate24 protocomp acfcomp shortseq vjThen reconnect to ensure that this makes no difference.
If things improve or if the problem is solved completely,
determine which setting makes the difference through trial
and error. This will provide good ammunition when you contact
your ISP (although it may make it apparent that you are not
running a Microsoft product).Before contacting your ISP, enable async logging locally
and wait until the connection hangs again. This may use up
quite a bit of disk space. The last data read from the port
may be of interest. It is usually ascii data, and may even
describe the problem
(Memory fault, core dumped?).If your ISP is helpful, they should be able to enable
logging on their end, then when the next link drop occurs,
they may be able to tell you why their side is having a
problem. Feel free to send the details to &a.brian;, or
even to ask your ISP to contact me directly.&man.ppp.8; has hung. What can I do?Your best bet here is to rebuild &man.ppp.8; by adding
CFLAGS+=-g and STRIP=
to the end of the Makefile, then doing a
make clean && make && make
install. When &man.ppp.8; hangs, find the &man.ppp.8; process id
with ps ajxww | fgrep ppp and run
gdb ppp PID.
From the gdb prompt, you can then use bt
to get a stack trace.Send the results to brian@Awfulhak.org.Why does nothing happen after the Login OK!
message?Prior to FreeBSD version 2.2.5, once the link was
established, &man.ppp.8;
would wait for the peer to initiate the Line Control Protocol
(LCP). Many ISPs will not initiate negotiations and expect
the client to do so. To force
&man.ppp.8; to initiate the LCP, use the
following line:set openmode activeIt usually does no
harm if both sides initiate negotiation, so openmode is now
active by default. However, the next section explains when
it does do some harm.I keep seeing errors about magic being the same. What does
it mean?Occasionally, just after connecting, you may see messages
in the log that say magic is the same.
Sometimes, these messages are harmless, and sometimes one side
or the other exits. Most PPP implementations cannot survive
this problem, and even if the link seems to come up, you will see
repeated configure requests and configure acknowledgments in
the log file until &man.ppp.8; eventually gives up and closes the
connection.This normally happens on server machines with slow disks
that are spawning a getty on the port, and executing &man.ppp.8; from
a login script or program after login. I have also heard reports
of it happening consistently when using slirp. The reason is
that in the time taken between &man.getty.8; exiting and &man.ppp.8; starting,
the client-side &man.ppp.8; starts sending Line Control Protocol (LCP)
packets. Because ECHO is still switched on for the port on
the server, the client &man.ppp.8; sees these packets
reflect back.One part of the LCP negotiation is to establish a magic
number for each side of the link so that
reflections can be detected. The protocol says
that when the peer tries to negotiate the same magic number, a
NAK should be sent and a new magic number should be chosen.
During the period that the server port has ECHO turned on, the
client &man.ppp.8; sends LCP packets, sees the same magic in the
reflected packet and NAKs it. It also sees the NAK reflect
(which also means &man.ppp.8; must change its magic). This produces a
potentially enormous number of magic number changes, all of
which are happily piling into the server's tty buffer. As soon
as &man.ppp.8; starts on the server, it is flooded with magic number
changes and almost immediately decides it has tried enough to
negotiate LCP and gives up. Meanwhile, the client, who no
longer sees the reflections, becomes happy just in time to see
a hangup from the server.This can be avoided by allowing the peer to start
negotiating with the following line in your ppp.conf
file:set openmode passiveThis tells &man.ppp.8; to wait for the server to initiate LCP
negotiations. Some servers however may never initiate
negotiations. If this is the case, you can do something
like:set openmode active 3This tells &man.ppp.8; to be passive for 3 seconds, and then to
start sending LCP requests. If the peer starts sending
requests during this period, &man.ppp.8; will immediately respond
rather than waiting for the full 3 second period.LCP negotiations continue until the connection is
closed. What is wrong?There is currently an implementation mis-feature in
&man.ppp.8; where it does not associate
LCP, CCP & IPCP responses with their original requests. As
a result, if one PPP
implementation is more than 6 seconds slower than the other
side, the other side will send two additional LCP configuration
requests. This is fatal.Consider two implementations,
A and
B. A starts
sending LCP requests immediately after connecting and
B takes 7 seconds to start. When
B starts, A
has sent 3 LCP REQs. We are assuming the line has ECHO switched
off, otherwise we would see magic number problems as described in
the previous section. B sends a
REQ, then an ACK to the first of
A's REQs. This results in
A entering the OPENED
state and sending and ACK (the first) back to
B. In the meantime,
B sends back two more ACKs in response to
the two additional REQs sent by A
before B started up.
B then receives the first ACK from
A and enters the
OPENED state.
A receives the second ACK from
B and goes back to the
REQ-SENT state, sending another (forth) REQ
as per the RFC. It then receives the third ACK and enters the
OPENED state. In the meantime,
B receives the forth REQ from
A, resulting in it reverting to the
ACK-SENT state and sending
another (second) REQ and (forth) ACK as per the RFC.
A gets the REQ, goes into
REQ-SENT and sends another REQ. It
immediately receives the following ACK and enters
OPENED.This goes on until one side figures out that they are
getting nowhere and gives up.The best way to avoid this is to configure one side to be
passive - that is, make one side
wait for the other to start negotiating. This can be done
with theset openmode passivecommand. Care should be taken with this option. You
should also use theset stopped Ncommand to limit the amount of time that
&man.ppp.8; waits for the peer to begin
negotiations. Alternatively, theset openmode active Ncommand (where N is the
number of seconds to wait before starting negotiations) can be
used. Check the manual page for details.Why does &man.ppp.8; lock up shortly after connection?Prior to version 2.2.5 of FreeBSD, it was possible that
your link was disabled shortly after connection due to
&man.ppp.8; mis-handling Predictor1
compression negotiation. This would only happen if both sides
tried to negotiate different Compression Control Protocols
(CCP). This problem is now corrected, but if you are still
running an old version of &man.ppp.8;
the problem can be circumvented with the linedisable pred1Why does &man.ppp.8; lock up when I shell out to test it?When you execute the shell or
! command, &man.ppp.8; executes a
shell (or if you have passed any arguments,
&man.ppp.8; will execute those arguments). Ppp will
wait for the command to complete before continuing. If you
attempt to use the PPP link while running the command, the link
will appear to have frozen. This is because
&man.ppp.8; is waiting for the command to
complete.If you wish to execute commands like this, use the
!bg command instead. This will execute
the given command in the background, and &man.ppp.8; can continue to
service the link.Why does &man.ppp.8; over a null-modem cable never exit?There is no way for &man.ppp.8; to
automatically determine that a direct connection has been
dropped. This is due to the lines that are used in a
null-modem serial cable. When using this sort of connection,
LQR should always be enabled with the lineenable lqrLQR is accepted by default if negotiated by the peer.Why does &man.ppp.8; dial for no reason in -auto mode?If &man.ppp.8; is dialing
unexpectedly, you must determine the cause, and set up Dial
filters (dfilters) to prevent such dialing.To determine the cause, use the following line:set log +tcp/ipThis will log all traffic through the connection. The
next time the line comes up unexpectedly, you will see the
reason logged with a convenient timestamp next to it.You can now disable dialing under these circumstances.
Usually, this sort of problem arises due to DNS lookups. To
prevent DNS lookups from establishing a connection (this will
not prevent
&man.ppp.8; from passing the packets
through an established connection), use the following:set dfilter 1 deny udp src eq 53
set dfilter 2 deny udp dst eq 53
set dfilter 3 permit 0/0 0/0This is not always suitable, as it will effectively break
your demand-dial capabilities - most programs will need a DNS
lookup before doing any other network related things.In the DNS case, you should try to determine what is
actually trying to resolve a host name. A lot of the time,
&man.sendmail.8; is the culprit. You should make sure that
you tell sendmail not to do any DNS lookups in its
configuration file. See the section on
Mail Configuration for details
on how to create your own configuration file and what should
go into it. You may also want to add the following line to
your .mc file:define(`confDELIVERY_MODE', `d')dnlThis will make sendmail queue everything until the queue
is run (usually, sendmail is invoked with
, telling it to run the queue every
30 minutes) or until a sendmail -q is done
(perhaps from your ppp.linkup file).What do these CCP errors mean?I keep seeing the following errors in my log file:CCP: CcpSendConfigReq
CCP: Received Terminate Ack (1) state = Req-Sent (6)This is because &man.ppp.8; is trying to negotiate Predictor1
compression, and the peer does not want to negotiate any
compression at all. The messages are harmless, but if you
wish to remove them, you can disable Predictor1 compression
locally too:disable pred1Why does &man.ppp.8; lock up during file transfers with IO
errors?Under FreeBSD 2.2.2 and before, there was a bug in the
tun driver that prevents incoming packets of a size larger
than the tun interface's MTU size. Receipt of a packet
greater than the MTU size results in an IO error being logged
via syslogd.The PPP specification says that an MRU of 1500 should
always be accepted as a minimum,
despite any LCP negotiations, therefore it is possible that
should you decrease the MTU to less than 1500, your ISP will
transmit packets of 1500 regardless, and you will tickle this
non-feature - locking up your link.The problem can be circumvented by never setting an MTU of
less than 1500 under FreeBSD 2.2.2 or before.Why does &man.ppp.8; not log my connection speed?In order to log all lines of your modem
conversation, you must enable the
following:set log +connectThis will make &man.ppp.8; log
everything up until the last requested expect
string.If you wish to see your connect speed and are using PAP
or CHAP (and therefore do not have anything to
chat after the CONNECT in the dial script - no
set login script), you must make sure that
you instruct &man.ppp.8; to expect the whole CONNECT
line, something like this:set dial "ABORT BUSY ABORT NO\\sCARRIER TIMEOUT 4 \
\"\" ATZ OK-ATZ-OK ATDT\\T TIMEOUT 60 CONNECT \\c \\n"Here, we get our CONNECT, send nothing, then expect a
line-feed, forcing &man.ppp.8; to read
the whole CONNECT response.Why does &man.ppp.8; ignore the \ character
in my chat script?Ppp parses each line in your config files so that it can
interpret strings such as
set phone "123 456 789" correctly (and
realize that the number is actually only
one argument. In order to specify a
" character, you must escape it
using a backslash (\).When the chat interpreter parses each argument, it
re-interprets the argument in order to find any special
escape sequences such as \P or
\T (see the man page). As a result of this
double-parsing, you must remember to use the correct number of
escapes.If you wish to actually send a \
character to (say) your modem, you would need something
like:set dial "\"\" ATZ OK-ATZ-OK AT\\\\X OK"resulting in the following sequence:ATZ
OK
AT\X
OKorset phone 1234567
set dial "\"\" ATZ OK ATDT\\T"resulting in the following sequence:ATZ
OK
ATDT1234567Why does &man.ppp.8; get a seg-fault, but I see no
ppp.core file?Ppp (or any other program for that matter) should never
dump core. Because &man.ppp.8; runs with an effective user id of 0,
the operating system will not write &man.ppp.8;'s core image to disk
before terminating it. If, however &man.ppp.8;
is actually terminating due to a
segmentation violation or some other signal that normally
causes core to be dumped, and
you are sure you are using the latest version (see the start of
this section), then you should do the following:&prompt.user; tar xfz ppp-*.src.tar.gz
&prompt.user; cd ppp*/ppp
&prompt.user; echo STRIP= >>Makefile
&prompt.user; echo CFLAGS+=-g >>Makefile
&prompt.user; make clean all
&prompt.user; su
&prompt.root; make install
&prompt.root; chmod 555 /usr/sbin/pppYou will now have a debuggable version of &man.ppp.8; installed.
You will have to be root to run &man.ppp.8; as all of its privileges
have been revoked. When you start &man.ppp.8;, take a careful note
of what your current directory was at the time.Now, if and when &man.ppp.8; receives the segmentation violation,
it will dump a core file called ppp.core. You should then do
the following:&prompt.user; su
&prompt.root; gdb /usr/sbin/ppp ppp.core(gdb)bt
.....
(gdb)f 0
....
(gdb)i args
....
(gdb)l
.....All of this information should be given alongside your
question, making it possible to diagnose the problem.If you are familiar with gdb, you may wish to find out some
other bits and pieces such as what actually caused the dump and
the addresses & values of the relevant variables.Why does the process that forces a dial in auto mode never
connect?This was a known problem with
&man.ppp.8; set up to negotiate a
dynamic local IP number with the peer in auto mode. It is
fixed in the latest version - search the man page for
iface.The problem was that when that initial program calls
&man.connect.2;, the IP number of the tun interface is assigned
to the socket endpoint. The kernel creates the first outgoing
packet and writes it to the tun device.
&man.ppp.8; then reads the packet and
establishes a connection. If, as a result of
&man.ppp.8;'s dynamic IP assignment, the
interface address is changed, the original socket endpoint will
be invalid. Any subsequent packets sent to the peer will
usually be dropped. Even if they are not, any responses will
not route back to the originating machine as the IP number is
no longer owned by that machine.There are several theoretical ways to approach this
problem. It would be nicest if the peer would re-assign the
same IP number if possible :-)
The current version of &man.ppp.8; does
this, but most other implementations do not.The easiest method from our side would be to never change
the tun interface IP number, but instead to change all outgoing
packets so that the source IP number is changed from the
interface IP to the negotiated IP on the fly. This is
essentially what the iface-alias option in
the latest version of &man.ppp.8; is
doing (with the help of
&man.libalias.3; and &man.ppp.8;'s switch) -
it is maintaining all previous interface addresses and NATing
them to the last negotiated address.Another alternative (and probably the most reliable) would
be to implement a system call that changes all bound sockets
from one IP to another. &man.ppp.8; would
use this call to modify the sockets of all existing programs
when a new IP number is negotiated. The same system call could
be used by dhcp clients when they are forced to re-bind() their
sockets.Yet another possibility is to allow an interface to be
brought up without an IP number. Outgoing packets would be
given an IP number of 255.255.255.255 up until the first
SIOCAIFADDR ioctl is done. This would result in fully binding
the socket. It would be up to &man.ppp.8;
to change the source IP number, but only if it is set to
255.255.255.255, and only the IP number and IP checksum would
need to change. This, however is a bit of a hack as the kernel
would be sending bad packets to an improperly configured
interface, on the assumption that some other mechanism is
capable of fixing things retrospectively.Why do most games not work with the -nat switch?The reason games and the like do not work when libalias
is in use is that the machine on the outside will try to open a
connection or send (unsolicited) UDP packets to the machine on
the inside. The NAT software does not know that it should send
these packets to the interior machine.To make things work, make sure that the only thing
running is the software that you are having problems with, then
either run tcpdump on the tun interface of the gateway or
enable &man.ppp.8; tcp/ip logging (set log +tcp/ip)
on the gateway.When you start the offending software, you should see
packets passing through the gateway machine. When something
comes back from the outside, it will be dropped (that is the
problem). Note the port number of these packets then shut down
the offending software. Do this a few times to see if the port
numbers are consistent. If they are, then the following line in
the relevant section of /etc/ppp/ppp.conf will make the
software functional:nat port protointernalmachine:portportwhere proto is either
tcp or udp,
internalmachine is the machine that
you want the packets to be sent to and
port is the destination port number
of the packets.You will not be able to use the software on other machines
without changing the above command, and running the software
on two internal machines at the same time is out of the question
- after all, the outside world is seeing your entire internal
network as being just a single machine.If the port numbers are not consistent, there are three
more options:Submit support in
libalias. Examples of special cases can be found
in /usr/src/lib/libalias/alias_*.c
(alias_ftp.c is a good prototype). This
usually involves reading certain recognised outgoing packets,
identifying the instruction that tells the outside machine to
initiate a connection back to the internal machine on a
specific (random) port and setting up a route in
the alias table so that the subsequent packets know where to
go.This is the most difficult solution, but it is the best
and will make the software work with multiple machines.Use a proxy. The
application may support socks5 for example, or (as in the
cvsup case) may have a passive
option that avoids ever requesting that the peer open
connections back to the local machine.Redirect everything to
the internal machine using nat addr. This
is the sledge-hammer approach.Has anybody made a list of useful port numbers?Not yet, but this is intended to grow into such a list
(if any interest is shown). In each example,
internal should be replaced with
the IP number of the machine playing the game.Asheron's Callnat port udp
internal
:65000 65000Manually change the port number within the game to
65000. If you have got a number of machines that you wish
to play on assign a unique port number for each (i.e.
65001, 65002, etc) and add a nat port
line for each one.Half Lifenat port udp
internal:27005
27015PCAnywhere 8.0nat port udp
internal:5632
5632nat port tcp
internal:5631
5631Quakenat port udp
internal:6112
6112Alternatively, you may want to take a look at
www.battle.net for Quake proxy support.Quake 2nat port udp
internal:27901
27910nat port udp
internal:60021
60021nat port udp
internal:60040
60040Red Alertnat port udp
internal:8675
8675nat port udp
internal:5009
5009What are FCS errors?FCS stands for Frame
Check
Sequence. Each PPP packet
has a checksum attached to ensure that the data being
received is the data being sent. If the FCS of an incoming
packet is incorrect, the packet is dropped and the HDLC FCS
count is increased. The HDLC error values can be displayed
using the show hdlc command.If your link is bad (or if your serial driver is dropping
packets), you will see the occasional FCS error. This is not
usually worth worrying about although it does slow down the
compression protocols substantially. If you have an external
modem, make sure your cable is properly shielded from
interference - this may eradicate the problem.If your link freezes as soon as you have connected and you
see a large number of FCS errors, this may be because your link
is not 8 bit clean. Make sure your modem is not using software
flow control (XON/XOFF). If your datalink
must use software flow control, use the
command set accmap 0x000a0000 to tell
&man.ppp.8; to escape the ^Q and
^S characters.Another reason for seeing too many FCS errors may be that
the remote end has stopped talking PPP. You
may want to enable async logging at this
point to determine if the incoming data is actually a login or
shell prompt. If you have a shell prompt at the remote end,
it is possible to terminate &man.ppp.8; without dropping the line by
using the close lcp command (a following
term command will reconnect you to the shell
on the remote machine.If nothing in your log file indicates why the link might
have been terminated, you should ask the remote administrator
(your ISP?) why the session was terminated.Why do MacOS and Windows 98 connections freeze when
running PPPoE on the gateway?Thanks to Michael Wozniak
mwozniak@netcom.ca for figuring this out and
Dan Flemming danflemming@mac.com for the Mac
solution:This is due to what is called a Black Hole
router. MacOS and Windows 98 (and maybe other Microsoft OSs)
send TCP packets with a requested segment size too big to fit
into a PPPoE frame (MTU is 1500 by default for Ethernet)
and have the do not
fragment bit set (default of TCP) and the Telco router
is not sending ICMP must fragment back to the
www site you are trying to load. (Alternatively, the router is
sending the ICMP packet correctly, but the firewall at the www
site is dropping it.) When the www server is sending
you frames that do not fit into the PPPoE pipe the Telco router
drops them on the floor and your page does not load (some
pages/graphics do as they are smaller than a MSS.) This seems
to be the default of most Telco PPPoE configurations (if only
they knew how to program a router... sigh...)One fix is to use regedit on your 95/98 boxes to add the
following registry entry...HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Class\NetTrans\0000\MaxMTUIt should be a string with a value 1436, as
some ADSL routers are reported to be unable to deal with packets
larger than this. This registry key has been changed to
Tcpip\Parameters\Interfaces\ID for adapter\MTU
in Windows 2000 and becomes a DWORD.Refer to the Microsoft Knowledge Base documents Q158474
- Windows TCPIP Registry Entries and Q120642
- TCPIP & NBT Configuration Parameters for Windows
NT for more information on changing Windows MTU to
work with a NAT router.Another regedit possibility under Windows 2000 is to
set the
Tcpip\Parameters\Interfaces\ID for
adapter\EnablePMTUBHDetect DWORD
to 1 as mentioned in the Microsoft document 120642
mentioned above.Unfortunately, MacOS does not provide an interface for
changing TCP/IP settings. However, there is commercial software
available, such as OTAdvancedTuner (OT for OpenTransport, the
MacOS TCP/IP stack) by Sustainable Softworks,
that will allow users to customize TCP/IP settings. MacOS NAT
users should select ip_interface_MTU from
the drop-down menu, enter 1450 instead of
1500 in the box, click the box next to
Save as Auto Configure, and click
Make Active.The latest version of &man.ppp.8;
(2.3 or greater) has an enable tcpmssfixup
command that will automatically adjust the MSS to an appropriate
value. This facility is enabled by default. If you are stuck
with an older version of &man.ppp.8;, you
may want to look at the tcpmssd
port.None of this helps - I am desperate! What can I do?If all else fails, send as much information as you can,
including your config files, how you are starting
&man.ppp.8;, the relevant parts of your
log file and the output of the netstat -rn
command (before and after connecting) to the &a.questions; or
the
comp.unix.bsd.freebsd.misc news group, and someone
should point you in the right direction.Serial CommunicationsThis section answers common questions about serial
communications with FreeBSD. PPP and SLIP are covered in the
section.How do I tell if FreeBSD found my serial ports?As the FreeBSD kernel boots, it will probe for the serial
ports in your system for which the kernel was configured.
You can either watch your system closely for the messages it
prints or run the command&prompt.user; dmesg | grep sioafter your system is up and running.Here is some example output from the above command:sio0 at 0x3f8-0x3ff irq 4 on isa
sio0: type 16550A
sio1 at 0x2f8-0x2ff irq 3 on isa
sio1: type 16550AThis shows two serial ports. The first is on irq 4, is
using port address 0x3f8, and has a
16550A-type UART chip. The second uses the same kind of chip
but is on irq 3 and is at port address 0x2f8.
Internal modem cards are treated just like serial ports---except
that they always have a modem attached to the
port.The GENERIC kernel includes support
for two serial ports using the same irq and port address
settings in the above example. If these settings are not
right for your system, or if you have added modem cards or have
more serial ports than your kernel is configured for, just
reconfigure your kernel. See section
about building a kernel for
more details.How do I tell if FreeBSD found my modem cards?Refer to the answer to the previous question.I just upgraded to 2.0.5 and my
tty0X
are missing! How do I solve this problem?Do not worry, they have been merged with the
ttydX devices. You will have to change
any old configuration files you have, though.How do I access the serial ports on FreeBSD?The third serial port,
sio2
(see &man.sio.4;, known as COM3 in DOS), is on /dev/cuaa2
for dial-out devices, and on /dev/ttyd2
for dial-in devices. What is the difference between these two
classes of devices?You use ttydX for dial-ins. When
opening /dev/ttydX in blocking mode, a
process will wait for the corresponding
cuaaX device to become inactive, and then
wait for the carrier detect line to go active. When you open
the cuaaX device, it makes sure the serial
port is not already in use by the ttydX
device. If the port is available, it steals it
from the ttydX device. Also, the
cuaaX device does not care about carrier
detect. With this scheme and an auto-answer modem, you can have
remote users log in and you can still dial out with the same
modem and the system will take care of all the
conflicts.How do I enable support for a multiport serial
card?Again, the section on kernel configuration provides
information about configuring your kernel. For a multiport
serial card, place an &man.sio.4; line
for each serial port on the card in the kernel configuration
file. But place the irq and vector specifiers on only one of
the entries. All of the ports on the card should share one irq.
For consistency, use the last serial port to specify the irq.
Also, specify the COM_MULTIPORT
option.The following example is for an AST 4-port serial card on
irq 7:options "COM_MULTIPORT"
device sio4 at isa? port 0x2a0 tty flags 0x781
device sio5 at isa? port 0x2a8 tty flags 0x781
device sio6 at isa? port 0x2b0 tty flags 0x781
device sio7 at isa? port 0x2b8 tty flags 0x781 irq 7 vector siointrThe flags indicate that the master port has minor number 7
(0x700), diagnostics enabled during probe
(0x080), and all the ports share an irq
(0x001).Can FreeBSD handle multiport serial cards sharing
irqs?Not yet. You will have to use a different irq for each
card.Can I set the default serial parameters for a
port?The ttydX (or
cuaaX) device is the regular device
you will want to open for your applications. When a process
opens the device, it will have a default set of terminal I/O
settings. You can see these settings with the command&prompt.root; stty -a -f /dev/ttyd1When you change the settings to this device, the settings
are in effect until the device is closed. When it is reopened,
it goes back to the default set. To make changes to the
default set, you can open and adjust the settings of the
initial state device. For example, to turn on
CLOCAL mode, 8 bits, and
XON/XOFF flow control by default for
ttyd5, do:&prompt.root; stty -f /dev/ttyid5 clocal cs8 ixon ixoffA good place to do this is in
/etc/rc.serial. Now, an application will
have these settings by default when it opens
ttyd5. It can still change these settings
to its liking, though.You can also prevent certain settings from being changed
by an application by making adjustments to the
lock state device. For example, to lock the
speed of ttyd5 to 57600 bps, do&prompt.root; stty -f /dev/ttyld5 57600Now, an application that opens ttyd5
and tries to change the speed of the port will be stuck with
57600 bps.Naturally, you should make the initial state and lock state
devices writable only by root. The
&man.MAKEDEV.8;
script does NOT do this when it creates the
device entries.How can I enable dialup logins on my modem?So you want to become an Internet service provider, eh?
First, you will need one or more modems that can auto-answer.
Your modem will need to assert carrier-detect when it detects a
carrier and not assert it all the time. It will need to hang up
the phone and reset itself when the data terminal ready
(DTR) line goes from on to off. It should
probably use RTS/CTS flow control or no
local flow control at all. Finally, it must use a constant
speed between the computer and itself, but (to be nice to your
callers) it should negotiate a speed between itself and the
remote modem.For many Hayes command-set--compatible modems, this
command will make these settings and store them in
nonvolatile memory:AT &C1 &D3 &K3 &Q6 S0=1 &WSee the section on sending AT
commands below for information on how to make these
settings without resorting to an MS-DOS terminal program.Next, make an entry in
/etc/ttys (see &man.ttys.5;) for the modem. This file lists all the ports
on which the operating system will await logins. Add a line
that looks something like this:ttyd1 "/usr/libexec/getty std.57600" dialup on insecureThis line indicates that the second serial port
(/dev/ttyd1) has a modem connected
running at 57600 bps and no parity
(std.57600, which comes from the file
/etc/gettytab, see &man.gettytab.5;).
The terminal type for this port is dialup.
The port is on and is
insecure---meaning root
logins on the port are not allowed. For dialin ports like this one,
use the ttydX
entry.It is common practice to use dialup as
the terminal type. Many users set up in their .profile or
.login files a prompt for the actual terminal type if the
starting type is dialup. The example shows the port as
insecure. To become root on this port, you
have to login as a regular user, then &man.su.1; to become
root. If you use secure
then root can login in directly.After making modifications to
/etc/ttys, you need to send a hangup or
HUP signal to the
&man.init.8; process:&prompt.root; kill -HUP 1This forces the &man.init.8; process to reread
/etc/ttys. The init process will then start getty
processes on all on ports. You can find
out if logins are available for your port by typing&prompt.user; ps -ax | grep '[t]tyd1'You should see something like:747 ?? I 0:00.04 /usr/libexec/getty std.57600 ttyd1How can I connect a dumb terminal to my FreeBSD
box?If you are using another computer as a terminal into your
FreeBSD system, get a null modem cable to go between the two
serial ports. If you are using an actual terminal, see its
accompanying instructions.Then, modify
/etc/ttys (see &man.ttys.5;), like above. For example, if you are
hooking up a WYSE-50 terminal to the fifth serial port,
use an entry like this:ttyd4 "/usr/libexec/getty std.38400" wyse50 on secureThis example shows that the port on
/dev/ttyd4 has a wyse50 terminal
connected at 38400 bps with no parity
(std.38400 from
/etc/gettytab, see &man.gettytab.5;) and root logins are
allowed (secure).Why can I not run tip or
cu?On your system, the programs &man.tip.1;
and &man.cu.1;
are probably executable only by
uucp
and group dialer. You can use the group
dialer to control who has access to your
modem or remote systems. Just add yourself to group
dialer.Alternatively, you can let everyone on your system
run &man.tip.1; and &man.cu.1; by
typing:&prompt.root; chmod 4511 /usr/bin/cu
&prompt.root; chmod 4511 /usr/bin/tipMy stock Hayes modem is not supported---what
can I do?Actually, the man page for &man.tip.1; is
out of date. There is a generic Hayes dialer already built in.
Just use at=hayes in your
/etc/remote (see &man.remote.5;) file.The Hayes driver is not smart enough to recognize some of
the advanced features of newer modems---messages like
BUSY, NO DIALTONE, or
CONNECT 115200 will just confuse it. You
should turn those messages off when you use &man.tip.1;
(using ATX0&W).Also, the dial timeout for &man.tip.1; is 60
seconds. Your modem should use something less, or else tip
will think there is a communication problem. Try
ATS7=45&W.Actually, as shipped &man.tip.1; does not yet
support it fully. The solution is to edit the file
tipconf.h in the directory
/usr/src/usr.bin/tip/tip. Obviously you
need the source distribution to do this.Edit the line #define HAYES 0
to #define HAYES 1. Then
make and make install.
Everything works nicely after that.How am I expected to enter these AT commands?Make what is called a direct entry in your
/etc/remote file (see &man.remote.5;). For example, if your modem is hooked
up to the first serial port, /dev/cuaa0,
then put in the following line:cuaa0:dv=/dev/cuaa0:br#19200:pa=noneUse the highest bps rate your modem supports in the br
capability. Then, type
tip cuaa0 (see &man.tip.1;)
and you will be connected to your modem.If there is no /dev/cuaa0 on your
system, do this:&prompt.root; cd /dev
&prompt.root; sh MAKEDEV cuaa0Or use cu as root with the following command:&prompt.root; cu -lline -sspeedwith line being the serial port (e.g.
/dev/cuaa0) and speed being the speed
(e.g.57600). When you are done entering
the AT commands hit ~. to exit.Why does the <@> sign for the pn
capability not work?The <@> sign in the phone number
capability tells tip to look in
/etc/phones for a phone number. But the
<@> sign is also a special character
in capability files like /etc/remote.
Escape it with a backslash:pn=\@How can I dial a phone number on the command
line?Put what is called a generic entry in your
/etc/remote file (see &man.remote.5;). For example:tip115200|Dial any phone number at 115200 bps:\
:dv=/dev/cuaa0:br#115200:at=hayes:pa=none:du:
tip57600|Dial any phone number at 57600 bps:\
:dv=/dev/cuaa0:br#57600:at=hayes:pa=none:du:Then you can do something like tip -115200
5551234. If you prefer &man.cu.1;
over
&man.tip.1;, use a generic cu entry:cu115200|Use cu to dial any number at 115200bps:\
:dv=/dev/cuaa1:br#57600:at=hayes:pa=none:du:and type cu 5551234 -s 115200.Do I have to type in the bps rate every time I do
that?Put in an entry for tip1200 or
cu1200, but go ahead and use whatever bps
rate is appropriate with the br capability.
&man.tip.1;
thinks a good default is 1200 bps which is why it looks for
a tip1200 entry. You do not have to use 1200
bps, though.How can I more easily access a number of hosts through a
terminal server?Rather than waiting until you are connected and typing
CONNECT host
each time, use tip's cm capability. For
example, these entries in
/etc/remote (see &man.remote.5;):pain|pain.deep13.com|Forrester's machine:\
:cm=CONNECT pain\n:tc=deep13:
muffin|muffin.deep13.com|Frank's machine:\
:cm=CONNECT muffin\n:tc=deep13:
deep13:Gizmonics Institute terminal server:\
:dv=/dev/cuaa2:br#38400:at=hayes:du:pa=none:pn=5551234:will let you type tip pain or
tip muffin to connect to the hosts
pain or muffin; and
tip deep13 to get to the terminal
server.Can tip try more than one line for each site?This is often a problem where a university has several
modem lines and several thousand students trying to use
them...Make an entry for your university in
/etc/remote (see &man.remote.5;) and use <\@> for
the pn capability:big-university:\
:pn=\@:tc=dialout
dialout:\
:dv=/dev/cuaa3:br#9600:at=courier:du:pa=none:Then, list the phone numbers for the university in
/etc/phones (see &man.phones.5;):big-university 5551111
big-university 5551112
big-university 5551113
big-university 5551114&man.tip.1;
will try each one in the listed order, then give
up. If you want to keep retrying, run &man.tip.1;
in a while loop.Why do I have to hit CTRL+P twice to send CTRL+P
once?CTRL+P is the default force character,
used to tell &man.tip.1;
that the next character is literal data. You can set the
force character to any other character with the
~s escape, which means set a
variable.Type ~sforce=single-char
followed by a newline.
single-char is any single character.
If you leave out single-char,
then the force character is the nul character, which you can
get by typing CTRL+2 or CTRL+SPACE. A pretty good value for
single-char is SHIFT+CTRL+6, which
I have seen only used on some terminal servers.You can have the force character be whatever you want by
specifying the following in your
$HOME/.tiprc file:force=single-charWhy is everything I type suddenly in UPPER CASE?You must have pressed CTRL+A, &man.tip.1;
raise character, specially
designed for people with broken caps-lock keys. Use
~s as above and set the variable
raisechar to something reasonable. In fact,
you can set it to the same as the force character, if you
never expect to use either of these features.Here is a sample .tiprc file perfect for Emacs users who
need to type CTRL+2 and CTRL+A a lot:force=^^
raisechar=^^The ^^ is SHIFT+CTRL+6.How can I do file transfers with
tip?If you are talking to another Unix system, you can send
and receive files with ~p (put) and
~t (take). These commands run
&man.cat.1; and
&man.echo.1; on the remote system to accept and send files.
The syntax is:~p <local-file> [<remote-file>]
~t <remote-file> [<local-file>]There is no error checking, so you probably should use
another protocol, like zmodem.How can I run zmodem with
tip?First, install one of the zmodem programs from the
ports collection (such as one of the two from the comms
category, lrzsz or
rzsz.To receive files, start the sending program on the
remote end. Then, press enter and type
~C rz (or ~C lrz if you
installed lrzsz) to begin
receiving them locally.To send files, start the receiving program on the remote
end. Then, press enter and type
~C sz files
(or ~C lsz files)
to send them to the remote system.Why does FreeBSD not find my serial ports, even
when the settings are correct?Motherboards and cards with Acer UARTs do not probe
properly under the FreeBSD sio probe. Obtain a patch from
www.lemis.com to fix your problem.其它各式各樣的問題為甚麼 FreeBSD 用的置換(swap)空間比 Linux 多?FreeBSD僅是看起來置換空間(swap)用的比Linux多而已。在事實上,
並不然。主要的差異是在於,FreeBSD積極的將閒置無用的主記憶體內容
推入置換空間(swap)中,以使得主記憶體可以更為有效率的被使用。而
Linux的策略是將置換空間(swap)用來作為解決記憶體問題的最終手段。
較頻繁的使用置換空間(swap)。是一種更有效率的使用主記憶體的手段。
註:當一方面FreeBSD積極的使用置換空間(swap)的同時,你必需注
意到,FreeBSD並不會任意的將所有的東西都推入置換空間(swap)中。如此,
你才不會在一夜宿醉起床後發現,整個系統都被倒進了置換空間(swap)之中。
即使我只有運行少數程式,為什麼 top 顯示出
來的剩餘記憶體還是很少?簡單的答案是,所有未使用到的閒置記憶體都是被浪費的記憶體,
任何未被你的程式所利用到的記憶體將被核心(kernel)用來當
作磁碟快取(disk cache)。而這種記憶體被 &man.top.1; 標記為
閒置的(Inact),快取(Cache),
以及 緩衝區(Buf),並負責在各個不同的位置負責
暫存資料。被暫存(cached)的資料代表系統不需要去存取較慢的磁碟裝置
就可以得到資料,如此,可以提升系統的效能。總而言之,&man.top.1;
顯示出較少的 閒置(Free) 記憶體是好的,只要顯示
出來的值不是 非常 的低。為甚麼要用(甚麼是) a.out 和 ELF 執行檔格式?要了解為什麼Freebsd使用 ELF 格式,你有必
要先認識一下三種在目前 Unix 系統中最被廣泛應用到的執行檔格式:
在 FreeBSD 3.x 之前,FreeBSD 使用 a.out 格式。&man.a.out.5;這是最早,同是也是 最典型 的Unix目的檔
格式。這種格式的檔案使用一種短且緊密的檔頭,同時,伴隨著一
個魔術數字用來辨識格式。(參考 &man.a.out.5; 有更多詳細的說
明)。它包含有三個節區: .text .data 及 .bss 加上一個符號表
及字串表。COFFSVR3目的檔格式。檔頭包含了一個節區表,所以可以具備比
.text .data .bss 還多的節區。ELFELF為 COFF 格式的後繼者,主要的特徵為
可以具有複數節區段,並可以使用32-bits或是64-bits的數值。
主要的缺點為: ELF 格式是在每個系統中只
會有一種 ABI 的假設為前題被設計出來的。但是,在事實上,這個
假設錯的離譜。因為,縱使在商用的 SYSV 世界裡,也至少有 SVR4,
Solaris 和 SCO 三種 ABI。譯註:ABI(Application Binary Interface)。如果一定要翻譯,
就叫它 應用程式二進位介面 好了。 ABI被發
展出來的用意,是為了促使在相同CPU所發展出來的應用程式,能夠
在不同的系統上,作到二元檔(Binary Code)相容。比方說,
Sun 所提出的 Solaris ABI
,保證執行檔能夠在相同 CPU 的 Solaris 系統上執行,另一個例子是
Windows 系統。同屬於 Intel x86 版本的執行檔能夠自由的在Windows
9x/me及Windows NT/2k/XP之間執行。FreeBSD提供一個公用程式將程式所需的ABI資訊烙上,藉此試著
去解決這個問題。請參考 &man.brandelf.1; 以取得更多資訊。i
FreeBSD 來自 傳統 的陣營。在傳統上,FreeBSD都
使用 &man.a.out.5; 格式,這樣的技術在好幾代的 BSD 都被證明是可靠的。
雖然,在FreeBSD上可以建立以及正確的執行原生 ELF
格式檔案(包含核心)。然而, FreeBSD在一開始反對將預設格式轉換為 ELF,
為什麼呢?當Linux開始痛苦的轉換至 ELF 格式時,
並非是為了要逃離 a.out 格式。相反的,這是因
為之前 Linux的共享函式庫(shared libraries)採用以跳躍表格
(jump-table)為基礎的技術去設計。這是一種讓發展者感到困擾,且非常
難以使用,不具足夠彈性的方法。既然,已經存在的
ELF 工具提供了共享函式庫(shared libraries)的解
決方案,而且,那看起來是個 前衛的方法,因此,所需
的轉換代價就可接受因而轉換。在FreeBSD的狀況中,我們的共享函式庫(shared libraries)機制和
SunOS 的型式非常相近,且易於使用。然而,
從 3.0 開始,FreeBSD 正式將 ELF 改為預設格式。
雖然,a.out 格式依舊如以往般的好,但是,我們
編譯工具的撰寫者,GNU 的成員,他們中止了對
a.out 格式的支援與維護。在這種狀況下,迫使
我們必須自行維護另一份版本的 compiler 和 linker,也使得我們無法
從最新的 GNU 發展成果中獲得好處。此外,對 ISO-C++ 的需求,尤其是
建構子(constructors)和解構子(destructors),也帶動未來版本中對
ELF 的原生支援。是的, 但是, 為什麼會有這麼多不同格式的執行檔存在呢?在黑暗而遙遠的過去,僅有簡陋的硬體存在。而因為硬體簡陋,當然也
只能執行小而簡單的系統。a.out 格式是基於那個時代所需要,而被創造
出來的(例如像PDP-11)。在這之後,許多人試著將 Unix 移植到其他平台
時,他們也保留了 a.out 格式的執行檔。因為,這對早期的 Motorola 68k,
VAXen 之類的系統已經足夠使用了。然而,人並不會滿足於現狀。一些聰明的硬體工程師想到了,如果能
讓軟體多處理一些事,那 CPU 的電晶體數就能少一點,並且跑得更快。要
在這種新式的硬體上工作(現在稱為RISC),a.out
這種格式就不合適了。基於這樣的現實所需,更多的執行檔格式被發展出
來,以提供比簡單且受到許多限制的 a.out 格式
更好的效能。比方像是 COFF,
ECOFF,已及一些較不為人所周知的格式紛紛被創造
出來。但是,這些格式都已達到各自的極限,直到有一天
ELF 的出現。此外,當程式的體積越來越大,而磁碟空間和主記憶體相對來說都較
小時,共享函式庫(shared libraries)的觀念被發展出來了。在這同時,
虛擬記憶體系統(VM System)也變得越來越精巧。當每一種進步都在
a.out格式上被發展出來時,它的可用性也同時變
得越來越低。另外,人們還希望程式能在執行期間動態載入,或是將已經
執行過且沒有用的初始化程式碼丟棄,藉以節省更多的記憶。程式語言在
這個時期也便得更精巧,人們也希望在 main 之前自動的執行更多的東西。
因此,許多繁雜且另人嘆為觀止的技巧被用在 a.out
格式上去解決這些問題。但是,由於 a.out 格式
先天的限制,要解決這些問題必需付出更多的代價及時間成本,並讓程式
的複雜度大為提升。而 ELF 格式可以一舉解決這一
切問題。但是,要將整個系統從根本轉換過去,將會有不短的陣痛期,因
此, ELF格式將會有一陣子與
a.out 並存。然而,隨著時間的過去,FreeBSD的 build tools 演化成平行的兩個
支線(尤其是組譯器和載入器)。FreeBSD這條路加進了共享函式庫
(shared libraries)並修正了一些錯誤。而原來發展這些程式的 GNU 成員
則為了因應現況,重寫了這些程式,以更簡單的方式對跨平台編譯
(building cross compilers),以及多種格式
(plugging in different formats) 作出了支援。許多人想作出以 FreeBSD
為目的平台的跨平台編譯器。但不幸的是,FreeBSD 的 as 和 ld 不能作
這項工作。新的 GNU 工具程式加入了跨平台編譯 (Cross Compiler),
ELF格式支援,共享函式庫(shared libraries),
C++ 的擴充... 等等。此外,許多廠商以 ELF 格式
發行其產品,如果這些東西能在 FreeBSD 上執行的話當然是最好的。既然,
能夠執行 ELF 格式的執行檔了,為什麼還須要
a.out 呢?它已經是一匹垂垂老矣的馬了,在竭力
盡忠的奉獻這麼多年之後,該是讓它在牧場肥沃的草地上好好休息的時候
了。ELF 格式比 a.out 具有更良好的展現能力,並
且在底層系統中具有更多的可擴展性。ELF 工具程式
更容易被維護,且提供跨平台編譯的支援,這一點對很多人來說是很重要
的。ELF 格式可能比 a.out 慢一點,但是其差異非
常難測量出來。這兩者間還有許多細節上的不同,比方說分頁對應的方式,
程式碼初始化的方法...等等。這些並不是很重要,但是,兩者就是不同。
以後,GENERIC 核心(kernel)將會移除對 a.out
格式。當不在有執行傳統 a.out 程式的須要時,
將會從核心(kernel)中移除。為甚麼chmod不會改變符號連結(symlink)的存取權限?Symlinks 本身並沒有存取權限,同時,在預設的狀況下,
&man.chmod.1; 將不會跟隨著 symlinks 去改便目標檔案的存取權限。因此,
如果你有一個檔案 foo,同時,有一個 symlink
bar 指向這個檔案,以下這個命令將永遠會成功
的被執行。&prompt.user; chmod g-w bar然而,在 foo 上的存取權限將不會被改
變。你必需使用 或是將
與 選項一起使用,參考 &man.chmod.1; 以及
&man.symlink.7; 以取得更多的資訊。使用選項 會讓 &man.chmod.1; 以
遞迴(RECURSIVE) 的方式工作。當你把
&man.chmod.1; 用在目錄或是連結到目錄的符號連結時更要小心。
如果你要改變一個符號連結參考到的目錄之存取權限 &man.chmod.1; ,
且注意不要加上任何選項,並且在 symlink 的結尾加上斜線
(/)。舉例來說,如果
foo 連結到目錄 bar,
而你要更改 foo (實際上是
bar),那就使用:&prompt.user; chmod 555 foo/結尾的斜線會使得 &man.chmod.1; 改變
foo 所指向的目錄 bar
的權限。為什麼在 FreeBSD 2.2.x 及更早的版本中,登入名稱(login names)
被限制在八個字元以下呢?你可能認為修改 UT_NAMESIZE 後在重新編譯整個
系統是很容易的事。而且在這之後,每件事都可以運作的很好。不幸的是,
有許多的程式和工具(包含系統工具)把數字寫死在程式裡頭(並非總是
8 或 9,有時可能是古怪的
15 或 20)。這不僅僅是會將
你的系統記錄檔弄壞而已(來自於變動長度和固定長度記錄的差異),同時
也會破壞 Sun 的 NIS Client 的運作。同時,和其他的Unix系統之間也
有可能會產生未知的問題。在FreeBSD 3.0 及之後的版本,帳號的最大長度增加到16個字元,
同時,那些將長度寫死的程式也被找出來並作了適當的修正。正因為影響
系統的範圍很廣,所以直到3.0版之後才算大致修正完成。如果你有自信在出問題的時後能自行解決,你可以利用下面的方法讓
較早期的版本支援較長的帳號。首先,修改
/usr/include/utmp.h 中的UT_NAMESIZE。
然後,你必須把 /usr/include/sys/param.h
中的 MAXLOGNAME 改成跟 UT_NAMESIZE 相同。最後,如果你是從原始程
式建立系統, 別忘了 /usr/include 每次都會被更新。
修改 /usr/src/.. 中適當的檔案。我能在FreeBSD下執行DOS程式嗎?是的,自3.0版起你可以使用BSDI的
doscmd DOS 模擬器,如果你對這個東西
有興趣,或是想加入發展行列,請寄一封電子郵件到 &a.emulation; 。
對於3.0之前的系統,在 ports 中有一套軟體可以模儗 8088,並提
供足夠的BIOS中斷服務以執行DOS文字模式的程式,這套軟體叫做
pcemu,同時,運行它須要
X Windows(由XFree86提供)。如果要把FreeBSD文件翻譯成我的母語,我需要作什麼?參閱FreeBSD文件中的 翻譯常見問答。為什麼我寄到 FreeBSD.org 相關地址的電子郵件都被退回了呢?FreeBSD.org 的郵件系統對於進來的郵件採取嚴格的檢查,並且退回
所有設定不正確,或是潛在的垃圾郵件。你的郵件被退回可能是因為下列
原因所引起:這封電子郵件來自已知的垃圾郵件區域或是IP中。FreeBSD郵件伺服器將拒絕接收已知的垃圾郵件來源的電子郵件。
如果提供你網路服務的公司或是網域中有產生過垃圾郵件或是有垃圾
郵件轉播站,請你換一個服務提供者,或是乾脆放棄。電子郵件的本文僅有HTML。郵件應該已純文字格式發送,請設定你的電子郵件軟體送出純文
字格式。FreeBSD的郵件處理程式無法由IP反查送件主機的IP。設置 DNS 反查是接受一台主機郵件的一個標準要求,請為您的郵件
主機設置 DNS 反查。許多提供家庭網路服務 (DSL,cable,dialup 等)
的公司並不提供這樣的服務。在這種情況下,請透過網路服務提供者的
郵件伺服器送出您的電子郵件。在 SMTP 使用 EHLO/HELO 命令時所給予的 hostname 無法被解析到
一個 IP 位置。在郵件被接受以前,一個充分合格,且可被解析的主機名稱在
SMTP 協定的對談中是必要的。如果你沒有在 DNS 伺服器中登記你
的主機名稱,請透過網路服務提供者的郵件伺服器送出您的電子郵
件。你的訊息中夾帶著一個 message ID 以 localhost
字串結束。某些郵件軟體產生某些不正確的 message ID,這將不被接受。
你必需更改設定讓你的郵件軟體產生正確的 message ID,如果這無
法解決,考慮說服你的郵件軟體作者更新程式以處理這個問題。我可以在哪裡找到一個免費的FreeBSD帳號?FreeBSD的伺服器本身不提供任何對外的服務,其他的單位中,
有人提供開放的 Unix 系統服務。其中有些可能要收取些許費用。Arbornet, Inc,
也被稱為 M-Net,自 1983 年起就開始提供 Unix 系統服務。一開始,
他們使用 Altos 並執行 System III。他們在 1991 年轉換系統成為
BSD/OS。在 2000 年六月,他們再度更換成為 FreeBSD。M-Net 能讓使
用者透過 SSH 及 telnet 連線到主機,並提供完整的 FreeBSD 軟體以
供使用。然而,M-Net 作為一個非盈利組織運行,存取權只限於成員和
贊助者,M-Net 也提供 BBS 系統和網路聊天服務。Grex 提供了非常
類似 M-Net 的服務,包括了 BBS 系統和網路聊天。然而,機器是使用
Sun 4M,並執行 SunOS。什麼是 sup,我該如何使用它?
SUP 的意思是 Software Update Protocol,由 CMU 發展,
用來維持整個發展的同步。我們利用它保持遠端的站台和原始站台之間
的同步工作。然而,SUP 在頻寬的使用上並不太友善,同時,目前也不再使用了。
目前建議維持原始碼同步更新的方法是
CVSup。
- 這個可愛的小紅人的名字是什麼?
+ 這個可愛的小紅人叫作什麼?似乎,他並沒有一個正式的名字,姑且就稱其為
BSD 小惡魔 吧。如果你執意要使用一個名字。那就叫他
小動物(beastie) 吧。註:beastie
在讀音上跟 BSD 很接近。你可以在BSD小惡魔的 主頁
上取得更多的資訊。
- 我能使用BSD的小惡魔圖案嗎?
+ 我能使用 BSD 小惡魔圖案嗎?
- 也許吧,我也不確定。BSD小惡魔圖案的版權是屬於馬歇爾蘇格蘭教會
- (Marshall Kirk McKusick)所擁有。你可以試著去查看網頁敘述關於BSD小惡魔肖像
- 以取得更詳細關於使用他的資訊。
+ 也許吧,我也不確定。BSD小惡魔圖案的版權是屬於馬歇爾蘇格蘭教會的
+ Marshall Kirk McKusick 所擁有。你可以試著去查看網頁關於BSD小惡魔肖像
+ 以取得更詳細的使用細節。
- 總歸的來說,如果你純粹為了自己想要鑑賞,那麼,你可以自由的使
- 用肖像。如果你是個人使用,只要情況適當,應該都會被許可。如果你想
- 在商業上使用,則你必需聯繫蘇格蘭教會(Kirk McKusick)以取得許可。
+ 總而言之,如果你純粹為了自己想要鑑賞,那麼,你可以自由的使用肖像。如果你是個人使用,只要情況適當,應該都會被許可。
+ 如果你想在商業上使用,則你必需聯繫蘇格蘭教會的 Kirk McKusick 以取得許可。
如果你需要更進一步詳細的資訊,請參考 BSD小惡魔的首頁。
你有任何的 BSD 小惡魔圖案可以讓我使用嗎?
- 你可以在 /usr/share/examples/BSD_daemon/
- 發現 eps 及 Xfig 兩種格式的圖檔。
+ 你可以在 /usr/share/examples/BSD_daemon/ 找到 Xfig 及 eps 兩種格式的圖檔。我在文件、郵遞論壇上,常會看到一些縮寫字、技術字彙,這些可以去哪邊查呢?請參閱
&os; 字彙表。
- 為什麼我該在意腳踏車棚的顏色?
+ 為什麼我該在意腳踏車車棚的顏色?
- 一個最短最短的答案是,你不該在意。稍微長一點的答案是,雖然
- 你有能力自己去建造一座腳踏車棚,但是,這不代表因為你不喜歡現在這
- 個腳踏車棚的顏色,就中止他的建築。這個比喻的意思是,你不需要去爭論
- 每一個細項特徵,只因為你有辦法去作它。某些人的評論是,雜音的產生度
- 對變化的複雜性相反地比例。
+ 最短最短的答案是:『不用在意』。稍微長一點的答案是:『雖然你有能力自己去建造一座腳踏車車棚,但是,
+ 這不代表因為你不喜歡現在這個車棚的顏色,就要中止他的建築。』這個比喻的意思是,
+ 你不需要去爭論每一個細項特徵,只因為你有辦法去作它。
+ 某些人的評論是:『雜音的程度,與變化的複雜性是成反比』。更長且較完整的答案是,在經過長時間爭論關於是否該將 &man.sleep.1;
的秒參數移除,&a.phk;發表了一篇長論 一座自行車蓬 (任何顏色的)在青脆的草地上...。
- 那則訊息被適當的部分被引用在下面。
+ url="http://www.FreeBSD.org/cgi/getmsg.cgi?fetch=506636+517178+/usr/local/www/db/text/1999/freebsd-hackers/19991003.freebsd-hackers">
+ 在青翠草地上的腳踏車車棚(任何顏色的)...。以下,僅摘要該則文章部分內容:
&a.jkh;不停的更新過時的 FAQ&a.dwhite;經常在 freebsd-questions 上回答問題&a.joerg;經常在 Usenet 上回答問題&a.wollman;Networking and formattingJim LoweMulticast information&a.pds;FreeBSD FAQ 這份文件的打字苦工The FreeBSD TeamKvetching, moaning, submitting data對於那些曾經對這份 FAQ 提供幫助,而我們沒提到的人們,
我們由衷的感謝您!
&bibliography;
diff --git a/zh_TW.Big5/books/fdp-primer/see-also/chapter.sgml b/zh_TW.Big5/books/fdp-primer/see-also/chapter.sgml
index ab689d847c..add75bf067 100644
--- a/zh_TW.Big5/books/fdp-primer/see-also/chapter.sgml
+++ b/zh_TW.Big5/books/fdp-primer/see-also/chapter.sgml
@@ -1,135 +1,135 @@
- See Also
+ 他山之石This document is deliberately not an exhaustive discussion of SGML,
the DTDs listed, and the FreeBSD Documentation Project. For more
information about these, you are encouraged to see the following web
sites.The FreeBSD Documentation ProjectThe FreeBSD
Documentation Project web pagesThe FreeBSD HandbookSGMLThe SGML/XML web
page, a comprehensive SGML resourceGentle introduction to SGMLHTMLThe World Wide Web
ConsortiumThe HTML 4.0
specificationDocBookThe DocBook
Technical Committee, maintainers of the DocBook DTDDocBook: The Definitive
Guide, the online documentation for the DocBook
DTD.The DocBook Open
Repository contains DSSSL stylesheets and other resources
for people using DocBook.The Linux Documentation ProjectThe Linux Documentation
Project web pages
diff --git a/zh_TW.Big5/books/fdp-primer/translations/chapter.sgml b/zh_TW.Big5/books/fdp-primer/translations/chapter.sgml
index 89a2adaa66..7743dbcac0 100644
--- a/zh_TW.Big5/books/fdp-primer/translations/chapter.sgml
+++ b/zh_TW.Big5/books/fdp-primer/translations/chapter.sgml
@@ -1,456 +1,454 @@
翻譯時的常見問題本章是翻譯 FreeBSD 文件(包含:FAQ, Handbook, tutorials, manual pages等)的常見問題(FAQ)。It is very heavily based on the translation FAQ
from the FreeBSD German Documentation Project, originally written by Frank
Gründer elwood@mc5sys.in-berlin.de and translated back to
English by Bernd Warken bwarken@mayn.de.The FAQ is maintained by the &a.doceng;.
- Why a FAQ?
+ FAQ 的目的是?
- More and more people are approaching the freebsd-doc mailing
- list and volunteering to translate FreeBSD documentation to other
- languages. This FAQ aims to answer their questions so they can start
- translating documentation as quickly as possible.
+ 隨著越來越多人參與 freebsd-doc 郵遞論壇,而且希望將 FreeBSD 文件翻譯為各種語言版本。
+ 我們希望這份 FAQ 能儘可能為這些參與翻譯者提供快速的解惑。What do i18n and l10n
mean?i18n means
internationalization and l10n
means localization. They are just a convenient
shorthand.i18n can be read as i followed by
18 letters, followed by n. Similarly,
l10n is l followed by 10 letters,
followed by n.Is there a mailing list for translators?Yes. Different translation groups have their own mailing
lists. The list
of translation projects has more information about the
mailing lists and web sites run by each translation project.Are more translators needed?Yes. The more people work on translation the faster it gets
done, and the faster changes to the English documentation are
mirrored in the translated documents.You do not have to be a professional translator to be able to
help.What languages do I need to know?Ideally, you will have a good knowledge of written English, and
obviously you will need to be fluent in the language you are
translating to.English is not strictly necessary. For example, you could do a
Hungarian translation of the FAQ from the Spanish
translation.What software do I need to know?It is strongly recommended that you maintain a local copy of the
FreeBSD CVS repository (at least the documentation part) either
using CTM or
CVSup. The "Staying current with FreeBSD"
chapter in the Handbook explains how to use these
applications.You should be comfortable using CVS.
This will allow you to see what has changed between different
versions of the files that make up the documentation.[XXX To Do -- write a tutorial that shows how to use CVSup to
get just the documentation, check it out, and see what has changed
between two arbitrary revisions]How do I find out who else might be translating to the same
language?The Documentation
Project translations page lists the translation efforts
that are currently known about. If others are already working
on translating documentation to your language, please do not
duplicate their efforts. Instead, contact them to see how you can
help.If no one is listed on that page as translating for your
language, then send a message to the &a.doc; in case someone else
is thinking of doing a translation, but has not announced it yet.
No one else is translating to my language. What do I do?Congratulations, you have just started the FreeBSD
your-language-here Documentation
Translation Project. Welcome aboard.First, decide whether or not you have got the time to spare. Since
you are the only person working on your language at the moment it is
going to be your responsibility to publicize your work and
coordinate any volunteers that might want to help you.Write an email to the Documentation Project mailing list,
announcing that you are going to translate the documentation, so the
Documentation Project translations page can be maintained.If there is already someone in your country providing FreeBSD
mirroring services you should contact them and ask if you can
have some webspace for your project, and possibly an email
address or mailing list services.Then pick a document and start translating. It is best to start
with something fairly small—either the FAQ, or one of the
tutorials.I have translated some documentation, where do I send it?That depends. If you are already working with a translation team
(such as the Japanese team, or the German team) then they will have
their own procedures for handling submitted documentation, and these
will be outlined on their web pages.If you are the only person working on a particular language (or
you are responsible for a translation project and want to submit
your changes back to the FreeBSD project) then you should send your
translation to the FreeBSD project (see the next question).I am the only person working on translating to this language, how
do I submit my translation?orWe are a translation team, and want to submit documentation that
our members have translated for us?First, make sure your translation is organized properly. This
means that it should drop into the existing documentation tree and
build straight away.Currently, the FreeBSD documentation is stored in a top level
directory called doc/. Directories below this
are named according to the language code they are written in, as
defined in ISO639 (/usr/share/misc/iso639 on a
version of FreeBSD newer than 20th January 1999).If your language can be encoded in different ways (for example,
Chinese) then there should be directories below this, one for each
encoding format you have provided.Finally, you should have directories for each document.For example, a hypothetical Swedish translation might look
like:doc/
sv_SE.ISO8859-1/
Makefile
books/
faq/
Makefile
book.sgmlsv_SE.ISO8859-1 is the name of the
translation, in
lang.encoding
form. Note the
two Makefiles, which will be used to build the documentation.Use &man.tar.1; and &man.gzip.1; to compress up your
documentation, and send it to the project.&prompt.user; cd doc
&prompt.user; tar cf swedish-docs.tar sv
&prompt.user; gzip -9 swedish-docs.tarPut swedish-docs.tar.gz somewhere. If you
do not have access to your own webspace (perhaps your ISP does not
let you have any) then you can email &a.doceng;, and arrange to email
the files when it is convenient.Either way, you should use &man.send-pr.1; to submit a report
indicating that you have submitted the documentation. It would be
very helpful if you could get other people to look over your
translation and double check it first, since it is unlikely that the
person committing it will be fluent in the language.Someone (probably the Documentation Project Manager, currently
&a.doceng;) will then take your translation and confirm that it builds.
In particular, the following things will be looked at:Do all your files use RCS strings (such as "ID")?Does make all in the
sv_SE.ISO8859-1 directory work correctly?Does make install work correctly?If there are any problems then whoever is looking at the
submission will get back to you to work them out.If there are no problems your translation will be committed
as soon as possible.Can I include language or country specific text in my
translation?We would prefer that you did not.For example, suppose that you are translating the Handbook to
Korean, and want to include a section about retailers in Korea in
your Handbook.There is no real reason why that information should not be in the
English (or German, or Spanish, or Japanese, or …) versions
as well. It is feasible that an English speaker in Korea might try
- and pick up a copy of FreeBSD whilst over there. It also helps
+ to pick up a copy of FreeBSD whilst over there. It also helps
increase FreeBSD's perceived presence around the globe, which is not
a bad thing.If you have country specific information, please submit it as a
change to the English Handbook (using &man.send-pr.1;) and then
translate the change back to your language in the translated
Handbook.Thanks.How should language specific characters be included?Non-ASCII characters in the documentation should be included
using SGML entities.Briefly, these look like an ampersand (&), the name of the
entity, and a semi-colon (;).The entity names are defined in ISO8879, which is in the ports
tree as textproc/iso8879.A few examples include:EntityAppearanceDescriptionééSmall e with an acute accentÉÉLarge E with an acute accentüüSmall u with an umlautAfter you have installed the iso8879 port, the files in
/usr/local/share/sgml/iso8879 contain the
complete list.Addressing the readerIn the English documents, the reader is addressed as
you, there is no formal/informal distinction as there
is in some languages.If you are translating to a language which does distinguish, use
whichever form is typically used in other technical documentation in
your language. If in doubt, use a mildly polite form.Do I need to include any additional information in my
translations?Yes.The header of the English version of each document will look
something like this:<!--
The FreeBSD Documentation Project
$FreeBSD: doc/en_US.ISO8859-1/books/fdp-primer/translations/chapter.sgml,v 1.5 2000/07/07 18:38:38 dannyboy Exp $
-->The exact boilerplate may change, but it will always include a
$FreeBSD$ line and the phrase The FreeBSD Documentation
Project.
Note that the $FreeBSD part is expanded automatically by
CVS, so it should be empty (just
$FreeBSD$) for new files.Your translated documents should include their own
$FreeBSD$ line, and change the
FreeBSD Documentation Project line to
The FreeBSD language
Documentation Project.In addition, you should add a third line which indicates which
revision of the English text this is based on.So, the Spanish version of this file might start:<!--
The FreeBSD Spanish Documentation Project
$FreeBSD: doc/es_ES.ISO8859-1/books/fdp-primer/translations/chapter.sgml,v 1.3 1999/06/24 19:12:32 jesusr Exp $
Original revision: 1.11
-->
diff --git a/zh_TW.Big5/books/handbook/Makefile b/zh_TW.Big5/books/handbook/Makefile
index 0f4c36edbc..d7b6509d6b 100644
--- a/zh_TW.Big5/books/handbook/Makefile
+++ b/zh_TW.Big5/books/handbook/Makefile
@@ -1,255 +1,255 @@
#
-# $FreeBSD$
+# $FreeBSD$
# Original revision: 1.97
#
# Build the FreeBSD Handbook.
#
# ------------------------------------------------------------------------
#
# Handbook-specific variables
#
# WITH_PGPKEYS The print version of the handbook only prints PGP
# fingerprints by default. If you would like for the
# entire key to be displayed, then set this variable.
# This option has no affect on the HTML formats.
#
# Handbook-specific targets
#
# pgpkeyring This target will read the contents of
# pgpkeys/chapter.sgml and will extract all of
# the pgpkeys to standard out. This output can then
# be redirected into a file and distributed as a
# public keyring of FreeBSD developers that can
# easily be imported into PGP/GPG.
#
# ------------------------------------------------------------------------
.PATH: ${.CURDIR}/../../share/sgml/glossary
MAINTAINER= doc@FreeBSD.org
DOC?= book
FORMATS?= html-split
HAS_INDEX= true
USE_PS2PDF= yes
INSTALL_COMPRESSED?= gz
INSTALL_ONLY_COMPRESSED?=
IMAGES_EN = advanced-networking/isdn-bus.eps
IMAGES_EN+= advanced-networking/isdn-twisted-pair.eps
IMAGES_EN+= advanced-networking/natd.eps
IMAGES_EN+= advanced-networking/net-routing.pic
IMAGES_EN+= advanced-networking/static-routes.pic
IMAGES_EN+= geom/striping.pic
IMAGES_EN+= install/adduser1.scr
IMAGES_EN+= install/adduser2.scr
IMAGES_EN+= install/adduser3.scr
IMAGES_EN+= install/boot-mgr.scr
IMAGES_EN+= install/console-saver1.scr
IMAGES_EN+= install/console-saver2.scr
IMAGES_EN+= install/console-saver3.scr
IMAGES_EN+= install/console-saver4.scr
IMAGES_EN+= install/desktop.scr
IMAGES_EN+= install/disklabel-auto.scr
IMAGES_EN+= install/disklabel-ed1.scr
IMAGES_EN+= install/disklabel-ed2.scr
IMAGES_EN+= install/disklabel-fs.scr
IMAGES_EN+= install/disklabel-root1.scr
IMAGES_EN+= install/disklabel-root2.scr
IMAGES_EN+= install/disklabel-root3.scr
IMAGES_EN+= install/disk-layout.eps
IMAGES_EN+= install/dist-set.scr
IMAGES_EN+= install/dist-set2.scr
IMAGES_EN+= install/docmenu1.scr
IMAGES_EN+= install/ed0-conf.scr
IMAGES_EN+= install/ed0-conf2.scr
IMAGES_EN+= install/edit-inetd-conf.scr
IMAGES_EN+= install/fdisk-drive1.scr
IMAGES_EN+= install/fdisk-drive2.scr
IMAGES_EN+= install/fdisk-edit1.scr
IMAGES_EN+= install/fdisk-edit2.scr
IMAGES_EN+= install/ftp-anon1.scr
IMAGES_EN+= install/ftp-anon2.scr
IMAGES_EN+= install/hdwrconf.scr
IMAGES_EN+= install/keymap.scr
IMAGES_EN+= install/main1.scr
IMAGES_EN+= install/mainexit.scr
IMAGES_EN+= install/main-std.scr
IMAGES_EN+= install/main-options.scr
IMAGES_EN+= install/main-doc.scr
IMAGES_EN+= install/main-keymap.scr
IMAGES_EN+= install/media.scr
IMAGES_EN+= install/mouse1.scr
IMAGES_EN+= install/mouse2.scr
IMAGES_EN+= install/mouse3.scr
IMAGES_EN+= install/mouse4.scr
IMAGES_EN+= install/mouse5.scr
IMAGES_EN+= install/mouse6.scr
IMAGES_EN+= install/mta-main.scr
IMAGES_EN+= install/net-config-menu1.scr
IMAGES_EN+= install/net-config-menu2.scr
IMAGES_EN+= install/nfs-server-edit.scr
IMAGES_EN+= install/ntp-config.scr
IMAGES_EN+= install/options.scr
IMAGES_EN+= install/pkg-cat.scr
IMAGES_EN+= install/pkg-confirm.scr
IMAGES_EN+= install/pkg-install.scr
IMAGES_EN+= install/pkg-sel.scr
IMAGES_EN+= install/probstart.scr
IMAGES_EN+= install/routed.scr
IMAGES_EN+= install/security.scr
IMAGES_EN+= install/sysinstall-exit.scr
IMAGES_EN+= install/timezone1.scr
IMAGES_EN+= install/timezone2.scr
IMAGES_EN+= install/timezone3.scr
IMAGES_EN+= install/userconfig.scr
IMAGES_EN+= install/userconfig2.scr
IMAGES_EN+= install/xf86setup.scr
IMAGES_EN+= mail/mutt1.scr
IMAGES_EN+= mail/mutt2.scr
IMAGES_EN+= mail/mutt3.scr
IMAGES_EN+= mail/pine1.scr
IMAGES_EN+= mail/pine2.scr
IMAGES_EN+= mail/pine3.scr
IMAGES_EN+= mail/pine4.scr
IMAGES_EN+= mail/pine5.scr
IMAGES_EN+= install/example-dir1.eps
IMAGES_EN+= install/example-dir2.eps
IMAGES_EN+= install/example-dir3.eps
IMAGES_EN+= install/example-dir4.eps
IMAGES_EN+= install/example-dir5.eps
IMAGES_EN+= security/ipsec-network.pic
IMAGES_EN+= security/ipsec-crypt-pkt.pic
IMAGES_EN+= security/ipsec-encap-pkt.pic
IMAGES_EN+= security/ipsec-out-pkt.pic
IMAGES_EN+= vinum/vinum-concat.pic
IMAGES_EN+= vinum/vinum-mirrored-vol.pic
IMAGES_EN+= vinum/vinum-raid10-vol.pic
IMAGES_EN+= vinum/vinum-raid5-org.pic
IMAGES_EN+= vinum/vinum-simple-vol.pic
IMAGES_EN+= vinum/vinum-striped-vol.pic
IMAGES_EN+= vinum/vinum-striped.pic
# Images from the cross-document image library
IMAGES_LIB= callouts/1.png
IMAGES_LIB+= callouts/2.png
IMAGES_LIB+= callouts/3.png
IMAGES_LIB+= callouts/4.png
IMAGES_LIB+= callouts/5.png
IMAGES_LIB+= callouts/6.png
IMAGES_LIB+= callouts/7.png
IMAGES_LIB+= callouts/8.png
IMAGES_LIB+= callouts/9.png
IMAGES_LIB+= callouts/10.png
#
# SRCS lists the individual SGML files that make up the document. Changes
# to any of these files will force a rebuild
#
# SGML content
SRCS+= audit/chapter.sgml
SRCS+= book.sgml
SRCS+= colophon.sgml
SRCS+= freebsd-glossary.sgml
SRCS+= advanced-networking/chapter.sgml
SRCS+= basics/chapter.sgml
SRCS+= bibliography/chapter.sgml
SRCS+= boot/chapter.sgml
SRCS+= config/chapter.sgml
SRCS+= cutting-edge/chapter.sgml
SRCS+= desktop/chapter.sgml
SRCS+= disks/chapter.sgml
SRCS+= eresources/chapter.sgml
SRCS+= firewalls/chapter.sgml
SRCS+= geom/chapter.sgml
SRCS+= install/chapter.sgml
SRCS+= introduction/chapter.sgml
SRCS+= kernelconfig/chapter.sgml
SRCS+= l10n/chapter.sgml
SRCS+= linuxemu/chapter.sgml
SRCS+= mac/chapter.sgml
SRCS+= mail/chapter.sgml
SRCS+= mirrors/chapter.sgml
SRCS+= multimedia/chapter.sgml
SRCS+= network-servers/chapter.sgml
SRCS+= pgpkeys/chapter.sgml
SRCS+= ports/chapter.sgml
SRCS+= ppp-and-slip/chapter.sgml
SRCS+= preface/preface.sgml
SRCS+= printing/chapter.sgml
SRCS+= security/chapter.sgml
SRCS+= serialcomms/chapter.sgml
SRCS+= users/chapter.sgml
SRCS+= vinum/chapter.sgml
SRCS+= x11/chapter.sgml
# Entities
SRCS+= chapters.ent
SYMLINKS= ${DESTDIR} index.html handbook.html
# Turn on all the chapters.
CHAPTERS?= ${SRCS:M*chapter.sgml}
SGMLFLAGS+= ${CHAPTERS:S/\/chapter.sgml//:S/^/-i chap./}
SGMLFLAGS+= -i chap.freebsd-glossary
pgpkeyring: pgpkeys/chapter.sgml
@${JADE} -V nochunks ${OTHERFLAGS} ${JADEOPTS} -d ${DSLPGP} -t sgml ${MASTERDOC}
#
# Handbook-specific variables
#
.if defined(WITH_PGPKEYS)
JADEFLAGS+= -V withpgpkeys
.endif
URL_RELPREFIX?= ../../../..
DOC_PREFIX?= ${.CURDIR}/../../..
#
# rules generating lists of mirror site from XML database.
#
XMLDOCS= mirrors-ftp:::mirrors.sgml.ftp.inc.tmp \
mirrors-cvsup:::mirrors.sgml.cvsup.inc.tmp \
eresources:::eresources.sgml.www.inc.tmp
DEPENDSET.DEFAULT= transtable mirror
XSLT.DEFAULT= ${XSL_MIRRORS}
XML.DEFAULT= ${XML_MIRRORS}
NO_TIDY.DEFAULT= yes
PARAMS.mirrors-ftp+= --param 'type' "'ftp'" \
--param 'proto' "'ftp'" \
--param 'target' "'handbook/mirrors/chapter.sgml'"
PARAMS.mirrors-cvsup+= --param 'type' "'cvsup'" \
--param 'proto' "'cvsup'" \
--param 'target' "'handbook/mirrors/chapter.sgml'"
PARAMS.eresources+= --param 'type' "'www'" \
--param 'proto' "'http'" \
--param 'target' "'handbook/eresources/chapter.sgml'"
SRCS+= mirrors.sgml.ftp.inc \
mirrors.sgml.cvsup.inc \
eresources.sgml.www.inc
CLEANFILES+= mirrors.sgml.ftp.inc mirrors.sgml.ftp.inc.tmp \
mirrors.sgml.cvsup.inc mirrors.sgml.cvsup.inc.tmp \
eresources.sgml.www.inc eresources.sgml.www.inc.tmp
.include "${DOC_PREFIX}/share/mk/doc.project.mk"
.for p in ftp cvsup
mirrors.sgml.${p}.inc: mirrors.sgml.${p}.inc.tmp
${SED} -e 's,<\([^ >]*\)\([^>]*\)/>,<\1\2>\1>,;s,,,'\
< $@.tmp > $@ || (${RM} -f $@ && false)
.endfor
eresources.sgml.www.inc: eresources.sgml.www.inc.tmp
${SED} -e 's,<\([^ >]*\)\([^>]*\)/>,<\1\2>\1>,;s,,,'\
< $@.tmp > $@ || (${RM} -f $@ && false)
diff --git a/zh_TW.Big5/books/handbook/audit/chapter.sgml b/zh_TW.Big5/books/handbook/audit/chapter.sgml
index ceb4525a83..36bdcef9df 100644
--- a/zh_TW.Big5/books/handbook/audit/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/audit/chapter.sgml
@@ -1,531 +1,571 @@
-
-
-
TomRhodesWritten by
- Kernel Event Auditing
+ Security Event AuditingSynopsisAUDIT
- Kernel Event Auditing
+ Security Event AuditingMAC
- The &os; 6.0 operating system release has included
+ The &os; 7-CURRENT development branch includes
support for Event Auditing based on the &posix;.1e draft and
- the &sun; BSM implementation. Event auditing
- permits the selective logging of security-relevant system events
- for the purposes of system analysis, system monitoring, and
- security evaluation.
+ Sun's published BSM API and file format.
+ Event auditing permits the selective logging of security-relevant
+ system events for the purposes of post-mortem analysis, system
+ monitoring, and intrusion detection. After some settling time in
+ &os; 7-CURRENT, this support will be merged to &os; 6-STABLE
+ and appear in subsequent releases.
+
+
+ The audit facility in FreeBSD is considered experimental, and
+ production deployment should occur only after careful consideration
+ of the risks of deploying experimental software.
+ This chapter will focus mainly on the installation and
configuration of Event Auditing. Explanation of audit policies,
and an example configuration will be provided for the
convenience of the reader.After reading this chapter, you will know:What Event Auditing is and how it works.How to configure Event Auditing on &os; for users
and processes.Before reading this chapter, you should:Understand &unix; and &os; basics
().Be familiar with the basics of kernel
configuration/compilation
().Have some familiarity with security and how it
pertains to &os; ().Event auditing can generate a great deal of log file
- data, exceeding gigabytes a week in some configurations. An administrator
- should read this chapter in its entirety to avoid possible
- self inflicted DoS attacks due to improper
- configuration.
+ data, exceeding gigabytes a week in some configurations. An
+ administrator should read this chapter in its entirety to avoid
+ possible self-inflicted DoS attacks due to
+ improper configuration.
The implementation of Event Auditing in &os; is similar to
that of the &sun; Basic Security Module, or BSM
library. Thus, the configuration is almost completely
- interchangeable with &solaris; and Darwin operating systems.
+ interchangeable with &solaris; and Mac OS X/Darwin operating
+ systems.
Key Terms - Words to KnowBefore reading this chapter, a few key terms must be
explained. This is intended to clear up any confusion that
may occur and to avoid the abrupt introduction of new terms
and information.
- class: A class specifies the category
- different actions the system are placed in. For example,
- use of &man.login.1; could be placed in a class.
+ event: An auditable event is
+ an event that can be logged using the audit subsystem. The
+ administrator can configure which events will be audited.
+ Examples of security-relevant events include the creation of
+ a file, the building of a network connection, or the logging
+ in of a user. Events are either attributable,
+ meaning that they can be traced back to a user
+ authentication, or non-attributable. Examples
+ of non-attributable events are any events that occur before
+ authentication has succeeded in the login process, such as
+ failed authentication attempts.
- event: An event could be considered
- an action taken on the system. Creating a file would be
- an event.
+ class: Events may be assigned to
+ one or more classes, usually based on the general category
+ of the events, such as file creation,
+ file access, or network. Login
+ and logout events are assigned to the lo
+ class. The use of classes allows the administrator to
+ specify high level auditing rules without having to specify
+ whether each individual auditable operation will be logged.
- record: A record is a log or a note
- about a specific action.
+ record: A record is a log entry
+ describing a security event. Records typically have a
+ record event type, information on the subject (user) associated
+ with the event, time information, information on any objects,
+ such as files, and information on whether the event corresponded
+ to a successful operation.
+
+ trail: An audit trail, or log file,
+ consists of a series of audit records describing security
+ events. Typically, trails are in roughly chronological
+ order with respect to the time events completed. Only
+ authorized processes are allowed to commit records to the
+ audit trail.
+
prefix: A prefix is considered to
be the configuration element used to toggle auditing for
success and failed events.Installing Audit Support
- Support for Event Auditing should have been installed with
+ Support for Event Auditing is installed with
the normal installworld process. An
administrator may confirm this by viewing the contents
of /etc/security. Files
beginning with the word audit should be present.
For example, audit_event.In-kernel support for the framework must also exist. This
may be done by adding the following lines to the local kernel
configuration file:options AUDITRebuild and reinstall
the kernel via the normal process explained in
.Once completed, enable the audit daemon by adding the
following line to &man.rc.conf.5;:auditd_enable="YES"Functionality not provided by the default may be added
here with the option.Audit Configuration
- By default, all configuration is done within the realm of
- /etc/security and the
- files contained within. The following files must be present
- before the audit daemon is started:
+ All configuration files for security audit are found in
+ /etc/security. The following
+ files must be present before the audit daemon is started:audit_class - Contains the
definitions of the audit classes.audit_control - Controls aspects
of the audit subsystem, such as default audit classes,
minimum disk space to leave on the audit log volume,
etc.audit_event - Defines the kernel
audit events. These map, mostly, to system calls.audit_user - The events to audit
- for individual users. A user name does not need to appear
- in here.
+ for individual users. Users not appearing here will be
+ subject to the default configuration in the control
+ configuration file.
audit_warn - A shell script
- used by auditd to form warning messages.
+ used by auditd to generate warning messages in
+ exceptional situations, such as when space for audit
+ records is running low.
- If these files do not exist, for whatever reason, they can
- be installed easily by issuing the following commands:
-
- &prompt.root; cd /usr/src/contrib/bsm/etc && make install
-
Audit File SyntaxThe configuration file syntax is rather arcane, albeit easy
to work with. One thing an administrator must be leery about
is overriding system defaults. This could create potential
openings for audit data to not be collected properly.The audit subsystem will accept both the short name and
long name with regards to configuration syntax. A syntax
map has been included below.The following list contains all supported audit
classes: - all - All
audit flags set. - administrative
- Administrative actions performed on the system as a
whole. - application -
Application defined action. - file_close -
Audit calls to the close system
call. - exec - Audit
program or utility execution. - file_attr_acc
- Audit the access of object attributes such as
&man.stat.1;, &man.pathconf.2; and similar events. - file_creation
- Audit events where a file is created as a result. - file_deletion
- Audit events where file deletion occurs. - file_attr_mod
- Audit events where file attribute modification occurs,
such as &man.chown.8;, &man.chflags.1;, &man.flock.2;,
etc. - file_read
- Audit events in which data is read, files are opened for
reading, etc. - file_write -
Audit events in which data is written, files are written
or modified, etc. - ioctl - Audit
use of the &man.ioctl.2; system call. - ipc - Audit
- System V IPC operations.
+ various forms of Inter-Process Communication, including POSIX
+ pipes and System V IPC operations.
- login_logout -
Audit &man.login.1; and &man.logout.1; events occurring
on the system. - non_attrib -
Audit non-attributable events. - no_class -
Null class used to disable event auditing. - network -
Audit events related to network actions, such as
&man.connect.2; and &man.accept.2;. - other -
Audit miscellaneous events. - process -
Audit process operations, such as &man.exec.3; and
&man.exit.3;.
-
-
- - tfm -
- I HAVE NO CLUE!
- Following is a list of all supported audit prefixes:none - Audit both the success
or failure of an event. For example, just listing a
class will result in the auditing of both success and
failure.+ - Audit successful events
only.- - Audit failed events
only.Using the class with either the
positive or negative prefix can generate a large amount
of data at an extremely rapid rate.Extra prefixes used to modify the default configuration
values:^- - Disable auditing of failed events.^+ - Enable auditing of successful events.^ - Disable auditing of both successful and failed
events.Configuration Files
- Configuration is set in only two files, the first being
- audit_control and
- audit_user being the second. The first
- is system-wide, controlling every aspect of event auditing
- in the system. The latter may be used for fine grained user
- auditing.
+ In most cases, administrators will need to modify only two files
+ when configuring the audit system: audit_control
+ and audit_user. The first controls system-wide
+ audit paramaters and defaults for both attributable and
+ non-attributable events. The second may be used to tune the level
+ and nature of auditing for individual users.The audit_control File
- The audit_control contains some basic
+ The audit_control file contains some basic
defaults that the administrator may wish to modify. Perhaps
even set some new ones. Viewing the contents of this file,
we see the following:dir:/var/audit
-flags:lo,ad,-all,^-fa,^-fc,^-cl
+flags:lo
minfree:20
naflags:lo
- The is used to set the default
- directory where audit logs are stored.
-
- The is used to set the system-wide
- defaults. The current setting,
+ The option is used to set the default
+ directory where audit logs are stored. Audit is frequently
+ configured so that audit logs are stored on a dedicated file
+ system, so as to prevent interference between the audit
+ subsystem and other subsystems when file systems become full.
+
+
+ The option is used to set the
+ system-wide defaults. The current setting,
+ configures the auditing of all &man.login.1; and &man.logout.1;
+ actions. A more complex example,
audits all system
&man.login.1; and &man.logout.1; actions, all administrator
- actions, all failed events in the system, and finally disable
+ actions, all failed events in the system, and finally disables
auditing of failed attempts for ,
, and . Even though
the turned on the auditing of all
failed attempts, the prefix will override
that for the latter options.Notice that the previous paragraph shows the file is
read from left to right. As such, values further on the
right side may override a previous value specified to
its left.The option defines the minimum
percentage of free space for audit file systems. This
relates to the file system where audit logs are stored.
For example, if the specifies
/var/audit and
is set to twenty (20), warning
messages will be generated when the
/var file system grows
to eighty (80) percent full.The option specifies audit
- flags to be considered non attributable; i.e.: classes of
- events which cannot be attributed to a specific user
- on the system. This can be overridden with the
- audit_user configuration file.
+ classes to be audited for non-attributed events —
+ that is, events for which there is no authenticated user.
+ The audit_user File
- The audit_user permits the
- administrator to map audit specific events to directly
- to users. This adds a finer-grained control mechanism
- for all system users.
+ The audit_user file permits the
+ administrator to determine which classes of audit events
+ should be logged for which system users.The following is the defaults currently placed in
the audit_user file:root:lo:no
audit:fc:noNotice how the default is to audit all cases of
login/logout
and disable auditing of all other actions for
root. This configuration
also audits all file creation and disables all
other auditing for the audit
user. While event auditing does not require a special
user exist, some configurations, specifically environments
- making use of MAC may require it.
+ making use of MAC, may require it.
Event Audit Administration
- Events from the auditd daemon cannot
+ Events written by the kernel audit subsystem cannot
be altered or read in plain text. Data is stored and accessed
- in a method similar to that of &man.ktrace.1; and &man.kdump.1,
+ in a method similar to that of &man.ktrace.1; and &man.kdump.1;,
that is, they may only be viewed by dumping them using the
- praudit or auditreduce
- utilities.
+ praudit command; audit trails may be reduced
+ using the auditreduce command, which selects
+ records from an audit trail based on properties of interest, such
+ as the user, time of the event, and type of operation.
- There are two utilities because of different requirements.
- For example, the praudit will dump the entire
- contents of a specified audit log in plain text. To dump an
+ For example, the praudit utility will dump the
+ entire contents of a specified audit log in plain text. To dump an
audit log in its entirety, use:&prompt.root; praudit /var/audit/AUDITFILEWhere AUDITFILE is the audit log
of viewing choice. Since audit logs may contain enormous
amounts of data, an administrator may prefer to select records
for specific users. This is made possible with the following
command, where trhodes is the user of
choice:
- &prompt.root; auditreduce -e trhodes /var/audit/AUDITFILE
+ &prompt.root; auditreduce -e trhodes /var/audit/AUDITFILE | prauditThis will select all audit records produced by the user
trhodes stored in the
AUDITFILE file.There are several other options available for reading audit
records, see the aforementioned command's manual pages for
a more in depth explanation.Rotating Audit Log Files
- Manually rotating audit log files will cause great
- havoc within the system. Therefore, adding a line to
- &man.newsyslog.conf.5; will provide no usefulness. So how
- are the logs to be rotated? Sending the appropriate flag
- to the audit utility will shut down
- event auditing and safely rotate. The following command
- should handle everything for an administrator:
+ Due to log reliability requirements, audit trails
+ are written to only by the kernel, and managed only by
+ auditd. Administrators should not
+ attempt to use &man.newsyslog.conf.5; or other tools to
+ directly rotate audit logs. Instead, the audit
+ management tool should be used to shut down auditing,
+ reconfigure the audit system, and perform log rotation.
+ The following command causes the audit daemon to create a
+ new audit log and signal the kernel to switch to using the
+ new log. The old log will be terminated and renamed, at
+ which point it may then be manipulated by the administrator.&prompt.root; audit -nIf the auditd daemon is not currently
running, the previous command will fail and an error message
will be produced.Adding the following line to
/etc/crontab will force the rotation
every twelve hours from &man.cron.8;:* */12 * * * root /usr/sbin/audit -nThe change will take effect once you have saved the
new /etc/crontab.
+
+
+ Delegating Audit Review Rights
+
+ By default, only the root user has the right to read system audit
+ logs. However, that right may be delegated to members of the
+ audit group, as the audit directory and audit
+ trail files are assigned to that group, and made group-readable. As
+ the ability to track audit log contents provides significant insight
+ into the behavior of users and processes, it is recommended that the
+ delegation of audit review rights be performed with caution.
+
diff --git a/zh_TW.Big5/books/handbook/basics/chapter.sgml b/zh_TW.Big5/books/handbook/basics/chapter.sgml
index 98054a02e6..e9dc78b35c 100644
--- a/zh_TW.Big5/books/handbook/basics/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/basics/chapter.sgml
@@ -1,2547 +1,2538 @@
ChrisShumwayRewritten by UNIX 基礎概念概述接下來的這一章將含蓋 FreeBSD 作業系統的基本指令及功能。
大部份的內容在 &unix;-like 作業系統中都是相通的。
如果您對這些內容熟悉的話,可以放心的跳過。
如果您剛接觸 FreeBSD ,那您一定要仔細的讀完這章。讀完這一章,您將會了解:如何使用 FreeBSD 的virtual consoles。&unix; 檔案權限運作的方式以及 &os; 中檔案的 flags。預設的 &os; 檔案系統配置。&os; 的磁碟結構。如何掛載(mount)、卸載(umount)檔案系統什麼是processes 、 daemons 以及 signals 。什麼是 shell ,以及如何變更您預設的登入環境。如何使用基本的文字編輯器。什麼是 devices 和 device nodes 。&os; 下使用的 binary 格式。如何閱讀 manual pages 以獲得更多的資訊。Virtual Consoles 和終端機virtual consolesterminals
- FreeBSD 的使用方式有很多種,其中一種就是在文字終端機上打字。
+ 有很多方法可以操作 FreeBSD ,其中一種就是在文字終端機上打字。
如此使用 FreeBSD 即可輕易的體會到 &unix; 作業系統的威力和彈性。
這一節描述什麼是終端機和console,及以您在 FreeBSD 中可以怎麼使用它們。
The Consoleconsole如果您沒有將 FreeBSD 設定成開機時自動進入圖形化模式,系統會在啟動的 script 跑完之後顯示登入的提示符號。
您將會看到像是這樣的東西:Additional ABI support:.
Local package initialization:.
Additional TCP options:.
Fri Sep 20 13:01:06 EEST 2002
FreeBSD/i386 (pc3.example.org) (ttyv0)
login:這個訊息在您的系統上會有些許的不同,但是應該會看到類似的東西。
我們感興趣的是最後兩行,最後兩行是:FreeBSD/i386 (pc3.example.org) (ttyv0)這行包含了剛開機完系統的資訊。 您看到的是在 Intel 或相容處理器的 x86
架構上執行的FreeBSD的 console這就是 i386 的意義。
注意即使您不是在 Intel 的 386 處理器上執行 FreeBSD ,一樣是i386。
這不是指你的處理器的型號,這裡顯示的是你處理器的架構。
這台機器的名字 (每台 &unix; 機器都有一個名字) 是 pc3.example.org
,而您現在看到的是它的系統 console— ttyv0終端機。最後的一行應該都會是:login:這是您應該要輸入您的帳號名稱的地方。
下一小節將描述如何登入 FreeBSD。
登入 FreeBSDFreeBSD 是一個 multiuser 、 multiprocessing 的系統。
這是一個正式的名稱,指的是一個在單一機器上可以同時被不同的人使用,同時可以執行很多程式的系統。每一種多使用者系統都需要可以分辨不同使用者的方法。
在 FreeBSD (以及所有的 &unix;-like 作業系統) 中,所有的使用者在執行程式之前必須先登入系統。
每個使用者都有一組獨特的帳號名稱(username)及密碼(password)
。FreeBSD 在允許使用者執行程式前將會先問這兩個問題。
startup scripts在 FreeBSD 開機並跑完起動的 script 之後
這些起動的 script 是在開機的時候 FreeBSD 會自動執行的程式。
他們主要的功能是將所有該執行的東西設定好,並將您設定成背景執行的服務啟動。
,它將會印出提示字元要求您輸入正確的帳號名稱:login:在這個範例裡,我們假設您的帳號是john。
在提示字元處輸入john並按下Enter,您應該會看到另一個提示字元要您輸入密碼:login: john
Password:輸入 john 的密碼, 再按下
Enter。 輸入的密碼 不會顯示在螢幕上。
您不需要擔心這個,這樣做是為了安全上的問題。如果您輸入了正確的密碼,您應該已經登入 FreeBSD,可以嘗試所有可用的指令了。您應該會看到MOTD (即今日訊息、Messages Of The Day),後面接著命令提示字元
(一個 #,$, 或是 % 字元)。
這就表示您已經成功登入 FreeBSD 了。
- Multiple Consoles
-
- Running &unix; commands in one console is fine, but FreeBSD can
- run many programs at once. Having one console where commands can be
- typed would be a bit of a waste when an operating system like FreeBSD
- can run dozens of programs at the same time. This is where
- virtual consoles can be very helpful.
-
- FreeBSD can be configured to present you with many different
- virtual consoles. You can switch from one of them to any other
- virtual console by pressing a couple of keys on your keyboard. Each
- console has its own different output channel, and FreeBSD takes care
- of properly redirecting keyboard input and monitor output as you
- switch from one virtual console to the next.
-
- Special key combinations have been reserved by FreeBSD for
- switching consoles
- A fairly technical and accurate description of all the details
- of the FreeBSD console and keyboard drivers can be found in the
- manual pages of &man.syscons.4;, &man.atkbd.4;, &man.vidcontrol.1;
- and &man.kbdcontrol.1;. We will not expand on the details here,
- but the interested reader can always consult the manual pages for
- a more detailed and thorough explanation of how things
- work.
- . You can use
- AltF1,
- AltF2, through
- AltF8 to switch
- to a different virtual console in FreeBSD.
-
- As you are switching from one console to the next, FreeBSD takes
- care of saving and restoring the screen output. The result is an
- illusion of having multiple virtual
- screens and keyboards that you can use to type commands for
- FreeBSD to run. The programs that you launch on one virtual console
- do not stop running when that console is not visible. They continue
- running when you have switched to a different virtual console.
+ 多重 Console
+
+ 在一個 Console 下執行 &unix; 當然是沒有問題,然而FreeBSD是可以同時執行很多程式的。
+ 像 FreeBSD 這樣可以同時執行一大堆程式的作業系統,只有一個 console 可以輸入指令是有點浪費。
+ 在此virtual consoles就很有用了。
+
+
+ FreeBSD 可以被設定成同時有很多 virtual console ,用幾個按鍵的組合就可以從一個 virtual console 跳到別的 virtual console 去。 每一個 console 都有自已不同的輸出頻道, 當從某一個 virtual console 切換到下一個的時候,FreeBSD 會適當的處理鍵盤輸入及螢幕輸出。
+
+ FreeBSD 保留了特別的按鍵組合來切換 console
+
+ 在 &man.syscons.4;、 &man.atkbd.4;、 &man.vidcontrol.1;、以及
+ &man.kbdcontrol.1;等 manual page 中,對於 FreeBSD 的 console
+ 及鍵盤驅動程式有十分技術性且詳細的描述。
+ 我們在這裡不討論細節,有興趣的讀者隨時可以在 manual page
+ 中查到關於運作方式的更詳細且完整的解釋
+ 。 您可以用
+ AltF1、
+ AltF2、到
+ AltF8來切換 FreeBSD
+ 的不同 console。
+
+
+ 當您從一個 console 切換到下一個的時候, FreeBSD 會處理螢幕輸出的儲存及回復。
+ 這就好像有很多虛擬的螢幕和鍵盤可以讓您輸入指令給
+ FreeBSD 執行。 在某一個 console 上執行的程式並不會因為切到別的 console
+ 而停止執行,當您切換到另一個 console 的時候,他們會繼續執行。
+ The /etc/ttys FileThe default configuration of FreeBSD will start up with eight
virtual consoles. This is not a hardwired setting though, and
you can easily customize your installation to boot with more
or fewer virtual consoles. The number and settings of the
virtual consoles are configured in the
/etc/ttys file.You can use the /etc/ttys file to configure
the virtual consoles of FreeBSD. Each uncommented line in this file
(lines that do not start with a # character) contains
settings for a single terminal or virtual console. The default
version of this file that ships with FreeBSD configures nine virtual
consoles, and enables eight of them. They are the lines that start with
ttyv:# name getty type status comments
#
ttyv0 "/usr/libexec/getty Pc" cons25 on secure
# Virtual terminals
ttyv1 "/usr/libexec/getty Pc" cons25 on secure
ttyv2 "/usr/libexec/getty Pc" cons25 on secure
ttyv3 "/usr/libexec/getty Pc" cons25 on secure
ttyv4 "/usr/libexec/getty Pc" cons25 on secure
ttyv5 "/usr/libexec/getty Pc" cons25 on secure
ttyv6 "/usr/libexec/getty Pc" cons25 on secure
ttyv7 "/usr/libexec/getty Pc" cons25 on secure
ttyv8 "/usr/X11R6/bin/xdm -nodaemon" xterm off secureFor a detailed description of every column in this file and all
the options you can use to set things up for the virtual consoles,
consult the &man.ttys.5; manual page.Single User Mode ConsoleA detailed description of what single user mode is
can be found in . It is worth noting
that there is only one console when you are running FreeBSD in single
user mode. There are no virtual consoles available. The settings of
the single user mode console can also be found in the
/etc/ttys file. Look for the line that starts
with console:# name getty type status comments
#
# If console is marked "insecure", then init will ask for the root password
# when going to single-user mode.
console none unknown off secureAs the comments above the console line
indicate, you can edit this line and change secure to
insecure. If you do that, when FreeBSD boots
into single user mode, it will still ask for the
root password.Be careful when changing this to
insecure. If you ever forget
the root password, booting into single user
mode is a bit involved. It is still possible, but it might be a bit
hard for someone who is not very comfortable with the FreeBSD
booting process and the programs involved.PermissionsUNIXFreeBSD, being a direct descendant of BSD &unix;, is based on
several key &unix; concepts. The first and
most pronounced is that FreeBSD is a multi-user operating system.
The system can handle several users all working simultaneously on
completely unrelated tasks. The system is responsible for properly
sharing and managing requests for hardware devices, peripherals,
memory, and CPU time fairly to each user.Because the system is capable of supporting multiple users,
everything the system manages has a set of permissions governing who
can read, write, and execute the resource. These permissions are
stored as three octets broken into three pieces, one for the owner of
the file, one for the group that the file belongs to, and one for
everyone else. This numerical representation works like
this:permissionsfile permissionsValuePermissionDirectory Listing0No read, no write, no execute---1No read, no write, execute--x2No read, write, no execute-w-3No read, write, execute-wx4Read, no write, no executer--5Read, no write, executer-x6Read, write, no executerw-7Read, write, executerwxlsdirectoriesYou can use the command line
argument to &man.ls.1; to view a long directory listing that
includes a column with information about a file's permissions
for the owner, group, and everyone else. For example, a
ls -l in an arbitrary directory may show:&prompt.user; ls -l
total 530
-rw-r--r-- 1 root wheel 512 Sep 5 12:31 myfile
-rw-r--r-- 1 root wheel 512 Sep 5 12:31 otherfile
-rw-r--r-- 1 root wheel 7680 Sep 5 12:31 email.txt
...Here is how the first column of ls -l is
broken up:-rw-r--r--The first (leftmost) character
tells if this file is a regular file, a directory, a special
character device, a socket, or any other special
pseudo-file device. In this case, the -
indicates a regular file. The next three characters,
rw- in this example, give the permissions for the owner of the
file. The next three characters, r--, give the
permissions for the group that the file belongs to. The final three
characters, r--, give the permissions for the
rest of the world. A dash means that the permission is turned off.
In the case of this file, the permissions are set so the owner can
read and write to the file, the group can read the file, and the
rest of the world can only read the file. According to the table
above, the permissions for this file would be
644, where each digit represents the three parts
of the file's permission.This is all well and good, but how does the system control
permissions on devices? FreeBSD actually treats most hardware
devices as a file that programs can open, read, and write data to
just like any other file. These special device files are stored on
the /dev directory.Directories are also treated as files. They have read, write,
and execute permissions. The executable bit for a directory has a
slightly different meaning than that of files. When a directory is
marked executable, it means it can be traversed into, that is, it is
possible to cd (change directory) into it. This also means that
within the directory it is possible to access files whose names are
known (subject, of course, to the permissions on the files
themselves).In particular, in order to perform a directory listing,
read permission must be set on the directory, whilst to delete a file
that one knows the name of, it is necessary to have write
and execute permissions to the directory
containing the file.There are more permission bits, but they are primarily used in
special circumstances such as setuid binaries and sticky
directories. If you want more information on file permissions and
how to set them, be sure to look at the &man.chmod.1; manual
page.TomRhodesContributed by Symbolic PermissionspermissionssymbolicSymbolic permissions, sometimes referred to as symbolic expressions,
use characters in place of octal values to assign permissions to files
or directories. Symbolic expressions use the syntax of (who) (action)
(permissions), where the following values are available:OptionLetterRepresents(who)uUser(who)gGroup owner(who)oOther(who)aAll (world)(action)+Adding permissions(action)-Removing permissions(action)=Explicitly set permissions(permissions)rRead(permissions)wWrite(permissions)xExecute(permissions)tSticky bit(permissions)sSet UID or GIDThese values are used with the &man.chmod.1; command
just like before, but with letters. For an example, you could use
the following command to block other users from accessing
FILE:&prompt.user; chmod go= FILEA comma separated list can be provided when more than one set
of changes to a file must be made. For example the following command
will remove the groups and world write permission
on FILE, then it adds the execute
permissions for everyone:&prompt.user; chmod go-w,a+x FILETomRhodesContributed by &os; File FlagsIn addition to file permissions discussed previously, &os;
supports the use of file flags. These flags
add an additional level of security and control over files, but
not directories.These file flags add an additional level of control over
files, helping to ensure that in some cases not even the
root can remove or alter files.File flags are altered by using the &man.chflags.1; utility,
using a simple interface. For example, to enable the system
undeletable flag on the file file1,
issue the following command:&prompt.root; chflags sunlink file1And to disable the system undeletable flag, simply
issue the previous command with no in
front of the . Observe:&prompt.root; chflags nosunlink file1To view the flags of this file, use the &man.ls.1;
with the flags:&prompt.root; ls -lo file1The output should look like the following:-rw-r--r-- 1 trhodes trhodes sunlnk 0 Mar 1 05:54 file1Several flags may only added or removed to files by the
root user. In other cases, the file owner
may set these flags. It is recommended an administrator read
over the &man.chflags.1; and &man.chflags.2; manual pages for
more information.Directory Structuredirectory hierarchyThe FreeBSD directory hierarchy is fundamental to obtaining
an overall understanding of the system. The most important
concept to grasp is that of the root directory,
/. This directory is the first one mounted at
boot time and it contains the base system necessary to prepare
the operating system for multi-user operation. The root
directory also contains mount points for every other file system
that you may want to mount.A mount point is a directory where additional file systems can
be grafted onto the root file system.
This is further described in .
Standard mount points include
/usr, /var, /tmp,
/mnt, and /cdrom. These
directories are usually referenced to entries in the file
/etc/fstab. /etc/fstab is
a table of various file systems and mount points for reference by the
system. Most of the file systems in /etc/fstab
are mounted automatically at boot time from the script &man.rc.8;
unless they contain the option.
Details can be found in .A complete description of the file system hierarchy is
available in &man.hier.7;. For now, a brief overview of the
most common directories will suffice.DirectoryDescription/Root directory of the file system./bin/User utilities fundamental to both single-user
and multi-user environments./boot/Programs and configuration files used during
operating system bootstrap./boot/defaults/Default bootstrapping configuration files; see
&man.loader.conf.5;./dev/Device nodes; see &man.intro.4;./etc/System configuration files and scripts./etc/defaults/Default system configuration files; see &man.rc.8;./etc/mail/Configuration files for mail transport agents such
as &man.sendmail.8;./etc/namedb/named configuration files; see
&man.named.8;./etc/periodic/Scripts that are run daily, weekly, and monthly,
via &man.cron.8;; see &man.periodic.8;./etc/ppp/ppp configuration files; see
&man.ppp.8;./mnt/Empty directory commonly used by system administrators as a
temporary mount point./proc/Process file system; see &man.procfs.5;,
&man.mount.procfs.8;./rescue/Statically linked programs for emergency recovery; see
&man.rescue.8;./root/Home directory for the root
account./sbin/System programs and administration utilities fundamental to
both single-user and multi-user environments./stand/Programs used in a standalone environment./tmp/Temporary files. The contents of
/tmp are usually NOT
preserved across a system reboot. A memory-based file system
is often mounted at
/tmp.
This can be automated using the tmpmfs-related variables of
&man.rc.conf.5; (or with an entry in
/etc/fstab; see &man.mdmfs.8;,
or for FreeBSD 4.X, &man.mfs.8;)./usr/The majority of user utilities and applications./usr/bin/Common utilities, programming tools, and applications./usr/include/Standard C include files./usr/lib/Archive libraries./usr/libdata/Miscellaneous utility data files./usr/libexec/System daemons & system utilities (executed by other
programs)./usr/local/Local executables, libraries, etc. Also used as
the default destination for the FreeBSD ports
framework. Within /usr/local,
the general layout sketched out by &man.hier.7; for
/usr should be used. Exceptions
are the man directory, which is directly under
/usr/local rather than under
/usr/local/share, and the ports
documentation is in
share/doc/port.
/usr/obj/Architecture-specific target tree produced by building
the /usr/src tree./usr/portsThe FreeBSD Ports Collection (optional)./usr/sbin/System daemons & system utilities (executed by users)./usr/share/Architecture-independent files./usr/src/BSD and/or local source files./usr/X11R6/X11R6 distribution executables, libraries, etc
(optional)./var/Multi-purpose log, temporary, transient, and spool files.
A memory-based file system is sometimes mounted at
/var.
This can be automated using the varmfs-related variables of
&man.rc.conf.5 (or with an entry in
/etc/fstab; see &man.mdmfs.8;,
or for FreeBSD 4.X, &man.mfs.8;)./var/log/Miscellaneous system log files./var/mail/User mailbox files./var/spool/Miscellaneous printer and mail system spooling directories.
/var/tmp/Temporary files.
The files are usually preserved across a system reboot,
unless /var
is a memory-based file system./var/ypNIS maps.Disk OrganizationThe smallest unit of organization that FreeBSD uses to find files
is the filename. Filenames are case-sensitive, which means that
readme.txt and README.TXT
are two separate files. FreeBSD does not use the extension
(.txt) of a file to determine whether the file is
a program, or a document, or some other form of data.Files are stored in directories. A directory may contain no
files, or it may contain many hundreds of files. A directory can also
contain other directories, allowing you to build up a hierarchy of
directories within one another. This makes it much easier to organize
your data.Files and directories are referenced by giving the file or
directory name, followed by a forward slash, /,
followed by any other directory names that are necessary. If you have
directory foo, which contains directory
bar, which contains the file
readme.txt, then the full name, or
path to the file is
foo/bar/readme.txt.Directories and files are stored in a file system. Each file system
contains exactly one directory at the very top level, called the
root directory for that file system. This root
directory can then contain other directories.So far this is probably similar to any other operating system you
may have used. There are a few differences; for example, &ms-dos; uses
\ to separate file and directory names, while &macos;
uses :.FreeBSD does not use drive letters, or other drive names in the
path. You would not write c:/foo/bar/readme.txt
on FreeBSD.Instead, one file system is designated the root
file system. The root file system's root directory is
referred to as /. Every other file system is then
mounted under the root file system. No matter
how many disks you have on your FreeBSD system, every directory
appears to be part of the same disk.Suppose you have three file systems, called A,
B, and C. Each file system has
one root directory, which contains two other directories, called
A1, A2 (and likewise
B1, B2 and
C1, C2).Call A the root file system. If you used the
ls command to view the contents of this directory
you would see two subdirectories, A1 and
A2. The directory tree looks like this: /
|
+--- A1
|
`--- A2A file system must be mounted on to a directory in another
file system. So now suppose that you mount file system
B on to the directory A1. The
root directory of B replaces A1,
and the directories in B appear accordingly: /
|
+--- A1
| |
| +--- B1
| |
| `--- B2
|
`--- A2Any files that are in the B1 or
B2 directories can be reached with the path
/A1/B1 or /A1/B2 as
necessary. Any files that were in /A1 have been
temporarily hidden. They will reappear if B is
unmounted from A.If B had been mounted on A2
then the diagram would look like this: /
|
+--- A1
|
`--- A2
|
+--- B1
|
`--- B2and the paths would be /A2/B1 and
/A2/B2 respectively.File systems can be mounted on top of one another. Continuing the
last example, the C file system could be mounted on
top of the B1 directory in the B
file system, leading to this arrangement: /
|
+--- A1
|
`--- A2
|
+--- B1
| |
| +--- C1
| |
| `--- C2
|
`--- B2Or C could be mounted directly on to the
A file system, under the A1
directory: /
|
+--- A1
| |
| +--- C1
| |
| `--- C2
|
`--- A2
|
+--- B1
|
`--- B2If you are familiar with &ms-dos;, this is similar, although not
identical, to the join command.This is not normally something you need to concern yourself with.
Typically you create file systems when installing FreeBSD and decide
where to mount them, and then never change them unless you add a new
disk.It is entirely possible to have one large root file system, and not
need to create any others. There are some drawbacks to this approach,
and one advantage.Benefits of Multiple File SystemsDifferent file systems can have different mount
options. For example, with careful planning, the
root file system can be mounted read-only, making it impossible for
you to inadvertently delete or edit a critical file. Separating
user-writable file systems, such as /home,
from other file systems also allows them to be mounted
nosuid; this option prevents the
suid/guid bits on
executables stored on the file system from taking effect, possibly
improving security.FreeBSD automatically optimizes the layout of files on a
file system, depending on how the file system is being used. So a
file system that contains many small files that are written
frequently will have a different optimization to one that contains
fewer, larger files. By having one big file system this
optimization breaks down.FreeBSD's file systems are very robust should you lose power.
However, a power loss at a critical point could still damage the
structure of the file system. By splitting your data over multiple
file systems it is more likely that the system will still come up,
making it easier for you to restore from backup as necessary.Benefit of a Single File SystemFile systems are a fixed size. If you create a file system when
you install FreeBSD and give it a specific size, you may later
discover that you need to make the partition bigger. This is not
easily accomplished without backing up, recreating the file system
with the new size, and then restoring the backed up data.FreeBSD 4.4 and later versions feature the &man.growfs.8;
command, which makes it possible to increase the size of
file system on the fly, removing this limitation.File systems are contained in partitions. This does not have the
same meaning as the common usage of the term partition (for example, &ms-dos;
partition), because of &os;'s &unix; heritage. Each partition is
identified by a letter from a through to
h. Each partition can contain only one file system,
which means that file systems are often described by either their
typical mount point in the file system hierarchy, or the letter of the
partition they are contained in.FreeBSD also uses disk space for swap
space. Swap space provides FreeBSD with
virtual memory. This allows your computer to
behave as though it has much more memory than it actually does. When
FreeBSD runs out of memory it moves some of the data that is not
currently being used to the swap space, and moves it back in (moving
something else out) when it needs it.Some partitions have certain conventions associated with
them.PartitionConventionaNormally contains the root file systembNormally contains swap spacecNormally the same size as the enclosing slice. This
allows utilities that need to work on the entire slice (for
example, a bad block scanner) to work on the
c partition. You would not normally create
a file system on this partition.dPartition d used to have a special
meaning associated with it, although that is now gone. To
this day, some tools may operate oddly if told to work on
partition d, so
sysinstall will not normally create
partition d.Each partition-that-contains-a-file-system is stored in what
FreeBSD calls a slice. Slice is FreeBSD's term
for what the common call partitions, and again, this is because of
FreeBSD's &unix; background. Slices are numbered, starting at 1,
through to 4.slicespartitionsdangerously dedicatedSlice numbers follow
the device name, prefixed with an s,
starting at 1. So da0s1
is the first slice on the first SCSI drive. There can only be
four physical slices on a disk, but you can have logical
slices inside physical slices of the appropriate type. These
extended slices are numbered starting at 5, so
ad0s5 is the first
extended slice on the first IDE disk. These devices are used by file
systems that expect to occupy a slice.Slices, dangerously dedicated physical
drives, and other drives contain
partitions, which are represented as
letters from a to h.
This letter is appended to the device name, so
da0a is the a partition on
the first da drive, which is dangerously dedicated.
ad1s3e is the fifth partition
in the third slice of the second IDE disk drive.Finally, each disk on the system is identified. A disk name
starts with a code that indicates the type of disk, and then a number,
indicating which disk it is. Unlike slices, disk numbering starts at
0. Common codes that you will see are listed in
.When referring to a partition FreeBSD requires that you also name
the slice and disk that contains the partition, and when referring to
a slice you should also refer to the disk name. Do this by listing
the disk name, s, the slice number, and then the
partition letter. Examples are shown in
. shows a conceptual
model of the disk layout that should help make things clearer.In order to install FreeBSD you must first configure the disk
slices, then create partitions within the slice you will use for
FreeBSD, and then create a file system (or swap space) in each
partition, and decide where that file system will be mounted.
Disk Device CodesCodeMeaningadATAPI (IDE) diskdaSCSI direct access diskacdATAPI (IDE) CDROMcdSCSI CDROMfdFloppy disk
Sample Disk, Slice, and Partition NamesNameMeaningad0s1aThe first partition (a) on the first
slice (s1) on the first IDE disk
(ad0).da1s2eThe fifth partition (e) on the
second slice (s2) on the second SCSI disk
(da1).Conceptual Model of a DiskThis diagram shows FreeBSD's view of the first IDE disk attached
to the system. Assume that the disk is 4 GB in size, and contains
two 2 GB slices (&ms-dos; partitions). The first slice contains a &ms-dos;
disk, C:, and the second slice contains a
FreeBSD installation. This example FreeBSD installation has three
partitions, and a swap partition.The three partitions will each hold a file system. Partition
a will be used for the root file system,
e for the /var directory
hierarchy, and f for the
/usr directory hierarchy..-----------------. --.
| | |
| DOS / Windows | |
: : > First slice, ad0s1
: : |
| | |
:=================: ==: --.
| | | Partition a, mounted as / |
| | > referred to as ad0s2a |
| | | |
:-----------------: ==: |
| | | Partition b, used as swap |
| | > referred to as ad0s2b |
| | | |
:-----------------: ==: | Partition c, no
| | | Partition e, used as /var > file system, all
| | > referred to as ad0s2e | of FreeBSD slice,
| | | | ad0s2c
:-----------------: ==: |
| | | |
: : | Partition f, used as /usr |
: : > referred to as ad0s2f |
: : | |
| | | |
| | --' |
`-----------------' --'Mounting and Unmounting File SystemsThe file system is best visualized as a tree,
rooted, as it were, at /.
/dev, /usr, and the
other directories in the root directory are branches, which may
have their own branches, such as
/usr/local, and so on.root file systemThere are various reasons to house some of these
directories on separate file systems. /var
contains the directories log/,
spool/,
and various types of temporary files, and
as such, may get filled up. Filling up the root file system
is not a good idea, so splitting /var from
/ is often favorable.Another common reason to contain certain directory trees on
other file systems is if they are to be housed on separate
physical disks, or are separate virtual disks, such as Network File System mounts, or CDROM
drives.The fstab Filefile systemsmounted with fstabDuring the boot process,
file systems listed in /etc/fstab are
automatically mounted (unless they are listed with the
option).The /etc/fstab file contains a list
of lines of the following format:device/mount-pointfstypeoptionsdumpfreqpassnodeviceA device name (which should exist), as explained in
.mount-pointA directory (which should exist), on which
to mount the file system.fstypeThe file system type to pass to
&man.mount.8;. The default FreeBSD file system is
ufs.optionsEither for read-write
file systems, or for read-only
file systems, followed by any other options that may be
needed. A common option is for
file systems not normally mounted during the boot sequence.
Other options are listed in the &man.mount.8; manual page.dumpfreqThis is used by &man.dump.8; to determine which
file systems require dumping. If the field is missing,
a value of zero is assumed.passnoThis determines the order in which file systems should
be checked. File systems that should be skipped should have
their passno set to zero. The root
file system (which needs to be checked before everything
else) should have its passno set to
one, and other file systems' passno
should be set to values greater than one. If more than one
file systems have the same passno then
&man.fsck.8; will attempt to check file systems in parallel
if possible.Consult the &man.fstab.5; manual page for more information
on the format of the /etc/fstab file and
the options it contains.The mount Commandfile systemsmountingThe &man.mount.8; command is what is ultimately used to
mount file systems.In its most basic form, you use:&prompt.root; mount devicemountpointThere are plenty of options, as mentioned in the
&man.mount.8; manual page, but the most common are:Mount OptionsMount all the file systems listed in
/etc/fstab. Except those
marked as noauto, excluded by the
flag, or those that are already
mounted.Do everything except for the actual mount system call.
This option is useful in conjunction with the
flag to determine what
&man.mount.8; is actually trying to do.Force the mount of an unclean file system
(dangerous), or forces the revocation of write access
when downgrading a file system's mount status from
read-write to read-only.Mount the file system read-only. This is identical
to using the (
for &os; versions older than 5.2) argument to the
option.fstypeMount the given file system as the given file system
type, or mount only file systems of the given type, if
given the option.ufs is the default file system
type.Update mount options on the file system.Be verbose.Mount the file system read-write.The option takes a comma-separated list of
the options, including the following:nodevDo not interpret special devices on the
file system. This is a useful security option.noexecDo not allow execution of binaries on this
file system. This is also a useful security option.nosuidDo not interpret setuid or setgid flags on the
file system. This is also a useful security option.The umount Commandfile systemsunmountingThe &man.umount.8; command takes, as a parameter, one of a
mountpoint, a device name, or the or
option.All forms take to force unmounting,
and for verbosity. Be warned that
is not generally a good idea. Forcibly
unmounting file systems might crash the computer or damage data
on the file system. and are used to
unmount all mounted file systems, possibly modified by the
file system types listed after .
, however, does not attempt to unmount the
root file system.ProcessesFreeBSD is a multi-tasking operating system. This means that it
seems as though more than one program is running at once. Each program
running at any one time is called a process.
Every command you run will start at least one new process, and there are
a number of system processes that run all the time, keeping the system
functional.Each process is uniquely identified by a number called a
process ID, or PID, and,
like files, each process also has one owner and group. The owner and
group information is used to determine what files and devices the
process can open, using the file permissions discussed earlier. Most
processes also have a parent process. The parent process is the process
that started them. For example, if you are typing commands to the shell
then the shell is a process, and any commands you run are also
processes. Each process you run in this way will have your shell as its
parent process. The exception to this is a special process called
&man.init.8;. init is always the first
process, so its PID is always 1. init is started
automatically by the kernel when FreeBSD starts.Two commands are particularly useful to see the processes on the
system, &man.ps.1; and &man.top.1;. The ps command is used to
show a static list of the currently running processes, and can show
their PID, how much memory they are using, the command line they were
started with, and so on. The top command displays all the
running processes, and updates the display every few seconds, so that
you can interactively see what your computer is doing.By default, ps only shows you the commands that are running
and are owned by you. For example:&prompt.user; ps
PID TT STAT TIME COMMAND
298 p0 Ss 0:01.10 tcsh
7078 p0 S 2:40.88 xemacs mdoc.xsl (xemacs-21.1.14)
37393 p0 I 0:03.11 xemacs freebsd.dsl (xemacs-21.1.14)
48630 p0 S 2:50.89 /usr/local/lib/netscape-linux/navigator-linux-4.77.bi
48730 p0 IW 0:00.00 (dns helper) (navigator-linux-)
72210 p0 R+ 0:00.00 ps
390 p1 Is 0:01.14 tcsh
7059 p2 Is+ 1:36.18 /usr/local/bin/mutt -y
6688 p3 IWs 0:00.00 tcsh
10735 p4 IWs 0:00.00 tcsh
20256 p5 IWs 0:00.00 tcsh
262 v0 IWs 0:00.00 -tcsh (tcsh)
270 v0 IW+ 0:00.00 /bin/sh /usr/X11R6/bin/startx -- -bpp 16
280 v0 IW+ 0:00.00 xinit /home/nik/.xinitrc -- -bpp 16
284 v0 IW 0:00.00 /bin/sh /home/nik/.xinitrc
285 v0 S 0:38.45 /usr/X11R6/bin/sawfishAs you can see in this example, the output from &man.ps.1; is
organized into a number of columns. PID is the
process ID discussed earlier. PIDs are assigned starting from 1, go up
to 99999, and wrap around back to the beginning when you run out.
The TT column shows the tty the program is running on, and can
safely be ignored for the moment. STAT shows the
program's state, and again, can be safely ignored.
TIME is the amount of time the program has been
running on the CPU—this is usually not the elapsed time since
you started the program, as most programs spend a lot of time waiting
for things to happen before they need to spend time on the CPU.
Finally, COMMAND is the command line that was used to
run the program.&man.ps.1; supports a number of different options to change the
information that is displayed. One of the most useful sets is
auxww. displays information
about all the running processes, not just your own.
displays the username of the process' owner, as well as memory usage.
displays information about daemon processes, and
causes &man.ps.1; to display the full command line,
rather than truncating it once it gets too long to fit on the
screen.The output from &man.top.1; is similar. A sample session looks like
this:&prompt.user; top
last pid: 72257; load averages: 0.13, 0.09, 0.03 up 0+13:38:33 22:39:10
47 processes: 1 running, 46 sleeping
CPU states: 12.6% user, 0.0% nice, 7.8% system, 0.0% interrupt, 79.7% idle
Mem: 36M Active, 5256K Inact, 13M Wired, 6312K Cache, 15M Buf, 408K Free
Swap: 256M Total, 38M Used, 217M Free, 15% Inuse
PID USERNAME PRI NICE SIZE RES STATE TIME WCPU CPU COMMAND
72257 nik 28 0 1960K 1044K RUN 0:00 14.86% 1.42% top
7078 nik 2 0 15280K 10960K select 2:54 0.88% 0.88% xemacs-21.1.14
281 nik 2 0 18636K 7112K select 5:36 0.73% 0.73% XF86_SVGA
296 nik 2 0 3240K 1644K select 0:12 0.05% 0.05% xterm
48630 nik 2 0 29816K 9148K select 3:18 0.00% 0.00% navigator-linu
175 root 2 0 924K 252K select 1:41 0.00% 0.00% syslogd
7059 nik 2 0 7260K 4644K poll 1:38 0.00% 0.00% mutt
...The output is split into two sections. The header (the first five
lines) shows the PID of the last process to run, the system load averages
(which are a measure of how busy the system is), the system uptime (time
since the last reboot) and the current time. The other figures in the
header relate to how many processes are running (47 in this case), how
much memory and swap space has been taken up, and how much time the
system is spending in different CPU states.Below that are a series of columns containing similar information
to the output from &man.ps.1;. As before you can see the PID, the
username, the amount of CPU time taken, and the command that was run.
&man.top.1; also defaults to showing you the amount of memory space
taken by the process. This is split into two columns, one for total
size, and one for resident size—total size is how much memory the
application has needed, and the resident size is how much it is actually
using at the moment. In this example you can see that &netscape; has
required almost 30 MB of RAM, but is currently only using 9 MB.&man.top.1; automatically updates this display every two seconds;
this can be changed with the option.Daemons, Signals, and Killing ProcessesWhen you run an editor it is easy to control the editor, tell it to
load files, and so on. You can do this because the editor provides
facilities to do so, and because the editor is attached to a
terminal. Some programs are not designed to be
run with continuous user input, and so they disconnect from the terminal
at the first opportunity. For example, a web server spends all day
responding to web requests, it normally does not need any input from
you. Programs that transport email from site to site are another
example of this class of application.We call these programs daemons. Daemons were
characters in Greek mythology; neither good or evil, they were little
attendant spirits that, by and large, did useful things for mankind.
Much like the web servers and mail servers of today do useful things.
This is why the BSD mascot has, for a long time, been the cheerful
looking daemon with sneakers and a pitchfork.There is a convention to name programs that normally run as daemons
with a trailing d. BIND is the
Berkeley Internet Name Daemon (and the actual program that executes is called
named), the Apache web
server program is called httpd, the line printer
spooling daemon is lpd and so on. This is a
convention, not a hard and fast rule; for example, the main mail daemon
for the Sendmail application is called
sendmail, and not maild, as you
might imagine.Sometimes you will need to communicate with a daemon process. These
communications are called signals, and you can
communicate with a daemon (or with any other running process) by sending it a
signal. There are a number of different signals that you can
send—some of them have a specific meaning, others are interpreted
by the application, and the application's documentation will tell you
how that application interprets signals. You can only send a signal to
a process that you own. If you send a signal to someone else's
process with &man.kill.1; or &man.kill.2; permission will be denied.
The exception to this is the
root user, who can send signals to everyone's
processes.FreeBSD will also send applications signals in some cases. If an
application is badly written, and tries to access memory that it is not
supposed to, FreeBSD sends the process the Segmentation
Violation signal (SIGSEGV). If an
application has used the &man.alarm.3; system call to be alerted after a
period of time has elapsed then it will be sent the Alarm signal
(SIGALRM), and so on.Two signals can be used to stop a process,
SIGTERM and SIGKILL.
SIGTERM is the polite way to kill a process; the
process can catch the signal, realize that you want
it to shut down, close any log files it may have open, and generally
finish whatever it is doing at the time before shutting down. In some
cases a process may even ignore SIGTERM if it is in
the middle of some task that can not be interrupted.SIGKILL can not be ignored by a process. This is
the I do not care what you are doing, stop right now
signal. If you send SIGKILL to a process then
FreeBSD will stop that process there and thenNot quite true—there are a few things that can not be
interrupted. For example, if the process is trying to read from a
file that is on another computer on the network, and the other
computer has gone away for some reason (been turned off, or the
network has a fault), then the process is said to be
uninterruptible. Eventually the process will time
out, typically after two minutes. As soon as this time out occurs
the process will be killed..The other signals you might want to use are
SIGHUP, SIGUSR1, and
SIGUSR2. These are general purpose signals, and
different applications will do different things when they are
sent.Suppose that you have changed your web server's configuration
file—you would like to tell the web server to re-read its
configuration. You could stop and restart httpd, but
this would result in a brief outage period on your web server, which may
be undesirable. Most daemons are written to respond to the
SIGHUP signal by re-reading their configuration
file. So instead of killing and restarting httpd you
would send it the SIGHUP signal. Because there is no
standard way to respond to these signals, different daemons will have
different behavior, so be sure and read the documentation for the
daemon in question.Signals are sent using the &man.kill.1; command, as this example
shows.Sending a Signal to a ProcessThis example shows how to send a signal to &man.inetd.8;. The
inetd configuration file is
/etc/inetd.conf, and inetd will re-read
this configuration file when it is sent
SIGHUP.Find the process ID of the process you want to send the signal
to. Do this using &man.ps.1; and &man.grep.1;. The &man.grep.1;
command is used to search through output, looking for the string you
specify. This command is run as a normal user, and &man.inetd.8; is
run as root, so the options
must be given to &man.ps.1;.&prompt.user; ps -ax | grep inetd
198 ?? IWs 0:00.00 inetd -wWSo the &man.inetd.8; PID is 198. In some cases the
grep inetd command might also occur in this
output. This is because of the way &man.ps.1; has to find the list
of running processes.Use &man.kill.1; to send the signal. Because &man.inetd.8; is
being run by root you must use &man.su.1; to
become root first.&prompt.user; suPassword:
&prompt.root; /bin/kill -s HUP 198In common with most &unix; commands, &man.kill.1; will not print any
output if it is successful. If you send a signal to a
process that you do not own then you will see kill:
PID: Operation not
permitted. If you mistype the PID you will either
send the signal to the wrong process, which could be bad, or, if
you are lucky, you will have sent the signal to a PID that is not
currently in use, and you will see kill:
PID: No such process.Why Use /bin/kill?Many shells provide the kill command as a
built in command; that is, the shell will send the signal
directly, rather than running /bin/kill.
