diff --git a/mn_MN.UTF-8/books/handbook/cutting-edge/chapter.xml b/mn_MN.UTF-8/books/handbook/cutting-edge/chapter.xml
index 61446d6846..4b9b537a3e 100644
--- a/mn_MN.UTF-8/books/handbook/cutting-edge/chapter.xml
+++ b/mn_MN.UTF-8/books/handbook/cutting-edge/chapter.xml
@@ -1,3027 +1,2970 @@
Жим
Мок
Бүтцийг дахин өөрчлөн зохион байгуулж зарим х��гүүдийг шин�чил��н
Жордан
Хаббард
�нхлан �хийг бич��н
Поул-Х�ннинг
Камп
Жон
Пол�тра
�ик
Кл�йтон
Цагаанхүүгийн
Ганболд
Орчуул�ан
&os;-г шин�чилж �айжруулах нь
Ерөнхий агуулга
&os; нь өөрийн хувилбаруудын хооронд байнгын хөгжүүл�лтийн доор оршин тогтнож
байдаг. Зарим хүмүү� албан ё�оор гарга�ан хувилбаруудыг ашиглах хү��лт�й
байдаг бол зарим хүмүү� хамгийн �үүлийн үеийн хөгжүүл�лтийг дагах �онирхолтой
байдаг. Г�хд�� албан ё�ны хувилбарууд хүрт�л аюулгүй байдлын болоод бу�ад
чухал за�варуудаар шин�чл�гд�ж байдаг. Ямар хувилбар ашиглаж байгаагаа� үл
хамаараад &os; нь таны �и�темийг шин� байлгахад шаардлагатай бүх л х�р�г�лүүд
болон хувилбар хооронд х�лбараар шин�чл�х боломжоор хангадаг.
ÐнÑ�Ñ…Ò¯Ò¯ бүлÑ�г нь хөгжүүлÑ�лтийн Ñ�иÑ�темийг дагахыг Ñ…Ò¯Ñ�Ñ�Ñ… Ñ�Ñ�вÑ�л гаргаÑ�ан
хувилбартай үлд�х ���хийг шийд�х�д танд ту�лах болно. Таны �и�темийг шин�чл�х�д
зориул�ан үнд��н х�р�г�лүүдийг ба� харуулах болно.
ÐнÑ� бүлгийг уншÑ�аны дараа, та дараах зүйлÑ�ийг мÑ�дÑ�Ñ… болно:
Си�тем болон портын цуглуулгыг �мар х�р�г�лүүд
ашиглан шин�чилж болох талаар.
freebsd-update,
Subversion,
CVSup,
CVS, ��в�л
CTM програмуудын ту�ламжтай өөрийн �и�темийг
х�рх�н хамгийн �үүлийн х�лб�рт авчрах талаар.
Суулгагд�ан �и�темийн төлвийг м�д�гд�ж байгаа �айн хуулбартай
х�рх�н харьцуулах талаар.
Subversion ��в�л баримтжуулах порт ашиглан өөрийн баримтуудыг
х�рх�н �үүлийн хувилбарт байлгаж байх талаар.
&os.stable; болон &os.current; хөгжүүл�лтийн
�албаруудын �лгаа.
Бүх үнд��н �и�темийг make buildworld
(г�х м�т) ашиглан х�рх�н дахин бүт��ж �уулгах талаар.
ÐнÑ� бүлгийг уншихааÑ�аа өмнө, та дараах зүйлÑ�ийг мÑ�дÑ�Ñ… шаардлагатай:
Өөрийн �үлж��ний холболтыг зөв тохируулах ().
��м�лт гуравдагч програм хангамжуудыг
х�рх�н �уулгахыг м�д�х ().
ÐнÑ� бүлÑ�гт &os;-ийн Ñ�хийг авч шинÑ�члÑ�хийн тулд
svn тушаалыг ашиглагд�ан. Үүнийг х�р�гл�хийн
тулд devel/subversion
г���н порт буюу багцыг та �уулгах х�р�гт�й.
Том
Рөүд�
Бич��н
Колин
Пер�ивал
Т�мд�гл�г�� бич��н
FreeBSD-ийн шин�чл�лт
Updating and Upgrading
freebsd-update
updating-upgrading
�юулгүй байдлын за�варуудыг хийн� г�д�г компьютерийн програм
хангамж �лангу�а үйлдлийн �и�темийг арчлалтын чухал х��гийн н�г юм.
Удаан хугацааны туршид &os; д��р �н� проце�� х�лбар биш байлаа.
За�варуудыг �х код руу хийж кодыг хоёртын х�лб�р рүү дахин бүт��ж
дараа нь хоёртын файлуудыг дахин �уулгах шаардлагатай байлаа.
ÐнÑ� нь одоо тийм биш болÑ�он бөгөөд &os; нь
freebsd-update г�гдд�г х�р�г�лийг агуулдаг.
ÐнÑ� Ñ…Ñ�Ñ€Ñ�гÑ�Ñ�л нь хоёр туÑ�даа функцÑ�Ñ�Ñ€ хангадаг. Ð�Ñ�гдүгÑ�Ñ�рт Ñ�нÑ� нь
бүт��лт болон �уулгах шаардлагагүйг��р хоёртын аюулгүй байдал болон
алдааны шин�чл�лтүүдийг &os;-ийн үнд��н �и�темд оруулах боломжийг
олгодог. Хоёрдугаарт уг х�р�г��л бага болон том хувилбарын шин�чл�лтүүдийг
д�мжд�г.
�юулгүй байдлын багаар д�мжигд��н бүх архитектур болон
хувилбаруудын хувьд хоёртын шин�чл�лтүүд байдаг. Шин� хувилбар
руу шин�чл�х��� өмнө хү���н хувилбарт чинь хамаатай чухал м�д��л�л байж
болох учир одоогийн хувилбарын зарлалуудыг дахин үз�х х�р�гт�й. Т�дг��р
зарлалуудыг дараах холбоо�оо� үз�ж болно:
.
Х�р�в crontab нь freebsd-update-ийн
боломжуудыг х�р�гл�ж байвал дараах үйлдлийг �хл�х��� өмнө түүнийг болиулах
х�р�гт�й.
Тохиргооны файл
Проце��ийг илүү х�нах боломжтой болгож зарим х�р�гл�гчид
/etc/freebsd-update.conf анхны тохиргооны
файлыг өөрчлөхийг хү��ж болох юм. Тохиргоонууд нь
маш �айн баримтжуулагд�ан байдаг боловч дараах х�д�н зүйлийг
арай илүү тайлбарлах шаардлагатай байж болох юм:
# Components of the base system which should be kept updated.
Components src world kernel
ÐнÑ� өгөгдөл нь &os;-ийн аль Ñ…Ñ�Ñ�гийг шинÑ�члÑ�хийг Ñ…Ñ�надаг.
�нхдагчаар �х код, үнд��н �и�тем бүтн��р�� ба цөмийг шин�чл�х
байдаг. Бүр�лд�хүүн х��гүүд нь �уулгах �вцад байдагтай адил
байдаг бөгөөд жиш�� нь world/games г�дгийг �нд н�м�х�д
тоглоомын за�варуудыг хийх боломжийг олгоно. src/bin г�дгийг
ашиглах нь src/bin
дахь �х кодыг шин�чл�х боломжийг олгодог.
Хамгийн �айн тохиргоо бол үүнийг анхдагчаар нь үлд��х бөгөөд
ту�гай зүйл� оруулж үүнийг өөрчил�нөөр х�р�гл�гчид өөр�дийн шин�чл�хийг
хү���н зүйл болгоноо жаг�ааж оруулах шаардлагатай болно. Инг��н��р
�х код болон хоёртын файлуудын хоорондох у�лдаа алдагдаж гамшигт
үр дагаварт хүрг�ж болно.
# Paths which start with anything matching an entry in an IgnorePaths
# statement will be ignored.
IgnorePaths
/bin ��в�л
/sbin з�р�г замуудыг
н�мж �дг��р ту�гай �ангуудыг шин�чл�х проце��ийн �вцад
оролдохгүй орхиж болно. ÐнÑ� тохиргоо нь
freebsd-update локал өөрчлөлтүүдийг
дарж бичих��� хамгаалахад х�р�гл�ж болно.
# Paths which start with anything matching an entry in an UpdateIfUnmodified
# statement will only be updated if the contents of the file have not been
# modified by the user (unless changes are merged; see below).
UpdateIfUnmodified /etc/ /var/ /root/ /.cshrc /.profile
Заагд�ан �ангууд дахь тохиргооны файлууд өөрчлөгдөөгүй
тохиолдолд шин�чилн�. Х�р�гл�гчийн хий��н өөрчлөлтүүд �дг��р
файлуудын автомат шин�чл�лтийг хүчингүй болгоно.
freebsd-update-г нийлүүл�х �вцад
өөрчлөлтүүдийг хадгалахыг тушаах KeepModifiedMetadata
г���н өөр н�г тохиргоо байдаг.
# When upgrading to a new &os; release, files which match MergeChanges
# will have any local changes merged into the version from the new release.
MergeChanges /etc/ /var/named/etc/
freebsd-update-ийн нийлүүл�хийг оролдох
тохиргооны файлуудтай �ангуудын жаг�аалт. Файл нийлүүл�х проце�� нь
цөөн тохиргоотой &man.mergemaster.8;-тай тө�т�й &man.diff.1; за�варууд
бөгөөд нийлүүл�лтийг ��в�л хүл��н авах юм уу ��в�л за�варлагч н��ж ��в�л
freebsd-update ажиллагаагаа зогÑ�оох болно. ÐргÑ�лзÑ�ж
байвал /etc �анг нөөцөлж аваад
нийлүүл�лтүүдийг хүл��н авах х�р�гт�й. mergemaster тушаалын
талаар д�лг�р�нгүй м�д��ллийг -� үзн� үү.
# Directory in which to store downloaded updates and temporary
# files used by &os; Update.
# WorkDir /var/db/freebsd-update
ÐнÑ� Ñ�ан нь бүх заÑ�варууд болон түр зуурын файлууд байх Ñ�ан
юм. Х�р�гл�гч хувилбар шин�чл�лт хийж байвал �н� байрлал нь хамгийн
багаар бодоход гигабайт ди�кийн зайтай байх шаардлагатай.
# When upgrading between releases, should the list of Components be
# read strictly (StrictComponents yes) or merely as a list of components
# which *might* be installed of which &os; Update should figure out
# which actually are installed and upgrade those (StrictComponents no)?
# StrictComponents no
yes г�ж тохируул�ан үед
freebsd-update нь Components буюу
бүр�лд�хүүн х��гүүдийн жаг�аалт бүр�н г�ж тооцох бөгөөд жаг�аалтаа� гадна өөрчлөлт
хийхийг оролдохгүй. freebsd-update нь
Components-ийн жаг�аалтад хамаарах файл
бүрийг шин�чл�хийг оролдох болно.
�юулгүй байдлын за�варууд
�юулгүй байдлын за�варууд нь ал�ын машин д��р хадгалагддаг
бөгөөд дараах тушаал ашиглан татан авч �уулгаж болно:
&prompt.root; freebsd-update fetch
&prompt.root; freebsd-update install
Х�р�в цөмийн �мар н�г за�вар хийгд��н бол �и�темийг дахин
ачаалах х�р�гт�й. Х�р�в бүгд зөв �вагд�ан бол �и�тем нь за�вар хийгд��н
байх ё�той бөгөөд freebsd-update-ийг
&man.cron.8; ажлааÑ� шөнө бүр ажиллуулж болно. ÐнÑ� ажлыг хийхÑ�д
дараах мөрийг /etc/crontab-д хийх�д
хангалттай байх болно:
@daily root freebsd-update cron
ÐнÑ� мөр нь өдөр бүр freebsd-update Ñ…Ñ�Ñ€Ñ�гÑ�лийг
ажиллуулахыг зааж байна. Ийм аргаар -ий н�м�лт
өгөгдлийг ашиглан freebsd-update нь зөвхөн
шин�чл�лт байгаа ���хийг шалгах болно. Х�р�в за�варууд байвал т�дг��рийг
автоматаар ди�к рүү татаж авах бөгөөд г�хд�� за�варуудыг хийхгүй.
root х�р�гл�гч рүү захиа илг��гд�х бөгөөд
дараа нь т�д гараар �уулгаж болох юм.
Х�р�в �мар н�г зүйл буруу болбол freebsd-update нь
дараах тушаалаар �үүлийн өөрчлөлтүүдийг буцаах чадвартай байдаг:
&prompt.root; freebsd-update rollback
Дуу��аны дараа цөм ��в�л цөмийн модулиуд өөрчлөгд�өн бол
Ñ�иÑ�темийг дахин Ñ�хлүүлÑ�Ñ… Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� нь шинÑ� хоёртын файлуудыг Ñ�анах
ой руу дуудах боломжийг &os;-д олгоно.
freebsd-update х�р�г��л нь автоматаар
зөвхөн GENERIC цөмийг шин�чилж чаддаг.
Х�р�в өөрчлөн тохируул�ан цөм ашиглагдаж байвал freebsd-update нь
шин�чл�лтийг хийж дуу��аны дараа цөмийг дахин бүт��ж �уулгах шаардлагатай.
Г�хд�� freebsd-update нь /boot/GENERIC (х�р�в байгаа бол)
дахь GENERIC цөмийг �и�темийн тухайн үеийн (ажиллаж байгаа)
цөм биш бай�ан ч г���н олж шин�чилд�г.
/boot/GENERIC дахь
GENERIC цөмийн хуулбарыг үрг�лж хадгалах нь ер нь зүйт�й
байдаг. ÐнÑ� нь төрөл бүрийн аÑ�уудлуудыг шинжлÑ�Ñ… болон
-т тайлбарла�ны дагуу
freebsd-update-г ашиглан
хувилбар шин�чл�лтийг хийх�д ач ту�тай байх болно.
/etc/freebsd-update.conf дахь анхдагч тохиргоо
өөрчлөгдөөгүй л бол freebsd-update шин�чл�гд��н
цөмийн �хийг бу�ад шин�чл�лтт�й цуг �уулгах болно. Дараа нь өөрийн өөрчлөн
тохируул�ан цөмийг дахин бүт��ж �уулгахдаа �нгийн �ур�ан аргаараа хийж
болно.
freebsd-update-аар түг��гд��н шин�чл�лтүүд нь
цөмт�й үрг�лж холбоотой байдаггүй. freebsd-update install
тушаалаар цөмийн �х өөрчлөгдөөгүй бол өөрийн өөрчлөн тохируул�ан цөмийг дахин
бүт��х шаардлагагүй юм. Г�хд�� freebsd-update
тушаал /usr/src/sys/conf/newvers.sh файлыг
үрг�лж шин�чл�х болно. Тухайн үеийн нөхөө�ийн түвшинг (uname -r
тушаалаа� гар�ан -p дугаараар заагд�ан) �н� файлаа�
авдаг. Өөр бу�ад юм� өөрчлөгдөөгүй бай�ан ч г���н өөрийн өөрчлөн тохируул�ан
цөмийг дахин бүт��х нь �и�темийн тухайн үеийн нөхөө�ийн түвшинг зөв гаргах
боломжийг &man.uname.1;-д олгоно. ÐнÑ� нь олон Ñ�иÑ�темийг арчилж байгаа үед
�лангу�а ач ту�тай байдаг бөгөөд инг��н��р т�р �и�темүүд д��р �уулгагд�ан
шин�чл�лтүүд�д түрг�н шуурхай үн�лг�� өгөх боломжийг олгодог.
Major ба Minor буюу Том ба Бага шин�чл�лтүүд
ÐнÑ� процеÑ�Ñ� нь ихÑ�нх гуравдагч талын прорамуудыг Ñ�вдÑ�Ñ…
хуучин обьект файлууд болон �ангуудыг у�тгах болно.
Бүх �уулгагд�ан портуудыг у�тгаж дахин �уулгах ��в�л
ports-mgmt/portupgrade
х�р�г��л ашиглан �үүлд нь шин�чл�хийг зөвлөдөг. Дараах тушаалыг
ашиглан их�нх х�р�гл�гчид те�т бүт��лтийг ажиллуулахыг хү�н�:
&prompt.root; portupgrade -af
ÐнÑ� нь бүгдийг зөв дахин Ñ�уулгах баталгаа болох юм.
BATCH орчны хувь�агчийг yes
г�ж тохируул�наар �н� проце��ийн �вцад гарч ир�х хүл��х мөрөнд
yes г�ж хариулан бүт��х проце��ийн
үед оролцох шаардлагыг үгүй болгоно.
Х�р�в өөрчлөн тохируул�ан цөм ашиглагдаж байгаа бол шин�чл�х
проце�� арай илүү ажиллагаатай. GENERIC цөмийн
хуулбар шаардлагатай бөгөөд /boot/GENERIC-д байрлуулах
шаардлагатай. Х�р�в GENERIC цөм �и�темд байхгүй
бол үүнийг доор дурд�ан аргуудын аль н�гийг ашиглан олж авч болно:
Х�р�в өөрчлөн тохируул�ан цөм зөвхөн н�г удаа бүт��гд��н бол
/boot/kernel.old дахь
цөм нь GENERIC цөм юм. ÐнÑ� Ñ�анг
/boot/GENERIC г�ж
өөрчлөхөд л болно.
Машинд физик��р хандах боломжтой г�ж тооцвол
GENERIC цөмийн хуулбарыг CD-ROM зөөвөрлөгчөө�
�уулгаж болно. Өөрийн �уулгац ди�кийг хийж дараах тушаалуудыг
ашиглана:
&prompt.root; mount /cdrom
&prompt.root; cd /cdrom/X.Y-RELEASE/kernels
&prompt.root; ./install.sh GENERIC
X.Y-RELEASE-г
өөрийн ашиглаж байгаа хувилбараар �олих х�р�гт�й. GENERIC
цөм анхдагчаар /boot/GENERIC-д �уулгагдах болно.
Д��р дурд�ан бүгдийг хийх боломжгүй бол GENERIC
цөмийг �х��� нь дахин бүт��ж �уулгаж болох юм:
&prompt.root; cd /usr/src
&prompt.root; env DESTDIR=/boot/GENERIC make kernel
&prompt.root; mv /boot/GENERIC/boot/kernel/* /boot/GENERIC
&prompt.root; rm -rf /boot/GENERIC/boot
ÐнÑ� цөмийг freebsd-update Ñ…Ñ�Ñ€Ñ�гÑ�Ñ�лд
GENERIC г�ж харуулахын тулд GENERIC
тохиргооны файлыг �мар ч тохиолдолд өөрчил�өн байх ё�гүй. Ба� �мар н�г
ту�гай �онголтуудгүйг��р (аль болох хоо�он /etc/make.conf
файлтайгаар) бүт��гд��н байх ё�тойг зөвлөдөг.
ÐнÑ� үед GENERIC цөм Ñ€Ò¯Ò¯ дахин ачаалах
шаардлагагүй юм.
Том ба бага хувилбарын шин�чл�лтүүдийг
freebsd-update тушаалд хувилбарын дугаарыг өгч
гүйц�тг�ж болно, жиш�� нь дараах тушаал &os; 8.1 руу
шин�чилн�:
&prompt.root; freebsd-update -r 8.1-RELEASE upgrade
Тушаал хүл��н ав�ны дараа freebsd-update
�и�темийг шин�чл�х�д шаардлагатай м�д��ллийг цуглуулахын тулд
тохиргооны файл болон одоогийн �и�темийг шалгана. Ямар бүр�лд�хүүн
х��гүүд илрүүл�гд��н болон �мар бүр�лд�хүүн х��гүүд илрүүл�гд��гүй
г�дгийг д�лг�ц д��р үзүүлн�. Жиш�� нь:
Looking up update.FreeBSD.org mirrors... 1 mirrors found.
Fetching metadata signature for 8.1-RELEASE from update1.FreeBSD.org... done.
Fetching metadata index... done.
Inspecting system... done.
The following components of FreeBSD seem to be installed:
kernel/smp src/base src/bin src/contrib src/crypto src/etc src/games
src/gnu src/include src/krb5 src/lib src/libexec src/release src/rescue
src/sbin src/secure src/share src/sys src/tools src/ubin src/usbin
world/base world/info world/lib32 world/manpages
The following components of FreeBSD do not seem to be installed:
kernel/generic world/catpages world/dict world/doc world/games
world/proflibs
Does this look reasonable (y/n)? y
Ðнд хүрÑ�Ñ…Ñ�д freebsd-update шинÑ�члÑ�лтÑ�д
шаардлагатай бүх файлуудыг татан авахаар оролдох болно. Зарим
тохиолдолд х�р�гл�гч��� юу �уулгах ��в�л х�рх�н цааш үрг�лжлүүл�х
талаар а�уултууд а�ууж болох юм.
Өөрчлөн тохируул�ан цөмийг ашиглаж байх үед д��рх алхам
дараахтай тө�т�й анхааруулгыг харуулах болно:
WARNING: This system is running a "MYKERNEL" kernel, which is not a
kernel configuration distributed as part of FreeBSD 8.0-RELEASE.
This kernel will not be updated: you MUST update the kernel manually
before running "/usr/sbin/freebsd-update install"
ÐнÑ� анхааруулгыг Ñ�нÑ� үед орхигдуулахад аюулгүй байдаг. ШинÑ�члÑ�гдÑ�Ñ�н
GENERIC цөм шин�чл�лтийн �вцад зав�рын алхам
болон ашиглагдах болно.
Бүх за�варууд локал �и�тем рүү татагд�аны дараа т�дг��рийг
хийж өгөх болно. Машины хурд болон ачааллаа� хамаарч �н� проце�� нь
хугацаа шаардаж болох юм. Тохиргооны файлуудыг нийлүүл�х болно.
Файл нийлүүл�гд�х юм уу ��в�л гараар нийлүүл�х�д зориулж за�варлагч
д�лг�ц д��р гарч ирч болох учир проце��ийн �н� х���г х�р�гл�гчийн
оролцоо шаардана. �мжилттай нийлүүл�лт болгоны үр дүн х�р�гл�гчид
харуулагдаж проце�� үрг�лжл�х болно. �мжилтгүй бол�он ��в�л орхигд�он
нийлүүл�лт нь проце��ийг зог�оох болно. Х�р�гл�гчид нь
/etc �ангийн нөөцийг
хийж master.passwd ��в�л
group з�р�г чухал файлуудыг гараар �үүлд нь
нийлүүл�хийг хү��ж болох юм.
Си�тем нь өөрчлөгдөөгүй байгаа бөгөөд бүх за�вар оруулалт
болон нийлүүл�лт өөр �ан дотор болж байгаа болно. Бүх за�варууд
амжилттай хийгд�ж бүх тохиргооны файлууд нийлүүл�гд�ж проце��
т�гш �вагдаж байгаа м�т �анагдвал х�р�гл�гч өөрчлөлтүүдийг хийх
х�р�гт�й.
ÐнÑ� процеÑ�Ñ� дууÑ�Ñ�аны дараа шинÑ�члÑ�лтийг дараах тушаалыг ашиглан
ди�к рүү хийж болно.
&prompt.root; freebsd-update install
Цөм болон цөмийн модулиудад Ñ�хлÑ�Ñ�д заÑ�вар хийнÑ�. ÐнÑ� үед
машиныг дахих ачаалах ё�той. Х�р�в �и�тем өөрчлөн тохируул�ан цөмөөр
ажиллаж байгаа бол цөмийг /boot/GENERIC (шин�чл�гд��н)
цөмөөр дараа нь ачаалахаар болгохын тулд &man.nextboot.8;-ийг
ашиглана:
&prompt.root; nextboot -k GENERIC
GENERIC цөмөөр ачаалахаа� өмнө (х�р�в шин�чл�гд�ж
байгаа машинд ал�аа� хандаж байгаа бол �үлж��нд холбогдон) таны �и�тем зөв ачаалахын
тулд шаардлагатай бүх драйверуудыг агуул�ан ���хийг шалгах х�р�гт�й. Ялангу�а
х�р�в өмнө нь ажиллаж бай�ан өөрчлөн тохируул�ан цөм ерөнхийдөө цөмийн модулиудаар
хангагдаж байдаг ажиллагааг өөртөө агуул�ан бол /boot/loader.conf
боломжийг ашиглан �дг��р модулиудыг GENERIC цөмд түр зуур
ачаалахаа мартуузай. Шин�чл�х проце�� бүр�н дуу�тал шаардлагагүй үйлчилг��нүүд, ди�к
болон �үлж��ний холболтууд г�х м�тийг та ба� хааж өгч болох юм.
Одоо машин шин�чл�гд��н цөмөөр ачаалагдах ё�той:
&prompt.root; shutdown -r now
Си�тем буцаж а��аны дараа freebsd-update-г
дахин �хлүүл�х х�р�гт�й. Проце��ийн төлөв хадгалагд�ан болохоор
freebsd-update �хн����� �хл�хгүй бөгөөд бүх
хуучин хуваалц�ан �ангууд болон обьект файлуудыг у�тгах болно.
ÐнÑ� шатыг үргÑ�лжлүүлÑ�хийн тулд дараах тушаалыг ажиллуулна:
&prompt.root; freebsd-update install
Сангуудын хувилбарын тоо д��шил��н ���х��� хамаарч
�уулгах гурван шатны оронд хоёр шат байж болох юм.
Бүх гуравдагч талын програм хангамжийг дахин бүт��ж дахин �уулгах
х�р�гт�й. Суулгагд�ан програм хангамж нь шин�чл�лтийн проце��ийн �вцад
у�тгагд�ан �ангуудаа� хамаарч болох учраа� �н� нь шаардлагатай юм.
ports-mgmt/portupgrade тушаалыг
үүнийг автоматжуулахад ашиглаж болох юм. ÐнÑ� процеÑ�Ñ�ийг Ñ�хлүүлÑ�хийн
тулд дараах тушаалыг х�р�гл�ж болно:
&prompt.root; portupgrade -f ruby
&prompt.root; rm /var/db/pkg/pkgdb.db
&prompt.root; portupgrade -f ruby18-bdb
&prompt.root; rm /var/db/pkg/pkgdb.db /usr/ports/INDEX-*.db
&prompt.root; portupgrade -af
Үүнийг дуу��аны дараа шин�чл�лтийн проце��ийг
freebsd-update-ийг �үүлийн удаа дуудаж
төг�гөнө. Шин�чл�лтийн проце��ийн �ул байгаа бүх зүйл�ийг гүйц��хийн
тулд дараах тушаалыг ажиллуулна:
&prompt.root; freebsd-update install
Х�р�в GENERIC цөм түр зуур ашиглагдаж бай�ан
бол өөрчлөн тохируул�ан шин� цөмийг ердийн х�вш��н аргаар одоо бүт��ж �уулгах цаг
болж��.
Машинаа &os;-ийн шин� хувилбар руу дахин ачаалах х�р�гт�й.
Проце�� дуу�лаа.
Си�темийн төлвийн харьцуулалт
freebsd-update х�р�г�лийг
&os;-ийн �уулгагд�ан хувилбарын төлвийг байгаа зөв хуулбарын
Ñ�Ñ�Ñ€Ñ�г теÑ�Ñ‚ хийхÑ�д Ñ…Ñ�Ñ€Ñ�глÑ�ж болно. ÐнÑ� Ñ�онголт нь Ñ�иÑ�темийн Ñ…Ñ�Ñ€Ñ�гÑ�лүүд
�ангууд болон тохиргооны файлуудын одоогийн хувилбаруудыг шалгадаг.
Харьцуулалтыг �хлүүл�хийн тулд дараах тушаалыг ажиллуулна:
&prompt.root; freebsd-update IDS >> outfile.ids
Тушаалын н�р IDS боловч �н� нь
�мар ч тохиолдолд security/snort з�р�г
халдлага илрүүл�гч �и�темийг �олих зориулалттай биш юм.
freebsd-update нь өгөгдлийг ди�к д��р
хадгалдаг бөгөөд түүнийг өөрчлөх боломж тодорхой юм.
kern.securelevel тохиргоог ашиглах болон
freebsd-update-ийн өгөгдлийг зөвхөн уншигдах файлын
�и�тем д��р ашиглагдаагүй тохиолдолд хадгалах нь �н� боломжийг
бага�гах боловч илүү �айн шийд�л нь �и�темийг DVD ��в�л
нууцлаг хадгал�ан гадаад USB ди�кийн төхөөрөмж з�р�г
нууцлаг ди�кт�й харьцуулах �вдал юм.
Си�тем нь одоо шалгагдах бөгөөд файлууд нь өөр�дийн
&man.sha256.1; утгуудын хамт, хувилбар дахь м�д�гд�ж байгаа �айн утгууд болон
одоо �уугд�ан байгаа утгуудын хамт х�вл�гд�н харуулагдана.
ÐнÑ� нь Ñ�агаад гаралт outfile.ids файл руу
илг��гд��н шалтгаан юм. Үүнийг нүд��р шалгахад х�т�рхий хурдан д��ш
гүйж удалгүй кон�олын буфферийг дүүрг�х болно.
ÐдгÑ�Ñ�Ñ€ мөрүүд нь баÑ� Ñ…Ñ�Ñ‚Ñ�рхий урт боловч гаралтын Ñ…Ñ�лбÑ�рийг
х�лбараар задлан �лгаж болно. Жиш�� нь хувилбарт байгаагаа� ондоо
бүх файлуудын жаг�аалтыг авахын тулд дараах тушаалыг ажиллуулна:
&prompt.root; cat outfile.ids | awk '{ print $1 }' | more
/etc/master.passwd
/etc/motd
/etc/passwd
/etc/pf.conf
ÐнÑ� гаралт нь тайрагдÑ�ан бөгөөд олон файл байгаа болно.
ÐдгÑ�Ñ�Ñ€ файлуудын зарим нь төрөлхийн өөрчлөлтүүдтÑ�й байна, жишÑ�Ñ� нь
/etc/passwd нь х�р�гл�гч �и�темд н�м�гд��н
болохоор өөрчлөгд�өн байна. Зарим тохиолдолд
freebsd-update нь шин�чил��н байж болзошгүй учир
цөмийн модулиуд з�р�г бу�ад файлууд өөр байж болох юм.
Ту�гай файлууд болон �ангуудыг ха�ахын тулд т�дг��рийг
/etc/freebsd-update.conf файлын
IDSIgnorePaths тохиргоонд н�мж өгнө.
Өмнө х�л�лц��н хувилбараа� гадна нарийн н�гт шин�чл�лтийн аргын
х���г болгон �н� �и�темийг ашиглаж болно.
Том
Рөүд�
Бич��н
Колин
Пер�ивал
Т�мд�гл�г�� бич��н
Portsnap: Портын цуглуулгыг шин�чл�х х�р�г��л
Updating and Upgrading
Portsnap
updating-upgrading
&os;-ийн үнд��н �и�тем портын цуглуулгыг ба� шин�чилд�г
&man.portsnap.8; х�р�г�лийг агуулдаг. �жиллуул�ны дараа �н� нь
ал�ын �айт руу холбогдож нууц түлхүүрийг шалгаж портын цуглуулгын шин�
хуулбарыг татан авдаг. Түлхүүр нь бүх татаж ав�ан файлууд татагдаж байхдаа
өөрчлөгдөөгүй ���хийг х�нан бүр�н бүт�н байдлыг шалгахад ашиглагддаг.
Хамгийн �үүлийн үеийн портын цуглуулгыг татаж авахын тулд дараах
тушаалыг ажиллуулна:
&prompt.root; portsnap fetch
Looking up portsnap.FreeBSD.org mirrors... 9 mirrors found.
Fetching snapshot tag from geodns-1.portsnap.FreeBSD.org... done.
Fetching snapshot metadata... done.
Updating from Tue May 22 02:12:15 CEST 2012 to Wed May 23 16:28:31 CEST 2012.
Fetching 3 metadata patches.. done.
Applying metadata patches... done.
Fetching 3 metadata files... done.
Fetching 90 patches.....10....20....30....40....50....60....70....80....90. done.
Applying patches... done.
Fetching 133 new ports or files... done.
ÐнÑ� жишÑ�Ñ� нь юу үзүүлж байна вÑ� гÑ�Ñ…Ñ�Ñ�Ñ€ &man.portsnap.8;
одоо байгаа портын өгөгдөлд х�д х�д�н за�варууд байгааг олж шалгаж байна.
ÐнÑ� нь баÑ� уг Ñ…Ñ�Ñ€Ñ�гÑ�Ñ�л өмнө нь ажиллаÑ�ныг харуулж байгаа бөгөөд
х�р�в �хний удаа ажилла�ан бол цуглуулга татагдан авагдах бай�ан
юм.
&man.portsnap.8; нь fetch үйлдлийг хийж
дуу��аны дараа локал �и�тем д��р байгаа портын цуглуулга болон дараа дараагийн
за�варуудыг шалгалтад дамжуулна. portsnap-ийг �хний удаа ажиллуулахдаа
extract-г ашиглан татан ав�ан файлуудыг �уулгаж болно:
&prompt.root; portsnap extract
/usr/ports/.cvsignore
/usr/ports/CHANGES
/usr/ports/COPYRIGHT
/usr/ports/GIDs
/usr/ports/KNOBS
/usr/ports/LEGAL
/usr/ports/MOVED
/usr/ports/Makefile
/usr/ports/Mk/bsd.apache.mk
/usr/ports/Mk/bsd.autotools.mk
/usr/ports/Mk/bsd.cmake.mk
...
�ль х�дийн �уулга�ан портын цуглуулгыг шин�чл�хд��
portsnap update тушаалыг ашиглах ё�той:
&prompt.root; portsnap update
Проце�� одоо дуу��ан бөгөөд портын цуглуулыг ашиглан
програмуудыг �уулгаж ��в�л шин�чилж болно.
fetch болон extract ��в�л
update үйлдлүүдийг доор харуул�ан шиг дараалуулан
ажиллуулж болно:
&prompt.root; portsnap fetch update
ÐнÑ� тушаал нь портын цуглуулгын Ñ�үүлийн хувилбарыг
татан авч таны машин д��р байгаа локал хувилбарыг
/usr/ports �анд
шин�чилд�г.
Баримтын цуглуулгыг шин�чл�х нь
Updating and Upgrading
Documentation
Updating and Upgrading
Үнд��н �и�тем болон портын цуглуулгаа� гадна
баримтууд нь &os; үйлдлийн �и�темийн �алшгүй х���г юм. Х�дийг��р
&os;-ийн хамгийн �үүлийн үеийн баримтын цуглуулга &os; в�б �айт д��р
үрг�лж байдаг боловч зарим х�р�гл�гчид удаан �үлж��ний холболттой ��в�л
бүр тогтмол �үлж��ний холболтгүй байж болох юм. �заар &os;-ийн хамгийн
�үүлийн үеийн баримтын цуглуулгын локал хуулбарыг арчлан хувилбар бүрт�й цуг
ирд�г баримтыг шин�чл�х х�д х�д�н арга байдаг.
Баримтыг шин�чл�хийн тулд Subversion-г ашиглах нь
&os;-ийн
баримтуудын �хийг Subversion
ашиглан авч болно. ÐнÑ� Ñ…Ñ�Ñ�Ñ�г дараах зүйлÑ�ийг
тайлбарладаг:
&os;-ийн баримтуудыг �х��� нь бүт��х�д шаардлагатай
х�р�г�лүүд, баримтын х�р�г�лүүдийг х�рх�н �уулгах
талаар.
Subversion ашиглан
/usr/doc дахь
баримтын �хийн хуулбарыг х�рх�н татаж авах талаар.
&os;-ийн баримтыг �х��� нь х�рх�н бүт��ж
/usr/share/doc дотор
�уулгах талаар.
Баримтыг бүт��х �и�темийн д�мжд�г бүт��лтийн
зарим тохируулгууд, өөрөөр х�лб�л баримтын зарим н�г
х�л д��рх орчуулгыг зөвхөн бүт��д�г тохируулгууд ��в�л
ту�гай гаралтын х�лб�ржүүл�лтийг �онгодог тохируулгууд.
Subversion болон баримтын х�р�г�лүүдийг �уулгах нь
&os;-ийн баримтыг �х��� нь бүт��х�д н�л��н олон
тооны Ñ…Ñ�Ñ€Ñ�гÑ�лүүдийг шаарддаг. ÐдгÑ�Ñ�Ñ€ Ñ…Ñ�Ñ€Ñ�гÑ�лүүд нь
&os;-ийн үнд��н �и�темийн х���г биш байдаг. Учир нь �дг��р нь
их��х�н х�мж��ний ди�кийн зай шаарддаг бөгөөд &os;-ийн бүх
х�р�гл�гчд�д х�р�гт�й байдаггүй. Т�дг��р нь &os;-д зориулж
шин� баримтууд ид�вхт�й бичд�г ��в�л өөр�дийн баримтыг
�х��� нь байнга шин�чилд�г х�р�гл�гчд�д зөвхөн х�р�гт�й
байдаг.
Бүх шаардлагатай х�р�г�лүүд портын цуглуулгад байдаг.
ÐдгÑ�Ñ�Ñ€ Ñ…Ñ�Ñ€Ñ�гÑ�лүүдийн Ñ�хний Ñ�уулгалт болон хожмын шинÑ�члÑ�лтүүдийг
х�лбаршуулах textproc/docproj порт нь &os;-ийг
баримтжуулах тө�лөө� хөгжүүл��н ма�тер порт юм.
&postscript; ��в�л PDF баримт шаардлагагүй үед харин
textproc/docproj-nojadetex портыг
�уулгаж болох юм. Баримтын х�р�г�лийн �н� хувилбар нь
teTeX тайп�ет хөдөлгүүр��� бу�ад
бүгдийг багтаа�ан байдаг. teTeX нь
маш олон х�р�г�лүүдийн цуглуулга учир PDF гаралт үн�х��р
шаардлагагүй тохиолдолд �уулгахгүй байх нь зохимжтой
байдаг.
Subversion нь
textproc/docproj порттой цуг �уудаг.
Баримтын �хийг шин�чл�х нь
Subversion нь
баримтын �хийн ц�в�р хуулбарыг татан
авч чаддаг.
&prompt.root; svn checkout svn://svn.FreeBSD.org/doc/head /usr/doc
Баримтын �хийн �хний таталт хугацаа шаардаж болох юм. Дуу�тал нь
хүл��х х�р�гт�й.
Баримтын �хийн дараа дараагийн шин�чл�лтүүдийг доорх тушаалыг
ашиглан татан авч болно.
&prompt.root; svn update /usr/doc
Ðхийг татан авÑ�ныхаа дараа баримтыг шинÑ�члÑ�Ñ… Ó©Ó©Ñ€ нÑ�г арга нь
/usr/doc �ангийн
Makefile-аар д�мжигд��н байдаг бөгөөд
дараахийг ажиллуулна:
&prompt.root; cd /usr/doc
&prompt.root; make update
Баримтын �хийн тааруулж болох тохируулгууд
&os;-ийн баримтжуулалтыг бүт��ж шин�чл�х �и�тем нь баримтын
зөвхөн тодорхой х��гийг шин�чл�х ��в�л ту�гай орчуулгыг бүт��х
процеÑ�Ñ�ийг амарчлах Ñ…Ñ�дÑ�н тохируулгыг дÑ�мждÑ�г. ÐдгÑ�Ñ�Ñ€ тохируулгуудыг
/etc/make.conf файлд бүх�л �и�темийн
хувьд зааж өгөх юм уу ��в�л &man.make.1; х�р�г��лд тушаалын
мөрийн тохиргоо ма�гаар зааж өгч болно.
Дараах тохируулгууд нь �дг��рийн зарим нь юм:
DOC_LANG
Бүт��ж �уулгах х�л ба кодчилолын жаг�аалт, жиш�� нь
�нгли баримтад зөвхөн зориул�ан en_US.ISO8859-1
байна.
FORMATS
Бүт��х ганц х�лб�ржүүл�лт ��в�л гаралтын х�лб�ржүүл�лтийн
жаг�аалт. Одоогоор html,
html-split, txt,
ps, pdf,
болон rtf д�мжигд��н байгаа.
DOCDIR
Баримтыг �уулгах газар. �нхдагчаар
/usr/share/doc байдаг.
&os; д��рх �и�темийн тохируулга болон д�мжигд��н бүт��лтийн
хувь�агчуудын талаар д�лг�р�нгүйг &man.make.conf.5;-� үзн� үү.
&os;-ийн баримтжуулалт бүт��х �и�темийн д�мжд�г бүт��лтийн
хувь�агчуудын талаар д�лг�р�нгүйг
Шин� хувь н�м�р оруулагчдад
зориул�ан &os; баримтжуулах тө�лийн гарын авлагаа� үзн� үү.
&os;-ийн баримтуудыг �х��� �уулгах нь
Баримтын �хийн хамгийн �үүлийн хормын хувилбарыг
/usr/doc �анд татаж ав�наар
�уулгагд�ан баримтын шин�чл�лтийг хийх�д бүх юм б�л�н болно.
DOC_LANG makefile-ийн тохиргоонд заагд�ан
бүх х�лний бүр�н шин�чл�лтийг дараахийг бичин хийж болно:
&prompt.root; cd /usr/doc
&prompt.root; make install clean
Х�р�в зөвхөн ту�гай х�лний шин�чл�лт х�р�гт�й бол
/usr/doc-ийн тухайн х�лний
ту�гай д�д �анд &man.make.1;-ийг ажиллуулж болно, жиш�� нь:
&prompt.root; cd /usr/doc/en_US.ISO8859-1
&prompt.root; make update install clean
Суулгах гаралтын х�лб�ржүүл�лтийг FORMATS
бүт��лтийн хувь�агчийг зааж өгөн хийж өгч болно,
жиш�� нь:
&prompt.root; cd /usr/doc
&prompt.root; make FORMATS='html html-split' install clean
Марк
Фонвил
Хувь н�м�р болго�он
Баримтжуулах портуудыг ашиглах нь
Updating and Upgrading
documentation package
Updating and Upgrading
Өмнөх х���гт &os;-ийн баримтжуулалтыг �х��� нь
шин�чл�х аргыг бид танилцуул�ан. &os;-ийн бүх �и�темүүдийн
хувьд �х д��р тулгуурла�ан шин�чл�лтүүд нь боломжтой ��в�л
практикийн биш байж болох юм. Баримтжуулалтын �хүүдийг
бүт��х нь н�л��н их х�мж��ний х�р�г�лийн цуглуулга буюу
баримтжуулалт бүт��х х�р�г�лийн олонлог,
Subversion-ийг тодорхой х�мж��г��р м�д�х,
репозиторио� �хийг татаж авах болон татаж ав�ан �х��
бүтÑ�Ñ�Ñ… Ñ…Ñ�д Ñ…Ñ�дÑ�н шат дарааллуудыг шаарддаг. ÐнÑ� Ñ…Ñ�Ñ�Ñ�гт
бид &os;-ийн баримтжуулалтын �уулгагд�ан хуулбаруудыг
шинÑ�члÑ�Ñ… Ó©Ó©Ñ€ аргыг тайлбарлах болно. ÐнÑ� нь портын
цуглуулгыг ашиглах бөгөөд дараах боломжийг бүрдүүлн�:
Бүгдийг бүт��лгүйг��р баримтжуулалтын урьдчилан
бүт����н хормын хувилбарыг татан авч �уулгах
(инг��н��р баримтжуулалт бүт��х х�р�г�лийн олонлогийг
бүх�лд нь �уулгах шаардлагагүй болно).
Баримтжуулалтын �хийг татаж аван портын тогтолцоог
ашиглан бүт��х (татаж аван бүт��х алхмуудыг арай х�лбар
болгодог).
&os;-ийн баримтжуулалтыг шин�чл�х �дг��р хоёр арга нь
&a.doceng;-ийн �ар бүр шин�чилд�г баримтжуулалтын
портуудын цуглуулгаар дÑ�мжигддÑ�г. ÐдгÑ�Ñ�Ñ€ нь
&os;-ийн портын цуглуулгад docs
виртуал төрөлд байдаг.
Баримтжуулалтын портуудыг бүт��ж �уулгах нь
Баримтжуулалтын портууд нь баримтжуулалтын бүт��лтийг
х�лбар болгохын тулд порт бүт��х тогтолцоог х�р�гл�д�г.
&man.make.1;-ийг тохирох орчны тохиргоонууд болон тушаалын
мөрийн тохиргоонуудын хамтаар ажиллуулж баримтжуулалтын
�хийг татаж авах проце��ыг т�д автоматжуулдаг бөгөөд
баримтжуулалтын �уулгалт болон у�тгалтыг &os;-ийн
бу�ад порт ��в�л багцын �уулгалтын н�г�н адил х�лбар
болгодог.
Мөн баримтжуулалтын портуудыг бүт���ний дараа т�д
хамааралтай баримтжуулалтыг бүт��х х�р�г�лийн олонлогийн
портуудыг бүртг�д�г бөгөөд т�дг��рийг автоматаар ба�
�уулгадаг.
Баримтжуулалтын портуудын зохион байгуулалт нь
дараах х�лб�рийн байна:
Баримтжуулалтын портын файлууд байдаг
misc/freebsd-doc-en
ма�тер порт
байдаг. ÐнÑ� нь бүх
баримтжуулалтын портуудын үнд�� болдог. �нхдагчаар
�н� нь �нгли баримтжуулалтыг зөвхөн бүт��д�г.
��г портод бүгд багт�ан
misc/freebsd-doc-all байдаг
бөгөөд �н� нь байгаа бүх х�л д��р бүх баримтжуулалтыг
бүт��ж �уулгадаг.
ÐцÑ�Ñ�Ñ‚ нь орчуулга бүрийн хувьд зарц порт
байдаг, жиш�� нь Унгар х�л д��рх баримтуудад зориул�ан
misc/freebsd-doc-hu-г дурдаж
болно. ÐдгÑ�Ñ�Ñ€ нь бүгд маÑ�тер портооÑ� хамаарах бөгөөд
тухайн х�лний орчуул�ан баримтжуулалтыг �уулгадаг.
Баримтжуулалтын портыг �х��� �уулгахын тулд дараах
тушаалуудыг ажиллуулна (root �рх��р):
&prompt.root; cd /usr/ports/misc/freebsd-doc-en
&prompt.root; make install clean
ÐнÑ� нь Ð�нгли баримтжуулалтыг хуваагдÑ�ан HTML
х�лб�р��р ( д��р ашигладагийн адилаар)
бүт��ж /usr/local/share/doc/freebsd �анд
�уулгадаг.
�ийтл�г Knob болон тохируулгууд
Баримтжуулалтын портуудын анхдагч байдлыг өөрчлөх
олон тохиргоо байдаг. Доор цөөхөн х�д�н жаг�аалтыг
дурдав:
WITH_HTML
HTML х�лб�р��р бүт��хийг зөвшөөрдөг: баримт
бүрийн хувьд н�г HTML файл. Х�лб�ршүүл��н
баримтжуулалт нь тохирох article.html юм уу
��в�л book.html г���н файлуудад зургийн
хамтаар хадгалагддаг.
WITH_PDF
&adobe; &acrobat.reader;,
Ghostscript ��в�л бу�ад PDF уншигчдыг
ашиглах &adobe;-ийн хөрвөх баримтын х�лб�р��р бүт��хийг
зөвшөөрдөг. Х�лб�ршүүл��н
баримтжуулалт нь тохирох article.pdf юм уу
��в�л book.pdf г���н файлуудад
хадгалагддаг.
DOCBASE
Баримтжуулалтын Ñ�уулгах байрлал. ÐнÑ� нь
анхдагчаар /usr/local/share/doc/freebsd
байдаг.
�нхдагч �уулгах �ан нь Subversion
аргын ашигладаг �ангаа� �лгаатайг �анаарай.
ÐнÑ� нь Ñ�агаад гÑ�вÑ�л бид порт Ñ�уулгаж байгаа
бөгөөд портууд нь их�вчл�н /usr/local �анд
�уудаг. Үүнийг PREFIX хувь�агчийг
н�м�н өөрчилж болдог.
Ðнд Унгар баримтжуулалтыг Хөрвөх Баримтын Ð¥Ñ�лбÑ�Ñ€Ñ�Ñ�Ñ€ (PDF)
�уулгахын тулд д��р дурд�ан хувь�агчуудыг х�рх�н
ашиглахыг харуул�ан жиш��г үзүүл�в:
&prompt.root; cd /usr/ports/misc/freebsd-doc-hu
&prompt.root; make -DWITH_PDF DOCBASE=share/doc/freebsd/hu install clean
Баримтжуулалтын багцуудыг ашиглах нь
Өмнөх х���гт тайлбарла�наар баримтжуулалтын портуудыг
�х��� бүт��х нь баримтжуулалтыг бүт��х х�р�г�лийн
олонлогийг �уулгах болон портуудыг бүт��х�д тодорхой
х�мж��ний ди�кийн зай шаарддаг. Баримтжуулалтын
х�р�г�лүүдийг �уулгахад �х үү�в�р хүр�лц�хгүй үед ��в�л
�х��� бүт��х нь их��х�н х�мж��ний ди�кийн зай �зл�х
бол баримтжуулалтын портуудын урьдчилан бүт����н
хормын хувилбаруудыг �уулгах боломж ба� байдаг.
&a.doceng; нь &os;-ийн баримтжуулалтын багцуудын
Ñ�ар бүрийн хормын хувилбаруудыг бÑ�лддÑ�г. ÐдгÑ�Ñ�Ñ€
хоёртын багцуудыг &man.pkg.add.1;,
&man.pkg.delete.1; г�х з�р�г багцын х�р�г�лүүдийн
хамтаар ашиглаж болдог.
Хоёртын багцуудыг ашиглаж байгаа үед &os;-ийн
баримтжуулалт нь тухайн х�лний хувьд байгаа
бүх х�лб�р��р �уудаг.
Жиш�� нь дараах тушаал Унгар баримтжуулалтын
хамгийн �үүлийн урьдчилан бүт����н багцыг �уулгах
болно:
&prompt.root; pkg_add -r hu-freebsd-doc
Багцууд нь харгалзах портын н�рн����� �лгаатай дараах
н�рийн х�лб�рт�й байдаг:
lang-freebsd-doc.
Ðнд lang нь Ñ…Ñ�лний кодын богино
х�лб�р юм, жиш�� нь hu нь Унгар, ��в�л
zh_cn нь х�лбаршуул�ан Х�тад х�л юм.
Баримтжуулалтын портуудыг шин�чл�х нь
Өмнө нь �уулга�ан баримтжуулалтын портыг шин�чл�хийн
тулд портууд шин�чл�х аль ч х�р�г��л байхад хангалттай.
Жиш�� нь дараах тушаал �уулга�ан Унгар баримтжуулалтыг
ports-mgmt/portupgrade х�р�г�лийн
ту�ламжтайгаар зөвхөн багцуудыг ашиглан шин�чилн�:
&prompt.root; portupgrade -PP hu-freebsd-doc
Хөгжүүл�лтийн �албарыг дагах нь
-CURRENT
-STABLE
FreeBSD-ийн хоёр хөгжүүл�лтийн �албар байдаг: &os.current; болон
&os.stable;. ÐнÑ� Ñ…Ñ�Ñ�Ñ�гт Ñ�дгÑ�Ñ�Ñ€ туÑ� бүрийг тайлбарлаж өөрийн Ñ�иÑ�темийг туÑ�
ту�ын модны хувьд хамгийн шин� х�лб�рт байнга байлгах талаар тайлбарлах болно.
&os.current; �хл��д х�л�лц�гд�х бөгөөд дараа нь &os.stable;-ийн тухай
�ригдах болно.
&os;-ийн одоо үеийн х�лб�рт байх нь
Та үүнийг уншихдаа &os.current; нь &os;-ийн хөгжүүл�лтийн
bleeding edge �албар буюу амжилт ололтын хамгийн т�ргүүний
�албар
г�дгийг �анаарай. &os.current; х�р�гл�гчдийг техникийн өндөр
чадавхитай бөгөөд �и�темийн хүнд х�цүү а�уудлуудыг өөр�дөө шийдв�рл�х
чадвартай байна г�ж тооцдог. Х�р�в та &os;-д анхлан �уралцагч бол
үүнийг �уулгахаа�аа өмнө дахин �айн бодоорой.
&os.current; г�ж юу в�?
хормын агшны хувилбар
&os.current; нь &os;-ийн хамгийн �үүлийн үеийн ажлын �х юм.
ÐнÑ� нь хийгдÑ�ж байгаа ажлууд, туршилтын өөрчлөлтүүд болон програм хангамжийн
дараагийн албан ё�ны хувилбарт байхгүй ч байж болох ��в�л байж ч болох
шилжилтийн аргуудыг багтаадаг. &os;-ийн олон хөгжүүл�гчид &os.current;-ийн
�х кодыг өдөр болгон �мх�тг�н хөрвүүлж байдаг боловч �хийг бүт��х боломжгүй үе ба�
байдаг. ÐдгÑ�Ñ�Ñ€ аÑ�уудлууд нь боломжийн Ñ…Ñ�Ñ€Ñ�Ñ�Ñ€ хурдан шийдÑ�гддÑ�г боловч
&os.current; нь �үйр�л авчрах ��в�л тун их хү���н ажиллагааг авчрах ���х нь
та �г �мар агшинд �х кодыг татаж ав�наа� хамаарах юм!
&os.current; х�нд х�р�гт�й в�?
&os.current; нь үнд��н 3 �онирхлын бүл�гт зориулагдан
хийгд��н:
ÐÑ… модны зарим Ñ…Ñ�Ñ�Ñ�г дÑ�Ñ�Ñ€ идÑ�вхтÑ�йгÑ�Ñ�Ñ€ ажиллаж байгаа &os;-ийн хүрÑ�Ñ�ний
гишүүд болон current буюу одоо үеийн х�лб�рт
байлгах нь
туйлын шаардлага бол�он хүмүү�т.
&os.current;-г аль болох ухаалаг байлгахыг хич��ж а�уудлуудыг шийдв�рл�х�д
цагаа зарах хү��лт�й байдаг ид�вхт�й те�т хийгч &os;-ийн хүр��ний гишүүд.
ÐдгÑ�Ñ�Ñ€ хүмүүÑ� нь өөрчлөлтүүд болон &os;-ийн ерөнхий чиглÑ�лд цаг үеийн
�аналуудыг ту�гахыг хү��ж т�дг��рийг шийд�х за�варуудыг илг��д�г ба� хүмүү�
юм..
Юу болж байгааг зөвхөн харж м�д�ж байхыг хү���н ��в�л одоо үеийн �хийг
лавлагааны зорилгоор ашиглахыг зөвхөн хү���н хүмүү� (өөрөөр х�лб�л
ажиллуулах биш унших зорилгоор).
ÐдгÑ�Ñ�Ñ€ хүмүүÑ� нь хааÑ�а баÑ� Ñ�анал гаргаж кодонд хувь нÑ�мÑ�Ñ€ оруулдаг.
&os.current; нь юу Биш в�?
Та зарим н�г дажгүй шин� боломж байгааг �он��он учраа� бу�даа�
түрүүлж урьдчил�ан хувилбарын т�дг��р битүүдийг авах таны н�н т�ргүүний
арга зам. Шин� боломжийг авч �х�нд байна г�д�г нь та шин� алдаанууд,
хорхойнуудыг ба� авч �х�нд байна г���н үг юм.
�лдааны за�варуудыг хурдан авах арга зам. &os.current;-ийн
өгөгд�өн дурын хувилбар нь ил�р��н алдаануудыг за�ахын хажуугаар ба�
магадгүй шин� алдаанууд ба� гаргаж байдаг.
�ль ч үед албан ё�оор д�мжигд��н
. Бид өөр�дийн
чадлын хир��р хууль ё�ны
3 &os.current; бүлгийн
аль н�г�нд хүмүү�т бодитоор ту�лахыг хич��д�г, г�хд�� бид�нд ердөө л
техникийн д�мжл�г үзүүл�х цаг байдаггүй.
ÐнÑ� нь бид хүмүүÑ�Ñ‚ туÑ�лах дургүй өөдгүй муухай хүмүүÑ� учрааÑ� гÑ�Ñ�Ñ�н үг
биш юм (х�р�в бид байгаагүй бол бид &os;-г хийж байхгүй байх бай�ан).
Бид ердөө л өдрийн х�д�н зуун захидлуудад хариулахын
хажуугаар FreeBSD д��р ажиллаж чаддаггүй!
&os;-г �айжруулах болон туршилтын кодон д��р тавигд�ан маш олон
а�уултуудад хариулах хоёр �онголтын �хнийхийг хөгжүүл�гчид �онго�он
юм.
&os.current; ашиглах нь
-
- -CURRENT
- ашиглах нь
-
-
- &a.current.name; болон &a.svn-src-head.name; жаг�аалтуудад �л��н орно уу.
+ &a.current.name;-CURRENTашиглах нь болон &a.svn-src-head.name; жаг�аалтуудад �л��н орно уу.
ÐнÑ� нь зөвхөн Ñ�айн Ñ�анаанааÑ� гадна баÑ� чухал
юм. Х�р�в та &a.current.name; жаг�аалтад
ороогүй бол �и�темийн одоогийн төлвийн талаар хүмүү�ийн өгч байгаа �анал
хү��лтүүдийг харахгүй учраа� бу�дын аль х�дийн олоод шийд��н маш их а�уудлууд
д��р магадгүй та бүдр�н төөрөлдөж дуу�ах биз ��. Бүр илүү чухал зүйл нь юу в� г�в�л
таны �и�темийн �рүүл м�нд�д �гз�гт�й байж болох чухал м�д��нүүд��� та хоцрох
болно.
&a.svn-src-head.name; жаг�аалт нь кодонд оруул�ан өөрчлөлт бүрийн
бүртг�л оруулгыг болзошгүй �өрөг нөлөөнүүдийн талаар тохир�он м�д��ллийн
хамтаар танд харах боломжийг олгодог.
ÐдгÑ�Ñ�Ñ€ жагÑ�аалтууд Ñ�Ñ�вÑ�л байгаа буÑ�дын аль нÑ�гÑ�нд Ñ�лÑ�Ñ�хийн тулд
&a.mailman.lists.link; ха�г уруу орж �л��хийг хү���н жаг�аалтаа
�онгоорой. Дарааллын үлд��н зааврууд т�нд байгаа болно. Х�р�в та
бүх л �х модон дахь өөрчлөлтийг дагах �онирхолтой байгаа бол
&a.svn-src-all.name; жаг�аалтад бүртгүүл�хийг бид зөвлөж байна.
&os;-ийн толин ту�галаа�
�хийг авна. Та үүнийг гурван аргаар хийж болно:
-
- svn
-
-
- cvsup
-
-
- cron
-
-
- -CURRENT
- CVSup ашиглан �үүлийн х�лб�рт аваачих
-
-
Хү���н хөгжүүл�лт ��в�л �албар хувилбарыг
- татаж авахдаа svn програмыг
+ татаж авахдаа svnsvn програмыг
ашиглах Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� аргыг &os;-н хөгжүүлÑ�лтÑ�д хандахад
зөвлөдөг. -CURRENT �уурь �и�темийн
- Subversion татаж авах үнд��н
+ Subversion-CURRENTSVN ашиглан �үүлийн х�лб�рт аваачих татаж авах үнд��н
URL нь http://svn.freebsd.org/base/head/ бөгөөд
репозиторын х�мж�� их тул зөвхөн хү���н д�д модоо
татаж авахыг зөвлөдөг.
/usr/share/examples/cvsup �анд байх
standard-supfile г�ж н�рл�гд��н
supfile-тай цуг
cvsup програм ашигла.
Та д��р дурд�ан жиш�� supfile-г
өөрчлөн cvsup-г өөрийн орчны хувьд
тохируулах х�р�гт�й.
cvsup-г ашиглах нь хуучир�ан
бөгөөд тө�өл ашиглахыг зөвлөдөггүй.
Жиш�� standard-supfile нь
&os.current;-ийн биш &os;-ийн аюулгүй байдлын ту�гай
�албарыг дагахад х�р�гл�гд�н�. Танд �н� файлыг за�варлаж дараах
мөрийг өөрчлөх х�р�гт�й болно:
*default release=cvs tag=RELENG_X_Y
Д��рх мөрийг дараах мөрөөр �ольно:
*default release=cvs tag=.
Х�р�гц��т�й ха�г/шошгонуудын д�лг�р�нгүй тайлбарыг
гарын авлагын CVS ха�г/шошгонууд х��г��� үзн� үү.
-
- -CURRENT
- CTM ашиглан �үүлийн х�лб�рт аваачих
-
-
CTM х�р�г�лийг ашигла.
+ linkend="ctm">CTM-CURRENTCTM ашиглан �үүлийн х�лб�рт аваачих х�р�г�лийг ашигла.
Х�р�в та маш муу холболттой (өндөр үн�т�й холболтууд ��в�л
зөвхөн цахим захидлын хандалт) бол CTM
нь �онголт болох юм. Г�хд�� �н� нь бөөн зовлон бөгөөд та �вд�р��н
файлуудтай үлдÑ�ж болох юм. ÐнÑ� нь үүнийг ховор ашиглахад хүргÑ�дÑ�г бөгөөд
инг��н��р ажиллахгүй байх боломжийг н�л��н удаан хугацаагаар их��г�д�г.
Бид Интерн�т холболттой хүмүү�т
Subversion-г
ашиглахыг зөвлөдөг.
Х�р�в та �хийг зөвхөн харахаар биш ажиллуулахаар татаж авч байгаа бол
зөвхөн �онго�он х��гүүдийг биш &os.current;-ийн бүх
�хийг татаж аваарай. Үүний шалтгаан нь �хийн төрөл бүрийн х��гүүд нь бу�ад хаа н�гт�� байгаа
шин�чл�лтүүд��� хамаардаг бөгөөд зөвхөн х���г бүл�г �хийг хөрвүүл�хийг оролдох нь
таныг бараг л баталгаатайгаар а�уудалтай учруулах болно.
-
- -CURRENT
- хөрвүүл�х
-
- &os.current;-ийг хөрвүүл�х����� өмнө /usr/src
+ &os.current;-ийг-CURRENTхөрвүүл�х хөрвүүл�х����� өмнө /usr/src
дахь Makefile-г анхааралтай уншина уу.
Ðхний удаа та хамгийн багаар бодоход шинÑ�члÑ�лтийн процеÑ�Ñ�ийн Ñ…Ñ�Ñ�Ñ�г болох шинÑ� цөмийг Ñ�уулгаж ертенцийг дахин бүтÑ�Ñ�Ñ… Ñ…Ñ�Ñ�гÑ�Ñ�Ñ€
дамжих х�р�гт�й. &a.current; болон /usr/src/UPDATING
файлыг унших нь биднийг дараагийн хувилбар уруу шилжих�д заримдаа шаардлагатай
болдог бу�ад �хлүүл�х процедуруудын хувьд хамгийн �үүлийн м�д��л�лт�й байлгах
боломжийг бид�нд олгодог.
Ид�вхт�й бай! Х�р�в та &os.current; ажиллуулж байгаа бол
түүний талаар таныг юу х�л�хийг �лангу�а х�р�в танд өргөжүүл�лт ��в�л
алдааны за�варуудын талаар �анал хү��лт байвал түүнийг бид м�д�хийг
хү�д�г юм. Хав�арга�ан кодтой �анал хү��лтүүдийг хамгийн их урам зоригтойгоор
хүл��н авдаг бил��!
&os;-ийн тогтвортой х�лб�рт байх нь
&os.stable; г�ж юу в�?
-STABLE
&os.stable; нь үнд��н хувилбарууд гардаг бидний хөгжүүл�лтийн �албар юм.
Өөрчлөлтүүд нь �хл��д те�т хийгд�х зорилгоор &os.current; уруу ордог г���н
ерөнхий тө�өөлөл/таамаглалтайгаар �нз бүрийн зөвшөөрлөөр �н� �албар уруу
ордог. ÐнÑ� нь одоо болтол хөгжүүлÑ�лтийн Ñ�албар
бөгөөд г�хд�� �н� нь �мар ч үед &os.stable;-д зориулагд�ан �х нь �мар ч зорилгод
тохирч Ñ�Ñ�вÑ�л тохирохгүй байж болно гÑ�Ñ�Ñ�н үг юм. ÐнÑ� нь Ñ�цÑ�ийн Ñ…Ñ�Ñ€Ñ�глÑ�гчид
зориулагд�ан �х үү�в�р бу� ердөө л өөр н�г инженерчл�лийн хөгжүүл�лтийн арга зам
юм.
&os.stable; х�нд х�р�гт�й в�?
Х�р�в та FreeBSD-ийн хөгжүүл�лтийн проце��од хувь н�м�р оруулах �онирхолтой,
�н� нь �лангу�а FreeBSD-ийн дараагийн гарах
хувилбартай холбоотой байдаг,
��в�л юу болж байгааг м�д�ж байх �онирхолтой байгаа бол та дараах
&os.stable;-г бодолцох х�р�гт�й.
�юулгүй байдлын за�варууд ба� &os.stable; �албар уруу орж байдаг нь
үн�н боловч та үүнийг хийхийн тулд &os.stable;-г заавал дагах
х�р�ггүй. FreeBSD-ийн аюулгүй байдлын
зөвлөмжүүд нь тухайн хувилбарт хамааралтай а�уудлыг х�рх�н за�ах тухай
тайлбарладаг
ÐнÑ� нь бүр Ñ�г үнÑ�н биш юм. Бид FreeBSD-ийн хуучин хувилбаруудыг
үрг�лж д�мжиж чадахгүй, г�хд�� бид т�дг��рийг олон жилийн турш д�мж���р
ир��н. FreeBSD-ийн хуучин хувилбаруудын одоогийн аюулгүй байдлын бодлогын
бүр�н тайлбарыг http://www.FreeBSD.org/security/-�
үзн� үү.
бөгөөд зөвхөн аюулгүй байдлын үүдн��� бүх�л бүт�н хөгжүүл�лтийн �албарыг
дагаж байна г�д�г ба� зөндөө олон хү���гүй өөрчлөлтүүдийг авчрах
магадлалтай юм.
Бид &os.stable; �албар үрг�лж хөрвүүл�гд�н �мх�тг�гд�ж дандаа ажилладаг байлгахаар
чармайж байдаг боловч �н� нь баталгаатай биш юм. ��мж х�л�х�д код нь &os.stable;-д
орохоо�оо өмнө &os.current;-д хөгжүүл�гд�ж байдаг боловч &os.current;-г
ашиглан ажиллуулдгаа� илүү &os.stable;-г хүмүү� ажиллуулдаг болохоор
&os.current;-ийн хувьд ил�рхий биш бай�ан алдаанууд болон булангийн тохиолдлууд
&os.stable;-д илр�х нь заримдаа зайлшгүй юм.
ÐдгÑ�Ñ�Ñ€ шалтгаануудааÑ� болоод бид &os.stable;-г Ñ�охроор дагахыг танд
зөвлөдөггүй бөгөөд �н� нь
өөрийн хөгжүүл�лтийн орчиндоо кодыг �хл��д �айтар те�т хийлгүйг��р
үйлдв�рл�лд (production) ашиглаж байгаа �ерверүүд�� &os.stable;
уруу шин�чл�хгүй байхад танд �лангу�а чухал ач холбогдолтой юм.
Х�р�в танд үүнийг хийх �х үү�в�рүүд байхгүй бол бид FreeBSD-ийн хамгийн �үүлийн үеийн
хувилбарыг ажиллуулж хоёртын шин�чл�лт хийх аргыг хувилбараа� хувилбар уруу шилжихд��
ашиглахыг танд зөвлөж байна.
&os.stable; ашиглах нь
-
- -STABLE
- ашиглах нь
-
-
- &a.stable.name; жагÑ�аалтад Ñ�лÑ�Ñ�н орно уу. ÐнÑ� нь
+ &a.stable.name;-STABLEашиглах нь жагÑ�аалтад Ñ�лÑ�Ñ�н орно уу. ÐнÑ� нь
&os.stable;-д ил�рч болох бүт��лтийн хамаарлууд ��в�л
ту�гайл�ан анхаарал шаардлагатай өөр бу�ад а�уудлуудын талаар
танд м�д��лж байх болно. Хөгжүүл�гчид нь зарим н�г маргаантай за�вар
��в�л шин�чл�лийн талаар бодож байгаа талаараа ба� �н� захидлын жаг�аалтад
м�д��лд�г бөгөөд ийнхүү �анал болгож байгаа өөрчлөлтийн талаар х�р�гл�гчд�д
�мар н�г а�уудал байвал т�д�нд �рг��д хариу өгөх боломж олгодог юм.
Өөрийн дагаж байгаа �албарын тохирох SVN
жаг�аалтад �л��н орох х�р�гт�й. Жиш�� нь х�р�в та 9-STABLE �албарыг дагаж
байгаа бол &a.svn-src-stable-9.name; жаг�аалтад �л��н ороорой.
ÐнÑ� нь кодонд оруулÑ�ан өөрчлөлт бүрийн
бүртг�л оруулгыг болзошгүй �өрөг нөлөөнүүдийн талаар тохир�он м�д��ллийн
хамтаар танд харах боломжийг олгодог.
ÐдгÑ�Ñ�Ñ€ жагÑ�аалтууд Ñ�Ñ�вÑ�л байгаа буÑ�дын аль нÑ�гÑ�нд Ñ�лÑ�Ñ�хийн тулд
&a.mailman.lists.link; ха�г уруу орж �л��хийг хү���н жаг�аалтаа
�онгоорой. Дарааллын үлд��н зааврууд т�нд байгаа болно. Х�р�в та
бүх л �х модон дахь өөрчлөлтийг дагах �онирхолтой байгаа бол
&a.svn-src-all.name; жаг�аалтад бүртгүүл�хийг бид зөвлөж байна.
Х�р�в та шин� �и�тем �уулгаж &os.stable;-��� бүт����н �ар бүрийн хормын
агшны хувилбарыг түүн д��р ажиллуулахыг хү��ж байгаа бол д�лг�р�нгүй
м�д��ллийн талаар
Хормын агшны хувилбарууд в�б хууда�наа� шалгана уу.
Үүн��� гадна хамгийн �үүлийн үеийн &os.stable; хувилбарыг
толин ту�галын ха�гуудаа�
татан авч �уулгах боломжтой бөгөөд доор дурд�ан заавруудыг дагаж
өөрийн �и�темийг хамгийн �үүлийн үеийн &os.stable; �х код уруу
шин�чилж болох юм.
Х�р�в та &os;-ийн урдны хувилбар аль х�дийн ажиллуулж байгаа бөгөөд
�х��� шин�чл�хийг хү��ж байгаа бол &os;-ийн
толин ту�гал хууда�аа� х�лбараар
хийж болно. Үүнийг гурван аргаар хийж болно:
-
- svn
-
-
- cvsup
-
-
- cron
-
-
- -STABLE
- Subversion ашиглан �үүлийн х�лб�рт аваачих
-
-
Хү���н хөгжүүл�лт ��в�л �албар хувилбарыг
- татахдаа svn програмыг ашиглах х�р�гт�й.
+ татахдаа svnsvn програмыг ашиглах х�р�гт�й.
ÐнÑ� аргыг &os;-н хөгжүүлÑ�лтÑ�д хандахад
зөвлөдөг. Салбарын н�р��д одоогийн хөгжүүл�лтийн
толгой хувилбарын хувьд head,
болон stable/9 ��в�л
releng/9.0 г�х з�р�г хувилбар инженерчл�лийн хууда�
дахь �албарууд ордог. Суурь �и�темийн
Subversion татаж авах үнд��н
- URL нь http://svn.freebsd.org/base/ бөгөөд
+ URL нь http://svn.freebsd.org/base/-STABLESubversion ашиглан �үүлийн х�лб�рт аваачих бөгөөд
репозиторын х�мж�� их тул зөвхөн хү���н д�д модоо
татаж авахыг зөвлөдөг.
/usr/share/examples/cvsup �анд байх
standard-supfile г�ж н�рл�гд��н
supfile-тай цуг
cvsup програм ашигла.
Та д��р дурд�ан жиш�� supfile-г
өөрчлөн cvsup-г өөрийн орчны хувьд
тохируулах х�р�гт�й.
cvsup нь хуучир�ан бөгөөд
тө�өл ашиглахыг зөвлөдөггүй.
-
- -STABLE
- CTM ашиглан �үүлийн х�лб�рт аваачих
-
-
CTM х�р�г�лийг ашигла.
+ linkend="ctm">CTM-STABLECTM ашиглан �үүлийн х�лб�рт аваачих х�р�г�лийг ашигла.
Х�р�в танд Интерн�т уруу холбогд�он хурдан х�мд холболт байхгүй бол
�н� аргыг та ашиглах х�р�гт�й.
Гол нь х�р�в та �х�д хурдан, шаардлагын улмаа� хандах х�р�гт�й болоод
холболтуудын зурва�ын өргөн ач холбогдолгүй бол cvsup ��в�л
ftp ашиглаарай. Бу�ад тохиолдолд
CTM-г ашигла.
-
- -STABLE
- хөрвүүл�х нь
-
-
- &os.current;-ийг хөрвүүл�х����� өмнө /usr/src
+ &os.current;-ийг-STABLEхөрвүүл�х нь хөрвүүл�х����� өмнө /usr/src
дахь Makefile-г анхааралтай уншина уу.
Ðхний удаа та хамгийн багаар бодоход шинÑ�члÑ�лтийн процеÑ�Ñ�ийн Ñ…Ñ�Ñ�Ñ�г болох шинÑ� цөмийг Ñ�уулгаж ертенцийг дахин бүтÑ�Ñ�Ñ… Ñ…Ñ�Ñ�гÑ�Ñ�Ñ€
дамжих х�р�гт�й. &a.current; болон /usr/src/UPDATING
файлыг унших нь биднийг дараагийн хувилбар уруу шилжих�д заримдаа шаардлагатай
болдог бу�ад �хлүүл�х процедуруудын хувьд хамгийн �үүлийн м�д��л�лт�й байлгах
боломжийг бид�нд олгодог.
Өөрийн �хийг хамгийн �үүлийн х�лб�рт аваачих нь
Интернетийн (��в�л цахим захидал) холболт ашиглан &os; тө�лийн �хүүдийн аль ч
х��гийн хувьд ��в�л таны юу �онирхож байгаагаа� хамааран бүх х��гүүдийг
хамгийн шин� байлгаж байх төрөл бүрийн аргууд байдаг. Бидний �анал болгодог үнд��н
үйлчилг��нүүд бол Subversion, Anonymous буюу н�ргүй
CVS, CVSup болон CTM юм.
Өөрийн �х модны зөвхөн зарим х��гийг шин�чл�х боломжтой боловч
цорын ганц шин�чл�х арга бол модыг бүтн��р нь шин�чилж х�р�гл�гчийн талбар
(өөрөөр х�лб�л /bin болон
/sbin г�х м�т д�х х�р�гл�гчийн талбарт ажилладаг
бүх програмууд) болон цөмийн �хүүдийг дахин �мх�тг�х �вдал юм. Өөрийн �х модны
зөвхөн н�г х���г зөвхөн цөм ��в�л зөвхөн х�р�гл�гчийн талбарыг шин�чл�х нь
аÑ�уудлууд гарахад ихÑ�вчлÑ�н хүргÑ�дÑ�г. ÐдгÑ�Ñ�Ñ€ аÑ�уудлууд нь Ñ�мхÑ�тгÑ�лтийн үеийн
алдаануудаа� авахуулаад цөмийн �үйрлүүд ��в�л өгөгдлийн �вдр�лийг хүрт�л
хамардаг.
CVS
anonymous буюу н�ргүй
Subversion, ��ргүй CVS болон
CVSup нь �хийг шин�чл�хд��
татах загварыг х�р�гл�д�г.
Subversion-ийн хувьд х�р�гл�гч (��в�л
cron �крипт) svn
програмыг �хлүүл�н файлуудыг хамгийн шин� х�лб�рт авчирдаг.
Локал �х модыг шин�чл�х�д зөвлөдөг арга бол Subversion
юм. cvsup ба cvs нь ижил
зарчмаар ажиллах боловч хуучир�ан бөгөөд Subversion-ийг ашиглахыг зөвлөдөг.
Таны хүл��н авах шин�чл�лтүүд нь хамгийн �үүлийн минут хүрт�лх үеийнх
байх бөгөөд та т�дг��рийг зөвхөн өөрийн хү���н т�р үед�� авдаг. Та өөрийн
шин�чл�лтүүдийг таны �онирхож байгаа ту�гайл�ан файлууд ��в�л �ангуудаар
х�лбараар х�згаарлаж болно. Шин�чл�лтүүд нь таны юуг авахыг хү���н болон танд
юу байгаагаа� хамааран �ервер��р тухайн үед үү�г�гдд�г.
Үн�х��р шаардлагагүй л бол хуучирч ир��дүйд үрг�лжүүл�н ашиглахаа болих
бу�ад �инхрон хийх аргуудаа� илүүт�й Subversion-г
ашиглах ё�той юм.
CTM
�өгөө талаа� CTM нь танд байгаа �хийг
ма�тер архив дахь �хт�й лавлаж а�уух зарчмаар харьцуулдаггүй бөгөөд өөрөөр х�лб�л
т�дг��рийг татаж авдаггүй. Инг�хийн оронд харин өмнө нь ажиллуул�наа� хойшх
файл дахь өөрчлөлтүүдийг таньдаг �крипт өдөрт х�д х�д�н удаа ма�тер CTM машин
д��р ажиллаж ил�р��н өөрчлөлтүүдийг шахаж дарааллын-дугаар тавин цахим
захидлаар дамжуулахад зориулан кодчилдог (зөвхөн х�вл�гд�х боломжтой ASCII
Ñ…Ñ�лбÑ�Ñ€Ñ�Ñ�Ñ€). ÐдгÑ�Ñ�Ñ€ CTM дельтануудыг
ав�аны дараа
т�дг��рийг автоматаар декод хийж шалган х�р�гчид байгаа �хийн хуулбарт
өөрчлөлтүүдийг хийх &man.ctm.rmail.1; Ñ…Ñ�Ñ€Ñ�гÑ�Ñ�л уруу өгдөг. ÐнÑ� процеÑ�Ñ�
нь CVSup-� хамаагүй илүү үр дүнт�й
бөгөөд �н� нь татах биш харин
түлх�х загвар учраа� бидний �ерверийн �х үү�в�рт
бага ачаалал учруулдаг юм.
М�д��ж үүн��� гадна харилцан �ул болон давуу талуудтай а�уудлууд байдаг.
Х�р�в та �анам�аргүйг��р өөрийн архивын х��гийг у�тгачих юм бол
CVSup үүнийг илрүүлж �вд�р��н х��гүүдийг
дахин бүт��ж өгдөг. CTM инг�ж
хийд�ггүй бөгөөд х�р�в та өөрийн �х модны зарим х��гийг у�тга�ан
(ба� нөөцлөн аваагүй) бол та дахин шин��р �хн��� нь (хамгийн �үүлийн үеийн
CVS �уурь дельтагаа�
) �х�лж
CTM-ийн ту�ламжтайгаар бүгдийг дахин бүт��х
буюу ��в�л ��ргүй CVS-ийн ту�ламжтайгаар
муу битүүдийг ердөө л у�тгаж дахин �үүлийн х�лб�рт аваачих х�р�гт�й болно.
Ертөнц
ийг дахин бүт��х нь
Ертөнц
ийг дахин бүт��х нь
Та өөрийн локал �х модоо &os;-ийн тухайн хувилбарын (&os.stable;,
&os.current;, г�х з�р�г) хамгийн �үүлийн үеийн х�лб�рт аваач�аныхаа
дараа та �х модоо ашиглан �и�темийг дахин бүт��ж болно.
�өөц хий
Та д��рхийг хийх����� өмнө өөрийн �и�темийг
нөөцлөн авах нь �мар чухал болохыг �н� нь хангалттай х�лж өгч чаддаггүй.
Ертөнцийг дахин бүт��х нь (х�р�в та �дг��р заавруудыг дага�ан тохиолдолд)
х�лбар боловч таныг алдаа гаргахад ��в�л бу�дын �х модонд хий��н алдаанууд
нь таны �и�темийг ачаалагдахгүй болгох нөхцөлд зайлшгүй хүрг�д�г.
�өөц хийж ав�ан ���х�� шалгаарай. За�варлах у�н ди�к ��в�л ачаалагдах
CD-г гарын дор байлгаарай. Магадгүй та үүнийг х�з�� ч х�р�гл�хгүй байж болох
юм, г�хд�� харам�ахаа�аа өмнө аюулгүй байж байх нь илүү д��р юм!
Тохирох захидлын жаг�аалтад бүртгүүл
захидлын жаг�аалт
&os.stable; болон &os.current; �албарууд нь угаа�аа
хөгжүүл�лт�д байдаг. &os;-д хувь н�м�р
оруулж байгаа хүмүү� нь хүн л учраа� алдаанууд заримдаа гардаг.
Заримдаа �дг��р алдаанууд нь н�г их хор хөнөөлгүй бөгөөд ердөө л таны
Ñ�иÑ�темийг шинÑ� оношлогооны анхааруулга Ñ…Ñ�влÑ�Ñ…Ñ�д хүргÑ�дÑ�г. ÐÑ�вÑ�л
өөрчлөлт нь �үйрлийн байж болзошгүй байдаг бөгөөд таны �и�темийг ачаалагдахгүй
болгож ��в�л файлын �и�темүүдийг чинь у�тгаж (��в�л бүр муу юм болж) болох юм.
ÐдгÑ�Ñ�ртÑ�й адил аÑ�уудлууд гарвал аÑ�уудлын учир шалтгаан болон аль Ñ�иÑ�тем дÑ�Ñ�Ñ€
�н� а�уудал хамааралтайг тайлбарла�ан heads up буюу бүхний �онорт
ханд�ан зарлал тохирох захидлын жаг�аалтад илг��гдд�г. Т�г��д
all clear буюу бүгд ц�в�р
зарлал а�уудал шийд�гд��ний дараа
тавигддаг.
Х�р�в та &os.stable; ��в�л &os.current;-ийг дагахыг оролдож &a.stable;
��в�л &a.current;-г харгалзуулан уншихгүй байгаа бол �н� нь та өөртөө гай төвөг а�ууж
байна л г���н үг юм.
make world тушаалыг бүү ашигла
Их�нх хуучин баримтууд үүнд зориулан make world
тушаалыг ашиглахыг зөвлөдөг. ÐнÑ� тушаалыг ажиллуулÑ�наар зарим нÑ�г чухал алхмуудыг
алга�ах бөгөөд та юу хийж байгаагаа м�д�ж байгаа тохиолдолд үүнийг зөвхөн ашиглах
х�р�гт�й. Бараг их�нх тохиолдолд make world хийх нь
буруу зүйл бөгөөд �нд тайлбарла�ан процедурыг түүний оронд ашиглах ё�той юм.
Шалгагд�ан аргаар өөрийн �и�темийг шин�чл�х нь
Өөрийн �и�темийг шин�чл�хийн тулд өөрт чинь байгаа �хийн хувилбарт шаардлагатай байгаа
бүт��х��� урьдах алхмууд та /usr/src/UPDATING
файлд байгаа ���хийг шалгах х�р�гт�й бөгөөд үүний дараа �нд дурд�ан процедурыг
ашиглана.
ÐдгÑ�Ñ�Ñ€ шинÑ�члÑ�лтийн алхмууд нь таныг хуучин хөрвүүлÑ�гч, хуучин цөм, хуучин
ертөнц болон хуучин тохиргооны файлууд бүхий &os;-ийн хуучин хувилбар ашиглаж
байгаа г�ж тооцдог. Ертөнц
г�дгийг бид �нд �и�темийн гол хоёртын
файлууд, �ангууд болон програмын файлууд г�ж ойлгоно. Хөрвүүл�гч нь
ертөнц
ийн х���г бөгөөд цөөн а�уудлуудтай байдаг.
Таныг шин� �и�темийн �хийг аль х�дийн ав�ан байгаа г�ж бид ба�
�нд тооцдог. Тухайн �и�тем д��р байгаа �хүүд ба� хуучин байвал шин� хувилбар
руу шилжүүл�х талаар бич��н -� д�лг�р�нгүйг
үзн� үү.
Си�темийг �х��� шин�чл�х нь �хл��д �анагд�анаа�аа илүү нарийн байдаг
бөгөөд тойрон гарах боломжгүй, хамаарлууд бүхий шин� а�уудлууд гардгаа� болоод
&os;-ийн хөгжүүл�гчид зөвлөдөг чиг хандлагаа жил ир�х тутам н�л��н��р
өөрчлөх шаардлагатай болÑ�он. ÐнÑ� Ñ…Ñ�Ñ�гийн үлдÑ�Ñ�н Ñ…Ñ�Ñ�Ñ�г нь одоогоор зөвлөж
байгаа шин�чл�х дарааллын талаар тайлбарлах болно.
�мжилттай болох шин�чл�х дараалал бүр дараах а�уудлуудыг
шийд�х ё�той:
Хуучин хөрвүүл�гч шин� цөмийг бүт��ж чадахгүй байж болох
юм. (Хуучин хөрвүүл�гчид заримдаа алдаатай байдаг.) Тийм��� шин�
цөмийг шин� хөрвүүл�гч��р бүт��х ё�той. Ялангу�а шин� цөм бүт��х�����
өмнө шинÑ� хөрвүүлÑ�гчийг бүтÑ�Ñ�Ñ… Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� нь шинÑ� хөрвүүлÑ�гчийг
заавал шин� цөмөө� өмнө �уулга�ан байх ё�той
г���н үг биш юм.
Шин� ертөнц шин� цөмийн боломжууд д��р тулгуурлаж байж
болох юм. Тийм��� шин� цөмийг шин� ертөнцийг �уулгахаа�аа өмнө
�уулга�ан байх шаардлагатай.
ÐдгÑ�Ñ�Ñ€ хоёр аÑ�уудал нь бидний дараагийн Ñ…Ñ�Ñ�гүүдÑ�д тайлбарлах
гол buildworld,
buildkernel,
installkernel,
installworld дарааллын үнд�� болдог.
ÐнÑ� нь одоогоор зөвлөдөг шинÑ�члÑ�лтийн проÑ�еÑ�Ñ�ийг та Ñ�агаад заавал
�онгох ё�тойг харуул�ан бүх шалтгаануудын бүр�н дүүр�н жаг�аалт
биш юм. Зарим н�г тийм ч м�д��жийн биш зүйл�ийг доор жаг�аав:
Хуучин ертөнц шин� цөм д��р зөв ажиллахгүй байж болох учир
та шин� цөм �уулга�ныхаа дараа шин� ертөнцийг даруйхан �уулгах
ё�той.
Шин� ертөнц �уулгахаа�аа өмнө зарим н�г тохиргооны өөрчлөлтүүдийг
хийх ё�той боловч зарим нь хуучин ертөнцийг �вд�ж магадгүй юм. Тийм
болохоор хоёр өөр тохиргооны шин�чл�лтийн алхам ерөнхийдөө шаардлагатай
байдаг.
Их�нх х��гийн хувьд шин�чл�х проце�� нь зөвхөн файлуудыг �олих юм уу
��в�л н�мд�г бөгөөд байгаа хуучин файлуудыг у�тгадаггүй. Цөөн тохиолдолд
�н� нь а�уудал үү�г�ж болох юм. Үүний дүнд шин�чл�х арга зам нь зарим н�г
алхам д��р гараар у�тгах тодорхой файлуудыг заримдаа зааж өгдөг. Үүнийг
ир��дүйд автоматчилах юм уу ��в�л үгүй ч байж болох юм.
ÐдгÑ�Ñ�Ñ€ зүйлÑ� нь дараах зөвлөÑ�өн дараалалд хүргÑ�дÑ�г. Тухайн шинÑ�члÑ�лтүүдÑ�д
зориул�ан д�лг�р�нгүй дараалал нь н�м�лт алхмуудыг шаардаж болохыг �анаарай.
Г�хд�� �дг��р гол проце��ууд тодорхой хугацаагаар өөрчлөгдөхгүй байх
ё�той юм:
make buildworld
ÐнÑ� нь Ñ�хлÑ�Ñ�д шинÑ� хөрвүүлÑ�гч болон хамааралтай цөөн Ñ…Ñ�Ñ€Ñ�гÑ�лүүдийг
бүт��ж дараа нь шин� ертөнцийн бу�дыг хөрвүүл�хийн тулд шин� хөрвүүл�гчийг
ашигладаг. Үр дүн нь /usr/obj-д
хадгалагддаг.
make buildkernel
&man.config.8; болон &man.make.1;-ийг ашигладаг хуучин аргаа�аа
�лгаатай нь �н� тушаал /usr/obj
�анд байрлаж байгаа шин� хөрвүүл�гчийг ашигладаг.
ÐнÑ� нь хөрвүүлÑ�гч болон цөмийн хооронд тохиромжгүй байдал Ò¯Ò¯Ñ�Ñ�Ñ…Ñ�Ñ�Ñ� таныг
хамгаалдаг.
make installkernel
Шин� цөм болон цөмийн модулиудыг ди�к�д байрлуулж шин��р шин�чил��н
цөмөөр ачаалах боломжийг бүрдүүлд�г.
Ганц х�р�гл�гчийн горим руу ачаалан орно.
Ганц х�р�гл�гчийн горим нь ажиллаж байгаа програм хангамжуудыг
шинÑ�члÑ�Ñ…Ñ�д гарах аÑ�уудлуудыг багаÑ�гадаг. ÐнÑ� нь баÑ� шинÑ� цөм дÑ�Ñ�Ñ€
хуучин ертөнцийг ажиллуулахад гарах а�уудлыг бага�гадаг.
mergemaster
ÐнÑ� нь шинÑ� ертөнцөд зориулж зарим нÑ�г тохиргооны файлуудын Ñ�хний
шин�чл�лтүүдийг хийд�г. Жиш�� нь �н� нь шин� х�р�гл�гчийн бүлгийг
�и�темд н�м�х, ��в�л шин� х�р�гл�гчийн н�р�ийг нууц үгийн м�д��ллийн �анд
н�мж болох юм. Сүүлийн шин�чл�лт��� хойш шин� бүлгүүд ��в�л �и�темийн
ту�гай х�р�гл�гчийн бүртг�лүүдийг н�м�х үед �н� нь их�вчл�н шаардлагатай
байдаг. Инг��н��р installworld алхам нь
шин��р �уулгагд�ан �и�темийн х�р�гл�гч ��в�л �и�темийн бүлгийн н�р�ийг
�мар ч а�уудалгүйг��р ашиглах боломжтой болох юм.
make installworld
/usr/obj �ангаа�
ертөнцийг хуулдаг. Та одоо ди�к д��р�� шин� цөм болон шин� ертөнцт�й
боллоо.
mergemaster
��г�нт ди�к д��р�� шин� ертөнцт�й бол�он болохоор та одоо
үлд��н тохиргооны файлуудаа шин�чилж болно.
Дахин ачаална.
Шин� цөм болон шин� ертөнцийг шин� тохиргооны файлуудтай
дуудахын тулд машиныг бүр�н дахин ачаалах х�р�гт�й.
Х�р�в та &os;-ийн н�г �албар дотор н�г хувилбараа� илүү �үүлийн
хувилбар руу шин�чилж байгаа бол, өөрөөр х�лб�л 7.0-� 7.1 рүү шин�чилж
байгаа бол хөрвүүл�гч, цөм, х�р�гл�гчийн талбар болон тохиргооны файлуудын
хооронд айхтар таарамжгүй байдлууд тантай бараг л тохиолдохгүй учир �н�
арга нь заавал шаардлагатай биш байж болох юм. Хуучин арга болох
make world болон шин�
цөмийг бүт��ж �уулгах нь жижиг шин�чл�лтийн хувьд хангалттай �айн
ажиллаж болох юм.
Г�хд�� гол хувилбаруудын хооронд шин�чл�лт хийж байх үед �н� арга
замыг дагахгүй байгаа хүмүү�т зарим а�уудлууд учирч болох юм.
Олон шин�чл�лтүүд (өөрөөр х�лб�л 4.X-�
5.0 руу) ту�гайл�ан н�м�лт алхмуудыг (жиш�� нь installworld хийх��� өмнө
ту�гай файлуудын н�рийг өөрчлөх ��в�л у�тгах г�х м�т) шаардаж болохыг �нд
т�мд�гл�х нь зүйт�й юм. /usr/src/UPDATING файлыг
анхааралтай уншина уу, �лангу�а одоогоор зөвлө�өн байгаа шин�чл�х дарааллыг
ту�гайлан тайлбарла�ан төг�гөл х��гийг уншаарай.
Зарим н�г тохиромжгүй байдалтай холбоотой а�уудлуудаа� бүр�н
гүйц�д хамгаалах боломжгүйг хөгжүүл�гчид м�д��н��р �н� арга нь цаг хугацааны
туршид �айжруулагд�аар ир��н юм. Одоогийн арга замууд нь удаан хугацааны
туршид тогвортой байна г�д�гт найдаж байна.
Дүгн�х�д &os;-г �х��� шин�чл�х�д одоогоор зөвлөдөг арга
бол:
&prompt.root; cd /usr/src
&prompt.root; make buildworld
&prompt.root; make buildkernel
&prompt.root; make installkernel
&prompt.root; shutdown -r now
buildworld алхмаа� өмнө
mergemaster -p тушаалыг н�мж ажиллуулах
цөөн ховор тохиолдлууд байдаг. ÐдгÑ�Ñ�рийн талаар UPDATING
файлд тайлбарла�ан байдаг. Х�р�в та &os;-ийн н�г буюу олон голлох
хувилбаруудын дагуу шин�чл�л хийхгүй байгаа бол ерөнхийдөө �н� алхмыг
�м��лгүйг��р орхиж болох юм.
installkernel амжилттай дуу��аны
дараа та ганц х�р�гл�гчийн горим уруу ачаалах х�р�гт�й (өөрөөр х�лб�л
boot -s тушаалыг дуудагч мөрөө� ашиглана).
Дараа нь доор дурд�ан тушаалуудыг ажиллуулна:
&prompt.root; mount -u /
&prompt.root; mount -a -t ufs
&prompt.root; adjkerntz -i
&prompt.root; mergemaster -p
&prompt.root; cd /usr/src
&prompt.root; make installworld
&prompt.root; mergemaster
&prompt.root; reboot
Тайлбаруудыг цааш уншина уу
Д��р тайлбарла�ан дараалал нь зөвхөн таныг �хл�х�д ту�лах богино
��рг��лт болох юм. Г�хд�� х�р�в та �лангу�а өөрчлөн тохируул�ан
цөмийн тохиргоо ашиглахыг хү��ж байгаа бол дараах х��гүүдийг уншиж
алхам бүрийг �айтар ойлгох х�р�гт�й.
/usr/src/UPDATING файлыг унш
Өөр юм хийж �хл�х����� өмнө та /usr/src/UPDATING-г
(��в�л �х кодын хуулбар хаана байгаа т�нд��� үүнт�й тө�т�й файлыг ) уншаарай.
ÐнÑ� файл нь танд учирч болзошгүй аÑ�уудлуудын талаар чухал мÑ�дÑ�Ñ�лÑ�л агуулдаг бөгөөд
��в�л таны ажиллуулах зарим н�г тушаалуудын дарааллын талаар заа�ан байдаг.
Х�р�в UPDATING файл таны �нд унш�антай зөрчилдөж
байвал UPDATING файлд заа�ныг дагах х�р�гт�й.
UPDATING файлыг унших нь өмнө нь тайлбарла�наар
зөв захидлын жаг�аалтад бүртгүүл�хт�й харьцуулах юм бол хүл��н зөвшөөрч болохуйц
орлогч байж чадахгүй юм. ÐнÑ� хоёр шаардлага нь нÑ�мÑ�лт бөгөөд заавал шаардлагатай
биш юм.
/etc/make.conf файлыг шалга
make.conf
/usr/share/examples/etc/make.conf
болон /etc/make.conf файлыг шалгаарай.
Ðхнийх нь зарим нÑ�г анхдагч тодорхойлолтуудыг агуулдаг – Ñ‚Ñ�дгÑ�Ñ�рийн
их�нх нь тайлбар болон хаагд�ан байдаг. Та �и�тем�� �х��� нь дахин бүт��х үед��
т�дг��рийг ашиглахын тулд /etc/make.conf
файлд н�м�х х�р�гт�й. /etc/make.conf файлд
н�м��н болгон make тушаалыг ажиллуулах бүрд
ба� ашиглагддаг учир өөрийн �и�темд�� зориулан т�дг��рийг боломжийн утгаар
тохируулж өгөх нь зүйт�й юм.
Ердийн х�р�гл�гч /usr/share/examples/etc/make.conf
файлд байдаг NO_PROFILE мөрийг
/etc/make.conf уруу хуулж
тайлбар болго�ныг болиулж н��хийг магадгүй хү��ж
болох юм.
NOPORTDOCS г�х з�р�г бу�ад
тодорхойлолтуудыг шалгаж танд хамаатай
���х��� хамаарч оруулах ���х�� шийд��р�й.
/etc д�х файлуудыг шин�чил
/etc �ан нь таны �и�темийн тохиргооны м�д��ллийн
их�нх х��гийг агуулдгаа� гадна �и�темийг �хлүүл�х�д ажилладаг �криптүүд �нд байдаг.
ÐдгÑ�Ñ�Ñ€ Ñ�криптүүдийн зарим нь FreeBSD-ийн хувилбарааÑ� хувилбарт өөрчлөгддөг.
Тохиргооны файлуудын зарим нь ба� �и�темийг ажиллуулахад өдөр тутам х�р�гл�гдд�г.
Ялангу�а /etc/group-г дурдаж болно.
make installworld тушаалын �уулгалт хийх х���г нь
зарим н�г х�р�гл�гчийн н�р ��в�л бүлгүүд байж байна г�ж тооцдог тохиолдлууд байдаг.
Шин�чл�л хийж байх үед �дг��р х�р�гл�гчид ��в�л бүлгүүд их�нхд�� байхгүй байдаг.
ÐнÑ� нь шинÑ�члÑ�л хийхÑ�д аÑ�уудал учруулдаг. Зарим тохиолдолд make buildworld
нь �дг��р х�р�гл�гчид ��в�л бүлгүүд байгаа ���хийг шалгана.
Үүний н�г жиш�� нь smmsp х�р�гл�гч н�м�гд��н
тохиолдол юм. &man.mtree.8; нь /var/spool/clientmqueue-г
үү�г�хийг оролдох үед х�р�гл�гчийн �уулгалтын проце�� �н� а�уудлаа� болж амжилтгүй
болж бай�ан.
Үүний шийд�л нь &man.mergemaster.8;-г ертөнцийг бүт��х��� урд
тохируулгатай ажиллуулах Ñ�вдал юм. ÐнÑ� нь buildworld
��в�л installworld тушаалыг амжилттай болгоход
зөвхөн шаардлагатай файлуудыг харьцуулдаг.
Х�р�в та �лангу�а х�т�рхий �анаа зовж байгаа бол тухайн бүл�гт харь�алагдаж байгаа
н�рийг нь өөрчилж байгаа ��в�л у�тгаж байгаа �мар файлууд байгааг өөрийн �и�тем���
шалгаарай:
&prompt.root; find / -group GID -print
д��рх нь GID (�н� бүлгийн н�р байж болно ��в�л
бүлгийн тоон ID байж болно) бүлгийн �з�мшд�г файлуудыг харуулна.
Ганц х�р�гл�гчийн горимд шилж
ганц х�р�гл�гчийн горим
Та �и�темийг ганц х�р�гл�гчийн горимд �мх�тг�хийг хү��ж болох юм.
ÐнÑ� нь шинÑ�члÑ�лтийг арай илүү хурдаÑ�гах илÑ�рхий ашиг туÑ�тайгааÑ� гадна
�и�темийг дахин �уулгах нь �и�темийн �тандарт хоёртын файлууд,
libraries буюу ту�лах �ангууд, оруулгын файлууд г�х з�р�г �и�темийн
маш олон чухал файлуудыг хөнддөг. �жиллаж байгаа �и�тем д��р �дг��рийг
өөрчлөх нь (�лангу�а х�р�в тухайн үед таны �и�тем д��р ид�вхт�й х�р�гл�гчид
байвал) гай төвгийг өөрөө �рж байна г���н үг юм.
олон х�р�гл�гчийн горим
Өөр н�г арга бол �и�темийг олон х�р�гл�гчийн горимд �мх�тг�ж дараа нь
�уулгахдаа ганц х�р�гл�гчийн горимд шилжин хийх �вдал юм. Х�р�в та �н� замаар
хийхийг хү��ж байвал бүт��лт дуу�тал дараах алхмууд д��р хүл��ж байгаарай.
Та installkernel ��в�л
installworld хийх хүртл�� ганц х�р�гл�гчийн горимд
оролгүйг��р хүл��ж байж болно.
Супер х�р�гл�гч болоод та доор дурд�аныг:
&prompt.root; shutdown now
ажиллаж байгаа �и�тем��� ганц х�р�гл�гчийн горим уруу оруулахдаа
ажиллуулж болно.
Өөр н�г арга нь �и�темийг дахин ачаалаад ачаалалтын тушаал хүл��х мөрөн д��р
single user буюу ганц х�р�гл�гч
тохируулгыг �онгоорой.
Инг�х�д �и�тем ганц х�р�гл�гчийг ачаална. Бүрхүүлийн тушаал хүл��х мөрөнд та
доор дурд�ан тушаалуудыг ажиллуулах шаардлагатай:
&prompt.root; fsck -p
&prompt.root; mount -u /
&prompt.root; mount -a -t ufs
&prompt.root; swapon -a
ÐнÑ� нь файлын Ñ�иÑ�темүүдийг шалгаж /-г
дахин унших/бичих��р дахин холбож бу�ад бүх UFS файлын �и�темүүдийг
/etc/fstab-д заа�ны дагуу холбон дараа нь
swap-ийг ид�мвхжүүл�х болно.
Х�р�в таны CMOS цаг нь GMT биш локал хугацаагаар тохируулагд�ан бол
(х�р�в &man.date.1; тушаалын гаралт зөв цаг болон бү�ийг харуулахгүй
бол �н� нь үн�н) та дараах тушаалыг ба� ажиллуулах х�р�гт�й болж
болох юм:
&prompt.root; adjkerntz -i
ÐнÑ� нь таны локал цагийн бүÑ�ийн тохируулгуудыг зөвөөр тохируулж өгдөг —
үүнийг хийхгүй бол та дараа нь зарим а�уудлуудтай тулгарч магадгүй.
/usr/obj-г у�тга
Си�темийн х��гүүд дахин бүт��гд��нийх�� дараа (анхдагчаар)
/usr/obj дахь Ñ�ангуудад байршдаг. ÐдгÑ�Ñ�Ñ€ Ñ�ангууд нь
/usr/src дотор байгааг халхалдаг.
Та make buildworld проце��ийг хурда�гаж болох бөгөөд
�н� �анг ба� у�тга�наар хамаарлын зовлонгуудаа� өөрийгөө магадгүй аврах болно.
/usr/obj доторх зарим файлуудад immutable
буюу хувиршгүй туг тавигд�ан (д�лг�р�нгүй м�д��ллийг &man.chflags.1;-� үзн� үү )
байж болох бөгөөд түүнийг �хл��д арилгах х�р�гт�й.
&prompt.root; cd /usr/obj
&prompt.root; chflags -R noschg *
&prompt.root; rm -rf *
Үнд��н �и�темийг дахин �мх�тг�
Гаралтыг хадгалах нь
&man.make.1;-г ажиллуулахдаа гарах үр дүнг өөр файл уруу хадгалах нь
зүйт�й юм. Х�р�в �мар н�г юм болохоо боливол та алдааны м�д�гдлийн хуулбартай
байх болно. ÐнÑ� нь танд юу буруутÑ�аныг шинжлÑ�Ñ…Ñ�д чинь туÑ� болохгүй байж болох боловч
та өөрийн �н� а�уудлаа &os;-ийн аль н�г захидлын жаг�аалт уруу илг����н тохиолдолд
бу�дад ту� болж болох юм.
Үүнийг хамгийн амраар хийхийн тулд &man.script.1; тушаалыг бүх гаралтыг хадгалах
файлын н�рийг заа�ан параметрийн хамтаар ашиглана. Та үүнийг ертөнцийг дахин бүт��х���
өмнөхөн н�н даруй хийж дараа нь проце�� дуу��аны дараа exit
г�ж бичиж гарна.
&prompt.root; script /var/tmp/mw.out
Script started, output file is /var/tmp/mw.out
&prompt.root; make TARGET
… compile, compile, compile …
&prompt.root; exit
Script done, …
Х�р�в та үүнийг хийх бол гаралтыг /tmp дотор
битгий хадгалаарай. ÐнÑ� Ñ�ан нь таныг дахин ачаалÑ�ны
дараа цÑ�вÑ�рлÑ�гдÑ�ж болох юм. ÐнÑ� файлыг хадгалах арай илүү боломжийн газар нь
/var/tmp (өмнөх жиш��н д��рх шиг) ��в�л
root х�р�гл�гчийн г�р �ан байж болох юм.
Үнд��н �и�темийг �мх�тг�
Та /usr/src �ан дотор байх
шаардлагатай:
&prompt.root; cd /usr/src
(г�хд�� м�д��ж таны код өөр газар байгаа тохиолдолд т�р �ан уруугаа орох
х�р�гт�й).
make
Ертөнцийг дахин бүтÑ�Ñ�хдÑ�Ñ� та &man.make.1; тушаалыг ашиглана. ÐнÑ�
тушаал нь &os;-ийн агуул�ан програмууд �мар дарааллаар дахин х�рх�н бүт��гд�х з�ргийг
тайлбарла�ан Makefile файлаа� заавруудыг уншдаг.
Таны бичих тушаалын мөрийн ерөнхий х�лб�р нь дараах байдлаар байна:
&prompt.root; make -x -DVARIABLE target
ÐнÑ� жишÑ�Ñ�н дÑ�Ñ�Ñ€ нь
&man.make.1; уруу таны дамжуулах тохируулга юм. &man.make.1;-н гарын авлагын хууда�наа�
та дамжуулж болох тохируулгуудын жиш��г үзн� үү.
тохируулга нь Makefile уруу хувь�агч дамжуулж байна.
Makefile-ийн ажиллагаа �дг��р хувь�агчуудаар
Ñ…Ñ�нагдана. ÐдгÑ�Ñ�Ñ€ нь /etc/make.conf дотор
зааж өг�өн хувь�агчуудтай адил бөгөөд �н� нь т�дг��рийг тохируулах ба� н�г өөр
арга юм.
&prompt.root; make -DNO_PROFILE target
тушаал нь профиль хийгд��н �ангууд бүт��гд�х ё�гүйг заах өөр н�г арга бөгөөд
�н� нь /etc/make.conf дахь дараах
NO_PROFILE= true # Avoid compiling profiled libraries
мөрд харгалзах юм.
target нь &man.make.1;-д
таны юу хийхийг х�лж өгдөг. Makefile болгон
өөр өөр targets буюу даалгаврын төрлүүдийг
тодорхойлдог
бөгөөд таны �онго�он төрөл юу болохыг тодорхойлдог.
Зарим төрлүүд Makefile-д жаг�аагд�ан байх
бөгөөд г�хд�� �дг��р нь таныг ажиллуулахад зориулагдаагүй. Харин т�дг��р нь
�и�темийг дахин бүт��х�д шаардлагатай алхмуудыг х�д х�д�н д�д алхмуудад хуваахын
тулд бүт��х проце��од х�р�гл�гдд�г.
Их�нх тохиолдолд та &man.make.1; уруу �мар ч параметр дамжуулах
х�р�ггүй бөгөөд т�г�х��р таны тушаал дараахтай ижил байж болно:
&prompt.root; make target
д��рх target нь олон бүт��х тохируулгуудын
нÑ�г болно. Ðхний төрөл нь үргÑ�лж buildworld
байх ё�той.
��рт�йг�� адилаар buildworld нь
/usr/obj дотор бүр�н гүйц�д шин� модыг бүт��х бөгөөд
өөр н�г төрөл болох installworld нь
�н� модыг тухайн машин д��р �уулгадаг.
Ту�даа тохируулгуудтай байх нь хоёр шалтгаанаар маш ач холбогдолтой юм.
��гдүг��рт �н� нь бүт��лтийг таны ажиллаж байгаа �и�темийн �мар ч х���гт нөлөөлөхгүйг��р
аюулгүйг��р хийхийг танд зөвшөөрдөг. Бүт��лт нь өөр д��р�� хийгд�н� (self hosted)
.
Ийм болохоор та buildworld тушаалыг олон
х�р�гл�гчийн горимд ажиллаж байгаа машин д��р буруу нөлөөллөө� айлгүйг��р аюулгүйг��р
хийж болно. Г�хд�� installworld х��гийн хувьд ганц
х�р�гл�гчийн горимд хийхийг танд зөвлөдөг.
Хоёрдугаарт �н� нь �үлж��н д�х олон машинуудыг шин�чл�х�д
NFS холболтуудыг ашиглахыг танд зөвшөөрдөг. Х�р�в танд гурван машин байгаа бөгөөд
A, B болон C
машинуудыг шин�чл�хийг хү�в�л make
buildworld болон make installworld
тушаалыг A д��р ажиллуулна. Дараа нь B болон C
машинууд A д��рх /usr/src
болон /usr/obj �ангуудыг NFS холболт хийн
make installworld-г ажиллуулж
бүт��лтийн үр дүнг B болон C д��р
�уулгаж болох юм.
world төрөл бай�аар байгаа х�дий ч
танд түүнийг ашиглахгүй байхыг зөвлөж байна.
Дараах тушаалыг ажиллуул
&prompt.root; make buildworld
Х�д х�д�н з�р�гц�� проце��уудыг үү�г�х тохируулгыг
make тушаалд зааж өгөх боломжтой. ÐнÑ� нь олон CPU-Ñ‚Ñ�й
машинууд д��р хамгийн их ашигтай. Г�хд�� �мх�тг�х проце��ийн их�нх нь CPU д��р биш
IO д��р ажилладаг болохоор �н� нь ба� н�г CPU-т�й машинууд д��р ашигтай юм.
Ердийн н�г CPU-т�й машин д��р та доор дурд�аныг ажиллуулж болох юм:
&prompt.root; make -j4 buildworld
&man.make.1; нь 4 хүрт�лх проце��ийг н�г�н з�р�г ажиллуулах юм. Захидлын
жаг�аалтуудад илг��гд��н туршлагаа� харахад �н� нь ерөнхийдөө ажиллагааг хамгийн �айн
хангаж хурда�гадаг байна.
Х�р�в та олон CPU машинтай бөгөөд SMP тохируулагд�ан цөм ашиглаж байвал
утгыг 6-аа� 10 хүрт�л болгож х�р хурд�аж байгааг хараарай.
Хугацаа
ертөнцийг
дахин бүт��х нь
хугацаа
Бүт��х�д шаардагдах хугацаанд олон хүчин зүйл� нөлөөлдөг, г�хд��
н�л��н �үүлийн үеийн машинуудын хувьд &os.stable; модыг проце��ийн �вцад �мар н�г�н
заль м�х ��в�л дөт зам ашиглалгүйг��р бүт��х�д зөвхөн н�г юм уу ��в�л хоёр цаг л
шаардагдах болох юм. &os.current; модны хувьд арай удах болов уу.
Шин� цөмийг �мх�тг�ж �уулга
цөм
�уулгах нь
Та өөрийн шин� �и�темийн давуу талыг бүгдийг нь авахын тулд цөмөө дахин �мх�тг�х
х�р�гт�й. Зарим н�г �анах ойн бүтцүүд өөрчлөгд�өн байх талтай бөгөөд
&man.ps.1; болон &man.top.1; з�р�г програмууд нь цөм болон �х кодын хувилбарууд
адил болтол ажилладаггүй болохоор �мх�тг�х нь үн�нд�� чухал х�р�гц��т�й юм.
Үүнийг хамгийн х�лбараар аюулгүйг��р хийхийн тулд GENERIC
д��р тулгуурла�ан цөмийг бүт��ж �уулгах �вдал юм. GENERIC нь
таны �и�темийн хувьд х�р�гц��т�й төхөөрөмжүүдийг агуулаагүй байж болох боловч
таны �и�темийг �даж ганц х�р�гл�гчийн горимд ачаалахад шаардлагатай бүгдийг агуул�ан
байх ё�той. Шин� �и�тем зөв ажиллуулахад �н� �айн те�т болж өгдөг.
GENERIC-� ачаалж таны �и�тем ажиллаж байгааг шалга�ны
дараа та өөрийн ердийн цөмийн тохиргооны файл д��р тулгуурлан шин� цөмөө бүт��ж
болох юм.
&os; д��р шин� цөм бүт��х����� өмнө ертөнцийг бүт��х нь чухал юм.
Х�р�в та өөрчлөн тохируул�ан цөмийг бүт��хийг хү��ж тохиргооны файлаа аль
х�дийн үү�г���н бол доор дурд�антай адилаар
KERNCONF=MYKERNEL
г�ж ашиглаарай:
&prompt.root; cd /usr/src
&prompt.root; make buildkernel KERNCONF=MYKERNEL
&prompt.root; make installkernel KERNCONF=MYKERNEL
Х�р�в та kern.securelevel хувь�агчийг
1-��� д��ш болгон их��г���н бөгөөд
noschg ��в�л түүнт�й адил тугуудыг өөрийн цөмийн хоёртын
файлд тавь�ан бол installkernel хийхийн тулд
та ганц х�р�гл�гчийн горимд шилжин орох шаардлагатай байж болох юм. Үгүй бол
та �н� хоёр тушаалыг олон х�р�гл�гчийн горимоо� �мар ч а�уудалгүйг��р
ажиллуулах ё�той. kern.securelevel-ийн талаар
д�лг�р�нгүйг &man.init.8; болон төрөл бүрийн файлын тугуудын талаар д�лг�р�нгүйг
&man.chflags.1; гарын авлагын хууда�нуудаа� үзн� үү.
Ганц х�р�гл�гчийн горим уруу дахин ачаалан ор
ганц х�р�гл�гчийн горим
Та шин� цөмийн ажиллагааг шалгахын тулд ганц х�р�гл�гчийн горимд дахин
ачаалан орох х�р�гт�й. Үүнийг
дахь заавруудын дагуу хийн�.
Шин� �и�темийн хоёртын файлуудыг �уулга
Та шин� �и�темийн хоёртын
файлуудыг �уулгахын тулд installworld
тушаалыг ашиглах шаардлагатай.
Доор дурд�аныг ажиллуулна
&prompt.root; cd /usr/src
&prompt.root; make installworld
Х�р�в та make buildworld тушаалын мөрөнд
хувь�агчуудыг зааж өг�өн бол т�дг��р хувь�агчуудыг
make installworld тушаалын мөрөнд ба� адилаар
зааж өгөх Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� буÑ�ад тохируулгуудын хувьд заавал шаардлагатай биш
байж болох юм; жиш�� нь тохируулга
installworld-той цуг х�з�� ч х�р�гл�гд�х
ё�гүй.
Жиш�� нь х�р�в та доор дурд�аныг ажиллуул�ан бол:
&prompt.root; make -DNO_PROFILE buildworld
хоёртын файлуудыг дараах тушаалаар �уулгана:
&prompt.root; make -DNO_PROFILE installworld
инг�хгүй бол make buildworld тушаалын ажиллах
�вцад бүт��гд��гүй профиль хийгд��н �ангуудыг (libraries) �уулгахыг оролдох болно.
make installworld тушаалаар шин�чл�гд��гүй файлуудыг шин�чил
Ертөнцийг дахин бүт��х нь зарим н�г �ангуудыг (�лангу�а /etc,
/var болон /usr) шин� болон
өөрчлөгд�өн тохиргооны файлуудаар шин�чилд�ггүй.
ÐдгÑ�Ñ�Ñ€ файлуудыг хамгийн амархнаар шинÑ�члÑ�Ñ… арга нь &man.mergemaster.8;-г
ашиглах �вдал юм, г�хд�� та х�р�в хү�в�л үүнийг гараар ажиллуулах боломжтой юм.
�ль ч аргыг �онголоо г���н �мар н�г�н зүйл буруут�ан тохиолдолд ��рг��х боломжтойгоор
/etc-г нөөцөлж авах нь зүйт�й юм.
Том
Рөүд�
Хувь н�м�р болгон оруул�ан
mergemaster
mergemaster
&man.mergemaster.8; х�р�г��л нь /etc д�х
таны тохиргооны файлууд болон /usr/src/etc �х модон дахь
тохиргооны файлуудын �лгааг тодорхойлоход танд ту�алдаг Bourne �крипт юм.
ÐнÑ� нь Ñ�иÑ�темийн тохиргооны файлуудыг Ñ�Ñ… модон дахь тохиргооны файлуудаар шинÑ�члÑ�Ñ…
зориулалттай бидний зөвлөдөг шийд�л юм.
ÐхлÑ�хийн тулд өөрийн тушаал оруулах мөрөнд ердөө л mergemaster-г
бичиж түүний �хл�хийг нь хараарай. mergemaster нь түр зуурын
root орчныг /-� доошлуулан бүт��ж төрөл бүрийн �и�темийн тохиргооны
файлуудаар дамждаг. Т�дг��р файлууд нь таны �и�темд �уулгагд�ан файлуудтай харьцуулагддаг.
ÐнÑ� үед хоорондоо Ñ�лгаатай файлууд &man.diff.1; Ñ…Ñ�лбÑ�Ñ€Ñ�Ñ�Ñ€ үзүүлÑ�гддÑ�г бөгөөд
т�мд�гт��р н�м�гд��н ��в�л өөрчлөгд�өн мөрүүдийг
т�мд�гт��р у�тгагд�ан ��в�л шин� мөрөөр �олигд�он мөрүүдийг
харуулдаг. &man.diff.1;-н �интак� болон файлын өөрчлөлтүүдийг х�рх�н үзүүлд�г талаар
д�лг�р�нгүй м�д��ллийг &man.diff.1; гарын авлагын хууда�наа� үзн� үү.
&man.mergemaster.8; нь зөрчилдөөнүүдийг үзүүл��н файл болгоныг харуулдаг бөгөөд
�н� үед танд шин� файлыг у�тгах (түр зуурын файл г�гдд�г), түр зуурын файлыг өөрчлөлгүйг��р
�уулгах, �уу�ан байгаа файлтай түр зуурын файлыг нийлүүл�х ��в�л &man.diff.1;-н
гаралтыг дахин харах �онголтыг үзүүл�х болно.
Түр зуурын файлыг у�тгахыг �онго�ноор бид одоо байгаа файлаа х�в��р өөрчлөлгүй үлд��ж
шин� хувилбарыг у�тгахыг хү��ж байгаагаа &man.mergemaster.8;-д х�лж байна г���н үг юм.
Х�р�в та одоо байгаа файлаа өөрчлөх шалтгааныг олж харахгүй байгаагаа� бу�ад тохиолдолд
�н� �онголтыг хийхийг зөвлөдөггүй. Та �мар ч үед &man.mergemaster.8; тушаал хүл��х
мөрөн д��р ? г�ж бичин ту�ламж авч болох юм. Х�р�в х�р�гл�гч
файлыг орхихоор �онго�он бол �н� нь бу�ад бүх файлуудтай ажил�ны дараа дахин үзүүл�гд�н
х�р�гл�гч��� тушаал хүл��х болно.
Өөрчлөгдөөгүй түр зуурын файлыг �уулгахыг �онго�ноор одоо байгаа файлыг шин��р
�ольдог. Их�нх өөрчлөгдөөгүй файлуудын хувьд �н� нь хамгийн шилд�г �онголт юм.
Файлыг нийлүүл�хийг �онго�ноор тек�т за�варлагч болон хоёр файлын агуулгыг танд
харуулах болно. Та д�лг�цийн хоёр талд байрла�ан т�дг��р хоёр файлыг хоёуланг нь
шалган аль аль талаа� нь х�р�гт�й х��гүүдийг �онгон �ц�ийн бүт��гд�хүүн гаргаж аван
нийлүүлж болно. Файлууд нь д�лг�цийн хоёр талд байрлан харьцуулагдах �вцад
l түлхүүр таны зүүн талын агуулгыг �онгодог бол
r түлхүүр нь таны баруун тал дахь агуулгыг �онгох юм.
Гарах �ц�ийн үр дүн нь хоёр файлын хоёулангийн х��гүүдийг агуул�ан файл болох бөгөөд
түүнийг дараа нь Ñ�уулгах боломжтой болох юм. ÐнÑ� Ñ�онголтыг Ñ…Ñ�Ñ€Ñ�глÑ�гчийн тохиргоонуудад
хийгд��н өөрчлөлтүүдт�й файлуудын хувьд х�р�гл�х нь зуршил болж��.
&man.diff.1;-��� гарах үр дүнг дахин харахыг �онго�ноор өмнө нь
&man.mergemaster.8; файлын өөрчлөлтүүдийг харуулан таны �онголтыг хүл���ний
н�г�н адилыг дахин харуулдаг.
&man.mergemaster.8; �и�темийн файлуудтай ажиллаж дуу��аны дараа
танаа� бу�ад �онголтуудыг хийхийг хүл��д�г. &man.mergemaster.8; тушаал
нууц үгийн файлыг дахин бүт��хийг хү��ж байгаа ���хийг танаа� а�ууж үлд��н
түр зуурын файлуудыг у�тгах �онголтыг үзүүл�н дуу�даг.
Гараар шин�чл�х
Х�р�в та гараар шин�чл�хийг хү�в�л г�хд�� та /usr/src/etc
�ангаа� /etc �ан уруу файлуудыг зүг��р л дарж хуулж ажиллуулж
чадахгүй. Зарим файлуудыг �хл��д �уулгах
х�р�гт�й. Учир нь
/usr/src/etc �ан таны /etc
�ангийн хуулбар шиг байхаар харагддагүй. Мөн
/usr/src/etc �анд байдаггүй х�рн��
/etc �ан дотор байх шаардлагатай зарим файлууд
байдаг.
Х�р�в та &man.mergemaster.8; (зөвлө�ний дагуу) ашиглаж байвал та
дагаагийн х���г уруу
орж болно.
Үүнийг гараар хамгийн х�лбар аргаар хийхийн тулд файлуудыг шин� �ан уруу
�уулгаж н�г бүрчл�н өөрчлөлтүүдийг хайн ажиллах х�р�гт�й.
Өөрт байгаа /etc-г нөөцөл
Онолоор бол автоматаар �н� �анд юу ч хүрд�ггүй ч үүнд үрг�лж итг�лт�й
байх х�р�гт�й. Т�г�х��р өөрийн байгаа /etc �анг
хаа н�г аюулгүй газар хуулах х�р�гт�й. Доорхтой адилаар:
&prompt.root; cp -Rp /etc /etc.old
нь рекур�ив хуулбар хийх бөгөөд
нь файлуудын хугацаа, �з�мшигч г�х м�тийг
хадгалдаг.
Та шин� /etc болон бу�ад файлуудыг �уулгахын тулд
хоо�он �ангууд бүт��х х�р�гт�й. /var/tmp/root нь
боломжийн �онголт болох бөгөөд �н� �ангийн доор х�д х�д�н д�д �ангууд ба�
шаардлагатай болно.
&prompt.root; mkdir /var/tmp/root
&prompt.root; cd /usr/src/etc
&prompt.root; make DESTDIR=/var/tmp/root distrib-dirs distribution
ÐнÑ� нь шаардлагатай Ñ�ангийн бүтцийг бүтÑ�Ñ�ж файлуудыг Ñ�уулгадаг.
/var/tmp/root дотор үү�г�гд��н олон д�д �ангууд
хоо�он бөгөөд т�дг��рийг у�тгах шаардлагатай байдаг. Үүнийг хамгийн х�лбараар
хийхийн тулд:
&prompt.root; cd /var/tmp/root
&prompt.root; find -d . -type d | xargs rmdir 2>/dev/null
ÐнÑ� нь бүх хооÑ�он Ñ�ангуудыг уÑ�тгана. (ХооÑ�он биш Ñ�ангуудын тухай анхааруулгуудыг
гаргахгүйн тулд �тандарт алдаа нь /dev/null
уруу илг��гдд�г.)
Одоо /var/tmp/root нь /-�
доор байрлах тохирох байрлалуудад байршуулах ё�той бүх файлуудыг агуул�ан байх болно.
Та одоо �дг��р файл бүрийг шалгаж танд байгаа файлуудаа� х�рх�н �лгаатай болохыг
тогтоох х�р�гт�й.
/var/tmp/root дотор �уулгагд�ан зарим файлуудын н�р
урдаа .
Ñ‚Ñ�мдÑ�гттÑ�й байдгийг анхаарна уу. ÐнÑ� баримтыг бичиж байх үед
ийм файлуудтай адил файлууд /var/tmp/root/ болон
/var/tmp/root/root/ �ан дахь бүрхүүлийн �хлүүл�х файлууд
бай�ан, г�хд�� (таны х�з�� үүнийг уншиж байгаагаа� хамаарч) өөр бу�ад файлууд байхыг
үгүй�г�хгүй. Т�дг��рийг олж харахын тулд ls -a тушаалыг
заавал ашиглаарай.
Үүнийг хамгийн х�лбар аргаар хийж хоёр файлыг харьцуулахын тулд &man.diff.1;
тушаалыг ашиглах �вдал юм:
&prompt.root; diff /etc/shells /var/tmp/root/etc/shells
ÐнÑ� нь таны /etc/shells файл болон
шин� /var/tmp/root/etc/shells файлын хоорондын
Ñ�лгааг харуулна. ÐдгÑ�Ñ�рийг ашиглаж өөрийн хийÑ�Ñ�н өөрчлөлтүүдийг нийлүүлÑ�Ñ… Ñ�Ñ�вÑ�л
өөрийн хуучин файл д��р��� хуулах ���х�� шийд��р�й.
Хувилбаруудын Хоорондох Ялгаануудыг Х�лбараар Харьцуулахын Тулд Та
Шин� Root Сангаа Тухайн Үеийн Хугацаагаар ��рл��р�й
Ертөнцийг байнга дахин бүт��н� г�д�г нь /etc-г
та ба� байнга шин�чилн� г���н үг бөгөөд �н� нь ердөө л жижиг х�вшм�л ажил юм.
Та �н� проце��ийг /etc уруу нийлүүл��н
өөрийн хамгийн �үүлийн өөрчлөгд�өн файлуудыг хадгал�наар хурда�гаж болох юм.
Дараах процедур үүнийг х�рх�н хийж болох н�г �анааг өгч байна.
Ертөнцийг жирийн��р бүт��. /etc болон
бу�ад �ангуудыг шин�чл�хийг хү��хд�� тухайн цаг д��р тулгуурла�ан н�р бүхий
�анг өг. Х�р�в та үүнийг 1998 оны 2 �арын 14-нд хийж байгаа бол дараах
байдлаар хийн�:
&prompt.root; mkdir /var/tmp/root-19980214
&prompt.root; cd /usr/src/etc
&prompt.root; make DESTDIR=/var/tmp/root-19980214 \
distrib-dirs distribution
ÐнÑ� Ñ�ангийн өөрчлөлтүүдийг дÑ�Ñ�Ñ€ дурдÑ�аны дагуу нийлүүл.
Та дуу��аныхаа дараа /var/tmp/root-19980214
�анг битгий у�тгаарай.
Та �хийн хамгийн �үүлийн хувилбарыг татан авч дахин бүт��хд�� 1-р алхмыг дага.
ÐнÑ� нь танд шинÑ� Ñ�ан өгөх бөгөөд /var/tmp/root-19980221
г�ж н�рл�гд��н байж болох юм (х�р�в та шин�чл�лтүүдийг хийхд�� долоо хоног
хүл����н бол).
Та одоо &man.diff.1; ашиглан хоёр �ангийн хооронд рекур�ив diff үү�г�ж
долоо хоногийн хооронд хийгд��н өөрчлөлтүүдийг харж болно:
&prompt.root; cd /var/tmp
&prompt.root; diff -r root-19980214 root-19980221
Их�нхд�� �н� нь /var/tmp/root-19980221/etc болон
/etc хоёрын хоорондох өөрчлөлтүүдийг бодох юм бол
харьцангуй бага өөрчлөлтүүд байдаг. Өөрчлөлтүүд нь арай бага болохоор т�дг��р
өөрчлөлтүүдийг өөрийн /etc �ан уруу шилжүүл�х нь
илүү х�лбар байдаг.
Та одоо хоёр /var/tmp/root-* �ангуудын аль хуучныг
у�тгаж болно:
&prompt.root; rm -rf /var/tmp/root-19980214
/etc уруу өөрчлөлтүүдийг
нийлүүл�х болгондоо �н� проце��ийг давтах х�р�гт�й.