This can be very useful, but different shells have a different
syntax for specifying the name of the signal to send. Rather than
try to learn all of them, it can be simpler just to use the
/bin/kill ...
command directly.Sending other signals is very similar, just substitute
TERM or KILL in the command line
as necessary.Killing random process on the system can be a bad idea. In
particular, &man.init.8;, process ID 1, is very special. Running
/bin/kill -s KILL 1 is a quick way to shutdown your
system. Always double check the arguments you
run &man.kill.1; with before you press
Return.Shellsshellscommand lineIn FreeBSD, a lot of everyday work is done in a command line
interface called a shell. A shell's main job is to take commands
from the input channel and execute them. A lot of shells also have
built in functions to help everyday tasks such as file management,
file globbing, command line editing, command macros, and environment
variables. FreeBSD comes with a set of shells, such as
sh, the Bourne Shell, and tcsh,
the improved C-shell. Many other shells are available
from the FreeBSD Ports Collection, such as
zsh and bash.Which shell do you use? It is really a matter of taste. If you
are a C programmer you might feel more comfortable with a C-like shell
such as tcsh. If you have come from Linux or are new
to a &unix; command line interface you might try bash.
The point is that each
shell has unique properties that may or may not work with your
preferred working environment, and that you have a choice of what
shell to use.One common feature in a shell is filename completion. Given
the typing of the first few letters of a command or filename, you
can usually have the shell automatically complete the rest of the
command or filename by hitting the Tab key on the keyboard. Here is
an example. Suppose you have two files called
foobar and foo.bar. You
want to delete foo.bar. So what you would type
on the keyboard is: rm fo[Tab].[Tab].The shell would print out rm
foo[BEEP].bar.The [BEEP] is the console bell, which is the shell telling me it
was unable to totally complete the filename because there is more
than one match. Both foobar and
foo.bar start with fo, but
it was able to complete to foo. If you type in
., then hit Tab again, the shell would be able to
fill in the rest of the filename for you.environment variablesAnother feature of the shell is the use of environment variables.
Environment variables are a variable key pair stored in the shell's
environment space. This space can be read by any program invoked by
the shell, and thus contains a lot of program configuration. Here
is a list of common environment variables and what they mean:environment variablesVariableDescriptionUSERCurrent logged in user's name.PATHColon separated list of directories to search for
binaries.DISPLAYNetwork name of the X11 display to connect to, if
available.SHELLThe current shell.TERMThe name of the user's terminal. Used to determine the
capabilities of the terminal.TERMCAPDatabase entry of the terminal escape codes to perform
various terminal functions.OSTYPEType of operating system. e.g., FreeBSD.MACHTYPEThe CPU architecture that the system is running
on.EDITORThe user's preferred text editor.PAGERThe user's preferred text pager.MANPATHColon separated list of directories to search for
manual pages.Bourne shellsSetting an environment variable differs somewhat from
shell to shell. For example, in the C-Style shells such as
tcsh and csh, you would use
setenv to set environment variables.
Under Bourne shells such as sh and
bash, you would use
export to set your current environment
variables. For example, to set or modify the
EDITOR environment variable, under csh or
tcsh a
command like this would set EDITOR to
/usr/local/bin/emacs:&prompt.user; setenv EDITOR /usr/local/bin/emacsUnder Bourne shells:&prompt.user; export EDITOR="/usr/local/bin/emacs"You can also make most shells expand the environment variable by
placing a $ character in front of it on the
command line. For example, echo $TERM would
print out whatever $TERM is set to, because the shell
expands $TERM and passes it on to echo.Shells treat a lot of special characters, called meta-characters
as special representations of data. The most common one is the
* character, which represents any number of
characters in a filename. These special meta-characters can be used
to do filename globbing. For example, typing in
echo * is almost the same as typing in
ls because the shell takes all the files that
match * and puts them on the command line for
echo to see.To prevent the shell from interpreting these special characters,
they can be escaped from the shell by putting a backslash
(\) character in front of them. echo
$TERM prints whatever your terminal is set to.
echo \$TERM prints $TERM as
is.Changing Your ShellThe easiest way to change your shell is to use the
chsh command. Running chsh will
place you into the editor that is in your EDITOR
environment variable; if it is not set, you will be placed in
vi. Change the Shell: line
accordingly.You can also give chsh the
option; this will set your shell for you,
without requiring you to enter an editor.
For example, if you wanted to
change your shell to bash, the following should do the
trick:&prompt.user; chsh -s /usr/local/bin/bashThe shell that you wish to use must be
present in the /etc/shells file. If you
have installed a shell from the ports
collection, then this should have been done for you
already. If you installed the shell by hand, you must do
this.For example, if you installed bash by hand
and placed it into /usr/local/bin, you would
want to:&prompt.root; echo "/usr/local/bin/bash" >> /etc/shellsThen rerun chsh.Text Editorstext editorseditorsA lot of configuration in FreeBSD is done by editing text files.
Because of this, it would be a good idea to become familiar
with a text editor. FreeBSD comes with a few as part of the base
system, and many more are available in the Ports Collection.eeeditorseeThe easiest and simplest editor to learn is an editor called
ee, which stands for easy editor. To
start ee, one would type at the command
line ee filename where
filename is the name of the file to be edited.
For example, to edit /etc/rc.conf, type in
ee /etc/rc.conf. Once inside of
ee, all of the
commands for manipulating the editor's functions are listed at the
top of the display. The caret ^ character represents
the Ctrl key on the keyboard, so ^e expands to the key combination
Ctrle. To leave
ee, hit the Esc key, then choose leave
editor. The editor will prompt you to save any changes if the file
has been modified.vieditorsviemacseditorsemacsFreeBSD also comes with more powerful text editors such as
vi as part of the base system, while other editors, like
Emacs and vim,
are part of the FreeBSD Ports Collection (editors/emacs and editors/vim). These editors offer much
more functionality and power at the expense of being a little more
complicated to learn. However if you plan on doing a lot of text
editing, learning a more powerful editor such as
vim or Emacs
will save you much more time in the long run.Devices and Device NodesA device is a term used mostly for hardware-related
activities in a system, including disks, printers, graphics
cards, and keyboards. When FreeBSD boots, the majority
of what FreeBSD displays are devices being detected.
You can look through the boot messages again by viewing
/var/run/dmesg.boot.For example, acd0 is the
first IDE CDROM drive, while kbd0
represents the keyboard.Most of these devices in a &unix; operating system must be
accessed through special files called device nodes, which are
located in the /dev directory.Creating Device NodesWhen adding a new device to your system, or compiling
in support for additional devices, you may need to create one or
more device nodes for the new devices.MAKEDEV ScriptOn systems without DEVFS (this concerns all FreeBSD versions before 5.0), device nodes are created
using the &man.MAKEDEV.8; script as shown below:&prompt.root; cd /dev
&prompt.root; sh MAKEDEV ad1This example would make the proper device nodes
for the second IDE drive when installed.DEVFS (DEVice File System) The device file system, or DEVFS, provides access to
kernel's device namespace in the global file system namespace.
Instead of having to create and modify device nodes,
DEVFS maintains this particular file system for you.See the &man.devfs.5; manual page for more
information.DEVFS is used by default in FreeBSD 5.0 and above.Binary FormatsTo understand why &os; uses the &man.elf.5;
format, you must first know a little about the three currently
dominant executable formats for &unix;:&man.a.out.5;The oldest and classic &unix; object
format. It uses a short and compact header with a magic
number at the beginning that is often used to characterize
the format (see &man.a.out.5; for more details). It
contains three loaded segments: .text, .data, and .bss plus
a symbol table and a string table.COFFThe SVR3 object format. The header now comprises a
section table, so you can have more than just .text, .data,
and .bss sections.&man.elf.5;The successor to COFF, featuring
multiple sections and 32-bit or 64-bit possible values. One
major drawback: ELF was also designed
with the assumption that there would be only one ABI per
system architecture. That assumption is actually quite
incorrect, and not even in the commercial SYSV world (which
has at least three ABIs: SVR4, Solaris, SCO) does it hold
true.FreeBSD tries to work around this problem somewhat by
providing a utility for branding a
known ELF executable with information
about the ABI it is compliant with. See the manual page for
&man.brandelf.1; for more information.FreeBSD comes from the classic camp and used
the &man.a.out.5; format, a technology tried and proven through
many generations of BSD releases, until the beginning of the 3.X
branch. Though it was possible to build and run native
ELF binaries (and kernels) on a FreeBSD
system for some time before that, FreeBSD initially resisted the
push to switch to ELF as the
default format. Why? Well, when the Linux camp made their
painful transition to ELF, it was not so much
to flee the a.out executable format as it
was their inflexible jump-table based shared library mechanism,
which made the construction of shared libraries very difficult
for vendors and developers alike. Since the
ELF tools available offered a solution to the
shared library problem and were generally seen as the way
forward anyway, the migration cost was accepted as
necessary and the transition made. FreeBSD's shared library
mechanism is based more closely on Sun's
&sunos; style shared library mechanism
and, as such, is very easy to use.So, why are there so many different formats?Back in the dim, dark past, there was simple hardware. This
simple hardware supported a simple, small system. a.out was
completely adequate for the job of representing binaries on this
simple system (a PDP-11). As people ported &unix; from this simple
system, they retained the a.out format because it was sufficient
for the early ports of &unix; to architectures like the Motorola
68k, VAXen, etc.Then some bright hardware engineer decided that if he could
force software to do some sleazy tricks, then he would be able
to shave a few gates off the design and allow his CPU core to
run faster. While it was made to work with this new kind of
hardware (known these days as RISC), a.out
was ill-suited for this hardware, so many formats were developed
to get to a better performance from this hardware than the
limited, simple a.out format could
offer. Things like COFF,
ECOFF, and a few obscure others were invented
and their limitations explored before things seemed to settle on
ELF.In addition, program sizes were getting huge and disks (and
physical memory) were still relatively small so the concept of a
shared library was born. The VM system also became more
sophisticated. While each one of these advancements was done
using the a.out format, its usefulness was
stretched more and more with each new feature. In addition,
people wanted to dynamically load things at run time, or to junk
parts of their program after the init code had run to save in
core memory and swap space. Languages became more sophisticated
and people wanted code called before main automatically. Lots of
hacks were done to the a.out format to
allow all of these things to happen, and they basically worked
for a time. In time, a.out was not up to
handling all these problems without an ever increasing overhead
in code and complexity. While ELF solved many
of these problems, it would be painful to switch from the system
that basically worked. So ELF had to wait
until it was more painful to remain with
a.out than it was to migrate to
ELF.However, as time passed, the build tools that FreeBSD
derived their build tools from (the assembler and loader
especially) evolved in two parallel trees. The FreeBSD tree
added shared libraries and fixed some bugs. The GNU folks that
originally wrote these programs rewrote them and added simpler
support for building cross compilers, plugging in different
formats at will, and so on. Since many people wanted to build cross
compilers targeting FreeBSD, they were out of luck since the
older sources that FreeBSD had for as and ld were not up to the
task. The new GNU tools chain (binutils) does support cross
compiling, ELF, shared libraries, C++
extensions, etc. In addition, many vendors are releasing
ELF binaries, and it is a good thing for
FreeBSD to run them.ELF is more expressive than a.out and
allows more extensibility in the base system. The
ELF tools are better maintained, and offer
cross compilation support, which is important to many people.
ELF may be a little slower than a.out, but
trying to measure it can be difficult. There are also numerous
details that are different between the two in how they map
pages, handle init code, etc. None of these are very important,
but they are differences. In time support for
a.out will be moved out of the GENERIC
kernel, and eventually removed from the kernel once the need to
run legacy a.out programs is past.For More InformationManual Pagesmanual pagesThe most comprehensive documentation on FreeBSD is in the form
of manual pages. Nearly every program on the system comes with a
short reference manual explaining the basic operation and various
arguments. These manuals can be viewed with the man command. Use
of the man command is simple:&prompt.user; man commandcommand is the name of the command you
wish to learn about. For example, to learn more about
ls command type:&prompt.user; man lsThe online manual is divided up into numbered sections:User commands.System calls and error numbers.Functions in the C libraries.Device drivers.File formats.Games and other diversions.Miscellaneous information.System maintenance and operation commands.Kernel developers.In some cases, the same topic may appear in more than one
section of the online manual. For example, there is a
chmod user command and a
chmod() system call. In this case, you can
tell the man command which one you want by specifying the
section:&prompt.user; man 1 chmodThis will display the manual page for the user command
chmod. References to a particular section of
the online manual are traditionally placed in parenthesis in
written documentation, so &man.chmod.1; refers to the
chmod user command and &man.chmod.2; refers to
the system call.This is fine if you know the name of the command and simply
wish to know how to use it, but what if you cannot recall the
command name? You can use man to search for keywords in the
command descriptions by using the
switch:&prompt.user; man -k mailWith this command you will be presented with a list of
commands that have the keyword mail in their
descriptions. This is actually functionally equivalent to using
the apropos command.So, you are looking at all those fancy commands in
/usr/bin but do not have the faintest idea
what most of them actually do? Simply do:&prompt.user; cd /usr/bin
&prompt.user; man -f *or&prompt.user; cd /usr/bin
&prompt.user; whatis *which does the same thing.GNU Info FilesFree Software FoundationFreeBSD includes many applications and utilities produced by
the Free Software Foundation (FSF). In addition to manual pages,
these programs come with more extensive hypertext documents called
info files which can be viewed with the
info command or, if you installed
emacs, the info mode of
emacs.To use the &man.info.1; command, simply type:&prompt.user; infoFor a brief introduction, type h. For a
quick command reference, type ?.
diff --git a/zh_TW.Big5/books/handbook/book.sgml b/zh_TW.Big5/books/handbook/book.sgml
index c8968b3651..88d72fe818 100644
--- a/zh_TW.Big5/books/handbook/book.sgml
+++ b/zh_TW.Big5/books/handbook/book.sgml
@@ -1,317 +1,319 @@
%books.ent;
%chapters;
%txtfiles;
+
%pgpkeys;
]>
FreeBSD 使用手冊FreeBSD 文件計畫February 1999199519961997199819992000200120022003200420052006FreeBSD 文件計畫
&bookinfo.legalnotice;
&tm-attrib.freebsd;
&tm-attrib.3com;
&tm-attrib.3ware;
&tm-attrib.arm;
&tm-attrib.adaptec;
&tm-attrib.adobe;
&tm-attrib.apple;
&tm-attrib.corel;
&tm-attrib.creative;
&tm-attrib.cvsup;
&tm-attrib.heidelberger;
&tm-attrib.ibm;
&tm-attrib.ieee;
&tm-attrib.intel;
&tm-attrib.intuit;
&tm-attrib.linux;
&tm-attrib.lsilogic;
&tm-attrib.m-systems;
&tm-attrib.macromedia;
&tm-attrib.microsoft;
&tm-attrib.netscape;
&tm-attrib.nexthop;
&tm-attrib.opengroup;
&tm-attrib.oracle;
&tm-attrib.powerquest;
&tm-attrib.realnetworks;
&tm-attrib.redhat;
&tm-attrib.sap;
&tm-attrib.sun;
&tm-attrib.symantec;
&tm-attrib.themathworks;
&tm-attrib.thomson;
&tm-attrib.usrobotics;
&tm-attrib.vmware;
&tm-attrib.waterloomaple;
&tm-attrib.wolframresearch;
&tm-attrib.xfree86;
&tm-attrib.xiph;
&tm-attrib.general;
歡迎使用FreeBSD! 本使用手冊涵蓋範圍包括了
FreeBSD &rel2.current;-RELEASE 和
FreeBSD &rel.current;-RELEASE 的安裝和日常使用。
這份使用手冊是很多人的集體創作,而且仍然『持續不斷』的進行中。
許多章節仍未完成,已完成的部份也有些需要更新。
如果您對協助本計畫的進行有興趣的話,請寄 e-mail 到 &a.doc;。
在 FreeBSD 網站
可以找到這份文件的最新版本(舊版文件可從 取得),也可以從 FreeBSD FTP 伺服器
或是眾多 mirror 站臺
下載不同格式及不同壓縮選項的資料。
如果比較偏好擁有實體書面資料,那可以在
FreeBSD Mall 購買。
此外,也可以在 使用手冊
中搜尋資料。
&chap.preface;
開始使用 FreeBSD 這部份是提供給初次使用 FreeBSD 的使用者和系統管理者。
這些章節包括:介紹 FreeBSD 給您。 在安裝過程給您指引。 教您 &unix; 的基礎及原理。 展示給您看如何安裝豐富的 FreeBSD 的應用軟體向您介紹 X, &unix; 的視窗系統以及詳細的桌面環境設定,讓您更有生產力。
我們試著儘可能的讓這段文字的參考連結數目降到最低,讓您在讀使用手冊的這部份時可以不太需要常常前後翻頁。
一般性工作既然基礎的部分已經提過了,接下來的這個部分將會討論一些常會用到的 FreeBSD
的特色,這些章節包括:介紹給您常見且實用的桌面應用軟體:網頁瀏覽器、生產力工具、文件檢視程式等。介紹給您眾多 FreeBSD 上可用的多媒體工具。解釋如何編譯自訂 FreeBSD 核心以增加額外系統功能的流程。詳細描述列印系統,包含桌上型印表機及網路印表機的設定。展示給您看如何在您的 FreeBSD 系統中執行 Linux 應用軟體。這些章節中有些需要您預先閱讀些相關文件,在各章節開頭的概要內會提及。系統管理FreeBSD 使用手冊剩下的這些章節涵蓋了全方位的 FreeBSD 系統管理。
每個章節的開頭會先描述在該您讀完該章節後您會學到什麼,也會詳述在您在看這些資料時應該要有的一些背景知識。
這些章節是讓您在需要查資料的時候翻閱用的。
您不需要依照特定的順序來讀,也不需要將這些章節全部過讀之後才開始用 FreeBSD。
+
網路通訊FreeBSD 是一種廣泛的被使用在高效能的網路伺服器中的作業系統,這些章節包含了:序列埠通訊PPP 和 PPPoE電子郵件執行網路伺服程式防火牆其他的進階網路主題這些章節是讓您在需要查資料的時候翻閱用的。
您不需要依照特定的順序來讀,也不需要將這些章節全部讀過之後才將 FreeBSD 用在網路環境下。附錄
&chap.colophon;
diff --git a/zh_TW.Big5/books/handbook/chapters.ent b/zh_TW.Big5/books/handbook/chapters.ent
index aed7f9633b..7aa1df904b 100644
--- a/zh_TW.Big5/books/handbook/chapters.ent
+++ b/zh_TW.Big5/books/handbook/chapters.ent
@@ -1,59 +1,60 @@
+
diff --git a/zh_TW.Big5/books/handbook/desktop/chapter.sgml b/zh_TW.Big5/books/handbook/desktop/chapter.sgml
index 5480b8557f..b8d2912e93 100644
--- a/zh_TW.Big5/books/handbook/desktop/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/desktop/chapter.sgml
@@ -1,1108 +1,1093 @@
ChristopheJunietContributed by
- Desktop Applications
+ 桌面環境應用程式
- Synopsis
-
- FreeBSD can run a wide variety of desktop applications, such
- as browsers and word processors. Most of these are available as
- packages or can be automatically built from the ports
- collection. Many new users expect to find these kinds of
- applications on their desktop. This chapter will show you how
- to install some popular desktop applications effortlessly,
- either from their packages or from the Ports Collection.
-
- Note that when installing programs from the ports, they are
- compiled from source. This can take a very long time, depending
- on what you are compiling and the processing power of your
- machine(s). If building from source takes a prohibitively long
- amount of time for you, you can install most of the programs of
- the Ports Collection from pre-built packages.
-
- As FreeBSD features Linux binary compatibility, many
- applications originally developed for Linux are available for
- your desktop. It is strongly recommended that you read
- before installing any of the Linux
- applications. Many of the ports using the Linux binary
- compatibility start with linux-. Remember this
- when you search for a particular port, for instance with
- &man.whereis.1;. In the following text, it is assumed that you
- have enabled Linux binary compatibility before installing any of
- the Linux applications.
-
- Here are the categories covered by this chapter:
+ 概述
+
+ 在 FreeBSD 上面可以執行非常多種類的桌面應用程式,
+ 像是網頁瀏覽器和文字處理軟體等。
+ 這些程式大都可以透過套件來安裝或是從 ports collection 中自動編譯安裝。
+ 許多新的使用者會希望能在在他們的桌面系統中找到這些程式。
+ 這章將會告訴你如何不用費太多功夫去安裝一些熱門的桌面應用程式,
+ 不管是從套件或是從 ports collection 中安裝。
+
+ 需要注意到的是:當從 ports 中安裝程式的時候,
+ 它們是從源碼開始編譯的。依照你編譯的 ports 和電腦速度(硬體等級),
+ 有可能會花很長一段時間才能完成。
+ 如果從源碼編譯對你來說會花太多時間的話,
+ 大部分的 ports 你都能找到事先編譯好的套件來安裝。
+
+ 因為 FreeBSD 具有相容 Linux 二進制的特性,
+ 許多原先在 Linux 上開發的應用程式都能在你的 FreeBSD 桌面環境執行。
+ 在安裝任何 Linux 應用程式之前,強烈建議你先閱讀
+ Linux 執行相容模式這個章節。
+ 而許多用 Linux 二進制相容模式的軟體在 ports 裡頭通常都會用
+ linux- 開頭。
+ 當你在搜尋某個特定軟體時,記住這點,並且可以使用 &man.whereis.1;
+ 來找。 在下列的說明中,
+ 都假設你在安裝任何 Linux 應用軟體之前,
+ 已經事先啟用了 Linux 二進制相容模式。
+
+ 下列目錄是這章中所涵蓋的應用程式:
- Browsers (such as Mozilla,
+ 瀏覽器 (像是 Mozilla,
Opera,
Firefox,
Konqueror)
- Productivity (such as
+ 辦公軟體 (像是
KOffice,
AbiWord,
The GIMP,
OpenOffice.org)
- Document Viewers (such as &acrobat.reader;,
+ 文件瀏覽軟體 (像是 &acrobat.reader;,
gv,
Xpdf,
GQview)
- Finance (such as
+ 財務處理軟體 (像是
GnuCash,
Gnumeric,
Abacus)
- Before reading this chapter, you should:
+ 在閱讀這章之前,你必須
- Know how to install additional third-party software
+ 知道如何安裝其他的軟體(third-party software)
().
- Know how to install additional Linux software
+ 知道如何安裝 Linux 軟體
().
- For information on how to get a multimedia environment, read
- . If you want to set up and use
- electronic mail, please refer to .
+ 要知道更多關於多媒體環境的資訊,請先閱讀
+ 多媒體章節。
+ 如果你想要設定和使用電子郵件,也請你先看 郵件章節。
- Browsers
+ 瀏覽器
- browsers
- web
+ 瀏覽器
+ 網路
- FreeBSD does not come with a particular browser
- pre-installed. Instead, the
- www
- directory of the Ports Collection contains a lot of browsers
- ready to be installed. If you do not have time to compile
- everything (this can take a very long time in some cases) many
- of them are available as packages.
-
- KDE and
- GNOME already provide HTML browsers.
- Please refer to for more information on
- how to set up these complete desktops.
-
- If you are looking for light-weight browsers, you should
- investigate the Ports Collection for
+ 在 FreeBSD 中並沒有預先安裝好的特定瀏覽器。
+ 但在 Ports Collection 之中卻有許多瀏覽器可供你安裝使用。
+ 如果你沒有足夠時間去編譯所有的東西
+ (在某些情況下這可能會花上很長的一段時間),
+ 這些都有現成的套件可供直接安裝。
+
+ KDE 和
+ GNOME 桌面環境都已提供 HTML 瀏覽器。
+ 請參考 來了解更多有關如何設定這些完整的桌面環境系統資訊。
+
+ 如果你在尋找輕量化的瀏覽器,你可以從 Ports Collection 中找到下面的幾種:
www/dillo,
- www/links, or
- www/w3m.
+ www/links, 或
+ www/w3m。
- This section covers these applications:
+ 這節介紹這些瀏覽器:
- Application Name
- Resources Needed
- Installation from Ports
- Major Dependencies
+ 瀏覽器名稱
+ 所需的系統資源
+ 從 ports 安裝時間
+ 主要相依的軟體Mozilla
- heavy
- heavy
+ 多
+ 長Gtk+Opera
- light
- light
- FreeBSD and Linux versions available. The Linux
- version depends on the Linux Binary Compatibility and
+ 少
+ 短
+ FreeBSD 和 Linux 的版本都有。
+ Linux 的版本需要 Linux 二進制相容模組以及
linux-openmotif.Firefox
- medium
- heavy
+ 中度
+ 長Gtk+Konqueror
- medium
- heavy
- KDE Libraries
+ 中度
+ 長
+ KDE 函式庫MozillaMozilla
- Mozilla is perhaps the most
- suitable browser for your FreeBSD Desktop. It is modern,
- stable, and fully ported to FreeBSD. It features a very
- standards-compliant HTML display engine. It provides a mail
- and news reader. It even has a HTML composer if you plan to
- write some web pages yourself. Users of
- &netscape; will recognize the
- similarities with Communicator
- suite, as both browsers shared the same basis.
-
- On slow machines, with a CPU speed less than 233MHz or
- with less than 64MB of RAM, Mozilla
- can be too resource-consuming to be fully usable. You may
- want to look at the Opera browser
- instead, described a little later in this chapter.
-
- If you cannot or do not want to compile
- Mozilla for any reason, the FreeBSD
- GNOME team has already done this for you. Just install the
- package from the network by:
+ Mozilla
+ 也許是最適合 FreeBSD 桌面環境的瀏覽器。
+ 它極具現代化、穩定且完全移植至 FreeBSD 系統上。
+ 它也具備有十分符合 HTML 標準的顯示引擎,
+ 它更提供了郵件及新聞群組的閱讀功能。
+ 此外如果你打算要自己寫一些網頁的話,它還提供了 HTML 的編輯器。
+ 如果是 &netscape; 的使用者,
+ 你可能會認出這跟 Communicator 很像,
+ 它們其實同樣是使用相同基礎的瀏覽器。
+
+ 在速度較慢,像是 CPU 速度少於 233MHz 或是小於 64MB 記憶體的機器上面,
+ 完全使用 Mozilla 會是件極度耗費資源的事。
+ 所以在這樣的機器上面,你可能會想要使用 Opera
+ 這樣輕量級的瀏覽器,而接下來後面會提到。
+
+
+ 如果你有什麼原因不能或是不想編譯
+ Mozilla 的話,FreeBSD
+ GNOME 團隊已經為你做好了這件事。
+ 只要用下面的指令透過網路安裝套件就行了:&prompt.root; pkg_add -r mozilla
- If the package is not available, and you have enough time
- and disk space, you can get the source for
- Mozilla, compile it and install it
- on your system. This is accomplished by:
+ 如果沒有找到套件可以使用,而你也有足夠的時間和磁碟空間來編譯
+ Mozilla 並安裝到你的系統中,
+ 你可以透過下列步驟來安裝:&prompt.root; cd /usr/ports/www/mozilla
&prompt.root; make install clean
- The Mozilla port ensures a
- correct initialization by running the chrome registry setup
- with root privileges. However, if you
- want to fetch some add-ons like mouse gestures, you must run
- Mozilla as
- root to get them properly
- installed.
- Once you have completed the installation of
- Mozilla, you do not need to be
- root any longer. You can start
- Mozilla as a browser by typing:
+ Mozilla 需要使用
+ root 的權限來執行 chrome
+ 註冊來確保正確的初始化。
+ 另外,如果你需要抓一些額外的外掛程式像是 mouse gestures,
+ 你就必須要使用 root 的權限來安裝,
+ 以適當的安裝這些外掛程式。
+
+ 一旦你完成了 Mozilla 的安裝,
+ 你就再也不需要 root 的權限了。
+ 你可以直接打下面的指令來啟動 Mozilla:&prompt.user; mozilla
- You can start it directly as a mail and news reader as
- shown below:
+ 你也可以直接打下面的指令直接啟動郵件和新聞閱讀器:&prompt.user; mozilla -mailTomRhodesContributed by
- Mozilla and &java; plugin
+ Mozilla and &java; 外掛程式
+
+ 只安裝 Mozilla 很簡單,
+ 但安裝像是 &java; 和 ¯omedia; &flash;
+ 之類的外掛程式支援就需要耗費時間和硬碟空間了。
- Installing Mozilla is simple, but
- unfortunately installing Mozilla with
- support for add-ons like &java; and
- ¯omedia; &flash;
- consumes both time and disk
- space.
-
- The first thing is to download the files which will be used
- with Mozilla. Take your current web
- browser up to
- and
- create an account on their website. Remember to save the username
- and password from here as it may be needed in the future. Download
- the jdk-1_5_0-bin-scsl.zip (JDK 5.0
- SCSL Binaries) and jdk-1_5_0-src-scsl.zip (JDK 5.0
- SCSL Source) files and place them in
- /usr/ports/distfiles as the port will not
- fetch them automatically. This is due to license restrictions. While
- we are here, download the java environment from
- .
- The filename is j2sdk-1_4_2_08-linux-i586.bin.
- Like before, this file must be placed into
- /usr/ports/distfiles. Download a copy
- of the java patchkit from
+ 首先下載 Mozilla 所需要的檔案。
+ 用你的網頁瀏覽器連到
+
+ 並註冊一個帳號。
+ 記得要保存好這組使用者帳號和密碼,爾後會再用到。
+ 接下來下載 jdk-1_5_0-bin-scsl.zip (JDK 5.0
+ SCSL 二進位檔) 和 jdk-1_5_0-src-scsl.zip (JDK 5.0
+ SCSL 源碼) 這兩個檔案並放在 /usr/ports/distfiles 目錄下,
+ 因為授權的限制,所以 port 不能自動下載這些檔案。
+ 同時也要從
+ 下載「java 環境」,
+ 這個檔案名稱是 j2sdk-1_4_2_08-linux-i586.bin。
+ 就像先前描述的一樣,這個檔案必須放在
+ /usr/ports/distfiles 目錄底下。
+ 另外也要從
- and place it
- into /usr/ports/distfiles. Finally, install the
- java/jdk15 port
- with the standard make install clean.
+ 下載「java 修補程式集」並放在 /usr/ports/distfiles 目錄中。
+ 最後用標準的安裝指令 make install clean 從 port 中來安裝
+ java/jdk15
- Start Mozilla and access the
- About Plug-ins option from the
- Help menu. &java;
- plugin should be listed there now.
+ 接下來開啟 Mozilla,
+ 並且從協助(Help)選單中選取關於外掛程式(About Plug-ins)。
+ 你就可以看到 &java; 的外掛程式就會出現在裡面了。
- Mozilla and ¯omedia; &flash; plugin
-
- ¯omedia; &flash; plugin is not available for &os;. However,
- a software layer (wrapper) for running the Linux version of the plugin
- exists. This wrapper also supports &adobe; &acrobat; plugin,
- RealPlayer plugin and more.
-
- Install the www/linuxpluginwrapper
- port. This port requires
- emulators/linux_base which is a
- large port. Follow the instructions displayed by the port to set up
- your /etc/libmap.conf correctly! Example
- configurations are installed into
- /usr/local/share/examples/linuxpluginwrapper/
- directory.
-
- Install the www/mozilla port,
- if Mozilla is not already installed.
-
- Now just start Mozilla with:
+ Mozilla and ¯omedia; &flash; 外掛程式
+
+
+ 譯註:在 FreeBSD 上面沒有原生的 ¯omedia; &flash; 外掛程式,
+ 但是在 Ports Collection 中有 www/mozilla-plugin
+ 這個根據 GPL 獨立的 &flash; Mozilla 外掛程式。
+ 不過我們強烈建議安裝軟體層的 wrapper 來執行 Linux 版本的外掛程式。
+ 這個 wrapper 同時也支援 &adobe; &acrobat; 還有 RealPlayer 外掛程式等。
+
+
+ 從 port 安裝 www/linuxpluginwrapper。
+ linuxpluginwrapper 需要先裝一個很大的 emulators/linux_base
+ port。 然後根據 port 中指示的作法
+ 譯註:安裝完時顯示的說明,或參閱 pkg_message)
+ 去正確地設定你的 /etc/libmap.conf。
+ 設定的範例檔案位於 /usr/local/share/examples/linuxpluginwrapper/
+ 的目錄底下。
+
+ 如果 Mozilla 還沒安裝的話,
+ 從 www/mozilla port 來安裝。
+
+ 現在只要用下列的指令啟動 Mozilla :&prompt.user; mozilla &
- And access the About Plug-ins option from the
- Help menu. A list should appear with all the currently
- available plugins.
-
+ 接下來開啟 Mozilla,
+ 並且從協助(Help)選單中選取關於
+ 外掛程式(About Plug-ins)。
+ 你就可以看到所有安裝好的外掛程式之列表清單。
+
+
+ 不過如果你在 Mozilla
+ 或下面提到的 Firefox
+ 中使用上述的方法還是無法正常的啟用 &flash; 外掛程式的話,
+ 根據 Beech Rintoul 在郵件論壇中的解決方案如下:
+
+ 在安裝 www/linuxpluginwrapper 之前,
+ 執行下列步驟:
+
+ &prompt.root; rm -R /usr/X11R6/lib/browser_linux_plugins
+&prompt.root; ln -s /usr/X11R6/lib/browser_plugins /usr/X11R6/lib/browser_linux_plugins
+
+ 接下來用下列的指令來編譯 www/linuxpluginwrapper
+
+ &prompt.root; cd /usr/ports/www/linuxpluginwrapper&prompt.root; make -DWITH_PLUGINS install clean
+
- The linuxpluginwrapper only works on
- the &i386; system architecture.
+ linuxpluginwrapper 只能在
+ &i386; 的系統架構下運行。OperaOpera
- Opera is a very fast,
- full-featured, and standards-compliant browser. It comes in
- two favors: a native FreeBSD version and a
- version that runs under Linux emulation.
+ Opera 是個具備完整功能、符合標準的瀏覽器。
+ 它同時也具備了內建的郵件和新聞閱讀器、IRC、RSS/Atom feeds 閱讀器等。
+ 儘管如此,相對而言 Opera 是個輕量級、執行速度又快的瀏覽器。
+ 它在 ports 中有兩種版本:「原生」的 FreeBSD 版本還有在 Linux 模擬模式下的版本。
- To browse the Web with the FreeBSD version of Opera,
- install the package:
+ 要用 Opera 的 FreeBSD 版本來瀏覽網頁的話,
+ 用下面的指令安裝:&prompt.root; pkg_add -r opera
- Some FTP sites do not have all the packages, but the same
- result can be obtained with the Ports Collection by
- typing:
+ 有些 FTP 站台並沒有全部的套件,
+ 但是打下面的指令就能從 Ports Collection 中安裝:&prompt.root; cd /usr/ports/www/opera
&prompt.root; make install clean
- To install the Linux version of
- Opera, substitute
- linux-opera in place of
- opera in the examples above. The Linux
- version is useful in situations requiring the use of plug-ins
- that are only available for Linux, such as Adobe
- &acrobat.reader;. In all other respects, the
- FreeBSD and Linux versions appear to be functionally
- identical.
-
+ 要安裝 Opera 的 Linux 版本的話,
+ 請將上面例子中的 opera 替換成
+ linux-opera。
+ 有些時候, Linux 的版本是十分有用的,
+ 像是只有 Linux 版本外掛程式的時候。
+ 但在其他方面來說, FreeBSD 和 Linux 的版本功能上是一樣的。
+
FirefoxFirefox
- Firefox is the next-generation
- browser based on the Mozilla
- codebase. Mozilla is a complete
- suite of applications, such as a browser, a mail client, a chat
- client and much more. Firefox is
- just a browser, which makes it smaller and faster.
+ Firefox 是建構在
+ Mozilla 源碼庫中的下一代瀏覽器。
+ Mozilla 是一個完整的網頁軟體整合方案,
+ 像是郵件收發程式、聊天室程式及其他程式等。
+ Firefox 就只是個單純的瀏覽器,
+ 這也是讓它短小精悍的原因。
- Install the package by typing:
+ 你可以打以下的指令來安裝:&prompt.root; pkg_add -r firefox
- You can also use the Ports Collection if you
- prefer to compile from source code:
-
+ 如果你比較喜歡從源碼安裝的話,你也可以在 Ports Collection 中打以下指令:
+
&prompt.root; cd /usr/ports/www/firefox
&prompt.root; make install cleanKonquerorKonqueror
- Konqueror is part of
- KDE but it can also be used outside
- of KDE by installing
- x11/kdebase3.
- Konqueror is much more than a browser,
- it is also a file manager and a multimedia viewer.
+ Konqueror 是 KDE
+ 桌面系統的一部分,但是它也可以藉由安裝
+ x11/kdebase3
+ 在 KDE 環境以外使用。
+ Konqueror 不只是個網頁瀏覽器,
+ 他同時也是檔案管理器和多媒體瀏覽器。
- Konqueror also comes with a set of plugins,
- available in misc/konq-plugins.
+ Konqueror 也有許多的外掛程式,
+ 這些外掛程式可以從 misc/konq-plugins
+ 中安裝。
- Konqueror also supports &flash; and a How To
- is available at .
+ Konqueror 也支援 &flash; 的外掛程式。
+ 如何安裝的說明請參閱:。
- Productivity
+ 辦公室軟體
- When it comes to productivity, new users often look for a
- good office suite or a friendly word processor. While some
- desktop environments like
- KDE already provide an office suite,
- there is no default application. FreeBSD provides all that is
- needed, regardless of your desktop environment.
+ 當開始進行辦公,
+ 新的使用者通常會去找好用的辦公室軟體或是好上手的文字處理器。
+ 目前 有些桌面環境 像是
+ KDE已經提供了辦公軟體組合的套件。
+ FreeBSD 提供了所需的所有辦公軟體,桌面環境也不例外。
- This section covers these applications:
+ 這節涵蓋了下列的這些軟體:
- Application Name
- Resources Needed
- Installation from Ports
- Major Dependencies
+ 軟體名稱
+ 所需系統資源
+ 從 Ports 安裝的時間
+ 主要相依套件KOffice
- light
- heavy
+ 少
+ 長KDEAbiWord
- light
- light
- Gtk+ or GNOME
+ 少
+ 短
+ Gtk+ 或是 GNOMEThe Gimp
- light
- heavy
+ 少
+ 長Gtk+OpenOffice.org
- heavy
- huge
+ 多
+ 很久&jdk; 1.4, MozillaKOfficeKOffice
- office suite
+ 辦公軟體套件KOffice
- The KDE community has provided its desktop environment
- with an office suite which can be used outside
- KDE. It includes the four standard
- components that can be found in other office suites.
- KWord is the word processor,
- KSpread is the spreadsheet program,
- KPresenter manages slide
- presentations, and Kontour lets you
- draw graphical documents.
-
- Before installing the latest
- KOffice, make sure you have an
- up-to-date version of KDE.
-
- To install KOffice as a
- package, issue the following command:
-
+ KDE 社群在它的桌面環境裡頭提供了一個可以在 KDE
+ 外使用的辦公軟體組合。 它包含了四種模組:
+ KWord 是文字處理器,
+ KSpread 是試算表程式,
+ KPresenter 是簡報播放程式,
+ 另外 Karbon14 讓你可以產生圖形化的文件。
+ 譯註:Karbon14 是向量繪圖軟體,以前叫 Kontour ,更早之前稱為 Killustrator。
+
+
+
+ 在安裝最新版的 KOffice 之前,
+ 請先確定你有最新版本的 KDE。
+
+ 若要用套件來安裝 KOffice,
+ 請依照下面的指令:
+
&prompt.root; pkg_add -r koffice
- If the package is not available, you can use the ports
- collection. For instance, to install
- KOffice for
- KDE3, do:
+ 如果套件不存在的話,你可以使用 ports
+ collection. 例如要安裝 KDE3 中的
+ KOffice,請使用下列指令安裝:&prompt.root; cd /usr/ports/editors/koffice-kde3
&prompt.root; make install cleanAbiWordAbiWord
- AbiWord is a free word
- processing program similar in look and feel to µsoft; Word.
- It is suitable for typing papers, letters, reports, memos, and
- so forth. It is very fast, contains many features, and is
- very user-friendly.
-
- AbiWord can import or export
- many file formats, including some proprietary ones like
- Microsoft .doc.
+ AbiWord
+ 是一個免費的文字處理軟體,外觀和感覺都近似於 µsoft; Word。
+ 它適合處理文件、信件、報告、備忘錄等等。
+ 它也非常快速,包含了許多功能而且非常容易上手。
- AbiWord is available as a
- package. You can install it by:
+ AbiWord 可以輸入或輸出許多檔案格式,
+ 包括一些有專利的格式,例如微軟(Microsoft)公司的
+ .doc 格式。
+ AbiWord 也能用套件安裝,
+ 你可以用下列指令來安裝:
+
&prompt.root; pkg_add -r abiword
- If the package is not available, it can be compiled from
- the Ports Collection. The Ports Collection should be more
- up to date. It can be done as follows:
+ 如果找不到套件的話,它也可以從 Ports Collection 中編譯安裝。
+ 而 Ports Collection 應該要保持在最新的狀態。
+ AbiWord 可以透過下列方式編譯安裝:&prompt.root; cd /usr/ports/editors/abiword
&prompt.root; make install cleanThe GIMPThe GIMP
- For image authoring or picture retouching,
- The GIMP is a very sophisticated
- image manipulation program. It can be used as a simple paint
- program or as a quality photo retouching suite. It supports a
- large number of plug-ins and features a scripting interface.
- The GIMP can read and write a wide
- range of file formats. It supports interfaces with scanners
- and tablets.
-
- You can install the package by issuing this
- command:
+ 對於影像的編輯及修改來說,GIMP
+ 是非常精緻的影像處理軟體。
+ 它可以當作簡單的繪圖軟體或是高品質的相片處理軟體。
+ 它支援為數眾多的外掛程式及指令稿 (script-fu) 介面。
+ GIMP 可以讀寫許多檔案格式。
+ 它也支援掃描器
+
+ 譯註:你必須透過 sane-frontends 或 xsane 來掃描
+ 和手寫板。
+
+ 譯註:GIMP 在目前是 2.x 版,如果你想要安裝
+ 1.x 版的話,請用 Ports Collection 中的
+ graphics/gimp1。
+ 另外如果你已經使用習慣 Adobe Photoshop ,而且不習慣
+ GIMP 介面的話,你也可以嘗試安裝
+ graphics/gimpshop,
+ 它的使用介面十分類似 Adobe Photoshop。
+
+ 你可以使用下面指令安裝套件:&prompt.root; pkg_add -r gimp
- If your FTP site does not have this package, you can use
- the Ports Collection. The
+ 如果的你的 FTP 站台沒有這個套件,你可以使用
+ Ports Collection。 在 Ports Collection 的
graphics
- directory of the Ports Collection also contains
- The Gimp Manual. Here is how to
- get them installed:
+ 目錄下也包含了
+ The Gimp Manual(GIMP 使用手冊)。
+ 下面示範如何安裝這些程式:&prompt.root; cd /usr/ports/graphics/gimp
&prompt.root; make install clean
&prompt.root; cd /usr/ports/graphics/gimp-manual-pdf
&prompt.root; make install clean
-
- The
- graphics
- directory of the Ports Collection holds the development
- version of The GIMP in
- graphics/gimp-devel.
- An HTML version of
- The Gimp Manual is available from
- graphics/gimp-manual-html.
-
+ 譯註:另外在 Ports Collection 中也有一些外掛程式可以使用,
+ 例如說可以處理數位相機 raw 檔案格式的 gimp-ufraw。
+
+
+ GIMP 使用手冊也有 HTML 格式的,你可以在
+ graphics/gimp-manual-html
+ 中安裝。
+ OpenOffice.orgOpenOffice.orgoffice suiteOpenOffice.org
- OpenOffice.org includes all of the
- mandatory applications in a complete office productivity
- suite: a word processor, a spreadsheet, a presentation manager,
- and a drawing program. Its user interface is very similar
- to other office suites, and it can import and export in various
- popular file formats. It is available in a number of
- different languages including interfaces, spell checkers, and
- dictionaries.
-
- The word processor of
- OpenOffice.org uses a native XML
- file format for increased portability and flexibility. The
- spreadsheet program features a macro language and it can be
- interfaced with external databases.
- OpenOffice.org is already stable
- and runs natively on &windows;, &solaris;, Linux, FreeBSD,
- and &macos; X. More
- information about OpenOffice.org
- can be found on the
- OpenOffice.org web site.
- For FreeBSD specific information, and to directly
- download packages use the OpenOffice.org 包含了所有完整的辦公軟體組合:
+ 文字處理器、試算表、簡報軟體還有繪圖軟體。
+ 除了它的使用者介面非常類似其他的辦公軟體,
+ 他還能夠輸入和輸出許多熱門的檔案格式。
+ 它也包含了不同語言的使用者介面、拼字檢查和字典。
+
+ OpenOffice.org
+ 的文字處理器使用 XML 檔案格式來增加移植性及彈性。
+ 試算表程式支援巨集(macro)功能而且能夠使用外來的資料庫介面。
+ OpenOffice.org 已經十分穩定,
+ 並且能夠在 &windows;, &solaris;, Linux, FreeBSD 及
+ &macos; X 等作業系統上面執行。
+ 想知道更多關於 OpenOffice.org
+ 的資訊可以在
+ OpenOffice.org 網頁
+ 上查詢。你也可以在 FreeBSD OpenOffice.org
- Porting Team's web site.
+ 移植團隊
+ 的網頁上查詢關於 FreeBSD 上 OpenOffice 特定的資訊或直接下載已編譯好的套件
- To install OpenOffice.org,
- do:
+ 要安裝 OpenOffice.org,
+ 請用以下方式來執行:&prompt.root; pkg_add -r openoffice
- When running a -RELEASE version of &os;, this should work.
- Otherwise, you should look on the &os; OpenOffice.org Porting Team's
- web site to download and install the appropriate package
- using &man.pkg.add.1;. Both the current release and
- development version are available for download at this
- location.
+ 當你在使用 &os; -RELEASE 版本的時候,上面的作法應該行得通。
+ 要是其他的版本,你應該看一下 &os; OpenOffice.org
+ 移植團隊的網站,並且用 &man.pkg.add.1; 安裝合適的套件。
+ 在這個站台都可以下載到穩定的釋出版(release)或開發中的版本。
- Once the package is installed, you just have to type the
- following command to run
- OpenOffice.org:
+ 當已經安裝完之後,你只要鍵入下面的指令就能執行
+ OpenOffice.org:&prompt.user; openoffice.org
+
+ 譯註:端看你的版本,有時候需要輸入如 openoffice.org-2.0.1 之類的指令,
+ 不過你也可以用 shell 中的 alias 或是用 symbolic link 來處理。
- During the first launch, you will be asked some
- questions and a .openoffice.org2 folder
- will be created in your home directory.
+ 在第一次啟動的時候,OpenOffice 會問到一些問提。
+ 而且在你的家目錄底下會自動建立一個 .openoffice.org2
+ 的資料夾。
- If the OpenOffice.org packages
- are not available, you still have the option to compile the
- port. However, you must bear in mind that it requires a lot of
- disk space and a fairly long time to compile.
+ 如果無法取得 OpenOffice.org
+ 的套件,你仍然可以選擇從 port 編譯。
+ 不過你必須謹記在心:編譯的過程會需要大量的磁碟空間且相當耗時。
&prompt.root; cd /usr/ports/editors/openoffice.org-2.0
&prompt.root; make install clean
- If you want to build a localized version, replace the
- previous command line with the following:
+ 如果你想要安裝本地化的版本,把前面的指令代換成下面的:
- &prompt.root; make LOCALIZED_LANG=your_language install clean
+ &prompt.root; make LOCALIZED_LANG=你的語言 install clean
- You have to replace
- your_language with the correct
- language ISO-code. A list of supported language codes is
- available in the
- files/Makefile.localized file, located
- in the port directory.
+ 你必須把你的語言
+ 換成正確的語言 ISO-code 譯註:如臺灣正體中文使用者為 zh-TW)。
+ 所支援的語言代碼清單可以在 port 目錄裡的files/Makefile.localized
+ 檔案中找到。
+
- Once this is done,
- OpenOffice.org can be launched with
- the command:
+ 一旦完成了上述步驟,
+ OpenOffice.org 可用以下指令啟動:&prompt.user; openoffice.org
+
- Document Viewers
+ 文件閱覽器
- Some new document formats have recently gained popularity.
- The standard viewers they require may not be available in the
- base system. We will see how to install them in this
- section.
+ 近年來有些文件格式變得愈來愈流行,
+ 基本的系統中也許不會有這些格式所需的標準閱覽器。
+ 在這一節,我們來看看怎麼安裝這些軟體。
- This section covers these applications:
+ 這張涵蓋了下列的軟體
- Application Name
- Resources Needed
- Installation from Ports
- Major Dependencies
+ 軟體名稱
+ 所需系統資源
+ 從 Ports 安裝時間
+ 主要相依套件&acrobat.reader;
- light
- light
- Linux Binary Compatibility
+ 少
+ 短
+ Linux 二進制相容模組gv
- light
- light
+ 少
+ 短Xaw3dXpdf
- light
- light
+ 少
+ 短FreeTypeGQview
- light
- light
- Gtk+ or GNOME
+ 少
+ 短
+ Gtk+ 或是 GNOME&acrobat.reader;Acrobat ReaderPDF
- viewing
+ 閱覽
- Many documents are now distributed as PDF files,
- which stands for Portable Document Format. One
- of the recommended viewers for these types of files is
- &acrobat.reader;, released by Adobe
- for Linux. As FreeBSD can run Linux binaries, it is also
- available for FreeBSD.
+ 許多文件在散佈的時候都是用 PDF 的檔案格式,
+ 這個格式是基於 可攜式文件格式(Portable Document Format)。
+ 其中一個推薦的閱覽軟體就是&acrobat.reader;,
+ 它是由 Adobe 公司發行給 Linux 使用的版本。
+ 因為 FreeBSD 也可以執行 Linux 二進位檔案,
+ 所以它也能在 FreeBSD 上面執行。
- To install &acrobat.reader; 7 from
- the Ports collection, do:
+
+ 要從 Ports collection 中安裝
+ &acrobat.reader; 7
+ 只要:&prompt.root; cd /usr/ports/print/acroread7
&prompt.root; make install clean
- A package is not available due to licencing restrictions.
+ 因為授權的限制,所以不提供編譯好的套件。gvgvPDFviewingPostScript
- viewing
+ 閱覽
- gv is a &postscript; and PDF
- viewer. It is originally based on
- ghostview but it has a nicer look
- thanks to the Xaw3d library. It is fast and its interface is
- clean. gv has many features like
- orientation, paper size, scale, or antialias. Almost any
- operation can be done either from the keyboard or the
- mouse.
-
- To install gv as a package,
- do:
+ gv是 &postscript; 和 PDF 的閱覽器。
+ 它建構於 ghostview的基礎上,
+ 不過因為使用 Xaw3d 函式庫,
+ 所以外觀看起來比較漂亮。 gv 速度快,介面簡潔並且有許多功能,
+ 比如說方向性、紙張大小、縮放比例、和反鋸齒(antialias)等。
+ 而且幾乎所有的使用都可以從鍵盤或滑鼠來完成。
+ 用套件來安裝 gv,使用下列指令:
+
&prompt.root; pkg_add -r gv
- If you cannot get the package, you can use the Ports
- collection:
+ 如果你不能取得套件,你可以使用 Ports collection:&prompt.root; cd /usr/ports/print/gv
&prompt.root; make install cleanXpdfXpdfPDF
- viewing
+ 閱覽
- If you want a small FreeBSD PDF viewer,
- Xpdf is a light-weight and
- efficient viewer. It requires very few resources and is
- very stable. It uses the standard X fonts and does not
- require &motif; or any other X toolkit.
+ 如果你想要一個小型的 FreeBSD PDF 閱覽軟體,
+ Xpdf是個輕量級而且有效率的閱覽器。
+ 它只需要非常少的資源而且十分穩定。
+ 它只使用標準的 X 字型而不需要 &motif;
+ 或是其他的 X 工具組(toolkit)。
- To install the Xpdf package,
- issue this command:
+ 用套件來安裝 Xpdf,使用下列指令:&prompt.root; pkg_add -r xpdf
- If the package is not available or you prefer to use the
- Ports Collection, do:
-
+ 如果套件不存在或是你偏好使用 Ports Collection,
+ 使用以下指令:
+
&prompt.root; cd /usr/ports/graphics/xpdf
&prompt.root; make install clean
- Once the installation is complete, you can launch
- Xpdf and use the right mouse button
- to activate the menu.
+ 一旦完成了安裝,你可以啟動 Xpdf
+ 並且使用滑鼠右鍵去使用選單。GQviewGQview
- GQview is an image manager.
- You can view a file with a single click, launch an external
- editor, get thumbnail previews, and much more. It also
- features a slideshow mode and some basic file operations. You
- can manage image collections and easily find duplicates.
- GQview can do full screen viewing
- and supports internationalization.
-
- If you want to install the
- GQview package, do:
+ GQview 是影像管理軟體。
+ 你可以用單鍵來閱覽檔案、啟動額外的編輯器、縮圖預覽等功能。
+ 它也有幻燈片播放(slideshow)及一些基本的檔案操作功能。
+ 你可用 GQview 管理影像集並能輕鬆地找出重複的檔案。
+ GQview
+ 能夠使用全螢幕觀看並支援國際化。
+ 如果你想要安裝 GQview的套件,
+ 請使用下列指令:
+
&prompt.root; pkg_add -r gqview
- If the package is not available or you prefer to use the
- Ports Collection, do:
+ 如果套件無法取得,或是你比較喜歡使用 Ports Collection,只要:&prompt.root; cd /usr/ports/graphics/gqview
&prompt.root; make install clean
- Finance
+ 財務
- If, for any reason, you would like to manage your personal
- finances on your FreeBSD Desktop, there are some powerful and
- easy to use applications ready to be installed. Some of them
- are compatible with widespread file formats like those of
- Quicken or Excel documents.
+ 如果有任何理由你想要在你的 FreeBSD 桌面環境上管理你的個人財務,
+ 這裡有一些功能強大、使用簡單的應用程式可供安裝。
+ 這些財務管理軟體之中有些是相容於流行的
+ Quicken 或 Excel 文件。
- This section covers these applications:
+ 這節涵蓋了下面這些軟體:
- Application Name
- Resources Needed
- Installation from Ports
- Major Dependencies
+ 軟體名稱
+ 所需系統資源
+ 從 Ports 安裝的時間
+ 主要的相依套件GnuCash
- light
- heavy
+ 少
+ 長GNOMEGnumeric
- light
- heavy
+ 少
+ 長GNOMEAbacus
- light
- light
+ 少
+ 短Tcl/TkGnuCashGnuCash
- GnuCash is part of the
- GNOME effort to provide
- user-friendly yet powerful applications to end-users. With
- GnuCash, you can keep track of your
- income and expenses, your bank accounts, or your stocks. It
- features an intuitive interface while remaining very
- professional.
-
- GnuCash provides a smart
- register, a hierarchical system of accounts, many keyboard
- accelerators and auto-completion methods. It can split a
- single transaction into several more detailed pieces.
- GnuCash can import and merge
- Quicken QIF files. It also handles most international date
- and currency formats.
-
- To install GnuCash on your
- system, do:
+ GnuCash 是
+ GNOME 團隊努力成果中的一部分,
+ 而 GNOME 主要是提供終端使用者(end-users)
+ 親切而強大的桌面應用程式。
+ 使用 GnuCash,
+ 你可以持續紀錄你的收入及花費、你的銀行帳戶、或是你的股票證券等。
+ 它的特性是介面直覺但功能仍非常專業。
+
+ GnuCash 提供了一個智慧的註冊器、
+ 帳戶層級系統、許多快速鍵及自動完成(auto-completion)模式。
+ 它也能分開單一的報表至數個詳細的部份。
+ GnuCash 也能夠輸入及合併
+ Quicken QIF 檔案。
+ 它也能處理大部分國際的日期及通用貨幣之格式。
+
+ 要安裝 GnuCash 到你的系統中,
+ 只要做下列步驟:&prompt.root; pkg_add -r gnucash
- If the package is not available, you can use the ports
- collection:
+ 如果不能取得套件,你可以使用 ports collection:&prompt.root; cd /usr/ports/finance/gnucash
&prompt.root; make install cleanGnumericGnumeric
- spreadsheet
+ 試算表Gnumeric
- Gnumeric is a spreadsheet, part
- of the GNOME desktop environment.
- It features convenient automatic guessing of user
- input according to the cell format and an autofill system for
- many sequences. It can import files in a number of popular
- formats like those of Excel, Lotus 1-2-3, or Quattro Pro.
- Gnumeric supports graphs through
- the math/guppi graphing
- program. It has a large number of built-in functions and
- allows all of the usual cell formats such as number, currency,
- date, time, and much more.
-
- To install Gnumeric as a
- package, type in:
+ Gnumeric 是
+ GNOME 桌面環境中的試算表。
+ 它的特點是能夠根據儲存格格式(cell format)及自動補齊的系統,
+ 來方便自動地「猜出」使用者的輸入。
+ 它也能夠輸入許多熱門的檔案格式,像是
+ Excel, Lotus 1-2-3, 或是 Quattro Pro。
+
+ Gnumeric 支援使用
+ math/guppi 繪圖軟體來繪圖。
+ 它有許多內建的函數而且允許一般的儲存格格式,像是:
+ 數字、貨幣、日期、時間及其他格式等。
+
+ 要用套件安裝 Gnumeric,只要打以下指令:&prompt.root; pkg_add -r gnumeric
- If the package is not available, you can use the ports
- collection by doing:
+ 如果套件不存在,你可以做下面的步驟來使用 ports collection 編譯安裝:&prompt.root; cd /usr/ports/math/gnumeric
&prompt.root; make install cleanAbacusAbacus
- spreadsheet
+ 試算表Abacus
- Abacus is a small and easy to
- use spreadsheet. It includes many built-in functions useful
- in several domains such as statistics, finances, and
- mathematics. It can import and export the Excel file format.
- Abacus can produce &postscript;
- output.
+ Abacus 是個小巧又使用簡單的試算表。
+ 它包含了許多內建的函數,在相關的領域如統計學、財務、數學中很實用。
+ 它也可以輸出輸入 Excel 的檔案格式。
+ 另外 Abacus也能夠輸出 &postscript; 格式。
- To install Abacus from its
- package, do:
+ 從套件安裝 Abacus 只要做:&prompt.root; pkg_add -r abacus
- If the package is not available, you can use the ports
- collection by doing:
+ 如果套件不能取得的話,你可以使用 ports collection ,
+ 並用以下指令:&prompt.root; cd /usr/ports/deskutils/abacus
&prompt.root; make install clean
- Summary
+ 摘要
- While FreeBSD is popular among ISPs for its performance and
- stability, it is quite ready for day-to-day use as a desktop.
- With several thousand applications available as
- packages or
+ 雖然 FreeBSD 是因為效能及穩定性而在 ISP 之間很流行,
+ 不過它也可以完全當作桌面環境(desktop)來使用,
+ 並不侷限於使用在伺服器上面。目前有數千種應用程式的
+ 套件(packages)
+ 或
ports,
- you can build a perfect desktop that suits all your needs.
-
- Once you have achieved the installation of your desktop, you
- may want to go one step further with
- misc/instant-workstation.
- This meta-port allows you to build a typical set
- of ports for a workstation. You can customize it by editing
- /usr/ports/misc/instant-workstation/Makefile.
- Follow the syntax used for the default set to add or remove
- ports, and build it with the usual procedure.
- Eventually, you will be able to create a big package that
- corresponds to your very own desktop and install it to your
- other workstations!
-
- Here is a quick review of all the desktop applications
- covered in this chapter:
+ 可供使用,你可以根據你的需求打造出一個完美的桌面環境。
+
+ 一旦你完成了你的桌面環境的安裝,你也許想要使用
+ misc/instant-workstations
+ 來做更進一步的設置。這個「meta-port」允許你使用數個 ports
+ 來建造自定的工作站環境。你可以自行編輯客製化
+ /usr/ports/misc/instant-workstations/Makefile
+ 這個檔案。 遵循預設的語法去增加或減少 ports,
+ 並且使用一般的程序去做。
+ 最後,你將能夠建立一個適合你自己桌面環境的套件,
+ 並且可以安裝在你自己其他的工作站裡頭。
+
+ 下面是這章涵蓋的所有桌面應用軟體之快速回顧列表:
- Application Name
- Package Name
- Ports Name
+ 軟體名稱
+ 套件名稱
+ Ports 名稱Mozillamozillawww/mozillaOperaoperawww/operaFirefoxfirefoxwww/firefoxKOfficekoffice-kde3editors/koffice-kde3AbiWordabiwordeditors/abiwordThe GIMPgimpgraphics/gimpOpenOffice.orgopenofficeeditors/openoffice-1.1&acrobat.reader;acroreadprint/acroread7gvgvprint/gvXpdfxpdfgraphics/xpdfGQviewgqviewgraphics/gqviewGnuCashgnucashfinance/gnucashGnumericgnumericmath/gnumericAbacusabacusdeskutils/abacus
diff --git a/zh_TW.Big5/books/handbook/disks/chapter.sgml b/zh_TW.Big5/books/handbook/disks/chapter.sgml
index 27e04beb85..c6ec473169 100644
--- a/zh_TW.Big5/books/handbook/disks/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/disks/chapter.sgml
@@ -1,4131 +1,4114 @@
儲存設備篇概述
- 本章涵蓋如何在 FreeBSD 下使用碟片裝置,包含
- memory-backed disk (用記憶體作為硬碟使用)、跨網路使用的硬碟、
+ 本章涵蓋如何在 FreeBSD 下使用碟片裝置
+ 譯註:雖然有些設備沒有『碟片』,例如 USB 隨身碟,
+ 不過在此仍把 Disk 譯為『碟片裝置』。此外,為方便起見,
+ 後文所有的 Disk 都譯為『硬碟』。
+ 包含 memory-backed disk (用記憶體作為硬碟使用)、跨網路使用的硬碟、
標準 SCSI/IDE 硬碟、USB 介面的設備等。閱讀本章後,您裝學會:FreeBSD 如何描述資料在硬碟上的劃分情形
(partition 和 slices)。如何在系統上加入硬碟如何設定 &os; 來使用 USB 裝置。如何設定虛擬檔案系統 (virtual file systems),
例如 memory disks (用記憶體作為硬碟使用)。如何用 quota 來限制硬碟空間的使用。如何對硬碟加密以應付攻擊。如何在 FreeBSD 下建立、燒錄 CD 和 DVD。各種不同的備份設備。如何使用 FreeBSD 提供的備份工具。如何備份到軟碟。什麼是 snapshots ,且如何有效率地使用之。在閱讀之前,您應該:知道如何配置、安裝新的 FreeBSD 核心。
().裝置名稱下面是 FreeBSD 支援的儲存媒體列表,及它們對應的裝置名稱。
DavidO'BrienOriginally contributed by 新增硬碟diskadding假設我們想新增 SCSI 硬碟到一臺原先只有一顆硬碟的機器上,
首先將電腦關機,依製造商的指示將硬碟裝上去,
詳細的操作方式請參考製造商的說明文件。安裝好硬碟後,用 root 登入系統,
看一下 /var/run/dmesg.boot 以確認系統是否抓到新硬碟。
繼續剛才的範例,新增的硬碟會是 da1,
假設我們想將它掛載到 /1 這個位置
(如果您新增的是 IDE 硬碟的話,4.0 之前的系統是
wd1,4.X 及之後的系統則是
ad1)。partitionsslicesfdiskFreeBSD 為了在 IBM-PC 相容電腦上執行,
必須配合 PC BIOS partition,因此和傳統的 BSD partition 有很大的不同。
在 PC 裡硬碟最多可以有四筆 BIOS partition 資訊(亦即最多可分割成四個
partition)。如果這個硬碟打算全部讓 FreeBSD 使用,可選擇
dedicated 模式,
不然的話 FreeBSD 必須置身於其中一個 PC BIOS partition 中。
在 FreeBSD 裡,PC BIOS partition 稱為 slice,
- 這是為了不要和傳統的 BSD partition 搞混了。
+ 這是為了不要和傳統的 BSD partition 搞混了
+ 譯註:基於相同的理由,
+ 現在 BSD partition 常稱為 BSD label,或簡稱 label。
不論是完全由 FreeBSD 使用的硬碟,還是安裝了其它作業系統的硬碟,
您都可以使用 slice。這樣的好處是,其它非 FreeBSD 作業系統的
fdisk 工具可以順利操作。如果使用 slice,這個新增的硬碟會是
/dev/da1s1e。可以這樣來解讀它:SCSI 硬碟、
unit number 1(第二個 SCSI 硬碟)、slice 1(第一個 PC BIOS partition)、
及 e BSD partition。在 dedicated 模式的話,
新硬碟則是 /dev/da1e。因為 &man.bsdlabel.8;(在 &os; 4.X 稱為 &man.disklabel.8;)
用 32-bit 整數來儲存 sector(磁區) 數,
因此限制一個硬碟最大只能有 2^32-1 個 sector,亦即 2TB 的空間。
而 &man.fdisk.8; 的格式容許起始 sector 編號不超過 2^32-1,
長度也不超過 2^32-1,因此 partition 最大空間是 2TB,而硬碟最大是 4TB。
&man.sunlabel.8; 則限制 partition 最大是 2TB,硬碟最多可有 8 個 partition,
因此最大是 16TB。如果要使用更大的硬碟,請使用 &man.gpt.8;。
- Using &man.sysinstall.8;
+ 使用 &man.sysinstall.8;sysinstall
- adding disks
+ 新增硬碟su
- Navigating Sysinstall
+ 操作 Sysinstall
- You may use sysinstall
+ 透過 sysinstall
(/stand/sysinstall in &os; versions older
- than 5.2) to
- partition and label a new disk using its easy to use menus.
- Either login as user root or use the
- su command. Run
- sysinstall and enter the
- Configure menu. Within the
- FreeBSD Configuration Menu, scroll down and
- select the Fdisk option.
+ than 5.2) 的選單介面,您可以輕易為硬碟分割 BIOS partition(slice)
+ 和 BSD patition。您必須以 root 身份使用 sysinstall,
+ 要嘛用 root 登入,要嘛用 su 切換到 root。
+ 執行 sysinstall 後,選 Configure
+ ,在 FreeBSD Configuration Menu 裡移到
+ Fdisk 選項,
- fdisk Partition Editor
- Once inside fdisk, typing A will
- use the entire disk for FreeBSD. When asked if you want to
- remain cooperative with any future possible operating
- systems, answer YES. Write the
- changes to the disk using W. Now exit the
- FDISK editor by typing q. Next you will be
- asked about the Master Boot Record. Since you are adding a
- disk to an already running system, choose
- None.
+ fdisk Partition 編輯器
+ 在 fdisk 裡,按下
+ A 表示整個硬碟都給 FreeBSD 使用。
+ 接著會提示您『是否要相容其它的作業系統』,回答 YES。
+ 按 W 會將這些改變立即寫入硬碟,
+ 再按 q 可以離開 FDISK 編輯器。
+ 接下來會問您要將 Master Boot Record 安裝於何處,
+ 由於現在是新增硬碟,表示作業系統已經裝在別的硬碟上了,所以可以
+ None 就行了。
- Disk Label Editor
+ Disk Label Editor(硬碟 Label 編輯器)BSD partitions
- Next, you need to exit sysinstall
- and start it again. Follow the directions above, although this
- time choose the Label option. This will
- enter the Disk Label Editor. This
- is where you will create the traditional BSD partitions. A
- disk can have up to eight partitions, labeled
- a-h.
- A few of the partition labels have special uses. The
- a partition is used for the root partition
- (/). Thus only your system disk (e.g,
- the disk you boot from) should have an a
- partition. The b partition is used for
- swap partitions, and you may have many disks with swap
- partitions. The c partition addresses the
- entire disk in dedicated mode, or the entire FreeBSD slice in
- slice mode. The other partitions are for general use.
-
- sysinstall's Label editor
- favors the e
- partition for non-root, non-swap partitions. Within the
- Label editor, create a single file system by typing
- C. When prompted if this will be a FS
- (file system) or swap, choose FS and type in a
- mount point (e.g, /mnt). When adding a
- disk in post-install mode, sysinstall
- will not create entries
- in /etc/fstab for you, so the mount point
- you specify is not important.
-
- You are now ready to write the new label to the disk and
- create a file system on it. Do this by typing
- W. Ignore any errors from
- sysinstall that
- it could not mount the new partition. Exit the Label Editor
- and sysinstall completely.
+ 接著請關閉 sysinstall,
+ 再重開一次。照著上一節的指示,不過這次改選 Label
+ 進入 Disk Label Editor,在此您可以編輯傳統的
+ BSD partition。一個硬碟(或著一個 slice) 最多可切分成 8 個 BSD partition,
+ 依序用 a-h 來表示。
+ 有些字母有特別的意義,a partition 表示這是
+ root partition(根分割區,/),
+ 因此只有安裝系統的硬碟(例如用來開機的硬碟) 有
+ a partition。b partition
+ 表示這是 swap partitions(交換分割區),每個硬碟上都可以有交換分割區。
+ c partition
+ 用來表示整個硬碟(如果使用 dedicated mode 的話)
+ 或整個 slice。其它的字母則用來表示普通的 BSD partition。
+
+ sysinstall 的
+ Label editor(硬碟 Label 編輯器) 偏好用 e
+ 來表示非 root、也非 swap 的分割區
+ 譯註:老實說我看不懂這句指的是什麼?原文是
+ sysinstall Label editor
+ favors the e partition for non-root,
+ non-swap partitions. 在 Label editor 裡,
+ 按 C 可以新增一個檔案系統(BSD label),
+ 它會問您這是一個 FS(file system,檔案系統) 或是 swap(交換分割區),
+ 選擇 FS 接著輸入要掛載的位置
+ (例如 /mnt)。如果系統安裝完後才新增硬碟,
+ sysinstall 不會幫您把這筆掛載資料加入
+ /etc/fstab,所以掛載的位置不太重要。
+
+ 當您準備好將新的 label 寫入硬碟、建立檔案系統,
+ 按 W 即可。如果出現在什麼錯誤,
+ sysinstall 可能無法幫您掛載這個新分割區。
+ 結束 Label Editor、結束 sysinstall 就行了。
- Finish
+ 完成
- The last step is to edit /etc/fstab
- to add an entry for your new disk.
+ 最後要做的是編輯 /etc/fstab,
+ 加入您新增的分割區資訊。
- Using Command Line Utilities
+ 使用命令列工具
- Using Slices
-
- This setup will allow your disk to work correctly with
- other operating systems that might be installed on your
- computer and will not confuse other operating systems'
- fdisk utilities. It is recommended
- to use this method for new disk installs. Only use
- dedicated mode if you have a good reason
- to do so!
-
+ 使用 Slices(BIOS partitions)
+
+ 這種模式能讓您的硬碟分割區與其它作業系統的
+ fdisk 工具和平共處,因此我們建議您使用 slice 模式。
+ 如果您一定要使用 dedicated 模式,
+ 您得有個好理由!
+ 譯註:如果您自始至終都不打算將這個硬碟用於 FreeBSD
+ 之外的作業系統,那可以算是個好理由。不過就算如此,
+ 用 slice 模式也沒什麼壞處就是了:-)。
+
&prompt.root; dd if=/dev/zero of=/dev/da1 bs=1k count=1
-&prompt.root; fdisk -BI da1 #Initialize your new disk
-&prompt.root; disklabel -B -w -r da1s1 auto #Label it.
-&prompt.root; disklabel -e da1s1 # Edit the disklabel just created and add any partitions.
+&prompt.root; fdisk -BI da1 # 初始您的硬碟。
+&prompt.root; disklabel -B -w -r da1s1 auto # 建立 disklabel。
+&prompt.root; disklabel -e da1s1 # 編輯 disklabel 以新增 label。
&prompt.root; mkdir -p /1
-&prompt.root; newfs /dev/da1s1e # Repeat this for every partition you created.
-&prompt.root; mount /dev/da1s1e /1 # Mount the partition(s)
-&prompt.root; vi /etc/fstab # Add the appropriate entry/entries to your /etc/fstab.
-
- If you have an IDE disk, substitute ad
- for da. On pre-4.X systems use
- wd.
+&prompt.root; newfs /dev/da1s1e # 如果您新增了多個 label,對每個 label 重覆這個步驟。
+&prompt.root; mount /dev/da1s1e /1 # 掛載這些新 label。
+&prompt.root; vi /etc/fstab # 在 /etc/fstab 加入適當的資訊。
+
+ 如果您新增的是 IDE 硬碟,將 da
+ 改成 da 即可
+ 譯註:da 是 direct access,ad 則是 ata disk。。
+ 而如果是 4.X 之前的系統,用 wd。DedicatedOS/2
- If you will not be sharing the new drive with another operating
- system, you may use the dedicated mode. Remember
- this mode can confuse Microsoft operating systems; however, no damage
- will be done by them. IBM's &os2; however, will
- appropriate any partition it finds which it does not
- understand.
-
+ 如果您不打算將新硬碟用於其它的作業系統,
+ 您可以使用 dedicated 模式。注意:
+ Microsoft 的作業系統認不得這個模式,不過也不會去破壞它;
+ 然而 IBM 的 &os2; 就沒那麼好心了,它會去調整所有它不認得的分割區
+ 譯註:我對這句的意思沒什麼信心,原文是 IBM's &os2; however,
+ will appropriate any partition it finds which it does
+ not understand.。
+
&prompt.root; dd if=/dev/zero of=/dev/da1 bs=1k count=1
&prompt.root; disklabel -Brw da1 auto
-&prompt.root; disklabel -e da1 # create the `e' partition
+&prompt.root; disklabel -e da1 # 建立 `e' partition。
&prompt.root; newfs -d0 /dev/da1e
&prompt.root; mkdir -p /1
-&prompt.root; vi /etc/fstab # add an entry for /dev/da1e
+&prompt.root; vi /etc/fstab # 新增一筆 /dev/da1e 的資訊。
&prompt.root; mount /1
- An alternate method is:
+ 另一種方法:&prompt.root; dd if=/dev/zero of=/dev/da1 count=2
&prompt.root; disklabel /dev/da1 | disklabel -BrR da1 /dev/stdin
&prompt.root; newfs /dev/da1e
&prompt.root; mkdir -p /1
-&prompt.root; vi /etc/fstab # add an entry for /dev/da1e
+&prompt.root; vi /etc/fstab # 新增一筆 /dev/da1e 的資訊。
&prompt.root; mount /1
- Since &os; 5.1-RELEASE, the &man.bsdlabel.8;
- utility replaces the old &man.disklabel.8; program. With
- &man.bsdlabel.8; a number of obsolete options and parameters
- have been retired; in the examples above the option
- should be removed with &man.bsdlabel.8;.
- For more information, please refer to the &man.bsdlabel.8;
- manual page.
+ 從 &os; 5.1-RELEASE 開始,&man.bsdlabel.8; 取代原本的
+ &man.disklabel.8; 程式,某些指令參數已經廢棄不用。
+ 上面範例裡,如果用的是 &man.bsdlabel.8;,
+ 參數應該拿掉。更多的資訊請參考 &man.bsdlabel.8; manual page。
+ RAID
- Software RAID
+ 軟體 RAIDChristopherShumwayOriginal work by JimBrownRevised by RAIDsoftwareRAIDCCD
- Concatenated Disk Driver (CCD) Configuration
- When choosing a mass storage solution the most important
- factors to consider are speed, reliability, and cost. It is
- rare to have all three in balance; normally a fast, reliable mass
- storage device is expensive, and to cut back on cost either speed
- or reliability must be sacrificed.
+ 連接式磁碟裝置驅動程式(CCD, Concatenated Disk Driver) 設定
+ 對大容量儲存設備而言,最關鍵的要素乃是速度、可靠性及價格。
+ 然而這三者往往難以兼顧:快速可靠的設備通常很貴;
+ 而降低成本通常也犧牲了速度或可靠性。
+
+ 接下來要介紹的系統,價格是最重要的考量,接下來是速度,最後才是可靠性。
+ 順序如此是因為資料傳輸的速度最終取決於網路,而儘管可靠性十分重要,
+ 卻有簡單的取代方案:將資料完整備份於 CD-R 中。
- In designing the system described below, cost was chosen
- as the most important factor, followed by speed, then reliability.
- Data transfer speed for this system is ultimately
- constrained by the network. And while reliability is very important,
- the CCD drive described below serves online data that is already
- fully backed up on CD-R's and can easily be replaced.
+ 選擇大容量儲存設備方案時,首先要定義您的需求。如果您重視速度或可靠性
+ 甚於價格,接下來的介紹恐非您所需。
- Defining your own requirements is the first step
- in choosing a mass storage solution. If your requirements prefer
- speed or reliability over cost, your solution will differ from
- the system described in this section.
+
+ 安裝硬體
+ 除了系統磁碟外,下面介紹的 CCD 磁碟陣列將使用到三顆 30GB、
+ 5400 RPM 的 Western Digital IDE 磁碟,以提供約 90GB 的儲存空間。
+ 最理想的情況是每個磁碟由獨立使用的排線連接獨立使用的 IDE 控制器,
+ 不過為了降低成本,利用 jumper 設定磁碟,使每個 IDE 控制器可連接
+ 一個主磁碟加一個副磁碟,如此可不必加裝額外的 IDE 控制器。
-
- Installing the Hardware
-
- In addition to the IDE system disk, three Western
- Digital 30GB, 5400 RPM IDE disks form the core
- of the CCD disk described below providing approximately
- 90GB of online storage. Ideally,
- each IDE disk would have its own IDE controller
- and cable, but to minimize cost, additional
- IDE controllers were not used. Instead the disks were
- configured with jumpers so that each IDE controller has
- one master, and one slave.
-
- Upon reboot, the system BIOS was configured to
- automatically detect the disks attached. More importantly,
- FreeBSD detected them on reboot:
+ 開機後,BIOS 應該設定成自重偵測磁碟。更重要的是 FreeBSD 應該
+ 要偵測到它們:ad0: 19574MB <WDC WD205BA> [39770/16/63] at ata0-master UDMA33
ad1: 29333MB <WDC WD307AA> [59598/16/63] at ata0-slave UDMA33
ad2: 29333MB <WDC WD307AA> [59598/16/63] at ata1-master UDMA33
ad3: 29333MB <WDC WD307AA> [59598/16/63] at ata1-slave UDMA33
- If FreeBSD does not detect all the disks, ensure
- that you have jumpered them correctly. Most IDE drives
- also have a Cable Select jumper. This is
- not the jumper for the master/slave
- relationship. Consult the drive documentation for help in
- identifying the correct jumper.
-
- Next, consider how to attach them as part of the file
- system. You should research both &man.vinum.8; () and &man.ccd.4;. In this
- particular configuration, &man.ccd.4; was chosen.
+ 如果 FreeBSD 沒有偵測到所有磁碟,請確認 jumper 都設定正確。
+ 許多 IDE 磁碟可以設定成 Cable Select(根據排線位置決定),
+ 這並非 master(主磁碟) 或 slave(副磁碟)。請參閱磁
+ 碟的說明文件以正確設定 jumper。
+
+ 接下來,考慮如何將它們變成檔案系統的一部份。您可以參考
+ &man.vinum.8;() 及 &man.ccd.4。
+ 在此我們選擇 &man.ccd.4; 。Setting Up the CCDThe &man.ccd.4; driver allows you to take
several identical disks and concatenate them into one
logical file system. In order to use
&man.ccd.4;, you need a kernel with
&man.ccd.4; support built in.
Add this line to your kernel configuration file, rebuild, and
reinstall the kernel:pseudo-device ccd 4On 5.X systems, you have to use instead the following
line:device ccdIn FreeBSD 5.X, it is not necessary to specify
a number of &man.ccd.4; devices, as the &man.ccd.4; device driver is now
self-cloning — new device instances will automatically be
created on demand.The &man.ccd.4; support can also be
loaded as a kernel loadable module in FreeBSD 3.0 or
later.To set up &man.ccd.4;, you must first use
&man.disklabel.8; to label the disks:disklabel -r -w ad1 auto
disklabel -r -w ad2 auto
disklabel -r -w ad3 autoThis creates a disklabel for ad1c, ad2c and ad3c that
spans the entire disk.Since &os; 5.1-RELEASE, the &man.bsdlabel.8;
utility replaces the old &man.disklabel.8; program. With
&man.bsdlabel.8; a number of obsolete options and parameters
have been retired; in the examples above the option
should be removed. For more
information, please refer to the &man.bsdlabel.8;
manual page.The next step is to change the disk label type. You
can use &man.disklabel.8; to edit the
disks:disklabel -e ad1
disklabel -e ad2
disklabel -e ad3This opens up the current disk label on each disk with
the editor specified by the EDITOR
environment variable, typically &man.vi.1;.An unmodified disk label will look something like
this:8 partitions:
# size offset fstype [fsize bsize bps/cpg]
c: 60074784 0 unused 0 0 0 # (Cyl. 0 - 59597)Add a new e partition for &man.ccd.4; to use. This
can usually be copied from the c partition,
but the must
be 4.2BSD. The disk label should
now look something like this:8 partitions:
# size offset fstype [fsize bsize bps/cpg]
c: 60074784 0 unused 0 0 0 # (Cyl. 0 - 59597)
e: 60074784 0 4.2BSD 0 0 0 # (Cyl. 0 - 59597)Building the File SystemThe device node for
ccd0c may not exist yet, so to
create it, perform the following commands:cd /dev
sh MAKEDEV ccd0In FreeBSD 5.0, &man.devfs.5; will automatically
manage device nodes in /dev, so use of
MAKEDEV is not necessary.Now that you have all the disks labeled, you must
build the &man.ccd.4;. To do that,
use &man.ccdconfig.8;, with options similar to the following:ccdconfig ccd0 32 0 /dev/ad1e /dev/ad2e /dev/ad3eThe use and meaning of each option is shown below:The first argument is the device to configure, in this case,
/dev/ccd0c. The /dev/
portion is optional.The interleave for the file system. The interleave
defines the size of a stripe in disk blocks, each normally 512 bytes.
So, an interleave of 32 would be 16,384 bytes.Flags for &man.ccdconfig.8;. If you want to enable drive
mirroring, you can specify a flag here. This
configuration does not provide mirroring for
&man.ccd.4;, so it is set at 0 (zero).The final arguments to &man.ccdconfig.8;
are the devices to place into the array. Use the complete pathname
for each device.After running &man.ccdconfig.8; the &man.ccd.4;
is configured. A file system can be installed. Refer to &man.newfs.8;
for options, or simply run: newfs /dev/ccd0cMaking it All AutomaticGenerally, you will want to mount the
&man.ccd.4; upon each reboot. To do this, you must
configure it first. Write out your current configuration to
/etc/ccd.conf using the following command:ccdconfig -g > /etc/ccd.confDuring reboot, the script /etc/rc
runs ccdconfig -C if /etc/ccd.conf
exists. This automatically configures the
&man.ccd.4; so it can be mounted.If you are booting into single user mode, before you can
&man.mount.8; the &man.ccd.4;, you
need to issue the following command to configure the
array:ccdconfig -CTo automatically mount the &man.ccd.4;,
place an entry for the &man.ccd.4; in
/etc/fstab so it will be mounted at
boot time:/dev/ccd0c /media ufs rw 2 2The Vinum Volume ManagerRAIDsoftwareRAIDVinumThe Vinum Volume Manager is a block device driver which
implements virtual disk drives. It isolates disk hardware
from the block device interface and maps data in ways which
result in an increase in flexibility, performance and
reliability compared to the traditional slice view of disk
storage. &man.vinum.8; implements the RAID-0, RAID-1 and
RAID-5 models, both individually and in combination.See for more
information about &man.vinum.8;.Hardware RAIDRAIDhardwareFreeBSD also supports a variety of hardware RAID
controllers. These devices control a RAID subsystem
without the need for FreeBSD specific software to manage the
array.Using an on-card BIOS, the card controls most of the disk operations
itself. The following is a brief setup description using a Promise IDE RAID
controller. When this card is installed and the system is started up, it
displays a prompt requesting information. Follow the instructions
to enter the card's setup screen. From here, you have the ability to
combine all the attached drives. After doing so, the disk(s) will look like
a single drive to FreeBSD. Other RAID levels can be set up
accordingly.
Rebuilding ATA RAID1 ArraysFreeBSD allows you to hot-replace a failed disk in an array. This requires
that you catch it before you reboot.You will probably see something like the following in /var/log/messages or in the &man.dmesg.8;
output:ad6 on monster1 suffered a hard error.
ad6: READ command timeout tag=0 serv=0 - resetting
ad6: trying fallback to PIO mode
ata3: resetting devices .. done
ad6: hard error reading fsbn 1116119 of 0-7 (ad6 bn 1116119; cn 1107 tn 4 sn 11)\\
status=59 error=40
ar0: WARNING - mirror lostUsing &man.atacontrol.8;, check for further information:&prompt.root; atacontrol list
ATA channel 0:
Master: no device present
Slave: acd0 <HL-DT-ST CD-ROM GCR-8520B/1.00> ATA/ATAPI rev 0
ATA channel 1:
Master: no device present
Slave: no device present
ATA channel 2:
Master: ad4 <MAXTOR 6L080J4/A93.0500> ATA/ATAPI rev 5
Slave: no device present
ATA channel 3:
Master: ad6 <MAXTOR 6L080J4/A93.0500> ATA/ATAPI rev 5
Slave: no device present
&prompt.root; atacontrol status ar0
ar0: ATA RAID1 subdisks: ad4 ad6 status: DEGRADEDYou will first need to detach the ata channel with the failed
disk so you can safely remove it:&prompt.root; atacontrol detach ata3Replace the disk.Reattach the ata channel:&prompt.root; atacontrol attach ata3
Master: ad6 <MAXTOR 6L080J4/A93.0500> ATA/ATAPI rev 5
Slave: no device presentAdd the new disk to the array as a spare:&prompt.root; atacontrol addspare ar0 ad6Rebuild the array:&prompt.root; atacontrol rebuild ar0It is possible to check on the progress by issuing the
following command:&prompt.root; dmesg | tail -10
[output removed]
ad6: removed from configuration
ad6: deleted from ar0 disk1
ad6: inserted into ar0 disk1 as spare
&prompt.root; atacontrol status ar0
ar0: ATA RAID1 subdisks: ad4 ad6 status: REBUILDING 0% completedWait until this operation completes.MarcFonvieilleContributed by USB Storage DevicesUSBdisksA lot of external storage solutions, nowadays, use the
Universal Serial Bus (USB): hard drives, USB thumbdrives, CD-R
burners, etc. &os; provides support for these devices.ConfigurationThe USB mass storage devices driver, &man.umass.4;,
provides the support for USB storage devices. If you use the
GENERIC kernel, you do not have to change
anything in your configuration. If you use a custom kernel,
be sure that the following lines are present in your kernel
configuration file:device scbus
device da
device pass
device uhci
device ohci
device usb
device umassThe &man.umass.4; driver uses the SCSI subsystem to access
to the USB storage devices, your USB device will be seen as a
SCSI device by the system. Depending on the USB chipset on
your motherboard, you only need either device
uhci or device ohci, however
having both in the kernel configuration file is harmless. Do
not forget to compile and install the new kernel if you added
any lines.If your USB device is a CD-R or DVD burner, the SCSI CD-ROM
driver, &man.cd.4;, must be added to the kernel via the
line:device cdSince the burner is seen as a SCSI drive, the driver
&man.atapicam.4; should not be used in the kernel
configuration.Support for USB 2.0 controllers is provided on
&os; 5.X, and on the 4.X branch since &os; 4.10-RELEASE.
You have to add:device ehcito your configuration file for USB 2.0 support. Note
&man.uhci.4; and &man.ohci.4; drivers are still needed if you
want USB 1.X support.On &os; 4.X, the USB daemon (&man.usbd.8;) must be
running to be able to see some USB devices. To enable it,
add usbd_enable="YES" to your
/etc/rc.conf file and reboot the
machine.Testing the ConfigurationThe configuration is ready to be tested: plug in your USB
device, and in the system message buffer (&man.dmesg.8;), the
drive should appear as something like:umass0: USB Solid state disk, rev 1.10/1.00, addr 2
GEOM: create disk da0 dp=0xc2d74850
da0 at umass-sim0 bus 0 target 0 lun 0
da0: <Generic Traveling Disk 1.11> Removable Direct Access SCSI-2 device
da0: 1.000MB/s transfers
da0: 126MB (258048 512 byte sectors: 64H 32S/T 126C)Of course, the brand, the device node
(da0) and other details can differ
according to your configuration.Since the USB device is seen as a SCSI one, the
camcontrol command can be used to list the
USB storage devices attached to the system:&prompt.root; camcontrol devlist
<Generic Traveling Disk 1.11> at scbus0 target 0 lun 0 (da0,pass0)If the drive comes with a file system, you should be able
to mount it. The will help you
to format and create partitions on the USB drive if
needed.If you unplug the device (the disk must be unmounted
before), you should see, in the system message buffer,
something like the following:umass0: at uhub0 port 1 (addr 2) disconnected
(da0:umass-sim0:0:0:0): lost device
(da0:umass-sim0:0:0:0): removing device entry
GEOM: destroy disk da0 dp=0xc2d74850
umass0: detachedFurther ReadingBeside the Adding
Disks and Mounting and
Unmounting File Systems sections, reading various
manual pages may be also useful: &man.umass.4;,
&man.camcontrol.8;, and &man.usbdevs.8;.MikeMeyerContributed by Creating and Using Optical Media (CDs)CDROMscreatingIntroductionCDs have a number of features that differentiate them from
conventional disks. Initially, they were not writable by the
user. They are designed so that they can be read continuously without
delays to move the head between tracks. They are also much easier
to transport between systems than similarly sized media were at the
time.CDs do have tracks, but this refers to a section of data to
be read continuously and not a physical property of the disk. To
produce a CD on FreeBSD, you prepare the data files that are going
to make up the tracks on the CD, then write the tracks to the
CD.ISO 9660file systemsISO 9660The ISO 9660 file system was designed to deal with these
differences. It unfortunately codifies file system limits that were
common then. Fortunately, it provides an extension mechanism that
allows properly written CDs to exceed those limits while still
working with systems that do not support those extensions.sysutils/cdrtoolsThe sysutils/cdrtools
port includes &man.mkisofs.8;, a program that you can use to
produce a data file containing an ISO 9660 file
system. It has options that support various extensions, and is
described below.CD burnerATAPIWhich tool to use to burn the CD depends on whether your CD burner
is ATAPI or something else. ATAPI CD burners use the burncd program that is part of
the base system. SCSI and USB CD burners should use
cdrecord from
the sysutils/cdrtools port.burncd has a limited number of
supported drives. To find out if a drive is supported, see the
CD-R/RW supported
drives list.CD burnerATAPI/CAM driverIf you run &os; 5.X, &os; 4.8-RELEASE version or
higher, it will be possible to use cdrecord and other tools
for SCSI drives on an ATAPI hardware with the ATAPI/CAM module.If you want a CD burning software with a graphical user
interface, you should have a look to
X-CD-Roast or
K3b. These tools are available as
packages or from the sysutils/xcdroast and sysutils/k3b ports.
X-CD-Roast and
K3b require the ATAPI/CAM module with ATAPI
hardware.mkisofsThe &man.mkisofs.8; program, which is part of the
sysutils/cdrtools port,
produces an ISO 9660 file system
that is an image of a directory tree in the &unix; file system name
space. The simplest usage is:&prompt.root; mkisofs -o imagefile.iso/path/to/treefile systemsISO 9660This command will create an imagefile.iso
containing an ISO 9660 file system that is a copy of the tree at
/path/to/tree. In the process, it will
map the file names to names that fit the limitations of the
standard ISO 9660 file system, and will exclude files that have
names uncharacteristic of ISO file systems.file systemsHFSfile systemsJolietA number of options are available to overcome those
restrictions. In particular, enables the
Rock Ridge extensions common to &unix; systems,
enables Joliet extensions used by Microsoft systems, and
can be used to create HFS file systems used
by &macos;.For CDs that are going to be used only on FreeBSD systems,
can be used to disable all filename
restrictions. When used with , it produces a
file system image that is identical to the FreeBSD tree you started
from, though it may violate the ISO 9660 standard in a number of
ways.CDROMscreating bootableThe last option of general use is . This is
used to specify the location of the boot image for use in producing an
El Torito bootable CD. This option takes an
argument which is the path to a boot image from the top of the
tree being written to the CD. By default, &man.mkisofs.8; creates an
ISO image in the so-called floppy disk emulation mode,
and thus expects the boot image to be exactly 1200, 1440 or
2880 KB in size. Some boot loaders, like the one used by the
FreeBSD distribution disks, do not use emulation mode; in this case,
the option should be used. So, if
/tmp/myboot holds a bootable FreeBSD system
with the boot image in
/tmp/myboot/boot/cdboot, you could produce the
image of an ISO 9660 file system in
/tmp/bootable.iso like so:&prompt.root; mkisofs -R -no-emul-boot -b boot/cdboot -o /tmp/bootable.iso /tmp/mybootHaving done that, if you have vn
(FreeBSD 4.X), or md
(FreeBSD 5.X)
configured in your kernel, you can mount the file system with:&prompt.root; vnconfig -e vn0c /tmp/bootable.iso
&prompt.root; mount -t cd9660 /dev/vn0c /mntfor FreeBSD 4.X, and for FreeBSD 5.X:&prompt.root; mdconfig -a -t vnode -f /tmp/bootable.iso -u 0
&prompt.root; mount -t cd9660 /dev/md0 /mntAt which point you can verify that /mnt
and /tmp/myboot are identical.There are many other options you can use with
&man.mkisofs.8; to fine-tune its behavior. In particular:
modifications to an ISO 9660 layout and the creation of Joliet
and HFS discs. See the &man.mkisofs.8; manual page for details.burncdCDROMsburningIf you have an ATAPI CD burner, you can use the
burncd command to burn an ISO image onto a
CD. burncd is part of the base system, installed
as /usr/sbin/burncd. Usage is very simple, as
it has few options:&prompt.root; burncd -f cddevice data imagefile.iso fixateWill burn a copy of imagefile.iso on
cddevice. The default device is
/dev/acd0 (or /dev/acd0c under &os; 4.X). See &man.burncd.8; for options to
set the write speed, eject the CD after burning, and write audio
data.cdrecordIf you do not have an ATAPI CD burner, you will have to use
cdrecord to burn your
CDs. cdrecord is not part of the base system;
you must install it from either the port at sysutils/cdrtools
or the appropriate
package. Changes to the base system can cause binary versions of
this program to fail, possibly resulting in a
coaster. You should therefore either upgrade the
port when you upgrade your system, or if you are tracking -STABLE, upgrade the port when a
new version becomes available.While cdrecord has many options, basic usage
is even simpler than burncd. Burning an ISO 9660
image is done with:&prompt.root; cdrecord dev=deviceimagefile.isoThe tricky part of using cdrecord is finding
the to use. To find the proper setting, use
the flag of cdrecord,
which might produce results like this:CDROMsburning&prompt.root; cdrecord -scanbus
Cdrecord 1.9 (i386-unknown-freebsd4.2) Copyright (C) 1995-2000 Jörg Schilling
Using libscg version 'schily-0.1'
scsibus0:
0,0,0 0) 'SEAGATE ' 'ST39236LW ' '0004' Disk
0,1,0 1) 'SEAGATE ' 'ST39173W ' '5958' Disk
0,2,0 2) *
0,3,0 3) 'iomega ' 'jaz 1GB ' 'J.86' Removable Disk
0,4,0 4) 'NEC ' 'CD-ROM DRIVE:466' '1.26' Removable CD-ROM
0,5,0 5) *
0,6,0 6) *
0,7,0 7) *
scsibus1:
1,0,0 100) *
1,1,0 101) *
1,2,0 102) *
1,3,0 103) *
1,4,0 104) *
1,5,0 105) 'YAMAHA ' 'CRW4260 ' '1.0q' Removable CD-ROM
1,6,0 106) 'ARTEC ' 'AM12S ' '1.06' Scanner
1,7,0 107) *This lists the appropriate value for the
devices on the list. Locate your CD burner, and use the three
numbers separated by commas as the value for
. In this case, the CRW device is 1,5,0, so the
appropriate input would be
. There are easier
ways to specify this value; see &man.cdrecord.1; for
details. That is also the place to look for information on writing
audio tracks, controlling the speed, and other things.Duplicating Audio CDsYou can duplicate an audio CD by extracting the audio data from
the CD to a series of files, and then writing these files to a blank
CD. The process is slightly different for ATAPI and SCSI
drives.SCSI DrivesUse cdda2wav to extract the audio.&prompt.user; cdda2wav -v255 -D2,0 -B -OwavUse cdrecord to write the
.wav files.&prompt.user; cdrecord -v dev=2,0 -dao -useinfo *.wavMake sure that 2,0 is set
appropriately, as described in .ATAPI DrivesThe ATAPI CD driver makes each track available as
/dev/acddtnn,
where d is the drive number, and
nn is the track number written with two
decimal digits, prefixed with zero as needed.
So the first track on the first disk is
/dev/acd0t01, the second is
/dev/acd0t02, the third is
/dev/acd0t03, and so on.Make sure the appropriate files exist in
/dev. If the entries are missing,
force the system to retaste the media:&prompt.root; dd if=/dev/acd0 of=/dev/null count=1In &os; 4.X, the entries are not prefixed with
zero. If the necessary entries in /dev
are missing, use MAKEDEV to create
them:&prompt.root; cd /dev
&prompt.root; sh MAKEDEV acd0t99Extract each track using &man.dd.1;. You must also use a
specific block size when extracting the files.&prompt.root; dd if=/dev/acd0t01 of=track1.cdr bs=2352
&prompt.root; dd if=/dev/acd0t02 of=track2.cdr bs=2352
...
Burn the extracted files to disk using
burncd. You must specify that these are audio
files, and that burncd should fixate the disk
when finished.&prompt.root; burncd -f /dev/acd0 audio track1.cdr track2.cdr ... fixateDuplicating Data CDsYou can copy a data CD to a image file that is
functionally equivalent to the image file created with
&man.mkisofs.8;, and you can use it to duplicate
any data CD. The example given here assumes that your CDROM
device is acd0. Substitute your
correct CDROM device. Under &os; 4.X, a c must be appended
to the end of the device name to indicate the entire partition
or, in the case of CDROMs, the entire disc.&prompt.root; dd if=/dev/acd0 of=file.iso bs=2048Now that you have an image, you can burn it to CD as
described above.Using Data CDsNow that you have created a standard data CDROM, you
probably want to mount it and read the data on it. By
default, &man.mount.8; assumes that a file system is of type
ufs. If you try something like:&prompt.root; mount /dev/cd0 /mntyou will get a complaint about Incorrect super
block, and no mount. The CDROM is not a
UFS file system, so attempts to mount it
as such will fail. You just need to tell &man.mount.8; that
the file system is of type ISO9660, and
everything will work. You do this by specifying the
option &man.mount.8;. For
example, if you want to mount the CDROM device,
/dev/cd0, under
/mnt, you would execute:&prompt.root; mount -t cd9660 /dev/cd0 /mntNote that your device name
(/dev/cd0 in this example) could be
different, depending on the interface your CDROM uses. Also,
the option just executes
&man.mount.cd9660.8;. The above example could be shortened
to:&prompt.root; mount_cd9660 /dev/cd0 /mntYou can generally use data CDROMs from any vendor in this
way. Disks with certain ISO 9660 extensions might behave
oddly, however. For example, Joliet disks store all filenames
in two-byte Unicode characters. The FreeBSD kernel does not
speak Unicode (yet!), so non-English characters show up as
question marks. (If you are running FreeBSD 4.3 or later, the
CD9660 driver includes hooks to load an appropriate Unicode
conversion table on the fly. Modules for some of the common
encodings are available via the
sysutils/cd9660_unicode port.)Occasionally, you might get Device not
configured when trying to mount a CDROM. This
usually means that the CDROM drive thinks that there is no
disk in the tray, or that the drive is not visible on the bus.
It can take a couple of seconds for a CDROM drive to realize
that it has been fed, so be patient.Sometimes, a SCSI CDROM may be missed because it did not
have enough time to answer the bus reset. If you have a SCSI
CDROM please add the following option to your kernel
configuration and rebuild your kernel.options SCSI_DELAY=15000This tells your SCSI bus to pause 15 seconds during boot,
to give your CDROM drive every possible chance to answer the
bus reset.Burning Raw Data CDsYou can choose to burn a file directly to CD, without
creating an ISO 9660 file system. Some people do this for
backup purposes. This runs more quickly than burning a
standard CD:&prompt.root; burncd -f /dev/acd1 -s 12 data archive.tar.gz fixateIn order to retrieve the data burned to such a CD, you
must read data from the raw device node:&prompt.root; tar xzvf /dev/acd1You cannot mount this disk as you would a normal CDROM.
Such a CDROM cannot be read under any operating system
except FreeBSD. If you want to be able to mount the CD, or
share data with another operating system, you must use
&man.mkisofs.8; as described above.MarcFonvieilleContributed by CD burnerATAPI/CAM driverUsing the ATAPI/CAM DriverThis driver allows ATAPI devices (CD-ROM, CD-RW, DVD
drives etc...) to be accessed through the SCSI subsystem, and
so allows the use of applications like sysutils/cdrdao or
&man.cdrecord.1;.To use this driver, you will need to add the following
line to your kernel configuration file:device atapicamYou also need the following lines in your kernel
configuration file:device ata
device scbus
device cd
device passwhich should already be present.Then rebuild, install your new kernel, and reboot your
machine. During the boot process, your burner should show up,
like so:acd0: CD-RW <MATSHITA CD-RW/DVD-ROM UJDA740> at ata1-master PIO4
cd0 at ata1 bus 0 target 0 lun 0
cd0: <MATSHITA CDRW/DVD UJDA740 1.00> Removable CD-ROM SCSI-0 device
cd0: 16.000MB/s transfers
cd0: Attempt to query device size failed: NOT READY, Medium not present - tray closedThe drive could now be accessed via the
/dev/cd0 device name, for example to
mount a CD-ROM on /mnt, just type the
following:&prompt.root; mount -t cd9660 /dev/cd0 /mntAs root, you can run the following
command to get the SCSI address of the burner:&prompt.root; camcontrol devlist
<MATSHITA CDRW/DVD UJDA740 1.00> at scbus1 target 0 lun 0 (pass0,cd0)So 1,0,0 will be the SCSI address to
use with &man.cdrecord.1; and other SCSI application.For more information about ATAPI/CAM and SCSI system,
refer to the &man.atapicam.4; and &man.cam.4; manual
pages.MarcFonvieilleContributed by AndyPolyakovWith inputs from Creating and Using Optical Media (DVDs)DVDburningIntroductionCompared to the CD, the DVD is the next generation of
optical media storage technology. The DVD can hold more data
than any CD and is nowadays the standard for video
publishing.Five physical recordable formats can be defined for what
we will call a recordable DVD:DVD-R: This was the first DVD recordable format
available. The DVD-R standard is defined by the DVD Forum.
This format is write once.DVD-RW: This is the rewriteable version of
the DVD-R standard. A DVD-RW can be rewritten about 1000
times.DVD-RAM: This is also a rewriteable format
supported by the DVD Forum. A DVD-RAM can be seen as a
removable hard drive. However, this media is not
compatible with most DVD-ROM drives and DVD-Video players;
only a few DVD writers support the DVD-RAM format.DVD+RW: This is a rewriteable format defined by
the DVD+RW
Alliance. A DVD+RW can be rewritten about 1000
times.DVD+R: This format is the write once variation
of the DVD+RW format.A single layer recordable DVD can hold up to
4,700,000,000 bytes which is actually 4.38 GB or
4485 MB (1 kilobyte is 1024 bytes).A distinction must be made between the physical media and
the application. For example, a DVD-Video is a specific
file layout that can be written on any recordable DVD
physical media: DVD-R, DVD+R, DVD-RW etc. Before choosing
the type of media, you must be sure that both the burner and the
DVD-Video player (a standalone player or a DVD-ROM drive on
a computer) are compatible with the media under consideration.ConfigurationThe program &man.growisofs.1; will be used to perform DVD
recording. This command is part of the
dvd+rw-tools utilities (sysutils/dvd+rw-tools). The
dvd+rw-tools support all DVD media
types.These tools use the SCSI subsystem to access to the
devices, therefore the ATAPI/CAM
support must be added to your kernel. If your burner
uses the USB interface this addition is useless, and you should
read the for more details on USB
devices configuration.You also have to enable DMA access for ATAPI devices, this
can be done in adding the following line to the
/boot/loader.conf file:hw.ata.atapi_dma="1"Before attempting to use the
dvd+rw-tools you should consult the
dvd+rw-tools'
hardware compatibility notes for any information
related to your DVD burner.If you want a graphical user interface, you should have
a look to K3b (sysutils/k3b) which provides a
user friendly interface to &man.growisofs.1; and many others
burning tools.Burning Data DVDsThe &man.growisofs.1; command is a frontend to mkisofs, it will invoke
&man.mkisofs.8; to create the file system layout and will
perform the write on the DVD. This means you do not need to
create an image of the data before the burning process.To burn onto a DVD+R or a DVD-R the data from the /path/to/data directory, use the
following command:&prompt.root; growisofs -dvd-compat -Z /dev/cd0 -J -R /path/to/dataThe options are passed to
&man.mkisofs.8; for the file system creation (in this case: an
ISO 9660 file system with Joliet and Rock Ridge extensions),
consult the &man.mkisofs.8; manual page for more
details.The option is used for the initial
session recording in any case: multiple sessions or not. The
DVD device, /dev/cd0, must be
changed according to your configuration. The
parameter will close the disk,
the recording will be unappendable. In return this should provide better
media compatibility with DVD-ROM drives.It is also possible to burn a pre-mastered image, for
example to burn the image
imagefile.iso, we will run:&prompt.root; growisofs -dvd-compat -Z /dev/cd0=imagefile.isoThe write speed should be detected and automatically set
according to the media and the drive being used. If you want
to force the write speed, use the
parameter. For more information, read the &man.growisofs.1;
manual page.DVDDVD-VideoBurning a DVD-VideoA DVD-Video is a specific file layout based on ISO 9660
and the micro-UDF (M-UDF) specifications. The DVD-Video also
presents a specific data structure hierarchy, it is the reason
why you need a particular program such as multimedia/dvdauthor to author the
DVD.If you already have an image of the DVD-Video file system,
just burn it in the same way as for any image, see the
previous section for an example. If you have made the DVD
authoring and the result is in, for example, the directory
/path/to/video, the
following command should be used to burn the DVD-Video:&prompt.root; growisofs -Z /dev/cd0 -dvd-video /path/to/videoThe option will be passed down to
&man.mkisofs.8; and will instruct it to create a DVD-Video file system
layout. Beside this, the option
implies &man.growisofs.1;
option.DVDDVD+RWUsing a DVD+RWUnlike CD-RW, a virgin DVD+RW needs to be formatted before
first use. The &man.growisofs.1; program will take care of it
automatically whenever appropriate, which is the
recommended way. However you can use the
dvd+rw-format command to format the
DVD+RW:&prompt.root; dvd+rw-format /dev/cd0You need to perform this operation just once, keep in mind
that only virgin DVD+RW medias need to be formatted. Then you
can burn the DVD+RW in the way seen in previous
sections.If you want to burn new data (burn a totally new file
system not append some data) onto a DVD+RW, you do not need to
blank it, you just have to write over the previous recording
(in performing a new initial session), like this:&prompt.root; growisofs -Z /dev/cd0 -J -R /path/to/newdataDVD+RW format offers the possibility to easily append data
to a previous recording. The operation consists in merging a
new session to the existing one, it is not multisession
writing, &man.growisofs.1; will grow the
ISO 9660 file system present on the media.For example, if we want to append data to our previous
DVD+RW, we have to use the following:&prompt.root; growisofs -M /dev/cd0 -J -R /path/to/nextdataThe same &man.mkisofs.8; options we used to burn the
initial session should be used during next writes.You may want to use the
option if you want better media compatibility with DVD-ROM
drives. In the DVD+RW case, this will not prevent you from
adding data.If for any reason you really want to blank the media, do
the following:&prompt.root; growisofs -Z /dev/cd0=/dev/zeroDVDDVD-RWUsing a DVD-RWA DVD-RW accepts two disc formats: the incremental
sequential one and the restricted overwrite. By default
DVD-RW discs are in sequential format.A virgin DVD-RW can be directly written without the need
of a formatting operation, however a non-virgin DVD-RW in
sequential format needs to be blanked before to be able to
write a new initial session.To blank a DVD-RW in sequential mode, run:&prompt.root; dvd+rw-format -blank=full /dev/cd0A full blanking () will take
about one hour on a 1x media. A fast blanking can be
performed using the option if the
DVD-RW will be recorded in Disk-At-Once (DAO) mode. To burn
the DVD-RW in DAO mode, use the command:&prompt.root; growisofs -use-the-force-luke=dao -Z /dev/cd0=imagefile.isoThe option
should not be required since &man.growisofs.1; attempts to
detect minimally (fast blanked) media and engage DAO
write.In fact one should use restricted overwrite mode with
any DVD-RW, this format is more flexible than the default
incremental sequential one.To write data on a sequential DVD-RW, use the same
instructions as for the other DVD formats:&prompt.root; growisofs -Z /dev/cd0 -J -R /path/to/dataIf you want to append some data to your previous
recording, you will have to use the &man.growisofs.1;
option. However, if you perform data
addition on a DVD-RW in incremental sequential mode, a new
session will be created on the disc and the result will be a
multi-session disc.A DVD-RW in restricted overwrite format does not need to
be blanked before a new initial session, you just have to
overwrite the disc with the option, this
is similar to the DVD+RW case. It is also possible to grow an
existing ISO 9660 file system written on the disc in a same
way as for a DVD+RW with the option. The
result will be a one-session DVD.To put a DVD-RW in the restricted overwrite format, the
following command must be used:&prompt.root; dvd+rw-format /dev/cd0To change back to the sequential format use:&prompt.root; dvd+rw-format -blank=full /dev/cd0MultisessionVery few DVD-ROM drives support
multisession DVDs, they will most of time, hopefully, only read
the first session. DVD+R, DVD-R and DVD-RW in sequential
format can accept multiple sessions, the notion of multiple
sessions does not exist for the DVD+RW and the DVD-RW
restricted overwrite formats.Using the following command after an initial (non-closed)
session on a DVD+R, DVD-R, or DVD-RW in sequential format,
will add a new session to the disc:&prompt.root; growisofs -M /dev/cd0 -J -R /path/to/nextdataUsing this command line with a DVD+RW or a DVD-RW in restricted
overwrite mode, will append data in merging the new session to
the existing one. The result will be a single-session disc.
This is the way used to add data after an initial write on these
medias.Some space on the media is used between each session for
end and start of sessions. Therefore, one should add
sessions with large amount of data to optimize media space.
The number of sessions is limited to 154 for a DVD+R,
about 2000 for a DVD-R, and 127 for a DVD+R Double
Layer.For More InformationTo obtain more information about a DVD, the
dvd+rw-mediainfo
/dev/cd0 command can be
ran with the disc in the drive.More information about the
dvd+rw-tools can be found in
the &man.growisofs.1; manual page, on the dvd+rw-tools
web site and in the cdwrite mailing
list archives.The dvd+rw-mediainfo output of the
resulting recording or the media with issues is mandatory
for any problem report. Without this output, it will be
quite impossible to help you.JulioMerinoOriginal work by MartinKarlssonRewritten by Creating and Using Floppy DisksStoring data on floppy disks is sometimes useful, for
example when one does not have any other removable storage media
or when one needs to transfer small amounts of data to another
computer.This section will explain how to use floppy disks in
FreeBSD. It will primarily cover formatting and usage of
3.5inch DOS floppies, but the concepts are similar for other
floppy disk formats.Formatting FloppiesThe DeviceFloppy disks are accessed through entries in
/dev, just like other devices. To
access the raw floppy disk in 4.X and earlier releases, one
uses
/dev/fdN,
where N stands for the drive
number, usually 0, or
/dev/fdNX,
where X stands for a
letter.In 5.0 or newer releases, simply use
/dev/fdN.The Disk Size in 4.X and Earlier ReleasesThere are also /dev/fdN.size
devices, where size is a floppy disk
size in kilobytes. These entries are used at low-level format
time to determine the disk size. 1440kB is the size that will be
used in the following examples.Sometimes the entries under /dev will
have to be (re)created. To do that, issue:&prompt.root; cd /dev && ./MAKEDEV "fd*"The Disk Size in 5.0 and Newer ReleasesIn 5.0, &man.devfs.5; will automatically
manage device nodes in /dev, so use of
MAKEDEV is not necessary.The desired disk size is passed to &man.fdformat.1; through
the flag. Supported sizes are listed in
&man.fdcontrol.8;, but be advised that 1440kB is what works best.FormattingA floppy disk needs to be low-level formated before it
can be used. This is usually done by the vendor, but
formatting is a good way to check media integrity. Although
it is possible to force larger (or smaller) disk sizes,
1440kB is what most floppy disks are designed for.To low-level format the floppy disk you need to use
&man.fdformat.1;. This utility expects the device name as an
argument.Make note of any error messages, as these can help
determine if the disk is good or bad.Formatting in 4.X and Earlier ReleasesUse the
/dev/fdN.size
devices to format the floppy. Insert a new 3.5inch floppy
disk in your drive and issue:&prompt.root; /usr/sbin/fdformat /dev/fd0.1440Formatting in 5.0 and Newer ReleasesUse the
/dev/fdN
devices to format the floppy. Insert a new 3.5inch floppy
disk in your drive and issue:&prompt.root; /usr/sbin/fdformat -f 1440 /dev/fd0The Disk LabelAfter low-level formatting the disk, you will need to
place a disk label on it. This disk label will be destroyed
later, but it is needed by the system to determine the size of
the disk and its geometry later.The new disk label will take over the whole disk, and will
contain all the proper information about the geometry of the
floppy. The geometry values for the disk label are listed in
/etc/disktab.You can run now &man.disklabel.8; like so:&prompt.root; /sbin/disklabel -B -r -w /dev/fd0 fd1440Since &os; 5.1-RELEASE, the &man.bsdlabel.8;
utility replaces the old &man.disklabel.8; program. With
&man.bsdlabel.8; a number of obsolete options and parameters
have been retired; in the example above the option
should be removed. For more
information, please refer to the &man.bsdlabel.8;
manual page.The File SystemNow the floppy is ready to be high-level formated. This
will place a new file system on it, which will let FreeBSD read
and write to the disk. After creating the new file system, the
disk label is destroyed, so if you want to reformat the disk, you
will have to recreate the disk label.The floppy's file system can be either UFS or FAT.
FAT is generally a better choice for floppies.To put a new file system on the floppy, issue:&prompt.root; /sbin/newfs_msdos /dev/fd0The disk is now ready for use.Using the FloppyTo use the floppy, mount it with &man.mount.msdos.8; (in
4.X and earlier releases) or &man.mount.msdosfs.8; (in 5.0 or
newer releases). One can also use
emulators/mtools from the ports
collection.Creating and Using Data Tapestape mediaThe major tape media are the 4mm, 8mm, QIC, mini-cartridge and
DLT.4mm (DDS: Digital Data Storage)tape mediaDDS (4mm) tapestape mediaQIC tapes4mm tapes are replacing QIC as the workstation backup media of
choice. This trend accelerated greatly when Conner purchased Archive,
a leading manufacturer of QIC drives, and then stopped production of
QIC drives. 4mm drives are small and quiet but do not have the
reputation for reliability that is enjoyed by 8mm drives. The
cartridges are less expensive and smaller (3 x 2 x 0.5 inches, 76 x 51
x 12 mm) than 8mm cartridges. 4mm, like 8mm, has comparatively short
head life for the same reason, both use helical scan.Data throughput on these drives starts ~150 kB/s, peaking at ~500 kB/s.
Data capacity starts at 1.3 GB and ends at 2.0 GB. Hardware
compression, available with most of these drives, approximately
doubles the capacity. Multi-drive tape library units can have 6
drives in a single cabinet with automatic tape changing. Library
capacities reach 240 GB.The DDS-3 standard now supports tape capacities up to 12 GB (or
24 GB compressed).4mm drives, like 8mm drives, use helical-scan. All the benefits
and drawbacks of helical-scan apply to both 4mm and 8mm drives.Tapes should be retired from use after 2,000 passes or 100 full
backups.8mm (Exabyte)tape mediaExabyte (8mm) tapes8mm tapes are the most common SCSI tape drives; they are the best
choice of exchanging tapes. Nearly every site has an Exabyte 2 GB 8mm
tape drive. 8mm drives are reliable, convenient and quiet. Cartridges
are inexpensive and small (4.8 x 3.3 x 0.6 inches; 122 x 84 x 15 mm).
One downside of 8mm tape is relatively short head and tape life due to
the high rate of relative motion of the tape across the heads.Data throughput ranges from ~250 kB/s to ~500 kB/s. Data sizes start
at 300 MB and go up to 7 GB. Hardware compression, available with
most of these drives, approximately doubles the capacity. These
drives are available as single units or multi-drive tape libraries
with 6 drives and 120 tapes in a single cabinet. Tapes are changed
automatically by the unit. Library capacities reach 840+ GB.The Exabyte Mammoth model supports 12 GB on one tape
(24 GB with compression) and costs approximately twice as much as
conventional tape drives.Data is recorded onto the tape using helical-scan, the heads are
positioned at an angle to the media (approximately 6 degrees). The
tape wraps around 270 degrees of the spool that holds the heads. The
spool spins while the tape slides over the spool. The result is a
high density of data and closely packed tracks that angle across the
tape from one edge to the other.QICtape mediaQIC-150QIC-150 tapes and drives are, perhaps, the most common tape drive
and media around. QIC tape drives are the least expensive serious
backup drives. The downside is the cost of media. QIC tapes are
expensive compared to 8mm or 4mm tapes, up to 5 times the price per GB
data storage. But, if your needs can be satisfied with a half-dozen
tapes, QIC may be the correct choice. QIC is the
most common tape drive. Every site has a QIC
drive of some density or another. Therein lies the rub, QIC has a
large number of densities on physically similar (sometimes identical)
tapes. QIC drives are not quiet. These drives audibly seek before
they begin to record data and are clearly audible whenever reading,
writing or seeking. QIC tapes measure (6 x 4 x 0.7 inches; 152 x
102 x 17 mm).Data throughput ranges from ~150 kB/s to ~500 kB/s. Data capacity
ranges from 40 MB to 15 GB. Hardware compression is available on many
of the newer QIC drives. QIC drives are less frequently installed;
they are being supplanted by DAT drives.Data is recorded onto the tape in tracks. The tracks run along
the long axis of the tape media from one end to the other. The number
of tracks, and therefore the width of a track, varies with the tape's
capacity. Most if not all newer drives provide backward-compatibility
at least for reading (but often also for writing). QIC has a good
reputation regarding the safety of the data (the mechanics are simpler
and more robust than for helical scan drives).Tapes should be retired from use after 5,000 backups.DLTtape mediaDLTDLT has the fastest data transfer rate of all the drive types
listed here. The 1/2" (12.5mm) tape is contained in a single spool
cartridge (4 x 4 x 1 inches; 100 x 100 x 25 mm). The cartridge has a
swinging gate along one entire side of the cartridge. The drive
mechanism opens this gate to extract the tape leader. The tape leader
has an oval hole in it which the drive uses to hook the tape. The
take-up spool is located inside the tape drive. All the other tape
cartridges listed here (9 track tapes are the only exception) have
both the supply and take-up spools located inside the tape cartridge
itself.Data throughput is approximately 1.5 MB/s, three times the throughput of
4mm, 8mm, or QIC tape drives. Data capacities range from 10 GB to 20 GB
for a single drive. Drives are available in both multi-tape changers
and multi-tape, multi-drive tape libraries containing from 5 to 900
tapes over 1 to 20 drives, providing from 50 GB to 9 TB of
storage.With compression, DLT Type IV format supports up to 70 GB
capacity.Data is recorded onto the tape in tracks parallel to the direction
of travel (just like QIC tapes). Two tracks are written at once.
Read/write head lifetimes are relatively long; once the tape stops
moving, there is no relative motion between the heads and the
tape.AITtape mediaAITAIT is a new format from Sony, and can hold up to 50 GB (with
compression) per tape. The tapes contain memory chips which retain an
index of the tape's contents. This index can be rapidly read by the
tape drive to determine the position of files on the tape, instead of
the several minutes that would be required for other tapes. Software
such as SAMS:Alexandria can operate forty or more AIT tape libraries,
communicating directly with the tape's memory chip to display the
contents on screen, determine what files were backed up to which
tape, locate the correct tape, load it, and restore the data from the
tape.Libraries like this cost in the region of $20,000, pricing them a
little out of the hobbyist market.Using a New Tape for the First TimeThe first time that you try to read or write a new, completely
blank tape, the operation will fail. The console messages should be
similar to:sa0(ncr1:4:0): NOT READY asc:4,1
sa0(ncr1:4:0): Logical unit is in process of becoming readyThe tape does not contain an Identifier Block (block number 0).
All QIC tape drives since the adoption of QIC-525 standard write an
Identifier Block to the tape. There are two solutions:mt fsf 1 causes the tape drive to write an
Identifier Block to the tape.Use the front panel button to eject the tape.Re-insert the tape and dump data to
the tape.dump will report DUMP: End of tape
detected and the console will show: HARDWARE
FAILURE info:280 asc:80,96.rewind the tape using: mt rewind.Subsequent tape operations are successful.Backups to FloppiesCan I Use Floppies for Backing Up My Data?backup floppiesfloppy disksFloppy disks are not really a suitable media for
making backups as:The media is unreliable, especially over long periods of
time.Backing up and restoring is very slow.They have a very limited capacity (the days of backing up
an entire hard disk onto a dozen or so floppies has long since
passed).However, if you have no other method of backing up your data then
floppy disks are better than no backup at all.If you do have to use floppy disks then ensure that you use good
quality ones. Floppies that have been lying around the office for a
couple of years are a bad choice. Ideally use new ones from a
reputable manufacturer.So How Do I Backup My Data to Floppies?The best way to backup to floppy disk is to use
&man.tar.1; with the (multi
volume) option, which allows backups to span multiple
floppies.To backup all the files in the current directory and sub-directory
use this (as root):&prompt.root; tar Mcvf /dev/fd0 *When the first floppy is full &man.tar.1; will prompt you to
insert the next volume (because &man.tar.1; is media independent it
refers to volumes; in this context it means floppy disk).Prepare volume #2 for /dev/fd0 and hit return:This is repeated (with the volume number incrementing) until all
the specified files have been archived.Can I Compress My Backups?targzipcompressionUnfortunately, &man.tar.1; will not allow the
option to be used for multi-volume archives.