Та &man.date.1;-г ашиглан �ангийн н�р�ийг автоматаар үү�г�ж
болно:
&prompt.root; mkdir /var/tmp/root-`date "+%Y%m%d"`
Дахин ачаалах нь
Та ерөнхийдөө инг��д хийг��д дуу�ч байна. Та бүх зүйл байх ё�той байрандаа байгаа ���хийг шалга�ныхаа
дараа Ñ�иÑ�темийг дахин ачаалж болно. Ðнгийн &man.shutdown.8; үүнийг
хийх болно:
&prompt.root; shutdown -r now
Дуу�лаа
Одоо та өөрийн &os; �и�темийг амжилттайгаар шин�чл��д дуу��ан байх
ё�той. Ба�р хүрг�е.
Х�р�в юм� шал буруугаар �рг�в�л �и�темийн тухайн х��гийг дахин бүт��х�д амархан
байдаг. Жиш�� нь х�р�в та шин�чл�лтийн �вцад ��в�л /etc-г
нийлүүл�х �вцад �анам�аргүйг��р /etc/magic файлыг
у�тга�ан бол &man.file.1; тушаал ажиллахаа больно. Ийм тохиолдолд дараах
за�варыг ажиллуулж болох юм:
&prompt.root; cd /usr/src/usr.bin/file
&prompt.root; make all install
��уултууд
Өөрчлөлт бүрт зориулан ертөнцийг дахин бүт��х х�р�гт�й юу?
Үүнд х�лбар хариулт байхгүй, учир нь өөрчлөлтийн цаад утга чанараа�
хамаарна. Жиш�� нь х�р�в та CVSup-г
дөнгөж ажиллуулахад дараах файлууд шин�чл�гд�ж байгааг үзүүлж байгаа бол:
src/games/cribbage/instr.c
src/games/sail/pl_main.c
src/release/sysinstall/config.c
src/release/sysinstall/media.c
src/share/mk/bsd.port.mk
магадгүй бүх�л ертөнцийг дахин бүт��х х�р�ггүй байж болох юм.
Та тохирох д�д �ангууд уруу орж make all install
г�ж тушаалыг өгөөд л болох юм. Х�р�в зарим н�г гол чухал зүйл жиш�� нь
src/lib/libc/stdlib өөрчлөгд�өн бол
та ертөнцийг ��в�л хамгийн багаар бодоход �татикаар холбогд�он (statically linked)
түүний т�дг��р х��гүүдийг дахин бүт��х шаардлагатай болно.
ÐцÑ�ийн Ñ�цÑ�Ñ�Ñ‚ Ñ�нÑ� нь танааÑ� л хамаарна. Та жишÑ�Ñ� нь хоёр долоо хоног тутам
ертөнцийг дахин бүт��ж т�р хоёр долоо хоногийн хугацаанд өөрчлөлтүүдийг
хуримтлуулж байгаадаа Ñ�Ñ�тгÑ�л хангалуун байж болно. ÐÑ�вÑ�л та зөвхөн өөрчлөгдÑ�өн
зүйл�үүдийг дахин бүт��хийг хү��ж магадгүй бөгөөд бүх хамаарлуудыг шийдн�
г�д�гт�� итг�лт�й байх х�р�гт�й.
Т�г��д м�д��ж �н� бүх�н таны �мар давтамжтайгаар шин�чл�хийг хү�д�г болон
&os.stable; ��в�л &os.current;-ийн алийг дагаж байгаагаа� хамаарах
болно.
Миний �мх�тг�л маш олон дохио 11
дохио 11 (��в�л бу�ад дохионы дугаар)
алдаагаар амжилтгүй бол�он. Юу бол�он юм бол?
ÐнÑ� нь ихÑ�вчлÑ�н тоног төхөөрөмжийн аÑ�уудлыг илÑ�рхийлдÑ�г.
Ертөнцийг (дахин) бүт��х нь өөрийн тоног төхөөрөмжийг ачаалах те�т
хийх үр дүнт�й арга бөгөөд удаа дараа �анах ойн а�уудлууд байвал
Ñ‚Ñ�дгÑ�Ñ�рийг илрүүлдÑ�г. ÐмхÑ�тгÑ�гч нь Ñ�онин/хачин дохионуудыг хүлÑ�Ñ�н авч
ид шидийн байдлаар амжилтгүй бол�ноор т�дг��р а�уудлууд нь өөр�дийгөө
зарлан тунхагладаг.
Х�р�в та бүт��лтийг дахин �хлүүл��д т�р нь проце��ийн өөр өөр х���гт
амжилтгүй болж байвал �н� нь үүнийг тодоор зааж байна
г���н үг юм.
ÐнÑ� тохиолдолд та өөрийн машин дахь бүрÑ�лдÑ�хүүн Ñ…Ñ�Ñ�гүүдÑ�Ñ� өөрчлөн
н�г��� нөгөөд �ольж тавин аль нь ажиллахгүй байгааг олохоо� өөр зүйл
хийж чадахгүй л болов уу.
Би дуу��аныхаа дараа /usr/obj-г у�тгаж болох уу?
Товчхондоо бол болно.
/usr/obj нь �мх�тг�х үед бүт��гд��н бүх
обьект файлуудыг агуулдаг. Жирийн үед make buildworld
проце��ийн �хний алхмуудын н�г нь �н� �анг у�тгаад цоо шин��р �хл�х �вдал
юм. ÐнÑ� тохиолдолд /usr/obj-г дууÑ�Ñ�аныхаа
дараа байлгаад байх нь ухаалаг биш бөгөөд үүнийг у�тга�наар их��х�н х�мж��ний ди�кний зайг
�уллах болно (одоогоор 2 GB орчим).
Г�хд�� х�р�в та юу хийж байгаагаа м�д�ж байгаа бол make buildworld
хийхдÑ�Ñ� Ñ�нÑ� алхмыг алгаÑ�аж болно. ÐнÑ� нь дараа дараагийн бүтÑ�Ñ�лтийг илүү хурдаÑ�гадаг
бөгөөд учир нь их�нх �хүүд дахин �мх�тг�х шаардлагагүй байдаг. Үүний �ул тал нь
баригдашгүй хамаарлын а�уудлууд ил�рч таны бүт��лтийг хачин байдлаар амжилтгүй
болгодог. Х�н н�г�н илүү дөтлөх г��н����� болоод амжилтгүй бол�ныг м�д�лгүй өөрийн
бүт��лтийг амжилтгүй бол�ныг гомдолло�ноор &os;-ийн захидлын жаг�аалтуудад
хий д�мий шуугианыг удаа дараа үү�г�д�г бил��.
Та�алд�ан бүт��лтүүдийг үрг�лжлүүлж болох уу?
ÐнÑ� нь аÑ�уудлыг олох хүртлÑ�Ñ� та Ñ…Ñ�Ñ€ хол Ñ�вÑ�нааÑ� хамаарна.
Ерөнхийдөө (�н� нь х�цүү ба� хурдан дүр�м биш)
make buildworld проце�� нь үнд��н
багажуудын (&man.gcc.1;, болон &man.make.1; з�р�г) болон �и�темийн
�ангуудын шин� хуулбаруудыг бүт��д�г. Т�дг��р багажууд болон �ангууд нь
дараа нь �уулгагддаг. Шин� багажууд болон �ангууд дараа нь
өөр�дийгөө дахин бүт��х�д ашиглагддаг бөгөөд дахин �уулгагддаг. Бүх�л бүт�н
�и�тем (одоо &man.ls.1; ��в�л &man.grep.1; з�р�г ердийн х�р�гл�гчийн програмууд)
дараа нь шин� �и�темийн файлуудтайгаар дахин бүт��гдд�г.
Х�р�в та �үүлийн шатанд байгаа бөгөөд та үүнийг м�д�ж байгаа бол (та
хадгалж байгаа гаралтаа� хар�ан болохоор) та дараах тушаалыг ажиллуулж
(бараг л аюулгүйг��р) болно:
… fix the problem …
&prompt.root; cd /usr/src
&prompt.root; make -DNO_CLEAN all
ÐнÑ� нь өмнөх make buildworld тушаалын
хий�нийг буцаахгүй.
Х�р�в та доорх м�д�гдлийг :
--------------------------------------------------------------
Building everything..
--------------------------------------------------------------
make buildworld тушаалын гаралт д��р хар�ан
бол магадгүй т�гж хийх нь аюулгүй байж болох юм.
Х�р�в та тийм м�д�гд�л харахгүй байгаа бол ��в�л та итг�лт�й биш байгаа бол
харам�ахаа�аа өмнө аюулгүй байдлыг бодож бүт��лтийг бүр �хн��� нь дахин �хлүүл��н нь
д��р юм.
Би ертөнцийг бүт��хийг х�рх�н хурда�гах в�?
Ганц х�р�гл�гчийн горимд ажиллуул.
/usr/src болон
/usr/obj �ангуудыг ту� ту�даа байх ди�кнүүд
д��р ту� ту�даа байх файлын �и�темүүд д��р байрлуул. Х�р�в боломжтой бол
�дг��р ди�кнүүдийг ту� ту�ад нь ди�кний х�нагчууд д��р байрлуул.
&man.ccd.4; (нийлүүл��н ди�кний драйвер) төхөөрөмж ашиглан
�дг��р файлын �и�темүүдийг олон ди�кнүүдийн дагуу байрлуулах нь ба�
арай илүү хурда�гах юм.
Профиль хийгд�хийг (/etc/make.conf файлд
NO_PROFILE=true
г�ж зааж өг) болиул. Танд �н� бараг
гарцаагүй х�р�ггүй.
тохируулгыг
&man.make.1;-д дамжуулж олон процеÑ�Ñ�ийг зÑ�Ñ€Ñ�гцÑ�Ñ�гÑ�Ñ�Ñ€ ажиллуул. ÐнÑ� нь
танд ганц ��в�л олон проце��ортой машин аль нь ч бай�ан �лгаагүйг��р их�вчл�н ту�алдаг.
/usr/src-г агуулж байгаа файлын
�и�тем тохируулгаар холболт хийгд�ж (��в�л �алгагдаж)
болно. ÐнÑ� нь файлын Ñ�иÑ�тем файл уруу хандах хандалтын хугацааг бүртгÑ�хийг
болиулдаг. Танд магадгүй �н� м�д��л�л бараг л х�р�ггүй биз ��.
&prompt.root; mount -u -o noatime /usr/src
ÐнÑ� жишÑ�Ñ� /usr/src нь өөрийн файлын
�и�тем д��р байгаа г�ж тооцож байгаа болно. Х�р�в �н� нь тийм биш бол
(х�р�в �н� �ан жиш�� нь /usr-ийн х���г ма�гаар
байгаа бол) та /usr/src-г биш харин т�р
файлын �и�тем�� холболтын ц�г болгон ашиглах х�р�гт�й.
/usr/obj-г агуулж байгаа файлын �и�тем
тохируулгатай холболт хийгд�ж (��в�л �алгагдаж)
болно. ÐнÑ� нь диÑ�к уруу хийх бичилтийг аÑ�инхроноор буюу зÑ�Ñ€Ñ�г биш хийлгÑ�дÑ�г.
Өөрөөр х�лб�л бичилт н�н даруй хийгд��д өгөгдөл ди�к уруу цөөн �екундын дараа
бичигддÑ�г. ÐнÑ� нь бичилтүүдийг бүлÑ�глÑ�хийг зөвшөөрч маш их үр дүнтÑ�йгÑ�Ñ�Ñ€
ажиллагааг хурда�гаж болох юм.
ÐнÑ� тохируулга нь таны файлын Ñ�иÑ�темийг илүү
�мз�г болгохыг �анаарай. Т�ж��л та�алдаж машин дахин ачаалах үед
файлын �и�тем ��рг��ж болшгүй төлөвт орох магадлал �н� тохируулгатай
байхад илүү байдаг.
Х�р�в /usr/obj нь �н� файлын �и�тем
д��рх цорын ганц зүйл бол �н� а�уудал биш юм. Х�р�в танд уг файлын
�и�тем д��р өөр, үн�т�й өгөгдөл байгаа бол �н� тохируулгыг
ид�вхжүүл�х����� өмнө өөрийн нөөц чинь шин� ���хийг шалгаарай.
&prompt.root; mount -u -o async /usr/obj
Д��р дурд�ан шиг х�р�в /usr/obj нь
өөрийн файлын �и�тем д��р биш байх юм бол жиш��н д��рхийг
тохирох холболт хийх ц�гийн н�р��р �олиорой.
Х�р�в �мар н�г юм буруутвал би юу хийх в�?
Таны орчинд өмнөх бүт��лтүүдийн үеийн илүү үлд�гдлүүд
байхгүйд үнÑ�Ñ…Ñ�Ñ�Ñ€ итгÑ�лтÑ�й байх Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� нь их амархан
юм.
&prompt.root; chflags -R noschg /usr/obj/usr
&prompt.root; rm -rf /usr/obj/usr
&prompt.root; cd /usr/src
&prompt.root; make cleandir
&prompt.root; make cleandir
Тийм��, make cleandir тушаалыг үн�нд��
хоёр удаа ажиллуулах шаардлагатай.
Т�г��д make buildworld
тушаалыг �хлүүлж бүх проце��ийг дахин �хлүүл.
Х�р�в та а�уудалтай х�в��р байгаа бол алдаа болон
uname -a тушаалын дүнг &a.questions;
уруу �вуулаарай. Өөрийн тохиргооныхоо талаар бу�ад а�уултанд
хариулахад б�л�н байгаарай!
�нтон
Штеренлихт
Т�мд�гл�г�� хий��н
Хуучин файлууд, хавта�нууд болон �ангуудыг у�тгах
Хуучин файлууд, хавта�нууд болон �ангуудыг у�тгах
&os; хөгжүүл�лтийн �вцад файлууд болон т�дг��рийн агуулга
үе үе хуучирдаг.Т�дг��рийн үүр�г болон боломжууд өөр хаа н�гт��
хийгд��н юм уу ��в�л �ангийн хувилбарын дугаар өөрчлөгд�өн юм уу ��в�л
�и�тем��� бүрмө�өн ха�агд�анаа� болоод тийм
байж болох юм. ÐдгÑ�Ñ�рт хуучин файлууд, Ñ�ангууд болон хавтаÑ�нууд
ордог бөгөөд Ñ�дгÑ�Ñ�рийг Ñ�иÑ�темийг шинÑ�члÑ�хдÑ�Ñ� уÑ�тгах Ñ‘Ñ�той. ÐнÑ� нь
х�р�гл�гчийн хувьд хадгалах (болон нөөц) төхөөрөмж д��р х�р�гц��гүй
зай �зл��д байгаа хуучин файлуудаар �и�тем дүүр�хгүй байх ашигтай юм.
Үүн��� гадна хуучин �ан аюулгүй байдлын болон найдвартай ажиллагааны
хувьд а�уудалтай бай�ан бол та өөрийн �и�темийг аюулгүй болгож хуучин
�ангаа� болоод ажиллахаа болиод бай�ан а�уудлаа� ��ргийл�хийн тулд
шин� �ан руу шин�чл�х х�р�гт�й.
Хуучин г�гд��н файлууд, хавта�нууд, �ангуудын жаг�аалт
/usr/src/ObsoleteFiles.inc файлд байдаг.
Дараах заавар нь �и�темийг шин�чл�х �вцад хуучин файлуудыг у�тгахад
ту�лах болно.
Таныг -д заа�ны дагуу �вж байгаа г�ж �нд үзн�.
make
installworld болон дараагийн
mergemaster тушаал амжилттай х�р�гж��ний
дараа дараах ма�гаар та хуучин файлууд болон �ангуудыг шалгах
ё�той:
&prompt.root; cd /usr/src
&prompt.root; make check-old
Х�р�в �мар н�г хуучин файл олдвол дараах тушаал
ашиглан т�дг��рийг у�тгаж болно:
&prompt.root; make delete-old
Түлхүүр үг�ийн талаар д�лг�р�нгүйг �онирхож байгаа бол /usr/src/Makefile
файлыг үзн� үү.
Хуучин файл бүрийг у�тгахын өмнө а�ууж хариулах д�лг�ц гарна.
Та �н� д�лг�цийг өнгөрөөж �и�тем �дг��р файлуудыг автоматаар у�тгахаар
тохируулахын тулд BATCH_DELETE_OLD_FILES хувь�агчийг
дараах байдлаар ашиглана:
&prompt.root; make -DBATCH_DELETE_OLD_FILES delete-old
Мөн �н� зорилгод хүр�хийн тулд
доорхитой адилаар �дг��р тушаалд yes өгч хүрч болно:
&prompt.root; yes|make delete-old
�нхааруулга
Хуучин файлуудыг у�тгах нь т�дг��р хуучин файлуудаа�
хамааралтай програмуудыг ажиллахгүй болгоно.
ÐнÑ� нь Ñ�лангуÑ�а хуучин Ñ�ангуудын хувьд үнÑ�н байдаг.
Их�нх тохиолдолд та make
delete-old-libs тушаалыг биелүүл�х�����
өмнө хуучин �ан ашиглаж бай�ан програмууд, портууд ��в�л �ангуудыг
дахин бүт��х х�р�гт�й.
Хуваалц�ан �ангуудаа� хамааралтай ���хийг шалгадаг х�р�г�лүүд
sysutils/libchk ��в�л
sysutils/bsdadminscripts з�р�г портын
цуглуулгад байдаг.
Хуучин хуваалц�ан �ангууд нь шин� �ангуудтай зөрчилдөж болох
бөгөөд доорх шиг алдаа өгч болно:
/usr/bin/ld: warning: libz.so.4, needed by /usr/local/lib/libtiff.so, may conflict with libz.so.5
/usr/bin/ld: warning: librpcsvc.so.4, needed by /usr/local/lib/libXext.so, may conflict with librpcsvc.so.5
ÐдгÑ�Ñ�Ñ€ аÑ�уудлуудыг шийдÑ�хийн тулд уг Ñ�анг аль порт Ñ�уулгаÑ�ныг
олно:
&prompt.root; pkg_info -W /usr/local/lib/libtiff.so
/usr/local/lib/libtiff.so was installed by package tiff-3.9.4
&prompt.root; pkg_info -W /usr/local/lib/libXext.so
/usr/local/lib/libXext.so was installed by package libXext-1.1.1,1
Дараа нь уг портыг deinstall хийг��д дахин бүт��ж �уулгах
Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� Ñ�вцыг автоматжуулахын тулд ports-mgmt/portmaster болон ports-mgmt/portupgrade
х�р�г�лийг ашиглаж болно. Бүх портуудыг дахин бүт����н г�д�гт��
итг�лт�й бол�ны дараа хуучин �ангуудыг ашиглах х�р�ггүй бөгөөд т�дг��рийг
дараах тушаал ашиглан у�тгаж болно:
&prompt.root; make delete-old-libs
Майк
М�й�р
Хувь н�м�р болгон оруул�ан
Олон машины хувьд дагах нь
NFS
олон машин �уулгах нь
Х�р�в та олон машинуудын хувьд ижил �х модыг дагахыг хү��ж бүгдийн хувьд
�хийг татан авахуулж бүгдийг дахин бүт��хийг хү��ж байгаа бол �н� нь ди�кний зай,
�үлж��ний зурва�ын өргөн болон
CPU циклүүд з�р�г �х үү�в�рүүдийг үр ашиггүйг��р ашиглахад хүрг�х��р �анагдаж
болох юм. Тийм��, үүний шийд�л нь н�г машинаар их�нх ажлыг хийлг�ж
буÑ�ад машинууд нь Ñ‚Ñ�Ñ€ ажлыг NFS-Ñ�Ñ�Ñ€ дамжуулан холбох Ñ�вдал юм. ÐнÑ� Ñ…Ñ�Ñ�Ñ�гт
инг�ж хийх аргыг тайлбар�ан.
Б�лтг�л ажлууд
ÐхлÑ�Ñ�д хоёртын адил файлуудыг ажиллуулах build set буюу
бүт��х олонлог г�ж бидний н�рл�х машинуудыг олох х�р�гт�й.
Машин бүр өөрчлөн тохируул�ан цөмт�й байж болох бөгөөд г�хд�� т�д ижил х�р�гл�гчийн
талбарын хоёртын файлуудыг ажиллуулж байх ё�той. Т�р олонлогоо�
бүтÑ�Ñ�Ñ… машиныг Ñ�онгох Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐнÑ� нь
ертөнц болон цөм бүт��гд�х машин байх юм. Туйлын хү�л��р бол �н�
нь make buildworld болон
make buildkernel тушаалуудыг ажиллуулахад
хангалттай нөөц CPU бүхий хурдан машин байх х�р�гт�й. Та мөн
үйлдв�рл�лд ашиглахаа� өмнө програм хангамжуудыг те�т хийд�г
те�т машин �онгохыг ба� хү��ж болох юм.
ÐнÑ� нь удаан хугацаагаар унтрааÑ�тай Ñ�Ñ�вÑ�л зогÑ�Ñ�он байж болох машин байх
Ñ‘Ñ�той. ÐнÑ� нь бүтÑ�Ñ�Ñ… машин байж болох юм, гÑ�хдÑ�Ñ� заавал
биш юм.
ÐнÑ� бүтÑ�Ñ�Ñ… олонлог дахь бүх машинууд нь Ó©Ó©Ñ€ өөрийн машин дÑ�Ñ�Ñ€Ñ�Ñ�Ñ�Ñ�Ñ� ижил цÑ�г дÑ�Ñ�Ñ€
/usr/obj болон /usr/src-г
холболт хийх х�р�гт�й. Туйлын хү�л��р бол �н� нь бүт��х машин д��рх хоёр өөр ди�кнүүд
байж болох бөгөөд г�хд�� �дг��р нь уг машин д��р NFS холболт ба� хийгд�ж болохоор
байж болох юм. Х�р�в танд олон бүт��х олонлогууд байгаа бол
/usr/src �ан нь н�г бүт��х машин д��р байрлаж
бу�ад д��р нь NFS холболт хийгд��н байх юм.
Төг�гөлд нь бүт��х олонлогийн бүх машинууд д��рх /etc/make.conf
болон /etc/src.conf файлууд бүтÑ�Ñ�Ñ… машиныхтай тохирч байгаа Ñ�Ñ�Ñ�хийг шалгаарай. ÐнÑ� нь бүтÑ�Ñ�Ñ… олонлогийн
машин бүрийн �уулгах үнд��н �и�темийн бүх х��гүүдийг бүт��х машин хийх ё�той г���н
үг юм. Мөн бүт��х машин бүр өөрийн цөмийн н�рийг /etc/make.conf
файлд KERNCONF хувь�агчид заан өгөх ё�той бөгөөд бүт��х
машин бүр KERNCONF хувь�агчдаа өөрийн цөмийг �х�нд
оруулан дараа нь т�дг��рийг жаг�аах ё�той байдаг. Бүт��х машин нь машин бүрийн
цөмийг бүт��х��р болох юм бол т�дг��рийн тохиргооны файлыг
/usr/src/sys/arch/conf
�анд агуул�ан байх шаардлагатай.
Үнд��н �и�тем
Одоо бүх юм инг�ж хийгд��ний дараа та бүгдийг бүт��х�д б�л�н боллоо.
Бүт��х машин д��р -д тайлбарла�ны
дагуу цөм болон ертөнцийг бүт��, г�хд�� юуг ч битгий �уулгаарай. Бүт��лт
дуу��аны дараа те�т машин д��р дөнгөж �а�хан бүт����н цөмөө �уулга.
Х�р�в �н� машин нь /usr/src
болон /usr/obj �ангуудыг NFS-��р холболт хийх
г�ж байгаа бол та ганц х�р�гл�гчийн горимд дахин ачаалахдаа �үлж��г н��ж
т�дг��рийг холбож өгөх х�р�гт�й. Үүнийг хамгийн х�лбараар хийхийн тулд
олон х�р�гл�гчийн горимд ачаалан shutdown now
тушаалыг ажиллуулж ганц х�р�гл�гчийн горимд орох �вдал юм. Т�г�ж ор�ныхоо
дараа та шин� цөм болон ертөнцийг �уулгаж жирийн үед�� хийд�г
mergemaster тушаалыг ажиллуулж болно.
Инг�ж дуу��аныхаа дараа �н� машины хувьд ердийн олон х�р�гл�гчийн
үйлдлүүд�д дахин ачаалж орно.
Те�т машин д��рх бүх зүйл� зөв ажиллаж байгааг м�д��нийх�� дараа та
бүт��х олонлогийн бу�ад машин бүр д��р шин� програм хангамж �уулгахдаа
ижил процедурыг ашиглаарай.
Портууд
ҮүнтÑ�й адил Ñ�анааг баÑ� портуудын модонд ашиглаж болно. Ðхний чухал
алхам бол нөгөө машин д��рх /usr/ports �анг
бүт��х олонлогийн бу�ад машинууд д��р холбож өгөх �вдал юм. Дараа нь та
/etc/make.conf файлыг distfiles
буюу түг��лтийн файлуудыг хуваалцахаар зөв тохируулж өгч болно.
Та DISTDIR хувь�агчийг таны NFS холболтуудад заагд�ан
аль ч root х�р�гл�гчийн хувьд бичигд�х боломжтой байх
нийтл�г хуваалц�ан �ангаар тохируулах шаардлагатай.
Машин бүр WRKDIRPREFIX хувь�агчийг локал
бүтÑ�Ñ�Ñ… Ñ�ангаар зааж өгөх Ñ…Ñ�Ñ€Ñ�гтÑ�й. ÐцÑ�Ñ�Ñ‚ нь Ñ…Ñ�Ñ€Ñ�в та багцуудыг бүтÑ�Ñ�ж түгÑ�Ñ�Ñ…
г�ж байгаа бол PACKAGES хувь�агчийг
DISTDIR хувь�агчийн н�г�н адил �ангаар зааж өгөх
х�р�гт�й.
diff --git a/zh_CN.GB2312/articles/contributing/article.xml b/zh_CN.GB2312/articles/contributing/article.xml
index 4309e0c9bc..ba80c2c4cd 100644
--- a/zh_CN.GB2312/articles/contributing/article.xml
+++ b/zh_CN.GB2312/articles/contributing/article.xml
@@ -1,510 +1,505 @@
Ϊ FreeBSD Ìṩ°ïÖú
ÎÞÂÛÊÇ×÷Ϊ¸öÈË»¹ÊÇ×éÖ¯»ú¹¹£¬Èç¹ûÄúÏ£ÍûΪFreeBSDÏîÄ¿Ìṩ°ïÖú£¬
¶¼¿ÉÒÔÔÚ±¾ÎÄÖÐÕÒµ½ºÏÊʵķ½·¨¡£
Jordan
Hubbard
ÔÖø
&tm-attrib.freebsd;
&tm-attrib.ieee;
&tm-attrib.general;
$FreeBSD$
$FreeBSD$
¹±Ï×
ÄúÏ£Íû¸ø FreeBSD ÏîÄ¿×öµãʲôÂ𣿠̫ºÃÁË£¬ ÎÒÃÇ»¶ÓÄú¡£ FreeBSD ÕýÊÇ
ÒÀ¿¿ ¹ã´óÓû§µÄ¹±ÏײŵÃÒÔ·¢Õ¹×³´óµÄ¡£
ÎÒÃDz»½ö·Ç³£¸ÐлÄúËù×öµÄ¹±Ï×£¬¶øÇÒ£¬ÕâЩ¹¤×÷¶ÔÓÚ FreeBSD µÄ³ÖÐø·¢Õ¹Ò²ÖÁ¹ØÖØÒª¡£
Ò²ÐíÓëÄúÏëÏóµÄ²»Í¬£¬ Äú¼È²»±ØÊÇÒ»Ãû³öÉ«µÄ³ÌÐòÔ±£¬ Ò²ÎÞÐëºÍ
FreeBSD ºËÐÄÍŶӳÉÔ±ÓкܺõÄ˽½»£¬ ÎÒÃÇ»áÒ»ÊÓͬÈʵĶԴýÄúµÄ¹¤×÷¡£
FreeBSD µÄ¿ª·¢ÈËÔ±±é²¼È«Çò£¬ ´ó¼Ò¼¼Êõר³¤¸÷Ò죬 ÄêÁä·Ö²¼Ò²·Ç³£¹ã·º¡£
ÿÌ죬 ÎÒÃǶ¼ÔÚÃæ¶Ô³ÖÐøÔö³¤µÄ¹¤×÷¶ø¿àÓÚûÓÐ×ã¹»µÄÈËÊÖ£¬
Òò´ËÎÒÃÇËæÊ±»¶ÓÄúµÄ°ïÖú¡£
FreeBSD ÏîÄ¿´¦ÀíµÄÊÇÒ»¸öÍêÕûµÄ²Ù×÷ϵͳ»·¾³£¬
¶ø²»Ö»ÊÇÒ»¸öÄں˻òÊÇһЩÁãÉ¢µÄ¹¤¾ß°ü¡£ Òò´Ë£¬ ÎÒÃǵÄ
TODO ÈÎÎñÁбíÀï°üº¬¸÷ÖÖ¸÷ÑùµÄ¹¤×÷£¬
´ÓÎĵµ¡¢Óû§²âÊÔ¡¢ÑÝʾ£¬ µ½ÏµÍ³°²×°³ÌÐòºÍ¸ß¶ÈרҵµÄÄں˿ª·¢¡£
Òò´ËÎÞÂÛÄúµÄ¼¼ÊõˮƽÈçºÎ£¬ ´ÓʺÎÖÖÁìÓò£¬ ¶¼¿ÉÒÔ°ïÖúÕâ¸öÏîÄ¿¡£
ÎÒÃǹÄÀø´ÓÊÂºÍ FreeBSD Ïà¹Ø¹¤×÷µÄÆóÒµºÍÎÒÃÇÁªÏµ¡£
ÄúÐèÒªÒ»Ð©ÌØÊâµÄÀ©Õ¹À´Ê¹ÄúµÄ²úÆ·ÔËתÆðÀ´Ã´£¿
Äú»á·¢ÏÖÎÒÃǺÜÀÖÒâ´ðÓ¦ÄúµÄÇëÇó£¬ ³ý·ÇÊÇÌØ±ðÏ¡Ææ¹Å¹ÖµÄ¡£
ÄúÊÇ·ñÕý´ÓÊÂÏà¹ØµÄÔöÖµÒµÎñ£¿ ÈÃÎÒÃÇÀ´°ïÖúÄú°É£¬
ÎÒÃÇÒ²Ðí¿ÉÒÔÔÚÆäÖеÄijЩ·½ÃæÏ໥Ð×÷¡£
×ÔÓÉÈí¼þÊÀ½çÕýÔÚŬÁ¦´òÆÆ¾ÉÓеĹØÓÚÈí¼þ¿ª·¢¡¢ ÏúÊÛºÍά»¤µÄ¿ò¿ò£¬
ÎÒÃÇÏ£Íû¿ÒÇëÄúÖÁÉÙÄܸøËüÒ»´Î»ú»á¡£
ÎÒÃǵÄÐèÇó
ÏÂÃæÁгöÁËһЩÐèÒªÍê³ÉµÄÈÎÎñºÍ×ÓÏîÄ¿£¬
ËüÃÇ»ù±¾ÉÏ¿ÉÒÔ±»µÈͬÓÚ TODO(ÈÎÎñÁбí)
ÁÐ±í£¬ ÒÔ¼°Óû§µÄÒªÇó¡£
ÕýÔÚ½øÐÐÖеķǿª·¢ÈÎÎñ
ºÜ¶à²Î¼ÓFreeBSDÏîÄ¿µÄÈ˲»ÊdzÌÐòÔ±¡£
Õâ¸öÏîÄ¿ÀïÓÐÎĵµ×«Ð´Õß¡¢ ÍøÒ³Éè¼ÆÊ¦¡¢ ÒÔ¼°¼¼ÊõÖ§³ÖÈËÔ±¡£
¶ÔÓÚÕâЩ־ԸÕßÀ´Ëµ£¬ ËûÃÇÖ»ÐèÒª¹±Ï×һЩʱ¼ä£¬
²¢ÇÒ¾ßÓÐѧϰµÄÒâÔ¸¡£
Äú¿ÉÒÔ¾³£Í¨¶ÁFAQºÍÊֲᣬ Èç¹ûÄú·¢ÏÖÁË·±ËöµÄ½âÊÍ£¬
»òÕßÊǹýʱµÄ֪ʶ£¬ ÉõÖÁÍêÈ«²»ÕýÈ·µÄµØ·½£¬ ¶¼Çë¸æËßÎÒÃÇ¡£
Èç¹ûÄúÄÜ˳ÊÖ°ÑËûÃǸĹýÀ´ÄǾ͸üºÃÁË
(SGMLÆäʵ²¢²»ÄÑѧ£¬ µ«ÎÒÃÇÒ²²»·´¶ÔÄúÖ±½ÓÌá½»
ASCII µÄ°æ±¾)¡£
°ïÖúÎÒÃÇ°Ñ FreeBSD Îĵµ·Òë³ÉÄúµÄĸÓï¡£
Èç¹ûÄúµÄĸÓï°æ±¾ÒѾ´æÔÚÁË£¬
ÄúÒ²¿ÉÒÔ·ÒëһЩÆäËûµÄÎĵµ»òÕß¼ì²éÄÇЩÒÑÓеÄÎĵµÊÇ·ñÊÇ×îиüйýµÄ¡£
Äú¿ÉÒÔÏȼòµ¥¿´¿´ FreeBSD Îĵµ¼Æ»®ÖÐÓÐ¹Ø ·ÒëµÄ³£¼ûÎÊÌâ¡£
²Î¼Ó·Ò빤×÷²¢²»ÊÇ˵ÄúÒª¹Â¾ü·ÜÕ½·ÒëËùÓÐµÄ FreeBSD Îĵµ¡£
×÷Ϊһ¸öÖ¾Ô¸Õߣ¬ ×ö¶àÉÙ¹¤×÷Íêȫȡ¾öÓÚÄúµÄÒâÔ¸¡£ Ò»µ©Ä³¸öÈË¿ªÊ¼·ÒëÁË£¬
ÆäËûÈ˼¸ºõÒ»¶¨»á²ÎÓëµ½ÕâЩ¹¤×÷ÖÐÀ´¡£
Èç¹ûÄúÖ»ÓÐÓÐÏÞµÄʱ¼ä»òÕß¾«Á¦È¥·Ò벿·ÖÎĵµ£¬
Äú¿ÉÒÔÊ×ÏÈÈ¥·Òë°²×°Ö¸ÄÏ¡£
ÔĶÁ &a.questions; ²¢Å¼¶û¿´Ò»¿´ &ng.misc;
(ÉõÖÁÓйæÂɵØÕâÑù×ö)¡£ Óë±ðÈË·ÖÏíÄúµÄרҵ֪ʶ£¬
²¢°ïÖúËûÃǽâ¾öÎÊÌâÊÇÒ»¼þÁîÈËÓäÔõÄÊÂÇ飻
ÓÐЩʱºòÄúÉõÖÁ¿ÉÒÔÔÚÕâ¸ö¹ý³ÌÖÐѧµ½Ò»Ð©Ð¶«Î÷£¡
ÕâЩÂÛ̳ÓÐʱҲ»áΪÄúÌṩһЩÓмÛÖµµÄÖ÷Òâ¡£
ÕýÔÚ½øÐеĿª·¢ÈÎÎñ
ÁÐÔÚÕâÀïµÄ´ó²¿·ÖÈÎÎñ¶¼ÐèÒªÄúͶÈë¿É¹ÛµÄʱ¼ä£¬
»òÕßÐèÒªÄúÔÚ FreeBSD Äں˷½ÃæÓзḻµÄ֪ʶ£¬ »òÕßÁ½Õß¶¼Òª¡£
µ±È»ÕâÀïÒ²ÓкܶàÖØÒªµÄÈÎÎñÒ²ÐíÄúÒ»¸ö
ÖÜÄ©¿ª·¢ÈËÔ±
¾Í¿ÉÒÔ¸ÉÍê¡£
Èç¹ûÄúÕýÔÚÔËÐÐ FreeBSD-CURRENT °æ±¾²¢ÇÒÓÐÒ»Ìõ¸ßËÙµÄ
Internet½ÓÈëÏß·£¬ Äú¿ÉÒÔ·ÃÎÊ current.FreeBSD.org£¬
ÕâÀïÿÌì»áÓÐÒ»¸öа汾 — Èç¹ûÄúÓпգ¬
Äú¿ÉÒÔ¸ôÈý²íÎ嵨ÏÂÔØÒ»·Ý²¢ÇÒ°²×°Ëü£¬
Æä¼äÈç¹û³öÁËʲôÎÊÌ⣬Çë¸æËßÎÒÃÇ¡£
ÔĶÁ &a.bugs;¡£ Äú¿ÉÄÜ»áΪÕâЩÎÊÌâÌṩ¾ßÓн¨ÉèÐÔÒâÒåµÄÆÀÂÛ£¬
»òÕß°ïæ²âÊÔһЩ²¹¶¡¡£ ´ËÍ⣬
ÄúÉõÖÁ¿ÉÒÔ³¢ÊÔÐÞÕýÆäÖеÄһЩÎÊÌâ¡£
Èç¹ûÄúÖªµÀÓÐһЩÐÞÕýÒѾÔÚ -CURRENT Éϳɹ¦µØ½øÐУ¬
µ«ÔÚ¾¹ýÒ»¶Îʱ¼äÖ®ºóÈÔȻûÓкϲ¢µ½ -STABLE
(ͨ³£ÊÇ 2ÖÜ×óÓÒ)£¬ ¸øÏà¹ØµÄ committer ·¢Ò»·âÀñòµÄÌáʾÐÅ¡£
½«µÚÈý·½Èí¼þ¼ÓÈëµ½Ô´´úÂëÖеÄ
src/contrib Ŀ¼¡£
È·±£ src/contrib
ÖеĴúÂëÊÇ×îеÄ
ÒÔ¸ü¸ßµÄ¾¯¸æ¼¶±ð¹¹½¨Ô´´úÂë (»òÒ»²¿·ÖÔ´´úÂë)
²¢ÇåÀíÕâЩ¾¯¸æ¡£
¸üÐÂÄÇЩÔÚ ports ÖÐʹÓùýʱµÄ¶«Î÷£¬
ÀýÈç gets() »ò°üº¬
malloc.h Ëù²úÉúµÄ¾¯¸æ¡£
Èç¹ûÄúÖÆ×÷ÁË ports£¬ ²¢½øÐÐÁËһЩÕë¶Ô
&os; µÄ¸Ä¶¯£¬ ½«ÄúµÄ²¹¶¡·¢»Ø¸øÔ×÷Õß
(ÕâÑùÏ´ÎÉý¼¶Ê±ÄúµÄ¹¤×÷»á±äµÃÇáËÉһЩ)¡£
»ñȡһ·ÝÕýʽµÄ±ê×¼£¬ Èç &posix; µÄ¸±±¾¡£
Äú¿ÉÒÔÔÚ FreeBSD
C99 & POSIX ±ê׼˳ӦÏîÄ¿ ÍøÕ¾Éϵõ½Ïà¹ØµÄÁ´½Ó¡£
½« FreeBSD µÄÐÐΪͬ±ê×¼½øÐбȽϡ£ Èç¹ûÓë±ê×¼²»Í¬£¬
ÌØ±ðÊÇÄÇЩϸ½ÚµØ·½µÄ΢С²îÒ죬 Çë·¢ËÍÒ»¸ö¹ØÓÚËüµÄ PR (ÎÊÌⱨ¸æ)¡£
Èç¹û¿ÉÄÜ£¬ ÇëÖ¸³öÈçºÎÐÞÕýËü£¬ ²¢Ëæ PR Ìá½»²¹¶¡¡£
Èç¹ûÄúÈÏΪ±ê×¼ÓÐÎÊÌ⣬
ÇëÏò±ê×¼»¯ÍÅÌåÒªÇó¶ÔÆä½øÐÐÖØÐµĿ¼ÂÇ¡£
ΪÕâ·ÝÁÐ±í½¨Òé¸ü¶àµÄÄÚÈÝ£¡
²é¿´Õû¸ö PR Êý¾Ý¿â
ÎÊÌⱨ¸æÊý¾Ý¿â
FreeBSD
PR Áбí չʾÁËËùÓе±Ç°´¦ÓÚ»îԾ״̬µÄÎÊÌⱨ¸æ£¬ ÒÔ¼°ÓÉ
FreeBSD Óû§Ìá½»µÄ¸Ä½ø½¨Òé¡£ PR
Êý¾Ý¿âͬʱ°üÀ¨ÁË¿ª·¢ÈËÔ±ºÍ·Ç¿ª·¢ÈËÔ±µÄÈÎÎñ¡£
²é¿´ÄÇЩÉÐδ½â¾öµÄ PR£¬ ²¢¿´¿´ÊÇ·ñÓÐÄú¸ÐÐËȤµÄÈÎÎñ¡£
ÕâÆäÖпÉÄÜÓÐһЩÊǷdz£¼òµ¥µÄÎÊÌ⣬
Ö»ÐèÒª¿´Ò»¿´²¢È·ÈÏ PR ÊÇÕýÈ·µÄ¡£ ÁíÍâһЩ¿ÉÄÜ»á·Ç³£¸´ÔÓ£¬
»òÕßÍêȫûÓаüÀ¨ÈκÎÐÞÕý¡£
Ê×ÏÈ¿´Ò»¿´ÄÇЩ»¹Ã»ÓÐÈ˽ÓÊÖµÄ PR¡£
Èç¹û PR ÒѾ·ÖÅ䏸ÁËÆäËüÈË£¬ µ«¿´ÆðÀ´ÊÇÄúÄܹ»´¦ÀíµÄ£¬
Äú¿ÉÒÔ¸øÄǸöÈË·¢ÐÅ£¬ ²¢Ñ¯ÎÊÄúÊÇ·ñ¿ÉÒÔÌṩ°ïÖú —
ËûÃÇ¿ÉÄÜÒѾÓÐÁ˿ɹ©²âÊԵIJ¹¶¡£¬ »òÓÐһЩ¿É¹©ÌÖÂÛµÄÒâ¼û¡£
´Ó µã×Ó
ÍøÒ³ÉÏÈÏÁìÏîÄ¿
&os;
Ö¾Ô¸ÕßÏîÄ¿ºÍµã×ÓÇåµ¥ Ò²ÊÇÌṩ¸øÔ¸ÒâΪ
&os; ÏîÄ¿×ö³ö¹±Ï×µÄÈËÃǵġ£
ÕâÕÅÇåµ¥Ò»Ö±ÔÚ±»¶¨ÆÚ¸üÐÂ×Å£¬
°üº¬Á˶ԳÌÐòÔ±ºÍ·Ç³ÌÐòÔ±ÓÐÓõÄÿ¸öÏîÄ¿µÄÐÅÏ¢¡£
ÈçºÎÌṩ°ïÖú
°ïÖú¸Ä½øÏµÍ³»ù±¾ÉÏ¿ÉÒÔ·ÖΪ 5 Àࣺ
´íÎ󱨸æºÍÒ»°ãµÄ×¢½â
ͨ³££¬ Ò»°ãÒâÒåÉϵÄ
¼¼ÊõÏë·¨ºÍ½¨ÒéÓ¦¸Ã·¢µ½ &a.hackers;¡£
ͬÑùµØ£¬ ¶ÔÓÚÕâЩ¶«Î÷ÓÐÐËȤµÄÈË (µ±È»£¬
ËûÃÇͬʱ»¹ÒªÄܹ»ÈÝÈÌ ´óÁ¿µÄ Óʼþ£¡)
¿ÉÒÔ¿¼ÂǶ©ÔÄ &a.hackers;¡£
²Î¼û FreeBSD
ʹÓÃÊÖ²á ÒÔÁË½â¹ØÓÚÕâ¸öÓʼþÁÐ±í£¬
ÒÔ¼°ÆäËüÓʼþÁбíµÄÏêϸÇé¿ö¡£
Èç¹ûÄú·¢ÏÖÁË bug »òÕßÏëÒªÌύijЩÐ޸ģ¬
Çëͨ¹ý &man.send-pr.1; ³ÌÐò»òʹÓÃ
»ùÓÚ WEB
µÄÌá½»Ò³Ãæ À´Ìá½»¡£ ÇëÊÔ×ÅÌîд bug ±¨¸æµÄÿһÏî¡£
Ò»°ãÀ´Ëµ£¬ ÎÒÃǽ¨ÒéÔÚ bug ±¨¸æÖÐÖ±½Ó¸½Éϲ¹¶¡£¬ ³ý·ÇËü³¬¹ýÁË 65KB¡£
Èç¹û²¹¶¡¿ÉÒÔÖ±½ÓÓ¦Óõ½Ô´´úÂëÉÏ£¬ Ôò½¨ÒéÄúÔÚ±¨¸æµÄ
synopsis Ò»À¸Ð´ÉÏ [PATCH]¡£
ÔÚ¸½´ø²¹¶¡Ê±£¬ Çë ²»Òª
ͨ¹ý¸´ÖƺÍÕ³ÌùÀ´½øÐУ¬ ÒòΪÕâÑù×ö»á°Ñ tab ±ä³É¿Õ¸ñ£¬
½á¹û²¹¶¡ºÜ¿ÉÄܾͲ»ÄÜÓÃÁË¡£ Èç¹û²¹¶¡³¬¹ý 20KB ºÜ¶à£¬
Ó¦¿¼Âǽ«ÆäѹËõ (ÀýÈçʹÓà &man.gzip.1; »ò &man.bzip2.1;)
Ö®ºóÓà &man.uuencode.1; ½øÐбàÂëÖ®ºóÔٷŽøÄúµÄÎÊÌⱨ¸æÖС£
Ò»µ©±¨¸æ±»´æµµ£¬ Äú»áÊÕµ½Ò»·âÈ·ÈÏÓʼþÒÔ¼°Ò»¸öʼþ×·×Ù±àºÅ¡£
Çë±£ÁôÕâ¸ö±àºÅ£¬ ÒòΪÄú¿ÉÒÔÔÚÖ®ºóʹÓÃÕâ¸ö±àºÅ£¬
·¢Óʼþµ½ &a.bugfollowup;
À´Ìṩ¹ØÓÚ¸ÃʼþµÄ½øÒ»²½ÐÅÏ¢¡£ ÄúÐèÒª×öµÄÊǽ«±àºÅ·Åµ½ÓʼþµÄ±êÌâÖУ¬
ÀýÈç "Re:
kern/3377"¡£
¹ØÓÚͬһÎÊÌâ¸ü½øÒ»²½µÄÇé¿öÓ¦¸Ãͨ¹ýÕâÖÖ·½Ê½À´Ìá½»¡£
Èç¹ûÄúÔÚÒ»¶Îʱ¼äÖ®ºóÈÔȻûÓÐÊÕµ½È·ÈÏÐÅ (³¬¹ý 3
ÌìÉõÖÁ 1 ÖÜ£¬ ÕâÈ¡¾öÓÚÄúµÄÓʼþ·þÎñ)
»òÕßÓÉÓÚijÖÖÔÒòÎÞ·¨Ê¹Óà &man.send-pr.1; ÃüÁ
Ôò¿ÉÒÔ·¢ÐŸø &a.bugs; ÒªÇó±ðÈË´úÄú·¢ËÍËü¡£
Çë²Î¼û ÕâÆªÎÄÕÂ
Á˽âÈçºÎ׫дºÃµÄÎÊÌⱨ¸æ¡£
¶ÔÓÚÎĵµµÄÐÞ¶©
Ìá½»Îĵµ
¶ÔÓÚÎĵµµÄÐÞ¸ÄÓÉ &a.doc; À´Éó²é¡£
Çë²Î¼û FreeBSD
Îĵµ¼Æ»®³õ¼¶¶Á±¾ À´»ñµÃÍêÕûµÄÖ¸µ¼¡£
Çë°´ÕÕ ÖнéÉܵķ½·¨Ê¹Óà &man.send-pr.1;
À´·¢ËÍеÄÎĵµ»òÕß¶ÔÓÚÏÖÓÐÎĵµµÄÍêÉÆ (ÄÄÅÂÊǺÜСµÄ¸Ä½øÒ²ÊÇ»¶ÓµÄ£¡)¡£
¶ÔÓÚÏÖÓÐÔ´´úÂëµÄÐÞ¸Ä
FreeBSD-CURRENT
ÔÚÏÖÓдúÂëÉϽøÐÐÐ޸ĻòÔö¼Ó¹¦ÄÜÔÚijÖ̶ֳÈÉÏÊÇÐèÒª¸ü¶à¼¼ÇɵÄÊÂÇ飬
²¢ÇÒ»¹ºÍÄú¶ÔÓÚĿǰ FreeBSD µÄ¿ª·¢ÏÖ×´µÄÁ˽âÓйء£
ÓжàÖÖ·½Ê½¿ÉÒԵõ½±»³Æ×÷ FreeBSD-CURRENT
µÄ FreeBSD ¿ª·¢°æ±¾£¬ Äú¿ÉÒÔͨ¹ýËüÀ´Á˽â×î½üµÄ¿ª·¢Çé¿ö¡£
Çë²Î¼û FreeBSD
ʹÓÃÊÖ²á À´Á˽âʹÓà FreeBSD-CURRENT µÄ½øÒ»²½ÏêÇé¡£
ÔھɵĴúÂëÉϽøÐÐÐ޸ģ¬ Ôòͨ³£¿ÉÄÜÓÉÓÚ´úÂëÒѾ¹ýʱ£¬
»òÓëеĿª·¢°æ±¾²îÒìÌ«´ó¶øÎÞ·¨±»ÖØÐ¼¯³Éµ½ FreeBSD ÖС£
Èç¹ûÄú¶©ÔÄÁË &a.announce; ÒÔ¼° &a.current; ÓʼþÁÐ±í£¬
Ôò¿ÉÒÔͨ¹ýËüÃÇÀ´´óÌåÁ˽âĿǰµÄ¿ª·¢×´Ì¬¡£
¼ÙÈç˵ÄúÄܹ»»ùÓÚ¾¡¿ÉÄÜеĴúÂëÀ´Íê³ÉÄúµÄÐ޸ģ¬
ÔòÏÂÒ»²½Òª×öµÄÊÂÇé¾ÍÊÇÉú³ÉÄúËù½øÐеÄÐ޸ĵIJîÒìÎļþ£¬
²¢½«Ëü·¢¸ø FreeBSD µÄά»¤ÈËÔ±¡£ ÕâÏ×÷¿ÉÒÔͨ¹ý &man.diff.1;
ÃüÁîÀ´Íê³É¡£
Ìá½»²¹¶¡Ê±ÍƼöµÄ &man.diff.1; ¸ñʽÊÇÒ»Ö²îÒì (unified diff)£¬
Ëü¿ÉÒÔͨ¹ý diff
-u À´Éú³É¡£ ²»¹ý£¬ Èç¹ûÄúÐÞ¸ÄÁË´óÁ¿µÄ´úÂ룬
ÔòʹÓà diff -c À´Éú³ÉµÄÉÏÏÂÎĸñʽ (context diff)
µÄ²îÒì¿ÉÄܸüÈÝÒ×ÔĶÁ£¬ Òò¶øÍƼöʹÓá£
diff
ÀýÈ磺
&prompt.user; diff -c oldfile newfile
»òÕß
&prompt.user; diff -c -r olddir newdir
½«·Ö±ðÉú³É¸ø¶¨Îļþ»òĿ¼½á¹¹µÄ context diff¡£
ÀàËÆµØ£¬
&prompt.user; diff -u oldfile newfile
»ò
&prompt.user; diff -u -r olddir newdir
µÄ×÷ÓÃÓëÇ°ÃæµÄÀàËÆ£¬ µ«²ÉÓõĸñʽÊÇ unified diff¡£
Çë²Î¼û &man.diff.1; Áª»úÊÖ²áÁ˽â¸ü¶àϸ½Ú¡£
Ò»µ©ÄúʹÓà &man.diff.1; Éú³ÉÁ˲îÒ켯 (¿ÉÒÔʹÓÃ
&man.patch.1; ÃüÁîÀ´²âÊÔÒ»ÏÂ)£¬ ¾Í¿ÉÒÔÌá½»ËüÃÇ£¬
ÒԱ㱻 FreeBSD ÊÕ¼¡£ ͨ¹ýʹÓÃ
ÖÐËù½éÉÜµÄ &man.send-pr.1; ³ÌÐò¾Í¿ÉÒÔÍê³ÉÕâÏ×÷¡£
²»Òª Ö»ÊǰѲîÒ켯·¢µ½ &a.hackers;£¬
·ñÔòËüÃÇ¿ÉÄܻᱻ¶ªµô£¡ ÎÒÃÇ»á·Ç³£¸Ð¼¤ÄúÌá½»µÄÐÞ¸Ä
(ÕâÊÇÒ»¸öÖ¾Ô¸ÕßÏîÄ¿£¡)£» ÒòΪÎÒÃǶ¼ºÜ棬
Òò´ËÓÐʱ²»Ò»¶¨Äܹ»Á¢¼´ÐÞÕýÎÊÌ⣬ µ« PR
Êý¾Ý¿â½«Ò»Ö±±£³Ö×ÅÕâЩ¼Ç¼£¬
Òò´ËÖ»ÒªÓÐÈËÓÐÁËʱ¼äËüÃǾÍÄܱ»¸ÄÕýÁË¡£
Èç¹ûÄúµÄÎÊÌⱨ¸æÖаüÀ¨²¹¶¡£¬ Ò»¶¨²»ÒªÍüÁËÔÚ±êÌâÉÏÓÃ
[PATCH] À´Ç¿µ÷һϡ£
uuencode
Èç¹ûÄúÈÏΪºÏÊÊ (ÀýÈçÄúÌí¼Ó¡¢ ɾ³ý»òÖØÃüÃûÁËÎļþ)£¬
»¹¿ÉÒÔ¿¼ÂÇʹÓÃ
tar À´½«Îļþ´ò°ü£¬ È»ºóÓà &man.uuencode.1;
À´±àÂë¡£ ÎÒÃÇÒ²»¶ÓÓà &man.shar.1; ´´½¨µÄ°ü¡£
Èç¹ûÄúµÄÐ޸ĿÉÄÜ´æÔÚDZÔÚµÄÕùÒ飬 ÀýÈ磬
Äú²»È·¶¨ÓëÖ®Ïà¹ØµÄ°æÈ¨ÎÊÌ⣬ »òÕ߸оõÐèÒª¾¹ý¸üÑϸñµÄ¸´Éó²Å¿ÉÒÔ·¢²¼ËüÃÇ£¬
ÔòÓ¦Ö±½Ó·¢¸ø &a.core;£¬ ¶ø²»ÊÇͨ¹ý &man.send-pr.1; À´·¢ËÍ¡£
&a.core; ÊÇÒ»¸öС×飬 Æä³ÉÔ±¸ü¶àµÄ´ÓÊ FreeBSD µÄÈÕ³£¹¤×÷¡£
ÐèҪעÒâµÄÊÇ£¬ Õâ¸öС×éÒ²Òò´Ë ºÜ棬
Òò´ËÖ»ÓÐÔڷdz£±ØÒªµÄʱºò²ÅÓ¦¸øËûÃÇдÐÅ¡£
Çë²Î¿¼ &man.intro.9; ºÍ &man.style.9; ÒÔÁË½â¹ØÓÚ±àÂëϰ¹ßºÍÔ¼¶¨µÄÏêÇé¡£
Èç¹ûÄúÁ˽âÕâЩԼ¶¨£¬ Ôò¶ÔÎÒÃÇÀ´Ëµ½«ÊǼ«´óµÄ°ïÖú¡£
дúÂë»òÖØÒªµÄÔöÖµÈí¼þ°ü
Èç¹ûÄú´òËãÌṩ¹æÄ£½Ï´óµÄ´úÂ룬 »òÕßΪ FreeBSD Ôö¼ÓÖØÒªµÄй¦ÄÜ£¬
Ôò¿ÉÄܱØÐ뽫ËüÃÇͨ¹ý uuencode ½øÐбàÂ룬 »ò´«µ½Ä³¸ö Web »ò
FTP Õ¾µã£¬ ÒÔ±ã¸ü¶àµÄÈËÄܹ»µÃµ½Ëü¡£ Èç¹ûÄúûÓÐÕâÑùµÄ·þÎñÆ÷£¬
Çëµ½Ïà¹ØµÄ FreeBSD ÓʼþÁбíÌá³ö£¬ ¿´¿´ÊÇ·ñÓÐÈËÔ¸Òâ°ïÄú·ÅÖÃËüÃÇ¡£
¶ÔÓÚ´óÁ¿µÄ´úÂë¶øÑÔ£¬ ¹ØÓÚ°æÈ¨µÄÎÊÌâ¿Ï¶¨»á±»Ìá³ö¡£
FreeBSD »ù±¾ÏµÍ³ÖÐÄܹ»Ê¹ÓõİæÈ¨ÉùÃ÷°üÀ¨£º
- BSD °æÈ¨ÉùÃ÷
- BSD °æÈ¨¡£ ÎÒÃÇÇãÏòÓÚʹÓÃÕâÀàÊÚȨµÄ´úÂ룬
+ BSDBSD °æÈ¨ÉùÃ÷ °æÈ¨¡£ ÎÒÃÇÇãÏòÓÚʹÓÃÕâÀàÊÚȨµÄ´úÂ룬
ÒòΪËü ²»¸½¼Ó¶àÓàµÄÌõ¼þ
£¬ Òò¶ø¸üÄܹ»ÎüÒýÉÌÒµÆóҵʹÓá£
FreeBSD ²¢²»·´¶ÔÉÌÒµ¹«Ë¾Ê¹ÓÃËüµÄ´úÂ룬 Ïà·´£¬
ÎÒÃÇ»ý¼«µØ¹ÄÀøÉÌÒµ¹«Ë¾Ê¹ÓÃÎÒÃǵĴúÂ룬
µ±È»£¬ Èç¹ûËüÃÇ×îÖÕ°ÑÒ»²¿·Ö´úÂëÖØÐ¾èÔù¸ø FreeBSD
¾Í¸üºÃÁË¡£
- GPLGNU General Public License
-
- GNU General Public License
-
- GNU General Public License£¬ »ò¼ò³Æ GPL
¡£
+ GNU General Public License£¬GPLGNU General Public LicenseGNU General Public License »ò¼ò³Æ GPL
¡£
ÎÒÃDz¢²»ºÜ»¶ÓʹÓÃÕâÑùÊÚȨµÄ´úÂ룬
ÒòΪÉÌÒµ¹«Ë¾Ê¹ÓÃËüÐèÒª×ö¸ü¶àµÄ¹¤×÷¡£ ²»¹ý£¬ ÓÉÓںܶàʹÓÃ
GPL ÊÚȨµÄ´úÂëĿǰÊÇÎÞ·¨±ÜÃâµÄ (±àÒëÆ÷¡¢ »ã±àÆ÷£¬
Îı¾ÅŰæ³ÌÐòµÈµÈ)£¬ ¾Ü¾øÊ¹ÓÃËùÓвÉÓÃÕâÑùÊÚȨµÄÈí¼þÊǺܲ»Ã÷Öǵġ£
²ÉÓà GPL ÊÚȨµÄ´úÂë»á±»·Åµ½Ô´´úÂëµÄһЩרÃŵÄλÖ㬠ÀýÈç
/sys/gnu »ò
/usr/src/gnu£¬
ÒÔ·½±ãÄÇЩʹÓà GPL ´úÂë¿ÉÄÜ»á¸øËûÃÇ´øÀ´ÎÊÌâµÄÈËʶ±ð¡£
ʹÓÃÆäËüÊÚȨµÄ´úÂëÔÚ½øÈë FreeBSD ֮ǰ±ØÐë¾¹ýÉ÷ÖØµÄ¸´ÉóºÍ¿¼ÂÇ¡£
²ÉÓðüº¬ÑÏÀ÷ÏÞÖÆµÄÉÌÒµÊÚȨµÄ´úÂ룬 Ò»°ãÀ´Ëµ»á±»¾Ü¾ø£¬
µ«ÎÒÃǹÄÀøÕâЩ´úÂëµÄ×÷Õßͨ¹ý×Ô¼ºµÄÇþµÀÀ´·¢²¼ËüÃÇ¡£
ÒªÔÚÄúµÄ³É¹ûÉϼÓÈë BSDʽ
µÄ°æÈ¨£¬
Çë°ÑÏÂÁÐÎı¾·Åµ½Ã¿Ò»¸öÔ´ÎļþµÄ×ʼ²¿·Ö£¬
²¢ÓÃÊʵ±µÄÎÄ×ÖÌæ»» %% Ö®¼äµÄÎÄ×Ö¡£
Copyright (c) %%proper_years_here%%
%%your_name_here%%, %%your_state%% %%your_zip%%.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer as
the first lines of this file unmodified.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY %%your_name_here%% ``AS IS'' AND ANY EXPRESS OR
IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
IN NO EVENT SHALL %%your_name_here%% BE LIABLE FOR ANY DIRECT, INDIRECT,
INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
$Id$
ΪÁË·½±ãÄúµÄʹÓ㬠ÔÚ
/usr/share/examples/etc/bsd-style-copyright
Ò²¿ÉÒÔÕÒµ½´ËÊÚȨµÄ¸±±¾¡£
×ʽ𡢠Ӳ¼þ»ò Internet ½ÓÈë
ÎÒÃǷdz£Ô¸Òâ½ÓÊܸ÷ÖÖÐÎʽµÄ¾èÔù£¬ ÒÔ½øÒ»²½ÍØÕ¹ FreeBSD
Project µÄÊÂÒµ£¬ ÒòΪÓÐÄúµÄÖ§³Ö£¬
ÏñÎÒÃÇÕâÑùµÄÖ¾Ô¸ÕßŬÁ¦²ÅÄܹ»Óиü´óµÄ³É¾Í£¡
¾èÔùÓ²¼þÒ²·Ç³£ÖØÒª£¬ ÒòΪÕâÑùÄܹ»°ïÖúÎÒÃÇÔö¼Ó¿ÉÒÔÖ§³ÖµÄÓ²¼þÖÖÀ࣬
¶øÎÒÃÇÖеĺܶàÈ˲¢Ã»ÓÐ×ã¹»µÄ×ʽðÀ´¹ºÖÃÕâЩӲ¼þ¡£
¾è¿î
FreeBSD »ù½ð»áÊÇÒ»¸ö·ÇÓªÀûµÄ¡¢ ÓпÎ˰»íÃâȨµÄ»ù½ð»á£¬
½¨Á¢Õâ¸ö»ù½ð»áµÄÄ¿±êÊÇΪÁËÈà FreeBSD Project Äܹ»´ï³É¸ü¼Ó³¤Ô¶µÄÄ¿±ê¡£
×÷Ϊ 501(c)3 ʵÌ壬 Ò»°ã¶øÑÔ»ù½ð»á¿ÉÒÔÃâÓèÉϽÉÃÀ¹úÁª°îÊÕÈë˰£¬
ÒÔ¼°¿ÆÂÞÀ¶àÖÝÊÕÈë˰¡£ ͨ³£¶ÔÓÚ¿Î˰»íÃâµÄʵÌå½øÐоèÔù£¬
¿ÉÒÔÕÛµÖÁª°îÊÕÈëÖÐÓ¦¿Î˰²¿·ÖµÄ½ð¶î¡£
Äú¿ÉÒÔ°Ñ֧Ʊ¼ÄÍù£º
The FreeBSD Foundation
7321 Brockway Dr.
Boulder, CO 80303
USA
FreeBSD »ù½ð»áÏÖÔÚ¿ÉÒÔͨ¹ý PayPal ´ÓÍøÉϽÓÊܾè¿î¡£
Èç¹ûÄúÏëÏò»ù½ð»á¾è¿î£¬ Çë·ÃÎÊËüµÄ web
Õ¾µã¡£
¹ØÓÚ FreeBSD »ù½ð»áµÄ¸ü¶àÏêÇ飬 ¿ÉÒÔÔÚ FreeBSD
»ù½ð»á -- ½éÉÜ ÕÒµ½¡£ ÒªÁªÂç»ù½ð»á£¬
Çë·¢Ë͵ç×ÓÓʼþµ½
bod@FreeBSDFoundation.org¡£
¾èÔùÓ²¼þ
¾èÔù
FreeBSD ¼Æ»®»¶ÓÈκÎÈ˾èÔù¿ÉÒÔʹÓõÄÓ²¼þ¡£
Èç¹ûÄúÓÐÐËȤ¾èÔùÓ²¼þ£¬ ÇëÁªÏµ ¾èÔùÁªÂçÈ˰칫ÊÒ¡£
¾èÔù Internet ½ÓÈë
ÎÒÃÇ»¶ÓÐ嵀 FTP¡¢ WWW »ò
cvsup ¾µÏñ¡£ Èç¹ûÄúÏ£Íû³ÉΪÕâÑùµÄ¾µÏñ£¬
Çë²Î¼û ÈçºÎ¼ÜÉè FreeBSD ¾µÏñ
Ò»ÎÄ£¬ ÒÔÁË½â½øÒ»²½µÄÇé¿ö¡£
diff --git a/zh_CN.GB2312/books/handbook/boot/chapter.xml b/zh_CN.GB2312/books/handbook/boot/chapter.xml
index 67e51f1240..72edb0e0df 100644
--- a/zh_CN.GB2312/books/handbook/boot/chapter.xml
+++ b/zh_CN.GB2312/books/handbook/boot/chapter.xml
@@ -1,868 +1,864 @@
FreeBSD Òýµ¼¹ý³Ì
¸ÅÊö
Òýµ¼
Æô¶¯µçÄÔÒÔ¼°¼ÓÔØ²Ù×÷ϵͳµÄ¹ý³Ì±»³ÆÎªÒýµ¼¹ý³Ì
£¬
»òÕß¼ò³ÆÎªÒýµ¼
¡£
FreeBSD µÄÒýµ¼¹ý³Ì¸øÓû§×Ô¶¨ÒåÆô¶¯ÌṩÁ˺ܴóµÄÉìËõÐÔ£¬
Äú¿ÉÒÔÑ¡ÔñÆô¶¯²»Í¬µÄ²Ù×÷ϵͳ£¬»òÕßÊÇͬһϵͳµÄ²»Í¬°æ±¾¼°Äںˡ£
±¾Õ½«Ïêϸ½éÉÜÄúÄÜÔÚ FreeBSD Òýµ¼¹ý³ÌÖÐÉèÖõÄÅäÖÃÑ¡Ïî¡£
Õâ°üÀ¨ÁËÒýµ¼Äںˡ¢Ì½²âÉ豸²¢Æô¶¯ &man.init.8; µÈµÈ֮ǰËù·¢ÉúµÄËùÓÐÊÂÇé¡£
ÕâЩÊÂÏîÒ»°ã·¢ÉúÔÚÎı¾Óɰױä»Òʱ¡£
¶ÁÍêÕâÕÂÄú½«»áÖªµÀ£º
FreeBSD Òýµ¼ÏµÍ³ÀïµÄ¸÷Ïî×é¼þ£¬
ÒÔ¼°ËüÃÇÖ®¼äµÄ½»»¥·½Ê½.