You could, of course, &man.gzip.1; all the files,
&man.tar.1; them to the floppies, then
&man.gunzip.1; the files again!How Do I Restore My Backups?To restore the entire archive use:&prompt.root; tar Mxvf /dev/fd0There are two ways that you can use to restore only
specific files. First, you can start with the first floppy
and use:&prompt.root; tar Mxvf /dev/fd0 filenameThe utility &man.tar.1; will prompt you to insert subsequent floppies until it
finds the required file.Alternatively, if you know which floppy the file is on then you
can simply insert that floppy and use the same command as above. Note
that if the first file on the floppy is a continuation from the
previous one then &man.tar.1; will warn you that it cannot
restore it, even if you have not asked it to!LowellGilbertOriginal work by Backup StrategiesThe first requirement in devising a backup plan is to make sure that
all of the following problems are covered:Disk failureAccidental file deletionRandom file corruptionComplete machine destruction (e.g. fire), including destruction
of any on-site backups.It is perfectly possible that some systems will be best served by
having each of these problems covered by a completely different
technique. Except for strictly personal systems with very low-value
data, it is unlikely that one technique would cover all of them.Some of the techniques in the toolbox are:Archives of the whole system, backed up onto permanent media
offsite. This actually provides protection against all of the
possible problems listed above, but is slow and inconvenient to
restore from. You can keep copies of the backups onsite and/or
online, but there will still be inconveniences in restoring files,
especially for non-privileged users.Filesystem snapshots. This is really only helpful in the
accidental file deletion scenario, but it can be
very helpful in that case, and is quick and
easy to deal with.Copies of whole filesystems and/or disks (e.g. periodic rsync of
the whole machine). This is generally most useful in networks with
unique requirements. For general protection against disk failure,
it is usually inferior to RAID. For restoring
accidentally deleted files, it can be comparable to
UFS snapshots, but that depends on your
preferences.RAID. Minimizes or avoids downtime when a
disk fails. At the expense of having to deal with disk failures
more often (because you have more disks), albeit at a much lower
urgency.Checking fingerprints of files. The &man.mtree.8; utility is
very useful for this. Although it is not a backup technique, it
helps guarantee that you will notice when you need to resort to your
backups. This is particularly important for offline backups, and
should be checked periodically.It is quite easy to come up with even more techniques, many of them
variations on the ones listed above. Specialized requirements will
usually lead to specialized techniques (for example, backing up a live
database usually requires a method particular to the database software
as an intermediate step). The important thing is to know what dangers
you want to protect against, and how you will handle each.Backup BasicsThe three major backup programs are
&man.dump.8;,
&man.tar.1;,
and
&man.cpio.1;.Dump and Restorebackup softwaredump / restoredumprestoreThe traditional &unix; backup programs are
dump and restore. They
operate on the drive as a collection of disk blocks, below the
abstractions of files, links and directories that are created by
the file systems. dump backs up an entire
file system on a device. It is unable to backup only part of a
file system or a directory tree that spans more than one
file system. dump does not write files and
directories to tape, but rather writes the raw data blocks that
comprise files and directories.If you use dump on your root directory, you
would not back up /home,
/usr or many other directories since
these are typically mount points for other file systems or
symbolic links into those file systems.dump has quirks that remain from its early days in
Version 6 of AT&T UNIX (circa 1975). The default
parameters are suitable for 9-track tapes (6250 bpi), not the
high-density media available today (up to 62,182 ftpi). These
defaults must be overridden on the command line to utilize the
capacity of current tape drives..rhostsIt is also possible to backup data across the network to a
tape drive attached to another computer with rdump and
rrestore. Both programs rely upon &man.rcmd.3; and
&man.ruserok.3; to access the remote tape drive. Therefore,
the user performing the backup must be listed in the
.rhosts file on the remote computer. The
arguments to rdump and rrestore must be suitable
to use on the remote computer. When
rdumping from a FreeBSD computer to an
Exabyte tape drive connected to a Sun called
komodo, use:&prompt.root; /sbin/rdump 0dsbfu 54000 13000 126 komodo:/dev/nsa8 /dev/da0a 2>&1Beware: there are security implications to
allowing .rhosts authentication. Evaluate your
situation carefully.It is also possible to use dump and
restore in a more secure fashion over
ssh.Using dump over ssh&prompt.root; /sbin/dump -0uan -f - /usr | gzip -2 | ssh -c blowfish \
targetuser@targetmachine.example.com dd of=/mybigfiles/dump-usr-l0.gzOr using dump's built-in method,
setting the environment variable RSH:Using dump over ssh with RSH set&prompt.root; RSH=/usr/bin/ssh /sbin/dump -0uan -f targetuser@targetmachine.example.com:/dev/sa0 /usrtarbackup softwaretar&man.tar.1; also dates back to Version 6 of AT&T UNIX
(circa 1975). tar operates in cooperation
with the file system; it writes files and
directories to tape. tar does not support the
full range of options that are available from &man.cpio.1;, but
it does not require the unusual command
pipeline that cpio uses.tarOn FreeBSD 5.3 and later, both GNU tar
and the default bsdtar are available. The
GNU version can be invoked with gtar. It
supports remote devices using the same syntax as
rdump. To tar to an
Exabyte tape drive connected to a Sun called
komodo, use:&prompt.root; /usr/bin/gtar cf komodo:/dev/nsa8 . 2>&1The same could be accomplished with
bsdtar by using a pipeline and
rsh to send the data to a remote tape
drive.&prompt.root; tar cf - . | rsh hostname dd of=tape-device obs=20bIf you are worried about the security of backing up over a
network you should use the ssh command
instead of rsh.cpiobackup softwarecpio&man.cpio.1; is the original &unix; file interchange tape
program for magnetic media. cpio has options
(among many others) to perform byte-swapping, write a number of
different archive formats, and pipe the data to other programs.
This last feature makes cpio an excellent
choice for installation media. cpio does not
know how to walk the directory tree and a list of files must be
provided through stdin.cpiocpio does not support backups across
the network. You can use a pipeline and rsh
to send the data to a remote tape drive.&prompt.root; for f in directory_list; dofind $f >> backup.listdone
&prompt.root; cpio -v -o --format=newc < backup.list | ssh user@host "cat > backup_device"Where directory_list is the list of
directories you want to back up,
user@host is the
user/hostname combination that will be performing the backups, and
backup_device is where the backups should
be written to (e.g., /dev/nsa0).paxbackup softwarepaxpaxPOSIXIEEE&man.pax.1; is IEEE/&posix;'s answer to
tar and cpio. Over the
years the various versions of tar and
cpio have gotten slightly incompatible. So
rather than fight it out to fully standardize them, &posix;
created a new archive utility. pax attempts
to read and write many of the various cpio
and tar formats, plus new formats of its own.
Its command set more resembles cpio than
tar.Amandabackup softwareAmandaAmandaAmanda (Advanced Maryland
Network Disk Archiver) is a client/server backup system,
rather than a single program. An Amanda server will backup to
a single tape drive any number of computers that have Amanda
clients and a network connection to the Amanda server. A
common problem at sites with a number of large disks is
that the length of time required to backup to data directly to tape
exceeds the amount of time available for the task. Amanda
solves this problem. Amanda can use a holding disk to
backup several file systems at the same time. Amanda creates
archive sets: a group of tapes used over a period of time to
create full backups of all the file systems listed in Amanda's
configuration file. The archive set also contains nightly
incremental (or differential) backups of all the file systems.
Restoring a damaged file system requires the most recent full
backup and the incremental backups.The configuration file provides fine control of backups and the
network traffic that Amanda generates. Amanda will use any of the
above backup programs to write the data to tape. Amanda is available
as either a port or a package, it is not installed by default.Do NothingDo nothing is not a computer program, but it is the
most widely used backup strategy. There are no initial costs. There
is no backup schedule to follow. Just say no. If something happens
to your data, grin and bear it!If your time and your data is worth little to nothing, then
Do nothing is the most suitable backup program for your
computer. But beware, &unix; is a useful tool, you may find that within
six months you have a collection of files that are valuable to
you.Do nothing is the correct backup method for
/usr/obj and other directory trees that can be
exactly recreated by your computer. An example is the files that
comprise the HTML or &postscript; version of this Handbook.
These document formats have been created from SGML input
files. Creating backups of the HTML or &postscript; files is
not necessary. The SGML files are backed up regularly.Which Backup Program Is Best?LISA&man.dump.8; Period. Elizabeth D. Zwicky
torture tested all the backup programs discussed here. The clear
choice for preserving all your data and all the peculiarities of &unix;
file systems is dump. Elizabeth created file systems containing
a large variety of unusual conditions (and some not so unusual ones)
and tested each program by doing a backup and restore of those
file systems. The peculiarities included: files with holes, files with
holes and a block of nulls, files with funny characters in their
names, unreadable and unwritable files, devices, files that change
size during the backup, files that are created/deleted during the
backup and more. She presented the results at LISA V in Oct. 1991.
See torture-testing
Backup and Archive Programs.Emergency Restore ProcedureBefore the DisasterThere are only four steps that you need to perform in
preparation for any disaster that may occur.disklabelFirst, print the disklabel from each of your disks
(e.g. disklabel da0 | lpr), your file system table
(/etc/fstab) and all boot messages,
two copies of
each.fix-it floppiesSecond, determine that the boot and fix-it floppies
(boot.flp and fixit.flp)
have all your devices. The easiest way to check is to reboot your
machine with the boot floppy in the floppy drive and check the boot
messages. If all your devices are listed and functional, skip on to
step three.Otherwise, you have to create two custom bootable
floppies which have a kernel that can mount all of your disks
and access your tape drive. These floppies must contain:
fdisk, disklabel,
newfs, mount, and
whichever backup program you use. These programs must be
statically linked. If you use dump, the
floppy must contain restore.Third, create backup tapes regularly. Any changes that you make
after your last backup may be irretrievably lost. Write-protect the
backup tapes.Fourth, test the floppies (either boot.flp
and fixit.flp or the two custom bootable
floppies you made in step two.) and backup tapes. Make notes of the
procedure. Store these notes with the bootable floppy, the
printouts and the backup tapes. You will be so distraught when
restoring that the notes may prevent you from destroying your backup
tapes (How? In place of tar xvf /dev/sa0, you
might accidentally type tar cvf /dev/sa0 and
over-write your backup tape).For an added measure of security, make bootable floppies and two
backup tapes each time. Store one of each at a remote location. A
remote location is NOT the basement of the same office building. A
number of firms in the World Trade Center learned this lesson the
hard way. A remote location should be physically separated from
your computers and disk drives by a significant distance.A Script for Creating a Bootable FloppyAfter the DisasterThe key question is: did your hardware survive? You have been
doing regular backups so there is no need to worry about the
software.If the hardware has been damaged, the parts should be replaced
before attempting to use the computer.If your hardware is okay, check your floppies. If you are using
a custom boot floppy, boot single-user (type -s
at the boot: prompt). Skip the following
paragraph.If you are using the boot.flp and
fixit.flp floppies, keep reading. Insert the
boot.flp floppy in the first floppy drive and
boot the computer. The original install menu will be displayed on
the screen. Select the Fixit--Repair mode with CDROM or
floppy. option. Insert the
fixit.flp when prompted.
restore and the other programs that you need are
located in /mnt2/rescue
(/mnt2/stand for
&os; versions older than 5.2).Recover each file system separately.mountroot partitiondisklabelnewfsTry to mount (e.g. mount /dev/da0a
/mnt) the root partition of your first disk. If the
disklabel was damaged, use disklabel to re-partition and
label the disk to match the label that you printed and saved. Use
newfs to re-create the file systems. Re-mount the root
partition of the floppy read-write (mount -u -o rw
/mnt). Use your backup program and backup tapes to
recover the data for this file system (e.g. restore vrf
/dev/sa0). Unmount the file system (e.g. umount
/mnt). Repeat for each file system that was
damaged.Once your system is running, backup your data onto new tapes.
Whatever caused the crash or data loss may strike again. Another
hour spent now may save you from further distress later.* I Did Not Prepare for the Disaster, What Now?
]]>
MarcFonvieilleReorganized and enhanced by Network, Memory, and File-Backed File Systemsvirtual disksdisksvirtualAside from the disks you physically insert into your computer:
floppies, CDs, hard drives, and so forth; other forms of disks
are understood by FreeBSD - the virtual
disks.NFSCodadisksmemoryThese include network file systems such as the Network File System and Coda, memory-based
file systems and
file-backed file systems.According to the FreeBSD version you run, you will have to use
different tools for creation and use of file-backed and
memory-based file systems.The FreeBSD 4.X users will have to use &man.MAKEDEV.8;
to create the required devices. FreeBSD 5.0 and later use
&man.devfs.5; to allocate device nodes transparently for the
user.File-Backed File System under FreeBSD 4.Xdisksfile-backed (4.X)The utility &man.vnconfig.8; configures and enables vnode pseudo-disk
devices. A vnode is a representation
of a file, and is the focus of file activity. This means that
&man.vnconfig.8; uses files to create and operate a
file system. One possible use is the mounting of floppy or CD
images kept in files.To use &man.vnconfig.8;, you need &man.vn.4; support in your
kernel configuration file:pseudo-device vnTo mount an existing file system image:Using vnconfig to Mount an Existing File System
Image under FreeBSD 4.X&prompt.root; vnconfig vn0diskimage
&prompt.root; mount /dev/vn0c /mntTo create a new file system image with &man.vnconfig.8;:Creating a New File-Backed Disk with vnconfig&prompt.root; dd if=/dev/zero of=newimage bs=1k count=5k
5120+0 records in
5120+0 records out
&prompt.root; vnconfig -s labels -c vn0newimage
&prompt.root; disklabel -r -w vn0 auto
&prompt.root; newfs vn0c
Warning: 2048 sector(s) in last cylinder unallocated
/dev/vn0c: 10240 sectors in 3 cylinders of 1 tracks, 4096 sectors
5.0MB in 1 cyl groups (16 c/g, 32.00MB/g, 1280 i/g)
super-block backups (for fsck -b #) at:
32
&prompt.root; mount /dev/vn0c /mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/vn0c 4927 1 4532 0% /mntFile-Backed File System under FreeBSD 5.Xdisksfile-backed (5.X)The utility &man.mdconfig.8; is used to configure and enable
memory disks, &man.md.4;, under FreeBSD 5.X. To use
&man.mdconfig.8;, you have to load &man.md.4; module or to add
the support in your kernel configuration file:device mdThe &man.mdconfig.8; command supports three kinds of
memory backed virtual disks: memory disks allocated with
&man.malloc.9;, memory disks using a file or swap space as
backing. One possible use is the mounting of floppy
or CD images kept in files.To mount an existing file system image:Using mdconfig to Mount an Existing File System
Image under FreeBSD 5.X&prompt.root; mdconfig -a -t vnode -f diskimage -u 0
&prompt.root; mount /dev/md0/mntTo create a new file system image with &man.mdconfig.8;:Creating a New File-Backed Disk with mdconfig&prompt.root; dd if=/dev/zero of=newimage bs=1k count=5k
5120+0 records in
5120+0 records out
&prompt.root; mdconfig -a -t vnode -f newimage -u 0
&prompt.root; disklabel -r -w md0 auto
&prompt.root; newfs md0c
/dev/md0c: 5.0MB (10240 sectors) block size 16384, fragment size 2048
using 4 cylinder groups of 1.27MB, 81 blks, 256 inodes.
super-block backups (for fsck -b #) at:
32, 2624, 5216, 7808
&prompt.root; mount /dev/md0c /mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/md0c 4846 2 4458 0% /mntIf you do not specify the unit number with the
option, &man.mdconfig.8; will use the
&man.md.4; automatic allocation to select an unused device.
The name of the allocated unit will be output on stdout like
md4. For more details about
&man.mdconfig.8;, please refer to the manual page.Since &os; 5.1-RELEASE, the &man.bsdlabel.8;
utility replaces the old &man.disklabel.8; program. With
&man.bsdlabel.8; a number of obsolete options and parameters
have been retired; in the example above the option
should be removed. For more
information, please refer to the &man.bsdlabel.8;
manual page.The utility &man.mdconfig.8; is very useful, however it
asks many command lines to create a file-backed file system.
FreeBSD 5.0 also comes with a tool called &man.mdmfs.8;,
this program configures a &man.md.4; disk using
&man.mdconfig.8;, puts a UFS file system on it using
&man.newfs.8;, and mounts it using &man.mount.8;. For example,
if you want to create and mount the same file system image as
above, simply type the following:Configure and Mount a File-Backed Disk with mdmfs&prompt.root; dd if=/dev/zero of=newimage bs=1k count=5k
5120+0 records in
5120+0 records out
&prompt.root; mdmfs -F newimage -s 5m md0/mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/md0 4846 2 4458 0% /mntIf you use the option without unit
number, &man.mdmfs.8; will use &man.md.4; auto-unit feature to
automatically select an unused device. For more details
about &man.mdmfs.8;, please refer to the manual page.Memory-Based File System under FreeBSD 4.Xdisksmemory file system (4.X)The &man.md.4; driver is a simple, efficient means to create memory
file systems under FreeBSD 4.X. &man.malloc.9; is used
to allocate the memory.Simply take a file system you have prepared with, for
example, &man.vnconfig.8;, and:md Memory Disk under FreeBSD 4.X&prompt.root; dd if=newimage of=/dev/md0
5120+0 records in
5120+0 records out
&prompt.root; mount /dev/md0c/mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/md0c 4927 1 4532 0% /mntFor more details, please refer to &man.md.4; manual
page.Memory-Based File System under FreeBSD 5.Xdisksmemory file system (5.X)The same tools are used for memory-based and file-backed
file systems: &man.mdconfig.8; or &man.mdmfs.8;. The storage
for memory-based file system is allocated with
&man.malloc.9;.Creating a New Memory-Based Disk with
mdconfig&prompt.root; mdconfig -a -t malloc -s 5m -u 1
&prompt.root; newfs -U md1
/dev/md1: 5.0MB (10240 sectors) block size 16384, fragment size 2048
using 4 cylinder groups of 1.27MB, 81 blks, 256 inodes.
with soft updates
super-block backups (for fsck -b #) at:
32, 2624, 5216, 7808
&prompt.root; mount /dev/md1/mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/md1 4846 2 4458 0% /mntCreating a New Memory-Based Disk with
mdmfs&prompt.root; mdmfs -M -s 5m md2/mnt
&prompt.root; df /mnt
Filesystem 1K-blocks Used Avail Capacity Mounted on
/dev/md2 4846 2 4458 0% /mntInstead of using a &man.malloc.9; backed file system, it is
possible to use swap, for that just replace
with in the
command line of &man.mdconfig.8;. The &man.mdmfs.8; utility
by default (without ) creates a swap-based
disk. For more details, please refer to &man.mdconfig.8;
and &man.mdmfs.8; manual pages.Detaching a Memory Disk from the Systemdisksdetaching a memory diskWhen a memory-based or file-based file system
is not used, you should release all resources to the system.
The first thing to do is to unmount the file system, then use
&man.mdconfig.8; to detach the disk from the system and release
the resources.For example to detach and free all resources used by
/dev/md4:&prompt.root; mdconfig -d -u 4It is possible to list information about configured
&man.md.4; devices in using the command mdconfig
-l.For FreeBSD 4.X, &man.vnconfig.8; is used to detach
the device. For example to detach and free all resources
used by /dev/vn4:&prompt.root; vnconfig -u vn4TomRhodesContributed by File System Snapshotsfile systemssnapshotsFreeBSD 5.0 offers a new feature in conjunction with
Soft Updates: File system snapshots.Snapshots allow a user to create images of specified file
systems, and treat them as a file.
Snapshot files must be created in the file system that the
action is performed on, and a user may create no more than 20
snapshots per file system. Active snapshots are recorded
in the superblock so they are persistent across unmount and
remount operations along with system reboots. When a snapshot
is no longer required, it can be removed with the standard &man.rm.1;
command. Snapshots may be removed in any order,
however all the used space may not be acquired because another snapshot will
possibly claim some of the released blocks.The un-alterable file flag is set
by &man.mksnap.ffs.8; after initial creation of a snapshot file.
The &man.unlink.1; command makes an exception for snapshot files
since it allows them to be removed.Snapshots are created with the &man.mount.8; command. To place
a snapshot of /var in the file
/var/snapshot/snap use the following
command:&prompt.root; mount -u -o snapshot /var/snapshot/snap /varAlternatively, you can use &man.mksnap.ffs.8; to create
a snapshot:&prompt.root; mksnap_ffs /var /var/snapshot/snapOne can find snapshot files on a file system (e.g. /var)
by using the &man.find.1; command:&prompt.root; find /var -flags snapshotOnce a snapshot has been created, it has several
uses:Some administrators will use a snapshot file for backup purposes,
because the snapshot can be transfered to CDs or tape.File integrity, &man.fsck.8; may be ran on the snapshot.
Assuming that the file system was clean when it was mounted, you
should always get a clean (and unchanging) result.
This is essentially what the
background &man.fsck.8; process does.Run the &man.dump.8; utility on the snapshot.
A dump will be returned that is consistent with the
file system and the timestamp of the snapshot. &man.dump.8;
can also take a snapshot, create a dump image and then
remove the snapshot in one command using the
flag.&man.mount.8; the snapshot as a frozen image of the file system.
To &man.mount.8; the snapshot
/var/snapshot/snap run:&prompt.root; mdconfig -a -t vnode -f /var/snapshot/snap -u 4
&prompt.root; mount -r /dev/md4 /mntYou can now walk the hierarchy of your frozen /var
file system mounted at /mnt. Everything will
initially be in the same state it was during the snapshot creation time.
The only exception is that any earlier snapshots will appear
as zero length files. When the use of a snapshot has delimited,
it can be unmounted with:&prompt.root; umount /mnt
&prompt.root; mdconfig -d -u 4For more information about and
file system snapshots, including technical papers, you can visit
Marshall Kirk McKusick's website at
.File System Quotasaccountingdisk spacedisk quotasQuotas are an optional feature of the operating system that
allow you to limit the amount of disk space and/or the number of
files a user or members of a group may allocate on a per-file
system basis. This is used most often on timesharing systems where
it is desirable to limit the amount of resources any one user or
group of users may allocate. This will prevent one user or group
of users from consuming all of the available disk space.Configuring Your System to Enable Disk QuotasBefore attempting to use disk quotas, it is necessary to make
sure that quotas are configured in your kernel. This is done by
adding the following line to your kernel configuration
file:options QUOTAThe stock GENERIC kernel does not have
this enabled by default, so you will have to configure, build and
install a custom kernel in order to use disk quotas. Please refer
to for more information on kernel
configuration.Next you will need to enable disk quotas in
/etc/rc.conf. This is done by adding the
line:enable_quotas="YES"disk quotascheckingFor finer control over your quota startup, there is an
additional configuration variable available. Normally on bootup,
the quota integrity of each file system is checked by the
&man.quotacheck.8; program. The
&man.quotacheck.8; facility insures that the data in
the quota database properly reflects the data on the file system.
This is a very time consuming process that will significantly
affect the time your system takes to boot. If you would like to
skip this step, a variable in /etc/rc.conf
is made available for the purpose:check_quotas="NO"Finally you will need to edit /etc/fstab
to enable disk quotas on a per-file system basis. This is where
you can either enable user or group quotas or both for all of your
file systems.To enable per-user quotas on a file system, add the
option to the options field in the
/etc/fstab entry for the file system you want
to enable quotas on. For example:/dev/da1s2g /home ufs rw,userquota 1 2Similarly, to enable group quotas, use the
option instead of
. To enable both user and
group quotas, change the entry as follows:/dev/da1s2g /home ufs rw,userquota,groupquota 1 2By default, the quota files are stored in the root directory of
the file system with the names quota.user and
quota.group for user and group quotas
respectively. See &man.fstab.5; for more
information. Even though the &man.fstab.5; manual page says that
you can specify
an alternate location for the quota files, this is not recommended
because the various quota utilities do not seem to handle this
properly.At this point you should reboot your system with your new
kernel. /etc/rc will automatically run the
appropriate commands to create the initial quota files for all of
the quotas you enabled in /etc/fstab, so
there is no need to manually create any zero length quota
files.In the normal course of operations you should not be required
to run the &man.quotacheck.8;,
&man.quotaon.8;, or &man.quotaoff.8;
commands manually. However, you may want to read their manual pages
just to be familiar with their operation.Setting Quota Limitsdisk quotaslimitsOnce you have configured your system to enable quotas, verify
that they really are enabled. An easy way to do this is to
run:&prompt.root; quota -vYou should see a one line summary of disk usage and current
quota limits for each file system that quotas are enabled
on.You are now ready to start assigning quota limits with the
&man.edquota.8; command.You have several options on how to enforce limits on the
amount of disk space a user or group may allocate, and how many
files they may create. You may limit allocations based on disk
space (block quotas) or number of files (inode quotas) or a
combination of both. Each of these limits are further broken down
into two categories: hard and soft limits.hard limitA hard limit may not be exceeded. Once a user reaches his
hard limit he may not make any further allocations on the file
system in question. For example, if the user has a hard limit of
500 kbytes on a file system and is currently using 490 kbytes, the
user can only allocate an additional 10 kbytes. Attempting to
allocate an additional 11 kbytes will fail.soft limitSoft limits, on the other hand, can be exceeded for a limited
amount of time. This period of time is known as the grace period,
which is one week by default. If a user stays over his or her
soft limit longer than the grace period, the soft limit will
turn into a hard limit and no further allocations will be allowed.
When the user drops back below the soft limit, the grace period
will be reset.The following is an example of what you might see when you run
the &man.edquota.8; command. When the
&man.edquota.8; command is invoked, you are placed into
the editor specified by the EDITOR environment
variable, or in the vi editor if the
EDITOR variable is not set, to allow you to edit
the quota limits.&prompt.root; edquota -u testQuotas for user test:
/usr: kbytes in use: 65, limits (soft = 50, hard = 75)
inodes in use: 7, limits (soft = 50, hard = 60)
/usr/var: kbytes in use: 0, limits (soft = 50, hard = 75)
inodes in use: 0, limits (soft = 50, hard = 60)You will normally see two lines for each file system that has
quotas enabled. One line for the block limits, and one line for
inode limits. Simply change the value you want updated to modify
the quota limit. For example, to raise this user's block limit
from a soft limit of 50 and a hard limit of 75 to a soft limit of
500 and a hard limit of 600, change:/usr: kbytes in use: 65, limits (soft = 50, hard = 75)to:/usr: kbytes in use: 65, limits (soft = 500, hard = 600)The new quota limits will be in place when you exit the
editor.Sometimes it is desirable to set quota limits on a range of
UIDs. This can be done by use of the option
on the &man.edquota.8; command. First, assign the
desired quota limit to a user, and then run
edquota -p protouser startuid-enduid. For
example, if user test has the desired quota
limits, the following command can be used to duplicate those quota
limits for UIDs 10,000 through 19,999:&prompt.root; edquota -p test 10000-19999For more information see &man.edquota.8; manual page.Checking Quota Limits and Disk Usagedisk quotascheckingYou can use either the &man.quota.1; or the
&man.repquota.8; commands to check quota limits and
disk usage. The &man.quota.1; command can be used to
check individual user or group quotas and disk usage. A user
may only examine his own quota, and the quota of a group he
is a member of. Only the super-user may view all user and group
quotas. The
&man.repquota.8; command can be used to get a summary
of all quotas and disk usage for file systems with quotas
enabled.The following is some sample output from the
quota -v command for a user that has quota
limits on two file systems.Disk quotas for user test (uid 1002):
Filesystem usage quota limit grace files quota limit grace
/usr 65* 50 75 5days 7 50 60
/usr/var 0 50 75 0 50 60grace periodOn the /usr file system in the above
example, this user is currently 15 kbytes over the soft limit of
50 kbytes and has 5 days of the grace period left. Note the
asterisk * which indicates that the user is
currently over his quota limit.Normally file systems that the user is not using any disk
space on will not show up in the output from the
&man.quota.1; command, even if he has a quota limit
assigned for that file system. The option
will display those file systems, such as the
/usr/var file system in the above
example.Quotas over NFSNFSQuotas are enforced by the quota subsystem on the NFS server.
The &man.rpc.rquotad.8; daemon makes quota information available
to the &man.quota.1; command on NFS clients, allowing users on
those machines to see their quota statistics.Enable rpc.rquotad in
/etc/inetd.conf like so:rquotad/1 dgram rpc/udp wait root /usr/libexec/rpc.rquotad rpc.rquotadNow restart inetd:&prompt.root; kill -HUP `cat /var/run/inetd.pid`LuckyGreenContributed by shamrock@cypherpunks.toEncrypting Disk PartitionsdisksencryptingFreeBSD offers excellent online protections against
unauthorized data access. File permissions and Mandatory
Access Control (MAC) (see ) help prevent
unauthorized third-parties from accessing data while the operating
system is active and the computer is powered up. However,
the permissions enforced by the operating system are irrelevant if an
attacker has physical access to a computer and can simply move
the computer's hard drive to another system to copy and analyze
the sensitive data.Regardless of how an attacker may have come into possession of
a hard drive or powered-down computer, both GEOM
Based Disk Encryption (gbde) and
geli cryptographic subsystems in &os; are able
to protect the data on the computer's file systems against even
highly-motivated attackers with significant resources. Unlike
cumbersome encryption methods that encrypt only individual files,
gbde and geli transparently
encrypt entire file systems. No cleartext ever touches the hard
drive's platter.Disk Encryption with gbdeBecome rootConfiguring gbde requires
super-user privileges.&prompt.user; su -
Password:Verify the Operating System Version&man.gbde.4; requires FreeBSD 5.0 or higher.&prompt.root; uname -r
5.0-RELEASEAdd &man.gbde.4; Support to the Kernel Configuration FileAdd the following line to the kernel configuration
file:options GEOM_BDERebuild the kernel as described in .Reboot into the new kernel.Preparing the Encrypted Hard DriveThe following example assumes that you are adding a new hard
drive to your system that will hold a single encrypted partition.
This partition will be mounted as /private.
gbde can also be used to encrypt
/home and /var/mail, but
this requires more complex instructions which exceed the scope of
this introduction.Add the New Hard DriveInstall the new drive to the system as explained in . For the purposes of this example,
a new hard drive partition has been added as
/dev/ad4s1c. The
/dev/ad0s1*
devices represent existing standard FreeBSD partitions on
the example system.&prompt.root; ls /dev/ad*
/dev/ad0 /dev/ad0s1b /dev/ad0s1e /dev/ad4s1
/dev/ad0s1 /dev/ad0s1c /dev/ad0s1f /dev/ad4s1c
/dev/ad0s1a /dev/ad0s1d /dev/ad4Create a Directory to Hold gbde Lock Files&prompt.root; mkdir /etc/gbdeThe gbde lock file contains
information that gbde requires to
access encrypted partitions. Without access to the lock file,
gbde will not be able to decrypt
the data contained in the encrypted partition without
significant manual intervention which is not supported by the
software. Each encrypted partition uses a separate lock
file.Initialize the gbde PartitionA gbde partition must be
initialized before it can be used. This initialization needs to
be performed only once:&prompt.root; gbde init /dev/ad4s1c -i -L /etc/gbde/ad4s1c&man.gbde.8; will open your editor, permitting you to set
various configuration options in a template. For use with UFS1
or UFS2, set the sector_size to 2048:$FreeBSD: src/sbin/gbde/template.txt,v 1.1 2002/10/20 11:16:13 phk Exp $
#
# Sector size is the smallest unit of data which can be read or written.
# Making it too small decreases performance and decreases available space.
# Making it too large may prevent filesystems from working. 512 is the
# minimum and always safe. For UFS, use the fragment size
#
sector_size = 2048
[...]
&man.gbde.8; will ask you twice to type the passphrase that
should be used to secure the data. The passphrase must be the
same both times. gbde's ability to
protect your data depends entirely on the quality of the
passphrase that you choose.
For tips on how to select a secure passphrase that is easy
to remember, see the Diceware
Passphrase website.The gbde init command creates a lock
file for your gbde partition that in
this example is stored as
/etc/gbde/ad4s1c.gbde lock files
must be backed up together with the
contents of any encrypted partitions. While deleting a lock
file alone cannot prevent a determined attacker from
decrypting a gbde partition,
without the lock file, the legitimate owner will be unable
to access the data on the encrypted partition without a
significant amount of work that is totally unsupported by
&man.gbde.8; and its designer.Attach the Encrypted Partition to the Kernel&prompt.root; gbde attach /dev/ad4s1c -l /etc/gbde/ad4s1c You will be asked to provide the passphrase that you
selected during the initialization of the encrypted partition.
The new encrypted device will show up in
/dev as
/dev/device_name.bde:&prompt.root; ls /dev/ad*
/dev/ad0 /dev/ad0s1b /dev/ad0s1e /dev/ad4s1
/dev/ad0s1 /dev/ad0s1c /dev/ad0s1f /dev/ad4s1c
/dev/ad0s1a /dev/ad0s1d /dev/ad4 /dev/ad4s1c.bdeCreate a File System on the Encrypted DeviceOnce the encrypted device has been attached to the kernel,
you can create a file system on the device. To create a file
system on the encrypted device, use &man.newfs.8;. Since it is
much faster to initialize a new UFS2 file system than it is to
initialize the old UFS1 file system, using &man.newfs.8; with
the option is recommended.The option is the default
with &os; 5.1-RELEASE and later.&prompt.root; newfs -U -O2 /dev/ad4s1c.bdeThe &man.newfs.8; command must be performed on an
attached gbde partition which
is identified by a
*.bde
extension to the device name.Mount the Encrypted PartitionCreate a mount point for the encrypted file system.&prompt.root; mkdir /privateMount the encrypted file system.&prompt.root; mount /dev/ad4s1c.bde /privateVerify That the Encrypted File System is AvailableThe encrypted file system should now be visible to
&man.df.1; and be available for use.&prompt.user; df -H
Filesystem Size Used Avail Capacity Mounted on
/dev/ad0s1a 1037M 72M 883M 8% /
/devfs 1.0K 1.0K 0B 100% /dev
/dev/ad0s1f 8.1G 55K 7.5G 0% /home
/dev/ad0s1e 1037M 1.1M 953M 0% /tmp
/dev/ad0s1d 6.1G 1.9G 3.7G 35% /usr
/dev/ad4s1c.bde 150G 4.1K 138G 0% /privateMounting Existing Encrypted File SystemsAfter each boot, any encrypted file systems must be
re-attached to the kernel, checked for errors, and mounted, before
the file systems can be used. The required commands must be
executed as user root.Attach the gbde Partition to the Kernel&prompt.root; gbde attach /dev/ad4s1c -l /etc/gbde/ad4s1cYou will be asked to provide the passphrase that you
selected during initialization of the encrypted
gbde partition.Check the File System for ErrorsSince encrypted file systems cannot yet be listed in
/etc/fstab for automatic mounting, the
file systems must be checked for errors by running &man.fsck.8;
manually before mounting.&prompt.root; fsck -p -t ffs /dev/ad4s1c.bdeMount the Encrypted File System&prompt.root; mount /dev/ad4s1c.bde /privateThe encrypted file system is now available for use.Automatically Mounting Encrypted PartitionsIt is possible to create a script to automatically attach,
check, and mount an encrypted partition, but for security reasons
the script should not contain the &man.gbde.8; password. Instead,
it is recommended that such scripts be run manually while
providing the password via the console or &man.ssh.1;.As of &os; 5.2-RELEASE, there is a new rc.d script
provided. Arguments for this script can be passed via
&man.rc.conf.5;, for example:gbde_autoattach_all="YES"
gbde_devices="ad4s1c"This will require that the gbde
passphrase be entered at boot time. After typing the correct
passphrase, the gbde encrypted
partition will be mounted automatically. This can be very
useful when using gbde on
notebooks.Cryptographic Protections Employed by gbde&man.gbde.8; encrypts the sector payload using 128-bit AES in
CBC mode. Each sector on the disk is encrypted with a different
AES key. For more information on gbde's
cryptographic design, including how the sector keys are derived
from the user-supplied passphrase, see &man.gbde.4;.Compatibility Issues&man.sysinstall.8; is incompatible with
gbde-encrypted devices. All
*.bde devices must be detached from the
kernel before starting &man.sysinstall.8; or it will crash during
its initial probing for devices. To detach the encrypted device
used in our example, use the following command:&prompt.root; gbde detach /dev/ad4s1cAlso note that, as &man.vinum.4; does not use the
&man.geom.4; subsystem, you cannot use
gbde with
vinum volumes.DanielGerzoContributed by Disk Encryption with geliA new cryptographic GEOM class is available as of &os; 6.0 -
geli. It is currently being developed by
&a.pjd;. Geli is different to
gbde; it offers different features and uses
a different scheme for doing cryptographic work.The most important features of &man.geli.8; are:Utilizes the &man.crypto.9; framework — when
cryptographic hardware is available, geli
will use it automatically.Supports multiple cryptographic algorithms (currently
AES, Blowfish, and 3DES).Allows the root partition to be encrypted. The
passphrase used to access the encrypted root partition will
be requested during the system boot.Allows the use of two independent keys (e.g. a
key and a company key).geli is fast - performs simple
sector-to-sector encryption.Allows backup and restore of Master Keys. When a user
has to destroy his keys, it will be possible to get access
to the data again by restoring keys from the backup.Allows to attach a disk with a random, one-time key
— useful for swap partitions and temporary file
systems.More geli features can be found in the
&man.geli.8; manual page.The next steps will describe how to enable support for
geli in the &os; kernel and will explain how
to create a new geli encryption provider. At
the end it will be demonstrated how to create an encrypted swap
partition using features provided by geli.In order to use geli, you must be running
&os; 6.0-RELEASE or later. Super-user privileges will be
required since modifications to the kernel are necessary.Adding geli Support to the Kernel
Configuration FileAdd the following lines to the kernel configuration
file:options GEOM_ELI
device cryptoRebuild the kernel as described in .Alternatively, the geli module can
be loaded at boot time. Add the following line to the
/boot/loader.conf:geom_eli_load="YES"&man.geli.8; should now be supported by the kernel.Generating the Master KeyThe following example will describe how to generate a
key file, which will be used as part of the Master Key for
the encrypted provider mounted under
/private. The key
file will provide some random data used to encrypt the
Master Key. The Master Key will be protected by a
passphrase as well. Provider's sector size will be 4kB big.
Furthermore, the discussion will describe how to attach the
geli provider, create a file system on
it, how to mount it, how to work with it, and finally how to
detach it.It is recommended to use a bigger sector size (like 4kB) for
better performance.The Master Key will be protected with a passphrase and
the data source for key file will be
/dev/random. The sector size of
/dev/da2.eli, which we call provider,
will be 4kB.&prompt.root; dd if=/dev/random of=/root/da2.key bs=64 count=1
&prompt.root; geli init -s 4096 -K /root/da2.key /dev/da2
Enter new passphrase:
Reenter new passphrase:It is not mandatory that both a passphrase and a key
file are used; either method of securing the Master Key can
be used in isolation.If key file is given as -, standard
input will be used. This example shows how more than one
key file can be used.&prompt.root; cat keyfile1 keyfile2 keyfile3 | geli init -K - /dev/da2Attaching the Provider with the generated Key&prompt.root; geli attach -k /root/da2.key /dev/da2
Enter passphrase:The new plaintext device will be named
/dev/da2.eli.&prompt.root; ls /dev/da2*
/dev/da2 /dev/da2.eliCreating the new File System&prompt.root; dd if=/dev/random of=/dev/da2.eli bs=1m
&prompt.root; newfs /dev/da2.eli
&prompt.root; mount /dev/da2.eli /privateThe encrypted file system should be visible to &man.df.1;
and be available for use now.&prompt.root; df -H
Filesystem Size Used Avail Capacity Mounted on
/dev/ad0s1a 248M 89M 139M 38% /
/devfs 1.0K 1.0K 0B 100% /dev
/dev/ad0s1f 7.7G 2.3G 4.9G 32% /usr
/dev/ad0s1d 989M 1.5M 909M 0% /tmp
/dev/ad0s1e 3.9G 1.3G 2.3G 35% /var
/dev/da2.eli 150G 4.1K 138G 0% /privateUnmounting and Detaching the ProviderOnce the work on the encrypted partition is done, and
the /private partition
is no longer needed, it is prudent to consider unmounting
and detaching the geli encrypted
partition from the kernel.&prompt.root; umount /private
&prompt.root; geli detach da2.eliMore information about the use of &man.geli.8; can be
found in the manual page.Encrypting a Swap PartitionThe following example demonstrates how to create a
geli encrypted swap partition.&prompt.root; dd if=/dev/random of=/dev/ad0s1b bs=1m
&prompt.root; geli onetime -d -a 3des ad0s1b
&prompt.root; swapon /dev/ad0s1b.eliUsing the gelirc.d Scriptgeli comes with a rc.d script which
can be used to simplify the usage of geli.
An example of configuring geli through
&man.rc.conf.5; follows:geli_devices="da2"
geli_da2_flags="-p -k /root/da2.key"This will configure /dev/da2 as a
geli provider of which the Master Key file
is located in /root/da2.key, and
geli will not use a passphrase when
attaching the provider (note that this can only be used if -P
was given during the geli init phase). The
system will detach the geli provider from
the kernel before the system shuts down.More information about configuring rc.d is provided in the
rc.d section of the
Handbook.
diff --git a/zh_TW.Big5/books/handbook/firewalls/chapter.sgml b/zh_TW.Big5/books/handbook/firewalls/chapter.sgml
index df23209f99..eae7b2e7e4 100644
--- a/zh_TW.Big5/books/handbook/firewalls/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/firewalls/chapter.sgml
@@ -1,3378 +1,3307 @@
Joseph J.BarbishContributed by BradDavisConverted to SGML and updated by
- Firewalls
+ 防火牆
- firewall
+ 防火牆
- security
+ 安全
- firewalls
+ 防火牆
- Introduction
-
- Firewalls make it possible to filter
- incoming and outgoing traffic that flows through your system.
- A firewall can use one or more sets of rules to
- inspect the network packets as they come in or go out of your
- network connections and either allows the traffic through or
- blocks it. The rules of a firewall can inspect one or more
- characteristics of the packets, including but not limited to the
- protocol type, the source or destination host address, and the
- source or destination port.
-
- Firewalls can greatly enhance the security of a host or a
- network. They can be used to do one or more of
- the following things:
-
+ 介紹
+
+ 防火牆能夠過濾你的系統中進出的流量。
+ 防火牆也能藉由設置一或多組「規則 (rules)」
+ 來檢查你的網路連結中進出的網路封包 (network packets),
+ 並且能允許或阻擋其通過。
+ 這些防火牆的規則可以檢查封包中的特徵,
+ 這些特徵涵蓋,但不限於某些通訊協定類型、主機位址的來源或目的,
+ 以及連接埠 (port) 的來源及目的。
+
+ 防火牆能夠大幅地增強主機或是網路的安全性。
+ 它也能夠用來執行下列事項:
+
- To protect and insulate the applications, services and
- machines of your internal network from unwanted traffic
- coming in from the public Internet.
+ 保護或隔離你內部網路的應用程式、
+ 服務以及機器,免於被來自 Internet 中你不想要的傳輸所影響
+
- To limit or disable access from hosts of the internal
- network to services of the public Internet.
+ 限制或禁止內部網路對 Internet 的存取服務
- To support network address translation
- (NAT), which allows your internal network
- to use private IP addresses and share a
- single connection to the public Internet (either with a
- single IP address or by a shared pool of
- automatically assigned public addresses).
+ 支援「網路位址轉換」(network address translation
+ , NAT),
+ 它可以允許你的內部網路使用私有IP
+ 位址並可以共同分享一個單一連線到網際網路上
+ (可同時用單一IP位址或是一組公共網址)
+
- After reading this chapter, you will know:
+ 讀完這章之後,你將會知道:
- How to properly define packet filtering rules.
+ 如何適當地訂出封包過濾的規則。
- The differences between the firewalls
- built into &os;.
+ &os; 中內建的防火牆之間的差異。
- How to use and configure the OpenBSD
- PF firewall.
+ 如何使用及設定 OpenBSD 的
+ PF 防火牆。
- How to use and configure
- IPFILTER.
+ 如何使用及設定
+ IPFILTER。
- How to use and configure
- IPFW.
+ 如何使用及設定
+ IPFW。
- Before reading this chapter, you should:
+ 在閱讀這章之前,你必須:
- Understand basic &os; and Internet concepts.
+ 了解基本的 &os; 和 Internet 觀念
- Firewall Concepts
+ 防火牆概念
- firewall
+ 防火牆
- rulesets
+ 規則
- There are two basic ways to create firewall rulesets:
- inclusive or exclusive. An
- exclusive firewall allows all traffic through except for the
- traffic matching the ruleset. An inclusive firewall does the
- reverse. It only allows traffic matching the rules through and
- blocks everything else.
-
- Inclusive firewalls are generally safer than exclusive
- firewalls because they significantly reduce the risk of allowing
- unwanted traffic to pass through the firewall.
-
- Security can be tightened further using a stateful
- firewall. With a stateful firewall the firewall keeps
- track of which connections are opened through the firewall and
- will only allow traffic through which either matches an existing
- connection or opens a new one. The disadvantage of a stateful
- firewall is that it can be vulnerable to Denial of Service
- (DoS) attacks if a lot of new connections are
- opened very fast. With most firewalls it is possible to use a
- combination of stateful and non-stateful behavior to make an
- optimal firewall for the site.
+
+ 有兩種基本的方式可以建立防火牆規則:
+ 「先容式(exclusive)」或是「後容式(inclusive)」。
+
+ 「先容式(exclusive)」類似「黑名單」,它先允許所有封包通過,
+ 然後違反規則的封包則禁止通過防火牆。
+ 相反的,「後容式(inclusive)」類似「白名單」,它先擋住所有封包通過,
+ 然後只允許有符合規則的才可通過防火牆。
+
+
+ 整體來說,「後容式(inclusive)」的防火牆會比「先容式(exclusive)」的防火牆安全些。
+ 因為後容式明顯降低了不必要的風險。
+
+ 此外,使用「狀態防火牆(stateful firewall)」可讓安全性更嚴密。
+ 它會持續記錄通過防火牆開放的連線,
+ 並且只允許符合現存或開啟新的連線才能通過防火牆。
+ 狀態防火牆的缺點是如果在非常快的速度下開啟許多新連線,就可能會受到阻絕式服務攻擊
+ (DoS, Denial of Service)。
+ 在大多數的防火牆方案中,也可以交互運用「狀態」及「非狀態」防火牆的組合,
+ 使該站的防火牆達到最佳化。
+
+
- Firewall Packages
-
- &os; has three different firewall packages built
- into the base system. They are: IPFILTER
- (also known as IPF),
- IPFIREWALL (also known as IPFW),
- and OpenBSD's PacketFilter (also known as
- PF). &os; also has two built in packages for
- traffic shaping (basically controlling bandwidth usage):
- &man.altq.4; and &man.dummynet.4;. Dummynet has traditionally been
- closely tied with IPFW, and
- ALTQ with
- IPF/PF. IPF,
- IPFW, and PF all use rules to control the access of packets to and
- from your system, although they go about it different ways and
- have different rule syntaxes.
-
- The reason that &os; has multiple built in firewall packages
- is that different people have different requirements and
- preferences. No single firewall package is the best.
-
- The author prefers IPFILTER because its stateful rules are
- much less complicated to use in a NAT
- environment and it has a built in ftp proxy that simplifies the
- rules to allow secure outbound FTP usage.
-
- Since all firewalls are based on inspecting the values of
- selected packet control fields, the creator of the firewall
- rulesets must have an understanding of how
- TCP/IP works, what the different values in
- the packet control fields are and how these values are used in a
- normal session conversation. For a good explanation go to:
+ 防火牆軟體套件
+
+
+ 在 &os; 基本系統中內建有三種不同的防火牆軟體套件。
+ 它們分別是 IPFILTER
+ (也就是 IPF)、
+ IPFIREWALL (也就是 IPFW),
+ 以及 OpenBSD 的 PacketFilter (即有名的 PF)。
+ &os; 也有兩個內建的流量控管套件(基本上是控制頻寬的使用):
+ &man.altq.4; 以及 &man.dummynet.4;。
+ 通常我們習慣把 Dummynet 與 IPFW 一併運用,
+ 而 ALTQ 則是搭配
+ IPF/PF 一同使用。
+ 雖然 IPF、IPFW 以及 PF 是使用不同的實做方式及規則語法,
+ 但是它們都使用規則來控制是否允許資料封包進出你的系統。
+
+ &os; 為何會內建許多不同的防火牆軟體套件,
+ 這是因為不同人會有不同的需求、偏好,很難說哪一個防火牆軟體套件是最好的。
+
+ 而筆者偏好 IPFILTER 的原因,是因為運用在 NAT
+ 環境的時候,它的狀態規則是相對簡單許多的。
+ 而且它內建的 FTP 代理,也簡化了如何設定安全的對外 FTP 服務規則。
+
+
+ 正由於所有的防火牆都是以「檢查、控制所選定之封包」的實作,所以,
+ 制定防火牆規則的人就更必須了解 TCP/IP 如何運作,
+ 以及如何控制封包在正常 session 的各種作用。
+ 更詳盡的說明,請參閱:
.
+ url="http://www.ipprimer.com/overview.cfm">。
+
- The OpenBSD Packet Filter (PF) and
+ OpenBSD 封包過濾器 (Packet Filter, PF)及
ALTQ
- firewall
+ 防火牆PF
- As of July 2003 the OpenBSD firewall software application
- known as PF was ported to &os; and was made
- available in the &os; Ports Collection; the first release that
- contained PF as an integrated part of the
- base system was &os; 5.3 in November 2004.
- PF is a complete, fully featured firewall
- that has optional support for ALTQ (Alternate
- Queuing). ALTQ provides Quality of Service
- (QoS) bandwidth shaping that allows
- guaranteeing bandwidth to different services based on filtering
- rules. The OpenBSD Project does an outstanding job of
- maintaining the PF User's Guide that it will not be made part of
- this handbook firewall section as that would just be duplicated
- effort.
-
- The availability of PF for the various &os; releases and
- versions is summarized below:
-
-
-
-
-
- &os; Version
-
- PF Availability
-
-
-
-
-
- Pre-4.X versions
-
- PF is not available for any release of &os; older
- than the 4.X branch.
-
-
-
- All versions of the 4.X branch
-
- PF is available as part of KAME.
-
-
-
- 5.X releases before 5.3-RELEASE
-
- The security/pf
- port can be used to install PF on these versions of &os;.
- These releases were targeted to developers and people who
- wanted a preview of early 5.X versions. Upgrading to
- 5.3-RELEASE or newer versions of &os; is strongly
- recommended.
-
-
-
- 5.3-RELEASE and later versions
-
- PF is part of the base system. Do
- not use the security/pf port on these
- versions of &os;. It will not work. Use the &man.pf.4;
- support of the base system instead.
-
-
-
-
-
- More info can be found at the PF for &os; web site: 在 2003 年 6 月份,OpenBSD 的防火牆軟體 PF
+ 被移植到 &os; 中,並且收錄於 Ports Collection 內。
+ 而 2004 年 11 月份所發行的 &os; 5.3 版也是第一次將 PF
+ 整合為基礎系統的一部分。
+ PF是個完備、全功能的防火牆,
+ 並且具有選擇性 ALTQ(交錯佇列,Alternate Queuing)
+
+ 的功能。
+ ALTQ提供了「服務品質」(QoS,
+ Quality of Service)的頻寬管理功能,
+ 這提供了以過濾規則的方式來保障各種不同服務的頻寬。
+ OpenBSD 計劃中已經對 PF 的使用指南提供了詳盡的解說,
+ 因此在這本手冊中我們不會作重複的贅述,而只介紹概要。
+
+
+ 更多關於 PF 的資訊可於下列網址查詢: .
- Enabling PF
+ 啟用 PF
- PF is included in the basic &os; install for versions newer
- than 5.3 as a separate run time loadable module. The system
- will dynamically load the PF kernel loadable module when the
- rc.conf statement pf_enable="YES" is used.
- The loadable module was created with &man.pflog.4; logging
- enabled.
+ PF 在 &os; 5.3 之後的系統中,可以輕鬆使用動態模組來載入。
+ 在 rc.conf 中加入 pf_enable="YES" 後,
+ 系統將會動態地載入 PF 核心動態模組。這個模組會在建立時也啟用
+ &man.pflog.4; 記錄功能。
- The module assumes the presence of options
- INET and device bpf. Unless
- NOINET6 (for example in &man.make.conf.5;)
- was defined during the build, it also requires options
- INET6.
+ 這個模組會假設核心內已有 options INET 和
+ device bpf。
+ 除非編譯時在核心中有事先(像是在 &man.make.conf.5; 中)加入 NOINET6,
+ &os; 6.0 以後的版本則是 NO_INET6
+ 這樣才會避免不打開 IPv6 支援,否則 pf 模組同時也需要 options INET6,
+ 也就是 IPv6 支援。
+
+ 一旦載入 PF 核心模組或靜態地編譯入核心中,
+ 就可以使用 pfctl 來啟動或關閉
+ pf。
- Once the kernel module is loaded or the kernel is statically
- built with PF support, it is possible to enable or disable
- pf with the pfctl
- command.
-
- This example demonstrates how to enable
+ 這個例子示範了如何啟動
pf:&prompt.root; pfctl -e
- The pfctl command provides a way to work
- with the pf firewall. It is a good
- idea to check the &man.pfctl.8; manual page to find out more
- information about using it.
+ pfctl指令提供了一個使用pf
+ 防火牆的方式。
+ 要了解更多使用 pfctl 的資訊,
+ 查閱 &man.pfctl.8; 的線上手冊會是個好方式。
- Kernel options
+ kernel 選項
- kernel options
+ kernel 選項device pf
- kernel options
+ kernel 選項device pflog
- kernel options
+ kernel 選項device pfsync
- It is not a mandatory requirement that you enable PF by
- compiling the following options into the &os; kernel. It is
- only presented here as background information. Compiling PF
- into the kernel causes the loadable module to never be
- used.
-
- Sample kernel config PF option statements are in the
- /usr/src/sys/conf/NOTES kernel source and
- are reproduced here:
-
+ 在編譯 &os; kernel 時,並不必完全加入下列的選項來啟用 PF。
+ 在這裡只是要列出給你參考的一些資訊而已。
+ 將 PF 編譯入 kernel 中,會導致無法使用 kernel 的動態載入模組。
+
+ 設定 PF 的核心選項範例在 kernel 原始碼中的
+ /usr/src/sys/conf/NOTES,轉貼內容如下:
+
device pf
device pflog
device pfsync
- device pf enables support for the
- Packet Filter firewall.
-
- device pflog enables the optional
- &man.pflog.4; pseudo network device which can be used to log
- traffic to a &man.bpf.4; descriptor. The &man.pflogd.8; daemon
- can be used to store the logging information to disk.
-
- device pfsync enables the optional
- &man.pfsync.4; pseudo network device that is used to monitor
- state changes. As this is not part of the
- loadable module one has to build a custom kernel to use
- it.
-
- These settings will take effect only after you have built
- and installed a kernel with them set.
+ device pf 啟用了
+ 「封包過濾(packet filter)」 的防火牆支援.
+
+ device pflog 啟動了選擇性的 &man.pflog.4;
+ 虛擬網路設備 pseudo network device),它可以透過 &man.bpf.4;
+ 的描述符號來記錄流量。
+ &man.pflogd.8; 服務可以用來儲存訊息,並可以用日誌的形式記錄在硬碟上。
+
+
+ device pfsync 啟動了選擇性 的&man.pfsync.4;
+ 虛擬網路設備,它可以用來監控「狀態的改變」。
+ device pfsync並不是可載入模組,
+ 要使用的話,必須要編入自訂的核心中才行。
+
+ 這些設定將會在你編譯及安裝好新核心後才會生效。
- Available rc.conf Options
+ rc.conf 可用的選項
- You need the following statements in
- /etc/rc.conf to activate PF at boot
- time:
+ 你需要在 /etc/rc.conf
+ 中加入下列的設定以便在啟動系統時同時啟用 PF:
- pf_enable="YES" # Enable PF (load module if required)
-pf_rules="/etc/pf.conf" # rules definition file for pf
-pf_flags="" # additional flags for pfctl startup
-pflog_enable="YES" # start pflogd(8)
-pflog_logfile="/var/log/pflog" # where pflogd should store the logfile
-pflog_flags="" # additional flags for pflogd startup
+ pf_enable="YES" # 啟用 PF (如果需要的話載入模組)
+pf_rules="/etc/pf.conf" # PF 的規則定義檔案
+pf_flags="" # pfctl 啟動時附加的選項
+pflog_enable="YES" # 啟動 pflogd(8)
+pflog_logfile="/var/log/pflog" # pflogd 儲存記錄檔案的地方
+pflog_flags="" # pflogd 啟動時附加的選項
- If you have a LAN behind this firewall and have to forward
- packets for the computers in the LAN or want to do NAT, you
- have to enable the following option as well:
+ 如果在這個防火牆後方你有個區域網路,並透過它來轉送封包,
+ 你就必須要設定下列選項:
- gateway_enable="YES" # Enable as LAN gateway
+ gateway_enable="YES" # 啟用作為區域網路閘道器
- Enabling ALTQ
-
- ALTQ is only available by compiling the
- options into the &os; Kernel. ALTQ is not
- supported by all of the available network card drivers. Please
- see the &man.altq.4; manual page for a list of drivers that are
- supported in your release of &os;. The following options will
- enable ALTQ and add additional
- functionality.
+ 啟用 ALTQ
+
+ ALTQ的選項只有在編入 &os; 核心中才能生效。
+ 不是所有的網路卡驅動程式都支援 ALTQ。
+ 請看 &man.altq.4; 線上手冊來了解你使用的 &os; 版本中支援驅動程式的清單。
+ 下面列出的選項將會啟用 ALTQ 及加入其他附加的功能。options ALTQ
options ALTQ_CBQ # Class Bases Queuing (CBQ)
options ALTQ_RED # Random Early Detection (RED)
options ALTQ_RIO # RED In/Out
options ALTQ_HFSC # Hierarchical Packet Scheduler (HFSC)
options ALTQ_PRIQ # Priority Queuing (PRIQ)
options ALTQ_NOPCC # Required for SMP build
- options ALTQ enables the
- ALTQ framework.
+ options ALTQ 啟用了
+ ALTQ 主架構。
- options ALTQ_CBQ enables Class Based
- Queuing (CBQ). CBQ
+ options ALTQ_CBQ 啟用「基於分類的佇列」
+ (Class Based Queuing, CBQ)支援。
+ CBQ 允許你
allows you to divide a connection's bandwidth into different
classes or queues to prioritize traffic based on filter
rules.options ALTQ_RED enables Random Early
Detection (RED). RED is
used to avoid network congestion. RED does
this by measuring the length of the queue and comparing it to
the minimum and maximum thresholds for the queue. If the
queue is over the maximum all new packets will be dropped.
True to its name, RED drops packets from
different connections randomly.options ALTQ_RIO enables Random Early
Detection In and Out.options ALTQ_HFSC enables the
Hierarchical Fair Service Curve Packet Scheduler. For more
information about HFSC see: .options ALTQ_PRIQ enables Priority
Queuing (PRIQ). PRIQ
will always pass traffic that is in a higher queue
first.options ALTQ_NOPCC enables
SMP support for ALTQ.
This option is required on SMP
systems.Creating Filtering RulesThe Packet Filter reads its configuration rules from the
&man.pf.conf.5; file and it modifies, drops or passes packets
according to the rules or definitions specified there. The &os;
installation comes with a default
/etc/pf.conf which contains useful examples
and explanations.Although &os; has its own /etc/pf.conf
the syntax is the same as one used in OpenBSD. A great
resource for configuring the pf
firewall has been written by OpenBSD team and is available at
.When browsing the pf user's guide, please keep in mind that
different versions of &os; contain different versions of pf. The
pf firewall in &os; 5.X is at the level
of OpenBSD version 3.5 and in &os; 6.X is at the level of OpenBSD
version 3.7.The &a.pf; is a good place to ask questions about
configuring and running the pf
firewall. Do not forget to check the mailing list archives
before asking questions.
- The IPFILTER (IPF) Firewall
+ IPFILTER (IPF) 防火牆
- firewall
+ 防火牆IPFILTER
- This section is work in progress. The contents might
- not be accurate at all times.
+ 此小節的說明仍待陸續補充、更新,所以本內容可能並非完全符合現況。
- The author of IPFILTER is Darren Reed. IPFILTER is not
- operating system dependent: it is an open source application and
- has been ported to &os;, NetBSD, OpenBSD, &sunos;, HP/UX, and
- &solaris; operating systems. IPFILTER is actively being
- supported and maintained, with updated versions being released
- regularly.
+ IPFILTER 的作者為 Darren Reed。IPFILTER 並非
+ operating system dependent:它是個 open source 應用程式,且已被移植到
+ &os;、NetBSD、OpenBSD、&sunos;、HP/UX 以及
+ &solaris; 這些作業系統上。此外,IPFILTER 的支援以及維護也相當積極,也有定期釋出的更新版。IPFILTER is based on a kernel-side firewall and
NAT mechanism that can be controlled and
monitored by userland interface programs. The firewall rules can
be set or deleted with the &man.ipf.8; utility. The
NAT rules can be set or deleted with the
&man.ipnat.1; utility. The &man.ipfstat.8; utility can print
run-time statistics for the kernel parts of IPFILTER. The
&man.ipmon.8; program can log IPFILTER actions to the system log
files.IPF was originally written using a rule processing logic of
- the last matching rule wins and used only
+ 「the last matching rule wins」 and used only
stateless type of rules. Over time IPF has been enhanced to
- include a quick option and a stateful keep
- state option which drastically modernized the rules
+ include a 「quick」 option and a stateful 「keep
+ state」 option which drastically modernized the rules
processing logic. IPF's official documentation covers the legacy
rule coding parameters and the legacy rule file processing
logic. The modernized functions are only included as additional
options, completely understating their benefits in producing a
far superior secure firewall.The instructions contained in this section are based on
- using rules that contain the quick option and the
- stateful keep state option. This is the basic
+ using rules that contain the 「quick」 option and the
+ stateful 「keep state」 option. This is the basic
framework for coding an inclusive firewall rule set.An inclusive firewall only allows packets matching the rules
to pass through. This way you can control what services can
originate behind the firewall destined for the public Internet
and also control the services which can originate from the
public Internet accessing your private network. Everything else
is blocked and logged by default design. Inclusive firewalls are
much, much more secure than exclusive firewall rule sets and is
the only rule set type covered herein.For detailed explanation of the legacy rules processing
method see:
and .
- The IPF FAQ is at IPF 的 FAQ 位於 .
- Enabling IPF
+ 啟用 IPFIPFILTER
- enabling
+ 啟用IPF is included in the basic &os; install as a separate run
time loadable module. The system will dynamically load the IPF
kernel loadable module when the rc.conf statement
ipfilter_enable="YES" is used. The loadable
module was created with logging enabled and the
default pass all options. You do not need
to compile IPF into the &os; kernel just to change the default
to block all, you can do that by just coding
a block all rule at the end of your rule set.
- Kernel options
+ kernel 選項kernel optionsIPFILTERkernel optionsIPFILTER_LOGkernel optionsIPFILTER_DEFAULT_BLOCKIPFILTERkernel options
- It is not a mandatory requirement that you enable IPF by
- compiling the following options into the &os; kernel. It is
- only presented here as background information. Compiling IPF
- into the kernel causes the loadable module to never be
- used.
+ 在編譯 &os; kernel 時,並不必完全加入下列的選項來啟用 IPF。
+ 在這裡只是要列出給你參考的一些資訊而已。
+ 將 IPF 編譯入 kernel 中,會導致無法使用 kernel 的動態載入模組。Sample kernel config IPF option statements are in the
/usr/src/sys/conf/NOTES kernel source
(/usr/src/sys/arch/conf/LINT
for &os; 4.X) and are reproduced here:options IPFILTER
options IPFILTER_LOG
options IPFILTER_DEFAULT_BLOCKoptions IPFILTER enables support for the
- IPFILTER firewall.
+ 「IPFILTER」 firewall.
options IPFILTER_LOG enables the option
to have IPF log traffic by writing to the
ipl packet logging pseudo—device
for every rule that has the log
keyword.options IPFILTER_DEFAULT_BLOCK changes
the default behavior so any packet not matching a firewall
pass rule gets blocked.These settings will take effect only after you have built
and installed a kernel with them set.
- Available rc.conf Options
+ 可用的 rc.conf 選項
- You need the following statements in
- /etc/rc.conf to activate IPF at boot
- time:
+ 須在 /etc/rc.conf 內加入下列內容,以便在開機時就會啟用 IPF:ipfilter_enable="YES" # Start ipf firewall
-ipfilter_rules="/etc/ipf.rules" # loads rules definition text file
-ipmon_enable="YES" # Start IP monitor log
-ipmon_flags="-Ds" # D = start as daemon
- # s = log to syslog
- # v = log tcp window, ack, seq
- # n = map IP & port to names
+ipfilter_rules="/etc/ipf.rules" # 載入定義規則的文字檔案
+ipmon_enable="YES" # 啟用 IP 監控記錄
+ipmon_flags="-Ds" # D = 使用服務程序 (daemon) 啟動
+ # s = 使用 syslog 記錄
+ # v = 記錄於 tcp window, ack, seq
+ # n = 將 IP 及 port 對應至名稱中
If you have a LAN behind this firewall that uses the
reserved private IP address ranges, then you need to add the
following to enable NAT
functionality:
- gateway_enable="YES" # Enable as LAN gateway
+ gateway_enable="YES" # 啟用為區域網路閘道器
ipnat_enable="YES" # Start ipnat function
ipnat_rules="/etc/ipnat.rules" # rules definition file for ipnatIPFipfThe ipf command is used to load your rules file. Normally
you create a file containing your custom rules and use this
command to replace in mass the currently running firewall
internal rules:&prompt.root; ipf -Fa -f /etc/ipf.rules means flush all internal rules
tables. means this is the file to read for the
rules to load.This gives you the ability to make changes to your custom
rules file, run the above IPF command, and thus update the
running firewall with a fresh copy of all the rules without
having to reboot the system. This method is very convenient
for testing new rules as the procedure can be executed as many
times as needed.See the &man.ipf.8; manual page for details on the other
flags available with this command.The &man.ipf.8; command expects the rules file to be a
standard text file. It will not accept a rules file written as
a script with symbolic substitution.There is a way to build IPF rules that utilizes the power
of script symbolic substitution. For more information, see
.IPFSTATipfstatIPFILTERstatisticsThe default behavior of &man.ipfstat.8; is to retrieve and
display the totals of the accumulated statistics gathered as a
result of applying the user coded rules against packets going
in and out of the firewall since it was last started, or since
the last time the accumulators were reset to zero by the
ipf -Z command.See the &man.ipfstat.8; manual page for details.The default &man.ipfstat.8; command output will look
something like this:input packets: blocked 99286 passed 1255609 nomatch 14686 counted 0
output packets: blocked 4200 passed 1284345 nomatch 14687 counted 0
input packets logged: blocked 99286 passed 0
output packets logged: blocked 0 passed 0
packets logged: input 0 output 0
log failures: input 3898 output 0
fragment state(in): kept 0 lost 0
fragment state(out): kept 0 lost 0
packet state(in): kept 169364 lost 0
packet state(out): kept 431395 lost 0
ICMP replies: 0 TCP RSTs sent: 0
Result cache hits(in): 1215208 (out): 1098963
IN Pullups succeeded: 2 failed: 0
OUT Pullups succeeded: 0 failed: 0
Fastroute successes: 0 failures: 0
TCP cksum fails(in): 0 (out): 0
Packet log flags set: (0)When supplied with either for inbound
or for outbound, it will retrieve and
display the appropriate list of filter rules currently
installed and in use by the kernel.ipfstat -in displays the inbound
internal rules table with rule number.ipfstat -on displays the outbound
internal rules table with the rule number.The output will look something like this:@1 pass out on xl0 from any to any
@2 block out on dc0 from any to any
@3 pass out quick on dc0 proto tcp/udp from any to any keep stateipfstat -ih displays the inbound
internal rules table, prefixing each rule with a count of how
many times the rule was matched.ipfstat -oh displays the outbound
internal rules table, prefixing each rule with a count of how
many times the rule was matched.The output will look something like this:2451423 pass out on xl0 from any to any
354727 block out on dc0 from any to any
430918 pass out quick on dc0 proto tcp/udp from any to any keep stateOne of the most important functions of the
ipfstat command is the
flag which displays the state table in a way similar to the way
&man.top.1; shows the &os; running process table. When your
firewall is under attack this function gives you the ability to
identify, drill down to, and see the attacking packets. The
optional sub-flags give the ability to select the destination
or source IP, port, or protocol that you want to monitor in
real time. See the &man.ipfstat.8; manual page for
details.IPMONipmonIPFILTERloggingIn order for ipmon to work properly, the
kernel option IPFILTER_LOG must be turned on. This command has
two different modes that it can be used in. Native mode is the
default mode when you type the command on the command line
without the flag.Daemon mode is for when you want to have a continuous
system log file available so that you can review logging of
past events. This is how &os; and IPFILTER are configured to
work together. &os; has a built in facility to automatically
rotate system logs. That is why outputting the log information
to syslogd is better than the default of outputting to a
regular file. In the default rc.conf file
you see the ipmon_flags statement uses the
flags:ipmon_flags="-Ds" # D = start as daemon
# s = log to syslog
# v = log tcp window, ack, seq
# n = map IP & port to namesThe benefits of logging are obvious. It provides the
ability to review, after the fact, information such as which
packets had been dropped, what addresses they came from and
where they were going. These all give you a significant edge
in tracking down attackers.Even with the logging facility enabled, IPF will not
generate any rule logging on its own. The firewall
administrator decides what rules in the rule set he wants to
log and adds the log keyword to those rules. Normally only
deny rules are logged.It is very customary to include a default deny everything
rule with the log keyword included as your last rule in the
rule set. This way you get to see all the packets that did not
match any of the rules in the rule set.IPMON LoggingSyslogd uses its own special
method for segregation of log data. It uses special groupings
- called facility and level. IPMON
+ called 「facility」 and level. IPMON
in mode uses security
- (local0 in 4.X) as the facility
+ (local0 in 4.X) as the 「facility」
name. All IPMON logged data goes to security
(local0 in 4.X). The following levels can be
used to further segregate the logged data if desired:LOG_INFO - packets logged using the "log" keyword as the action rather than pass or block.
LOG_NOTICE - packets logged which are also passed
LOG_WARNING - packets logged which are also blocked
LOG_ERR - packets which have been logged and which can be considered shortTo setup IPFILTER to log all data to
/var/log/ipfilter.log, you will need to
create the file. The following command will do that:&prompt.root; touch /var/log/ipfilter.logThe syslog function is controlled by definition statements
in the /etc/syslog.conf file. The
syslog.conf file offers considerable
flexibility in how syslog will deal with system messages issued
by software applications like IPF.Add the following statement to
/etc/syslog.conf for &os; 5.X and
later:security.* /var/log/ipfilter.logOr add the following statement to
/etc/syslog.conf for &os; 4.X:local0.* /var/log/ipfilter.logThe security.* (local0
for 4.X) means to write all the logged messages to the coded
file location.To activate the changes to /etc/syslog.conf
you can reboot or bump the syslog task into
re-reading /etc/syslog.conf by running
/etc/rc.d/syslogd reload
(killall -HUP syslogd in &os; 4.X).Do not forget to change
/etc/newsyslog.conf to rotate the new log
you just created above.The Format of Logged MessagesMessages generated by ipmon consist of
data fields separated by white space. Fields common to all
messages are:The date of packet receipt.The time of packet receipt. This is in the form
HH:MM:SS.F, for hours, minutes, seconds, and fractions of a
second (which can be several digits long).The name of the interface the packet was processed on,
e.g. dc0.The group and rule number of the rule, e.g.
@0:17.These can be viewed with ipfstat
-in.The action: p for passed, b for blocked, S for a short
packet, n did not match any rules, L for a log rule. The
order of precedence in showing flags is: S, p, b, n, L. A
capital P or B means that the packet has been logged due to
a global logging setting, not a particular rule.The addresses. This is actually three fields: the
source address and port (separated by a comma), the ->
symbol, and the destination address and port.
209.53.17.22,80 -> 198.73.220.17,1722.PR followed by the protocol name or
number, e.g. PR tcp.len followed by the header length
and total length of the packet, e.g. len 20 40.If the packet is a TCP packet, there
will be an additional field starting with a hyphen followed by
letters corresponding to any flags that were set. See the
&man.ipmon.8; manual page for a list of letters and their
flags.If the packet is an ICMP packet, there will be two fields
- at the end, the first always being ICMP, and the
+ at the end, the first always being 「ICMP」, and the
next being the ICMP message and sub-message type, separated by
a slash, e.g. ICMP 3/3 for a port unreachable message.Building the Rule Script with Symbolic
SubstitutionSome experienced IPF users create a file containing the
rules and code them in a manner compatible with running them as
a script with symbolic substitution. The major benefit of
doing this is that you only have to change the value associated
with the symbolic name and when the script is run all the rules
containing the symbolic name will have the value substituted in
the rules. Being a script, you can use symbolic substitution
to code frequently used values and substitute them in multiple
rules. You will see this in the following example.The script syntax used here is compatible with the sh, csh,
and tcsh shells.Symbolic substitution fields are prefixed with a dollar
sign: $.Symbolic fields do not have the $ prefix.The value to populate the symbolic field must be enclosed
with double quotes (").Start your rule file with something like this:
- ############# Start of IPF rules script ########################
+ ############# IPF 規則命令稿的開始 ########################
-oif="dc0" # name of the outbound interface
-odns="192.0.2.11" # ISP's DNS server IP address
-myip="192.0.2.7" # my static IP address from ISP
+oif="dc0" # 對外網路裝置的名稱
+odns="192.0.2.11" # ISP 的 DNS 伺服器 IP 位址
+myip="192.0.2.7" # 從我的 ISP 提供的靜態 IP
ks="keep state"
fks="flags S keep state"
# You can choose between building /etc/ipf.rules file
# from this script or running this script "as is".
#
# Uncomment only one line and comment out another.
#
# 1) This can be used for building /etc/ipf.rules:
#cat > /etc/ipf.rules << EOF
#
# 2) This can be used to run script "as is":
/sbin/ipf -Fa -f - << EOF
# Allow out access to my ISP's Domain name server.
pass out quick on $oif proto tcp from any to $odns port = 53 $fks
pass out quick on $oif proto udp from any to $odns port = 53 $ks
# Allow out non-secure standard www function
pass out quick on $oif proto tcp from $myip to any port = 80 $fks
# Allow out secure www function https over TLS SSL
pass out quick on $oif proto tcp from $myip to any port = 443 $fks
EOF
################## End of IPF rules script ########################That is all there is to it. The rules are not important in
this example; how the symbolic substitution fields are
populated and used are. If the above example was in a file
named /etc/ipf.rules.script, you could
reload these rules by entering the following command:&prompt.root; sh /etc/ipf.rules.scriptThere is one problem with using a rules file with embedded
symbolics: IPF does not understand symbolic substitution, and
cannot read such scripts directly.This script can be used in one of two ways:Uncomment the line that begins with
cat, and comment out the line that
begins with /sbin/ipf. Place
ipfilter_enable="YES" into
/etc/rc.conf as usual, and run script
once after each modification to create or update
/etc/ipf.rules.Disable IPFILTER in system startup scripts by adding
ipfilter_enable="NO" (this is default
value) into /etc/rc.conf file.Add a script like the following to your
/usr/local/etc/rc.d/ startup
directory. The script should have an obvious name like
ipf.loadrules.sh. The
.sh extension is mandatory.#!/bin/sh
sh /etc/ipf.rules.scriptThe permissions on this script file must be read,
write, execute for owner root.&prompt.root; chmod 700 /usr/local/etc/rc.d/ipf.loadrules.sh
- Now, when your system boots, your IPF rules will be
- loaded.
+ 從現在起,當你的系統開機時,
+ 你的 IPF 規則將會被載入
- IPF Rule Sets
+ IPF 規則A rule set is a group of ipf rules coded to pass or block
packets based on the values contained in the packet. The
bi-directional exchange of packets between hosts comprises a
session conversation. The firewall rule set processes the
packet two times, once on its arrival from the public Internet
host and again as it leaves for its return trip back to the
public Internet host. Each TCP/IP service (i.e. telnet, www,
mail, etc.) is predefined by its protocol, source and
destination IP address, or the source and destination port
number. This is the basic selection criteria used to create
rules which will pass or block services.IPFILTERrule processing orderIPF was originally written using a rules processing logic
- of the last matching rule wins and used only
+ of 「the last matching rule wins」 and used only
stateless rules. Over time IPF has been enhanced to include a
- quick option and a stateful keep
- state option which drastically modernized the rule
+ 「quick」 option and a stateful 「keep
+ state」 option which drastically modernized the rule
processing logic.The instructions contained in this section are based on
- using rules that contain the quick option and
- the stateful keep state option. This is the
+ using rules that contain the 「quick」 option and
+ the stateful 「keep state」 option. This is the
basic framework for coding an inclusive firewall rule
set.An inclusive firewall only allows services matching the
rules through. This way you can control what services can
originate behind the firewall destined for the public Internet
and also control the services which can originate from the
public Internet accessing your private network. Everything
else is blocked and logged by default design. Inclusive
firewalls are much, much securer than exclusive firewall rule
sets and is the only rule set type covered herein.When working with the firewall rules, be very
careful. Some configurations will
lock you out of the server. To be on the safe
side, you may wish to consider performing the initial
firewall configuration from the local console rather than
doing it remotely e.g. via
ssh.Rule SyntaxIPFILTERrule syntaxThe rule syntax presented here has been simplified to only
- address the modern stateful rule context and first
- matching rule wins logic. For the complete legacy rule
+ address the modern stateful rule context and 「first
+ matching rule wins」 logic. For the complete legacy rule
syntax description see the &man.ipf.8; manual page.A # character is used to mark the start
of a comment and may appear at the end of a rule line or on its
own line. Blank lines are ignored.Rules contain keywords. These keywords have to be coded in
a specific order from left to right on the line. Keywords are
identified in bold type. Some keywords have sub-options which
may be keywords themselves and also include more sub-options.
Each of the headings in the below syntax has a bold section
header which expands on the content.ACTION IN-OUT OPTIONS SELECTION STATEFUL PROTO
SRC_ADDR,DST_ADDR OBJECT PORT_NUM TCP_FLAG
STATEFULACTION = block | passIN-OUT = in | outOPTIONS = log | quick | on
interface-nameSELECTION = proto value |
source/destination IP | port = number | flags
flag-valuePROTO = tcp/udp | udp | tcp |
icmpSRC_ADD,DST_ADDR = all | from
object to objectOBJECT = IP address | anyPORT_NUM = port numberTCP_FLAG = SSTATEFUL = keep stateACTIONThe action indicates what to do with the packet if it
matches the rest of the filter rule. Each rule
must have a action. The following
actions are recognized:block indicates that the packet should
be dropped if the selection parameters match the
packet.pass indicates that the packet should
exit the firewall if the selection parameters match the
packet.IN-OUTA mandatory requirement is that each filter rule
explicitly state which side of the I/O it is to be used on.
The next keyword must be either in or out and one or the
other has to be coded or the rule will not pass syntax
checks.in means this rule is being applied
against an inbound packet which has just been received on the
interface facing the public Internet.out means this rule is being applied
against an outbound packet destined for the interface facing
the public Internet.OPTIONSThese options must be used in the order shown
here.log indicates that the packet header
will be written to
the ipl log (as described in the
LOGGING section below) if the selection parameters match the
packet.quick indicates that if the selection
parameters match the packet, this rule will be the last rule
- checked, allowing a short-circuit path to avoid processing
+ checked, allowing a 「short-circuit」 path to avoid processing
any following rules for this packet. This option is a
mandatory requirement for the modernized rules processing
logic.on indicates the interface name to be
incorporated into the selection parameters. Interface names
are as displayed by &man.ifconfig.8;. Using this option, the
rule will only match if the packet is going through that
interface in the specified direction (in/out). This option
is a mandatory requirement for the modernized rules
processing logic.When a packet is logged, the headers of the packet are
written to the IPL packet logging pseudo-device.
Immediately following the log keyword, the following
qualifiers may be used (in this order):body indicates that the first 128
bytes of the packet contents will be logged after the
headers.first If the log
- keyword is being used in conjunction with a keep
- state option, it is recommended that this option is
+ keyword is being used in conjunction with a 「keep
+ state」 option, it is recommended that this option is
also applied so that only the triggering packet is logged and
- not every packet which thereafter matches the keep
- state information.
+ not every packet which thereafter matches the 「keep
+ state」 information.
SELECTIONThe keywords described in this section are used to
describe attributes of the packet to be interrogated when
determining whether rules match or not. There is a
keyword subject, and it has sub-option keywords, one of
which has to be selected. The following general-purpose
attributes are provided for matching, and must be used in
this order:PROTOproto is the subject keyword and must
be coded along with one of its corresponding keyword
sub-option values. The value allows a specific protocol to
be matched against. This option is a mandatory requirement
for the modernized rules processing logic.tcp/udp | udp | tcp | icmp or any
protocol names found in /etc/protocols
are recognized and may be used. The special protocol keyword
tcp/udp may be used to match either a
TCP or a UDP packet, and has been added as
a convenience to save duplication of otherwise identical
rules.SRC_ADDR/DST_ADDRThe all keyword is essentially a
- synonym for from any to any with no other
+ synonym for 「from any to any」 with no other
match parameters.from src to dst: the from and to
keywords are used to match against IP addresses. Rules must
specify BOTH source and destination parameters.
any is a special keyword that matches any
- IP address. Examples of use: from any to any
- or from 0.0.0.0/0 to any or from any to
- 0.0.0.0/0 or from 0.0.0.0 to any or
- from any to 0.0.0.0.
+ IP address. Examples of use: 「from any to any」
+ or 「from 0.0.0.0/0 to any」 or from any to
+ 0.0.0.0/0」 or 「from 0.0.0.0 to any or
+ 「from any to 0.0.0.0」.
IP addresses may be specified as a dotted IP address
numeric form/mask-length, or as single dotted IP address
numeric form.There is no way to match ranges of IP addresses which
do not express themselves easily as mask-length. See this
web page for help on writing mask-length: .PORTIf a port match is included, for either or both of source
and destination, then it is only applied to
TCP and UDP packets. When composing port
comparisons, either the service name from
/etc/services or an integer port number
may be used. When the port appears as part of the from
object, it matches the source port number; when it appears
as part of the to object, it matches the destination port
number. The use of the port option with the
to object is a mandatory requirement for
the modernized rules processing logic. Example of use:
- from any to any port = 80
+ 「from any to any port = 80」
Port comparisons may be done in a number of forms, with
a number of comparison operators, or port ranges may be
specified.port "=" | "!=" | "<" | ">" | "<=" | ">=" |
"eq" | "ne" | "lt" | "gt" | "le" | "ge".To specify port ranges, port "<>" |
"><"Following the source and destination matching
parameters, the following two parameters are mandatory
requirements for the modernized rules processing
logic.TCP_FLAGFlags are only effective for TCP
filtering. The letters represents one of the possible flags
that can be interrogated in the TCP packet
header.The modernized rules processing logic uses the
flags S parameter to identify the tcp
session start request.STATEFULkeep state indicates that on a pass
rule, any packets that match the rules selection parameters
should activate the stateful filtering facility.This option is a mandatory requirement for the
modernized rules processing logic.Stateful FilteringIPFILTERstateful filteringStateful filtering treats traffic as a bi-directional
exchange of packets comprising a session conversation. When
activated, keep-state dynamically generates internal rules for
each anticipated packet being exchanged during the
bi-directional session conversation. It has the interrogation
abilities to determine if the session conversation between the
originating sender and the destination are following the valid
procedure of bi-directional packet exchange. Any packets that
do not properly fit the session conversation template are
automatically rejected as impostors.Keep state will also allow ICMP packets related to a
TCP or UDP session through. So if you get
ICMP type 3 code 4 in response to some web surfing allowed out
by a keep state rule, they will be automatically allowed in.
Any packet that IPF can be certain is part of an active
session, even if it is a different protocol, will be let
in.What happens is:Packets destined to go out the interface connected to the
public Internet are first checked against the dynamic state
table, if the packet matches the next expected packet
comprising in a active session conversation, then it exits the
firewall and the state of the session conversation flow is
updated in the dynamic state table, the remaining packets get
checked against the outbound rule set.Packets coming in to the interface connected to the public
Internet are first checked against the dynamic state table, if
the packet matches the next expected packet comprising a
active session conversation, then it exits the firewall and
the state of the session conversation flow is updated in the
dynamic state table, the remaining packets get checked against
the inbound rule set.When the conversation completes it is removed from the
dynamic state table.Stateful filtering allows you to focus on blocking/passing
new sessions. If the new session is passed, all its subsequent
packets will be allowed through automatically and any impostors
automatically rejected. If a new session is blocked, none of
its subsequent packets will be allowed through. Stateful
filtering has technically advanced interrogation abilities
capable of defending against the flood of different attack
methods currently employed by attackers.Inclusive Rule Set ExampleThe following rule set is an example of how to code a very
secure inclusive type of firewall. An inclusive firewall only
allows services matching pass rules through and blocks all
other by default. All firewalls have at the minimum two
interfaces which have to have rules to allow the firewall to
function.All &unix; flavored systems including &os; are designed to
use interface lo0 and IP address
127.0.0.1 for internal
communication within the operating system. The firewall rules
must contain rules to allow free unmolested movement of these
special internally used packets.The interface which faces the public Internet is the one
where you place your rules to authorize and control access out
to the public Internet and access requests arriving from the
public Internet. This can be your user PPP
tun0 interface or your NIC that is
connected to your DSL or cable modem.In cases where one or more NICs are cabled to private LANs
behind the firewall, those interfaces must have a rule coded to
allow free unmolested movement of packets originating from
those LAN interfaces.The rules should be first organized into three major
sections: all the free unmolested interfaces, the public
interface outbound, and the public interface inbound.The rules in each of the public interface sections should
have the most frequently matched rules placed before less
commonly matched rules, with the last rule in the section
blocking and logging all packets on that interface and
direction.The Outbound section in the following rule set only
contains 'pass' rules which contain selection values that
uniquely identify the service that is authorized for public
Internet access. All the rules have the 'quick', 'on',
'proto', 'port', and 'keep state' option coded. The 'proto
tcp' rules have the 'flag' option included to identify the
session start request as the triggering packet to activate the
stateful facility.The Inbound section has all the blocking of undesirable
packets first, for two different reasons. The first is that
these things being blocked may be part of an otherwise valid
packet which may be allowed in by the later authorized service
rules. The second reason is that by having a rule that
explicitly blocks selected packets that I receive on an
infrequent basis and that I do not want to see in the log, they
will not be caught by the last rule in the section which blocks
and logs all packets which have fallen through the rules. The
last rule in the section which blocks and logs all packets is
how you create the legal evidence needed to prosecute the
people who are attacking your system.Another thing you should take note of, is there is no
response returned for any of the undesirable stuff, their
packets just get dropped and vanish. This way the attacker
has no knowledge if his packets have reached your system. The
less the attackers can learn about your system, the more
time they must invest before actually doing something bad.
The inbound 'nmap OS fingerprint' attempts rule I log
the first occurrence because this is something a attacker
would do.Any time you see log messages on a rule with 'log first'.
You should do an ipfstat -hio command to see
the number of times the rule has been matched so you know if
you are being flooded, i.e. under attack.When you log packets with port numbers you do not
recognize, look it up in /etc/services or
go to
and do a port number lookup to find what the purpose of that
port number is.Check out this link for port numbers used by Trojans .The following rule set is a complete very secure
'inclusive' type of firewall rule set that I have used on my
system. You can not go wrong using this rule set for your own.
Just comment out any pass rules for services that you do not
want to authorize.If you see messages in your log that you want to stop
seeing just add a block rule in the inbound section.You have to change the dc0
interface name in every rule to the interface name of the Nic
card that connects your system to the public Internet. For
user PPP it would be tun0.Add the following statements to
/etc/ipf.rules:#################################################################
# No restrictions on Inside LAN Interface for private network
# Not needed unless you have LAN
#################################################################
#pass out quick on xl0 all
#pass in quick on xl0 all
#################################################################
# No restrictions on Loopback Interface
#################################################################
pass in quick on lo0 all
pass out quick on lo0 all
#################################################################
# Interface facing Public Internet (Outbound Section)
# Interrogate session start requests originating from behind the
# firewall on the private network
# or from this gateway server destine for the public Internet.
#################################################################
# Allow out access to my ISP's Domain name server.
# xxx must be the IP address of your ISP's DNS.
# Dup these lines if your ISP has more than one DNS server
# Get the IP addresses from /etc/resolv.conf file
pass out quick on dc0 proto tcp from any to xxx port = 53 flags S keep state
pass out quick on dc0 proto udp from any to xxx port = 53 keep state
# Allow out access to my ISP's DHCP server for cable or DSL networks.
# This rule is not needed for 'user ppp' type connection to the
# public Internet, so you can delete this whole group.
# Use the following rule and check log for IP address.
# Then put IP address in commented out rule & delete first rule
pass out log quick on dc0 proto udp from any to any port = 67 keep state
#pass out quick on dc0 proto udp from any to z.z.z.z port = 67 keep state
# Allow out non-secure standard www function
pass out quick on dc0 proto tcp from any to any port = 80 flags S keep state
# Allow out secure www function https over TLS SSL
pass out quick on dc0 proto tcp from any to any port = 443 flags S keep state
# Allow out send & get email function
pass out quick on dc0 proto tcp from any to any port = 110 flags S keep state
pass out quick on dc0 proto tcp from any to any port = 25 flags S keep state
# Allow out Time
pass out quick on dc0 proto tcp from any to any port = 37 flags S keep state
# Allow out nntp news
pass out quick on dc0 proto tcp from any to any port = 119 flags S keep state
# Allow out gateway & LAN users non-secure FTP ( both passive & active modes)
# This function uses the IPNAT built in FTP proxy function coded in
# the nat rules file to make this single rule function correctly.
# If you want to use the pkg_add command to install application packages
# on your gateway system you need this rule.
pass out quick on dc0 proto tcp from any to any port = 21 flags S keep state
# Allow out secure FTP, Telnet, and SCP
# This function is using SSH (secure shell)
pass out quick on dc0 proto tcp from any to any port = 22 flags S keep state
# Allow out non-secure Telnet
pass out quick on dc0 proto tcp from any to any port = 23 flags S keep state
# Allow out FBSD CVSUP function
pass out quick on dc0 proto tcp from any to any port = 5999 flags S keep state
# Allow out ping to public Internet
pass out quick on dc0 proto icmp from any to any icmp-type 8 keep state
# Allow out whois for LAN PC to public Internet
pass out quick on dc0 proto tcp from any to any port = 43 flags S keep state
# Block and log only the first occurrence of everything
# else that's trying to get out.
# This rule enforces the block all by default logic.
block out log first quick on dc0 all
#################################################################
# Interface facing Public Internet (Inbound Section)
# Interrogate packets originating from the public Internet
# destine for this gateway server or the private network.
#################################################################
# Block all inbound traffic from non-routable or reserved address spaces
block in quick on dc0 from 192.168.0.0/16 to any #RFC 1918 private IP
block in quick on dc0 from 172.16.0.0/12 to any #RFC 1918 private IP
block in quick on dc0 from 10.0.0.0/8 to any #RFC 1918 private IP
block in quick on dc0 from 127.0.0.0/8 to any #loopback
block in quick on dc0 from 0.0.0.0/8 to any #loopback
block in quick on dc0 from 169.254.0.0/16 to any #DHCP auto-config
block in quick on dc0 from 192.0.2.0/24 to any #reserved for docs
block in quick on dc0 from 204.152.64.0/23 to any #Sun cluster interconnect
block in quick on dc0 from 224.0.0.0/3 to any #Class D & E multicast
##### Block a bunch of different nasty things. ############
# That I do not want to see in the log
# Block frags
block in quick on dc0 all with frags
# Block short tcp packets
block in quick on dc0 proto tcp all with short
# block source routed packets
block in quick on dc0 all with opt lsrr
block in quick on dc0 all with opt ssrr
# Block nmap OS fingerprint attempts
# Log first occurrence of these so I can get their IP address
block in log first quick on dc0 proto tcp from any to any flags FUP
# Block anything with special options
block in quick on dc0 all with ipopts
# Block public pings
block in quick on dc0 proto icmp all icmp-type 8
# Block ident
block in quick on dc0 proto tcp from any to any port = 113
# Block all Netbios service. 137=name, 138=datagram, 139=session
# Netbios is MS/Windows sharing services.
# Block MS/Windows hosts2 name server requests 81
block in log first quick on dc0 proto tcp/udp from any to any port = 137
block in log first quick on dc0 proto tcp/udp from any to any port = 138
block in log first quick on dc0 proto tcp/udp from any to any port = 139
block in log first quick on dc0 proto tcp/udp from any to any port = 81
# Allow traffic in from ISP's DHCP server. This rule must contain
# the IP address of your ISP's DHCP server as it's the only
# authorized source to send this packet type. Only necessary for
# cable or DSL configurations. This rule is not needed for
# 'user ppp' type connection to the public Internet.
# This is the same IP address you captured and
# used in the outbound section.
pass in quick on dc0 proto udp from z.z.z.z to any port = 68 keep state
# Allow in standard www function because I have apache server
pass in quick on dc0 proto tcp from any to any port = 80 flags S keep state
# Allow in non-secure Telnet session from public Internet
# labeled non-secure because ID/PW passed over public Internet as clear text.
# Delete this sample group if you do not have telnet server enabled.
#pass in quick on dc0 proto tcp from any to any port = 23 flags S keep state
# Allow in secure FTP, Telnet, and SCP from public Internet
# This function is using SSH (secure shell)
pass in quick on dc0 proto tcp from any to any port = 22 flags S keep state
# Block and log only first occurrence of all remaining traffic
# coming into the firewall. The logging of only the first
# occurrence stops a .denial of service. attack targeted
# at filling up your log file space.
# This rule enforces the block all by default logic.
block in log first quick on dc0 all
################### End of rules file #####################################NATNATIP masqueradingNATnetwork address translationNATNAT stands for Network Address
Translation. To those familiar with &linux;, this concept is
called IP Masquerading; NAT and IP
Masquerading are the same thing. One of the many things the
IPF NAT function enables is the ability to
have a private Local Area Network (LAN) behind the firewall
sharing a single ISP assigned IP address on the public
Internet.You may ask why would someone want to do this. ISPs
normally assign a dynamic IP address to their non-commercial
users. Dynamic means that the IP address can be different each
time you dial in and log on to your ISP, or for cable and DSL
modem users when you power off and then power on your modems
you can get assigned a different IP address. This IP address
is how you are known to the public Internet.Now lets say you have five PCs at home and each one needs
Internet access. You would have to pay your ISP for an
individual Internet account for each PC and have five phone
lines.With NAT you only need a single account
with your ISP, then cable your other four PCs to a switch and
the switch to the NIC in your &os; system which is going to
service your LAN as a gateway. NAT will
automatically translate the private LAN IP address for each
separate PC on the LAN to the single public IP address as it
exits the firewall bound for the public Internet. It also does
the reverse translation for returning packets.NAT is most often accomplished without
the approval, or knowledge, of your ISP and in most cases is
grounds for your ISP terminating your account if found out.
Commercial users pay a lot more for their Internet connection
and usually get assigned a block of static IP address which
never change. The ISP also expects and consents to their
Commercial customers using NAT for their
internal private LANs.There is a special range of IP addresses reserved for
NATed private LAN IP address. According to
RFC 1918, you can use the following IP ranges for private nets
which will never be routed directly to the public
Internet:Start IP 10.0.0.0-Ending IP 10.255.255.255Start IP 172.16.0.0-Ending IP 172.31.255.255Start IP 192.168.0.0-Ending IP 192.168.255.255IPNATNATand IPFILTERipnatNAT rules are loaded by using the
ipnat command. Typically the
NAT rules are stored in
/etc/ipnat.rules. See &man.ipnat.1; for
details.When changing the NAT rules after
NAT has been started, make your changes to
the file containing the NAT rules, then run ipnat command with
the flags to delete the internal in use
NAT rules and flush the contents of the
translation table of all active entries.To reload the NAT rules issue a command
like this:&prompt.root; ipnat -CF -f /etc/ipnat.rulesTo display some statistics about your
NAT, use this command:&prompt.root; ipnat -sTo list the NAT table's current
mappings, use this command:&prompt.root; ipnat -lTo turn verbose mode on, and display information relating
to rule processing and active rules/table entries:&prompt.root; ipnat -vIPNAT RulesNAT rules are very flexible and can
accomplish many different things to fit the needs of commercial
and home users.The rule syntax presented here has been simplified to what
is most commonly used in a non-commercial environment. For a
complete rule syntax description see the &man.ipnat.5; manual
page.The syntax for a NAT rule looks
something like this:map IFLAN_IP_RANGE -> PUBLIC_ADDRESSThe keyword map starts the rule.Replace IF with the external
interface.The LAN_IP_RANGE is what your
internal clients use for IP Addressing, usually this is
something like 192.168.1.0/24.The PUBLIC_ADDRESS can either
be the external IP address or the special keyword
0/32, which means to use the IP address
assigned to IF.How NAT worksA packet arrives at the firewall from the LAN with a public
destination. It passes through the outbound filter rules,
NAT gets his turn at the packet and applies
its rules top down, first matching rule wins.
NAT tests each of its rules against the
packets interface name and source IP address. When a packets
interface name matches a NAT rule then the
[source IP address, i.e. private LAN IP address] of the packet
is checked to see if it falls within the IP address range
specified to the left of the arrow symbol on the
NAT rule. On a match the packet has its
source IP address rewritten with the public IP address
obtained by the 0/32 keyword.
NAT posts a entry in its internal
NAT table so when the packet returns from
the public Internet it can be mapped back to its original
private IP address and then passed to the filter rules for
processing.Enabling IPNATTo enable IPNAT add these statements to
/etc/rc.conf.To enable your machine to route traffic between
interfaces:gateway_enable="YES"To start IPNAT automatically each
time:ipnat_enable="YES"To specify where to load the IPNAT rules
from:ipnat_rules="/etc/ipnat.rules"NAT for a very large LANFor networks that have large numbers of PC's on the LAN or
networks with more than a single LAN, the process of funneling
all those private IP addresses into a single public IP address
becomes a resource problem that may cause problems with the
same port numbers being used many times across many
NATed LAN PC's, causing collisions. There
are two ways to relieve this resource problem.Assigning Ports to UseA normal NAT rule would look like:map dc0 192.168.1.0/24 -> 0/32In the above rule the packet's source port is unchanged
as the packet passes through IPNAT. By
adding the portmap keyword you can tell
IPNAT to only use source ports in a range.
For example the following rule will tell
IPNAT to modify the source port to be
within that range:map dc0 192.168.1.0/24 -> 0/32 portmap tcp/udp 20000:60000Additionally we can make things even easier by using the
auto keyword to tell
IPNAT to determine by itself which ports
are available to use:map dc0 192.168.1.0/24 -> 0/32 portmap tcp/udp autoUsing a pool of public addressesIn very large LANs there comes a point where there are
just too many LAN addresses to fit into a single public
address. By changing the following rule:map dc0 192.168.1.0/24 -> 204.134.75.1Currently this rule maps all connections through 204.134.75.1. This can be changed
to specify a range:map dc0 192.168.1.0/24 -> 204.134.75.1-10Or a subnet using CIDR notation such as:map dc0 192.168.1.0/24 -> 204.134.75.0/24Port RedirectionA very common practice is to have a web server, email
server, database server and DNS server each segregated to a
different PC on the LAN. In this case the traffic from these
servers still have to be NATed, but there
has to be some way to direct the inbound traffic to the
correct LAN PCs. IPNAT has the redirection
facilities of NAT to solve this problem.
Lets say you have your web server on LAN address 10.0.10.25 and your single public IP
address is 20.20.20.5 you would
code the rule like this:rdr dc0 20.20.20.5/32 port 80 -> 10.0.10.25 port 80or:rdr dc0 0/32 port 80 -> 10.0.10.25 port 80or for a LAN DNS Server on LAN address of 10.0.10.33 that needs to receive
public DNS requests:rdr dc0 20.20.20.5/32 port 53 -> 10.0.10.33 port 53 udpFTP and NATFTP is a dinosaur left over from the time before the
Internet as it is known today, when research universities were
leased lined together and FTP was used to share files among
research Scientists. This was a time when data security was
not a consideration. Over the years the FTP protocol became
buried into the backbone of the emerging Internet and its
username and password being sent in clear text was never
changed to address new security concerns. FTP has two flavors,
it can run in active mode or passive mode. The difference is
in how the data channel is acquired. Passive mode is more
secure as the data channel is acquired be the ordinal ftp
session requester. For a real good explanation of FTP and the
different modes see .IPNAT RulesIPNAT has a special built in FTP proxy
option which can be specified on the NAT
map rule. It can monitor all outbound packet traffic for FTP
active or passive start session requests and dynamically
create temporary filter rules containing only the port number
really in use for the data channel. This eliminates the
security risk FTP normally exposes the firewall to from
having large ranges of high order port numbers open.This rule will handle all the traffic for the internal
LAN:map dc0 10.0.10.0/29 -> 0/32 proxy port 21 ftp/tcpThis rule handles the FTP traffic from the
gateway:map dc0 0.0.0.0/0 -> 0/32 proxy port 21 ftp/tcpThis rule handles all non-FTP traffic from the internal
LAN:map dc0 10.0.10.0/29 -> 0/32The FTP map rule goes before our regular map rule. All
packets are tested against the first rule from the top.
Matches on interface name, then private LAN source IP
address, and then is it a FTP packet. If all that matches
then the special FTP proxy creates temp filter rules to let
the FTP session packets pass in and out, in addition to also
NATing the FTP packets. All LAN packets
that are not FTP do not match the first rule and fall
through to the third rule and are tested, matching on
interface and source IP, then are
NATed.IPNAT FTP Filter RulesOnly one filter rule is needed for FTP if the
NAT FTP proxy is used.Without the FTP Proxy you will need the following three
rules:# Allow out LAN PC client FTP to public Internet
# Active and passive modes
pass out quick on rl0 proto tcp from any to any port = 21 flags S keep state
# Allow out passive mode data channel high order port numbers
pass out quick on rl0 proto tcp from any to any port > 1024 flags S keep state
# Active mode let data channel in from FTP server
pass in quick on rl0 proto tcp from any to any port = 20 flags S keep stateFTP NAT Proxy BugAs of &os; 4.9 which includes IPFILTER version 3.4.31
the FTP proxy works as documented during the FTP session
until the session is told to close. When the close happens
packets returning from the remote FTP server are blocked and
logged coming in on port 21. The NAT
FTP/proxy appears to remove its temp rules prematurely,
before receiving the response from the remote FTP server
acknowledging the close. A problem report was posted to the
IPF mailing list.The solution is to add a filter rule to get rid of these
unwanted log messages or do nothing and ignore FTP inbound
error messages in your log. Most people do not use outbound
FTP too often.block in quick on rl0 proto tcp from any to any port = 21IPFWfirewallIPFWThis section is work in progress. The contents might
not be accurate at all times.The IPFIREWALL (IPFW) is a &os; sponsored firewall software
application authored and maintained by &os; volunteer staff
members. It uses the legacy stateless rules and a legacy rule
coding technique to achieve what is referred to as Simple
Stateful logic.The IPFW sample rule set (found in
/etc/rc.firewall) in the standard &os;
install is rather simple and it is not expected that it used
directly without modifications. The example does not use
stateful filtering, which is beneficial in most setups, so it
will not be used as base for this section.The IPFW stateless rule syntax is empowered with technically
sophisticated selection capabilities which far surpasses the
knowledge level of the customary firewall installer. IPFW is
targeted at the professional user or the advanced technical
computer hobbyist who have advanced packet selection
requirements. A high degree of detailed knowledge into how
different protocols use and create their unique packet header
information is necessary before the power of the IPFW rules can
be unleashed. Providing that level of explanation is out of the
scope of this section of the handbook.IPFW is composed of seven components, the primary component
is the kernel firewall filter rule processor and its integrated
packet accounting facility, the logging facility, the 'divert'
rule which triggers the NAT facility, and the
advanced special purpose facilities, the dummynet traffic shaper
facilities, the 'fwd rule' forward facility, the bridge
facility, and the ipstealth facility.Enabling IPFWIPFWenablingIPFW is included in the basic &os; install as a separate
run time loadable module. The system will dynamically load the
kernel module when the rc.conf statement
firewall_enable="YES" is used. You do not
need to compile IPFW into the &os; kernel unless you want
NAT function enabled.After rebooting your system with
firewall_enable="YES" in
rc.conf the following white highlighted
message is displayed on the screen as part of the boot
process:ipfw2 initialized, divert disabled, rule-based forwarding disabled, default to deny, logging disabledThe loadable module does have logging ability
compiled in. To enable logging and set the verbose logging
limit, there is a knob you can set in
/etc/sysctl.conf by adding these
statements, logging will be enabled on future reboots:net.inet.ip.fw.verbose=1
net.inet.ip.fw.verbose_limit=5Kernel Optionskernel optionsIPFIREWALLkernel optionsIPFIREWALL_VERBOSEkernel optionsIPFIREWALL_VERBOSE_LIMITIPFWkernel optionsIt is not a mandatory requirement that you enable IPFW by
compiling the following options into the &os; kernel unless
you need NAT function. It is presented here
as background information.options IPFIREWALLThis option enables IPFW as part of the kerneloptions IPFIREWALL_VERBOSEEnables logging of packets that pass through IPFW and have
the 'log' keyword specified in the rule set.options IPFIREWALL_VERBOSE_LIMIT=5Limits the number of packets logged through &man.syslogd.8;
on a per entry basis. You may wish to use this option in
hostile environments which you want to log firewall activity.
This will close a possible denial of service attack via syslog
flooding.kernel optionsIPFIREWALL_DEFAULT_TO_ACCEPToptions IPFIREWALL_DEFAULT_TO_ACCEPTThis option will allow everything to pass through the
firewall by default, which is a good idea when you are first
setting up your firewall.options IPV6FIREWALL
options IPV6FIREWALL_VERBOSE
options IPV6FIREWALL_VERBOSE_LIMIT
options IPV6FIREWALL_DEFAULT_TO_ACCEPTThese options are exactly the same as the IPv4 options but
they are for IPv6. If you do not use IPv6 you might want to
use IPV6FIREWALL without any rules to block all IPv6kernel optionsIPDIVERToptions IPDIVERTThis enables the use of NAT
functionality.If you do not include IPFIREWALL_DEFAULT_TO_ACCEPT or set
your rules to allow incoming packets you will block all
packets going to and from this machine./etc/rc.conf OptionsIf you do not have IPFW compiled into your kernel you will
need to load it with the following statement in your
/etc/rc.conf:firewall_enable="YES"Set the script to run to activate your rules:firewall_script="/etc/ipfw.rules"Enable logging:firewall_logging="YES"The only thing that the
firewall_logging variable will do is
setting the net.inet.ip.fw.verbose sysctl
variable to the value of 1 (see ). There is no
rc.conf variable to set log limitations,
but it can be set via sysctl variable, manually or from the
/etc/sysctl.conf file:net.inet.ip.fw.verbose_limit=5If your machine is acting as a gateway, i.e. providing
Network Address Translation (NAT) via &man.natd.8;, please
refer to for information
regarding the required /etc/rc.conf
options.The IPFW CommandipfwThe ipfw command is the normal vehicle for making manual
single rule additions or deletions to the firewall active
internal rules while it is running. The problem with using
this method is once your system is shutdown or halted all the
rules you added or changed or deleted are lost. Writing all
your rules in a file and using that file to load the rules at
boot time, or to replace in mass the currently running firewall
rules with changes you made to the files content is the
recommended method used here.The ipfw command is still a very useful to display the
running firewall rules to the console screen. The IPFW
accounting facility dynamically creates a counter for each
rule that counts each packet that matches the rule. During the
process of testing a rule, listing the rule with its counter
is the one of the ways of determining if the rule is
functioning.To list all the rules in sequence:&prompt.root; ipfw listTo list all the rules with a time stamp of when the last
time the rule was matched:&prompt.root; ipfw -t listTo list the accounting information, packet count for
matched rules along with the rules themselves. The first
column is the rule number, followed by the number of outgoing
matched packets, followed by the number of incoming matched
packets, and then the rule itself.&prompt.root; ipfw -a listList the dynamic rules in addition to the static
rules:&prompt.root; ipfw -d listAlso show the expired dynamic rules:&prompt.root; ipfw -d -e listZero the counters:&prompt.root; ipfw zeroZero the counters for just rule
NUM:&prompt.root; ipfw zero NUMIPFW Rule SetsA rule set is a group of ipfw rules coded to allow or deny
packets based on the values contained in the packet. The
bi-directional exchange of packets between hosts comprises a
session conversation. The firewall rule set processes the
packet twice: once on its arrival from the public Internet host
and again as it leaves for its return trip back to the public
Internet host. Each tcp/ip service (i.e. telnet, www, mail,
etc.) is predefined by its protocol, and port number. This is
the basic selection criteria used to create rules which will
allow or deny services.IPFWrule processing orderWhen a packet enters the firewall it is compared against
the first rule in the rule set and progress one rule at a time
moving from top to bottom of the set in ascending rule number
sequence order. When the packet matches a rule selection
parameters, the rules action field value is executed and the
search of the rule set terminates for that packet. This is
- referred to as the first match wins search
+ referred to as 「the first match wins」 search
method. If the packet does not match any of the rules, it gets
caught by the mandatory ipfw default rule, number 65535 which
denies all packets and discards them without any reply back to
the originating destination.The search continues after count,
skipto and tee
rules.The instructions contained here are based on using rules
that contain the stateful 'keep state', 'limit', 'in'/'out',
and via options. This is the basic framework for coding an
inclusive type firewall rule set.An inclusive firewall only allows services matching the
rules through. This way you can control what services can
originate behind the firewall destine for the public Internet
and also control the services which can originate from the
public Internet accessing your private network. Everything
else is denied by default design. Inclusive firewalls are
much, much more secure than exclusive firewall rule sets and
is the only rule set type covered here in.When working with the firewall rules be careful, you can
end up locking your self out.Rule SyntaxIPFWrule syntaxThe rule syntax presented here has been simplified to
what is necessary to create a standard inclusive type
firewall rule set. For a complete rule syntax description
see the &man.ipfw.8; manual page.Rules contain keywords: these keywords have to be coded
in a specific order from left to right on the line. Keywords
are identified in bold type. Some keywords have sub-options
which may be keywords them selves and also include more
sub-options.# is used to mark the start of a
comment and may appear at the end of a rule line or on its
own lines. Blank lines are ignored.CMD RULE_NUMBER ACTION LOGGING SELECTION
STATEFULCMDEach new rule has to be prefixed with
add to add the
rule to the internal table.RULE_NUMBEREach rule has to have a rule number to go with
it.ACTIONA rule can be associated with one of the following
actions, which will be executed when the packet matches
the selection criterion of the rule.allow | accept | pass |
permitThese all mean the same thing which is to allow packets
that match the rule to exit the firewall rule processing.
The search terminates at this rule.check-stateChecks the packet against the dynamic rules table. If
a match is found, execute the action associated with the
rule which generated this dynamic rule, otherwise move to
the next rule. The check-state rule does not have
selection criterion. If no check-state rule is present in
the rule set, the dynamic rules table is checked at the
first keep-state or limit rule.deny | dropBoth words mean the same thing which is to discard
packets that match this rule. The search
terminates.Logginglog or
logamountWhen a packet matches a rule with the log keyword, a
message will be logged to syslogd with a facility name of
SECURITY. The logging only occurs if the number of
packets logged so far for that particular rule does not
exceed the logamount parameter. If no logamount is
specified, the limit is taken from the sysctl variable
net.inet.ip.fw.verbose_limit. In both cases, a value of
zero removes the logging limit. Once the limit is
reached, logging can be re-enabled by clearing the
logging counter or the packet counter for that rule, see
the ipfw reset log command.Logging is done after
all other packet matching conditions have been
successfully verified, and before performing the final
action (accept, deny) on the packet. It is up to you to
decide which rules you want to enable logging on.SelectionThe keywords described in this section are used to
describe attributes of the packet to be interrogated when
determining whether rules match the packet or not.
The following general-purpose attributes are provided for
matching, and must be used in this order:udp | tcp | icmpor any protocol names found in
/etc/protocols are recognized and may
be used. The value specified is protocol to be matched
against. This is a mandatory requirement.from src to dstThe from and to keywords are used to match against IP
addresses. Rules must specify BOTH source and destination
parameters. any is a special keyword
that matches any IP address. me is a
special keyword that matches any IP address configured on
an interface in your &os; system to represent the PC the
firewall is running on (i.e. this box) as in 'from me to
any' or 'from any to me' or 'from 0.0.0.0/0 to any' or
'from any to 0.0.0.0/0' or 'from 0.0.0.0 to any' or 'from
any to 0.0.0.0' or 'from me to 0.0.0.0'. IP addresses are
specified as a dotted IP address numeric form/mask-length,
or as single dotted IP address numeric form. This is a
mandatory requirement. See this link for help on writing
mask-lengths. port numberFor protocols which support port numbers (such as
TCP and UDP). It is mandatory that you
code the port number of the service you want to match
on. Service names (from
/etc/services) may be used instead of
numeric port values.in | outMatches incoming or outgoing packets, respectively.
The in and out are keywords and it is mandatory that you
code one or the other as part of your rule matching
criterion.via IFMatches packets going through the interface specified
by exact name. The via keyword causes
the interface to always be checked as part of the match
process.setupThis is a mandatory keyword that identifies the session
start request for TCP packets.keep-stateThis is a mandatory> keyword. Upon a match, the
firewall will create a dynamic rule, whose default behavior
is to match bidirectional traffic between source and
destination IP/port using the same protocol.limit {src-addr | src-port | dst-addr |
dst-port}The firewall will only allow
N connections with the same set
of parameters as specified in the rule. One or more of
source and destination addresses and ports can be
specified. The 'limit' and 'keep-state' can not be used on
same rule. Limit provides the same stateful function as
'keep-state' plus its own functions.Stateful Rule OptionIPFWstateful filteringStateful filtering treats traffic as a bi-directional
exchange of packets comprising a session conversation. It
has the interrogation abilities to determine if the session
conversation between the originating sender and the
destination are following the valid procedure of
bi-directional packet exchange. Any packets that do not
properly fit the session conversation template are
automatically rejected as impostors.'check-state' is used to identify where in the IPFW rules
set the packet is to be tested against the dynamic rules
facility. On a match the packet exits the firewall to
continue on its way and a new rule is dynamic created for
the next anticipated packet being exchanged during this
bi-directional session conversation. On a no match the
packet advances to the next rule in the rule set for
testing.The dynamic rules facility is vulnerable to resource
depletion from a SYN-flood attack which would open a huge
number of dynamic rules. To counter this attack, &os;
version 4.5 added another new option named limit. This
option is used to limit the number of simultaneous session
conversations by interrogating the rules source or
destinations fields as directed by the limit option and
using the packet's IP address found there, in a search of
the open dynamic rules counting the number of times this
rule and IP address combination occurred, if this count is
greater that the value specified on the limit option, the
packet is discarded.Logging Firewall MessagesIPFWloggingThe benefits of logging are obvious: it provides the
ability to review after the fact the rules you activated
logging on which provides information like, what packets had
been dropped, what addresses they came from, where they were
going, giving you a significant edge in tracking down
attackers.Even with the logging facility enabled, IPFW will not
generate any rule logging on it's own. The firewall
administrator decides what rules in the rule set he wants
to log and adds the log verb to those rules. Normally only
deny rules are logged, like the deny rule for incoming
ICMP pings. It is very customary to
duplicate the ipfw default deny everything rule with the
log verb included as your last rule in the rule set. This
way you get to see all the packets that did not match any
of the rules in the rule set.Logging is a two edged sword, if you are not careful, you
can lose yourself in the over abundance of log data and fill
your disk up with growing log files. DoS attacks that fill
up disk drives is one of the oldest attacks around. These
log message are not only written to syslogd, but also are
displayed on the root console screen and soon become very
annoying.The IPFIREWALL_VERBOSE_LIMIT=5
kernel option limits the number of consecutive messages
sent to the system logger syslogd, concerning the packet
matching of a given rule. When this option is enabled in
the kernel, the number of consecutive messages concerning
a particular rule is capped at the number specified. There
is nothing to be gained from 200 log messages saying the
same identical thing. For instance, five consecutive
messages concerning a particular rule would be logged to
syslogd, the remainder identical consecutive messages would
be counted and posted to the syslogd with a phrase like
this:last message repeated 45 timesAll logged packets messages are written by default to
/var/log/security file, which is defined
in the /etc/syslog.conf file.Building a Rule ScriptMost experienced IPFW users create a file containing the
rules and code them in a manner compatible with running them
as a script. The major benefit of doing this is the firewall
rules can be refreshed in mass without the need of rebooting
the system to activate the new rules. This method is very
convenient in testing new rules as the procedure can be
executed as many times as needed. Being a script, you can
use symbolic substitution to code frequent used values and
substitution them in multiple rules. You will see this in
the following example.The script syntax used here is compatible with the 'sh',
'csh', 'tcsh' shells. Symbolic substitution fields are
prefixed with a dollar sign $. Symbolic fields do not
have the $ prefix. The value to populate the Symbolic
field must be enclosed to "double quotes".Start your rules file like this:############### start of example ipfw rules script #############
#
ipfw -q -f flush # Delete all rules
# Set defaults
oif="tun0" # out interface
odns="192.0.2.11" # ISP's DNS server IP address
cmd="ipfw -q add " # build rule prefix
ks="keep-state" # just too lazy to key this each time
$cmd 00500 check-state
$cmd 00502 deny all from any to any frag
$cmd 00501 deny tcp from any to any established
$cmd 00600 allow tcp from any to any 80 out via $oif setup $ks
$cmd 00610 allow tcp from any to $odns 53 out via $oif setup $ks
$cmd 00611 allow udp from any to $odns 53 out via $oif $ks
################### End of example ipfw rules script ############That is all there is to it. The rules are not important
in this example, how the Symbolic substitution field are
populated and used are.If the above example was in
/etc/ipfw.rules file, you could reload
these rules by entering on the command line.&prompt.root; sh /etc/ipfw.rulesThe /etc/ipfw.rules file could be
located anywhere you want and the file could be named any
thing you would like.The same thing could also be accomplished by running
these commands by hand:&prompt.root; ipfw -q -f flush
&prompt.root; ipfw -q add check-state
&prompt.root; ipfw -q add deny all from any to any frag
&prompt.root; ipfw -q add deny tcp from any to any established
&prompt.root; ipfw -q add allow tcp from any to any 80 out via tun0 setup keep-state
&prompt.root; ipfw -q add allow tcp from any to 192.0.2.11 53 out via tun0 setup keep-state
&prompt.root; ipfw -q add 00611 allow udp from any to 192.0.2.11 53 out via tun0 keep-stateStateful RulesetThe following non-NATed rule set is an
example of how to code a very secure 'inclusive' type of
firewall. An inclusive firewall only allows services
matching pass rules through and blocks all other by default.
All firewalls have at the minimum two interfaces which have
to have rules to allow the firewall to function.All &unix; flavored operating systems, &os; included, are
designed to use interface lo0 and IP
address 127.0.0.1 for internal
communication with in the operating system. The firewall
rules must contain rules to allow free unmolested movement of
these special internally used packets.The interface which faces the public Internet, is the one
which you code your rules to authorize and control access out
to the public Internet and access requests arriving from the
public Internet. This can be your ppp
tun0 interface or your NIC that is
connected to your DSL or cable modem.In cases where one or more than one NIC are connected to
a private LANs behind the firewall, those interfaces must
have rules coded to allow free unmolested movement of
packets originating from those LAN interfaces.The rules should be first organized into three major
sections, all the free unmolested interfaces, public
interface outbound, and the public interface inbound.The order of the rules in each of the public interface
sections should be in order of the most used rules being
placed before less often used rules with the last rule in
the section being a block log all packets on that interface
and direction.The Outbound section in the following rule set only
contains 'allow' rules which contain selection values that
uniquely identify the service that is authorized for public
Internet access. All the rules have the, proto, port,
in/out, via and keep state option coded. The 'proto tcp'
rules have the 'setup' option included to identify the start
session request as the trigger packet to be posted to the
keep state stateful table.The Inbound section has all the blocking of undesirable
packets first for two different reasons. First is these
things being blocked may be part of an otherwise valid packet
which may be allowed in by the later authorized service
rules. Second reason is that by having a rule that
explicitly blocks selected packets that I receive on an
infrequent bases and do not want to see in the log, this
keeps them from being caught by the last rule in the section
which blocks and logs all packets which have fallen through
the rules. The last rule in the section which blocks and
logs all packets is how you create the legal evidence needed
to prosecute the people who are attacking your system.Another thing you should take note of, is there is no
response returned for any of the undesirable stuff, their
packets just get dropped and vanish. This way the attackers
has no knowledge if his packets have reached your system.
The less the attackers can learn about your system the more
secure it is. When you log packets with port numbers you do
not recognize, look the numbers up in
/etc/services/ or go to
and do a port number lookup to find what the purpose of that
port number is. Check out this link for port numbers used by
Trojans: .An Example Inclusive RulesetThe following non-NATed rule set is a
complete inclusive type ruleset. You can not go wrong using
this rule set for you own. Just comment out any pass rules
for services you do not want. If you see messages in your
log that you want to stop seeing just add a deny rule in the
inbound section. You have to change the 'dc0' interface name
in every rule to the interface name of the NIC that connects
your system to the public Internet. For user ppp it would be
'tun0'.You will see a pattern in the usage of these
rules.All statements that are a request to start a session
to the public Internet use keep-state.All the authorized services that originate from the
public Internet have the limit option to stop
flooding.All rules use in or out to clarify direction.All rules use via interface name to specify the
interface the packet is traveling over.The following rules go into
/etc/ipfw.rules.################ Start of IPFW rules file ###############################
# Flush out the list before we begin.
ipfw -q -f flush
# Set rules command prefix
cmd="ipfw -q add"
pif="dc0" # public interface name of NIC
# facing the public Internet
#################################################################
# No restrictions on Inside LAN Interface for private network
# Not needed unless you have LAN.
# Change xl0 to your LAN NIC interface name
#################################################################
#$cmd 00005 allow all from any to any via xl0
#################################################################
# No restrictions on Loopback Interface
#################################################################
$cmd 00010 allow all from any to any via lo0
#################################################################
# Allow the packet through if it has previous been added to the
# the "dynamic" rules table by a allow keep-state statement.
#################################################################
$cmd 00015 check-state
#################################################################
# Interface facing Public Internet (Outbound Section)
# Interrogate session start requests originating from behind the
# firewall on the private network or from this gateway server
# destine for the public Internet.
#################################################################
# Allow out access to my ISP's Domain name server.
# x.x.x.x must be the IP address of your ISP.s DNS
# Dup these lines if your ISP has more than one DNS server
# Get the IP addresses from /etc/resolv.conf file
$cmd 00110 allow tcp from any to x.x.x.x 53 out via $pif setup keep-state
$cmd 00111 allow udp from any to x.x.x.x 53 out via $pif keep-state
# Allow out access to my ISP's DHCP server for cable/DSL configurations.
# This rule is not needed for .user ppp. connection to the public Internet.
# so you can delete this whole group.
# Use the following rule and check log for IP address.
# Then put IP address in commented out rule & delete first rule
$cmd 00120 allow log udp from any to any 67 out via $pif keep-state
#$cmd 00120 allow udp from any to x.x.x.x 67 out via $pif keep-state
# Allow out non-secure standard www function
$cmd 00200 allow tcp from any to any 80 out via $pif setup keep-state
# Allow out secure www function https over TLS SSL
$cmd 00220 allow tcp from any to any 443 out via $pif setup keep-state
# Allow out send & get email function
$cmd 00230 allow tcp from any to any 25 out via $pif setup keep-state
$cmd 00231 allow tcp from any to any 110 out via $pif setup keep-state
# Allow out FBSD (make install & CVSUP) functions
# Basically give user root "GOD" privileges.
$cmd 00240 allow tcp from me to any out via $pif setup keep-state uid root
# Allow out ping
$cmd 00250 allow icmp from any to any out via $pif keep-state
# Allow out Time
$cmd 00260 allow tcp from any to any 37 out via $pif setup keep-state
# Allow out nntp news (i.e. news groups)
$cmd 00270 allow tcp from any to any 119 out via $pif setup keep-state
# Allow out secure FTP, Telnet, and SCP
# This function is using SSH (secure shell)
$cmd 00280 allow tcp from any to any 22 out via $pif setup keep-state
# Allow out whois
$cmd 00290 allow tcp from any to any 43 out via $pif setup keep-state
# deny and log everything else that.s trying to get out.
# This rule enforces the block all by default logic.
$cmd 00299 deny log all from any to any out via $pif
#################################################################
# Interface facing Public Internet (Inbound Section)
# Interrogate packets originating from the public Internet
# destine for this gateway server or the private network.
#################################################################
# Deny all inbound traffic from non-routable reserved address spaces
$cmd 00300 deny all from 192.168.0.0/16 to any in via $pif #RFC 1918 private IP
$cmd 00301 deny all from 172.16.0.0/12 to any in via $pif #RFC 1918 private IP
$cmd 00302 deny all from 10.0.0.0/8 to any in via $pif #RFC 1918 private IP
$cmd 00303 deny all from 127.0.0.0/8 to any in via $pif #loopback
$cmd 00304 deny all from 0.0.0.0/8 to any in via $pif #loopback
$cmd 00305 deny all from 169.254.0.0/16 to any in via $pif #DHCP auto-config
$cmd 00306 deny all from 192.0.2.0/24 to any in via $pif #reserved for docs
$cmd 00307 deny all from 204.152.64.0/23 to any in via $pif #Sun cluster interconnect
$cmd 00308 deny all from 224.0.0.0/3 to any in via $pif #Class D & E multicast
# Deny public pings
$cmd 00310 deny icmp from any to any in via $pif
# Deny ident
$cmd 00315 deny tcp from any to any 113 in via $pif
# Deny all Netbios service. 137=name, 138=datagram, 139=session
# Netbios is MS/Windows sharing services.
# Block MS/Windows hosts2 name server requests 81
$cmd 00320 deny tcp from any to any 137 in via $pif
$cmd 00321 deny tcp from any to any 138 in via $pif
$cmd 00322 deny tcp from any to any 139 in via $pif
$cmd 00323 deny tcp from any to any 81 in via $pif
# Deny any late arriving packets
$cmd 00330 deny all from any to any frag in via $pif
# Deny ACK packets that did not match the dynamic rule table
$cmd 00332 deny tcp from any to any established in via $pif
# Allow traffic in from ISP's DHCP server. This rule must contain
# the IP address of your ISP.s DHCP server as it.s the only
# authorized source to send this packet type.
# Only necessary for cable or DSL configurations.
# This rule is not needed for .user ppp. type connection to
# the public Internet. This is the same IP address you captured
# and used in the outbound section.
#$cmd 00360 allow udp from any to x.x.x.x 67 in via $pif keep-state
# Allow in standard www function because I have apache server
$cmd 00400 allow tcp from any to me 80 in via $pif setup limit src-addr 2
# Allow in secure FTP, Telnet, and SCP from public Internet
$cmd 00410 allow tcp from any to me 22 in via $pif setup limit src-addr 2
# Allow in non-secure Telnet session from public Internet
# labeled non-secure because ID & PW are passed over public
# Internet as clear text.
# Delete this sample group if you do not have telnet server enabled.
$cmd 00420 allow tcp from any to me 23 in via $pif setup limit src-addr 2
# Reject & Log all incoming connections from the outside
$cmd 00499 deny log all from any to any in via $pif
# Everything else is denied by default
# deny and log all packets that fell through to see what they are
$cmd 00999 deny log all from any to any
################ End of IPFW rules file ###############################An Example NAT and Stateful
RulesetNATand IPFWThere are some additional configuration statements that
need to be enabled to activate the NAT
function of IPFW. The kernel source needs 'option divert'
statement added to the other IPFIREWALL statements compiled
into a custom kernel.In addition to the normal IPFW options in
/etc/rc.conf, the following are
needed.natd_enable="YES" # Enable NATD function
natd_interface="rl0" # interface name of public Internet NIC
natd_flags="-dynamic -m" # -m = preserve port numbers if possibleUtilizing stateful rules with divert natd rule (Network
Address Translation) greatly complicates the rule set coding
logic. The positioning of the check-state, and 'divert natd'
rules in the rule set becomes very critical. This is no
longer a simple fall-through logic flow. A new action type
is used, called 'skipto'. To use the skipto command it is
mandatory that you number each rule so you know exactly
where the skipto rule number is you are really jumping
to.The following is an uncommented example of one coding
method, selected here to explain the sequence of the packet
flow through the rule sets.The processing flow starts with the first rule from the
top of the rule file and progress one rule at a time deeper
into the file until the end is reach or the packet being
tested to the selection criteria matches and the packet is
released out of the firewall. It is important to take notice
of the location of rule numbers 100 101, 450, 500, and 510.