ÔÚ FreeBSD Òýµ¼Ê±¸ø¸÷×é¼þÅäÖÃÑ¡ÏîÒÔ¿ØÖÆÒýµ¼¹ý³Ì¡£
&man.device.hints.5;µÄ»ù±¾ÖªÊ¶¡£
Ö»ÊÊÓÃÓÚx86
±¾ÕÂÖ»ÃèÊöÁËÔËÐÐÓÚ Intel x86 Ìåϵ֮É쵀 FreeBSD µÄÒýµ¼¹ý³Ì¡£
Òýµ¼ÎÊÌâ
Æô¶¯µçÄÔ¼°Æô¶¯ºÍÒýµ¼²Ù×÷ϵͳ¹¹³ÉÁËÒ»¸öÓÐȤµÄÁ½ÄѾ³µØ¡£
°´ÕÕ¶¨ÒåÔÚ²Ù×÷ϵͳ±»Æô¶¯Ö®Ç°¼ÆËã»úÊÇÎÞ·¨Íê³ÉÈκÎÈÎÎñµÄ£¬°üÀ¨ÔËÐдÅÅÌÉϵijÌÐò¡£
Èç¹û¼ÆËã»úÔÚûÓвÙ×÷ϵͳµÄÇé¿öϲ»ÄÜÔËÐÐÀ´×ÔÓÚ´ÅÅÌÉϵijÌÐò¶ø²Ù×÷ϵͳÓÖÊÇ·ÅÔÚ´ÅÅÌÉϵģ¬
ÄDzÙ×÷ϵͳÊÇÈçºÎÆô¶¯µÄÄØ£¿
ÔÚ MunchausenÄоôÀúÏÕ¼Ç (The Adventures of
Baron Munchausen) Õâ±¾ÊéÖÐÓÐÒ»¸öºÍÕâ¸ö¹ý³ÌÀàËÆµÄ¹ÊÊ£¬
Ò»¸öÈ˵ôµ½ÁËÏÂË®¹ÜµÀÀ È»ºó¿¿×ÅÀ×Ô¼ºµÄÑ¥ñá (bootstrap)
¿Ë·þÖØÖØÀ§ÄÑÅÀÁ˳öÀ´¡£ ÔÚÔçÆÚÎÄÏ×ÖУ¬ ¶àÒÔÊõÓï
bootstrap À´Ö¸´ú²Ù×÷ϵͳµÄ¼ÓÔØ»úÖÆ£¬
Èç½ñËüÖð½¥±»¼òдΪ booting
¡£
BIOS
»ù±¾ÊäÈë/Êä³öϵͳBIOS
ÔÚ x86 Ó²¼þÌåϵÖУ¬»ù±¾ÊäÈë/Êä³öϵͳ (BIOS) ¸ºÔð¼ÓÔØ²Ù×÷ϵͳ£¬
ΪÁË×öµ½ÕâÒ»µã£¬BIOS ÔÚ´ÅÅÌÉÏѰÕÒÖ÷Òýµ¼¼Ç¼ (MBR)£¬¶ø MBR
±ØÐëÔÚ·ÅÖõĴÅÅ̵ÄÌØ¶¨Î»Öá£BIOS ÓÐ×ã¹»µÄÄÜÁ¦À´¶ÁÈëºÍÔËÐÐ MBR£¬
ÇÒ¼ÙʹµØÈÏΪ MBR ÄÜÍê³É¼ÓÔØ²Ù×÷ϵͳµÄÊ£ÓàÈÎÎñ£¬
MBR¿ÉÄÜÐèÒªBIOSµÄ°ïÖú¡£
Master Boot Record (MBR)
Boot Manager
Boot Loader
ÔÚMBRÖеĴúÂëͨ³£±»ÌáΪÒýµ¼¹ÜÀíÆ÷£¬
ÓÈÆäÊÇÓëÓû§½»»¥µÄÄÇÀà¡£ÕâÒ»ÀàÒýµ¼Æ÷ͨ³£Óиü¶à´úÂëλÓÚ´ÅÅ̵ÚÒ»
¹ìµÀ»òÔÚ²Ù×÷ϵͳµÄÎļþϵͳÖС£
(Òýµ¼¹ÜÀíÆ÷ÓÐʱҲ±»³ÆÎªboot loader£¬
µ«ÊÇFreeBSD¶ÔºóÃæµÄÒýµ¼½×¶Î²ÅʹÓÃÕâ¸öÊõÓï¡£)
Á÷ÐеÄÒýµ¼¹ÜÀíÆ÷°üÀ¨boot0(Òà³ÆBoot
Easy£¬±ê×¼µÄ &os; Òýµ¼¹ÜÀíÆ÷)¡¢
Grub¡¢GAG£¬ÒÔ¼°
LILO¡£
(Ö»ÓÐboot0ÄÜ×°µÃ½øMBR¡£)
Èç¹ûÄúÖ»°²×°ÁËÒ»¸ö²Ù×÷ϵͳ£¬ÄÇôһ¸ö±ê×¼µÄ MBR ¾Í×ã¹»ÁË¡£
Õâ¸ö MBR ÏÈÔÚ´ÅÅÌÉÏËÑË÷¿ÉÒýµ¼µÄ(Òà³Æ¡°»î¶¯µÄ¡±)·ÖÇø£¬
È»ºóÔËÐзÖÇøÉϵĴúÂëÒÔ¼ÓÔØ²Ù×÷ϵͳµÄÆäËü²¿·Ö¡£
MBRÓÉ&man.fdisk.8;°²×°£¬ÊÇÒ»¸öȱʡµÄMBR¡£Ïà¹ØÎļþΪ
/boot/mbr¡£
Èç¹ûÄúÔÚ´ÅÅÌÉϰ²×°Á˶à¸ö²Ù×÷ϵͳÄÇôÄú¿ÉÒÔ°²×°Ò»¸ö²»Í¬µÄ
Òýµ¼¹ÜÀíÆ÷£¬ËüÄÜÏÔʾһÕŲÙ×÷ϵͳµÄÁÐ±í£¬ÄúÄÜ´ÓÖÐÑ¡ÔñÆô¶¯Äĸö¡£
ÕâÑùµÄÁ½ÖÖÒýµ¼Æ÷½«ÔÚÏÂһС½ÚÖÐÌÖÂÛ¡£
Æô¶¯ÏµÍ³µÄÊ£Óಿ·Ö±»·ÖΪÈý¸ö½×¶Î¡£µÚÒ»½×¶ÎÓÉ
MBR Ö´ÐÐ,ËüÖ»ÊÇʹ¼ÆËã»ú½øÈëÌØ¶¨µÄ״̬ȻºóÖ´Ðеڶþ½×¶Î¡£
µÚ¶þ½×¶ÎÉÔ΢¸ÉµÃ¶àһЩ¡£µÚÈý½×¶ÎÍê³É¼ÓÔØ²Ù×÷ϵͳµÄÈÎÎñ¡£
¹¤×÷±»·ÖΪÈý¸ö½×¶ÎÊÇÒòΪ PC ±ê×¼¶ÔµÚÒ»µÚ¶þ½×¶ÎÖ´ÐеijÌÐòµÄ´óСÓÐËùÏÞÖÆ¡£
°ÑÕâЩÈÎÎñÁ¬ÔÚÒ»ÆðʹµÃ FreeBSD ¿ÉÒÔÌṩ¸ü´óÉìËõÐԵļÓÔØÆ÷ (loader)¡£
ÄÚºË
init
È»ºóÄÚºËÆô¶¯£¬Ëü¿ªÊ¼Ì½²âÉ豸²¢³õʼ»¯ËüÃÇ¡£
Ò»µ©ÄÚºËÒýµ¼½ø³ÌÍê³ÉÈÎÎñ£¬Äں˽«¿ØÖÆÈ¨½»¸øÓû§½ø³Ì &man.init.8;£¬
ËüÈ·ÈÏ´ÅÅÌÊÇ·ñ´¦ÓÚ¿ÉÓÃ״̬¡£&man.init.8; È»ºó¿ªÊ¼Óû§¼¶×ÊÔ´ÅäÖãº
¼ÓÔØÎļþϵͳÆô¶¯Íø¿¨£¬¼°´ÖÂÔµØÆô¶¯ËùÓÐ FreeBSD
ϵͳ¼ÓÔØÊ±¾³£ÔËÐеĽø³Ì¡£
Òýµ¼¹ÜÀíÆ÷ºÍ¸÷Òýµ¼½×¶Î
Boot Manager
The Boot Manager
Ö÷Òýµ¼¼Ç¼ (MBR)
ÔÚMBR»òÒýµ¼¹ÜÀíÆ÷ÖеĴúÂëÓÐʱ±»ÌáΪÒýµ¼¹ý³ÌµÄ
½×¶Î0¡£ÕâһС½Ú±ãÊÇÇ°ÃæÌáµ½Òýµ¼Æ÷ÖеÄÁ½ÖÖ£º
boot0ºÍLILO¡£
boot0Òýµ¼¹ÜÀíÆ÷£º
ÓÉ FreeBSD µÄ°²×°³ÌÐòÒÔ¼° boot0cfg(8) Ëù°²×°µÄ MBR£¬
ĬÈÏ»ùÓÚ /boot/boot0¡£
(³ÌÐòboot0·Ç³£¼òµ¥£¬
ÓÉÓÚÔÚMBRÖеijÌÐòÖ»ÄÜÓÐ446×Ö½Ú³¤£¬
·ÖÇø±íºÍMBRÄ©¶ËµÄ0x55AA±êʶҲҪ¼·Õ¼Ò»Ð©¿Õ¼ä¡£)
Èç¹ûÄãÒѾ°²×°boot0
²¢ÇÒÓжà¸ö²Ù×÷ϵͳÔÚÄãµÄÓ²ÅÌÉÏ£¬
ÄÇôÄãÈç¹ûÄú°²×°ÁË FreeBSD MBR ¶øÇÒ°²×°Á˶à¸ö²Ù×÷ϵͳ£¬
Ôò»áÔÚϵͳÆô¶¯Ê±¿´µ½ÀàËÆÏÂÃæµÄÌáʾ£º
boot0 ½ØÆÁ
F1 DOS
F2 FreeBSD
F3 Linux
F4 ??
F5 Drive 1
Default: F2
ĿǰÒѾ֪µÀһЩÆäËü²Ù×÷ϵͳ£¬ÌرðÊÇ &windows; £¬ »áÒÔ×Ô¼ºµÄ
MBR ¸²¸ÇÏÖÓÐ MBR¡£ Èç¹û·¢ÉúÁËÕâÖÖÊÂÇ飬 »òÕßÄúÏëÓÃ
FreeBSD µÄ MBR ¸²¸ÇÏÖÓÐµÄ MBR£¬Äú¿ÉÒÔʹÓÃÒÔϵÄÃüÁ
&prompt.root; fdisk -B -b /boot/boot0 device
device ÊÇҪдÈë MBR
µÄÉ豸Ãû£¬±ÈÈç ad0
´ú±íµÚÒ»¸ö IDE ´ÅÅÌ£¬ad2
´ú±íµÚ¶þ¸ö IDE ¿ØÖÆÆ÷ÉϵĵÚÒ»¸ö IDE ´ÅÅÌ£¬
da0 ´ú±íµÚÒ»¸ö SCSI ´ÅÅÌ£¬µÈµÈ¡£
ÒÖ»ò£¬Èç¹ûÄãÐèÒªÒ»¸ö×ÔÐÐÅäÖõÄMBR£¬ÇëʹÓÃ&man.boot0cfg.8;¡£
The LILO Boot Manager:
ÒªÏë°²×°Õâ¸öÒýµ¼¹ÜÀíÆ÷²¢Ò²ÓÃÀ´Òýµ¼FreeBSD£¬
Ê×ÏÈÆô¶¯Linux£¬²¢½«ÒÔÏÂÑ¡Ïî¼ÓÈëµ½ÒÑÓеÄÅäÖÃÎļþ
/etc/lilo.conf£º
other=/dev/hdXY
table=/dev/hdX
loader=/boot/chain.b
label=FreeBSD
ÔÚÉÏÃæµÄÄÚÈÝÀʹÓÃLinuxµÄ±êʾ·ûÖ¸¶¨ÁËFreeBSDµÄÖ÷·ÖÇøºÍÇý¶¯Æ÷£¬
½«XÌæ»»ÎªLinuxÇý¶¯Æ÷×Öĸ£¬
½«YÌæ»»ÎªLinuxÖ÷·ÖÇøºÅ¡£
Èç¹ûÄúʹÓõÄÊÇ SCSI Çý¶¯Æ÷£¬ÄúÐèÒª½«
/dev/hd ¸Ä³É /dev/sd£¬
ÕâÀïÔÙ´ÎʹÓÃÁË XY µÄÓï·¨¡£
Èç¹ûÄú°²×°µÄÁ½¸öϵͳÔÚͬһÇý¶¯Æ÷ÉÏ£¬
Ñ¡Ïî¿ÉÒÔÈ¥µô¡£ÏÖÔÚÄú¿ÉÒÔÖ´ÐÐ /sbin/lilo -v
ʹÐÞ¸ÄÉúЧ£»Ó¦¼ì²éÆÁÄ»ÉϵÄÏûϢȷÈÏÐ޸ġ£
µÚÒ»½×¶Î£¬/boot/boot1£¬ºÍµÚ¶þ½×¶Î£¬
/boot/boot2
¸ÅÄîÉÏ£¬µÚÒ»£¬µÚ¶þ½×¶ÎͬÊôÓÚÒ»¸ö³ÌÐò£¬´¦ÓÚ´ÅÅ̵ÄÏàÍ¬ÇøÓò¡£µ«ÓÉÓÚ¿Õ¼äÏÞÖÆ£¬
ËüÃDZ»·ÖΪÁ½²¿·Ö¡£¿ÉÊÇÄú×ÜÊÇ»áÒ»Æð°²×°ËüÃÇ¡£ËüÃÇÓɰ²×°Æ÷»ò
bsdlabel(¼ûÏÂÎÄ)¸´ÖÆ×Ô±»×éºÏ¶ø³ÉµÄ
/boot/boot¡£
ËüÃÇλÓÚÎļþϵͳÍ⣬Òýµ¼·ÖÇøµÄµÚÒ»¹ìµÀ£¬´ÓµÚÒ»ÉÈÇø¿ªÊ¼¡£ÔÚÕâÀïboot0£¬»òÕßÈÎºÎÆäËüÒýµ¼¹ÜÀíÆ÷£¬
ÆÚÍûÕÒµ½Ò»¸ö³ÌÐòÔËÐУ¬¼ÌÐøÒýµ¼½ø³Ì¡£
ËùʹÓõÄÉÈÇøÊý¿ÉÓÉ/boot/bootµÄ´óСȷ¶¨¡£
boot1 ·Ç³£¼òµ¥£¬ÒòΪËüÔÙ¶àÒ²Ö»ÄÜÓÐ 512 ×Ö½Ú£¬
Ö»ÄÜʶ±ð´¢´æ×Å·ÖÇøÐÅÏ¢µÄ bsdlabel£¬
¼°Ñ°ÕÒÖ´ÐÐ boot2¡£
boot2 ÉÔ΢Óеã¼ÓÇ¿£¬Äܹ»Àí½â FreeBSD
µÄÎļþϵͳÒÔ±ãÓÚѰÕÒÀïÃæµÄÎļþ£¬
ÄÜÌṩѡÔñÄں˺ͼÓÔØÆ÷µÄ¼òµ¥½çÃæ¡£
ÒòΪ loader ÓÐןüÇ¿µÄ¹¦ÄÜ£¬
ÌṩÁËÒ»Ì×Ò×ÓÚʹÓõÄÒýµ¼ÅäÖã¬boot2 Ò»°ã¶¼Ö´ÐÐ loader£¬
µ«ÒÔǰËüµÄÈÎÎñÊÇÖ±½ÓÔËÐÐÄںˡ£
boot2 µÄÆÁÄ»Êä³ö
>> FreeBSD/i386 BOOT
Default: 0:ad(0,a)/boot/loader
boot:
Èç¹ûÄúÒª¸ü¸ÄÒѰ²×°µÄ boot1 ºÍ
boot2£¬ÇëʹÓÃÃüÁî
&man.bsdlabel.8;¡£
&prompt.root; bsdlabel -B diskslice
diskslice ÊÇÓÃÓÚÒýµ¼µÄ´ÅÅ̺ͷÖÇø£¬
±ÈÈç ad0s1
´ú±íµÚÒ»¸ö IDE ´ÅÅÌÉϵĵÚÒ»¸ö·ÖÇø¡£
dangerously dedicated
Èç¹ûÄúÔÚ &man.bsdlabel.8; ÃüÁîÖÐֻʹÓÃÁË´ÅÅÌÃû£¬±ÈÈç
ad0£¬¾Í»áÆÆ»µ´ÅÅÌÉϵÄËùÓзÖÇø¡£
Õ⵱Ȼ²»ÊÇÄúËùÏ£ÍûµÄ£¬ËùÒÔÔÚ°´Ï »Ø³µ ֮ǰ
Ò»¶¨Òª¶ÔÃüÁî½øÐжà´ÎÈ·ÈÏ¡£
µÚÈý½×¶Î£¬/boot/loader
boot-loader
¼ÓÔØÆ÷ (loader) ÊÇÈý¸ö½×¶ÎÖеÄ×îºó½×¶Î£¬
ÇÒÊÇ·ÅÖÃÔÚÎļþϵͳ֮Öеģ¬Ò»°ãÊÇÎļþ
/boot/loader¡£
loader ±»×÷ΪһÖÖÓѺõÄÅäÖ÷½Ê½£¬Ê¹ÓÃÁËÒ»×éÄÚ½¨ÇÒÒ×ÓõÄÃüÁ¡£
ÕâЩÃüÁîÓÉÒ»¸öÇ¿´óµÄ¶àµÄ½âÊÍÆ÷Ö§³Ö¹¹½¨£¬Æä±¾Éí´øÓи´ÔӵöàµÄÃüÁ¡£
Loader ³ÌÐòÁ÷³Ì
³õʼʱ£¬loader »á̽²â¿ØÖÆÌ¨ºÍ´ÅÅÌ£¬Ê¶±ðÊÇ´ÓÄÄ¿éÅÌÒýµ¼µÄ¡£
Ëü»á¸ù¾ÝÕâЩÐÅÏ¢ÉèÖñäÁ¿£¬
Æô¶¯½âÊÍÆ÷ÒÔ½ÓÊÜͨ¹ý½Å±¾»ò½»»¥·½Ê½´«À´µÄÓû§ÃüÁî¡£
loader
loader ÅäÖÃ
loader È»ºó»á¶ÁÈ¡²¢ÔËÐÐ /boot/loader.rc£¬
ĬÈϵضÁÈ¡ /boot/defaults/loader.conf
ÒÔÉèÖÿɿ¿µÄĬÈϱäÁ¿£¬¶ÁÈ¡ /boot/loader.conf
¶ÔÕâЩ±äÁ¿×÷±¾µØÐ޸ġ£loader.rc
ÒÀ¾ÝÕâЩ±äÁ¿½øÐж¯×÷£¬¼ÓÔØÈκα»Ñ¡ÔñµÄÄ£¿éºÍÄںˡ£
×îºó£¬Ä¬Èϵأ¬loader »áÍ£Áô 10 ÃëµÈ´ý°´¼ü£¬
ÈôûÓз¢ÉúÖжϣ¬¾Í¿ªÊ¼Òýµ¼Äںˡ£Èç¹û±»Öжϣ¬Óû§»áµÃµ½Ò»¸öÃüÁîÐÐÌáʾ·û£¬
ÔÚÕâÀïÓû§µÃ¸ü¸Ä±äÁ¿¡¢Ð¶ÔØËùÓÐÄ£¿é¡¢¼ÓÔØÄ£¿é¡¢×îºóÒýµ¼
»òÖØÐÂÒýµ¼¡£
Loader ÄÚ½¨µÄÃüÁî
ÕâЩÊÇ×î³£ÓÃµÄ loader ÃüÁî.¶ÔËùÓпÉÓÃÃüÁîµÄ½âÊÍÇë²Î¼û
&man.loader.8;¡£
autobootseconds
ÔÚ¸ø¶¨µÄʱ¼äÄÚÈç¹ûûÓÐÖжϷ¢Éú¾ÍÒýµ¼Äںˡ£ËüÏÔʾһ¸öµ¹Êý¼ÆÊ±£¬
ĬÈϵÄʱ¼ä·¶Î§ÊÇ 10 Ãë¡£
boot
-options
kernelname
Á¢¼´°´Ö¸¶¨µÄÑ¡ÏîÆô¶¯Ö¸¶¨Ãû×ÖµÄÄÚºË (Èç¹ûÓÐÖ¸¶¨µÄ»°)¡£
Ö»ÓÐÊ×ÏÈÖ´Ðйý unload
ÃüÁîÖ®ºóÖ¸¶¨µÄÄÚºËÃû×ֲŻáÉúЧ£¬
·ñÔò£¬ Æô¶¯µÄ½«ÊÇÏÈǰÒѾ¼ÓÔØµÄÄںˡ£
boot-conf
»ùÓÚ±äÁ¿¶Ô¸÷ÖÖÄ£¿é½øÐÐ×Ô¶¯ÅäÖà (ºÍÒýµ¼ÄÚºËʱ·¢ÉúµÄÒ»Ñù)¡£
ÄúÖ»Ðë¼ÇסҪÏÈʹÓà unload ÃüÁ
È»ºóÐÞ¸ÄһЩ±äÁ¿£¬±ÈÈç kernel¡£
help
topic
ÏÔʾ´ÓÎļþ /boot/loader.help
¶ÁÈ¡µÄ°ïÖúÐÅÏ¢¡£Èç¹û¸ø¶¨µÄÖ÷ÌâÊÇ index£¬
ÄÇôÁгöÀ´µÄÊÇËùÓпÉÓõÄÖ÷Ìâ¡£
include filename
…
ͨ¹ý¸ø¶¨µÄÎļþÃû´¦ÀíÎļþ¡£Îļþ±»¶ÁÈ룬Ȼºó±»Ò»ÐÐÒ»ÐеؽâÊÍ¡£
ÈκδíÎó¶¼»áÁ¢¼´ÖÐÖ¹ include ÃüÁî¡£
load
type
filename
¼ÓÔØÄںˡ¢ÄÚºËÄ£¿é£¬»òÕßÊǸø¶¨ÀàÐ͵ÄÎļþ (ͨ¹ý¸ø¶¨µÄÎļþÃû)¡£
ÈκÎÔÚÎļþÃûºóÃæµÄ²ÎÊý¶¼»á±»´«¸øÎļþ¡£
ls
path
ÏÔʾ¸ø¶¨Â·¾¶»òÕßÊǸùĿ¼ (Èç¹û·¾¶Ã»ÓÐÖ¸¶¨) ÏÂÃæµÄÎļþÁÐ±í¡£
Èç¹ûÖ¸¶¨ÁË Ñ¡ÏÎļþ´óСҲ»áÏÔʾ¡£
lsdev
ÁгöËùÓпÉÒÔ¼ÓÔØÄ£¿éµÄÉ豸¡£
Èç¹ûÖ¸¶¨ÁË Ñ¡Ï»áÏÔʾ³ö¸ü¶àµÄϸ½Ú¡£
lsmod
ÏÔʾÒѱ»¼ÓÔØµÄÄ£¿é¡£Èç¹ûÖ¸Ã÷ÁË Ñ¡Ï
»áÏÔʾ¸ü¶àµÄϸ½Ú¡£
more filename
ÏÔʾָ¶¨µÄÎļþ£¬Ã¿¸ô LINES Í£¶ÙÒ»´Î¡£
reboot
Á¢¼´ÖØÆôϵͳ¡£
set variable
set
variable=value
ÉèÖà loader µÄ»·¾³±äÁ¿¡£
unload
ÒÆ³ýËùÓÐÒѱ»¼ÓÔØµÄÄ£¿é¡£
Loader ʾÀý
ÕâÀïÓÐһЩʵ¼ÊÖÐ loader Ó÷¨µÄʾÀý
- single-user mode
- Ö»ÊǼòµ¥µÄÒýµ¼Ä¬ÈÏÄںˣ¬²»Í¬µÄÊǽøÈëµ¥Óû§Ä£Ê½£º
+ Ö»ÊǼòµ¥µÄÒýµ¼Ä¬ÈÏÄںˣ¬²»Í¬µÄÊǽøÈëµ¥Óû§Ä£Ê½£ºsingle-user mode
boot -s
Ð¶ÔØÄ¬ÈÏÄں˺ÍÄ£¿é£¬È»ºó¼ÓÔØ¾ÉµÄ (»òÕ߯äËü) µÄÄںˣº
-
- kernel.old
-
unload
load kernel.old
Äú¿ÉÒÔʹÓñ»³ÆÎªÍ¨ÓÃÄÚºËµÄ kernel.GENERIC£¬
- »òÕßÄúÒÔǰ°²×°µÄÄÚºË kernel.old
+ »òÕßÄúÒÔǰ°²×°µÄÄÚºË kernel.oldkernel.old
(µ±ÄúÉý¼¶»òÅäÖÃÁËÄú×Ô¼ºµÄÄں˵Èʱºò)¡£
ʹÓÃÒÔÏÂÃüÁî¼ÓÔØ³£ÓõÄÄ£¿éºÍÁíÒ»¸öÄںˣº
unload
set kernel="kernel.old"
boot-conf
¼ÓÔØÄÚºËÅäÖýű¾£º
load -t userconfig_script /boot/kernel.conf
Joseph J.
Barbish
Contributed by
Æô¶¯Ê±µÄ Splash ͼÏñ
ÔÚÆô¶¯Ê±³öÏÖµÄ splash ͼÏñ±ÈÆðÔ±¾µÄÆô¶¯ÐÅÏ¢¸ü¼Ó¿ÉÊÓ»°¡£
Õâ¸öͼÏñ½«±»Ê¼ÖÕÏÔʾÔÚÆÁÄ»ÉÏÖ±µ½³öÏÖ¿ØÖÆÌ¨µÄµÇ¼Ìáʾ»òÕß
X ÏÔʾ¹ÜÀíÆ÷ÌṩÁ˵Ǽ»Ãæ¡£
ÔÚ &os; ϵͳÖÐÓÐÁ½¸ö»ù±¾µÄ»·¾³¡£
µÚÒ»¸öÊÇĬÈÏ´«Í³µÄ¿ØÖÆÌ¨ÃüÁîÐл·¾³¡£ ÔÚϵͳÆô¶¯Ö®ºó£¬
»áÔÚ¿ØÖÆÌ¨ÉϳöÏÖÒ»¸öµÇ¼Ìáʾ¡£ µÚ¶þ¸ö»·¾³ÊÇ X11
×ÀÃæÍ¼Ðλ·¾³¡£ ÔÚ°²×°ÁË X11
ºÍÒ»ÖÖͼÐÎ ×ÀÃæ»·¾³£¬
±ÈÈç GNOME£¬
KDE£¬ »òÕß
XFce£¬
X11 ×ÀÃæ¿ÉÒÔÓà startx ÃüÁîÔËÐС£
±ÈÆð´«Í³»ùÓÚ×Ö·ûµÄµÇ¼Ìáʾ£¬ÓÐЩÓû§¿ÉÄܸüϲ»¶ X11
ͼÐλ¯µÄµÇ¼½çÃæ¡£ ͼÐλ¯µÄµÇ¼¹ÜÀíÆ÷Ïñ
&xorg; µÄ XDM£¬
GNOME µÄ gdm£¬
KDE µÄ kdm
(»¹ÓÐÆäËû Port Collection ÖеÄ)
»ù±¾É϶¼ÌṩÁËÒ»¸öͼÐλ¯µÄµÇ¼½çÃæ´úÌæ¿ØÖÆÌ¨ÉϵĵǼÌáʾ·û¡£
Ôڳɹ¦µÇ¼֮ºó£¬ ËüÃÇÕ¹ÏÖ¸øÓû§Ò»¸öͼÐλ¯µÄ×ÀÃæ¡£
ÔÚÃüÁîÐл·¾³£¬ splash
ͼÏñ½«ÔÚÏÔʾµÇ¼Ìáʾ·û֮ǰÒþ²ØËùÓÐÆô¶¯Ê±µÄ¼à²âÓëÈÎÎñÆô¶¯µÄÏûÏ¢¡£
ÔÚ X11 »·¾³£¬ Óû§½«»á»ñµÃÒ»¸öÊÓ¾õÉϸü¼ÓÇåˬÆô¶¯ÌåÑ飬
ÀàËÆÓÚijЩÏñ (µsoft; &windows; »òÕß·Ç &unix; ÀàÐ͵Äϵͳ)
Óû§ËùÏ£ÍûÌåÑéµ½µÄ¡£
Splash ͼÏñ¹¦ÄÜ
ĿǰµÄ splash ͼÏñµÄ¹¦ÄܽöÏÞÓÚÖ§³Ö 256 É«µÄλͼ
(.bmp) »òÕß ZSoft
PCX (.pcx) Îļþ¡£
´ËÍ⣬ splash ͼÏñÎļþµÄ·Ö±æÂʱØÐëÊÇ 320x200 ÏñËØ»òÕ߸üÉÙ£¬
²Å¹»ÄÜÔÚ±ê×¼ VGA ÊÊÅäÆ÷ÉÏʹÓá£
ҪʹÓóߴç¸ü´óµÄͼÏñ£¬ ´ïµ½×î´ó·Ö±æÂÊ 1024x768 ÏñËØ£¬
ÔòÐ迪Æô &os; µÄ VESA Ö§³Ö¡£
Õâ¿ÉÒÔͨ¹ýÔÚϵͳÆô¶¯Ê±¼ÓÔØ VESA Ä£¿éÍê³É£¬
»òÕßÔÚÄÚºËÅäÖÃÎļþÖмÓÈë VESA Ñ¡Ïî²¢±àÒë
(²ÎÔÄ )¡£ VESA
Ö§³Ö¸øÓèÁËÓû§ÏÔʾ¸²¸ÇÕû¸öÏÔʾÆ÷µÄÆô¶¯»ÃæÄÜÁ¦¡£
ÔÚÆô¶¯µÄʱºò splash ͼÏñ¾Í»á±»ÏÔʾÔÚÆÁÄ»ÉÏ£¬
Ëü¿ÉÒÔÔÚÈκÎʱºò¶¼°´ÈÎÒâ¼ü¹Ø±Õ¡£
Splash ͼÏñͬÑùÒ²»áÊÇ X11 Ö®ÍâĬÈÏµÄÆÁÄ»±£»¤¡£
ÔÚÒ»¶Îʱ¼äµÄÏÐÖÃºó£¬ÆÁÄ»±ã»áתΪÖÜÆÚÐԵı任ÏÔʾ splash ͼÏñ£¬
´ÓÃ÷ÁÁÖÁ°µµ£¬ Öܶø¸´Ê¼¡£ ĬÈ쵀 splash ͼÏñ (ÆÁÄ»±£»¤)
¿ÉÓÉ /etc/rc.conf ÖеÄ
saver= Ñ¡Ïî¿ØÖÆ¡£
saver= Ñ¡ÏîÓÐһЩÄÚÖÃµÄÆÁÄ»±£»¤¿É¹©Ñ¡Ôñ£¬
ÍêÕûµÄÁбí¿ÉÒÔÔÙ &man.splash.4; ÊÖ²áÒ³ÖÐÕÒµ½¡£
ĬÈÏµÄÆÁÄ»±£»¤±»³ÆÎª warp
¡£
Çë×¢ÒâÔÚ /etc/rc.conf ÖÐËùÖ¸¶¨
saver= Ñ¡Ïî½öÏÞÓ¦ÓÃÓÚÐéÄâ¿ØÖÆÌ¨¡£
¶ÔÓÚ X11 ͼÐλ¯µÄµÇ¼¹ÜÀíÆ÷ÎÞЧ¡£
һЩÓÐ¹ØÆô¶¯Òýµ¼Æ÷µÄÐÅÏ¢£¬
°üÀ¨Æô¶¯Ñ¡Ïî²Ëµ¥ºÍÒ»¸ö¶¨Ê±µ¹ÊýÌáʾ·û¶¼»áÔÚÆô¶¯Ê±ÏÔʾ£¬
¼´ÊÇ¿ªÆôÁË splash ͼÏñ¹¦ÄÜ¡£
splash ͼÏñÎļþÑù±¾¿ÉÒÔ´Ó http://artwork.freebsdgr.org ÏÂÔØ¡£
°²×°ÁË sysutils/bsd-splash-changer
port Ö®ºó£¬ ÿ´ÎÆô¶¯µÄʱºò±ãÄÜ´Ó¼¯ºÏÖÐËæ»úÑ¡Ôñ
splash ͼÏñ¡£
¿ªÆô Splash ͼÏñ¹¦ÄÜ
Splash ͼÏñ (.bmp) »òÕß
(.pcx) Îļþ±ØÐë·ÅÖÃÔÚ root ·ÖÇøÉÏ£¬
±ÈÈç /boot Ŀ¼¡£
¶ÔÓÚĬÈϵÄÏÔʾ·Ö±æÂÊ (256 É«£¬320x200 ÏñËØ»ò¸üÉÙ)
±à¼ /boot/lodaer.conf£¬
Ìí¼ÓÈçϵÄÉèÖãº
splash_bmp_load="YES"
bitmap_load="YES"
bitmap_name="/boot/splash.bmp"
¶ÔÓÚ¸ü¸ßµÄ·Ö±æÂÊ£¬×î´óÖÁ 1024x768 ÏñËØ£¬
±à¼ /boot/lodaer.conf£¬
Ìí¼ÓÈçϵÄÉèÖãº
vesa_load="YES"
splash_bmp_load="YES"
bitmap_load="YES"
bitmap_name="/boot/splash.bmp"
ÒÔÉÏÕâЩÉèÖüÙÉè
/boot/splash.bmp
ΪÐèÒª±»Ê¹ÓÃµÄ splash ͼÏñ¡£ µ±ÐèҪʹÓà PCX
ÎļþµÄʱºò£¬ Ìí¼ÓÈëÏÂÁÐÉèÖ㬠¸ù¾Ý·Ö±æÂʵĸߵÍÌí¼Ó
vesa_load="YES"¡£
splash_pcx_load="YES"
bitmap_load="YES"
bitmap_name="/boot/splash.pcx"
ÎļþÃû²¢²»ÏÞÓÚÒÔÉÏÀý×ÓÖÐµÄ splash
¡£
Ëü¿ÉÒÔÊÇÈκÎÃû³Æ£¬Ö»ÒªÊÇ BMP »òÕß
PCX ÀàÐ͵ÄÎļþ£¬ ±ÈÈç
splash_640x400.bmp
»òÕß
blue_wave.pcx.
һЩÓÐȤµÄ loader.conf Ñ¡Ï
beastie_disable="YES"
Õ⽫¹Ø±ÕÏÔʾÆô¶¯Ñ¡Ïî²Ëµ¥£¬
µ«Êǵ¹Êý¼ÇʱÈÔÈ»»á³öÏÖ¡£ ¼´ÊÇÔÚÆô¶¯²Ëµ¥Ñ¡Ïî±»½ûÓõÄʱºò£¬
ÔÚµ¹Êý¼Çʱ¶Î¼üÈëÏàÓ¦µÄÆô¶¯Ñ¡ÏîÈÔÈ»ÓÐЧ¡£
loader_logo="beastie"
Õâ½«Ìæ»»Æô¶¯Ñ¡Ïî²Ëµ¥ÓÒ²àĬÈÏÏÔʾµÄ
&os;
Ϊ²ÊÉ«µÄСħ¹í±êÖ¾£¬
¾ÍÏñÒÔÍùµÄ·¢ÐаæÄÇÑù¡£
Çë²ÎÔÄ &man.splash.4;£¬ &man.loader.conf.5; ºÍ
&man.vga.4; ÊÖ²áÒ³»ñÈ¡¸ü¶àÏêϸÐÅÏ¢¡£
ÄÚºËÔÚÒýµ¼Ê±µÄ½»»¥
ÄÚºË
Òýµ¼½»»¥
Ò»µ©Äں˱» loader (Ò»°ãÇé¿öÏÂ) »òÕß boot2 (Ô½¹ý loader) ¼ÓÔØ£¬
Ëü½«¼ì²éÒýµ¼±êÖ¾£¬Èç¹ûÓеϰ£¬¾Í»á½øÐбØÒªµÄ¶¯×÷µ÷Õû¡£
ÄÚºËÒýµ¼±êÖ¾
ÄÚºË
Òýµ¼±êÖ¾
ÕâÀïÊÇһЩ³£ÓõÄÒýµ¼±êÖ¾£º
ÔÚÄں˳õʼ»¯Ê±£¬Ñ¯ÎÊ×÷Ϊ¸ù¼ÓÔØµÄÉ豸¡£
´Ó CDROM Òýµ¼¡£
ÔËÐÐ UserConfig (Òýµ¼Ê±µÄÄÚºËÅäÖÃÆ÷)
Òýµ¼½øÈëµ¥Óû§Ä£Ê½
ÔÚÄÚºËÒýµ¼¹ý³ÌÖÐÏÔʾ¸üÓеÄÐÅÏ¢
»¹Óиü¶àµÄÒýµ¼±êÖ¾£¬ÔĶÁ &man.boot.8;
ÒÔ»ñÈ¡ÓйØËüÃǵÄÐÅÏ¢¡£
Tom
Rhodes
Contributed by
Device Hints
device.hints
ÔÚ³õʼ»¯ÏµÍ³Æô¶¯Ê±£¬&man.loader.8; »á¶ÁÈ¡
&man.device.hints.5; Îļþ¡£Õâ¸öÎļþÒÔ±äÁ¿µÄÐÎʽ´¢´æ×ÅÄÚºËÒýµ¼ÐÅÏ¢£¬
ÓÐʱ±»³ÆÎª device hints
¡£
É豸Çý¶¯³ÌÐòÓÃdevice hints
¶ÔÉ豸½øÐÐÅäÖá£
Device hints Ò²¿ÉÒÔÔÚ
µÚÈý½×¶ÎµÄboot loader µÄÃüÁîÐÐÌáʾ·ûÖÐÖ¸¶¨¡£±äÁ¿¿ÉÒÔÓÃ
set ÃüÁîÌí¼Ó£¬unset ÃüÁîɾ³ý£¬
show ÃüÁî²é¿´¡£ÔÚÎļþ /boot/device.hints
ÉèÖõıäÁ¿Òà¿ÉÒÔÔÚÕâÀï±»¸²¸Ç¡£¼üÈë boot loader
ÖеıäÁ¿²»ÊÇÓÀ¾ÃÐԵģ¬ÔÚÏÂ´ÎÆô¶¯Ê±¾Í»á±»Íü¼Ç¡£
Ò»µ©ÏµÍ³Òýµ¼³É¹¦£¬&man.kenv.1; ÃüÁî¿ÉÒÔÓÃÀ´Çå³þËùÓеıäÁ¿¡£
Îļþ /boot/device.hints µÄÓï·¨ÊÇÒ»ÐÐÒ»¸ö±äÁ¿£¬
ʹÓÃ#
×÷ΪעÊͱê¼Ç¡£
ÿÐÐÊǰ´ÕÕÈçÏ·½Ê½×éÖ¯µÄ£º
hint.driver.unit.keyword="value"
µÚÈý½×¶Î boot loader µÄÓï·¨ÊÇ£º
set hint.driver.unit.keyword=value
driver ÊÇÉ豸Çý¶¯³ÌÐòÃû£¬unit
ÊÇÉ豸Çý¶¯³ÌÐòµ¥Î»Ãû£¬keyword ÊÇ hint ¹Ø¼ü×Ö¡£
¹Ø¼ü×Ö¿ÉÒÔÓÉÒÔÏÂÑ¡Ïî×é³É£º
at£ºÖ¸Ã÷É豸Ëù°ó¶¨µÄ×ÜÏß
port£ºÖ¸Ã÷ËùʹÓà I/O
µÄÆðʼµØÖ·¡£
irq£ºÖ¸Ã÷ËùʹÓõÄÖжÏÇëÇóºÅ¡£
drq£ºÖ¸Ã÷ DMA channel ºÅ¡£
maddr£ºÖ¸Ã÷É豸ռÓõÄÎïÀíÄÚ´æµØÖ·¡£
flags£º¸øÉ豸ÉèÖø÷ÖÖ±ê־λ¡£
disabled£ºÈç¹ûÉè³É 1£¬
É豸±»½ûÓá£
É豸Çý¶¯³ÌÐòÄܹ»½ÓÊܸü¶àµÄ hints£¬ÍƼöÄú²Î¿´ËüÃǵÄÁª»úÊֲᡣ²Î¿´
&man.device.hints.5;¡¢&man.kenv.1;¡¢&man.loader.conf.5; ºÍ
&man.loader.8; Áª»úÊÖ²áÒÔ»ñÈ¡¸ü¶àµÄÐÅÏ¢¡£
Init£º½ø³Ì¿ØÖƼ°³õʼ»¯
init
Ò»µ©ÄÚºËÍê³ÉÒýµ¼£¬Ëü¾Í°Ñ¿ØÖÆÈ¨½»¸øÁËÓû§½ø³Ì
&man.init.8;£¬Ëü·ÅÖÃÔÚ /sbin/init£¬
»òÕß init_path ±äÁ¿Ö¸¶¨µÄ³ÌÐò·¾¶ÖС£
Õâ¸ö±äÁ¿ÊÇÔÚ loader ÀïÃæÉèÖõġ£
×Ô¶¯ÖØÆô¹ý³Ì
×Ô¶¯ÖØÆô¹ý³Ì»áÈ·ÈÏϵͳÖпÉÓõÄÎļþϵͳ´¦ÓÚ½¡¿µµÄ״̬¡£
Èç¹û²»ÊÇ£¬ ¶øÇÒʹÓà &man.fsck.8; Ò²ÎÞ·¨ÐÞ¸´ÕâЩÎÊÌ⣬
&man.init.8; »á½øÈë µ¥Óû§Ä£Ê½
ÒÔ±ãϵͳ¹ÜÀíÔ±Ö±½ÓÐÞÕýÕâЩÎÊÌâ¡£
µ¥Óû§Ä£Ê½
µ¥Óû§Ä£Ê½
¿ØÖÆÌ¨
´Ëģʽ¿ÉÒÔͨ¹ý
×Ô¶¯ÖØÆô¹ý³Ì »òÕßͨ¹ý´øÓÐ
Ñ¡ÏîµÄÓû§Òýµ¼»òͨ¹ýÔÚ loader
ÀïÉèÖà boot_single ±äÁ¿µÈ¶àÖÖ·½Ê½À´´ïµ½¡£
Ò²¿ÉÒÔÔÚ¶àÓû§Ä£Ê½Ïµ÷¶¯ÎÞÖØÆô () Ñ¡ÏîºÍÍ£»ú
() Ñ¡ÏîµÄ &man.shutdown.8;
ÃüÁîÀ´½øÈëµ¥Óû§Ä£Ê½¡£
Èç¹ûϵͳ ¿ØÖÆÌ¨ ÔÚÎļþ
/etc/ttys Öб»ÉèÖÃΪ
²»°²È«(insecure)£¬
ÔÚ³õʼ»¯µ¥Óû§Ä£Ê½Ç°»á³öÏÖÒªÇóÊäÈë root
ÃÜÂëµÄÃüÁîÐÐÌáʾ·û¡£
ÔÚ /etc/ttys ÎļþÖеIJ»°²È«¿ØÖÆÌ¨
# name getty type status comments
#
# If console is marked "insecure", then init will ask for the root password # when going to single-user mode.
console none unknown off insecure
°Ñ¿ØÖÆÌ¨ÉèÖÃ³É ²»°²È« (insecure)
ʹֻ֪µÀ root ÃÜÂëµÄÈ˲ÅÄܽøÈëµ¥Óû§Ä£Ê½£¬
ÒòΪÄúÈÏΪ¿ØÖÆÌ¨ÔÚÎïÀíÉÏÊDz»°²È«µÄ¡£Òò´ËÈç¹ûÄú¿¼Âǵ½°²È«ÐÔ£¬
ÇëÑ¡Ôñ ²»°²È« (insecure)£¬¶ø·Ç
°²È« (secure)¡£
¶àÓû§Ä£Ê½
¶àÓû§Ä£Ê½
Èç¹û &man.init.8; ·¢ÏÖÄúµÄÎļþϵͳһÇÐÕý³££¬ÓÖ»òÕßÓû§ÔÚµ¥Óû§Ä£Ê½Íê³ÉÁ˹¤×÷£¬
ϵͳ¾Í»á½øÈë¶àÓû§Ä£Ê½£¬¿ªÊ¼ÏµÍ³µÄ×ÊÔ´ÅäÖá£
×ÊÔ´ÅäÖà (rc)
rc Îļþ
×ÊÔ´ÅäÖ÷ֱð´ÓÎļþ /etc/defaults/rc.conf¡¢
/etc/rc.conf ÖжÁȡĬÈÏÅäÖúÍϸ½ÚÅäÖã¬
È»ºó¼ÓÔØÔÚÎļþ /etc/fstab ÖÐÌá¼°µÄÎļþϵͳ¡¢
Æô¶¯ÍøÂç·þÎñ¡¢Æô¶¯¸÷ÖÖÏµÍ³ÊØ»¤½ø³Ì£¬×îºóÆô¶¯±¾µØ°²×°°üµÄÆô¶¯½Å±¾¡£
&man.rc.8; Áª»úÊÖ²áÊǹØÓÚ×ÊÔ´ÅäÖõĺܺõIJο¼¡£
¹Ø»ú (shutdown) ¹ý³Ì
shutdown
ÓÉÃüÁî &man.shutdown.8; µÄ·¢ÆðµÄ¹Ø»ú¹ý³ÌÖУ¬
&man.init.8; »áÊÔ×ÅÔËÐÐ /etc/rc.shutdown ½Å±¾£¬
¸øËùÓнø³Ì·¢ËÍ TERM Ðźţ¬ ×îºó¸ø²»°´Ê±Í£Ö¹µÄ½ø³Ì·¢ËÍ
KILL Ðźš£
ÔÚÖ§³ÖµçÔ´¹ÜÀíµÄƽ̨ÉÏ¹Ø±Õ FreeBSD ϵͳµÄµçÔ´£¬ Ö»Òª¼òµ¥µØÊ¹ÓÃÃüÁî
shutdown -p now ¼´¿É¡£ ´ËÍ⣬ ¿ÉÒÔÓÃÃüÁî
shutdown -r now À´ÖØÆô FreeBSD¡£ ÒªÖ´ÐÐ &man.shutdown.8;
Äú±ØÐëÊÇ root Óû§»ò operator ×éµÄ³ÉÔ±¡£
Ò²¿ÉÒÔʹÓà &man.halt.8; ºÍ &man.reboot.8; ÃüÁîÀ´¹Ø±Õϵͳ£¬
Çë²Î¿´ËüÃǵÄÁª»úÊÖ²áÒÔ»ñµÃ¸ü¶àµÄÐÅÏ¢¡£
µçÔ´¹ÜÀíÐèÒªÖ§³Ö£¬ ÕâÒªÇóÄÚºËÖ§³Ö
&man.acpi.4; »òÒÔÄ£¿éÐÎʽ¼ÓÔØËü¡£
diff --git a/zh_CN.GB2312/books/handbook/l10n/chapter.xml b/zh_CN.GB2312/books/handbook/l10n/chapter.xml
index 2975100ce9..63be4917f6 100644
--- a/zh_CN.GB2312/books/handbook/l10n/chapter.xml
+++ b/zh_CN.GB2312/books/handbook/l10n/chapter.xml
@@ -1,846 +1,843 @@
Andrey
Chernov
Contributed by
Michael C.
Wu
Rewritten by
±¾µØ»¯£I18N/L10NʹÓúÍÉèÖÃ
¸ÅÊö
FreeBSDÊÇÒ»¸öÓÉ·Ö²¼ÓÚÈ«ÊÀ½çµÄÓû§ºÍ¹±Ï×ÕßÖ§³ÖµÄÏîÄ¿¡£
ÕâÕ½«ÌÖÂÛFreeBSDµÄ¹ú¼Ê»¯ºÍ±¾µØ»¯µÄÎÊÌâ,ÔÊÐí·ÇÓ¢ÓïÓû§Ò²ÄÜʹÓÃFreeBSDºÜºÃµØ¹¤×÷¡£
ÔÚϵͳºÍÓ¦ÓÃˮƽÉÏ£¬Ö÷ÒªÊÇͨ¹ýÖ´ÐÐi18N±ê×¼À´ÊµÏֵģ¬ËùÒÔÕâÀïÎÒÃǽ«Îª¶ÁÕßÌṩÏêϸµÄ½éÉÜ¡£
¶ÁÍêÕâÒ»Õ£¬Äú½«Á˽⣺
²»Í¬µÄÓïÑԺ͵ØÓòÊÇÈçºÎÔÚÏÖ´ú²Ù×÷ϵͳÉϽøÐбàÂëµÄ¡£
ÈçºÎΪÄúµÄµÇÈëshellÉèÖñ¾µØ»¯¡£
ÈçºÎÅäÖÃÄúµÄ¿ØÖÆÌ¨Îª·ÇÓ¢ÓïÓïÑÔ¡£
languages.
ÈçºÎʹÓò»Í¬µÄÓïÑÔÀ´ÓÐЧµØÊ¹ÓÃX Windows¡£
ÔÚÄÄÀï¿ÉÒÔÕÒµ½¸ü¶àÓйؿª·¢·ûºÏi18N±ê×¼µÄÓ¦ÓóÌÐòµÄÐÅÏ¢¡£
ÔĶÁÕâÕÂ֮ǰ£¬ÄúÓ¦µ±Á˽⣺
ÔõÑù°²×°¶îÍâµÄµÚÈý·½³ÌÐò£¨£©¡£
»ù´¡ÖªÊ¶
I18N/L10N ÊÇʲô£¿
¹ú¼Ê»¯
±¾µØ»¯
±¾µØ»¯
¿ª·¢ÈËÔ±°Ñinternationalization¼òд³ÉI18N,ÖмäµÄÊý×ÖÊÇǰºóÁ½¸ö×Öĸ¼äµÄ×Öĸ¸öÊý¡£
L10NÒÀ¾Ýlocalization
ʹÓÃͬÑùµÄÃüÃû¹æÔò¡£
I18N/L10N·½·¨¡¢ÐÒéºÍÓ¦ÓýáºÏÔÚÒ»Æð£¬ÔÊÐíÓû§Ê¹ÓÃËûÃÇ×Ô¼ºËùÑ¡ÔñµÄÓïÑÔ¡£
I18NÓ¦ÓóÌÐòʹÓÃI18N¹¤¾ßÀ´±à³Ì¡£ËüÔÊÐí¿ª·¢ÈËԱдһ¸ö¼òµ¥µÄÎļþ£¬
¾Í¿ÉÒÔ½«ÏÔʾµÄ²Ëµ¥ºÍÎı¾·Òë³É±¾µØÓïÑÔ¡£ÎÒÃǷdz£¹ÄÀø³ÌÐòÔ±×ñÑÕâÖÖ¹æÔò¡£
ΪʲôҪʹÓÃI18N/L10N?
I18N/L10N±ê×¼Äܹ»ºÜºÃµØÖ§³ÖÄú²é¿´¡¢ÊäÈë»ò´¦Àí·ÇÓ¢ÓïÓïÑÔ¡£
I18NÖ§³ÖÄÄЩÓïÑÔ£¿
I18NºÍL10N²»ÊÇFreeBSDÌØÓеġ£µ±Ç°£¬ËüÄÜÖ§³ÖÊÀ½çÉϾø´ó²¿·ÖÖ÷Á¦ÓïÑÔ£¬
°üÀ¨µ«²»ÏÞÓÚ£ºÖÐÎÄ£¬µÂÎÄ£¬ÈÕÎÄ£¬³¯ÏÊÎÄ£¬·¨ÎÄ£¬¶íÎÄ£¬Ô½ÄÏÎĵȵȡ£
ʹÓñ¾µØ»¯ÓïÑÔ
I18N²»ÊÇFreeBSDÌØÓеģ¬ËüÊÇÒ»¸ö¹æÔò¡£ÎÒÃǹÄÀøÄú°ïÖúFreeBSDÍêÉÆÕâÒ»¹æÔò¡£
locale
±¾µØ»¯ÉèÖÃÐèÒª¾ß±¸Èý¸öÌõ¼þ£ºÓïÑÔ´úÂë (Language Code)¡¢ ¹ú¼Ò´úÂë
(Country Code) ºÍ±àÂë(Encoding)¡£ ±¾µØÃû×Ö¿ÉÒÔÓÃÏÂÃæÕâЩ²¿·ÖÀ´¹¹Ô죺
ÓïÑÔ´úÂë_¹ú¼Ò´úÂë.±àÂë
ÓïÑԺ͹ú¼Ò´úÂë
ÓïÑÔ´úÂë
¹ú¼Ò´úÂë
ΪÁËÓÃÌØÊâµÄÓïÑÔÀ´¶ÔFreeBSDϵͳ½øÐб¾µØ»¯£¨»òÆäËûÀà&unix;ϵͳ£©£¬
Óû§±ØÐëÒªÖªµÀÏàÓ¦µÄ¹ú¼ÒºÍÓïÑÔ´úÂ루¹ú¼Ò´úÂë¸æËßÓ¦ÓóÌÐòʹÓÃÄÄÒ»ÖÖÓïÑԹ淶£©¡£
´ËÍ⣬WEBä¯ÀÀÆ÷£¬SMTP/POP·þÎñÆ÷£¬web·þÎñÆ÷µÈ¶¼ÊÇÒÔÕâ¸öΪ»ù´¡µÄ¡£ÏÂÃæ¾ÍÊÇÒ»¸ö¹ú¼ÒºÍÓïÑÔ´úÂëµÄÀý×Ó:
ÓïÑÔ/¹ú¼Ò´úÂë
ÃèÊö
en_US
ÃÀ¹úÓ¢Óï
ru_RU
¶íÓï
zh_CN
¼òÌåÖÐÎÄ
±àÂë
±àÂë
ASCII
һЩÓïÑÔ²»Ê¹Óà ASCII ±àÂ룬ËüÃÇʹÓÃ8-룬 ¿í»ò¶à×Ö½ÚµÄ×Ö·û£¬
¸ü¶àµÄÐÅÏ¢Çë²Î¿¼ &man.multibyte.3;¡£
±È½ÏÀϵÄÓ¦ÓóÌÐò¿ÉÄÜ»áÎÞ·¨Ê¶±ðËüÃÇ£¬ ²¢ÎóÈÏΪÊÇ¿ØÖÆ×Ö·û¡£
±È½ÏеÄÓ¦ÓóÌÐòͨ³£»áÈϳö 8-λ×Ö·û¡£ ËæÊµÏֵIJ»Í¬£¬
Óû§¿ÉÄܲ»µÃ²»½«¿í»ò¶à×Ö½Ú×Ö·ûÖ§³Ö±àÈëÓ¦ÓóÌÐò£¬ »ò½øÐÐһЩ¶îÍâµÄÅäÖã¬
²ÅÄܹ»Õý³£Ê¹ÓÃËüÃÇ¡£ ÒªÊäÈëºÍ´¦Àí¿í»ò¶à×Ö½Ú×Ö·û£¬ FreeBSD Ports Collection
ÒѾΪÿÖÖÓïÑÔÌṩÁ˲»Í¬µÄ³ÌÐò¡£ Çë²Î¿¼¸÷¸ö FreeBSD Port ÖÐµÄ I18N
Îĵµ¡£
ÌØ±ðÐèÒªÖ¸³öµÄÊÇ£¬ Óû§¿ÉÄÜÐèÒª²é¿´Ó¦ÓóÌÐòµÄÎĵµ£¬
ÒÔÈ·¶¨ÈçºÎÕýÈ·µØÅäÖÃËü£¬ »òÐèҪΪ configure/Makefile/±àÒëÆ÷
Ö¸¶¨Ê²Ã´ÑùµÄ²ÎÊý¡£
¼ÇסÏÂÃæÕâЩ:
ÌØ¶¨ÓïÑԵļòµ¥C×Ö·û¼¯ (²Î¼û &man.multibyte.3;)£¬ÀýÈç
ISO8859-1, ISO8859-15, KOI8-R, CP437¡£
¿í×Ö½Ú»ò¶à×Ö½Ú±àÂ룬ÈçEUC, Big5¡£
Äú¿ÉÒÔÔÚIANA Registry¼ì²éÒ»ÏÂÏÖÐеÄ×Ö·û¼¯ÁÐ±í¡£
Óë´Ë²»Í¬µÄÊÇ£¬ &os; ʹÓÃÓë X11-¼æÈݵı¾µØ±àÂëģʽ¡£
I18NÓ¦ÓóÌÐò
ÔÚFreeBSD PortsºÍPackageϵͳÀïÃæ£¬I18NÓ¦ÓóÌÐòÒѾʹÓÃI18N
À´ÃüÃû¡£È»¶øËüÃDz»ÊÇ×ÜÖ§³ÖÐèÒªµÄÓïÑÔ¡£
±¾µØ»¯ÉèÖÃ
ͨ³£Ö»ÒªÔÚµÇÈëshellÀïÃæÉèÖÃLANGΪ±¾µØ»¯£¬
Ò»°ãͨ¹ýÉèÖÃÓû§µÄ ~/.login_conf
»òÓû§shellµÄÆô¶¯Îļþ£¨~/.profile£¬~/.bashrc,
~/.cshrc£©¡£Ã»ÓбØÒªÉèÖÃ
LC_CTYPE£¬LC_CTIME¡£
¸ü¶àµÄÐÅÏ¢Çë²Î¿¼Ìض¨ÓïÑÔµÄFreeBSDÎĵµ¡£
ÄúÓ¦µ±ÔÚÄúµÄÅäÖÃÎļþÖÐÉèÖÃÏÂÃæÁ½¸ö±äÁ¿£º
- POSIX
- LANG Ϊ&posix;ÉèÖñ¾µØ»¯ÓïÑÔ¹¦ÄÜ¡£
+ LANG Ϊ&posix;ÉèÖñ¾µØ»¯ÓïÑÔ¹¦ÄÜ¡£POSIX
- MIME
-
- MM_CHARSETÓ¦ÓóÌÐòµÄMIME×Ö·û¼¯¡£
+ MM_CHARSETÓ¦ÓóÌÐòµÄMIME×Ö·û¼¯¡£MIME
Õâ°üÀ¨Óû§µÄshellÅäÖã¬Ìض¨µÄÓ¦ÓÃÅäÖúÍX11ÅäÖá£
ÉèÖñ¾µØ»¯µÄ·½·¨
±¾µØ»¯
µÇÈë·ÖÀà
ÓÐÁ½ÖÖ·½·¨À´ÉèÖñ¾µØ»¯£¬½ÓÏÂÀ´¶¼»áÃèÊö¡£
µÚÒ»ÖÖ (ÍÆ¼ö) ¾ÍÊÇÔÚ µÇÈë·ÖÀàÀïÃæÖ¸¶¨»·¾³±äÁ¿¡£
µÚ¶þÖÖ·½·¨Êǰѻ·¾³±äÁ¿¼Óµ½shellµÄÆô¶¯ÎļþÀïÃæ¡£
µÇÈë·ÖÀà·½·¨
ÕâÖÖ·½·¨ÔÊÐí°Ñ±¾µØ»¯Ãû³ÆºÍMIME×Ö·û¼¯µÄ»·¾³±äÁ¿¸³¸ø¿ÉÄܵÄshell£¬
¶ø²»ÊǼӵ½Ã¿¸öÌØ¶¨shellµÄÆô¶¯ÎļþÀïÃæ¡£
Óû§¼¶ÉèÖÃ
Level Setup ÔÊÐíÆÕͨÓû§×Ô¼ºÍê³ÉÕâ¸öÉèÖ㬶ø¹ÜÀíÔ±¼¶ÉèÖÃÐèÒª³¬¼¶Óû§È¨ÏÞ¡£
Óû§¼¶ÉèÖÃ
ÕâÓÐÒ»¸öÉèÖÃÓû§¸ùĿ¼Îļþ.login_confµÄСÀý×Ó£¬
ËüΪÉÏÊöÁ½¸ö±äÁ¿ÉèÖÃÁËLatin-1±àÂë¡£
me:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:
·±ÌåÖÐÎÄBIG-5±àÂë
ÕâÊÇÒ»¸öΪ.login_confÉèÖ÷±ÌåÖÐÎĵÄBIG-5±àÂëµÄÀý×Ó¡£Ó¦¸ÃÉèÖÃÏÂÃæµÄ´ó²¿·Ö±äÁ¿£¬
ÒòΪºÜ¶àÈí¼þ¶¼Ã»ÓÐΪÖÐÎÄ£¬ÈÕÎĺͺ«ÎÄÉèÖÃÕýÈ·µÄ±¾µØ»¯±äÁ¿¡£
#Users who do not wish to use monetary units or time formats
#of Taiwan can manually change each variable
me:\
:lang=zh_TW.Big5:\
:setenv=LC_ALL=zh_TW.Big5:\
:setenv=LC_COLLATE=zh_TW.Big5:\
:setenv=LC_CTYPE=zh_TW.Big5:\
:setenv=LC_MESSAGES=zh_TW.Big5:\
:setenv=LC_MONETARY=zh_TW.Big5:\
:setenv=LC_NUMERIC=zh_TW.Big5:\
:setenv=LC_TIME=zh_TW.Big5:\
:charset=big5:\
:xmodifiers="@im=gcin": #Set gcin as the XIM Input Server
¸ü¶àµÄÐÅÏ¢²Î¿¼¹ÜÀíÔ±¼¶ÉèÖúÍ&man.login.conf.5;
¹ÜÀíÔ±¼¶ÉèÖÃ
¼ì²éÓû§µÄµÇÈë·ÖÀàÔÚ
/etc/login.confÀïÃæÊÇ·ñÉèÖÃÁËÕýÈ·µÄÓïÑÔ¡£Ö÷Ҫȷ¶¨ÏÂÃæµÄ¼¸¸öÉèÖãº
language_name|Account Type Description:\
:charset=MIME_charset:\
:lang=locale_name:\
:tc=default:
ÔÙ´ÎʹÓÃÇ°ÃæµÄLatin-1±àÂëµÄÀý×Ó£º
german|German Users Accounts:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:\
:tc=default:
ÔÚÐÞ¸ÄÓû§µÄµÇÈëÀàÐÍ֮ǰ£¬ Ó¦Ê×ÏÈÖ´ÐÐÏÂÃæµÄÃüÁ
&prompt.root; cap_mkdb /etc/login.conf
ÒÔ±ãʹÔÚ
/etc/login.conf ÖÐÐÂÔöµÄÅäÖÃÉúЧ¡£
ʹÓà &man.vipw.8; ¸Ä±äµÇÈëÀàÐÍ¡£
vipw
ʹÓÃvipwÌí¼ÓÐÂÓû§£¬¿´ÆðÀ´ÏñÏÂÃæÕâÑù£º
user:password:1111:11:language:0:0:User Name:/home/user:/bin/sh
ÓÃ&man.adduser.8;¸Ä±äµÇÈëÀàÐÍ¡£
adduser
µÇÈë·ÖÀà
ÓÃadduserÌí¼ÓÐÂÓû§¿´ÆðÀ´ÏñÏÂÃæÕâÑù£º
ÔÚ/etc/adduser.confÀïÃæÉèÖÃdefaultclass =
ÓïÑÔ¡£Ó¦¸Ã¼Çס£¬Äú±ØÐëΪʹÓÃÆäËüÓïÑÔµÄËùÓÐÓû§ÉèÖÃ
ȱʡÀà±ð¡£
ÿһ´ÎʹÓÃ&man.adduser.8;µÄʱºò£¬Ò»¸öÌØ¶¨ÓïÑԵĿÉÑ¡ÔñÐԻشð»áÏñÏÂÃæÕâÑù¸ø³ö£º
Enter login class: default []:
Èç¹ûÄú´òËã¸øÃ¿Ò»¸öÓû§Ê¹ÓÃÁíÍâÒ»ÖÖÓïÑÔ£¬ÄúÓ¦¸ÃÕâÑù£º
&prompt.root; adduser -class language
ʹÓÃ&man.pw.8;¸Ä±äµÇÈëÀàÐÍ¡£
pw
Èç¹ûÄúʹÓÃ&man.pw.8;À´Ìí¼ÓÐÂÓû§£¬Ó¦¸ÃÕâÑùʹÓãº
&prompt.root; pw useradd user_name -L language
ShellÆô¶¯Îļþ·½·¨
²»ÍƼöʹÓÃÕâÖÖ·½·¨£¬ÒòΪËüÐèÒª¸øÃ¿Ò»¸ö¿ÉÄܵÄshell³ÌÐòÒ»¸ö²»Í¬µÄÆô¶¯Îļþ¡£
Ó¦¸ÃÓõÇÈë·ÖÀà·½·¨À´´úÌæÕâÖÖ·½·¨¡£
MIME
locale
ΪÁËÉèÖñ¾µØ»¯Ãû³ÆºÍMIME×Ö·û¼¯£¬Ö»ÒªÔÚ/etc/profile»ò
/etc/csh.loginÆô¶¯ÎļþÀïÃæÉèÖÃÕâÁ½¸ö±äÁ¿¡£ÏÂÃæÎÒÃÇʹÓõÂÓï×öÀý×Ó£º
ÔÚ/etc/profileÀïÃæ£º
LANG=de_DE.ISO8859-1; export LANG
MM_CHARSET=ISO-8859-1; export MM_CHARSET
»òÔÚ/etc/csh.loginÀïÃæ£º
setenv LANG de_DE.ISO8859-1
setenv MM_CHARSET ISO-8859-1
ÁíÍ⣬Äú¿ÉÒÔ°ÑÉÏÃæµÄÉèÖÃÌí¼Óµ½/usr/share/skel/dot.profile
£¨ºÍÇ°ÃæµÄ/etc/profileÒ»Ñù£©£¬»òÕß/usr/share/skel/dot.login
£¨ºÍÇ°ÃæµÄ/etc/csh.loginÒ»Ñù£©¡£
¶ÔÓÚX11£º
ÔÚ$HOME/.xinitrcÀïÃæ£º
LANG=de_DE.ISO8859-1; export LANG
»òÕߣº
setenv LANG de_DE.ISO8859-1
ÒÀÀµÄúµÄshell(¿´ÉÏÃæ£©¡£
¿ØÖÆÌ¨ÉèÖÃ
¶ÔÓÚËùÓеļòµ¥C×Ö·û¼¯£¬ÔÚ/etc/rc.confÖÐÓÃÕýÔÚÌÖÂÛµÄÓïÑÔÉèÖÃÕýÈ·µÄ¿ØÖÆÌ¨×Ö·û£º
font8x16=font_name
font8x14=font_name
font8x8=font_name
Õâ¶ùµÄfont_nameÀ´×ÔÓÚ/usr/share/syscons/fontsĿ¼£¬
²»´ø.fntºó׺¡£
sysinstall
keymap
screenmap
Èç¹ûÐèÒªµÄ»°£¬ »¹Ó¦Í¨¹ý
sysinstall À´ÅäÖÃÓëµ¥×Ö½Ú C
×Ö·û¼¯¶ÔÓ¦µÄ keymap ºÍ screenmap¡£
ÔÚ sysinstall ÖУ¬
Ñ¡Ôñ Configure Ö®ºóÑ¡Ôñ
Console ¼´¿É½øÐÐÅäÖá£
³ý´ËÖ®Í⣬ ÄúÒ²¿ÉÒÔÔÚ /etc/rc.conf ÖмÓÈëÀàËÆÏÂÃæµÄÅäÖãº
scrnmap=screenmap_name
keymap=keymap_name
keychange="fkey_number sequence"
Õâ¶ùµÄscreenmap_nameÊÇÀ´×Ô/usr/share/syscons/scrnmapsĿ¼£¬
²»´ø.scmºó׺¡£ Ò»¸ö´øÓ°Éä×ÖÌåµÄÆÁÄ»²¼¾Öͨ³£±»×÷Ϊһ¸ö¹¤×÷Çø£¬
ÓÃÀ´ÔÚVGAÊÊÅäÆ÷×ÖÌ徨ÕóÉÏÀ©Õ¹8λµ½9λ¡£ Èç¹ûÆÁÄ»×ÖÌåÊÇʹÓÃÒ»¸ö8λµÄÅÅÁУ¬ÒªÒƶ¯ÕâЩ×ÖĸÀ뿪ÕâÐ©ÇøÓò¡£
Èç¹ûÄúÔÚ/etc/rc.confÀïÃæÆôÓÃÁËmoused daemon£º
moused_enable="YES"
ÄÇôÐèÒªÔÚÏÂÒ»¶Î¼ì²éÊó±êÖ¸ÕëÐÅÏ¢¡£
moused
ĬÈÏÇé¿öÏ£¬ &man.syscons.4;Çý¶¯³ÌÐòµÄÊó±êÖ¸ÕëÔÚ×Ö·û¼¯ÖÐÕ¼ÓÃ0xd0-0xd3µÄ·¶Î§¡£
Èç¹ûÄúµÄÓïÑÔʹÓÃÕâ¸ö·¶Î§£¬Äú±ØÐë°ÑÖ¸Õë·¶Î§ÒÆ³öÕâ¸ö·¶Î§¡£
ÒªÈÆ¹ýÕâ¸öÎÊÌ⣬ ÐèÒªÔÚ
/etc/rc.conf ÖмÓÈ룺
mousechar_start=3
ÕâÀ keymap_name
À´×ÔÓÚ /usr/share/syscons/keymaps Ŀ¼£¬
µ«È¥µôÁË .kbd ºó׺¡£
Èç¹û²»È·¶¨Ó¦¸ÃʹÓÃÄÄÒ»¸ö¼üÅ̲¼¾Ö£¬ Ôò¿ÉÒÔʹÓà &man.kbdmap.1;
À´²âÊÔ£¬ ¶øÎÞÐè·´¸´ÖØÆô¡£
ͨ³££¬ keychange ÊÇÉ趨¹¦Äܼüʱ£¬
Æ¥ÅäÑ¡¶¨µÄÖÕ¶ËÀàÐÍÀ´ËµÊDZØÐèµÄ£¬ ÒòΪ¹¦ÄܼüÐòÁÐÎÞ·¨ÔÚ¼üÅ̲¼¾ÖÖж¨Òå¡£
´ËÍâÄú»¹Ó¦¸Ã¼ì²é²¢È·ÈÏÔÚ
/etc/ttys ÖÐÒѾΪËùÓÐµÄ ttyv*
ÏîÅäÖÃÁËÕýÈ·µÄÖÕ¶ËÀàÐÍ¡£ Ŀǰ£¬ Ïà¹ØµÄĬÈ϶¨ÒåÊÇ£º
×Ö·û¼¯ÉèÖÃ
ÖÕ¶ËÀàÐÍ
ISO8859-1 or ISO8859-15
cons25l1
ISO8859-2
cons25l2
ISO8859-7
cons25l7
KOI8-R
cons25r
KOI8-U
cons25u
CP437 (VGA default)
cons25
US-ASCII
cons25w
¶ÔÓÚ¶à×Ö½Ú×Ö·ûÓïÑÔ£¬¿ÉÒÔÄúµÄÔÚ
/usr/ports/language
Ŀ¼ÖÐʹÓÃÕýÈ·µÄFreeBSD port¡£Ò»Ð©portÒÔ¿ØÖÆÌ¨³öÏÖ£¬
¶øÏµÍ³°ÑËü×÷Ϊ´®ÐÐvttyÖÕ¶Ë£¬Òò´Ë£¬ ±ØÐëΪ X11
ºÍα´®ÐпØÖÆÌ¨×¼±¸×ã¹»µÄvttyÖÕ¶Ë¡£
ÏÂÃæÊÇÔÚ¿ØÖÆÌ¨ÖÐʹÓÃÆäËûÓïÑÔµÄÓ¦ÓóÌÐòµÄ²¿·ÖÁÐ±í£º
ÓïÑÔ
ÌØ¶¨ÇøÓò
Traditional Chinese (BIG-5)
chinese/big5con
Japanese
japanese/kon2-16dot or
japanese/mule-freewnn
Korean
korean/han
X11ÉèÖÃ
ËäÈ»X11²»ÊÇFreeBSD¼Æ»®µÄÒ»²¿·Ö£¬
µ«ÎÒÃÇÒѾΪFreeBSDÓû§°üº¬ÁËһЩÐÅÏ¢¡£
¾ßÌåϸ½Ú¿ÉÒԲο¼&xorg;
Web Õ¾µã
»òÊÇÄúʹÓÃµÄ X11 Server µÄÍøÕ¾¡£
ÔÚ~/.XresourcesÀïÃæ£¬Äú¿ÉÒÔÊʵ±µ÷ÕûÌØ¶¨Ó¦ÓóÌÐòµÄI18NÉèÖã¨Èç×ÖÌ壬²Ëµ¥µÈ£©¡£
ÏÔʾ×ÖÌå
X11 True Type ×ÖÌå·þÎñÆ÷
°²×° &xorg; ·þÎñÆ÷
(x11-servers/xorg-server)£¬
È»ºó°²×°¶ÔÓ¦ÓïÑ﵀ &truetype; ×ÖÌå¡£ ÇëÉèÖÃÕýÈ·µÄµØÇøÐÅÏ¢£¬
Õ⽫ÈÃÄúÄܹ»Ôڲ˵¥ºÍÆäËüµØ·½¿´µ½ËùÑ¡ÔñµÄÓïÑÔ¡£
ÊäÈë·ÇÓ¢Óï×Ö·û
X11ÊäÈë·½·¨(XIM)
X11ÊäÈë·½·¨£¨XIM£©ÐÒéÊÇËùÓÐX11¿Í»§¶ËµÄÒ»¸öбê×¼¡£
ËùÓн«×÷ΪXIM¿Í»§¶ËÀ´Ð´µÄX11Ó¦ÓóÌÐò´ÓXIMÊäÈë·þÎñÆ÷ÊäÈë¡£
²»Í¬µÄÓïÑÔÓм¸ÖÖXIM·þÎñÆ÷¿ÉÓá£
´òÓ¡»úÉèÖÃ
һЩ¼òµ¥µÄC×Ö·û¼¯Í¨³£ÊÇÓÃÓ²±àÂëÀ´±àÂë½ø´òÓ¡»úµÄ¡£¸ü¿í»ò¶àλµÄ×Ö·û¼¯ÐèÒªÌØ¶¨µÄÉèÖã¬
ÎÒÃÇÍÆ¼öʹÓÃapsfilter¡£ÄúÒ²¿ÉÒÔʹÓÃÌØ¶¨ÓïÑÔת»»Æ÷°ÑÎĵµ×ª»»Îª
&postscript;»òPDF¸ñʽ¡£
Äں˺ÍÎļþϵͳ
FreeBSD µÄ¿ìËÙÎļþϵͳ (FFS) ÊÇÍêȫ֧³Ö 8-λ ×Ö·ûµÄ£¬
Òò´ËËü¿ÉÒÔ±»ÓÃÓÚÈκμòµ¥µÄ C ×Ö·û¼¯ (²Î¼û &man.multibyte.3;)£¬
µ«ÔÚÎļþϵͳÖв»»á±£´æ×Ö·û¼¯µÄÃû×Ö£»
Ò²¾ÍÊÇ˵£¬ Ëü²»¼ÓÐ޸ĵر£´æ 8-λÐÅÏ¢£¬ ¶ø²¢²»ÖªµÀÈçºÎ±àÂë¡£
Õýʽ˵À´£¬ FFS Ŀǰ»¹²»Ö§³ÖÈκÎÐÎʽµÄ¿í»ò¶à×Ö½Ú×Ö·û¼¯¡£
²»¹ý£¬ ijЩ¿í»ò¶à×Ö·û¼¯ÌṩÁ˶ÀÁ¢µÄÕë¶Ô
FFS µÄ²¹¶¡À´°ïÖúÆôÓùØÓÚËüÃǵÄÖ§³Ö¡£ ĿǰÕâЩҪôÊÇÎÞ·¨ÒÆÖ²µÄ£¬
Ҫô¹ýÓÚ´Ö²Ú£¬ Òò´ËÎÒÃDz»´òËã°ÑËüÃǼÓÈëµ½Ô´´úÂëÖС£
Çë²Î¿¼Ïà¹ØÓïÑ﵀ Web Õ¾µã£¬ ÒÔÁË½â¹ØÓÚÕâЩ²¹¶¡µÄ½øÒ»²½Çé¿ö¡£
DOS
Unicode
FreeBSD &ms-dos;ÒѾÄܹ»ÅäÖóÉÓÃÔÚ&ms-dos;ÉÏ£¬Unicode×Ö·û¼¯ºÍ¿ÉÑ¡µÄFreeBSDÎļþϵͳ×Ö·û¼¯µÄ¸ü¶àÐÅÏ¢£¬
Çë²Î¿¼ &man.mount.msdosfs.8; Áª»úÊֲᡣ
±àÒëI18N³ÌÐò
Ðí¶àFreeBSD PortsÒѾ֧³ÖI18NÁË¡£ËûÃÇÖеÄһЩ¶¼ÓÃ-I18N×÷±ê¼Ç¡£
ÕâЩºÍÆäËûºÜ¶à³ÌÐòÒѾÄÚ½¨I18NµÄÖ§³Ö£¬²»ÐèÒª¿¼ÂÇÆäËûµÄÊÂÏîÁË¡£
MySQL
È»¶øÒ»Ð©ÏñMySQLÕâÑùµÄÓ¦ÓóÌÐòÐèÒªÖØÐÂÅäÖÃ×Ö·û¼¯£¬¿ÉÔÚ
MakefileÀïÃæÉèÖ㬻òÕßÖ±½Ó°Ñ²ÎÊý´«µÝ¸øconfigure¡£
±¾µØ»¯FreeBSD
Andrey
Chernov
Originally contributed by
¶íÓKOI8-R±àÂ룩
±¾µØ»¯
¶íÓï
¹ØÓÚKOI8-R±àÂëµÄ¸ü¶àÐÅÏ¢Çë²éÔÄKOI8-R²Î¿¼£¨Russian Net Character Set£©¡£
±¾µØÉèÖÃ
°ÑÏÂÃæµÄÐмÓÈëµ½ÄúµÄ~/.login_confÎļþ£º
me:My Account:\
:charset=KOI8-R:\
:lang=ru_RU.KOI8-R:
²Î¿´Ç°ÃæµÄÉèÖñ¾µØ»¯µÄÀý×Ó¡£
¿ØÖÆÌ¨ÉèÖÃ
°ÑÏÂÃæÒ»Ðмӵ½
/etc/rc.conf£º
mousechar_start=3
²¢ÔÚ /etc/rc.conf ÀïÃæÔö¼ÓÈçÏÂÉèÖãº
keymap="ru.koi8-r"
scrnmap="koi8-r2cp866"
font8x16="cp866b-8x16"
font8x14="cp866-8x14"
font8x8="cp866-8x8"
¶ÔÓÚ/etc/ttysÀïÃæµÄttyv*¼Ç¼£¬ÒªÊ¹ÓÃ
cons25r×÷ΪÖÕ¶ËÀàÐÍ¡£
²Î¿´Ç°ÃæµÄÉèÖÿØÖÆÌ¨µÄÀý×Ó¡£
´òÓ¡»úÉèÖÃ
´òÓ¡»ú
¼ÈÈ»¾ø´ó¶àÊý´ø¶íÓï×Ö·ûµÄ´òÓ¡»ú×ñÑCP866µÄ±ê×¼£¬
ÄÇôÐèÒªÒ»¸öÕë¶ÔKOI8-Rµ½CP866ת»»µÄÌØ¶¨Êä³ö¹ýÂËÆ÷¡£ÕâÑùµÄÒ»¸ö¹ýÂËÆ÷ĬÈϵݲװÔÚ
/usr/libexec/lpr/ru/koi2alt¡£
Ò»¸öÖ§³Ö¶íÓïµÄ´òÓ¡»úµÄ/etc/printcap¼Ç¼¿´ÆðÀ´ÊÇÕâÑùµÄ£º
lp|Russian local line printer:\
:sh:of=/usr/libexec/lpr/ru/koi2alt:\
:lp=/dev/lpt0:sd=/var/spool/output/lpd:lf=/var/log/lpd-errs:
¸ü¶àÐÅÏ¢²Î¿¼&man.printcap.5;ÊÖ²áÒ³¡£
&ms-dos;ÎļþϵͳºÍ¶íÓïÎļþÃû
ÏÂÃæµÄÀý×ÓÊÇÔÚ¹ÒÉÏ&ms-dos; Îļþϵͳºó£¬ÆôÓöԶíÓïÎļþÃûÖ§³ÖµÄ&man.fstab.5;¼Ç¼£º
/dev/ad0s2 /dos/c msdos rw,-Wkoi2dos,-Lru_RU.KOI8-R 0 0
Ñ¡Ïî ÓÃÓÚÑ¡ÔñµØÇøÃû³Æ£¬
¶ø ÔòÓÃÓÚÉèÖÃ×Ö·ûת»»±í¡£
ҪʹÓà ѡÏ
ÔòÒ»¶¨ÒªÊ×ÏÈ¹Ò½Ó /usr£¬
È»ºóÔÙ¹Ò½Ó &ms-dos; ·ÖÇø£¬ ÒòΪת»»±íÊÇ·ÅÔÚ
/usr/libdata/msdosfs µÄ¡£
ÒªÁË½â½øÒ»²½µÄϸ½Ú£¬ Çë²Î¿¼ &man.mount.msdosfs.8; Áª»úÊֲᡣ
X11ÉèÖÃ
Ê×ÏÈÇë½øÐÐÇ°Ãæ½éÉÜµÄ ·Ç-X
µÄ±¾µØ»¯ÉèÖá£
Èç¹ûÄúÕýʹÓà &xorg;£¬ Çë°²×°
x11-fonts/xorg-fonts-cyrillic
package¡£
¼ì²éÄú /etc/X11/xorg.conf ÎļþÖеÄ
"Files" С½Ú¡£ ÏÂÃæµÄÐУ¬ Ó¦¼Óµ½ÈÎºÎÆäËü
FontPath Ïî֮ǰ£º
FontPath "/usr/local/lib/X11/fonts/cyrillic"
Çë²é¿´ ports ÖÐµÄÆäËüÎ÷Àï¶û×ÖÌå¡£
Òª¼¤»î¶íÓï¼üÅÌ£¬ ÐèÒªÔÚ
xorg.conf ÎļþµÄ
"Keyboard" С½ÚÖмÓÈëÏÂÁÐÄÚÈÝ£º
Option "XkbLayout" "us,ru"
Option "XkbOptions" "grp:toggle"
ҪȷÐÅXkbDisable ÒѾ¹Ø±Õ (×¢Ê͵ô) ÁË¡£
RUS/LATµÄÇл»ÓÃCapsLock¡£ÀϵÄCapsLock¹¦ÄÜ¿ÉÒÔͨ¹ý
ShiftCapsLock
À´Ä£Ä⣨ֻÓÐÔÚLATģʽµÄʱºò£©¡£
ʹÓà grp:toggle
ʱ£¬ RUS/LAT Çл»¼ü½«ÊÇ ÓÒ Alt£¬
¶øÊ¹Óà grp:ctrl_shift_toggle Ôò±íʾÇл»¼üÊÇ
CtrlShift¡£
ʹÓà grp:caps_toggle
ʱ£¬ RUS/LAT Çл»¼üÔòÊÇ CapsLock¡£
¾ÉµÄ CapsLock ¹¦ÄÜÈÔ¿Éͨ¹ý ShiftCapsLock (Ö»¶Ô LAT
ģʽÓÐЧ)¡£ ÓÉÓÚ²»Ã÷ÔÒò£¬
grp:caps_toggle ÔÚ
&xorg; ÖÐÎÞ·¨Ê¹Óá£
Èç¹ûÄúµÄ¼üÅÌÉÏÓÐ &windows;
¼ü£¬
µ«·¢ÏÖ RUS ģʽÏ£¬ ijЩ·Ç×Öĸ¼üÓ³Éä²»Õý³££¬ ÔòÓ¦ÔÚÄúµÄ
xorg.conf ÎļþÖмÓÈëÏÂÃæÕâÐУº
Option "XkbVariant" ",winkeys"
¶íÓïµÄ XKB ¼üÅÌ¿ÉÄܲ¢²»ÎªÄ³Ð©²»¾ß±¸±¾µØ»¯¹¦ÄܵÄÓ¦ÓóÌÐòËùÖ§³Ö¡£
±¾µØ»¯³ÌÐò×îµÍÏÞ¶ÈÓ¦ÔÚ³ÌÐòÆô¶¯Ê±µ÷Óà XtSetLanguageProc (NULL, NULL,
NULL); º¯Êý¡£
²Î¼û
KOI8-R for X Window ÒÔ»ñµÃ¹ØÓÚ¶Ô X11 Ó¦ÓýøÐб¾µØ»¯µÄÖ¸µ¼¡£
ÉèÖ÷±ÌåÖÐÎÄ
±¾µØ»¯
·±ÌåÖÐÎÄ
FreeBSD-Taiwan¼Æ»®ÓÐÒ»¸öʹÓúܶàÖÐÎÄportsµÄÖÐÎÄ»¯Ö¸ÄÏÔÚ
¡£
Ŀǰ£¬ FreeBSD ÖÐÎÄ»¯Ö¸ÄÏ µÄά»¤ÈËÔ±ÊÇ
Éò¿¡ÐË statue@freebsd.sinica.edu.tw¡£
Éò¿¡ÐË statue@freebsd.sinica.edu.tw
ÀûÓà FreeBSD-Taiwan µÄ zh-L10N-tut½¨Á¢ÁË
Chinese FreeBSD Collection (CFC)¡£ Ïà¹ØµÄ packages ºÍ½Å±¾µÈ¿ÉÒÔÔÚ
ÕÒµ½¡£
µÂÓï±¾µØ»¯£¨ÊʺÏËùÓеÄISO 8859-1ÓïÑÔ£©
±¾µØ»¯
µÂÓï
Slaven Rezic eserte@cs.tu-berlin.de
дÁËÒ»¸öÔÚ FreeBSD »úÆ÷ÏÂÈçºÎʹÓÃÈÕ¶ûÂüÓïÑԵĵÂÓïÖ¸ÄÏ¡£ Õâ·ÝµÂÓï½Ì³Ì¿ÉÒÔÔÚ
ÕÒµ½¡£
Ï£À°Óï±¾µØ»¯
localization (±¾µØ»¯)
Greek (Ï£À°Óï)
Nikos Kokkalis nickkokkalis@gmail.com
׫дÁ˹ØÓÚÔÚ &os; ÉÏÖ§³ÖÏ£À°ÓïµÄÍêÕûÎÄÕ£¬ ÔÚ http://www.freebsd.org/doc/el_GR.ISO8859-7/articles/greek-language-support/index.html¡£
Çë×¢ÒâÕâÆªÎÄÕ ֻÓРϣÀ°ÓïµÄ°æ±¾¡£
ÈÕÓïºÍº«Óï±¾µØ»¯
±¾µØ»¯
ÈÕÓï
±¾µØ»¯
º«Óï
ÈÕÓï±¾µØ»¯Çë²Î¿¼£¬º«Óï²Î¿¼
¡£
·ÇÓ¢ÓïµÄFreeBSDÎĵµ
һЩ FreeBSD µÄ¹±Ï×ÕßÒѾ½«²¿·Ö FreeBSD Îĵµ·Òë³ÉÁËÆäËûÓïÑÔ¡£
Äú¿ÉÔÚ Ö÷Õ¾ ÒÔ¼°
/usr/share/doc ÕÒµ½¡£
diff --git a/zh_CN.GB2312/books/handbook/network-servers/chapter.xml b/zh_CN.GB2312/books/handbook/network-servers/chapter.xml
index ab71f2b27e..18435169f1 100644
--- a/zh_CN.GB2312/books/handbook/network-servers/chapter.xml
+++ b/zh_CN.GB2312/books/handbook/network-servers/chapter.xml
@@ -1,4843 +1,4829 @@
Murray
Stokely
Reorganized by
ÍøÂç·þÎñÆ÷
¸ÅÒª
±¾Õ½«¸²¸ÇijЩÔÚ &unix; ϵͳÉϳ£ÓõÄÍøÂç·þÎñ¡£»°Ì⽫»áÉæ¼°
ÈçºÎ°²×°¡¢ÅäÖᢲâÊÔºÍά»¤¶àÖÖ²»Í¬ÀàÐ͵ÄÍøÂç·þÎñ¡£±¾Õ½ÚÖн«Ìá
¹©´óÁ¿ÅäÖÃÎļþµÄÑùÀý£¬ÆÚÍûÄܹ»¶ÔÄúÓÐËùñÔÒæ¡£
ÔÚ¶ÁÍê±¾ÕÂÖ®ºó£¬Äú½«»áÖªµÀ£º
ÈçºÎ¹ÜÀí inetd¡£
ÈçºÎÉèÖÃÔËÐÐÒ»¸öÍøÂçÎļþϵͳ¡£
ÈçºÎÅäÖÃÒ»¸öÍøÂçÐÅÏ¢·þÎñÆ÷ÒÔ¹²ÏíÓû§Õʺš£
ÈçºÎͨ¹ýDHCP×Ô¶¯ÅäÖÃÍøÂç¡£
ÈçºÎÅäÖÃÒ»¸öÓòÃû·þÎñÆ÷¡£
ÈçºÎÉèÖÃApache HTTP ·þÎñÆ÷¡£
ÈçºÎÉèÖÃÎļþ´«Ê䣨FTP£©·þÎñÆ÷¡£
ÈçºÎʹÓÃSambaΪ &windows;
¿Í»§¶ËÉèÖÃÎļþºÍ´òÓ¡·þÎñ¡£
ÈçºÎͬ²½Ê±¼äºÍÈÕÆÚ£¬ÒÔ¼°ÈçºÎÉèÖÃʹÓÃNTPÐÒéµÄʱ¼ä·þÎñÆ÷¡£
ÈçºÎÅäÖñê×¼µÄÈÕÖ¾ÊØ»¤½ø³Ì£¬
syslogd£¬ ½ÓÊÜÔ¶³ÌÖ÷»úµÄÈÕÖ¾¡£
ÔÚÔĶÁ´ËÕ½Ú֮ǰ£¬ÄúÓ¦µ±£º
Àí½âÓйØ/etc/rcÖнű¾µÄ»ù±¾ÖªÊ¶¡£
ÊìϤ»ù±¾ÍøÂçÊõÓï¡£
¶®µÃÈçºÎ°²×°¶îÍâµÄµÚÈý·½Èí¼þ£¨£©¡£
Chern
Lee
Contributed by
¸üÐÂ
The &os; Documentation Project
inetd ³¬¼¶·þÎñÆ÷
×ÜÀÀ
&man.inetd.8; ÓÐʱҲ±»³Æ×÷ Internet
³¬¼¶·þÎñÆ÷
£¬ ÒòΪËü¿ÉÒÔΪ¶àÖÖ·þÎñ¹ÜÀíÁ¬½Ó¡£
µ± inetd ÊÕµ½Á¬½Óʱ£¬
ËüÄܹ»È·¶¨Á¬½ÓËùÐèµÄ³ÌÐò£¬ Æô¶¯ÏàÓ¦µÄ½ø³Ì£¬
²¢°Ñ socket ½»¸øËü (·þÎñ socket »á×÷Ϊ³ÌÐòµÄ±ê×¼ÊäÈë¡¢
Êä³öºÍ´íÎóÊä³öÃèÊö·û)¡£ ʹÓÃ
inetd À´ÔËÐÐÄÇЩ¸ºÔز»ÖصķþÎñÓÐÖúÓÚ½µµÍϵͳ¸ºÔØ£¬
ÒòΪËü²»ÐèҪΪÿ¸ö·þÎñ¶¼Æô¶¯¶ÀÁ¢µÄ·þÎñ³ÌÐò¡£
Ò»°ã˵À´£¬ inetd Ö÷ÒªÓÃÓÚÆô¶¯ÆäËü·þÎñ³ÌÐò£¬
µ«ËüÒ²ÓÐÄÜÁ¦Ö±½Ó´¦ÀíijЩ¼òµ¥µÄ·þÎñ£¬
ÀýÈç chargen¡¢
auth£¬ ÒÔ¼°
daytime¡£
ÕâÒ»½Ú½«½éÉܹØÓÚÈçºÎͨ¹ýÃüÁîÐÐÑ¡Ï ÒÔ¼°ÅäÖÃÎļþ
/etc/inetd.conf À´¶Ô
inetd ½øÐÐÅäÖõÄһЩ»ù´¡ÖªÊ¶¡£
ÉèÖÃ
inetd ÊÇͨ¹ý &man.rc.8; ϵͳÆô¶¯µÄ¡£
inetd_enable Ñ¡ÏîĬÈÏÉèΪ
NO£¬ µ«¿ÉÒÔÔÚ°²×°ÏµÍ³Ê±£¬
ÓÉÓû§¸ù¾ÝÐèҪͨ¹ý sysinstall À´´ò¿ª¡£
½«£º
inetd_enable="YES"
»ò
inetd_enable="NO"
дÈë
/etc/rc.conf ¿ÉÒÔÆôÓûò½ûÓÃϵͳÆô¶¯Ê±
inetd µÄ×Ô¶¯Æô¶¯¡£ ÃüÁ
&prompt.root; /etc/rc.d/inetd rcvar
¿ÉÒÔÏÔʾĿǰµÄÉèÖá£
´ËÍ⣬ Äú»¹¿ÉÒÔͨ¹ý
inetd_flags ²ÎÊýÀ´Ïò inetd
´«µÝ¶îÍâµÄÆäËü²ÎÊý¡£
ÃüÁîÐÐÑ¡Ïî
Óë¶àÊý·þÎñ³ÌÐòÀàËÆ£¬ inetd
Ò²ÌṩÁËΪÊýÖÚ¶àµÄÓÃÒÔ¿ØÖÆÆäÐÐΪµÄ²ÎÊý¡£ ÍêÕûµÄ²ÎÊýÁбíÈçÏ£º
inetd
ÕâЩ²ÎÊý¶¼¿ÉÒÔͨ¹ý
/etc/rc.conf µÄ
inetd_flags Ñ¡ÏîÀ´´«¸ø inetd¡£
ĬÈÏÇé¿öÏ£¬
inetd_flags ÉèΪ
-wW -C 60£¬ Õß±íʾϣÍûΪ
inetd µÄ·þÎñÆôÓà TCP wrapping£¬
²¢×èÖ¹À´×Ôͬһ IP ÿ·ÖÖÓ³¬¹ý 60 ´ÎµÄÇëÇó¡£
ËäÈ»ÎÒÃÇ»áÔÚÏÂÃæ½éÉܹØÓÚÏÞÖÆÁ¬½ÓƵÂʵÄÑ¡Ï
µ«³õѧµÄÓû§¿ÉÄÜ»áºÜ¸ßÐ˵ط¢ÏÖÕâЩ²ÎÊýͨ³£²¢²»ÐèÒª½øÐÐÐ޸ġ£
ÔÚÊÕµ½³¬´óÁ¿µÄÁ¬½ÓÇëÇóʱ£¬ ÕâЩѡÏîÔòÓпÉÄܻᷢ»Ó×÷Óá£
ÍêÕûµÄ²ÎÊýÁÐ±í£¬ ¿ÉÒÔÔÚ &man.inetd.8; Áª»úÊÖ²áÖÐÕÒµ½¡£
-c maximum
Ö¸¶¨µ¥¸ö·þÎñµÄ×î´ó²¢·¢·ÃÎÊÊýÁ¿£¬Ä¬ÈÏΪ²»ÏÞ¡£
Ò²¿ÉÒÔÔÚ´Ë·þÎñµÄ¾ßÌåÅäÖÃÀïÃæÍ¨¹ý¸Äµô¡£
-C rate
Ö¸¶¨µ¥¸ö·þÎñÒ»·ÖÖÓÄÚÄܱ»µ¥¸öIPµØÖ·µ÷ÓõÄ×î´ó´ÎÊý£¬
ĬÈϲ»ÏÞ¡£Ò²¿ÉÒÔÔÚ´Ë·þÎñµÄ¾ßÌåÅäÖÃÀïÃæÍ¨¹ý
¸Äµô¡£
-R rate
Ö¸¶¨µ¥¸ö·þÎñÒ»·ÖÖÓÄÚÄܱ»µ÷ÓõÄ×î´ó´ÎÊý£¬Ä¬ÈÏΪ256¡£
ÉèΪ0 ÔòÔÊÐí²»ÏÞ´ÎÊýµ÷Óá£
-s maximum
Ö¸¶¨Í¬Ò» IP ͬʱÇëÇóͬһ·þÎñʱÔÊÐíµÄ×î´óÖµ£» ĬÈÏֵΪ²»ÏÞÖÆ¡£
Äú¿ÉÒÔͨ¹ý
²ÎÊýÀ´ÒÔ·þÎñΪµ¥Î»½øÐÐÏÞÖÆ¡£
inetd.conf
¶ÔÓÚ inetd µÄÅäÖã¬
ÊÇͨ¹ý /etc/inetd.conf ÎļþÀ´Íê³ÉµÄ¡£
ÔÚÐÞ¸ÄÁË
/etc/inetd.conf Ö®ºó£¬ ¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁîÀ´Ç¿ÖÆ
inetd ÖØÐ¶ÁÈ¡ÅäÖÃÎļþ£º
ÖØÐ¼ÓÔØ inetd
ÅäÖÃÎļþ
&prompt.root; /etc/rc.d/inetd reload
ÅäÖÃÎļþÖеÄÿһÐж¼ÊÇÒ»¸ö¶ÀÁ¢µÄ·þÎñ³ÌÐò¡£ ÔÚÕâ¸öÎļþÖУ¬ Ç°ÃæÓÐ
#
µÄÄÚÈݱ»ÈÏΪÊÇ×¢ÊÍ¡£
/etc/inetd.conf ÎļþµÄ¸ñʽÈçÏ£º
service-name
socket-type
protocol
{wait|nowait}[/max-child[/max-connections-per-ip-per-minute[/max-child-per-ip]]]
user[:group][/login-class]
server-program
server-program-arguments
ÏÂÃæÊÇÕë¶Ô IPv4 µÄ &man.ftpd.8; ·þÎñµÄÀý×Ó£º
ftp stream tcp nowait root /usr/libexec/ftpd ftpd -l
service-name
Ö¸Ã÷¸÷¸ö·þÎñµÄ·þÎñÃû¡£Æä·þÎñÃû±ØÐëÓë/etc/servicesÖÐÁгöµÄÒ»Ö¡£
Õ⽫¾ö¶¨inetd»á¼àÌýÄĸöport¡£
Ò»µ©ÓÐеķþÎñÐèÒªÌí¼Ó£¬±ØÐëÏÈÔÚ/etc/servicesÀïÃæÌí¼Ó¡£
socket-type
¿ÉÒÔÊÇstream¡¢dgram¡¢raw»òÕß
seqpacket¡£ stream
ÓÃÓÚ»ùÓÚÁ¬½ÓµÄ TCP ·þÎñ£»¶ø dgram ÔòÓÃÓÚʹÓà UDP ÐÒéµÄ·þÎñ¡£
protocol
ÏÂÁÐÖ®Ò»£º
ÐÒé
˵Ã÷
tcp£¬ tcp4
TCP IPv4
udp£¬ udp4
UDP IPv4
tcp6
TCP IPv6
udp6
UDP IPv6
tcp46
Both TCP IPv4 and v6
udp46
Both UDP IPv4 and v6
{wait|nowait}[/max-child[/max-connections-per-ip-per-minute[/max-child-per-ip]]]
Ö¸Ã÷´Óinetd
ÀïÍ·µ÷ÓõķþÎñÊÇ·ñ¿ÉÒÔ×Ô¼º´¦Àísocket.
socketÀàÐͱØÐëʹÓã¬
¶østream socket daemons£¬ ÓÉÓÚͨ³£Ê¹ÓöàÏ̷߳½Ê½£¬Ó¦µ±Ê¹ÓÃ
. ͨ³£°Ñ¶à¸ö
socket ¶ª¸øµ¥¸ö·þÎñ½ø³Ì£¬ ¶ø Ôò
»áΪÿ¸öÐ嵀 socket Éú³ÉÒ»¸ö×Ó½ø³Ì¡£
Ñ¡ÏîÄܹ»ÅäÖÃ
inetd ÄÜΪ±¾·þÎñÅÉÉú³öµÄ×î´ó×Ó½ø³ÌÊýÁ¿¡£
Èç¹ûÄ³ÌØ¶¨·þÎñÐèÒªÏÞ¶¨×î¸ß10¸öʵÀý£¬ °Ñ/10
·Åµ½ºóÍ·¾Í¿ÉÒÔÁË¡£ Ö¸¶¨ /0
±íʾ²»ÏÞÖÆ×Ó½ø³ÌµÄÊýÁ¿¡£
³ýÁË Ö®Í⣬
»¹ÓÐÁ½¸öÑ¡Ïî¿ÉÒÔÏÞÖÆÀ´×ÔͬһλÖõ½Ìض¨·þÎñµÄ×î´óÁ¬½ÓÊý¡£
¿ÉÒÔÏÞÖÆÌØ¶¨ IP
µØÖ·Ã¿·ÖÖÓµÄ×ÜÁ¬½ÓÊý£¬ ÀýÈ磬 ÏÞÖÆÈκÎ
IP µØÖ·Ã¿·ÖÖÓ×î¶àÁ¬½ÓÊ®´Î¡£
Ôò¿ÉÒÔÏÞÖÆÎªÄ³Ò» IP µØÖ·ÔÚÈκÎʱºòËùÆô¶¯µÄ×Ó½ø³ÌÊýÁ¿¡£
ÕâЩѡÏî¶ÔÓÚ·ÀÖ¹Õë¶Ô·þÎñÆ÷ÓÐÒâ»òÎÞÒâµÄ×ÊÔ´ºÄ½ßºÍ¾Ü¾ø·þÎñ (DoS)
¹¥»÷Ê®·ÖÓÐÓá£
Õâ¸ö×Ö¶ÎÖУ¬ ±ØÐëÖ¸¶¨ »ò
Á½ÕßÖ®Ò»¡£ ¶ø
¡¢
ºÍ
ÔòÊÇ¿ÉÑ¡Ïî¡£
Á÷ʽ¶àÏ̷߳þÎñ£¬ ²¢ÇÒ²»ÅäÖÃÈκÎ
¡¢
»ò
ÏÞÖÆÊ±£¬
ÆäÅäÖÃΪ£º nowait¡£
ͬһ¸ö·þÎñ£¬ µ«Ï£Íû½«·þÎñÆô¶¯µÄÊýÁ¿ÏÞÖÆÎªÊ®¸öʱ£¬
ÔòÊÇ£º nowait/10¡£
ͬÑùÅäÖ㬠ÏÞÖÆÃ¿¸ö IP µØÖ·Ã¿·ÖÖÓ×î¶àÁ¬½Ó¶þÊ®´Î£¬
¶øÍ¬Ê±Æô¶¯µÄ×Ó½ø³Ì×î¶àÊ®¸ö£¬ Ӧд×÷£º
nowait/10/20¡£
ÏÂÃæÊÇ &man.fingerd.8; ·þÎñµÄĬÈÏÅäÖãº
finger stream tcp nowait/3/10 nobody /usr/libexec/fingerd fingerd -s
×îºóÕâ¸öÀý×ÓÖУ¬ ½«×Ó½ø³ÌÊýÏÞÖÆÎª
100 ¸ö£¬ ¶øÈÎÒâ IP ×î¶àͬʱ½¨Á¢ 5 ¸öÁ¬½Ó£º
nowait/100/0/5¡£
user
¸Ã¿ª¹ØÖ¸¶¨·þÎñ½«ÒÔʲôÓû§Éí·ÝÔËÐС£Ò»°ã¶øÑÔ£¬·þÎñÔËÐÐÉí·ÝÊÇ
root¡£»ùÓÚ°²È«Ä¿µÄ£¬¿ÉÒÔ¿´µ½ÓÐЩ·þÎñÒÔ
daemonÉí·Ý£¬»òÕßÊÇ×îÐ¡ÌØÈ¨µÄ
nobodyÉí·ÝÔËÐС£
server-program
µ±Á¬½Óµ½À´Ê±£¬Ö´ÐзþÎñ³ÌÐòµÄȫ·¾¶¡£Èç¹û·þÎñÊÇÓÉ
inetdÄÚÖÃÌṩµÄ£¬ÒÔ´úÌæ¡£
server-program-arguments
µ±µ÷Óõ½Ê±£¬¸Ã¿ª¹Ø
µÄֵͨ¹ýargv[0]ͨ¹ý´«µÝ¸ø·þÎñ¶ø¹¤×÷¡£
Èç¹ûÃüÁîÐÐΪ£ºmydaemon -d£¬Ôò
mydaemon -dΪ
¿ª¹ØµÄÖµ¡£Í¬ÑùµÄ£¬Èç¹û·þÎñÊÇÓÉinetd
ÄÚÖÃÌṩµÄ£¬ÕâÀﻹÊÇ
¡£
Security
Ëæ°²×°Ê±ËùÑ¡µÄģʽ²»Í¬£¬
Ðí¶à inetd µÄ·þÎñ¿ÉÄÜÒѾĬÈÏÆôÓá£
Èç¹ûȷʵ²»ÐèҪij¸öÌØ¶¨µÄ·þÎñ£¬ ÔòÓ¦¿¼ÂǽûÓÃËü¡£
ÔÚ /etc/inetd.conf ÖУ¬
½«¶ÔÓ¦·þÎñµÄÄÇÐÐÇ°Ãæ¼ÓÉÏ #
£¬
È»ºó ÖØÐ¼ÓÔØ
inetd ÅäÖà ¾Í¿ÉÒÔÁË¡£ ijЩ·þÎñ£¬ ÀýÈç
fingerd£¬ ¿ÉÄÜÊÇÍêÈ«²»ÐèÒªµÄ£¬
ÒòΪËüÃÇÌṩµÄÐÅÏ¢¿ÉÄܶԹ¥»÷ÕßÓÐÓá£
ijЩ·þÎñÔÚÉè¼ÆÊ±ÊÇȱÉÙ°²È«ÒâʶµÄ£¬ »òÕßÓйý³¤»òѹ¸ùûÓÐÁ¬½ÓÇëÇóµÄ³¬Ê±»úÖÆ¡£
ÕâʹµÃ¹¥»÷ÕßÄܹ»Í¨¹ý»ºÂýµØ¶ÔÕâЩ·þÎñ·¢ÆðÁ¬½Ó£¬ ²¢ºÄ¾¡¿ÉÓõÄ×ÊÔ´¡£
¶ÔÓÚÕâÖÖÇé¿ö£¬ ÉèÖà ¡¢
»ò ÏÞÖÆ£¬
À´ÖÆÔ¼·þÎñµÄÐÐΪÊǸöºÃ°ì·¨¡£
ĬÈÏÇé¿öÏ£¬TCP wrapping ÊÇ´ò¿ªµÄ¡£²Î¿¼
&man.hosts.access.5; ÊֲᣬÒÔ»ñµÃ¸ü¶à¹ØÓÚÔÚ¸÷ÖÖ inetd
µ÷ÓõķþÎñÉÏÉèÖÃTCPÏÞÖÆµÄÐÅÏ¢¡£
ÔÓÏî
daytime¡¢
time¡¢
echo¡¢
discard¡¢
chargen£¬ ÒÔ¼°
auth ¶¼ÊÇÓÉ inetd
ÌṩµÄÄÚ½¨·þÎñ¡£
auth ·þÎñÌṩÁËÍøÂçÉí·Ý·þÎñ£¬
Ëü¿ÉÒÔÅäÖÃΪÌṩ²»Í¬¼¶±ðµÄ·þÎñ£¬ ¶øÆäËü·þÎñÔòͨ³£Ö»Äܼòµ¥µÄ´ò¿ª»ò¹Ø±Õ¡£
²Î¿¼ &man.inetd.8; ÊÖ²á»ñµÃ¸ü¶àÐÅÏ¢¡£
Tom
Rhodes
Reorganized and enhanced by
Bill
Swingle
Written by
ÍøÂçÎļþϵͳ£¨NFS£©
NFS
ÍøÂçÎļþϵͳÊÇFreeBSDÖ§³ÖµÄÎļþϵͳÖеÄÒ»ÖÖ£¬
Ò²±»³ÆÎª NFS¡£ NFSÔÊÐíÒ»¸öϵͳÔÚÍøÂçÉÏÓëËüÈ˹²ÏíĿ¼ºÍÎļþ¡£Í¨¹ýʹÓÃNFS£¬Óû§ºÍ³ÌÐò¿ÉÒÔÏó·ÃÎʱ¾µØÎļþ
Ò»Ñù·ÃÎÊÔ¶¶ËϵͳÉϵÄÎļþ¡£
ÒÔÏÂÊÇNFS×îÏÔ¶øÒ×¼ûµÄºÃ´¦£º
±¾µØ¹¤×÷վʹÓøüÉٵĴÅÅ̿ռ䣬ÒòΪͨ³£µÄÊý¾Ý¿ÉÒÔ´æ·ÅÔÚÒ»
̨»úÆ÷É϶øÇÒ¿ÉÒÔͨ¹ýÍøÂç·ÃÎʵ½¡£
Óû§²»±ØÔÚÿ¸öÍøÂçÉÏ»úÆ÷ÀïÍ·¶¼ÓÐÒ»¸öhomeĿ¼¡£HomeĿ¼
¿ÉÒÔ±»·ÅÔÚNFS·þÎñÆ÷Éϲ¢ÇÒÔÚÍøÂçÉÏ´¦´¦¿ÉÓá£
ÖîÈçÈíÇý£¬CDROM£¬ºÍ &iomegazip; Ö®ÀàµÄ´æ´¢É豸¿ÉÒÔÔÚÍøÂçÉÏÃæ±»±ðµÄ»úÆ÷ʹÓá£
Õâ¿ÉÒÔ¼õÉÙÕû¸öÍøÂçÉϵĿÉÒÆ¶¯½éÖÊÉ豸µÄÊýÁ¿¡£
NFSÊÇÈçºÎ¹¤×÷µÄ
NFS ÖÁÉÙ°üÀ¨Á½¸öÖ÷ÒªµÄ²¿·Ö£º һ̨·þÎñÆ÷£¬
ÒÔ¼°ÖÁÉÙһ̨¿Í»§»ú£¬ ¿Í»§»úÔ¶³ÌµØ·ÃÎʱ£´æÔÚ·þÎñÆ÷ÉϵÄÊý¾Ý¡£
ÒªÈÃÕâÒ»ÇÐÔËתÆðÀ´£¬ ÐèÒªÅäÖò¢ÔËÐм¸¸ö³ÌÐò¡£
·þÎñÆ÷±ØÐëÔËÐÐÒÔÏ·þÎñ£º
NFS
server (·þÎñ)
Îļþ·þÎñÆ÷
UNIX ¿Í»§»ú
rpcbind
mountd
nfsd
·þÎñ
ÃèÊö
nfsd
NFS£¬ÎªÀ´×ÔNFS¿Í»§¶ËµÄ
ÇëÇó·þÎñ¡£
mountd
NFS¹ÒÔØ·þÎñ£¬´¦Àí&man.nfsd.8;µÝ½»¹ýÀ´µÄÇëÇó¡£
rpcbind
´Ë·þÎñÔÊÐí
NFS ¿Í»§³ÌÐò²éѯÕýÔÚ±» NFS ·þÎñʹÓõĶ˿ڡ£
¿Í»§¶ËͬÑùÔËÐÐһЩ½ø³Ì£¬±ÈÈç
nfsiod¡£
nfsiod´¦ÀíÀ´×ÔNFSµÄÇëÇó¡£
ÕâÊÇ¿ÉÑ¡µÄ£¬¶øÇÒ¿ÉÒÔÌá¸ßÐÔÄÜ£¬¶ÔÓÚÆÕͨºÍÕýÈ·µÄ²Ù×÷À´Ëµ²¢²»ÊDZØÐëµÄ¡£
²Î¿¼&man.nfsiod.8;ÊÖ²á»ñµÃ¸ü¶àÐÅÏ¢¡£
ÅäÖÃNFS
NFS
configuration
NFSµÄÅäÖùý³ÌÏà¶Ô¼òµ¥¡£Õâ¸ö¹ý³ÌÖ»ÐèÒª
¶Ô/etc/rc.confÎļþ×÷һЩ¼òµ¥Ð޸ġ£
ÔÚNFS·þÎñÆ÷Õâ¶Ë£¬È·ÈÏ/etc/rc.conf
ÎļþÀïÍ·ÒÔÏ¿ª¹Ø¶¼ÅäÉÏÁË:
rpcbind_enable="YES"
nfs_server_enable="YES"
mountd_flags="-r"
Ö»ÒªNFS·þÎñ±»ÖÃΪenable£¬mountd
¾ÍÄÜ×Ô¶¯ÔËÐС£
ÔÚ¿Í»§¶ËÒ»²à£¬È·ÈÏÏÂÃæÕâ¸ö¿ª¹Ø³öÏÖÔÚ
/etc/rc.confÀïÍ·:
nfs_client_enable="YES"
/etc/exportsÎļþÖ¸¶¨ÁËÄĸöÎļþϵͳ
NFSÓ¦¸ÃÊä³ö£¨ÓÐʱ±»³ÆÎª¹²Ïí
£©¡£
/etc/exportsÀïÃæÃ¿ÐÐÖ¸¶¨Ò»¸öÊä³öµÄÎļþϵͳºÍ
ÄÄЩ»úÆ÷¿ÉÒÔ·ÃÎʸÃÎļþϵͳ¡£ÔÚÖ¸¶¨»úÆ÷·ÃÎÊȨÏÞµÄͬʱ£¬·ÃÎÊÑ¡Ïî
¿ª¹ØÒ²¿ÉÒÔ±»Ö¸¶¨¡£Óкܶ࿪¹Ø¿ÉÒÔ±»ÓÃÔÚÕâ¸öÎļþÀïÍ·£¬²»¹ý²»»áÔÚÕâ
ÀïÏêϸ̸¡£Äú¿ÉÒÔͨ¹ýÔĶÁ&man.exports.5; ÊÖ²áÀ´·¢ÏÖÕâЩ¿ª¹Ø¡£
ÒÔÏÂÊÇһЩ/etc/exportsµÄÀý×Ó£º
NFS
export examples
ÏÂÃæÊÇÒ»¸öÊä³öÎļþϵͳµÄÀý×Ó£¬ ²»¹ýÕâÖÖÅäÖÃÓëÄúËù´¦µÄÍøÂç»·¾³¼°ÆäÅäÖÃÃÜÇÐÏà¹Ø¡£
ÀýÈ磬 Èç¹ûÒª°Ñ /cdrom Êä³ö¸øÓë·þÎñÆ÷ÓòÃûÏàͬµÄÈý̨¼ÆËã»ú
(Òò´ËÀý×ÓÖÐÖ»ÓлúÆ÷Ãû£¬ ¶øÃ»Óиø³öÕâЩ¼ÆËã»úµÄÓòÃû)£¬ »òÔÚ
/etc/hosts ÎļþÖнøÐÐÁËÕâÖÖÅäÖá£
±êÖ¾±íʾ°ÑÊä³öµÄÎļþϵͳÖÃΪֻ¶Á¡£ ÓÉÓÚʹÓÃÁËÕâ¸ö±êÖ¾£¬
Ô¶³ÌϵͳÔÚÊä³öµÄÎļþϵͳÉϾͲ»ÄÜдÈëÈκα䶯ÁË¡£
/cdrom -ro host1 host2 host3
ÏÂÃæµÄÀý×Ó¿ÉÒÔÊä³ö/home¸øÈý¸öÒÔIPµØÖ··½Ê½±íʾµÄÖ÷»ú¡£
¶ÔÓÚÔÚûÓÐÅäÖÃDNS·þÎñÆ÷µÄ˽ÓÐÍøÂçÀïÍ·£¬ÕâºÜÓÐÓá£
´ËÍ⣬ /etc/hosts ÎļþÒ²¿ÉÒÔÓÃÒÔÅäÖÃÖ÷»úÃû£»²Î¿´ &man.hosts.5; ¡£
±ê¼ÇÔÊÐí×ÓĿ¼±»×÷Ϊ¹ÒÔØµã¡£
Ò²¾ÍÊÇ˵£¬¿Í»§¶Ë¿ÉÒÔ¸ù¾ÝÐèÒª¹ÒÔØÐèÒªµÄĿ¼¡£
/home -alldirs 10.0.0.2 10.0.0.3 10.0.0.4
ÏÂÃæ¼¸ÐÐÊä³ö /a £¬ÒÔ±ãÁ½¸öÀ´×Ô²»Í¬ÓòµÄ¿Í»§¶Ë¿ÉÒÔ·ÃÎÊÎļþϵͳ¡£
±ê¼ÇÊÚȨԶ¶ËϵͳÉϵÄ
root Óû§ÔÚ±»Êä³öµÄÎļþϵͳÉÏÒÔrootÉí·Ý½øÐжÁд¡£
Èç¹ûûÓÐÌØ±ðÖ¸¶¨ -maproot=root ±ê¼Ç£¬
Ôò¼´Ê¹Óû§ÔÚÔ¶¶ËϵͳÉÏÊÇ root Éí·Ý£¬
Ò²²»ÄÜÐ޸ı»Êä³öÎļþϵͳÉϵÄÎļþ¡£
/a -maproot=root host.example.com box.example.org
ΪÁËÄܹ»·ÃÎʵ½±»Êä³öµÄÎļþϵͳ£¬¿Í»§¶Ë±ØÐë±»ÊÚȨ¡£
ÇëÈ·ÈϿͻ§¶ËÔÚÄúµÄ /etc/exports ±»Áгö¡£
ÔÚ /etc/exports ÀïÍ·£¬Ã¿Ò»ÐÐÀïÃæ£¬Êä³öÐÅÏ¢ºÍÎļþϵͳһһ¶ÔÓ¦¡£
Ò»¸öÔ¶³ÌÖ÷»úÿ´ÎÖ»ÄܶÔÓ¦Ò»¸öÎļþϵͳ¡£¶øÇÒÖ»ÄÜÓÐÒ»¸öĬÈÏÈë¿Ú¡£±ÈÈ磬¼ÙÉè
/usr ÊǶÀÁ¢µÄÎļþϵͳ¡£Õâ¸ö /etc/exports ¾ÍÊÇÎÞЧµÄ£º
# Invalid when /usr is one file system
/usr/src client
/usr/ports client
Ò»¸öÎļþϵͳ£¬/usr£¬ ÓÐÁ½ÐÐÖ¸¶¨Êä³öµ½Í¬Ò»Ö÷»ú£¬
client.