These rules control the translation of the outbound and
inbound packets so their entries in the keep-state dynamic
table always register the private LAN IP address. Next
notice that all the allow and deny rules specified the
direction the packet is going (IE outbound or inbound) and
the interface. Also notice that all the start outbound
session requests all skipto rule 500 for the network address
translation.Lets say a LAN user uses their web browser to get a web
page. Web pages use port 80 to communicate over. So the
packet enters the firewall, It does not match 100 because it
is headed out not in. It passes rule 101 because this is the
first packet so it has not been posted to the keep-state
dynamic table yet. The packet finally comes to rule 125 a
matches. It is outbound through the NIC facing the public
Internet. The packet still has it's source IP address as a
private LAN IP address. On the match to this rule, two
actions take place. The keep-state option will post this
rule into the keep-state dynamic rules table and the
specified action is executed. The action is part of the info
posted to the dynamic table. In this case it is "skipto rule
500". Rule 500 NATs the packet IP address
and out it goes. Remember this, this is very important.
This packet makes its way to the destination and returns and
enters the top of the rule set. This time it does match rule
100 and has it destination IP address mapped back to its
corresponding LAN IP address. It then is processed by the
check-state rule, it's found in the table as an existing
session conversation and released to the LAN. It goes to the
LAN PC that sent it and a new packet is sent requesting
another segment of the data from the remote server. This
time it gets checked by the check-state rule and its outbound
entry is found, the associated action, 'skipto 500', is
executed. The packet jumps to rule 500 gets
NATed and released on it's way out.On the inbound side, everything coming in that is part
of an existing session conversation is being automatically
handled by the check-state rule and the properly placed
divert natd rules. All we have to address is denying all the
bad packets and only allowing in the authorized services.
Lets say there is a apache server running on the firewall box
and we want people on the public Internet to be able to
access the local web site. The new inbound start request
packet matches rule 100 and its IP address is mapped to LAN
IP for the firewall box. The packet is them matched against
all the nasty things we want to check for and finally matches
against rule 425. On a match two things occur. The packet
rule is posted to the keep-state dynamic table but this time
any new session requests originating from that source IP
address is limited to 2. This defends against DoS attacks of
service running on the specified port number. The action is
allow so the packet is released to the LAN. On return the
check-state rule recognizes the packet as belonging to an
existing session conversation sends it to rule 500 for
NATing and released to outbound
interface.Example Ruleset #1:#!/bin/sh
cmd="ipfw -q add"
skip="skipto 500"
pif=rl0
ks="keep-state"
good_tcpo="22,25,37,43,53,80,443,110,119"
ipfw -q -f flush
$cmd 002 allow all from any to any via xl0 # exclude LAN traffic
$cmd 003 allow all from any to any via lo0 # exclude loopback traffic
$cmd 100 divert natd ip from any to any in via $pif
$cmd 101 check-state
# Authorized outbound packets
$cmd 120 $skip udp from any to xx.168.240.2 53 out via $pif $ks
$cmd 121 $skip udp from any to xx.168.240.5 53 out via $pif $ks
$cmd 125 $skip tcp from any to any $good_tcpo out via $pif setup $ks
$cmd 130 $skip icmp from any to any out via $pif $ks
$cmd 135 $skip udp from any to any 123 out via $pif $ks
# Deny all inbound traffic from non-routable reserved address spaces
$cmd 300 deny all from 192.168.0.0/16 to any in via $pif #RFC 1918 private IP
$cmd 301 deny all from 172.16.0.0/12 to any in via $pif #RFC 1918 private IP
$cmd 302 deny all from 10.0.0.0/8 to any in via $pif #RFC 1918 private IP
$cmd 303 deny all from 127.0.0.0/8 to any in via $pif #loopback
$cmd 304 deny all from 0.0.0.0/8 to any in via $pif #loopback
$cmd 305 deny all from 169.254.0.0/16 to any in via $pif #DHCP auto-config
$cmd 306 deny all from 192.0.2.0/24 to any in via $pif #reserved for docs
$cmd 307 deny all from 204.152.64.0/23 to any in via $pif #Sun cluster
$cmd 308 deny all from 224.0.0.0/3 to any in via $pif #Class D & E multicast
# Authorized inbound packets
$cmd 400 allow udp from xx.70.207.54 to any 68 in $ks
$cmd 420 allow tcp from any to me 80 in via $pif setup limit src-addr 1
$cmd 450 deny log ip from any to any
# This is skipto location for outbound stateful rules
$cmd 500 divert natd ip from any to any out via $pif
$cmd 510 allow ip from any to any
######################## end of rules ##################The following is pretty much the same as above, but uses
a self documenting coding style full of description comments
to help the inexperienced IPFW rule writer to better
understand what the rules are doing.Example Ruleset #2:#!/bin/sh
################ Start of IPFW rules file ###############################
# Flush out the list before we begin.
ipfw -q -f flush
# Set rules command prefix
cmd="ipfw -q add"
skip="skipto 800"
pif="rl0" # public interface name of NIC
# facing the public Internet
#################################################################
# No restrictions on Inside LAN Interface for private network
# Change xl0 to your LAN NIC interface name
#################################################################
$cmd 005 allow all from any to any via xl0
#################################################################
# No restrictions on Loopback Interface
#################################################################
$cmd 010 allow all from any to any via lo0
#################################################################
# check if packet is inbound and nat address if it is
#################################################################
$cmd 014 divert natd ip from any to any in via $pif
#################################################################
# Allow the packet through if it has previous been added to the
# the "dynamic" rules table by a allow keep-state statement.
#################################################################
$cmd 015 check-state
#################################################################
# Interface facing Public Internet (Outbound Section)
# Interrogate session start requests originating from behind the
# firewall on the private network or from this gateway server
# destine for the public Internet.
#################################################################
# Allow out access to my ISP's Domain name server.
# x.x.x.x must be the IP address of your ISP's DNS
# Dup these lines if your ISP has more than one DNS server
# Get the IP addresses from /etc/resolv.conf file
$cmd 020 $skip tcp from any to x.x.x.x 53 out via $pif setup keep-state
# Allow out access to my ISP's DHCP server for cable/DSL configurations.
$cmd 030 $skip udp from any to x.x.x.x 67 out via $pif keep-state
# Allow out non-secure standard www function
$cmd 040 $skip tcp from any to any 80 out via $pif setup keep-state
# Allow out secure www function https over TLS SSL
$cmd 050 $skip tcp from any to any 443 out via $pif setup keep-state
# Allow out send & get email function
$cmd 060 $skip tcp from any to any 25 out via $pif setup keep-state
$cmd 061 $skip tcp from any to any 110 out via $pif setup keep-state
# Allow out FreeBSD (make install & CVSUP) functions
# Basically give user root "GOD" privileges.
$cmd 070 $skip tcp from me to any out via $pif setup keep-state uid root
# Allow out ping
$cmd 080 $skip icmp from any to any out via $pif keep-state
# Allow out Time
$cmd 090 $skip tcp from any to any 37 out via $pif setup keep-state
# Allow out nntp news (i.e. news groups)
$cmd 100 $skip tcp from any to any 119 out via $pif setup keep-state
# Allow out secure FTP, Telnet, and SCP
# This function is using SSH (secure shell)
$cmd 110 $skip tcp from any to any 22 out via $pif setup keep-state
# Allow out whois
$cmd 120 $skip tcp from any to any 43 out via $pif setup keep-state
# Allow ntp time server
$cmd 130 $skip udp from any to any 123 out via $pif keep-state
#################################################################
# Interface facing Public Internet (Inbound Section)
# Interrogate packets originating from the public Internet
# destine for this gateway server or the private network.
#################################################################
# Deny all inbound traffic from non-routable reserved address spaces
$cmd 300 deny all from 192.168.0.0/16 to any in via $pif #RFC 1918 private IP
$cmd 301 deny all from 172.16.0.0/12 to any in via $pif #RFC 1918 private IP
$cmd 302 deny all from 10.0.0.0/8 to any in via $pif #RFC 1918 private IP
$cmd 303 deny all from 127.0.0.0/8 to any in via $pif #loopback
$cmd 304 deny all from 0.0.0.0/8 to any in via $pif #loopback
$cmd 305 deny all from 169.254.0.0/16 to any in via $pif #DHCP auto-config
$cmd 306 deny all from 192.0.2.0/24 to any in via $pif #reserved for docs
$cmd 307 deny all from 204.152.64.0/23 to any in via $pif #Sun cluster
$cmd 308 deny all from 224.0.0.0/3 to any in via $pif #Class D & E multicast
-# Deny ident
+# 拒絕 ident
$cmd 315 deny tcp from any to any 113 in via $pif
-# Deny all Netbios service. 137=name, 138=datagram, 139=session
-# Netbios is MS/Windows sharing services.
-# Block MS/Windows hosts2 name server requests 81
+# 拒絕所有的 Netbios 服務. 137=name, 138=datagram, 139=session
+# Netbios 是 MS/Windows 網路分享服務
+# 阻擋所有的 MS/Windows 主機名稱伺服器hosts2 name server requests 81
$cmd 320 deny tcp from any to any 137 in via $pif
$cmd 321 deny tcp from any to any 138 in via $pif
$cmd 322 deny tcp from any to any 139 in via $pif
$cmd 323 deny tcp from any to any 81 in via $pif
-# Deny any late arriving packets
+# 拒絕任何的延遲到達之封包
$cmd 330 deny all from any to any frag in via $pif
# Deny ACK packets that did not match the dynamic rule table
$cmd 332 deny tcp from any to any established in via $pif
# Allow traffic in from ISP's DHCP server. This rule must contain
# the IP address of your ISP's DHCP server as it's the only
# authorized source to send this packet type.
# Only necessary for cable or DSL configurations.
# This rule is not needed for 'user ppp' type connection to
# the public Internet. This is the same IP address you captured
# and used in the outbound section.
$cmd 360 allow udp from x.x.x.x to any 68 in via $pif keep-state
# Allow in standard www function because I have Apache server
$cmd 370 allow tcp from any to me 80 in via $pif setup limit src-addr 2
# Allow in secure FTP, Telnet, and SCP from public Internet
$cmd 380 allow tcp from any to me 22 in via $pif setup limit src-addr 2
# Allow in non-secure Telnet session from public Internet
# labeled non-secure because ID & PW are passed over public
# Internet as clear text.
# Delete this sample group if you do not have telnet server enabled.
$cmd 390 allow tcp from any to me 23 in via $pif setup limit src-addr 2
# Reject & Log all unauthorized incoming connections from the public Internet
$cmd 400 deny log all from any to any in via $pif
# Reject & Log all unauthorized out going connections to the public Internet
$cmd 450 deny log all from any to any out via $pif
# This is skipto location for outbound stateful rules
$cmd 800 divert natd ip from any to any out via $pif
$cmd 801 allow ip from any to any
# Everything else is denied by default
# deny and log all packets that fell through to see what they are
$cmd 999 deny log all from any to any
################ End of IPFW rules file ###############################
diff --git a/zh_TW.Big5/books/handbook/install/chapter.sgml b/zh_TW.Big5/books/handbook/install/chapter.sgml
index d69e529b00..874ef49286 100644
--- a/zh_TW.Big5/books/handbook/install/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/install/chapter.sgml
@@ -1,5523 +1,5488 @@
JimMockRestructured, reorganized, and parts
rewritten by RandyPrattThe sysinstall walkthrough, screenshots, and general
copy by 安裝 FreeBSD概述installationFreeBSD 提供一個簡單好用的文字介面安裝程式,叫做 sysinstall。
這是 FreeBSD 預設使用的安裝程式。協力廠商如果想,也可以改用自己的安裝程式。
本章將說明如何使用 sysinstall 來安裝 FreeBSD。讀完這章,您將了解︰如何製作 FreeBSD 安裝片FreeBSD 對硬碟的使用及配置。如何啟動 sysinstall 程式。在執行 sysinstall 時會問的相關問題有哪些、
這些問題的意思為何、以及該如何回答。在開始閱讀這章之前,您需要︰閱讀要安裝的 FreeBSD 版本所附之硬體支援表,以確定您的硬體有沒有被支援。一般來說,此安裝說明是針對 &i386; (相容的 PC 機種)
架構的電腦。 如果有其他架構(比如 Alpha)的安裝說明,我們會一併列出。
雖然本文件會常常更新,但有可能與您安裝版本上所附的說明文件有些許出入。
在此,我們建議您把本說明文章當作一般的安裝參考原則就好。安裝前的準備工作列出您電腦的硬體清單在安裝 FreeBSD 之前,您應該試著將您電腦中的硬體清單列出來。
FreeBSD 安裝程式會將這些硬體(硬碟、網路卡、光碟機等等)以型號及製造廠商列出來。
FreeBSD 也會嘗試為這些硬體找出最適當的 IRQ 及 IO port 的設定。
但是因為 PC 的硬體種類實在太過複雜,這個步驟不一定保證絕對成功。
這時,您就可能需要手動更改有問題的設定值哩。如果您已裝了其它的作業系統,如:
&windows; 或 Linux,那麼可先由這些系統所提供的工具,來查看這些硬體設定值是怎麼設定的。
若真的沒辦法確定某些卡用什麼設定值,那麼可以檢查看看卡上面所標示的東西,說不定它的設定已有標示在卡上。
常用的 IRQ 號碼為 3、5 以及 7;而 IO 埠的值通常以 16 進位表示,例如 0x330。建議您在安裝 FreeBSD 之前,把這些資料列印或抄錄下來,做成表格的樣子也許會較有用喔,例如:
硬體清單(舉例)硬體名稱IRQIO port(s)備註第一顆 IDE 硬碟N/AN/A40 GB,Seagate 製造,first IDE masterCDROMN/AN/AFirst IDE slave第二顆硬碟N/AN/A20 GB,IBM 製造, second IDE master第一個 IDE controller140x1f0網路卡N/AN/A&intel; 10/100數據機N/AN/A&tm.3com; 56K faxmodem,接在 COM1…
備份您的資料如果要裝的電腦上面存有重要資料,那麼在安裝 FreeBSD 前,
請確定您已經將這些資料備份了,並且先測試過這些備份檔是否沒有問題。
FreeBSD 安裝程式在要寫入任何資料到您的硬碟前,都會先提醒您確認,
一旦您確定要寫入,那麼之後就再也沒有反悔的機會囉。決定要將 FreeBSD 安裝到哪裡如果您想讓 FreeBSD 直接使用整顆硬碟,那麼請直接跳到下一節。然而,如果您想要 FreeBSD 跟既有的系統並存,那麼,您必須對硬碟的資料分佈方式有深入的了解,
以及其所造成的影響。&i386; 架構的硬碟配置模式PC 上的硬碟可以被細分為許多分散的區域。這些區域叫做 分割區(Partitions)。
因為設計的方式,每個硬碟最多可以有 4 個分割區,而這些分割叫做
主要分割區(Primary Partitions)。
為了突破這個限制,以便能使用更多的分割區,就有了新的分割區類型,叫作:
延伸分割區(Extended Partition)。
每個硬碟就只能有一個延伸分割區。然而,在延伸分割區裡面可以建立許多個特殊分割區,叫作
邏輯分割區(Logical Partitions)。每種分割區都有其 分割區代號(Partition ID)
用以區別每種分割區的資料類型。而 FreeBSD 分割區代號是 165。一般來講,每種作業系統都會有自己獨特的方式來區別分割區。舉例: DOS 及其之後的作業系統,比如
&windows; ,會分配給每個主要分割區及邏輯分割區 1 個
磁碟代號(drive letter),從 C: 開始。FreeBSD 必須安裝在主要分割區。FreeBSD 可以在這個分割區上面存放資料或是您建立的任何檔案。
然而,如果您有很多顆硬碟,也可以在這些(或部份)硬碟建立 FreeBSD 分割區。
安裝 FreeBSD 的時候,必須至少要有 1 個分割區給 FreeBSD 使用,
這個分割區可以是尚未使用的分割區,或是現存的分割區。(但上面的資料不打算繼續使用)如果您已經用完了您磁碟上所有的分割區,那麼您必須使用其他作業系統所提供的工具
(像是 DOS or &windows; 上的 fdisk)來騰出一個分割區給 FreeBSD 用。如果有多餘的分割區,也可以使用它。但使用前,您可能需要先整理一下這些分割區。FreeBSD最小安裝需要約 100 MB 的空間,但是這只是『最小安裝』,
幾乎沒剩下多少空間來存放您自己的檔案。 較理想的(不含圖形介面)最小安裝是約
250 MB,或者是 350 MB 左右(包含圖形介面)。
還需要安裝其他的套件軟體,那麼將需要更多的硬碟空間。您可以使用商業軟體,例如 &partitionmagic;
來重新調整分割區空間,來給 FreeBSD 用的空間。FreeBSD 光碟、FTP 上面的 tools
目錄包含兩個免費的工具,也可以達成這個工作,叫作:
FIPS 及
PResizer。這些工具的說明文件可以在同個目錄內找到。
FIPS,
PResizer 和
&partitionmagic; 可以重新調整在 &ms-dos; 到 &windows; ME 所使用的
FAT16 及 FAT32
分割區大小。另外,
&partitionmagic; 則是上述軟體中唯一可以重新調整
NTFS 分割區大小。不當的使用這些工具,可能會刪除所有硬碟上的資料。
在使用這些工具前,請確定您已有先備份好資料。使用現有的分割區假設您只有一個 4 GB 的硬碟,而且已經裝了 &windows;
,然後將這顆硬碟分成兩個磁碟代號:C: 及
D:,每個大小為 2 GB 。
C: 槽上放了 1 GB 的資料,而 D:
槽上放了 0.5 GB 的資料。這表示硬碟上有兩個分割區,每個磁碟代號槽都是分割區。您可以把所有放在
D: 的資料,都移動到 C:
,這樣就空出了第二個分割區可以給 FreeBSD 使用。縮減現有的分割區假設您只有一個 4 GB 硬碟,而且已經裝了 &windows; 。在安裝
&windows; 時把 4 GB 都給 C: 槽,並且現在已經用了 1.5 GB
空間,而你想將剩下空間的 2 GB 給 FreeBSD 使用。如此一來,為了裝 FreeBSD ,你必須在以下兩種方式二選一:備份 &windows; 資料,然後重裝 &windows;,並在安裝 &windows; 時給 2 GB 的分割空間。使用上述的工具,像是 &partitionmagic;,來重新調整 &windows;
所用的分割區大小。Alpha 架構的磁碟配置模式Alpha在 Alpha 上,您必須使用一整顆硬碟給 FreeBSD
,沒有辦法在同顆硬碟上跟其他作業系統共存。根據不同型號的 Alpha
機器,您的硬碟可以是 SCSI 或 IDE 硬碟,只要您的機器可以從這些硬碟開機就可以。按照 Digital / Compaq 使用手冊的編排風格,所有 SRM 輸入的部分都用大寫表示。
注意,SRM 大小寫有別。要得知您磁碟的名稱以及型號,可以在 SRM console 提示下使用
SHOW DEVICE 命令:>>>SHOW DEVICE
dka0.0.0.4.0 DKA0 TOSHIBA CD-ROM XM-57 3476
dkc0.0.0.1009.0 DKC0 RZ1BB-BS 0658
dkc100.1.0.1009.0 DKC100 SEAGATE ST34501W 0015
dva0.0.0.0.1 DVA0
ewa0.0.0.3.0 EWA0 00-00-F8-75-6D-01
pkc0.7.0.1009.0 PKC0 SCSI Bus ID 7 5.27
pqa0.0.0.4.0 PQA0 PCI EIDE
pqb0.0.1.4.0 PQB0 PCI EIDE例子中機器為 Digital Personal Workstation
433au 並且顯示出此機器有連接三個磁碟機。第一個是 CDROM,叫做 DKA0
;另外兩個是磁碟機, 分別叫做:
DKC0 及
DKC100 。磁碟機的名稱中有 DKx
字樣的是 SCSI 硬碟。例如: DKA100
表示是 SCSI 硬碟,其 SCSI ID 為 1, 位在第一個 SCSI 匯流排(A);
而 DKC300 表示是 SCSI 硬碟,其 SCSI ID 為 3
,位於第三個 SCSI 匯流排(C)。裝置名稱
PKx 表示 SCSI 控制卡。由上述 SHOW DEVICE 的結果看來,
SCSI 光碟機也被視為是 SCSI 硬碟的一種。若為 IDE 硬碟的話,名稱會有 DQx 字樣,而
PQx 則表示相對應的 IDE 磁碟控制器。整理你的網路設定資料如果想透過網路( FTP 站或 NFS)安裝 FreeBSD,那麼就必須知道您的網路組態。
在安裝 FreeBSD 的過程中將會提示您輸入這些資訊,以順利完成安裝過程。使用乙太網路(Ethernet)或 Cable/DSL 數據機上網若使用乙太網路,或是要透過 Cable/DSL 數據機上網,那麼您必須準備 下面的資訊:IP 位址預設 Gateway(閘道) 的 IP 位址Hostname(機器名稱)DNS 伺服器的 IP 位址Subnet Mask若不知道這些資訊,您可以詢問系統管理者或是您的 ISP 業者。
他們可能會說這些資訊會由 DHCP 自動指派;如果是這樣的話, 請記住這一點就可以了。使用數據機上網若由一般的數據機撥接上網,您仍然可以安裝 FreeBSD,只是會需要很長的時間。您必須知道:撥接到 ISP 的電話號碼。您的數據機是連到哪個 COM 埠。您撥接到 ISP 所用的帳號跟密碼。查閱 FreeBSD 勘誤表(Errata)雖然我們盡力使得每個 FreeBSD 發行版本都很穩定,但是過程中仍然不免有時會發生錯誤。
在很罕見的情形下,這些錯誤會影響到安裝的過程。當發現這些錯誤且修正後,會將它們列在
FreeBSD 勘誤表(Errata) 中。在您安裝 FreeBSD
前,應該先看看勘誤表中有沒有什麼問題會影響到您的安裝。關於所有發行版本的資訊,包括勘誤表,可以在 FreeBSD 網站 的
發行情報(release information) 找到。準備好 FreeBSD 安裝檔案FreeBSD 可以透過下面任何一種安裝來源進行安裝︰Local MediaCDROM 或 DVD現有的 DOS 分割區SCSI 或 QIC 磁帶。軟碟磁片NetworkFTP 站、支援 Passvie 模式的 FTP 站(若您機器在 NAT 內)、甚至 HTTP proxy 都可以。NFS 伺服器專用(dedicated)的 parallel 或 serial 連線若已經有 FreeBSD 的 CD 或 DVD,但機器不支援從光碟開機的話,那麼請直接進下一節
()。若沒有 FreeBSD 安裝片的話,那麼請先看
這裡會介紹如何準備所需要的安裝片,照該節步驟弄好後,就可以繼續下一步
。準備好開機磁片FreeBSD 安裝流程是要從電腦開機後,進入 FreeBSD 安裝畫面 —— 而不是在其他作業系統上執行程式。
一般來講,電腦都是用裝在硬碟上的作業系統來開機,也可以用開機磁片來開機;
此外,現在大多數電腦都可以從光碟開機。如果您有 FreeBSD 的 CDROM 或 DVD(無論是用買的或是自己燒錄的), 且您的電腦可支援由光碟開機,
(通常在 BIOS 中會有 Boot
Order 或類似選項),那麼您就可以跳過此小節。因為 FreeBSD CDROM 或 DVD 都可以用來開機。請按照下面步驟,以製作開機片:取得開機片的映像檔(images)開機磁片用的映像檔(images)通常會放在光碟片上的 floppies/ 目錄內,另外也可以從像是下面 FTP 站的 floppies
目錄下載:
ftp://ftp.FreeBSD.org/pub/FreeBSD/releases/<arch>/<version>-RELEASE/floppies/
。請將『arch』、『version』替換為打算安裝的電腦架構、OS 版本。例如:要裝的電腦屬 &i386 架構,而要裝的是
&os; &rel.current;-RELEASE ,那麼可以到 下載。映像檔(images)的附檔名都是 .flp 。而
floppies/ 目錄內包含一些不同用途的映像檔(images),這取決於您要裝的 FreeBSD 版本、需求、硬體配備為何。
若要裝的是
FreeBSD 4.X 那麼通常只需要 2 個映像檔,也就是 kern.flp 與
mfsroot.flp。而若要裝的是 FreeBSD 5.X
,那麼通常要 3 個映像檔,也就是: boot.flp、
kern1.flp、
kern2.flp。若有疑問的話,請翻閱同一目錄下的
README.TXT 文件檔,以瞭解相關最新注意事項。安裝 &os; 5.3 之前的 5.X 系統時,有些硬體設備可能需要額外的驅動程式才能使用。
這些驅動程式都會放在 drivers.flp 這個映像檔內。在使用 FTP 下載時,必須使用 binary 模式 進行傳輸。有些瀏覽器預設是以 text (或
ASCII) 模式來傳輸資料,所以這些錯誤傳輸模式下載的映像檔所做成的磁片,會無法使用。準備開機磁片每個映像檔都需要一張磁片,並且請避免使用到壞的磁片。最簡單的檢測方式就是自己先把這些磁片再重新格式化(format)
而不要相信所謂的已格式化的磁片,&windows; 內的 format
在格式化時,並不會告訴你是否有壞軌,而只會直接將它們標示壞軌而不使用壞軌部分而已。
此外,建議採用全新的磁片來製作安裝片比較保險。若在安裝 FreeBSD 的過程中發生當機、畫面凍結或是其他怪異的現象,首先要懷疑的就是開機磁片是否壞掉。
請用其他的磁片製作映像檔再試試看。將映像檔(images)寫入到磁片內.flp 檔並非一般檔案,不能直接把它複製到磁片上。
事實上它是包含整張磁片所有內容的映像檔(image)。也就是說,不能純粹複製檔案到磁片上,
而必須使用特別的工具程式,來將映像檔直接寫到磁片上。DOS若要用 &ms-dos;/&windows; 來作安裝片的話,那麼可以用 fdimage
工具程式來將映像檔,寫到磁片上。若您用的是 FreeBSD 光碟的話(假設光碟機代號為 E: ,那麼請執行類似下面的指令:E:\>tools\fdimage floppies\kern.flp A:請針對每個需要用到的 .flp 映像檔,重複上述的指令(記得更改相關檔名),每次的映像檔完成後,
都需要換另外一片來裝新的映像檔;請記得,在作好的磁片上註明是使用哪個映像檔作的。若 .flp
映像檔放在不同地方,請自行修改上述指令。若沒有 FreeBSD 光碟的話,可以到 FTP 上面的 tools
目錄 下載 fdimage 使用。如果要用 &unix; 系統(比如其他台 FreeBSD 機器)來製作開機片的話,可以用 &man.dd.1;
指令來把映像檔直接寫入到磁片上。在 FreeBSD上的話,可以打類似下面的指令:&prompt.root; dd if=kern.flp of=/dev/fd0在 FreeBSD 中,/dev/fd0 就是指第一台軟碟機(即一般 &ms-dos;/&windows;
上的 A: 磁碟機);而 /dev/fd1 指
B: 磁碟機,其餘的依此類推。不過其他的 &unix;
系統可能會用不同的名稱,這時就要查閱該系統的說明文件了。現在起,我們可以開始安裝 FreeBSD 囉!開始安裝預設的情況下,安裝過程並不會改變您磁碟機中的任何資料,除非您看到下面的訊息:Last Chance: Are you SURE you want continue the installation?
If you're running this on a disk with data you wish to save then WE
STRONGLY ENCOURAGE YOU TO MAKE PROPER BACKUPS before proceeding!
We can take no responsibility for lost disk contents!在看到這最後的警告訊息前,您都可以隨時離開安裝程式而不會變更您的硬碟。
如果您發現有任何設定錯誤,這時您可以直接將電源關掉而不會造成任何傷害。開機啟動流程篇&i386; 平台的開機流程在一開始,電腦電源開關是關閉的。打開電腦電源開關。剛開始的時候,它應該會顯示進入系統設定選單或 BIOS 要按哪個鍵,常見的有: F2, F10,
Del 或
AltS。(按鍵請依據實際情況決定)不論是要按哪個鍵,請按它進入 BIOS
設定畫面。有時您的電腦可能會顯示一個圖形畫面,通常做法是按 Esc
鍵將離開這個圖形畫面,以使您能夠看到必要的設定訊息。找出可以設定『開機順序(Boot Order)』的選項,通常該選項會列出一些設備讓您選擇,例如︰
Floppy, CDROM,
First Hard Disk 等等。如果要用軟碟安裝,請確定 floppy disk 要列為開機順序的第一個;若要用光碟安裝,記得 CDROM
要列為開機順序的第一個。為了避免疑惑,請參考機器、主機板說明手冊。儲存設定並離開,系統應該會重新啟動。
- 用磁片安裝,請把在
+ 若要用磁片安裝,請把在
一節中製作好的 kern.flp 那張安裝磁片放到第一台軟碟機中。如果是從光碟安裝,那麼開機後請將 FreeBSD 光碟放入光碟機中。如果,開機後如往常一樣而沒有從軟碟或光碟開機,請檢查︰是不是磁片或光碟太晚放入而錯失開機時間。如果是,請將它們放入,然後重新開機。BIOS 設定不對或忘了儲存設定,請重新檢查 BIOS 的設定。您的電腦 BIOS 不支援從光碟開機。此時,FreeBSD 就開始啟動了。如果是從光碟開機,會見到類似下面的畫面(版本部分省略)::Verifying DMI Pool Data ........
Boot from ATAPI CD-ROM :
1. FD 2.88MB System Type-(00)
Uncompressing ... done
BTX loader 1.00 BTX version is 1.01
Console: internal video/keyboard
BIOS drive A: is disk0
BIOS drive B: is disk1
BIOS drive C: is disk2
BIOS drive D: is disk3
BIOS 639kB/261120kB available memory
FreeBSD/i386 bootstrap loader, Revision 0.8
/kernel text=0x277391 data=0x3268c+0x332a8 |
|
Hit [Enter] to boot immediately, or any other key for command prompt.
Booting [kernel] in 9 seconds... _如果您從軟碟開機,會看到類似下面的畫面(版本部分省略):Verifying DMI Pool Data ........
BTX loader 1.00 BTX version is 1.01
Console: internal video/keyboard
BIOS drive A: is disk0
BIOS drive C: is disk1
BIOS 639kB/261120kB available memory
FreeBSD/i386 bootstrap loader, Revision 0.8
/kernel text=0x277391 data=0x3268c+0x332a8 |
Please insert MFS root floppy and press enter:請根據提示將 kern.flp 磁片取出, 並放入 mfsroot.flp
這張磁片,然後按 Enter 鍵。若是 &os; 5.3
(含之後)的話,還有另外一張磁片(在前一節已經介紹過了)。
總之,您只需從第一張磁片啟動, 然後根據提示,再放入相關磁片即可。
- 不論從軟碟或光碟開機,您都會看到下面這段訊息:
+ 無論從軟碟或光碟開機,您都會看到下面這段訊息:Hit [Enter] to boot immediately, or any other key for command prompt.
Booting [kernel] in 9 seconds... _您可以等待 10 秒,或是按 Enter 鍵。
(若是 &os; 4.X 的話,則將出現 kernel configuration 選單畫面)Alpha 平台的開機流程Alpha
- Start with your computer turned off.
+ 在一開始,電腦電源開關是關閉的。
- Turn on the computer and wait for a boot monitor
- prompt.
+ 打開電腦電源開關,然後等開機畫面出現。
- If you needed to prepare boot floppies, as described in
- then one of them will be the
- first boot disc, probably the one containing
- kern.flp. Put this disc in your floppy
- drive and type the following command to boot the disk
- (substituting the name of your floppy drive if
- necessary):
+ 若要用磁片安裝,請把在
+ 一節中製作好的 kern.flp 那張安裝磁片放到第一台軟碟機中。
+ 然後,打下列指令來從磁片開機(請把下列軟碟機代號改為你電腦的軟碟機代號):>>>BOOT DVA0 -FLAGS '' -FILE ''
- If you are booting from CDROM, insert the CDROM into
- the drive and type the following command to start the
- installation (substituting the name of the appropriate
- CDROM drive if necessary):
+ 若要用光碟安裝,請把做好的安裝片放入光碟機,然後打下列指令來從光碟開機(請把下列光碟機代號改為你電腦的光碟機代號):>>>BOOT DKA0 -FLAGS '' -FILE ''
- FreeBSD will start to boot. If you are booting from a
- floppy disc, at some point you will see the message:
+ 接著 FreeBSD 開機片就會開始了。若是由軟碟開機的話,這時會看到以下訊息:Please insert MFS root floppy and press enter:
- Follow these instructions by removing the
- kern.flp disc, insert the
- mfsroot.flp disc, and press
- Enter.
+ 請照指示,拿走 kern.flp 片,改放
+ mfsroot.flp 片,然後按 Enter。
- Whether you booted from floppy or CDROM, the
- boot process will then get to this point:
+ 無論從軟碟或光碟開機,您都會看到下面這段訊息:Hit [Enter] to boot immediately, or any other key for command prompt.
Booting [kernel] in 9 seconds... _
- Either wait ten seconds, or press Enter. This
- will then launch the kernel configuration menu.
+ 您可以等待 10 秒,或是按 Enter 鍵。接下來就會進入kernel configuration 選單。Kernel 的設定從 FreeBSD 5.0 版開始,改用新的 &man.device.hints.5; 方式,而淘汰舊的 userconfig 方式。
關於 &man.device.hints.5; 機制的細節介紹,請參閱 。
- The kernel is the core of the operating
- system. It is responsible for many things, including access to all
- the devices you may have on your system, such as hard disks, network
- cards, sound cards, and so on. Each piece of hardware supported by
- the FreeBSD kernel has a driver associated with it. Each driver has a
- two or three letter name, such as sa for the
- SCSI sequential access driver, or sio for the
- Serial I/O driver (which manages COM ports).
-
- When the kernel starts, each driver checks the system to see
- whether or not the hardware it supports exists on your system. If it
- does, then the driver configures the hardware and makes it available
- to the rest of the kernel.
-
- This checking is commonly referred to as device
- probing. Unfortunately, it is not always possible to do
- this in a safe way. Some hardware drivers do not co-exist well,
- and probing for one piece of hardware can sometimes leave
- another in an inconsistent state. This is a basic
- limitation of the PC design.
+ kernel 乃是作業系統中的核心,負責許多事情,像是:控制系統上所有設備,比如硬碟、網路卡、音效卡等。
+ 每項 FreeBSD 所支援的硬體都有相對應的驅動程式。
+ 每個驅動程式名稱都有 2 到 3 個字母所組成,像是 sa 代表 SCSI 驅動程式,而
+ sio 代表 Serial I/O 驅動程式(管 COM ports 用的)。
+
+ 當 kernel 開始啟動時,每個驅動程式就會去檢查系統上是否有支援的硬體存在,
+ 若有的話,驅動程式就會作相關硬體設定,以便讓 kernel 使用該硬體。
+
+ 上述的檢查動作,我們稱為 device probing(偵測硬體)。
+ 但是,這樣子的方式並不是永遠都那麼順利。
+ 有些硬體驅動程式無法同時共存,而有時候偵測某硬體時,又會造成另一硬體不穩出槌。
+ 這問題,乃是由於 PC 本身設計上天生的限制所致。Many older devices are called ISA devices—as opposed
to PCI devices. The ISA specification requires each device to have
some information hard coded into it, typically the Interrupt Request
Line number (IRQ) and IO port address that the driver uses. This
information is commonly set by using physical
jumpers on the card, or by using a DOS based
utility.This was often a source of problems, because it was not possible
to have two devices that shared the same IRQ or port address.Newer devices follow the PCI specification, which does not require
this, as the devices are supposed to cooperate with the BIOS, and are
told which IRQ and IO port addresses to use.If you have any ISA devices in your computer then FreeBSD's
driver for that device will need to be configured with the IRQ and
port address that you have set the card to. This is why carrying out
an inventory of your hardware (see ) can be useful.Unfortunately, the default IRQs and memory ports used by some
drivers clash. This is because some ISA devices are shipped with IRQs
or memory ports that clash. The defaults in FreeBSD's drivers are
deliberately set to mirror the manufacturer's defaults, so that, out
of the box, as many devices as possible will work.This is almost never an issue when running FreeBSD day-to-day.
Your computer will not normally contain two pieces of hardware that
clash, because one of them would not work (irrespective of the
operating system you are using).It becomes an issue when you are installing FreeBSD for the first
time because the kernel used to carry out the install has to contain
as many drivers as possible, so that many different hardware
configurations can be supported. This means that some of
those drivers will have conflicting configurations. The devices are
probed in a strict order, and if you own a device that is probed late
in the process, but conflicted with an earlier probe, then your
hardware might not function or be probed correctly when you install
FreeBSD.Because of this, the first thing you have the opportunity to do
when installing FreeBSD is look at the list of drivers that are
configured into the kernel, and either disable some of them, if you
do not own that device, or confirm (and alter) the driver's
configuration if you do own the device but the defaults are
wrong.This probably sounds much more complicated than it actually
is. shows the first kernel
configuration menu. We recommend that you choose the
Start kernel configuration in full-screen visual
mode option, as it presents the easiest interface for
the new user.Kernel 設定畫面&txt.install.userconfig;The kernel configuration screen ()
is then divided into four sections:A collapsible list of all the drivers that are currently
marked as active, subdivided into groups such as
Storage, and Network. Each
driver is shown as a description, its two or three letter driver
name, and the IRQ and memory port used by that driver. In
addition, if an active driver conflicts with another active driver
then CONF is shown next to the driver name.
This section also shows the total number of conflicting drivers
that are currently active.Drivers that have been marked inactive. They remain in the
kernel, but they will not probe for their device when the kernel
starts. These are subdivided into groups in the same way as the
active driver list.More detail about the currently selected driver, including its
IRQ and memory port address.Information about the keystrokes that are valid at this point
in time.Kernel Device 的設定畫面&txt.install.userconfig2;Do not worry if any conflicts are listed,
it is to be expected; all the drivers are enabled, and
as has already been explained, some of them will conflict with one
another.You now have to work through the list of drivers, resolving the
conflicts.解除相衝的驅動程式Press X. This will completely expand the
list of drivers, so you can see all of them. You will need to use
the arrow keys to scroll back and forth through the active driver
list. shows the result of
pressing X.展開驅動程式一覽表Disable all the drivers for devices that you do not have. To
disable a driver, highlight it with the arrow keys and press
Del. The driver will be moved to the
Inactive Drivers list.If you inadvertently disable a device that you need then press
Tab to switch to the Inactive
Drivers list, select the driver that you disabled, and
press Enter to move it back to the active
list.Do not disable sc0. This controls
the screen, and you will need this unless you are installing
over a serial cable.Only disable atkbd0 if you are
using a USB keyboard. If you have a normal keyboard then you
must keep atkbd0.If there are no conflicts listed then you can skip this step.
Otherwise, the remaining conflicts need to be examined. If they
do not have the indication of an allowed conflict
in the message area, then either the IRQ/address for device probe
will need to be changed, or the IRQ/address
on the hardware will need to be changed.To change the driver's configuration for IRQ and IO port
address, select the device and press Enter. The
cursor will move to the third section of the screen, and you can
change the values. You should enter the values for IRQ and port
address that you discovered when you made your hardware inventory.
Press Q to finish editing the device's
configuration and return to the active driver list.If you are not sure what these figures should be then you can
try using -1. Some FreeBSD drivers can safely
probe the hardware to discover what the correct value should be,
and a value of -1 configures them to do
this.The procedure for changing the address on the hardware varies
from device to device. For some devices you may need to
physically remove the card from your computer and adjust jumper
settings or DIP switches. Other cards may have come with a DOS
floppy that contains the programs used to reconfigure the card.
In any case, you should refer to the documentation that came with
the device. This will obviously entail restarting your computer,
so you will need to boot back into the FreeBSD installation
routine when you have reconfigured the card.When all the conflicts have been resolved the screen will look
similar to .沒有衝突的驅動程式設定As you can see, the active driver list is now much smaller,
with only drivers for the hardware that actually exists being
listed.You can now save these changes, and move on to the next step
of the install. Press Q to quit the device
configuration interface. This message will appear:Save these parameters before exiting? ([Y]es/[N]o/[C]ancel)Answer Y to save the parameters to memory
(it will be saved to disk if you finish the install) and the
probing will start. After displaying the probe results in white
on black text sysinstall will start
and display its main menu
().Sysinstall 主選單那要怎麼去翻閱偵測硬體的結果呢?先前在螢幕上所顯示的最後幾百行字,會存在暫存區(buffer)以便您翻閱。若要翻閱暫存區,請按 Scroll Lock 鍵,這會開啟捲動畫面功能。
然後就可以使用方向鍵,或是 PageUp、PageDown
鍵來上下翻閱。再按一次 Scroll Lock 鍵,就會停止畫面捲動。Do this now, to review the text that scrolled off the screen when
the kernel was carrying out the device probes. You will see text
similar to , although the precise
text will differ depending on the devices that you have in your
computer.偵測硬體的例子avail memory = 253050880 (247120K bytes)
Preloaded elf kernel "kernel" at 0xc0817000.
Preloaded mfs_root "/mfsroot" at 0xc0817084.
md0: Preloaded image </mfsroot> 4423680 bytes at 0xc03ddcd4
md1: Malloc disk
Using $PIR table, 4 entries at 0xc00fde60
npx0: <math processor> on motherboard
npx0: INT 16 interface
pcib0: <Host to PCI bridge> on motherboard
pci0: <PCI bus> on pcib0
pcib1:<VIA 82C598MVP (Apollo MVP3) PCI-PCI (AGP) bridge> at device 1.0 on pci0
pci1: <PCI bus> on pcib1
pci1: <Matrox MGA G200 AGP graphics accelerator> at 0.0 irq 11
isab0: <VIA 82C586 PCI-ISA bridge> at device 7.0 on pci0
isa0: <iSA bus> on isab0
atapci0: <VIA 82C586 ATA33 controller> port 0xe000-0xe00f at device 7.1 on pci0
ata0: at 0x1f0 irq 14 on atapci0
ata1: at 0x170 irq 15 on atapci0
uhci0 <VIA 83C572 USB controller> port 0xe400-0xe41f irq 10 at device 7.2 on pci
0
usb0: <VIA 83572 USB controller> on uhci0
usb0: USB revision 1.0
uhub0: VIA UHCI root hub, class 9/0, rev 1.00/1.00, addr1
uhub0: 2 ports with 2 removable, self powered
pci0: <unknown card> (vendor=0x1106, dev=0x3040) at 7.3
dc0: <ADMtek AN985 10/100BaseTX> port 0xe800-0xe8ff mem 0xdb000000-0xeb0003ff ir
q 11 at device 8.0 on pci0
dc0: Ethernet address: 00:04:5a:74:6b:b5
miibus0: <MII bus> on dc0
ukphy0: <Generic IEEE 802.3u media interface> on miibus0
ukphy0: 10baseT, 10baseT-FDX, 100baseTX, 100baseTX-FDX, auto
ed0: <NE2000 PCI Ethernet (RealTek 8029)> port 0xec00-0xec1f irq 9 at device 10.
0 on pci0
ed0 address 52:54:05:de:73:1b, type NE2000 (16 bit)
isa0: too many dependant configs (8)
isa0: unexpected small tag 14
orm0: <Option ROM> at iomem 0xc0000-0xc7fff on isa0
fdc0: <NEC 72065B or clone> at port 0x3f0-0x3f5,0x3f7 irq 6 drq2 on isa0
fdc0: FIFO enabled, 8 bytes threshold
fd0: <1440-KB 3.5" drive> on fdc0 drive 0
atkbdc0: <Keyboard controller (i8042)> at port 0x60,0x64 on isa0
atkbd0: <AT Keyboard> flags 0x1 irq1 on atkbdc0
kbd0 at atkbd0
psm0: <PS/2 Mouse> irq 12 on atkbdc0
psm0: model Generic PS/@ mouse, device ID 0
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
sc0: <System console> at flags 0x100 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
sio0 at port 0x3f8-0x3ff irq 4 flags 0x10 on isa0
sio0: type 16550A
sio1 at port 0x2f8-0x2ff irq 3 on isa0
sio1: type 16550A
ppc0: <Parallel port> at port 0x378-0x37f irq 7 on isa0
pppc0: SMC-like chipset (ECP/EPP/PS2/NIBBLE) in COMPATIBLE mode
ppc0: FIFO with 16/16/15 bytes threshold
plip0: <PLIP network interface> on ppbus0
ad0: 8063MB <IBM-DHEA-38451> [16383/16/63] at ata0-master UDMA33
acd0: CD-RW <LITE-ON LTR-1210B> at ata1-slave PIO4
Mounting root from ufs:/dev/md0c
/stand/sysinstall running as init on vty0Check the probe results carefully to make sure that FreeBSD found
all the devices you expected. If a device was not found, then it will
not be listed. If the device's driver required configuring
with the IRQ and port address then you should check that you entered
them correctly.If you need to make changes to the UserConfig device probing,
it is easy to exit the sysinstall program
and start over again. It is also a good way to become more familiar
with the process.離開 Sysinstall 程式Use the arrow keys to select
Exit Install from the Main
Install Screen menu. The following message will display: User Confirmation Requested
Are you sure you wish to exit? The system will reboot
(be sure to remove any floppies from the drives).
[ Yes ] NoThe install program will start again if the CDROM is left
in the drive and &gui.yes; is selected.If you are booting from floppies it will be necessary to remove
the mfsroot.flp floppy and replace it with
kern.flp before rebooting.介紹 SysinstallThe sysinstall utility is the installation
application provided by the FreeBSD Project. It is console based and is
divided into a number of menus and screens that you can use to
configure and control the installation process.The sysinstall menu system is controlled
by the arrow keys, Enter, Space, and
other keys. A detailed description of these keys and what they do is
contained in sysinstall's usage
information.To review this information, ensure that the
Usage entry is highlighted and that the
[Select] button is selected, as shown in , then press Enter.The instructions for using the menu system will be displayed. After
reviewing them, press Enter to return to the Main
Menu.選擇 Sysinstall 主選單的『Usage(快速說明)』選擇『 Documentation(說明文件)』選單From the Main Menu, select Doc with
the arrow keys and
press Enter.選擇『Documentation(說明文件)』選單This will display the Documentation Menu.Sysinstall 的說明文件(Documentation)選單It is important to read the documents provided.To view a document, select it with the arrow keys and
press Enter. When finished reading a document,
pressing Enter will return to the Documentation
Menu.To return to the Main Installation Menu, select
Exit with the
arrow keys and press Enter.選擇『鍵盤對應』選單To change the keyboard mapping, use the arrow keys to select
Keymap from the menu and press
Enter. This is only required if you are
using a non-standard or non-US keyboard.Sysinstall 主選單A different keyboard mapping may be chosen by selecting the
menu item using up/down arrow keys and pressing Space.
Pressing Space again will unselect the item.
When finished, choose the &gui.ok; using the arrow keys and press
Enter.Only a partial list is shown in this screen representation.
Selecting &gui.cancel; by pressing Tab will use the default
keymap and return to the Main Install Menu.Sysinstall 鍵盤對應選單安裝選項的設定畫面Select Options and press
Enter.Sysinstall 主選單Sysinstall 選項設定The default values are usually fine for most users and do
not need to be changed. The release name will vary according
to the version being installed.The description of the selected item will appear at the
bottom of the screen highlighted in blue. Notice that one of the
options is Use Defaults to reset all
values to startup defaults.Press F1 to read the help screen about the
various options.Pressing Q will return to the Main Install
menu.開始進行標準安裝Standard(標準)安裝適用於那些初探 &unix;
或 FreeBSD 的使用者。用方向鍵選擇 Standard
然後按 Enter 即可開始進入標準安裝。開始進行標準安裝硬碟空間的分配Your first task is to allocate disk space for FreeBSD, and label
that space so that sysinstall can prepare
it. In order to do this you need to know how FreeBSD expects to find
information on the disk.BIOS 磁碟機編號Before you install and configure FreeBSD on your system, there is an
important subject that you should be aware of, especially if you have
multiple hard drives.DOSMicrosoft WindowsIn a PC running a BIOS-dependent operating system such as
&ms-dos; or µsoft.windows;, the BIOS is able to abstract the
normal disk drive order, and
the operating system goes along with the change. This allows the user
to boot from a disk drive other than the so-called primary
master. This is especially convenient for some users who have
found that the simplest and cheapest way to keep a system backup is to
buy an identical second hard drive, and perform routine copies of the
first drive to the second drive using
Ghost or XCOPY
. Then, if the
first drive fails, or is attacked by a virus, or is scribbled upon by an
operating system defect, he can easily recover by instructing the BIOS
to logically swap the drives. It is like switching the cables on the
drives, but without having to open the case.SCSIBIOSMore expensive systems with SCSI controllers often include BIOS
extensions which allow the SCSI drives to be re-ordered in a similar
fashion for up to seven drives.A user who is accustomed to taking advantage of these features may
become surprised when the results with FreeBSD are not as expected.
FreeBSD does not use the BIOS, and does not know the logical BIOS
drive mapping. This can lead to very perplexing situations,
especially when drives are physically identical in geometry, and have
also been made as data clones of one another.When using FreeBSD, always restore the BIOS to natural drive
numbering before installing FreeBSD, and then leave it that way. If you
need to switch drives around, then do so, but do it the hard way, and
open the case and move the jumpers and cables.範例:Bill 及 Fred 的安裝歷險Bill breaks-down an older Wintel box to make another FreeBSD box
for Fred. Bill installs a single SCSI drive as SCSI unit zero and
installs FreeBSD on it.Fred begins using the system, but after several days notices that
the older SCSI drive is reporting numerous soft errors and reports
this fact to Bill.After several more days, Bill decides it is time to address the
situation, so he grabs an identical SCSI drive from the disk drive
archive in the back room. An initial surface scan
indicates that
this drive is functioning well, so Bill installs this drive as SCSI
unit four and makes an image copy from drive zero to drive four. Now
that the new drive is installed and functioning nicely, Bill decides
that it is a good idea to start using it, so he uses features in the
SCSI BIOS to re-order the disk drives so that the system boots from
SCSI unit four. FreeBSD boots and runs just fine.Fred continues his work for several days, and soon Bill and Fred
decide that it is time for a new adventure — time to upgrade to a
newer version of FreeBSD. Bill removes SCSI unit zero because it was
a bit flaky and replaces it with another identical disk drive from
the archive. Bill then installs the new version of
FreeBSD onto the new SCSI unit zero using Fred's magic Internet FTP
floppies. The installation goes well.Fred uses the new version of FreeBSD for a few days, and certifies
that it is good enough for use in the engineering department. It is
time to copy all of his work from the old version. So Fred mounts
SCSI unit four (the latest copy of the older FreeBSD version). Fred
is dismayed to find that none of his precious work is present on SCSI
unit four.Where did the data go?When Bill made an image copy of the original SCSI unit zero onto
SCSI unit four, unit four became the new clone.
When Bill re-ordered the SCSI BIOS so that he could boot from
SCSI unit four, he was only fooling himself.
FreeBSD was still running on SCSI unit zero.
Making this kind of BIOS change will cause some or all of the Boot and
Loader code to be fetched from the selected BIOS drive, but when the
FreeBSD kernel drivers take-over, the BIOS drive numbering will be
ignored, and FreeBSD will transition back to normal drive numbering.
In the illustration at hand, the system continued to operate on the
original SCSI unit zero, and all of Fred's data was there, not on SCSI
unit four. The fact that the system appeared to be running on SCSI
unit four was simply an artifact of human expectations.We are delighted to mention that no data bytes were killed or
harmed in any way by our discovery of this phenomenon. The older SCSI
unit zero was retrieved from the bone pile, and all of Fred's work was
returned to him, (and now Bill knows that he can count as high as
zero).Although SCSI drives were used in this illustration, the concepts
apply equally to IDE drives.以 FDisk 來建立分割磁區(Slices)No changes you make at this point will be written to the disk.
If you think you have made a mistake and want to start again you can
use the menus to exit sysinstall and try
again or press U to use the Undo option.
If you get confused and can not see how to exit you can
always turn your computer off.After choosing to begin a standard installation in
sysinstall you will be shown this
message: Message
In the next menu, you will need to set up a DOS-style ("fdisk")
partitioning scheme for your hard disk. If you simply wish to devote
all disk space to FreeBSD (overwriting anything else that might be on
the disk(s) selected) then use the (A)ll command to select the default
partitioning scheme followed by a (Q)uit. If you wish to allocate only
free space to FreeBSD, move to a partition marked "unused" and use the
(C)reate command.
[ OK ]
[ Press enter or space ]Press Enter as instructed. You will then be
shown a list of all the hard drives that the kernel found when it
carried out the device probes.
shows an example from a
system with two IDE disks. They have been called
ad0 and ad2.選擇 FDisk 要分割的硬碟You might be wondering why ad1 is not
listed here. Why has it been missed?Consider what would happen if you had two IDE hard disks, one
as the master on the first IDE controller, and one as the master on
the second IDE controller. If FreeBSD numbered these as it found
them, as ad0 and
ad1 then everything would work.But if you then added a third disk, as the slave device on the
first IDE controller, it would now be ad1,
and the previous ad1 would become
ad2. Because device names (such as
ad1s1a) are used to find filesystems, you
may suddenly discover that some of your filesystems no longer
appear correctly, and you would need to change your FreeBSD
configuration.To work around this, the kernel can be configured to name IDE
disks based on where they are, and not the order in which they were
found. With this scheme the master disk on the second IDE
controller will always be
ad2, even if there are no
ad0 or ad1
devices.This configuration is the default for the FreeBSD kernel, which
is why this display shows ad0 and
ad2. The machine on which this screenshot
was taken had IDE disks on both master channels of the IDE
controllers, and no disks on the slave channels.You should select the disk on which you want to install FreeBSD,
and then press &gui.ok;.
FDisk will start, with a display similar to
that shown in .The FDisk display is broken into three
sections.The first section, covering the first two lines of the display,
shows details about the currently selected disk, including its FreeBSD
name, the disk geometry, and the total size of the disk.The second section shows the slices that are currently on the
disk, where they start and end, how large they are, the name FreeBSD
gives them, and their description and sub-type. This example shows two
small unused slices, which are artifacts of disk layout schemes on the
PC. It also shows one large FAT slice, which almost certainly appears
as C: in &ms-dos; / &windows;, and an extended
slice, which may contain other drive letters for &ms-dos; / &windows;.The third section shows the commands that are available in
FDisk.(舉例)未編輯前的 Fdisk 分割區(Partition)What you do now will depend on how you want to slice up your
disk.If you want to use FreeBSD for the entire disk (which will delete
all the other data on this disk when you confirm that you want
sysinstall to continue later in the
installation process) then you can press A, which
corresponds to the Use Entire Disk option.
The existing slices will be removed, and replaced with a small area
flagged as unused (again, an artifact of PC disk
layout), and then one large slice for FreeBSD. If you do this, then
you should select the newly created FreeBSD slice using the arrow
keys, and press S to mark the slice as being
bootable. The screen will then look very similar to
. Note the
A in the Flags column, which
indicates that this slice is active, and will be
booted from.If you will be deleting an existing slice to make space for
FreeBSD then you should select the slice using the arrow keys, and
then press D. You can then press C,
and be prompted for size of slice you want to create. Enter the
appropriate figure and press Enter. The default
value in this box represents the largest possible slice you can
make, which could be the largest contiguous block of unallocated
space or the size of the entire hard disk.If you have already made space for FreeBSD (perhaps by using a
tool such as &partitionmagic;) then you can
press C to create a new slice. Again, you will be
prompted for the size of slice you would like to create.Fdisk 採用整顆硬碟作分割區(Partition)When finished, press Q. Your changes will be
saved in sysinstall, but will not yet be
written to disk.安裝 Boot ManagerYou now have the option to install a boot manager. In general,
you should choose to install the FreeBSD boot manager if:You have more than one drive, and have installed FreeBSD onto
a drive other than the first one.You have installed FreeBSD alongside another operating system
on the same disk, and you want to choose whether to start FreeBSD
or the other operating system when you start the computer.If FreeBSD is going to be the only operating system on
this machine, installed on the first hard disk, then the
Standard boot manager will suffice.
Choose None if you are using a
third-party boot manager capable of booting FreeBSD.Make your choice and press Enter.Sysinstall 的 Boot Manager 選單The help screen, reached by pressing F1,
discusses the problems that can be encountered when trying to share
the hard disk between operating systems.在其他硬碟上建立分割磁區(Slices)If there is more than one drive, it will return to the
Select Drives screen after the boot manager selection. If you wish to
install FreeBSD on to more than one disk, then you can select another
disk here and repeat the slice process using
FDisk.If you are installing FreeBSD on a drive other than your
first, then the FreeBSD boot manager needs to be installed on
both drives.離開『選擇硬碟』畫面The Tab key toggles between the last drive
selected, &gui.ok;, and
&gui.cancel;.Press the Tab once to toggle to the
&gui.ok;, then
press Enter
to continue with the installation.以 Disklabel 來建立分割區(Partitions)
You must now create some partitions inside each slice that you
have just created. Remember that each partition is lettered, from
a through to h, and that
partitions b, c, and
d have conventional meanings that you should adhere
to.Certain applications can benefit from particular partition
schemes, especially if you are laying out partitions across more than
one disk. However, for this, your first FreeBSD installation, you do
not need to give too much thought to how you partition the disk. It
is more important that you install FreeBSD and start learning how to
use it. You can always re-install FreeBSD to change your partition
scheme when you are more familiar with the operating system.This scheme features four partitions—one for swap space, and
three for filesystems.
第一顆硬碟的分割區(Partition)配置PartitionFilesystemSizeDescriptiona/100 MBThis is the root filesystem. Every other filesystem
will be mounted somewhere under this one. 100 MB is a
reasonable size for this filesystem. You will not be storing
too much data on it, as a regular FreeBSD install will put
about 40 MB of data here. The remaining space is for temporary
data, and also leaves expansion space if future versions of
FreeBSD need more space in /.bN/A2-3 x RAMThe system's swap space is kept on this partition.
Choosing the right amount of swap space can be a bit of an
art. A good rule of thumb is that your swap
space should be two or three times as much as the
available physical memory (RAM).
You should also have at least 64 MB of swap, so if you have
less than 32 MB of RAM in your computer then set the swap
amount to 64 MB.
If you have more than one disk then you can put swap
space on each disk. FreeBSD will then use each disk for
swap, which effectively speeds up the act of swapping. In
this case, calculate the total amount of swap you need
(e.g., 128 MB), and then divide this by the number of disks
you have (e.g., two disks) to give the amount of swap you
should put on each disk, in this example, 64 MB of swap per
disk.e/var50 MBThe /var directory contains
files that are constantly varying;
log files, and other administrative files. Many
of these files are read-from or written-to extensively during
FreeBSD's day-to-day running. Putting these files on another
filesystem allows FreeBSD to optimize the access of these
files without affecting other files in other directories that
do not have the same access pattern.f/usrRest of diskAll your other files will typically be stored in
/usr and its subdirectories.
If you will be installing FreeBSD on to more than one disk then
you must also create partitions in the other slices that you
configured. The easiest way to do this is to create two partitions on
each disk, one for the swap space, and one for a filesystem.
其他硬碟的分割區(Partition)配置PartitionFilesystemSizeDescriptionbN/ASee descriptionAs already discussed, you can split swap space across
each disk. Even though the a partition is
free, convention dictates that swap space stays on the
b partition.e/disknRest of diskThe rest of the disk is taken up with one big partition.
This could easily be put on the a
partition, instead of the e partition.
However, convention says that the a
partition on a slice is reserved for the filesystem that will
be the root (/) filesystem. You do not
have to follow this convention, but
sysinstall does, so following it
yourself makes the installation slightly cleaner. You can
choose to mount this filesystem anywhere; this example
suggests that you mount them as directories
/diskn, where
n is a number that changes for each
disk. But you can use another scheme if you prefer.
Having chosen your partition layout you can now create it using
sysinstall. You will see this
message: Message
Now, you need to create BSD partitions inside of the fdisk
partition(s) just created. If you have a reasonable amount of disk
space (200MB or more) and don't have any special requirements, simply
use the (A)uto command to allocate space automatically. If you have
more specific needs or just don't care for the layout chosen by
(A)uto, press F1 for more information on manual layout.
[ OK ]
[ Press enter or space ]Press Enter to start the FreeBSD partition
editor, called Disklabel. shows the display when you first
start Disklabel. The display is divided in
to three sections.The first few lines show the name of the disk you are currently
working on, and the slice that contains the partitions you are
creating (at this point Disklabel calls
this the Partition name rather than slice name).
This display also shows the amount of free space within the slice;
that is, space that was set aside in the slice, but that has not yet
been assigned to a partition.The middle of the display shows the partitions that have been
created, the name of the filesystem that each partition contains,
their size, and some options pertaining to the creation of the
filesystem.The bottom third of the screen shows the keystrokes that are valid
in Disklabel.Sysinstall 的 Disklabel 編輯器Disklabel can automatically create
partitions for you and assign them default sizes. Try this now, by
Pressing A. You will see a display similar to that
shown in . Depending on the size of
the disk you are using, the defaults may or may not be appropriate.
This does not matter, as you do not have to accept the
defaults.Beginning with FreeBSD 4.5, the default partitioning assigns
the /tmp directory its own partition instead
of being part of the / partition. This
helps avoid filling the / partition with
temporary files.Sysinstall 的 Disklabel 編輯器 — 使用自動分配If you choose to not use the default partitions and wish to
replace them with your
own, use the arrow keys to select the first partition, and press
D to delete it. Repeat this to delete all the
suggested partitions.To create the first partition (a, mounted as
/ — root), make sure the proper disk slice at the top of
the screen is selected and press C. A dialog box
will appear prompting you for the size of the new partition (as shown
in ). You can enter the size as
the number of disk blocks you want to use, or as a
number followed by either M for megabytes,
G for gigabytes, or C for
cylinders.Beginning with FreeBSD 5.X, users can: select
UFS2 (which is default on &os; 5.1 and
above) using the Custom Newfs
(Z) option, create labels with
Auto Defaults and modify them with the Custom Newfs option or
add during the regular creation period.
Do not forget to add for SoftUpdates if you use the Custom Newfs
option!Free Space for Root PartitionThe default size shown will create a partition that takes up the
rest of the slice. If you are using the partition sizes described
in the earlier example, then delete the existing figure using
Backspace, and then type in
64M, as shown in
. Then press
&gui.ok;.Edit Root Partition SizeHaving chosen the partition's size you will then be asked whether
this partition will contain a filesystem or swap space. The dialog
box is shown in . This first
partition will contain a filesystem, so check that
FS is selected and press
Enter.Choose the Root Partition TypeFinally, because you are creating a filesystem, you must tell
Disklabel where the filesystem is to be
mounted. The dialog box is shown in
. The root filesystem's mount
point is /, so type /, and
then press Enter.Choose the Root Mount PointThe display will then update to show you the newly created
partition. You should repeat this procedure for the other
partitions. When you create the swap partition, you will not be
prompted for the filesystem mount point, as swap partitions are never
mounted. When you create the final partition,
/usr, you can leave the suggested size as is, to
use the rest of the slice.Your final FreeBSD DiskLabel Editor screen will appear similar to
, although your values chosen may
be different. Press Q to finish.Sysinstall Disklabel Editor選擇想要安裝的選擇要安裝的套件集(Distribution Set)Deciding which distribution set to install will depend largely
on the intended use of the system and the amount of disk space
available. The predefined options range from installing the
smallest possible configuration to everything. Those who are
new to &unix; and/or FreeBSD should almost certainly select one
of these canned options. Customizing a distribution set is
typically for the more experienced user.Press F1 for more information on the
distribution set options and what they contain. When finished
reviewing the help, pressing Enter will return
to the Select Distributions Menu.If a graphical user interface is desired then a distribution
set that is preceded by an X should be
chosen. The configuration of the X server and selection of a default
desktop must be done after the installation of &os;. More
information regarding the configuration of a X server can be
found in .The default version of X11 that is installed depends on the
version of FreeBSD that you are installing. For FreeBSD versions
prior to 5.3, &xfree86; 4.X is installed. For &os; 5.3 and later,
&xorg; is the default.If compiling a custom kernel is anticipated, select an option
which includes the source code. For more information on why a
custom kernel should be built or how to build a custom kernel, see
.Obviously, the most versatile system is one that includes
everything. If there is adequate disk space, select
All as shown in
by using the arrow keys and
press Enter. If there is a concern about disk
space consider using an option that is more suitable for the
situation.
Do not fret over the perfect choice, as other distributions can be
added after installation.選擇套件(Distributions)安裝 Ports CollectionAfter selecting the desired distribution, an opportunity to
install the FreeBSD Ports Collection is presented. The ports
collection is an easy and convenient way to install software.
The Ports Collection does not contain the source code necessary
to compile the software. Instead, it is a collection of files which
automates the downloading, compiling and installation
of third-party software packages.
discusses how to use the ports
collection.The installation program does not check to see if you have
adequate space. Select this option only if you have
adequate hard disk space. As of FreeBSD &rel.current;, the FreeBSD
Ports Collection takes up about &ports.size; of disk space.
You can safely assume a larger value for more recent versions
of FreeBSD. User Confirmation Requested
Would you like to install the FreeBSD ports collection?
This will give you ready access to over &os.numports; ported software packages,
at a cost of around &ports.size; of disk space when "clean" and possibly much
more than that if a lot of the distribution tarballs are loaded
(unless you have the extra CDs from a FreeBSD CD/DVD distribution
available and can mount it on /cdrom, in which case this is far less
of a problem).
The Ports Collection is a very valuable resource and well worth having
on your /usr partition, so it is advisable to say Yes to this option.
For more information on the Ports Collection & the latest ports,
visit:
http://www.FreeBSD.org/ports
[ Yes ] NoSelect &gui.yes; with the arrow keys to
install the Ports Collection or &gui.no; to
skip this option. Press Enter to continue.
The Choose Distributions menu will redisplay.Confirm DistributionsIf satisfied with the options, select
Exit with the arrow keys, ensure that
&gui.ok; is highlighted, and pressing
Enter to continue.選擇安裝來源
- If Installing from a CDROM or DVD, use the arrow keys to highlight
- Install from a FreeBSD CD/DVD. Ensure
- that &gui.ok; is highlighted, then press
- Enter to proceed with the installation.
+ 若要從 CDROM 或 DVD 安裝,用方向鍵將游標移到 Install from a FreeBSD CD/DVD,並確定
+ 選 &gui.ok; 後按下 Enter 就會開始裝了。
- For other methods of installation, select the appropriate
- option and follow the instructions.
+ 若是要用其他的方式安裝的話,請選擇適當的安裝來源,然後遵照螢幕指示進行安裝即可。
- Press F1 to display the Online Help for
- installation media. Press Enter to return
- to the media selection menu.
+ 按 F1 可以顯示針對此部分(安裝來源)的線上說明。按一下 Enter
+ 就會回到『選擇安裝來源』的畫面了。選擇安裝來源FTP 安裝模式installationnetworkFTP
- There are three FTP installation modes you can choose from:
- active FTP, passive FTP, or via a HTTP proxy.
+ 使用 FTP 安裝的話,有分三種模式︰主動式(active)FTP、被動式(passive)FTP 或是透過 HTTP proxy server。FTP Active: Install from an FTP
serverThis option will make all FTP transfers
use Active
mode. This will not work through firewalls, but will
often work with older FTP servers that do not support
passive mode. If your connection hangs with passive
mode (the default), try active!FTP Passive: Install from an FTP server through a
firewallFTPpassive modeThis option instructs sysinstall to use
Passive mode for all FTP operations.
This allows the user to pass through firewalls
that do not allow incoming connections on random TCP ports.
FTP via a HTTP proxy: Install from an FTP server
through a http proxyFTPvia a HTTP proxyThis option instructs sysinstall to use the HTTP
protocol (like a web browser) to connect to a proxy
for all FTP operations. The proxy will translate
the requests and send them to the FTP server.
This allows the user to pass through firewalls
that do not allow FTP at all, but offer a HTTP
proxy.
In this case, you have to specify the proxy in
addition to the FTP server.For a proxy FTP server, you should usually give the name of the
server you really want as a part of the username, after an
@ sign. The proxy server then fakes
the real server. For example, assuming you want to install from
ftp.FreeBSD.org, using the proxy FTP
server foo.example.com, listening on port
1024.In this case, you go to the options menu, set the FTP username
to ftp@ftp.FreeBSD.org, and the password to your
email address. As your installation media, you specify FTP (or
passive FTP, if the proxy supports it), and the URL
ftp://foo.example.com:1234/pub/FreeBSD.Since /pub/FreeBSD from
ftp.FreeBSD.org is proxied under
foo.example.com, you are able to install
from that machine (which will fetch the files
from ftp.FreeBSD.org as your
installation requests them).開始進行安裝到此為止,可以開始進行安裝了,這也是您避免更動到硬碟的最後機會。 User Confirmation Requested
Last Chance! Are you SURE you want to continue the installation?
If you're running this on a disk with data you wish to save then WE
STRONGLY ENCOURAGE YOU TO MAKE PROPER BACKUPS before proceeding!
We can take no responsibility for lost disk contents!
[ Yes ] No選擇 &gui.yes; 並按下
Enter以確認真的要開始安裝安裝所需時間會依據所選擇安裝的套件集(distribution)
、安裝來源以及電腦速度而有所不同。
在安裝的過程中,會有一些訊息顯示目前的安裝進度。當您看到下面的訊息表示已經安裝完成了︰ Message
Congratulations! You now have FreeBSD installed on your system.
We will now move on to the final configuration questions.
For any option you do not wish to configure, simply select No.
If you wish to re-enter this utility after the system is up, you may
do so by typing: /stand/sysinstall .
[ OK ]
[ Press enter to continue ]
- Press Enter to proceed with post-installation
- configurations.
+ 請按 Enter 鍵來進行相關的後續設定。
- Selecting &gui.no; and pressing
- Enter will abort
- the installation so no changes will be made to your system. The
- following message will appear:
+ 如果剛選的是 &gui.no; 並按下
+ Enter 鍵,那麼會中斷安裝(就不會動到你的原有系統)。
+ 接著,會出現以下訊息: Message
Installation complete with some errors. You may wish to scroll
through the debugging messages on VTY1 with the scroll-lock feature.
You can also choose "No" at the next prompt and go back into the
installation menus to retry whichever operations have failed.
[ OK ]
- This message is generated because nothing was installed.
- Pressing Enter will return to the
- Main Installation Menu to exit the installation.
+ 這段訊息乃是因為都沒裝任何東西之故,請按 Enter 以跳回主畫面。後續安裝安裝系統成功之後,可以在新裝好的 FreeBSD
重開機之前,或者是事後再透過 sysinstall
(&os; 5.2 之前版本則是 /stand/sysinstall) 然後選擇
Configure 選項以進行後續設定。
- Network Device Configuration
+ 設定網路
- If you previously configured PPP for an FTP install, this screen
- will not display and can be configured later as described
- above.
+ 如果您之前有設定用 PPP 連線透過 FTP 安裝,那麼這個畫面將不會出現;
+ 正如上面剛所說的,您可以稍後再做更改。
- For detailed information on Local Area Networks and
- configuring FreeBSD as a gateway/router refer to the
- Advanced Networking
- chapter.
+ 有關 LAN 或把 FreeBSD 設定為 gateway 或 router 請參閱使用手冊中有關
+ 網路進階運用 的章節。 User Confirmation Requested
Would you like to configure any Ethernet or SLIP/PPP network devices?
[ Yes ] No
- To configure a network device, select
- &gui.yes; and press Enter.
- Otherwise, select &gui.no; to continue.
+ 如果要設定網路卡,請選擇 &gui.yes; 然後按 Enter。
+ 否則請選 &gui.no; 以繼續。
- Selecting an Ethernet Device
+ 選擇網路卡
- Select the interface to be configured with the arrow keys and press
- Enter.
+ 用方向鍵選擇您要設定的網路卡,然後按 Enter。 User Confirmation Requested
Do you want to try IPv6 configuration of the interface?
Yes [ No ]In this private local area network, the current Internet
type protocol (IPv4) was sufficient and &gui.no;
was selected with the arrow keys and Enter
pressed.If you are connected to an existing IPv6 network
with an RA server, then choose
&gui.yes; and press Enter.
It will take several seconds to scan for RA servers. User Confirmation Requested
Do you want to try DHCP configuration of the interface?
Yes [ No ]If DHCP (Dynamic Host Configuration Protocol) is not required
select &gui.no; with the arrow keys and press
Enter.Selecting &gui.yes; will execute
dhclient, and if successful, will fill
in the network configuration information automatically. Refer to
for more information.The following Network Configuration screen shows the
configuration of the Ethernet device for a system that will act
as the gateway for a Local Area Network.Set Network Configuration for ed0Use Tab to select the information fields and
fill in appropriate information:HostThe fully-qualified hostname, such as k6-2.example.com in
this case.DomainThe name of the domain that your machine is
in, such as example.com for this case.IPv4 GatewayIP address of host forwarding packets to non-local
destinations. You must fill this in if the machine is a node
on the network. Leave this field blank
if the machine is the gateway to the Internet for the
network. The IPv4 Gateway is also known as the default
gateway or default route.Name serverIP address of your local DNS server. There is no local
DNS server on this private local area network so the IP
address of the provider's DNS server
(208.163.10.2) was used.IPv4 addressThe IP address to be used for this interface was
192.168.0.1NetmaskThe address block being used for this local area
network is a Class C block
(192.168.0.0 -
192.168.255.255).
The default netmask is for a Class C network
(255.255.255.0).Extra options to ifconfigAny interface-specific options to ifconfig
you would like to add. There were none in this case.Use Tab to select &gui.ok;
when finished and press Enter. User Confirmation Requested
Would you like to Bring Up the ed0 interface right now?
[ Yes ] NoChoosing &gui.yes; and pressing
Enter will bring
the machine up on the network and be ready for use. However,
this does not accomplish much during installation, since
the machine still needs to be rebooted.Configure Gateway User Confirmation Requested
Do you want this machine to function as a network gateway?
[ Yes ] NoIf the machine will be acting as the gateway for a local area
network and forwarding packets between other machines then select
&gui.yes; and press Enter.
If the machine is a node on a network then
select &gui.no; and press
Enter to continue.Configure Internet Services User Confirmation Requested
Do you want to configure inetd and the network services that it provides?
Yes [ No ]If &gui.no; is selected, various services
such telnetd will not be enabled. This
means that remote users will not be able to
telnet into this machine. Local users
will be still be able to access remote machines with
telnet.These services can be enabled after installation by editing
/etc/inetd.conf with your favorite text editor.
See for more information.Select &gui.yes; if you wish to
configure these services during install. An additional
confirmation will display: User Confirmation Requested
The Internet Super Server (inetd) allows a number of simple Internet
services to be enabled, including finger, ftp and telnetd. Enabling
these services may increase risk of security problems by increasing
the exposure of your system.
With this in mind, do you wish to enable inetd?
[ Yes ] NoSelect &gui.yes; to continue. User Confirmation Requested
inetd(8) relies on its configuration file, /etc/inetd.conf, to determine
which of its Internet services will be available. The default FreeBSD
inetd.conf(5) leaves all services disabled by default, so they must be
specifically enabled in the configuration file before they will
function, even once inetd(8) is enabled. Note that services for
IPv6 must be separately enabled from IPv4 services.
Select [Yes] now to invoke an editor on /etc/inetd.conf, or [No] to
use the current settings.
[ Yes ] NoSelecting &gui.yes; will allow adding
services by deleting the # at the beginning
of a line.Editing inetd.confAfter adding the desired services, pressing Esc
will display a menu which will allow exiting and saving
the changes.Anonymous FTPFTPanonymous User Confirmation Requested
Do you want to have anonymous FTP access to this machine?
Yes [ No ]Deny Anonymous FTPSelecting the default &gui.no; and pressing
Enter will still allow users who have accounts
with passwords to use FTP to access the machine.Allow Anonymous FTPAnyone can access your machine if you elect to allow
anonymous FTP connections. The security implications should be
considered before enabling this option. For more information
about security see .To allow anonymous FTP, use the arrow keys to select
&gui.yes; and press Enter.
The following screen (or similar) will display:Default Anonymous FTP ConfigurationPressing F1 will display the help:This screen allows you to configure the anonymous FTP user.
The following configuration values are editable:
UID: The user ID you wish to assign to the anonymous FTP user.
All files uploaded will be owned by this ID.
Group: Which group you wish the anonymous FTP user to be in.
Comment: String describing this user in /etc/passwd
FTP Root Directory:
Where files available for anonymous FTP will be kept.
Upload subdirectory:
Where files uploaded by anonymous FTP users will go.The ftp root directory will be put in /var
by default. If you do not have enough room there for the
anticipated FTP needs, the /usr directory
could be used by setting the FTP Root Directory to
/usr/ftp.When you are satisfied with the values, press
Enter to continue. User Confirmation Requested
Create a welcome message file for anonymous FTP users?
[ Yes ] NoIf you select &gui.yes; and press
Enter, an editor will automatically start
allowing you to edit the message.Edit the FTP Welcome MessageThis is a text editor called ee. Use the
instructions to change the message or change the message later
using a text editor of your choice. Note the file name/location
at the bottom of the editor screen.Press Esc and a pop-up menu will default
to a) leave editor. Press
Enter to exit and continue. Press
Enter again to save changes if you made
any.Configure Network File SystemNetwork File System (NFS) allows sharing of files across a
network. A machine can be configured as a server, a client, or
both. Refer to for a more information.NFS Server User Confirmation Requested
Do you want to configure this machine as an NFS server?
Yes [ No ]If there is no need for a Network File System server,
select &gui.no; and press
Enter.If &gui.yes; is chosen, a message will
pop-up indicating that the exports file must be
created. Message
Operating as an NFS server means that you must first configure an
/etc/exports file to indicate which hosts are allowed certain kinds of
access to your local filesystems.
Press [Enter] now to invoke an editor on /etc/exports
[ OK ]Press Enter to continue. A text editor will
start allowing the exports file to be created
and edited.Editing exportsUse the instructions to add the actual exported filesystems
now or later using a text editor of your choice. Note the
file name/location at the bottom of the editor screen.Press Esc and a pop-up menu will default to
a) leave editor. Press
Enter to exit and continue.NFS ClientThe NFS client allows your machine to access NFS servers. User Confirmation Requested
Do you want to configure this machine as an NFS client?
Yes [ No ]With the arrow keys, select &gui.yes;
or &gui.no; as appropriate and
press Enter.Security ProfileA security profile is a set of
configuration options that attempts to achieve the desired
ratio of security to convenience by enabling and disabling
certain programs and other settings. The more severe the
security profile, the fewer programs will be enabled by
default. This is one of the basic principles of security: do
not run anything except what you must.Please note that the security profile is just a default
setting. All programs can be enabled and disabled after you
have installed FreeBSD by editing or adding the appropriate
line(s) to /etc/rc.conf. For more
information, please see the &man.rc.conf.5; manual
page.The following table describes what each of the security
profiles does. The columns are the choices you have for a
security profile, and the rows are the program or feature that
the profile enables or disables.
Possible Security ProfilesExtremeModerate&man.sendmail.8;NOYES&man.sshd.8;NOYES&man.portmap.8;NOMAYBE
The portmapper is enabled if the machine has
been configured as an NFS client or server earlier
in the installation.NFS serverNOYES&man.securelevel.8;YES
If you choose a security profile that sets the
securelevel to Extreme or
High, you must be aware of the
implications. Please read the &man.init.8;
manual page and pay particular attention to the
meanings of the security levels, or you may have
significant trouble later!NO
User Confirmation Requested
Do you want to select a default security profile for this host (select
No for "medium" security)?
[ Yes ] NoSelecting &gui.no; and pressing
Enter will set the security profile to medium.Selecting &gui.yes; and pressing
Enter will allow selecting a different security
profile.Security Profile OptionsPress F1 to display the help. Press
Enter to return to selection menu.Use the arrow keys to choose Medium
unless your are sure that another level is required for your needs.
With &gui.ok; highlighted, press
Enter.An appropriate confirmation message will display depending on
which security setting was chosen. Message
Moderate security settings have been selected.
Sendmail and SSHd have been enabled, securelevels are
disabled, and NFS server setting have been left intact.
PLEASE NOTE that this still does not save you from having
to properly secure your system in other ways or exercise
due diligence in your administration, this simply picks
a standard set of out-of-box defaults to start with.
To change any of these settings later, edit /etc/rc.conf
[OK] Message
Extreme security settings have been selected.
Sendmail, SSHd, and NFS services have been disabled, and
securelevels have been enabled.
PLEASE NOTE that this still does not save you from having
to properly secure your system in other ways or exercise
due diligence in your administration, this simply picks
a more secure set of out-of-box defaults to start with.
To change any of these settings later, edit /etc/rc.conf
[OK]Press Enter to continue with the
post-installation configuration.The security profile is not a silver bullet! Even if
you use the extreme setting, you need to keep up with
security issues by reading an appropriate mailing
list (),
using good passwords and passphrases, and
generally adhering to good security practices. It simply
sets up the desired security to convenience ratio out of the
box.System Console SettingsThere are several options available to customize the system
console. User Confirmation Requested
Would you like to customize your system console settings?
[ Yes ] NoTo view and configure the options, select
&gui.yes; and press
Enter.System Console Configuration OptionsA commonly used option is the screen saver. Use the arrow keys
to select Saver and then press
Enter.Screen Saver OptionsSelect the desired screen saver using the arrow keys
and then press Enter. The System Console
Configuration menu will redisplay.The default time interval is 300 seconds. To change the time
interval, select Saver again. At the
Screen Saver Options menu, select Timeout
using the arrow keys and press Enter. A pop-up
menu will appear:Screen Saver TimeoutThe value can be changed, then select &gui.ok;
and press Enter to return to the System Console
Configuration menu.System Console Configuration ExitSelecting Exit and pressing
Enter will continue with the post-installation
configurations.Setting the Time ZoneSetting the time zone for your machine will allow it to
automatically correct for any regional time changes and perform
other time zone related functions properly.The example shown is for a machine located in the Eastern
time zone of the United States. Your selections will vary according
to your geographical location. User Confirmation Requested
Would you like to set this machine's time zone now?
[ Yes ] NoSelect &gui.yes; and press
Enter to set the time zone. User Confirmation Requested
Is this machine's CMOS clock set to UTC? If it is set to local time
or you don't know, please choose NO here!
Yes [ No ]Select &gui.yes;
or &gui.no; according to how the machine's
clock is configured and press Enter.Select Your RegionThe appropriate region is selected using the arrow keys
and then pressing Enter.Select Your CountrySelect the appropriate country using the arrow keys
and press Enter.Select Your Time ZoneThe appropriate time zone is selected using the arrow
keys and pressing Enter. Confirmation
Does the abbreviation 'EDT' look reasonable?
[ Yes ] NoConfirm the abbreviation for the time zone is correct.
If it looks okay, press Enter to continue with
the post-installation configuration.Linux Compatibility User Confirmation Requested
Would you like to enable Linux binary compatibility?
[ Yes ] NoSelecting &gui.yes; and pressing
Enter will allow
running Linux software on FreeBSD. The install will add
the appropriate packages for Linux compatibility.If installing by FTP, the machine will need to be connected to
the Internet. Sometimes a remote ftp site will not have all the
distributions like the Linux binary compatibility. This can
be installed later if necessary.Mouse SettingsThis option will allow you to cut and paste text in the
console and user programs with a 3-button mouse. If using a 2-button
mouse, refer to manual page, &man.moused.8;, after installation for
details on emulating the 3-button style. This example depicts a
non-USB mouse configuration (such as a PS/2 or COM port mouse): User Confirmation Requested
Does this system have a non-USB mouse attached to it?
[ Yes ] No Select &gui.yes; for a non-USB mouse or
&gui.no; for a USB mouse and press
Enter.Select Mouse Protocol TypeUse the arrow keys to select Type and
press Enter.Set Mouse ProtocolThe mouse used in this example is a PS/2 type, so the default
Auto was appropriate. To change protocol,
use the arrow keys to select another option. Ensure that &gui.ok; is
highlighted and press Enter to exit this menu.Configure Mouse PortUse the arrow keys to select Port and
press Enter.Setting the Mouse PortThis system had a PS/2 mouse, so the default
PS/2 was appropriate. To change the port,
use the arrow keys and then press Enter.Enable the Mouse DaemonLast, use the arrow keys to select
Enable, and press
Enter to enable and test the mouse
daemon.Test the Mouse DaemonMove the mouse around the screen and verify the cursor
shown responds properly. If it does, select
&gui.yes; and press Enter. If
not, the mouse has not been configured correctly — select
&gui.no; and try using different configuration
options.Select Exit with the arrow keys
and press Enter to return to continue with the
post-installation configuration.TomRhodesContributed by Configure Additional Network ServicesConfiguring network services can be a daunting
task for new users if they lack previous
knowledge in this area. Networking, including the Internet,
is critical to all modern operating systems including &os;;
as a result, it is very useful to have some understanding
&os;'s extensive networking capabilities. Doing this
during the installation will ensure users have some
understanding of the various services available to them.Network services are programs that accept input from
anywhere on the network. Every effort is made to make sure
these programs will not do anything harmful.
Unfortunately, programmers are not perfect and through time
there have been cases where bugs in network services have been
exploited by attackers to do bad things. It is important that
you only enable the network services you know that you need. If
in doubt it is best if you do not enable a network service until
you find out that you do need it. You can always enable it
later by re-running sysinstall or by
using the features provided by the
/etc/rc.conf file.Selecting the Networking option will display
a menu similar to the one below:Network Configuration Upper-levelThe first option, Interfaces, was previously covered during
the , thus this option can
safely be ignored.Selecting the AMD option adds
support for the BSD automatic mount utility.
This is usually used in conjunction with the
NFS protocol (see below)
for automatically mounting remote file systems.
No special configuration is required here.Next in line is the AMD Flags
option. When selected, a menu will pop up for you
to enter specific AMD flags.
The menu already contains a set of default options:-a /.amd_mnt -l syslog /host /etc/amd.map /net /etc/amd.mapThe option sets the default mount
location which is specified here as
/.amd_mnt. The
option specifies the default log file;
however, when syslogd is used all log
activity will be sent to the system log daemon. The
/host directory is used
to mount an exported file system from a remote
host, while /net
directory is used to mount an exported file system from an
IP address. The
/etc/amd.map file defines the default
options for AMD exports.FTPanonymousThe Anon FTP option permits anonymous
FTP connections. Select this option to
make this machine an anonymous FTP server.
Be aware of the security risks involved with this option.
Another menu will be displayed to explain the security risks
and configuration in depth.The Gateway configuration menu will set
the machine up to be a gateway as explained previously. This
can be used to unset the Gateway option if you accidentally
selected it during the installation process.The Inetd option can be used to configure
or completely disable the &man.inetd.8; daemon as discussed
above.The Mail option is used to configure the system's
default MTA or Mail Transfer Agent.
Selecting this option will bring up the following menu:Select a default MTAHere you are offered a choice as to which
MTA to install
and set as the default. An MTA is nothing
more than a mail server which delivers email to users on the
system or the Internet.Selecting Sendmail will install
the popular sendmail server which
is the &os; default. The Sendmail local option
will set sendmail to be the default
MTA, but disable its ability to receive
incoming email from the Internet. The other options here,
Postfix and
Exim act similar to
Sendmail. They both deliver
email; however, some users prefer these alternatives to the
sendmail
MTA.After selecting an MTA, or choosing
not to select an MTA, the network configuration menu will appear
with the next option being NFS client.The NFS client option will
configure the system to communicate with a server via
NFS. An NFS server
makes file systems available to other machines on the
network via the NFS protocol. If this is
a stand alone machine, this option can remain unselected.
The system may require more configuration later; see
for more
information about client and server configuration.Below that option is the NFS server
option, permitting you to set the system up as an
NFS server. This adds the required
information to start up the RPC remote
procedure call services. RPC is used to
coordinate connections between hosts and programs.Next in line is the Ntpdate option,
which deals with time synchronization. When selected, a menu
like the one below shows up:Ntpdate ConfigurationFrom this menu, select the server which is the closest
to your location. Selecting a close one will make the time
synchronization more accurate as a server further from your
location may have more connection latency.The next option is the PCNFSD selection.
This option will install the
net/pcnfsd package from
the Ports Collection. This is a useful utility which provides
NFS authentication services for systems which
are unable to provide their own, such as Microsoft's
&ms-dos; operating system.Now you must scroll down a bit to see the other
options:Network Configuration Lower-levelThe &man.rpcbind.8;, &man.rpc.statd.8;, and
&man.rpc.lockd.8; utilities are all used for Remote Procedure
Calls (RPC).
The rpcbind utility manages communication
between NFS servers and clients, and is
required for NFS servers to operate
correctly. The rpc.statd daemon interacts
with the rpc.statd daemon on other hosts to
provide status monitoring. The reported status is usually held
in the /var/db/statd.status file. The
next option listed here is the rpc.lockd
option, which, when selected, will provide file locking
services. This is usually used with
rpc.statd to monitor what hosts are
requesting locks and how frequently they request them.
While these last two options are marvelous for debugging, they
are not required for NFS servers and clients
to operate correctly.As you progress down the list the next item here is
Routed, which is the routing daemon. The
&man.routed.8; utility manages network routing tables,
discovers multicast routers, and supplies a copy of the routing
tables to any physically connected host on the network upon
request. This is mainly used for machines which act as a
gateway for the local network. When selected, a menu will be
presented requesting the default location of the utility.
The default location is already defined for you and can be
selected with the Enter key. You will then
be presented with yet another menu, this time asking for the
flags you wish to pass on to routed. The
default is and it should already appear
on the screen.Next in line is the Rwhod option which,
when selected, will start the &man.rwhod.8; daemon
during system initialization. The rwhod
utility broadcasts system messages across the network
periodically, or collects them when in consumer
mode. More information can be found in the &man.ruptime.1; and
&man.rwho.1; manual pages.The next to the last option in the list is for the
&man.sshd.8; daemon. This is the secure shell server for
OpenSSH and it is highly recommended
over the standard telnet and
FTP servers. The sshd
server is used to create a secure connection from one host to
another by using encrypted connections.Finally there is the TCP Extensions
option. This enables the TCP Extensions
defined in RFC 1323 and
RFC 1644. While on many hosts this can
speed up connections, it can also cause some connections to be
dropped. It is not recommended for servers, but may be
beneficial for stand alone machines.Now that you have configured the network services, you can
scroll up to the very top item which is Exit
and continue on to the next configuration section.Configure X ServerAs of &os; 5.3-RELEASE, the X server configuration
facility has been removed from
sysinstall, you have to install
and configure the X server after the installation of &os;.
More information regarding the installation and the
configuration of a X server can be found in . You can skip this section if you are not
installing a &os; version prior to 5.3-RELEASE.In order to use a graphical user interface such as
KDE, GNOME,
or others, the X server will need to be configured.In order to run &xfree86; as a
non root user you will need to
have x11/wrapper installed.
This is installed by default beginning with FreeBSD 4.7. For
earlier versions this can be added
from the Package Selection menu.To see whether your video card is supported, check the
&xfree86; web site. User Confirmation Requested
Would you like to configure your X server at this time?
[ Yes ] NoIt is necessary to know your monitor specifications and
video card information. Equipment damage can occur if settings
are incorrect. If you do not have this information, select
&gui.no; and perform the configuration
after installation when you have the information using
sysinstall (/stand/sysinstall
in &os; versions older than 5.2), selecting
Configure and then
XFree86. Improper configuration
of the X server at this time can leave the machine in a
frozen state. It is often advised to configure the X server
once the installation has completed.
If you have graphics card and monitor information, select
&gui.yes; and press Enter
to proceed with configuring the X server.Select Configuration Method MenuThere are several ways to configure the X server.
Use the arrow keys to select one of the methods and press
Enter. Be sure to read all instructions
carefully.The xf86cfg and
xf86cfg -textmode methods may make the screen
go dark and take a few seconds to start. Be patient.The following will illustrate the use of the
xf86config configuration tool. The
configuration choices you make will depend on the hardware in the
system so your choices will probably be different than those
shown: Message
You have configured and been running the mouse daemon.
Choose "/dev/sysmouse" as the mouse port and "SysMouse" or
"MouseSystems" as the mouse protocol in the X configuration utility.
[ OK ]
[ Press enter to continue ]This indicates that the mouse daemon previously configured has been
detected.
Press Enter to continue.Starting xf86config will display
a brief introduction:This program will create a basic XF86Config file, based on menu selections you
make.
The XF86Config file usually resides in /usr/X11R6/etc/X11 or /etc/X11. A sample
XF86Config file is supplied with XFree86; it is configured for a standard
VGA card and monitor with 640x480 resolution. This program will ask for a
pathname when it is ready to write the file.
You can either take the sample XF86Config as a base and edit it for your
configuration, or let this program produce a base XF86Config file for your
configuration and fine-tune it.
Before continuing with this program, make sure you know what video card
you have, and preferably also the chipset it uses and the amount of video
memory on your video card. SuperProbe may be able to help with this.
Press enter to continue, or ctrl-c to abort.Pressing Enter will start the mouse
configuration. Be sure to follow the instructions and use
Mouse Systems as the mouse protocol and
/dev/sysmouse as the mouse port even if
using a PS/2 mouse is shown as an illustration.First specify a mouse protocol type. Choose one from the following list:
1. Microsoft compatible (2-button protocol)
2. Mouse Systems (3-button protocol) & FreeBSD moused protocol
3. Bus Mouse
4. PS/2 Mouse
5. Logitech Mouse (serial, old type, Logitech protocol)
6. Logitech MouseMan (Microsoft compatible)
7. MM Series
8. MM HitTablet
9. Microsoft IntelliMouse
If you have a two-button mouse, it is most likely of type 1, and if you have
a three-button mouse, it can probably support both protocol 1 and 2. There are
two main varieties of the latter type: mice with a switch to select the
protocol, and mice that default to 1 and require a button to be held at
boot-time to select protocol 2. Some mice can be convinced to do 2 by sending
a special sequence to the serial port (see the ClearDTR/ClearRTS options).
Enter a protocol number: 2
You have selected a Mouse Systems protocol mouse. If your mouse is normally
in Microsoft-compatible mode, enabling the ClearDTR and ClearRTS options
may cause it to switch to Mouse Systems mode when the server starts.
Please answer the following question with either 'y' or 'n'.
Do you want to enable ClearDTR and ClearRTS? n
You have selected a three-button mouse protocol. It is recommended that you
do not enable Emulate3Buttons, unless the third button doesn't work.
Please answer the following question with either 'y' or 'n'.
Do you want to enable Emulate3Buttons? y
Now give the full device name that the mouse is connected to, for example
/dev/tty00. Just pressing enter will use the default, /dev/mouse.
On FreeBSD, the default is /dev/sysmouse.
Mouse device: /dev/sysmouseThe keyboard is the next item to be configured. A generic
101-key model is shown for illustration. Any name may be used
for the variant or simply press Enter to accept
the default value.Please select one of the following keyboard types that is the better
description of your keyboard. If nothing really matches,
choose 1 (Generic 101-key PC)
1 Generic 101-key PC
2 Generic 102-key (Intl) PC
3 Generic 104-key PC
4 Generic 105-key (Intl) PC
5 Dell 101-key PC
6 Everex STEPnote
7 Keytronic FlexPro
8 Microsoft Natural
9 Northgate OmniKey 101
10 Winbook Model XP5
11 Japanese 106-key
12 PC-98xx Series
13 Brazilian ABNT2
14 HP Internet
15 Logitech iTouch
16 Logitech Cordless Desktop Pro
17 Logitech Internet Keyboard
18 Logitech Internet Navigator Keyboard
19 Compaq Internet
20 Microsoft Natural Pro
21 Genius Comfy KB-16M
22 IBM Rapid Access
23 IBM Rapid Access II
24 Chicony Internet Keyboard
25 Dell Internet Keyboard
Enter a number to choose the keyboard.
1
Please select the layout corresponding to your keyboard
1 U.S. English
2 U.S. English w/ ISO9995-3
3 U.S. English w/ deadkeys
4 Albanian
5 Arabic
6 Armenian
7 Azerbaidjani
8 Belarusian
9 Belgian
10 Bengali
11 Brazilian
12 Bulgarian
13 Burmese
14 Canadian
15 Croatian
16 Czech
17 Czech (qwerty)
18 Danish
Enter a number to choose the country.
Press enter for the next page
1
Please enter a variant name for 'us' layout. Or just press enter
for default variant
us
Please answer the following question with either 'y' or 'n'.
Do you want to select additional XKB options (group switcher,
group indicator, etc.)? nNext, we proceed to the configuration for the monitor. Do not
exceed the ratings of your monitor. Damage could occur. If you
have any doubts, do the configuration after you have the
information.Now we want to set the specifications of the monitor. The two critical
parameters are the vertical refresh rate, which is the rate at which the
whole screen is refreshed, and most importantly the horizontal sync rate,
which is the rate at which scanlines are displayed.
The valid range for horizontal sync and vertical sync should be documented
in the manual of your monitor. If in doubt, check the monitor database
/usr/X11R6/lib/X11/doc/Monitors to see if your monitor is there.
Press enter to continue, or ctrl-c to abort.
You must indicate the horizontal sync range of your monitor. You can either
select one of the predefined ranges below that correspond to industry-
standard monitor types, or give a specific range.
It is VERY IMPORTANT that you do not specify a monitor type with a horizontal
sync range that is beyond the capabilities of your monitor. If in doubt,
choose a conservative setting.
hsync in kHz; monitor type with characteristic modes
1 31.5; Standard VGA, 640x480 @ 60 Hz
2 31.5 - 35.1; Super VGA, 800x600 @ 56 Hz
3 31.5, 35.5; 8514 Compatible, 1024x768 @ 87 Hz interlaced (no 800x600)
4 31.5, 35.15, 35.5; Super VGA, 1024x768 @ 87 Hz interlaced, 800x600 @ 56 Hz
5 31.5 - 37.9; Extended Super VGA, 800x600 @ 60 Hz, 640x480 @ 72 Hz
6 31.5 - 48.5; Non-Interlaced SVGA, 1024x768 @ 60 Hz, 800x600 @ 72 Hz
7 31.5 - 57.0; High Frequency SVGA, 1024x768 @ 70 Hz
8 31.5 - 64.3; Monitor that can do 1280x1024 @ 60 Hz
9 31.5 - 79.0; Monitor that can do 1280x1024 @ 74 Hz
10 31.5 - 82.0; Monitor that can do 1280x1024 @ 76 Hz
11 Enter your own horizontal sync range
Enter your choice (1-11): 6
You must indicate the vertical sync range of your monitor. You can either
select one of the predefined ranges below that correspond to industry-
standard monitor types, or give a specific range. For interlaced modes,
the number that counts is the high one (e.g. 87 Hz rather than 43 Hz).
1 50-70
2 50-90
3 50-100
4 40-150
5 Enter your own vertical sync range
Enter your choice: 2
You must now enter a few identification/description strings, namely an
identifier, a vendor name, and a model name. Just pressing enter will fill
in default names.
The strings are free-form, spaces are allowed.
Enter an identifier for your monitor definition: HitachiThe selection of a video card driver from a list is
next. If you pass your card on the list, continue to press
Enter and the list will repeat. Only an
excerpt from the list is shown:Now we must configure video card specific settings. At this point you can
choose to make a selection out of a database of video card definitions.
Because there can be variation in Ramdacs and clock generators even
between cards of the same model, it is not sensible to blindly copy
the settings (e.g. a Device section). For this reason, after you make a
selection, you will still be asked about the components of the card, with
the settings from the chosen database entry presented as a strong hint.
The database entries include information about the chipset, what driver to
run, the Ramdac and ClockChip, and comments that will be included in the
Device section. However, a lot of definitions only hint about what driver
to run (based on the chipset the card uses) and are untested.
If you can't find your card in the database, there's nothing to worry about.
You should only choose a database entry that is exactly the same model as
your card; choosing one that looks similar is just a bad idea (e.g. a
GemStone Snail 64 may be as different from a GemStone Snail 64+ in terms of
hardware as can be).
Do you want to look at the card database? y
288 Matrox Millennium G200 8MB mgag200
289 Matrox Millennium G200 SD 16MB mgag200
290 Matrox Millennium G200 SD 4MB mgag200
291 Matrox Millennium G200 SD 8MB mgag200
292 Matrox Millennium G400 mgag400
293 Matrox Millennium II 16MB mga2164w
294 Matrox Millennium II 4MB mga2164w
295 Matrox Millennium II 8MB mga2164w
296 Matrox Mystique mga1064sg
297 Matrox Mystique G200 16MB mgag200
298 Matrox Mystique G200 4MB mgag200
299 Matrox Mystique G200 8MB mgag200
300 Matrox Productiva G100 4MB mgag100
301 Matrox Productiva G100 8MB mgag100
302 MediaGX mediagx
303 MediaVision Proaxcel 128 ET6000
304 Mirage Z-128 ET6000
305 Miro CRYSTAL VRX Verite 1000
Enter a number to choose the corresponding card definition.
Press enter for the next page, q to continue configuration.
288
Your selected card definition:
Identifier: Matrox Millennium G200 8MB
Chipset: mgag200
Driver: mga
Do NOT probe clocks or use any Clocks line.
Press enter to continue, or ctrl-c to abort.
Now you must give information about your video card. This will be used for
the "Device" section of your video card in XF86Config.
You must indicate how much video memory you have. It is probably a good
idea to use the same approximate amount as that detected by the server you
intend to use. If you encounter problems that are due to the used server
not supporting the amount memory you have (e.g. ATI Mach64 is limited to
1024K with the SVGA server), specify the maximum amount supported by the
server.
How much video memory do you have on your video card:
1 256K
2 512K
3 1024K
4 2048K
5 4096K
6 Other
Enter your choice: 6
Amount of video memory in Kbytes: 8192
You must now enter a few identification/description strings, namely an
identifier, a vendor name, and a model name. Just pressing enter will fill
in default names (possibly from a card definition).
Your card definition is Matrox Millennium G200 8MB.
The strings are free-form, spaces are allowed.
Enter an identifier for your video card definition:Next, the video modes are set for the resolutions
desired. Typically, useful ranges are 640x480, 800x600, and 1024x768
but those are a function of video card capability, monitor size,
and eye comfort. When selecting a color depth, select the highest
mode that your card will support.For each depth, a list of modes (resolutions) is defined. The default
resolution that the server will start-up with will be the first listed
mode that can be supported by the monitor and card.
Currently it is set to:
"640x480" "800x600" "1024x768" "1280x1024" for 8-bit
"640x480" "800x600" "1024x768" "1280x1024" for 16-bit
"640x480" "800x600" "1024x768" "1280x1024" for 24-bit
Modes that cannot be supported due to monitor or clock constraints will
be automatically skipped by the server.
1 Change the modes for 8-bit (256 colors)
2 Change the modes for 16-bit (32K/64K colors)
3 Change the modes for 24-bit (24-bit color)
4 The modes are OK, continue.
Enter your choice: 2
Select modes from the following list:
1 "640x400"
2 "640x480"
3 "800x600"
4 "1024x768"
5 "1280x1024"
6 "320x200"
7 "320x240"
8 "400x300"
9 "1152x864"
a "1600x1200"
b "1800x1400"
c "512x384"
Please type the digits corresponding to the modes that you want to select.
For example, 432 selects "1024x768" "800x600" "640x480", with a
default mode of 1024x768.
Which modes? 432
You can have a virtual screen (desktop), which is screen area that is larger
than the physical screen and which is panned by moving the mouse to the edge
of the screen. If you don't want virtual desktop at a certain resolution,
you cannot have modes listed that are larger. Each color depth can have a
differently-sized virtual screen
Please answer the following question with either 'y' or 'n'.
Do you want a virtual screen that is larger than the physical screen? n
For each depth, a list of modes (resolutions) is defined. The default
resolution that the server will start-up with will be the first listed
mode that can be supported by the monitor and card.
Currently it is set to:
"640x480" "800x600" "1024x768" "1280x1024" for 8-bit
"1024x768" "800x600" "640x480" for 16-bit
"640x480" "800x600" "1024x768" "1280x1024" for 24-bit
Modes that cannot be supported due to monitor or clock constraints will
be automatically skipped by the server.
1 Change the modes for 8-bit (256 colors)
2 Change the modes for 16-bit (32K/64K colors)
3 Change the modes for 24-bit (24-bit color)
4 The modes are OK, continue.
Enter your choice: 4
Please specify which color depth you want to use by default:
1 1 bit (monochrome)
2 4 bits (16 colors)
3 8 bits (256 colors)
4 16 bits (65536 colors)
5 24 bits (16 million colors)
Enter a number to choose the default depth.
4Finally, the configuration needs to be saved. Be sure
to enter /etc/X11/XF86Config as the location
for saving the configuration.I am going to write the XF86Config file now. Make sure you don't accidently
overwrite a previously configured one.
Shall I write it to /etc/X11/XF86Config? yIf the configuration fails, you can try the configuration again
by selecting &gui.yes; when the following
message appears: User Confirmation Requested
The XFree86 configuration process seems to have
failed. Would you like to try again?
[ Yes ] NoIf you have trouble configuring &xfree86;, select
&gui.no; and press Enter
and continue with the installation process. After installation
you can use xf86cfg -textmode or
xf86config to access the command line
configuration utilities as root. There is
an additional method for configuring &xfree86; described in
. If you choose not to configure
&xfree86; at this time the next menu will be for package
selection.The default setting which allows the server to be killed
is the hotkey sequence CtrlAltBackspace. This
can be executed if something is wrong with the server settings and
prevent hardware damage.The default setting that allows video mode switching will
permit changing of the mode while running X with the hotkey
sequence
CtrlAlt+ or
CtrlAlt-.
After you have &xfree86;
running, the display can be adjusted for height, width,
or centering by using xvidtune.There are warnings that improper settings can
damage your equipment. Heed them. If in doubt, do not do
it. Instead, use the monitor controls to adjust the display for
X Window. There may be some display differences when switching
back to text mode, but it is better than damaging equipment.Read the &man.xvidtune.1; manual page before making
any adjustments.Following a successful &xfree86; configuration, it will proceed
to the selection of a default desktop.Select Default X DesktopAs of &os; 5.3-RELEASE, the X desktop selection
facility has been removed from
sysinstall, you have to configure
the X desktop after the installation of &os;. More
information regarding the installation and the configuration
of a X desktop can be found in . You
can skip this section if you are not installing a &os;
version prior to 5.3-RELEASE.There are a variety of window managers available. They range
from very basic environments to full desktop environments with a
large suite of software. Some require only minimal disk space and
low memory while others with more features require much more. The
best way to determine which is most suitable for you is to try a few
different ones. Those are available from the Ports Collection or as
packages and can be added after installation.You can select one of the popular desktops to be installed
and configured as the default desktop. This will allow you
to start it right after installation.Select Default DesktopUse the arrow keys to select a desktop and press
Enter. Installation of the selected desktop will
proceed.Install PackagesPackages are pre-compiled binaries and are a convenient
way to install software.Installation of one package is shown for purposes of
illustration. Additional packages can also be added at this
time if desired. After installation
sysinstall (/stand/sysinstall
in &os; versions older than 5.2) can be used to add additional
packages. User Confirmation Requested
The FreeBSD package collection is a collection of hundreds of
ready-to-run applications, from text editors to games to WEB servers
and more. Would you like to browse the collection now?
[ Yes ] NoSelecting &gui.yes; and pressing
Enter will be
followed by the Package Selection screens:Select Package CategoryOnly packages on the current installation media are
available for installation at any given time.All packages available will be displayed if
All is selected or you can select a
particular category. Highlight your selection with the arrow
keys and press Enter.A menu will display showing all the packages available for
the selection made:Select PackagesThe bash shell is shown selected.
Select as many as desired by highlighting the package and pressing the
Space key. A short description of each package will
appear in the lower left corner of the screen.Pressing the Tab key will toggle between the last
selected package, &gui.ok;, and &gui.cancel;.When you have finished marking the packages for installation,
press Tab once to toggle to the &gui.ok; and press
Enter to return to the Package Selection menu.The left and right arrow keys will also toggle between &gui.ok;
and &gui.cancel;. This method can also be used to select &gui.ok; and
press Enter to return to the Package Selection
menu.Install PackagesUse the Tab and arrow keys to select [ Install ]
and press Enter. You will then need to confirm
that you want to install the packages:Confirm Package InstallationSelecting &gui.ok; and pressing Enter will start
the package installation. Installing messages will appear until
completed. Make note if there are any error messages.The final configuration continues after packages are
installed. If you end up not selecting any packages, and wish
to return to the final configuration, select
Install anyways.Add Users/GroupsYou should add at least one user during the installation so
that you can use the system without being logged in as
root. The root partition is generally small
and running applications as root can quickly
fill it. A bigger danger is noted below: User Confirmation Requested
Would you like to add any initial user accounts to the system? Adding
at least one account for yourself at this stage is suggested since
working as the "root" user is dangerous (it is easy to do things which
adversely affect the entire system).
[ Yes ] NoSelect &gui.yes; and press
Enter to continue with adding a user.Select UserSelect User with the arrow keys
and press Enter.Add User InformationThe following descriptions will appear in the lower part of
the screen as the items are selected with Tab
to assist with entering the required information:Login IDThe login name of the new user (mandatory).UIDThe numerical ID for this user (leave blank for
automatic choice).GroupThe login group name for this user (leave blank for
automatic choice).PasswordThe password for this user (enter this field with
care!).Full nameThe user's full name (comment).Member groupsThe groups this user belongs to (i.e. gets access
rights for).Home directoryThe user's home directory (leave blank for
default).Login shellThe user's login shell (leave blank for
default, e.g. /bin/sh).The login shell was changed from /bin/sh to
/usr/local/bin/bash to use the
bash shell that was previously installed as
a package. Do not try to use a shell that does not exist or you will
not be able to login. The most common shell used in the
BSD-world is the C shell, which can be indicated as
/bin/tcsh.The user was also added to the wheel group
to be able to become a superuser with root
privileges.When you are satisfied, press &gui.ok; and
the User and Group Management menu will redisplay:Exit User and Group ManagementGroups can also be added at this time if specific needs
are known. Otherwise, this may be accessed through using
sysinstall (/stand/sysinstall
in &os; versions older than 5.2) after installation is
completed.When you are finished adding users, select
Exit with the arrow keys and press
Enter to continue the installation.Set the root Password Message
Now you must set the system manager's password.
This is the password you'll use to log in as "root".
[ OK ]
[ Press enter to continue ]Press Enter to set the root
password.The password will need to be typed in twice correctly. Needless to
say, make sure you have a way of finding the password if you
forget. Notice that the password you type in is not echoed, nor
are asterisks displayed.Changing local password for root.
New password :
Retype new password :The installation will continue after the password is
successfully entered.Exiting InstallIf you need to configure additional network devices or
any other configuration, you can do it at this point or
after installation with sysinstall
(/stand/sysinstall in &os; versions older
than 5.2). User Confirmation Requested
Visit the general configuration menu for a chance to set any last
options?
Yes [ No ]Select &gui.no; with the arrow keys
and press Enter to return to the Main
Installation Menu.Exit InstallSelect [X Exit Install] with the arrow
keys and press Enter. You will be asked to
confirm exiting the installation: User Confirmation Requested
Are you sure you wish to exit? The system will reboot (be sure to
remove any floppies from the drives).
[ Yes ] NoSelect &gui.yes; and remove the floppy if
booting from the floppy. The CDROM drive is locked until the machine
starts to reboot. The CDROM drive is then unlocked and the disk can
be removed from drive (quickly).The system will reboot so watch for any error messages that
may appear.FreeBSD BootupFreeBSD Bootup on the &i386;If everything went well, you will see messages scroll
off the screen and you will arrive at a login prompt. You can view
the content of the messages by pressing Scroll-Lock
and using PgUp and PgDn.
Pressing Scroll-Lock again will return
to the prompt.The entire message may not display (buffer limitation) but
it can be viewed from the command line after logging in by typing
dmesg at the prompt.Login using the username/password you set during installation
(rpratt, in this example). Avoid logging in as
root except when necessary.Typical boot messages (version information omitted):Copyright (c) 1992-2002 The FreeBSD Project.
Copyright (c) 1979, 1980, 1983, 1986, 1988, 1989, 1991, 1992, 1993, 1994
The Regents of the University of California. All rights reserved.
Timecounter "i8254" frequency 1193182 Hz
CPU: AMD-K6(tm) 3D processor (300.68-MHz 586-class CPU)
Origin = "AuthenticAMD" Id = 0x580 Stepping = 0
Features=0x8001bf<FPU,VME,DE,PSE,TSC,MSR,MCE,CX8,MMX>
AMD Features=0x80000800<SYSCALL,3DNow!>
real memory = 268435456 (262144K bytes)
config> di sn0
config> di lnc0
config> di le0
config> di ie0
config> di fe0
config> di cs0
config> di bt0
config> di aic0
config> di aha0
config> di adv0
config> q
avail memory = 256311296 (250304K bytes)
Preloaded elf kernel "kernel" at 0xc0491000.
Preloaded userconfig_script "/boot/kernel.conf" at 0xc049109c.
md0: Malloc disk
Using $PIR table, 4 entries at 0xc00fde60
npx0: <math processor> on motherboard
npx0: INT 16 interface
pcib0: <Host to PCI bridge> on motherboard
pci0: <PCI bus> on pcib0
pcib1: <VIA 82C598MVP (Apollo MVP3) PCI-PCI (AGP) bridge> at device 1.0 on pci0
pci1: <PCI bus> on pcib1
pci1: <Matrox MGA G200 AGP graphics accelerator> at 0.0 irq 11
isab0: <VIA 82C586 PCI-ISA bridge> at device 7.0 on pci0
isa0: <ISA bus> on isab0
atapci0: <VIA 82C586 ATA33 controller> port 0xe000-0xe00f at device 7.1 on pci0
ata0: at 0x1f0 irq 14 on atapci0
ata1: at 0x170 irq 15 on atapci0
uhci0: <VIA 83C572 USB controller> port 0xe400-0xe41f irq 10 at device 7.2 on pci0
usb0: <VIA 83C572 USB controller> on uhci0
usb0: USB revision 1.0
uhub0: VIA UHCI root hub, class 9/0, rev 1.00/1.00, addr 1
uhub0: 2 ports with 2 removable, self powered
chip1: <VIA 82C586B ACPI interface> at device 7.3 on pci0
ed0: <NE2000 PCI Ethernet (RealTek 8029)> port 0xe800-0xe81f irq 9 at
device 10.0 on pci0
ed0: address 52:54:05:de:73:1b, type NE2000 (16 bit)
isa0: too many dependant configs (8)
isa0: unexpected small tag 14
fdc0: <NEC 72065B or clone> at port 0x3f0-0x3f5,0x3f7 irq 6 drq 2 on isa0
fdc0: FIFO enabled, 8 bytes threshold
fd0: <1440-KB 3.5" drive> on fdc0 drive 0
atkbdc0: <keyboard controller (i8042)> at port 0x60-0x64 on isa0
atkbd0: <AT Keyboard> flags 0x1 irq 1 on atkbdc0
kbd0 at atkbd0
psm0: <PS/2 Mouse> irq 12 on atkbdc0
psm0: model Generic PS/2 mouse, device ID 0
vga0: <Generic ISA VGA> at port 0x3c0-0x3df iomem 0xa0000-0xbffff on isa0
sc0: <System console> at flags 0x1 on isa0
sc0: VGA <16 virtual consoles, flags=0x300>
sio0 at port 0x3f8-0x3ff irq 4 flags 0x10 on isa0
sio0: type 16550A
sio1 at port 0x2f8-0x2ff irq 3 on isa0
sio1: type 16550A
ppc0: <Parallel port> at port 0x378-0x37f irq 7 on isa0
ppc0: SMC-like chipset (ECP/EPP/PS2/NIBBLE) in COMPATIBLE mode
ppc0: FIFO with 16/16/15 bytes threshold
ppbus0: IEEE1284 device found /NIBBLE
Probing for PnP devices on ppbus0:
plip0: <PLIP network interface> on ppbus0
lpt0: <Printer> on ppbus0
lpt0: Interrupt-driven port
ppi0: <Parallel I/O> on ppbus0
ad0: 8063MB <IBM-DHEA-38451> [16383/16/63] at ata0-master using UDMA33
ad2: 8063MB <IBM-DHEA-38451> [16383/16/63] at ata1-master using UDMA33
acd0: CDROM <DELTA OTC-H101/ST3 F/W by OIPD> at ata0-slave using PIO4
Mounting root from ufs:/dev/ad0s1a
swapon: adding /dev/ad0s1b as swap device
Automatic boot in progress...
/dev/ad0s1a: FILESYSTEM CLEAN; SKIPPING CHECKS
/dev/ad0s1a: clean, 48752 free (552 frags, 6025 blocks, 0.9% fragmentation)
/dev/ad0s1f: FILESYSTEM CLEAN; SKIPPING CHECKS
/dev/ad0s1f: clean, 128997 free (21 frags, 16122 blocks, 0.0% fragmentation)
/dev/ad0s1g: FILESYSTEM CLEAN; SKIPPING CHECKS
/dev/ad0s1g: clean, 3036299 free (43175 frags, 374073 blocks, 1.3% fragmentation)
/dev/ad0s1e: filesystem CLEAN; SKIPPING CHECKS
/dev/ad0s1e: clean, 128193 free (17 frags, 16022 blocks, 0.0% fragmentation)
Doing initial network setup: hostname.
ed0: flags=8843<UP,BROADCAST,RUNNING,SIMPLEX,MULTICAST> mtu 1500
inet 192.168.0.1 netmask 0xffffff00 broadcast 192.168.0.255
inet6 fe80::5054::5ff::fede:731b%ed0 prefixlen 64 tentative scopeid 0x1
ether 52:54:05:de:73:1b
lo0: flags=8049<UP,LOOPBACK,RUNNING,MULTICAST> mtu 16384
inet6 fe80::1%lo0 prefixlen 64 scopeid 0x8
inet6 ::1 prefixlen 128
inet 127.0.0.1 netmask 0xff000000
Additional routing options: IP gateway=YES TCP keepalive=YES
routing daemons:.
additional daemons: syslogd.
Doing additional network setup:.
Starting final network daemons: creating ssh RSA host key
Generating public/private rsa1 key pair.
Your identification has been saved in /etc/ssh/ssh_host_key.
Your public key has been saved in /etc/ssh/ssh_host_key.pub.
The key fingerprint is:
cd:76:89:16:69:0e:d0:6e:f8:66:d0:07:26:3c:7e:2d root@k6-2.example.com
creating ssh DSA host key
Generating public/private dsa key pair.
Your identification has been saved in /etc/ssh/ssh_host_dsa_key.
Your public key has been saved in /etc/ssh/ssh_host_dsa_key.pub.
The key fingerprint is:
f9:a1:a9:47:c4:ad:f9:8d:52:b8:b8:ff:8c:ad:2d:e6 root@k6-2.example.com.
setting ELF ldconfig path: /usr/lib /usr/lib/compat /usr/X11R6/lib
/usr/local/lib
a.out ldconfig path: /usr/lib/aout /usr/lib/compat/aout /usr/X11R6/lib/aout
starting standard daemons: inetd cron sshd usbd sendmail.
Initial rc.i386 initialization:.
rc.i386 configuring syscons: blank_time screensaver moused.
Additional ABI support: linux.
Local package initialization:.
Additional TCP options:.
FreeBSD/i386 (k6-2.example.com) (ttyv0)
login: rpratt
Password:Generating the RSA and DSA keys may take some time on slower
machines. This happens only on the initial boot-up of a new
installation. Subsequent boots will be faster.If the X server has been configured and a Default Desktop
chosen, it can be started by typing startx at
the command line.Bootup of FreeBSD on the AlphaAlphaOnce the install procedure has finished, you will be
able to start FreeBSD by typing something like this to the
SRM prompt:>>>BOOT DKC0This instructs the firmware to boot the specified
disk. To make FreeBSD boot automatically in the future, use
these commands:>>>SET BOOT_OSFLAGS A>>>SET BOOT_FILE ''>>>SET BOOTDEF_DEV DKC0>>>SET AUTO_ACTION BOOTThe boot messages will be similar (but not identical) to
those produced by FreeBSD booting on the &i386;.FreeBSD ShutdownIt is important to properly shutdown the operating
system. Do not just turn off power. First, become a superuser by
typing su at the command line and entering the
root password. This will work only if the user
is a member of the wheel group.
Otherwise, login as root and use
shutdown -h now.The operating system has halted.
Please press any key to reboot.It is safe to turn off the power after the shutdown command
has been issued and the message Please press any key to reboot
appears. If any key is pressed instead of turning off the power
switch, the system will reboot.You could also use the
CtrlAltDel
key combination to reboot the system, however this is not recommended
during normal operation.支援的硬體hardwareFreeBSD currently runs on a wide variety of ISA, VLB, EISA, and PCI
bus-based PCs with Intel, AMD, Cyrix, or NexGen x86
processors, as well as a number of machines based on the Compaq Alpha
processor. Support for generic IDE or ESDI drive configurations,
various SCSI controllers, PCMCIA cards, USB devices, and network and
serial cards is also provided. FreeBSD also supports IBM's microchannel
(MCA) bus.A list of supported hardware is provided with each FreeBSD release
in the FreeBSD Hardware Notes. This document can usually be found in a
file named HARDWARE.TXT, in the top-level directory
of a CDROM or FTP distribution or in
sysinstall's documentation menu. It lists,
for a given architecture, what hardware devices are known to be
supported by each release of FreeBSD. Copies of the supported
hardware list for various releases and architectures can also be
found on the Release
Information page of the FreeBSD Web site.安裝的疑難雜症解決installationtroubleshootingThe following section covers basic installation troubleshooting,
such as common problems people have reported. There are also a few
questions and answers for people wishing to dual-boot FreeBSD with
&ms-dos;.What to Do If Something Goes WrongDue to various limitations of the PC architecture, it is
impossible for probing to be 100% reliable, however, there are a
few things you can do if it fails.Check the Hardware Notes document for your version of
FreeBSD to make sure your hardware is
supported.If your hardware is supported and you still experience
lock-ups or other problems, reset your computer, and when the
visual kernel configuration option is given, choose it. This will
allow you to go through your hardware and supply information to the
system about it. The kernel on the boot disks is configured
assuming that most hardware devices are in their factory default
configuration in terms of IRQs, IO addresses, and DMA channels. If
your hardware has been reconfigured, you will most likely need to
use the configuration editor to tell FreeBSD where to find
things.It is also possible that a probe for a device not present will
cause a later probe for another device that is present to fail. In
that case, the probes for the conflicting driver(s) should be
disabled.Some installation problems can be avoided or alleviated
by updating the firmware on various hardware components, most notably
the motherboard. The motherboard firmware may also be referred to
as BIOS and most of the motherboard or computer
manufactures have a website where the upgrades and upgrade information
may be located.Most manufacturers strongly advise against upgrading the motherboard
BIOS unless there is a good reason for doing so, which
could possibly be a critical update of sorts. The upgrade process
can go wrong, causing permanent damage to the
BIOS chip.Do not disable any drivers you will need during the
installation, such as your screen (sc0).
If the installation wedges or fails mysteriously after leaving
the configuration editor, you have probably removed or changed
something you should not have. Reboot and try again.In configuration mode, you can:List the device drivers installed in the kernel.Disable device drivers for hardware that is not present in
your system.Change IRQs, DRQs, and IO port addresses used by a device
driver.After adjusting the kernel to match your hardware
configuration, type Q to boot with the new
settings. Once the installation has completed, any changes you
made in the configuration mode will be permanent so you do not have
to reconfigure every time you boot. It is still highly likely that
you will eventually want to build a custom kernel.Dealing with Existing &ms-dos; PartitionsDOSMany users wish to install &os; on PCs inhabited by
µsoft; based operating systems. For those instances, &os; has a
utility known as FIPS. This utility can be found
in the tools directory on the install CD-ROM, or downloaded
from one of various &os; mirrors.The FIPS utility allows you to split an
existing &ms-dos; partition into two pieces, preserving the original
partition and allowing you to install onto the second free piece.
You first need to defragment your &ms-dos; partition using the &windows;
Disk Defragmenter utility (go into Explorer, right-click on
the hard drive, and choose to defrag your hard drive), or use
Norton Disk Tools. Now you can run the
FIPS utility. It will prompt you for the rest of
the information, just follow the on screen instructions. Afterwards, you can
reboot and install &os; on the new free slice. See the Distributions menu
for an estimate of how much free space you will need for the kind of
installation you want.There is also a very useful product from PowerQuest
(http://www.powerquest.com) called
&partitionmagic;. This application has far more
functionality than FIPS, and is highly recommended
if you plan to add/remove operating systems often. It does cost money, so if you
plan to install &os; and keep it installed, FIPS
will probably be fine for you.Using &ms-dos; and &windows; File SystemsAt this time, &os; does not support file systems compressed with the
Double Space™ application. Therefore the file
system will need to be uncompressed before &os; can access the data. This
can be done by running the Compression Agent
located in the Start> Programs >
System Tools menu.&os; can support &ms-dos; based file systems. This requires you use
the &man.mount.msdos.8; command (in &os; 5.X, the command is &man.mount.msdosfs.8;)
with the required parameters. The utilities most common usage is:&prompt.root; mount_msdos /dev/ad0s1 /mntIn this example, the &ms-dos; file system is located on the first partition of
the primary hard disk. Your situation may be different, check the output from
the dmesg, and mount commands. They should
produce enough information to give an idea of the partition layout.Extended &ms-dos; file systems are usually mapped after the &os;
partitions. In other words, the slice number may be higher than the ones
&os; is using. For instance, the first &ms-dos; partition may be
/dev/ad0s1, the &os; partition may be
/dev/ad0s2, with the extended &ms-dos; partition being
located on /dev/ad0s3. To some, this can be confusing
at first.NTFS partitions can also be mounted in a similar manner
using the &man.mount.ntfs.8; command.Alpha User's Questions and AnswersAlphaThis section answers some commonly asked questions about
installing FreeBSD on Alpha systems.Can I boot from the ARC or Alpha BIOS Console?ARCAlpha BIOSSRMNo. &os;, like Compaq Tru64 and VMS, will only boot
from the SRM console.Help, I have no space! Do I need to delete
everything first?Unfortunately, yes.Can I mount my Compaq Tru64 or VMS filesystems?No, not at this time.ValentinoVaschettoContributed by 進階安裝指南This section describes how to install FreeBSD in exceptional
cases.Installing FreeBSD on a System without a Monitor or
Keyboardinstallationheadless (serial console)serial consoleThis type of installation is called a headless
install, because the machine that you are trying to install
FreeBSD on either does not have a monitor attached to it, or does not
even have a VGA output. How is this possible you ask? Using a
serial console. A serial console is basically using another
machine to act as the main display and keyboard for a
system. To do this, just follow the steps to create
installation floppies, explained in .To modify these floppies to boot into a serial console, follow
these steps:Enabling the Boot Floppies to Boot into a Serial ConsolemountIf you were to boot into the floppies that you just
made, FreeBSD would boot into its normal install mode. We
want FreeBSD to boot into a serial console for our
install. To do this, you have to mount the
kern.flp floppy onto your FreeBSD
system using the &man.mount.8; command.&prompt.root; mount /dev/fd0 /mntNow that you have the floppy mounted, you must
change into the /mnt directory:&prompt.root; cd /mntHere is where you must set the floppy to boot into a
serial console. You have to make a file called
boot.config containing
/boot/loader -h. All this does is pass a flag to the bootloader to
boot into a serial console.&prompt.root; echo "/boot/loader -h" > boot.configNow that you have your floppy configured correctly,
you must unmount the floppy using the &man.umount.8;
command:&prompt.root; cd /
&prompt.root; umount /mntNow you can remove the floppy from the floppy
drive.Connecting Your Null-modem Cablenull-modem cableYou now need to connect a
null-modem cable between
the two machines. Just connect the cable to the serial
ports of the 2 machines. A normal serial cable
will not work here, you need a null-modem
cable because it has some of the wires inside crossed
over.Booting Up for the InstallIt is now time to go ahead and start the install. Put
the kern.flp floppy in the floppy
drive of the machine you are doing the headless install
on, and power on the machine.Connecting to Your Headless MachinecuNow you have to connect to that machine with
&man.cu.1;:&prompt.root; cu -l /dev/cuaa0That's it! You should now be able to control the headless machine
through your cu session. It will ask you to
put in the mfsroot.flp, and then it will come up
with a selection of what kind of terminal to use. Select the
FreeBSD color console and proceed with your install!製作安裝片為避免重覆說明,在文中所提到的「FreeBSD 光碟」,
在這裡指的是您所購買或自行燒錄的 FreeBSD CDROM 或 DVD。There may be some situations in which you need to create your own
FreeBSD installation media and/or source. This might be physical media,
such as a tape, or a source that sysinstall
can use to retrieve the files, such as a local FTP site, or an &ms-dos;
partition.For example:You have many machines connected to your local network, and one
FreeBSD disc. You want to create a local FTP site using the
contents of the FreeBSD disc, and then have your machines use this
local FTP site instead of needing to connect to the Internet.You have a FreeBSD disc, and FreeBSD does not recognize your CD/DVD
drive, but &ms-dos;/&windows; does. You want to copy the FreeBSD
installation files to a DOS partition on the same computer, and
then install FreeBSD using those files.The computer you want to install on does not have a CD/DVD
drive or a network card, but you can connect a
Laplink-style serial or parallel cable to a computer
that does.You want to create a tape that can be used to install
FreeBSD.Creating an Installation CDROMAs part of each release, the FreeBSD project makes available two
CDROM images (ISO images). These images can be written
(burned) to CDs if you have a CD writer, and then used
to install FreeBSD. If you have a CD writer, and bandwidth is cheap,
then this is the easiest way to install FreeBSD.Download the Correct ISO ImagesThe ISO images for each release can be downloaded from ftp://ftp.FreeBSD.org/pub/FreeBSD/ISO-IMAGES-arch/version or the closest mirror.
Substitute arch and
version as appropriate.That directory will normally contain the following images:
FreeBSD 4.X ISO Image Names and MeaningsFilenameContainsversion-RELEASE-arch-miniinst.isoEverything you need to install FreeBSD.version-RELEASE-arch-disc1.isoEverything you need to install FreeBSD, and as many
additional third party packages as would fit on the
disc.version-RELEASE-arch-disc2.isoA live filesystem, which is used in
conjunction with the Repair facility in
sysinstall. A copy of the
FreeBSD CVS tree. As many additional third party packages
as would fit on the disc.
FreeBSD 5.X ISO Image Names and MeaningsFilenameContainsversion-RELEASE-arch-bootonly.isoEverything you need to boot into a FreeBSD
kernel and start the installation interface.
The installable files have to be pulled over FTP
or some other supported source.version-RELEASE-arch-miniinst.isoEverything you need to install FreeBSD.version-RELEASE-arch-disc1.isoEverything you need to install &os; and a
live filesystem, which is used in
conjunction with the Repair facility
in sysinstall.version-RELEASE-arch-disc2.iso&os; documentation and as many third party packages as
would fit on the disc.
You must download one of either the miniinst
ISO image, or the image of disc one. Do not download both of them,
since the disc one image contains everything that the miniinst ISO
image contains.The miniinst ISO image is only available for releases prior
to 5.4-RELEASE.Use the miniinst ISO if Internet access is cheap for you. It will
let you install FreeBSD, and you can then install third party
packages by downloading them using the ports/packages system (see
) as
necessary.Use the image of disc one if you want to install a
&os; 4.X release and want
a reasonable selection of third party packages on the disc
as well.The additional disc images are useful, but not essential,
especially if you have high-speed access to the Internet.Write the CDsYou must then write the CD images to disc. If you will be
doing this on another FreeBSD system then see
for more information (in
particular, and
).If you will be doing this on another platform then you will
need to use whatever utilities exist to control your CD writer on
that platform. The images provided are in the standard ISO format,
which many CD writing applications support.If you are interested in building a customized
release of FreeBSD, please see the Release Engineering
Article.Creating a Local FTP Site with a FreeBSD DiscinstallationnetworkFTPFreeBSD discs are laid out in the same way as the FTP site. This
makes it very easy for you to create a local FTP site that can be used
by other machines on your network when installing FreeBSD.On the FreeBSD computer that will host the FTP site, ensure
that the CDROM is in the drive, and mounted on
/cdrom.&prompt.root; mount /cdromCreate an account for anonymous FTP in
/etc/passwd. Do this by editing
/etc/passwd using &man.vipw.8; and adding
this line:ftp:*:99:99::0:0:FTP:/cdrom:/nonexistentEnsure that the FTP service is enabled in
/etc/inetd.conf.Anyone with network connectivity to your machine can now
chose a media type of FTP and type in
ftp://your machine
after picking Other in the FTP sites menu during
the install.If the boot media (floppy disks, usually) for your FTP
clients is not precisely the same version as that provided
by the local FTP site, then sysinstall will not let you
complete the installation. If the versions are not similar and
you want to override this, you must go into the Options menu
and change distribution name to
any.This approach is OK for a machine that is on your local network,
and that is protected by your firewall. Offering up FTP services to
other machines over the Internet (and not your local network)
exposes your computer to the attention of crackers and other
undesirables. We strongly recommend that you follow good security
practices if you do this.Creating Installation FloppiesinstallationfloppiesIf you must install from floppy disk (which we suggest you
do not do), either due to unsupported
hardware or simply because you insist on doing things the hard
way, you must first prepare some floppies for the installation.At a minimum, you will need as many 1.44 MB or 1.2 MB floppies
as it takes to hold all the files in the
bin (binary distribution) directory. If
you are preparing the floppies from DOS, then they
must be formatted using the &ms-dos;
FORMAT command. If you are using &windows;,
use Explorer to format the disks (right-click on the
A: drive, and select Format).Do not trust factory pre-formatted
floppies. Format them again yourself, just to be sure. Many
problems reported by our users in the past have resulted from
the use of improperly formatted media, which is why we are
making a point of it now.If you are creating the floppies on another FreeBSD machine,
a format is still not a bad idea, though you do not need to put
a DOS filesystem on each floppy. You can use the
disklabel and newfs
commands to put a UFS filesystem on them instead, as the
following sequence of commands (for a 3.5" 1.44 MB floppy)
illustrates:&prompt.root; fdformat -f 1440 fd0.1440
&prompt.root; disklabel -w -r fd0.1440 floppy3
&prompt.root; newfs -t 2 -u 18 -l 1 -i 65536 /dev/fd0Use fd0.1200 and
floppy5 for 5.25" 1.2 MB disks.Then you can mount and write to them like any other
filesystem.After you have formatted the floppies, you will need to copy
the files to them. The distribution files are split into chunks
conveniently sized so that five of them will fit on a conventional
1.44 MB floppy. Go through all your floppies, packing as many
files as will fit on each one, until you have all of the
distributions you want packed up in this fashion. Each
distribution should go into a subdirectory on the floppy, e.g.:
a:\bin\bin.aa,
a:\bin\bin.ab, and so on.Once you come to the Media screen during the install
process, select Floppy and you
will be prompted for the rest.Installing from an &ms-dos; Partitioninstallationfrom MS-DOSTo prepare for an installation from an &ms-dos; partition,
copy the files from the distribution into a directory
called freebsd in the root directory of the
partition. For example, c:\freebsd. The
directory structure of the CDROM or FTP site must be partially
reproduced within this directory, so we suggest using the DOS
xcopy command if you are copying it from a CD.
For example, to prepare for a minimal installation of
FreeBSD:C:\>md c:\freebsdC:\>xcopy e:\bin c:\freebsd\bin\ /sC:\>xcopy e:\manpages c:\freebsd\manpages\ /sAssuming that C: is where you have
free space and E: is where your CDROM
is mounted.If you do not have a CDROM drive, you can download the
distribution from ftp.FreeBSD.org.
Each distribution is in its own directory; for example, the
base distribution can be found in the &rel.current;/base/
directory.In the 4.X and older releases of &os; the base
distribution is called bin. Adjust the sample
commands and URLs above accordingly, if you are using one of these
versions.For as many distributions you wish to install from an &ms-dos;
partition (and you have the free space for), install each one
under c:\freebsd — the
BIN distribution is the only one required for
a minimum installation.Creating an Installation Tapeinstallationfrom QIC/SCSI TapeInstalling from tape is probably the easiest method, short
of an online FTP install or CDROM install. The installation
program expects the files to be simply tarred onto the tape.
After getting all of the distribution files you are interested
in, simply tar them onto the tape:&prompt.root; cd /freebsd/distdir
&prompt.root; tar cvf /dev/rwt0 dist1 ... dist2When you perform the installation, you should make
sure that you leave enough room in some temporary directory
(which you will be allowed to choose) to accommodate the
full contents of the tape you have created.
Due to the non-random access nature of tapes, this method of
installation requires quite a bit of temporary storage.When starting the installation, the tape must be in the
drive before booting from the boot
floppy. The installation probe may otherwise fail to find
it.Before Installing over a Networkinstallationnetworkserial (SLIP or PPP)installationnetworkparallel (PLIP)installationnetworkEthernetThere are three types of network installations available.
Serial port (SLIP or PPP), Parallel port (PLIP (laplink cable)),
or Ethernet (a standard Ethernet controller (includes some
PCMCIA)).The SLIP support is rather primitive, and limited primarily
to hard-wired links, such as a serial cable running between a
laptop computer and another computer. The link should be
hard-wired as the SLIP installation does not currently offer a
dialing capability; that facility is provided with the PPP
utility, which should be used in preference to SLIP whenever
possible.If you are using a modem, then PPP is almost certainly
your only choice. Make sure that you have your service
provider's information handy as you will need to know it fairly
early in the installation process.If you use PAP or CHAP to connect your ISP (in other words, if
you can connect to the ISP in &windows; without using a script), then
all you will need to do is type in dial at the
ppp prompt. Otherwise, you will need to
know how to dial your ISP using the AT commands
specific to your modem, as the PPP dialer provides only a very
simple terminal emulator. Please refer to the user-ppp handbook and FAQ entries for further information.
If you have problems, logging can be directed to the screen using
the command set log local ....If a hard-wired connection to another FreeBSD (2.0-R or
later) machine is available, you might also consider installing
over a laplink parallel port cable. The data rate
over the parallel port is much higher than what is typically
possible over a serial line (up to 50 kbytes/sec), thus resulting
in a quicker installation.Finally, for the fastest possible network installation, an
Ethernet adapter is always a good choice! FreeBSD supports most
common PC Ethernet cards; a table of supported cards (and their
required settings) is provided in the Hardware Notes for each
release of FreeBSD. If you are using one of the supported PCMCIA
Ethernet cards, also be sure that it is plugged in
before the laptop is powered on! FreeBSD does
not, unfortunately, currently support hot insertion of PCMCIA cards
during installation.You will also need to know your IP address on the network,
the netmask value for your address class, and the name of your
machine. If you are installing over a PPP connection and do not
have a static IP, fear not, the IP address can be dynamically
assigned by your ISP. Your system administrator can tell you
which values to use for your particular network setup. If you
will be referring to other hosts by name rather than IP address,
you will also need a name server and possibly the address of a
gateway (if you are using PPP, it is your provider's IP address)
to use in talking to it. If you want to install by FTP via a
HTTP proxy, you will also need the proxy's address.
If you do not know the answers to all or most of these questions,
then you should really probably talk to your system administrator
or ISP before trying this type of
installation.Before Installing via NFSinstallationnetworkNFSThe NFS installation is fairly straight-forward. Simply
copy the FreeBSD distribution files you want onto an NFS server
and then point the NFS media selection at it.If this server supports only privileged port
(as is generally the default for Sun workstations), you will
need to set the option NFS Secure in the
Options menu before installation can proceed.If you have a poor quality Ethernet card which suffers
from very slow transfer rates, you may also wish to toggle the
NFS Slow flag.In order for NFS installation to work, the server must
support subdir mounts, for example, if your FreeBSD &rel.current; distribution
directory lives on:
ziggy:/usr/archive/stuff/FreeBSD, then
ziggy will have to allow the direct mounting
of /usr/archive/stuff/FreeBSD, not just
/usr or
/usr/archive/stuff.In FreeBSD's /etc/exports file, this
is controlled by the options. Other NFS
servers may have different conventions. If you are getting
permission denied messages from the
server, then it is likely that you do not have this enabled
properly.
diff --git a/zh_TW.Big5/books/handbook/introduction/chapter.sgml b/zh_TW.Big5/books/handbook/introduction/chapter.sgml
index 3f0c083c59..d2ccd9ed9a 100644
--- a/zh_TW.Big5/books/handbook/introduction/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/introduction/chapter.sgml
@@ -1,825 +1,826 @@
JimMockRestructured, reorganized, and parts
rewritten by 簡介概述非常感謝您對 FreeBSD 感興趣!以下章節涵蓋 FreeBSD
計劃的各方面:比如它的歷史、目標、開發模式等等。讀完這章,您將了解︰FreeBSD 與其他 OS 之間的關係;
- FreeBSD 計劃的歷史淵源;
+ FreeBSD 計劃的歷史源流;FreeBSD 計劃的目標;FreeBSD open-source 開發模式的基礎概念;當然囉,還有 FreeBSD 這名字的緣故。Welcome to FreeBSD!4.4BSD-LiteFreeBSD 是一個從 4.4BSD-Lite 衍生出而能在以 Intel (x86 and &itanium;),
AMD64, Alpha, Sun &ultrasparc;
為基礎的電腦上執行的作業系統。同時,移植到其他平台的工作也在進行中。
- 對於本計劃歷史的介紹,請看 FreeBSD 歷史淵源,
+ 對於本計劃歷史的介紹,請看 FreeBSD 歷史源流,
對於 FreeBSD 的最新版本介紹,請看 current release
。若打算對於 FreeBSD 計劃有所貢獻的話(像是程式碼硬體設備,資金),
請看 如何對 FreeBSD
有貢獻。FreeBSD 能做什麼?FreeBSD 提供給你許多先進功能。這些功能包括:先佔式多工(preemptive multitasking)動態優先權調整的『先佔式多工』能夠確保,即使在系統負擔很重的情況下,
程式執行平順並且應用程式與使用者公平地共享資源。支援多人共用『多人共用(multi-user)』代表著許多人可以同時使用一個 FreeBSD 系統來處理各自的事務。
系統的硬體周邊(如印表機及磁帶機)也可以讓所有的使用者適當地分享。
也可以針對各別使用者或一群使用者的系統資源,予以設限,
以保護系統不致被過度使用。TCP/IP 網路功能好用的『TCP/IP 網路功能』可支援許多業界標準,比如:SLIP、PPP、NFS、DHCP
和 NIS 的支援,也就是說 FreeBSD 可以容易地跟其他作業系統透過網路共同運作,
或是當作企業的伺服器用途,例如提供遠端檔案共享(NFS)及電子郵件(email)等服務,
或是讓您的企業連上網際網路(Internet)並提供 WWW、FTP、路由(routing)
、及防火牆(firewall、security) 等必備服務。記憶體保護『記憶體保護(Memory protection)』能確保程式(或是使用者)不會互相干擾,
即使任何程式有不正常的運作,都不會影響其他程式的執行。FreeBSD 是『32位元(32-bit)』的作業系統
(在 Alpha、&itanium;、 AMD64 及 &ultrasparc; 上則是『64位元(64-bit)』)
— 打從一開始便是這樣設計的。X Window SystemXFree86業界標準的『X Window 系統』(X11R6)可以在常見的便宜 VGA 顯示卡/螢幕,
提供了圖形化的使用者介面(GUI),並且包括了完整的原始程式碼。binary compatibilityLinuxbinary compatibilitySCObinary compatibilitySVR4binary compatibilityBSD/OSbinary compatibilityNetBSD能『直接執行』許多其他作業系統(比如: Linux、SCO、SVR4、BSDI 和 NetBSD)
的可執行檔。數以萬計的立即可以執行的應用程式,這些都可透過 FreeBSD
的『ports』及『packages』軟體管理機制來取得。
不再需要費心到網路上到處搜尋所需要的軟體。此外,網路上尚有可非常容易移植的數以萬計應用程式。
FreeBSD 的原始程式碼與許多常見的商業版 &unix; 系統都相容,
所以大部分的程式都只需要很少的修改(或根本不用修改)
,就可以編譯執行。virtual memory需要時才置換(demand paged) virtual memory 及
merged VM/buffer cache 的設計,
這點在系統中有用去大量記憶體的程式執行時,仍然有不錯的效率表現。Symmetric Multi-Processing (SMP)支援 CPU 的對稱多工處理(SMP):可以支援多 CPU
的電腦系統。compilersCcompilersC++compilersFORTRAN
- 完全相容的 C、C++、
- Fortran 和 Perl 開發工具及環境。
+ 完全相容的 C、C++ 以及
+ Fortran 的環境和其他開發工具。
以及其他許多可供進階研發的程式語言也收集在 ports 和 packages。
source code整個系統都有『原始程式碼』,
這讓你對作業環境擁有最完全的掌握度。
既然能擁有完全開放的系統,何苦被特定封閉軟體所約束,任廠商擺佈呢?
廣泛且豐富的『線上文件』。當然囉,還不止如此!4.4BSD-LiteComputer Systems Research Group (CSRG)U.C. BerkeleyFreeBSD 系統乃是基於美國加州大學柏克萊分校的電腦系統研究群
(Computer Systems Research Group 也就是 CSRG) 所發行的
4.4BSD-Lite,以及基於 BSD 系統開發的優良傳統。
除了由 CSRG 所提供的高品質的成果,
為了提供可處理真正具負荷的工作,
FreeBSD 計劃也投入了數千小時以上的細部調整,
以能獲得最好的執行效率以及系統的穩定度。
正當許多商業上的巨人正努力地希望能提供效能及穩定時,
FreeBSD 已經具備這樣的特質 -- 就是現在!
FreeBSD 的運用範圍無限,其實完全限制在你的想像力上。
從軟體的開發到工廠自動化,或是人造衛星上面的天線的方位角度的遠端控制;
這些功能若可以用商用的 Unix 產品來達成,
那麼極有可能使用 FreeBSD 也能辦到!
FreeBSD 也受益於來自於全球各研究中心及大學所開發的數千個高品質的軟體
,這些通常只需要花費很少的費用或根本就是免費的。
當然也有商業軟體,而且出現的數目是與日俱增。由於每個人都可以取得 FreeBSD 的原始程式碼,
這個系統可以被調整而能執行任何原本完全無法想像的功能或計劃,
而對於從各廠商取得的作業系統通常沒有辦法這樣地被修改。
以下提供一些人們使用 FreeBSD 的例子:網路服務: FreeBSD
內建強勁的網路功能使它成為網路服務(如下例)的理想平台:FTP servers檔案伺服器(FTP servers)web servers全球資訊網伺服器(WWW servers)
(標準的或更安全的 SSL 連線)firewallIP masquerading防火牆以及 NAT (IP masquerading)
gateways。electronic mail電子郵件伺服器(Electronic Mail servers)USENET網路新聞伺服器(USENET News)
或是電子佈告欄系統(BBS)還有更多...有了 FreeBSD,您可以容易地先用便宜的 386 PC,
再逐步升級您的機器到四個 CPU 的 Xeon
並使用磁碟陣列(RAID)來滿足您企業運用上的需求。教育:
如果你是資訊或相關工程領域的學生,再也沒有比使用 FreeBSD
能學到更多作業系統、計算機結構、及網路的方法了。
另外如果你想利用電腦來處理一些其他的
工作,還有一些如 CAD、
數學運算以及圖形處理軟體等可以免費地取得使用。研究:有了完整的原始程式碼,FreeBSD
是研究作業系統及電腦科學的極佳環境。
具有免費且自由取得特性的 FreeBSD
也使得一個分置兩地的合作計劃,不必擔心版權及系統開放性的問題,
而能自在的交流。routerDNS Server網路:
你如果需要 router、Name Server (DNS) 或安全的防火牆(Firewall),
FreeBSD 可以輕易的將你沒有用到的 386 或 486 PC
變身成為絕佳的伺服器,甚至具有過濾封包(packet-filter) 的功能。
X Window SystemXFree86X Window SystemAccelerated-XX 視窗工作站: FreeBSD 是 X
終端機的良策,你可以使用免費的 X11 Server 或是由
Xi Graphics 所提供的商業版 X Server。
FreeBSD 不但可以充當遠端 X 程式終端機,
也可以執行本地的 X 程式而減輕大型工作站的負荷。
如果有一台中央伺服器的話,FreeBSD 甚至可以經由網路開機
(不需硬碟,也就是diskless)
,而變成更便宜且易於管理的工作站。GNU Compiler Collection軟體開發:
基本安裝的 FreeBSD 就包含了完整的程式開發工具,如 GNU C/C++
編譯器及除錯器。你可以經由燒錄 CDROM、DVD 或是從 FTP 站上抓回 FreeBSD --
包括立即可執行的系統以及系統的完整程式碼。
詳情請參閱 取得 FreeBSD。誰在用 FreeBSD?userslarge sites running FreeBSD許多 Internet 上的大型網站都是以 FreeBSD 作為它的作業系統,例如:Yahoo!Yahoo!ApacheApacheBlue Mountain ArtsBlue Mountain
ArtsPair NetworksPair
NetworksSony JapanSony
JapanNetcraftNetcraftWeathernewsWeathernewsSupervaluSupervaluTELEHOUSE AmericaTELEHOUSE
AmericaSophos Anti-VirusSophos
Anti-VirusJMA WiredJMA Wired以及許多其他的網站。關於 FreeBSD 計劃
- 接下來講的是 FreeBSD 計劃的背景,包含歷史淵源的簡介、計劃的目標,以及開發的模式。
+ 接下來講的是 FreeBSD 計劃的背景,包含歷史源流的簡介、計劃的目標,以及開發的模式。JordanHubbardContributed by
- FreeBSD 歷史淵源的簡介
+ FreeBSD 歷史源流的簡介386BSD PatchkitHubbard, JordanWilliams, NateGrimes, RodFreeBSD ProjecthistoryFreeBSD 計畫的想法是在 1993 年初所形成的,
那是源自於維護一組 『非官方 386BSD 的 patchkit(修正工具)』計劃的三個協調維護人
Nate Williams,Rod Grimes 和我(Jordan Hubbard)。386BSD我們最初的目標是做出一份 386BSD 綜合修正的 snapshot 版,以便修正當時一堆
patchkit 都不容易解決的問題。有些人可能還記得早期的計劃名稱叫做
386BSD 0.5 或 386BSD Interim 就是這個原因。Jolitz, Bill386BSD 是 Bill Jolitz 的作業系統,在當時就已有約一年的分裂討論。
當該修正工具 (patchkit) 日漸龐雜得令人不舒服,我們無異議地同意要作一些事了,
並決定提供一份臨時性的 淨化版(cleanup) 來幫助 Bill。
然而,由於 Bill Jolitz 忽然決定取消其對該計劃的認可,且沒有明確指出未來的打算,
所以該計劃便突然面臨斷炊危機。Greenman, DavidWalnut Creek CDROM不久我們便決定在即使沒有 Bill 的支持下,讓該計劃仍然繼續下去,
最後我們採用 David Greenman 丟銅板決定的名字,也就是『FreeBSD』。
在詢問了當時的一些使用者意見之後,就開始決定了最初的目標,
當該計劃開始實施一切就要成真時,一切就變得更清楚了。
我跟 Walnut Creek CDROM 討論發行 CDROM
這樣子不便上網的人就可以用比較簡單的方式取得 FreeBSD。
Walnut Creek CDROM 不只贊成以 CDROM 來發行 FreeBSD
的想法,同時提供了一台機器以及快速的網際網路的頻寬。
如果不是 Walnut Creek CDROM 幾乎是空前的信任這個剛開始還是完全默默無聞的計劃,
那麼很可能 FreeBSD 不會如此快速的成長到今日這樣的規模。4.3BSD-LiteNet/2U.C. Berkeley386BSDFree Software Foundation第一張以 CDROM (及網路)發行的 FreeBSD 1.0 是在 1993 年十二月。
該版本是基於由 U.C. Berkeley 以磁帶方式發行的
4.3BSD-Lite (Net/2)以及許多來自於 386BSD
和自由軟體基金會的軟體。對於第一次發行而言還算成功,
我們又接著於 1994 年 5 月發行了相當成功的 FreeBSD 1.1。NovellU.C. BerkeleyNet/2AT&T然而此後不久,另一個意外的風暴在 Novell 和 U.C. Berkeley 關於
Berkeley Net/2 磁帶之法律地位的訴訟確定之後形成。
U.C. Berkeley 接受大部份的 Net/2 的程式碼都是『侵佔來的』且是屬於 Novell 的財產
-- 事實上是當時不久前從 AT&T 取得的。
Berkeley 得到的是 Novell 對於 4.4BSD-Lite 的『祝福』,最後當 4.4BSD-Lite
終於發行之後,便不再是侵佔行為。
而所有現有 Net/2 使用者都被強烈建議更換新版本,這包括了 FreeBSD。
於是,我們被要求於 1994 年 6 月底前停止散佈基於 Net/2
的產品。在此前提之下,本計劃被允許在期限以前作最後一次發行,也就是
FreeBSD 1.1.5.1。FreeBSD 便開始了這宛如『重新發明輪子』的艱鉅工作 -- 從全新的且不完整的
4.4BSD-Lite 重新整合。
這個 Lite 版本是不完整的,因為
Berkeley 的 CSRG 已經刪除了大量在建立一個可以開機執行的系統所需要的程式碼
(基於若干法律上的要求),且該版本在 Intel 平台的移植是非常不完整的。
直到 1994 年 11 月本計劃才完成了這個轉移,
同時在該年 12 月底以 CDROM 以及網路的形式發行了 FreeBSD 2.0。
雖然該份版本在當時有點匆促粗糙,但仍是富有意義的成功。
隨之於 1995 年 6 月又發行了更容易安裝,更好的 FreeBSD 2.0.5。我們在 1996 年 8 月發行了 FreeBSD 2.1.5,在 ISP 和商業團體中非常流行。
隨後, 2.1-STABLE 分支的另一個版本應運而生,它就是在 1997 年 2 月發行 FreeBSD 2.1.7.1
,同時也是 2.1-STABLE 分支的最後版。之後此分支便進入維護狀態,
僅僅提供安全性的加強和其他嚴重錯誤修補的維護(RELENG_2_1_0)。1996 年 11 月 FreeBSD 2.2 從開發主軸分支 (-CURRENT)
出來成為 RELENG_2_2 分支。它的第一個完整版(2.2.1)於 1997 年 4 月發行。
2.2 分支的延續版本在 97 年夏秋之間發行的,其最後版是在 1998 年 11 月發行的 2.2.8 版。
第一個正式的 3.0 版本在 1998 年 10 月發行,亦即宣告 2.2 分支的落幕。1999/01/20 日再度分支,這產生了 4.0-CURRENT 以及 3.X-STABLE 兩個分支。
3.X-STABLE 方面,3.1 發行於 1999/02/15,3.2 發行於1999/05/15,3.3 發行於 1999/09/16,
3.4 發行於 1999/12/20,3.5 發行於 2000/06/24
,接下來幾天後發佈了一些的修補檔(對 Kerberos 安全性方面的修正),就升級至 3.5.1
,這是 3.X 分支最後一個發行版本。在 2000/03/13 又有了一個新的分支, 也就是 4.X-STABLE
。這個分支之後發佈了許多的發行版本︰ 4.0-RELEASE 在 2000 年 3 月發行,
而最後的 4.11-RELEASE 則在 2005 年 1 月發行。4-STABLE 分支的支援會持續到 2007/01/31
,但主要焦點在於安全方面的漏洞、臭蟲及其他嚴重問題的修補。期待已久的 5.0-RELEASE 在 2003/01/19 正式發行。這是將近開發三年的巔峰之作,同時
也開始加強多顆CPU(SMPng)的支援、kernel thread(KSE) 的支援、檔案系統採用 UFS2 以及支援 snapshot
等, 並支援 &ultrasparc; 和
ia64 平台、支援藍芽、32 bit 的 PCMCIA 等。之後於 2003 年 6 月發行了 5.1。
而 -CURRENT 這個發展主軸分支的最後 5.X 版本是在 2004 年 2 月正式發行的 5.2.1-RELEASE,在 5.X
系列進入 -STABLE (RELENG_5分支)之後,-CURRENT 就轉移為 6.X 系列。RELENG_5 分支於 2004 年 8 月正式開跑,之後是 5.3-RELEASE
- ,它是 5-STABLE 分支的第一個發行版本。5-STABLE 的最新發表是在 &rel2.current.date; 發行的 &rel2.current;-RELEASE,當然囉,RELENG_5 分支還將有後續的發行版。
+ ,它是 5-STABLE 分支的第一個發行版本。&rel2.current;-RELEASE 的最新發表是在 &rel2.current.date; 發行的 &rel2.current;-RELEASE,照往例 RELENG_5 分支還將有後續的發行版。
- RELENG_6 分支於 2005 年 11 月開跑,最新的 &rel.current;-RELEASE 是在 &rel.current.date; 發行。
+ RELENG_6 分支於 2005 年 7 月開跑,而 6.X 分支的第一個 release(6.0-RELEASE) 是在 2005 年 11 月出的。
+ 最新的 &rel.current;-RELEASE 是在 &rel.current.date; 發行。當然囉,RELENG_6 分支還將有後續的發行版。目前,長期的開發計畫繼續在 7.X-CURRENT (trunk) 分支中進行,而 7.X 的 CDROM
(當然,也可以用網路抓) snapshot 版本可以在 FreeBSD snapshot server
取得。JordanHubbardContributed by FreeBSD 計劃的目標FreeBSD ProjectgoalsFreeBSD 計劃的目標在於提供可作任意用途的軟體而不附帶任何限制條文。
我們之中許多人對程式碼 (以及計畫本身) 都有非常大的投入,
因此,當然不介意偶爾有一些資金上的補償,但我們並沒打算堅決地要求得到這類資助。
我們認為我們的首要『使命(mission)』是為任何人提供程式碼,
不管他們打算用這些程式碼做什麼, 因為這樣程式碼將能夠被更廣泛地使用,從而發揮其價值。
我認為這是自由軟體最基本的,同時也是我們所倡導的一個目標。GNU General Public License (GPL)GNU Lesser General Public License (LGPL)BSD Copyright我們程式碼樹中,有若干是以 GNU GPL 或者 LGPL
發佈的那些程式碼帶有少許的附加限制,還好只是強制性的要求開放程式碼而不是別的。
由於使用 GPL 的軟體在商業用途上會增加若干複雜性,因此,如果可以選擇的話,
我們會比較喜歡使用限制相對更寬鬆的 BSD 版權來發佈軟體。SatoshiAsamiContributed by FreeBSD 的開發模式FreeBSD Projectdevelopment modelFreeBSD 的開發是一個非常開放且具彈性的過程,就像從 貢獻者名單
所看到的,是由全世界上千上萬的貢獻者發展起來的。
FreeBSD 的開發基礎架構允許數以百計的開發者透過網際網路協同工作。
我們也經常關注著那些對我們的計畫感興趣的新開發者和新的創意,
那些有興趣更進一步參與計劃的人只需要在 &a.hackers; 連繫我們。
&a.announce; 對那些希望了解我們進度的人也是相當有用的。無論是單獨開發者或者封閉式的團隊合作,若能了解 FreeBSD 計劃和它的開發過程都是有用的︰The CVS repositoryCVSrepositoryConcurrent Versions SystemCVSThe central source tree for FreeBSD is maintained by
- CVS
+ CVS
(Concurrent Versions System), a freely available source code
control tool that comes bundled with FreeBSD. The primary
CVS
repository resides on a machine in Santa Clara CA, USA
from where it is replicated to numerous mirror machines
throughout the world. The CVS tree, which contains the -CURRENT and -STABLE trees,
can all be easily replicated to your own machine as well.
Please refer to the Synchronizing
your source tree section for more information on
doing this.The committers listcommittersThe committers
are the people who have write access to
the CVS tree, and are authorized to make modifications
to the FreeBSD source (the term committer
comes from the &man.cvs.1; commit
command, which is used to bring new changes into the CVS
repository). The best way of making submissions for review
by the committers list is to use the &man.send-pr.1;
command. If something appears to be jammed in the
system, then you may also reach them by sending mail to
the &a.committers;.The FreeBSD core teamcore teamFreeBSD core team
就等於董事會 -- 如果把 FreeBSD 看成是一家公司的話。
core team 的主要職責在於確保此計劃有良好的架構,以朝著正確的方向發展。
此外,邀請熱血且負責的軟體開發者加入 committers 行列,以在若干成員離去時得以補充新血。
目前的 core team 是在 2004 年 6 月 committers 候選人中選出來的,每兩年會舉辦一次選舉Some core team members also have specific areas of
responsibility, meaning that they are committed to
ensuring that some large portion of the system works as
advertised. For a complete list of FreeBSD developers
and their areas of responsibility, please see the Contributors
ListMost members of the core team are volunteers when it
comes to FreeBSD development and do not benefit from the
project financially, so commitment should
also not be misconstrued as meaning guaranteed
support. The board of directors
analogy above is not very accurate, and it may be
more suitable to say that these are the people who gave up
their lives in favor of FreeBSD against their better
judgment!Outside contributorscontributorsLast, but definitely not least, the largest group of
developers are the users themselves who provide feedback and
bug fixes to us on an almost constant basis. The primary
way of keeping in touch with FreeBSD's more non-centralized
development is to subscribe to the &a.hackers; where such
things are discussed. See for more information about
the various FreeBSD mailing lists.The
FreeBSD Contributors List is a long
and growing one, so why not join it by contributing
something back to FreeBSD today?Providing code is not the only way of contributing to
the project; for a more complete list of things that need
doing, please refer to the FreeBSD Project web
site.In summary, our development model is organized as a loose set
of concentric circles. The centralized model is designed for the
convenience of the users of FreeBSD, who are
provided with an easy way of tracking one central code
base, not to keep potential contributors out! Our desire is to
present a stable operating system with a large set of coherent
application programs that the users
can easily install and use — this model works very well in
accomplishing that.All we ask of those who would join us as FreeBSD developers is
some of the same dedication its current people have to its
continued success!最新的 FreeBSD 發行版本NetBSDOpenBSD386BSDFree Software FoundationU.C. BerkeleyComputer Systems Research Group (CSRG)FreeBSD 是免費使用且帶有完整原始程式碼的以 4.4BSD-Lite 為基礎的系統,可以在
Intel &i386;, &i486;, &pentium;,
&pentium; Pro,
&celeron;,
&pentium; II,
&pentium; III,
&pentium; 4 (或者相容型號),
&xeon;, DEC Alpha
和 Sun &ultrasparc; 為基礎的電腦上執行的作業系統。
它主要以加州大學巴爾克利分校 的 CSRG 研究小組的軟體為基礎,並加入了
NetBSD、OpenBSD、386BSD 以及自由軟體基金會的一些東西。自從 1994 年末,我們發佈了 FreeBSD 2.0 之後,系統的執行效率、
功能、穩定性都有了令人注目的提升。
最大的改變就是我們將記憶體與檔案系統的 cache 機制結合在一起。
這不只使得系統的表現變得更好, 並且使得 FreeBSD
系統最少的記憶體需求減少到 5 MB。
其它的改進包括完整的 NIS cilent and server 功能支援,
支援 transaction TCP、PPP 撥接連線、整合的 DHCP 支援、
SCSI 子系統的改進、ISDN 的支援,ATM、FDDI 以及乙太網路 (Ethernet、包括
100 Mbit 和 Gigabit) 的支援,提升了最新的 Adaptec
控制卡驅動程式的改善,以及數以千計的 bug 修正。除了最基本的系統軟體,FreeBSD 還提供了廣受歡迎的套件軟體管理機制: Ports Collection。
到本書付印時,已有超過 &os.numports; 個 ports,其中範疇包括從 http(WWW)
伺服器到遊戲、程式語言、編輯器以及您能想到的幾乎所有的東西。
完整的 Ports Collection 需要約 &ports.size; 的硬碟空間,除了
port 基本架構檔案外,都只儲存與該 port 軟體的原始碼有『須要變更』的部份。
如此一來,我們可以更容易更新這些 ports,
也大量的減少如舊的 1.0 版 Ports Collection 對於硬碟空間的需求。
要安裝一個 port 的話,只需要進入該 port 的目錄,輸入 make install
,這樣子系統就會幫你裝好了。您要編譯的每個程式的完整原始程式,
都可從 FTP 或 CDROM 中獲得,所以您只需準備足夠的硬碟空間來編譯你要的 port 軟體。
幾乎每一個 port 都有已事先編譯好的 package以方便安裝,
如果不想從編譯 port 的人,只要用個簡單指令(pkg_add)就可以安裝。
有關 packages 和 ports 的細節,可以參閱 。FreeBSD 主機的 /usr/share/doc 目錄下找到許多有用的文件,
來幫助您安裝、使用 FreeBSD。也可以使用下面的網址,以瀏覽器來翻閱本機上安裝的手冊︰FreeBSD 使用手冊/usr/share/doc/handbook/index.htmlFreeBSD 常見問答集/usr/share/doc/faq/index.html此外,可在下列網址找到最新版 (也是更新最頻繁的版本):。
diff --git a/zh_TW.Big5/books/handbook/kernelconfig/chapter.sgml b/zh_TW.Big5/books/handbook/kernelconfig/chapter.sgml
index f81768c10d..5615d71d15 100644
--- a/zh_TW.Big5/books/handbook/kernelconfig/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/kernelconfig/chapter.sgml
@@ -1,1694 +1,1669 @@
JimMock
- Updated and restructured by
+ 更新、重排:JakeHamby
- Originally contributed by
+ 原作為:
- Configuring the FreeBSD Kernel
+ 設定 FreeBSD Kernel
- Synopsis
+ 概述kernelbuilding a custom kernel
- The kernel is the core of the &os; operating system. It is
- responsible for managing memory, enforcing security controls,
- networking, disk access, and much more. While more and more of &os;
- becomes dynamically configurable it is still occasionally necessary to
- reconfigure and recompile your kernel.
+ kernel 是整個 &os; 作業系統的核心。
+ 它控制了系統的整體運作,包含和記憶體管理、安全控管、網路、硬碟存取等等。
+ 儘管目前 &os; 大多可以用動態 module 來載入、卸載所需功能,但有時候仍有必要學會重新調配 kernel。
- After reading this chapter, you will know:
+ 讀完這章,您將了解︰
- Why you might need to build a custom kernel.
+ 為何需要重新調配、編譯 kernel?
- How to write a kernel configuration file, or alter an existing
- configuration file.
+ 要怎麼修改 kernel 設定檔?
- How to use the kernel configuration file to create and build a
- new kernel.
+ 如何以 kernel 設定檔來建立、編譯新的 kernel 呢?
- How to install the new kernel.
+ 如何安裝新的 kernel。
- How to create any entries in /dev that may
- be required.
+ 如何在 /dev 下來安裝新的硬體。
- How to troubleshoot if things go wrong.
+ 如何處理 kernel 錯誤無法開機的情形。
- All of the commands listed within this chapter by way of example
- should be executed as root in order to
- succeed.
+ 本章所舉例的相關指令都是以 root 權限來進行。
- Why Build a Custom Kernel?
-
- Traditionally, &os; has had what is called a
- monolithic kernel. This means that the kernel was one
- large program, supported a fixed list of devices, and if you wanted to
- change the kernel's behavior then you had to compile a new kernel, and
- then reboot your computer with the new kernel.
-
- Today, &os; is rapidly moving to a model where much of the
- kernel's functionality is contained in modules which can be
- dynamically loaded and unloaded from the kernel as necessary.
- This allows the kernel to adapt to new hardware suddenly
- becoming available (such as PCMCIA cards in a laptop), or for
- new functionality to be brought into the kernel that was not
- necessary when the kernel was originally compiled. This is
- known as a modular kernel.
-
- Despite this, it is still necessary to carry out some static kernel
- configuration. In some cases this is because the functionality is so
- tied to the kernel that it can not be made dynamically loadable. In
- others it may simply be because no one has yet taken the time to write a
- dynamic loadable kernel module for that functionality.
-
- Building a custom kernel is one of the most important rites of
- passage nearly every BSD user must endure. This process, while
- time consuming, will provide many benefits to your &os; system.
- Unlike the GENERIC kernel, which must support a
- wide range of hardware, a custom kernel only contains support for
- your PC's hardware. This has a number of
- benefits, such as:
+ 為何需要重新調配、編譯 kernel?
+
+ 早期的 &os; 的 kernel 被戲稱為 monolithic kernel。
+ 這意思是說當時的 kernel 是個大塊頭程式,且只支援固定的硬體而已。
+ 如果您想改變 kernel 的設定,那麼必須編譯一個新的並重新開機,才能啟用。
+
+ 現在的 &os; 已快速成長到新型態的管理模式,其重要特色是:
+ kernel 功能可以隨時依據需求,而以動態載入或卸載相關的 kernel module。
+ 這使得 kernel 能夠快速因應新的環境而作調整(有點像是:筆記型電腦上的 PCMCIA 卡一樣即插即用)
+ ,或是增加其他原本的預設 kernel(GENERIC) 所沒有的功能。
+ 這種模式,就叫做 modular kernel(核心模組)。
+
+ 儘管如此,還是有一些功能仍須編譯在 kernel 內才行。因為有時候是因為這些功能與 kernel
+ 結合的相當複雜緊密,而無法將它們弄成可動態載入的 module
+ ;而有時候,則是因為沒有人有空來弄那些 kernel module 的實作。
+
+ 重新調配、編譯 kernel 幾乎是每位 BSD 使用者所必須經歷的過程。
+ 儘管這項工作可能比較耗時,但在 &os; 的使用上會有許多好處。
+ 跟必須支援大多數各式硬體的 GENERIC kernel 相比的話,自行調配 kernel 不同處在於:可以更『體貼』,只支援『自己硬體』的部分就好。
+ 好處在於,譬如︰
- Faster boot time. Since the kernel will only probe the
- hardware you have on your system, the time it takes your system to
- boot can decrease dramatically.
+ 開機速度更快:因為自行調配的 kernel 只需要偵測您系統上的硬體,所以讓啟動所花的過程更流暢快速。
- Lower memory usage. A custom kernel often uses less memory
- than the GENERIC kernel, which is important
- because the kernel must always be present in real
- memory. For this reason, a custom kernel is especially useful
- on a system with a small amount of RAM.
+ 佔用的記憶體更少:自行調配的 kernel 通常會比 GENERIC 核心使用更少的記憶體,
+ 由於 kernel 必須一直存放在記憶體內,因此這就顯得更加重要。因此,對於記憶體較小的系統來說,自行調配的 kernel 就可發揮更多的作用、揮灑空間。
- Additional hardware support. A custom kernel allows you to
- add in support for devices which are not
- present in the GENERIC kernel, such as
- sound cards.
+ 可支援更多硬體:您可在自行調配的 kernel 增加一些原本 GENERIC 核心沒有提供的硬體支援,像是音效卡之類的。
- Building and Installing a Custom Kernel
+ 重新調配、編譯 kernelkernelbuilding / installingFirst, let us take a quick tour of the kernel build directory.
All directories mentioned will be relative to the main
/usr/src/sys directory, which is also
accessible through the path name /sys. There are a number of
subdirectories here representing different parts of the kernel, but
the most important for our purposes are
arch/conf, where you
will edit your custom kernel configuration, and
compile, which is the staging area where your
kernel will be built. arch represents
one of i386, alpha,
amd64, ia64,
powerpc, sparc64, or
pc98 (an alternative development branch of PC
hardware, popular in Japan). Everything inside a particular
architecture's directory deals with that architecture only; the rest
of the code is machine independent code common to all platforms to which &os; could
potentially be ported. Notice the logical organization of the
directory structure, with each supported device, file system, and
option in its own subdirectory. Versions of &os; prior to 5.X
support only the i386, alpha
and pc98 architectures.This chapter assumes that you are using the i386 architecture
in the examples. If this is not the case for your situation,
make appropriate adjustments to the path names for your system's
architecture.If there is not a
/usr/src/sys directory on your system,
then the kernel source has not been installed. The easiest
way to do this is by running
sysinstall (/stand/sysinstall
in &os; versions older than 5.2) as
root, choosing
Configure, then
Distributions, then
src, then
sys. If you have an aversion to
sysinstall and you have access to
an official &os; CDROM, then you can also
install the source from the command line:&prompt.root; mount /cdrom
&prompt.root; mkdir -p /usr/src/sys
&prompt.root; ln -s /usr/src/sys /sys
&prompt.root; cat /cdrom/src/ssys.[a-d]* | tar -xzvf -Next, move to the
arch/conf directory
and copy the GENERIC configuration file to the
name you want to give your kernel. For example:&prompt.root; cd /usr/src/sys/i386/conf
&prompt.root; cp GENERIC MYKERNELTraditionally, this name is in all capital letters and, if you
are maintaining multiple &os; machines with different hardware,
it is a good idea to name it after your machine's hostname. We will
call it MYKERNEL for the purpose of this
example.Storing your kernel configuration file directly under
/usr/src can be a bad idea. If you are
experiencing problems it can be tempting to just delete
/usr/src and start again. After doing this,
it usually only takes a few seconds for
you to realize that you have deleted your custom kernel
configuration file. Also, do not edit GENERIC
directly, as it may get overwritten the next time you
update your source tree, and
your kernel modifications will be lost.You might want to keep your kernel configuration file
elsewhere, and then create a symbolic link to the file in
the i386
directory.For example:&prompt.root; cd /usr/src/sys/i386/conf
&prompt.root; mkdir /root/kernels
&prompt.root; cp GENERIC /root/kernels/MYKERNEL
&prompt.root; ln -s /root/kernels/MYKERNELNow, edit MYKERNEL with your favorite text
editor. If you are just starting out, the only editor available
will probably be vi, which is too complex to
explain here, but is covered well in many books in the bibliography. However, &os; does
offer an easier editor called ee which, if
you are a beginner, should be your editor of choice. Feel free to
change the comment lines at the top to reflect your configuration or
the changes you have made to differentiate it from
GENERIC.SunOSIf you have built a kernel under &sunos; or some other BSD
operating system, much of this file will be very familiar to you.
If you are coming from some other operating system such as DOS, on
the other hand, the GENERIC configuration file
might seem overwhelming to you, so follow the descriptions in the
Configuration File
section slowly and carefully.If you sync your source tree with the
latest sources of the &os; project,
be sure to always check the file
/usr/src/UPDATING before you perform any update
steps. This file describes any important issues or areas
requiring special attention within the updated source code.
/usr/src/UPDATING always matches
your version of the &os; source, and is therefore more up to date
with new information than this handbook.You must now compile the source code for the kernel. There are two
procedures you can use to do this, and the one you will use depends on
why you are rebuilding the kernel and the version of &os; that you are
running.If you have installed only the kernel
source code, use procedure 1.If you are running a &os; version prior to 4.0, and you are
not upgrading to &os; 4.0 or higher using
the make buildworld procedure, use procedure 1.
If you are building a new kernel without updating the source
code (perhaps just to add a new option, such as
IPFIREWALL) you can use either procedure.If you are rebuilding the kernel as part of a
make buildworld process, use procedure 2.
cvsupCTMCVSanonymousIf you have not upgraded your source
tree in any way since the last time you successfully completed
a buildworld-installworld cycle
(you have not run CVSup,
CTM, or used
anoncvs), then it is safe to use the
config, make depend,
make, make install sequence.
Procedure 1. Building a Kernel the Traditional WayRun &man.config.8; to generate the kernel source code.&prompt.root; /usr/sbin/config MYKERNELChange into the build directory. &man.config.8; will print
the name of this directory after being run as above.&prompt.root; cd ../compile/MYKERNELFor &os; versions prior to 5.0, use the following form instead:&prompt.root; cd ../../compile/MYKERNELCompile the kernel.&prompt.root; make depend
&prompt.root; makeInstall the new kernel.&prompt.root; make installProcedure 2. Building a Kernel the New
WayChange to the /usr/src directory.&prompt.root; cd /usr/srcCompile the kernel.&prompt.root; make buildkernel KERNCONF=MYKERNELInstall the new kernel.&prompt.root; make installkernel KERNCONF=MYKERNELThis method of kernel building requires full source files. If you
only installed the kernel source, use the traditional method, as
described above.By default, when you build a custom kernel,
- all kernel modules also will be rebuilded.
+ all kernel modules will be rebuilt as well.
If you want to update a kernel faster or to build only custom
modules, you should edit /etc/make.conf
before starting to build the kernel:MODULES_OVERRIDE = linux acpi sound/sound sound/driver/ds1 ntfsThis variable sets up a list of modules to build instead
of all of them. For other variables which you may find useful
in the process of building kernel, refer to &man.make.conf.5;
manual page.In &os; 4.2 and older you must replace
KERNCONF= with KERNEL=.
4.2-STABLE that was fetched before Feb 2nd, 2001 does not
recognize KERNCONF=./boot/kernel.oldThe new kernel will be copied to the /boot/kernel directory as
/boot/kernel/kernel and the old kernel will be moved to
/boot/kernel.old/kernel. Now, shutdown the system and
reboot to use your new kernel. If something goes wrong, there are
some troubleshooting
instructions at the end of this chapter that you may find useful. Be sure to read the
section which explains how to recover in case your new kernel does not boot.In &os; 4.X and earlier, kernels are installed
in /kernel, modules in /modules, and old kernels
are backed up in /kernel.old.
Other files relating to the boot process, such as the boot
&man.loader.8; and configuration are stored in
/boot. Third party or custom modules
can be placed in /modules, although
users should be aware that keeping modules in sync with the
compiled kernel is very important. Modules not intended
to run with the compiled kernel may result in instability
or incorrectness.If you have added any new devices (such as sound cards)
and you are running &os; 4.X or previous versions, you
may have to add some device nodes to your
/dev directory before
you can use them. For more information, take a look at Making Device Nodes
section later on in this chapter.JoelDahlUpdated for &os; 5.X by The Configuration FilekernelNOTESkernelLINTNOTESLINTkernelconfiguration fileThe general format of a configuration file is quite simple.
Each line contains a keyword and one or more arguments. For
simplicity, most lines only contain one argument. Anything
following a # is considered a comment and
ignored. The following sections describe each keyword, in
the order they are listed in GENERIC.
For an exhaustive list of architecture
dependent options and devices, see the NOTES
file in the same directory as GENERIC. For
architecture independent options, see
/usr/src/sys/conf/NOTES.NOTES does not exist in &os; 4.X.
Instead, see the LINT file for detailed
explanations of options and devices in GENERIC.
LINT served two purposes in 4.X: to provide a
reference for choosing kernel options when building a custom
kernel, and to provide a kernel configuration with as many
tweakable options tweaked to non-default values as possible. The
reason behind this was that such a configuration helped (and still
does) a lot when testing new code and changes to existing code that
may cause conflicts with other parts of the kernel. However,
the kernel configuration framework went through some heavy changes
in 5.X; one example of this is that the driver configuration options were moved
to a hints file so that they could be changed
and loaded dynamically at boot time, and LINT
could not contain those hints anymore. For this and other
reasons, the LINT file was renamed to
NOTES and retained mostly the first reason for
its existence: documenting the available options for user
convenience.In &os; 5.X and later versions you can still generate a buildable
LINT file by typing:&prompt.root; cd /usr/src/sys/i386/conf && make LINTkernelconfiguration fileThe following is an example of the GENERIC kernel
configuration file with various additional comments where needed for
clarity. This example should match your copy in
/usr/src/sys/i386/conf/GENERIC
fairly closely.kernel optionsmachinemachine i386This is the machine architecture. It must be either
alpha, amd64,
i386, ia64,
pc98, powerpc, or
sparc64.kernel optionscpucpu I486_CPU
cpu I586_CPU
cpu I686_CPUThe above option specifies the type of CPU you have in your
system. You may have multiple instances of the CPU line (if, for
example, you are not sure whether you should use
I586_CPU or I686_CPU),
but for a custom kernel it is best to specify only the CPU
you have. If you are unsure of your CPU type, you can check the
/var/run/dmesg.boot file to view your boot
messages.kernel optionscpu typeSupport for I386_CPU is still provided in the
source of &os;, but it is disabled by default in both -STABLE and
-CURRENT. This means that to install &os; with a 386-class cpu, you now
have the following options:Install an older &os; release and rebuild from source as
described in .Build the userland and kernel on a newer machine and install on
the 386 using the precompiled /usr/obj
files (see for details).Roll your own release of &os; which includes
I386_CPU support in the kernels of the
installation CD-ROM.The first of these options is probably the easiest of all, but you
will need a lot of disk space which, on a 386-class machine, may be
difficult to find.kernel optionsidentident GENERICThis is the identification of the kernel. You should change
this to whatever you named your kernel,
i.e. MYKERNEL if you have followed the
instructions of the previous examples. The value you put in the
ident string will print when you boot up the
kernel, so it is useful to give the new kernel a different name if you
want to keep it separate from your usual kernel (e.g., you want to
build an experimental kernel).#To statically compile in device wiring instead of /boot/device.hints
#hints "GENERIC.hints" # Default places to look for devices.In &os; 5.X and newer versions the &man.device.hints.5; is
used to configure options of the device drivers. The default
location that &man.loader.8; will check at boot time is
/boot/device.hints. Using the
hints option you can compile these hints
statically into your kernel. Then there is no need to create a
device.hints file in
/boot.#makeoptions DEBUG=-g # Build kernel with gdb(1) debug symbolsThe normal build process of &os; does not include
debugging information when building the kernel and strips most
symbols after the resulting kernel is linked, to save some space
at the install location. If you are going to do tests of kernels
in the -CURRENT branch or develop changes of your own for the &os;
kernel, you might want to uncomment this line. It will enable the
use of the option which enables debugging
information when passed to &man.gcc.1;. The same can be
accomplished by the &man.config.8; option, if
you are using the traditional way for building your
kernels (see
for more information).options SCHED_4BSD # 4BSD schedulerThe traditional scheduler for &os;. Depending on your system's
workload, you may gain performance by using the new ULE scheduler for
&os; that has been designed specially for SMP, but works just fine on UP
systems too. If you wish to try it out, replace SCHED_4BSD
with SCHED_ULE in your configuration file.options INET # InterNETworkingNetworking support. Leave this in, even if you do not plan to
be connected to a network. Most programs require at least loopback
networking (i.e., making network connections within your PC), so
this is essentially mandatory.options INET6 # IPv6 communications protocolsThis enables the IPv6 communication protocols.options FFS # Berkeley Fast FilesystemThis is the basic hard drive file system. Leave it in if you
boot from the hard disk.options SOFTUPDATES # Enable FFS Soft Updates supportThis option enables Soft Updates in the kernel, this will
help speed up write access on the disks. Even when this
functionality is provided by the kernel, it must be turned on
for specific disks. Review the output from &man.mount.8; to see
if Soft Updates is enabled for your system disks. If you do not
see the soft-updates option then you will
need to activate it using the &man.tunefs.8; (for existing
file systems) or &man.newfs.8; (for new file systems)
commands.options UFS_ACL # Support for access control listsThis option, present only in &os; 5.X, enables kernel support
for access control lists. This relies on the use of extended
attributes and UFS2, and the feature is described
in detail in . ACLs are
enabled by default and should not be
disabled in the kernel if they have been used previously on a file
system, as this will remove the access control lists, changing the
way files are protected in unpredictable ways.options UFS_DIRHASH # Improve performance on big directoriesThis option includes functionality to speed up disk
operations on large directories, at the expense of using
additional memory. You would normally keep this for a large
server, or interactive workstation, and remove it if you are
using &os; on a smaller system where memory is at a premium and
disk access speed is less important, such as a firewall.options MD_ROOT # MD is a potential root deviceThis option enables support for a memory backed virtual disk
used as a root device.kernel optionsNFSkernel optionsNFS_ROOToptions NFSCLIENT # Network Filesystem Client
options NFSSERVER # Network Filesystem Server
options NFS_ROOT # NFS usable as /, requires NFSCLIENTThe network file system. Unless you plan to mount partitions
from a &unix; file server over TCP/IP, you can comment these
out.kernel optionsMSDOSFSoptions MSDOSFS # MSDOS FilesystemThe &ms-dos; file system. Unless you plan to mount a DOS formatted
hard drive partition at boot time, you can safely comment this out.
It will be automatically loaded the first time you mount a DOS
partition, as described above. Also, the excellent
emulators/mtools software
allows you to access DOS floppies without having to mount and
unmount them (and does not require MSDOSFS at
all).options CD9660 # ISO 9660 FilesystemThe ISO 9660 file system for CDROMs. Comment it out if you do
not have a CDROM drive or only mount data CDs occasionally (since it
will be dynamically loaded the first time you mount a data CD).
Audio CDs do not need this file system.options PROCFS # Process filesystemThe process file system. This is a pretend
file system mounted on /proc which allows
programs like &man.ps.1; to give you more information on what
processes are running. In &os; 5.X and above, use of PROCFS
is not required under most circumstances, as most
debugging and monitoring tools have been adapted to run without
PROCFS: unlike in &os; 4.X, new installations of
&os; 5.X will not mount the process file system by default.
In addition, 6.X-CURRENT kernels
making use of PROCFS must now also include
support for PSEUDOFS:options PSEUDOFS # Pseudo-filesystem frameworkPSEUDOFS is not available in &os; 4.X.options GEOM_GPT # GUID Partition Tables.This option brings the ability to have a large number of
partitions on a single disk.options COMPAT_43 # Compatible with BSD 4.3 [KEEP THIS!]Compatibility with 4.3BSD. Leave this in; some programs will
act strangely if you comment this out.options COMPAT_FREEBSD4 # Compatible with &os;4This option is required on &os; 5.X &i386; and Alpha systems
to support applications compiled on older versions of &os;
that use older system call interfaces. It is recommended that
this option be used on all &i386; and Alpha systems that may
run older applications; platforms that gained support only in
5.X, such as ia64 and &sparc64;, do not require this option.options SCSI_DELAY=15000 # Delay (in ms) before probing SCSIThis causes the kernel to pause for 15 seconds before probing
each SCSI device in your system. If you only have IDE hard drives,
you can ignore this, otherwise you will probably want to lower this
number, perhaps to 5 seconds, to speed up booting. Of course, if
you do this and &os; has trouble recognizing your SCSI devices,
you will have to raise it again.options KTRACE # ktrace(1) supportThis enables kernel process tracing, which is useful in
debugging.options SYSVSHM # SYSV-style shared memoryThis option provides for System V shared memory. The most
common use of this is the XSHM extension in X, which many
graphics-intensive programs will automatically take advantage of for
extra speed. If you use X, you will definitely want to include
this.options SYSVMSG # SYSV-style message queuesSupport for System V messages. This option only adds
a few hundred bytes to the kernel.options SYSVSEM # SYSV-style semaphoresSupport for System V semaphores. Less commonly used but only
adds a few hundred bytes to the kernel.The option of the &man.ipcs.1; command will
list any processes using each of these System V facilities.options _KPOSIX_PRIORITY_SCHEDULING # POSIX P1003_1B real-time extensionsReal-time extensions added in the 1993 &posix;. Certain
applications in the Ports Collection use these
(such as &staroffice;).options KBD_INSTALL_CDEV # install a CDEV entry in /devThis option is related to the keyboard. It installs a CDEV entry
in /dev.options AHC_REG_PRETTY_PRINT # Print register bitfields in debug
# output. Adds ~128k to driver.
options AHD_REG_PRETTY_PRINT # Print register bitfields in debug
# output. Adds ~215k to driver.This helps debugging by printing easier register definitions for
reading.options ADAPTIVE_GIANT # Giant mutex is adaptive.Giant is the name of a mutual exclusion mechanism (a sleep mutex)
that protects a large set of kernel resources. Today, this is an
unacceptable performance bottleneck which is actively being replaced
with locks that protect individual resources. The
ADAPTIVE_GIANT option causes Giant to be included
in the set of mutexes adaptively spun on. That is, when a thread
wants to lock the Giant mutex, but it is already locked by a thread
on another CPU, the first thread will keep running and wait for the
lock to be released. Normally, the thread would instead go back to
sleep and wait for its next chance to run. If you are not sure,
leave this in.kernel optionsSMPdevice apic # I/O APICThe apic device enables the use of the I/O APIC for interrupt
delivery. The apic device can be used in both UP and SMP kernels, but
is required for SMP kernels. Add options SMP to
include support for multiple processors.device isaAll PCs supported by &os; have one of these. Do not remove this,
even if you have no ISA slots. If you have an
IBM PS/2 (Micro Channel Architecture) system, &os; provides only
limited support at this time. For more information about the
MCA support, see
/usr/src/sys/i386/conf/NOTES.device eisaInclude this if you have an EISA motherboard. This enables
auto-detection and configuration support for all devices on the EISA
bus.device pciInclude this if you have a PCI motherboard. This enables
auto-detection of PCI cards and gatewaying from the PCI to ISA
bus.# Floppy drives
device fdcThis is the floppy drive controller.# ATA and ATAPI devices
device ataThis driver supports all ATA and ATAPI devices. You only need
one device ata line for the kernel to detect all
PCI ATA/ATAPI devices on modern machines.device atadisk # ATA disk drivesThis is needed along with device ata for
ATA disk drives.device ataraid # ATA RAID drivesThis is needed along with device ata for ATA
RAID drives.
device atapicd # ATAPI CDROM drivesThis is needed along with device ata for
ATAPI CDROM drives.device atapifd # ATAPI floppy drivesThis is needed along with device ata for
ATAPI floppy drives.device atapist # ATAPI tape drivesThis is needed along with device ata for
ATAPI tape drives.options ATA_STATIC_ID # Static device numberingThis makes the controller number static; without this,
the device numbers are dynamically allocated.# SCSI Controllers
device ahb # EISA AHA1742 family
device ahc # AHA2940 and onboard AIC7xxx devices
device ahd # AHA39320/29320 and onboard AIC79xx devices
device amd # AMD 53C974 (Teckram DC-390(T))
device isp # Qlogic family
device mpt # LSI-Logic MPT-Fusion
#device ncr # NCR/Symbios Logic
device sym # NCR/Symbios Logic (newer chipsets)
device trm # Tekram DC395U/UW/F DC315U adapters
device adv # Advansys SCSI adapters
device adw # Advansys wide SCSI adapters
device aha # Adaptec 154x SCSI adapters
device aic # Adaptec 15[012]x SCSI adapters, AIC-6[23]60.
device bt # Buslogic/Mylex MultiMaster SCSI adapters
device ncv # NCR 53C500
device nsp # Workbit Ninja SCSI-3
device stg # TMC 18C30/18C50SCSI controllers. Comment out any you do not have in your
system. If you have an IDE only system, you can remove these
altogether.# SCSI peripherals
device scbus # SCSI bus (required for SCSI)
device ch # SCSI media changers
device da # Direct Access (disks)
device sa # Sequential Access (tape etc)
device cd # CD
device pass # Passthrough device (direct SCSI access)
device ses # SCSI Environmental Services (and SAF-TE)SCSI peripherals. Again, comment out any you do not have, or if
you have only IDE hardware, you can remove them completely.The USB &man.umass.4; driver and a few other drivers use
the SCSI subsystem even though they are not real SCSI devices.
Therefore make sure not to remove SCSI support, if any such
drivers are included in the kernel configuration.# RAID controllers interfaced to the SCSI subsystem
device amr # AMI MegaRAID
device arcmsr # Areca SATA II RAID
device asr # DPT SmartRAID V, VI and Adaptec SCSI RAID
device ciss # Compaq Smart RAID 5*
device dpt # DPT Smartcache III, IV - See NOTES for options
device hptmv # Highpoint RocketRAID 182x
device iir # Intel Integrated RAID
device ips # IBM (Adaptec) ServeRAID
device mly # Mylex AcceleRAID/eXtremeRAID
device twa # 3ware 9000 series PATA/SATA RAID
# RAID controllers
device aac # Adaptec FSA RAID
device aacp # SCSI passthrough for aac (requires CAM)
device ida # Compaq Smart RAID
device mlx # Mylex DAC960 family
device pst # Promise Supertrak SX6000
device twe # 3ware ATA RAIDSupported RAID controllers. If you do not have any of these,
you can comment them out or remove them.# atkbdc0 controls both the keyboard and the PS/2 mouse
device atkbdc # AT keyboard controllerThe keyboard controller (atkbdc) provides I/O
services for the AT keyboard and PS/2 style pointing devices. This
controller is required by the keyboard driver
(atkbd) and the PS/2 pointing device driver
(psm).device atkbd # AT keyboardThe atkbd driver, together with
atkbdc controller, provides access to the AT 84
keyboard or the AT enhanced keyboard which is connected to the AT
keyboard controller.device psm # PS/2 mouseUse this device if your mouse plugs into the PS/2 mouse
port.device vga # VGA video card driverThe video card driver.# splash screen/screen saver
device splash # Splash screen and screen saver supportSplash screen at start up! Screen savers require this
too. Use the line pseudo-device splash with
&os; 4.X.# syscons is the default console driver, resembling an SCO console
device scsc is the default console driver and
resembles a SCO console. Since most full-screen programs access the
console through a terminal database library like
termcap, it should not matter whether you use
this or vt, the VT220
compatible console driver. When you log in, set your
TERM variable to scoansi if
full-screen programs have trouble running under this console.# Enable this for the pcvt (VT220 compatible) console driver
#device vt
#options XSERVER # support for X server on a vt console
#options FAT_CURSOR # start with block cursorThis is a VT220-compatible console driver, backward compatible to
VT100/102. It works well on some laptops which have hardware
incompatibilities with sc. Also set your
TERM variable to vt100 or
vt220 when you log in. This driver might also
prove useful when connecting to a large number of different machines
over the network, where termcap or
terminfo entries for the sc
device are often not available — vt100
should be available on virtually any platform.device agpInclude this if you have an AGP card in the system. This
will enable support for AGP, and AGP GART for boards which
have these features.# Floating point support - do not disable.
device npxnpx is the interface to the floating point
math unit in &os;, which is either the hardware co-processor or
the software math emulator. This is not
optional.APM# Power management support (see NOTES for more options)
#device apmAdvanced Power Management support. Useful for laptops,
although in &os; 5.X and above this is disabled in
GENERIC by default.# Add suspend/resume support for the i8254.
device pmtimerTimer device driver for power management events, such as APM and
ACPI.# PCCARD (PCMCIA) support
# PCMCIA and cardbus bridge support
device cbb # cardbus (yenta) bridge
device pccard # PC Card (16-bit) bus
device cardbus # CardBus (32-bit) busPCMCIA support. You want this if you are using a
laptop.# Serial (COM) ports
device sio # 8250, 16[45]50 based serial portsThese are the serial ports referred to as
COM ports in the &ms-dos;/&windows;
world.If you have an internal modem on COM4
and a serial port at COM2, you will have
to change the IRQ of the modem to 2 (for obscure technical reasons,
IRQ2 = IRQ 9) in order to access it
from &os;. If you have a multiport serial card, check the
manual page for &man.sio.4; for more information on the proper
values to add to your /boot/device.hints.
Some video cards (notably those based on
S3 chips) use IO addresses in the form of
0x*2e8, and since many cheap serial cards do
not fully decode the 16-bit IO address space, they clash with
these cards making the COM4 port
practically unavailable.Each serial port is required to have a unique IRQ (unless you
are using one of the multiport cards where shared interrupts are
supported), so the default IRQs for COM3
and COM4 cannot be used.# Parallel port
device ppcThis is the ISA-bus parallel port interface.device ppbus # Parallel port bus (required)Provides support for the parallel port bus.device lpt # PrinterSupport for parallel port printers.All three of the above are required to enable parallel printer
support.device plip # TCP/IP over parallelThis is the driver for the parallel network interface.device ppi # Parallel port interface deviceThe general-purpose I/O (geek port) + IEEE1284
I/O.#device vpo # Requires scbus and dazip driveThis is for an Iomega Zip drive. It requires
scbus and da support. Best
performance is achieved with ports in EPP 1.9 mode.#device pucUncomment this device if you have a dumb serial
or parallel PCI card that is supported by the &man.puc.4; glue
driver.# PCI Ethernet NICs.
device de # DEC/Intel DC21x4x (Tulip)
device em # Intel PRO/1000 adapter Gigabit Ethernet Card
device ixgb # Intel PRO/10GbE Ethernet Card
device txp # 3Com 3cR990 (Typhoon)
device vx # 3Com 3c590, 3c595 (Vortex)Various PCI network card drivers. Comment out or remove any of
these not present in your system.# PCI Ethernet NICs that use the common MII bus controller code.
# NOTE: Be sure to keep the 'device miibus' line in order to use these NICs!
device miibus # MII bus supportMII bus support is required for some PCI 10/100 Ethernet NICs,
namely those which use MII-compliant transceivers or implement
transceiver control interfaces that operate like an MII. Adding
device miibus to the kernel config pulls in
support for the generic miibus API and all of the PHY drivers,
including a generic one for PHYs that are not specifically handled
by an individual driver.device bfe # Broadcom BCM440x 10/100 Ethernet
device bge # Broadcom BCM570xx Gigabit Ethernet
device dc # DEC/Intel 21143 and various workalikes
device fxp # Intel EtherExpress PRO/100B (82557, 82558)
device lge # Level 1 LXT1001 gigabit ethernet
device nge # NatSemi DP83820 gigabit ethernet
device pcn # AMD Am79C97x PCI 10/100 (precedence over 'lnc')
device re # RealTek 8139C+/8169/8169S/8110S
device rl # RealTek 8129/8139
device sf # Adaptec AIC-6915 (Starfire)
device sis # Silicon Integrated Systems SiS 900/SiS 7016
device sk # SysKonnect SK-984x & SK-982x gigabit Ethernet
device ste # Sundance ST201 (D-Link DFE-550TX)
device ti # Alteon Networks Tigon I/II gigabit Ethernet
device tl # Texas Instruments ThunderLAN
device tx # SMC EtherPower II (83c170 EPIC)
device vge # VIA VT612x gigabit ethernet
device vr # VIA Rhine, Rhine II
device wb # Winbond W89C840F
device xl # 3Com 3c90x (Boomerang, Cyclone)Drivers that use the MII bus controller code.# ISA Ethernet NICs. pccard NICs included.
device cs # Crystal Semiconductor CS89x0 NIC
# 'device ed' requires 'device miibus'
device ed # NE[12]000, SMC Ultra, 3c503, DS8390 cards
device ex # Intel EtherExpress Pro/10 and Pro/10+
device ep # Etherlink III based cards
device fe # Fujitsu MB8696x based cards
device ie # EtherExpress 8/16, 3C507, StarLAN 10 etc.
device lnc # NE2100, NE32-VL Lance Ethernet cards
device sn # SMC's 9000 series of Ethernet chips
device xe # Xircom pccard Ethernet
# ISA devices that use the old ISA shims
#device leISA Ethernet drivers. See
/usr/src/sys/i386/conf/NOTES for details
of which cards are
supported by which driver.# Wireless NIC cards
device wlan # 802.11 support
device an # Aironet 4500/4800 802.11 wireless NICs.
device awi # BayStack 660 and others
device wi # WaveLAN/Intersil/Symbol 802.11 wireless NICs.
#device wl # Older non 802.11 Wavelan wireless NIC.Support for various wireless cards.# Pseudo devices
device loop # Network loopbackThis is the generic loopback device for TCP/IP. If you telnet
or FTP to localhost (a.k.a. 127.0.0.1) it will come back at you through
this device. This is mandatory. Under
&os; 4.X you have to use the line pseudo-device
loop.device mem # Memory and kernel memory devicesThe system memory devices.device io # I/O deviceThis option allows a process to gain I/O privileges. This is
useful in order to write userland programs that can handle hardware
directly. This is required to run the X Window system.device random # Entropy deviceCryptographically secure random number generator.device ether # Ethernet supportether is only needed if you have an Ethernet
card. It includes generic Ethernet protocol code. Under
&os; 4.X use the line pseudo-device
ether.device sl # Kernel SLIPsl is for SLIP support. This has been almost
entirely supplanted by PPP, which is easier to set up, better suited
for modem-to-modem connection, and more powerful.
With &os; 4.X use the line pseudo-device
sl.device ppp # Kernel PPPThis is for kernel PPP support for dial-up connections. There
is also a version of PPP implemented as a userland application that
uses tun and offers more flexibility and features
such as demand dialing.
With &os; 4.X use the line
pseudo-device ppp.device tun # Packet tunnel.This is used by the userland PPP software.
See
the PPP section of this book for more
information. With &os; 4.X use the line pseudo-device
tun.
device pty # Pseudo-ttys (telnet etc)This is a pseudo-terminal or simulated login port.
It is used by incoming telnet and
rlogin sessions,
xterm, and some other applications such
as Emacs.Under &os; 4.X, you
have to use the line pseudo-device pty
number. The
number after pty
indicates the number of
ptys to create. If you need more than the
default of 16 simultaneous xterm windows
and/or remote logins, be sure to increase this number accordingly,
up to a maximum of 256.device md # Memory disksMemory disk pseudo-devices. With &os; 4.X use the
line pseudo-device md.device gif # IPv6 and IPv4 tunnelingThis implements IPv6 over IPv4 tunneling, IPv4 over IPv6 tunneling,
IPv4 over IPv4 tunneling, and IPv6 over IPv6 tunneling. Beginning with
&os; 4.4 the gif device is
auto-cloning, and you should use the line
pseudo-device gif.
Earlier versions of &os; 4.X require a number, for example
pseudo-device gif 4.device faith # IPv6-to-IPv4 relaying (translation)This pseudo-device captures packets that are sent to it and
diverts them to the IPv4/IPv6 translation daemon. With
&os; 4.X use the line
pseudo-device faith 1.# The `bpf' device enables the Berkeley Packet Filter.
# Be aware of the administrative consequences of enabling this!
# Note that 'bpf' is required for DHCP.
device bpf # Berkeley packet filterThis is the Berkeley Packet Filter. This pseudo-device allows
network interfaces to be placed in promiscuous mode, capturing every
packet on a broadcast network (e.g., an Ethernet). These packets
can be captured to disk and or examined with the &man.tcpdump.1;
program. With &os; 4.X use the line
pseudo-device bpf.The &man.bpf.4; device is also used by
&man.dhclient.8; to obtain the IP address of the default router
(gateway) and so on. If you use DHCP, leave this
uncommented.# USB support
device uhci # UHCI PCI->USB interface
device ohci # OHCI PCI->USB interface
#device ehci # EHCI PCI->USB interface (USB 2.0)
device usb # USB Bus (required)
#device udbp # USB Double Bulk Pipe devices
device ugen # Generic
device uhid # Human Interface Devices
device ukbd # Keyboard
device ulpt # Printer
device umass # Disks/Mass storage - Requires scbus and da
device ums # Mouse
device urio # Diamond Rio 500 MP3 player
device uscanner # Scanners
# USB Ethernet, requires mii
device aue # ADMtek USB Ethernet
device axe # ASIX Electronics USB Ethernet
device cdce # Generic USB over Ethernet
device cue # CATC USB Ethernet
device kue # Kawasaki LSI USB Ethernet
device rue # RealTek RTL8150 USB EthernetSupport for various USB devices.# FireWire support
device firewire # FireWire bus code
device sbp # SCSI over FireWire (Requires scbus and da)
device fwe # Ethernet over FireWire (non-standard!)Support for various Firewire devices.For more information and additional devices supported by
&os;, see
/usr/src/sys/i386/conf/NOTES.Large Memory Configurations (PAE)Physical Address Extensions
(PAE)large memoryLarge memory configuration machines require access to
more than the 4 gigabyte limit on User+Kernel Virtual
Address (KVA) space. Due to this
limitation, Intel added support for 36-bit physical address
space access in the &pentium; Pro and later line of CPUs.The Physical Address Extension (PAE)
capability of the &intel; &pentium; Pro and later CPUs
allows memory configurations of up to 64 gigabytes.
&os; provides support for this capability via the
kernel configuration option, available
in the 4.X series of &os; beginning with 4.9-RELEASE and
in the 5.X series of &os; beginning with 5.1-RELEASE. Due to
the limitations of the Intel memory architecture, no distinction
is made for memory above or below 4 gigabytes. Memory allocated
above 4 gigabytes is simply added to the pool of available
memory.To enable PAE support in the kernel,
simply add the following line to your kernel configuration
file:options PAEThe PAE support in &os; is only
available for &intel; IA-32 processors. It should also be
noted, that the PAE support in &os; has
not received wide testing, and should be considered beta
quality compared to other stable features of &os;.PAE support in &os; has a few limitations:A process is not able to access more than 4
gigabytes of VM space.KLD modules cannot be loaded into
a PAE enabled kernel, due to the
differences in the build framework of a module and the
kernel.Device drivers that do not use the &man.bus.dma.9;
interface will cause data corruption in a
PAE enabled kernel and are not
recommended for use. For this reason, the
PAE kernel
configuration file is provided in &os; 5.X, which
excludes all drivers not known to work in a PAE enabled
kernel.Some system tunables determine memory resource usage
by the amount of available physical memory. Such
tunables can unnecessarily over-allocate due to the
large memory nature of a PAE system.
One such example is the
sysctl, which controls the maximum number of vnodes allowed
in the kernel. It is advised to adjust this and other
such tunables to a reasonable value.It might be necessary to increase the kernel virtual
address (KVA) space or to reduce the
amount of specific kernel resource that is heavily used
(see above) in order to avoid KVA
exhaustion. The kernel option
can be used for increasing the
KVA space.For performance and stability concerns, it is advised to
consult the &man.tuning.7; manual page. The &man.pae.4;
manual page contains up-to-date information on &os;'s
PAE support.Making Device Nodesdevice nodesMAKEDEVIf you are running &os; 5.0 or later
you can safely skip this section. These versions use
&man.devfs.5; to allocate device nodes transparently for
the user.Almost every device in the kernel has a corresponding
node entry in the /dev directory.
These nodes look like regular files, but are actually special
entries into the kernel which programs use to access the device.
The shell script /dev/MAKEDEV, which is
executed when you first install the operating system, creates
nearly all of the device nodes supported. However, it does not
create all of them, so when you add support for
a new device, it pays to make sure that the appropriate entries are
in this directory, and if not, add them. Here is a simple
example:Suppose you add the IDE CD-ROM support to the kernel. The line
to add is:device acd0This means that you should look for some entries that start with
acd0 in the /dev
directory, possibly followed by a letter, such as
c, or preceded by the letter
r, which means a raw device. It
turns out that those files are not there, so you must change to the
/dev directory and type:MAKEDEV&prompt.root; sh MAKEDEV acd0When this script finishes, you will find that there are now
acd0c and racd0c entries
in /dev so you know that it executed
correctly.For sound cards, the following command creates the appropriate
entries:&prompt.root; sh MAKEDEV snd0When creating device nodes for devices such as sound cards, if
other people have access to your machine, it may be desirable to
protect the devices from outside access by adding them to the
/etc/fbtab file. See &man.fbtab.5; for more
information.Follow this simple procedure for any other
non-GENERIC devices which do not have
entries.All SCSI controllers use the same set of
/dev entries, so you do not need to create
these. Also, network cards and SLIP/PPP pseudo-devices do not
have entries in /dev at all, so you do not
have to worry about these either.If Something Goes WrongThere are five categories of trouble that can occur when
building a custom kernel. They are:config fails:If the &man.config.8; command fails when you
give it your kernel description, you have probably made a
simple error somewhere. Fortunately,
&man.config.8; will print the line number that it
had trouble with, so that you can quickly locate the line
containing the error. For example, if you see:config: line 17: syntax errorMake sure the
keyword is typed correctly by comparing it to the
GENERIC kernel or another
reference.make fails:If the make command fails, it usually
signals an error in your kernel description which is not severe
enough for &man.config.8; to catch. Again, look
over your configuration, and if you still cannot resolve the
problem, send mail to the &a.questions; with your kernel
configuration, and it should be diagnosed quickly.Installing the new kernel fails:If the kernel compiled fine, but failed to install
(the make install or
make installkernel command failed),
the first thing to check is if your system is running at
securelevel 1 or higher (see &man.init.8;). The kernel
installation tries to remove the immutable flag from
your kernel and set the immutable flag on the new one.
Since securelevel 1 or higher prevents unsetting the immutable
flag for any files on the system, the kernel installation needs
to be performed at securelevel 0 or lower.The above only applies to &os; 4.X and earlier versions.
&os; 5.X, along with later versions, does not set the
immutable flag on the kernel and a failure to install a
kernel probably indicates a more fundamental problem.The kernel does not boot:If your new kernel does not boot, or fails to
recognize your devices, do not panic! Fortunately, &os; has
an excellent mechanism for recovering from incompatible
kernels. Simply choose the kernel you want to boot from at
the &os; boot loader. You can access this when the system
counts down from 10 at the boot menu. Hit any key except for the
Enter key, type unload
and then type
boot /boot/kernel.old/kernel,
or the filename of any other kernel that will boot properly.
When reconfiguring a kernel, it is always a good idea to keep
a kernel that is known to work on hand.After booting with a good kernel you can check over your
configuration file and try to build it again. One helpful
resource is the /var/log/messages file
which records, among other things, all of the kernel messages
from every successful boot. Also, the &man.dmesg.8; command
will print the kernel messages from the current boot.If you are having trouble building a kernel, make sure
to keep a GENERIC, or some other kernel
that is known to work on hand as a different name that will
not get erased on the next build. You cannot rely on
kernel.old because when installing a
new kernel, kernel.old is overwritten
with the last installed kernel which may be non-functional.
Also, as soon as possible, move the working kernel to the
proper /boot/kernel
location or commands such
as &man.ps.1; may not work properly. To do this, simply
rename the directory containing the good kernel:&prompt.root; mv /boot/kernel /boot/kernel.bad
&prompt.root; mv /boot/kernel.good /boot/kernelFor versions of &os; prior to 5.X, the proper command to
unlock the kernel file that
make installs (in order to move another
kernel back permanently) is:&prompt.root; chflags noschg /kernelIf you find you cannot do this, you are probably running
at a &man.securelevel.8; greater than zero. Edit
kern_securelevel in
/etc/rc.conf and set it to
-1, then reboot. You can change it back
to its previous setting when you are happy with your new
kernel.And, if you want to lock your new kernel
into place, or any file for that matter, so that it cannot
be moved or tampered with:&prompt.root; chflags schg /kernelThe kernel works, but &man.ps.1; does not work
any more:If you have installed a different version of the kernel
from the one that the system utilities have been built with,
for example, a 5.X kernel on a 4.X system, many system-status
commands like &man.ps.1; and &man.vmstat.8; will not work any
more. You should recompile and install
a world built with the same version of the source tree as
your kernel. This is one reason it is
not normally a good idea to use a different version of the
kernel from the rest of the operating system.
diff --git a/zh_TW.Big5/books/handbook/l10n/chapter.sgml b/zh_TW.Big5/books/handbook/l10n/chapter.sgml
index 36e2aa63ff..b937b7d4ad 100644
--- a/zh_TW.Big5/books/handbook/l10n/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/l10n/chapter.sgml
@@ -1,972 +1,972 @@
AndreyChernovContributed by Michael C.WuRewritten by
- Localization - I18N/L10N Usage and Setup
+ 地區、語系 - I18N/L10N 用法與設定
- Synopsis
+ 概述FreeBSD is a very distributed project with users and
contributors located all over the world. This chapter discusses
the internationalization and localization features of FreeBSD
that allow non-English speaking users to get real work done.
There are many aspects of the i18n implementation in both the system
and application levels, so where applicable we refer the reader
to more specific sources of documentation.After reading this chapter, you will know:How different languages and locales are encoded
on modern operating systems.How to set the locale for your login
shell.How to configure your console for non-English
languages.How to use X Window System effectively with different
languages.Where to find more information about writing
i18n-compliant applications.Before reading this chapter, you should:Know how to install additional third-party
applications ().The Basics
- What Is I18N/L10N?
+ 啥是 I18N/L10N?internationalizationlocalizationlocalizationDevelopers shortened internationalization into the term I18N,
counting the number of letters between the first and the last
letters of internationalization. L10N uses the same naming
scheme, coming from localization. Combined
together, I18N/L10N methods, protocols, and applications allow
users to use languages of their choice.I18N applications are programmed using I18N kits under
libraries. It allows for developers to write a simple file and
translate displayed menus and texts to each language. We strongly
encourage programmers to follow this convention.Why Should I Use I18N/L10N?I18N/L10N is used whenever you wish to either view, input, or
process data in non-English languages.What Languages Are Supported in the I18N Effort?I18N and L10N are not FreeBSD specific. Currently, one can
choose from most of the major languages of the World, including
but not limited to: Chinese, German, Japanese, Korean, French,
Russian, Vietnamese and others.Using LocalizationIn all its splendor, I18N is not FreeBSD-specific and is a
convention. We encourage you to help FreeBSD in following this
convention.localeLocalization settings are based on three main terms:
Language Code, Country Code, and Encoding. Locale names are
constructed from these parts as follows:LanguageCode_CountryCode.EncodingLanguage and Country Codeslanguage codescountry codesIn order to localize a FreeBSD system to a specific language
(or any other I18N-supporting &unix; like systems), the user needs to find out
the codes for the specify country and language (country
codes tell applications what variation of given
language to use). In addition, web
browsers, SMTP/POP servers, web servers, etc. make decisions based on
them. The following are examples of language/country codes:Language/Country CodeDescriptionen_USEnglish - United Statesru_RURussian for Russiazh_TWTraditional Chinese for TaiwanEncodingsencodingsASCIISome languages use non-ASCII encodings that are 8-bit, wide
or multibyte characters, see &man.multibyte.3; for more
details. Older applications do not recognize them
and mistake them for control characters. Newer applications
usually do recognize 8-bit characters. Depending on the
implementation, users may be required to compile an application
with wide or multibyte characters support, or configure it correctly.
To be able to input and process wide or multibyte characters, the FreeBSD Ports Collection has provided
each language with different programs. Refer to the I18N
documentation in the respective FreeBSD Port.Specifically, the user needs to look at the application
documentation to decide on how to configure it correctly or to
pass correct values into the configure/Makefile/compiler.Some things to keep in mind are:Language specific single C chars character sets
(see &man.multibyte.3;), e.g.
ISO-8859-1, ISO-8859-15, KOI8-R, CP437.Wide or multibyte encodings, e.g. EUC, Big5.You can check the active list of character sets at the
IANA Registry.FreeBSD versions 4.5 and up use X11-compatible locale
encodings instead.I18N ApplicationsIn the FreeBSD Ports and Package system, I18N applications
have been named with I18N in their names for
easy identification. However, they do not always support the
language needed.Setting LocaleUsually it is sufficient to export the value of the locale name
as LANG in the login shell. This could be done in
the user's ~/.login_conf file or in the
startup file of the user's shell (~/.profile,
~/.bashrc, ~/.cshrc).
There is no need to set the locale subsets such as
LC_CTYPE, LC_CTIME. Please
refer to language-specific FreeBSD documentation for more
information.You should set the following two environment variables in your configuration
files:POSIXLANG for &posix; &man.setlocale.3; family
functionsMIMEMM_CHARSET for applications' MIME character
setThis includes the user shell configuration, the specific application
configuration, and the X11 configuration.Setting Locale Methodslocalelogin classThere are two methods for setting locale, and both are
described below. The first (recommended one) is by assigning
the environment variables in login
class, and the second is by adding the environment
variable assignments to the system's shell startup file.Login Classes MethodThis method allows environment variables needed for locale
name and MIME character sets to be assigned once for every
possible shell instead of adding specific shell assignments to
each shell's startup file. User
Level Setup can be done by an user himself and Administrator Level Setup require
superuser privileges.User Level SetupHere is a minimal example of a
.login_conf file in user's home
directory which has both variables set for Latin-1
encoding:me:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:Traditional ChineseBIG-5 encodingHere is an example of a
.login_conf that sets the variables
for Traditional Chinese in BIG-5 encoding. Notice the many
more variables set because some software does not respect
locale variables correctly for Chinese, Japanese, and Korean.#Users who do not wish to use monetary units or time formats
#of Taiwan can manually change each variable
me:\
:lang=zh_TW.Big5:\
:lc_all=zh_TW.Big:\
:lc_collate=zh_TW.Big5:\
:lc_ctype=zh_TW.Big5:\
:lc_messages=zh_TW.Big5:\
:lc_monetary=zh_TW.Big5:\
:lc_numeric=zh_TW.Big5:\
:lc_time=zh_TW.Big5:\
:charset=big5:\
:xmodifiers="@im=xcin": #Setting the XIM Input ServerSee Administrator Level
Setup and &man.login.conf.5; for more details.Administrator Level SetupVerify that the user's login class in
/etc/login.conf sets the correct
language. Make sure these settings
appear in /etc/login.conf:language_name:accounts_title:\
:charset=MIME_charset:\
:lang=locale_name:\
:tc=default:So sticking with our previous example using Latin-1, it
would look like this:german:German Users Accounts:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:\
:tc=default:Changing Login Classes with &man.vipw.8;vipwUse vipw to add new users, and make
the entry look like this:user:password:1111:11:language:0:0:User Name:/home/user:/bin/shChanging Login Classes with &man.adduser.8;adduserlogin classUse adduser to add new users, and do
the following:Set defaultclass =
language in
/etc/adduser.conf. Keep in mind
you must enter a default class for
all users of other languages in this case.An alternative variant is answering the specified
language each time that
Enter login class: default []:
appears from &man.adduser.8;.Another alternative is to use the following for each
user of a different language that you wish to
add:&prompt.root; adduser -class languageChanging Login Classes with &man.pw.8;pwIf you use &man.pw.8; for adding new users, call it in
this form:&prompt.root; pw useradd user_name -L languageShell Startup File MethodThis method is not recommended because it requires a
different setup for each possible shell program chosen. Use
the Login Class Method
instead.MIMElocaleTo add the locale name and MIME character set, just set
the two environment variables shown below in the
/etc/profile and/or
/etc/csh.login shell startup files. We
will use the German language as an example below:In /etc/profile:LANG=de_DE.ISO8859-1; export LANGMM_CHARSET=ISO-8859-1; export MM_CHARSETOr in /etc/csh.login:setenv LANG de_DE.ISO8859-1setenv MM_CHARSET ISO-8859-1Alternatively, you can add the above instructions to
/usr/share/skel/dot.profile (similar to
what was used in /etc/profile above), or
/usr/share/skel/dot.login (similar to
what was used in /etc/csh.login
above).For X11:In $HOME/.xinitrc:LANG=de_DE.ISO8859-1; export LANGOr:setenv LANG de_DE.ISO8859-1Depending on your shell (see above).Console SetupFor all single C chars character sets, set the correct
console fonts in /etc/rc.conf for the
language in question with:font8x16=font_name
font8x14=font_name
font8x8=font_nameThe font_name here is taken from
the /usr/share/syscons/fonts directory,
without the .fnt suffix.sysinstallkeymapscreenmapAlso be sure to set the correct keymap and screenmap for your
single C chars character set through
sysinstall (/stand/sysinstall
in &os; versions older than 5.2).
Once inside sysinstall, choose Configure, then
Console. Alternatively, you can add the
following to /etc/rc.conf:scrnmap=screenmap_name
keymap=keymap_name
keychange="fkey_number sequence"The screenmap_name here is taken
from the /usr/share/syscons/scrnmaps
directory, without the .scm suffix. A
screenmap with a corresponding mapped font is usually needed as a
workaround for expanding bit 8 to bit 9 on a VGA adapter's font
character matrix in pseudographics area, i.e., to move letters out
of that area if screen font uses a bit 8 column.If you have the moused daemon
enabled by setting the following
in your /etc/rc.conf:moused_enable="YES"then examine the mouse cursor information in the next
paragraph.mousedBy default the mouse cursor of the &man.syscons.4; driver occupies the
0xd0-0xd3 range in the character set. If your language uses this
range, you need to move the cursor's range outside of it. To enable
the workaround for FreeBSD versions before 5.0, insert the following
line into your kernel configuration:options SC_MOUSE_CHAR=0x03For FreeBSD versions 4.4 and up insert the following line
into /etc/rc.conf:mousechar_start=3The keymap_name here is taken from
the /usr/share/syscons/keymaps directory,
without the .kbd suffix. If you are
uncertain which keymap to use, you use can &man.kbdmap.1; to test
keymaps without rebooting.The keychange is usually needed to program
function keys to match the selected terminal type because
function key sequences cannot be defined in the key map.Also be sure to set the correct console terminal type in
/etc/ttys for all ttyv*
entries. Current pre-defined correspondences are:Character SetTerminal TypeISO-8859-1 or ISO-8859-15cons25l1ISO-8859-2cons25l2ISO-8859-7cons25l7KOI8-Rcons25rKOI8-Ucons25uCP437 (VGA default)cons25US-ASCIIcons25wFor wide or multibyte characters languages, use the correct
FreeBSD port in your
/usr/ports/language
directory. Some ports appear as console while the system sees it
as serial vtty's, hence you must reserve enough vtty's for both
X11 and the pseudo-serial console. Here is a partial list of
applications for using other languages in console:LanguageLocationTraditional Chinese (BIG-5)chinese/big5conJapanesejapanese/kon2-16dot or
japanese/mule-freewnnKoreankorean/hanX11 SetupAlthough X11 is not part of the FreeBSD Project, we have
included some information here for FreeBSD users. For more
details, refer to the &xorg;
web site or whichever X11 Server you use.In ~/.Xresources, you can additionally
tune application specific I18N settings (e.g., fonts, menus,
etc.).Displaying FontsX11 True Type font serverInstall &xorg; server
(x11-servers/xorg-server)
or &xfree86; server
(x11-servers/XFree86-4-Server),
then install the language &truetype; fonts. Setting the correct
locale should allow you to view your selected language in menus
and such.Inputting Non-English CharactersX11 Input Method (XIM)The X11 Input Method (XIM) Protocol is a new standard for
all X11 clients. All X11 applications should be written as XIM
clients that take input from XIM Input servers. There are
several XIM servers available for different languages.Printer SetupSome single C chars character sets are usually hardware
coded into printers. Wide or multibyte
character sets require special setup and we recommend using
apsfilter. You may also convert the
document to &postscript; or PDF formats using language specific
converters.Kernel and File SystemsThe FreeBSD fast filesystem (FFS) is 8-bit clean, so it can be used
with any single C chars character set (see &man.multibyte.3;),
but there is no character set
name stored in the filesystem; i.e., it is raw 8-bit and does not
know anything about encoding order. Officially, FFS does not
support any form of wide or multibyte character sets yet. However, some
wide or multibyte character sets have independent patches for FFS
enabling such support. They are only temporary unportable
solutions or hacks and we have decided to not include them in the
source tree. Refer to respective languages' web sites for more
information and the patch files.DOSUnicodeThe FreeBSD &ms-dos; filesystem has the configurable ability to
convert between &ms-dos;, Unicode character sets and chosen
FreeBSD filesystem character sets. See &man.mount.msdos.8; for
details.Compiling I18N ProgramsMany FreeBSD Ports have been ported with I18N support. Some
of them are marked with -I18N in the port name. These and many
other programs have built in support for I18N and need no special
consideration.MySQLHowever, some applications such as
MySQL need to be have the
Makefile configured with the specific
charset. This is usually done in the
Makefile or done by passing a value to
configure in the source.Localizing FreeBSD to Specific LanguagesAndreyChernovOriginally contributed by Russian Language (KOI8-R Encoding)localizationRussianFor more information about KOI8-R encoding, see the KOI8-R References
(Russian Net Character Set).Locale SetupPut the following lines into your
~/.login_conf file:me:My Account:\
:charset=KOI8-R:\
:lang=ru_RU.KOI8-R:See earlier in this chapter for examples of setting up the
locale.Console SetupFor the FreeBSD versions before 5.0 add the following line
to your kernel configuration file:options SC_MOUSE_CHAR=0x03For FreeBSD versions 4.4 and up insert the following
line into /etc/rc.conf:mousechar_start=3Use following settings in
/etc/rc.conf:keymap="ru.koi8-r"
scrnmap="koi8-r2cp866"
font8x16="cp866b-8x16"
font8x14="cp866-8x14"
font8x8="cp866-8x8"For each ttyv* entry in
/etc/ttys, use
cons25r as the terminal type.See earlier in this chapter for examples of setting up the
console.Printer SetupprintersSince most printers with Russian characters come with
hardware code page CP866, a special output filter is needed
to convert from KOI8-R to CP866. Such a filter is installed by
default as /usr/libexec/lpr/ru/koi2alt.
A Russian printer /etc/printcap entry
should look like:lp|Russian local line printer:\
:sh:of=/usr/libexec/lpr/ru/koi2alt:\
:lp=/dev/lpt0:sd=/var/spool/output/lpd:lf=/var/log/lpd-errs:See &man.printcap.5; for a detailed description.&ms-dos; FS and Russian FilenamesThe following example &man.fstab.5; entry enables support
for Russian filenames in mounted &ms-dos; filesystems:/dev/ad0s2 /dos/c msdos rw,-Wkoi2dos,-Lru_RU.KOI8-R 0 0The option selects the locale name
used, and sets the character conversion
table. To use the option, be sure to
mount /usr before the &ms-dos; partition
because the conversion tables are located in
/usr/libdata/msdosfs. For more
information, see the &man.mount.msdos.8; manual
page.X11 SetupDo non-X locale
setup first as described.The Russian KOI8-R locale
may not work with old &xfree86; releases (lower than 3.3).
&xorg; is now the default
version of the X Window System on FreeBSD.
This should not be an
issue unless you are using an old version of
FreeBSD.If you use &xorg;,
install
x11-fonts/xorg-fonts-cyrillic
package.Check the "Files" section
in your /etc/X11/xorg.conf file.
The following
lines must be added before any other
FontPath entries:FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/misc"
FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/75dpi"
FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/100dpi"If you use a high resolution video mode, swap the 75 dpi
and 100 dpi lines.To activate a Russian keyboard, add the following to the
"Keyboard" section of your
XF86Config file.For &xfree86; 3.X:XkbLayout "ru"
XkbOptions "grp:caps_toggle"For &xorg; (or
&xfree86; 4.X):Option "XkbLayout" "us,ru"
Option "XkbOptions" "grp:toggle"Also make sure that XkbDisable is
turned off (commented out) there.For grp:caps_toggle
the RUS/LAT switch will be CapsLock.
The old CapsLock function is still
available via ShiftCapsLock (in LAT mode
only). For grp:toggle
the RUS/LAT switch will be Right Alt.
grp:caps_toggle does not work in
&xorg; for unknown reason.If you have &windows; keys on your keyboard,
and notice that some non-alphabetical keys are mapped
incorrectly in RUS mode, add the following line in your
XF86Config file.For &xfree86; 3.X:XkbVariant "winkeys"For &xorg; (or
&xfree86; 4.X):Option "XkbVariant" ",winkeys"The Russian XKB keyboard may not work with old &xfree86;
versions, see the above
note for more information. The Russian XKB
keyboard may also not work with non-localized
applications as well.Minimally localized applications
should call a XtSetLanguageProc (NULL, NULL,
NULL); function early in the program.See
KOI8-R for X Window for more instructions on
localizing X11 applications.Traditional Chinese Localization for TaiwanlocalizationTraditional ChineseThe FreeBSD-Taiwan Project has an Chinese HOWTO for
FreeBSD at
using many Chinese ports.
Current editor for the FreeBSD Chinese HOWTO is
Shen Chuan-Hsing statue@freebsd.sinica.edu.tw.
Chuan-Hsing Shen statue@freebsd.sinica.edu.tw has
created the
Chinese FreeBSD Collection (CFC) using FreeBSD-Taiwan's
zh-L10N-tut. The packages and the script files
are available at .German Language Localization (for All ISO 8859-1
Languages)localizationGermanSlaven Rezic eserte@cs.tu-berlin.de wrote a
tutorial how to use umlauts on a FreeBSD machine. The tutorial
is written in German and available at
.Japanese and Korean Language LocalizationlocalizationJapaneselocalizationKoreanFor Japanese, refer to
,
and for Korean, refer to
.Non-English FreeBSD DocumentationSome FreeBSD contributors have translated parts of FreeBSD to
other languages. They are available through links on the main site or in
/usr/share/doc.
diff --git a/zh_TW.Big5/books/handbook/mirrors/chapter.sgml b/zh_TW.Big5/books/handbook/mirrors/chapter.sgml
index 4ae6c6af8d..0f48824b55 100644
--- a/zh_TW.Big5/books/handbook/mirrors/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/mirrors/chapter.sgml
@@ -1,3178 +1,3188 @@
取得 FreeBSDCDROM 及 DVD PublishersRetail Boxed ProductsFreeBSD is available as a boxed product (FreeBSD CDs,
additional software, and printed documentation) from several
retailers:CompUSA
WWW: Frys Electronics
WWW: CD and DVD SetsFreeBSD CD and DVD sets are available from many online
retailers:BSD Mall by Daemon NewsPO Box 161Nauvoo, IL62354USA
Phone: +1 866 273-6255
Fax: +1 217 453-9956
Email: sales@bsdmall.com
WWW: BSD-Systems
Email: info@bsd-systems.co.uk
WWW: fastdiscs.com6 Eltham CloseLeeds, LS6 2TYUnited Kingdom
Phone: +44 870 1995 171
Email: sales@fastdiscs.com
WWW: FreeBSD Mall, Inc.3623 Sanford StreetConcord, CA94520-1405USA
Phone: +1 925 674-0783
Fax: +1 925 674-0821
Email: info@freebsdmall.com
WWW: Hinner EDVSt. Augustinus-Str. 10D-81825MünchenGermany
Phone: (089) 428 419
WWW: Ikarios22-24 rue Voltaire92000NanterreFrance
WWW: JMC SoftwareIreland
Phone: 353 1 6291282
WWW: Linux CD MallPrivate Bag MBE N348Auckland 1030New Zealand
Phone: +64 21 866529
WWW: The Linux EmporiumHilliard House, Lester WayWallingfordOX10 9TAUnited Kingdom
Phone: +44 1491 837010
Fax: +44 1491 837016
WWW: Linux+ DVD MagazineLewartowskiego 6Warsaw00-190Poland
Phone: +48 22 860 18 18
Email: editors@lpmagazine.org
WWW: Linux System Labs Australia21 Ray DriveBalwyn NorthVIC - 3104Australia
Phone: +61 3 9857 5918
Fax: +61 3 9857 8974
WWW: LinuxCenter.RuGalernaya Street, 55Saint-Petersburg190000Russia
Phone: +7-812-3125208
Email: info@linuxcenter.ru
WWW: DistributorsIf you are a reseller and want to carry FreeBSD CDROM products,
please contact a distributor:Cylogistics809B Cuesta Dr., #2149Mountain View, CA94040USA
Phone: +1 650 694-4949
Fax: +1 650 694-4953
Email: sales@cylogistics.com
WWW: Ingram Micro1600 E. St. Andrew PlaceSanta Ana, CA92705-4926USA
Phone: 1 (800) 456-8000
WWW: Kudzu, LLC7375 Washington Ave. S.Edina, MN55439USA
Phone: +1 952 947-0822
Fax: +1 952 947-0876
Email: sales@kudzuenterprises.comLinuxCenter.RuGalernaya Street, 55Saint-Petersburg190000Russia
Phone: +7-812-3125208
Email: info@linuxcenter.ru
WWW: Navarre Corp7400 49th Ave SouthNew Hope, MN55428USA
Phone: +1 763 535-8333
Fax: +1 763 535-0341
WWW: FTP SitesThe official sources for FreeBSD are available via anonymous FTP
from a worldwide set of mirror sites. The site
is well
connected and allows a large number of connections to it, but
you are probably better off finding a closer
mirror site (especially if you decide to set up some sort of
mirror site).The FreeBSD mirror
sites database is more accurate than the mirror listing in the
Handbook, as it gets its information from the DNS rather than relying on
static lists of hosts.Additionally, FreeBSD is available via anonymous FTP from the
following mirror sites. If you choose to obtain FreeBSD via anonymous
FTP, please try to use a site near you. The mirror sites listed as
Primary Mirror Sites typically have the entire FreeBSD archive (all
the currently available versions for each of the architectures) but
you will probably have faster download times from a site that is
in your country or region. The regional sites carry the most recent
versions for the most popular architecture(s) but might not carry
the entire FreeBSD archive. All sites provide access via anonymous
FTP but some sites also provide access via other methods. The access
methods available for each site are provided in parentheses
after the hostname.
&chap.mirrors.ftp.inc;
Anonymous CVSIntroductionCVSanonymousAnonymous CVS (or, as it is otherwise known,
anoncvs) is a feature provided by the CVS
utilities bundled with FreeBSD for synchronizing with a remote
CVS repository. Among other things, it allows users of FreeBSD
to perform, with no special privileges, read-only CVS operations
against one of the FreeBSD project's official anoncvs servers.
To use it, one simply sets the CVSROOT
environment variable to point at the appropriate anoncvs server,
provides the well-known password anoncvs with the
cvs login command, and then uses the
&man.cvs.1; command to access it like any local
repository.The cvs login command, stores the passwords
that are used for authenticating to the CVS server in a file
called .cvspass in your
HOME directory. If this file does not exist,
you might get an error when trying to use cvs
login for the first time. Just make an empty
.cvspass file, and retry to login.While it can also be said that the CVSup and anoncvs
services both perform essentially the same function, there are
various trade-offs which can influence the user's choice of
synchronization methods. In a nutshell,
CVSup is much more efficient in its
usage of network resources and is by far the most technically
sophisticated of the two, but at a price. To use
CVSup, a special client must first be
installed and configured before any bits can be grabbed, and
then only in the fairly large chunks which
CVSup calls
collections.Anoncvs, by contrast, can be used
to examine anything from an individual file to a specific
program (like ls or grep)
by referencing the CVS module name. Of course,
anoncvs is also only good for
read-only operations on the CVS repository, so if it is your
intention to support local development in one repository shared
with the FreeBSD project bits then
CVSup is really your only
option.Using Anonymous CVSConfiguring &man.cvs.1; to use an Anonymous CVS repository
is a simple matter of setting the CVSROOT
environment variable to point to one of the FreeBSD project's
anoncvs servers. At the time of this
writing, the following servers are available:Austria:
:pserver:anoncvs@anoncvs.at.FreeBSD.org:/home/ncvs
(Use cvs login and enter any
password when prompted.)France:
:pserver:anoncvs@anoncvs.fr.FreeBSD.org:/home/ncvs
(pserver (password anoncvs), ssh (no password))
Germany:
:pserver:anoncvs@anoncvs.de.FreeBSD.org:/home/ncvs
(Use cvs login and enter the password
anoncvs when prompted.)Germany:
:pserver:anoncvs@anoncvs2.de.FreeBSD.org:/home/ncvs
(rsh, pserver, ssh, ssh/2022)
Japan:
:pserver:anoncvs@anoncvs.jp.FreeBSD.org:/home/ncvs
(Use cvs login and enter the password
anoncvs when prompted.)
-
USA:
anoncvs@anoncvs1.FreeBSD.org:/home/ncvs (ssh only - no
password)
- SSH HostKey: 1024 4b:83:b6:c5:70:75:6c:5b:18:8e:3a:7a:88:a0:43:bb root@ender.liquidneon.com
-SSH2 HostKey: 1024 80:a7:87:fa:61:d9:25:5c:33:d5:48:51:aa:8f:b6:12 ssh_host_dsa_key.pub
+ SSH HostKey: 1024 8b:c4:6f:9a:7e:65:8a:eb:50:50:29:7c:a1:47:03:bc root@ender.liquidneon.com
+SSH2 HostKey: 2048 4d:59:19:7b:ea:9b:76:0b:ca:ee:da:26:e2:3a:83:b8 ssh_host_dsa_key.pubSince CVS allows one to check out virtually
any version of the FreeBSD sources that ever existed (or, in
some cases, will exist), you need to be
familiar with the revision () flag to
&man.cvs.1; and what some of the permissible values for it in
the FreeBSD Project repository are.There are two kinds of tags, revision tags and branch tags.
A revision tag refers to a specific revision. Its meaning stays
the same from day to day. A branch tag, on the other hand,
refers to the latest revision on a given line of development, at
any given time. Because a branch tag does not refer to a
specific revision, it may mean something different tomorrow than
it means today. contains revision tags that users
might be interested
in. Again, none of these are valid for the Ports Collection
since the Ports Collection does not have multiple
revisions.When you specify a branch tag, you normally receive the
latest versions of the files on that line of development. If
you wish to receive some past version, you can do so by
specifying a date with the flag.
See the &man.cvs.1; manual page for more details.ExamplesWhile it really is recommended that you read the manual page
for &man.cvs.1; thoroughly before doing anything, here are some
quick examples which essentially show how to use Anonymous
CVS:Checking Out Something from -CURRENT (&man.ls.1;):&prompt.user; setenv CVSROOT :pserver:anoncvs@anoncvs.jp.FreeBSD.org:/home/ncvs
&prompt.user; cvs loginAt the prompt, enter the passwordanoncvs.
&prompt.user; cvs co lsUsing SSH to check out the src/
tree:&prompt.user; cvs -d freebsdanoncvs@anoncvs.FreeBSD.org:/home/ncvs co src
The authenticity of host 'anoncvs.freebsd.org (128.46.156.46)' can't be established.
DSA key fingerprint is 52:02:38:1a:2f:a8:71:d3:f5:83:93:8d:aa:00:6f:65.
Are you sure you want to continue connecting (yes/no)? yes
Warning: Permanently added 'anoncvs.freebsd.org' (DSA) to the list of known hosts.Checking Out the Version of &man.ls.1; in the 6-STABLE
Branch:&prompt.user; setenv CVSROOT :pserver:anoncvs@anoncvs.jp.FreeBSD.org:/home/ncvs
&prompt.user; cvs loginAt the prompt, enter the passwordanoncvs.
&prompt.user; cvs co -rRELENG_6 lsCreating a List of Changes (as Unified Diffs) to &man.ls.1;&prompt.user; setenv CVSROOT :pserver:anoncvs@anoncvs.jp.FreeBSD.org:/home/ncvs
&prompt.user; cvs loginAt the prompt, enter the passwordanoncvs.
&prompt.user; cvs rdiff -u -rRELENG_5_3_0_RELEASE -rRELENG_5_4_0_RELEASE lsFinding Out What Other Module Names Can Be Used:&prompt.user; setenv CVSROOT :pserver:anoncvs@anoncvs.jp.FreeBSD.org:/home/ncvs
&prompt.user; cvs loginAt the prompt, enter the passwordanoncvs.
&prompt.user; cvs co modules
&prompt.user; more modules/modulesOther ResourcesThe following additional resources may be helpful in learning
CVS:CVS Tutorial from Cal Poly.
- CVS Home,
+ CVS Home,
the CVS development and support community.CVSweb is
the FreeBSD Project web interface for CVS.Using CTMCTMCTM is a method for keeping a
remote directory tree in sync with a central one. It has been
developed for usage with FreeBSD's source trees, though other
people may find it useful for other purposes as time goes by.
Little, if any, documentation currently exists at this time on the
process of creating deltas, so contact the &a.ctm-users.name; mailing list for more
information and if you wish to use CTM
for other things.Why Should I Use CTM?CTM will give you a local copy of
the FreeBSD source trees. There are a number of
flavors of the tree available. Whether you wish
to track the entire CVS tree or just one of the branches,
CTM can provide you the information.
If you are an active developer on FreeBSD, but have lousy or
non-existent TCP/IP connectivity, or simply wish to have the
changes automatically sent to you,
CTM was made for you. You will need
to obtain up to three deltas per day for the most active
branches. However, you should consider having them sent by
automatic email. The sizes of the updates are always kept as
small as possible. This is typically less than 5K, with an
occasional (one in ten) being 10-50K and every now and then a
large 100K+ or more coming around.You will also need to make yourself aware of the various
caveats related to working directly from the development sources
rather than a pre-packaged release. This is particularly true
if you choose the current sources. It is
recommended that you read Staying
current with FreeBSD.What Do I Need to Use
CTM?You will need two things: The CTM
program, and the initial deltas to feed it (to get up to
current levels).The CTM program has been part of
FreeBSD ever since version 2.0 was released, and lives in
/usr/src/usr.sbin/ctm if you have a copy
of the source available.The deltas you feed
CTM can be had two ways, FTP or
email. If you have general FTP access to the Internet then the
following FTP sites support access to
CTM:or see section mirrors.FTP the relevant directory and fetch the
README file, starting from there.If you wish to get your deltas via email:Subscribe to one of the
CTM distribution lists.
&a.ctm-cvs-cur.name; supports the entire CVS tree.
&a.ctm-src-cur.name; supports the head of the development
branch. &a.ctm-src-4.name; supports the 4.X release
branch, etc.. (If you do not know how to subscribe yourself
to a list, click on the list name above or go to
&a.mailman.lists.link; and click on the list that you
wish to subscribe to. The list page should contain all of
the necessary subscription instructions.)When you begin receiving your CTM
updates in the mail, you may use the
ctm_rmail program to unpack and apply them.
You can actually use the ctm_rmail program
directly from a entry in /etc/aliases if
you want to have the process run in a fully automated fashion.
Check the ctm_rmail manual page for more
details.No matter what method you use to get the
CTM deltas, you should subscribe to
the &a.ctm-announce.name; mailing list. In
the future, this will be the only place where announcements
concerning the operations of the
CTM system will be posted. Click
on the list name above and follow the instructions
to subscribe to the
list.Using CTM for the First
TimeBefore you can start using CTM
deltas, you will need to get to a starting point for the deltas
produced subsequently to it.First you should determine what you already have. Everyone
can start from an empty directory. You must use
an initial Empty delta to start off your
CTM supported tree. At some point it
is intended that one of these started deltas be
distributed on the CD for your convenience, however, this does
not currently happen.Since the trees are many tens of megabytes, you should
prefer to start from something already at hand. If you have a
-RELEASE CD, you can copy or extract an initial source from it.
This will save a significant transfer of data.You can recognize these starter deltas by the
X appended to the number
(src-cur.3210XEmpty.gz for instance). The
designation following the X corresponds to
the origin of your initial seed.
Empty is an empty directory. As a rule a
base transition from Empty is produced
every 100 deltas. By the way, they are large! 70 to 80
Megabytes of gzip'd data is common for the
XEmpty deltas.Once you have picked a base delta to start from, you will also
need all deltas with higher numbers following it.Using CTM in Your Daily
LifeTo apply the deltas, simply say:&prompt.root; cd /where/ever/you/want/the/stuff
&prompt.root; ctm -v -v /where/you/store/your/deltas/src-xxx.*CTM understands deltas which have
been put through gzip, so you do not need to
gunzip them first, this saves disk space.Unless it feels very secure about the entire process,
CTM will not touch your tree. To
verify a delta you can also use the flag and
CTM will not actually touch your
tree; it will merely verify the integrity of the delta and see
if it would apply cleanly to your current tree.There are other options to CTM
as well, see the manual pages or look in the sources for more
information.That is really all there is to it. Every time you get a new
delta, just run it through CTM to
keep your sources up to date.Do not remove the deltas if they are hard to download again.
You just might want to keep them around in case something bad
happens. Even if you only have floppy disks, consider using
fdwrite to make a copy.Keeping Your Local ChangesAs a developer one would like to experiment with and change
files in the source tree. CTM
supports local modifications in a limited way: before checking
for the presence of a file foo, it first
looks for foo.ctm. If this file exists,
CTM will operate on it instead of
foo.This behavior gives us a simple way to maintain local
changes: simply copy the files you plan to modify to the
corresponding file names with a .ctm
suffix. Then you can freely hack the code, while CTM keeps the
.ctm file up-to-date.Other Interesting CTM OptionsFinding Out Exactly What Would Be Touched by an
UpdateYou can determine the list of changes that
CTM will make on your source
repository using the option to
CTM.This is useful if you would like to keep logs of the
changes, pre- or post- process the modified files in any
manner, or just are feeling a tad paranoid.Making Backups Before UpdatingSometimes you may want to backup all the files that would
be changed by a CTM update.Specifying the option
causes CTM to backup all files that
would be touched by a given CTM
delta to backup-file.Restricting the Files Touched by an UpdateSometimes you would be interested in restricting the scope
of a given CTM update, or may be
interested in extracting just a few files from a sequence of
deltas.You can control the list of files that
CTM would operate on by specifying
filtering regular expressions using the
and options.For example, to extract an up-to-date copy of
lib/libc/Makefile from your collection of
saved CTM deltas, run the commands:&prompt.root; cd /where/ever/you/want/to/extract/it/
&prompt.root; ctm -e '^lib/libc/Makefile' ~ctm/src-xxx.*For every file specified in a
CTM delta, the
and options are applied in the order given
on the command line. The file is processed by
CTM only if it is marked as
eligible after all the and
options are applied to it.Future Plans for CTMTons of them:Use some kind of authentication into the CTM system, so
as to allow detection of spoofed CTM updates.Clean up the options to CTM,
they became confusing and counter intuitive.Miscellaneous StuffThere is a sequence of deltas for the
ports collection too, but interest has not
been all that high yet.CTM MirrorsCTM/FreeBSD is available via anonymous
FTP from the following mirror sites. If you choose to obtain CTM via
anonymous FTP, please try to use a site near you.In case of problems, please contact the &a.ctm-users.name;
mailing list.California, Bay Area, official sourceSouth Africa, backup server for old deltasTaiwan/R.O.C.If you did not find a mirror near to you or the mirror is
incomplete, try to use a search engine such as
alltheweb.Using CVSupIntroductionCVSup is a software package for
distributing and updating source trees from a master CVS
repository on a remote server host. The FreeBSD sources are
maintained in a CVS repository on a central development machine
in California. With CVSup, FreeBSD
users can easily keep their own source trees up to date.CVSup uses the so-called
pull model of updating. Under the pull
model, each client asks the server for updates, if and when they
are wanted. The server waits passively for update requests from
its clients. Thus all updates are instigated by the client.
The server never sends unsolicited updates. Users must either
run the CVSup client manually to get
an update, or they must set up a cron job to
run it automatically on a regular basis.The term CVSup, capitalized just
so, refers to the entire software package. Its main components
are the client cvsup which runs on each
user's machine, and the server cvsupd which
runs at each of the FreeBSD mirror sites.As you read the FreeBSD documentation and mailing lists, you
may see references to sup.
Sup was the predecessor of
CVSup, and it served a similar
purpose. CVSup is used much in the
same way as sup and, in fact, uses configuration files which are
backward-compatible with sup's.
Sup is no longer used in the FreeBSD
project, because CVSup is both faster
and more flexible.InstallationThe easiest way to install CVSup
is to use the precompiled net/cvsup package
from the FreeBSD packages collection.
If you prefer to build CVSup from
source, you can use the net/cvsup
port instead. But be forewarned: the
net/cvsup port depends on the Modula-3
system, which takes a substantial amount of time and
disk space to download and build.If you are going to be using
CVSup on a machine which will not have
&xfree86; or &xorg; installed, such as a server, be
sure to use the port which does not include the
CVSup GUI,
net/cvsup-without-gui.CVSup ConfigurationCVSup's operation is controlled
by a configuration file called the supfile.
There are some sample supfiles in the
directory /usr/share/examples/cvsup/.The information in a supfile answers
the following questions for CVSup:Which files do you
want to receive?Which versions of them
do you want?Where do you want to
get them from?Where do you want to
put them on your own machine?Where do you want to
put your status files?In the following sections, we will construct a typical
supfile by answering each of these
questions in turn. First, we describe the overall structure of
a supfile.A supfile is a text file. Comments
begin with # and extend to the end of the
line. Lines that are blank and lines that contain only
comments are ignored.Each remaining line describes a set of files that the user
wishes to receive. The line begins with the name of a
collection, a logical grouping of files defined by
the server. The name of the collection tells the server which
files you want. After the collection name come zero or more
fields, separated by white space. These fields answer the
questions listed above. There are two types of fields: flag
fields and value fields. A flag field consists of a keyword
standing alone, e.g., delete or
compress. A value field also begins with a
keyword, but the keyword is followed without intervening white
space by = and a second word. For example,
release=cvs is a value field.A supfile typically specifies more than
one collection to receive. One way to structure a
supfile is to specify all of the relevant
fields explicitly for each collection. However, that tends to
make the supfile lines quite long, and it
is inconvenient because most fields are the same for all of the
collections in a supfile.
CVSup provides a defaulting mechanism
to avoid these problems. Lines beginning with the special
pseudo-collection name *default can be used
to set flags and values which will be used as defaults for the
subsequent collections in the supfile. A
default value can be overridden for an individual collection, by
specifying a different value with the collection itself.
Defaults can also be changed or augmented in mid-supfile by
additional *default lines.With this background, we will now proceed to construct a
supfile for receiving and updating the main
source tree of FreeBSD-CURRENT.Which files do you want
to receive?The files available via CVSup
are organized into named groups called
collections. The collections that are
available are described in the following section. In this
example, we
wish to receive the entire main source tree for the FreeBSD
system. There is a single large collection
src-all which will give us all of that.
As a first step toward constructing our
supfile, we
simply list the collections, one per line (in this case,
only one line):src-allWhich version(s) of them
do you want?With CVSup, you can receive
virtually any version of the sources that ever existed.
That is possible because the
cvsupd server works directly from
the CVS repository, which contains all of the versions. You
specify which one of them you want using the
tag= and value
fields.Be very careful to specify any tag=
fields correctly. Some tags are valid only for certain
collections of files. If you specify an incorrect or
misspelled tag, CVSup
will delete files which you probably
do not want deleted. In particular, use only
tag=. for the
ports-* collections.The tag= field names a symbolic tag
in the repository. There are two kinds of tags, revision
tags and branch tags. A revision tag refers to a specific
revision. Its meaning stays the same from day to day. A
branch tag, on the other hand, refers to the latest revision
on a given line of development, at any given time. Because
a branch tag does not refer to a specific revision, it may
mean something different tomorrow than it means
today. contains branch tags that
users might be interested in. When specifying a tag in
CVSup's configuration file, it
must be preceded with tag=
(RELENG_4 will become
tag=RELENG_4).
Keep in mind that only the tag=. is
relevant for the Ports Collection.Be very careful to type the tag name exactly as shown.
CVSup cannot distinguish
between valid and invalid tags. If you misspell the tag,
CVSup will behave as though you
had specified a valid tag which happens to refer to no
files at all. It will delete your existing sources in
that case.When you specify a branch tag, you normally receive the
latest versions of the files on that line of development.