½â¾öÕâÒ»ÎÊÌâµÄÕýÈ·µÄ¸ñʽÊÇ£º
/usr/src /usr/ports client
ÔÚͬһÎļþϵͳÖУ¬ Êä³öµ½Ö¸¶¨¿Í»§»úµÄËùÓÐĿ¼£¬ ¶¼±ØÐëдµ½Í¬Ò»ÐÐÉÏ¡£
ûÓÐÖ¸¶¨¿Í»§»úµÄÐлᱻÈÏΪÊǵ¥Ò»Ö÷»ú¡£ ÕâÏÞÖÆÁËÄã¿ÉÒÔÔõÑùÊä³öµÄÎļþϵͳ£¬
µ«¶Ô¾ø´ó¶àÊýÈËÀ´ËµÕâ²»ÊÇÎÊÌâ¡£
ÏÂÃæÊÇÒ»¸öÓÐЧÊä³öÁбíµÄÀý×Ó£¬
/usr ºÍ /exports
ÊDZ¾µØÎļþϵͳ£º
# Export src and ports to client01 and client02, but only
# client01 has root privileges on it
/usr/src /usr/ports -maproot=root client01
/usr/src /usr/ports client02
# The client machines have root and can mount anywhere
# on /exports. Anyone in the world can mount /exports/obj read-only
/exports -alldirs -maproot=root client01 client02
/exports/obj -ro
ÔÚÐÞ¸ÄÁË /etc/exports ÎļþÖ®ºó£¬
¾Í±ØÐëÈà mountd ·þÎñÖØÐ¼ì²éËü£¬
ÒÔ±ãʹÐÞ¸ÄÉúЧ¡£ Ò»ÖÖ·½·¨ÊÇͨ¹ý¸øÕýÔÚÔËÐеķþÎñ³ÌÐò·¢ËÍ HUP
ÐźÅÀ´Íê³É£º
&prompt.root; kill -HUP `cat /var/run/mountd.pid`
»òÖ¸¶¨Êʵ±µÄ²ÎÊýÀ´ÔËÐÐ mountd &man.rc.8; ½Å±¾£º
&prompt.root; /etc/rc.d/mountd onereload
¹ØÓÚʹÓà rc ½Å±¾µÄϸ½Ú£¬ Çë²Î¼û ¡£
ÁíÍ⣬ ÏµÍ³ÖØÆô¶¯¿ÉÒÔÈà FreeBSD °ÑÒ»Çж¼ÅªºÃ¡£ ¾¡¹ÜÈç´Ë£¬
ÖØÆô²»ÊDZØÐëµÄ¡£ ÒÔ root Éí·ÝÖ´ÐÐÏÂÃæµÄÃüÁî¿ÉÒԸ㶨һÇС£
ÔÚ NFS ·þÎñÆ÷¶Ë£º
&prompt.root; rpcbind
&prompt.root; nfsd -u -t -n 4
&prompt.root; mountd -r
ÔÚ NFS ¿Í»§¶Ë£º
&prompt.root; nfsiod -n 4
ÏÖÔÚÿ¼þÊÂÇé¶¼Ó¦¸Ã¾ÍÐ÷£¬ÒÔ±¸¹ÒÔØÒ»¸öÔ¶¶ËÎļþϵͳ¡£ ÔÚÕâЩÀý×ÓÀïÍ·£¬
·þÎñÆ÷Ãû×Ö½«ÊÇ£ºserver £¬¶ø¿Í»§¶ËµÄÃû×Ö½«ÊÇ£º client¡£
Èç¹ûÄúÖ»´òËãÁÙʱ¹ÒÔØÒ»¸öÔ¶¶ËÎļþϵͳ»òÕßÖ»ÊÇ´òËã×÷²âÊÔÅäÖÃÕýÈ·Óë·ñ£¬
Ö»ÒªÔÚ¿Í»§¶ËÒÔ root Éí·ÝÖ´ÐÐÏÂÃæµÄÃüÁ
NFS
mounting
&prompt.root; mount server:/home /mnt
ÕâÌõÃüÁî»á°Ñ·þÎñ¶ËµÄ /home Ŀ¼¹ÒÔØµ½¿Í»§¶ËµÄ /mnt ÉÏ¡£
Èç¹ûÅäÖÃÕýÈ·£¬ÄúÓ¦¸Ã¿ÉÒÔ½øÈë¿Í»§¶ËµÄ /mnt Ŀ¼²¢ÇÒ¿´µ½ËùÓзþÎñ¶ËµÄÎļþ¡£
Èç¹ûÄú´òËãÈÃϵͳÿ´ÎÔÚÖØÆô¶¯µÄʱºò¶¼×Ô¶¯¹ÒÔØÔ¶¶ËµÄÎļþϵͳ£¬°ÑÄǸöÎļþϵͳ¼Óµ½
/etc/fstab ÎļþÀïÍ·È¥¡£ÏÂÃæÊÇÀý×Ó£º
server:/home /mnt nfs rw 0 0
&man.fstab.5; ÊÖ²áÀïÓÐËùÓпÉÓõĿª¹Ø¡£
Ëø
ijЩӦÓóÌÐò (ÀýÈç mutt)
ÐèÒªÎļþÉÏËøÖ§³Ö²ÅÄÜÕý³£ÔËÐС£ ÔÚʹÓÃ
NFS ʱ£¬ ¿ÉÒÔÓà rpc.lockd
À´Ö§³ÖÎļþÉÏËø¹¦ÄÜ¡£ ÒªÆôÓÃËü£¬
ÐèÒªÔÚ·þÎñÆ÷ºÍ¿Í»§»úµÄ /etc/rc.conf ÖмÓÈë
(¼Ù¶¨Á½¶Ë¾ùÒÑÅäºÃÁË NFS)£º
rpc_lockd_enable="YES"
rpc_statd_enable="YES"
È»ºóʹÓÃÏÂÊöÃüÁîÆô¶¯¸Ã³ÌÐò£º
&prompt.root; /etc/rc.d/lockd start
&prompt.root; /etc/rc.d/statd start
Èç¹û²¢²»ÐèÒªÕæµÄÔÚ NFS ¿Í»§»úºÍ
NFS ·þÎñÆ÷¼äÈ·±£ÉÏËøµÄÓïÒ壬
¿ÉÒÔÈà NFS ¿Í»§»úÔÚ±¾µØÉÏËø£¬
·½·¨ÊÇʹÓà &man.mount.nfs.8; ʱָ¶¨ ²ÎÊý¡£
Çë²Î¼û &man.mount.nfs.8; Áª»úÊÖ²áÒÔÁ˽â¸ü¶àϸ½Ú¡£
ʵ¼ÊÓ¦ÓÃ
NFS Óкܶàʵ¼ÊÓ¦Óá£ÏÂÃæÊDZȽϳ£¼ûµÄһЩ£º
NFS
uses
¶à¸ö»úÆ÷¹²Ïíһ̨CDROM»òÕ߯äËûÉ豸¡£Õâ¶ÔÓÚÔÚ¶ą̀»úÆ÷Öа²×°Èí¼þÀ´Ëµ¸ü¼Ó±ãÒ˸ú·½±ã¡£
ÔÚ´óÐÍÍøÂçÖУ¬ÅäÖÃһ̨ÖÐÐÄ NFS ·þÎñÆ÷ÓÃÀ´·ÅÖÃËùÓÐÓû§µÄhomeĿ¼¿ÉÄÜ»á´øÀ´±ãÀû¡£
ÕâЩĿ¼Äܱ»Êä³öµ½ÍøÂçÒÔ±ãÓû§²»¹ÜÔÚÄĄ̈¹¤×÷Õ¾ÉϵǼ£¬×ÜÄܵõ½ÏàͬµÄhomeĿ¼¡£
¼¸Ì¨»úÆ÷¿ÉÒÔÓÐͨÓõÄ/usr/ports/distfiles Ŀ¼¡£
ÕâÑùµÄ»°£¬µ±ÄúÐèÒªÔÚ¼¸Ì¨»úÆ÷Éϰ²×°portʱ£¬Äú¿ÉÒÔÎÞÐèÔÚÿ̨É豸ÉÏÏÂÔØ¶ø¿ìËÙ·ÃÎÊÔ´Âë¡£
Wylie
Stilwell
Contributed by
Chern
Lee
Rewritten by
ͨ¹ý amd ×Ô¶¯µØ¹Ò½Ó
amd
×Ô¶¯¹Ò½Ó·þÎñ
&man.amd.8; (×Ô¶¯¹Ò½Ó·þÎñ) Äܹ»×Ô¶¯µØÔÚ·ÃÎÊʱ¹Ò½ÓÔ¶³ÌµÄÎļþϵͳ¡£
Èç¹ûÎļþϵͳÔÚÒ»¶Îʱ¼äÖ®ÄÚûÓл£¬ Ôò»á±»
amd ×Ô¶¯Ð¶Ï¡£ ͨ¹ýʹÓÃ
amd£¬ Äܹ»Ìṩһ¸ö³Ö¾Ã¹Ò½ÓÒÔÍâµÄÑ¡Ôñ£¬
¶øºóÕßÍùÍùÐèÒªÁÐÈë
/etc/fstab¡£
amd ͨ¹ý½«×Ô¼ºÒÔ NFS ·þÎñÆ÷µÄÐÎʽ£¬
¸½¼Óµ½ /host ºÍ
/net Ŀ¼ÉÏÀ´¹¤×÷¡£
µ±·ÃÎÊÕâЩĿ¼ÖеÄÎļþʱ£¬ amd
½«²éÕÒÏàÓ¦µÄÔ¶³Ì¹Ò½Óµã£¬ ²¢×Ô¶¯µØ¹Ò½Ó¡£
/net ÓÃÓÚ¹Ò½ÓÔ¶³Ì IP µØÖ·Éϵ¼³öµÄÎļþϵͳ£¬
¶ø /host ÔòÓÃÓÚ¹Ò½ÓÔ¶³ÌÖ÷»úÃûÉϵÄÎļþϵͳ¡£
·ÃÎÊ
/host/foobar/usr ÖеÄÎļþ£¬ Ï൱ÓÚ¸æËß
amd ³¢ÊÔ¹Ò½ÓÔÚÖ÷»ú
foobar Éϵ¼³öµÄ
/usr¡£
ͨ¹ý amd À´¹Ò½Óµ¼³öµÄÎļþϵͳ
Äú¿ÉÒÔͨ¹ýʹÓà showmount
ÃüÁîÀ´²é¿´Ô¶³ÌÖ÷»úÉϵ¼³öµÄÎļþϵͳ¡£ ÀýÈ磬
Òª²é¿´ foobar Éϵ¼³öµÄÎļþϵͳ£¬ ¿ÉÒÔÓãº
&prompt.user; showmount -e foobar
Exports list on foobar:
/usr 10.10.10.0
/a 10.10.10.0
&prompt.user; cd /host/foobar/usr
ÈçͬÔÚÇ°ÃæÀý×ÓÖÐËù¿´µ½µÄ£¬ showmount ÏÔʾÁ˵¼³öµÄ
/usr¡£ µ±½øÈë
/host/foobar/usr Õâ¸öĿ¼ʱ£¬ amd
½«³¢ÊÔ½âÎöÖ÷»úÃû foobar
²¢×Ô¶¯µØ¹Ò½ÓÐèÒªµÄÎļþϵͳµ¼³ö¡£
amd ¿ÉÒÔͨ¹ýÆô¶¯½Å±¾À´Æô¶¯£¬ ·½·¨ÊÇÔÚ
/etc/rc.conf ÖмÓÈ룺
amd_enable="YES"
³ý´ËÖ®Í⣬ »¹¿ÉÒÔ¸ø
amd ͨ¹ý
amd_flags Ñ¡ÏîÀ´´«µÝ¶îÍâµÄ²ÎÊý¡£ ĬÈÏÇé¿öÏ£¬
amd_flags Ϊ£º
amd_flags="-a /.amd_mnt -l syslog /host /etc/amd.map /net /etc/amd.map"
/etc/amd.map
Îļþ¶¨ÒåÁ˹ҽӵ¼³öÎļþϵͳʱËùʹÓõÄĬÈÏÑ¡Ïî¡£
/etc/amd.conf Îļþ£¬ Ôò¶¨ÒåÁ˸ü¶à¹ØÓÚ
amd µÄ¸ß¼¶¹¦ÄÜÑ¡Ïî¡£
Çë²Î¿¼ &man.amd.8; ºÍ &man.amd.conf.5; Áª»úÊֲᣬ
ÒÔÁË½â½øÒ»²½µÄÇé¿ö¡£
John
Lind
Contributed by
ÓëÆäËûϵͳ¼¯³ÉʱµÄ³£¼ûÎÊÌâ
Ä³Ð©ÌØ¶¨µÄ ISA PC ϵͳÉϵÄÒÔÌ«ÍøÊÊÅäÆ÷ÉÏÓÐһЩÏÞÖÆ£¬
ÕâЩÏÞÖÆ¿ÉÄܻᵼÖÂÑÏÖØµÄÍøÂçÎÊÌ⣬ ÌØ±ðÊÇÓë NFS ÅäºÏʹÓÃʱ¡£
ÕâЩÎÊÌâ²¢·Ç FreeBSD ËùÌØÓеģ¬ µ« FreeBSD ϵͳ»áÊܵ½ÕâЩÎÊÌâµÄÓ°Ïì¡£
ÕâÑùµÄÎÊÌ⣬ ¼¸ºõ×ÜÊÇÔÚµ± (FreeBSD) PC ϵͳÓë¸ßÐÔÄܵŤ×÷Õ¾£¬
ÀýÈç Silicon Graphics, Inc., ºÍ Sun Microsystems, Inc. µÄ¹¤×÷Õ¾ÁªÍøÊ±·¢Éú¡£
NFS ¹Ò½ÓÄܹ»Õý³£¹¤×÷£¬ ¶øÇÒһЩ²Ù×÷Ò²¿ÉÄܳɹ¦£¬
µ«·þÎñÆ÷»áºÜ¿ì±äµÃ¶Ô¿Í»§»ú²»Ì«Àí»á£¬
ËäÈ»¶ÔÆäËû¿Í»§»úµÄÇëÇóÈÔÈ»Äܹ»Õý³£´¦Àí¡£
ÕâÖÖÇé¿öͨ³£·¢ÉúÔÚ¿Í»§¶Ë£¬ ÎÞÂÛËüÊÇÒ»¸ö FreeBSD ϵͳ»òÊÇÖÕ¶Ë¡£
ÔÚÐí¶àϵͳÉÏ£¬ Ò»µ©·¢ÉúÁËÕâÑùµÄÎÊÌ⣬ ͨ³£Ã»°ì·¨Õý³£µØ¹Ø±Õ¿Í»§»ú¡£
ΨһµÄ°ì·¨Í¨³£ÊÇÈÃÖն˸´Î»£¬ ÒòΪÕâÒ» NFS ×´¿öûÓа취±»½â¾ö¡£
¾¡¹Ü ÕýÈ·µÄ
½â¾ö°ì·¨£¬ ÊÇΪ
FreeBSD ϵͳÅ䱸һ¿é¸ßÐÔÄܵġ¢ ÊÊÓõÄÒÔÌ«ÍøÊÊÅäÆ÷£¬
È»¶øÒ²ÓÐ°ì·¨ÈÆ¹ýÎÊÌâ²¢µÃµ½Ïà¶ÔÂúÒâµÄ½á¹û¡£
Èç¹û FreeBSD ϵͳÊÇ
·þÎñÆ÷£¬ ÔòÔÚ¿Í»§»ú¹Ò½Óʱ£¬ Ó¦¸ÃÖ¸¶¨
¡£ Èç¹û
FreeBSD ϵͳÊÇ ¿Í»§»ú£¬
ÔòÓ¦¼ÓÈë ²ÎÊý¡£ ÕâЩѡÏî¿ÉÒÔͨ¹ýÔÚ¶ÔÓ¦µÄ
fstab µÄµÚËĸö×ֶμÓÈ룬
ÒÔ±ãÈÿͻ§»úÄܹ»×Ô¶¯µØ¹Ò½Ó£¬ »òÕßͨ¹ý &man.mount.8; µÄ
²ÎÊýÔÚÊÖ¹¤¹Ò½Óʱָ¶¨¡£
»¹ÐèҪעÒâµÄÊÇÁíÒ»¸öÎÊÌ⣬ ÓÐʱ»á±»ÎóÈÏΪÊǺÍÉÏÃæÒ»ÑùµÄÎÊÌâ¡£
Õâ¸öÎÊÌâ¶à¼ûÓÚ NFS ·þÎñÆ÷ºÍ¿Í»§»úÔÚ²»Í¬µÄÍøÂçÉÏʱ¡£ Èç¹ûÊÇÕâÖÖÇé¿ö£¬ Ò»¶¨Òª
È·¶¨ ÄúµÄ·ÓÉÆ÷ȷʵ°Ñ±ØÐèµÄ UDP
ÐÅϢ·Óɵ½ÁËÄ¿µÄµØ£¬ ·ñÔòÄú½«Ê²Ã´Ò²×ö²»ÁË¡£
ÏÂÃæµÄÀý×ÓÖУ¬ fastws ÊÇÖ÷»ú
(½Ó¿Ú) µÄÃû×Ö£¬ ËüÊÇһ̨¸ßÐÔÄܵÄÖÕ¶Ë£¬ ¶ø
freebox ÊÇÁíһ̨Ö÷»ú (½Ó¿Ú) µÄÃû×Ö£¬
ËüÊÇÒ»¸öʹÓýϵÍÐÔÄܵÄÒÔÌ«ÍøÊÊÅäÆ÷µÄ FreeBSD ϵͳ¡£ ͬʱ£¬
/sharedfs ½«±»µ¼³ö³ÉΪ NFS
Îļþϵͳ (²Î¼û &man.exports.5;)£¬ ¶ø
/project
½«Êǿͻ§»úÉϹҽÓÕâÒ»µ¼³öÎļþϵͳµÄ¹Ò½Óµã¡£ ËùÓеÄÓ¦Óó¡¾°ÖУ¬
Çë×¢Ò⸽¼ÓÑ¡Ï ÀýÈç »ò
ÒÔ¼° ¿ÉÄÜÊÇÄúµÄÓ¦ÓÃËùÐèÒªµÄ¡£
¹ØÓÚ FreeBSD ϵͳ (freebox)
×÷Ϊ¿Í»§»úµÄʾ·¶ /etc/fstab Îļþ£¬ ¼ûÓÚ
freebox Ö®ÉÏ£º
fastws:/sharedfs /project nfs rw,-r=1024 0 0
ÔÚ freebox ÉÏÊÖ¹¤¹Ò½Ó£º
&prompt.root; mount -t nfs -o -r=1024 fastws:/sharedfs /project
ÒÔ FreeBSD ϵͳ×÷Ϊ·þÎñÆ÷µÄÀý×Ó£¬ ÊÇ fastws ÉϵÄ
/etc/fstab£º
freebox:/sharedfs /project nfs rw,-w=1024 0 0
ÔÚ fastws ÉÏÊÖ¹¤¹Ò½ÓµÄÃüÁîÊÇ£º
&prompt.root; mount -t nfs -o -w=1024 freebox:/sharedfs /project
¼¸ºõËùÓÐµÄ 16-λ ÒÔÌ«Íø¿ØÖÆÆ÷£¬
¶¼Äܹ»ÔÚûÓÐÉÏÊö¶Áд³ß´çÏÞÖÆµÄÇé¿öÏÂÕý³£¹¤×÷¡£
¶ÔÓÚÄÇЩ¹ØÐĵ½µ×ÊÇʲôÎÊÌâµÄÈË£¬ ÏÂÃæÊÇʧ°ÜÈçºÎ·¢ÉúµÄ½âÊÍ£¬
ͬʱÕâҲ˵Ã÷ÁËΪʲôÕâÊÇÒ»¸öÎÞ·¨»Ö¸´µÄÎÊÌâ¡£ µäÐÍÇé¿öÏ£¬
NFS »áʹÓÃÒ»¸ö ¿é
Ϊµ¥Î»½øÐвÙ×÷£¬ Æä³ß´çÊÇ
8 K (ËäÈ»Ëü¿ÉÄܻὫ²Ù×÷·Ö³É¸üС³ß´çµÄ·ÖƬ)¡£
ÓÉÓÚ×î´óµÄÒÔÌ«Íø°ü³ß´ç´óÔ¼ÊÇ 1500 ×Ö½Ú£¬
Òò´Ë NFS ¿é
»á·Ö³É¶à¸öÒÔÌ«Íø°ü£¬
ËäÈ»ÔÚ¸ü¸ß²ãµÄ´úÂë¿´À´ËüÈÔÈ»ÊÇÒ»¸öÍêÕûµÄµ¥Ôª£¬
²¢ÔÚ½ÓÊÕ·½ÖØÐÂ×é×°£¬ ×÷Ϊһ¸öÕûÌåÀ´
È·ÈÏ¡£ ¸ßÐÔÄܵŤ×÷Õ¾£¬
¿ÉÒÔ½«¹¹³É NFS µ¥ÔªµÄ°üѸËÙ·¢³ö£¬ Æä½Ú×à»á¿ìµ½±ê×¼ÔÊÐíµÄ×î´óÏÞ¶È¡£
ÔÚÈÝÁ¿½ÏСµÄ¿¨ÉÏ£¬ ºóÀ´µÄ°ü»á³åµôͬһµ¥ÔªÄڵĽÏÔçµÄ°ü£¬
Òò¶øÕû¸öµ¥ÔªÎÞ·¨±»Öؽ¨»òÈ·ÈÏ¡£ Æä½á¹ûÊÇ£¬
¹¤×÷Õ¾½«³¬Ê±²¢ÖØÊÔ£¬ µ«ÈÔÈ»ÊÇÍêÕûµÄ 8 K µ¥Ôª£¬
ÕâÒ»¹ý³Ì½«ÎÞÐÝÖ¹µØÖظ´ÏÂÈ¥¡£
Èç¹û½«µ¥Ôª³ß´çÏÞÖÆÔÚÒÔÌ«Íø°ü³ß´ç֮ϣ¬
ÎÒÃǾÍÄܹ»È·±£Ã¿Ò»¸öÒÔÌ«Íø°ü¶¼Äܹ»±»¶ÀÁ¢µØ½ÓÊÕºÍÈ·ÈÏ£¬
´Ó¶ø±ÜÃâÁËÉÏÃæµÄËÀËøÇéÐΡ£
Òç³öÔÚ¸ßÐÔÄܹ¤×÷Õ¾½«Êý¾Ý¿âͶÏò PC ϵͳʱÈԻᷢÉú£¬
µ«ÔÚ¸üºÃµÄÍø¿¨ÉÏ£¬ Äܹ»±£Ö¤ÕâÀàÒç³ö²»»áÔÚÿһ¸ö NFS
µ¥Ôª
É϶¼·¢Éú¡£ µ±³öÏÖÒç³öʱ£¬
±»Ó°ÏìµÄµ¥Ôª±»ÖØ´«£¬ Òò¶ø´ËʱÓкܴóµÄ»ú»áËü½«±»ÕýÈ·½ÓÊÕ¡¢
ÖØ×飬 ²¢È·ÈÏ¡£
Bill
Swingle
Written by
Eric
Ogren
Enhanced by
Udo
Erdelhoff
ÍøÂçÐÅÏ¢·þÎñ (NIS/YP)
ËüÊÇʲô£¿
NIS
Solaris
HP-UX
AIX
Linux
NetBSD
OpenBSD
NIS£¬
±íÊ¾ÍøÂçÐÅÏ¢·þÎñ (Network Information Services)£¬
×î³õÓÉ Sun Microsystems ¿ª·¢£¬ ÓÃÓÚ &unix;
(×î³õÊÇ &sunos;) ϵͳµÄ¼¯ÖйÜÀí¡£ Ŀǰ£¬
Ëü»ù±¾ÉÏÒѾ³ÉΪÁËÒµ½ç±ê×¼£» ËùÓÐÖ÷Á÷µÄÀà &unix; ϵͳ
(&solaris;, HP-UX, &aix;, Linux, NetBSD, OpenBSD, FreeBSD,
µÈµÈ) ¶¼Ö§³Ö NIS¡£
»ÆÒ³ (yellow pages)NIS
NIS
Ò²¾ÍÊÇÈËÃÇËùÊìÖªµÄ»ÆÒ³(Yellow Pages)£¬ µ«ÓÉÓÚÉ̱êµÄÎÊÌ⣬
Sun ½«Æä¸ÄÃûΪÏÖÔÚµÄÃû×Ö¡£ ¾ÉµÄÊõÓï (ÒÔ¼° yp)£¬
ÈÔÈ»¾³£¿ÉÒÔ¿´µ½£¬ ²¢±»¹ã·ºÊ¹Óá£
NIS
Óò
ÕâÊÇÒ»¸ö»ùÓÚ RPC µÄ¿Í»§»ú/·þÎñÆ÷ϵͳ£¬
ËüÔÊÐíÔÚÒ»¸ö NIS ÓòÖеÄÒ»×é»úÆ÷¹²ÏíһϵÁÐÅäÖÃÎļþ¡£
ÕâÑù£¬ ϵͳ¹ÜÀíÔ±¾Í¿ÉÒÔÅäÖÃÖ»°üº¬×î»ù±¾ÅäÖÃÊý¾ÝµÄ NIS ¿Í»§»úϵͳ£¬
²¢ÔÚµ¥µãÉÏÔö¼Ó¡¢ ɾ³ý»òÐÞ¸ÄÅäÖÃÊý¾Ý¡£
Windows NT
¾¡¹ÜʵÏÖµÄÄÚ²¿Ï¸½Ú½ØÈ»²»Í¬£¬ ÕâºÍ &windowsnt; Óòϵͳ·Ç³£ÀàËÆ£¬
ÒÔÖÁÓÚ¿ÉÒÔ½«Á½ÕߵĻù±¾¹¦ÄÜÏ໥Àà±È¡£
ÄúÓ¦¸ÃÖªµÀµÄÊõÓïºÍ½ø³Ì
ÓÐһϵÁÐÊõÓïºÍÖØÒªµÄÓû§½ø³Ì½«ÔÚÄúÔÚ FreeBSD
ÉÏʵÏÖ NIS ʱÓõ½£¬ ÎÞÂÛÊÇÔÚ´´½¨
NIS ·þÎñÆ÷£¬ »ò×÷Ϊ NIS ¿Í»§»ú£º
rpcbind
portmap
ÊõÓï
˵Ã÷
NIS ÓòÃû
NIS Ö÷·þÎñÆ÷ºÍËùÓÐÆä¿Í»§»ú
(°üÀ¨´Ó·þÎñÆ÷) »áʹÓÃͬһ NIS ÓòÃû¡£
ºÍ &windowsnt; ÓòÃûÀàËÆ£¬ NIS ÓòÃûÓë
DNS Î޹ء£
rpcbind
±ØÐëÔËÐÐÕâ¸ö³ÌÐò£¬ ²ÅÄܹ»ÆôÓÃ
RPC (Ô¶³Ì¹ý³Ìµ÷Ó㬠NIS
Óõ½µÄÒ»ÖÖÍøÂçÐÒé)¡£ Èç¹ûûÓÐÔËÐÐ
rpcbind£¬
ÔòûÓа취ÔËÐÐ NIS ·þÎñÆ÷£¬
»ò×÷Ϊ NIS ¿Í»§»ú¡£
ypbind
°ó¶¨(bind)
NIS ¿Í»§»úµ½ËüµÄ NIS
·þÎñÆ÷ÉÏ¡£ ÕâÑù£¬ Ëü½«´ÓϵͳÖлñÈ¡ NIS ÓòÃû£¬
²¢Ê¹Óà RPC Á¬½Óµ½·þÎñÆ÷ÉÏ¡£
ypbind ÊÇ NIS »·¾³ÖУ¬
¿Í»§»ú-·þÎñÆ÷ͨѶµÄºËÐÄ£» Èç¹û¿Í»§»úÉϵÄ
ypbind ËÀµôµÄ»°£¬ Ëü½«ÎÞ·¨·ÃÎÊ
NIS ·þÎñÆ÷¡£
ypserv
Ö»Ó¦ÔÚ NIS ·þÎñÆ÷ÉÏÔËÐÐËü£» ÕâÊÇ NIS µÄ·þÎñÆ÷½ø³Ì¡£
Èç¹û &man.ypserv.8; ËÀµôµÄ»°£¬
Ôò·þÎñÆ÷½«²»ÔÙ¾ßÓÐÏìÓ¦ NIS ÇëÇóµÄÄÜÁ¦ (´Ëʱ£¬
Èç¹ûÓдӷþÎñÆ÷µÄ»°£¬ Ôò»á½Ó¹Ü²Ù×÷)¡£ ÓÐһЩ NIS
µÄʵÏÖ (µ«²»ÊÇ FreeBSD µÄÕâ¸ö) µÄ¿Í»§»úÉÏ£¬
Èç¹û֮ǰÓùýÒ»¸ö·þÎñÆ÷£¬ ¶øÄÇ̨·þÎñÆ÷ËÀµôµÄ»°£¬
²¢²»³¢ÊÔÖØÐÂÁ¬½Óµ½ÁíÒ»¸ö·þÎñÆ÷¡£ ͨ³££¬
·¢ÉúÕâÖÖÇé¿öʱ£¬ ΨһµÄ°ì·¨¾ÍÊÇÖØÐÂÆô¶¯·þÎñÆ÷½ø³Ì
(»òÕߣ¬ ÉõÖÁÖØÐÂÆô¶¯·þÎñÆ÷) »ò¿Í»§»úÉϵÄ
ypbind ½ø³Ì¡£
rpc.yppasswdd
ÁíÒ»¸öÖ»Ó¦ÔÚ
NIS Ö÷·þÎñÆ÷ÉÏÔËÐеĽø³Ì£» ÕâÊÇÒ»¸ö·þÎñ³ÌÐò£¬
Æä×÷ÓÃÊÇÔÊÐí NIS ¿Í»§»ú¸Ä±äËüÃÇµÄ NIS ¿ÚÁî¡£
Èç¹ûûÓÐÔËÐÐÕâ¸ö·þÎñ£¬ Óû§½«±ØÐëµÇ¼µ½ NIS
Ö÷·þÎñÆ÷ÉÏ£¬ ²¢ÔÚÄÇÀïÐ޸ĿÚÁî¡£
ËüÊÇÈçºÎ¹¤×÷µÄ£¿
ÔÚ NIS »·¾³ÖУ¬ ÓÐÈýÖÖÀàÐ͵ÄÖ÷»ú£º
Ö÷·þÎñÆ÷£¬ ´Ó·þÎñÆ÷£¬ ÒÔ¼°¿Í»§»ú¡£
·þÎñÆ÷µÄ×÷ÓÃÊdz䵱Ö÷»úÅäÖÃÐÅÏ¢µÄÖÐÑëÊý¾Ý¿â¡£
Ö÷·þÎñÆ÷Éϱ£´æ×ÅÕâЩÐÅÏ¢µÄȨÍþ¸±±¾£¬
¶ø´Ó·þÎñÆ÷ÔòÊDZ£´æÕâЩÐÅÏ¢µÄÈßÓั±¾¡£
¿Í»§»úÒÀÀµÓÚ·þÎñÆ÷ÏòËüÃÇÌṩÕâЩÐÅÏ¢¡£
Ðí¶àÎļþµÄÐÅÏ¢¿ÉÒÔͨ¹ýÕâÖÖ·½Ê½À´¹²Ïí¡£
ͨ³£Çé¿öÏ£¬ master.passwd¡¢
group£¬ ÒÔ¼° hosts
ÊÇͨ¹ý NIS ·Ö·¢µÄ¡£ ÎÞÂÛʲôʱºò£¬
Èç¹û¿Í»§»úÉϵÄij¸ö½ø³ÌÇëÇóÕâЩ±¾Ó¦ÔÚ±¾µØµÄÎļþÖеÄ×ÊÁϵÄʱºò£¬
Ëü¶¼»áÏòËù°ó¶¨µÄ NIS ·þÎñÆ÷·¢³öÇëÇó£¬ ¶ø²»Ê¹Óñ¾µØµÄ°æ±¾¡£
»úÆ÷ÀàÐÍ
-
- NIS
- Ö÷·þÎñÆ÷
-
- һ̨ NIS Ö÷·þÎñÆ÷¡£
+ һ̨ NIS Ö÷·þÎñÆ÷¡£NISÖ÷·þÎñÆ÷
Õą̂·þÎñÆ÷£¬ ºÍ &windowsnt; Óò¿ØÖÆÆ÷ÀàËÆ£¬
»áά»¤ËùÓÐ NIS ¿Í»§»úËùʹÓõÄÎļþ¡£ passwd£¬
group£¬ ÒÔ¼°Ðí¶àÆäËû NIS
¿Í»§»úËùʹÓõÄÎļþ£¬ ¶¼±»´æ·Åµ½Ö÷·þÎñÆ÷ÉÏ¡£
¿ÉÒÔ½«Ò»Ì¨ NIS Ö÷·þÎñÆ÷ÓÃÔÚ¶à¸ö NIS ÓòÖС£
È»¶ø£¬ ±¾Êé²»´òËã¶ÔÕâÖÖÅäÖýøÐнéÉÜ£¬
ÒòΪÕâÖÖÅäÖ㬠ͨ³£Ö»³öÏÖÔÚС¹æÄ£µÄ NIS »·¾³ÖС£
-
- NIS
- ´Ó·þÎñÆ÷
-
-
- NIS ´Ó·þÎñÆ÷¡£ ÕâÒ»¸ÅÄ
+ NIS ´Ó·þÎñÆ÷NIS´Ó·þÎñÆ÷¡£ ÕâÒ»¸ÅÄ
Óë &windowsnt; µÄ±¸·ÝÓò¿ØÖÆÆ÷ÀàËÆ¡£ NIS ´Ó·þÎñÆ÷£¬
ÓÃÓÚά»¤ NIS Ö÷·þÎñÆ÷µÄÊý¾ÝÎļþ¸±±¾¡£
NIS ´Ó·þÎñÆ÷ÌṩÁËÒ»ÖÖÈßÓ࣬
ÕâÔÚÐí¶àÖØÒªµÄ»·¾³ÖÐÊDZØÐèµÄ¡£ ´ËÍ⣬
ËüÒ²°ïÖú¼õÇáÁËÖ÷·þÎñÆ÷µÄ¸ººÉ£º NIS
¿Í»§»ú×ÜÊǹҽӵ½×îÏÈÏìÓ¦ËüÃÇµÄ NIS ·þÎñÆ÷ÉÏ£¬
¶øÕâÒ²°üÀ¨À´×Ô´Ó·þÎñÆ÷µÄÏìÓ¦¡£
-
- NIS
- ¿Í»§»ú
-
-
- NIS ¿Í»§»ú¡£ NIS ¿Í»§»ú£¬
+ NIS ¿Í»§»ú¡£NIS¿Í»§»ú NIS ¿Í»§»ú£¬
ºÍ¶àÊý &windowsnt; ¹¤×÷Õ¾ÀàËÆ£¬ ͨ¹ý
NIS ·þÎñÆ÷ (»ò¶ÔÓÚ &windowsnt; ¹¤×÷Õ¾£¬ ÔòÊÇ
&windowsnt; Óò¿ØÖÆÆ÷) À´Íê³ÉµÇ¼ʱµÄÉí·ÝÑéÖ¤¹ý³Ì¡£
ʹÓà NIS/YP
ÕâÒ»½Ú½«Í¨¹ýʵÀý½éÉÜÈçºÎÅäÖà NIS »·¾³¡£
¹æ»®
¼Ù¶¨ÄúÕýÔÚ¹ÜÀí´óѧÖеÄÒ»¸öСÐÍʵÑéÊÒ¡£ ÔÚÕâ¸öʵÑéÊÒÖУ¬
ÓÐ 15 ̨ FreeBSD »úÆ÷£¬ ĿǰÉÐûÓм¯ÖеĹÜÀíµã£»
ÿһ̨»úÆ÷ÉÏÓÐ×Ô¼ºµÄ
/etc/passwd ºÍ
/etc/master.passwd¡£
ÕâЩÎļþͨ¹ýÈ˹¤¸ÉÔ¤µÄ·½·¨À´±£³ÖÓëÆäËû»úÆ÷Éϰ汾µÄͬ²½£»
Ŀǰ£¬ Èç¹ûÄúÔÚʵÑéÊÒÖÐÔö¼ÓÒ»¸öÓû§£¬ ½«²»µÃ²»ÔÚËùÓÐ 15
̨»úÆ÷ÉÏÊÖ¹¤Ö´ÐÐ adduser ÃüÁî¡£
ÎãÓ¹ÖÃÒÉ£¬ ÕâÒ»ÏÖ×´±ØÐë¸Ä±ä£¬
Òò´ËÄú¾ö¶¨½«Õû¸öʵÑéÊÒתΪʹÓà NIS£¬
²¢Ê¹ÓÃÁ½Ì¨»úÆ÷×÷Ϊ·þÎñÆ÷¡£
Òò´Ë£¬ ʵÑéÊÒµÄÅäÖÃÓ¦¸ÃÊÇÕâÑùµÄ£º
»úÆ÷Ãû
IP µØÖ·
»úÆ÷µÄ½ÇÉ«
ellington
10.0.0.2
NIS Ö÷·þÎñÆ÷
coltrane
10.0.0.3
NIS ´Ó·þÎñÆ÷
basie
10.0.0.4
½ÌÔ±¹¤×÷Õ¾
bird
10.0.0.5
¿Í»§»ú
cli[1-11]
10.0.0.[6-17]
ÆäËû¿Í»§»ú
Èç¹ûÄúÊÇÊ×´ÎÅäÖà NIS£¬ ×Ðϸ˼¿¼ÈçºÎ½øÐй滮¾ÍÊ®·ÖÖØÒª¡£
ÎÞÂÛÄúµÄÍøÂçµÄ´óСÈçºÎ£¬ ¶¼±ØÐë½øÐм¸¸ö¾ö²ß¡£
Ñ¡Ôñ NIS ÓòÃû
NIS
ÓòÃû
Õâ¿ÉÄܲ»ÊÇÄú¹ýȥʹÓÃµÄ ÓòÃû(domainname)
¡£
ËüµÄ¹æ·¶µÄ½Ð·¨£¬ Ó¦¸ÃÊÇ
NIS ÓòÃû
¡£ µ±¿Í»§»ú¹ã²¥¶Ô´ËÐÅÏ¢µÄÇëÇóʱ£¬
Ëü»á½« NIS ÓòµÄÃû×Ö×÷ΪÇëÇóµÄÒ»²¿·Ö·¢³ö¡£ ÕâÑù£¬
Í³Ò»ÍøÂçÉϵĶà¸ö·þÎñÆ÷£¬ ¾ÍÄܹ»ÖªµÀËÓ¦¸Ã»ØÓ¦ÇëÇó¡£
Äú¿ÉÒÔ°Ñ NIS ÓòÃûÏëÏó³ÉÒÔijÖÖ·½Ê½Ïà¹ØµÄÒ»×éÖ÷»úµÄÃû×Ö¡£
һЩ»ú¹¹»áÑ¡ÔñʹÓÃËüÃÇµÄ Internet
ÓòÃûÀ´×÷Ϊ NIS ÓòÃû¡£ ²¢²»ÍƼöÕâÑù×ö£¬ ÒòΪÔÚµ÷ÊÔÍøÂçÎÊÌâʱ£¬
Õâ¿ÉÄܻᵼÖ²»±ØÒªµÄÀ§ÈÅ¡£ NIS ÓòÃûÓ¦¸ÃÊÇÔÚÄúÍøÂçÉÏΨһµÄ£¬
²¢ÇÒÓÐÖúÓÚÁ˽âËüËùÃèÊöµÄµ½µ×ÊÇÄÄÒ»×é»úÆ÷¡£ ÀýÈç¶ÔÓÚ Acme
¹«Ë¾µÄÃÀ¹¤²¿ÃÅ£¬ ¿ÉÒÔ¿¼ÂÇʹÓÃ
acme-art
ÕâÑùµÄ NIS ÓòÃû¡£
ÔÚÕâ¸öÀý×ÓÖУ¬ ÄúʹÓõÄÓòÃûÊÇ
test-domain¡£
SunOS
È»¶ø£¬ ijЩ²Ù×÷ϵͳ (×îÖøÃûµÄÊÇ &sunos;)
»áʹÓÃÆä NIS ÓòÃû×÷Ϊ Internet ÓòÃû¡£
Èç¹ûÄúµÄÍøÂçÉÏ´æÔÚ°üº¬ÕâÀàÏÞÖÆµÄ»úÆ÷£¬ ¾Í
±ØÐë ʹÓà Internet ÓòÃûÀ´×÷ΪÄúµÄ NIS ÓòÃû¡£
·þÎñÆ÷µÄÎïÀíÒªÇó
Ñ¡Ôñ NIS ·þÎñÆ÷ʱ£¬ ÐèҪʱ¿ÌÀμÇһЩ¶«Î÷¡£
NIS µÄÒ»¸ö²»Ì«ºÃµÄÌØÐÔ¾ÍÊÇÆä¿Í»§»ú¶ÔÓÚ·þÎñÆ÷µÄÒÀÀµ³Ì¶È¡£
Èç¹û¿Í»§»úÎÞ·¨ÓëÆä NIS ÓòµÄ·þÎñÆ÷ÁªÏµ£¬
ÔòÕą̂»úÆ÷ͨ³£»áÏÝÓÚ²»¿ÉÓõÄ״̬¡£ ȱÉÙÓû§ºÍ×éÐÅÏ¢£¬
»áʹ¾ø´ó¶àÊýϵͳ½øÈë¶ÌÔݵͳ½á״̬¡£ »ùÓÚÕâÑùµÄ¿¼ÂÇ£¬
ÄúÐèҪѡÔñһ̨²»¾³£ÖØÐÂÆô¶¯£¬ »òÓÃÓÚ¿ª·¢µÄ»úÆ÷À´³Ðµ£ÆäÔðÈΡ£
Èç¹ûÄúµÄÍøÂ粻̫棬 Ò²¿ÉÒÔʹÓÃÔËÐÐ×ÅÆäËû·þÎñµÄ»úÆ÷À´°²·Å NIS
·þÎñ£¬ Ö»ÊÇÐèҪעÒ⣬ Ò»µ© NIS ·þÎñÆ÷²»¿ÉÓ㬠Ôò
ËùÓÐ µÄ NIS ¿Í»§»ú¶¼»áÊܵ½Ó°Ïì¡£
NIS ·þÎñÆ÷
ËùÓÐµÄ NIS ÐÅÏ¢µÄÕý¹æ°æ±¾£¬
¶¼±»±£´æÔÚһ̨µ¥¶ÀµÄ³Æ×÷ NIS Ö÷·þÎñÆ÷µÄ»úÆ÷ÉÏ¡£
ÓÃÓÚ±£´æÕâЩÐÅÏ¢µÄÊý¾Ý¿â£¬ ³ÆÎª NIS Ó³Éä(map)¡£
ÔÚ FreeBSD ÖУ¬ ÕâЩӳÉä±»±£´æÔÚ
/var/yp/[domainname] À ÆäÖÐ
[domainname] ÊÇÌṩ·þÎñµÄ NIS
ÓòµÄÃû×Ö¡£ һ̨ NIS ·þÎñÆ÷£¬ ¿ÉÒÔͬʱ֧³Ö¶à¸öÓò£¬
Òò´Ë¿ÉÒÔ½¨Á¢ºÜ¶àÕâÑùµÄĿ¼£¬ ËùÖ§³ÅÒ»¸öÓò¶ÔÓ¦Ò»¸ö¡£
ÿһ¸öÓò¶¼»áÓÐÒ»×é¶ÀÁ¢µÄÓ³Éä¡£
NIS Ö÷ºÍ´Ó·þÎñÆ÷£¬ ͨ¹ý ypserv
·þÎñ³ÌÐòÀ´´¦ÀíËùÓÐµÄ NIS ÇëÇó¡£
ypserv ÓÐÔðÈνÓÊÕÀ´×Ô NIS ¿Í»§»úµÄÇëÇó£¬
·ÒëÇëÇóµÄÓò£¬ ²¢½«Ãû×ÖÓ³ÉäΪÏà¹ØµÄÊý¾Ý¿âÎļþµÄ·¾¶£¬
È»ºó½«À´×ÔÊý¾Ý¿âµÄÊý¾Ý´«»Ø¿Í»§»ú¡£
ÅäÖà NIS Ö÷·þÎñÆ÷
NIS
·þÎñÆ÷ÅäÖÃ
ÅäÖÃÖ÷ NIS ·þÎñÆ÷Ïà¶Ô¶øÑÔÊ®·ÖµÄ¼òµ¥£¬
¶øÆä¾ßÌå²½ÖèÔòÈ¡¾öÓÚÄúµÄÐèÒª¡£ FreeBSD
ÌṩÁËÒ»²½µ½Î»µÄ NIS Ö§³Ö¡£ ÄúÐèÒª×öµÄÈ«²¿ÊÂÇ飬 Ö»ÊÇÔÚ
/etc/rc.conf ÖмÓÈëһЩÅäÖã¬
ÆäËû¹¤×÷»áÓÉ FreeBSD Íê³É¡£
nisdomainname="test-domain"
ÕâÒ»Ðн«ÔÚÍøÂçÆô¶¯ (ÀýÈçÖØÐÂÆô¶¯) ʱ£¬ °Ñ NIS ÓòÃûÅäÖÃΪ
test-domain¡£
nis_server_enable="YES"
Õ⽫ҪÇó FreeBSD ÔÚÍøÂç×ÓϵͳÆô¶¯Ö®ºóÁ¢¼´Æô¶¯
NIS ·þÎñ½ø³Ì¡£
nis_yppasswdd_enable="YES"
Õ⽫ÆôÓà rpc.yppasswdd
·þÎñ³ÌÐò£¬ ÈçÇ°ÃæÌáµ½µÄ£¬
ËüÔÊÐíÓû§ÔÚ¿Í»§»úÉÏÐÞ¸Ä×Ô¼ºµÄ NIS ¿ÚÁî¡£
Ëæ NIS ÅäÖõIJ»Í¬£¬ ¿ÉÄÜ»¹ÐèÒªÔö¼ÓÆäËûһЩÏîÄ¿¡£ Çë²Î¼û ¹ØÓÚ NIS ·þÎñÆ÷ͬʱ³äµ± NIS
¿Í»§»ú ÕâÒ»½Ú£¬ ÒÔÁË½â½øÒ»²½µÄÇé¿ö¡£
ÉèÖúÃÇ°ÃæÕâЩÅäÖÃÖ®ºó£¬ ÐèÒªÒÔ³¬¼¶Óû§Éí·ÝÔËÐÐ
/etc/netstart ÃüÁî¡£ Ëü»á¸ù¾Ý
/etc/rc.conf µÄÉèÖÃÀ´ÅäÖÃϵͳÖÐµÄÆäËû²¿·Ö¡£
×îºó£¬ ÔÚ³õʼ»¯ NIS Ó³Éä֮ǰ£¬ »¹ÐèÒªÊÖ¹¤Æô¶¯
ypserv ·þÎñ³ÌÐò£º
&prompt.root; /etc/rc.d/ypserv start
³õʼ»¯ NIS Ó³Éä
NIS
Ó³Éä
NIS Ó³Éä ÊÇһЩÊý¾Ý¿âÎļþ£¬
ËüÃÇλÓÚ /var/yp Ŀ¼ÖС£
ÕâЩÎļþ»ù±¾É϶¼ÊǸù¾Ý NIS Ö÷·þÎñÆ÷µÄ /etc
Ŀ¼×Ô¶¯Éú³ÉµÄ£¬ ΨһµÄÀýÍâÊÇ£º
/etc/master.passwd Îļþ¡£ Ò»°ãÀ´Ëµ£¬
Äú»áÓзdz£³ä·ÖµÄÀíÓɲ»½« root
ÒÔ¼°ÆäËû¹ÜÀíÕʺŵĿÚÁî·¢µ½ËùÓÐ NIS ÓòÉϵķþÎñÆ÷ÉÏ¡£
Òò´Ë£¬ ÔÚ¿ªÊ¼³õʼ»¯ NIS Ó³Éä֮ǰ£¬ ÎÒÃÇÓ¦¸Ã£º
&prompt.root; cp /etc/master.passwd /var/yp/master.passwd
&prompt.root; cd /var/yp
&prompt.root; vi master.passwd
ÕâÀ ɾ³ýµôºÍϵͳÓйصÄÕʺŶÔÓ¦µÄÏî (bin¡¢
tty¡¢ kmem¡¢
games£¬ µÈµÈ)£¬
ÒÔ¼°ÆäËû²»Ï£Íû±»À©É¢µ½ NIS ¿Í»§»úµÄÕʺÅ
(ÀýÈç root ºÍÈÎºÎÆäËû UID 0
(³¬¼¶Óû§) µÄÕʺÅ)¡£
È·ÈÏ
/var/yp/master.passwd Õâ¸öÎļþÊÇͬ×éÓû§£¬
ÒÔ¼°ÆäËûÓû§²»¿É¶ÁµÄ (ģʽ 600)£¡ Èç¹ûÐèÒªµÄ»°£¬ ÓÃ
chmod ÃüÁîÀ´¸ÄËü¡£
Tru64 UNIX
Íê³ÉÕâЩ¹¤×÷Ö®ºó£¬ ¾Í¿ÉÒÔ³õʼ»¯
NIS Ó³ÉäÁË£¡ FreeBSD ÌṩÁËÒ»¸öÃûΪ
ypinit µÄ½Å±¾À´°ïÖúÄúÍê³ÉÕâÏ×÷ (ÏêϸÐÅÏ¢£¬
Çë¼ûÆäÁª»úÊÖ²á)¡£ Çë×¢Ò⣬ Õâ¸ö½Å±¾ÔÚ¾ø´ó¶àÊý &unix;
²Ù×÷ϵͳÉ϶¼¿ÉÒÔÕÒµ½£¬ µ«²¢²»ÊÇËùÓвÙ×÷ϵͳµÄ¶¼Ìṩ¡£
ÔÚ Digital UNIX/Compaq Tru64 UNIX ÉÏËüµÄÃû×ÖÊÇ
ypsetup¡£ ÓÉÓÚÎÒÃÇÕýÔÚÉú³ÉµÄÊÇ NIS
Ö÷·þÎñÆ÷µÄÓ³É䣬 Òò´ËÓ¦¸ÃʹÓà ypinit µÄ
²ÎÊý¡£ Èç¹ûÒѾÍê³ÉÁËÉÏÊö²½Ö裬
ÒªÉú³É NIS Ó³É䣬 Ö»ÐèÖ´ÐУº
ellington&prompt.root; ypinit -m test-domain
Server Type: MASTER Domain: test-domain
Creating an YP server will require that you answer a few questions.
Questions will all be asked at the beginning of the procedure.
Do you want this procedure to quit on non-fatal errors? [y/n: n] n
Ok, please remember to go back and redo manually whatever fails.
If you don't, something might not work.
At this point, we have to construct a list of this domains YP servers.
rod.darktech.org is already known as master server.
Please continue to add any slave servers, one per line. When you are
done with the list, type a <control D>.
master server : ellington
next host to add: coltrane
next host to add: ^D
The current list of NIS servers looks like this:
ellington
coltrane
Is this correct? [y/n: y] y
[..output from map generation..]
NIS Map update completed.
ellington has been setup as an YP master server without any errors.
ypinit Ó¦¸Ã»á¸ù¾Ý
/var/yp/Makefile.dist À´´´½¨
/var/yp/Makefile Îļþ¡£
´´½¨ÍêÖ®ºó£¬ Õâ¸öÎļþ»á¼Ù¶¨ÄúÕýÔÚ²Ù×÷Ö»ÓÐ FreeBSD
»úÆ÷µÄµ¥·þÎñÆ÷ NIS »·¾³¡£ ÓÉÓÚ test-domain
»¹ÓÐÒ»¸ö´Ó·þÎñÆ÷£¬ Äú±ØÐë±à¼
/var/yp/Makefile£º
ellington&prompt.root; vi /var/yp/Makefile
Ó¦¸ÃÄܹ»¿´µ½ÕâÑùÒ»ÐУ¬ ÆäÄÚÈÝÊÇ
NOPUSH = "True"
(Èç¹û»¹Ã»ÓÐ×¢Ê͵ôµÄ»°)¡£
ÅäÖà NIS ´Ó·þÎñÆ÷
NIS
´Ó·þÎñÆ÷
ÅäÖà NIS ´Ó·þÎñÆ÷£¬ ÉõÖÁ±ÈÅäÖÃÖ÷·þÎñÆ÷»¹Òª¼òµ¥¡£
µÇ¼µ½´Ó·þÎñÆ÷ÉÏ£¬ ²¢°´ÕÕÇ°ÃæµÄ·½·¨£¬
±à¼ /etc/rc.conf Îļþ¡£ ΨһµÄÇø±ðÊÇ£¬
ÔÚÔËÐÐ ypinit ʱÐèҪʹÓÃ
²ÎÊý¡£
ÕâÀïµÄ Ñ¡Ï ͬʱҪÇóÌṩ NIS
Ö÷·þÎñÆ÷µÄÃû×Ö£¬ Òò´ËÎÒÃǵÄÃüÁîÐÐÓ¦¸ÃÊÇ£º
coltrane&prompt.root; ypinit -s ellington test-domain
Server Type: SLAVE Domain: test-domain Master: ellington
Creating an YP server will require that you answer a few questions.
Questions will all be asked at the beginning of the procedure.
Do you want this procedure to quit on non-fatal errors? [y/n: n] n
Ok, please remember to go back and redo manually whatever fails.
If you don't, something might not work.
There will be no further questions. The remainder of the procedure
should take a few minutes, to copy the databases from ellington.
Transferring netgroup...
ypxfr: Exiting: Map successfully transferred
Transferring netgroup.byuser...
ypxfr: Exiting: Map successfully transferred
Transferring netgroup.byhost...
ypxfr: Exiting: Map successfully transferred
Transferring master.passwd.byuid...
ypxfr: Exiting: Map successfully transferred
Transferring passwd.byuid...
ypxfr: Exiting: Map successfully transferred
Transferring passwd.byname...
ypxfr: Exiting: Map successfully transferred
Transferring group.bygid...
ypxfr: Exiting: Map successfully transferred
Transferring group.byname...
ypxfr: Exiting: Map successfully transferred
Transferring services.byname...
ypxfr: Exiting: Map successfully transferred
Transferring rpc.bynumber...
ypxfr: Exiting: Map successfully transferred
Transferring rpc.byname...
ypxfr: Exiting: Map successfully transferred
Transferring protocols.byname...
ypxfr: Exiting: Map successfully transferred
Transferring master.passwd.byname...
ypxfr: Exiting: Map successfully transferred
Transferring networks.byname...
ypxfr: Exiting: Map successfully transferred
Transferring networks.byaddr...
ypxfr: Exiting: Map successfully transferred
Transferring netid.byname...
ypxfr: Exiting: Map successfully transferred
Transferring hosts.byaddr...
ypxfr: Exiting: Map successfully transferred
Transferring protocols.bynumber...
ypxfr: Exiting: Map successfully transferred
Transferring ypservers...
ypxfr: Exiting: Map successfully transferred
Transferring hosts.byname...
ypxfr: Exiting: Map successfully transferred
coltrane has been setup as an YP slave server without any errors.
Don't forget to update map ypservers on ellington.
ÏÖÔÚÓ¦¸Ã»áÓÐÒ»¸ö½Ð×ö
/var/yp/test-domain µÄĿ¼¡£
ÔÚÕâ¸öĿ¼ÖУ¬ Ó¦¸Ã±£´æ NIS Ö÷·þÎñÆ÷ÉϵÄÓ³ÉäµÄ¸±±¾¡£
½ÓÏÂÀ´ÐèҪȷ¶¨ÕâЩÎļþ¶¼¼°Ê±µØÍ¬²½¸üÐÂÁË¡£ ÔÚ´Ó·þÎñÆ÷ÉÏ£¬ ÏÂÃæµÄ
/etc/crontab Ï°ïÖúÄúÈ·±£ÕâÒ»µã£º
20 * * * * root /usr/libexec/ypxfr passwd.byname
21 * * * * root /usr/libexec/ypxfr passwd.byuid
ÕâÁ½Ðн«Ç¿ÖÆ´Ó·þÎñÆ÷½«Ó³ÉäÓëÖ÷·þÎñÆ÷ͬ²½¡£
ÓÉÓÚÖ÷·þÎñÆ÷»á³¢ÊÔÈ·±£ËùÓÐÆä NIS Ó³ÉäµÄ±ä¶¯¶¼Öª»á´Ó·þÎñÆ÷£¬
Òò´ËÕâЩÏî²¢²»ÊǾø¶Ô±ØÐèµÄ¡£ ²»¹ý£¬
ÓÉÓÚ±£³ÖÆäËû¿Í»§¶ËµÄ¿ÚÁîÐÅÏ¢ÕýÈ·ÐÔÊ®·ÖÖØÒª£¬ ¶øÕâÔòÒÀÀµÓÚ´Ó·þÎñÆ÷£¬
Ç¿ÁÒÍÆ¼öÃ÷È·Ö¸¶¨ÈÃϵͳʱ³£Ç¿ÖƸüпÚÁîÓ³Éä¡£ ¶ÔÓÚ·±Ã¦µÄÍøÂç¶øÑÔ£¬
ÕâÒ»µãÓÈÆäÖØÒª£¬ ÒòΪÓÐʱ¿ÉÄܳöÏÖÓ³Éä¸üв»ÍêÈ«µÄÇé¿ö¡£
ÏÖÔÚ£¬ ÔÚ´Ó·þÎñÆ÷ÉÏÖ´ÐÐ /etc/netstart£¬
¾Í¿ÉÒÔÆô¶¯ NIS ·þÎñÁË¡£
NIS ¿Í»§»ú
NIS ¿Í»§»ú»áͨ¹ý
ypbind ·þÎñ³ÌÐòÀ´ÓëÌØ¶¨µÄ NIS
·þÎñÆ÷½¨Á¢Ò»ÖÖ³Æ×÷°ó¶¨µÄÁªÏµ¡£
ypbind »á¼ì²éϵͳµÄĬÈÏÓò
(ÕâÊÇͨ¹ý domainname ÃüÁîÀ´ÉèÖõÄ)£¬
²¢¿ªÊ¼ÔÚ±¾µØÍøÂçÉϹ㲥 RPC ÇëÇó¡£ ÕâЩÇëÇó»áÖ¸¶¨
ypbind ³¢Ê԰󶨵ÄÓòÃû¡£
Èç¹ûÒѾÅäÖÃÁË·þÎñÆ÷£¬ ²¢ÇÒÕâЩ·þÎñÆ÷½Óµ½Á˹㲥£¬ Ëü½«»ØÓ¦
ypbind£¬ ºóÕßÔò¼Ç¼·þÎñÆ÷µÄµØÖ·¡£
Èç¹ûÓжà¸ö¿ÉÓõķþÎñÆ÷ (ÀýÈçÒ»¸öÖ÷·þÎñÆ÷£¬ ¼ÓÉ϶à¸ö´Ó·þÎñÆ÷)£¬
ypbind ½«Ê¹ÓõÚÒ»¸öÏìÓ¦µÄµØÖ·¡£
´ÓÕâһʱ¿Ì¿ªÊ¼£¬ ¿Í»§»ú»á°ÑËùÓÐµÄ NIS ÇëÇóÖ±½Ó·¢¸øÄǸö·þÎñÆ÷¡£
ypbind ż¶û»á ping
·þÎñÆ÷ÒÔÈ·ÈÏÆäÈÔÈ»ÔÚÕý³£ÔËÐС£ Èç¹ûÔÚºÏÀíµÄʱ¼äÄÚûÓеõ½ÏìÓ¦£¬ Ôò
ypbind »á°ÑÓò±ê¼ÇΪδ°ó¶¨£¬ ²¢Ôٴη¢Æð¹ã²¥£¬
ÒÔÆÚÕÒµ½Áíһ̨·þÎñÆ÷¡£
ÉèÖÃ NIS ¿Í»§»ú
NIS
¿Í»§»úÅäÖÃ
ÅäÖÃһ̨ FreeBSD »úÆ÷×÷Ϊ NIS ¿Í»§»úÊǷdz£¼òµ¥µÄ¡£
±à¼ /etc/rc.conf Îļþ£¬
²¢ÔÚÆäÖмÓÉÏÏÂÃæ¼¸ÐУ¬ ÒÔÉèÖà NIS ÓòÃû£¬
²¢ÔÚÍøÂçÆô¶¯Ê±Æô¶¯ ypbind£º
nisdomainname="test-domain"
nis_client_enable="YES"
Òª´Ó NIS ·þÎñÆ÷µ¼ÈëËùÓеĿÚÁîÏ
ÐèÒª´ÓÄúµÄ
/etc/master.passwd ÎļþÖÐɾ³ýËùÓÐÓû§£¬
²¢Ê¹ÓÃ
vipw ÔÚÕâ¸öÎļþµÄ×îºóÒ»ÐмÓÈ룺
+:::::::::
ÕâÒ»Ðн«Èà NFS ·þÎñÆ÷µÄ¿ÚÁîÓ³ÉäÖеÄÕʺÅÄܹ»µÇ¼¡£
Ò²ÓкܶàÐÞ¸ÄÕâÒ»ÐÐÀ´ÅäÖà NIS ¿Í»§»úµÄ°ì·¨¡£
Çë²Î¼ûÉÔºóµÄ netgroups
С½Ú ÒÔÁË½â½øÒ»²½µÄÇé¿ö¡£
ÒªÁ˽â¸ü¶àÐÅÏ¢£¬ ¿ÉÒÔ²ÎÔÄ O'Reilly µÄ
Managing NFS and NIS Õâ±¾Êé¡£
ÐèÒªÖÁÉÙ±£ÁôÒ»¸ö±¾µØÕʺŠ(Ò²¾ÍÊDz»Í¨¹ý NIS µ¼Èë) ÔÚÄúµÄ
/etc/master.passwd ÎļþÖУ¬
¶øÕâ¸öÕʺÅÓ¦¸ÃÊÇ
wheel ×éµÄ³ÉÔ±¡£ Èç¹û NIS ·¢Éú²»²â£¬
Õâ¸öÕʺſÉÒÔÓÃÀ´Ô¶³ÌµÇ¼£¬
³ÉΪ root£¬ ²¢ÐÞÕýÎÊÌâ¡£
Òª´Ó NIS ·þÎñÆ÷Éϵ¼Èë×éÐÅÏ¢£¬ ÐèÒªÔÚ
/etc/group Îļþĩβ¼ÓÈ룺
+:*::
ÏëÒªÁ¢¼´Æô¶¯ NIS ¿Í»§¶Ë£¬ ÐèÒªÒÔ³¬¼¶Óû§Éí·ÝÔËÐÐÖ´ÐÐÏÂÁÐÃüÁ
&prompt.root; /etc/netstart
&prompt.root; /etc/rc.d/ypbind start
Íê³ÉÕâЩ²½ÖèÖ®ºó£¬ ¾ÍÓ¦¸Ã¿ÉÒÔͨ¹ýÔËÐÐ
ypcat passwd À´¿´µ½ NIS ·þÎñÆ÷µÄ¿ÚÁîÓ³ÉäÁË¡£
NIS µÄ°²È«ÐÔ
»ù±¾ÉÏ£¬ ÈκÎÔ¶³ÌÓû§¶¼¿ÉÒÔ·¢ÆðÒ»¸ö RPC µ½
&man.ypserv.8; ²¢»ñµÃÄúµÄ NIS Ó³ÉäµÄÄÚÈÝ£¬
Èç¹ûÔ¶³ÌÓû§Á˽âÄúµÄÓòÃûµÄ»°¡£
Òª±ÜÃâÕâÀàδ¾ÊÚȨµÄ·ÃÎÊ£¬ &man.ypserv.8;
Ö§³ÖÒ»¸ö³ÆÎª securenets
µÄÌØÐÔ£¬
ÓÃÒÔ½«·ÃÎÊÏÞÖÆÔÚÒ»×éÌØ¶¨µÄ»úÆ÷ÉÏ¡£ ÔÚÆô¶¯¹ý³ÌÖУ¬
&man.ypserv.8; »á³¢ÊÔ´Ó
/var/yp/securenets
ÖмÓÔØ securenet ÐÅÏ¢¡£
Õâ¸ö·¾¶Ëæ
²ÎÊý¸Ä±ä¡£ Õâ¸öÎļþ°üº¬ÁËһЩÏ
ÿһÏîÖаüº¬ÁËÒ»¸öÍøÂç±êʶºÍ×ÓÍøÑÚÂ룬 ÖмäÓÿոñ·Ö¿ª¡£
ÒÔ #
¿ªÍ·µÄÐлᱻÈÏΪÊÇ×¢ÊÍ¡£
ʾ·¶µÄ securenets ÎļþÈçÏÂËùʾ£º
# allow connections from local host -- mandatory
127.0.0.1 255.255.255.255
# allow connections from any host
# on the 192.168.128.0 network
192.168.128.0 255.255.255.0
# allow connections from any host
# between 10.0.0.0 to 10.0.15.255
# this includes the machines in the testlab
10.0.0.0 255.255.240.0
Èç¹û &man.ypserv.8; ½Óµ½ÁËÀ´×ÔÆ¥ÅäÉÏÊöÈÎÒ»¹æÔòµÄµØÖ·µÄÇëÇó£¬
ÔòËü»áÕý³£´¦ÀíÇëÇó¡£ ·´Ö®£¬ ÔòÇëÇ󽫱»ºöÂÔ£¬ ²¢¼Ç¼һÌõ¾¯¸æÐÅÏ¢¡£ Èç¹û
/var/yp/securenets Îļþ²»´æÔÚ£¬ Ôò
ypserv »áÔÊÐíÀ´×ÔÈÎÒâÖ÷»úµÄÇëÇó¡£
ypserv ³ÌÐòÒ²Ö§³Ö
Wietse Venema µÄ TCP Wrapper Èí¼þ°ü¡£
ÕâÑù£¬ ¹ÜÀíÔ±¾ÍÄܹ»Ê¹ÓÃ
TCP Wrapper µÄÅäÖÃÎļþÀ´´úÌæ
/var/yp/securenets Íê³É·ÃÎÊ¿ØÖÆ¡£
¾¡¹ÜÕâÁ½ÖÖ·ÃÎÊ¿ØÖÆ»úÖÆ¶¼Äܹ»ÌṩijÖ̶ֳȵݲȫ£¬
µ«ÊÇ£¬ ºÍÌØÈ¨¶Ë¿Ú¼ì²éÒ»Ñù£¬
ËüÃÇÎÞ·¨±ÜÃâ IP αÔì
¹¥»÷¡£ ÄúµÄ·À»ðǽӦ¸Ã×èÖ¹ËùÓÐÓë
NIS ÓйصķÃÎÊ¡£
ʹÓà /var/yp/securenets µÄ·þÎñÆ÷£¬
¿ÉÄÜ»áÎÞ·¨ÎªÄ³Ð©Ê¹ÓÃ³Â¾ÉµÄ TCP/IP ʵÏÖµÄ NIS ¿Í»§»ú·þÎñ¡£
ÕâЩʵÏÖ¿ÉÄÜ»áÔڹ㲥ʱ£¬ ½«Ö÷»úλ¶¼ÉèÖÃΪ 0£¬
»òÔÚ¼ÆËã¹ã²¥µØÖ·Ê±ºöÂÔ×ÓÍøÑÚÂë¡£
¾¡¹ÜÕâЩÎÊÌâ¿ÉÒÔͨ¹ýÐ޸Ŀͻ§»úµÄÅäÖÃÀ´½â¾ö£¬
ÆäËûһЩÎÊÌâÒ²¿ÉÄܵ¼Ö²»µÃ²»ÌÔÌÄÇЩ¿Í»§»úϵͳ£¬
»òÕß²»Ê¹Óà /var/yp/securenets¡£
ÔÚʹÓÃ³Â¾ÉµÄ TCP/IP ʵÏÖµÄϵͳÉÏ£¬
ʹÓà /var/yp/securenets ÊÇÒ»¸ö·Ç³£Ôã¸âµÄ×ö·¨£¬
ÒòΪÕ⽫µ¼ÖÂÄúµÄÍøÂçÉ쵀 NIS ɥʧ´ó²¿·Ö¹¦ÄÜ¡£
TCP Wrappers
ʹÓà TCP Wrapper
Èí¼þ°ü£¬ »áµ¼ÖÂÄúµÄ NIS ·þÎñÆ÷µÄÏìÓ¦ÑÓ³ÙÔö¼Ó¡£
¶øÔö¼ÓµÄÑÓ³Ù£¬ Ôò¿ÉÄܻᵼÖ¿ͻ§¶Ë³ÌÐò³¬Ê±£¬
ÌØ±ðÊÇÔÚ·±Ã¦µÄÍøÂç»òÕߺÜÂýµÄ
NIS ·þÎñÆ÷ÉÏ¡£ Èç¹ûÄúµÄij¸ö¿Í»§»úÒò´Ë¶ø²úÉúһЩÒì³££¬
ÔòÓ¦½«ÕâЩ¿Í»§»ú±äΪ NIS ´Ó·þÎñÆ÷£¬
²¢Ç¿ÖÆÆä°ó¶¨×Ô¼º¡£
²»ÔÊÐíijЩÓû§µÇ¼
ÔÚÎÒÃǵÄʵÑéÊÒÖУ¬ basie Õą̂»úÆ÷£¬
ÊÇһ̨½ÌԱרÓõŤ×÷Õ¾¡£ ÎÒÃDz»Ï£Íû½«Õą̂»úÆ÷Äóö NIS Óò£¬
¶øÖ÷ NIS ·þÎñÆ÷É쵀 passwd Îļþ£¬
Ôòͬʱ°üº¬Á˽ÌÔ±ºÍѧÉúµÄÕʺš£ ÕâʱӦ¸ÃÔõô×ö£¿
ÓÐÒ»ÖÖ°ì·¨À´½ûÖ¹ÌØ¶¨µÄÓû§µÇ¼»úÆ÷£¬ ¼´Ê¹ËûÃÇÉí´¦ NIS Êý¾Ý¿âÖ®ÖС£
ÒªÍê³ÉÕâÒ»¹¤×÷£¬ Ö»ÐèÒªÔÚ¿Í»§»úµÄ /etc/master.passwd
ÎļþÖмÓÈëһЩ
-username ÕâÑùµÄÏ
ÆäÖУ¬ username ÊÇÏ£Íû½ûÖ¹µÇ¼µÄÓû§Ãû¡£
Ò»°ãÍÆ¼öʹÓà vipw À´Íê³ÉÕâ¸ö¹¤×÷£¬
ÒòΪ vipw »á¶ÔÄúÔÚ /etc/master.passwd
ÎļþÉÏËù×÷µÄÐ޸ĽøÐкϷ¨ÐÔ¼ì²é£¬
²¢Ôڱ༽áÊøÊ±ÖØÐ¹¹½¨¿ÚÁîÊý¾Ý¿â¡£ ÀýÈ磬 Èç¹ûÏ£Íû½ûÖ¹Óû§
bill 怬
basie£¬ ÎÒÃÇÓ¦¸Ã£º
basie&prompt.root; vipw
[ÔÚĩβ¼ÓÈë -bill£¬ ²¢Í˳ö]
vipw: rebuilding the database...
vipw: done
basie&prompt.root; cat /etc/master.passwd
root:[password]:0:0::0:0:The super-user:/root:/bin/csh
toor:[password]:0:0::0:0:The other super-user:/root:/bin/sh
daemon:*:1:1::0:0:Owner of many system processes:/root:/sbin/nologin
operator:*:2:5::0:0:System &:/:/sbin/nologin
bin:*:3:7::0:0:Binaries Commands and Source,,,:/:/sbin/nologin
tty:*:4:65533::0:0:Tty Sandbox:/:/sbin/nologin
kmem:*:5:65533::0:0:KMem Sandbox:/:/sbin/nologin
games:*:7:13::0:0:Games pseudo-user:/usr/games:/sbin/nologin
news:*:8:8::0:0:News Subsystem:/:/sbin/nologin
man:*:9:9::0:0:Mister Man Pages:/usr/share/man:/sbin/nologin
bind:*:53:53::0:0:Bind Sandbox:/:/sbin/nologin
uucp:*:66:66::0:0:UUCP pseudo-user:/var/spool/uucppublic:/usr/libexec/uucp/uucico
xten:*:67:67::0:0:X-10 daemon:/usr/local/xten:/sbin/nologin
pop:*:68:6::0:0:Post Office Owner:/nonexistent:/sbin/nologin
nobody:*:65534:65534::0:0:Unprivileged user:/nonexistent:/sbin/nologin
+:::::::::
-bill
basie&prompt.root;
Udo
Erdelhoff
Contributed by
ʹÓà Netgroups
netgroups
ǰһ½Ú½éÉܵķ½·¨£¬
ÔÚÄúÐèҪΪ·Ç³£ÉÙµÄÓû§ºÍ/»ò»úÆ÷½øÐÐÌØÊâµÄ¹æÔòÅäÖÃʱ»¹Ëã´ÕºÏ¡£
ÔÚ¸ü´óµÄÍøÂçÉÏ£¬ Äú
Ò»¶¨»á Íü¼Ç½ûֹijЩÓû§µÇ¼µ½Ãô¸ÐµÄ»úÆ÷ÉÏ£¬
»òÕߣ¬ ÉõÖÁ±ØÐëµ¥¶ÀµØÐÞ¸Äÿһ̨»úÆ÷µÄÅäÖ㬠Òò¶ø¶ªµôÁË NIS ×îÖØÒªµÄÓÅÔ½ÐÔ£º
¼¯ÖÐʽ ¹ÜÀí¡£
NIS ¿ª·¢ÈËԱΪÕâ¸öÎÊÌâÌṩµÄ½â¾ö·½°¸£¬ ±»³Æ×÷
netgroups¡£ ËüÃǵÄ×÷ÓúÍÓïÒ壬
»ù±¾ÉÏ¿ÉÒÔµÈͬÓÚ &unix; ÎļþϵͳÉÏʹÓõÄ×é¡£
Ö÷ÒªµÄÇø±ðÊÇËüÃÇûÓÐÊý×Ö»¯µÄ ID£¬ ÒÔ¼°¿ÉÒÔÔÚ netgroup
ÖÐͬʱ°üº¬Óû§ºÍÆäËû netgroup¡£
Netgroups ±»Éè¼ÆÓÃÀ´´¦Àí´óµÄ¡¢ ¸´Ôӵİüº¬Êý°ÙÓû§ºÍ»úÆ÷µÄÍøÂç¡£
Ò»·½Ã棬 ÔÚÄú²»µÃ²»´¦ÀíÕâÀàÇéÐÎʱ£¬ ÕâÊÇÒ»¸öºÜÓÐÓõĶ«Î÷¡£
¶øÁíÒ»·½Ã棬 ËüµÄ¸´ÔÓÐÔÓÖʹµÃͨ¹ý·Ç³£¼òµ¥µÄÀý×ÓºÜÄѽâÊÍ netgroup
µ½µ×ÊÇʲô¡£ ÕâÒ»½ÚµÄÆäÓಿ·ÖµÄÀý×Ó½«Õ¹Ê¾Õâ¸öÎÊÌâ¡£
¼ÙÉèÄúÔÚʵÑéÊÒÖгɹ¦µØ²¿Êð NIS ÒýÆðÁËÉÏ˾µÄÐËȤ¡£
Äú½ÓÏÂÀ´µÄÈÎÎñÊǽ« NIS ÓòÀ©Õ¹£¬ ÒÔ¸²¸ÇУ԰ÖеÄһЩÆäËûµÄ»úÆ÷¡£
ÏÂÃæÁ½¸ö±í¸ñÖаüÀ¨ÁËÐÂÓû§ºÍлúÆ÷£¬ ¼°Æä¼òҪ˵Ã÷¡£
Óû§Ãû
˵Ã÷
alpha, beta
IT ²¿ÃŵįÕͨ¹ÍÔ±
charlie, delta
IT ²¿ÃŵÄѧͽ
echo, foxtrott, golf, ...