If you wish to receive some past version, you can do so by
specifying a date with the value
field. The &man.cvsup.1; manual page explains how to do
that.For our example, we wish to receive FreeBSD-CURRENT. We
add this line at the beginning of our
supfile:*default tag=.There is an important special case that comes into play
if you specify neither a tag= field nor a
date= field. In that case, you receive
the actual RCS files directly from the server's CVS
repository, rather than receiving a particular version.
Developers generally prefer this mode of operation. By
maintaining a copy of the repository itself on their
systems, they gain the ability to browse the revision
histories and examine past versions of files. This gain is
achieved at a large cost in terms of disk space,
however.Where do you want to get
them from?We use the host= field to tell
cvsup where to obtain its updates. Any
of the CVSup mirror
sites will do, though you should try to select one
that is close to you in cyberspace. In this example we will
use a fictional FreeBSD distribution site,
cvsup99.FreeBSD.org:*default host=cvsup99.FreeBSD.orgYou will need to change the host to one that actually
exists before running CVSup.
On any particular run of
cvsup, you can override the host setting
on the command line, with .Where do you want to put
them on your own machine?The prefix= field tells
cvsup where to put the files it receives.
In this example, we will put the source files directly into
our main source tree, /usr/src. The
src directory is already implicit in
the collections we have chosen to receive, so this is the
correct specification:*default prefix=/usrWhere should
cvsup maintain its status files?The CVSup client maintains
certain status files in what
is called the base directory. These files
help CVSup to work more
efficiently, by keeping track of which updates you have
already received. We will use the standard base directory,
/var/db:*default base=/var/dbIf your base directory does not already exist, now would
be a good time to create it. The cvsup
client will refuse to run if the base directory does not
exist.Miscellaneous supfile
settings:There is one more line of boiler plate that normally
needs to be present in the
supfile:*default release=cvs delete use-rel-suffix compressrelease=cvs indicates that the server
should get its information out of the main FreeBSD CVS
repository. This is virtually always the case, but there
are other possibilities which are beyond the scope of this
discussion.delete gives
CVSup permission to delete files.
You should always specify this, so that
CVSup can keep your source tree
fully up-to-date. CVSup is
careful to delete only those files for which it is
responsible. Any extra files you happen to have will be
left strictly alone.use-rel-suffix is ... arcane. If you
really want to know about it, see the &man.cvsup.1; manual
page. Otherwise, just specify it and do not worry about
it.compress enables the use of
gzip-style compression on the communication channel. If
your network link is T1 speed or faster, you probably should
not use compression. Otherwise, it helps
substantially.Putting it all together:Here is the entire supfile for our
example:*default tag=.
*default host=cvsup99.FreeBSD.org
*default prefix=/usr
*default base=/var/db
*default release=cvs delete use-rel-suffix compress
src-allThe refuse FileAs mentioned above, CVSup uses
a pull method. Basically, this means that
you connect to the CVSup server, and
it says, Here is what you can download from
me..., and your client responds OK, I will take
this, this, this, and this. In the default
configuration, the CVSup client will
take every file associated with the collection and tag you
chose in the configuration file. However, this is not always
what you want, especially if you are synching the doc, ports, or
www trees — most people cannot read four or five
languages, and therefore they do not need to download the
language-specific files. If you are
CVSuping the Ports Collection, you
can get around this by specifying each collection individually
(e.g., ports-astrology,
ports-biology, etc instead of simply
saying ports-all). However, since the doc
and www trees do not have language-specific collections, you
must use one of CVSup's many nifty
features: the refuse file.The refuse file essentially tells
CVSup that it should not take every
single file from a collection; in other words, it tells the
client to refuse certain files from the
server. The refuse file can be found (or, if you do not yet
have one, should be placed) in
base/sup/.
base is defined in your supfile;
our defined base is
/var/db,
which means that by default the refuse file is
/var/db/sup/refuse.The refuse file has a very simple format; it simply
contains the names of files or directories that you do not wish
to download. For example, if you cannot speak any languages other
than English and some German, and you do not feel the need to read
the German translation of documentation, you can put the following in your
refuse file:doc/bn_*
doc/da_*
doc/de_*
doc/el_*
doc/es_*
doc/fr_*
doc/it_*
doc/ja_*
doc/nl_*
doc/no_*
doc/pl_*
doc/pt_*
doc/ru_*
doc/sr_*
doc/tr_*
doc/zh_*and so forth for the other languages (you can find the
full list by browsing the FreeBSD
CVS repository).With this very useful feature, those users who are on
slow links or pay by the minute for their Internet connection
will be able to save valuable time as they will no longer need
to download files that they will never use. For more
information on refuse files and other neat
features of CVSup, please view its
manual page.Running CVSupYou are now ready to try an update. The command line for
doing this is quite simple:&prompt.root; cvsup supfilewhere supfile
is of course the name of the supfile you have just created.
Assuming you are running under X11, cvsup
will display a GUI window with some buttons to do the usual
things. Press the go button, and watch it
run.Since you are updating your actual
/usr/src tree in this example, you will
need to run the program as root so that
cvsup has the permissions it needs to update
your files. Having just created your configuration file, and
having never used this program before, that might
understandably make you nervous. There is an easy way to do a
trial run without touching your precious files. Just create an
empty directory somewhere convenient, and name it as an extra
argument on the command line:&prompt.root; mkdir /var/tmp/dest
&prompt.root; cvsup supfile /var/tmp/destThe directory you specify will be used as the destination
directory for all file updates.
CVSup will examine your usual files
in /usr/src, but it will not modify or
delete any of them. Any file updates will instead land in
/var/tmp/dest/usr/src.
CVSup will also leave its base
directory status files untouched when run this way. The new
versions of those files will be written into the specified
directory. As long as you have read access to
/usr/src, you do not even need to be
root to perform this kind of trial run.If you are not running X11 or if you just do not like GUIs,
you should add a couple of options to the command line when you
run cvsup:&prompt.root; cvsup -g -L 2 supfileThe tells
CVSup not to use its GUI. This is
automatic if you are not running X11, but otherwise you have to
specify it.The tells
CVSup to print out the
details of all the file updates it is doing. There are three
levels of verbosity, from to
. The default is 0, which means total
silence except for error messages.There are plenty of other options available. For a brief
list of them, type cvsup -H. For more
detailed descriptions, see the manual page.Once you are satisfied with the way updates are working, you
can arrange for regular runs of CVSup
using &man.cron.8;.
Obviously, you should not let CVSup
use its GUI when running it from &man.cron.8;.CVSup File CollectionsThe file collections available via
CVSup are organized hierarchically.
There are a few large collections, and they are divided into
smaller sub-collections. Receiving a large collection is
equivalent to receiving each of its sub-collections. The
hierarchical relationships among collections are reflected by
the use of indentation in the list below.The most commonly used collections are
src-all, and
ports-all. The other collections are used
only by small groups of people for specialized purposes, and
some mirror sites may not carry all of them.cvs-all release=cvsThe main FreeBSD CVS repository, including the
cryptography code.distrib release=cvsFiles related to the distribution and mirroring
of FreeBSD.doc-all release=cvsSources for the FreeBSD Handbook and other
documentation. This does not include files for
the FreeBSD web site.ports-all release=cvsThe FreeBSD Ports Collection.If you do not want to update the whole of
ports-all (the whole ports tree),
but use one of the subcollections listed below,
make sure that you always update
the ports-base subcollection!
Whenever something changes in the ports build
infrastructure represented by
ports-base, it is virtually certain
that those changes will be used by real
ports real soon. Thus, if you only update the
real ports and they use some of the new
features, there is a very high chance that their build
will fail with some mysterious error message. The
very first thing to do in this
case is to make sure that your
ports-base subcollection is up to
date.If you are going to be building your own local
copy of ports/INDEX, you
must accept
ports-all (the whole ports tree).
Building ports/INDEX with
a partial tree is not supported. See the
FAQ.ports-accessibility
release=cvsSoftware to help disabled users.ports-arabic
release=cvsArabic language support.ports-archivers
release=cvsArchiving tools.ports-astro
release=cvsAstronomical ports.ports-audio
release=cvsSound support.ports-base
release=cvsThe Ports Collection build infrastructure -
various files located in the
Mk/ and
Tools/ subdirectories of
/usr/ports.Please see the important
warning above: you should
always update this
subcollection, whenever you update any part of
the FreeBSD Ports Collection!ports-benchmarks
release=cvsBenchmarks.ports-biology
release=cvsBiology.ports-cad
release=cvsComputer aided design tools.ports-chinese
release=cvsChinese language support.ports-comms
release=cvsCommunication software.ports-converters
release=cvscharacter code converters.ports-databases
release=cvsDatabases.ports-deskutils
release=cvsThings that used to be on the desktop
before computers were invented.ports-devel
release=cvsDevelopment utilities.ports-dns
release=cvsDNS related software.ports-editors
release=cvsEditors.ports-emulators
release=cvsEmulators for other operating
systems.ports-finance
release=cvsMonetary, financial and related applications.ports-ftp
release=cvsFTP client and server utilities.ports-games
release=cvsGames.ports-german
release=cvsGerman language support.ports-graphics
release=cvsGraphics utilities.ports-hebrew
release=cvsHebrew language support.ports-hungarian
release=cvsHungarian language support.ports-irc
release=cvsInternet Relay Chat utilities.ports-japanese
release=cvsJapanese language support.ports-java
release=cvs&java; utilities.ports-korean
release=cvsKorean language support.ports-lang
release=cvsProgramming languages.ports-mail
release=cvsMail software.ports-math
release=cvsNumerical computation software.ports-mbone
release=cvsMBone applications.ports-misc
release=cvsMiscellaneous utilities.ports-multimedia
release=cvsMultimedia software.ports-net
release=cvsNetworking software.ports-net-im
release=cvsInstant messaging software.ports-net-mgmt
release=cvsNetwork management software.ports-net-p2p
release=cvsPeer to peer networking.ports-news
release=cvsUSENET news software.ports-palm
release=cvsSoftware support for Palm
series.ports-polish
release=cvsPolish language support.ports-portuguese
release=cvsPortuguese language support.ports-print
release=cvsPrinting software.ports-russian
release=cvsRussian language support.ports-science
release=cvsScience.ports-security
release=cvsSecurity utilities.ports-shells
release=cvsCommand line shells.ports-sysutils
release=cvsSystem utilities.ports-textproc
release=cvstext processing utilities (does not
include desktop publishing).ports-ukrainian
release=cvsUkrainian language support.ports-vietnamese
release=cvsVietnamese language support.ports-www
release=cvsSoftware related to the World Wide
Web.ports-x11
release=cvsPorts to support the X window
system.ports-x11-clocks
release=cvsX11 clocks.ports-x11-fm
release=cvsX11 file managers.ports-x11-fonts
release=cvsX11 fonts and font utilities.ports-x11-toolkits
release=cvsX11 toolkits.ports-x11-servers
release=cvsX11 servers.ports-x11-themes
release=cvsX11 themes.ports-x11-wm
release=cvsX11 window managers.src-all release=cvsThe main FreeBSD sources, including the
cryptography code.src-base
release=cvsMiscellaneous files at the top of
/usr/src.src-bin
release=cvsUser utilities that may be needed in
single-user mode
(/usr/src/bin).src-contrib
release=cvsUtilities and libraries from outside the
FreeBSD project, used relatively unmodified
(/usr/src/contrib).src-crypto release=cvsCryptography utilities and libraries from
outside the FreeBSD project, used relatively
unmodified
(/usr/src/crypto).src-eBones release=cvsKerberos and DES
(/usr/src/eBones). Not
used in current releases of FreeBSD.src-etc
release=cvsSystem configuration files
(/usr/src/etc).src-games
release=cvsGames
(/usr/src/games).src-gnu
release=cvsUtilities covered by the GNU Public
License (/usr/src/gnu).src-include
release=cvsHeader files
(/usr/src/include).src-kerberos5
release=cvsKerberos5 security package
(/usr/src/kerberos5).src-kerberosIV
release=cvsKerberosIV security package
(/usr/src/kerberosIV).src-lib
release=cvsLibraries
(/usr/src/lib).src-libexec
release=cvsSystem programs normally executed by other
programs
(/usr/src/libexec).src-release
release=cvsFiles required to produce a FreeBSD
release
(/usr/src/release).src-sbin release=cvsSystem utilities for single-user mode
(/usr/src/sbin).src-secure
release=cvsCryptographic libraries and commands
(/usr/src/secure).src-share
release=cvsFiles that can be shared across multiple
systems
(/usr/src/share).src-sys
release=cvsThe kernel
(/usr/src/sys).src-sys-crypto
release=cvsKernel cryptography code
(/usr/src/sys/crypto).src-tools
release=cvsVarious tools for the maintenance of
FreeBSD
(/usr/src/tools).src-usrbin
release=cvsUser utilities
(/usr/src/usr.bin).src-usrsbin
release=cvsSystem utilities
(/usr/src/usr.sbin).www release=cvsThe sources for the FreeBSD WWW site.distrib release=selfThe CVSup server's own
configuration files. Used by CVSup
mirror sites.gnats release=currentThe GNATS bug-tracking database.mail-archive release=currentFreeBSD mailing list archive.www release=currentThe pre-processed FreeBSD WWW site files (not the
source files). Used by WWW mirror sites.For More InformationFor the CVSup FAQ and other
information about CVSup, see
The
CVSup Home Page.Most FreeBSD-related discussion of
CVSup takes place on the
&a.hackers;. New versions of the software are announced there,
as well as on the &a.announce;.Questions and bug reports should be addressed to the author
of the program at cvsup-bugs@polstra.com.CVSup SitesCVSup servers for FreeBSD are running
at the following sites:
&chap.mirrors.cvsup.inc;
Using PortsnapIntroductionPortsnap is a system for securely
distributing the &os; ports tree. Approximately once an hour,
a snapshot of the ports tree is generated,
repackaged, and cryptographically signed. The resulting files
are then distributed via HTTP.Like CVSup,
Portsnap uses a
pull model of updating: The packaged and
signed ports trees are placed on a web server which waits
passively for clients to request files. Users must either run
&man.portsnap.8; manually to download updates
or set up a &man.cron.8; job to download updates
automatically on a regular basis.For technical reasons, Portsnap
does not update the live ports tree in
/usr/ports/ directly; instead, it works
via a compressed copy of the ports tree stored in
/var/db/portsnap/ by default. This
compressed copy is then used to update the live ports tree.If Portsnap is installed from
the &os; Ports Collection, then the default location for its
compressed snapshot will be /usr/local/portsnap/
instead of /var/db/portsnap/.InstallationOn &os; 6.0 and more recent versions,
Portsnap is contained in the &os;
base system. On older versions of &os;, it can be installed
using the sysutils/portsnap
port.Portsnap ConfigurationPortsnap's operation is controlled
by the /etc/portsnap.conf configuration
file. For most users, the default configuration file will
suffice; for more details, consult the &man.portsnap.conf.5;
manual page.If Portsnap is installed from
the &os; Ports Collection, it will use the configuration file
/usr/local/etc/portsnap.conf instead of
/etc/portsnap.conf. This configuration
file is not created when the port is installed, but a sample
configuration file is distributed; to copy it into place, run
the following command:&prompt.root; cd /usr/local/etc && cp portsnap.conf.sample portsnap.confRunning Portsnap for the First
TimeThe first time &man.portsnap.8; is run,
it will need to download a compressed snapshot of the entire
ports tree into /var/db/portsnap/ (or
/usr/local/portsnap/ if
Portsnap was installed from the
- Ports Collection). This is approximately a 38 MB
+ Ports Collection). For the beginning of 2006 this is approximately a 41 MB
download.&prompt.root; portsnap fetchOnce the compressed snapshot has been downloaded, a
live copy of the ports tree can be extracted into
/usr/ports/. This is necessary even if a
ports tree has already been created in that directory (e.g., by
using CVSup), since it establishes a
baseline from which portsnap can
determine which parts of the ports tree need to be updated
later.&prompt.root; portsnap extractIn the default installation
/usr/ports is not
- created. It should be created before
- portsnap is used.
+ created. If you run &os; 6.0-RELEASE, it should be created before
+ portsnap is used. On more recent
+ versions of &os; or Portsnap,
+ this operation will be done automatically at first use
+ of the portsnap command.Updating the Ports TreeAfter an initial compressed snapshot of the ports tree has
been downloaded and extracted into /usr/ports/,
updating the ports tree consists of two steps:
fetching updates to the compressed
snapshot, and using them to update the
live ports tree. These two steps can be specified to
portsnap as a single command:&prompt.root; portsnap fetch updateSome older versions of portsnap
do not support this syntax; if it fails, try instead the
following:&prompt.root; portsnap fetch
&prompt.root; portsnap updateRunning Portsnap from cronIn order to avoid problems with flash crowds
accessing the Portsnap servers,
portsnap fetch will not run from
a &man.cron.8; job. Instead, a special
portsnap cron command exists, which
waits for a random duration up to 3600 seconds before fetching
updates.In addition, it is strongly recommended that
portsnap update not be run from a
cron job, since it is liable to cause
major problems if it happens to run at the same time as a port
is being built or installed. However, it is safe to update
- the ports INDEX files, and this can be done by passing the
+ the ports' INDEX files, and this can be done by passing the
flag to
portsnap. (Obviously, if
portsnap -I update is run from
cron, then it will be necessary to run
portsnap update without the
flag at a later time in order to update the rest of the tree.)Adding the following line to /etc/crontab
will cause portsnap to update its
- compressed snapshot and the INDEX files in
+ compressed snapshot and the INDEX files in
/usr/ports/, and will send an email if any
installed ports are out of date:0 3 * * * root portsnap -I cron update && pkg_version -vIL=If the system clock is not set to the local time zone,
please replace 3 with a random
value between 0 and 23, in order to spread the load on the
Portsnap servers more evenly.Some older versions of portsnap
do not support listing multiple commands (e.g., cron update)
in the same invocation of portsnap. If
the line above fails, try replacing
portsnap -I cron update with
portsnap cron && portsnap -I update.CVS TagsWhen obtaining or updating sources using
cvs or
CVSup, a revision tag must be specified.
A revision tag refers to either a particular line of &os;
development, or a specific point in time. The first type are called
branch tags, and the second type are called
release tags.Branch TagsAll of these, with the exception of HEAD (which
is always a valid tag), only apply to the src/
tree. The ports/, doc/, and
www/ trees are not branched.HEADSymbolic name for the main line, or FreeBSD-CURRENT.
Also the default when no revision is specified.In CVSup, this tag is represented
by a . (not punctuation, but a literal
. character).In CVS, this is the default when no revision tag is
specified. It is usually not
a good idea to checkout or update to CURRENT sources
on a STABLE machine, unless that is your intent.RELENG_6The line of development for FreeBSD-6.X, also known
as FreeBSD 6-STABLE
+
+
+
+
+ RELENG_6_1
+
+
+ The release branch for FreeBSD-6.1, used only for
+ security advisories and other critical fixes.RELENG_6_0The release branch for FreeBSD-6.0, used only for
security advisories and other critical fixes.RELENG_5The line of development for FreeBSD-5.X, also known
as FreeBSD 5-STABLE.RELENG_5_4The release branch for FreeBSD-5.4, used only
for security advisories and other critical fixes.RELENG_5_3The release branch for FreeBSD-5.3, used only
for security advisories and other critical fixes.RELENG_5_2The release branch for FreeBSD-5.2 and FreeBSD-5.2.1, used only
for security advisories and other critical fixes.RELENG_5_1The release branch for FreeBSD-5.1, used only
for security advisories and other critical fixes.RELENG_5_0The release branch for FreeBSD-5.0, used only
for security advisories and other critical fixes.RELENG_4The line of development for FreeBSD-4.X, also known
as FreeBSD 4-STABLE.RELENG_4_11The release branch for FreeBSD-4.11, used only
for security advisories and other critical fixes.RELENG_4_10The release branch for FreeBSD-4.10, used only
for security advisories and other critical fixes.RELENG_4_9The release branch for FreeBSD-4.9, used only
for security advisories and other critical fixes.RELENG_4_8The release branch for FreeBSD-4.8, used only
for security advisories and other critical fixes.RELENG_4_7The release branch for FreeBSD-4.7, used only
for security advisories and other critical fixes.RELENG_4_6The release branch for FreeBSD-4.6 and FreeBSD-4.6.2,
used only for security advisories and other
critical fixes.RELENG_4_5The release branch for FreeBSD-4.5, used only
for security advisories and other critical fixes.RELENG_4_4The release branch for FreeBSD-4.4, used only
for security advisories and other critical fixes.RELENG_4_3The release branch for FreeBSD-4.3, used only
for security advisories and other critical fixes.RELENG_3The line of development for FreeBSD-3.X, also known
as 3.X-STABLE.RELENG_2_2The line of development for FreeBSD-2.2.X, also known
as 2.2-STABLE. This branch is mostly obsolete.Release TagsThese tags refer to a specific point in time when a particular
version of &os; was released. The release engineering process is
documented in more detail by the
Release Engineering
Information and
Release
Process documents.
The src tree uses tag names that
start with RELENG_ tags.
The ports and
doc trees use tags whose names
begin with RELEASE tags.
Finally, the www tree is not
tagged with any special name for releases.RELENG_6_0_0_RELEASEFreeBSD 6.0RELENG_5_4_0_RELEASEFreeBSD 5.4RELENG_4_11_0_RELEASEFreeBSD 4.11RELENG_5_3_0_RELEASEFreeBSD 5.3RELENG_4_10_0_RELEASEFreeBSD 4.10RELENG_5_2_1_RELEASEFreeBSD 5.2.1RELENG_5_2_0_RELEASEFreeBSD 5.2RELENG_4_9_0_RELEASEFreeBSD 4.9RELENG_5_1_0_RELEASEFreeBSD 5.1RELENG_4_8_0_RELEASEFreeBSD 4.8RELENG_5_0_0_RELEASEFreeBSD 5.0RELENG_4_7_0_RELEASEFreeBSD 4.7RELENG_4_6_2_RELEASEFreeBSD 4.6.2RELENG_4_6_1_RELEASEFreeBSD 4.6.1RELENG_4_6_0_RELEASEFreeBSD 4.6RELENG_4_5_0_RELEASEFreeBSD 4.5RELENG_4_4_0_RELEASEFreeBSD 4.4RELENG_4_3_0_RELEASEFreeBSD 4.3RELENG_4_2_0_RELEASEFreeBSD 4.2RELENG_4_1_1_RELEASEFreeBSD 4.1.1RELENG_4_1_0_RELEASEFreeBSD 4.1RELENG_4_0_0_RELEASEFreeBSD 4.0RELENG_3_5_0_RELEASEFreeBSD-3.5RELENG_3_4_0_RELEASEFreeBSD-3.4RELENG_3_3_0_RELEASEFreeBSD-3.3RELENG_3_2_0_RELEASEFreeBSD-3.2RELENG_3_1_0_RELEASEFreeBSD-3.1RELENG_3_0_0_RELEASEFreeBSD-3.0RELENG_2_2_8_RELEASEFreeBSD-2.2.8RELENG_2_2_7_RELEASEFreeBSD-2.2.7RELENG_2_2_6_RELEASEFreeBSD-2.2.6RELENG_2_2_5_RELEASEFreeBSD-2.2.5RELENG_2_2_2_RELEASEFreeBSD-2.2.2RELENG_2_2_1_RELEASEFreeBSD-2.2.1RELENG_2_2_0_RELEASEFreeBSD-2.2.0AFS SitesAFS servers for FreeBSD are running at the following sites:SwedenThe path to the files are:
/afs/stacken.kth.se/ftp/pub/FreeBSD/stacken.kth.se # Stacken Computer Club, KTH, Sweden
130.237.234.43 #hot.stacken.kth.se
130.237.237.230 #fishburger.stacken.kth.se
130.237.234.3 #milko.stacken.kth.seMaintainer ftp@stacken.kth.sersync SitesThe following sites make FreeBSD available through the rsync
protocol. The rsync utility works in
much the same way as the &man.rcp.1; command,
but has more options and uses the rsync remote-update protocol
which transfers only the differences between two sets of files,
thus greatly speeding up the synchronization over the network.
This is most useful if you are a mirror site for the
FreeBSD FTP server, or the CVS repository. The
rsync suite is available for many
operating systems, on FreeBSD, see the
net/rsync
port or use the package.Czech Republicrsync://ftp.cz.FreeBSD.org/Available collections:ftp: A partial mirror of the FreeBSD FTP
server.FreeBSD: A full mirror of the FreeBSD FTP
server.Germanyrsync://grappa.unix-ag.uni-kl.de/Available collections:freebsd-cvs: The full FreeBSD CVS
repository.This machine also mirrors the CVS repositories of the
NetBSD and the OpenBSD projects, among others.Netherlandsrsync://ftp.nl.FreeBSD.org/Available collections:vol/4/freebsd-core: A full mirror of the
FreeBSD FTP server.United Kingdomrsync://rsync.mirror.ac.uk/Available collections:ftp.FreeBSD.org: A full mirror of the
FreeBSD FTP server.United States of Americarsync://ftp-master.FreeBSD.org/This server may only be used by FreeBSD primary mirror
sites.Available collections:FreeBSD: The master archive of the FreeBSD
FTP server.acl: The FreeBSD master ACL
list.rsync://ftp13.FreeBSD.org/Available collections:FreeBSD: A full mirror of the FreeBSD FTP
server.
diff --git a/zh_TW.Big5/books/handbook/multimedia/chapter.sgml b/zh_TW.Big5/books/handbook/multimedia/chapter.sgml
index 689de84000..cdd803f47f 100644
--- a/zh_TW.Big5/books/handbook/multimedia/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/multimedia/chapter.sgml
@@ -1,1842 +1,1833 @@
RossLippertEdited by 多媒體影音娛樂(Multimedia)概述FreeBSD 廣泛地支援各種音效卡, 讓您可以享受來自電腦上的高傳真音質(Hi-Fi),
此外還包括了錄製和播放 MPEG Audio Layer 3 (MP3)、 WAV、 以及 Ogg Vorbis
等許多種格式聲音的能力。同時 FreeBSD Ports Collection 也包括了許多的應用程式,
讓您可以錄音、編修音效以及控制 MIDI 配備。要是喜歡動手嘗試不同的體驗, FreeBSD 也能播放一般的視訊檔和 DVD。
編碼、轉換和播放視訊的程式比起處理聲音的程式略少一些。例如, 在撰寫這章時,
FreeBSD Ports Collection 中還沒有類似 audio/sox 那樣好用的編碼工具,能夠用來轉換不同的格式。
不過,這個領域的軟體研發進展是相當迅速的。本章將介紹設定音效卡的必要步驟。先前介紹到的 X11
() 安裝和設定裡,已經講到了顯示卡的部份,
但要想有更好的播放效果, 仍需要一些細部調整。讀完這章,您將了解:如何設定系統,以正確識別音效卡。Methods to test that your card is working using
sample applications.如何解決音效卡的設定問題。How to playback and encode MP3s and other audio.How video is supported by the X server.Some video player/encoder ports which give good results.如何播放 DVD 的 .mpg 及
.avi 檔如何從 CD 和 DVD 中擷取(rip)檔案。如何設定電視卡如何設定掃描器在閱讀這章之前,您應當了解:知道如何設定、安裝新的 kernel ()。Trying to mount audio CDs
with the &man.mount.8; command will
result in an error, at least, and a kernel
panic, at worst. These media have specialized
encodings which differ from the usual ISO-filesystem.MosesMooreContributed by MarcFonvieilleEnhanced for &os; 5.X by 設定音效卡Configuring the SystemPCIISAsound cardsBefore you begin, you should know the model of the card you
have, the chip it uses, and whether it is a PCI or ISA card.
FreeBSD supports a wide variety of both PCI and ISA cards.
Check the supported audio devices list of the Hardware Notes to see if
your card is supported. This document will also mention which
driver supports your card.kernelconfigurationTo use your sound device, you will need to load the proper
device driver. This may be accomplished in one of two ways.
The easiest way is to simply load a kernel module for your sound
card with &man.kldload.8; which can either be done from the
command line:&prompt.root; kldload snd_emu10k1or by adding the appropriate line to the file
/boot/loader.conf like this:snd_emu10k1_load="YES"These examples are for a Creative &soundblaster; Live! sound
card. Other available loadable sound modules are listed in
/boot/defaults/loader.conf.
If you are not sure which driver to use, you may try to load
the snd_driver module:&prompt.root; kldload snd_driverThis is a metadriver loading the most common device drivers
at once. This speeds up the search for the correct driver. It
is also possible to load all sound drivers via the
/boot/loader.conf facility.If you wish to find out the driver selected for your
soundcard after loading the snd_driver
metadriver, you may check the /dev/sndstat
file with the cat /dev/sndstat
command.Under &os; 4.X, to load all sound drivers, you have
to load the snd module instead of
snd_driver.A second method is to statically
compile in support for your sound card in your kernel. The
section below provides the information you need to add support
for your hardware in this manner. For more information about
recompiling your kernel, please see .Configuring a Custom Kernel with Sound SupportThe first thing to do is adding the generic audio driver
&man.sound.4; to the kernel, for that you will need to
add the following line to the kernel configuration file:device soundUnder &os; 4.X, you would use the following
line:device pcmThen we have to add the support for our sound card.
Therefore, we need to know which driver supports the card.
Check the supported audio devices list of the Hardware Notes, to
determine the correct driver for your sound card. For
example, a Creative &soundblaster; Live! sound card is
supported by the &man.snd.emu10k1.4; driver. To add the support
for this card, use the following:device snd_emu10k1Be sure to read the manual page of the driver for the
syntax to use. Information regarding the syntax of sound
drivers in the kernel configuration can also be found in the
/usr/src/sys/conf/NOTES file
(/usr/src/sys/i386/conf/LINT for
&os; 4.X).Non-PnP ISA cards may require you to provide the kernel
with information on the sound card settings (IRQ, I/O port,
etc). This is done via the
/boot/device.hints file. At system boot,
the &man.loader.8; will read this file and pass the settings
to the kernel. For example, an old
Creative &soundblaster; 16 ISA non-PnP card will use the
&man.snd.sbc.4; driver in conjunction with snd_sb16(4). For this card the following lines have to be added to
the kernel configuration file:device snd_sbc
device snd_sb16as well as the following in
/boot/device.hints:hint.sbc.0.at="isa"
hint.sbc.0.port="0x220"
hint.sbc.0.irq="5"
hint.sbc.0.drq="1"
hint.sbc.0.flags="0x15"In this case, the card uses the 0x220
I/O port and the IRQ 5.The syntax used in the
/boot/device.hints file is covered in the
sound driver manual page. On &os; 4.X, these settings
are directly written in the kernel configuration file. In the
case of our ISA card, we would only use this line:device sbc0 at isa? port 0x220 irq 5 drq 1 flags 0x15The settings shown above are the defaults. In some
cases, you may need to change the IRQ or the other settings to
match your card. See the &man.snd.sbc.4; manual page for more
information.Under &os; 4.X, some systems with built-in
motherboard sound devices may require the following option in
the kernel configuration:options PNPBIOSTesting the Sound CardAfter rebooting with the modified kernel, or after loading
the required module, the sound card should appear in your system
message buffer (&man.dmesg.8;) as something like:pcm0: <Intel ICH3 (82801CA)> port 0xdc80-0xdcbf,0xd800-0xd8ff irq 5 at device 31.5 on pci0
pcm0: [GIANT-LOCKED]
pcm0: <Cirrus Logic CS4205 AC97 Codec>The status of the sound card may be checked via the
/dev/sndstat file:&prompt.root; cat /dev/sndstat
FreeBSD Audio Driver (newpcm)
Installed devices:
pcm0: <Intel ICH3 (82801CA)> at io 0xd800, 0xdc80 irq 5 bufsz 16384
kld snd_ich (1p/2r/0v channels duplex default)The output from your system may vary. If no
pcm devices show up, go back and review
what was done earlier. Go through your kernel
configuration file again and make sure the correct
device is chosen. Common problems are listed in .If all goes well, you should now have a functioning sound
card. If your CD-ROM or DVD-ROM drive is properly coupled to
your sound card, you can put a CD in the drive and play it
with &man.cdcontrol.1;:&prompt.user; cdcontrol -f /dev/acd0 play 1Various applications, such as audio/workman can provide a friendlier
interface. You may want to install an application such as
audio/mpg123 to listen to
MP3 audio files. A quick way to test the card is sending data
to the /dev/dsp, like this:&prompt.user; cat filename > /dev/dspwhere filename can be any file.
This command line should produce some noise, confirming the
sound card is actually working.&os; 4.X users need to create the sound card device
nodes before being able to use it. If the card showed up in
message buffer as pcm0, you will have
to run the following as root:&prompt.root; cd /dev
&prompt.root; sh MAKEDEV snd0If the card detection returned pcm1,
follow the same steps as shown above, replacing
snd0 with
snd1.MAKEDEV will create a group of device
nodes that will be used by the different sound related
applications.Sound card mixer levels can be changed via the &man.mixer.8;
command. More details can be found in the &man.mixer.8; manual
page.Common Problemsdevice nodesI/O portIRQDSPErrorSolutionunsupported subdevice XXOne or more of the device nodes was not created
correctly. Repeat the steps above.sb_dspwr(XX) timed outThe I/O port is not set correctly.bad irq XXThe IRQ is set incorrectly. Make sure that
the set IRQ and the sound IRQ are the same.xxx: gus pcm not attached, out of memoryThere is not enough available memory to use
the device.xxx: can't open /dev/dsp!Check with fstat | grep dsp
if another application is holding the device open.
Noteworthy troublemakers are esound and KDE's sound
support.MunishChopraContributed by Utilizing Multiple Sound SourcesIt is often desirable to have multiple sources of sound that
are able to play simultaneously, such as when
esound or
artsd do not support sharing of the
sound device with a certain application.FreeBSD lets you do this through Virtual Sound
Channels, which can be set with the &man.sysctl.8;
facility. Virtual channels allow you to multiplex your sound
card's playback channels by mixing sound in the kernel.To set the number of virtual channels, there are two sysctl
knobs which, if you are the root user, can
be set like this:&prompt.root; sysctl hw.snd.pcm0.vchans=4
&prompt.root; sysctl hw.snd.maxautovchans=4The above example allocates four virtual channels, which is a
practical number for everyday use. hw.snd.pcm0.vchans
is the number of virtual channels pcm0 has, and is configurable
once a device has been attached.
hw.snd.maxautovchans is the number of virtual channels
a new audio device is given when it is attached using
&man.kldload.8;. Since the pcm module
can be loaded independently of the hardware drivers,
hw.snd.maxautovchans can store how many
virtual channels any devices which are attached later will be
given.You cannot change the number of virtual channels for a
device while it is in use. First close any programs using the
device, such as music players or sound daemons.If you are not using &man.devfs.5;, you will have to point
your applications at
/dev/dsp0.x,
where x is 0 to 3 if
hw.snd.pcm.0.vchans is set to 4 as in the
above example. On a system using &man.devfs.5;, the above will
automatically be allocated transparently to the user.JosefEl-RayesContributed by 設定預設(Mixer Channel)的音量大小本功能只有在 &os; 5.3-RELEASE 及之後版本才有支援。The default values for the different mixer channels are
hardcoded in the sourcecode of the &man.pcm.4; driver. There are
a lot of different applications and daemons that allow
you to set values for the mixer they remember and set
each time they are started, but this is not a clean
solution, we want to have default values at the driver
level. This is accomplished by defining the appropriate
values in /boot/device.hints. E.g.:hint.pcm.0.vol="100"This will set the volume channel to a default value of
100, when the &man.pcm.4; module is loaded.ChernLeeContributed by MP3 音樂MP3 (MPEG Layer 3 Audio) accomplishes near CD-quality sound,
leaving no reason to let your FreeBSD workstation fall short of
its offerings.MP3 PlayersBy far, the most popular X11 MP3 player is
XMMS (X Multimedia System).
Winamp
skins can be used with XMMS since the
GUI is almost identical to that of Nullsoft's
Winamp.
XMMS also has native plug-in
support.XMMS can be installed from the
multimedia/xmms port or package.XMMS' interface is intuitive,
with a playlist, graphic equalizer, and more. Those familiar
with Winamp will find
XMMS simple to use.The audio/mpg123 port is an alternative,
command-line MP3 player.mpg123 can be run by specifying
the sound device and the MP3 file on the command line, as
shown below:&prompt.root; mpg123 -a /dev/dsp1.0 Foobar-GreatestHits.mp3
High Performance MPEG 1.0/2.0/2.5 Audio Player for Layer 1, 2 and 3.
Version 0.59r (1999/Jun/15). Written and copyrights by Michael Hipp.
Uses code from various people. See 'README' for more!
THIS SOFTWARE COMES WITH ABSOLUTELY NO WARRANTY! USE AT YOUR OWN RISK!
Playing MPEG stream from Foobar-GreatestHits.mp3 ...
MPEG 1.0 layer III, 128 kbit/s, 44100 Hz joint-stereo
/dev/dsp1.0 should be replaced with the
dsp device entry on your system.Ripping CD Audio TracksBefore encoding a CD or CD track to MP3, the audio data on
the CD must be ripped onto the hard drive. This is done by
copying the raw CDDA (CD Digital Audio) data to WAV
files.The cdda2wav tool, which is a part of
the sysutils/cdrtools
suite, is used for ripping audio information from CDs and the
information associated with them.With the audio CD in the drive, the following command can
be issued (as root) to rip an entire CD
into individual (per track) WAV files:&prompt.root; cdda2wav -D 0,1,0 -Bcdda2wav will support
ATAPI (IDE) CDROM drives. To rip from an IDE drive, specify
the device name in place of the SCSI unit numbers. For
example, to rip track 7 from an IDE drive:&prompt.root; cdda2wav -D /dev/acd0a -t 7The
indicates the SCSI device 0,1,0,
which corresponds to the output of cdrecord
-scanbus.To rip individual tracks, make use of the
option as shown:&prompt.root; cdda2wav -D 0,1,0 -t 7This example rips track seven of the audio CDROM. To rip
a range of tracks, for example, track one to seven, specify a
range:&prompt.root; cdda2wav -D 0,1,0 -t 1+7The utility &man.dd.1; can also be used to extract audio tracks
on ATAPI drives, read
for more information on that possibility.Encoding MP3sNowadays, the mp3 encoder of choice is
lame.
Lame can be found at
audio/lame in the ports tree.Using the ripped WAV files, the following command will
convert audio01.wav to
audio01.mp3:&prompt.root; lame -h -b 128 \
--tt "Foo Song Title" \
--ta "FooBar Artist" \
--tl "FooBar Album" \
--ty "2001" \
--tc "Ripped and encoded by Foo" \
--tg "Genre" \
audio01.wav audio01.mp3128 kbits seems to be the standard MP3 bitrate in use.
Many enjoy the higher quality 160, or 192. The higher the
bitrate, the more disk space the resulting MP3 will
consume--but the quality will be higher. The
option turns on the higher quality
but a little slower mode. The options beginning with
indicate ID3 tags, which usually contain
song information, to be embedded within the MP3 file.
Additional encoding options can be found by consulting the
lame man page.Decoding MP3sIn order to burn an audio CD from MP3s, they must be
converted to a non-compressed WAV format. Both
XMMS and
mpg123 support the output of MP3 to
an uncompressed file format.Writing to Disk in XMMS:Launch XMMS.Right-click on the window to bring up the
XMMS menu.Select Preference under
Options.Change the Output Plugin to Disk Writer
Plugin.Press Configure.Enter (or choose browse) a directory to write the
uncompressed files to.Load the MP3 file into XMMS
as usual, with volume at 100% and EQ settings turned
off.Press Play —
XMMS will appear as if it is
playing the MP3, but no music will be heard. It is
actually playing the MP3 to a file.Be sure to set the default Output Plugin back to what
it was before in order to listen to MP3s again.Writing to stdout in mpg123:Run mpg123 -s audio01.mp3
> audio01.pcmXMMS writes a file in the WAV
format, while mpg123 converts the
MP3 into raw PCM audio data. Both of these formats can be
used with cdrecord to create audio CDs.
You have to use raw PCM with &man.burncd.8;.
If you use WAV files, you will notice a small tick sound at the
beginning of each track, this sound is the header of the WAV
file. You can simply remove the header of a WAV file with the
utility SoX (it can be installed from
the audio/sox port or
package):&prompt.user; sox -t wav -r 44100 -s -w -c 2 track.wav track.rawRead for more information on using a
CD burner in FreeBSD.RossLippertContributed by 播放影片Video playback is a very new and rapidly developing application
area. Be patient. Not everything is going to work as smoothly as
it did with sound.Before you begin, you should know the model of the video
card you have and the chip it uses. While &xorg; and &xfree86; support a
wide variety of video cards, fewer give good playback
performance. To obtain a list of extensions supported by the
X server using your card use the command &man.xdpyinfo.1; while
X11 is running.It is a good idea to have a short MPEG file which can be
treated as a test file for evaluating various players and
options. Since some DVD players will look for DVD media in
/dev/dvd by default, or have this device
name hardcoded in them, you might find it useful to make
symbolic links to the proper devices:&prompt.root; ln -sf /dev/acd0c /dev/dvd
&prompt.root; ln -sf /dev/racd0c /dev/rdvdOn FreeBSD 5.X, which uses &man.devfs.5; there
is a slightly different set of recommended links:&prompt.root; ln -sf /dev/acd0 /dev/dvd
&prompt.root; ln -sf /dev/acd0 /dev/rdvdNote that due to the nature of &man.devfs.5;,
manually created links like these will not persist if you reboot
your system. In order to create the symbolic links
automatically whenever you boot your system, add the following
lines to /etc/devfs.conf:link acd0 dvd
link acd0 rdvdAdditionally, DVD decryption, which requires invoking
special DVD-ROM functions, requires write permission on the DVD
devices.kernel optionsCPU_ENABLE_SSEkernel optionsUSER_LDTSome of the ports discussed rely on the following kernel
options to build correctly. Before attempting to build, add
this option to the kernel configuration file, build a new kernel, and reboot:options CPU_ENABLE_SSEOn &os; 4.X options USER_LDT should
be added to the kernel configuration file. This option is not
available on &os; 5.X and later version.To enhance the shared memory X11 interface, it is
recommended that the values of some &man.sysctl.8; variables
should be increased:kern.ipc.shmmax=67108864
kern.ipc.shmall=32768Determining Video CapabilitiesXVideoSDLDGAThere are several possible ways to display video under X11.
What will really work is largely hardware dependent. Each
method described below will have varying quality across
different hardware. Secondly, the rendering of video in X11 is
a topic receiving a lot of attention lately, and with each
version of &xorg;, or of &xfree86;, there may be significant improvement.A list of common video interfaces:X11: normal X11 output using shared memory.XVideo: an extension to the X11
interface which supports video in any X11 drawable.SDL: the Simple Directmedia Layer.DGA: the Direct Graphics Access.SVGAlib: low level console graphics layer.XVideo&xorg; and &xfree86; 4.X have an extension called
XVideo (aka Xvideo, aka Xv, aka xv) which
allows video to be directly displayed in drawable objects
through a special acceleration. This extension provides very
good quality playback even on low-end machines.To check whether the extension is running,
use xvinfo:&prompt.user; xvinfoXVideo is supported for your card if the result looks like:X-Video Extension version 2.2
screen #0
Adaptor #0: "Savage Streams Engine"
number of ports: 1
port base: 43
operations supported: PutImage
supported visuals:
depth 16, visualID 0x22
depth 16, visualID 0x23
number of attributes: 5
"XV_COLORKEY" (range 0 to 16777215)
client settable attribute
client gettable attribute (current value is 2110)
"XV_BRIGHTNESS" (range -128 to 127)
client settable attribute
client gettable attribute (current value is 0)
"XV_CONTRAST" (range 0 to 255)
client settable attribute
client gettable attribute (current value is 128)
"XV_SATURATION" (range 0 to 255)
client settable attribute
client gettable attribute (current value is 128)
"XV_HUE" (range -180 to 180)
client settable attribute
client gettable attribute (current value is 0)
maximum XvImage size: 1024 x 1024
Number of image formats: 7
id: 0x32595559 (YUY2)
guid: 59555932-0000-0010-8000-00aa00389b71
bits per pixel: 16
number of planes: 1
type: YUV (packed)
id: 0x32315659 (YV12)
guid: 59563132-0000-0010-8000-00aa00389b71
bits per pixel: 12
number of planes: 3
type: YUV (planar)
id: 0x30323449 (I420)
guid: 49343230-0000-0010-8000-00aa00389b71
bits per pixel: 12
number of planes: 3
type: YUV (planar)
id: 0x36315652 (RV16)
guid: 52563135-0000-0000-0000-000000000000
bits per pixel: 16
number of planes: 1
type: RGB (packed)
depth: 0
red, green, blue masks: 0x1f, 0x3e0, 0x7c00
id: 0x35315652 (RV15)
guid: 52563136-0000-0000-0000-000000000000
bits per pixel: 16
number of planes: 1
type: RGB (packed)
depth: 0
red, green, blue masks: 0x1f, 0x7e0, 0xf800
id: 0x31313259 (Y211)
guid: 59323131-0000-0010-8000-00aa00389b71
bits per pixel: 6
number of planes: 3
type: YUV (packed)
id: 0x0
guid: 00000000-0000-0000-0000-000000000000
bits per pixel: 0
number of planes: 0
type: RGB (packed)
depth: 1
red, green, blue masks: 0x0, 0x0, 0x0Also note that the formats listed (YUV2, YUV12, etc) are not
present with every implementation of XVideo and their absence may
hinder some players.If the result looks like:X-Video Extension version 2.2
screen #0
no adaptors presentThen XVideo is probably not supported for your card.If XVideo is not supported for your card, this only means
that it will be more difficult for your display to meet the
computational demands of rendering video. Depending on your
video card and processor, though, you might still be able to
have a satisfying experience. You should probably read about
ways of improving performance in the advanced reading .Simple Directmedia LayerThe Simple Directmedia Layer, SDL, was intended to be a
porting layer between µsoft.windows;, BeOS, and &unix;,
allowing cross-platform applications to be developed which made
efficient use of sound and graphics. The SDL layer provides a
low-level abstraction to the hardware which can sometimes be
more efficient than the X11 interface.The SDL can be found at devel/sdl12.Direct Graphics AccessDirect Graphics Access is an X11 extension which allows
a program to bypass the X server and directly alter the
framebuffer. Because it relies on a low level memory mapping to
effect this sharing, programs using it must be run as
root.The DGA extension can be tested and benchmarked by
&man.dga.1;. When dga is running, it
changes the colors of the display whenever a key is pressed. To
quit, use q.Ports and Packages Dealing with Videovideo portsvideo packagesThis section discusses the software available from the
FreeBSD Ports Collection which can be used for video playback.
Video playback is a very active area of software development,
and the capabilities of various applications are bound to
diverge somewhat from the descriptions given here.Firstly, it is important to know that many of the video
applications which run on FreeBSD were developed as Linux
applications. Many of these applications are still
beta-quality. Some of the problems that you may encounter with
video packages on FreeBSD include:An application cannot playback a file which another
application produced.An application cannot playback a file which the
application itself produced.The same application on two different machines,
rebuilt on each machine for that machine, plays back the same
file differently.A seemingly trivial filter like rescaling of the image
size results in very bad artifacts from a buggy rescaling
routine.An application frequently dumps core.Documentation is not installed with the port and can be
found either on the web or under the port's work
directory.Many of these applications may also exhibit
Linux-isms. That is, there may be
issues resulting from the way some standard libraries are
implemented in the Linux distributions, or some features of the
Linux kernel which have been assumed by the authors of the
applications. These issues are not always noticed and worked around
by the port maintainers, which can lead to problems like
these:The use of /proc/cpuinfo to detect
processor characteristics.A misuse of threads which causes a program to hang upon
completion instead of truly terminating.Software not yet in the FreeBSD Ports Collection
which is commonly used in conjunction with the application.So far, these application developers have been cooperative with
port maintainers to minimize the work-arounds needed for
port-ing.MPlayerMPlayer is a recently developed and rapidly developing
video player. The goals of the MPlayer team are speed and
flexibility on Linux and other Unices. The project was
started when the team founder got fed up with bad playback
performance on then available players. Some would say that
the graphical interface has been sacrificed for a streamlined
design. However, once
you get used to the command line options and the key-stroke
controls, it works very well.Building MPlayerMPlayermakingMPlayer resides in multimedia/mplayer.
MPlayer performs a variety of
hardware checks during the build process, resulting in a
binary which will not be portable from one system to
another. Therefore, it is important to build it from
ports and not to use a binary package. Additionally, a
number of options can be specified in the make
command line, as described in the Makefile and at the start of the build:&prompt.root; cd /usr/ports/multimedia/mplayer
&prompt.root; make
N - O - T - E
Take a careful look into the Makefile in order
to learn how to tune mplayer towards you personal preferences!
For example,
make WITH_GTK1
builds MPlayer with GTK1-GUI support.
If you want to use the GUI, you can either install
/usr/ports/multimedia/mplayer-skins
or download official skin collections from
http://www.mplayerhq.hu/homepage/dload.html
The default port options should be sufficient for most
users. However, if you need the XviD codec, you have to
specify the WITH_XVID option in the
command line. The default DVD device can also be defined
with the WITH_DVD_DEVICE option, by
default /dev/acd0 will be used.As of this writing, the MPlayer port will build its HTML
documentation and two executables,
mplayer, and
mencoder, which is a tool for
re-encoding video.The HTML documentation for MPlayer is very informative.
If the reader finds the information on video hardware and
interfaces in this chapter lacking, the MPlayer documentation
is a very thorough supplement. You should definitely take
the time to read the MPlayer
documentation if you are looking for information about video
support in &unix;.Using MPlayerMPlayeruseAny user of MPlayer must set up a
.mplayer subdirectory of her
home directory. To create this necessary subdirectory,
you can type the following:&prompt.user; cd /usr/ports/multimedia/mplayer
&prompt.user; make install-userThe command options for mplayer are
listed in the manual page. For even more detail there is HTML
documentation. In this section, we will describe only a few
common uses.To play a file, such as
testfile.avi,
through one of the various video interfaces set the
option:&prompt.user; mplayer -vo xv testfile.avi&prompt.user; mplayer -vo sdl testfile.avi&prompt.user; mplayer -vo x11 testfile.avi&prompt.root; mplayer -vo dga testfile.avi&prompt.root; mplayer -vo 'sdl:dga' testfile.aviIt is worth trying all of these options, as their relative
performance depends on many factors and will vary significantly
with hardware.To play from a DVD, replace the
testfile.avi with where N is
the title number to play and
DEVICE is the
device node for the DVD-ROM. For example, to play title 3
from /dev/dvd:&prompt.root; mplayer -vo xv dvd://3 -dvd-device /dev/dvdThe default DVD device can be defined during the build
of the MPlayer port via the
WITH_DVD_DEVICE option. By default,
this device is /dev/acd0. More
details can be found in the port
Makefile.To stop, pause, advance and so on, consult the
keybindings, which are output by running mplayer
-h or read the manual page.Additional important options for playback are:
which engages the fullscreen mode
and which helps performance.In order for the mplayer command line to not become too
large, the user can create a file
.mplayer/config and set default options
there:vo=xv
fs=yes
zoom=yesFinally, mplayer can be used to rip a
DVD title into a .vob file. To dump
out the second title from a DVD, type this:&prompt.root; mplayer -dumpstream -dumpfile out.vob dvd://2 -dvd-device /dev/dvdThe output file, out.vob, will be
MPEG and can be manipulated by the other packages described
in this section.mencodermencoderBefore using
mencoder it is a good idea to
familiarize yourself with the options from the HTML
documentation. There is a manual page, but it is not very
useful without the HTML documentation. There are innumerable ways to
improve quality, lower bitrate, and change formats, and some
of these tricks may make the difference between good
or bad performance. Here are a couple of examples to get
you going. First a simple copy:&prompt.user; mencoder input.avi -oac copy -ovc copy -o output.aviImproper combinations of command line options can yield
output files that are
unplayable even by mplayer. Thus, if you
just want to rip to a file, stick to the
in mplayer.To convert input.avi to the MPEG4
codec with MPEG3 audio encoding (audio/lame is required):&prompt.user; mencoder input.avi -oac mp3lame -lameopts br=192 \
-ovc lavc -lavcopts vcodec=mpeg4:vhq -o output.aviThis has produced output playable by mplayer
and xine.input.avi can be replaced with
and run as
root to re-encode a DVD title
directly. Since you are likely to be dissatisfied with
your results the first time around, it is recommended you
dump the title to a file and work on the file.The xine Video PlayerThe xine video player is a project of wide scope aiming not only at being an
all in one video solution, but also in producing a reusable base
library and a modular executable which can be extended with
plugins. It comes both as a package and as a port, multimedia/xine.The xine player
is still very rough around the edges, but it is clearly off to a
good start. In practice, xine requires either a fast CPU with a
fast video card, or support for the XVideo extension. The GUI is
usable, but a bit clumsy.As of this writing, there is no input module shipped with
xine which will play CSS encoded DVD's. There are third party
builds which do have modules for this built in them, but none
of these are in the FreeBSD Ports Collection.Compared to MPlayer, xine does more for the user, but at the
same time, takes some of the more fine-grained control away from
the user. The xine video player
performs best on XVideo interfaces.By default, xine player will
start up in a graphical user interface. The menus can then be
used to open a specific file:&prompt.user; xineAlternatively, it may be invoked to play a file immediately
without the GUI with the command:&prompt.user; xine -g -p mymovie.aviThe transcode UtilitiesThe software transcode is not a player, but a suite of tools for
re-encoding video and audio files. With transcode, one has the
ability to merge video files, repair broken files, using command
line tools with stdin/stdout stream
interfaces.A great number of options can be specified during
the build from the multimedia/transcode port, we recommend the
following command line to build
transcode:&prompt.root; make WITH_OPTIMIZED_CFLAGS=yes WITH_LIBA52=yes WITH_LAME=yes WITH_OGG=yes \
WITH_MJPEG=yes -DWITH_XVID=yesThe proposed settings should be sufficient for most users.To illustrate transcode capacities, one
example to show how to convert a DivX file into a PAL MPEG-1
file (PAL VCD):&prompt.user; transcode -i input.avi -V --export_prof vcd-pal -o output_vcd
&prompt.user; mplex -f 1 -o output_vcd.mpg output_vcd.m1v output_vcd.mpaThe resulting MPEG file,
output_vcd.mpg, is ready to be played with
MPlayer. You could even burn the
file on a CD-R media to create a Video CD, in this case you will
need to install and use both multimedia/vcdimager and sysutils/cdrdao programs.There is a manual page for transcode, but
you should also consult the transcode
wiki for further information and examples.Further ReadingThe various video software packages for FreeBSD are
developing rapidly. It is quite possible that in the near
future many of the problems discussed here will have been
resolved. In the mean time, those who
want to get the very most out of FreeBSD's A/V capabilities will
have to cobble together knowledge from several FAQs and tutorials
and use a few different applications. This section exists to
give the reader pointers to such additional information.The
MPlayer documentation
is very technically informative.
These documents should probably be consulted by anyone wishing
to obtain a high level of expertise with &unix; video. The
MPlayer mailing list is hostile to anyone who has not bothered
to read the documentation, so if you plan on making bug reports
to them, RTFM.The
xine HOWTO
contains a chapter on performance improvement
which is general to all players.Finally, there are some other promising applications which
the reader may try:Avifile which
is also a port multimedia/avifile.Ogle
which is also a port multimedia/ogle.Xtheatermultimedia/dvdauthor, an open
source package for authoring DVD content.JosefEl-RayesOriginal contribution by MarcFonvieilleEnhanced and adapted by 設定電視卡(TV Cards)TV cards介紹電視卡(TV card)可以讓您用電腦來看無線、有線電視節目。許多卡都是透過 RCA 或 S-video
輸入端子來接收視訊,而且有些卡還可接收 FM 廣播的功能。&os; 可透過 &man.bktr.4; 驅動程式,來支援 PCI 介面的電視卡,只要這些卡使用的是 Brooktree Bt848/849/878/879
或 Conexant CN-878/Fusion 878a 視訊擷取晶片。此外,要再確認哪些卡上所附的選台功能是否有支援,可以參考 &man.bktr.4;
說明,以查看所支援的硬體清單。設定相關驅動程式要用電視卡的話,就要載入 &man.bktr.4; 驅動程式,這個可以透過在 /boot/loader.conf
檔加上下面這一行就可以了:bktr_load="YES"此外,也可以把該 kernel module 直接與 kernel 編譯在一起,作法就是在你的 kernel 設定檔內,加上下面這幾行:device bktr
device iicbus
device iicbb
device smbus之所以要加上這些額外的驅動程式,是因為卡的各組成部分都是透過 I2C 匯流排而相互連接的。接下來,請重新編譯、安裝新的 kernel 。安裝好新的 kernel 之後,要重開機才會生效。開機時,應該會看到類似下面的正確偵測到 TV card 訊息:bktr0: <BrookTree 848A> mem 0xd7000000-0xd7000fff irq 10 at device 10.0 on pci0
iicbb0: <I2C bit-banging driver> on bti2c0
iicbus0: <Philips I2C bus> on iicbb0 master-only
iicbus1: <Philips I2C bus> on iicbb0 master-only
smbus0: <System Management Bus> on bti2c0
bktr0: Pinnacle/Miro TV, Philips SECAM tuner.當然,這些訊息可能因您的硬體不同而有所不同。However you should check if the tuner is correctly
detected; it is still possible to override some of the
detected parameters with &man.sysctl.8; MIBs and kernel
configuration file options. For example, if you want to force
the tuner to a Philips SECAM tuner, you should add the
following line to your kernel configuration file:options OVERRIDE_TUNER=6or you can directly use &man.sysctl.8;:&prompt.root; sysctl hw.bt848.tuner=6See the &man.bktr.4; manual page and the
/usr/src/sys/conf/NOTES file for more
details on the available options. (If you are under
&os; 4.X, /usr/src/sys/conf/NOTES is
replaced with
/usr/src/sys/i386/conf/LINT.)好用的程式要用電視卡,可以視需要安裝下列應用程式之一︰multimedia/fxtv
provides TV-in-a-window and image/audio/video capture
capabilities.multimedia/xawtv
is also a TV application, with the same features as
fxtv.misc/alevt decodes
and displays Videotext/Teletext.audio/xmradio, an
application to use the FM radio tuner coming with some
TV cards.audio/wmtune, a handy
desktop application for radio tuners.More applications are available in the &os; Ports
Collection.TroubleshootingIf you encounter any problem with your TV card, you should
check at first if the video capture chip and the tuner are
really supported by the &man.bktr.4; driver and if you used the right
configuration options. For more support and various questions
about your TV card you may want to contact and use the
archives of the &a.multimedia.name; mailing list.MarcFonvieilleWritten by 掃描器image scanners介紹
- &os;, like any modern operating system, allows the use of
- image scanners. Standardized access to scanners is provided
- by the SANE (Scanner Access Now
- Easy) API available through the &os; Ports
- Collection. SANE will also use
- some &os; devices drivers to access to the scanner
- hardware.
-
- &os; supports both SCSI and USB scanners. Be sure your
- scanner is supported by SANE prior
- to performing any configuration.
- SANE has a supported
- devices list that can provide you with information
- about the support for a scanner and its status. The
- &man.uscanner.4; manual page also provides a list of supported
- USB scanners.
+ &os; 就像任何現代作業系統一樣,都可以使用掃描器。
+ 在 &os; 是透過 Ports Collection 內的 SANE(Scanner Access Now Easy)
+ 所提供的 API 來操作掃描器。
+ SANE 也會使用一些 &os; 的驅動程式來控制掃描器硬體。
+
+ &os; 同時支援 SCSI 和 USB 兩種介面的掃描器。在做任何設定之前,請確保
+ SANE 有支援您的掃描器。
+ SANE 有張 支援硬體
+ 的清單,這裡有介紹掃描器的支援情況和狀態訊息。
+ 在 &man.uscanner.4; 內也有提供一份 USB 掃描器的支援列表。
- Kernel Configuration
+ Kernel 的設定
- As mentioned above both SCSI and USB interfaces are
- supported. According to your scanner interface, different
- device drivers are required.
+ 如同上述所提的 SCSI 和 USB 界面都有支援。這要取決於您的掃描器界面,而需要不同的設備驅動程式。
- USB Interface
+ USB 介面The GENERIC kernel by default
includes the device drivers needed to support USB scanners.
Should you decide to use a custom kernel, be sure that the
following lines are present in your kernel configuration
file:device usb
device uhci
device ohci
device uscannerDepending upon the USB chipset on your motherboard, you
will only need either device uhci or
device ohci, however having both in the
kernel configuration file is harmless.If you do not want to rebuild your kernel and your
kernel is not the GENERIC one, you can
directly load the &man.uscanner.4; device driver module with
the &man.kldload.8; command:&prompt.root; kldload uscannerTo load this module at each system startup, add the
following line to
/boot/loader.conf:uscanner_load="YES"After rebooting with the correct kernel, or after
loading the required module, plug in your USB scanner. The
scanner should appear in your system message buffer
(&man.dmesg.8;) as something like:uscanner0: EPSON EPSON Scanner, rev 1.10/3.02, addr 2This shows that our scanner is using the
/dev/uscanner0 device node.On &os; 4.X, the USB daemon (&man.usbd.8;) must
be running to be able to see some USB devices. To enable
this, add usbd_enable="YES" to your
/etc/rc.conf file and reboot the
machine.
- SCSI Interface
+ SCSI 介面If your scanner comes with a SCSI interface, it is
important to know which SCSI controller board you will use.
According to the SCSI chipset used, you will have to tune
your kernel configuration file. The
GENERIC kernel supports the most common
SCSI controllers. Be sure to read the
NOTES file (LINT
under &os; 4.X) and add the correct line to your kernel
configuration file. In addition to the SCSI adapter driver,
you need to have the following lines in your kernel
configuration file:device scbus
device passOnce your kernel has been properly compiled, you should
be able to see the devices in your system message buffer,
when booting:pass2 at aic0 bus 0 target 2 lun 0
pass2: <AGFA SNAPSCAN 600 1.10> Fixed Scanner SCSI-2 device
pass2: 3.300MB/s transfersIf your scanner was not powered-on at system boot, it is
still possible to manually force the detection by performing
a SCSI bus scan with the &man.camcontrol.8; command:&prompt.root; camcontrol rescan all
Re-scan of bus 0 was successful
Re-scan of bus 1 was successful
Re-scan of bus 2 was successful
Re-scan of bus 3 was successfulThen the scanner will appear in the SCSI devices
list:&prompt.root; camcontrol devlist
<IBM DDRS-34560 S97B> at scbus0 target 5 lun 0 (pass0,da0)
<IBM DDRS-34560 S97B> at scbus0 target 6 lun 0 (pass1,da1)
<AGFA SNAPSCAN 600 1.10> at scbus1 target 2 lun 0 (pass3)
<PHILIPS CDD3610 CD-R/RW 1.00> at scbus2 target 0 lun 0 (pass2,cd0)More details about SCSI devices, are available in the
&man.scsi.4; and &man.camcontrol.8; manual pages.
- SANE Configuration
+ 設定 SANEThe SANE system has been
splitted in two parts: the backends (graphics/sane-backends) and the
frontends (graphics/sane-frontends). The
backends part provides access to the scanner itself. The
SANE's supported
devices list specifies which backend will support your
image scanner. It is mandatory to determine the correct
backend for your scanner if you want to be able to use your
device. The frontends part provides the graphical scanning
interface (xscanimage).The first thing to do is install the graphics/sane-backends port or
package. Then, use the sane-find-scanner
command to check the scanner detection by the
SANE system:&prompt.root; sane-find-scanner -q
found SCSI scanner "AGFA SNAPSCAN 600 1.10" at /dev/pass3The output will show the interface type of the scanner and
the device node used to attach the scanner to the system. The
vendor and the product model may not appear, it is not
important.Some USB scanners require you to load a firmware, this
is explained in the backend manual page. You should also read
&man.sane-find-scanner.1; and &man.sane.7; manual
pages.Now we have to check if the scanner will be identified by
a scanning frontend. By default, the
SANE backends comes with a command
line tool called &man.scanimage.1;. This command allows you
to list the devices and to perform an image acquisition from
the command line. The option is used to
list the scanner device:&prompt.root; scanimage -L
device `snapscan:/dev/pass3' is a AGFA SNAPSCAN 600 flatbed scannerNo output or a message saying that no scanners were
identified indicates that &man.scanimage.1; is unable to
identify the scanner. If this happens, you will need to edit
the backend configuration file and define the scanner device
used. The /usr/local/etc/sane.d/ directory
contains all backends configuration files. This
identification problem does appear with certain USB
scanners.For example, with the USB scanner used in the ,
sane-find-scanner gives us the following
information:&prompt.root; sane-find-scanner -q
found USB scanner (UNKNOWN vendor and product) at device /dev/uscanner0The scanner is correctly detected, it uses the USB
interface and is attached to the
/dev/uscanner0 device node. We can now
check if the scanner is correctly identified:&prompt.root; scanimage -L
No scanners were identified. If you were expecting something different,
check that the scanner is plugged in, turned on and detected by the
sane-find-scanner tool (if appropriate). Please read the documentation
which came with this software (README, FAQ, manpages).Since the scanner is not identified, we will need to edit
the /usr/local/etc/sane.d/epson.conf
file. The scanner model used was the &epson.perfection; 1650,
so we know the scanner will use the epson
backend. Be sure to read the help comments in the backends
configuration files. Line changes are quite simple: comment
out all lines that have the wrong interface for your scanner
(in our case, we will comment out all lines starting with the
word scsi as our scanner uses the USB
interface), then add at the end of the file a line specifying
the interface and the device node used. In this case, we add
the following line:usb /dev/uscanner0Please be sure to read the comments provided in the
backend configuration file as well as the backend manual page
for more details and correct syntax to use. We can now verify
if the scanner is identified:&prompt.root; scanimage -L
device `epson:/dev/uscanner0' is a Epson GT-8200 flatbed scannerOur USB scanner has been identified. It is not important
if the brand and the model do not match. The key item to be
concerned with is the
`epson:/dev/uscanner0' field, which give us
the right backend name and the right device node.Once the scanimage -L command is able
to see the scanner, the configuration is complete. The device
is now ready to scan.While &man.scanimage.1; does allow us to perform an
image acquisition from the command line, it is preferable to
use a graphical user interface to perform image scanning.
SANE offers a simple but efficient
graphical interface: xscanimage
(graphics/sane-frontends).Xsane (graphics/xsane) is another popular
graphical scanning frontend. This frontend offers advanced
features such as various scanning mode (photocopy, fax, etc.),
color correction, batch scans, etc. Both of these applications
are useable as a GIMP
plugin.Allowing Scanner Access to Other UsersAll previous operations have been done with
root privileges. You may however, need
other users to have access
to the scanner. The user will need read and write
permissions to the device node used by the scanner. As an
example, our USB scanner uses the device node
/dev/uscanner0 which is owned by the
operator group. Adding the user
joe to the
operator group will allow him to use
the scanner:&prompt.root; pw groupmod operator -m joeFor more details read the &man.pw.8; manual page. You
also have to set the correct write permissions (0660 or 0664)
on the /dev/uscanner0 device node, by
default the operator group can only
read the device node. This is done by adding the following
lines to the /etc/devfs.rules file:[system=5]
add path uscanner0 mode 660Then add the following to
/etc/rc.conf and reboot the
machine:devfs_system_ruleset="system"More information regarding these lines can be found in the
&man.devfs.8; manual page. Under &os; 4.X, the
operator group has, by default, read
and write permissions to
/dev/uscanner0.Of course, for security reasons, you should think twice
before adding a user to any group, especially the
operator group.
diff --git a/zh_TW.Big5/books/handbook/ports/chapter.sgml b/zh_TW.Big5/books/handbook/ports/chapter.sgml
index d508252e61..fa1a33c1fb 100644
--- a/zh_TW.Big5/books/handbook/ports/chapter.sgml
+++ b/zh_TW.Big5/books/handbook/ports/chapter.sgml
@@ -1,1367 +1,1353 @@
軟體套件管理篇:Packages 及 Ports 機制概述portspackages儘管 FreeBSD 在 base system 已加了很多系統工具。
然而,在實務運用上,您可能仍需要安裝額外的軟體。
FreeBSD 提供了 2 種安裝應用程式的套件管理系統︰Ports Collection(以 soucre 來編譯、安裝) 和
package(預先編譯好的 binary 檔)。上述的方式,無論要用哪一種,都可以由像是 CDROM
等或網路上來安裝想裝的最新版軟體。讀完這章,您將了解:如何以 packages 來安裝軟體。如何以 ports 來安裝軟體。已安裝的 packages 或 ports 要如何移除。如何更改(override) ports collection 所使用的預設值。如何在套件管理系統中,找出想裝的軟體。如何升級已安裝的軟體。安裝軟體的各種方式介紹通常要在 &unix; 系統上安裝軟體時,有幾個步驟要作:先下載該軟體壓縮檔(tarball),有可能是原始碼或是 binary 執行檔。解開該壓縮檔。(通常是以 &man.compress.1; , &man.gzip.1; 或 &man.bzip2.1; 壓縮的)閱讀相關文件檔,以了解如何安裝。(通常檔名是 INSTALL 或
README, 或在 doc/ 目錄下的一些文件)如果所下載的是原始碼,可能要先修改 Makefile 或是執行
./configure 之類的 script ,接著再編譯該軟體。最後測試再測試與安裝。如果一切順利的話,就這麼簡單。如果在安裝非專門設計(移植)給 FreeBSD 的軟體時出問題,
那可能需要修改一下它的程式碼,才能正常使用。當然,我們可以在 FreeBSD 上使用上述的傳統方式來安裝軟體,但是,我們還有更簡單的選擇。
FreeBSD 提供了兩種省事的軟體管理機制: packages 和 ports。就在寫這篇文章的時候,
已經有超過 &os.numports; 個 port 軟體可以使用。
- For any given application, the FreeBSD package for that
- application is a single file which you must download. The
- package contains pre-compiled copies of all the commands for the
- application, as well as any configuration files or
- documentation. A downloaded package file can be manipulated
- with FreeBSD package management commands, such as
- &man.pkg.add.1;, &man.pkg.delete.1;, &man.pkg.info.1;, and so
- on. Installing a new application can be carried out with a
- single command.
-
- A FreeBSD port for an application is a collection of files
- designed to automate the process of compiling an application
- from source code.
+ 所謂的 FreeBSD package 就是別人把該應用程式編譯、打包完畢。
+ 該 package 會包括該應用程式的所有執行檔、設定檔、文件等。
+ 而下載到硬碟上的 package 都可透過 FreeBSD 套件管理指令來進行管理,比如:
+ &man.pkg.add.1;、&man.pkg.delete.1;、&man.pkg.info.1;等指令。
+ 所以,只需簡單打個指令就可輕鬆安裝新的應用程式了。
+
+ 而 FreeBSD port 則是用一些檔案,來自動處理應用程式的安裝流程。Remember that there are a number of steps you would normally
carry out if you compiled a program yourself (downloading,
unpacking, patching, compiling, installing). The files that
make up a port contain all the necessary information to allow
the system to do this for you. You run a handful of simple
commands and the source code for the application is
automatically downloaded, extracted, patched, compiled, and
installed for you.
- In fact, the ports system can also be used to generate packages
- which can later be manipulated with pkg_add
- and the other package management commands that will be introduced
- shortly.
+ 事實上,ports 機制還可以用來產生 packages,以便他人可以用
+ pkg_add 來安裝,或是稍後會介紹到的其他套件管理指令。Both packages and ports understand
dependencies. Suppose you want to install
an application that depends on a specific library being
installed. Both the application and the library have been made
available as FreeBSD ports and packages. If you use the
pkg_add command or the ports system to add
the application, both will notice that the library has not been
installed, and automatically install the library first.Given that the two technologies are quite similar, you might
be wondering why FreeBSD bothers with both. Packages and ports
both have their own strengths, and which one you use will depend
on your own preference.Package 好處在於:A compressed package tarball is typically smaller than
the compressed tarball containing the source code for the
application.Packages do not require any additional compilation. For
large applications, such as
Mozilla,
KDE, or
GNOME this can be important,
particularly if you are on a slow system.Packages do not require any understanding of the process
involved in compiling software on FreeBSD.Ports 好處在於:Packages are normally compiled with conservative options,
because they have to run on the maximum number of systems. By
installing from the port, you can tweak the compilation options to
(for example) generate code that is specific to a Pentium
IV or Athlon processor.Some applications have compile time options relating to
what they can and cannot do. For example,
Apache can be configured with a
wide variety of different built-in options. By building
from the port you do not have to accept the default options,
and can set them yourself.In some cases, multiple packages will exist for the same
application to specify certain settings. For example,
Ghostscript is available as a
ghostscript package and a
ghostscript-nox11 package, depending on
whether or not you have installed an X11 server. This sort
of rough tweaking is possible with packages, but rapidly
becomes impossible if an application has more than one or
two different compile time options.The licensing conditions of some software distributions forbid
binary distribution. They must be distributed as source
code.Some people do not trust binary distributions. At least
with source code, you can (in theory) read through it and
look for potential problems yourself.If you have local patches, you will need the source in order to
apply them.Some people like having code around, so they can read it
if they get bored, hack it, borrow from it (license
permitting, of course), and so on.To keep track of updated ports, subscribe to the
&a.ports; and the &a.ports-bugs;.
- Before installing any application, you should check for security issues
- related to your application.
-
- You can also install security/portaudit which will
- automatically check all installed applications for known
- vulnerabilities; a check will be also performed before any port
- build. Meanwhile, you can use the command portaudit
- -F -a after you have installed some
- packages.
+ 在安裝軟體前,最好先看 內是否有該軟體的安全漏洞通報。
+
+
+ 此外,也可以裝 security/portaudit,它會自動檢查所有已裝的
+ 的軟體是否有已知的安全漏洞,另外,它還會在裝軟體的編譯過程前先行檢查。
+ 也可以在裝了某些軟體之後,用 portaudit -F -a
+ 來作全面強制安檢。The remainder of this chapter will explain how to use
packages and ports to install and manage third party software on
FreeBSD.尋找想裝的軟體
- Before you can install any applications you need to know what you
- want, and what the application is called.
+ 在安裝任何軟體之前,你必須先了解你想要什麼的軟體,以及該軟體叫做什麼名稱。
- FreeBSD's list of available applications is growing all the
- time. Fortunately, there are a number of ways to find what you
- want:
+ FreeBSD 上可裝的軟體清單不斷在增加中,
+ 不過,我們很慶幸有幾種方式可以來找你想裝的軟體:
- The FreeBSD web site maintains an up-to-date searchable
- list of all the available applications, at http://www.FreeBSD.org/ports/.
- The ports are divided into categories, and you may either
+ FreeBSD 網站上有更新頻繁的軟體清單,在
+ http://www.FreeBSD.org/ports/。
+ 各 ports 皆依其性質而分門別類,and you may either
search for an application by name (if you know it), or see
all the applications available in a category.FreshPorts
- Dan Langille maintains FreshPorts, at . FreshPorts
+ Dan Langille 維護 FreshPorts 網站,網址在 。 FreshPorts
tracks changes to the applications in the ports tree as they
happen, allows you to watch one or more
ports, and can send you email when they are updated.FreshMeatIf you do not know the name of the application you want,
try using a site like FreshMeat () to find an
application, then check back at the FreeBSD site to see if
the application has been ported yet.If you know the exact name of the port, but just need to
find out which category it is in, you can use the
&man.whereis.1; command.
Simply type whereis
file, where
file is the program you want to
install. If it is found on your system, you will be told
where it is, as follows:&prompt.root; whereis lsof
lsof: /usr/ports/sysutils/lsofThis tells us that lsof (a system
utility) can be found in the
/usr/ports/sysutils/lsof
directory.Yet another way to find a particular port is by using the
Ports Collection's built-in search mechanism. To use the
search feature, you will need to be in the
/usr/ports directory. Once in that
directory, run make search
name=program-name where
program-name is the name of the
program you want to find. For example, if you were looking
for lsof:&prompt.root; cd /usr/ports
&prompt.root; make search name=lsof
Port: lsof-4.56.4
Path: /usr/ports/sysutils/lsof
Info: Lists information about open files (similar to fstat(1))
Maint: obrien@FreeBSD.org
Index: sysutils
B-deps:
R-deps: The part of the output you want to pay particular
attention to is the Path: line, since that
tells you where to find the port. The other information
provided is not needed in order to install the port, so it
will not be covered here.For more in-depth searching you can also use make
search key=string where
string is some text to search for.
This searches port names, comments, descriptions and
dependencies and can be used to find ports which relate to a
particular subject if you do not know the name of the program
you are looking for.In both of these cases, the search string is case-insensitive.
Searching for LSOF will yield the same results as
searching for lsof.ChernLeeContributed by 使用 Packages 管理機制Package 的安裝方式packagesinstallingpkg_addYou can use the &man.pkg.add.1; utility to install a
FreeBSD software package from a local file or from a server on
the network.手動下載、安裝 Package (譯者chinsan: 因比較不便而不建議這麼做)&prompt.root; ftp -a ftp2.FreeBSD.org
Connected to ftp2.FreeBSD.org.
220 ftp2.FreeBSD.org FTP server (Version 6.00LS) ready.
331 Guest login ok, send your email address as password.
230-
230- This machine is in Vienna, VA, USA, hosted by Verio.
230- Questions? E-mail freebsd@vienna.verio.net.
230-
230-
230 Guest login ok, access restrictions apply.
Remote system type is UNIX.
Using binary mode to transfer files.
ftp>cd /pub/FreeBSD/ports/packages/sysutils/
250 CWD command successful.
ftp>get lsof-4.56.4.tgz
local: lsof-4.56.4.tgz remote: lsof-4.56.4.tgz
200 PORT command successful.
150 Opening BINARY mode data connection for 'lsof-4.56.4.tgz' (92375 bytes).
100% |**************************************************| 92375 00:00 ETA
226 Transfer complete.
92375 bytes received in 5.60 seconds (16.11 KB/s)
ftp>exit
&prompt.root; pkg_add lsof-4.56.4.tgzIf you do not have a source of local packages (such as a
FreeBSD CD-ROM set) then it will probably be easier to use the
option to &man.pkg.add.1;. This will
cause the utility to automatically determine the correct
object format and release and then fetch and install the
package from an FTP site.
pkg_add&prompt.root; pkg_add -r lsofThe example above would download the correct package and
add it without any further user intervention.
If you want to specify an alternative &os; Packages Mirror,
instead of the main distribution site, you have to set
PACKAGESITE accordingly, to
override the default settings. &man.pkg.add.1;
uses &man.fetch.3; to download the files, which honors various
environment variables, including
FTP_PASSIVE_MODE, FTP_PROXY, and
FTP_PASSWORD. You may need to set one or more
of these if you are behind a firewall, or need to use an
FTP/HTTP proxy. See &man.fetch.3; for the complete list.
Note that in the example above
lsof is used instead of
lsof-4.56.4. When the remote fetching
feature is used, the version number of the package must be
removed. &man.pkg.add.1; will automatically fetch the latest
version of the application.&man.pkg.add.1; will download the latest version of
your application if you are using &os.current; or
&os.stable;. If you run a -RELEASE version, it will grab
the version of the package that was built with your
release. It is possible to change this behavior by
overriding the PACKAGESITE environment
variable. For example, if you run a &os; 5.4-RELEASE
system, by default &man.pkg.add.1; will try to fetch
packages from
ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-5.4-release/Latest/.
If you want to force &man.pkg.add.1; to download
&os; 5-STABLE packages, set PACKAGESITE
to
ftp://ftp.freebsd.org/pub/FreeBSD/ports/i386/packages-5-stable/Latest/.
Package files are distributed in .tgz
and .tbz formats. You can find them at ,
or on the FreeBSD CD-ROM distribution. Every CD on the
FreeBSD 4-CD set (and the PowerPak, etc.) contains packages
in the /packages directory. The layout
of the packages is similar to that of the
/usr/ports tree. Each category has its
own directory, and every package can be found within the
All directory.
The directory structure of the package system matches the
ports layout; they work with each other to form the entire
package/port system.
管理 Packagespackagesmanaging&man.pkg.info.1; is a utility that lists and describes
the various packages installed.
pkg_info&prompt.root; pkg_info
cvsup-16.1 A general network file distribution system optimized for CV
docbook-1.2 Meta-port for the different versions of the DocBook DTD
...&man.pkg.version.1; is a utility that summarizes the
versions of all installed packages. It compares the package
version to the current version found in the ports tree.
pkg_version&prompt.root; pkg_version
cvsup =
docbook =
...The symbols in the second column indicate the relative age
of the installed version and the version available in the
local ports tree.符號代表意義=The version of the
installed package matches the one found in the
local ports tree.<The installed version is older than the one available
in the ports tree.>The installed version is newer
than the one found in the local ports tree. (The local ports
tree is probably out of date.)?The installed package cannot be
found in the ports index. (This can happen, for instance, if an
installed port is removed from the Ports Collection or
renamed.)*There are multiple versions of the
package.移除已安裝的 Packagepkg_deletepackagesdeletingTo remove a previously installed software package, use the
&man.pkg.delete.1; utility.
&prompt.root; pkg_delete xchat-1.7.1其他細節部份All package information is stored within the
/var/db/pkg directory. The installed
file list and descriptions of each package can be found within
files in this directory.
使用 Ports 管理機制The following sections provide basic instructions on using the
Ports Collection to install or remove programs from your
system. The detailed description of available make
targets and environment variables is available in &man.ports.7;.記得安裝 Ports CollectionBefore you can install ports, you must first obtain the
Ports Collection—which is essentially a set of
Makefiles, patches, and description files
placed in /usr/ports.
When installing your FreeBSD system,
sysinstall asked if you would like
to install the Ports Collection. If you chose no, you can
follow these instructions to obtain the ports
collection:CVSup 方式This is a quick method for getting and keeping your copy of the
Ports Collection up to date using CVSup.
If you want to learn more about CVSup, see
Using CVSup.Install the net/cvsup-without-gui package:&prompt.root; pkg_add -r cvsup-without-guiSee CVSup Installation () for more details.Run cvsup:&prompt.root; cvsup -L 2 -h cvsup.FreeBSD.org /usr/share/examples/cvsup/ports-supfileChange
cvsup.FreeBSD.org to a
CVSup server near you. See
CVSup Mirrors () for a complete listing of mirror
sites.One may want to use his own
ports-supfile, for example to avoid
the need of passing the CVSup
server on the command line.In this case, as root, copy
/usr/share/examples/cvsup/ports-supfile
to a new location, such as
/root or your home
directory.Edit ports-supfile.Change
CHANGE_THIS.FreeBSD.org
to a CVSup server near
you. See CVSup
Mirrors () for
a complete listing of mirror sites.And now to run cvsup, use the
following:&prompt.root; cvsup -L 2 /root/ports-supfileRunning the &man.cvsup.1; command later will download and apply all
the recent changes to your Ports Collection, except
actually rebuilding the ports for your own system.Portsnap 方式&man.portsnap.8; is an alternative system for distributing the
Ports Collection. It was first included in &os; 6.0. On older
systems, you can install it from sysutils/portsnap port:&prompt.root; pkg_add -r portsnapPlease refer to Using Portsnap
for a detailed description of all Portsnap
features.Create an empty directory /usr/ports if it does not exists.&prompt.root; mkdir /usr/portsDownload a compressed snapshot of the Ports Collection into
/var/db/portsnap. You can
disconnect from the Internet after this step, if you wish.&prompt.root; portsnap fetchIf you are running Portsnap for the
first time, extract the snapshot into /usr/ports:
&prompt.root; portsnap extractIf you already have a populated /usr/ports and you are just updating,
run the following command instead:&prompt.root; portsnap updateSysinstall 方式This method involves using sysinstall
to install the Ports Collection from the installation media. Note
that the old copy of Ports Collection from the date of the release
will be installed. If you have Internet access, you should always
use one of the methods mentioned above.As root, run
sysinstall
(/stand/sysinstall in &os;
versions older than 5.2) as shown below:&prompt.root; sysinstallScroll down and select Configure,
press Enter.Scroll down and select
Distributions, press
Enter.Scroll down to ports, press
Space.Scroll up to Exit, press
Enter.Select your desired installation media, such as CDROM,
FTP, and so on.Scroll up to Exit and press
Enter.Press X to exit
sysinstall.Ports 的安裝方式portsinstallingThe first thing that should be explained when it comes to
the Ports Collection is what is actually meant by a
skeleton. In a nutshell, a port skeleton is a
minimal set of files that tell your FreeBSD system how to
cleanly compile and install a program. Each port skeleton
includes:A Makefile. The
Makefile contains various statements
that specify how the application should be compiled and
where it should be installed on your system.A distinfo file. This file
contains information about the files that must be
downloaded to build the port and their checksums, to
verify that files have not been corrupted during the
download using &man.md5.1;.A files directory. This
directory contains patches to make the program compile and
install on your FreeBSD system. Patches are basically
small files that specify changes to particular files.
They are in plain text format, and basically say
Remove line 10 or Change line 26 to
this .... Patches are also known as
diffs because they are generated by the
&man.diff.1; program.This directory may also contain other files used to build
the port.A pkg-descr file. This is a more
detailed, often multiple-line, description of the program.A pkg-plist file. This is a list
of all the files that will be installed by the port. It
also tells the ports system what files to remove upon
deinstallation.Some ports have other files, such as
pkg-message. The ports system uses these
files to handle special situations. If you want more details
on these files, and on ports in general, check out the FreeBSD Porter's
Handbook.The port includes instructions on how to build source
code, but does not include the actual source code. You can
get the source code from a CD-ROM or from the Internet.
Source code is distributed in whatever manner the software
author desires. Frequently this is a tarred and gzipped file,
but it might be compressed with some other tool or even
uncompressed. The program source code, whatever form it comes
in, is called a distfile. The two methods for
installing a &os; port are described below.You must be logged in as root to
install ports.Before installing any port, you should be sure to have
an up-to-date Ports Collection and you should check for security issues
related to your port.A security vulnerabilities check can be automatically
done by portaudit before any new
application installation. This tool can be found in the
Ports Collection (security/portaudit). Consider
running portaudit -F before installing a
new port, to fetch the current vulnerabilities database. A
security audit and an update of the database will be
performed during the daily security system check. For more
information read the &man.portaudit.1; and &man.periodic.8;
manual pages.The Ports Collection makes an assumption that you have a working
Internet connection. If you do not, you will need to put a copy of the
distfile into /usr/ports/distfiles
manually.To begin, change to the directory for the port you want to
install:&prompt.root; cd /usr/ports/sysutils/lsofOnce inside the lsof directory, you
will see the port skeleton. The next step is to compile, or
build, the port. This is done by simply
typing make at the prompt. Once you have
done so, you should see something like this:&prompt.root; make
>> lsof_4.57D.freebsd.tar.gz doesn't seem to exist in /usr/ports/distfiles/.
>> Attempting to fetch from ftp://lsof.itap.purdue.edu/pub/tools/unix/lsof/.
===> Extracting for lsof-4.57
...
[extraction output snipped]
...
>> Checksum OK for lsof_4.57D.freebsd.tar.gz.
===> Patching for lsof-4.57
===> Applying FreeBSD patches for lsof-4.57
===> Configuring for lsof-4.57
...
[configure output snipped]
...
===> Building for lsof-4.57
...
[compilation output snipped]
...
&prompt.root;Notice that once the compile is complete you are
returned to your prompt. The next step is to install the
port. In order to install it, you simply need to tack one word
onto the make command, and that word is
install:&prompt.root; make install
===> Installing for lsof-4.57
...
[installation output snipped]
...
===> Generating temporary packing list
===> Compressing manual pages for lsof-4.57
===> Registering installation for lsof-4.57
===> SECURITY NOTE:
This port has installed the following binaries which execute with
increased privileges.
&prompt.root;Once you are returned to your prompt, you should be able to
run the application you just installed. Since
lsof is a
program that runs with increased privileges, a security
warning is shown. During the building and installation of
ports, you should take heed of any other warnings that
may appear.It is a good idea to delete the working subdirectory,
which contains all the temporary files used during compilation.
Not only it consumes a valuable disk space, it would also cause
problems later when upgrading to the newer version of the port.&prompt.root; make clean
===> Cleaning for lsof-4.57
&prompt.root;You can save an extra step by just running make
install clean instead of make,
make install and make clean
as three separate steps.Some shells keep a cache of the commands that are
available in the directories listed in the
PATH environment variable, to speed up
lookup operations for the executable file of these
commands. If you are using one of these shells, you might
have to use the rehash command after
installing a port, before the newly installed commands can
be used. This command will work for shells like
tcsh. Use the hash -r
command for shells like sh. Look at the
documentation for your shell for more information.Some third party DVD-ROM products such as the FreeBSD Toolkit
from the FreeBSD
Mall contain distfiles. They can be used with the Ports
Collection. Mount the DVD-ROM on /cdrom. If
you use a different mount point, set CD_MOUNTPTS
make variable. The needed distfiles will be automatically used
if they are present on the disk.Please be aware that the licenses of a few ports do
not allow for inclusion on the CD-ROM. This could be
because a registration form needs to be filled out before
downloading or redistribution is not allowed, or for
another reason. If you wish to install a port not
included on the CD-ROM, you will need to be online in
order to do so.The ports system uses &man.fetch.1; to download the
files, which honors various environment variables, including
FTP_PASSIVE_MODE, FTP_PROXY,
and FTP_PASSWORD. You may need to set one or
more of these if you are behind a firewall, or need to use
an FTP/HTTP proxy. See &man.fetch.3; for the complete
list.For users which cannot be connected all the time, the
make fetch option is
provided. Just run this command at the top level directory
(/usr/ports) and the required files
will be downloaded for you. This command will also work in
the lower level categories, for example:
/usr/ports/net.
Note that if a port depends on libraries or other ports this will
not fetch the distfiles of those ports too.
Replace fetch with
fetch-recursive
if you want to fetch all the dependencies of a port too.You can build all the ports in a category or as a
whole by running make in the top level
directory, just like the aforementioned make
fetch method. This is
dangerous, however, as some ports cannot co-exist. In other
cases, some ports can install two different files with the
same filename.In some rare cases, users may need to acquire the
tarballs from a site other than the
MASTER_SITES (the location where files
are downloaded from). You can override the
MASTER_SITES option with the following
command:&prompt.root; cd /usr/ports/directory
&prompt.root; make MASTER_SITE_OVERRIDE= \
ftp://ftp.FreeBSD.org/pub/FreeBSD/ports/distfiles/ fetchIn this example we change the
MASTER_SITES option to ftp.FreeBSD.org/pub/FreeBSD/ports/distfiles/.Some ports allow (or even require) you to provide
build options which can enable/disable parts of the
application which are unneeded, certain security options,
and other customizations. A few which come to mind are
www/mozilla, security/gpgme, and mail/sylpheed-claws. A message
will be displayed when options such as these are
available.更改(Override)預設的 Ports 目錄Sometimes it is useful (or mandatory) to use a different
distfiles and ports directory. The
PORTSDIR and PREFIX
variables can override the default directories. For
example:&prompt.root; make PORTSDIR=/usr/home/example/ports installwill compile the port in
/usr/home/example/ports and install
everything under /usr/local.&prompt.root; make PREFIX=/usr/home/example/local installwill compile it in /usr/ports and
install it in
/usr/home/example/local.And of course,&prompt.root; make PORTSDIR=../ports PREFIX=../local installwill combine the two (it is too long to completely write
on this page, but it should give you the general
idea).Alternatively, these variables can also be set as part
of your environment. Read the manual page for your shell
for instructions on doing so.Dealing with imakeSome ports that use imake (a part of
the X Window System) do not work well with
PREFIX, and will insist on installing
under /usr/X11R6. Similarly, some Perl
ports ignore PREFIX and install in the
Perl tree. Making these ports respect
PREFIX is a difficult or impossible
job.移除已安裝的 PortsportsremovingNow that you know how to install ports, you are probably
wondering how to remove them, just in case you install one and
later on decide that you installed the wrong port.
We will remove our previous example (which was
lsof for
those of you not paying attention). Ports are being removed exactly
the same as the packages (discussed in the Packages section), using the
&man.pkg.delete.1; command:&prompt.root; pkg_delete lsof-4.57升級已安裝的 PortsportsupgradingFirst, list outdated ports that have a newer version available in
the Ports Collection with the &man.pkg.version.1; command:&prompt.root; pkg_version -vOnce you updated your Ports Collection, before
attempting a port upgrade, you should check the
/usr/ports/UPDATING file. This file
describes various issues and additional steps users may
encounter and need to perform when updating a port.以 Portupgrade 來升級已安裝的 PortsportupgradeThe portupgrade utility is designed
to easily upgrade installed ports. It is available from the sysutils/portupgrade port. Install it like
any other port, using the make install
clean command:&prompt.root; cd /usr/ports/sysutils/portupgrade
&prompt.root; make install cleanScan the list of installed ports with the pkgdb
-F command and fix all the inconsistencies it reports. It is
a good idea to do this regularly, before every upgrade.When you run portupgrade -a,
portupgrade will begin to upgrade all the
outdated ports installed on your system. Use the
flag if you want to be asked for confirmation of every individual
upgrade.&prompt.root; portupgrade -aiIf you want to upgrade only a
certain application, not all available ports, use portupgrade
pkgname. Include the
flag if portupgrade
should first upgrade all the ports required by the given
application.&prompt.root; portupgrade -R firefoxTo use packages instead of ports for installation, provide
flag. With this option
portupgrade searches
the local directories listed in PKG_PATH, or
fetches packages from remote site if it is not found locally.
If packages can not be found locally or fetched remotely,
portupgrade will use ports.
To avoid using ports, specify .&prompt.root; portupgrade -PR gnome2To just fetch distfiles (or packages, if
is specified) without building or
installing anything, use .
For further information see &man.portupgrade.1;.以 Portmanager 來升級已安裝的 PortsportmanagerPortmanager is another utility for
easy upgrading of installed ports. It is available from the
sysutils/portmanager port:&prompt.root; cd /usr/ports/sysutils/portmanager
&prompt.root; make install cleanAll the installed ports can be upgraded using this simple
command:&prompt.root; portmanager -uYou can add the flag to get asked for
confirmation of every step Portmanager
will perform. Portmanager can also be
used to install new ports on the system. Unlike the usual
make install clean command, it will upgrade all
the dependencies prior to building and installing the
selected port.&prompt.root; portmanager x11/gnome2If there are any problems regarding the dependencies for the
selected port, you can use Portmanager to
rebuild all of them in the correct order. Once finished, the
problematic port will be rebuilt too.&prompt.root; portmanager graphics/gimp -fFor more information see
Portmanager's manual page.Ports 與硬碟空間portsdisk-spaceUsing the Ports Collection will use up disk
space over time. After building and installing software from the
ports, you should always remember to clean up
the temporary work directories using the make
clean command. You can sweep the whole
Ports Collection with the following command:&prompt.root; portsclean -CYou will accumulate a lot of old source distribution files in the
distfiles directory over time.
You can remove them by hand, or you can use the following command to
delete all the distfiles that are no longer referenced by any
ports:&prompt.root; portsclean -DThe portsclean utility is part of the
portupgrade suite.Do not forget to remove the installed ports once you no longer need
them. A nice tool to help automate this task is available from the
sysutils/pkg_cutleaves port.安裝之後,有什麼後續注意事項嗎?通常,安裝完軟體後,我們可以閱讀所附的一些文件,或需要編輯設定檔,
來確保這個軟體能順利運作,或在機器開機的時候啟動(如果是 daemon 的話)等等。不同的軟體會有不同的設定步驟。不管怎樣,如果裝好了軟體,
但是不知道下一步怎麼辦的時候, 可以試試看這些小技巧:善用 &man.pkg.info.1; ,這指令可以顯示:透過套件管理系統(Packages/Ports)裝了哪些軟體、檔案裝在哪邊。舉例來說,若剛裝了 FooPackage (版本 1.0.0),那麼下面這指令:&prompt.root; pkg_info -L foopackage-1.0.0 | less就會顯示這軟體所安裝的檔案清單。 Pay
special attention to files in man/
directories, which will be manual pages,
etc/ directories, which will be
configuration files, and doc/, which
will be more comprehensive documentation.If you are not sure which version of the application was
just installed, a command like this&prompt.root; pkg_info | grep -i foopackagewill find all the installed packages that have
foopackage in the package name.
Replace foopackage in your
command line as necessary.Once you have identified where the application's manual
pages have been installed, review them using &man.man.1;.
Similarly, look over the sample configuration files, and any
additional documentation that may have been provided.If the application has a web site, check it for
additional documentation, frequently asked questions, and so
forth. If you are not sure of the web site address it may
be listed in the output from&prompt.root; pkg_info foopackage-1.0.0A WWW: line, if present, should provide a URL
for the application's web site.Ports that should start at boot (such as Internet
servers) will usually install a sample script in
/usr/local/etc/rc.d. You should
review this script for correctness and edit or rename it if
needed. See Starting
Services for more information.如何處理爛掉(Broken)的 Ports?如果發現某個 port 無法順利安裝、運作, 有幾種方法可以試試看:從 Problem Report
資料庫 中挖寶看看,說不定已經有人送可用的 patch 上去囉,
那麼或許就可以順利解決問題哩。向該 port 的 maintainer 尋求協助:請打
make maintainer 或翻閱
Makefile 以查詢 maintainer 的
email address。記得寄信給 maintainer 時,要附註該 port 的名稱、版本(或是把 Makefile 內的 $FreeBSD: 那一整行附上) 以及相關錯誤訊息。
- Some ports are not maintained by an individual but
- instead by a 有些 port 不是由專門的單一 maintainer 負責,而是透過 mailing
- list. Many, but not all, of these addresses look like
- freebsd-listname@FreeBSD.org. Please
- take this into account when phrasing your questions.
+ list 的專題討論。許多(但非全部)的聯絡 email 格式通常是
+ freebsd-list名稱@FreeBSD.org。發問時,請記得把『freebsd-list名稱』改為相關討論的 mailing list 名稱。
尤其當 port 的 maintainer 欄位是
freebsd-ports@FreeBSD.org
時,事實上已經沒人當該 port maintainer 了。
因此若該 port 仍有修正或其他技術支援的話,相關討論都會在 freebsd-ports 郵遞論壇上出現。
喔,對了,如果有熟悉該軟體者,志願當該 port maintainer 的話,我們也都很歡迎您的加入喔。若 port maintainer 沒有回覆您的信件, 則可以用 &man.send-pr.1;
來提交問題報告 PR。(請參閱 Writing
FreeBSD Problem Reports)。試試看修正它吧! Porter's
Handbook 包括了 Ports
架構的細節部份,這些書中內容有助您修好有問題的 port 甚至提交自己的 port﹗從較近的 FTP 站點下載編譯好的 package。
package collection 的最上游站是在 ftp.FreeBSD.org 上的 packages
目錄內,但請記得先檢查是否已有 local mirror
站! 通常情況下這些 package 都可以直接使用,而且應該比自行編譯快一些。
用 &man.pkg.add.1; 即可順利安裝 package 。
diff --git a/zh_TW.Big5/books/porters-handbook/book.sgml b/zh_TW.Big5/books/porters-handbook/book.sgml
index 49bf3f4ce0..a27d6c900a 100644
--- a/zh_TW.Big5/books/porters-handbook/book.sgml
+++ b/zh_TW.Big5/books/porters-handbook/book.sgml
@@ -1,10036 +1,9980 @@
%books.ent;
]>
FreeBSD Porter's HandbookFreeBSD 文件計劃April 20002000200120022003200420052006FreeBSD 文件計劃
&bookinfo.trademarks;
&bookinfo.legalnotice;
楔子幾乎每個 FreeBSD 愛用者都是透過 FreeBSD Ports Collection
來裝各式應用程式("ports")。如同 FreeBSD 的其他部分一樣,
這些 ports 都主要來自許多志工的努力成果,所以在閱讀這份文件時,
請務必感恩在心。在 FreeBSD 上面,每個人都可以提交新的 port,
或假如該 port 並沒有人維護的話,可以自願維護 —
這點並不需要任何 commit 的權限,就可以來做這件事情。自行打造 port那麼,開始對自行製作 port 或更新現有 port
有一些興趣了嗎?太好囉!下面將介紹一些建立 port 時該注意的事項。如果是想升級現有的 port
,那麼也請參閱 說明。因為這份文件可能講得不是十分詳細,可能需要參考
/usr/ports/Mk/bsd.port.mk
這檔是所有 port 的 Makefile 檔都會用到的。就算你不是每天不斷 hacking Makefiles
,也都可以藉由它來對整個 port 機制、Makefile 更瞭解,裡面的註釋相當詳細。
此外,若有其他特定 port 的問題,也可以到 &a.ports; 來獲得答案。
- Only a fraction of the variables
- (VAR) that can be
- overridden are mentioned in this document. Most (if not all)
- are documented at the start of /usr/ports/Mk/bsd.port.mk;
- the others probably ought to be.
- Note that this file uses a non-standard tab setting:
- Emacs and
- Vim should recognize the setting on
- loading the file. Both &man.vi.1; and
- &man.ex.1; can be set to use the correct value by
- typing :set tabstop=4 once the file has been
- loaded.
+ 本文內所提及的環境變數(VAR)部份,
+ 只有一些可以替換(overridden)。大部份的環境變數(非全部)通常都會寫在
+ /usr/ports/Mk/bsd.port.mk 內,其他的也是差不多。
+ 請注意:該檔並非使用一般的 tab 設定值,而是採用 1 個 tab 等於 4 個 space:
+ Emacs 與
+ Vim 應該都會在載入該檔時順便讀取相關設定值。
+ &man.vi.1; 及
+ &man.ex.1; 這兩個程式也都可以打 :set tabstop=4 以修改設定值。打造 Port 快速上手篇本節主要介紹如何來快速打造 port,然而,很多時候這些內容並不是很夠用,
建議閱讀本文件中更深奧的地方。首先取得該應用程式的原始程式碼壓縮檔(tarball),並把它放到
DISTDIR,預設路徑應該是
/usr/ports/distfiles。下面的例子,是假設並不需要再修改該應用程式的原始碼,就可以在
FreeBSD 上編譯成功的;假如還需要另外修改才能成功編譯的話,那麼請參考下一章的說明。
編寫 Makefile最簡單的 Makefile 大概是像這樣:# New ports collection makefile for: oneko
# Date created: 5 December 1994
# Whom: asami
#
# $FreeBSD$
#
PORTNAME= oneko
PORTVERSION= 1.1b
CATEGORIES= games
MASTER_SITES= ftp://ftp.cs.columbia.edu/archives/X11R5/contrib/
MAINTAINER= asami@FreeBSD.org
COMMENT= A cat chasing a mouse all over the screen
MAN1= oneko.1
MANCOMPRESSED= yes
USE_IMAKE= yes
.include <bsd.port.mk>嗯,大致就是這樣,看看你已經領略多少了呢?看到 $FreeBSD$
這一行的話,別想太多,它是 CVS ID tag 用途,當該 port 正式進入 port tree 時,就會自動轉換為相關字串囉。
有關這點的細節部份,可以參閱 sample Makefile 章節。撰寫該軟體的說明檔無論是否打算再加工做成 package,有 2 個檔案是任何實體 port (Slave port則不一定)都必須要具備的。
這 2 個檔分別是 pkg-descr 檔及
pkg-plist 檔。這兩個檔案檔名前面都有 pkg-
以跟其他檔案做區別。pkg-descr這是此 port 的詳細說明檔,請用一段或幾段文字來說明該 port 的作用,並附上 WWW
網址(若有的話)請注意,這檔絕非「該軟體的說明手冊」或是「如何編譯、使用該 port 的說明」。
若是從該軟體的 README 或 manpage 直接複製過來的話,
請注意,因為它們通常都寫得太詳細、格式較特別(比如 manpage 會自動調整空白),
請儘量避免這些冗長贅詞或採用特殊格式。若該軟體有官方版首頁的話,請在此列出來。
每個網址請用 WWW: 作為開頭,這樣子相關工具程式就會自動處理完畢。該 port 的 pkg-descr 內容,大致如下面例子:This is a port of oneko, in which a cat chases a poor mouse all over
the screen.
:
(etc.)
WWW: http://www.oneko.org/pkg-plist這是該 port 所會裝的所有檔案清單,另外因為 package 會由這清單所產生,因此也被稱為『packing list
(打包清單)』。 以 ${PREFIX} 為基準點,而用相對路徑表示。
(${PREFIX} 通常是 /usr/local 或
/usr/X11R6) 但是如果該程式有安裝 man page 的話,則要以類似
MANn= 的方式寫在
Makefile 內,不能列在 pkg-plist 哦。
除了列出檔案以外,也要把該 port 所會建立的目錄也列進去,方式有兩種:一種是寫在
pkg-plist 內的方式,比如:
@dirrm 。至於另外一種方式,則是寫在 Makefile 內,比如
:PLIST_FILES= 之類的方式。該 port 的 pkg-plist 內容,大致如下面例子:bin/oneko
lib/X11/app-defaults/Oneko
lib/X11/oneko/cat1.xpm
lib/X11/oneko/cat2.xpm
lib/X11/oneko/mouse.xpm
@dirrm lib/X11/oneko關於 packing list 方面,可以參閱 &man.pkg.create.1; 會有詳解。建議清單內的檔名,依照字母順序作排序,那麼下次要升級時,會比較清楚、方便來更新這份清單。 手動生這份清單實在太苦了。尤其若該 port 會裝一大堆檔案的話,請多善用 自動產生 packing list 會比較省時省力唷。
- 只有在一 種情況下可以省略不用生 pkg-plist 檔。 If the port installs just a handful
- of files, and perhaps directories, the files and directories may
- be listed in the variables PLIST_FILES and
- PLIST_DIRS, respectively, within the port's
- Makefile. For instance, we could get along
- without pkg-plist in the above
- oneko port by adding the
- following lines to the Makefile:
+ 只有在一種情況下可以省略不用生 pkg-plist 檔:
+ 若安裝的 port 相當單純,只有裝一些檔案,以及都在同一目錄下的話,
+ 那麼可以在 Makefile 內改用 PLIST_FILES 及
+ PLIST_DIRS 來取代。
+ 比如,可以在上述的 oneko port 內不必附上
+ pkg-plist ,而只需在 Makefile 內加入下列幾行:PLIST_FILES= bin/oneko \
lib/X11/app-defaults/Oneko \
lib/X11/oneko/cat1.xpm \
lib/X11/oneko/cat2.xpm \
lib/X11/oneko/mouse.xpm
PLIST_DIRS= lib/X11/oneko
- Of course, PLIST_DIRS should be left
- unset if a port installs no directories of its own.
-
- The price for this way of listing port's files and
- directories is that you cannot use command sequences
- described in &man.pkg.create.1;. Therefore, it is suitable
- only for simple ports and makes them even simpler. At the
- same time, it has the advantage of reducing the number of files
- in the ports collection. Please consider using this technique
- before you resort to pkg-plist.
-
- Later we will see how pkg-plist
- and PLIST_FILES can be used to fulfil
- more sophisticated
- tasks.
+ 當然,若該 port 並無安裝自屬的目錄的話,就不必設 PLIST_DIRS 囉。
+
+ 然而,使用 PLIST_FILES 、PLIST_DIRS 是必須付出代價:
+ 不能使用 &man.pkg.create.1; 內所說的 command sequences。
+ 因此,這招僅適用於較簡單的 port ,以及簡化該 port 的作法。
+ 此外,這招還有一個好處:可以減少 ports collection 的整體檔案總數。
+ 所以,在考慮是否一定要用 pkg-plist 之前,可以先斟酌這個替代方案看看。
+
+ 後面會介紹到如何運用 pkg-plist、PLIST_FILES
+ 這些技巧以因應 更複雜的狀況。產生 checksum 用途的 distinfo 檔只要打『make makesum』就好了,接下來就會自動產生相對應的
- distinfo 檔哩。
-
- If a file fetched has its checksum changed regularly and you are
- certain the source is trusted (i.e. it comes from manufacturer CDs
- or documentation generated daily), you should specify these files in
- the IGNOREFILES variable.
- Then the checksum is not calculated for that file when you run
- make makesum, but set to
- IGNORE.
+ distinfo 檔了唷。
+
+ 若抓下來的檔案,它的 checksum 會經常變更,而你也很確信所抓的來源是正確無誤的話,
+ (比如:來源是光碟或是每天自動產生的文件),那麼可以設定那些檔案為 IGNOREFILES 。
+ 如此一來,在打 make makesum 的時候就不會計算那些檔案的 checksum,而自動改為
+ IGNORE 囉。檢驗 port 是否完整、可行
- You should make sure that the port rules do exactly what you
- want them to do, including packaging up the port. These are the
- important points you need to verify.
+ 接下來,必須檢驗是否有符合 port 的遊戲規則,包括打包該 port 為 package。
+ 以下有幾個需要確認的重要地方:
- pkg-plist does not contain anything not
- installed by your port
+ 若該 port 沒裝的東西,不要列在 pkg-plist 內。
- pkg-plist contains everything that is
- installed by your port
+ 若該 port 有裝的東西,請務必列在 pkg-plist 內。
- Your port can be installed multiple times using the
- reinstall target
+ 該 port 可以用 reinstall 來重新安裝。
- Your port cleans up
- after itself upon deinstall
+ 該 port 在移除之後,確定都可 cleans up。
- 建議採行的測試順序:
+ 建議的測試步驟順序:make installmake packagemake deinstallpkg_add package-namemake deinstallmake reinstallmake package
- Make sure that there are not any warnings issued in any of the
- package and
- deinstall stages. After step 3, check to
- see if all the new directories are correctly deleted. Also, try
- using the software after step 4, to ensure that it works correctly
- when installed from a package.
+ 確認在 package 和 deinstall
+ 這兩個階段都沒有任何錯誤訊息出現。
+ 完成第三步驟之後,檢查一下是否所裝的檔案、目錄都有移除完畢。此外,第四步驟完成後,也檢查一下以 package
+ 裝的該軟體,是否都能正常運作。以 portlint 來作檢驗
- 請用 portlint 來檢查該 port 是否有遵循上述規則。 The
- devel/portlint program is part of the ports collection.
- In particular, you may want to check if the
- Makefile is in the right
- shape and the package is named
- appropriately.
+ 請用 portlint 來檢查該 port 是否有遵循上述遊戲規則。 說到這
+ devel/portlint 它是 ports collection 的其中一個套件。
+ 它主要可以用來檢驗 Makefile 內容是否正確以及
+ package 是否有正確命名。提交(Submit) port首先,請確認是否有瞭解 DOs and DON'Ts 該章部分。現在你很高興終於打造出 port 來囉,唯一剩下要做的就是把它正式放到 FreeBSD ports tree
內,才能讓每個人都能分享使用這個 port。請先拿掉 work 目錄或檔名像是
pkgname.tgz 的 package 可以砍掉。接著,只要用 shar `find
port_dir` 來產生 shar 格式,並配合 &man.send-pr.1; 程式以提交出去。
(&man.send-pr.1; 的部分可以參閱
- 錯誤報告和意見發表) 記得在填寫 PR 時『分類(Category)』選
- ports 還有『種類(Class)』填 change-request
+ 錯誤報告和意見發表)
+
+ 記得在填寫 PR 時『分類(Category)』選 ports,還有『種類(Class)』填 change-request
(千萬別傻傻地把該 PR 的『Confidential(機密)』設為 yes!),此外在『描述(Description)』
那邊寫上該程式的簡潔說明,而 shar 檔則附在『修正(Fix)』欄位內。
- You can make our work a lot easier, if you use a good
- description in the synopsis of the problem report.
- We prefer something like
+ 若 Synopsis 欄清楚描述該 PR 重點的話,那麼會讓整個流程更為順暢。
+ new ports 的話,我們習慣用:
New port: <category>/<portname>
- <short description of the port> for new ports and
+ <該 port 的簡介> ,而更新 port 的話,則是
Update port: <category>/<portname>
- <short description of the update> for port updates.
- If you stick to this scheme, the chance that someone will take a
- look at your PR soon is much better.
+ <本次 update 的簡介>。
+ 若你也採用這樣的格式的話,那麼會被受理的機會就會越高囉。
- One more time, do not include the original source
- distfile, the work directory, or the package
- you built with make package.
-
- After you have submitted your port, please be patient.
- Sometimes it can take a few months before a port is included
- in FreeBSD, although it might only take a few days. You can
- view the list of ports
- waiting to be committed to FreeBSD.
-
- Once we have looked at your port, we will get back to you if necessary, and put
- it in the tree. Your name will also appear in the list of
- Additional FreeBSD Contributors
- and other files. Isn't that great?!? :-)Slow Porting
- Ok...事實上並不太可能這麼簡單,port方面可能需要作些修改才能正常使用。
+ Ok...事實上並不太可能這麼簡單,port 方面可能需要作些修改才能正常使用。
因此,本節將一步一步來介紹如何修改上一章的樣本以正常使用。How things work
- First, this is the sequence of events which occurs when the user
- first types make in your port's directory.
- You may find that having bsd.port.mk in another
- window while you read this really helps to understand it.
+ 首先,先介紹一下在你所作的 port 目錄內打 make 時,所會作哪些事情的順序吧。
+ 你可以另開一窗來看 bsd.port.mk 內容,以便瞭解我們下面在講什麼。但別太擔心是否完全看懂
bsd.port.mk 在做啥,很多人都還沒完全看完...
:->
- The fetch target is run. The
- fetch target is responsible for making
- sure that the tarball exists locally in
- DISTDIR. If fetch
- cannot find the required files in DISTDIR it
- will look up the URL MASTER_SITES, which is
- set in the Makefile, as well as our main FTP site at ,
- where we put sanctioned distfiles as backup. It will then
- attempt to fetch the named distribution file with
- FETCH, assuming that the requesting site has
- direct access to the Internet. If that succeeds, it will save
- the file in DISTDIR for future use and
- proceed.
+ 首先,進行 fetch 階段。
+ fetch 是確認 tarball 檔有沒有已在
+ DISTDIR 內了?若 fetch
+ 在 DISTDIR 找不到的話,它會搜尋 Makefile 內的 MASTER_SITES URL
+ ,或者是主 FTP 站專門放備份 distfiles 的目錄 。
+ 假設都找不到的話,但是網路有接上 Internet 的話,它會試著用 FETCH 來抓所指定的檔案。
+ 抓到之後,它會把檔案存到 DISTDIR 以便開始使用或日後運用。
- The extract target is run. It
- looks for your port's distribution file (typically a gzip'd
- tarball) in DISTDIR and unpacks it into a
- temporary subdirectory specified by WRKDIR
- (defaults to work).
+ 其次,進行 extract 階段,它會從 DISTDIR 內找出該 port
+ 所需的檔案(通常是 gzip 格式的 tarball),然後解壓縮到 WRKDIR 所設定的臨時目錄名稱
+ (預設是 work 目錄)內。
- The patch target is run. First,
- any patches defined in PATCHFILES are
- applied. Second, if any patch files named
- patch-* are found in
- PATCHDIR (defaults to the
- files subdirectory), they are applied at
- this time in alphabetical order.
+ 之後,進行 patch 階段,一開始會先套用 PATCHFILES
+ 指定的任何 patch 檔。
+ 接著,是 PATCHDIR(預設是 files 子目錄) 內的檔名為
+ patch-* 之類的檔案,會以字母順序而逐一套用 patch。
- The configure target is run. This
- can do any one of many different things.
+ 接著是 configure 階段,可以照 port 的類型來作各種不同設定以調整,比如:
- If it exists, scripts/configure is
- run.
+ 若有放 scripts/configure 的話,那麼就會跑裡面的設定。
- If HAS_CONFIGURE or
- GNU_CONFIGURE is set,
- WRKSRC/configure is
- run.
+ 若有設 HAS_CONFIGURE 或是
+ GNU_CONFIGURE 的話,那麼就會跑
+ WRKSRC/configure
- If USE_IMAKE is set,
- XMKMF (default: xmkmf
- -a) is run.
+ 若有設 USE_IMAKE 的話,那麼就會跑
+ XMKMF (預設是 xmkmf
+ -a) 。
- The build target is run. This is
- responsible for descending into the port's private working
- directory (WRKSRC) and building it. If
- USE_GMAKE is set, GNU make
- will be used, otherwise the system make will
- be used.
+ 最後是 build 階段,它會在該
+ port 的 working directory(由 WRKSRC 所設定) 內開始編譯。
+ 若有設 USE_GMAKE 的話,那麼就會改用 GNU make
+ 來編譯,否則就用系統本身的 make 來編譯。
- The above are the default actions. In addition, you can define
- targets
- pre-something or
- post-something,
- or put scripts with those names, in the scripts
- subdirectory, and they will be run before or after the default
- actions are done.
-
- For example, if you have a post-extract
- target defined in your Makefile, and a file
- pre-build in the scripts
- subdirectory, the post-extract target will
- be called after the regular extraction actions, and the
- pre-build script will be executed before the
- default build rules are done. It is recommended that you use
- Makefile targets if the actions are simple
- enough, because it will be easier for someone to figure out what
- kind of non-default action the port requires.
-
- The default actions are done by the
- bsd.port.mk targets
- do-something.
- For example, the commands to extract a port are in the target
- do-extract. If you are not happy with the
- default target, you can fix it by redefining the
- do-something
- target in your Makefile.
+ 上面講的都是打 make 時的預設階段。
+ 此外,還可以設定各階段之前、之後要作的事情:透過定義
+ pre-something 或
+ post-something,
+ 或者把這些檔名的 script 丟到 scripts 子目錄去,
+ 這樣子它們就會在各預設階段的之前、之後進行囉。
+
+ 舉例來說,若在 Makefile 內設定 post-extract
+ ,而且在 scripts 子目錄內又有 pre-build 檔的話,
+ 那麼在作解壓縮之後,就會開始 post-extract 階段以進行解壓縮後的後續動作,
+ 而在跑 build 階段之前,就會先執行 pre-build 這隻 script 作先期準備。
+ 通常較簡單的修改動作,建議直接放在 Makefile
+ 內就好了,因為這樣會比較方便加上這些原本沒有的階段,同時也方便他人協助除錯。
+
+ 預設的各階段動作都是照
+ bsd.port.mk 內的
+ do-something 之類所定義的。
+ 舉例:do-extract 就是定義怎麼把檔案解壓縮的。
+ 若對預設方式覺得不妥的話,都可以在該 port 的 Makefile 重新定義。The main targets (e.g.,
extract,
configure, etc.) do nothing more than
make sure all the stages up to that one are completed and call
the real targets or scripts, and they are not intended to be
changed. If you want to fix the extraction, fix
do-extract, but never ever change
the way extract operates!
- Now that you understand what goes on when the user types
- make, let us go through the recommended steps to
- create the perfect port.
+ 現在,你已經知道打 make 到底會作些什麼事囉,接下來會教你如何作更完美的
+ port。
- Getting the original sources
-
- Get the original sources (normally) as a compressed tarball
- (foo.tar.gz or
- foo.tar.Z) and copy
- it into DISTDIR. Always use
- mainstream sources when and where you
- can.
+ 取得原始的 source 檔
+
+ 取得原始的 source 檔(通常檔名是 foo.tar.gz
+ 或 foo.tar.Z 之類的壓縮檔),
+ 然後會把抓下來的檔案放在 DISTDIR 內。
+ 記得:抓的時候,儘量使用『主流站』上面的來源檔,以確保檔案有效、可信。You will need to set the variable MASTER_SITES
to reflect where the original tarball resides. You will find
convenient shorthand definitions for most mainstream sites
in bsd.sites.mk. Please use these
sites—and the associated definitions—if
at all possible, to help avoid the problem of having the same
information repeated over again many times in the source base.
As these sites tend to change over time, this becomes a
maintenance nightmare for everyone involved.If you cannot find a FTP/HTTP site that is well-connected to the
net, or can only find sites that have irritatingly non-standard
formats, you might want to put a copy on a reliable FTP or HTTP
server that you control (e.g., your home page).If you cannot find somewhere convenient and reliable to put the
distfile
we can house it ourselves
on ftp.FreeBSD.org; however, this is the
least-preferred solution.
The distfile must be placed into
~/public_distfiles/ of someone's
freefall account.
Ask the person who commits your port to do this.
This person will also set MASTER_SITES to
MASTER_SITE_LOCAL and
MASTER_SITE_SUBDIR to their
freefall username.If your port's distfile changes all the time without any
kind of version update by the author,
consider putting the distfile on your home page and listing it as
the first MASTER_SITES. If you can, try
to talk the port author out of doing this; it
really does help to establish some kind of source code control.
Hosting your own version will prevent users
from getting checksum mismatch errors, and
also reduce the workload of maintainers of our FTP site. Also, if
there is only one master site for the port, it is recommended that
you house a backup at your site and list it as the second
MASTER_SITES.If your port requires some additional `patches' that are
available on the Internet, fetch them too and put them in
DISTDIR. Do not worry if they come from a site
other than where you got the main source tarball, we have a way to
handle these situations (see the description of PATCHFILES below).Modifying the portUnpack a copy of the tarball in a private directory and make
whatever changes are necessary to get the port to compile properly
under the current version of FreeBSD. Keep careful
track of everything you do, as you will be automating
the process shortly. Everything, including the deletion, addition,
or modification of files should be doable using an automated script
or patch file when your port is finished.If your port requires significant user interaction/customization
to compile or install, you should take a look at one of Larry Wall's
classic Configure scripts and perhaps do
something similar yourself. The goal of the new ports collection is
to make each port as plug-and-play as possible for the
end-user while using a minimum of disk space.Unless explicitly stated, patch files, scripts, and other
files you have created and contributed to the FreeBSD ports
collection are assumed to be covered by the standard BSD copyright
conditions.PatchingIn the preparation of the port, files that have been added or
changed can be picked up with a &man.diff.1;
for later feeding to &man.patch.1;. Each patch you
wish to apply should be saved into a file named
patch-* where
* indicates
the pathname of the file that is patched,
such as patch-Imakefile or
patch-src-config.h. These files should
be stored in PATCHDIR
(usually files/, from where they will be
automatically applied. All patches must be relative to
WRKSRC (generally the directory your port's
tarball unpacks itself into, that being where the build is done).
To make fixes and upgrades easier, you should avoid having more than
one patch fix the same file (e.g., patch-file and
patch-file2 both changing
WRKSRC/foobar.c).Please only use characters [-+._a-zA-Z0-9] for
naming your patches. Do not use any other characters besides them.
Do not name your patches like patch-aa or
patch-ab etc, always mention path and file name
in patch names.Do not put RCS strings in patches. CVS will mangle them when we
put the files into the ports tree, and when we check them out again,
they will come out different and the patch will fail. RCS strings
are surrounded by dollar ($) signs, and
typically start with $Id or
$RCS.Using the recurse () option to
&man.diff.1; to generate patches is fine, but please take
a look at the resulting patches to make sure you do not have any
unnecessary junk in there. In particular, diffs between two backup
files, Makefiles when the port uses
Imake or GNU configure, etc.,
are unnecessary and should be deleted. If you had to edit
configure.in and run
autoconf to regenerate
configure, do not take the diffs of
configure (it often grows to a few thousand
lines!); define USE_AUTOTOOLS=autoconf:253 and take the
diffs of configure.in.If you had to delete a file, then you can do it in the
post-extract target rather than as part of
the patch.Simple replacements can be performed directly from the port
Makefile using the in-place mode of
&man.sed.1;. This is very useful when you need to patch in
a variable value. Example:post-patch:
@${REINPLACE_CMD} -e 's|for Linux|for FreeBSD|g' ${WRKSRC}/README
@${REINPLACE_CMD} -e 's|-pthread|${PTHREAD_LIBS}|' ${WRKSRC}/configureQuite often, there is a situation when the software being
ported, especially if it is primarily developed on &windows;, uses
the CR/LF convention for most of its source files. This may cause
problems with further patching, compiler warnings, scripts
execution (/bin/sh^M not found), etc. To
quickly convert all files from CR/LF to just LF, add
USE_DOS2UNIX=yes to the port
Makefile. A list of files to convert can
be specified:USE_DOS2UNIX= util.c util.hConfiguringInclude any additional customization commands in your
configure script and save it in the
scripts subdirectory. As mentioned above, you
can also do this with Makefile targets and/or
scripts with the name pre-configure or
post-configure.Handling user inputIf your port requires user input to build, configure, or install,
you must set IS_INTERACTIVE in your Makefile. This
will allow overnight builds to skip your port if the
user sets the variable BATCH in his environment (and
if the user sets the variable INTERACTIVE, then
only those ports requiring interaction are
built). This will save a lot of wasted time on the set of
machines that continually build ports (see below).It is also recommended that if there are reasonable default
answers to the questions, you check the
PACKAGE_BUILDING variable and turn off the
interactive script when it is set. This will allow us to build the
packages for CDROMs and FTP.Configuring the MakefileConfiguring the Makefile is pretty simple, and again we suggest
that you look at existing examples before starting. Also, there is a
sample Makefile in this
handbook, so take a look and please follow the ordering of variables
and sections in that template to make your port easier for others to
read.Now, consider the following problems in sequence as you design
your new Makefile:The original sourceDoes it live in DISTDIR as a standard
gzip'd tarball named something like
foozolix-1.2.tar.gz? If so, you can go on
to the next step. If not, you should look at overriding any of
the DISTVERSION, DISTNAME,
EXTRACT_CMD,
EXTRACT_BEFORE_ARGS,
EXTRACT_AFTER_ARGS,
EXTRACT_SUFX, or DISTFILES
variables, depending on how alien a format your port's
distribution file is. (The most common case is
EXTRACT_SUFX=.tar.Z, when the tarball is
condensed by regular compress, not
gzip.)In the worst case, you can simply create your own
do-extract target to override the
default, though this should be rarely, if ever,
necessary.NamingThe first part of the port's Makefile names
the port, describes its version number, and lists it in the correct
category.PORTNAME and PORTVERSIONYou should set PORTNAME to the
base name of your port, and PORTVERSION
to the version number of the port.PORTREVISION and
PORTEPOCHPORTREVISIONThe PORTREVISION variable is a
monotonically increasing value which is reset to 0 with
every increase of PORTVERSION (i.e.
every time a new official vendor release is made), and
appended to the package name if non-zero.