ÆÕͨ¹ÍÔ±
able, baker, ...
ĿǰµÄʵϰÉú
»úÆ÷Ãû
˵Ã÷
war, death,
famine,
pollution
×îÖØÒªµÄ·þÎñÆ÷¡£ Ö»ÓÐ IT
²¿ÃŵĹÍÔ±²ÅÔÊÐíµÇ¼ÕâЩ»úÆ÷¡£
pride, greed,
envy, wrath,
lust, sloth
²»Ì«ÖØÒªµÄ·þÎñÆ÷£¬ ËùÓÐ IT ²¿ÃŵijÉÔ±£¬
¶¼¿ÉÒԵǼÕâЩ»úÆ÷¡£
one, two,
three, four,
...
ÆÕͨ¹¤×÷Õ¾¡£ Ö»ÓÐ
ÕæÕýµÄ ¹ÍÔ±²ÅÔÊÐíµÇ¼ÕâЩ»úÆ÷¡£
trashcan
һ̨²»°üº¬¹Ø¼üÊý¾ÝµÄ¾É»úÆ÷¡£
¼´Ê¹ÊÇʵϰÉú£¬ Ò²ÔÊÐíµÇ¼Ëü¡£
Èç¹ûÄú³¢ÊÔͨ¹ýÒ»¸öÒ»¸öµØ×èÖ¹Óû§À´ÊµÏÖÕâЩÏÞÖÆ£¬
¾ÍÐèÒªÔÚÿһ¸öϵͳµÄ passwd ÎļþÖУ¬
Ϊÿһ¸ö²»ÔÊÐíµÇ¼¸ÃϵͳµÄÓû§Ìí¼Ó¶ÔÓ¦µÄ
-user ÐС£
Èç¹ûÍü¼ÇÁËÈκÎÒ»¸ö£¬ ¾Í¿ÉÄÜ»áÔì³ÉÎÊÌâ¡£ ÔÚ½øÐгõʼÅäÖÃʱ£¬
ÕýÈ·µØÅäÖÃÒ²Ðí²»ÊÇʲôÎÊÌ⣬ µ«Ëæ×ÅÈÕ¸´Ò»ÈÕµØÌí¼ÓÐÂÓû§£¬
×ÜÓÐÒ»Ìì Äú»áÍü¼ÇΪÐÂÓû§Ìí¼Óij¸öÐС£
±Ï¾¹£¬ Murphy ÊÇÒ»¸öÀÖ¹ÛµÄÈË¡£
ʹÓà netgroups À´´¦ÀíÕâÒ»×´¿ö¿ÉÒÔ´øÀ´Ðí¶àºÃ´¦¡£
²»ÐèÒªµ¥¶ÀµØ´¦Àíÿһ¸öÓû§£» Äú¿ÉÒÔ¸³ÓèÓû§Ò»¸ö»ò¶à¸ö netgroups
Éí·Ý£¬ ²¢ÔÊÐí»ò½ûֹijһ¸ö netgroup µÄËùÓгÉÔ±µÇ¼¡£
Èç¹ûÌí¼ÓÁËеĻúÆ÷£¬ Ö»ÐèÒª¶¨Òå netgroup µÄµÇ¼ÏÞÖÆ¡£
Èç¹ûÔö¼ÓÁËÐÂÓû§£¬ Ò²Ö»ÐèÒª½«Óû§¼ÓÈëÒ»¸ö»ò¶à¸ö netgroup¡£
ÕâЩ±ä»¯ÊÇÏ໥¶ÀÁ¢µÄ£º ²»ÔÙÐèÒª ¶Ôÿһ¸öÓû§ºÍ»úÆ÷Ö´ÐÐ
¡¡
¡£ Èç¹ûÄúµÄ NIS ÅäÖþ¹ýÁ˽÷É÷µÄ¹æ»®£¬
¾ÍÖ»ÐèÒªÐÞ¸ÄÒ»¸öÖÐÑëµÄÅäÖÃÎļþ£¬ ¾ÍÄܹ»ÔÊÐí»ò½ûÖ¹·ÃÎÊij̨»úÆ÷µÄȨÏÞÁË¡£
µÚÒ»²½Êdzõʼ»¯ NIS Ó³Éä
netgroup¡£ FreeBSD µÄ &man.ypinit.8; ĬÈÏÇé¿öϲ¢²»´´½¨Õâ¸öÓ³É䣬
µ«ËüµÄ NIS ʵÏÖÄܹ»ÔÚ´´½¨Õâ¸öÓ³ÉäÖ®ºóÁ¢¼´¶ÔÆäÌṩ֧³Ö¡£
Òª´´½¨¿ÕÓ³É䣬 ¼òµ¥µØÊäÈë
ellington&prompt.root; vi /var/yp/netgroup
²¢¿ªÊ¼Ôö¼ÓÄÚÈÝ¡£ ÔÚÎÒÃǵÄÀý×ÓÖУ¬ ÖÁÉÙÐèÒªËĸö nergruop£º
IT ¹ÍÔ±£¬ IT ѧͽ£¬ ÆÕͨ¹ÍÔ±ºÍʵϰÉú¡£
IT_EMP (,alpha,test-domain) (,beta,test-domain)
IT_APP (,charlie,test-domain) (,delta,test-domain)
USERS (,echo,test-domain) (,foxtrott,test-domain) \
(,golf,test-domain)
INTERNS (,able,test-domain) (,baker,test-domain)
IT_EMP, IT_APP µÈµÈ£¬
ÊÇ netgroup µÄÃû×Ö¡£ ÿһ¸öÀ¨ºÅÖеÄ×éÖУ¬
¶¼ÓÐһЩÓû§Õʺš£ ×éÖеÄÈý¸ö×Ö¶ÎÊÇ£º
ÔÚÄÄЩ»úÆ÷ÉÏÄܹ»Ê¹ÓÃÕâЩÏî¡£ Èç¹û²»Ö¸¶¨Ö÷»úÃû£¬
ÔòÏîÔÚËùÓлúÆ÷É϶¼ÓÐЧ¡£ Èç¹ûÖ¸¶¨ÁËÖ÷»ú£¬
ÔòºÜÈÝÒ×Ôì³É»ìÏý¡£
ÊôÓÚÕâ¸ö netgroup µÄÕʺš£
ÕÊºÅµÄ NIS Óò¡£ Äú¿ÉÒÔ´ÓÆäËû NIS
ÓòÖаÑÕʺŵ¼Èëµ½ÄúµÄ netgroup ÖУ¬
Èç¹ûÄú¹ÜÀí¶à¸ö NIS ÓòµÄ»°¡£
ÿһ¸ö×ֶζ¼¿ÉÒÔ°üÀ¨Í¨Åä·û¡£ ²Î¼û
&man.netgroup.5; Á˽â¸ü¶àϸ½Ú¡£
netgroups
Netgroup µÄÃû×ÖÒ»°ãÀ´Ëµ²»Ó¦³¬¹ý 8 ¸ö×Ö·û£¬
ÌØ±ðÊǵ±ÄúµÄ NIS ÓòÖÐÓлúÆ÷´òËãÔËÐÐÆäËü²Ù×÷ϵͳµÄʱºò¡£
Ãû×ÖÊÇÇø·Ö´óСдµÄ£» ʹÓôóд×Öĸ×÷Ϊ netgroup µÄÃû×Ö£¬
Äܹ»ÈÃÄú¸üÈÝÒ×µØÇø·ÖÓû§¡¢ »úÆ÷ºÍ netgroup µÄÃû×Ö¡£
ijЩ NIS ¿Í»§³ÌÐò (FreeBSD ÒÔÍâµÄÄÇЩ) ¿ÉÄÜÎÞ·¨´¦Àíº¬ÓдóÁ¿ÏîµÄ
netgroup¡£ ÀýÈ磬 ijЩÔçÆÚ°æ±¾µÄ &sunos; »áÔÚ netgroup
Öаüº¬¶àÓÚ 15 ¸ö Ïî ʱ³öÏÖÎÊÌâ¡£
ÒªÈÆ¹ýÕâ¸öÎÊÌ⣬ ¿ÉÒÔ´´½¨¶à¸ö ×Ónetgroup£¬Ã¿Ò»¸öÖаüº¬ÉÙÓÚ 15 ¸öÓû§£¬
ÒÔ¼°Ò»¸ö°üº¬ËùÓÐ ×Ónetgroup µÄÕæÕýµÄ netgroup£º
BIGGRP1 (,joe1,domain) (,joe2,domain) (,joe3,domain) [...]
BIGGRP2 (,joe16,domain) (,joe17,domain) [...]
BIGGRP3 (,joe31,domain) (,joe32,domain)
BIGGROUP BIGGRP1 BIGGRP2 BIGGRP3
Èç¹ûÐèÒª³¬¹ý 225 ¸öÓû§£¬ ¿ÉÒÔ¼ÌÐøÖØ¸´ÉÏÃæµÄ¹ý³Ì¡£
¼¤»î²¢·Ö·¢Ð嵀 NIS Ó³Éä·Ç³£¼òµ¥£º
ellington&prompt.root; cd /var/yp
ellington&prompt.root; make
Õâ¸ö²Ù×÷»áÉú³ÉÈý¸ö NIS Ó³É䣬 ¼´
netgroup¡¢
netgroup.byhost ºÍ
netgroup.byuser¡£ ÓÃ &man.ypcat.1;
¿ÉÒÔ¼ì²éÕâЩ NIS Ó³ÉäÊÇ·ñ¿ÉÓÃÁË£º
ellington&prompt.user; ypcat -k netgroup
ellington&prompt.user; ypcat -k netgroup.byhost
ellington&prompt.user; ypcat -k netgroup.byuser
µÚÒ»¸öÃüÁîµÄÊä³ö£¬
Ó¦¸ÃÓë /var/yp/netgroup µÄÄÚÈÝÏà½ü¡£
µÚ¶þ¸öÃüÁ Èç¹ûûÓÐÖ¸¶¨±¾»úרÓÐµÄ netgroup£¬
ÔòÓ¦¸ÃûÓÐÊä³ö¡£ µÚÈý¸öÃüÁ
ÔòÓÃÓÚÏÔʾij¸öÓû§¶ÔÓ¦µÄ netgroup ÁÐ±í¡£
¿Í»§»úµÄÉèÖÃÒ²ºÜ¼òµ¥¡£ ÒªÅäÖ÷þÎñÆ÷
war£¬ Ö»Ðè½øÈë
&man.vipw.8; ²¢°Ñ
+:::::::::
¸ÄΪ
+@IT_EMP:::::::::
ÏÖÔÚ£¬ Ö»ÓÐ netgroup
IT_EMP Öж¨ÒåµÄÓû§»á±»µ¼Èëµ½
war µÄ¿ÚÁîÊý¾Ý¿âÖУ¬
Òò´ËÖ»ÓÐÕâЩÓû§Äܹ»µÇ¼¡£
²»¹ý£¬ Õâ¸öÏÞÖÆÒ²»á×÷ÓÃÓÚ shell µÄ
~£¬ ÒÔ¼°ËùÓÐÔÚÓû§ÃûºÍÊý×ÖÓû§ ID
Ö®¼äʵʩת»»µÄº¯ÊýµÄ¹¦ÄÜ¡£ »»ÑÔÖ®£¬ cd
~user ½«²»»áÕý³£¹¤×÷£¬ ¶ø
ls -l Ò²½«ÏÔʾÊý×ÖµÄ ID ¶ø²»ÊÇÓû§Ãû£¬
²¢ÇÒ find . -user joe -print
½«Ê§°Ü£¬ ²¢¸ø³ö No such user µÄ´íÎóÐÅÏ¢¡£
ÒªÐÞÕýÕâ¸öÎÊÌ⣬ ÄúÐèÒªµ¼ÈëËùÓеÄÓû§Ï ¶ø
²»ÔÊÐíËûÃǵǼ·þÎñÆ÷¡£
Õâ¿ÉÒÔͨ¹ýÔÚ
/etc/master.passwd ¼ÓÈëÁíÒ»ÐÐÀ´Íê³É¡£
ÕâÐеÄÄÚÈÝÊÇ£º
+:::::::::/sbin/nologin£¬ Òâ˼ÊÇ
µ¼ÈëËùÓеÄÏ µ«µ¼ÈëÏîµÄ shell ÔòÌæ»»Îª
/sbin/nologin
¡£
ͨ¹ýÔÚ /etc/master.passwd
ÖÐÔö¼ÓĬÈÏÖµ£¬ ¿ÉÒÔÌæ»»µô
passwd ÖеÄÈÎÒâ×ֶΡ£
Îñ±ØÈ·ÈÏ
+:::::::::/sbin/nologin ÕâÒ»ÐгöÏÖÔÚ
+@IT_EMP::::::::: Ö®ºó¡£
·ñÔò£¬ ËùÓÐ´Ó NIS µ¼ÈëµÄÓû§ÕʺŽ«ÒÔ /sbin/nologin
×÷ΪµÇ¼ shell¡£
Íê³ÉÉÏÃæµÄÐÞ¸ÄÖ®ºó£¬ ÔÚ IT ²¿ÃÅÓÐÁËÐÂÔ±¹¤Ê±£¬
Ö»ÐèÐÞ¸ÄÒ»¸ö NIS Ó³Éä¾Í×ã¹»ÁË¡£ ÄúÒ²¿ÉÒÔÓÃÀàËÆµÄ·½·¨£¬
ÔÚ²»Ì«ÖØÒªµÄ·þÎñÆ÷ÉÏ£¬ °ÑÏÈǰ±¾µØ°æ±¾µÄ /etc/master.passwd
ÖÐµÄ +::::::::: ¸ÄΪ£º
+@IT_EMP:::::::::
+@IT_APP:::::::::
+:::::::::/sbin/nologin
Ïà¹ØµÄÓÃÓÚÆÕͨ¹¤×÷Õ¾µÄÅäÖÃÔòÓ¦ÊÇ£º
+@IT_EMP:::::::::
+@USERS:::::::::
+:::::::::/sbin/nologin
Ò»ÇÐÆ½°²ÎÞÊ£¬ Ö±µ½ÊýÖÜºó£¬ ÓÐÒ»Ìì²ßÂÔ·¢ÉúÁ˱仯£º
IT ²¿ÃÅÒ²¿ªÊ¼ÕÐÊÕʵϰÉúÁË¡£ IT ʵϰÉúÔÊÐíʹÓÃÆÕͨµÄÖÕ¶Ë£¬
ÒÔ¼°²»Ì«ÖØÒªµÄ·þÎñÆ÷£» ¶ø IT ѧͽ£¬ Ôò¿ÉÒԵǼÖ÷·þÎñÆ÷¡£
ÄúÔö¼ÓÁËÐ嵀 netgroup IT_INTERN£¬ ÒÔ¼°Ð嵀 IT
ʵϰÉúµ½Õâ¸ö netgroup ²¢¿ªÊ¼ÐÞ¸Äÿһ̨»úÆ÷ÉϵÄÅäÖá¡
ÀÏ»°ËµµÃºÃ£ºÇ£Ò»·¢£¬ ¶¯È«Éí
¡£
NIS ͨ¹ý netgroup À´½¨Á¢ netgroup µÄÄÜÁ¦£¬
Õý¿ÉÒÔ±ÜÃâÕâÑùµÄÇéÐΡ£ Ò»ÖÖ¿ÉÄܵķ½·¨Êǽ¨Á¢»ùÓÚ½ÇÉ«µÄ netgroup¡£
ÀýÈ磬 Äú¿ÉÒÔ´´½¨³ÆÎª
BIGSRV µÄ netgroup£¬ ÓÃÓÚ¶¨Òå×îÖØÒªµÄ·þÎñÆ÷ÉϵĵǼÏÞÖÆ£¬
ÒÔ¼°ÁíÒ»¸ö³ÉΪ SMALLSRV µÄ netgroup£¬
ÓÃÒÔ¶¨Òå´ÎÖØÒªµÄ·þÎñÆ÷£¬ ÒÔ¼°µÚÈý¸ö£¬ ÓÃÓÚÆÕͨ¹¤×÷Õ¾µÄ netgroup
USERBOX¡£ ÕâÈý¸ö netgroup ÖеÄÿһ¸ö£¬
¶¼°üº¬ÁËÔÊÐíµÇ¼µ½ÕâЩ»úÆ÷ÉϵÄËùÓÐ netgroup¡£
ÄúµÄ NIS Ó³ÉäÖеÄÐÂÏîÈçÏÂËùʾ£º
BIGSRV IT_EMP IT_APP
SMALLSRV IT_EMP IT_APP ITINTERN
USERBOX IT_EMP ITINTERN USERS
ÕâÖÖ¶¨ÒåµÇ¼ÏÞÖÆµÄ·½·¨£¬
ÔÚÄúÄܹ»½«»úÆ÷·Ö×é²¢¼ÓÒÔÏÞÖÆµÄʱºò¿ÉÒÔ¹¤×÷µÄÏ൱ºÃ¡£
²»ÐÒµÄÊÇ£¬ ÕâÊÇÖÖÀýÍ⣬ ¶ø·Ç³£¹æÇé¿ö¡£ ¶àÊýʱºò£¬
ÐèÒª°´»úÆ÷È¥¶¨ÒåµÇ¼ÏÞÖÆ¡£
Óë»úÆ÷Ïà¹ØµÄ netgroup ¶¨Ò壬 ÊÇ´¦ÀíÉÏÊö²ßÂԸ͝µÄÁíÒ»ÖÖ¿ÉÄܵķ½·¨¡£
´Ëʱ£¬ ÿ̨»úÆ÷µÄ /etc/master.passwd ÖУ¬
¶¼°üº¬Á½¸ö +
¿ªÍ·µÄÐС£ µÚÒ»¸öÓÃÓÚÌí¼ÓÔÊÐíµÇ¼µÄ netgroup
Õʺţ¬ ¶øµÚ¶þ¸öÔòÓÃÓÚÔö¼ÓÆäËüÕʺţ¬ ²¢°Ñ shell
ÉèÖÃΪ /sbin/nologin¡£ ʹÓà ȫ´óд
µÄ»úÆ÷Ãû×÷Ϊ netgroup ÃûÊǸöºÃÖ÷Òâ¡£ »»ÑÔÖ®£¬ ÕâЩÐÐÓ¦¸ÃÀàËÆÓÚ£º
+@BOXNAME:::::::::
+:::::::::/sbin/nologin
Ò»µ©ÔÚËùÓлúÆ÷É϶¼Íê³ÉÁËÕâÑùµÄÐ޸ģ¬ ¾ÍÔÙÒ²²»ÐèÒªÐ޸ı¾µØµÄ
/etc/master.passwd ÁË¡£
ËùÓÐδÀ´µÄÐ޸ͼ¿ÉÒÔÔÚ NIS Ó³ÉäÖнøÐС£ ÕâÀïÊÇÒ»¸öÀý×Ó£¬
ÆäÖÐչʾÁËÔÚÕâÒ»Ó¦ÓÃÇé¾°ÖÐËùÐèÒªµÄ netgroup Ó³É䣬
ÒÔ¼°ÆäËüһЩ³£Óõļ¼ÇÉ£º
# Define groups of users first
IT_EMP (,alpha,test-domain) (,beta,test-domain)
IT_APP (,charlie,test-domain) (,delta,test-domain)
DEPT1 (,echo,test-domain) (,foxtrott,test-domain)
DEPT2 (,golf,test-domain) (,hotel,test-domain)
DEPT3 (,india,test-domain) (,juliet,test-domain)
ITINTERN (,kilo,test-domain) (,lima,test-domain)
D_INTERNS (,able,test-domain) (,baker,test-domain)
#
# Now, define some groups based on roles
USERS DEPT1 DEPT2 DEPT3
BIGSRV IT_EMP IT_APP
SMALLSRV IT_EMP IT_APP ITINTERN
USERBOX IT_EMP ITINTERN USERS
#
# And a groups for a special tasks
# Allow echo and golf to access our anti-virus-machine
SECURITY IT_EMP (,echo,test-domain) (,golf,test-domain)
#
# machine-based netgroups
# Our main servers
WAR BIGSRV
FAMINE BIGSRV
# User india needs access to this server
POLLUTION BIGSRV (,india,test-domain)
#
# This one is really important and needs more access restrictions
DEATH IT_EMP
#
# The anti-virus-machine mentioned above
ONE SECURITY
#
# Restrict a machine to a single user
TWO (,hotel,test-domain)
# [...more groups to follow]
Èç¹ûÄúÕýʹÓÃijÖÖÊý¾Ý¿âÀ´¹ÜÀíÕʺţ¬
Ó¦¸Ã¿ÉÒÔʹÓÃÄúµÄÊý¾Ý¿âµÄ±¨¸æ¹¤¾ßÀ´´´½¨Ó³ÉäµÄµÚÒ»²¿·Ö¡£
ÕâÑù£¬ ÐÂÓû§¾Í×Ô¶¯µØ¿ÉÒÔ·ÃÎÊÕâЩ»úÆ÷ÁË¡£
×îºóµÄÌáÐÑ£º ʹÓûùÓÚ»úÆ÷µÄ netgroup ²¢²»×ÜÊÇÊÊÓõġ£
Èç¹ûÕýÔÚΪѧÉúʵÑéÊÒ²¿ÊðÊýʮ̨ÉõÖÁÉϰŲ̀ͬÑùµÄ»úÆ÷£¬
ÄúÓ¦¸ÃʹÓûùÓÚ½ÇÉ«µÄ netgroup£¬ ¶ø²»ÊÇ»ùÓÚ»úÆ÷µÄ netgroup£¬
ÒÔ±ã°Ñ NIS Ó³ÉäµÄ³ß´ç±£³ÖÔÚÒ»¸öºÏÀíµÄ·¶Î§ÄÚ¡£
ÐèÒªÀμǵÄÊÂÏî
ÕâÀïÊÇһЩÆäËüÔÚʹÓà NIS »·¾³Ê±ÐèҪעÒâµÄµØ·½¡£
ÿ´ÎÐèÒªÔÚʵÑéÊÒÖÐÔö¼ÓÐÂÓû§Ê±£¬
±ØÐë Ö» ÔÚ NIS ·þÎñÆ÷ÉϼÓÈëÓû§£¬
¶øÇÒ Ò»¶¨Òª¼ÇµÃÖØ½¨ NIS Ó³Éä¡£
Èç¹ûÄúÍü¼ÇÁËÕâÑù×ö£¬ ÐÂÓû§½«ÎÞ·¨µÇ¼³ý NIS
Ö÷·þÎñÆ÷Ö®ÍâµÄÈÎºÎÆäËü»úÆ÷¡£ ÀýÈ磬 Èç¹ûÒªÔÚʵÑéÊÒÔö¼ÓÐÂÓû§
jsmith£¬ ÎÒÃÇÐèÒª£º
&prompt.root; pw useradd jsmith
&prompt.root; cd /var/yp
&prompt.root; make test-domain
Ò²¿ÉÒÔÔËÐÐ adduser jsmith ¶ø²»ÊÇ
pw useradd jsmith.
½«¹ÜÀíÓõÄÕʺÅÅųýÔÚ
NIS Ó³ÉäÖ®Íâ¡£ Ò»°ãÀ´Ëµ£¬
Äú²»Ï£ÍûÕâЩ¹ÜÀíÕʺźͿÚÁî±»À©É¢µ½ÄÇЩ°üº¬²»Ó¦Ê¹ÓÃËüÃǵÄÓû§µÄ»úÆ÷ÉÏ¡£
È·±£ NIS Ö÷ºÍ´Ó·þÎñÆ÷µÄ°²È«£¬
²¢¾¡¿ÉÄܼõÉÙÆäÍ£»úʱ¼ä¡£
Èç¹ûÓÐÈ˹¥Èë»ò¼òµ¥µØ¹Ø±ÕÕâЩ»úÆ÷£¬
ÔòÕû¸öʵÑéÊÒµÄÈÎÒ²¾ÍÎÞ·¨µÇ¼ÁË¡£
ÕâÊǼ¯ÖÐʽ¹ÜÀíϵͳÖÐ×ÈõµÄ»·½Ú¡£
Èç¹ûûÓб£»¤ºÃ NIS ·þÎñÆ÷£¬ Äú¾ÍÓдóÅú·ßŵÄÓû§ÐèÒª¶Ô¸¶ÁË£¡
NIS v1 ¼æÈÝÐÔ
FreeBSD µÄ ypserv ÌṩÁËijЩΪ NIS v1
¿Í»§Ìṩ·þÎñµÄÖ§³ÖÄÜÁ¦¡£ FreeBSD µÄ NIS ʵÏÖ£¬
ֻʹÓà NIS v2 ÐÒ飬 µ«ÆäËüʵÏÖ¿ÉÄÜ»á°üº¬ v1 ÐÒ飬
ÒÔÌṩ¶Ô¾ÉϵͳµÄÏòϼæÈÝÄÜÁ¦¡£ ËæÕâЩϵͳÌṩµÄ
ypbind ·þÎñ½«Ê×Ïȳ¢ÊÔ°ó¶¨ NIS v1
·þÎñÆ÷£¬ ¼´Ê¹ËüÃDz¢²»ÕæµÄÐèÒªËü (ÓÐЩÉõÖÁ¿ÉÄÜ»áÒ»Ö±¹ã²¥ËÑË÷ÇëÇó£¬
¼´Ê¹ÒѾ´Óij̨ v2 ·þÎñÆ÷µÃµ½ÁË»ØÓ¦Ò²ÊÇÈç´Ë)¡£
×¢Ò⣬ ¾¡¹ÜÖ§³ÖÒ»°ãµÄ¿Í»§»úµ÷Ó㬠Õâ¸ö°æ±¾µÄ
ypserv ²¢²»ÄÜ´¦Àí v1 µÄÓ³Éä´«ËÍÇëÇó£»
Òò¶ø£¬ Ëü¾Í²»ÄÜÓë½ÏÔçµÄÖ§³Ö v1 ÐÒéµÄ NIS ·þÎñÆ÷ÅäºÏʹÓã¬
ÎÞÂÛÊÇ×÷ΪÖ÷·þÎñÆ÷»¹ÊÇ´Ó·þÎñÆ÷¡£ ÐÒÔ˵ÄÊÇ£¬
ÏÖ½ñÓ¦¸ÃÒѾûÓÐÈÔÈ»ÔÚÓõÄÕâÑùµÄ·þÎñÆ÷ÁË¡£
ͬʱ×÷Ϊ NIS ¿Í»§»úµÄ NIS ·þÎñÆ÷
ÔÚ¶à·þÎñÆ÷ÓòµÄ»·¾³ÖУ¬ Èç¹û·þÎñÆ÷ͬʱ×÷Ϊ NIS ¿Í»§£¬ ÔÚÔËÐÐ
ypserv Ê±ÒªÌØ±ðСÐÄ¡£
Ò»°ãÀ´Ëµ£¬ Ç¿ÖÆ·þÎñÆ÷°ó¶¨×Ô¼ºÒª±ÈÔÊÐíËüÃǹ㲥°ó¶¨ÇëÇóÒªºÃ£¬
ÒòΪÕâÖÖÇé¿öÏÂËüÃÇ¿ÉÄÜ»áÏ໥°ó¶¨¡£ ijЩ¹ÖÒìµÄ¹ÊÕÏ£¬
ºÜ¿ÉÄÜÊÇÓÉÓÚijһ̨·þÎñÆ÷Í£»ú£¬ ¶øÆäËü·þÎñÆ÷¶¼ÒÀÀµÆä·þÎñËùµ¼Öµġ£
×îÖÕ£¬ ËùÓеĿͻ§»ú¶¼»á³¬Ê±²¢°ó¶¨µ½ÆäËü·þÎñÆ÷£¬
µ«Õâ¸öÑÓ³Ù¿ÉÄÜ»áÏ൱¿É¹Û£¬
¶øÇÒ»Ö¸´Ö®ºóÈÔÈ»´æÔÚÔٴη¢Éú´ËÀàÎÊÌâµÄÒþ»¼¡£
Äú¿ÉÒÔÇ¿ÖÆÒ»Ì¨»úÆ÷°ó¶¨µ½Ìض¨µÄ·þÎñÆ÷£¬ ÕâÊÇͨ¹ý
ypbind µÄ
²ÎÊýÀ´Íê³ÉµÄ¡£ Èç¹û²»Ï£Íûÿ´ÎÆô¶¯ NIS ·þÎñÆ÷ʱ¶¼ÊÖ¹¤Íê³ÉÕâÏ×÷£¬
¿ÉÒÔÔÚ /etc/rc.conf ÖмÓÈ룺
nis_client_enable="YES" # run client stuff as well
nis_client_flags="-S NIS domain,server"
²Î¼û &man.ypbind.8; ÒÔÁ˽â¸ü¶àÇé¿ö¡£
¿ÚÁî¸ñʽ
NIS
¿ÚÁî¸ñʽ
ÔÚʵÏÖ NIS ʱ£¬ ¿ÚÁî¸ñʽµÄ¼æÈÝÐÔÎÊÌâÊÇÒ»ÖÖ×îΪ³£¼ûµÄÎÊÌâ¡£
¼ÙÈçÄúµÄ NIS ·þÎñÆ÷ʹÓà DES ¼ÓÃÜ¿ÚÁ ÔòËüÖ»ÄÜÖ§³ÖʹÓà DES
µÄ¿Í»§»ú¡£ ÀýÈ磬 Èç¹ûÄúµÄÍøÂçÉÏÓÐ
&solaris; NIS ¿Í»§»ú£¬ Ôò¼¸ºõ¿Ï¶¨ÐèҪʹÓà DES ¼ÓÃÜ¿ÚÁî¡£
Òª¼ì²éÄúµÄ·þÎñÆ÷ºÍ¿Í»§»úʹÓõĿÚÁî¸ñʽ£¬
ÐèÒª²é¿´ /etc/login.conf¡£
Èç¹ûÖ÷»ú±»ÅäÖÃΪʹÓà DES ¼ÓÃܵĿÚÁ Ôò
default class ½«°üº¬ÀàËÆÕâÑùµÄÏ
default:\
:passwd_format=des:\
:copyright=/etc/COPYRIGHT:\
[Further entries elided]
ÆäËûһЩ¿ÉÄÜµÄ passwd_format
°üÀ¨ blf ºÍ md5
(·Ö±ð¶ÔÓ¦ÓÚ Blowfish ºÍ MD5 ¼ÓÃÜ¿ÚÁî)¡£
Èç¹ûÐÞ¸ÄÁË
/etc/login.conf£¬ ¾Í±ØÐëÖØ½¨µÇ¼ÐÔÄÜÊý¾Ý¿â£¬
ÕâÊÇͨ¹ýÒÔ
root Éí·ÝÔËÐÐÏÂÃæµÄ³ÌÐòÀ´Íê³ÉµÄ£º
&prompt.root; cap_mkdb /etc/login.conf
ÒѾÔÚ
/etc/master.passwd ÖеĿÚÁîµÄ¸ñʽ²»»á±»¸üУ¬
Ö±µ½Óû§ÔڵǼÐÔÄÜÊý¾Ý¿âÖØ½¨
Ö®ºó Ê×´ÎÐ޸ĿÚÁîΪֹ¡£
½ÓÏÂÀ´£¬ ΪÁËÈ·±£ËùÓеĿÚÁî¶¼°´ÕÕÄúÑ¡ÔñµÄ¸ñʽ¼ÓÃÜÁË£¬
»¹ÐèÒª¼ì²é /etc/auth.conf
ÖÐ crypt_default ¸ø³öµÄÓÅÏÈÑ¡ÔñµÄ¿ÚÁî¸ñʽ¡£
ÒªÍê³É´Ë¹¤×÷£¬ ½«ÄúÑ¡ÔñµÄ¸ñʽ·Åµ½ÁбíµÄµÚÒ»Ïî¡£ ÀýÈ磬
µ±Ê¹Óà DES ¼ÓÃܵĿÚÁîʱ£¬ ¶ÔÓ¦ÏîӦΪ£º
crypt_default = des blf md5
ÔÚÿһ̨»ùÓÚ &os; µÄ NIS ·þÎñÆ÷ºÍ¿Í»§»úÉÏÍê³ÉÉÏÊö¹¤×÷Ö®ºó£¬
¾Í¿ÉÒԿ϶¨ÄúµÄÍøÂçÉÏËüÃǶ¼ÔÚʹÓÃͬÑùµÄ¿ÚÁî¸ñʽÁË¡£ Èç¹ûÔÚ NIS
¿Í»§»úÉÏ×öÉí·ÝÑé֤ʱ·¢ÉúÎÊÌ⣬ ÕâÒ²ÊǵÚÒ»¸ö¿ÉÄܳöÏÖÎÊÌâµÄµØ·½¡£
×¢Ò⣺ Èç¹ûÄúÏ£ÍûÔÚ»ìºÏµÄÍøÂçÉϲ¿Êð NIS ·þÎñÆ÷£¬
¿ÉÄܾÍÐèÒªÔÚËùÓÐϵͳÉ϶¼Ê¹Óà DES£¬
ÒòΪÕâÊÇËùÓÐϵͳ¶¼Äܹ»Ö§³ÖµÄ×îµÍÏ޶ȵĹ«¹²±ê×¼¡£
Greg
Sutter
Written by
ÍøÂç×Ô¶¯ÅäÖà (DHCP)
ʲôÊÇ DHCP£¿
¶¯Ì¬Ö÷»úÅäÖÃÐÒé
DHCP
Internet Systems Consortium (ISC)
DHCP£¬ ¶¯Ì¬Ö÷»úÅäÖÃÐÒ飬 ÊÇÒ»ÖÖÈÃϵͳµÃÒÔÁ¬½Óµ½ÍøÂçÉÏ£¬
²¢»ñÈ¡ËùÐèÒªµÄÅäÖòÎÊýÊֶΡ£ FreeBSD ʹÓÃÀ´×Ô OpenBSD 3.7
µÄ OpenBSD dhclient¡£
ÕâÀïÌṩµÄËùÓйØÓÚ dhclient µÄÐÅÏ¢£¬
¶¼ÊÇÒÔ ISC »ò OpenBSD DHCP ¿Í»§¶Ë³ÌÐòΪ׼µÄ¡£ DHCP
·þÎñÆ÷ÊÇ ISC Èí¼þ°üµÄÒ»²¿·Ö¡£
ÕâÒ»½Ú¶¼½éÉÜÄÄЩÄÚÈÝ
ÕâÒ»½ÚÃèÊöÁË ISC ºÍ DHCP ϵͳÖеĿͻ§¶Ë£¬
ÒÔ¼°ºÍ ISC DHCP ϵͳÖеķþÎñÆ÷¶ËµÄ×é¼þ¡£
¿Í»§¶Ë³ÌÐò£¬ dhclient£¬
ÊÇËæ FreeBSD ×÷ΪËüµÄÒ»²¿·ÖÌṩµÄ£» ¶ø·þÎñÆ÷²¿·Ö£¬
Ôò¿ÉÒÔͨ¹ý net/isc-dhcp31-server port µÃµ½¡£
&man.dhclient.8;¡¢ &man.dhcp-options.5;¡¢ ÒÔ¼°
&man.dhclient.conf.5; Áª»úÊֲᣬ ¼ÓÉÏÏÂÃæËù½éÉܵIJο¼ÎÄÏ×£¬
¶¼ÊǷdz£ÓÐÓõÄ×ÊÔ´¡£
ËüÈçºÎ¹¤×÷
UDP
µ± DHCP ¿Í»§³ÌÐò£¬ dhclient
ÔÚ¿Í»§»úÉÏÔËÐÐʱ£¬ Ëü»á¿ªÊ¼¹ã²¥ÇëÇóÅäÖÃÐÅÏ¢µÄÏûÏ¢¡£ ĬÈÏÇé¿öÏ£¬
ÕâЩÇëÇóÊÇÔÚ UDP ¶Ë¿Ú 68 ÉÏ¡£ ·þÎñÆ÷ͨ¹ý UDP 67
¸ø³öÏìÓ¦£¬ Ïò¿Í»§»úÌṩһ¸ö IP µØÖ·£¬ ÒÔ¼°ÆäËûÓйصÄÅäÖòÎÊý£¬
ÀýÈç×ÓÍøÑÚÂë¡¢ ·ÓÉÆ÷£¬ ÒÔ¼° DNS ·þÎñÆ÷¡£
ËùÓÐÕâЩÐÅÏ¢¶¼»áÒÔ DHCP
lease
µÄÐÎʽ¸ø³ö£¬ ²¢ÇÒÖ»ÔÚÒ»¶ÎÌØ¶¨µÄʱ¼äÄÚÓÐЧ
(ÕâÊÇÓÉ DHCP ·þÎñÆ÷µÄά»¤ÕßÅäÖõÄ)¡£ ÕâÑù£¬
ÄÇЩÒѾ¶Ï¿ªÍøÂçµÄ¿Í»§»úʹÓÃµÄ³Â¾ÉµÄ IP µØÖ·¾ÍÄܱ»×Ô¶¯µØ»ØÊÕÁË¡£
DHCP ¿Í»§³ÌÐò¿ÉÒÔ´Ó·þÎñÆ÷¶Ë»ñÈ¡´óÁ¿µÄÐÅÏ¢¡£
¹ØÓÚÄÜ»ñµÃµÄÐÅÏ¢µÄÏêϸÁÐ±í£¬ Çë²Î¿¼
&man.dhcp-options.5;¡£
FreeBSD ¼¯³É
&os; ÍêÈ«µØ¼¯³ÉÁË OpenBSD µÄ DHCP ¿Í»§¶Ë£¬
dhclient¡£
DHCP ¿Í»§¶ËÖ§³ÖÔÚ°²×°³ÌÐòºÍ»ù±¾ÏµÍ³ÖоùÓÐÌṩ£¬
ÕâʹµÃÄú²»ÔÙÐèҪȥÁ˽âÄÇЩÒѾÔËÐÐÁË DHCP ·þÎñÆ÷µÄÍøÂçµÄ¾ßÌåÅäÖòÎÊý¡£
sysinstall
sysinstall Äܹ»Ö§³Ö DHCP¡£ ÔÚ
sysinstall ÖÐÅäÖÃÍøÂç½Ó¿Úʱ£¬
ËüѯÎʵĵڶþ¸öÎÊÌâ±ãÊÇ£º Do you want to try DHCP configuration of
the interface? (ÄúÊÇ·ñÏ£ÍûÔڴ˽ӿÚÉϳ¢ÊÔ DHCP ÅäÖÃ?)
¡£
Èç¹û×ö¿Ï¶¨µÄ»Ø´ð£¬ Ôò½«ÔËÐÐ dhclient£¬
Ò»µ©³É¹¦£¬ Ôò½«×Ô¶¯µØÌîÐ´ÍøÂçÅäÖÃÐÅÏ¢¡£
ÒªÔÚϵͳÆô¶¯Ê±Ê¹Óà DHCP£¬ Äú±ØÐë×öÁ½¼þÊ£º
DHCP
ÐèÇó
ÄúµÄÄÚºËÖУ¬ ±ØÐë°üº¬ bpf
É豸¡£ Èç¹ûÐèÒªÕâÑù×ö£¬ ÐèÒª½«
device bpf Ìí¼Óµ½Äں˵ıàÒëÅäÖÃÎļþÖУ¬ ²¢ÖØÐ±àÒëÄںˡ£
ÒªÁË½â¹ØÓÚ±àÒëÄں˵ĽøÒ»²½ÐÅÏ¢£¬ Çë²Î¼û ¡£ bpf
É豸ÒѾÊÇ FreeBSD ·¢ÐаæÖÐĬÈ쵀 GENERIC
Äں˵ÄÒ»²¿·ÖÁË£¬ Òò´ËÈç¹ûÄúûÓжÔÄں˽øÐж¨ÖÆ£¬
Ôò²»Óô´½¨Ò»·ÝеÄÄÚºËÅäÖÃÎļþ£¬ DHCP ¾ÍÄܹ¤×÷ÁË¡£
¶ÔÓÚÄÇЩ°²È«ÒâʶºÜÇ¿µÄÈËÀ´Ëµ£¬
ÄúÓ¦¸ÃÖªµÀ bpf
Ò²ÊǰüÕìÌý¹¤¾ßÄܹ»ÕýÈ·¹¤×÷µÄÌõ¼þÖ®Ò» (µ±È»£¬
ËüÃÇ»¹ÐèÒªÒÔ
root Éí·ÝÔËÐвÅÐÐ)¡£ bpf
ÊÇ Ê¹Óà DHCP Ëù±ØÐëµÄ£¬
µ«Èç¹ûÄú¶Ô°²È«·Ç³£Ãô¸Ð£¬
ÔòºÜ¿ÉÄÜ»áÓÐÀíÓɲ»°Ñ bpf
¼ÓÈëµ½ÄúµÄÄÚºËÅäÖÃÖУ¬ Ö±µ½ÄúÕæµÄÐèҪʹÓà DHCP
Ϊֹ¡£
±à¼ÄúµÄ /etc/rc.conf ²¢¼ÓÈëÏÂÃæµÄÉèÖãº
ifconfig_fxp0="DHCP"
Îñ±Ø½« fxp0
Ìæ»»ÎªÄúÏ£Íû×Ô¶¯ÅäÖõÄÍøÂç½Ó¿ÚµÄÃû×Ö£¬ Äú¿ÉÒÔÔÚ
ÕÒµ½¸ü½øÒ»²½µÄ½éÉÜ¡£
Èç¹ûÄúÏ£ÍûʹÓÃÁíһλÖõÄ
dhclient£¬
»òÕßÐèÒª¸ø dhclient ´«µÝÆäËû²ÎÊý£¬
»¹¿ÉÒÔÌí¼ÓÏÂÃæµÄÅäÖà (¸ù¾ÝÐèÒª½øÐÐÐÞ¸Ä)£º
dhclient_program="/sbin/dhclient"
dhclient_flags=""
DHCP
·þÎñÆ÷
DHCP ·þÎñÆ÷£¬ dhcpd£¬
ÊÇ×÷Ϊ net/isc-dhcp31-server port µÄÒ»²¿·ÖÌṩµÄ¡£
Õâ¸ö port °üÀ¨ÁË ISC DHCP ·þÎñÆ÷¼°ÆäÎĵµ¡£
Îļþ
DHCP
ÅäÖÃÎļþ
/etc/dhclient.conf
dhclient ÐèÒªÒ»¸öÅäÖÃÎļþ£¬
/etc/dhclient.conf¡£ Ò»°ã˵À´£¬
Õâ¸öÎļþÖÐÖ»°üÀ¨×¢ÊÍ£¬ ¶øÄ¬ÈÏÖµ»ù±¾É϶¼ÊǺÏÀíµÄ¡£
Õâ¸öÅäÖÃÎļþÔÚ &man.dhclient.conf.5; Áª»úÊÖ²áÖнøÐÐÁ˽øÒ»²½µÄ²ûÊö¡£
/sbin/dhclient
dhclient ÊÇÒ»¸ö¾²Ì¬Á¬±àµÄ£¬
Ëü±»°²×°µ½ /sbin ÖС£ &man.dhclient.8;
Áª»úÊÖ²á¸ø³öÁ˹ØÓÚ
dhclient µÄ½øÒ»²½Ï¸½Ú¡£
/sbin/dhclient-script
dhclient-script ÊÇÒ»¸ö FreeBSD רÓõÄ
DHCP ¿Í»§¶ËÅäÖýű¾¡£ ÔÚ
&man.dhclient-script.8; ÖжÔËü½øÐÐÁËÃèÊö£¬
µ«Ò»°ãÀ´Ëµ£¬ Óû§²»ÐèÒª¶ÔÆä½øÐÐÈκÎÐ޸ģ¬
¾ÍÄܹ»ÈÃÒ»ÇÐÕý³£ÔËתÁË¡£
/var/db/dhclient.leases
DHCP ¿Í»§³ÌÐò»áά»¤Ò»¸öÊý¾Ý¿âÀ´±£´æÓÐЧµÄ lease£¬
ËüÃDZ»ÒÔÈÕÖ¾µÄÐÎʽ±£´æµ½Õâ¸öÎļþÖС£ &man.dhclient.leases.5;
¸ø³öÁ˸üΪϸÖµĽéÉÜ¡£
½ø½×¶ÁÎï
DHCP ÐÒéµÄÍêÕûÃèÊöÊÇ
RFC 2131¡£
¹ØÓÚËüµÄÆäËûÐÅÏ¢×ÊÔ´µÄÕ¾µã
Ò²ÌṩÁËÏ꾡µÄ×ÊÁÏ¡£
°²×°ºÍÅäÖà DHCP ·þÎñÆ÷
ÕâÒ»Õ°üº¬ÄÄЩÄÚÈÝ
ÕâÒ»ÕÂÌṩÁ˹ØÓÚÈçºÎÔÚ FreeBSD ϵͳÉÏʹÓà ISC
(Internet ϵͳлá) µÄ DHCP ʵÏÖÌ×¼þÀ´¼ÜÉè DHCP ·þÎñÆ÷µÄÐÅÏ¢¡£
DHCP Ì×¼þÖеķþÎñÆ÷²¿·Ö²¢Ã»ÓÐ×÷Ϊ FreeBSD µÄÒ»²¿·ÖÀ´Ìṩ£¬
Òò´ËÄúÐèÒª°²×°
net/isc-dhcp31-server
port ²ÅÄÜÌṩÕâ¸ö·þÎñ¡£ Çë²Î¼û
ÒÔÁË½â¹ØÓÚÈçºÎʹÓà Ports Collection µÄ½øÒ»²½ÏêÇé¡£
°²×° DHCP ·þÎñÆ÷
DHCP
°²×°
ΪÁËÔÚÄúµÄ FreeBSD ϵͳÉϽøÐÐÅäÖÃÒÔ±ã×÷Ϊ DHCP ·þÎñÆ÷À´Ê¹Óã¬
ÐèÒª°Ñ &man.bpf.4; É豸±àÒë½øÄںˡ£ ÒªÍê³ÉÕâÏ×÷£¬ ÐèÒª½«
device bpf ¼ÓÈëµ½ÄúµÄÄÚºËÅäÖÃÎļþÖУ¬
²¢ÖØÐÂÁª±àÄںˡ£ ÒªµÃµ½¹ØÓÚÈçºÎÁª±àÄں˵ĽøÒ»²½ÐÅÏ¢£¬ Çë²Î¼û
¡£
bpf É豸ÊÇ FreeBSD Ëù¸½´øµÄ
GENERIC ÄÚºËÖÐÒѾÁªÈëµÄ×é¼þ£¬
Òò´ËÄú²¢²»ÐèҪΪÁËÈà DHCP Õý³£¹¤×÷¶øÌØ±ðµØ¶¨ÖÆÄںˡ£
Èç¹ûÄúÓнÏÇ¿µÄ°²È«Òâʶ£¬ Ó¦¸Ã×¢Òâ
bpf ͬʱҲÊÇÈÃÌý°ü³ÌÐòÄܹ»ÕýÈ·¹¤×÷µÄÉ豸
(¾¡¹ÜÕâÀà³ÌÐòÈÔÈ»ÐèÒªÒÔÌØÈ¨Óû§Éí·ÝÔËÐÐ)¡£
bpf
ÊÇ Ê¹Óà DHCP Ëù±ØÐèµÄ£¬
µ«Èç¹ûÄú¶Ô°²È«·Ç³£Ãô¸Ð£¬ Äú¿ÉÄܻ᲻ϣÍû½«
bpf ·Å½øÄںˣ¬
Ö±µ½ÄúÕæµÄÈÏΪ DHCP ÊDZØÐèµÄΪֹ¡£
½ÓÏÂÀ´Òª×öµÄÊDZà¼Ê¾·¶µÄ
dhcpd.conf£¬ ËüÓÉ
net/isc-dhcp31-server port
°²×°¡£ ĬÈÏÇé¿öÏ£¬ ËüµÄÃû×ÖÓ¦¸ÃÊÇ
/usr/local/etc/dhcpd.conf.sample£¬
ÔÚ¿ªÊ¼ÐÞ¸Ä֮ǰ£¬ ÄúÐèÒª°ÑËü¸´ÖÆÎª
/usr/local/etc/dhcpd.conf¡£
ÅäÖà DHCP ·þÎñÆ÷
DHCP
dhcpd.conf
dhcpd.conf °üº¬ÁËһϵÁйØÓÚ×ÓÍøºÍÖ÷»úµÄ¶¨Ò壬
ÏÂÃæµÄÀý×Ó¿ÉÒÔ°ïÖúÄúÀí½âËü£º
option domain-name "example.com";
option domain-name-servers 192.168.4.100;
option subnet-mask 255.255.255.0;
default-lease-time 3600;
max-lease-time 86400;
ddns-update-style none;
subnet 192.168.4.0 netmask 255.255.255.0 {
range 192.168.4.129 192.168.4.254;
option routers 192.168.4.1;
}
host mailhost {
hardware ethernet 02:03:04:05:06:07;
fixed-address mailhost.example.com;
}
Õâ¸öÑ¡ÏîÖ¸¶¨ÁËÌṩ¸ø¿Í»§»ú×÷ΪĬÈÏËÑË÷ÓòµÄÓòÃû¡£ Çë²Î¿¼
&man.resolv.conf.5; ÒÔÁË½â¹ØÓÚÕâÒ»¸ÅÄîµÄÏêÇé¡£
Õâ¸öÑ¡ÏîÓÃÓÚÖ¸¶¨Ò»×é¿Í»§»úʹÓÃµÄ DNS ·þÎñÆ÷£¬
ËüÃÇÖ®¼äÒÔ¶ººÅ·Ö¸ô¡£
Ìṩ¸ø¿Í»§»úµÄ×ÓÍøÑÚÂë¡£
¿Í»§»ú¿ÉÒÔÇëÇó×âÔ¼µÄÓÐЧÆÚ£¬ ¶øÈç¹ûûÓУ¬
Ôò·þÎñÆ÷½«Ö¸¶¨Ò»¸ö×âÔ¼ÓÐЧÆÚ£¬ Ò²¾ÍÊÇÕâ¸öÖµ (µ¥Î»ÊÇÃë)¡£
ÕâÊÇ·þÎñÆ÷ÔÊÐí×â³öµØÖ·µÄ×î´óʱ³¤¡£
Èç¹û¿Í»§»úÇëÇóÁ˸ü³¤µÄ×âÆÚ£¬ ÔòËü½«µÃµ½Ò»¸öµØÖ·£¬
µ«Æä×âÆÚ½öÏÞÓÚ max-lease-time Ãë¡£
Õâ¸öÑ¡ÏîÓÃÓÚÖ¸¶¨ DHCP ·þÎñÆ÷ÔÚÒ»¸öµØÖ·±»½ÓÊÜ»òÊÍ·ÅʱÊÇ·ñÓ¦¶ÔÓ¦³¢ÊÔ¸üÐÂ
DNS¡£ ÔÚ ISC ʵÏÖÖУ¬ ÕâһѡÏîÊÇ ±ØÐëÖ¸¶¨µÄ¡£
Ö¸¶¨µØÖ·³ØÖпÉÒÔÓÃÀ´·ÖÅ䏸¿Í»§»úµÄ IP µØÖ··¶Î§¡£
ÔÚÕâ¸ö·¶Î§Ö®¼ä£¬ ÒÔ¼°Æä±ß½çµÄ IP µØÖ·½«·ÖÅ䏸¿Í»§»ú¡£
¶¨Òå¿Í»§»úµÄĬÈÏÍø¹Ø¡£
Ö÷»úµÄÓ²¼þ MAC µØÖ· (ÕâÑù DHCP
·þÎñÆ÷¾ÍÄܹ»ÔÚ½Óµ½ÇëÇóʱ֪µÀÇëÇóµÄÖ÷»úÉí·Ý)¡£
Ö¸¶¨×ÜÊǵõ½Í¬Ò» IP µØÖ·µÄÖ÷»ú¡£
Çë×¢ÒâÔÚ´Ë´¦Ê¹ÓÃÖ÷»úÃûÊǶԵģ¬ ÒòΪ DHCP
·þÎñÆ÷»áÔÚ·µ»Ø×â½èµØÖ·ÐÅϢ֮ǰ×ÔÐнâÎöÖ÷»úÃû¡£
ÔÚÅäÖÆºÃ
dhcpd.conf Ö®ºó£¬ Ó¦ÔÚ
/etc/rc.conf ÖÐÆôÓà DHCP ·þÎñÆ÷£¬
Ò²¾ÍÊÇÔö¼Ó£º
dhcpd_enable="YES"
dhcpd_ifaces="dc0"
´Ë´¦µÄ dc0 ½Ó¿ÚÃûÓ¦¸ÄΪ DHCP
·þÎñÆ÷ÐèÒª¼àÌý DHCP ¿Í»§¶ËÇëÇóµÄ½Ó¿Ú (Èç¹ûÓжà¸ö£¬ ÔòÓÿոñ·Ö¿ª)¡£
½ÓÏÂÀ´£¬ ¿ÉÒÔÓÃÏÂÃæµÄÃüÁîÀ´Æô¶¯·þÎñ£º
&prompt.root; /usr/local/etc/rc.d/isc-dhcpd start
Èç¹ûδÀ´ÄúÐèÒªÐ޸ķþÎñÆ÷µÄÅäÖ㬠ÇëÎñ±ØÀμǷ¢ËÍ
SIGHUP ÐźŸø
dhcpd ²¢ ²»»á
µ¼ÖÂÅäÖÃÎļþµÄÖØÐ¼ÓÔØ£¬ ¶øÕâÔÚÆäËû·þÎñ³ÌÐòÖÐÔòÊÇ±È½ÏÆÕ±éµÄÔ¼¶¨¡£
ÄúÐèÒª·¢ËÍ SIGTERM ÐźÅÀ´Í£Ö¹½ø³Ì£¬
È»ºóʹÓÃÉÏÃæµÄÃüÁîÀ´ÖØÐÂÆô¶¯Ëü¡£
Îļþ
DHCP
ÅäÖÃÎļþ
/usr/local/sbin/dhcpd
dhcpd ÊǾ²Ì¬Á¬½ÓµÄ£¬ ²¢°²×°µ½
/usr/local/sbin ÖС£ Ëæ port °²×°µÄ
&man.dhcpd.8; Áª»úÊÖ²áÌṩÁ˹ØÓÚ
dhcpd ¸üΪÏ꾡µÄÐÅÏ¢¡£
/usr/local/etc/dhcpd.conf
dhcpd ÐèÒªÅäÖÃÎļþ£¬
¼´ /usr/local/etc/dhcpd.conf
²ÅÄܹ»Ïò¿Í»§»úÌṩ·þÎñ¡£ Õâ¸öÎļþÐèÒª°üÀ¨Ó¦Ìṩ¸ø¿Í»§»úµÄËùÓÐÐÅÏ¢£¬
ÒÔ¼°¹ØÓÚ·þÎñÆ÷ÔËÐÐµÄÆäËûÐÅÏ¢¡£ ´ËÅäÖÃÎļþµÄÏêϸÃèÊö¿ÉÒÔÔÚËæ port
°²×°µÄ &man.dhcpd.conf.5; Áª»úÊÖ²áÉÏÕÒµ½¡£
/var/db/dhcpd.leases
DHCP ·þÎñÆ÷»áά»¤Ò»¸öËüÇ©·¢µÄ×âÓõØÖ·Êý¾Ý¿â£¬
²¢±£´æÔÚÕâ¸öÎļþÖУ¬ Õâ¸öÎļþÊÇÒÔÈÕÖ¾µÄÐÎʽ±£´æµÄ¡£
Ëæ port °²×°µÄ
&man.dhcpd.leases.5; Áª»úÊÖ²áÌṩÁ˸üÏêϸµÄÃèÊö¡£
/usr/local/sbin/dhcrelay
dhcrelay ÔÚ¸üΪ¸´ÔӵĻ·¾³ÖУ¬
¿ÉÒÔÓÃÀ´Ö§³ÖʹÓà DHCP ·þÎñÆ÷ת·¢ÇëÇó¸øÁíÒ»¸ö¶ÀÁ¢ÍøÂçÉϵÄ
DHCP ·þÎñÆ÷¡£ Èç¹ûÄúÐèÒªÕâ¸ö¹¦ÄÜ£¬ ÐèÒª°²×° net/isc-dhcp31-relay port¡£
&man.dhcrelay.8; Áª»úÊÖ²áÌṩÁ˸üΪÏ꾡µÄ½éÉÜ¡£
Chern
Lee
Contributed by
Tom
Rhodes
Daniel
Gerzo
ÓòÃûϵͳ (DNS)
×ÝÀÀ
BIND
&os; ÔÚĬÈÏÇé¿öÏÂʹÓÃÒ»¸ö°æ±¾µÄ BIND (Berkeley
Internet Name Domain)£¬ ÕâÊÇĿǰ×îΪÁ÷ÐÐµÄ DNS ÐÒéʵÏÖ¡£
DNS ÊÇÒ»ÖÖÐÒ飬 ¿ÉÒÔͨ¹ýËü½«ÓòÃûͬ IP µØÖ·Ï໥¶ÔÓ¦¡£
ÀýÈ磬 ²éѯ www.FreeBSD.org
½«µÃµ½ &os; Project µÄ web ·þÎñÆ÷µÄ IP µØÖ·£¬ ¶ø²éѯ ftp.FreeBSD.org Ôò½«µÃµ½ÏìÓ¦µÄ FTP »úÆ÷µÄ
IP µØÖ·¡£ ÀàËÆµØ£¬ Ò²¿ÉÒÔ×öÏà·´µÄÊÂÇé¡£ ²éѯ IP
µØÖ·¿ÉÒԵõ½ÆäÖ÷»úÃû¡£ µ±È»£¬ Íê³É DNS
²éѯ²¢²»ÐèÒªÔÚϵͳÖÐÔËÐÐÓòÃû·þÎñÆ÷¡£
Ŀǰ£¬ ĬÈÏÇé¿öÏÂ&os; ʹÓõÄÊÇ BIND9
DNS ·þÎñÈí¼þ¡£ ÎÒÃÇÄÚ½¨ÓÚϵͳÖеİ汾ÌṩÁËÔöÇ¿µÄ°²È«ÌØÐÔ¡¢
еÄÎļþĿ¼½á¹¹£¬ ÒÔ¼°×Ô¶¯µÄ &man.chroot.8; ÅäÖá£
DNS
ÔÚ Internet É쵀 DNS ÊÇͨ¹ýÒ»Ì×½ÏΪ¸´ÔÓµÄȨÍþ¸ùÓòÃûϵͳ£¬
¶¥¼¶ÓòÃû (TLD)£¬ ÒÔ¼°Ò»ÏµÁÐС¹æÄ£µÄ£¬
ÌṩÉÙÁ¿ÓòÃû½âÎö·þÎñ²¢¶ÔÓòÃûÐÅÏ¢½øÐлº´æµÄÓòÃû·þÎñÆ÷×é³ÉµÄ¡£
Ŀǰ£¬ BIND ÓÉ
Internet Systems Consortium
ά»¤¡£
ÊõÓï
ÒªÀí½âÕâ·ÝÎĵµ£¬ ÐèÒªÊ×ÏÈÁ˽âһЩÏà¹ØµÄ
DNS ÊõÓï¡£
resolver (½âÎöÆ÷)
reverse DNS (·´Ïò DNS)
root zone (¸ùÓò)
ÊõÓï
¶¨Òå
ÕýÏò DNS
½«ÓòÃûÓ³Éäµ½ IP µØÖ·
﵋ (Origin)
±íÊ¾ÌØ¶¨ÓòÎļþËùÔÚµÄÓò
named, BIND
ÔÚ &os; ÖÐ BIND ÓòÃû·þÎñÆ÷Èí¼þ°üµÄ³£¼û½Ð·¨¡£
½âÎöÆ÷ (Resolver)
¼ÆËã»úÓÃÒÔÏòÓòÃû·þÎñÆ÷²éѯÓòÃûÐÅÏ¢µÄÒ»¸öϵͳ½ø³Ì
·´Ïò DNS
½« IP µØÖ·Ó³ÉäΪÖ÷»úÃû
¸ùÓò
Internet Óò²ã´ÎµÄÆðµã¡£ ËùÓеÄÓò¶¼ÔÚ¸ùÓò֮ϣ¬
ÀàËÆÎļþϵͳÖУ¬ Îļþ¶¼ÔÚ¸ùĿ¼֮ÏÂÄÇÑù¡£
Óò (Zone)
¶ÀÁ¢µÄÓò£¬ ×ÓÓò£¬ »òÕßÓÉͬһ»ú¹¹¹ÜÀíµÄ DNS µÄÒ»²¿·Ö¡£
Óò
Àý×Ó
ÓòµÄÀý×Ó£º
. ÔÚ±¾ÎĵµÖÐͨ³£Ö¸´ú¸ùÓò¡£
org. ÊǸùÓò֮ϵÄÒ»¸ö¶¥¼¶ÓòÃû
(TLD)¡£
example.org. ÊÇÔÚ
org.