Changes to PORTREVISION are
used by automated tools (e.g. &man.pkg.version.1;)
to highlight the fact that a new package is
available.PORTREVISION should be increased
each time a change is made to the port which significantly
affects the content or structure of the derived
package.Examples of when PORTREVISION
should be bumped:Addition of patches to correct security
vulnerabilities, bugs, or to add new functionality to
the port.Changes to the port Makefile to enable or disable
compile-time options in the package.Changes in the packing list or the install-time
behavior of the package (e.g. change to a script
which generates initial data for the package, like ssh
host keys).Version bump of a port's shared library dependency
(in this case, someone trying to install the old
package after installing a newer version of the
dependency will fail since it will look for the old
libfoo.x instead of libfoo.(x+1)).Silent changes to the port distfile which have
significant functional differences, i.e. changes to
the distfile requiring a correction to
distinfo with no corresponding change to
PORTVERSION, where a diff
-ru of the old and new versions shows
non-trivial changes to the code.Examples of changes which do not require a
PORTREVISION bump:Style changes to the port skeleton with no
functional change to what appears in the resulting
package.Changes to MASTER_SITES or
other functional changes to the port which do not
affect the resulting package.Trivial patches to the distfile such as correction
of typos, which are not important enough that users of
the package should go to the trouble of
upgrading.Build fixes which cause a package to become
compilable where it was previously failing (as long as
the changes do not introduce any functional change on
any other platforms on which the port did previously
build). Since PORTREVISION reflects
the content of the package, if the package was not
previously buildable then there is no need to increase
PORTREVISION to mark a
change.A rule of thumb is to ask yourself whether a change
committed to a port is something which everyone
would benefit from having (either because of an
enhancement, fix, or by virtue that the new package will
actually work at all), and weigh that against that fact
that it will cause everyone who regularly updates their
ports tree to be compelled to update. If yes, the
PORTREVISION should be bumped.PORTEPOCHFrom time to time a software vendor or FreeBSD porter
will do something silly and release a version of their
software which is actually numerically less than the
previous version. An example of this is a port which goes
from foo-20000801 to foo-1.0 (the former will be
incorrectly treated as a newer version since 20000801 is a
numerically greater value than 1).In situations such as this, the
PORTEPOCH version should be increased.
If PORTEPOCH is nonzero it is appended
to the package name as described in section 0 above.
PORTEPOCH must never be decreased or reset
to zero, because that would cause comparison to a package
from an earlier epoch to fail (i.e. the package would not
be detected as out of date): the new version number (e.g.
1.0,1 in the above example) is still
numerically less than the previous version (20000801), but
the ,1 suffix is treated specially by
automated tools and found to be greater than the implied
suffix ,0 on the earlier package.Dropping or resetting PORTEPOCH
incorrectly leads
to no end of grief; if you do not understand the above discussion,
please keep after it until you do, or ask questions on
the mailing lists.It is expected that PORTEPOCH will
not be used for the majority of ports, and that sensible
use of PORTVERSION can often pre-empt
it becoming necessary if a future release of the software
should change the version structure. However, care is
needed by FreeBSD porters when a vendor release is made
without an official version number — such as a code
snapshot release. The temptation is to label the
release with the release date, which will cause problems
as in the example above when a new official release is
made.For example, if a snapshot release is made on the date
20000917, and the previous version of the software was
version 1.2, the snapshot release should be given a
PORTVERSION of 1.2.20000917 or similar,
not 20000917, so that the succeeding release, say 1.3, is
still a numerically greater value.Example of PORTREVISION and
PORTEPOCH usageThe gtkmumble port, version
0.10, is committed to the ports
collection:PORTNAME= gtkmumble
PORTVERSION= 0.10PKGNAME becomes
gtkmumble-0.10.A security hole is discovered which requires a local
FreeBSD patch. PORTREVISION is bumped
accordingly.PORTNAME= gtkmumble
PORTVERSION= 0.10
PORTREVISION= 1PKGNAME becomes
gtkmumble-0.10_1A new version is released by the vendor, numbered 0.2
(it turns out the author actually intended
0.10 to actually mean
0.1.0, not what comes after
0.9 - oops, too late now). Since the new minor
version 2 is numerically less than the
previous version 10, the
PORTEPOCH must be bumped to manually
force the new package to be detected as newer. Since it
is a new vendor release of the code,
PORTREVISION is reset to 0 (or removed
from the Makefile).PORTNAME= gtkmumble
PORTVERSION= 0.2
PORTEPOCH= 1PKGNAME becomes
gtkmumble-0.2,1The next release is 0.3. Since
PORTEPOCH never decreases, the version
variables are now:PORTNAME= gtkmumble
PORTVERSION= 0.3
PORTEPOCH= 1PKGNAME becomes
gtkmumble-0.3,1If PORTEPOCH were reset
to 0 with this upgrade, someone who had
installed the gtkmumble-0.10_1 package would not detect
the gtkmumble-0.3 package as newer, since
3 is still numerically less than
10. Remember, this is the whole point of
PORTEPOCH in the first place.PKGNAMEPREFIX and PKGNAMESUFFIXTwo optional variables, PKGNAMEPREFIX and
PKGNAMESUFFIX, are combined with
PORTNAME and
PORTVERSION to
form PKGNAME as
${PKGNAMEPREFIX}${PORTNAME}${PKGNAMESUFFIX}-${PORTVERSION}.
Make sure this conforms to our guidelines for a good package
name. In particular, you are not allowed to use a
hyphen (-) in
PORTVERSION. Also, if the package name
has the language- or the
-compiled.specifics part (see below), use
PKGNAMEPREFIX and
PKGNAMESUFFIX, respectively. Do not make
them part of PORTNAME.Package Naming ConventionsThe following are the conventions you should follow in naming your
packages. This is to have our package directory easy to scan, as
there are already thousands of packages and users are going to
turn away if they hurt their eyes!The package name should look like
language_region-name-compiled.specifics-version.numbers.The package name is defined as
${PKGNAMEPREFIX}${PORTNAME}${PKGNAMESUFFIX}-${PORTVERSION}.
Make sure to set the variables to conform to that format.FreeBSD strives to support the native language of its users.
The language- part should be a two
letter abbreviation of the natural language defined by ISO-639 if
the port is specific to a certain language. Examples are
ja for Japanese, ru for
Russian, vi for Vietnamese,
zh for Chinese, ko for
Korean and de for German.If the port is specific to a certain region within the
language area, add the two letter country code as well.
Examples are en_US for US English and
fr_CH for Swiss French.The language- part should
be set in the PKGNAMEPREFIX variable.The first letter of name part
should be lowercase. (The rest of the name can contain
capital letters, so use your own discretion when you are
converting a software name that has some capital letters in it.)
There is a tradition of naming perl 5 modules by
prepending p5- and converting the double-colon
separator to a hyphen; for example, the
Data::Dumper module becomes
p5-Data-Dumper. If the software in question
has numbers, hyphens, or underscores in its name, you may include
them as well (like kinput2).If the port can be built with different hardcoded defaults (usually
part of the directory name in a family of ports), the
-compiled.specifics part should state
the compiled-in defaults (the hyphen is optional). Examples are
papersize and font units.The -compiled.specifics part
should be set in the PKGNAMESUFFIX
variable.The version string should follow a dash
(-) and be a period-separated list of
integers and single lowercase alphabetics. In particular,
it is not permissible to have another dash inside the
version string. The only exception is the string
pl (meaning patchlevel), which can be
used only when there are no major and
minor version numbers in the software. If the software
version has strings like alpha, beta, rc, or pre, take
the first letter and put it immediately after a period.
If the version string continues after those names, the
numbers should follow the single alphabet without an extra
period between them.The idea is to make it easier to sort ports by looking
at the version string. In particular, make sure version
number components are always delimited by a period, and
if the date is part of the string, use the
yyyy.mm.dd
format, not
dd.mm.yyyy
or the non-Y2K compliant
yy.mm.dd
format.Here are some (real) examples on how to convert the name
as called by the software authors to a suitable package
name:Distribution NamePKGNAMEPREFIXPORTNAMEPKGNAMESUFFIXPORTVERSIONReasonmule-2.2.2(empty)mule(empty)2.2.2No changes requiredXFree86-3.3.6(empty)XFree86(empty)3.3.6No changes requiredEmiClock-1.0.2(empty)emiclock(empty)1.0.2No uppercase names for single programsrdist-1.3alpha(empty)rdist(empty)1.3.aNo strings like alpha
allowedes-0.9-beta1(empty)es(empty)0.9.b1No strings like beta
allowedmailman-2.0rc3(empty)mailman(empty)2.0.r3No strings like rc
allowedv3.3beta021.src(empty)tiff(empty)3.3What the heck was that anyway?tvtwm(empty)tvtwm(empty)pl11Version string always requiredpiewm(empty)piewm(empty)1.0Version string always requiredxvgr-2.10pl1(empty)xvgr(empty)2.10.1pl allowed only when no
major/minor version numbersgawk-2.15.6ja-gawk(empty)2.15.6Japanese language versionpsutils-1.13(empty)psutils-letter1.13Papersize hardcoded at package build timepkfonts(empty)pkfonts3001.0Package for 300dpi fontsIf there is absolutely no trace of version information in the
original source and it is unlikely that the original author will ever
release another version, just set the version string to
1.0 (like the piewm example above). Otherwise, ask
the original author or use the date string
(yyyy.mm.dd)
as the version.CategorizationCATEGORIESWhen a package is created, it is put under
/usr/ports/packages/All and links are made from
one or more subdirectories of
/usr/ports/packages. The names of these
subdirectories are specified by the variable
CATEGORIES. It is intended to make life easier
for the user when he is wading through the pile of packages on the
FTP site or the CDROM. Please take a look at the current list of categories and pick the ones
that are suitable for your port.This list also determines where in the ports tree the port is
imported. If you put more than one category here, it is assumed
that the port files will be put in the subdirectory with the name in
the first category. See below for more
discussion about how to pick the right categories.Current list of categoriesHere is the current list of port categories. Those
marked with an asterisk (*) are
virtual categories—those that do not have
a corresponding subdirectory in the ports tree. They are only
used as secondary categories, and only for search purposes.For non-virtual categories, you will find a one-line
description in the COMMENT in that
subdirectory's Makefile.CategoryDescriptionNotesaccessibilityPorts to help disabled users.afterstep*Ports to support the
AfterStep
window manager.arabicArabic language support.archiversArchiving tools.astroAstronomical ports.audioSound support.benchmarksBenchmarking utilities.biologyBiology-related software.cadComputer aided design tools.chineseChinese language support.commsCommunication software.Mostly software to talk to your serial port.convertersCharacter code converters.databasesDatabases.deskutilsThings that used to be on the desktop before
computers were invented.develDevelopment utilities.Do not put libraries here just because they are
libraries—unless they truly do not belong anywhere
else, they should not be in this category.dnsDNS-related software.editorsGeneral editors.Specialized editors go in the section for those
tools (e.g., a mathematical-formula editor will go
in math).elisp*Emacs-lisp ports.emulatorsEmulators for other operating systems.Terminal emulators do not belong
here—X-based ones should go to
x11 and text-based ones to either
comms or misc,
depending on the exact functionality.financeMonetary, financial and related applications.frenchFrench language support.ftpFTP client and server utilities.If your port speaks both FTP and HTTP, put it in
ftp with a secondary
category of www.gamesGames.germanGerman language support.gnome*Ports from the GNOME
Project.graphicsGraphics utilities.hamradio*Software for amateur radio.haskell*Software related to the Haskell language.hebrewHebrew language support.hungarianHungarian language support.ipv6*IPv6 related software.ircInternet Relay Chat utilities.japaneseJapanese language support.javaSoftware related to the Java language.The java category shall not be
the only one for a port. Save for ports directly related to
the Java language, porters are also encouraged not to
use java as the main category of a
port.kde*Ports from the K Desktop Environment (KDE)
Project.koreanKorean language support.langProgramming languages.linux*Linux applications and support utilities.lisp*Software related to the Lisp language.mailMail software.mathNumerical computation software and other utilities
for mathematics.mboneMBone applications.miscMiscellaneous utilitiesBasically things that
do not belong anywhere else.
If at all possible, try to
find a better category for your port than
misc, as ports tend to get overlooked
in here.multimediaMultimedia software.netMiscellaneous networking software.net-imInstant messaging software.net-mgmtNetworking management software.net-p2pPeer to peer network applications.newsUSENET news software.palmSoftware support for the Palm™ series.parallel*Applications dealing with parallelism in computing.pear*Ports related to the Pear PHP framework.perl5*Ports that require Perl version 5 to run.plan9*Various programs from Plan9.polishPolish language support.portuguesePortuguese language support.printPrinting software.Desktop publishing tools
(previewers, etc.) belong here too.python*Software related to the Python language.ruby*Software related to the Ruby language.rubygems*Ports of RubyGems packages.russianRussian language support.scheme*Software related to the Scheme language.scienceScientific ports that do not fit into other
categories such as astro,
biology and
math.securitySecurity utilities.shellsCommand line shells.sysutilsSystem utilities.tcl80*Ports that use Tcl version 8.0 to run.tcl81*Ports that use Tcl version 8.1 to run.tcl82*Ports that use Tcl version 8.2 to run.tcl83*Ports that use Tcl version 8.3 to run.tcl84*Ports that use Tcl version 8.4 to run.textprocText processing utilities.It does not include
desktop publishing tools, which go to print.tk80*Ports that use Tk version 8.0 to run.tk82*Ports that use Tk version 8.2 to run.tk83*Ports that use Tk version 8.3 to run.tk84*Ports that use Tk version 8.4 to run.tkstep80*Ports that use TkSTEP version 8.0 to run.ukrainianUkrainian language support.vietnameseVietnamese language support.windowmaker*Ports to support the WindowMaker window
manager.wwwSoftware related to the World Wide Web.HTML language
support belongs here too.x11The X Window System and friends.This category is only
for software that directly supports the window system. Do not
put regular X applications here; most of them should go
into other x11-* categories (see below).
If your port is an X
application, define USE_XLIB (implied by
USE_IMAKE) and put it in the appropriate
category.x11-clocksX11 clocks.x11-fmX11 file managers.x11-fontsX11 fonts and font utilities.x11-serversX11 servers.x11-themesX11 themes.x11-toolkitsX11 toolkits.x11-wmX11 window managers.xfce*Ports relating to the
Xfce desktop
environment.zope*Zope support.Choosing the right categoryAs many of the categories overlap, you often have to choose
which of the categories should be the primary category of your port.
There are several rules that govern this issue. Here is the list of
priorities, in decreasing order of precedence:The first category must be a physical category (see
above). This is
necessary to make the packaging work. Virtual categories and
physical categories may be intermixed after that.Language specific categories always come first. For
example, if your port installs Japanese X11 fonts, then your
CATEGORIES line would read japanese
x11-fonts.Specific categories are listed before less-specific ones. For
instance, an HTML editor should be listed as www
editors, not the other way around. Also, you should not
list net when the port belongs to
any of irc, mail,
mbone, news,
security, or www, as
net is included implicitly.x11 is used as a secondary category only
when the primary category is a natural language. In particular,
you should not put x11 in the category line
for X applications.Emacs modes should be
placed in the same ports category as the application
supported by the mode, not in
editors. For example, an
Emacs mode to edit source
files of some programming language should go into
lang.
misc
should not appear with any other non-virtual category.
If you have misc with something else in
your CATEGORIES line, that means you can
safely delete misc and just put the port
in that other subdirectory!If your port truly does not belong anywhere else, put it in
misc.If you are not sure about the category, please put a comment to
that effect in your &man.send-pr.1; submission so we can
discuss it before we import it. If you are a committer, send a note
to the &a.ports; so we can discuss it first. Too often, new ports are
imported to the wrong category only to be moved right away.
This causes unnecessary and undesirable bloat in the master
source repository.Proposing a new categoryAs the Ports Collection has grown over time, various new
categories have been introduced. New categories can either
be virtual categories—those that do
not have a corresponding subdirectory in the ports tree—
or physical categories—those that
do. The following text discusses the issues involved in creating
a new physical category so that you can understand them before
you propose one.Our existing practice has been to avoid creating a new
physical category unless either a large number of ports would
logically belong to it, or the ports that would belong to it
are a logically distinct group that is of limited general
interest (for instance, categories related to spoken human
languages), or preferably both.The rationale for this is that such a change creates a
fair amount of work for both the committers and also
for all users who track changes to the Ports Collection. In
addition, proposed category changes just naturally seem to
attract controversy. (Perhaps this is because there is no
clear consensus on when a category is too big,
nor whether categories should lend themselves to browsing (and
thus what number of categories would be an ideal number), and
so forth.)Here is the procedure:Propose the new category on &a.ports;. You should
include a detailed rationale for the new category,
including why you feel the existing categories are not
sufficient, and the list of existing ports proposed to move.
(If there are new ports pending in
GNATS that would fit this
category, list them too.) If you are the maintainer and/or
submitter, respectively, mention that as it may help you
to make your case.Participate in the discussion.If it seems that there is support for your idea,
file a PR which includes both the rationale and the list
of existing ports that need to be moved. Ideally, this
PR should also include patches for the following:Makefiles for the
new ports once they are repocopiedMakefile for the
new categoryMakefile for the
old ports' categoriesMakefiles for ports
that depend on the old ports(for extra credit, you can include the other
files that have to change, as per the procedure
in the Committer's Guide.)Since it affects the ports infrastructure and involves
not only performing repo-copies but also possibly running
regression tests on the build cluster, the PR should be
assigned to the &a.portmgr;.If that PR is approved, a committer will need to follow
the rest of the procedure that is
outlined in the Committer's Guide.Proposing a new virtual category should be similar to
the above but much less involved, since no ports will
actually have to move. In this case, the only patches to
include in the PR would be those to add the new category to the
CATEGORIESs of the affected ports.Proposing reorganizing all the categoriesOccasionally someone proposes reorganizing the categories
with either a 2-level structure, or some other kind of keyword
structure. To date, nothing has come of any of these proposals
because, while they are very easy to make, the effort involved to
retrofit the entire existing ports collection with any kind of
reorganization is daunting to say the very least. Please read
the history of these proposals in the mailing list archives before
you post this idea; furthermore, you should be prepared to be
challenged to offer a working prototype.The distribution filesThe second part of the Makefile describes the
files that must be downloaded in order to build the port, and where
they can be downloaded from.DISTVERSION/DISTNAMEDISTNAME is the name of the port as
called by the authors of the software.
DISTNAME defaults to
${PORTNAME}-${PORTVERSION}, so override it only if necessary.
DISTNAME is only used in two places.
First, the distribution file list
(DISTFILES) defaults to
${DISTNAME}${EXTRACT_SUFX}.
Second, the distribution file is expected to extract into a
subdirectory named WRKSRC, which defaults
to work/${DISTNAME}.Some vendor's distribution names which do not fit into the
${PORTNAME}-${PORTVERSION}-scheme can be handled
automatically by setting DISTVERSION.
PORTVERSION and DISTNAME will be
derived automatically, but can of course be overridden. The following
table lists some examples:DISTVERSIONPORTVERSION0.7.1d0.7.1.d10Alpha310.a33Beta7-pre23.b7.p28:f_178f.17PKGNAMEPREFIX and
PKGNAMESUFFIX do not affect
DISTNAME. Also note that if
WRKSRC is equal to
work/${PORTNAME}-${PORTVERSION}
while the original source archive is named something other than
${PORTNAME}-${PORTVERSION}${EXTRACT_SUFX},
you should probably leave DISTNAME
alone— you are better off defining
DISTFILES than having to set both
DISTNAME and WRKSRC
(and possibly EXTRACT_SUFX).MASTER_SITESRecord the directory part of the FTP/HTTP-URL pointing at the
original tarball in MASTER_SITES. Do not forget
the trailing slash (/)!The make macros will try to use this
specification for grabbing the distribution file with
FETCH if they cannot find it already on the
system.It is recommended that you put multiple sites on this list,
preferably from different continents. This will safeguard against
wide-area network problems. We are even planning to add support
for automatically determining the closest master site and fetching
from there; having multiple sites will go a long way towards
helping this effort.If the original tarball is part of one of the popular
archives such as X-contrib, GNU, or Perl CPAN, you may be able
refer to those sites in an easy compact form using
MASTER_SITE_*
(e.g., MASTER_SITE_XCONTRIB and
MASTER_SITE_PERL_GNU). Simply set
MASTER_SITES to one of these variables and
MASTER_SITE_SUBDIR to the path within the
archive. Here is an example:MASTER_SITES= ${MASTER_SITE_XCONTRIB}
MASTER_SITE_SUBDIR= applicationsThese variables are defined in
/usr/ports/Mk/bsd.sites.mk. There are
new entries added all the time, so make sure to check the
latest version of this file before submitting a port.The user can also set the MASTER_SITE_*
variables in /etc/make.conf to override our
choices, and use their favorite mirrors of these popular archives
instead.EXTRACT_SUFXIf you have one distribution file, and it uses an odd suffix to
indicate the compression mechanism, set
EXTRACT_SUFX.For example, if the distribution file was named
foo.tgz instead of the more normal
foo.tar.gz, you would write:DISTNAME= foo
EXTRACT_SUFX= .tgzThe USE_BZIP2 and USE_ZIP
variables automatically set EXTRACT_SUFX to
.tar.bz2 or .zip as necessary. If
neither of these are set then EXTRACT_SUFX
defaults to .tar.gz.You never need to set both EXTRACT_SUFX and
DISTFILES.DISTFILESSometimes the names of the files to be downloaded have no
resemblance to the name of the port. For example, it might be
called source.tar.gz or similar. In other
cases the application's source code might be in several different
archives, all of which must be downloaded.If this is the case, set DISTFILES to be a
space separated list of all the files that must be
downloaded.DISTFILES= source1.tar.gz source2.tar.gzIf not explicitly set, DISTFILES defaults to
${DISTNAME}${EXTRACT_SUFX}.EXTRACT_ONLYIf only some of the DISTFILES must be
extracted—for example, one of them is the source code, while
another is an uncompressed document—list the filenames that
must be extracted in EXTRACT_ONLY.DISTFILES= source.tar.gz manual.html
EXTRACT_ONLY= source.tar.gzIf none of the DISTFILES
should be uncompressed then set EXTRACT_ONLY to
the empty string.EXTRACT_ONLY=PATCHFILESIf your port requires some additional patches that are available
by FTP or HTTP, set PATCHFILES to the names of
the files and PATCH_SITES to the URL of the
directory that contains them (the format is the same as
MASTER_SITES).If the patch is not relative to the top of the source tree
(i.e., WRKSRC) because it contains some extra
pathnames, set PATCH_DIST_STRIP accordingly. For
instance, if all the pathnames in the patch have an extra
foozolix-1.0/ in front of the filenames, then set
PATCH_DIST_STRIP=-p1.Do not worry if the patches are compressed; they will be
decompressed automatically if the filenames end with
.gz or .Z.If the patch is distributed with some other files, such as
documentation, in a gzip'd tarball, you cannot just use
PATCHFILES. If that is the case, add the name
and the location of the patch tarball to
DISTFILES and MASTER_SITES.
Then, use the EXTRA_PATCHES variable to
point to those files and bsd.port.mk
will automatically apply them for you. In particular, do
not copy patch files into the
PATCHDIR directory—that directory may
not be writable.The tarball will have been extracted alongside the
regular source by then, so there is no need to explicitly extract
it if it is a regular gzip'd or compress'd tarball. If you do the
latter, take extra care not to overwrite something that already
exists in that directory. Also, do not forget to add a command to
remove the copied patch in the pre-clean
target.Multiple distribution files or patches from different
sites and subdirectories
(MASTER_SITES:n)(Consider this to be a somewhat advanced topic;
those new to this document may wish to skip this section at first).
This section has information on the fetching mechanism
known as both MASTER_SITES:n and
MASTER_SITES_NN. We will refer to this
mechanism as MASTER_SITES:n
hereon.A little background first. OpenBSD has a neat feature
inside both DISTFILES and
PATCHFILES variables, both files and
patches can be postfixed with :n
identifiers where n both can be
[0-9] and denote a group designation.
For example:DISTFILES= alpha:0 beta:1In OpenBSD, distribution file alpha
will be associated with variable
MASTER_SITES0 instead of our common
MASTER_SITES and
beta with
MASTER_SITES1.This is a very interesting feature which can decrease
that endless search for the correct download site.Just picture 2 files in DISTFILES and
20 sites in MASTER_SITES, the sites slow
as hell where beta is carried by all
sites in MASTER_SITES, and
alpha can only be found in the 20th
site. It would be such a waste to check all of them if
maintainer knew this beforehand, would it not? Not a good
start for that lovely weekend!Now that you have the idea, just imagine more
DISTFILES and more
MASTER_SITES. Surely our
distfiles survey meister would appreciate the
relief to network strain that this would bring.In the next sections, information will follow on the
FreeBSD implementation of this idea. We improved a bit on
OpenBSD's concept.Simplified informationThis section tells you how to quickly prepare fine
grained fetching of multiple distribution files and
patches from different sites and subdirectories. We
describe here a case of simplified
MASTER_SITES:n usage. This will be
sufficient for most scenarios. However, if you need
further information, you will have to refer to the next
section.Some applications consist of multiple distribution
files that must be downloaded from a number of different
sites. For example,
Ghostscript consists of the
core of the program, and then a large number of driver
files that are used depending on the user's printer. Some
of these driver files are supplied with the core, but many
others must be downloaded from a variety of different
sites.To support this, each entry in
DISTFILES may be followed by a colon
and a tag name. Each site listed in
MASTER_SITES is then followed by a
colon, and the tag that indicates which distribution files
should be downloaded from this site.For example, consider an application with the source
split in two parts, source1.tar.gz
and source2.tar.gz, which must be
downloaded from two different sites. The port's
Makefile would include lines like
.Simplified use of MASTER_SITES:n
with 1 file per siteMASTER_SITES= ftp://ftp.example1.com/:source1 \
ftp://ftp.example2.com/:source2
DISTFILES= source1.tar.gz:source1 \
source2.tar.gz:source2Multiple distribution files can have the same tag.
Continuing the previous example, suppose that there was a
third distfile, source3.tar.gz, that
should be downloaded from
ftp.example2.com. The
Makefile would then be written like
.Simplified use of MASTER_SITES:n
with more than 1 file per siteMASTER_SITES= ftp://ftp.example1.com/:source1 \
ftp://ftp.example2.com/:source2
DISTFILES= source1.tar.gz:source1 \
source2.tar.gz:source2 \
source3.tar.gz:source2Detailed informationOkay, so the previous section example did not reflect
your needs? In this section we will explain in detail how
the fine grained fetching mechanism
MASTER_SITES:n works and how you can
modify your ports to use it.Elements can be postfixed with
:n where
n is
[^:,]+, i.e.,
n could conceptually be any
alphanumeric string but we will limit it to
[a-zA-Z_][0-9a-zA-Z_]+ for
now.Moreover, string matching is case sensitive;
i.e., n is different from
N.However, the following words cannot be used for
postfixing purposes since they yield special meaning:
default, all and
ALL (they are used internally in
item ).
Furthermore, DEFAULT is a special
purpose word (check item ).Elements postfixed with :n
belong to the group n,
:m belong to group
m and so forth.Elements without a postfix are groupless, i.e.,
they all belong to the special group
DEFAULT. If you postfix any
elements with DEFAULT, you are just
being redundant unless you want to have an element
belonging to both DEFAULT and other
groups at the same time (check item ).The following examples are equivalent but the
first one is preferred:MASTER_SITES= alpha
MASTER_SITES= alpha:DEFAULTGroups are not exclusive, an element may belong to
several different groups at the same time and a group
can either have either several different elements or
none at all. Repeated elements within the same group
will be simply that, repeated elements.When you want an element to belong to several
groups at the same time, you can use the comma
operator (,).Instead of repeating it several times, each time
with a different postfix, we can list several groups
at once in a single postfix. For instance,
:m,n,o marks an element that
belongs to group m,
n and o.All the following examples are equivalent but the
last one is preferred:MASTER_SITES= alpha alpha:SOME_SITE
MASTER_SITES= alpha:DEFAULT alpha:SOME_SITE
MASTER_SITES= alpha:SOME_SITE,DEFAULT
MASTER_SITES= alpha:DEFAULT,SOME_SITEAll sites within a given group are sorted
according to MASTER_SORT_AWK. All
groups within MASTER_SITES and
PATCH_SITES are sorted as
well.Group semantics can be used in any of the
following variables MASTER_SITES,
PATCH_SITES,
MASTER_SITE_SUBDIR,
PATCH_SITE_SUBDIR,
DISTFILES, and
PATCHFILES according to the
following syntax:All MASTER_SITES,
PATCH_SITES,
MASTER_SITE_SUBDIR and
PATCH_SITE_SUBDIR elements must
be terminated with the forward slash
/ character. If any elements
belong to any groups, the group postfix
:n
must come right after the terminator
/. The
MASTER_SITES:n mechanism relies
on the existence of the terminator
/ to avoid confusing elements
where a :n is a valid part of
the element with occurrences where
:n denotes group
n. For compatibility purposes,
since the / terminator was not
required before in both
MASTER_SITE_SUBDIR and
PATCH_SITE_SUBDIR elements, if
the postfix immediate preceding character is not
a / then :n
will be considered a valid part of the element
instead of a group postfix even if an element is
postfixed with :n. See both
and .Detailed use of
MASTER_SITES:n in
MASTER_SITE_SUBDIRMASTER_SITE_SUBDIR= old:n new/:NEWDirectories within group
DEFAULT -> old:nDirectories within group
NEW -> newDetailed use of
MASTER_SITES:n with comma
operator, multiple files, multiple sites and
multiple subdirectoriesMASTER_SITES= http://site1/%SUBDIR%/ http://site2/:DEFAULT \
http://site3/:group3 http://site4/:group4 \
http://site5/:group5 http://site6/:group6 \
http://site7/:DEFAULT,group6 \
http://site8/%SUBDIR%/:group6,group7 \
http://site9/:group8
DISTFILES= file1 file2:DEFAULT file3:group3 \
file4:group4,group5,group6 file5:grouping \
file6:group7
MASTER_SITE_SUBDIR= directory-trial:1 directory-n/:groupn \
directory-one/:group6,DEFAULT \
directoryThe previous example results in the
following fine grained fetching. Sites are
listed in the exact order they will be
used.file1 will be
fetched fromMASTER_SITE_OVERRIDEhttp://site1/directory-trial:1/http://site1/directory-one/http://site1/directory/http://site2/http://site7/MASTER_SITE_BACKUPfile2 will be
fetched exactly as
file1 since they
both belong to the same groupMASTER_SITE_OVERRIDEhttp://site1/directory-trial:1/http://site1/directory-one/http://site1/directory/http://site2/http://site7/MASTER_SITE_BACKUPfile3 will be
fetched fromMASTER_SITE_OVERRIDEhttp://site3/MASTER_SITE_BACKUPfile4 will be
fetched fromMASTER_SITE_OVERRIDEhttp://site4/http://site5/http://site6/http://site7/http://site8/directory-one/MASTER_SITE_BACKUPfile5 will be
fetched fromMASTER_SITE_OVERRIDEMASTER_SITE_BACKUPfile6 will be
fetched fromMASTER_SITE_OVERRIDEhttp://site8/MASTER_SITE_BACKUPHow do I group one of the special variables from
bsd.sites.mk, e.g.,
MASTER_SITE_SOURCEFORGE?See .Detailed use of
MASTER_SITES:n with
MASTER_SITE_SOURCEFORGEMASTER_SITES= http://site1/ ${MASTER_SITE_SOURCEFORGE:S/$/:sourceforge,TEST/}
DISTFILES= something.tar.gz:sourceforgesomething.tar.gz will be
fetched from all sites within
MASTER_SITE_SOURCEFORGE.How do I use this with PATCH*
variables?All examples were done with
MASTER* variables but they work
exactly the same for PATCH* ones as
can be seen in .Simplified use of
MASTER_SITES:n with
PATCH_SITES.PATCH_SITES= http://site1/ http://site2/:test
PATCHFILES= patch1:testWhat does change for ports? What does not?All current ports remain the same. The
MASTER_SITES:n feature code is only
activated if there are elements postfixed with
:n like
elements according to the aforementioned syntax rules,
especially as shown in item .The port targets remain the same:
checksum,
makesum,
patch,
configure,
build, etc. With the obvious
exceptions of do-fetch,
fetch-list,
master-sites and
patch-sites.do-fetch: deploys the
new grouping postfixed
DISTFILES and
PATCHFILES with their matching
group elements within both
MASTER_SITES and
PATCH_SITES which use matching
group elements within both
MASTER_SITE_SUBDIR and
PATCH_SITE_SUBDIR. Check .fetch-list: works
like old fetch-list with
the exception that it groups just like
do-fetch.master-sites and
patch-sites:
(incompatible with older versions) only return the
elements of group DEFAULT; in
fact, they execute targets
master-sites-default and
patch-sites-default
respectively.Furthermore, using target either
master-sites-all or
patch-sites-all is
preferred to directly checking either
MASTER_SITES or
PATCH_SITES. Also,
directly checking is not guaranteed to work in any
future versions. Check item
for more information on these new port
targets.New port targetsThere are
master-sites-n
and
patch-sites-n
targets which will list the elements of the
respective group n
within MASTER_SITES and
PATCH_SITES respectively. For
instance, both
master-sites-DEFAULT and
patch-sites-DEFAULT will
return the elements of group
DEFAULT,
master-sites-test and
patch-sites-test of group
test, and thereon.There are new targets
master-sites-all and
patch-sites-all which do
the work of the old
master-sites and
patch-sites ones. They
return the elements of all groups as if they all
belonged to the same group with the caveat that it
lists as many
MASTER_SITE_BACKUP and
MASTER_SITE_OVERRIDE as there
are groups defined within either
DISTFILES or
PATCHFILES; respectively for
master-sites-all and
patch-sites-all.DIST_SUBDIRDo not let your port clutter
/usr/ports/distfiles. If your port requires a
lot of files to be fetched, or contains a file that has a name that
might conflict with other ports (e.g.,
Makefile), set DIST_SUBDIR
to the name of the port (${PORTNAME} or
${PKGNAMEPREFIX}${PORTNAME}
should work fine). This will change
DISTDIR from the default
/usr/ports/distfiles to
/usr/ports/distfiles/DIST_SUBDIR,
and in effect puts everything that is required for your port into
that subdirectory.It will also look at the subdirectory with the same name on the
backup master site at ftp.FreeBSD.org.
(Setting DISTDIR explicitly in your
Makefile will not accomplish this, so please use
DIST_SUBDIR.)This does not affect the MASTER_SITES you
define in your Makefile.ALWAYS_KEEP_DISTFILESIf your port uses binary distfiles and has a license that
requires that the source code is provided with packages distributed
in binary form, e.g. GPL, ALWAYS_KEEP_DISTFILES
will instruct the &os; build cluster to keep a copy of the files
specified in DISTFILES. Users of these ports
will generally not need these files, so it is a good idea to only
add the source distfiles to DISTFILES when
PACKAGE_BUILDING is defined.
Use of ALWAYS_KEEP_DISTFILES..if defined(PACKAGE_BUILDING)
DISTFILES+= foo.tar.gz
ALWAYS_KEEP_DISTFILES= yes
.endifWhen adding extra files to DISTFILES,
make sure you also add them to distinfo.
Also, the additional files will normally be extracted into
WRKDIR as well, which for some ports may
lead to undesirable sideeffects and require special handling.MAINTAINERSet your mail-address here. Please. :-)Note that only a single address without the comment part is
allowed as a MAINTAINER value.
The format used should be user@hostname.domain.
Please do not include any descriptive text such as your real
name in this entry—that merely confuses
bsd.port.mk.The maintainer is responsible for keeping the port up to
date, and ensuring the port works correctly.
For a detailed description of the responsibilities of a port
maintainer, refer to the The
challenge for port maintainers section.Changes to the port will be sent to the maintainer of
a port for a review and an approval before being committed.
If the maintainer does not respond to an update
request after two weeks (excluding major public
holidays), then that is considered a maintainer timeout, and the
update may be made without explicit maintainer approval. If the
maintainer does not respond within three months, then that
maintainer is considered absent without leave, and can be
replaced as the maintainer of the particular port in question.
Exceptions to this are anything maintained by the &a.portmgr;, or
the &a.security-officer;. No unauthorized commits may ever be
made to ports maintained by those groups.We reserve the right to modify the maintainer's submission
to better match existing policies and style of the Ports
Collection without explicit blessing from the submitter.
Also, large infrastructural changes can result in
a port being modified without maintainer's consent.
This kind of changes will never affect the port's
functionality.The &a.portmgr; reserves the right to revoke or override
anyone's maintainership for any reason, and the &a.security-officer;
reserves the right to revoke or override maintainership for security
reasons.COMMENTThis is a one-line description of the port.
Please do not include the package name (or
version number of the software) in the comment. The comment
should begin with a capital and end without a period. Here
is an example:COMMENT= A cat chasing a mouse all over the screenThe COMMENT variable should immediately follow the MAINTAINER
variable in the Makefile.Please try to keep the COMMENT line less than 70
characters, as it is displayed to users as a one-line
summary of the port.DependenciesMany ports depend on other ports. There are seven variables that
you can use to ensure that all the required bits will be on the
user's machine. There are also some pre-supported dependency
variables for common cases, plus a few more to control the behavior
of dependencies.LIB_DEPENDSThis variable specifies the shared libraries this port depends
on. It is a list of
lib:dir:target
tuples where lib is the name of the
shared library, dir is the
directory in which to find it in case it is not available, and
target is the target to call in that
directory. For example,
LIB_DEPENDS= jpeg.9:${PORTSDIR}/graphics/jpeg
will check for a shared jpeg library with major version 9, and
descend into the graphics/jpeg subdirectory
of your ports tree to build and install it if it is not found.
The target part can be omitted if it is
equal to DEPENDS_TARGET (which defaults to
install).The lib part is a regular
expression which is being looked up in the
ldconfig -r output. Values such as
intl.[5-7] and intl are
allowed. The first pattern,
intl.[5-7], will match any of:
intl.5, intl.6 or
intl.7. The second pattern,
intl, will match any version of the
intl library.The dependency is checked twice, once from within the
extract target and then from within the
install target. Also, the name of the
dependency is put into the package so that
&man.pkg.add.1; will automatically install it if it is
not on the user's system.RUN_DEPENDSThis variable specifies executables or files this port depends
on during run-time. It is a list of
path:dir:target
tuples where path is the name of the
executable or file, dir is the
directory in which to find it in case it is not available, and
target is the target to call in that
directory. If path starts with a slash
(/), it is treated as a file and its existence
is tested with test -e; otherwise, it is
assumed to be an executable, and which -s is
used to determine if the program exists in the search path.For example,RUN_DEPENDS= ${LOCALBASE}/etc/innd:${PORTSDIR}/news/inn \
wish8.0:${PORTSDIR}/x11-toolkits/tk80will check if the file or directory
/usr/local/etc/innd exists, and build and
install it from the news/inn subdirectory of
the ports tree if it is not found. It will also see if an
executable called wish8.0 is in the search
path, and descend into the x11-toolkits/tk80
subdirectory of your ports tree to build and install it if it is
not found.In this case, innd is actually an
executable; if an executable is in a place that is not expected
to be in the search path, you should use the full
pathname.The official search PATH used on the ports
build cluster is/sbin:/bin:/usr/sbin:/usr/bin:/usr/local/sbin:/usr/local/bin:/usr/X11R6/binThe dependency is checked from within the
install target. Also, the name of the
dependency is put into the package so that
&man.pkg.add.1; will automatically install it if it is
not on the user's system. The target
part can be omitted if it is the same as
DEPENDS_TARGET.BUILD_DEPENDSThis variable specifies executables or files this port
requires to build. Like RUN_DEPENDS, it is a
list of
path:dir:target
tuples. For example, BUILD_DEPENDS=
unzip:${PORTSDIR}/archivers/unzip will check
for an executable called unzip, and descend
into the archivers/unzip subdirectory of your
ports tree to build and install it if it is not found.build here means everything from extraction to
compilation. The dependency is checked from within the
extract target. The
target part can be omitted if it is
the same as DEPENDS_TARGETFETCH_DEPENDSThis variable specifies executables or files this port
requires to fetch. Like the previous two, it is a list of
path:dir:target
tuples. For example, FETCH_DEPENDS=
ncftp2:${PORTSDIR}/net/ncftp2 will check for an
executable called ncftp2, and descend into the
net/ncftp2 subdirectory of your ports tree to
build and install it if it is not found.The dependency is checked from within the
fetch target. The
target part can be omitted if it is the
same as DEPENDS_TARGET.EXTRACT_DEPENDSThis variable specifies executables or files this port
requires for extraction. Like the previous, it is a list of
path:dir:target
tuples. For example, EXTRACT_DEPENDS=
unzip:${PORTSDIR}/archivers/unzip will check
for an executable called unzip, and descend
into the archivers/unzip subdirectory of
your ports tree to build and install it if it is not found.The dependency is checked from within the
extract target. The
target part can be omitted if it is the
same as DEPENDS_TARGET.Use this variable only if the extraction does not already
work (the default assumes gzip) and cannot
be made to work using USE_ZIP or
USE_BZIP2 described in .PATCH_DEPENDSThis variable specifies executables or files this port
requires to patch. Like the previous, it is a list of
path:dir:target
tuples. For example, PATCH_DEPENDS=
${NONEXISTENT}:${PORTSDIR}/java/jfc:extract
will descend into the
java/jfc subdirectory of your ports tree to
extract it.The dependency is checked from within the
patch target. The
target part can be omitted if it is the
same as DEPENDS_TARGET.PERL_BUILD_DEPENDS and
PERL_RUN_DEPENDSThese variables allow you to specify dependencies on Perl
modules. For example,
PERL_RUN_DEPENDS= MIME-Base64:${PORTSDIR}/converters/p5-MIME-Base64
will check for the MIME::Base64 Perl module
(note the replacement of ::
with -) and install it if
it is missing.DEPENDSIf there is a dependency that does not fall into either of the
above categories, or your port requires having the source of
the other port extracted in addition to having it installed,
then use this variable. This is a list of
dir:target,
as there is nothing to check, unlike the previous four. The
target part can be omitted if it is the
same as DEPENDS_TARGET.USE_*A number of variables exist in order to encapsulate common
dependencies that many ports have. Although their use is
optional, they can help to reduce the verbosity of the port
Makefiles. Each of them is styled
as USE_*. The
usage of these variables is restricted to the port
Makefiles and
ports/Mk/bsd.*.mk and is not designed
to encapsulate user-settable options — use
WITH_* and
WITHOUT_*
for that purpose.It is always incorrect to set
any USE_*
in /etc/make.conf. For instance,
setting USE_GCC=3.2
would adds a dependency on gcc32 for every port,
including gcc32 itself!
The USE_*
variablesVariableMeansUSE_BZIP2The port's tarballs are compressed with
bzip2.USE_ZIPThe port's tarballs are compressed with
zip.USE_BISONThe port uses bison for
building.USE_GCCThe port requires a specific version of
gcc to build. The exact version can be
specified with value such as 3.2.
The minimal required version can be specified as
3.2+. The gcc from
the base system is used when it satisfies the requested
version, otherwise an appropriate gcc is
compiled from ports and the CC and
CXX variables are adjusted.
USE_GCC can't be used together with
USE_AUTOTOOLS=libtool:XX.
Variables related to gmake and
the configure script are described in
, while
autoconf,
automake and
libtool are described in
. Perl
related variables are described in .
X11 variables are listed in . deals with GNOME and with KDE related variables. documents Java variables, while contains information on
Apache, PHP
and PEAR modules. Python is discussed
in , while
Ruby in .
Finally, provides variables used for
SDL applications.Minimal version of a dependencyA minimal version of a dependency can be specified in any
*_DEPENDS variable using the following
syntax:p5-Spiffy>=0.26:${PORTSDIR}/devel/p5-SpiffyThe first field contains a dependent package name,
which must match the entry in the package database,
a comparison sign, and a package version. The dependency
is satisfied if p5-Spiffy-0.26 or newer is installed on
the machine.Notes on dependenciesAs mentioned above, the default target to call when a
dependency is required is DEPENDS_TARGET.
It defaults to install. This is a user
variable; it is never defined in a port's
Makefile. If your port needs a special way
to handle a dependency, use the :target part of
the *_DEPENDS variables instead of redefining
DEPENDS_TARGET.When you type make clean, its dependencies
are automatically cleaned too. If you do not wish this to happen,
define the variable NOCLEANDEPENDS in your
environment. This may be particularly desirable if the port
has something that takes a long time to rebuild in its
dependency list, such as KDE, GNOME or Mozilla.To depend on another port unconditionally, use the
variable ${NONEXISTENT} as the first field
of BUILD_DEPENDS or
RUN_DEPENDS. Use this only when you need to
get the source of the other port. You can often save
compilation time by specifying the target too. For
instance
BUILD_DEPENDS= ${NONEXISTENT}:${PORTSDIR}/graphics/jpeg:extract
will always descend to the jpeg port and extract it.Do not use DEPENDS unless there is no other
way the behavior you want can be accomplished. It will cause the
other port to always be built (and installed, by default), and the
dependency will go into the packages as well. If this is really
what you need, you should probably write it as
BUILD_DEPENDS and
RUN_DEPENDS instead—at least the
intention will be clear.Circular dependencies are fatalDo not introduce any circular dependencies into the
ports tree!The ports building technology does not tolerate
circular dependencies. If you introduce one, you will have
someone, somewhere in the world, whose FreeBSD installation will
break almost immediately, with many others quickly to follow.
These can really be hard to detect; if in doubt, before
you make that change, make sure you have done the following:
cd /usr/ports; make index. That process
can be quite slow on older machines, but you may be able to
save a large number of people—including yourself—
a lot of grief in the process.MASTERDIRIf your port needs to build slightly different versions of
packages by having a variable (for instance, resolution, or paper
size) take different values, create one subdirectory per package to
make it easier for users to see what to do, but try to share as many
files as possible between ports. Typically you only need a very short
Makefile in all but one of the directories if you
use variables cleverly. In the sole Makefile,
you can use MASTERDIR to specify the directory
where the rest of the files are. Also, use a variable as part of
PKGNAMESUFFIX so
the packages will have different names.This will be best demonstrated by an example. This is part of
japanese/xdvi300/Makefile;PORTNAME= xdvi
PORTVERSION= 17
PKGNAMEPREFIX= ja-
PKGNAMESUFFIX= ${RESOLUTION}
:
# default
RESOLUTION?= 300
.if ${RESOLUTION} != 118 && ${RESOLUTION} != 240 && \
${RESOLUTION} != 300 && ${RESOLUTION} != 400
@${ECHO} "Error: invalid value for RESOLUTION: \"${RESOLUTION}\""
@${ECHO} "Possible values are: 118, 240, 300 (default) and 400."
@${FALSE}
.endifjapanese/xdvi300 also has all the regular
patches, package files, etc. If you type make
there, it will take the default value for the resolution (300) and
build the port normally.As for other resolutions, this is the entirexdvi118/Makefile:RESOLUTION= 118
MASTERDIR= ${.CURDIR}/../xdvi300
.include "${MASTERDIR}/Makefile"(xdvi240/Makefile and
xdvi400/Makefile are similar). The
MASTERDIR definition tells
bsd.port.mk that the regular set of
subdirectories like FILESDIR and
SCRIPTDIR are to be found under
xdvi300. The RESOLUTION=118
line will override the RESOLUTION=300 line in
xdvi300/Makefile and the port will be built with
resolution set to 118.ManpagesThe MAN[1-9LN] variables will automatically add
any manpages to pkg-plist (this means you must
not list manpages in the
pkg-plist—see generating PLIST for more). It also
makes the install stage automatically compress or uncompress manpages
depending on the setting of NOMANCOMPRESS in
/etc/make.conf.If your port tries to install multiple names for manpages using
symlinks or hardlinks, you must use the MLINKS
variable to identify these. The link installed by your port will
be destroyed and recreated by bsd.port.mk
to make sure it points to the correct file. Any manpages
listed in MLINKS must not be listed in the
pkg-plist.To specify whether the manpages are compressed upon installation,
use the MANCOMPRESSED variable. This variable can
take three values, yes, no and
maybe. yes means manpages are
already installed compressed, no means they are
not, and maybe means the software already respects
the value of NOMANCOMPRESS so
bsd.port.mk does not have to do anything
special.MANCOMPRESSED is automatically set to
yes if USE_IMAKE is set and
NO_INSTALL_MANPAGES is not set, and to
no otherwise. You do not have to explicitly define
it unless the default is not suitable for your port.If your port anchors its man tree somewhere other than
PREFIX, you can use the
MANPREFIX to set it. Also, if only manpages in
certain sections go in a non-standard place, such as some perl modules
ports, you can set individual man paths using
MANsectPREFIX (where
sect is one of 1-9,
L or N).If your manpages go to language-specific subdirectories, set the
name of the languages to MANLANG. The value of
this variable defaults to "" (i.e., English
only).Here is an example that puts it all together.MAN1= foo.1
MAN3= bar.3
MAN4= baz.4
MLINKS= foo.1 alt-name.8
MANLANG= "" ja
MAN3PREFIX= ${PREFIX}/share/foobar
MANCOMPRESSED= yesThis states that six files are installed by this port;${PREFIX}/man/man1/foo.1.gz
${PREFIX}/man/ja/man1/foo.1.gz
${PREFIX}/share/foobar/man/man3/bar.3.gz
${PREFIX}/share/foobar/man/ja/man3/bar.3.gz
${PREFIX}/man/man4/baz.4.gz
${PREFIX}/man/ja/man4/baz.4.gzAdditionally ${PREFIX}/man/man8/alt-name.8.gz
may or may not be installed by your port. Regardless, a
symlink will be made to join the foo(1) manpage and
alt-name(8) manpage.Info filesIf your package needs to install GNU info files, they should be
listed in the INFO variable (without the trailing
.info), and appropriate installation/de-installation
code will be automatically added to the temporary
pkg-plist before package registration.Makefile OptionsSome large applications can be built in a number of
configurations, adding functionality if one of a number of
libraries or applications is available. Examples include
choice of natural (human) language, GUI versus command-line,
or type of database to support. Since not all users
want those libraries or applications, the ports system
provides hooks that the port author can use to control which
configuration should be built. Supporting these properly will
make users happy, and effectively provide 2 or more ports for the
price of one.KNOBSWITH_* and
WITHOUT_*These variables are designed to be set by the system
administrator. There are many that are standardized in
ports/Mk/bsd.*.mk; others are not,
which can be confusing. If you need to add such a
configuration variable, please consider using one of the
ones from the following list.You should not assume that a
WITH_*
necessarily has a corresponding
WITHOUT_*
variable and vice versa. In general, the default is
simply assumed.Unless otherwise specified, these variables are only
tested for being set or not set, rather than being set to
some kind of variable such as YES or
NO.
The WITH_*
and WITHOUT_*
variablesVariableMeansWITH_APACHE2If set, use
www/apache2
instead of the default of
www/apache.WITH_BERKELEY_DBDefine this variable to specify the ability to
use a variant of the Berkeley database package such as
databases/db41.
An associated variable,
WITH_BDB_VER, may be
set to values such as 2, 3, 4, 41 or 42.WITH_MYSQLDefine this variable to specify the ability to
use a variant of the MySQL database package such as
databases/mysql40-server.
An associated variable,
WANT_MYSQL_VER, may be
set to values such as 323, 40, 41, or 50.WITHOUT_NLSIf set, says that internationalization is not
needed, which can save compile time. By default,
internationalization is used.WITH_OPENSSL_BASEUse the version of OpenSSL in the base system.WITH_OPENSSL_PORTUse the version of OpenSSL from
security/openssh,
overwriting the version that was originally installed
in the base system.WITH_POSTGRESQLDefine this variable to specify the ability to
use a variant of the PostGreSQL database package such as
databases/postgresql72.
WITHOUT_X11If the port can be built both with and without
X support, then it should normally be built with
X support. If this variable is defined, then
the version that does not have X support should
be built instead.
Knob namingIt is recommended that porters use like-named knobs, for the
benefit of end-users and to help keep the number of knob names down.
A list of popular knob names can be found in the
KNOBS
file.Knob names should reflect what the knob is and does.
When a port has a lib-prefix in the PORTNAME
the lib-prefix should be dropped in knob naming.OPTIONSBackgroundThe OPTIONS variable gives the user who
installs the port a dialog with the available options and saves
them to /var/db/ports/portname/options.
Next time when the port has to be rebuild, the options are reused.
Never again you will have to remember all the twenty
WITH_* and
WITHOUT_* options you
used to build this port!When the user runs make config (or runs
make build for the first time), the framework will
check for
/var/db/ports/portname/options.
If that file does not exist, it will use the values of
OPTIONS to create a dialogbox where the options
can be enabled or disabled. Then the
options file is saved and the selected
variables will be used when building the port.Use make showconfig to see the saved
configuration. Use make rmconfig to remove the
saved configuration.SyntaxThe syntax for the OPTIONS variable is:
OPTIONS= OPTION "descriptive text" default ...
The value for default is either ON or
OFF. Multiple repetitions of these three fields
are allowed.OPTIONS definition must appear before
the inclusion of bsd.port.pre.mk.
The WITH_* and WITHOUT_*
variables can only be tested after the inclusion of
bsd.port.pre.mk. Due to a deficiency
in the infrastructure, you can only test
WITH_* variables for options, which are
OFF by default, and
WITHOUT_* variables for options, which
defaults to ON.ExampleSimple use of OPTIONSOPTIONS= FOO "Enable option foo" On \
BAR "Support feature bar" Off
.include <bsd.port.pre.mk>
.if defined(WITHOUT_FOO)
CONFIGURE_ARGS+= --without-foo
.else
CONFIGURE_ARGS+= --with-foo
.endif
.if defined(WITH_BAR)
RUN_DEPENDS+= bar:${PORTSDIR}/bar/bar
.endif
.include <bsd.port.post.mk>Specifying the working directoryEach port is extracted in to a working directory, which must be
writable. The ports system defaults to having the
DISTFILES unpack in to a directory called
${DISTNAME}. In other words, if you have
set:PORTNAME= foo
PORTVERSION= 1.0then the port's distribution files contain a top-level directory,
foo-1.0, and the rest of the files are located
under that directory.There are a number of variables you can override if that is not the
case.WRKSRCThe variable lists the name of the directory that is created when
the application's distfiles are extracted. If our previous example
extracted into a directory called foo (and not
foo-1.0) you would write:WRKSRC= ${WRKDIR}/fooor possiblyWRKSRC= ${WRKDIR}/${PORTNAME}NO_WRKSUBDIRIf the port does not extract in to a subdirectory at all then
you should set NO_WRKSUBDIR to indicate
that.NO_WRKSUBDIR= yesCONFLICTSIf your package cannot coexist with other packages
(because of file conflicts, runtime incompatibility, etc.),
list the other package names in the CONFLICTS
variable. You can use shell globs like * and
? here. Packages names should be
enumerated the same way they appear in
/var/db/pkg. Please make sure that
CONFLICTS does not match this port's
package itself, or else forcing its installation with
FORCE_PKG_REGISTER will no longer work.
CONFLICTS automatically sets
IGNORE, which is more fully documented
in .Special considerationsThere are some more things you have to take into account when you
create a port. This section explains the most common of those.Shared LibrariesIf your port installs one or more shared libraries, define a
INSTALLS_SHLIB make variable, which will instruct
a bsd.port.mk to run
${LDCONFIG} -m on the directory where the
new library is installed (usually
PREFIX/lib) during
post-install target to register it into the
shared library cache. This variable, when defined, will also
facilitate addition of an appropriate
@exec /sbin/ldconfig -m and
@unexec /sbin/ldconfig -R pair into your
pkg-plist file, so that a user who installed
the package can start using the shared library immediately and
de-installation will not cause the system to still believe the
library is there.If you need, you can override the default location where the new
library is installed by defining the LDCONFIG_DIRS
make variable, which should contain a list of directories into which
shared libraries are to be installed. For example if your port
installs shared libraries into
PREFIX/lib/foo and
PREFIX/lib/bar directories
you could use the following in your
Makefile:INSTALLS_SHLIB= yes
LDCONFIG_DIRS= %%PREFIX%%/lib/foo %%PREFIX%%/lib/barRemember that non-standard directories will not be passed to
&man.ldconfig.8; on (re-)boot! If any port really
needs this to work, install a startup-script as
x11/kdelibs3 does. Please
double-check, often this is not necessary at all or can be avoided
through -rpath or setting LD_RUN_PATH
during linking (see lang/moscow_ml
for an example), or through a shell-wrapper which sets
LD_LIBRARY_PATH before invoking the binary, like
www/mozilla does.Note that content of LDCONFIG_DIRS is passed
through &man.sed.1; just like the rest of pkg-plist,
so PLIST_SUB substitutions also apply here. It is
recommended that you use %%PREFIX%% for
PREFIX, %%LOCALBASE%% for
LOCALBASE and %%X11BASE%% for
X11BASE.Try to keep shared library version numbers in the
libfoo.so.0 format. Our runtime linker only
cares for the major (first) number.When the major library version number increments in the update
to the new port version, all other ports that link to the affected
library should have their PORTREVISION incremented,
to force recompilation with the new library version.Ports with distribution restrictionsLicenses vary, and some of them place restrictions on how the
application can be packaged, whether it can be sold for profit, and so
on.It is your responsibility as a porter to read the licensing
terms of the software and make sure that the FreeBSD project will
not be held accountable for violating them by redistributing the
source or compiled binaries either via FTP/HTTP or CD-ROM. If in doubt,
please contact the &a.ports;.In situations like this, the variables described in the following
sections can be set.NO_PACKAGEThis variable indicates that we may not generate a binary
package of the application. For instance, the license may
disallow binary redistribution, or it may prohibit distribution
of packages created from patched sources.However, the port's DISTFILES may be
freely mirrored on FTP/HTTP. They may also be distributed on
a CD-ROM (or similar media) unless NO_CDROM
is set as well.NO_PACKAGE should also be used if the binary
package is not generally useful, and the application should always
be compiled from the source code. For example, if the application
has configuration information that is site specific hard coded in to
it at compile time, set NO_PACKAGE.NO_PACKAGE should be set to a string
describing the reason why the package should not be
generated.NO_CDROMThis variable alone indicates that, although we are allowed
to generate binary packages, we may put neither those packages
nor the port's DISTFILES onto a CD-ROM (or
similar media) for resale. However, the binary packages and
the port's DISTFILES will still be available
via FTP/HTTP. If this variable is set along with
NO_PACKAGE, then only the port's
DISTFILES will be available, and only via
FTP/HTTP.NO_CDROM should be set to a string
describing the reason why the port cannot be redistributed
on CD-ROM. For instance, this should be used if the port's license
is for non-commercial use only.NOFETCHFILESFiles defined in the NOFETCHFILES
variable are not fetchable from any of the
MASTER_SITES. An example of such a
file is when the file is supplied on CD-ROM by the
vendor.Tools which check for the availability of these files
on the MASTER_SITES should ignore these
files and not report about them.RESTRICTEDSet this variable alone if the application's license permits
neither mirroring the application's DISTFILES
nor distributing the binary package in any way.NO_CDROM or NO_PACKAGE
should not be set along with RESTRICTED
since the latter variable implies the former ones.RESTRICTED should be set to a string
describing the reason why the port cannot be redistributed.
Typically, this indicates that the port contains proprietary
software and that the user will need to manually download the
DISTFILES, possibly after registering for the
software or agreeing to accept the terms of an
EULA.RESTRICTED_FILESWhen RESTRICTED or NO_CDROM
is set, this variable defaults to ${DISTFILES}
${PATCHFILES}, otherwise it is empty. If only some of the
distribution files are restricted, then set this variable to list
them.Note that the port committer should add an entry to
/usr/ports/LEGAL for every listed distribution
file, describing exactly what the restriction entails.Building mechanismsmake, gmake, and
imakeIf your port uses GNU make, set
USE_GMAKE=yes.
Variables for ports related to gmakeVariableMeansUSE_GMAKEThe port requires gmake to
build.GMAKEThe full path for gmake if it is not
in the PATH.
If your port is an X application that creates
Makefile files from
Imakefile files using
imake, then set
USE_IMAKE=yes. This will cause the
configure stage to automatically do an xmkmf -a.
If the flag is a problem for your port, set
XMKMF=xmkmf. If the port uses
imake but does not understand the
install.man target,
NO_INSTALL_MANPAGES=yes should be set.If your port's source Makefile has
something else than all as the main build
target, set ALL_TARGET accordingly. Same goes
for install and
INSTALL_TARGET.configure scriptIf your port uses the configure script to
generate Makefile files from
Makefile.in files, set
GNU_CONFIGURE=yes. If you want to give extra
arguments to the configure script (the default
argument is --prefix=${PREFIX}
${CONFIGURE_TARGET}), set those
extra arguments in CONFIGURE_ARGS. Extra
environment variables can be passed using
CONFIGURE_ENV variable.If your package uses GNU configure, and
the resulting executable file has a strange name
like
i386-portbld-freebsd4.7-appname,
you will need to additionally override the
CONFIGURE_TARGET variable to specify the
target in the way required by scripts generated by recent
versions of autoconf. Add the following line
immediately after the GNU_CONFIGURE=yes line
in your Makefile:CONFIGURE_TARGET=--build=${MACHINE_ARCH}-portbld-freebsd${OSREL}
Variables for ports that use configureVariableMeansGNU_CONFIGUREThe port uses configure script to
prepare build.HAS_CONFIGURESame as GNU_CONFIGURE, except
default configure target is not added to
CONFIGURE_ARGS.CONFIGURE_ARGSAdditional arguments passed to
configure script.CONFIGURE_ENVAdditional environment variables to be set
for configure script run.CONFIGURE_TARGETOverride default configure target. Default value is
${MACHINE_ARCH}-portbld-freebsd${OSREL}.
Using GNU autotoolsIntroductionThe various GNU autotools provide an abstraction mechanism for
building a piece of software over a wide variety of operating
systems and machine architectures. Within the Ports Collection,
an individual port can make use of these tools via a simple
construct:USE_AUTOTOOLS= tool:version[:operation] ...At the time of writing, tool can be
one of libtool, libltdl,
autoconf, autoheader,
automake or aclocal.version specifies the particular
tool revision to be used (see
devel/{automake,autoconf,libtool}[0-9]+ for
valid versions).operation is an optional extension
to modify how the tool is used.Multiple tools can be specified at once, either by including
them all on a single line, or using the +=
Makefile construct.Before proceeding any further, it cannot be stressed highly
enough that the constructs discussed here are for use ONLY in
building other ports. For cross-development work, the
devel/gnu-{automake,autoconf,libtool} ports
should be used, such as within an IDE. devel/anjuta and devel/kdevelop (GNOME and KDE
respectively) are good examples of how to achieve this.libtoolShared libraries using the GNU building framework usually use
libtool to adjust the compilation and
installation of shared libraries to match the specifics of the
underlying operating system. The Ports Collection provides a
number of versions of libtool modified for use by
&os;.USE_AUTOTOOLS= libtool:version[:inc|:env]With no additional operations,
libtool:version tells
the building framework that the port uses
libtool, implying
GNU_CONFIGURE. The configure script will be
patched with the system-installed copy of
libtool. Further, a number of make and shell
variables will be assigned for onward use by the port. See
bsd.autotools.mk for details.With the :inc operation, the environment
will be set up, and a slightly different set of patching will be
performed.With the :env operation, only the
environment will be set up.PreviouslyUSE_AUTOTOOLS constructUSE_LIBTOOL_VER=13libtool:13USE_INC_LIBTOOL_VER=15libtool:15:incWANT_LIBTOOL_VER=15libtool:15:envFinally, LIBTOOLFLAGS and
LIBTOOLFILES can be optionally set to override
the most likely arguments to, and files patched by,
libtool. Most ports are unlikely to need this.
See bsd.autotools.mk for further
details.libltdlSome ports make use of the libltdl library
package, which is part of the libtool suite.
Use of this library does not automatically necessitate the use of
libtool itself, so a separate construct is
provided.USE_AUTOTOOLS= libltdl:versionCurrently, all this does is to bring in a
LIB_DEPENDS on the appropriate
libltdl port, and is provided as a convenience
function to help eliminate any dependencies on the autotools ports
outside of the USE_AUTOTOOLS framework. There
are no optional operations for this tool.PreviouslyUSE_AUTOTOOLS constructUSE_LIBLTDL=YESlibltdl:15autoconf and
autoheaderSome ports do not contain a configure script, but do contain an
autoconf template in the configure.ac file.
You can use the following assignments to let
autoconf create the configure script, and also
have autoheader create template headers for use
by the configure script.USE_AUTOTOOLS= autoconf:version[:env]andUSE_AUTOTOOLS= autoheader:versionwhich also implies the use of
autoconf:version.Similarly to libtool, the inclusion of the
optional :env operation simply sets up the
environment for further use. Without it, patching and
reconfiguration of the port is carried out.PreviouslyUSE_AUTOTOOLS constructUSE_AUTOCONF_VER=213autoconf:213WANT_AUTOCONF_VER=259autoconf:259:envUSE_AUTOHEADER_VER=253autoheader:253 (implies
autoconf:253)The additional optional variables
AUTOCONF_ARGS and
AUTOHEADER_ARGS can be overridden by the port
Makefile if specifically requested. As with
the libtool equivalents, most ports are unlikely
to need this.automake and
aclocalSome packages only contain Makefile.am
files. These have to be converted into
Makefile.in files using
automake, and the further processed by
configure to generate an actual
Makefile.Similarly, packages occasionally do not ship with included
aclocal.m4 files, again required to build the
software. This can be achieved with aclocal,
which scans configure.ac or
configure.in.aclocal has a similar relationship to
automake as autoheader does
to autoconf, described in the previous section.
aclocal implies the use of
automake, thus we have:USE_AUTOTOOLS= automake:version[:env]andUSE_AUTOTOOLS= aclocal:versionwhich also implies the use of
automake:version.Similarly to libtool and
autoconf, the inclusion of the optional
:env operation simply sets up the environment
for further use. Without it, reconfiguration of the port is
carried out.PreviouslyUSE_AUTOTOOLS constructUSE_AUTOMAKE_VER=14automake:14WANT_AUTOMAKE_VER=15automake:15:envUSE_ACLOCAL_VER=19aclocal:19 (implies
automake:19)As with
autoconf and autoheader, both
automake and aclocal have
optional argument variables, AUTOMAKE_ARGS and
ACLOCAL_ARGS respectively, which may be
overriden by the port Makefile if
required.Using perl
Variables for ports that use perlVariableMeansUSE_PERL5Says that the port uses perl 5 to build and run.USE_PERL5_BUILDSays that the port uses perl 5 to build.USE_PERL5_RUNSays that the port uses perl 5 to run.PERLThe full path of perl 5, either in the
system or installed from a port, but without the version
number. Use this if you need to replace
#!lines in scripts.PERL_CONFIGUREConfigure using Perl's MakeMaker. It implies
USE_PERL5.PERL_MODBUILDConfigure, build and install using Module::Build. It
implies PERL_CONFIGURE.Read only variablesPERL_VERSIONThe full version of perl installed (e.g.,
5.00503).PERL_VERThe short version of perl installed (e.g.,
5.005).PERL_LEVELThe installed perl version as an integer of the form MNNNPP
(e.g., 500503).PERL_ARCHWhere perl stores architecture dependent libraries.
Defaults to ${ARCH}-freebsd.PERL_PORTName of the perl port that is
installed (e.g., perl5).SITE_PERLDirectory name where site specific
perl packages go.
This value is added to PLIST_SUB.
Ports of Perl modules, which do not have an official website,
should link cpan.org in the WWW line of a
pkg-descr file. The suggested URL scheme is
http://search.cpan.org/dist/Module-Name.Using X11Variable definitions
Variables for ports that use XUSE_X_PREFIXThe port installs in X11BASE, not
PREFIX.USE_XLIBThe port uses the X libraries.USE_MOTIFThe port uses the Motif toolkit. Implies
USE_XPM.USE_IMAKEThe port uses imake. Implies
USE_X_PREFIX.XMKMFSet to the path of xmkmf if not in the
PATH. Defaults to xmkmf
-a.
Variables for depending on individual parts of X11X_IMAKE_PORTPort providing imake and several
other utilities used to build X11.X_LIBRARIES_PORTPort providing X11 libraries.X_CLIENTS_PORTPort providing X clients.X_SERVER_PORTPort providing X server.X_FONTSERVER_PORTPort providing font server.X_PRINTSERVER_PORTPort providing print server.X_VFBSERVER_PORTPort providing virtual framebuffer server.X_NESTSERVER_PORTPort providing a nested X server.X_FONTS_ENCODINGS_PORTPort providing encodings for fonts.X_FONTS_MISC_PORTPort providing miscellaneous bitmap fonts.X_FONTS_100DPI_PORTPort providing 100dpi bitmap fonts.X_FONTS_75DPI_PORTPort providing 75dpi bitmap fonts.X_FONTS_CYRILLIC_PORTPort providing cyrillic bitmap fonts.X_FONTS_TTF_PORTPort providing &truetype; fonts.X_FONTS_TYPE1_PORTPort providing Type1 fonts.X_MANUALS_PORTPort providing developer oriented manual pages
Using X11 related variables in port# Use X11 libraries and depend on
# font server as well as cyrillic fonts.
RUN_DEPENDS= ${X11BASE}/bin/xfs:${X_FONTSERVER_PORT} \
${X11BASE}/lib/X11/fonts/cyrillic/crox1c.pcf.gz:${X_FONTS_CYRILLIC_PORT}
USE_XLIB= yesPorts that require MotifIf your port requires a Motif library, define
USE_MOTIF in the Makefile.
Default Motif implementation is
x11-toolkits/open-motif.
Users can choose
x11-toolkits/lesstif instead
by setting WANT_LESSTIF variable.The MOTIFLIB variable will be set by
bsd.port.mk to reference the appropriate
Motif library. Please patch the source of your port to
use ${MOTIFLIB} wherever the Motif library is referenced in the original
Makefile or
Imakefile.There are two common cases:If the port refers to the Motif library as
-lXm in its Makefile or
Imakefile, simply substitute
${MOTIFLIB} for it.If the port uses XmClientLibs in its
Imakefile, change it to
${MOTIFLIB} ${XTOOLLIB}
${XLIB}.Note that MOTIFLIB (usually) expands to
-L/usr/X11R6/lib -lXm or
/usr/X11R6/lib/libXm.a, so there is no need to
add -L or -l in front.X11 fontsIf your port installs fonts for the X Window System, put them in
X11BASE/lib/X11/fonts/local.Getting fake DISPLAY using XvfbSome applications require a working X11 display for compilation to
succeed. This pose a problem for the FreeBSD package building
cluster, which operates headless. When the following canonical hack
is used, the package cluster will start the virtual framebuffer
X server. The working DISPLAY is then passed
to the build..if defined(PACKAGE_BUILDING)
BUILD_DEPENDS+= Xvfb:${X_VFBSERVER_PORT} \
${X11BASE}/lib/X11/fonts/misc/8x13O.pcf.gz:${X_FONTS_MISC_PORT}
.endifUsing GNOMEThe FreeBSD/GNOME project uses its own set of variables
to define which GNOME components a
particular port uses. A
comprehensive
list of these variables exists within the FreeBSD/GNOME
project's homepage.Using KDE
Variables for ports that use KDEUSE_QT_VERThe port uses the Qt toolkit. Possible values are
1 and
3; each specify the major version
of Qt to use. Sets both MOC and
QTCPPFLAGSto default appropriate
values.USE_KDELIBS_VERThe port uses KDE libraries. Possible values are
3; each specify the major version
of KDE to use. Implies USE_QT_VER
of the appropriate version.USE_KDEBASE_VERThe port uses KDE base. Possible values are
3; each specify the major version
of KDE to use. Implies USE_KDELIBS_VER
of the appropriate version.MOCSet to the path of moc.
Default set according to USE_QT_VER
value.QTCPPFLAGSSet the CPPFLAGS to use when
processing Qt code. Default set according to
USE_QT_VER value.
Using JavaVariable definitionsIf your port needs a Java™ Development Kit (JDK) to
either build, run or even extract the distfile, then it should
define USE_JAVA.There are several JDKs in the ports collection, from various
vendors, and in several versions. If your port must use one of
these versions, you can define which one. The most current
version is java/jdk14.
Variables that may be set by ports that use JavaVariableMeansUSE_JAVAShould be defined for the remaining variables to have any
effect.JAVA_VERSIONList of space-separated suitable Java versions for
the port. An optional "+" allows you to
specify a range of versions (allowed values:
1.1[+] 1.2[+] 1.3[+] 1.4[+]).JAVA_OSList of space-separated suitable JDK port operating
systems for the port (allowed values: native
linux).JAVA_VENDORList of space-separated suitable JDK port vendors for
the port (allowed values: freebsd bsdjava sun ibm
blackdown).JAVA_BUILDWhen set, it means that the selected JDK port should
be added to the build dependencies of the port.JAVA_RUNWhen set, it means that the selected JDK port should
be added to the run dependencies of the port.JAVA_EXTRACTWhen set, it means that the selected JDK port should
be added to the extract dependencies of the port.USE_JIKESWhether the port should or should not use the
jikes bytecode compiler to build. When
no value is set for this variable, the port will use
jikes to build if available. You may
also explicitly forbid or enforce the use of
jikes (by setting 'no'
or 'yes'). In the later case, devel/jikes will be added to build
dependencies of the port. In any case that jikes
is actually used in place of javac, then the
HAVE_JIKES variable is defined by
bsd.java.mk.
Below is the list of all settings a port will receive after
setting USE_JAVA:
Variables provided to ports that use JavaVariableValueJAVA_PORTThe name of the JDK port (e.g.
'java/jdk14').JAVA_PORT_VERSIONThe full version of the JDK port (e.g.
'1.4.2'). If you only need the first
two digits of this version number, use
${JAVA_PORT_VERSION:C/^([0-9])\.([0-9])(.*)$/\1.\2/}.JAVA_PORT_OSThe operating system used by the JDK port (e.g.
'linux').JAVA_PORT_VENDORThe vendor of the JDK port (e.g.
'sun').JAVA_PORT_OS_DESCRIPTIONDescription of the operating system used by the JDK port
(e.g. 'Linux').JAVA_PORT_VENDOR_DESCRIPTIONDescription of the vendor of the JDK port (e.g.
'FreeBSD Foundation').JAVA_HOMEPath to the installation directory of the JDK (e.g.
'/usr/local/jdk1.3.1').JAVACPath to the Java compiler to use (e.g.
'/usr/local/jdk1.1.8/bin/javac' or
'/usr/local/bin/jikes').JARPath to the jar tool to use (e.g.
'/usr/local/jdk1.2.2/bin/jar' or
'/usr/local/bin/fastjar').APPLETVIEWERPath to the appletviewer utility (e.g.
'/usr/local/linux-jdk1.2.2/bin/appletviewer').JAVAPath to the java executable. Use
this for executing Java programs (e.g.
'/usr/local/jdk1.3.1/bin/java').JAVADOCPath to the javadoc utility
program.JAVAHPath to the javah program.JAVAPPath to the javap program.JAVA_KEYTOOLPath to the keytool utility program.
This variable is available only if the JDK is Java 1.2 or
higher.JAVA_N2APath to the native2ascii tool.JAVA_POLICYTOOLPath to the policytool program.
This variable is available only if the JDK is Java 1.2 or
higher.JAVA_SERIALVERPath to the serialver utility
program.RMICPath to the RMI stub/skeleton generator,
rmic.RMIREGISTRYPath to the RMI registry program,
rmiregistry.RMIDPath to the RMI daemon program rmid.
This variable is only available if the JDK is Java 1.2
or higher.JAVA_CLASSESPath to the archive that contains the JDK class
files. On JDK 1.2 or later, this is
${JAVA_HOME}/jre/lib/rt.jar. Earlier
JDKs used
${JAVA_HOME}/lib/classes.zip.HAVE_JIKESDefined whenever jikes is used by
the port (see USE_JIKES above).
You may use the java-debug make target
to get information for debugging your port. It will display the
value of many of the forecited variables.Additionally, the following constants are defined so all
Java ports may be installed in a consistent way:
Constants defined for ports that use JavaConstantValueJAVASHAREDIRThe base directory for everything related to Java.
Default: ${PREFIX}/share/java.
JAVAJARDIRThe directory where JAR files should be installed.
Default:
${JAVASHAREDIR}/classes.JAVALIBDIRThe directory where JAR files installed by other
ports are located. Default:
${LOCALBASE}/share/java/classes.
The related entries are defined in both
PLIST_SUB (documented in
) and
SUB_LIST.Building with AntWhen the port is to be built using Apache Ant, it has to
define USE_ANT. Ant is thus considered to be
the sub-make command. When no do-build target
is defined by the port, a default one will be set that simply
runs Ant according to MAKE_ENV,
MAKE_ARGS and ALL_TARGETS.
This is similar to the USE_GMAKE mechanism,
which is documented in .If jikes is used in place of
javac (see USE_JIKES in
), then Ant will automatically
use it to build the port.Best practicesWhen porting a Java library, your port should install the
JAR file(s) in ${JAVAJARDIR}, and everything
else under ${JAVASHAREDIR}/${PORTNAME}
(except for the documentation, see below). In order to reduce
the packing file size, you may reference the JAR file(s) directly
in the Makefile. Just use the following
statement (where myport.jar is the name
of the JAR file installed as part of the port):PLIST_FILES+= %%JAVAJARDIR%%/myport.jarWhen porting a Java application, the port usually installs
everything under a single directory (including its JAR
dependencies). The use of
${JAVASHAREDIR}/${PORTNAME} is strongly
encouraged in this regard. It is up the porter to decide
whether the port should install the additional JAR dependencies
under this directory or directly use the already installed ones
(from ${JAVAJARDIR}).Regardless of the type of your port (library or application),
the additional documentation should be installed in the
same location as for
any other port. The JavaDoc tool is known to produce a
different set of files depending on the version of the JDK that
is used. For ports that do not enforce the use of a particular
JDK, it is therefore a complex task to specify the packing list
(pkg-plist). This is one reason why
porters are strongly encouraged to use the
PORTDOCS macro. Moreover, even if you can
predict the set of files that will be generated by
javadoc, the size of the resulting
pkg-plist advocates for the use of
PORTDOCS.The default value for DATADIR is
${PREFIX}/share/${PORTNAME}. It is a good
idea to override DATADIR to
${JAVASHAREDIR}/${PORTNAME} for Java ports.
Indeed, DATADIR is automatically added to
PLIST_SUB (documented in ) so you may use
%%DATADIR%% directly in
pkg-plist.As for the choice of building Java ports from source or
directly installing them from a binary distribution, there is
no defined policy at the time of writing. However, people from
the &os; Java Project
encourage porters to have their ports built from source whenever
it is a trivial task.All the features that have been presented in this section
are implemented in bsd.java.mk. If you
ever think that your port needs more sophisticated Java support,
please first have a look at the
bsd.java.mk CVS log as it usually takes some time to
document the latest features. Then, if you think the support
you are lacking would be beneficial to many other Java ports,
feel free to discuss it on the &a.java;.Although there is a java category for
PRs, it refers to the JDK porting effort from the &os; Java
project. Therefore, you should submit your Java port in the
ports category as for any other port, unless
the issue you are trying to resolve is related to either a JDK
implementation or bsd.java.mk.Similarly, there is a defined policy regarding the
CATEGORIES of a Java port, which is detailed
in .Using Apache and PHPApache
Variables for ports that use ApacheUSE_APACHEThe port requires Apache.WITH_APACHE2The port requires Apache 2.0. Without this variable,
the port will depend on Apache 1.3.APXSFull path to the apxs binary
(read-only variable).
PHP
Variables for ports that use PHPUSE_PHPThe port requires PHP. The value yes
adds a dependency on PHP. The list of required PHP extensions
can be specified instead. Example: pcre xml
gettextDEFAULT_PHP_VERSelects which major version of PHP will be installed as
a dependency when no PHP is installed yet. Default is
4. Possible values: 4,
5BROKEN_WITH_PHPThe port does not work with PHP of the given version.
Possible values: 4,
5USE_PHPIZEThe port will be built as a PHP extension.USE_PHPEXTThe port will be treated as a PHP extension, including
installation and registration in the extension registry.USE_PHP_BUILDSet PHP as a build dependency.WANT_PHP_CLIWant the CLI (command line) version of PHP.WANT_PHP_CGIWant the CGI version of PHP.WANT_PHP_MODWant the Apache module version of PHP.WANT_PHP_SCRWant the CLI or the CGI version of PHP.WANT_PHP_WEBWant the Apache module or the CGI version of PHP.WANT_PHP_PEARWant the PEAR framework.
PEAR modulesPorting PEAR modules is a very simple process.Use the variables FILES,
TESTS, DATA,
SQLS, SCRIPTFILES,
DOCS and EXAMPLES to list the
files you want to install. All listed files will be automatically
installed into the appropriate locations and added to
pkg-plist.Include
${PORTSDIR}/devel/pear-PEAR/Makefile.common
on the last line of the Makefile.Example Makefile for PEAR classPORTNAME= Date
PORTVERSION= 1.4.3
CATEGORIES= devel www pear
MAINTAINER= example@domain.com
COMMENT= PEAR Date and Time Zone Classes
BUILD_DEPENDS= ${PEARDIR}/PEAR.php:${PORTSDIR}/devel/pear-PEAR
RUN_DEPENDS= ${BUILD_DEPENDS}
FILES= Date.php Date/Calc.php Date/Human.php Date/Span.php \
Date/TimeZone.php
TESTS= test_calc.php test_date_methods_span.php testunit.php \
testunit_date.php testunit_date_span.php wknotest.txt \
bug674.php bug727_1.php bug727_2.php bug727_3.php \
bug727_4.php bug967.php weeksinmonth_4_monday.txt \
weeksinmonth_4_sunday.txt weeksinmonth_rdm_monday.txt \
weeksinmonth_rdm_sunday.txt
DOCS= TODO
_DOCSDIR= .
.include <bsd.port.pre.mk>
.include "${PORTSDIR}/devel/pear-PEAR/Makefile.common"
.include <bsd.port.post.mk>Using Python
Most useful variables for ports that use PythonUSE_PYTHONThe port needs Python. Minimal required version can be
specified with values such as 2.3+.
Version ranges can also be specified, by separating two version
numbers with a dash, e.g.: 2.1-2.3USE_PYDISTUTILSUse Python distutils for configuring, compiling and
installing. This is required when the port comes with
setup.py. This overrides the
do-build and
do-install targets
and may also override do-configure if
GNU_CONFIGURE is not defined.PYTHON_PKGNAMEPREFIXUsed as a PKGNAMEPREFIX to distinguish
packages for different Python versions.
Example: py24-PYTHON_SITELIBDIRLocation of the site-packages tree, that contains
installation path of Python (usually LOCALBASE).
The PYTHON_SITELIBDIR variable can be very
useful when installing Python modules.PYTHONPREFIX_SITELIBDIRThe PREFIX-clean variant of PYTHON_SITELIBDIR.
Always use
%%PYTHON_SITELIBDIR%% in
pkg-plist when possible. The default value of
%%PYTHON_SITELIBDIR%% is
lib/python%%PYTHON_VERSION%%/site-packagesPYTHON_CMDPython interpreter command line, including version
number.PYNUMERICDependency line for numeric extension.PYXMLDependency line for XML extension (not needed for
Python 2.0 and higher as it is also in base distribution).USE_TWISTEDAdd dependency on twistedCore. The list of required
components can be specified as a value of this
variable. Example: web lore pair
flowUSE_ZOPEAdd dependency on Zope, a web application platform.
Change Python dependency to Python 2.3. Set
ZOPEBASEDIR containing a directory with
Zope installation.
A complete list of available variables can be found in
/usr/ports/Mk/bsd.python.mk.Using EmacsThis section is yet to be written.Using Ruby
Useful variables for ports that use RubyVariableDescriptionUSE_RUBYThe port requires Ruby.USE_RUBY_EXTCONFThe port uses extconf.rb to
configure.USE_RUBY_SETUPThe port uses setup.rb to
configure.RUBY_SETUPSet to the alternative name of
setup.rb. Common value is
install.rb.
The following table shows the selected variables available to port
authors via the ports infrastructure. These variables should be used
to install files into their proper locations. Use them in
pkg-plist as much as possible. These variables
should not be redefined in the port.
Selected read-only variables for ports that use RubyVariableDescriptionExample valueRUBY_PKGNAMEPREFIXUsed as a PKGNAMEPREFIX to distinguish
packages for different Ruby versions.ruby18-RUBY_VERSIONFull version of Ruby in the form of
x.y.z.1.8.2RUBY_SITELIBDIRArchitecture independent libraries installation
path./usr/local/lib/ruby/site_ruby/1.8RUBY_SITEARCHILIBDIRArchitecture dependent libraries installation
path./usr/local/lib/ruby/site_ruby/1.8/amd64-freebsd6RUBY_MODDOCDIRModule documentation installation path./usr/local/share/doc/ruby18/patsyRUBY_MODEXAMPLESDIRModule examples installation path./usr/local/share/examples/ruby18/patsy
A complete list of available variables can be found in
/usr/ports/Mk/bsd.ruby.mk.Using SDLThe USE_SDL variable is used to autoconfigure
the dependencies for ports which use an SDL based library like
devel/sdl12 and
x11-toolkits/sdl_gui.The following SDL libraries are recognized at the moment:sdl: devel/sdl12gfx: graphics/sdl_gfxgui: x11-toolkits/sdl_guiimage: graphics/sdl_imageldbad: devel/sdl_ldbadmixer: audio/sdl_mixermm: devel/sdlmmnet: net/sdl_netsound: audio/sdl_soundttf: graphics/sdl_ttfTherefore, if a port has a dependency on
net/sdl_net and
audio/sdl_mixer,
the syntax will be:USE_SDL= net mixerThe dependency devel/sdl12,
which is required by net/sdl_net and
audio/sdl_mixer, is automatically
added as well.If you use USE_SDL, it will automatically:Add a dependency on sdl12-config to
BUILD_DEPENDSAdd the variable SDL_CONFIG to
CONFIGURE_ENVAdd the dependencies of the selected libraries to the
LIB_DEPENDSTo check whether an SDL library is available, you can do it
with the WANT_SDL variable:WANT_SDL=yes
.include <bsd.port.pre.mk>
.if ${HAVE_SDL:Mmixer}!=""
USE_SDL+= mixer
.endif
.include <bsd.port.post.mk>Starting and stopping services (rc scripts)rc.d scripts are used to start services on system
startup, and to give administrators a standard way of stopping,
starting and restarting the service. Ports integrate into
the system rc.d framework. Details on usage
can be found in
the rc.d Handbook
chapter. Detailed explanation of available commands are in
&man.rc.8; and &man.rc.subr.8;.One or more rc scripts can be installed:USE_RC_SUBR= doorman.shScripts must be placed in the files
subdirectory and a .in suffix must be added to their
filename. The only difference from a base system rc.d script is that the
. /etc/rc.subr line must be replaced with the
. %%RC_SUBR%%, because older versions of &os;
do not have an /etc/rc.subr file. Standard
SUB_LIST expansions are used too.
Use of the %%PREFIX%%,
%%LOCALBASE%%, and
%%X11BASE%% expansions is strongly encouraged as well.
More on
SUB_LIST in the relevant section.Prior to &os; 6.1-RELEASE, integration with &man.rcorder.8; is available by using
USE_RCORDER instead of
USE_RC_SUBR.
However, use of this method is deprecated.As of &os; 6.1-RELEASE, local rc.d
scripts (including those installed by ports) are included in
the overall &man.rcorder.8; of the base system.Example simple rc.d script:#!/bin/sh
# PROVIDE: doorman
# REQUIRE: LOGIN
#
# Add the following lines to /etc/rc.conf.local or /etc/rc.conf to enable doorman:
# doorman_enable (bool): Set to "NO" by default.
# Set it to "YES" to enable doorman
# doorman_config (path): Set to "%%PREFIX%%/etc/doormand/doormand.cf" by default.
#
. %%RC_SUBR%%
name="doorman"
rcvar=`set_rcvar`
load_rc_config $name
: ${doorman_enable="NO"}
: ${doorman_config="%%PREFIX%%/etc/doormand/doormand.cf"}
command=%%PREFIX%%/sbin/doormand
pidfile=/var/run/doormand.pid
command_args="-p $pidfile -f $doorman_config"
run_rc_command "$1"The "=" style of default variable assignment
is preferable to the ":=" style here, since the
former sets a default value only if the variable is unset,
and the latter sets one if the variable is unset
or null.
A user might very well include something like
doorman_flags="" in their
rc.conf.local file, and a variable
substitution using ":=" would inappropriately
override the user's intention.Advanced pkg-plist practicesChanging pkg-plist based on make
variablesSome ports, particularly the p5- ports,
need to change their pkg-plist depending on
what options they are configured with (or version of
perl, in the case of p5-
ports). To make this easy, any instances in the
pkg-plist of %%OSREL%%,
%%PERL_VER%%, and
%%PERL_VERSION%% will be substituted for
appropriately. The value of %%OSREL%% is the
numeric revision of the operating system (e.g.,
4.9). %%PERL_VERSION%% is
the full version number of perl (e.g.,
5.00502) and %%PERL_VER%%
is the perl version number minus
the patchlevel (e.g., 5.005). Several other
%%VARS%% related to
port's documentation files are described in the relevant section.If you need to make other substitutions, you can set the
PLIST_SUB variable with a list of
VAR=VALUE
pairs and instances of
%%VAR%% will be
substituted with VALUE in the
pkg-plist.For instance, if you have a port that installs many files in a
version-specific subdirectory, you can put something likeOCTAVE_VERSION= 2.0.13
PLIST_SUB= OCTAVE_VERSION=${OCTAVE_VERSION}in the Makefile and use
%%OCTAVE_VERSION%% wherever the version shows up
in pkg-plist. That way, when you upgrade the port,
you will not have to change dozens (or in some cases, hundreds) of
lines in the pkg-plist.This substitution (as well as addition of any manual pages) will be done between
the pre-install and
do-install targets, by reading from
PLIST and writing to
TMPPLIST
(default:
WRKDIR/.PLIST.mktmp). So if
your port builds PLIST
on the fly, do so in or
before pre-install. Also, if your port
needs to edit the resulting file, do so in
post-install to a file named
TMPPLIST.Another possibility to modify port's packing list is based
on setting the variables PLIST_FILES and
PLIST_DIRS. The value of each variable
is regarded as a list of pathnames to
write to TMPPLIST
along with PLIST
contents. Names listed in PLIST_FILES
and PLIST_DIRS are subject to
%%VAR%%
substitution, as described above.
Except for that, names from PLIST_FILES
will appear in the final packing list unchanged,
while @dirrm will be
prepended to names from PLIST_DIRS.
To take effect, PLIST_FILES and
PLIST_DIRS must be set before
TMPPLIST is written,
i.e. in pre-install or earlier.Empty directoriesCleaning up empty directoriesDo make your ports remove empty directories when they are
de-installed. This is usually accomplished by adding
@dirrm lines for all directories that are
specifically created by the port. You need to delete subdirectories
before you can delete parent directories. :
lib/X11/oneko/pixmaps/cat.xpm
lib/X11/oneko/sounds/cat.au
:
@dirrm lib/X11/oneko/pixmaps
@dirrm lib/X11/oneko/sounds
@dirrm lib/X11/onekoHowever, sometimes @dirrm will give you
errors because other ports share the same directory. You
can use @dirrmtry to
remove only empty directories without warning.@dirrmtry share/doc/gimpThis will neither print any error messages nor cause
&man.pkg.delete.1; to exit abnormally even if
${PREFIX}/share/doc/gimp is not
empty due to other ports installing some files in there.Creating empty directoriesEmpty directories created during port installation need special
attention. They will not get created when installing the package,
because packages only store the files, and &man.pkg.add.1; creates
directories for them as needed. To make sure the empty directory
is created when installing the package, add this line to
pkg-plist above the corresponding
@dirrm line:@exec mkdir -p %D/share/foo/templatesConfiguration filesIf your port requires some configuration files in
PREFIX/etc, do
not just install them and list them in
pkg-plist. That will cause
&man.pkg.delete.1; to delete files carefully edited by
the user and a new installation to wipe them out.Instead, install sample files with a suffix
(filename.sample
will work well). Copy the sample file as the real configuration
file, if it does not exist. On deinstall, delete the configuration
file, but only if it was not modified by the user. You need to
handle this both in the port Makefile, and in
the pkg-plist (for installation from
the package).Example of the Makefile part:post-install:
@if [ ! -f ${PREFIX}/etc/orbit.conf ]; then \
${CP} -p ${PREFIX}/etc/orbit.conf.sample ${PREFIX}/etc/orbit.conf ; \
fiExample of the pkg-plist part:@unexec if cmp -s %D/etc/orbit.conf.sample %D/etc/orbit.conf; then rm -f %D/etc/orbit.conf; fi
etc/orbit.conf.sample
@exec if [ ! -f %D/etc/orbit.conf ] ; then cp -p %D/%F %B/orbit.conf; fiAlternatively, print out a message pointing out that the
user has to copy and edit the file before the software can be made
to work.Dynamic vs. static package listA static package list is a package list
which is available in the Ports Collection either as a
pkg-plist file (with or without variable
substitution), or embedded into the Makefile
via PLIST_FILES and PLIST_DIRS.
Even if the contents are auto-generated by a tool or a target
in the Makefile before the inclusion into the
Ports Collection by a committer, this is still considered a
static list, since it is possible to examine it without having
to download or compile the distfile.A dynamic package list is a package list
which is generated at the time the port is compiled based upon the
files and directories which are installed. It is not possible to
examine it before the source code of the ported application
is downloaded and compiled, or after running a make
clean.While the use of dynamic package lists is not forbidden,
maintainers should use static package lists wherever possible, as it
enables users to &man.grep.1; through available ports to discover,
for example, which port installs a certain file. Dynamic lists
should be primarily used for
complex ports where the package list changes drastically based upon
optional features of the port (and thus maintaining a static package
list is infeasible), or ports which change the
package list based upon the version of dependent software used (e.g.
ports which generate docs with
Javadoc).Maintainers who prefer dynamic package lists are encouraged to
add a new target to their port which generates the
pkg-plist file so that users may examine
the contents.自動產生 package list首先,先確認您的 port 除了 pkg-plist 尚未搞定之外,其他都完成了。接著, create a temporary directory tree into which your port can be
installed, and install any dependencies.
port-type should be local
for non-X ports and x11-4 or x11
for ports which install into the directory hierarchy of XFree86 4
or an earlier XFree86 release, respectively.&prompt.root; mkdir /var/tmp/port-name
&prompt.root; mtree -U -f /etc/mtree/BSD.port-type.dist -d -e -p /var/tmp/port-name
&prompt.root; make depends PREFIX=/var/tmp/port-nameStore the directory structure in a new file.&prompt.root; (cd /var/tmp/port-name && find -d * -type d) | sort > OLD-DIRSCreate an empty pkg-plist file:&prompt.root; touch pkg-plistIf your port honors PREFIX (which it should)
you can then install the port and create the package list.&prompt.root; make install PREFIX=/var/tmp/port-name
&prompt.root; (cd /var/tmp/port-name && find -d * \! -type d) | sort > pkg-plistYou must also add any newly created directories to the packing
list.&prompt.root; (cd /var/tmp/port-name && find -d * -type d) | sort | comm -13 OLD-DIRS - | sort -r | sed -e 's#^#@dirrm #' >> pkg-plistFinally, you need to tidy up the packing list by hand; it is not
all automated. Manual pages should be listed in
the port's Makefile under
MANn, and not in the
package list. User configuration files should be removed, or
installed as
filename.sample.
The info/dir file should not be listed
and appropriate install-info lines should
be added as noted in the info
files section. Any
libraries installed by the port should be listed as specified in the
shared libraries section.Alternatively, use the plist script in
/usr/ports/Tools/scripts/ to build the
package list automatically. The first step is the same as
above: take the first three lines, that is,
mkdir, mtree and
make depends. Then build and install the
port:&prompt.root; make install PREFIX=/var/tmp/port-nameAnd let plist create the
pkg-plist file:&prompt.root; /usr/ports/Tools/scripts/plist -Md -m /etc/mtree/BSD.port-type.dist /var/tmp/port-name > pkg-plistThe packing list still has to be tidied up by hand as
stated above.The pkg-* filesThere are some tricks we have not mentioned yet about the
pkg-* files
that come in handy sometimes.pkg-messageIf you need to display a message to the installer, you may place
the message in pkg-message. This capability is
often useful to display additional installation steps to be taken
after a &man.pkg.add.1; or to display licensing
information.The pkg-message file does not need to be
added to pkg-plist. Also, it will not get
automatically printed if the user is using the port, not the
package, so you should probably display it from the
post-install target yourself.pkg-installIf your port needs to execute commands when the binary package
is installed with &man.pkg.add.1; you can do this via the
pkg-install script. This script will
automatically be added to the package, and will be run twice by
&man.pkg.add.1;: the first time as
${SH} pkg-install ${PKGNAME}
PRE-INSTALL and the second time as
${SH} pkg-install ${PKGNAME} POST-INSTALL.
$2 can be tested to determine which mode
the script is being run in. The PKG_PREFIX
environmental variable will be set to the package installation
directory. See &man.pkg.add.1; for
additional information.This script is not run automatically if you install the port
with make install. If you are depending on it
being run, you will have to explicitly call it from your port's
Makefile, with a line like
PKG_PREFIX=${PREFIX} ${SH} ${PKGINSTALL}
${PKGNAME} PRE-INSTALL.pkg-deinstallThis script executes when a package is removed.
This script will be run twice by &man.pkg.delete.1;.
The first time as ${SH} pkg-deinstall ${PKGNAME}
DEINSTALL and the second time as
${SH} pkg-deinstall ${PKGNAME} POST-DEINSTALL.
pkg-reqIf your port needs to determine if it should install or not, you
can create a pkg-reqrequirements
script. It will be invoked automatically at
installation/de-installation time to determine whether or not
installation/de-installation should proceed.The script will be run at installation time by
&man.pkg.add.1; as
pkg-req ${PKGNAME} INSTALL.
At de-installation time it will be run by
&man.pkg.delete.1; as
pkg-req ${PKGNAME} DEINSTALL.Changing the names of
pkg-* filesAll the names of pkg-* files
are defined using variables so you can change them in your
Makefile if need be. This is especially useful
when you are sharing the same pkg-* files
among several ports or have to write to one of the above files (see
writing to places other than
WRKDIR for why it is a bad idea to write
directly into the pkg-* subdirectory).Here is a list of variable names and their default
values. (PKGDIR defaults to
${MASTERDIR}.)VariableDefault valueDESCR${PKGDIR}/pkg-descrPLIST${PKGDIR}/pkg-plistPKGINSTALL${PKGDIR}/pkg-installPKGDEINSTALL${PKGDIR}/pkg-deinstallPKGREQ${PKGDIR}/pkg-reqPKGMESSAGE${PKGDIR}/pkg-messagePlease change these variables rather than overriding
PKG_ARGS. If you change
PKG_ARGS, those files will not correctly be
installed in /var/db/pkg upon install from a
port.Making use of SUB_FILES and
SUB_LISTThe SUB_FILES and SUB_LIST
variables are useful for dynamic values in port files, such as the
installation PREFIX in
pkg-message.The SUB_FILES variable specifies a list
of files to be automatically modified. Each
file in the
SUB_FILES list must have a corresponding
file.in present
in FILESDIR. A modified version will
be created in WRKDIR. Files defined as a
value of USE_RC_SUBR (or the deprecated
USE_RCORDER)
are automatically added to the
SUB_FILES. For the files
pkg-message,
pkg-install, pkg-deinstall
and pkg-reg, the corresponding Makefile variable
is automatically set to point to the processed version.The SUB_LIST variable is a list of
VAR=VALUE pairs. For each pair
%%VAR%% will get replaced
with VALUE in each file listed in
SUB_FILES. Several common pairs are
automatically defined: PREFIX,
LOCALBASE, X11BASE,
DATADIR, DOCSDIR,
EXAMPLESDIR. Any line beginning with
@comment will be deleted from resulting files
after a variable substitution.The following example will replace %%ARCH%%
with the system architecture
in a pkg-message:SUB_FILES= pkg-message
SUB_LIST= ARCH=${ARCH}Note that for this example, the
pkg-message.in file must exist in
FILESDIR.Example of a good pkg-message.in:Now it's time to configure this package.
Copy %%PREFIX%%/share/examples/putsy/%%ARCH%%.conf into your home directory
as .putsy.conf and edit it.Testing your portRunning make describeSeveral of the &os; port maintenance tools, such as
&man.portupgrade.1;, rely on a database called
/usr/ports/INDEX which keeps track of such
items as port dependencies. INDEX is created
by the top-level ports/Makefile via
make index, which descends into each
port subdirectory and executes make describe
there. Thus, if make describe fails in any
port, no one can generate INDEX, and many
people will quickly become unhappy.It is important to be able to generate this file no
matter what options are present in make.conf,
so please avoid doing things such as using .error
statements when (for instance) a dependency is not satisfied.
(See .)If make describe produces a string
rather than an error message, you are probably safe. See
bsd.port.mk for the meaning of the
string produced.Also note that running a recent version of
portlint (as specified in the next section)
will cause make describe to be run
automatically.PortlintDo check your work with portlint
before you submit or commit it. portlint
warns you about many common errors, both functional and
stylistic. For a new (or repocopied) port,
portlint -A is the most thorough; for an
existing port, portlint -C is sufficient.Since portlint uses heuristics to
try to figure out errors, it can produce false positive
warnings. In addition, occasionally something that is
flagged as a problem really cannot be done in any other
way due to limitations in the ports framework. When in
doubt, the best thing to do is ask on &a.ports;.PREFIXDo try to make your port install relative to
PREFIX. The value of this variable will be set
to LOCALBASE (default
/usr/local). If
USE_X_PREFIX or USE_IMAKE is
set, PREFIX will be X11BASE (default
/usr/X11R6). If
USE_LINUX_PREFIX is set, PREFIX
will be LINUXBASE (default
/compat/linux).Avoiding the hard-coding of /usr/local or
/usr/X11R6 anywhere in the source will make the
port much more flexible and able to cater to the needs of other
sites. For X ports that use imake, this is
automatic; otherwise, this can often be done by simply replacing the
occurrences of /usr/local (or
/usr/X11R6 for X ports that do not use imake)
in the various scripts/Makefiles in the port to read
${PREFIX}, as this variable is automatically passed
down to every stage of the build and install processes.Make sure your application is not installing things in
/usr/local instead of PREFIX.
A quick test for this is to do this is:&prompt.root; make clean; make package PREFIX=/var/tmp/port-nameIf anything is installed outside of PREFIX,
the package creation process will complain that it
cannot find the files.This does not test for the existence of internal references,
or correct use of LOCALBASE for references to
files from other ports. Testing the installation in
/var/tmp/port-name
to do that while you have it installed would do that.Do not set USE_X_PREFIX unless your port
truly requires it (i.e., it links against X libs or it needs to
reference files in X11BASE).The variable PREFIX can be reassigned in your
Makefile or in the user's environment.
However, it is strongly discouraged for individual ports to set this
variable explicitly in the Makefiles.Also, refer to programs/files from other ports with the
variables mentioned above, not explicit pathnames. For instance, if
your port requires a macro PAGER to be the full
pathname of less, use the compiler flag:
-DPAGER=\"${LOCALBASE}/bin/less\"
instead of
-DPAGER=\"/usr/local/bin/less\". This way it will
have a better chance of working if the system administrator has
moved the whole /usr/local tree somewhere else.UpgradingWhen you notice that a port is out of date compared to the latest
version from the original authors, you should first ensure that you
have the latest
port. You can find them in the
ports/ports-current directory of the &os; FTP mirror
sites. However, if you are working with more than a few
ports, you will probably find it easier to use
CVSup to keep your whole ports collection
up-to-date, as described in the
Handbook.
This will have the added benefit of tracking all the ports'
dependencies.The next step is to see if there is an update already pending.
To do this, you have two options. There is a searchable interface
to the
FreeBSD Problem Report (PR) database (also known as
GNATS). Select ports in the
dropdown, and enter the name of the port.However, sometimes people forget to put the name of the port
into the Synopsis field in an unambiguous fashion. In that case,
you can try the
FreeBSD Ports Monitoring System (also known as
portsmon). This system attempts to classify
port PRs by portname. To search for PRs about a particular port,
use the
Overview of One Port.If there is no pending PR, the next step is to send an email
to the port's maintainer, as shown by
make maintainer. That person may
already be working on an upgrade, or have a reason to not upgrade the
port right now (because of, for example, stability problems of the new
version); you would not want to duplicate their work. Note that
unmaintained ports are listed with a maintainer of
ports@FreeBSD.org, which is just the general
ports mailing list, so sending mail there
probably will not help in this case.If the maintainer asks you to do the upgrade or there is
no maintainer, then you have a chance to help out &os; by
preparing the update yourself! Please make the changes and save
the result of the
recursive diff output
of the new and old
ports directories (e.g., if your modified port directory is
called superedit and the original is in our tree
as superedit.bak, then save the result of
diff -ruN superedit.bak superedit). Either
unified or context diff is fine, but port committers generally
prefer unified diffs. Note the use of the -N
option—this is the accepted way to force diff to properly
deal with the case of new files being added or old files being
deleted. Before sending us the diff, please examine the
output to make sure all the changes make sense. To
simplify common operations with patch files, you can use
/usr/ports/Tools/scripts/patchtool.py.
Before using it, please read
/usr/ports/Tools/scripts/README.patchtool.If the port is unmaintained, and you are actively using
it yourself, please consider volunteering to become its
maintainer. &os; has over 2000 ports without maintainers,
and this is an area where more volunteers are always needed.
(For a detailed description of the responsibilities of maintainers,
refer to the
MAINTAINER on Makefiles section.) The best way to
send us the diff is by including it via &man.send-pr.1; (category
ports). If you are volunteering to maintain the
port,
be sure to put [maintainer update] at the beginning
of your synopsis line and set the Class of your PR
to maintainer-update. Otherwise, the
Class of your PR should be
change-request. Please mention any added or
deleted files in the message, as they have to be explicitly specified
to &man.cvs.1; when doing a commit. If the diff is more than about 20KB,
please compress and uuencode it; otherwise, just include it in the PR
as is.Before you &man.send-pr.1;, you should review the
Writing the problem report section in the Problem
Reports article; it contains far more information about how to write
useful problem reports.If your upgrade is motivated by security concerns or a
serious fault in the currently committed port, please notify
the &a.portmgr; to request immediate rebuilding and
redistribution of your port's package. Unsuspecting users
of &man.pkg.add.1; will otherwise continue to install the
old version via pkg_add -r for several
weeks.Once again, please use &man.diff.1; and not &man.shar.1; to send
updates to existing ports!Now that you have done all that, you will want to read about
how to keep up-to-date in .Ports securityWhy security is so importantBugs are occasionally introduced to the software.
Arguably, the most dangerous of them are those opening
security vulnerabilities. From the technical viewpoint,
such vulnerabilities are to be closed by exterminating
the bugs that caused them. However, the policies for
handling mere bugs and security vulnerabilities are
very different.A typical small bug affects only those users who have
enabled some combination of options triggering the bug.
The developer will eventually release a patch followed
by a new version of the software, free of the bug, but
the majority of users will not take the trouble of upgrading
immediately because the bug has never vexed them. A
critical bug that may cause data loss represents a graver
issue. Nevertheless, prudent users know that a lot of
possible accidents, besides software bugs, are likely to
lead to data loss, and so they make backups of important
data; in addition, a critical bug will be discovered
really soon.A security vulnerability is all different. First,
it may remain unnoticed for years because often it does
not cause software malfunction. Second, a malicious party
can use it to gain unauthorized access to a vulnerable
system, to destroy or alter sensitive data; and in the
worst case the user will not even notice the harm caused.
Third, exposing a vulnerable system often assists attackers
to break into other systems that could not be compromised
otherwise. Therefore closing a vulnerability alone is
not enough: the audience should be notified of it in most
clear and comprehensive manner, which will allow to
evaluate the danger and take appropriate actions.Fixing security vulnerabilitiesWhile on the subject of ports and packages, a security
vulnerability may initially appear in the original
distribution or in the port files. In the former case,
the original software developer is likely to release a
patch or a new version instantly, and you will
only need to update the port promptly with respect to
the author's fix. If the fix is delayed for some reason,
you should either mark the port as
FORBIDDEN
or introduce a patch file of your own to the port. In
the case of a vulnerable port, just fix the port as soon as
possible. In either case, the
standard procedure for submitting your change should
be followed unless you have rights to commit it directly
to the ports tree.Being a ports committer is not enough to commit to
an arbitrary port. Remember that ports usually have
maintainers, whom you should respect.Please make sure that the port's revision is bumped
as soon as the vulnerability has been closed.
That is how the users who upgrade installed packages
on a regular basis will see they need to run an update.
Besides, a new package will be built and distributed
over FTP and WWW mirrors, replacing the vulnerable one.
PORTREVISION should be bumped unless
PORTVERSION has changed in the course
of correcting the vulnerability. That is you should
bump PORTREVISION if you have added a
patch file to the port, but you should not if you have updated
the port to the latest software version and thus already
touched PORTVERSION. Please refer to the
corresponding section
for more information.Keeping the community informedThe VuXML databaseA very important and urgent step to take as early as
a security vulnerability is discovered is to notify the
community of port users about the jeopardy. Such
notification serves two purposes. First, should the danger
be really severe, it will be wise to apply an instant workaround,
e.g., stop the affected network service or even deinstall
the port completely, until the vulnerability is closed.
Second, a lot of users tend to upgrade installed packages
just occasionally. They will know from the notification
that they must update the package
without delay as soon as a corrected version is available.Given the huge number of ports in the tree,
a security advisory cannot be issued on each incident
without creating a flood and losing the attention of
the audience by the time it comes to really serious
matters. Therefore security vulnerabilities found in
ports are recorded in the FreeBSD VuXML
database. The Security Officer Team members
are monitoring it for issues requiring their
intervention.If you have committer rights, you can update the VuXML
database by yourself. So you will both help the Security
Officer Team and deliver the crucial information to the
community earlier. However, if you are not a committer,
or you believe you have found an exceptionally severe
vulnerability, or whatever, please do not hesitate to
contact the Security Officer Team directly as described
on the FreeBSD
Security Information page.All right, you elected the hard way. As it may be obvious
from its title, the VuXML database is essentially an
XML document. Its source file vuln.xml
is kept right inside the port security/vuxml. Therefore
the file's full pathname will be
PORTSDIR/security/vuxml/vuln.xml.
Each time you discover a security vulnerability in a
port, please add an entry for it to that file.
Until you are familiar with VuXML, the best thing you can
do is to find an existing entry fitting your case, then copy
it and use as a template.A short introduction to VuXMLThe full-blown XML is complex and far beyond the scope of
this book. However, to gain basic insight on the structure
of a VuXML entry, you need only the notion of tags. XML
tag names are enclosed in angle brackets. Each opening
<tag> must have a matching closing </tag>.
Tags may be nested. If nesting, the inner tags must be
closed before the outer ones. There is a hierarchy of
tags, i.e. more complex rules of nesting them. Sounds
very similar to HTML, doesn't it? The major difference
is that XML is eXtensible, i.e. based
on defining custom tags. Due to its intrinsic structure,
XML puts otherwise amorphous data into shape. VuXML is
particularly tailored to mark up descriptions of security
vulnerabilities.Now let's consider a realistic VuXML entry:<vuln vid="f4bc80f4-da62-11d8-90ea-0004ac98a7b9">
<topic>Several vulnerabilities found in Foo</topic>
<affects>
<package>
<name>foo</name>
<name>foo-devel</name>
<name>ja-foo</name>
<range><ge>1.6</ge><lt>1.9</lt></range>
<range><ge>2.*</ge><lt>2.4_1</lt></range>
<range><eq>3.0b1</eq></range>
</package>
<package>
<name>openfoo</name>
<range><lt>1.10_7</lt></range>
<range><ge>1.2,1</ge><lt>1.3_1,1</lt></range>
</package>
</affects>
<description>
<body xmlns="http://www.w3.org/1999/xhtml">
<p>J. Random Hacker reports:</p>
<blockquote
cite="http://j.r.hacker.com/advisories/1">
<p>Several issues in the Foo software may be exploited
via carefully crafted QUUX requests. These requests will
permit the injection of Bar code, mumble theft, and the
readability of the Foo administrator account.</p>
</blockquote>
</body>
</description>
<references>
<freebsdsa>SA-10:75.foo</freebsdsa>
<freebsdpr>ports/987654</freebsdpr>
<cvename>CAN-2010-0201</cvename>
<cvename>CAN-2010-0466</cvename>
<bid>96298</bid>
<certsa>CA-2010-99</certsa>
<certvu>740169</certvu>
<uscertsa>SA10-99A</uscertsa>
<uscertta>SA10-99A</uscertta>
<mlist msgid="201075606@hacker.com">http://marc.theaimsgroup.com/?l=bugtraq&m=203886607825605</mlist>
<url>http://j.r.hacker.com/advisories/1</url>
</references>
<dates>
<discovery>2010-05-25</discovery>
<entry>2010-07-13</entry>
<modified>2010-09-17</entry>
</dates>
</vuln>The tag names are supposed to be self-descriptive,
so we shall take a closer look only at fields you will need
to fill in by yourself:This is the top-level tag of a VuXML entry. It has
a mandatory attribute, vid,
specifying a universally unique identifier (UUID) for
this entry (in quotes). You should generate a UUID
for each new VuXML entry (and do not forget to substitute
it for the template UUID unless you are writing the
entry from scratch). You can use &man.uuidgen.1; in
FreeBSD 5.x, or you may install the port devel/p5-Data-UUID and issue
the following command:perl -MData::UUID -le 'print lc new Data::UUID->create_str'This is a one-line description of the issue found.The names of packages affected are listed there.
Multiple names can be given since several packages may be
based on a single master port or software product. This
may include stable and development branches, localized
versions, and slave ports featuring different choices of
important build-time configuration options.It is your responsibility to find all such related
packages when writing a VuXML entry. Keep in mind that
make search name=foo is your friend.
The primary points to look for are as follows:the foo-devel variant
for a foo port;other variants with a suffix like
-a4 (for print-related packages),
-without-gui (for packages with X
support disabled), or similar;jp-, ru-,
zh-, and other possible localized
variants in the corresponding national categories of
the ports collection.Affected versions of the package(s) are specified
there as one or more ranges using a combination of
<lt>, <le>,
<eq>, <ge>,
and <gt> elements. The
version ranges given should not overlap.In a range specification, * (asterisk)
denotes the smallest version number. In particular,
2.* is less than 2.a.
Therefore an asterisk may be used for a range to match all
possible alpha, beta,
and RC versions. For instance,
<ge>2.*</ge><lt>3.*</lt>
will selectively match every 2.x version while
<ge>2.0</ge><lt>3.0</lt>
will obviously not since the latter misses
2.r3 and matches
3.b.The above example
specifies that affected are versions from 1.6
to 1.9 inclusive, versions
2.x before 2.4_1,
and version 3.0b1.Several related package groups (essentially, ports)
can be listed in the <affected>
section. This can be used if several software products
(say FooBar, FreeBar and OpenBar) grow from the same code base
and still share its bugs and vulnerabilities. Note the
difference from listing multiple names within a single
<package> section.The version ranges should allow for
PORTEPOCH and
PORTREVISION if applicable.
Please remember that according to the collation rules,
a version with a non-zero PORTEPOCH is
greater than any version without
PORTEPOCH, e.g., 3.0,1
is greater than 3.1 or even than
8.9.This is a summary of the issue.
XHTML is used in this field. At least enclosing
<p> and </p>
should appear. More complex mark-up may be used, but only for
the sake of accuracy and clarity: No eye candy please.This section contains references to relevant documents.
As many references as apply are encouraged.This is a
FreeBSD
security advisory.This is a
FreeBSD
problem report.This is a Mitre
CVE identifier.This is a
SecurityFocus
Bug ID.This is a
US-CERT
security advisory.This is a
US-CERT
vulnerability note.This is a
US-CERT
Cyber Security Alert.This is a
US-CERT
Technical Cyber Security Alert.This is a URL to an archived posting in a mailing list.
The attribute msgid is optional and
may specify the message ID of the posting.This is a generic URL. It should be used only if none of
the other reference categories apply.This is the date when the issue was disclosed
(YYYY-MM-DD).This is the date when the entry was added
(YYYY-MM-DD).This is the date when any information in the entry
was last modified (YYYY-MM-DD).
New entries must not include this field. It should be added
upon editing an existing entry.Testing your changes to the VuXML databaseAssume you just wrote or filled in an entry for a
vulnerability in the package clamav
that has been fixed in version 0.65_7.As a prerequisite, you need to install fresh versions of the
ports security/portaudit and
security/portaudit-db.First, check whether there already is an entry for this
vulnerability. If there were such entry, it would match the
previous version of the package,
0.65_6:&prompt.user; packaudit
&prompt.user; portaudit clamav-0.65_6To run packaudit, you must have
permission to write to its
DATABASEDIR,
typically /var/db/portaudit.If there is none found, you get the green light to add
a new entry for this vulnerability. Now you can generate
a brand-new UUID (assume it's
74a9541d-5d6c-11d8-80e3-0020ed76ef5a) and
add your new entry to the VuXML database. Please verify
its syntax after that as follows:&prompt.user; cd ${PORTSDIR}/security/vuxml && make validateYou will need at least one of the following packages
installed: textproc/libxml2,
textproc/jade.Now rebuild the portaudit database
from the VuXML file:&prompt.user; packauditTo verify that the <affected>
section of your entry will match correct package(s), issue
the following command:&prompt.user; portaudit -f /usr/ports/INDEX -r 74a9541d-5d6c-11d8-80e3-0020ed76ef5aPlease refer to &man.portaudit.1; for better understanding
of the command syntax.Make sure that your entry produces no spurious matches
in the output.Now check whether the right package versions are matched
by your entry:&prompt.user; portaudit clamav-0.65_6 clamav-0.65_7
Affected package: clamav-0.65_6 (matched by clamav<0.65_7)
Type of problem: clamav remote denial-of-service.
Reference: <http://www.freebsd.org/ports/portaudit/74a9541d-5d6c-11d8-80e3-0020ed76ef5a.html>
1 problem(s) found.Obviously, the former version should match while the
latter one should not.Finally, verify whether the web page generated from the
VuXML database looks like expected:&prompt.user; mkdir -p ~/public_html/portaudit
&prompt.user; packaudit
&prompt.user; lynx ~/public_html/portaudit/74a9541d-5d6c-11d8-80e3-0020ed76ef5a.htmlIf VuXML still scares you...As an easy alternative to writing VuXML, you may opt to add
a single line to a different file with much simpler syntax,
PORTSDIR/security/portaudit-db/database/portaudit.txt,
which resides within the port security/portaudit-db, and
send a request for review to the Security Officer Team
as described on the FreeBSD
Security Information page.A line in that file consists of four fields
separated by |, a pipe character.
The first field is a &man.pkg.version.1; pattern
expression matching the vulnerable packages. The second
field contains URLs to relevant information, separated
by space characters. The third field is a one-line
description of the issue. The fourth and last field
is the entry's UUID.You may want take a closer look at existing entries in
portaudit.txt before adding your
first line to that file.Dos and Don'tsIntroductionHere is a list of common dos and don'ts that you encounter during
the porting process. You should check your own port against this list,
but you can also check ports in the PR database that others have
submitted. Submit any comments on ports you check as described in
Bug Reports and General
Commentary. Checking ports in the PR database will both make
it faster for us to commit them, and prove that you know what you are
doing.Stripping BinariesDo not strip binaries manually unless you have to. All binaries
should be stripped, but the INSTALL_PROGRAM
macro will install and strip a binary at the same time (see the next
section).If you need to strip a file, but do not wish to use the
INSTALL_PROGRAM macro,
${STRIP_CMD} will strip your program. This is
typically done within the post-install
target. For example:post-install:
${STRIP_CMD} ${PREFIX}/bin/xdlUse the &man.file.1; command on the installed executable to
check whether the binary is stripped or not. If it does not say
not stripped, it is stripped. Additionally,
&man.strip.1; will not strip a previously stripped program; it
will instead exit cleanly.INSTALL_* macrosDo use the macros provided in bsd.port.mk
to ensure correct modes and ownership of files in your own
*-install targets.INSTALL_PROGRAM is a command to install
binary executables.INSTALL_SCRIPT is a command to install
executable scripts.INSTALL_DATA is a command to install
sharable data.INSTALL_MAN is a command to install
manpages and other documentation (it does not compress
anything).These are basically the install command with
all the appropriate flags. See below for an example on how to use
them.WRKDIRDo not write anything to files outside
WRKDIR. WRKDIR is the only
place that is guaranteed to be writable during the port build (see
installing ports from a CDROM for an
example of building ports from a read-only tree). If you need to
modify one of the pkg-*
files, do so by redefining a variable, not by
writing over it.WRKDIRPREFIXMake sure your port honors WRKDIRPREFIX.
Most ports do not have to worry about this. In particular, if you
are referring to a WRKDIR of another port, note
that the correct location is
WRKDIRPREFIXPORTSDIR/subdir/name/work not PORTSDIR/subdir/name/work or .CURDIR/../../subdir/name/work or some such.Also, if you are defining WRKDIR yourself,
make sure you prepend
${WRKDIRPREFIX}${.CURDIR} in the
front.Differentiating operating systems and OS versionsYou may come across code that needs modifications or conditional
compilation based upon what version of Unix it is running under. If
you need to make such changes to the code for conditional
compilation, make sure you make the changes as general as possible
so that we can back-port code to older FreeBSD systems and cross-port
to other BSD systems such as 4.4BSD from CSRG, BSD/386, 386BSD,
NetBSD, and OpenBSD.The preferred way to tell 4.3BSD/Reno (1990) and newer versions
of the BSD code apart is by using the BSD macro
defined in
sys/param.h.
Hopefully that
file is already included; if not, add the code:#if (defined(__unix__) || defined(unix)) && !defined(USG)
#include <sys/param.h>
#endifto the proper place in the .c file. We
believe that every system that defines these two symbols has
sys/param.h. If you find a system that
does not, we would like to know. Please send mail to the
&a.ports;.Another way is to use the GNU Autoconf style of doing
this:#ifdef HAVE_SYS_PARAM_H
#include <sys/param.h>
#endifDo not forget to add -DHAVE_SYS_PARAM_H to the
CFLAGS in the Makefile for
this method.Once you have sys/param.h included, you may
use:#if (defined(BSD) && (BSD >= 199103))to detect if the code is being compiled on a 4.3 Net2 code base
or newer (e.g. FreeBSD 1.x, 4.3/Reno, NetBSD 0.9, 386BSD, BSD/386
1.1 and below).Use:#if (defined(BSD) && (BSD >= 199306))to detect if the code is being compiled on a 4.4 code base or
newer (e.g. FreeBSD 2.x, 4.4, NetBSD 1.0, BSD/386 2.0 or
above).The value of the BSD macro is
199506 for the 4.4BSD-Lite2 code base. This is
stated for informational purposes only. It should not be used to
distinguish between versions of FreeBSD based only on 4.4-Lite vs.
versions that have merged in changes from 4.4-Lite2. The
__FreeBSD__ macro should be used instead.Use sparingly:__FreeBSD__ is defined in all versions of
FreeBSD. Use it if the change you are making
only affects FreeBSD. Porting gotchas like
the use of sys_errlist[] vs
strerror() are Berkeley-isms, not FreeBSD
changes.In FreeBSD 2.x, __FreeBSD__ is defined to
be 2. In earlier versions, it is
1. Later versions always bump it to match
their major version number.If you need to tell the difference between a FreeBSD 1.x
system and a FreeBSD 2.x or above system, usually the right answer
is to use the BSD macros described above. If
there actually is a FreeBSD specific change (such as special
shared library options when using ld) then it
is OK to use __FreeBSD__ and #if
__FreeBSD__ > 1 to detect a FreeBSD 2.x and later
system. If you need more granularity in detecting FreeBSD
systems since 2.0-RELEASE you can use the following:#if __FreeBSD__ >= 2
#include <osreldate.h>
# if __FreeBSD_version >= 199504
/* 2.0.5+ release specific code here */
# endif
#endifIn the hundreds of ports that have been done, there have only
been one or two cases where __FreeBSD__ should
have been used. Just because an earlier port screwed up and used it
in the wrong place does not mean you should do so too.FreeBSD 版本速查表(__FreeBSD_version)以下是 sys/param.h 內的 __FreeBSD_version 版本速查表:
__FreeBSD_version valuesRelease__FreeBSD_version2.0-RELEASE1194112.1-CURRENT199501, 1995032.0.5-RELEASE1995042.2-CURRENT before 2.11995082.1.0-RELEASE1995112.2-CURRENT before 2.1.51995122.1.5-RELEASE1996072.2-CURRENT before 2.1.61996082.1.6-RELEASE1996122.1.7-RELEASE1996122.2-RELEASE2200002.2.1-RELEASE220000 (no change)2.2-STABLE after 2.2.1-RELEASE220000 (no change)2.2-STABLE after texinfo-3.92210012.2-STABLE after top2210022.2.2-RELEASE2220002.2-STABLE after 2.2.2-RELEASE2220012.2.5-RELEASE2250002.2-STABLE after 2.2.5-RELEASE2250012.2-STABLE after ldconfig -R merge2250022.2.6-RELEASE2260002.2.7-RELEASE2270002.2-STABLE after 2.2.7-RELEASE2270012.2-STABLE after &man.semctl.2; change2270022.2.8-RELEASE2280002.2-STABLE after 2.2.8-RELEASE2280013.0-CURRENT before &man.mount.2; change3000003.0-CURRENT after &man.mount.2; change3000013.0-CURRENT after &man.semctl.2; change3000023.0-CURRENT after ioctl arg changes3000033.0-CURRENT after ELF conversion3000043.0-RELEASE3000053.0-CURRENT after 3.0-RELEASE3000063.0-STABLE after 3/4 branch3000073.1-RELEASE3100003.1-STABLE after 3.1-RELEASE3100013.1-STABLE after C++ constructor/destructor order
change3100023.2-RELEASE3200003.2-STABLE3200013.2-STABLE after binary-incompatible IPFW and
socket changes3200023.3-RELEASE3300003.3-STABLE3300013.3-STABLE after adding &man.mkstemp.3;
to libc3300023.4-RELEASE3400003.4-STABLE3400013.5-RELEASE3500003.5-STABLE3500014.0-CURRENT after 3.4 branch4000004.0-CURRENT after change in dynamic linker
handling4000014.0-CURRENT after C++ constructor/destructor
order change4000024.0-CURRENT after functioning &man.dladdr.3;4000034.0-CURRENT after __deregister_frame_info dynamic
linker bug fix (also 4.0-CURRENT after EGCS 1.1.2
integration)
4000044.0-CURRENT after &man.suser.9; API change
(also 4.0-CURRENT after newbus)4000054.0-CURRENT after cdevsw registration change4000064.0-CURRENT after the addition of so_cred for
socket level credentials4000074.0-CURRENT after the addition of a poll syscall
wrapper to libc_r4000084.0-CURRENT after the change of the kernel's
dev_t type to struct
specinfo pointer4000094.0-CURRENT after fixing a hole
in &man.jail.2;4000104.0-CURRENT after the sigset_t
datatype change4000114.0-CURRENT after the cutover to the GCC 2.95.2
compiler4000124.0-CURRENT after adding pluggable linux-mode
ioctl handlers4000134.0-CURRENT after importing OpenSSL4000144.0-CURRENT after the C++ ABI change in GCC 2.95.2
from -fvtable-thunks to -fno-vtable-thunks by
default4000154.0-CURRENT after importing OpenSSH4000164.0-RELEASE4000174.0-STABLE after 4.0-RELEASE4000184.0-STABLE after the introduction of delayed
checksums.4000194.0-STABLE after merging libxpg4 code into
libc.4000204.0-STABLE after upgrading Binutils to 2.10.0, ELF
branding changes, and tcsh in the base system.4000214.1-RELEASE4100004.1-STABLE after 4.1-RELEASE4100014.1-STABLE after &man.setproctitle.3; moved from
libutil to libc.4100024.1.1-RELEASE4110004.1.1-STABLE after 4.1.1-RELEASE4110014.2-RELEASE4200004.2-STABLE after combining libgcc.a and
libgcc_r.a, and associated GCC linkage changes.4200014.3-RELEASE4300004.3-STABLE after wint_t introduction.4300014.3-STABLE after PCI powerstate API merge.4300024.4-RELEASE4400004.4-STABLE after d_thread_t introduction.4400014.4-STABLE after mount structure changes (affects
filesystem klds).4400024.4-STABLE after the userland components of smbfs
were imported.4400034.5-RELEASE4500004.5-STABLE after the usb structure element rename.4500014.5-STABLE after the
sendmail_enable &man.rc.conf.5;
variable was made to take the value
NONE.4500044.5-STABLE after moving to XFree86 4 by default
for package builds.4500054.5-STABLE after accept filtering was fixed so
that is no longer susceptible to an easy DoS.4500064.6-RELEASE4600004.6-STABLE &man.sendfile.2; fixed to comply with
documentation, not to count any headers sent against
the amount of data to be sent from the file.4600014.6.2-RELEASE4600024.6-STABLE4601004.6-STABLE after MFC of `sed -i'.4601014.6-STABLE after MFC of many new pkg_install
features from the HEAD.4601024.7-RELEASE4700004.7-STABLE470100Start generated __std{in,out,err}p references rather
than __sF. This changes std{in,out,err} from a
compile time expression to a runtime one.4701014.7-STABLE after MFC of mbuf changes to replace
m_aux mbufs by m_tag's4701024.7-STABLE gets OpenSSL 0.9.74701034.8-RELEASE4800004.8-STABLE4801004.8-STABLE after &man.realpath.3; has been made
thread-safe4801014.8-STABLE 3ware API changes to twe.4801024.9-RELEASE4900004.9-STABLE4901004.9-STABLE after e_sid was added to struct
kinfo_eproc.4901014.9-STABLE after MFC of libmap functionality
for rtld.4901024.10-RELEASE4910004.10-STABLE4911004.10-STABLE after MFC of revision 20040629 of
the package tools4911014.10-STABLE after VM fix dealing with unwiring
of fictitious pages4911024.11-RELEASE4920004.11-STABLE4921005.0-CURRENT5000005.0-CURRENT after adding addition ELF header fields,
and changing our ELF binary branding method.5000015.0-CURRENT after kld metadata changes.5000025.0-CURRENT after buf/bio changes.5000035.0-CURRENT after binutils upgrade.5000045.0-CURRENT after merging libxpg4 code into
libc and after TASKQ interface introduction.5000055.0-CURRENT after the addition of AGP
interfaces.5000065.0-CURRENT after Perl upgrade to 5.6.05000075.0-CURRENT after the update of KAME code to
2000/07 sources.5000085.0-CURRENT after ether_ifattach() and
ether_ifdetach() changes.5000095.0-CURRENT after changing mtree defaults
back to original variant, adding -L to follow
symlinks.5000105.0-CURRENT after kqueue API changed.5000115.0-CURRENT after &man.setproctitle.3; moved from
libutil to libc.5000125.0-CURRENT after the first SMPng commit.5000135.0-CURRENT after <sys/select.h> moved to
<sys/selinfo.h>.5000145.0-CURRENT after combining libgcc.a and
libgcc_r.a, and associated GCC linkage changes.5000155.0-CURRENT after change allowing libc and libc_r
to be linked together, deprecating -pthread
option.5000165.0-CURRENT after switch from struct ucred to
struct xucred to stabilize kernel-exported API for
mountd et al.5000175.0-CURRENT after addition of CPUTYPE make variable
for controlling CPU-specific optimizations.5000185.0-CURRENT after moving machine/ioctl_fd.h to
sys/fdcio.h5000195.0-CURRENT after locale names renaming.5000205.0-CURRENT after Bzip2 import.
Also signifies removal of S/Key.5000215.0-CURRENT after SSE support.5000225.0-CURRENT after KSE Milestone 2.5000235.0-CURRENT after d_thread_t,
and moving UUCP to ports.5000245.0-CURRENT after ABI change for descriptor
and creds passing on 64 bit platforms.5000255.0-CURRENT after moving to XFree86 4 by default for
package builds, and after the new libc strnstr() function
was added.5000265.0-CURRENT after the new libc strcasestr() function
was added.5000275.0-CURRENT after the userland components of smbfs
were imported.5000285.0-CURRENT after the new C99 specific-width
integer types were added.(Not incremented.)5.0-CURRENT after a change was made in the return
value of &man.sendfile.2;.5000295.0-CURRENT after the introduction of the
type fflags_t, which is the
appropriate size for file flags.5000305.0-CURRENT after the usb structure element rename.5000315.0-CURRENT after the introduction of
Perl 5.6.1.5000325.0-CURRENT after the
sendmail_enable &man.rc.conf.5;
variable was made to take the value
NONE.5000335.0-CURRENT after mtx_init() grew a third argument.5000345.0-CURRENT with Gcc 3.1.5000355.0-CURRENT without Perl in /usr/src5000365.0-CURRENT after the addition of &man.dlfunc.3;5000375.0-CURRENT after the types of some struct
sockbuf members were changed and the structure was
reordered.5000385.0-CURRENT after GCC 3.2.1 import.
Also after headers stopped using
_BSD_FOO_T_ and started using _FOO_T_DECLARED.
This value can also be used as a conservative
estimate of the start of &man.bzip2.1; package
support.5000395.0-CURRENT after various changes to disk functions
were made in the name of removing dependency on disklabel
structure internals.5000405.0-CURRENT after the addition of &man.getopt.long.3;
to libc.5000415.0-CURRENT after Binutils 2.13 upgrade, which
included new FreeBSD emulation, vec, and output format.
5000425.0-CURRENT after adding weak pthread_XXX stubs
to libc, obsoleting libXThrStub.so. 5.0-RELEASE.5000435.0-CURRENT after branching for RELENG_5_0500100<sys/dkstat.h> is empty and should
not be included.5001015.0-CURRENT after the d_mmap_t interface
change.5001025.0-CURRENT after taskqueue_swi changed to run
without Giant, and taskqueue_swi_giant added to run
with Giant.500103cdevsw_add() and cdevsw_remove() no
longer exists.
Appearance of MAJOR_AUTO allocation facility.5001045.0-CURRENT after new cdevsw initialization method.500105devstat_add_entry() has been replaced by
devstat_new_entry()500106Devstat interface change; see sys/sys/param.h 1.149500107Token-Ring interface changes.500108Addition of vm_paddr_t.5001095.0-CURRENT after &man.realpath.3; has been made
thread-safe5001105.0-CURRENT after &man.usbhid.3; has been synced with
NetBSD5001115.0-CURRENT after new NSS implementation
and addition of POSIX.1 getpw*_r, getgr*_r
functions5001125.0-CURRENT after removal of the old rc system.5001135.1-RELEASE.5010005.1-CURRENT after branching for RELENG_5_1.5011005.1-CURRENT after correcting the semantics of
sigtimedwait(2) and sigwaitinfo(2).5011015.1-CURRENT after adding the lockfunc and lockfuncarg
fields to &man.bus.dma.tag.create.9;.5011025.1-CURRENT after GCC 3.3.1-pre 20030711 snapshot
integration.5011035.1-CURRENT 3ware API changes to twe.5011045.1-CURRENT dynamically-linked /bin and /sbin
support and movement of libraries to /lib.5011055.1-CURRENT after adding kernel support for
Coda 6.x.5011065.1-CURRENT after 16550 UART constants moved from
<dev/sio/sioreg.h> to
<dev/ic/ns16550.h>.
Also when libmap functionality was unconditionally
supported by rtld.5011075.1-CURRENT after PFIL_HOOKS API update5011085.1-CURRENT after adding kiconv(3)5011095.1-CURRENT after changing default operations
for open and close in cdevsw5011105.1-CURRENT after changed layout of cdevsw501111 5.1-CURRENT after adding kobj multiple inheritance
501112 5.1-CURRENT after the if_xname change in
struct ifnet501113 5.1-CURRENT after changing /bin and /sbin to
be dynamically linked5011145.2-RELEASE5020005.2.1-RELEASE5020105.2-CURRENT after branching for RELENG_5_25021005.2-CURRENT after __cxa_atexit/__cxa_finalize
functions were added to libc.5021015.2-CURRENT after change of default thread library
from libc_r to libpthread.5021025.2-CURRENT after device driver API megapatch.
5021035.2-CURRENT after getopt_long_only() addition.
5021045.2-CURRENT after NULL is made into ((void *)0)
for C, creating more warnings.
5021055.2-CURRENT after pf is linked to the build and
install.
5021065.2-CURRENT after time_t is changed to a
64-bit value on sparc64.
5021075.2-CURRENT after Intel C/C++ compiler support in some headers and execve(2) changes to be more strictly conforming to POSIX.
5021085.2-CURRENT after the introduction of the
bus_alloc_resource_any API
5021095.2-CURRENT after the addition of UTF-8 locales
5021105.2-CURRENT after the removal of the getvfsent(3)
API
5021115.2-CURRENT after the addition of the .warning
directive for make.5021125.2-CURRENT after ttyioctl() was made mandatory
for serial drivers.5021135.2-CURRENT after import of the ALTQ framework.
5021145.2-CURRENT after changing sema_timedwait(9) to
return 0 on success and a non-zero error code on
failure.
5021155.2-CURRENT after changing kernel dev_t to
be pointer to struct cdev *.
5021165.2-CURRENT after changing kernel udev_t to dev_t.
5021175.2-CURRENT after adding support for CLOCK_VIRTUAL
and CLOCK_PROF to clock_gettime(2) and clock_getres(2).
5021185.2-CURRENT after changing network interface
cloning overhaul.
5021195.2-CURRENT after the update of the package tools
to revision 20040629.
5021205.2-CURRENT after marking Bluetooth code as
non-i386 specific.
5021215.2-CURRENT after the introduction of the KDB
debugger framework, the conversion of DDB into a
backend and the introduction of the GDB backend.
5021225.2-CURRENT after change to make
VFS_ROOT take a struct
thread argument as does vflush. Struct kinfo_proc
now has a user data pointer.
The switch of the default X implementation to
xorg was also made at this time.
5021235.2-CURRENT after the change to separate the way
ports rc.d and legacy scripts are started.
5021245.2-CURRENT after the backout of the
previous change.
5021255.2-CURRENT after the removal of
kmem_alloc_pageable() and the import of gcc 3.4.2.
5021265.2-CURRENT after changing the UMA kernel
API to allow ctors/inits to fail.
5021275.2-CURRENT after the change of the
vfs_mount signature as well as global replacement of
PRISON_ROOT with SUSER_ALLOWJAIL for the suser(9)
API.
5021285.3-BETA/RC before the pfil API change5030005.3-RELEASE5030015.3-STABLE after branching for RELENG_5_35031005.3-STABLE after addition of glibc style
&man.strftime.3; padding options.5031015.3-STABLE after OpenBSD's nc(1) import MFC.5031025.4-PRERELEASE after the MFC of the fixes in
<src/include/stdbool.h> and
<src/sys/i386/include/_types.h>
for using the GCC-compatibility of the Intel C/C++ compiler.5031035.4-PRERELEASE after the MFC of the change of
ifi_epoch from wall clock time to uptime.5031045.4-PRERELEASE after the MFC of the fix of EOVERFLOW check in vswprintf(3).5031055.4-RELEASE.5040005.4-STABLE after branching for RELENG_5_45041005.4-STABLE after increasing the default
thread stacksizes5041015.4-STABLE after the addition of sha2565041025.4-STABLE after the MFC of if_bridge5041035.4-STABLE after the MFC of bsdiff and portsnap5041045.4-STABLE after MFC of ldconfig_local_dirs
change.5041056.0-CURRENT6000006.0-CURRENT after permanently enabling PFIL_HOOKS
in the kernel.
6000016.0-CURRENT after initial addition of
ifi_epoch to struct if_data. Backed out after a
few days. Do not use this value.
6000026.0-CURRENT after the re-addition of the
ifi_epoch member of struct if_data.
6000036.0-CURRENT after addition of the struct inpcb
argument to the pfil API.
6000046.0-CURRENT after addition of the "-d
DESTDIR" argument to newsyslog.
6000056.0-CURRENT after addition of glibc style
&man.strftime.3; padding options.
6000066.0-CURRENT after addition of 802.11 framework
updates.
6000076.0-CURRENT after changes to VOP_*VOBJECT() functions
and introduction of MNTK_MPSAFE flag for Giantfree filesystems.
6000086.0-CURRENT after addition of the cpufreq framework
and drivers.
6000096.0-CURRENT after importing OpenBSD's nc(1).6000106.0-CURRENT after removing semblance of SVID2
matherr() support.6000116.0-CURRENT after increase of default thread stacks'
size.6000126.0-CURRENT after fixes in
<src/include/stdbool.h> and
<src/sys/i386/include/_types.h>
for using the GCC-compatibility of the Intel C/C++ compiler.6000136.0-CURRENT after EOVERFLOW checks in vswprintf(3) fixed.6000146.0-CURRENT after changing the struct if_data
member, ifi_epoch, from wall clock time to uptime.6000156.0-CURRENT after LC_CTYPE disk format changed.6000166.0-CURRENT after NLS catalogs disk format changed.6000176.0-CURRENT after LC_COLLATE disk format changed.600018Installation of acpica includes into /usr/include.600019Addition of MSG_NOSIGNAL flag to send(2) API.600020Addition of fields to cdevsw600021Removed gtar from base system.600022LOCAL_CREDS, LOCAL_CONNWAIT socket options added to unix(4).600023&man.hwpmc.4; and related tools added to 6.0-CURRENT.600024struct icmphdr added to 6.0-CURRENT.600025pf updated to 3.7.600026Kernel libalias and ng_nat introduced.600027POSIX ttyname_r(3) made available through unistd.h and libc.6000286.0-CURRENT after libpcap updated to v0.9.1 alpha 096.6000296.0-CURRENT after importing NetBSD's if_bridge(4).6000306.0-CURRENT after struct ifnet was broken out
of the driver softcs.6000316.0-CURRENT after the import of libpcap v0.9.1.6000326.0-STABLE after bump of all shared library
versions that had not been changed since
RELENG_5.6000336.0-STABLE after credential argument is added to
dev_clone vent handler. 6.0-RELEASE.6000346.0-STABLE after 6.0-RELEASE6001006.0-STABLE after incorporating scripts from the
local_startup directories into the base &man.rcorder.8;.6001016.0-STABLE after updating the ELF types and
constants.6001026.0-STABLE after MFC of pidfile(3) API.6001036.0-STABLE after MFC of ldconfig_local_dirs
change.6001047.0-CURRENT.7000007.0-CURRENT after bump of all shared library
versions that had not been changed since
RELENG_5.7000017.0-CURRENT after credential argument is added to
dev_clone vent handler.7000027.0-CURRENT after memmem(3) is added to libc.7000037.0-CURRENT after solisten(9) kernel arguments
are modified to accept a backlog paramater.7000047.0-CURRENT after IFP2ENADDR() was changed to return
a pointer to IF_LLADDR().7000057.0-CURRENT after addition of if_addr
member to struct ifnet and IFP2ENADDR()
removal.7000067.0-CURRENT after incorporating scripts from the
local_startup directories into the base &man.rcorder.8;.7000077.0-CURRENT after removal of MNT_NODEV mount
option.7000087.0-CURRENT after ELF-64 type changes and symbol
versioning.7000097.0-CURRENT after addition of hostb and vgapci
drivers, addition of pci_find_extcap(), and changing
the AGP drivers to no longer map the aperture.7000107-0.CURRENT after tv_sec was made time_t on
all platforms but Alpha.7000117-0.CURRENT after ldconfig_local_dirs change.7000127-0.CURRENT after changes to
/etc/rc.d/abi to support
/compat/linux/etc/ld.so.cache
being a symlink in a readonly filesystem.7000137-0.CURRENT after pts import.700014
Note that 2.2-STABLE sometimes identifies itself as
2.2.5-STABLE after the 2.2.5-RELEASE. The pattern
used to be year followed by the month, but we decided to change it
to a more straightforward major/minor system starting from 2.2.
This is because the parallel development on several branches made
it infeasible to classify the releases simply by their real
release dates. If you are making a port now, you do not have to
worry about old -CURRENTs; they are listed here just for your
reference.Writing something after
bsd.port.mkDo not write anything after the .include
<bsd.port.mk> line. It usually can be avoided by
including bsd.port.pre.mk somewhere in the
middle of your Makefile and
bsd.port.post.mk at the end.You need to include either the
bsd.port.pre.mk/bsd.port.post.mk pair or
bsd.port.mk only; do not mix these two usages.bsd.port.pre.mk only defines a few
variables, which can be used in tests in the
Makefile, bsd.port.post.mk
defines the rest.Here are some important variables defined in
bsd.port.pre.mk (this is not the complete list,
please read bsd.port.mk for the complete
list).VariableDescriptionARCHThe architecture as returned by uname
-m (e.g., i386)OPSYSThe operating system type, as returned by
uname -s (e.g.,
FreeBSD)OSRELThe release version of the operating system (e.g.,
2.1.5 or
2.2.7)OSVERSIONThe numeric version of the operating system; the same as
__FreeBSD_version.PORTOBJFORMATThe object format of the system
(elf or aout;
note that for modern versions of FreeBSD,
aout is deprecated.)LOCALBASEThe base of the local tree (e.g.,
/usr/local/)X11BASEThe base of the X11 tree (e.g.,
/usr/X11R6)PREFIXWhere the port installs itself (see more on
PREFIX).If you have to define the variables
USE_IMAKE, USE_X_PREFIX, or
MASTERDIR, do so before including
bsd.port.pre.mk.Here are some examples of things you can write after
bsd.port.pre.mk:# no need to compile lang/perl5 if perl5 is already in system
.if ${OSVERSION} > 300003
BROKEN= perl is in system
.endif
# only one shlib version number for ELF
.if ${PORTOBJFORMAT} == "elf"
TCL_LIB_FILE= ${TCL_LIB}.${SHLIB_MAJOR}
.else
TCL_LIB_FILE= ${TCL_LIB}.${SHLIB_MAJOR}.${SHLIB_MINOR}
.endif
# software already makes link for ELF, but not for a.out
post-install:
.if ${PORTOBJFORMAT} == "aout"
${LN} -sf liblinpack.so.1.0 ${PREFIX}/lib/liblinpack.so
.endifYou did remember to use tab instead of spaces after
BROKEN= and
TCL_LIB_FILE=, did you not?
:-).Install additional documentationIf your software has some documentation other than the standard
man and info pages that you think is useful for the user, install it
under PREFIX/share/doc.
This can be done, like the previous item, in the
post-install target.Create a new directory for your port. The directory name should
reflect what the port is. This usually means
PORTNAME. However, if you
think the user might want different versions of the port to be
installed at the same time, you can use the whole
PKGNAME.Make the installation dependent on the variable
NOPORTDOCS so that users can disable it in
/etc/make.conf, like this:post-install:
.if !defined(NOPORTDOCS)
${MKDIR} ${DOCSDIR}
${INSTALL_MAN} ${WRKSRC}/docs/xvdocs.ps ${DOCSDIR}
.endifHere are some handy variables and how they are expanded
by default when used
in the Makefile:DATADIR gets expanded to
PREFIX/share/PORTNAME.DOCSDIR gets expanded to
PREFIX/share/doc/PORTNAME.EXAMPLESDIR gets expanded to
PREFIX/share/examples/PORTNAME.These variables are exported to PLIST_SUB.
Their values will appear there as pathnames relative to
PREFIX if possible.
That is, share/doc/PORTNAME
will be substituted for %%DOCSDIR%%
in the packing list by default, and so on.
(See more on pkg-plist substitution
here.)All documentation files and directories installed should
be included in pkg-plist with the
%%PORTDOCS%% prefix, for example:%%PORTDOCS%%%%DOCSDIR%%/AUTHORS
%%PORTDOCS%%%%DOCSDIR%%/CONTACT
%%PORTDOCS%%@dirrm %%DOCSDIR%%As an alternative to enumerating the documentation files
in pkg-plist, a port can set the variable
PORTDOCS to a list of file names and shell
glob patterns to add to the final packing list.
The names will be relative to DOCSDIR.
Therefore, a port that utilizes PORTDOCS and
uses a non-default location for its documentation should set
DOCSDIR accordingly.
If a directory is listed in PORTDOCS
or matched by a glob pattern from this variable,
the entire subtree of contained files and directories will be
registered in the final packing list. If NOPORTDOCS
is defined then files and directories listed in
PORTDOCS would not be installed and neither
would be added to port packing list.
Installing the documentation at PORTDOCS
as shown above remains up to the port itself.
A typical example of utilizing PORTDOCS
looks as follows:PORTDOCS= README.* ChangeLog docs/*You can also use the pkg-message file to
display messages upon installation. See the section on using
pkg-message for details.
The pkg-message file does not need to be
added to pkg-plist.SubdirectoriesTry to let the port put things in the right subdirectories of
PREFIX. Some ports lump everything and put it in
the subdirectory with the port's name, which is incorrect. Also,
many ports put everything except binaries, header files and manual
pages in the a subdirectory of lib, which does
not work well with the BSD paradigm. Many of the files should be
moved to one of the following: etc
(setup/configuration files), libexec
(executables started internally), sbin
(executables for superusers/managers), info
(documentation for info browser) or share
(architecture independent files). See &man.hier.7; for details;
the rules governing
/usr pretty much apply to
/usr/local too. The exception are ports
dealing with USENET news. They may use
PREFIX/news as a destination
for their files.UIDs and GIDsIf your port requires a certain user to be on the installed
system, let the pkg-install script call
pw to create it automatically. Look at
net/cvsup-mirror for an example.If your port must use the same user/group ID number when it is
installed as a binary package as when it was compiled, then you must
choose a free UID from 50 to 999 and register it below. Look at
japanese/Wnn6 for an example.Make sure you do not use a UID already used by the system or
other ports.This is the current list of UIDs between 50 and 999.bind:*:53:53:Bind Sandbox:/:/sbin/nologin
majordom:*:54:54:Majordomo Pseudo User:/usr/local/majordomo:/nonexistent
rdfdb:*:55:55:rdfDB Daemon:/var/db/rdfdb:/bin/sh
spamd:*:58:58:SpamAssassin user:/var/spool/spamd:/sbin/nologin
cyrus:*:60:60:the cyrus mail server:/nonexistent:/nonexistent
gnats:*:61:1:GNATS database owner:/usr/local/share/gnats/gnats-db:/bin/sh
proxy:*:62:62:Packet Filter pseudo-user:/nonexistent:/nonexistent
uucp:*:66:66:UUCP pseudo-user:/var/spool/uucppublic:/usr/libexec/uucp/uucico
xten:*:67:67:X-10 daemon:/usr/local/xten:/nonexistent
pop:*:68:6:Post Office Owner (popper):/nonexistent:/sbin/nologin
wnn:*:69:7:Wnn:/nonexistent:/nonexistent
pgsql:*:70:70:PostgreSQL pseudo-user:/usr/local/pgsql:/bin/sh
oracle:*:71:71::0:0:Oracle:/usr/local/oracle7:/sbin/nologin
ircd:*:72:72:IRC daemon:/nonexistent:/nonexistent
ircservices:*:73:73:IRC services:/nonexistent:/nonexistent
simscan:*:74:74:Simscan User:/nonexistent:/sbin/nologin
ifmail:*:75:66:Ifmail user:/nonexistent:/nonexistent
www:*:80:80:World Wide Web Owner:/nonexistent:/sbin/nologin
alias:*:81:81:QMail user:/var/qmail/alias:/nonexistent
qmaild:*:82:81:QMail user:/var/qmail:/nonexistent
qmaill:*:83:81:QMail user:/var/qmail:/nonexistent
qmailp:*:84:81:QMail user:/var/qmail:/nonexistent
qmailq:*:85:82:QMail user:/var/qmail:/nonexistent
qmailr:*:86:82:QMail user:/var/qmail:/nonexistent
qmails:*:87:82:QMail user:/var/qmail:/nonexistent
mysql:*:88:88:MySQL Daemon:/var/db/mysql:/sbin/nologin
vpopmail:*:89:89:VPop Mail User:/usr/local/vpopmail:/nonexistent
firebird:*:90:90:Firebird Database Administrator:/usr/local/firebird:/bin/sh
mailman:*:91:91:Mailman User:/usr/local/mailman:/sbin/nologin
gdm:*:92:92:GDM Sandbox:/:/sbin/nologin
jabber:*:93:93:Jabber Daemon:/nonexistent:/nonexistent
p4admin:*:94:94:Perforce admin:/usr/local/perforce:/sbin/nologin
interch:*:95:95:Interchange user:/usr/local/interchange:/sbin/nologin
squeuer:*:96:96:SQueuer Owner:/nonexistent:/bin/sh
mud:*:97:97:MUD Owner:/nonexistent:/bin/sh
msql:*:98:98:mSQL-2 pseudo-user:/var/db/msqldb:/bin/sh
rscsi:*:99:99:Remote SCSI:/usr/local/rscsi:/usr/local/sbin/rscsi
squid:*:100:100:squid caching-proxy pseudo user:/usr/local/squid:/sbin/nologin
quagga:*:101:101:Quagga route daemon pseudo user:/usr/local/etc/quagga:/sbin/nologin
ganglia:*:102:102:Ganglia User:/nonexistent:/sbin/nologin
sgeadmin:*:103:103:Sun Grid Engine Admin:/nonexistent:/sbin/nologin
slimserv:*:104:104:Slim Devices SlimServer pseudo-user:/nonexistent:/sbin/nologin
dnetc:*:105:105:distributed.net client and proxy pseudo-user:/nonexistent:/sbin/nologin
clamav:*:106:106:Clamav Antivirus:/nonexistent:/sbin/nologin
cacti:*:107:107:Cacti Sandbox:/nonexistent:/sbin/nologin
webkit:*:108:108:WebKit Default User:/usr/local/www/webkit:/bin/sh
quickml:*:109:109:quickml Server:/nonexistent:/sbin/nologin
vscan:*:110:110:Scanning Virus Account:/var/amavis:/bin/sh
fido:*:111:111:Fido System:/usr/local/fido:/bin/sh
dcc:*:112:112:Distributed Checksum Clearinghouse:/nonexistent:/sbin/nologin
amavis:*:113:113:Amavis-stats Account:/nonexistent:/sbin/nologin
dhis:*:114:114:DHIS Daemon:/nonexistent:/sbin/nologin
_symon:*:115:115:Symon Account:/var/empty:/sbin/nologin
postfix:*:125:125:Postfix Mail System:/var/spool/postfix:/sbin/nologin
rbldns:*:153:153:rbldnsd pseudo-user:/nonexistent:/sbin/nologin
sfs:*:171:171:Self-Certifying File System:/nonexistent:/sbin/nologin
agk:*:172:172:AquaGateKeeper:/nonexistent:/nonexistent
polipo:*:173:173:polipo web cache:/nonexistent:/sbin/nologin
bogomilter:*:174:174:milter-bogom:/nonexistent:/sbin/nologin
moinmoin:*:192:192:MoinMoin User:/nonexistent:/sbin/nologin
sympa:*:200:200:Sympa Owner:/nonexistent:/sbin/nologin
privoxy:*:201:201:Privoxy proxy user:/nonexistent:/sbin/nologin
dspam:*:202:202:Dspam:/nonexistent:/sbin/nologin
shoutcast:*:210:210:Shoutcast sandbox:/nonexistent:/bin/sh
_tor:*:256:256:Tor anonymising router:/var/db/tor:/bin/sh
smxs:*:260:260:Sendmail X SMTPS:/nonexistent:/sbin/nologin
smxq:*:261:261:Sendmail X QMGR:/nonexistent:/sbin/nologin
smxc:*:262:262:Sendmail X SMTPC:/nonexistent:/sbin/nologin
smxm:*:263:263:Sendmail X misc:/nonexistent:/sbin/nologin
smx:*:264:264:Sendmail X other:/nonexistent:/sbin/nologin
ldap:*:389:389:OpenLDAP Server:/nonexistent:/sbin/nologin
drweb:*:426:426:Dr.Web Mail Scanner:/nonexistent:/sbin/nologin
courier:*:465:465:Courier Mail Server:/nonexistent:/sbin/nologin
_bbstored:*:505:505::0:0:BoxBackup Store Daemon:/nonexistent:/bin/sh
qtss:*:554:554:Darwin Streaming Server:/nonexistent:/sbin/nologin
ircdru:*:555:555:Russian hybrid IRC server:/nonexistent:/bin/sh
messagebus:*:556:556:D-BUS Daemon User:/nonexistent:/sbin/nologin
avahi:*:558:558:Avahi Daemon User:/nonexistent:/sbin/nologin
bnetd:*:700:700:Bnetd user:/nonexistent:/sbin/nologin
bopm:*:717:717:Blitzed Open Proxy Monitor:/nonexistent:/bin/sh
bacula:*:910:910:Bacula Daemon:/var/db/bacula:/sbin/nologinThis is the current list of reserved GIDs.bind:*:53:
rdfdb:*:55:
spamd:*:58:
cyrus:*:60:
proxy:*:62:
authpf:*:63:
uucp:*:66:
xten:*:67:
dialer:*:68:
network:*:69:
pgsql:*:70:
simscan:*:74:
www:*:80:
qnofiles:*:81:
qmail:*:82:
mysql:*:88:
vpopmail:*:89:
firebird:*:90:
mailman:*:91:
gdm:*:92:
jabber:*:93:
p4admin:*:94:
interch:*:95:
squeuer:*:96:
mud:*:97:
msql:*:98:
rscsi:*:99:
squid:*:100:
quagga:*:101:
ganglia:*:102:
sgeadmin:*:103:
slimserv:*:104:
dnetc:*:105:
clamav:*:106:
cacti:*:107:
webkit:*:108:
quickml:*:109:
vscan:*:110:
fido:*:111:
dcc:*:112:
amavis:*:113:
dhis:*:114:
_symon:*:115:
postfix:*:125:
maildrop:*:126:
rbldns:*:153:
sfs:*:171:
agk:*:172:
polipo:*:173:
moinmoin:*:192:
sympa:*:200:
dspam:*:202:
_tor:*:256:
smxs:*:260:
smxq:*:261:
smxc:*:262:
smxm:*:263:
smx:*:264:
ldap:*:389:
drweb:*:426:
courier:*:465:
_bbstored:*:505:
qtss:*:554:
ircdru:*:555:
messagebus:*:556:
realtime:*:557:
avahi:*:558:
bnetd:*:700:
bopm:*:717:
bacula:*:910:Please include a notice when you submit a port (or an upgrade)
that reserves a new UID or GID in this range. This allows us to
keep the list of reserved IDs up to date.Do things rationallyThe Makefile should do things simply and
reasonably. If you can make it a couple of lines shorter or more
readable, then do so. Examples include using a make
.if construct instead of a shell
if construct, not redefining
do-extract if you can redefine
EXTRACT* instead, and using
GNU_CONFIGURE instead of CONFIGURE_ARGS
+= --prefix=${PREFIX}.If you find yourself having to write a lot
of new code to try to do something, please go back and review
bsd.port.mk to see if it contains an
existing implementation of what you are trying to do. While
hard to read, there are a great many seemingly-hard problems for
which bsd.port.mk already provides a
shorthand solution.Respect both CC and
CXXThe port should respect both CC
and CXX variables. What we mean by this
is that the port should not set the values of these variables
absolutely, overriding existing values; instead, it should append
whatever values it needs to the existing values. This is so that
build options that affect all ports can be set globally.If the port does not respect these variables,
please add NO_PACKAGE=ignores either cc or
cxx to the Makefile.An example of a Makefile respecting
both CC and CXX
variables follows. Note the ?=:CC?= gccCXX?= g++Here is an example which respects neither
CC nor CXX
variables:CC= gccCXX= g++Both CC and CXX
variables can be defined on FreeBSD systems in
/etc/make.conf. The first example
defines a value if it was not previously set in
/etc/make.conf, preserving any
system-wide definitions. The second example clobbers
anything previously defined.Respect CFLAGSThe port should respect the CFLAGS variable.
What we mean by this is that the port should not set the value of
this variable absolutely, overriding the existing value; instead,
it should append whatever values it needs to the existing value.
This is so that build options that affect all ports can be set
globally.If it does not, please add NO_PACKAGE=ignores
cflags to the Makefile.An example of a Makefile respecting
the CFLAGS variable follows. Note the
+=:CFLAGS+= -Wall -WerrorHere is an example which does not respect the
CFLAGS variable:CFLAGS= -Wall -WerrorThe CFLAGS variable is defined on
FreeBSD systems in /etc/make.conf. The
first example appends additional flags to the
CFLAGS variable, preserving any system-wide
definitions. The second example clobbers anything previously
defined.You should remove optimization flags from the third party
Makefiles. System CFLAGS
contains system-wide optimization flags. An example from
an unmodified Makefile:CFLAGS= -O3 -funroll-loops -DHAVE_SOUNDUsing system optimization flags, the
Makefile would look similar to the
following example:CFLAGS+= -DHAVE_SOUNDThreading librariesThe threading library must be linked to the binaries
using a special linker flag -pthread on
&os;. If a port insists on linking
-lpthread or -lc_r
directly, patch it to use PTHREAD_LIBS
variable provided by the ports framework. This variable
usually has the value of -pthread, but
on certain architectures and &os; versions it can have
different values, so do not just hardcode
-pthread into patches and always use
PTHREAD_LIBS.FeedbackDo send applicable changes/patches to the original
author/maintainer for inclusion in next release of the code. This
will only make your job that much easier for the next
release.README.htmlDo not include the README.html file. This
file is not part of the cvs collection but is generated using the
make readme command.
Marking a port not installable with BROKEN,
FORBIDDEN, or IGNOREIn certain cases users should be prevented from installing
a port. To tell a user that
a port should not be installed, there are several
make variables that can be used in a port's
Makefile. The value of the following
make variables will be the reason that is
given back to users for why the port refuses to install itself.
Please use the correct make variable as
each make variable conveys radically different meanings to
both users, and to automated systems that depend on the
Makefiles, such as
the ports build cluster,
FreshPorts, and
portsmon.VariablesBROKEN is reserved for ports that
currently do not compile, install, or deinstall correctly.
It should be used for ports where the the problem is
believed to be temporary.
The build cluster will still attempt to try to build
them to see if the underlying problem has been
resolved. For instance, use
BROKEN when a port:does not compilefails its configuration or installation processinstalls files outside of
${LOCALBASE} and
${X11BASE}does not remove all its files cleanly upon
deinstall (however, it may be acceptable, and desirable,
for the port to leave user-modified files behind)FORBIDDEN is used for ports that
do contain a security vulnerability or induce grave
concern regarding the security of a FreeBSD system with
a given port installed (ex: a reputably insecure program
or a program that provides easily exploitable services).
Ports should be marked as FORBIDDEN
as soon as a particular piece of software has a
vulnerability and there is no released upgrade. Ideally
ports should be upgraded as soon as possible when a
security vulnerability is discovered so as to reduce the
number of vulnerable FreeBSD hosts (we like being known
for being secure), however sometimes there is a
noticeable time gap between disclosure of a
vulnerability and an updated release of the
vulnerable software. Do not mark a port
FORBIDDEN for any reason other than
security.IGNORE is reserved for ports that
should not be built for some other reason.
It should be used for ports where the the problem is
believed to be structural.
The build
cluster will not, under any
circumstances, build ports marked as
IGNORE. For instance, use
IGNORE when a port:compiles but does not run properlydoes not work on the installed version of &os;requires &os; kernel sources to build, but the
user does not have them installedhas a distfile which may not be automatically
fetched due to licensing restrictionsdoes not work with some other currently installed
port (for instance, the port depends on
www/apache21 but
www/apache13
is installed)If a port would conflict with a currently installed
port (for example, if they install a file in the same
place that perfoms a different function),
use
CONFLICTS instead.
CONFLICTS will set
IGNORE by itself.If a port sould be marked IGNORE
only on certain architectures, there are two other
convenience variables that will automatically set
IGNORE for you:
ONLY_FOR_ARCHS and
NOT_FOR_ARCHS. Examples:ONLY_FOR_ARCHS= i386 amd64NOT_FOR_ARCHS= alpha ia64 sparc64Implementation NotesThe strings should not be quoted.
Also, the wording of the string should be somewhat
different due to the way the information is shown to the
user. Examples:BROKEN= this port is unsupported on FreeBSD 5.xIGNORE= is unsupported on FreeBSD 5.xresulting in the following output from
make describe:===> foobar-0.1 is marked as broken: this port is unsupported on FreeBSD 5.x.===> foobar-0.1 is unsupported on FreeBSD 5.x.Marking a port for removal with DEPRECATED
or EXPIRATION_DATEDo remember that BROKEN and
FORBIDDEN are to be used as a
temporary resort if a port is not working. Permanently
broken ports should be removed from the tree
entirely.When it makes sense to do so, users can be warned about
a pending port removal with DEPRECATED
and EXPIRATION_DATE. The former is
simply a string stating why the port is scheduled for removal;
the latter is a string in ISO 8601 format (YYYY-MM-DD). Both
will be shown to the user.It is possible to set DEPRECATED
without an EXPIRATION_DATE (for
instance, recommending a newer version of the port), but
the converse does not make any sense.There is no set policy on how much notice to give.
Current practice seems to be one month for security-related
issues and two months for build issues. This also gives any
interested committers a little time to fix the problems.Avoid use of the .error constructThe correct way for a Makefile to
signal that the port can not be installed due to some external
factor (for instance, the user has specified an illegal
combination of build options) is to set a nonblank value to
IGNORE. This value will be formatted and
shown to the user by make install.It is a common mistake to use .error
for this purpose. The problem with this is that many
automated tools that work with the ports tree will fail in
this situation. The most common occurence of this is seen
when trying to build /usr/ports/INDEX
(see ). However, even more
trivial commands such as make -V maintainer
also fail in this scenario. This is not acceptable.How to avoid using .errorAssume that someone has the line
USE_POINTYHAT=yes
in make.conf. The first of
the next two Makefile snippets will
cause make index to fail, while the
second one will not:.if USE_POINTYHAT
.error "POINTYHAT is not supported"
.endif.if USE_POINTYHAT
IGNORE=POINTYHAT is not supported
.endifNecessary workaroundsSometimes it is necessary to work around bugs in
software included with older versions of &os;.Some versions of &man.make.1; were broken
on at least 4.8 and 5.0 with respect to handling
comparisons based on OSVERSION.
This would often lead to failures during
make describe (and thus, the overall
ports make index). The workaround is
to enclose the conditional comparison in spaces, e.g.:
if ( ${OSVERSION} > 500023 )
Be aware that test-installing a port on 4.9 or 5.2
will not detect this problem.MiscellaneaThe files
pkg-descr and pkg-plist
should each be double-checked. If you are reviewing a port and feel
they can be worded better, do so.Do not copy more copies of the GNU General Public License into
our system, please.Please be careful to note any legal issues! Do not let us
illegally distribute software!A Sample MakefileHere is a sample Makefile that you can use to
create a new port. Make sure you remove all the extra comments (ones
between brackets)!It is recommended that you follow this format (ordering of
variables, empty lines between sections, etc.). This format is
designed so that the most important information is easy to locate. We
recommend that you use portlint to check the
Makefile.[the header...just to make it easier for us to identify the ports.]
# New ports collection makefile for: xdvi
[the "version required" line is only needed when the PORTVERSION
variable is not specific enough to describe the port.]
# Date created: 26 May 1995
[this is the person who did the original port to FreeBSD, in particular, the
person who wrote the first version of this Makefile. Remember, this should
not be changed when upgrading the port later.]
# Whom: Satoshi Asami <asami@FreeBSD.org>
#
# $FreeBSD$
[ ^^^^^^^^^ This will be automatically replaced with RCS ID string by CVS
when it is committed to our repository. If upgrading a port, do not alter
this line back to "$FreeBSD$". CVS deals with it automatically.]
#
[section to describe the port itself and the master site - PORTNAME
and PORTVERSION are always first, followed by CATEGORIES,
and then MASTER_SITES, which can be followed by MASTER_SITE_SUBDIR.
PKGNAMEPREFIX and PKGNAMESUFFIX, if needed, will be after that.
Then comes DISTNAME, EXTRACT_SUFX and/or DISTFILES, and then
EXTRACT_ONLY, as necessary.]
PORTNAME= xdvi
PORTVERSION= 18.2
CATEGORIES= print
[do not forget the trailing slash ("/")!
if you are not using MASTER_SITE_* macros]
MASTER_SITES= ${MASTER_SITE_XCONTRIB}
MASTER_SITE_SUBDIR= applications
PKGNAMEPREFIX= ja-
DISTNAME= xdvi-pl18
[set this if the source is not in the standard ".tar.gz" form]
EXTRACT_SUFX= .tar.Z
[section for distributed patches -- can be empty]
PATCH_SITES= ftp://ftp.sra.co.jp/pub/X11/japanese/
PATCHFILES= xdvi-18.patch1.gz xdvi-18.patch2.gz
[maintainer; *mandatory*! This is the person who is volunteering to
handle port updates, build breakages, and to whom a users can direct
questions and bug reports. To keep the quality of the Ports Collection
as high as possible, we no longer accept new ports that are assigned to
"ports@FreeBSD.org".]
MAINTAINER= asami@FreeBSD.org
COMMENT= A DVI Previewer for the X Window System
[dependencies -- can be empty]
RUN_DEPENDS= gs:${PORTSDIR}/print/ghostscript
LIB_DEPENDS= Xpm.5:${PORTSDIR}/graphics/xpm
[this section is for other standard bsd.port.mk variables that do not
belong to any of the above]
[If it asks questions during configure, build, install...]
IS_INTERACTIVE= yes
[If it extracts to a directory other than ${DISTNAME}...]
WRKSRC= ${WRKDIR}/xdvi-new
[If the distributed patches were not made relative to ${WRKSRC}, you
may need to tweak this]
PATCH_DIST_STRIP= -p1
[If it requires a "configure" script generated by GNU autoconf to be run]
GNU_CONFIGURE= yes
[If it requires GNU make, not /usr/bin/make, to build...]
USE_GMAKE= yes
[If it is an X application and requires "xmkmf -a" to be run...]
USE_IMAKE= yes
[et cetera.]
[non-standard variables to be used in the rules below]
MY_FAVORITE_RESPONSE= "yeah, right"
[then the special rules, in the order they are called]
pre-fetch:
i go fetch something, yeah
post-patch:
i need to do something after patch, great
pre-install:
and then some more stuff before installing, wow
[and then the epilogue]
.include <bsd.port.mk>Keeping UpThe &os; Ports Collection is constantly changing. Here is
some information on how to keep up.FreshPortsOne of the easiest ways to learn about updates that have
already been committed is by subscribing to
FreshPorts.
You can select multiple ports to monitor. Maintainers are
strongly encouraged to subscribe, because they will receive
notification of not only their own changes, but also any
changes that any other &os; committer has made. (These are
often necessary to keep up with changes in the underlying
ports framework—although it would be most polite to
receive an advance heads-up from those committing such changes,
sometimes this is overlooked or just simply impractical.
Also, in some cases, the changes are very minor in nature.
We expect everyone to use their best judgement in these
cases.)If you wish to use FreshPorts, all you need is an
account. If your registered email address is
@FreeBSD.org, you will see the opt-in link on the
right hand side of the webpages.
For those of you who already have a FreshPorts account, but are not
using your @FreeBSD.org email address,
just change your email to @FreeBSD.org, subscribe,
then change it back again.FreshPorts also has
a sanity test feature which automatically tests each commit to the
FreeBSD ports tree. If subscribed to this service, you will be
notified of any errors which FreshPorts detects during sanity
testing of your commits.The Web Interface to the Source RepositoryIt is possible to browse the files in the source repository by
using a web interface. Changes that affect the entire port system
are now documented in the
CHANGES file. Changes that affect individual ports
are now documented in the
UPDATING file. However, the definitive answer to any
question is undoubtedly to read the source code of
bsd.port.mk, and associated files.The &os; Ports Mailing ListIf you maintain ports, you should consider following the
&a.ports;. Important changes to the way ports work will be announced
there, and then committed to CHANGES.The &os; Port Building Cluster on
pointyhat.FreeBSD.orgOne of the least-publicized strengths of &os; is that
an entire cluster of machines is dedicated to continually
building the Ports Collection, for each of the major OS
releases and for each Tier-1 architecture. You can find
the results of these builds at
package building logs
and errors.Individual ports are built unless they are specifically
marked with IGNORE. Ports that are
marked with BROKEN will still be attempted,
to see if the underlying problem has been resolved. (This
is done by passing TRYBROKEN to the
port's Makefile.)The &os; Port Distfile SurveyThe build cluster is dedicated to building the latest
release of each port with distfiles that have already been
fetched. However, as the Internet continually changes,
distfiles can quickly go missing. The FreeBSD
Ports distfiles survey attempts to query every
download site for every port to find out if each distfile
is still currently available. Maintainers are asked to
check this report periodically, not only to speed up the
building process for users, but to help avoid wasting
bandwidth of the sites that volunteer to host all these
distfiles.The &os; Ports Monitoring SystemAnother handy resource is the
FreeBSD Ports Monitoring System (also known as
portsmon). This system comprises a
database that processes information from several sources
and allows its to be browsed via a web interface. Currently,
the ports Problem Reports (PRs), the error logs from
the build cluster, and individual files from the ports
collection are used. In the future, this will be expanded
to include the distfile survey, as well as other sources.To get started, you can view all information about a
particular port by using the
Overview of One Port.As of this writing, this is the only resource available
that maps GNATS PR entries to portnames. (PR submitters
do not always include the portname in their Synopsis, although
we would prefer that they did.) So, portsmon
is a good place to start if you want to find out whether an
existing port has any PRs filed against it and/or any build
errors; or, to find out if a new port that you may be thinking
about creating has already been submitted.
diff --git a/zh_TW.Big5/books/zh-tut/chapters/compose.sgml b/zh_TW.Big5/books/zh-tut/chapters/compose.sgml
index 973a2ecfa7..2af07b460c 100644
--- a/zh_TW.Big5/books/zh-tut/chapters/compose.sgml
+++ b/zh_TW.Big5/books/zh-tut/chapters/compose.sgml
@@ -1,1036 +1,1035 @@
中文排版軟體OpenOffice - 整合性的辦公室軟體安裝好 OpenOffice 1.0 後,預設是在
/usr/local/OpenOffice.org1.0/任何使用者執行 /usr/local/OpenOffice.org1.0/program/soffice
都會出現是否要 repair 畫面(in X),選擇 Yes,並選擇 Complete
會把一些東西裝到 ~/OpenOffice.org1.0/,
並跳出 setup再次執行 /usr/local/OpenOffice.org1.0/program/soffice
就可以看到 soffice 的 doc 文書處理畫面了Q1: 如何加入中文字型?A1: GUI 的加入方式:
執行 /usr/local/OpenOffice.org1.0/program/spadmin 列印管理程式,
Fonts -> Add -> Source directory: /usr/local/share/fonts/TrueType/
-> ˇCreate soft links only -> 文鼎PL細上海宋(bsmi00lp.ttf) -> OkCLI 的加入方式:
cd /usr/local/OpenOffice.org1.0/share/fonts/truetype
ln -s /usr/local/share/fonts/TrueType/bsmi00lp.ttf bsmi00lp.ttf
在加入完字型後,OpenOffice 在每次進入軟體前都會自動建立 fonts.dirQ2: 畫面很醜,英文字很寬?A2: 修改分成兩個部份,一個是將 Interface User 改成文鼎PL細上海宋,
另一個則是調整字型大小,字型稍微大一點就會有 AntiAlias 的效果,
建議值是 >= 120%GUI 的修改方式:
啟動 soffice 後修改 Interface User
Tools -> Options -> OpenOffice.org -> Font Replacement ->
ˇApply replacement table -> Font: Interface User
Replace with: 文鼎 PL 細上海宋 -> ˇ -> ˇalways -> Ok
修改字型大小
Tools -> Options -> OpenOffice.org -> View -> Scale: 120% -> OkQ3: 輸入中文變成方塊?A3: 因為預設的 Thorndale 並不能顯示中文,筆者會讓預設成文鼎PL細上海宋GUI 的修改方式:
啟動 soffice 後修改 Basic Fonts(Western) 和 Basic Fonts(Asian)
Tools -> Options -> OpenOffice.org -> Text Document ->
Basic Fonts(Western) -> Default: 文鼎PL細上海宋 ->
Heading: 文鼎PL細上海宋 -> OkQ4: 如何開啟中文的HTML及純文字檔?A4: 如果您要開純文字檔,在開啟檔案的對話框中,
FileType記得選:Text Encoded,
當選完您要開的檔案後,會再出現一個對話框,
最重要的是Fonts那兒要選:Chinese traditional ( Windows-950 ),
剩下的照您的要求選,之後中文就出來囉∼
還是看不到?試試看改一下字形,也許您選到了英文字型。如果是HTML呢?更是簡單,請在檔案一開頭加上:
<HEAD>
<META HTTP-EQUIV="CONTENT-TYPE" CONTENT="text/html; charset=big5">
</HEAD>Q5: 使用細明體與新細明體時,顯示的字會碎掉?A5: 徵求解答中。openoffice snapshotWWW:
http://www.openoffice.org/
- eioffice - 永中Office 2003
- eioffice 目前只有 Windows 和 GNU/Linux 的版本.
- FreeBSD 做法其實很簡單, 因為我本來以為他的 GNU/Linux
- 版用了特殊的壓縮來包裝, 結果抓去看了一下, 發現 fonts.data
- 和 source.data 這兩個最大的檔竟然是用 zip 壓縮的, 解開當然發現
- fonts.data 裡面包的是字型, source.data 裡面就是主要的程式囉,
- 拷貝到相對應的地方後就可以執行了.
- 要注意的是, unzip 一定要用 chinese/unzip, 因為我有弄中文的 patch 在上面, 不然可能會有錯.
- jdk 我只有測試 1.4.1, 不知道 1.4.2 有沒有差別.
+ eioffice - 永中Office 2004
+ eioffice 目前只有 Windows 和 GNU/Linux 的版本。
+ FreeBSD 做法其實很簡單,因為我本來以為他的 GNU/Linux
+ 版用了特殊的壓縮來包裝,結果抓去看了一下,發現 fonts.data
+ 和 source.data 這兩個最大的檔竟然是用 zip 壓縮的。解開當然發現
+ fonts.data 裡面包的是字型,而 source.data 裡面就是主要的程式囉,拷貝到相對應的地方後就可以執行了。
+ 要注意的是,unzip 一定要用 chinese/unzip 裝的,因為我有弄中文的 patch 在上面,不然可能會有錯。
+ jdk 我只有測試 1.4.1,不知道 1.4.2 有沒有差別。我也弄了兩個版本, 簡體(eioffice-zh_CN)和繁體(eioffice-zh_TW), 更新 outta-port 後就會看到囉.
- WWW: 台灣永中
+ WWW: 台灣永中WWW: 大陸永中AbiWord - 開放原始碼、跨平台、所見即所得的文字編輯器AbiWord 可以說是 Word 的翻版,
只是換了個作業系統,容易上手、
介面友善的優點仍在。但因他仍是發展中的軟體,許多的功能,
並不能與微軟的 Word 相比,整體上有一點點缺憾。可是他仍是
FreeBSD 上的重要指標,代表著未來 FreeBSD 將有不輸於 Word
的軟體出現,也說明著,FreeBSD 將從伺服器走向個人使用者。建議採用 editors/AbiWord2,
只要有設定好 gtk2 就可以正常使用,原本的
chinese/abiword 搭配
editors/AbiWord 已經無法正常使用,
所以以下的文章可以忽略,只要安裝完 AbiWord2,
輸入中文前選擇中文字體,就可以正常的輸入中文。AbiWord 已經可以在
zh_TW.Big5 的 locale 底下工作並輸入,
選單也已經部份中文化,中文的列印也可以透過
moecid-fonts。在 AbiWord 中新增字型:要在 AbiWord
中安裝中文字型才能輸入中文字,
安裝的方式必須透過 ttfm
這套好用的軟體。在此套件中已經預設安裝了文鼎繁體與簡體字型。
如果想自行安裝新字型,以下是文鼎繁體的安裝,可以參考看看:
&prompt.root; ttfm.sh --add abiword /usr/local/share/fonts/TrueType/bkai00lp.ttf
&prompt.root; ttfm.sh --add abiword /usr/local/share/fonts/TrueType/bsmi00lp.ttf並在 XF86Config 加入
。關於中文列印的部分,請參考 abiword 的粗體與斜體 一節。abiword snapshotWWW:
abisource projectWWW:
gnome-office abiwordXEmacs - 支援 XIM 且 Big5 設定的 XEmacs 文字編輯器當您問一些使用Unix多年的老玩家,
他們認為最具代表性的文書處理軟體是什麼呢?
他們幾乎都會回答-Emacs,而在X Window的風行之下,
Emacs也推出了XWindows版-XEmacs。XEmacs一項著名的能力是它能夠處理多國語文,
能夠處理各種不同文字的軟體己經令人十分驚異,
但要在一個文件中同時處理好幾種不同語文,
XEmacs還是可以做到,它在這方面的能力,
幾乎沒有同類形的軟體能望其項背。除此之外,XEmacs為了能處理各種文件,它將瀏覽HTML文件,
還有收發E-mail的功能全部整合進來,讓您能夠用XEmacs來編寫
HTML或是寫信的工作。它甚至還整合了C和Lisp語言的編譯器,
讓您在XEmacs上寫程式,並且也可以在其中編譯程式,
使寫程式時減少面對繁瑣的事務。像拼字檢查這種工作,一般都只有商業軟體提供,
但是XEmacs也提供了,連字典也可以自己指定,Unix的目錄結構,
XEmacs也可以編輯。其它還有許許多多的功能,很多人用了一段時間,
都只有使用了一小部分,可見其功能之廣。XEmacs是一個不可多得的文書處理軟體,試試看,
或許可以讓您有更方便處理文件的方法。安裝 chinese/xemacs21。還有,emacs 和 xemacs 是不一樣的,初學 *emacs 還是從 xemacs
學比較好。至少 &a.keith; 大大把一切都打點好了。~/Emacs 則是設 fontset。
Emacs.Font: fontset-18
Emacs.Fontset-0: -*-*-medium-r-normal-*-18-*-*-*-*-*-fontset-18,\
ascii:-*-lucidatypewriter-medium-r-normal-*-*-100-*-*-m-*-iso8859-1,\
chinese-big5-1:-*-fixed-medium-r-normal-*-*-160-*-*-c-*-big5-0,\
chinese-big5-2:-*-fixed-medium-r-normal-*-*-160-*-*-c-*-big5-0wvware - 可以轉換微軟 Word 檔案的工具Last Update: 2003年 1月26日 周日 03時34分02秒 CSTwv 是一套可以轉換微軟 Word 檔案的工具,
能夠讀取並且解析 Word 6-9 格式 (Word 6, 95, 97, 2000)。並且提供許多轉換工具,通稱為 wvWare。
wvHtml, wvLatex, wvCleanLatex, wvDVI, wvPS, wvPDF,
wvText, wvAbw, wvWml, wvMime安裝 textproc/wv。接著以最常用的 wvHtml 為例,要轉 Word 成 HTML,
只要下 wvHtml --charset=big5 input.doc ouput.html
。WWW:
wvware projectEmacs安裝 chinese/emacs20。emacs 不是完整的 XIM support,請看
http://www.FreeBSD.org/cgi/query-pr.cgi?pr=21160。~/.emacs 是設 mule
;; Set environment to Chinese-Big5
(set-language-environment 'chinese-big5)
(set-keyboard-coding-system 'chinese-big5)
(set-terminal-coding-system 'chinese-big5)
(set-buffer-file-coding-system 'chinese-big5)
(set-selection-coding-system 'chinese-big5)
(modify-coding-system-alist 'process "*" 'chinese-big5)至於 ~/.emacs 還有很多好玩的,可以到
http://dotfiles.com
參考參考。celvis - 類似 vi/ex 且中文顯示的文字編輯器Celvis 是一個很像 UNIX 上標準編輯器
vi/ex
的東西,幾乎支援所有 vi/
ex 的指令。
Celvis 可編輯同時含有中英文的文章。
它也同時支援 GB2312-80 和 BIG5 編碼。安裝 chinese/celvis。joe - 簡易且功能不錯的編輯程式joe 是一個 UNIX 上免費專業的
ASCII 文字編輯器。它用起來就像大部份 IBM PC 上的文字編輯器。
它是一套操作相當方便的文書編輯程式。安裝 chinese/joe。要在 joe 上使用中文,必須修改
/usr/local/lib/joerc 和
/usr/local/lib/rjoerc的設定。
-asis Characters 128 - 255 shown as-is
quote Enter Ctrl chars
將以上的自傳修改成以下的字串
-asis Characters 128 - 255 shown as-is
quote .k; Enter Ctrl chars 是要能顯示中文字,
而 是要輸入特殊的控制字元時使用的按鍵,
而預設值是 ,就會遇到有些中文字的內碼,
然後只要加參數 就可以看中文,如:
joe -asis filename 就可以了,但是
則必須改檔案,或是兩個都改檔案吧。joe snapshotnvi - 類似 vi/ex,有多種語言修補,預設為 big5有 nvi-big5、
nvi-enc-cn、
nvi-enc-tw 等不同的套件。
BIG5 或 GB 相容的 vi 操作介面編輯器
vi 是 UNIX
的標準編輯器,此程式和中文繁體、enc-cn、
euc-tw 相容。安裝 chinese/nvi-big5。編輯 ~/.nexrc
set noskipdisplay
set displayencoding=big5
set inputencoding=big5
set fileencoding=big5
set autodetect=twWWW:
http://www.itojun.org/qe - qe 是一個模仿 PE2 的編輯程式qe 是一個模仿 PE2 的編輯程式,叫 qe 的原因只是因為字母 Q 是排在 P
之後。和 DOS 不同的是,UNIX 沒有那麼多鍵可用,而且不同的 Terminal
的鍵碼也略有不同。因此一些常用的 function 最好定義到 Control Key
或 Meta Key 上,以免不堪使用。 安裝 chinese/qe。qe snapshotWWW:
qe projectve - NTHU-CS Maple BBS 發展的 BBS-like 文字編輯器一套由 NTHU-CS Maple BBS 2.36 發展的 BBS-like 文字編輯器。安裝 chinese/ve。ve snapshotChiTex - 中文 Tex/LaTexChiTeX 是一套中文 LeX
/LaTeX,只要會英文
TeX/LaTeX
就幾乎立刻可使用 ChiTeX,本版可適用於
Big5 及 GB 內碼之中文。此一 Unix 版可用於裝有
teTeX 的 GNU/Linux,FreeBSD,Solaris,與
SunOS 系統。安裝 chinese/chitex。ChiTeX 6.1.2 一系列的改進,
以及下載位置請參考:
chitex ftp site。ChiTex 的特點:用法簡單,不用特別學習,會用英文 TeX
/LaTeX 就幾乎立刻可使用
ChiTeX
(若要進一步使用較多功能,只要學習幾個簡單的特殊指令就可)。與英文 TeX/
LaTeX 相容性高。 功能完備而多樣化。 提供 cbibtex,cmakeindex 可用以引用內含中文的外在參考文獻資料及
自動編輯含中文之索引。提供中文化的 chilatex2html 可將含中文的
LaTeX 文件轉換為 HTML 格式檔。支援由 TeX/LaTeX
文件產生 pdf 檔。 同時支援 Big5 碼中文 (台灣,香港) 及 GB 碼中文 (新加坡與大陸)。
現在您可以拿 ChiTeX 附的範例來測試:
&prompt.root; cd /usr/local/share/texmf/tex/chinese
&prompt.root; chilatex math2.tex (編譯)
&prompt.root; xdvi math2.dvi (預視)
&prompt.root; dvips math2.dvi -o math2.ps (轉換成 PostScript 檔)
&prompt.root; gv math2.ps (用 gv 觀看)WWW:
yih's homepageWWW:
Kile: LaTeX source editorCJK - 可以使用 CJK scripts 的 LaTeX2e 巨集套件TeX/LaTeX
是一套的幕後排版軟體。其優秀的輸出品質早已為廣大的
學術界朋友所喜愛及採用。CJK 是一個
LaTeX2e 的巨集套件(macro package),
能讓您在 TeX 文件中使用
CJK (Chinese/Japanese/Korean)
的文字編碼。
您的系統必須先安裝好 teTeX/
LaTeX。如果沒有的話,您也可以自己裝。
請參考 /usr/ports/print/teTeX 的說明。安裝 chinese/CJK。在 CJK 套件中有一份中文文件,由李君宇先生所寫的介紹,
專門介紹 CJK 處理中文的語法,在
/usr/local/share/doc/CJK/chinese/READMEb5.tex,
在此提供 READMEb5.pdf 的下載。
&prompt.root; cd /usr/local/share/doc/CJK/chinese/
&prompt.root; bg5latex READMEb5.tex (看看有沒有產生 READMEb5.dvi)
&prompt.root; xdvi READMEb5.dvi (是否能看到中文? 當然您要先進 X Window)
&prompt.root; dvips READMEb5.dvi -o READMEb5.ps (轉換成 PostScript 格式))
&prompt.root; gv READMEb5.ps (用 gv 觀看)
% 測試文件
\documentclass{article}
\usepackage{CJK}
\begin{document}
\begin{CJK*}{Bg5}{song}
宋體
\end{CJK*}
\begin{CJK*}{Bg5}{kai}
楷體
\end{CJK*}
\end{document}CJK snapshotWWW:
我的 CJK - by EdwardWWW:
cjk projectCJK-LyX - 有 LaTeX 使用介面的文件編輯器(所見即所得)LyX 是一個有 LaTeX
介面文件編輯器,是一個容易使用的文字編輯器
,也是一個有彈性且強大的 LaTeX。有著所見即所得的介面,和許多 LaTeX
風格和自動產生的設計。加速學習 LaTeX
並使複雜的設計簡單化和直覺化。新的特色包含拼字檢查
,國際化,字元提供,所見即所得的圖形、表格、方程式。LyX 是一個進可攻
TeX/LaTeX,
退可守 (把 LyX 當成文書處理軟體)
的一個功能強大,可以處理圖文的文書處理軟體。安裝 print/cjk-lyx。必要的設定:請編輯一個 ~/.lyx/preferences
(沒有這個檔,請自行建立),內容如下:
\screen_dpi 100
\screen_font_roman "-*-times new roman"
\screen_font_sans "-*-arial"
\screen_font_typewriter "-*-courier new"
\screen_font_i18n1_encoding "big5-0"
\screen_font_i18n1_normal "-*-ar pl mingti2l big5"
\screen_font_i18n1_gothic "-*-ar pl mingti2l big5"
\screen_font_i18n2_encoding "big5-0"
\screen_font_i18n2_normal "-*-ar pl kaitim big5"
\screen_font_i18n2_gothic "-*-ar pl kaitim big5"另外針對 CJK 還會設定如下的東西:
\language_package "\usepackage{CJK}"
\language_command_begin "\begin{CJK*}{Bg5}{aming}"
\language_command_end "\end{CJK*}"
\language_auto_begin false
\language_auto_end false
\mark_foreign_language false
\converter latex dvi "bg5latex $$i" "latex"
#\converter dvi pdf "dvipdfm $$i" ""
#\font_encoding default如果您 TeX/LaTeX 是使用中文 Type1 字型的話,請將最後二行的 mark
拿掉。測試:請進入 LyX 後隨便編輯一個中文檔,
然後按 View => DVI 及 View => Postscript 看運作是不是正常。
另外 File => Export => Postscript 看是不是可以正確輸出文稿的
*.ps 檔。* 在此建議使用中文 Type1 字型,以免多花時間等待系統製造 pk 字型。
請參考六月份的舊信,標題是:
``[FYI] CJK/LaTeX enviroment 中文 Type1 及 TTF 的使用''要變換字型或做更複雜的變化,LyX 本身並沒有 CJK enviroment
的特殊功能,得自行加入 tags。例如要換字型,
可按功能表那個大的向下的黑箭頭選 LaTeX,以便輸入 CJK enviroment
的 tag:
\CJKfamily{akai}這樣以下的文字就會改用楷體字,注意,這裡指的是所輸出的 *.ps
檔的字型,而不一定是您螢幕上看到的字型
(依我的設定,螢幕上是明體)。其他的中文 TeX/LaTeX 系統,如 cwTeX/ChiTeX
請參考以上設定,自行更改。Copyright (c) 2001 李果正(&a.edwardlee;)本文為自由文件(FDL http://www.gnu.org/copyleft/fdl.html)
可自由複製/修改/散佈。但請保留版權聲明的部份。CJK-LyX snapshotWWW:
CJK-LyX 中使用中文WWW:
lyx projectWWW:
CJK-LyX project在 ConTeXt 使用 Big-5 中文Contributed by &a.edwardlee;Last Update: 2003年 4月30日 周三 03時25分52秒 CST在讓 ConTeXt 使用 Big-5 中文前,
至少要能在英文環境運作。
&prompt.root; cd ${TEXMF}/web2c
&prompt.root; texexec --make en metafun為了和 CJK 和 dvipdfmx 配合,
請先安裝 chinese/CJK 和
print/dvipdfmx,
採用 CJK standard encoding vector,這樣一來,
字型方面的資料就可以共用了。修改檔案:1. ${TEXMF}/tex/context/config/cont-usr.tex如果沒有這個檔,請將 ../base/cont-usr.ori 拷貝一份成 cont-usr.tex。
在 \protect \endinput 之前加入下列資料:
% 將 Poorman 的對應,轉成 CJK 的對應
\defineucharmapping{BIG5}#1#2%
{\unicodeposition=#1
\advance\unicodeposition -161
\multiply\unicodeposition 157
\advance\unicodeposition #2
\advance\unicodeposition-\ifnum#2>160 98\else64\fi
\dorepositionunicode}
% for Big-5 CJK standard encoding vector
\def\currentucharmapping{BIG5}
% font alias。這樣就不必更動原來的字型設定了
\definefontsynonym [b5song] [arb5sung] [encoding=big5]
\definefontsynonym [b5songsl] [arb5sungs] [encoding=big5]
\definefontsynonym [b5kai] [arb5kai] [encoding=big5]
\definefontsynonym [b5kaisl] [arb5kais] [encoding=big5]2. ${TEXMF}/tex/context/base/font-chi.tex將某行只有 改成 。改好後重新執行:
&prompt.root; cd ${TEXMF}/web2c/
&prompt.root; texec --make en前置處理 script由於「許、功」的問題,我們必須前置處理,以下是改自王佑中先生的
clatex 的 perl script。
#!/usr/bin/env perl
#
# Process Big-5 Traditional Chinese ConTeXt file.
# Usage: chcont.pl tex file(NO tex extension)
# By Edward G.J. Lee <edt1023@speedymail.org> 2003.04.24
# Inspire heavily from wycc's(wycc@iis.sinica.edu.tw) clatex.
#
$one = 161;
$two = 254;
open(CONT,">$ARGV[0].cont");
if ($ARGV[0] =~/(.*)\.tex$/)
{
-r $ARGV[0] || die " file $ARGV[0] not found\n";
open(INFILE,"<$ARGV[0]");
}
else
{
-r "$ARGV[0].tex" || die "file $ARGV[0].tex not found\n";
open(INFILE,"<$ARGV[0].tex");
}
while(<INFILE>)
{
&trans_print($_);
}
close(CONT);
system "texexec ${ARGV[0]}.cont";
sub trans_print {
local($s) = @_;
local($i,$c,$nc,$ordc,$ordc1);
for($i=0;$i<length($s);$i++)
{
$c = substr($s,$i,1);
$ordc = ord($c);
if (($ordc>=$one)&&($ordc<=$two))
{
$nc = substr($s,$i+1,1);
if ($nc =~/[\\{}\^_]/)
{
$ordc1 = ord($nc);
print CONT "\\uc{$ordc}{$ordc1}";
}
else
{
print CONT $c,$nc;
}
$i++;
}
else
{
print CONT $c;
}
}
}測試:
\usemodule[chinese]
\starttext
\completecontent
%\setupindenting[medium]
\setupwhitespace[10pt]
\chapter{桃花源記}
\ConTeXt\ 中文測試。
\section{桃花源記前段}
晉太元中,武陵人,捕魚為業,緣溪行,忘路之遠近;忽逢桃花林,夾岸數百步,
中無雜樹,芳草鮮美,落英繽紛,漁人甚異之。復前行,欲窮其林。林盡水源,
便得一山。山有小口,彷彿若有光,便捨船,從口入。
初極狹,纔通人;復行數十步,豁然開朗。土地平曠,屋舍儼然。有良田、美池、
桑、竹之屬,阡陌交通,雞犬相聞。其中往來種作,男女衣著,悉如外人;黃髮、
垂髫,並怡然自樂。見漁人,乃大驚,問所從來;具答之,便要還家,設酒、殺雞、
作食。村中聞有此人,咸來問訊。自云:「先世避秦時亂,率妻子邑人來此絕境,
不復出焉;遂與外人閒隔。」問今是何世;乃不知有漢,無論魏、晉。此人一一
為具言所聞,皆歎惋。餘人各復延至其家,皆出酒食。停數日,辭去。此中人語
云:「不足為外人道也。」
既出,得其船,便扶向路,處處誌之。及郡下,詣太守,說如此,太守即遣人隨
其往,尋向所誌,遂迷不復得路。南陽劉子驥,高尚士也,聞之,欣然規往,未
果,尋病終。後遂無問津者。
\chapter{將進酒}
君不見,黃河之水天上來,奔流到海不復回。
君不見,高堂明鏡悲白髮,朝如青絲暮成雪。
人生得意須盡歡,莫使金樽空對月。
天生我材必有用,千金散盡還復來。
烹羊宰牛且為樂,會須一飲三百杯。
岑夫子,丹丘生,將進酒,君莫停。
與君歌一曲,請君為我側耳聽。
鐘鼓饌玉不足貴,但願長醉不願醒。
古來聖賢皆寂寞,惟有飲者留其名。
陳王昔時宴平樂,斗酒十千恣讙謔。
主人何為言少錢,徑須沽取對君酌。
五花馬 千金裘,呼兒將出換美酒。
與爾同消萬古愁。
\chapter{許功開的問題}
許功開。這些有問題的字元要避開。
也就是說,要前置處理這些字元。
\stoptext
&prompt.root; chcont.pl cont-b5 ==> 千萬不要加副檔名,切記!這樣會產生 cont-b5.dvi
&prompt.root; dvipdfmx cont-b5 ==> 產生不內嵌字型且可 copy&paste 的 pdf 檔。這裡沒有用到 pdftex 嵌入 TTF 的功能,原因是他不僅嵌入整個 subfont
檔案會變得很大,而且又沒有 copy&paste&search 的功能。WWW:
http://www.pragma-ade.com/WWW:
http://www.pragma-ade.com/general/manuals/mchinese.pdfcwTeXcwTeX 排版系統由吳聰敏與吳聰慧共同發展,
它延伸 TeX/LaTeX 之功能,使之可以排版中文。當初吳老師設計 cwTeX 字型時,對字型的編排是仔細設計的。
他將最常用的字型依先後順序編排,越是常用的,就越放在前面。
所以,這和 windows 上的字型順序不相同。當初之所以如此設計,
是為了讓編譯的速度能夠變得比較快。不過,隨著電腦的速度越來越快,硬碟越來越便宜,他對這樣的設計
似乎覺得也可以改變。就和 Windows 的自行編排方式一致他覺得或許
亦不失為一個 user friendly 的方法。因為像 PuTeX 可以使用眾多
中文字字型的優點的確很吸引人,不過呢,這可能還需要「民意」。
請老師來傷腦筋吧。內附字形為:明體(m)、黑體(bb)、楷書(k)、圓體(r)、仿宋體(f),
若需要垂直字體則在前面加上 v。安裝 chinese/cwtex。cwTeX 的使用:
&prompt.user; vi file.ctx
&prompt.user; cwtex file
&prompt.user; latex file.tex
&prompt.user; dvips -o file.ps file.dvi
&prompt.user; gv -antialias file.ps這裡有吳老師 cwTeX 排版系統二版手冊
cxbook.pdf。WWW:
tmwu's homepagedvipdfmx - 轉換 *.dvi 成為不內嵌中文字型的 *.pdf 檔Copyright (c) 20021 李果正(&a.edwardlee;)這是 Jin-Hwan Cho(韓)、Shunsaku Hirata(日) 修改自 Mark A. Wicks
的 dvipdfm 而來的。主要的功能是轉換 *.dvi 成為不內嵌中文字型的 *.pdf 檔。
一般的英文檔也是可以照常使用(含原有 dvipdfm 的功能)。
不管是可處理 double-byte code 的 Omega 或只能處理 single-byte 使用
subfont 的 CJK package 都可以使用。最大的好處是可以利用 TeX/LaTeX 來製作中文 pdf 檔,
而且又不內嵌中文字型,可以使檔案小很多(是真的『很多』!:)。
可直接使用 TTF,但會被標記為 use font of acroread
所預設使用的字型(MHei-Medium 及 MSung-Light),這樣雖然不內嵌字型,
但在 acroread/xpdf 都可以正常閱覽,非常方便網路上的流通。
又不必再去花銀子買軟體來製作,更重要的是 TeX/LaTeX
的特殊功能還是可以繼續沿用。如果和 pslatex 配合使用的話,
那連英文字型及少數特殊符號也會不內嵌,使檔案更小,
當然 mathtime 的一些數學符號並沒有 free 的,這會內嵌 CM 字型。安裝 print/dvipdfmx。以 bsmi00lp.ttf 為例,安裝好後 $TEXMF/dvipdfm/config/cid-x.map 設為:
arb5sung@Big5@ ETen-B5-H :0:!arb5_sung.ttf
arb5sungs@Big5@ ETen-B5-H :0:!arb5_sung.ttf,Italic
arb5sung@Big5@ ETen-B5-H :0:!arb5_sung.ttf,Bold
arb5sungs@Big5@ ETen-B5-H :0:!arb5_sung.ttf,BoldItalic
arb5kai@Big5@ ETen-B5-H :0:!arb5_kai.ttf
arb5kais@Big5@ ETen-B5-H :0:!arb5_kai.ttf,Italic
arb5kai@Big5@ ETen-B5-H :0:!arb5_kai.ttf,Bold
arb5kais@Big5@ ETen-B5-H :0:!arb5_kai.ttf,BoldItalic
% 但不含 postscript name 的字型則無法使用。去掉 ``!'' 會嵌入 TTF(
% CIDFontType2,或 Type11),不需 *.enc 檔。另外也有人建議將 改成
,
改成 以避免斜體字顯示不正常,
沒有逗點的問題。裝完後記得執行 mktexlsr即可。當然,原先的系統 CJK package 要能夠正常運作
(不管是使用 Type1或 pk 字型),因為需要正確的 *.tfm 字型描述檔。
然後,依照一般正常程序編譯 CJK 文稿即可。由於並沒有去變造、嵌入字型本身,
所以只要是合法買來的字型應該都可以放心去使用了。% 我不是律師,可不負擔保責任。:)讓英文字型也不內嵌:由 *.tex 文稿中,加入:
\usepackage{pslatex}測試:
&prompt.user; cat cjk.tex
\documentclass{article}
\usepackage{CJK}
\begin{document}
Hello World
\begin{CJK*}{Bg5}{song}
您好
\end{CJK*}
\end{document}
&prompt.user; bg5latex cjk.tex
&prompt.user; dvips -o ps2pdf-cjk.ps cjk.dvi
&prompt.user; ps2pdf ps2pdf-cjk.ps
&prompt.user; dvipdfmx -o dvipdfmx-cjk.pdf cjk.dvi
&prompt.user; cat bg5pslatex
#!/bin/sh
f=`echo $1 | sed -e 's|\(.*\)\.[^/]*$|\1|'`
bg5conv < $1 > $f.cjk && pslatex $f.cjk
&prompt.user; ./bg5pslatex cjk.tex
&prompt.user; dvipdfmx -o pslatex-cjk.pdf cjk.dvi
&prompt.user; pdffonts ps2pdf-cjk.pdf
name type emb sub uni object ID
------------------------------------ ------------ --- --- --- ---------
[none] Type 3 no no no 9 0
&prompt.user; pdffonts dvipdfmx-cjk.pdf
name type emb sub uni object ID
------------------------------------ ------------ --- --- --- ---------
TGRGZY+CMR10 Type 1 yes yes no 10 0
ZenKai-Medium CID TrueType no no no 13 0
&prompt.user; pdffonts pslatex-cjk.pdf
name type emb sub uni object ID
------------------------------------ ------------ --- --- --- ---------
Times-Roman Type 1 no no no 8 0
ZenKai-Medium CID TrueType no no no 11 0
&prompt.user; ls -l *.pdf
-rw-r--r-- 1 root wheel 8427 7 6 00:17 dvipdfmx-cjk.pdf
-rw-r--r-- 1 root wheel 5373 7 6 00:17 ps2pdf-cjk.pdf
-rw-r--r-- 1 root wheel 3789 7 6 00:17 pslatex-cjk.pdf問題:無法由 pdf2ps/pdftops 來轉成 ps。也就是說一般表機會印不出來。對策:可經由 acroread 利用裡頭的 CIDKeyed font 來轉成 ps 檔。
品質相當精良,只是檔案很大就是了。終究解決方法:要和 gs 整合在一起。dvipdfmx snapshotWWW:
我的 CJK - by EdwardWWW:
dvipdfmx projectttf2pt1 - TTF 轉中文 Type1 字型Copyright (c) 2001 李果正(&a.edwardlee;)本文為自由文件(FDL http://www.gnu.org/copyleft/fdl.html)
可自由複製/修改/散佈。但請保留版權聲明的部份。安裝 chinese/ttf2pt1,
他會連 print/ttf2pt1 一起安裝。chinese 套件只是 map 表,有倚天字集可用。寫一個 sh script(mkfont) 內容如下:
=== mkfont begin ===
#!/bin/sh
#
# By Edward G.J. Lee 2001.11.25
# This code is Public Domain.
#
if [ $# -ne 1 ]
then
echo "Usage: `basename $0` your.ttf"
exit 1
fi
echo
echo "Now create *.t1a and *.enc and *.afm files. Wait... "
echo
FONTNAME=$1
MAPFILE=/usr/local/share/ttf2pt1/maps/cubig5.map
n=1
while [ $n -lt 10 ]
do
m=0$n
ttf2pt1 -GE -pft -Ohub -W0 -L $MAPFILE+$m $FONTNAME ${FONTNAME%.ttf}$m
n=`expr $n + 1`
done
m=10
while [ $m -lt 56 ]
do
ttf2pt1 -GE -pft -Ohub -W0 -L $MAPFILE+$m $FONTNAME ${FONTNAME%.ttf}$m
m=`expr $m + 1`
done
# avoid dvips(k)(before v5.86) t1part module bug.
#
perl -pi -e 's/_/Z/g' *.t1a *.afm
echo
echo "Now create *.pfb, wait... "
echo
for ps in *.t1a
do
t1asm -b $ps > ${ps%.t1a}.pfb
done
echo
echo "Now create *.tfm, wait... "
echo
for afm in *.afm
do
afm2tfm $afm
done
AFM=${FONTNAME%.ttf}-afm
TFM=${FONTNAME%.ttf}-tfm
PFB=${FONTNAME%.ttf}-pfb
ENC=${FONTNAME%.ttf}-enc
rm -f *.t1a
mkdir -p $AFM $TFM $PFB $ENC
mv -f *.enc $ENC
mv -f *.afm $AFM
mv -f *.tfm $TFM
mv -f *.pfb $PFB
echo
echo "OK, all done. :-)"
echo
=== mkfotn end ===在一個獨立目錄放 mkfont(要先 chmod +x mkfont),
再把字型置於同一目錄。* 一些路徑有不一樣的話,請自行修改。這裡以文鼎細上海宋和文鼎中楷為例:./mkfont bsmi00lp.ttf; ./mkfont bkai00mp.ttf即可。完成後會產生 afm, euc, tfm, pfb 等四個目錄,裡面都是字型資料。將資料搬移到所屬的地方(arphic 目錄請自行建立)。afm copy 至 /usr/local/share/texmf/fonts/afm/arphic。tfm copy 至 /usr/local/share/texmf/fonts/tfm/arphic。pfb copy 至 /usr/local/share/texmf/fonts/type1/arphic。euc copy 至 /usr/local/share/texmf/dvips/arphic。新增 /usr/local/share/texmf/dvips/config/aming.map 內容如下:
bsmi00lp01 ShanHeiSun-Light-01 <bsmi00lp01.pfb
bsmi00lp02 ShanHeiSun-Light-02 <bsmi00lp02.pfb
...
bsmi00lp55 ShanHeiSun-Light-55 <bsmi00lp55.pfb 新增 /usr/local/share/texmf/dvips/config/akai.map 內容如下:
bkai00mp01 ZenKai-Medium-01 <bkai00mp01.pfb
bkai00mp02 ZenKai-Medium-02 <bkai00mp02.pfb
...
bkai00mp55 ZenKai-Medium-55 <bkai00mp55.pfb在 /usr/local/share/texmf/dvips/config/config.ps 加入:
p +aming.map
p +akai.map 新增 /usr/local/share/texmf/dvips/config/bsmi00lp.map 內容如下:
bsmi00lp01 <bsmi00lp01.enc <bsmi00lp.ttf
bsmi00lp02 <bsmi00lp02.enc <bsmi00lp.ttf
...
bsmi00lp55 <bsmi00lp55.enc <bsmi00lp.ttf新增 /usr/local/share/texmf/dvips/config/bkai00lp.map 內容如下:
bkai00mp01 <bkai00mp01.enc <bkai00mp.ttf
bkai00mp02 <bkai00mp02.enc <bkai00mp.ttf
...
bkai00mp55 <bkai00mp55.enc <bkai00mp.ttf* bsmi00lp.ttf,bkai00mp.ttf 要置於 kpathsea 找得到的地方,如
/usr/local/share/texmf/fonts/truetype (目錄可自行建立)。修改 /usr/local/share/texmf/pdftex/config/pdftex.cfg,加入:
map +bsmi00lp.map
map +bkai00mp.map新增 /usr/local/share/texmf/tex/latex/CJK/Bg5/c00aming.fd 內容如下:
\def\fileversion{4.2.0}
\def\filedate{2001/09/28}
\ProvidesFile{c00aming.fd}[\filedate\space\fileversion]
\DeclareFontFamily{C00}{aming}{}
\DeclareFontShape{C00}{aming}{m}{n}{<-> CJK * bsmi00lp}{}
\DeclareFontShape{C00}{aming}{bx}{n}{<-> CJK * bkai00mp}{}
\endinput新增 /usr/local/share/texmf/tex/latex/CJK/Bg5/c00bsmi00lp.fd 內容如下:
\def\fileversion{4.2.0}
\def\filedate{2001/09/28}
\ProvidesFile{c00bsmi00lp.fd}[\filedate\space\fileversion]
\DeclareFontFamily{C00}{bsmi00lp}{}
\DeclareFontShape{C00}{bsmi00lp}{m}{n}{<-> CJK * bsmi00lp}{}
\DeclareFontShape{C00}{bsmi00lp}{bx}{n}{<-> CJK * bkai00mp}{}
\endinput這樣粗體字會去選用文鼎楷書體(個人不喜歡模擬出來的粗體字)。
當然楷書體也要自行按上述方法製作出來。執行 texhash(or mktexlsr)。這樣就可以了,要使用明體就使用
aming 的字型名稱,要使用楷體就使用 akai(依上述方法做一個 c00akai.fd)。當然,CJK 的使用方法,請參考 CJK 所附文件,一定要指定 aming
才會去使用所定義出來的字型,否則會去抓 CJK 預設字型,
那當然一般系統上是沒有的。為了配合中文 Type1 字型,執行 dvips 時請加上 -Ppdf 或 -Pcmz 參數,
這樣英文字型才會去使用 Type1。最後記得執行 texhash。測試例子
=== begin ex.tex ===
\def\Fn{\char}
\font\Aa=bsmi00lp01 scaled 1000
\font\CCC=bsmi00lp55 scaled 3000
\font\CCc=bsmi00lp55 scaled 2000
\font\Ccc=bsmi00lp55 scaled 1000
\font\JJJ=bsmi00lp24 scaled 3000
\font\JJj=bsmi00lp24 scaled 2000
\font\Jjj=bsmi00lp24 scaled 1000
{\CCC\Fn108}
{\CCC\Fn109}
{\CCc\Fn110}
{\CCc\Fn111}
{\Ccc\Fn112}
{\Ccc\Fn113}
{\Ccc\Fn114}
{\JJJ\Fn55}
{\JJj\Fn95}
{\Jjj\Fn84}
{\CCC\Fn101}
{\CCC\Fn102}
{\CCc\Fn103}
{\CCc\Fn104}
{\Ccc\Fn106}
{\Ccc\Fn107}
\bye
=== end ex.tex ===pdftex ex.tex 即可產生內嵌中文 TTF 的 ex.pdf。
如果有製作中文 Type1 字型,則 tex ex.tex ; dvipdf ex
則是會內嵌中文 Type1,各位可比較看看兩者有何不同。寫個 cjk-latex 稿試看看吧!字型名稱要使用 bsmi00lp。我寫的
sh script 只是個半成品,可能得多試幾次才會成功。have fun! :)* LaTeX 稿請用 pdflatex。要編譯 CJK-latex 文稿,可有兩種方式:1. bg5latex test.tex ; pdflatex test.cjk2. 寫一個 sh script(bg5pdflatex) 內容如下:
=== bg5pdflatex begin ===
#!/bin/sh
FILE=`echo $1 | sed -e 's|\(.*\)\.[^/]*$|\1|'`
bg5conv < $1 > $FILE.cjk
pdflatex $FILE.cjk
=== bg5pdflatex end ===chmod +x bg5pdflatex 後置於 PATH 可及之處。bg5pdflatex test.tex即可。其實這個 script 的內容和 bg5latex 是一樣的,只不過是把
latex 換成 pdflatex 而已。ps. 內容如有錯誤,請不吝指正。ttf2pt1 snapshotWWW:
使用 pdfTeX/pdfLaTeX 讓 pdf 檔內嵌中文 TTF/TTCWWW:
由 TeX/LaTeX 製作中文 PDF 檔WWW:
CJK/LaTeX environment 中文 Type1 及 TTF 的使用WWW:
http://ttf2pt1.sourceforge.net/
diff --git a/zh_TW.Big5/books/zh-tut/chapters/fonts.sgml b/zh_TW.Big5/books/zh-tut/chapters/fonts.sgml
index 8367b0068b..19c365b23e 100644
--- a/zh_TW.Big5/books/zh-tut/chapters/fonts.sgml
+++ b/zh_TW.Big5/books/zh-tut/chapters/fonts.sgml
@@ -1,1038 +1,1042 @@
輸出字型在這個章節中將會介紹點陣字型(Bitmapped Font),
以及曲線描邊字型(Outline Fonts)。點陣字型(Bitmapped Fonts):
這種字型就是直接將點矩陣的字型儲存在記憶體中,
使用時就直接取出,這種方式若儲存點數不多則輸出字型太難看;
但若儲存點數較多則需要佔掉太多記憶體,
同時將字體放大後可能產生鋸齒壯,因此目前除了特殊用途外,
幾乎很少用到。曲線描邊字型(Outline Fonts)是利用曲線公式來描繪字框,
因此不論放大縮小位數是多少都一樣平滑,
但是缺點是計算耗時,常見的包括常用在印刷的 Postscript
與用在螢幕顯示的 TrueType Font(TTF) 等。目前使用點陣字型的主要是控制台軟體,像是 big5con、zhcon 等,
主要是因為讀取曲線描邊字型的速度較慢,
也比較複雜,所以目前的控制台軟體都沒看到使用曲線描邊字型的。WWW:
Chinese, Japanese and Korean characters in English
WindowsWWW:
Chinese Fontsshowttf snapshotBitmapped Font - 點陣字型概論點陣字型代表字型 BDF(Bitmap Distribution Format,點陣分散格式)、
HBF(Hanzi Bitmap Font,漢字點陣字體)、
PCF(Portable Compiled Font)。BDF Spec:
5005.BDF_Spec.pdfcmexfonts - 中推會 Big5+ 點陣字型該著作權為中華民國行政院研考會、中文電腦推廣基金會所共有,
字形設計為華康科技 Dynalab Inc.。該套字型並不是標準的 Big5 字型,而是當時為了推廣 Big5+ 所製作的,
目前並無使用的價值。安裝 chinese/cmexfonts。這個套件中包含了 16 點、24 點兩套中文點陣字型。WWW:
cmex orgkcfonts - 國喬點陣字型國喬中文 PCF 字型是 FreeBSD 下最常用的點陣字型。要得知已安裝的 BIG5 字型用:
&prompt.user; xlsfonts | grep big5
kc15f.pcf.gz -kc-fixed-medium-r-normal--16-160-72-72-c-160-big5-0
kc24f.pcf.gz -kc-fixed-medium-r-normal--24-240-100-100-c-240-big5-0安裝 chinese/kcfonts。這個套件裡面包含了 16 點、20 點以及 24 點三套中
文點陣字體,足供一般情況顯示中文之用。適用於 640x480 解析度 (NoteBook)
&prompt.root; rxvt -ls -fm kc15 -fn 8x16 &適用於 +1024x768 解析度 (17 吋螢幕)
&prompt.root; rxvt -ls -fm kc24 -fn 12x24 &gugod-clean - 搭配中文點陣字型用的英文點陣字型看了一下 irc 上得聊天,終於懂得是為了終端機的殘影問題。節錄 gugod 的一段話:
配合 kc15f 改了一下 schumacher 的 clean,本來這兩種字不一樣高,
所以用久了 term 會髒髒的,改成一樣高就不會了,這個 clean 是 15 的,
怎麼改成一樣高的?大致上是改 bdf 中的 PIXEL_SIZE, POINT_SIZE,
FONT_ASCENT, FONT_DESCENT 還有 FONT 這些東東先,不過要先用
xmbdfed 把 bdf 字改成想要的長寬,不然 clean
字的每個字母長寬都不一樣,很難稿,相關工具請看
ports/x11-fonts。安裝 chinese/gugod-clean。
&prompt.root; cd /usr/X11R6/lib/X11/fonts/local
&prompt.root; mkfontdir
&prompt.root; xset fp rehash將以下加入 /usr/X11R6/lib/X11/fonts/local/fonts.alias
gugod16 -gugod-clean-medium-r-normal--16-160-75-75-c-90-iso8859-1
gugod18 -gugod-clean-medium-r-normal--18-180-75-75-c-80-iso8859-1
gugod20 -gugod-clean-medium-r-normal--20-200-75-75-c-100-iso8859-1
gugod22 -gugod-clean-medium-r-normal--22-220-75-75-c-110-iso8859-1 然後執行 Eterm --font gugod16 &就可以看到很漂亮的 Eterm 透明背景,
原來會髒掉的終端機也沒問題了。intlfonts - 各國的免費點陣字型
這個包含各國的免費 PCF 字型,而且裡面還包含了 cns11643 七個字面的
16pt、24pt 與 40pt,以及 big5 的 taipei16 與 taipei24,
裝完幾乎可以處理各種語言了。 安裝 x11-fonts/intlfonts。PostScript 概論 PostScript為美國Adobe(
http://www.adobe.com)公司於1985年所發表的文件描述技術,
Adobe並利用這個技術,創造著名合乎PostScript技術的字型,
並從而改變整個印刷工業,PostScript
可以精確的描述平面繪製任何文字及圖形,現今PostScript
的技術已經非常普遍的使用在印刷領域,包括螢幕顯示(Display),
雷射印表機(Laser Printer), 輸出機(Imagesetter),
數位印刷機(Digital Printing)..等等輸出設備。 而與PostScript技術搭配最重要的是PostScript字型,
使用者可以透過PostScript技術調整某些參數,而改變字型的大小,
陰影/立體/空心/粗細等特殊效果, 由於PostScript在印刷方面卓越表現,
目前世界上主要的文獻幾乎多是以PostScript的形式出現。目前常見的中文列印方案都是產生 Postscript 後,
再進行列印。產生的檔案又可分為內嵌(bg5ps、enscript、cnprint)
與不內嵌字型(truetype、cid font),
目前的解決方案偏向於使用 CID-Keyed font。CID-Keyed font,CID是Character ID的簡稱。CID字形格式的設計主要是為了各種PostScript輸出設備,
ATM(Adobe Type Manager)軟體,
CPSI(Configurable PostScript Interpreter)解譯器及
DPS(Display PostScript)顯示型PostScript軟體等,
能使用於大字庫字體集,特別是台灣、大陸、日本、韓國
等雙位元語系的國家文字。 CJK(Chinese , Japan , Korean)字集上日、韓二國文字,
除了平假名、片假名及韓文字外,佔最多字體容量的還是漢字部份,
而且中、日、韓的漢字很多都是相同的漢字,如果一套CJK字集能包括
Big5、GB、JIS及KSC碼的所有的字形、
容量一定比四種碼位分開的字形少30%以上,而且可以不用擔心,
以後從以上四個地區來的文件,輸出時沒有對應的字形輸出。 在1990年Adobe發表可以支援雙位元架構的PostScript字形格式,
一般我們通稱為OCF(Original Composite Font)格式,
它使用比較複雜字形構造及字形儲存方式,
因為它為了要支援雙位元的字形,就必須要做成這樣複雜的架構,
像目前大家所使用的中文Type1、Type3、Type4等字形格式,
都是屬於OCF格式。 OCF字形要抓取列印一個雙位元字形時,必須要經過複雜的對應關係,
才能取得字形的外框資料去列印,所以Type1、Type3、Type4等OCF
字形的檔頭(header)描述都非常複雜,
而且每一家字形廠商都不太一樣。CID字形的架構比OCF字形就簡單多了,
直接由CMap檔案去對應字形外框資料,
所以解譯器能快速的取得及解譯字形的外框資料及列印,
而且比較節省記憶體的使用。Character Collection(字形集)及CMap File(對應檔)這二者Adobe
有定義標準格式,字形廠商可以使用Adobe的標準格式,
以繁體中文為例,Adobe定義一個Character Collection,
和很多個的CMap File,如Adobe-CNS1-0,B5-H,B5pc-H,ETen-B5-H
等不同的CMap file。 不同的CMap file使用於不同的內碼系統,
如果這些內碼系統的字碼有擴充時,只要增加新的CMap file及CID
字形即可,可以不影響到原來的CMap file及CID字形檔。 WWW:
cid faqs at arphicWWW:
Fonts / Type / OpenType使用 TrueType 字型當作是 CID fontsgs-cjk 是一個讓 Aladdin/Artifex/GNU ghostscript(gs)
能夠使用 CJK 功能的發展計畫。在這個網站中,所提供的程式集,
包含讓 gs 能夠把 CJK ( 繁、簡中文,日文,韓文 )
的 TrueType 字型當作 CID-Keyed 的字型來處理的必要修補檔案( patch),
以及改進在 gs CID-Keyed 字型的handler。該計畫已經整合到 ghostscript7CID-Keyed font 由 CID font 和 CMap 所組成,
使用前記得安裝 print/adobe-cmap
。使用 ghostscript 來列印文件:
&prompt.root; gs -sDEVICE=cdj550 -sOutputFile=/dev/lpt0 xx.psgs --help 會有更多的選項以此套件搭配 arphicttf 就可以讓大部分的軟體可以透過
gs 讀取 ttf 來產生正確的 gs 檔。
- 以下是利用 ttfm 來將 arphicttf 的字型加入 gs-cjk 的列表:
+ 以下是利用 chinese/ttfm 來將 arphicttf 的字型加入 gs-cjk 的列表:
&prompt.root; ttfm.sh --add gs-cjk bkai00mp.ttf
&prompt.root; ttfm.sh --add gs-cjk bsmi00lp.ttf這樣會分別產生常用的 CID-Keyed:ShanHeiSun-Light-Eten-B5-H 以及
ZenKai-Medium-Eten-B5-H 以供需要列印的軟體使用,例如
Mozilla、KDE等。WWW:
Ghostscript, Ghostview and GSviewWWW:
gs-cjk projectmoefonts-cid - 由 Adobe 轉譯的 MOE CID FontCID-Keyed font 由 CID font 和 CMap 所組成,
CMap 可以透過安裝
print/adobe-cmaps 來達成,
而 CID font 則必須另外安裝。
中文 CID font(MOEKai 和 MOESung) 是從教育部而來的,
原本為 48x48 點陣字型,由 Adobe 製作成 CID font。安裝 chinese/moefonts-cid。自行安裝的話,CID-Keyed font 可以從
ftp://ftp.oreilly.com/pub/examples/nutshell/cjkv/adobe/samples/
取得 MOEKai-Regular MOESung-Regular 這兩個 CIDFont,並在
ftp://ftp.oreilly.com/pub/examples/nutshell/cjkv/adobe/
取得 ac14.tar.Z,裡面包含了 Adobe-CNS1 的 CMap 檔案。裝完後就有如下的 CID-Keyed font 可以使用:
MOEKai-Regular-ETen-B5-H
MOEKai-Regular-ETen-B5-V
MOESung-Regular-ETen-B5-H
MOESung-Regular-ETen-B5-V以下是一個測試的範例:
&prompt.user; cat cid.ps
/MOEKai-Regular-ETen-B5-H findfont 60 scalefont setfont
50 600 moveto (眾裡尋他千百度) show
50 520 moveto (驀然回首) show
50 440 moveto (那人卻在燈火欄珊處) show
showpage
quit
&prompt.user; gv -antialias cid.ps
&prompt.user; ps2ps cid.ps cid2.ps
&prompt.user; ps2pdf cid.ps
&prompt.user; ps2pdf cid2.ps
&prompt.user; xpdf cid.pdf (可能不行)
&prompt.user; xpdf cid2.pdfcid-gv snapshot
- 目前已經可以由 ttfm 搭配
+ 目前已經可以由 chinese/ttfm 搭配
gs-cjk
的方式來取代,而且效果更好。以下是以 MOESung-Regular 為例子,來增加粗體、斜體、粗斜體支援,
在安裝時,由於必須額外安裝 adobe-cmaps 來搭配,
所以會 DEPENDS print/adobe-cmaps。再來是建立粗體,斜體,粗斜體等,在看完 ttfm 的 gs-cjk 模組後,
有個想法就是 gs-cjk 的做法是在 ttf 上面建立粗體,斜體,粗斜體等,
這些做法是不是應該也適用於 moefonts-cid?因此就建立了 MOESung-Regular-Bold
%!PS-Adobe-3.0 Resource-CIDFont
%%BeginResource: CIDFont (MOESung-Regular-Bold)
/MOESung-Regular-Bold
/MOESung-Regular /CIDFont findresource
16 dict begin
/basecidfont exch def
/basefont-H /.basefont-H /Identity-H [ basecidfont ] composefont def
/basefont-V /.basefont-V /Identity-V [ basecidfont ] composefont def
/CIDFontName dup basecidfont exch get def
/CIDFontType 1 def
/CIDSystemInfo dup basecidfont exch get def
/FontInfo dup basecidfont exch get def
/FontMatrix [ 1 0 0 1 0 0 ] def
/FontBBox [
basecidfont /FontBBox get cvx exec
4 2 roll basecidfont /FontMatrix get transform
4 2 roll basecidfont /FontMatrix get transform
] def
/cid 2 string def
/BuildGlyph {
gsave
exch begin
dup 256 idiv cid exch 0 exch put
256 mod cid exch 1 exch put
rootfont /WMode known { rootfont /WMode get 1 eq } { false } ifelse
{ basefont-V } { basefont-H } ifelse setfont
.03 setlinewidth 1 setlinejoin
newpath
0 0 moveto cid false charpath stroke
0 0 moveto cid show
currentpoint setcharwidth
end
grestore
} bind def
currentdict
end
/CIDFont defineresource pop
%%EndResource
%%EOF以及 MOESung-Regular-Bold-ETen-B5-H.gsf
/MOESung-Regular-Bold-ETen-B5-H
/MOESung-Regular-Bold (MOESung-Regular-Bold)
/ETen-B5-H (CMap/ETen-B5-H)
1 index /CMap resourcestatus
{pop pop pop}
{runlibfile} ifelse
/CMap findresource
3 1 roll
1 index /CIDFont resourcestatus
{pop pop pop}
{runlibfile} ifelse
/CIDFont findresource
[ exch ] composefont pop 結果發現在測試檔 cid.ps
/MOESung-Regular-ETen-B5-H findfont 30 scalefont setfont
50 600 moveto (2000年5月29日) show
/MOESung-Regular-Bold-ETen-B5-H findfont 30 scalefont setfont
50 560 moveto (2000年5月29日) show
/MOESung-Regular-Italic-ETen-B5-H findfont 30 scalefont setfont
50 520 moveto (2000年5月29日) show
/MOESung-Regular-BoldItalic-ETen-B5-H findfont 30 scalefont setfont
50 480 moveto (2000年5月29日) show
/MOEKai-Regular-ETen-B5-H findfont 30 scalefont setfont
50 440 moveto (2000年5月29日) show
/MOEKai-Regular-Bold-ETen-B5-H findfont 30 scalefont setfont
50 400 moveto (2000年5月29日) show
/MOEKai-Regular-Italic-ETen-B5-H findfont 30 scalefont setfont
50 360 moveto (2000年5月29日) show
/MOEKai-Regular-BoldItalic-ETen-B5-H findfont 30 scalefont setfont
50 320 moveto (2000年5月29日) show
showpage
quit粗體的部分出現了預期的效果,所以就繼續製作斜體與粗斜體,
這部分可以參考 gs-cjk,斜體的名稱定為 MOESung-Regular-Italic,
而粗斜體則是 MOESung-Regular-BoldItalic。最後,記得把這些 .gsf 寫入
/usr/local/share/ghostscript/7.05/lib/Fontmap.GS
寫法是:字型 (字型.gsf) ;
/MOESung-Regular-ETen-B5-H (MOESung-Regular-ETen-B5-H.gsf) ;
/MOESung-Regular-Bold-ETen-B5-H (MOESung-Regular-Bold-ETen-B5-H.gsf) ;
/MOESung-Regular-BoldItalic-ETen-B5-H (MOESung-Regular-BoldItalic-ETen-B5-H.gsf) ;
/MOESung-Regular-Italic-ETen-B5-H (MOESung-Regular-Italic-ETen-B5-H.gsf) ;最後修改一下 -H 成 -V 再重複上面的過程即可,
其他的字型也是幾乎一樣的做法就可以完工了,
不過,真的比不上用 ttf 做出來的呀如此建立完,就會有一堆可用的 CID-Keyed 字型
MOESung-Regular-ETen-B5-H
MOESung-Regular-Bold-ETen-B5-H
MOESung-Regular-BoldItalic-ETen-B5-H
MOESung-Regular-Italic-ETen-B5-H這樣子在配合文書軟體上,應該會更好,
我想文書軟體慢慢的也會把列印的部分用
gs 所提供的字型來模擬,像是 editors/Abiword 就是個很棒的例子,
而 kde2 則是自己做粗體,斜體等的模擬,
不過我還沒去測試到粗體和斜體的部分,
等有空閒了再去試試。moefonts-cid snapshot以 gs 觀看不內嵌的 pdf 檔gs/gv 有個 dirty hack,就是看到
name type emb sub uni object ID
------------------------------------ ------------ --- --- --- ---------
國字標準宋體 CID TrueType no no no 22 0這種類型的不內嵌字,就自己到
/usr/local/share/ghostscript/7.05/lib/CIDFnmap
中加上 alias,以我而言會加上文鼎上海宋的 alias:
/國字標準宋體 /ShanHeiSun-Light ;李果正 Edward G.J. Lee 也提出比較正式的解法如下:
昨天玩了一下 gs。發現可能不必這麼麻煩,因為 CJK-latex + dvipdfmix
製作出來的不內嵌中文 PDF 檔,頗合 PDF-spec。雖然,pdffonts 看到的是:
name type emb sub uni object ID
------------------------------------ ------------ --- --- --- ---------
國字標準宋體 CID TrueType no no no 22 0但其實 PDF 檔裡頭會標記成 Adobe-CNS1,也就是說會去使用 PDF browser
Adobe-CNS1 的預設字型,例如:
34 0 obj
<<
/Type/Font
/Subtype/CIDFontType2
/BaseFont/#b0#ea#a6r#bc#d0#b7#c7#a7#ba#c5#e9,Italic
/FontDescriptor 35 0 R
/CIDSystemInfo<<
/Registry(Adobe)
/Ordering(CNS1)
/Supplement 0
>>
>>
endobj以此 object 為例。其中 # 是代表 hex notation,
那一堆就是『國字標準宋體』,
後面會有 /Registry(Adobe) /Ordering(CNS1),因此,只要 gs 的
CIDFnmap 設成:
/Adobe-CNS1 /ShanHeiSun-Light ;就可以了,也就是說,不管 PDF 使用什麼字型,如果找不到此字型,
就會使用預設的 (Adobe-CNS1)ShanHeiSun-Light。
這樣就不必遇到沒有的字型就得去加入 alias。
而 acroread 也會去找他的預設字型 MHei-Medium 或 MSung-Light
(視 acroread 如何設定,設成 sans 則取用黑體,設成 serif
則取用宋體)。為防意外,建議以下兩行也加入:
/Adobe-CNS1-Big5 /ShanHeiSun-Light ;
/Adobe-CNS1-Unicode /ShanHeiSun-Light ;這樣一來,列印的問題也解決了。pdf2ps(pswrite device) 時 gs 會去取用
ShanHeiSun-Light。當然,前提是 /usr/share/ghostscript/Resource 要把
ShanHeiSun-Light 預先設定好。TrueType - 全真字型概論TrueType字型格式為美國Apple (
http://www.apple.com)及Microsoft (
http://www.microsoft.com
)所共同制定,最先使用於Apple的Macintosh系列及
Microsoft Windows 3.1, 而目前Apple的OS 8.0及
Microsoft Windows 95/NT/2000/XP也都使用
TrueType作為字型格式。基本上TrueType和PostScript一樣,都是使用貝茲曲線(Bezier Curve)
來描述的外框字。 字型可以作任意尺寸的放大縮小,
或作其他屬性的變化,不過由於Apple及Microsoft
的作業系統都直接支援此字型格式,所以並不需要如PostScript
一樣,外掛(Adobe)Type Manager之類的程式。 WWW:
Features of TrueType and OpenTypettfm - TrueType 字型管理工具目前有許多程式都會要求使用 TTF 字型,所以我們最好還是幫 X 加
上中文的 TTF 字型支援。目前安裝字型所需的
fonts.dir 已經不需要
- 使用暴力的方法產生,使用 ttfm
+ 使用暴力的方法產生,使用 chinese/ttfm
就可以很順利的管理所有的中文字
- 型了。而現在在 ports 中的 TrueType 字型有三套,
+ 型了。而現在在 ports 中的 TrueType 字型有七套,
+ arnettf、
arphicttf、
+ dfsongsd、
+ fireflyttf、
+ mingunittf、
moettf、
- wangttf。
+ wqy。
安裝 chinese/ttfm。安裝後包含了:ttfinfo:一個可以用來讀取 ttf
字型格式資訊的小程式,範例如下:
&prompt.root; ttfinfo /usr/local/share/fonts/TrueType/bkai00mp.ttf
TTFINFO_FONT_FILE="/usr/local/share/fonts/TrueType/bkai00mp.ttf"
TTFINFO_FONT_NAME="AR PL KaitiM Big5"
TTFINFO_FONT_PSNAME="ZenKai-Medium"
TTFINFO_FOUNDRY_NAME="Arphic"
TTFINFO_WEIGHT_NAME="medium"
TTFINFO_WIDTH="normal"
TTFINFO_NUMCMAP="2"
TTFINFO_CMAP0="1,0"
TTFINFO_CMAPNAME0="Apple,Roman"
TTFINFO_CMAP1="3,1"
TTFINFO_CMAPNAME1="Windows,Unicode"
TTFINFO_MAPNUM="1"
TTFINFO_FONTMAP1="-Arphic-AR PL KaitiM Big5-medium-r-normal--0-0-0-0-c-0-big5-0"ttfinst.tk:圖形介面的 tk script,
可以用來安裝字型,不建議使用。ttfm.sh:shell script,預備作為 ttf 字型總管。
&prompt.root; ttfm.sh --help
True-Type Font Manager 0.9.3
Usage: /usr/local/bin/ttfm.sh [option]
--add [module] <file>... install ttf font
--remove [module] <file>... remove ttf font from the system
--list <module>... list all ttf fonts on the system
--modules list all ttf manager modules on the system
--initm <module>.. initialize modules
--help show this info這個程式會去利用位於
/usr/share/fonts/install/ 底下以
".ttfm" 結尾的可執行檔來安裝、設定字型,
這些 .ttfm 檔案我稱
為 ttfm module,由需要使用到 ttf 字型的程式提供,這些模組必
須符合以下要求:
可獨立使用,不一定透過 ttfm.sh 呼叫執行。
不對系統字型目錄有任何預設,只管理自己模組字型目錄下的檔案。
對 ttf 檔案位置需求不同於 ttfm.sh
中的系統字型目錄時,以
link 方式處理,不 copy ttf 檔案,移除字型時不更動系統字型目
錄中的檔案。
提供至少下面幾個參數供 ttfm.sh 使用:
--name 顯示模組名稱
--list 列出模組管理的現有字型與對應的名稱
--add <file> 增加字型,file 為一字型檔案名稱,如
/mnt/windows/fonts/mingliu.ttc
--remove <file> 移除字型,file 為字型檔案名稱,可以是
fullpath、亦可以是單純檔案名,如
/usr/local/share/fonts/TrueType/bkai00mp.ttf or bkai00mp.ttf
- ttfm 採用模組化的設計。
+ chinese/ttfm 採用模組化的設計。
每一個需要使用到 ttf 字型的
- 程式都可以提供 ttfm 的模組,
+ 程式都可以提供 chinese/ttfm 的模組,
然後便可透過 ttfm.sh 來做到
字型的安裝,移除,列表,設定預設字型等管理的動作。
- 目前已有的 ttfm 模組有:
+ 目前已有的 chinese/ttfm 模組有:
abiword 給 AbiWord 0.7.12 或是以上的版本使用。
chitex 安裝 ChiTeX 字型 (by cwhuang)
gscjk 給 Aladdin Ghostscript 使用。可以管理 TrueType 字型
和 CID 字型,Ghostscript 必須修補可以使用 TrueType 字型。
ttf2pk 供 freetype-contrib 的 ttf2tfm, ttf2pk 使用 (by cwhuang)
xfreetype 給 XFree86's freetype backend,在 3.x 是 Xfsft,
在 4.x 是 freetype 模組。
xttfm-tcl 給 XFree86 3.3.x X-TrueType server。
xttfm 安裝給 X window 用的 font.dir, font.alias (by 小虫)一些使用範例:1. 加入字型:
&prompt.root; ttfm.sh --add <path>/bsmi00lp.ttf(xttfm 會令 xfs 重新載入字型名稱。如果您不是使用 xfs,
您要自己下 xset fp rehash
令新的字型名稱生效,或者重新啟動 X Window )2. 列出字型:
&prompt.root; ttfm.sh --list xttfm會列出 xttfm 模組所有安裝的字型。
您現在可以用 xlsfonts 看到這些字型名稱。
並可用 xfd -fn <字型名稱>
試試能否看到字型。3. 移除字型:
&prompt.root; ttfm.sh --remove bsmi00lp.ttf這不需多做解釋吧?4. 設定預設字型:
&prompt.root; ttfm.sh --setdefault xttfm bkai00mp.ttf將 xttfm 模組的預設字型更改為
- bkai00mp.ttf 這或許是 ttfm
+ bkai00mp.ttf 這或許是 chinese/ttfm
最 powerful 的功能之一了。
您可發現 X Window 預設的中文字型通通變成楷體的。注意預設字型是跟 encoding 有關的。您可以對不同的
- encoding 分別給定預設字型。ttfm
+ encoding 分別給定預設字型。chinese/ttfm
會自動根據所給定
ttf 自動判斷應設定那種 encoding 的預設字型。
例如 ttfm.sh --setdefault xttfm gkai00mp.ttf
會設定 GB 的預設字型為楷體。 5. 模組的初始化:
&prompt.root; ttfm.sh --initm <module name>...這個功能是用來在安裝一模組時,將系統已有的
ttf 字型通通安裝到該模組中。
如果下:
&prompt.root; ttfm.sh --initm all會令所有已安裝的模組都做初始化的動作。
(也就是將所有字型安裝到所有的模組中) 如果您撰寫了一個 ttfm 的模組,請記得在安裝時
執行 ttfm.sh --initm <您的模組名稱>關於 TrueType 字型的設定,在啟動您的 X 之前,
記得檢查 /etc/XFree86 下面有沒有
或是在 ~/.xinitrc 中加上
。
&prompt.root; cvs -d :pserver:anonymous@cle.linux.org.tw:/var/lib/CVSROOT login
(Logging in to anonymous@cle.linux.org.tw)
CVS password:
&prompt.root; cvs -d :pserver:anonymous@cle.linux.org.tw:/var/lib/CVSROOT checkout ttfmWWW:
ttfm projectmingliu - 微軟細明體 TrueType 字型Contributed by EricChengLast Update: 2003年 9月21日 周日 21時13分54秒 CSTmingliu 是微軟向華康購買的中文繁體字型,
也是 Windows 使用者最習慣的電腦字。
&prompt.root; cd /usr/ports/outta-port/mingliu
&prompt.root; make install cleanmingliu.ttc 有兩個 faces,第零個 face 是
細明體(MingLiU),英文字型是等寬的,
第一個是新細明體(PMingLiU),不等寬的英文字型,
預設會使用第零個,如果要使用新細明體的話,必須另外設定。細明體在 11, 12, 13, 15, 16, 20 點的大小有特別做內嵌的點陣字,
換句話說,由於中文字的 hinting 不易,有時點陣字會比較有效。
又因為新細明體使用了 bytecode 來組合筆劃,
沒有編進 bytecode interpreter 的 freetype 版本在 render 的時候,
就會碎掉。
在目前 ports/print/freetype2 中,預設會利用
files/patch-include::freetype::config::ftoption.h 將
TT_CONFIG_OPTION_BYTECODE_INTERPRETER 打開。設定讓細明體在這些大小時,顯示內建的點陣字而不要用 anti-aliased,
在 ~/.fonts.conf 加入:
<match target="font">
<test name="family"><string>MingLiU</string></test>
<edit name="antialias"><bool>true</bool></edit>
<edit name="hinting"><bool>true</bool></edit>
<edit name="autohint"><bool>false</bool></edit>
</match>
<match target="font">
<test name="family"><string>MingLiU</string></test>
<test name="size" compare="less_eq"><int>12</int></test>
<edit name="antialias" mode="assign"><bool>false</bool></edit>
<edit name="hinting" mode="assign"><bool>true</bool></edit>
</match>因為 MingLiU 宣稱自己是 monospaced 字型,
但實際上它有兩種固定寬度:中文的全形以及英文的半形,
造成 freetype 誤判所有字都是跟中文的全形一樣寬,
使得英文字和中文字會等寬。可以修改 freetype 的 globaladvance flag 或是 spacing,
0 是 proportional 的 spacing,100 是 mono,110 是 charcell:
<match target="font">
<test name="family"><string>MingLiU</string></test>
<edit name="globaladvance"><bool>false</bool></edit>
</match>
<match target="font">
<test name="family"><string>MingLiU</string></test>
<edit name="spacing"><int>0</int></edit>
</match>記得在 ~/.fonts.conf 的頭尾加上
<?xml version="1.0"?>
<!DOCTYPE fontconfig SYSTEM "fonts.dtd">
<fontconfig>
...
</fontconfig>在 X11 Core Font 上,則是利用 xtt 的功能來選取 Face 1 的
PMingLiU 來顯示,也就是在最前面加上 fn=1,並檢查
Spacing 欄位是否為 p,MingLiU 的 Spacing 欄位是 m。
如果安裝 chinese/ttfm 會自動加入兩個 face。
mingliu.ttc -DynaLab-MingLiU-medium-r-normal--0-0-0-0-m-0-iso8859-1
fn=1:mingliu.ttc -DynaLab-PMingLiU-medium-r-normal--0-0-0-0-p-0-iso8859-1WWW:
EricCheng Fontconfigsimsun - 微軟宋體 TrueType 字型simsun 是微軟向 ZHONGYI Electronic Co. 購買的中文簡體字型,
也是 Windows 使用者最習慣的電腦字。
&prompt.root; cd /usr/ports/outta-port/simsun
&prompt.root; make install cleansimsun.ttc 有兩個 faces,第零個 face 是
SimSun,英文字型是不等寬的,
第一個是NSimSun,等寬的英文字型,
預設會使用第零個,如果要使用NSimSun的話,必須另外設定。因為 NSimSun 宣稱自己是 monospaced 字型,
但實際上它有兩種固定寬度:中文的全形以及英文的半形,
造成 freetype 誤判所有字都是跟中文的全形一樣寬,
使得英文字和中文字會等寬。可以修改 freetype 的 globaladvance flag 或是 spacing,
0 是 proportional 的 spacing,100 是 mono,110 是 charcell:
<match target="font">
<test name="family"><string>NSimSun</string></test>
<edit name="globaladvance"><bool>false</bool></edit>
</match>
<match target="font">
<test name="family"><string>NSimSun</string></test>
<edit name="spacing"><int>0</int></edit>
</match>記得在 ~/.fonts.conf 的頭尾加上
<?xml version="1.0"?>
<!DOCTYPE fontconfig SYSTEM "fonts.dtd">
<fontconfig>
...
</fontconfig>若要使用等寬的 NSimSun,在 X11 Core Font 上,
則是 xtt 的功能來選取 Face 1 的
NSimSun 來顯示,也就是在最前面加上 fn=1,並檢查
Spacing 欄位是否為 m,SimSun 的 Spacing 欄位是 p。
如果安裝 chinese/ttfm 會自動加入兩個 face。
simsun.ttc -misc-SimSun-medium-r-normal--0-0-0-0-p-0-iso8859-1
fn=1:simsun.ttc -misc-NSimSun-medium-r-normal--0-0-0-0-m-0-iso8859-1mingunittf - 香港補增字符集2001mingunittf 包含了香港補增字符集2001的所有字。mingunittf 的安裝:
&prompt.root; cd /usr/ports/outta-port/mingunittf
&prompt.root; make install clean由於搭配 ttfm 的 xttfm 模組,因此在 XF86Config
裡面一定要 才行。moettf - 台灣教育部標準 TrueType 字型moettf 台灣教育部標準楷書、宋體
ttf 字形檔,現在又加了兩個字型
moe_sungext.ttf 和
moe_sungsym.ttf,雖然字型是 BIG5 編碼,
字元和符號在 CNS 中還是偶而會用到。安裝 chinese/moettf。以下按照年代說明
85.12.03 國字標準字體楷書母稿
85.12.03 國字標準字體宋體母稿
85.12.05 國字方體母稿這時 Wukai 從教育部的標準字體轉成兩個 ttf,
http://bbs.ee.ntu.edu.tw/boards/Linux/7/8/4.html
,也就是第一版的 moe_kai.ttf 與 moe_sung.ttf,
moe_sung 的字數是 13865,moe_kai 的字數是 13849 少了幾個特別複雜的字,
這是教育部原始提供的字面母稿的少了的,不是轉換過程中 lost 掉的。
87.12.28 國字隸書母稿
88.05.20 國字標準字體宋體母稿增補編這兩個就是後來增加的 edustd-15.exe、edustds1.exe、edustds2.exe,
也就是後來的第二版。
92.02 教育部楷書字形檔這個則是最近新增的檔案,品質比楷書母稿好很多,
有 Big5 和 Unicode 版。當然有機會取代原 moe_kai.ttf,
不過還需要比較字數等可能問題。總結:目前在 ports/chinese/moettf 中有五個檔案,方別是
2059101 edustd-15.exe 教育部隸書字形檔[註1]
1971355 edustds1.exe 教育部標宋體增補編字形檔[註2]
139950 edustds2.exe 教育部標宋體增補編字形檔[註2]
9194491 moe_kai.ttf 國字標準字體楷書母稿[註3]
8647174 moe_sung.ttf 國字標準字體宋體母稿[註3]
[註1] http://www.edu.tw/mandr/allbook/lishu/lishu.htm
[註2] http://www.edu.tw/mandr/result/5879/5879.html
[註3] http://www.edu.tw/mandr/bbs/1-4-2/ksf.html但是在教育部楷書字形檔[註4],看到三個不同的楷書字型?
13842688 kai-pc.ttf PC 版(92.2) Windows 系統適用
13837924 kai-linux.ttf Linux 版(92.2) Linux作業環境適用
9300584 ct.sit MAC 版(92.2) APPLE電腦適用
[註4] http://www.edu.tw/mandr/bbs/1-4-2/kai.htmmoettf snapshotWWW:
教育部國字標準字體公告arphicttf - 文鼎科技 TrueType 字型arphicttf 是由文鼎科技提供,
包含文鼎PL細上海宋,文鼎PL中楷
(BIG-5碼)和文鼎PL簡報宋、文鼎PL簡中楷(GB碼)。它可以被用來
作為 X Window 系統或是排版軟體例如
CJK。感謝文鼎科技,您可以
在 GPL-base 版權下自由散佈這些高品質的字型。
ARPHIC_*.TXT 有更詳細的文件。盡量避免使用文鼎PL細上海宋於教育用途,
該字型有許多字的字形會造成教育用途上的誤導,
為了避免誤人子弟,盡可能的不要使用該字體。
其中細上海宋的部份是採用對岸的慣用的繁體寫法,和台灣的寫法並不相同,
最顯著的例子是『角』,中間的『土』中間是縱穿的,
大家可以和 MS 的新細明比較便可知道。但中楷的部份則無此情形。
因此,提醒大家,如果是用在學校、公務單位,或家裡有在學子弟在使用的話,
建議盡量避免使用細上海宋,改採中楷,或另行購置台灣通用的字型。
能保留中文繁體的正體寫法的國家,大概就只剩台灣了,
請大家好好愛護我們的珍貴文化遺產。
還有一些台灣繁體與大陸繁體的寫法差異,
「骨」、「體」、「過」字等等,「┌」那兩劃被簡化成一劃,變成「┐」。
草花頭:台灣標準寫法是 「十十」,大陸標準寫法是「廾」(四劃 --> 三劃)。
「吳」字,大陸標準寫法是「口天」,「娛、誤」等字同例。
「充」字,台灣五劃 (橫ㄙ),香港和大陸六劃 (點橫ㄙ)。
「這」字部首,台灣四劃 (點3捺),大陸三劃 (點7捺)。
「以」字,台灣五劃,大陸四劃 (最左邊的兩劃連筆)。安裝 chinese/arphicttf。以下表格式整理過後的文鼎字體速查表,
會有兩個 Font Family 是因為英文的是
的資訊,常用於 gtk2 等字型設定,
中文的則是
的資訊,通常是 utf8 編碼,常用於 openoffice 的字型設定,
Font Family, Unique subfamily identification, Full name
的資訊通常都會相同。