TLD ֮ϵÄÒ»¸öÓò¡£
1.168.192.in-addr.arpa ÊÇÒ»¸ö±íʾËùÓÐ
192.168.1.*
IP µØÖ·¿Õ¼äÖÐ IP
µØÖ·µÄÓò¡£
ÈçÄúËù¼û£¬ ÓòÃûÖÐԽϸ½ÚµÄ²¿·Ö»áÔ½¿¿×ó³öÏÖ¡£ ÀýÈ磬 example.org. ¾Í±È
org. ·¶Î§¸üС£¬ ÀàËÆµØ org. ÓֱȸùÓò¸üС¡£
ÓòÃû¸÷¸ö²¿·ÖµÄ¸ñ¾ÖÓëÎļþϵͳʮ·ÖÀàËÆ£º
/dev Ŀ¼ÔÚ¸ùĿ¼֮Ï£¬ µÈµÈ¡£
ÔËÐÐÓòÃû·þÎñÆ÷µÄÀíÓÉ
ÓòÃû·þÎñÆ÷ͨ³£»áÓÐÁ½ÖÖÐÎʽ£º ȨÍþÓòÃû·þÎñÆ÷£¬
ÒÔ¼°»º´æÓòÃû·þÎñÆ÷¡£
ÏÂÁÐÇé¿öÐèÒªÓÐȨÍþÓòÃû·þÎñÆ÷£º
ÏëÒªÏòÈ«ÊÀ½çÌṩ DNS ÐÅÏ¢£¬
²¢¶ÔÇëÇó¸ø³öȨÍþÓ¦´ð¡£
×¢²áÁËÀàËÆ example.org
µÄÓò£¬ ¶øÐèÒª½« IP Ö¸¶¨µ½ÆäϵÄÖ÷»úÃûÉÏ¡£
ij¸ö IP µØÖ·¿éÐèÒª·´Ïò
DNS Ïî (IP µ½Ö÷»úÃû)¡£
±¸·Ý·þÎñÆ÷£¬ »ò³£ËµµÄ´Ó (slave) ·þÎñÆ÷£¬
»áÔÚÖ÷·þÎñÆ÷³öÏÖÎÊÌâ»òÎÞ·¨·ÃÎÊʱÀ´Ó¦´ð²éѯÇëÇó¡£
ÏÂÁÐÇé¿öÐèÒªÓлº´æÓòÃû·þÎñÆ÷£º
±¾µØµÄ DNS ·þÎñÆ÷Äܹ»»º´æ£¬
²¢±ÈÖ±½ÓÏòÍâ½çµÄÓòÃû·þÎñÆ÷ÇëÇó¸ü¿ìµØµÃµ½Ó¦´ð¡£
µ±ÓÐÈ˲éѯ www.FreeBSD.org ʱ£¬½âÎöÆ÷ͨ³£»áÏòÉϼ¶
ISP µÄÓòÃû·þÎñÆ÷·¢³öÇëÇó£¬ ²¢»ñµÃ»ØÓ¦¡£ Èç¹ûÓб¾µØµÄ»º´æ
DNS ·þÎñÆ÷£¬ ²éѯֻÓÐÔÚµÚÒ»´Î±»»º´æ DNS
·þÎñÆ÷·¢µ½ÍⲿÊÀ½ç¡£ ÆäËûµÄ²éѯ²»»á·¢Ïò¾ÖÓòÍøÍ⣬
ÒòΪËüÃÇÒѾÓÐÔÚ±¾µØµÄ»º´æÁË¡£
DNS ÈçºÎÔË×÷
ÔÚ &os; ÖУ¬ BIND ·þÎñ³ÌÐò±»³ÆÎª
named¡£
Îļþ
ÃèÊö
&man.named.8;
BIND ·þÎñ³ÌÐò
&man.rndc.8;
ÓòÃû·þÎñ¿ØÖƳÌÐò
/etc/namedb
BIND ´æ·ÅÓòÃûÐÅÏ¢µÄλÖá£
/etc/namedb/named.conf
ÓòÃû·þÎñÅäÖÃÎļþ
ËæÔÚ·þÎñÆ÷ÉÏÅäÖõÄÓòµÄÐÔÖʲ»Í¬£¬
ÓòµÄ¶¨ÒåÎļþÒ»°ã»á´æ·Åµ½
/etc/namedb Ŀ¼ÖÐµÄ master¡¢ slave£¬ »ò dynamic ×ÓĿ¼ÖС£
ÕâЩÎļþÖÐÌṩÁËÓòÃû·þÎñÆ÷ÔÚÏìÓ¦²éѯʱËùÐèÒªµÄ DNS ÐÅÏ¢¡£
Æô¶¯ BIND
BIND
starting (Æô¶¯)
ÓÉÓÚ BIND ÊÇĬÈϰ²×°µÄ£¬ Òò´ËÅäÖÃËüÏà¶Ô¶øÑԺܼòµ¥¡£
ĬÈ쵀 named ÅäÖ㬠ÊÇÔÚ
&man.chroot.8; »·¾³ÖÐÌṩ»ù±¾µÄÓòÃû½âÎö·þÎñ£¬
²¢ÇÒÖ»ÏÞÓÚ¼àÌý±¾µØ IPv4 »Ø»·µØÖ· (127.0.0.1)¡£
Èç¹ûÏ£ÍûÆô¶¯ÕâÒ»ÅäÖ㬠¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁ
&prompt.root; /etc/rc.d/named onestart
Èç¹ûÏ£Íû named
·þÎñÔÚÿ´ÎÆô¶¯µÄʱºò¶¼Äܹ»Æô¶¯£¬ ÐèÒªÔÚ
/etc/rc.conf ÖмÓÈ룺
named_enable="YES"
µ±È»£¬ ³ýÁËÕâ·ÝÎĵµËù½éÉܵÄÅäÖÃÑ¡ÏîÖ®Í⣬ ÔÚ
/etc/namedb/named.conf Öл¹ÓкܶàÆäËüµÄÑ¡Ïî¡£
²»¹ý£¬ Èç¹ûÄúÐèÒªÁ˽â &os; ÖÐÓÃÓÚÆô¶¯ named
µÄÄÇЩѡÏîµÄ»°£¬ Ôò¿ÉÒԲ鿴
/etc/defaults/rc.conf ÖеÄ
named_* ²ÎÊý£¬ ²¢²Î¿¼
&man.rc.conf.5; Áª»úÊֲᡣ ³ý´ËÖ®Í⣬
Ò²ÊÇÒ»¸ö²»´íµÄÆðµã¡£
ÅäÖÃÎļþ
BIND
configuration files (ÅäÖÃÎļþ)
Ŀǰ£¬ named µÄÅäÖÃÎļþ´æ·ÅÓÚ
/etc/namedb Ŀ¼£¬
ÔÚʹÓÃǰӦ¸ù¾ÝÐèÒª½øÐÐÐ޸ģ¬
³ý·ÇÄúÖ»´òËãÈÃËüÍê³É¼òµ¥µÄÓòÃû½âÎö·þÎñ¡£
Õâ¸öĿ¼ͬʱҲÊÇÄú½øÐоø´ó¶àÊýÅäÖõĵط½¡£
/etc/namedb/named.conf
// $FreeBSD$
//
// Refer to the named.conf(5) and named(8) man pages, and the documentation
// in /usr/share/doc/bind9 for more details.
//
// If you are going to set up an authoritative server, make sure you
// understand the hairy details of how DNS works. Even with
// simple mistakes, you can break connectivity for affected parties,
// or cause huge amounts of useless Internet traffic.
options {
// Relative to the chroot directory, if any
directory "/etc/namedb";
pid-file "/var/run/named/pid";
dump-file "/var/dump/named_dump.db";
statistics-file "/var/stats/named.stats";
// If named is being used only as a local resolver, this is a safe default.
// For named to be accessible to the network, comment this option, specify
// the proper IP address, or delete this option.
listen-on { 127.0.0.1; };
// If you have IPv6 enabled on this system, uncomment this option for
// use as a local resolver. To give access to the network, specify
// an IPv6 address, or the keyword "any".
// listen-on-v6 { ::1; };
// These zones are already covered by the empty zones listed below.
// If you remove the related empty zones below, comment these lines out.
disable-empty-zone "255.255.255.255.IN-ADDR.ARPA";
disable-empty-zone "0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA";
disable-empty-zone "1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.IP6.ARPA";
// If you've got a DNS server around at your upstream provider, enter
// its IP address here, and enable the line below. This will make you
// benefit from its cache, thus reduce overall DNS traffic in the Internet.
/*
forwarders {
127.0.0.1;
};
*/
// If the 'forwarders' clause is not empty the default is to 'forward first'
// which will fall back to sending a query from your local server if the name
// servers in 'forwarders' do not have the answer. Alternatively you can
// force your name server to never initiate queries of its own by enabling the
// following line:
// forward only;
// If you wish to have forwarding configured automatically based on
// the entries in /etc/resolv.conf, uncomment the following line and
// set named_auto_forward=yes in /etc/rc.conf. You can also enable
// named_auto_forward_only (the effect of which is described above).
// include "/etc/namedb/auto_forward.conf";
ÕýÈç×¢ÊÍËùÑÔ£¬ Èç¹ûÏ£Íû´ÓÉϼ¶»º´æÖÐÊÜÒæ£¬
¿ÉÒÔÔÚ´Ë´¦ÆôÓà forwarders¡£
Õý³£Çé¿öÏ£¬ ÓòÃû·þÎñÆ÷»áÖ𼶵زéѯ
Internet À´ÕÒµ½Ìض¨µÄÓòÃû·þÎñÆ÷£¬ Ö±µ½µÃµ½´ð°¸ÎªÖ¹¡£
Õâ¸öÑ¡ÏÈÃËüÊ×ÏȲéѯÉϼ¶ÓòÃû·þÎñÆ÷ (»òÁíÍâÌṩµÄÓòÃû·þÎñÆ÷)£¬
´Ó¶ø´ÓËüÃǵĻº´æÖеõ½½á¹û¡£ Èç¹ûÉϼ¶ÓòÃû·þÎñÆ÷ÊÇÒ»¸ö·±Ã¦µÄ¸ßËÙÓòÃû·þÎñÆ÷£¬
ÔòÆôÓÃËü½«ÓÐÖúÓÚ¸ÄÉÆ·þÎñÆ·ÖÊ¡£
127.0.0.1
²»»á Õý³£¹¤×÷¡£
Ò»¶¨Òª°ÑµØÖ·¸ÄΪÄúÉϼ¶·þÎñÆ÷µÄ IP µØÖ·¡£
/*
Modern versions of BIND use a random UDP port for each outgoing
query by default in order to dramatically reduce the possibility
of cache poisoning. All users are strongly encouraged to utilize
this feature, and to configure their firewalls to accommodate it.
AS A LAST RESORT in order to get around a restrictive firewall
policy you can try enabling the option below. Use of this option
will significantly reduce your ability to withstand cache poisoning
attacks, and should be avoided if at all possible.
Replace NNNNN in the example with a number between 49160 and 65530.
*/
// query-source address * port NNNNN;
};
// If you enable a local name server, don't forget to enter 127.0.0.1
// first in your /etc/resolv.conf so this server will be queried.
// Also, make sure to enable it in /etc/rc.conf.
// The traditional root hints mechanism. Use this, OR the slave zones below.
zone "." { type hint; file "named.root"; };
/* Slaving the following zones from the root name servers has some
significant advantages:
1. Faster local resolution for your users
2. No spurious traffic will be sent from your network to the roots
3. Greater resilience to any potential root server failure/DDoS
On the other hand, this method requires more monitoring than the
hints file to be sure that an unexpected failure mode has not
incapacitated your server. Name servers that are serving a lot
of clients will benefit more from this approach than individual
hosts. Use with caution.
To use this mechanism, uncomment the entries below, and comment
the hint zone above.
*/
/*
zone "." {
type slave;
file "slave/root.slave";
masters {
192.5.5.241; // F.ROOT-SERVERS.NET.
};
notify no;
};
zone "arpa" {
type slave;
file "slave/arpa.slave";
masters {
192.5.5.241; // F.ROOT-SERVERS.NET.
};
notify no;
};
zone "in-addr.arpa" {
type slave;
file "slave/in-addr.arpa.slave";
masters {
192.5.5.241; // F.ROOT-SERVERS.NET.
};
notify no;
};
*/
/* Serving the following zones locally will prevent any queries
for these zones leaving your network and going to the root
name servers. This has two significant advantages:
1. Faster local resolution for your users
2. No spurious traffic will be sent from your network to the roots
*/
// RFC 1912
zone "localhost" { type master; file "master/localhost-forward.db"; };
zone "127.in-addr.arpa" { type master; file "master/localhost-reverse.db"; };
zone "255.in-addr.arpa" { type master; file "master/empty.db"; };
// RFC 1912-style zone for IPv6 localhost address
zone "0.ip6.arpa" { type master; file "master/localhost-reverse.db"; };
// "This" Network (RFCs 1912 and 3330)
zone "0.in-addr.arpa" { type master; file "master/empty.db"; };
// Private Use Networks (RFC 1918)
zone "10.in-addr.arpa" { type master; file "master/empty.db"; };
zone "16.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "17.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "18.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "19.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "20.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "21.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "22.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "23.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "24.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "25.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "26.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "27.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "28.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "29.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "30.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "31.172.in-addr.arpa" { type master; file "master/empty.db"; };
zone "168.192.in-addr.arpa" { type master; file "master/empty.db"; };
// Link-local/APIPA (RFCs 3330 and 3927)
zone "254.169.in-addr.arpa" { type master; file "master/empty.db"; };
// TEST-NET for Documentation (RFC 3330)
zone "2.0.192.in-addr.arpa" { type master; file "master/empty.db"; };
// Router Benchmark Testing (RFC 3330)
zone "18.198.in-addr.arpa" { type master; file "master/empty.db"; };
zone "19.198.in-addr.arpa" { type master; file "master/empty.db"; };
// IANA Reserved - Old Class E Space
zone "240.in-addr.arpa" { type master; file "master/empty.db"; };
zone "241.in-addr.arpa" { type master; file "master/empty.db"; };
zone "242.in-addr.arpa" { type master; file "master/empty.db"; };
zone "243.in-addr.arpa" { type master; file "master/empty.db"; };
zone "244.in-addr.arpa" { type master; file "master/empty.db"; };
zone "245.in-addr.arpa" { type master; file "master/empty.db"; };
zone "246.in-addr.arpa" { type master; file "master/empty.db"; };
zone "247.in-addr.arpa" { type master; file "master/empty.db"; };
zone "248.in-addr.arpa" { type master; file "master/empty.db"; };
zone "249.in-addr.arpa" { type master; file "master/empty.db"; };
zone "250.in-addr.arpa" { type master; file "master/empty.db"; };
zone "251.in-addr.arpa" { type master; file "master/empty.db"; };
zone "252.in-addr.arpa" { type master; file "master/empty.db"; };
zone "253.in-addr.arpa" { type master; file "master/empty.db"; };
zone "254.in-addr.arpa" { type master; file "master/empty.db"; };
// IPv6 Unassigned Addresses (RFC 4291)
zone "1.ip6.arpa" { type master; file "master/empty.db"; };
zone "3.ip6.arpa" { type master; file "master/empty.db"; };
zone "4.ip6.arpa" { type master; file "master/empty.db"; };
zone "5.ip6.arpa" { type master; file "master/empty.db"; };
zone "6.ip6.arpa" { type master; file "master/empty.db"; };
zone "7.ip6.arpa" { type master; file "master/empty.db"; };
zone "8.ip6.arpa" { type master; file "master/empty.db"; };
zone "9.ip6.arpa" { type master; file "master/empty.db"; };
zone "a.ip6.arpa" { type master; file "master/empty.db"; };
zone "b.ip6.arpa" { type master; file "master/empty.db"; };
zone "c.ip6.arpa" { type master; file "master/empty.db"; };
zone "d.ip6.arpa" { type master; file "master/empty.db"; };
zone "e.ip6.arpa" { type master; file "master/empty.db"; };
zone "0.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "1.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "2.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "3.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "4.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "5.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "6.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "7.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "8.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "9.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "a.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "b.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "0.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "1.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "2.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "3.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "4.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "5.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "6.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "7.e.f.ip6.arpa" { type master; file "master/empty.db"; };
// IPv6 ULA (RFC 4193)
zone "c.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "d.f.ip6.arpa" { type master; file "master/empty.db"; };
// IPv6 Link Local (RFC 4291)
zone "8.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "9.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "a.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "b.e.f.ip6.arpa" { type master; file "master/empty.db"; };
// IPv6 Deprecated Site-Local Addresses (RFC 3879)
zone "c.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "d.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "e.e.f.ip6.arpa" { type master; file "master/empty.db"; };
zone "f.e.f.ip6.arpa" { type master; file "master/empty.db"; };
// IP6.INT is Deprecated (RFC 4159)
zone "ip6.int" { type master; file "master/empty.db"; };
// NB: Do not use the IP addresses below, they are faked, and only
// serve demonstration/documentation purposes!
//
// Example slave zone config entries. It can be convenient to become
// a slave at least for the zone your own domain is in. Ask
// your network administrator for the IP address of the responsible
// master name server.
//
// Do not forget to include the reverse lookup zone!
// This is named after the first bytes of the IP address, in reverse
// order, with ".IN-ADDR.ARPA" appended, or ".IP6.ARPA" for IPv6.
//
// Before starting to set up a master zone, make sure you fully
// understand how DNS and BIND work. There are sometimes
// non-obvious pitfalls. Setting up a slave zone is usually simpler.
//
// NB: Don't blindly enable the examples below. :-) Use actual names
// and addresses instead.
/* An example dynamic zone
key "exampleorgkey" {
algorithm hmac-md5;
secret "sf87HJqjkqh8ac87a02lla==";
};
zone "example.org" {
type master;
allow-update {
key "exampleorgkey";
};
file "dynamic/example.org";
};
*/
/* Example of a slave reverse zone
zone "1.168.192.in-addr.arpa" {
type slave;
file "slave/1.168.192.in-addr.arpa";
masters {
192.168.1.1;
};
};
*/
ÔÚ named.conf ÖУ¬
»¹¸ø³öÁË´ÓÓò¡¢×ª·¢ÓòºÍ·´½âÎöÓòµÄÀý×Ó¡£
Èç¹ûÐÂÔöÁËÓò£¬ ¾Í±ØÐèÔÚ named.conf ÖмÓÈë¶ÔÓ¦µÄÏîÄ¿¡£
ÀýÈ磬 ÓÃÓÚ
example.org µÄÓòÎļþµÄÃèÊöÀàËÆÏÂÃæÕâÑù£º
zone "example.org" {
type master;
file "master/example.org";
};
Èç Óï¾äËù±êʾµÄÄÇÑù£¬
ÕâÊÇÒ»¸öÖ÷Óò£¬ ÆäÐÅÏ¢±£´æÔÚ
/etc/namedb/master/example.org
ÖУ¬ Èç Óï¾äËùʾ¡£
zone "example.org" {
type slave;
file "slave/example.org";
};
ÔÚ´ÓÓòµÄÇéÐÎÖУ¬ ËùÖ¸¶¨µÄÓòµÄÐÅÏ¢»á´ÓÖ÷ÓòÃû·þÎñÆ÷´«µÝ¹ýÀ´£¬
²¢±£´æµ½¶ÔÓ¦µÄÎļþÖС£ µ±Ö÷Óò·þÎñÆ÷·¢ÉúÎÊÌâ»ò²»¿É´ïʱ£¬
´ÓÓòÃû·þÎñÆ÷¾ÍÓÐÒ»·Ý¿ÉÓõÄÓòÃûÐÅÏ¢£¬ ´Ó¶øÄܹ»¶ÔÍâÌṩ·þÎñ¡£
ÓòÎļþ
BIND
zone files (ÓòÎļþ)
ÏÂÃæµÄÀý×ÓչʾÁËÓÃÓÚ example.org µÄÖ÷ÓòÎļþ (´æ·ÅÓÚ
/etc/namedb/master/example.org)£º
$TTL 3600 ; 1 hour default TTL
example.org. IN SOA ns1.example.org. admin.example.org. (
2006051501 ; Serial
10800 ; Refresh
3600 ; Retry
604800 ; Expire
300 ; Negative Reponse TTL
)
; DNS Servers
IN NS ns1.example.org.
IN NS ns2.example.org.
; MX Records
IN MX 10 mx.example.org.
IN MX 20 mail.example.org.
IN A 192.168.1.1
; Machine Names
localhost IN A 127.0.0.1
ns1 IN A 192.168.1.2
ns2 IN A 192.168.1.3
mx IN A 192.168.1.4
mail IN A 192.168.1.5
; Aliases
www IN CNAME example.org.
Çë×¢ÒâÒÔ .
½áβµÄÖ÷»úÃûÊÇÈ«³ÆÖ÷»úÃû£¬ ¶ø½áβûÓÐ
.
µÄÔòÊÇÏà¶ÔÓÚÔµãµÄÖ÷»úÃû¡£ ÀýÈ磬
ns1 ½«±»×ª»»Îª
ns1.example.org.
ÓòÐÅÏ¢ÎļþµÄ¸ñʽÈçÏ£º
¼Ç¼Ãû IN ¼Ç¼ÀàÐÍ Öµ
DNS
¼Ç¼
×î³£ÓÃµÄ DNS ¼Ç¼£º
SOA
ÓòȨÍþ¿ªÊ¼
NS
ȨÍþÓòÃû·þÎñÆ÷
A
Ö÷»úµØÖ·
CNAME
±ðÃû¶ÔÓ¦µÄÕý¹æÃû³Æ
MX
Óʼþ´«µÝ·þÎñÆ÷
PTR
ÓòÃûÖ¸Õë (ÓÃÓÚ·´Ïò DNS)
example.org. IN SOA ns1.example.org. admin.example.org. (
2006051501 ; Serial
10800 ; Refresh after 3 hours
3600 ; Retry after 1 hour
604800 ; Expire after 1 week
300 ) ; Negative Reponse TTL
example.org.
ÓòÃû£¬ ͬʱҲÊÇÕâ¸öÓòÐÅÏ¢ÎļþµÄԵ㡣
ns1.example.org.
¸ÃÓòµÄÖ÷/ȨÍþÓòÃû·þÎñÆ÷¡£
admin.example.org.
´ËÓòµÄ¸ºÔðÈ˵ĵç×ÓÓʼþµØÖ·£¬
ÆäÖÐ @
ÐèÒª»»µô (admin@example.org ¶ÔÓ¦
admin.example.org)
2006051501
ÎļþµÄÐòºÅ¡£ ÿ´ÎÐÞ¸ÄÓòÎļþʱ¶¼±ØÐëÔö¼ÓÕâ¸öÊý×Ö¡£
ÏÖ½ñ£¬ Ðí¶à¹ÜÀíÔ±»á¿¼ÂÇʹÓÃ
yyyymmddrr ÕâÑùµÄ¸ñʽÀ´±íʾÐòºÅ¡£
2006051501 ͨ³£±íʾÉÏ´ÎÐÞ¸ÄÓÚ
05/15/2006£¬ ¶øºóÃæµÄ
01 Ôò±íʾÔÚÄÇÌìµÄµÚÒ»´ÎÐ޸ġ£
ÐòºÅ·Ç³£ÖØÒª£¬ ËüÓÃÓÚ֪ͨ´ÓÓò·þÎñÆ÷¸üÐÂÊý¾Ý¡£
IN NS ns1.example.org.
ÕâÊÇÒ»¸ö NS Ïî¡£ ÿ¸ö×¼±¸ÌṩȨÍþÓ¦´ðµÄ·þÎñÆ÷¶¼±ØÐëÓÐÒ»¸ö¶ÔÓ¦Ïî¡£
localhost IN A 127.0.0.1
ns1 IN A 192.168.1.2
ns2 IN A 192.168.1.3
mx IN A 192.168.1.4
mail IN A 192.168.1.5
A ¼Ç¼ָÃ÷ÁË»úÆ÷Ãû¡£ ÕýÈçÔÚÇ°ÃæËù¿´µ½µÄ£¬
ns1.example.org ½«½âÎöΪ
192.168.1.2¡£
IN A 192.168.1.1
ÕâÒ»Ðаѵ±Ç°Ôµã example.org
Ö¸¶¨ÎªÊ¹Óà IP µØÖ·
192.168.1.1¡£
www IN CNAME @
Õý¹æÃû (CNAME) ¼Ç¼ͨ³£ÓÃÓÚΪij̨»úÆ÷Ö¸¶¨±ðÃû¡£
ÔÚÕâ¸öÀý×ÓÖУ¬ ½« www
Ö¸¶¨³ÉÁË Ö÷
»úÆ÷µÄÒ»¸ö±ðÃû£¬
ºóÕßµÄÃû×ÖÓëÓòÃû
example.org
(192.168.1.1) Ïàͬ¡£
CNAME ²»ÄÜͬÓëÖ®ÓÐÏàͬÃû×ÖµÄÈÎºÎÆäËü¼Ç¼²¢´æ¡£
MX ¼Ç¼
IN MX 10 mail.example.org.
MX ¼Ç¼±íʾÄĸöÓʼþ·þÎñÆ÷¸ºÔð½ÓÊÕ·¢µ½Õâ¸öÓòµÄÓʼþ¡£
mail.example.org ÊÇÓʼþ·þÎñÆ÷µÄÖ÷»úÃû£¬
¶ø 10 ÔòÊÇËüµÄÓÅÏȼ¶¡£
¿ÉÒÔÓжą̀Óʼþ·þÎñÆ÷£¬ ÆäÓÅÏȼ¶·Ö±ðÊÇ 10¡¢
20 µÈµÈ¡£ ³¢ÊÔÏò example.org ͶµÝÓʼþµÄ·þÎñÆ÷£¬
»áÊ×Ïȳ¢ÊÔÓÅÏȼ¶×î¸ßµÄ MX (ÓÅÏȼ¶ÊýÖµ×îСµÄ¼Ç¼)¡¢
½Ó×ų¢ÊԴθߵģ¬ ²¢Öظ´ÕâÒ»¹ý³ÌÖ±µ½ÓʼþµÝ´ïΪֹ¡£
in-addr.arpa ÓòÃûÐÅÏ¢Îļþ (·´Ïò DNS)£¬ ²ÉÓõĸñʽÊÇͬÑùµÄ£¬
Ö»ÊÇ PTR Ïî´úÌæÁË A »ò CNAME µÄλÖá£
$TTL 3600
1.168.192.in-addr.arpa. IN SOA ns1.example.org. admin.example.org. (
2006051501 ; Serial
10800 ; Refresh
3600 ; Retry
604800 ; Expire
300 ) ; Negative Reponse TTL
IN NS ns1.example.org.
IN NS ns2.example.org.
1 IN PTR example.org.
2 IN PTR ns1.example.org.
3 IN PTR ns2.example.org.
4 IN PTR mx.example.org.
5 IN PTR mail.example.org.
Õâ¸öÎļþ¸ø³öÁËÉÏÊö¼ÙÏëÓòÖÐ IP µØÖ·µ½ÓòÃûµÄÓ³Éä¹ØÏµ¡£
ÐèҪ˵Ã÷µÄÊÇ£¬ ÔÚ PTR ¼Ç¼ÓÒ²àµÄÃû×Ö±ØÐëÊÇÈ«³ÆÓòÃû
(Ò²¾ÍÊDZØÐëÒÔ .
½áÊø)¡£
»º´æÓòÃû·þÎñÆ÷
BIND
»º´æÓòÃû·þÎñÆ÷
»º´æÓòÃû·þÎñÆ÷ÊÇÒ»ÖÖÖ÷Òª³Ðµ£½âÎöµÝ¹é²éѯ½ÇÉ«µÄÓòÃû·þÎñÆ÷¡£
Ëü¼òµ¥µØ×ÔÐнøÐвéѯ£¬ ²¢½«²éѯ½á¹û¼ÇסÒÔ±¸ºóÐøÊ¹Óá£
°²È«
¾¡¹Ü BIND ÊÇ×îΪ³£ÓÃµÄ DNS ʵÏÖ£¬ µ«Ëü×ÜÊÇÓÐһЩ°²È«ÎÊÌâ¡£
ʱ³£»áÓÐÈË·¢ÏÖһЩ¿ÉÄܵÄÉõÖÁ¿ÉÒÔÀûÓõݲȫ©¶´¡£
¾¡¹Ü &os; »á×Ô¶¯½«
named ·Åµ½ &man.chroot.8;
»·¾³ÖÐÔËÐУ¬ µ«ÈÔÓÐһЩÆäËü¿ÉÓõݲȫ»úÖÆÀ´°ïÖúÄú¹æ±ÜDZÔÚµÄÕë¶Ô
DNS ·þÎñµÄ¹¥»÷¡£
ÔĶÁ CERT µÄ°²È«¹«¸æ£¬
²¢¶©ÔÄ the &a.security-notifications; ÊÇÒ»¸öÓÐÖúÓÚ°ïÖúÄúÁ˽â×îÐÂ
Internet ¼° &os; °²È«ÎÊÌâµÄºÃϰ¹ß¡£
Èç¹û·¢ÏÖÁËÎÊÌ⣬ È·±£Ô´´úÂëÊÇ×îеģ¬
²¢ÖØÐÂÁª±àÒ»·Ý named ÓпÉÄÜ»áÓÐËù°ïÖú¡£
½øÒ»²½ÔĶÁ
BIND/named Áª»úÊֲ᣺
&man.rndc.8; &man.named.8; &man.named.conf.5;
¹Ù·½µÄ ISC BIND
Ò³Ãæ
Official ISC BIND
Forum
O'Reilly
DNS ºÍ BIND µÚ 5 °æ
RFC1034
- ÓòÃû - ¸ÅÄîºÍ¹¤¾ß
RFC1035
- ÓòÃû - ʵÏÖ¼°Æä±ê×¼
Murray
Stokely
Contributed by
Apache HTTP ·þÎñÆ÷
web ·þÎñÆ÷
ÅäÖÃ
Apache
×ÝÀÀ
&os; ±»ÓÃÓÚÔËÐÐÐí¶àÈ«Çò×îΪ·±Ã¦µÄ web Õ¾µã¡£
´ó¶àÊý Internet É쵀 web ·þÎñÆ÷£¬
¶¼Ê¹Óà Apache HTTP ·þÎñÆ÷¡£
Apache Èí¼þ°ü¿ÉÒÔÔÚÄúµÄ FreeBSD
°²×°ÅÌÉÏÕÒµ½¡£ Èç¹ûûÓÐÔÚÊ״ΰ²×°Ê±¸½´ø°²×°
Apache£¬ Ôò¿ÉÒÔͨ¹ý www/apache13 »ò www/apache22 port À´°²×°¡£
Ò»µ©³É¹¦µØ°²×°ÁË Apache£¬
¾Í±ØÐë¶ÔÆä½øÐÐÅäÖá£
ÕâÒ»½Ú½éÉÜÁË 1.3.X °æ±¾µÄ
Apache HTTP ·þÎñÆ÷ µÄÅäÖã¬
ÒòΪËüÊÇËæ &os; һͬʹÓõÄ×î¶àµÄ°æ±¾¡£
Apache 2.X ÒýÈëÁ˺ܶàм¼Êõ£¬
µ«Ôڴ˲¢²»ÌÖÂÛ¡£ ÒªÁË½â¹ØÓÚ Apache 2.X
µÄ¸ü¶à×ÊÁÏ£¬ Çë²Î¼û ¡£
ÅäÖÃ
Apache
ÅäÖÃÎļþ
Ö÷ÒªµÄ Apache HTTP Server ÅäÖÃÎļþ£¬
ÔÚ &os; ÉϻᰲװΪ
/usr/local/etc/apache/httpd.conf¡£
ÕâÊÇÒ»¸öµäÐ굀 &unix; Îı¾ÅäÖÃÎļþ£¬ ËüʹÓà #
×÷ΪעÊÍ·û¡£ ¹ØÓÚÈ«²¿ÅäÖÃÑ¡ÏîµÄÏ꾡½éÉܳ¬³öÁ˱¾ÊéµÄ·¶Î§£¬
ÕâÀォֻ½éÉÜ×î³£±»Ð޸ĵÄÄÇЩ¡£
ServerRoot "/usr/local"
ÕâÖ¸¶¨ÁË Apache
°²×°µÄ¶¥¼¶Ä¿Â¼¡£ Ö´ÐÐÎļþ±»·Åµ½·þÎñÆ÷¸ùĿ¼ (server root) µÄ
bin ºÍ
sbin ×ÓĿ¼ÖУ¬
¶øÅäÖÃÎļþÔòλÓÚ
etc/apache¡£
ServerAdmin you@your.address
Õâ¸öµØÖ·ÊÇÔÚ·þÎñÆ÷·¢ÉúÎÊÌâʱӦ·¢Ë͵ç×ÓÓʼþµÄµØÖ·£¬
Ëü»á³öÏÖÔÚ·þÎñÆ÷Éú³ÉµÄÒ³ÃæÉÏ£¬ ÀýÈç´íÎóÒ³Ãæ¡£
ServerName www.example.com
ServerName ÔÊÐíÄúÅäÖ÷¢Ëͻؿͻ§¶ËµÄÖ÷»úÃû£¬
Èç¹ûÄúµÄ·þÎñÆ÷±»Óû§ÒÔ±ðµÄÃû×Ö·ÃÎÊ (ÀýÈ磬 ʹÓà www
¶ø²»ÊÇÖ÷»ú±¾ÉíµÄÕæÊµÃû×Ö)¡£
DocumentRoot "/usr/local/www/data"
DocumentRoot£º Õâ¸öĿ¼ÊÇÄúµÄÎĵµËùÔÚµÄĿ¼¡£
ĬÈÏÇé¿öÏ£¬ ËùÓеÄÇëÇó¶¼»á´ÓÕâ¸öλÖÃÈ¥»ñÈ¡£¬
µ«Ò²¿ÉÒÔͨ¹ý·ûºÅÁ¬½ÓºÍ±ðÃûÖ¸¶¨ÆäËüµÄλÖá£
ÔÚÐÞ¸ÄÅäÖÃ֮ǰ±¸·Ý
Apache µÄÅäÖÃÎļþÓÀÔ¶ÊÇÒ»¸öºÃϰ¹ß¡£
Ò»µ©¶Ô³õʼÅäÖÃÂúÒâÁË£¬ ¾Í¿ÉÒÔ¿ªÊ¼ÔËÐÐ Apache ÁË¡£
ÔËÐÐ Apache
Apache
Æô¶¯ºÍÍ£Ö¹
ÓëÐí¶àÆäËüÍøÂç·þÎñ²»Í¬£¬ Apache ²¢²»ÒÀÀµ
inetd ³¬¼¶·þÎñÆ÷À´ÔËÐС£
Ò»°ãÇé¿öÏ»á°ÑËüÅäÖÃΪһ¸ö¶ÀÁ¢µÄ·þÎñÆ÷£¬ ÒÔÆÚÔÚ¿Í»§µÄ web
ä¯ÀÀÆ÷Á¬Èë HTTP ÇëÇóʱ£¬ Äܹ»»ñµÃ¸üºÃµÄÐÔÄÜ¡£ ËüÌṩÁËÒ»¸ö shell
½Å±¾À´Ê¹Æô¶¯¡¢ Í£Ö¹ºÍÖØÐÂÆô¶¯·þÎñÆ÷±äµÃ¾¡¿ÉÄܵؼòµ¥¡£
Ê×´ÎÆô¶¯ Apache£¬
Ö»ÐèÖ´ÐУº
&prompt.root; /usr/local/sbin/apachectl start
¿ÉÒÔÔÚÈκÎʱºòʹÓÃÏÂÃæµÄÃüÁîÀ´Í£Ö¹·þÎñ£º
&prompt.root; /usr/local/sbin/apachectl stop
µ±ÓÉÓÚijÖÖÔÒòÐÞ¸ÄÁËÅäÖÃÎļþÖ®ºó£¬ ÐèÒªÖØÆô·þÎñÆ÷£º
&prompt.root; /usr/local/sbin/apachectl restart
ÒªÔÚÖØÆô Apache ·þÎñÆ÷ʱ²»Öжϵ±Ç°µÄÁ¬½Ó£¬
ÔòÓ¦ÔËÐУº
&prompt.root; /usr/local/sbin/apachectl graceful
¸ü¶àµÄÐÅÏ¢£¬ ¿ÉÒÔÔÚ
&man.apachectl.8; Áª»úÊÖ²áÖÐÕÒµ½¡£
ÒªÔÚϵͳÆô¶¯Ê±Æô¶¯ Apache£¬ ÔòÓ¦ÔÚ
/etc/rc.conf ÖмÓÈ룺
apache_enable="YES"
»òÕß¶ÔÓÚApache 2.2£º
apache22_enable="YES"
Èç¹ûÄúÏ£ÍûÔÚϵͳÒýµ¼Ê±Æô¶¯ Apache
httpd ³ÌÐò²¢Ö¸¶¨ÆäËüһЩѡÏ
Ôò¿ÉÒÔ°ÑÏÂÃæµÄÐмӵ½
rc.conf£º
apache_flags=""
ÏÖÔÚ web ·þÎñÆ÷¾Í¿ªÊ¼ÔËÐÐÁË£¬ Äú¿ÉÒÔʹÓà web ä¯ÀÀÆ÷´ò¿ª
http://localhost/¡£ ĬÈÏÏÔʾµÄ web Ò³ÃæÊÇ
/usr/local/www/data/index.html¡£
ÐéÄâÖ÷»ú
Apache Ö§³ÖÁ½ÖÖ²»Í¬ÀàÐ͵ÄÐéÄâÖ÷»ú¡£
µÚÒ»ÖÖ·½·¨ÊÇ»ùÓÚÃû×ÖµÄÐéÄâÖ÷»ú¡£ »ùÓÚÃû×ÖµÄÐéÄâÖ÷»úʹÓÿͻ§»ú·¢À´µÄ
HTTP/1.1 Í·À´±æ±ðÖ÷»úÃû¡£ ÕâʹµÃ²»Í¬µÄÓòµÃÒÔ¹²Ïíͬһ¸ö IP µØÖ·¡£
ÒªÅäÖà Apache À´Ê¹ÓûùÓÚÃû×ÖµÄÐéÄâÖ÷»ú£¬
ÐèÒª°ÑÀàËÆÏÂÃæµÄÏî¼Óµ½ÄúµÄ httpd.conf ÖУº
NameVirtualHost *
Èç¹ûÄúµÄ web ·þÎñÆ÷µÄÃû×ÖÊÇ www.domain.tld£¬
¶øÄúÏ£Íû½¨Á¢Ò»¸ö
www.someotherdomain.tld µÄÐéÄâÓò£¬
ÔòÓ¦ÔÚ
httpd.conf ÖмÓÈ룺
<VirtualHost *>
ServerName www.domain.tld
DocumentRoot /www/domain.tld
</VirtualHost>
<VirtualHost *>
ServerName www.someotherdomain.tld
DocumentRoot /www/someotherdomain.tld
</VirtualHost>
ÄúÐèÒª°ÑÉÏÃæµÄµØÖ·ºÍÎĵµÂ·¾¶¸ÄΪËùʹÓõÄÄÇЩ¡£
ÒªÁË½â¹ØÓÚÐéÄâÖ÷»úµÄ¸ü¶àÐÅÏ¢£¬
Çë²Î¿¼¹Ù·½µÄ Apache Îĵµ£¬ ÕâЩÎĵµ¿ÉÒÔÔÚ ÕÒµ½¡£
Apache Ä£¿é
Apache
Ä£¿é
ÓÐÐí¶à²»Í¬µÄ Apache Ä£¿é£¬
ËüÃÇ¿ÉÒÔÔÚ»ù±¾µÄ·þÎñÆ÷»ù´¡ÉÏÌṩÐí¶à¸½¼ÓµÄ¹¦ÄÜ¡£ FreeBSD µÄ
Ports Collection Ϊ°²×°
Apache
ºÍ³£Óõĸ½¼ÓÄ£¿éÌṩÁ˷dz£·½±ãµÄ·½·¨¡£
mod_ssl
web ·þÎñÆ÷
°²È«
SSL
ÃÜÂëѧ
mod_ssl Õâ¸öÄ£¿éʹÓà OpenSSL ¿â£¬
À´Ìṩͨ¹ý °²È«Ì×½Ó×Ö²ã (SSL v2/v3) ºÍ ´«Êä²ã°²È« (TLS v1)
ÐÒéµÄÇ¿¼ÓÃÜÄÜÁ¦¡£
Õâ¸öÄ£¿éÌṩÁË´ÓijһÊÜÐŵÄÖ¤ÊéÇ©Êð»ú¹¹ÉêÇëÇ©ÃûÖ¤ÊéËùÐèµÄËùÓй¤¾ß£¬
Äú¿ÉÒÔ½å´ËÔÚ &os; ÉÏÔËÐа²È«µÄ web ·þÎñÆ÷¡£
Èç¹ûÄúÎ´Ôø°²×°
Apache£¬ Ò²¿ÉÒÔÖ±½Ó°²×°Ò»·Ý°üº¬ÁË
mod_ssl µÄ°æ±¾µÄ
Apache
1.3.X£¬ Æä·½·¨ÊÇͨ¹ý www/apache13-modssl port À´½øÐС£ SSL
Ö§³ÖÒѾ×÷Ϊ Apache 2.X µÄÒ»²¿·ÖÌṩ£¬
Äú¿ÉÒÔͨ¹ý
www/apache22 port À´°²×°ºóÕß¡£
ÓïÑÔ°ó¶¨
Apache¶ÔÓÚһЩÖ÷ÒªµÄ½Å±¾ÓïÑÔ¶¼ÓÐÏàÓ¦µÄÄ£¿é¡£
ÕâЩģ¿éʹµÃÍêȫʹÓÃijÖֽű¾ÓïÑÔÀ´Ð´
Apache Ä£¿é³ÉΪ¿ÉÄÜ¡£
ËûÃÇͨ³£Ò²±»Ç¶Èëµ½·þÎñÆ÷×÷Ϊһ¸ö³£×¤ÄÚ´æµÄ½âÊÍÆ÷£¬
ÒÔ±ÜÃâÆô¶¯Ò»¸öÍⲿ½âÊÍÆ÷¶ÔÓÚÏÂÒ»½Ú½«ÃèÊöµÄ¶¯Ì¬ÍøÕ¾ËùÐèʱ¼äºÍ×ÊÔ´ÉϵĿªÏú¡£
¶¯Ì¬ÍøÕ¾
web servers
dynamic
ÔÚ¹ýÈ¥µÄÊ®ÄêÀԽÀ´Ô½¶àµÄÆóҵΪÁËÔö¼ÓÊÕÒæºÍ±©¹âÂʶø×ªÏòÁË»¥ÁªÍø¡£
ÕâҲͬʱÔö½øÁ˶ÔÓÚ»¥¶¯ÍøÒ³ÄÚÈݵÄÐèÇó¡£ÓÐЩ¹«Ë¾£¬±ÈÈç µsoft;
ÍÆ³öÁË»ùÓÚËûÃÇרÓвúÆ·µÄ½â¾ö·½°¸£¬¿ªÔ´ÉçÇøÒ²×ö³öÁË»ý¼«µÄ»ØÓ¦¡£
±È½ÏʱÉеÄÑ¡Ôñ°üÀ¨ Django£¬Ruby on Rails£¬
mod_perl, and
mod_php.
Django
Python
Django
Django ÊÇÒ»¸öÒÔ BSD Ðí¿ÉÖ¤·¢²¼µÄ framework£¬
ÄÜÈÿª·¢Õß¿ìËÙд³ö¸ßÐÔÄ܏߯·Ö浀 web Ó¦ÓóÌÐò¡£
ËüÌṩ¸øÒ»¸ö¶ÔÏó¹ØÏµÓ³Éä×é¼þ£¬Êý¾ÝÀàÐÍ¿ÉÒÔ±»µ± Python
ÖеĶÔÏ󣬺ÍÒ»×é·á¸»µÄ¶¯Ì¬Êý¾Ý¿â·ÃÎÊ API£¬
ʹ¿ª·¢Õß±ÜÃâÁËд SQL Óï¾ä¡£Ëüͬʱ»¹ÌṩÁË¿ÉÀ©Õ¹µÄÄ£°åϵͳ£¬
ÈÃÓ¦ÓóÌÐòµÄÂß¼²¿·ÖÓë HTML µÄ±íÏÖ²ã·ÖÀë¡£
Django ÒÀÀµÓë mod_python£¬
Apache, ºÍÒ»¸ö¿ÉÑ¡µÄ SQL
Êý¾Ý¿âÒýÇæ¡£ ÔÚÉèÖÃÁËһЩǡµ±µÄ±êÖ¾ºó£¬FreeBSD µÄ Port
ϵͳ½«»á°ïÖúÄã°²×°ÕâЩ±ØÐèµÄÒÀÀµ¿â¡£
°²×° Django£¬Apache2£¬ mod_python3£¬ºÍ PostgreSQL
&prompt.root; cd /usr/ports/www/py-django; make all install clean -DWITH_MOD_PYTHON3 -DWITH_POSTGRESQL
ÔÚ°²×°ÁË Django ºÍÄÇЩÒÀÀµµÄÈí¼þÖ®ºó£¬
ÄãÐèÒª´´½¨Ò»¸ö Django ÏîÄ¿µÄĿ¼£¬È»ºóÅäÖÃ
Apache£¬µ±ÓжÔÓÚÄãÍøÕ¾ÉÏÓ¦ÓóÌÐòµÄijЩָ¶¨µÄ URL
ʱµ÷ÓÃÄÚǶµÄ Python ½âÊÍÆ÷¡£
Django/mod_python ÓÐ¹Ø Apache ²¿·ÖµÄÅäÖÃ
ÄãÐèÒªÔÚ Apache µÄÅäÖÃÎļþ
httpd.conf ¼ÓÈëÒÔÏÂÕ⼸ÐУ¬
°Ñ¶ÔijЩ URL µÄÇëÇ󴫸øÄãµÄ web Ó¦ÓóÌÐò£º
<Location "/">
SetHandler python-program
PythonPath "['/dir/to/your/django/packages/'] + sys.path"
PythonHandler django.core.handlers.modpython
SetEnv DJANGO_SETTINGS_MODULE mysite.settings
PythonAutoReload On
PythonDebug On
</Location>
Ruby on Rails
Ruby on Rails
Ruby on Rails ÊÇÁíÍâÒ»¸ö¿ªÔ´µÄ web framework£¬
ÌṩÁËÒ»¸öÈ«ÃæµÄ¿ª·¢¿ò¼Ü£¬ÄܰïÖú web
¿ª·¢Õß¹¤×÷¸üÓгÉЧºÍ¿ìËÙд³öÇ¿´óµÄÓ¦Óá£
ËüÄܷdz£ÈÝÒ×µÄ´Ó posts ϵͳ°²×°¡£
&prompt.root; cd /usr/ports/www/rubygem-rails; make all install clean
mod_perl
mod_perl
Perl
Apache/Perl ¼¯³É¼Æ»®£¬ ½« Perl
³ÌÐòÉè¼ÆÓïÑÔµÄÇ¿´ó¹¦ÄÜ£¬ Óë Apache
HTTP ·þÎñÆ÷ ½ôÃܵؽáºÏµ½ÁËÒ»Æð¡£
ͨ¹ý mod_perl Ä£¿é£¬
¿ÉÒÔÍêȫʹÓà Perl À´×«Ð´ Apache Ä£¿é¡£
´ËÍ⣬ ·þÎñÆ÷ÖÐǶÈëµÄ³Ö¾ÃÐÔ½âÊÍÆ÷£¬ Ïû³ýÁËÓÉÓÚÆô¶¯ÍⲿµÄ½âÊÍÆ÷Ϊ Perl
½Å±¾µÄÆô¶¯ËùÔì³ÉµÄÐÔÄÜËðʧ¡£
mod_perl ͨ¹ý¶àÖÖ·½Ê½Ìṩ¡£
ҪʹÓà mod_perl£¬
Ó¦¸Ã×¢Òâ mod_perl 1.0
Ö»ÄÜÅäºÏ Apache 1.3 ¶ø
mod_perl 2.0 Ö»ÄÜÅäºÏ
Apache 2.X ʹÓá£
mod_perl 1.0 ¿ÉÒÔͨ¹ý
www/mod_perl °²×°£¬
¶øÒÔ¾²Ì¬·½Ê½Áª±àµÄ°æ±¾£¬ Ôò¿ÉÒÔͨ¹ý
www/apache13-modperl
À´°²×°¡£
mod_perl 2.0 Ôò¿ÉÒÔͨ¹ý
www/mod_perl2 °²×°¡£
Tom
Rhodes
Written by
mod_php
mod_php
PHP
PHP£¬ Ò²³ÆÎª PHP:
Hypertext Preprocessor
£¬
ÊÇÒ»ÖÖÌØ±ðÊʺÏÓÚ Web ¿ª·¢µÄͨÓýű¾ÓïÑÔ¡£
ËüÄܹ»ºÜÈÝÒ×µØÇ¶Èëµ½ HTML Ö®ÖУ¬
ÆäÓï·¨½Ó½üÓÚ C¡¢ &java;£¬ ÒÔ¼° Perl£¬ ÒÔÆÚÈà web
¿ª·¢ÈËÔ±µÄһѸËÙ׫д¶¯Ì¬Éú³ÉµÄÒ³Ãæ¡£
Òª»ñµÃÓÃÓÚ
Apache web ·þÎñÆ÷µÄ
PHP5 Ö§³Ö£¬ ¿ÉÒÔ´Ó°²×°
lang/php5
port ¿ªÊ¼¡£
ÔÚÊ״ΰ²×° lang/php5 port
µÄʱºò£¬ ϵͳ»á×Ô¶¯ÏÔʾ¿ÉÓõÄһϵÁÐ
OPTIONS (ÅäÖÃÑ¡Ïî)¡£ Èç¹ûÄúûÓп´µ½²Ëµ¥£¬
ÀýÈçÓÉÓÚ¹ýÈ¥Ôø¾°²×°¹ý lang/php5 port µÈµÈ£¬
¿ÉÒÔÓÃÏÂÃæµÄÃüÁîÔÙ´ÎÏÔʾÅäÖò˵¥£¬ ÔÚ port µÄĿ¼ÖÐÖ´ÐУº
&prompt.root; make config
ÔÚÅäÖÃÑ¡Ïî¶Ô»°¿òÖУ¬ Ñ¡ÖÐ
APACHE ÕâÒ»Ï ¾Í¿ÉÒÔÁª±à³öÓÃÓÚÓë
Apache web ·þÎñÆ÷ÅäºÏʹÓõĿɶ¯Ì¬¼ÓÔØµÄ
mod_php5 Ä£¿éÁË¡£
ÓÉÓÚ¸÷ʽ¸÷ÑùµÄÔÒò (ÀýÈ磬 ³öÓÚÒѾ²¿ÊðµÄ web Ó¦ÓõļæÈÝÐÔ¿¼ÂÇ)£¬
Ðí¶àÍøÕ¾ÈÔÔÚʹÓà PHP4¡£ Èç¹ûÄúÐèÒª
mod_php4 ¶ø²»ÊÇ
mod_php5£¬ ÇëʹÓÃ
lang/php4 port¡£
lang/php4 port Ò²Ö§³ÖÐí¶à
lang/php5 port ÌṩµÄÅäÖúͱàÒëʱѡÏî¡£
Ç°ÃæÎÒÃÇÒѾ³É¹¦µØ°²×°²¢ÅäÖÃÁËÓÃÓÚÖ§³Ö¶¯Ì¬ PHP Ó¦ÓÃËùÐèµÄÄ£¿é¡£
Çë¼ì²é²¢È·ÈÏÄúÒѽ«ÏÂÊöÅäÖüÓÈëµ½ÁË
/usr/local/etc/apache/httpd.conf ÖУº
LoadModule php5_module libexec/apache/libphp5.so
AddModule mod_php5.c
<IfModule mod_php5.c>
DirectoryIndex index.php index.html
</IfModule>
<IfModule mod_php5.c>
AddType application/x-httpd-php .php
AddType application/x-httpd-php-source .phps
</IfModule>
ÕâЩ¹¤×÷Íê³ÉÖ®ºó£¬ »¹ÐèҪʹÓÃ
apachectl ÃüÁîÀ´Íê³ÉÒ»´Î graceful
restart ÒÔ±ã¼ÓÔØ PHP Ä£¿é£º
&prompt.root; apachectl graceful
ÔÚδÀ´ÄúÉý¼¶ PHP ʱ£¬
make config Õâ²½²Ù×÷¾Í²»ÔÙÊDZØÐèµÄÁË£»
ÄúËùÑ¡ÔñµÄ OPTIONS »áÓÉ &os;
µÄ Ports ¿ò¼Ü×Ô¶¯±£´æ¡£
ÔÚ &os; ÖÐµÄ PHP Ö§³ÖÊǸ߶ÈÄ£¿é»¯µÄ£¬
Òò´Ë»ù±¾°²×°µÄ¹¦ÄÜÊ®·ÖÓÐÏÞ¡£ Ôö¼ÓÆäËû¹¦ÄܵÄÖ§³Ö·Ç³£¼òµ¥£¬ Ö»Ðèͨ¹ý
lang/php5-extensions port
¼´¿ÉÍê³É¡£ Õâ¸ö port ÌṩÁËÒ»¸ö²Ëµ¥Çý¶¯µÄ½çÃæÀ´°ïÖúÍê³É
PHP À©Õ¹µÄ°²×°¡£ ÁíÍ⣬ Ò²¿ÉÒÔͨ¹ý¶ÔÓ¦µÄ port
À´µ¥¶À°²×°À©Õ¹¡£
ÀýÈ磬 Òª½«¶ÔÓÚ
MySQL Êý¾Ý¿â·þÎñÆ÷µÄÖ§³Ö¼ÓÈë
PHP5£¬ Ö»Ðè¼òµ¥µØ°²×°
databases/php5-mysql¡£
°²×°ÍêÀ©Õ¹Ö®ºó£¬ ±ØÐëÖØÐÂÆô¶¯
Apache ·þÎñÆ÷£¬
À´ÁîÆäÊÊӦеÄÅäÖñä¸ü£º
&prompt.root; apachectl graceful
Murray
Stokely
Contributed by
Îļþ´«ÊäÐÒé (FTP)
FTP ·þÎñÆ÷
×ÝÀÀ
Îļþ´«ÊäÐÒé (FTP) ΪÓû§ÌṩÁËÒ»¸ö¼òµ¥µÄ£¬ Óë FTP ·þÎñÆ÷½»»»ÎļþµÄ·½·¨¡£ &os;
ϵͳÖаüº¬ÁË FTP
·þÎñÈí¼þ£¬ ftpd¡£ ÕâʹµÃÔÚ &os;
ÉϽ¨Á¢ºÍ¹ÜÀí FTP ·þÎñÆ÷±äµÃ·Ç³£¼òµ¥¡£
ÅäÖÃ
×îÖØÒªµÄÅäÖò½ÖèÊǾö¶¨ÔÊÐíÄÄЩÕʺŷÃÎÊ FTP ·þÎñÆ÷¡£
Ò»°ãµÄ &os; ϵͳ°üº¬ÁËһϵÁÐϵͳÕʺŷֱðÓÃÓÚÖ´Ðв»Í¬µÄ·þÎñ³ÌÐò£¬
µ«Î´ÖªµÄÓû§²»Ó¦±»ÔÊÐíµÇ¼²¢Ê¹ÓÃÕâЩÕʺš£
/etc/ftpusers ÎļþÖУ¬ ÁгöÁ˲»ÔÊÐíͨ¹ý
FTP ·ÃÎʵÄÓû§¡£ ĬÈÏÇé¿öÏ£¬ Õâ°üº¬ÁËǰÊöµÄϵͳÕʺţ¬
µ«Ò²¿ÉÒÔÔÚÕâÀï¼ÓÈëÆäËü²»Ó¦Í¨¹ý FTP ·ÃÎʵÄÓû§¡£
Äú¿ÉÄÜ»áÏ£ÍûÏÞÖÆÍ¨¹ý FTP µÇ¼µÄijЩÓû§£¬
¶ø²»ÊÇÍêÈ«×èÖ¹ËûÃÇʹÓà FTP¡£ Õâ¿ÉÒÔͨ¹ý /etc/ftpchroot
ÎļþÀ´Íê³É¡£ ÕâÒ»ÎļþÁгöÁËÏ£Íû¶Ô FTP ·ÃÎʽøÐÐÏÞÖÆµÄÓû§ºÍ×éµÄ±í¡£
¶øÔÚ &man.ftpchroot.5; Áª»úÊÖ²áÖУ¬ ÒѾ¶Ô´Ë½øÐÐÁËÏ꾡µÄ½éÉÜ£¬
¹Ê¶ø²»ÔÙ׸Êö¡£
FTP
ÄäÃû
Èç¹ûÄúÏëÒªÔÚ·þÎñÆ÷ÉÏÆôÓÃÄäÃûµÄ FTP ·ÃÎÊ£¬ Ôò±ØÐ뽨Á¢Ò»¸öÃûΪ
ftp µÄ &os; Óû§¡£ ÕâÑù£¬ Óû§¾Í¿ÉÒÔʹÓÃ
ftp »ò anonymous
ºÍÈÎÒâµÄ¿ÚÁî (ϰ¹ßÉÏ£¬ Ó¦¸ÃÊÇÒÔÄǸöÓû§µÄÓʼþµØÖ·×÷Ϊ¿ÚÁî)
À´µÇ¼ºÍ·ÃÎÊÄúµÄ FTP ·þÎñÆ÷¡£ FTP ·þÎñÆ÷½«ÔÚÄäÃûÓû§µÇ¼ʱµ÷ÓÃ
&man.chroot.2;£¬ ÒԱ㽫Æä·ÃÎÊÏÞÖÆÔÚ
ftp Óû§µÄÖ÷Ŀ¼ÖС£
ÓÐÁ½¸öÎı¾Îļþ¿ÉÒÔÓÃÀ´Ö¸¶¨ÏÔʾÔÚ FTP ¿Í»§³ÌÐòÖе϶ÓÎÄ×Ö¡£
/etc/ftpwelcome ÎļþÖеÄÄÚÈݽ«ÔÚÓû§Á¬½ÓÉÏÖ®ºó£¬
ÔڵǼÌáʾ֮ǰÏÔʾ¡£ Ôڳɹ¦µÄµÇ¼֮ºó£¬ ½«ÏÔʾ
/etc/ftpmotd ÎļþÖеÄÄÚÈÝ¡£
Çë×¢ÒâºóÕßÊÇÏà¶ÔÓڵǼ»·¾³µÄ£¬ Òò´Ë¶ÔÓÚÄäÃûÓû§¶øÑÔ£¬
½«ÏÔʾ ~ftp/etc/ftpmotd¡£
Ò»µ©ÕýÈ·µØÅäÖÃÁË FTP ·þÎñÆ÷£¬
¾Í±ØÐëÔÚ /etc/inetd.conf ÖÐÆôÓÃËü¡£
ÕâÀïÐèÒª×öµÄÈ«²¿¹¤×÷¾ÍÊǽ«×¢ÊÍ·û
#
´ÓÒÑÓеÄ
ftpd ÐÐ֮ǰȥµô£º
ftp stream tcp nowait root /usr/libexec/ftpd ftpd -l
Èç Ëù½éÉܵÄÄÇÑù£¬
ÐÞ¸ÄÕâ¸öÎļþÖ®ºó£¬ ±ØÐëÈà inetd ÖØÐ¼ÓÔØËü£¬
²ÅÄÜʹеÄÉèÖÃÉúЧ¡£Çë²ÎÔÄ
ÒÔ»ñÈ¡¸ü¶àÓйØÈçºÎÔÚÄãϵͳÉÏÆôÓà inetd
µÄÏêϸÐÅÏ¢¡£
ftpd Ò²¿ÉÒÔ×÷Ϊһ¸ö¶ÀÁ¢µÄ·þÎñÆô¶¯¡£
ÕâÑùµÄ»°¾ÍÐèÒªÔÚ /etc/rc.conf
ÖÐÉèÖÃÈçϵıäÁ¿£º
ftpd_enable="YES"
ÔÚÉèÖÃÁËÉÏÊö±äÁ¿Ö®ºó£¬¶ÀÁ¢µÄ·þÎñ½«ÔÚÏ´ÎÏµÍ³ÖØÆôµÄʱºòÆô¶¯£¬
»òÕßͨ¹ýÒÔ root Éí·ÝÊÖ¶¯Ö´ÐÐÈçϵÄÃüÁîÆô¶¯£º
&prompt.root; /etc/rc.d/ftpd start
ÏÖÔÚ¿ÉÒÔͨ¹ýÊäÈëÏÂÃæµÄÃüÁîÀ´µÇ¼ÄúµÄ FTP ·þÎñÆ÷ÁË£º
&prompt.user; ftp localhost
ά»¤
syslog
ÈÕÖ¾Îļþ
FTP
ftpd ·þÎñ³ÌÐòʹÓÃ
&man.syslog.3; À´¼Ç¼ÏûÏ¢¡£ ĬÈÏÇé¿öÏ£¬
ϵͳÈÕÖ¾½«°ÑºÍ FTP Ïà¹ØµÄÏûÏ¢¼Ç¼µ½
/var/log/xferlog ÎļþÖС£ FTP ÈÕÖ¾µÄλÖã¬
¿ÉÒÔͨ¹ýÐÞ¸Ä
/etc/syslog.conf ÖÐÈçÏÂËùʾµÄÐÐÀ´Ð޸ģº
ftp.info /var/log/xferlog
FTP
ÄäÃû
Ò»¶¨ÒªÐ¡ÐĶԴýÔÚÄäÃû FTP ·þÎñÆ÷ÖпÉÄÜÓöµ½µÄDZÔÚÎÊÌâ¡£
Ò»°ã¶øÑÔ£¬ ÔÊÐíÄäÃûÓû§ÉÏ´«ÎļþÓ¦Èý˼¡£ Äú¿ÉÄÜ·¢ÏÖ×Ô¼ºµÄ FTP
Õ¾µã³ÉΪÁ˽»Ò×δ¾ÊÚȨµÄÉÌÒµÈí¼þµÄÂÛ̳£¬ »ò·¢Éú¸üÔã¸âµÄÇé¿ö¡£
Èç¹û²»ÐèÒªÄäÃûµÄ FTP ÉÏ´«£¬ ¿ÉÒÔÔÚÎļþÉÏÅäÖÃȨÏÞ£¬
ʹµÃÄúÄܹ»ÔÚÆäËüÄäÃûÓû§Äܹ»ÏÂÔØÕâЩÎļþ֮ǰ¸´²éËüÃÇ¡£
Murray
Stokely
Contributed by
Ϊ µsoft.windows; ¿Í»§»úÌṩÎļþºÍ´òÓ¡·þÎñ (Samba)
Samba ·þÎñÆ÷
Microsoft Windows
Îļþ·þÎñÆ÷
Windows ¿Í»§»ú
´òÓ¡·þÎñÆ÷
Windows ¿Í»§»ú
×ÝÀÀ
Samba ÊÇÒ»¸öÁ÷ÐеĿªÔ´Èí¼þ°ü£¬
ËüÌṩÁËÕë¶Ô µsoft.windows; ¿Í»§»úµÄÎļþºÍ´òÓ¡·þÎñ¡£
ÕâÀà¿Í»§»ú¿ÉÒÔÁ¬½Ó²¢Ê¹Óà FreeBSD ϵͳÉϵÄÎļþ¿Õ¼ä£¬
¾ÍÈçͬʹÓñ¾µØµÄ´ÅÅÌÒ»Ñù£¬ »òÕßÏñʹÓñ¾µØ´òÓ¡»úÒ»ÑùʹÓÃ
FreeBSD ÉϵĴòÓ¡»ú¡£
Samba Èí¼þ°ü¿ÉÒÔÔÚÄúµÄ FreeBSD
°²×°ÅÌÉÏÕÒµ½¡£ Èç¹ûÄúûÓÐÔÚ³õ´Î°²×° FreeBSD
ʱ°²×° Samba£¬ Ôò¿ÉÒÔͨ¹ý net/samba34 port »ò package À´°²×°¡£
ÅäÖÃ
ĬÈ쵀 Samba ÅäÖÃÎļþ»áÒÔ
/usr/local/share/examples/samba34/smb.conf.default
µÄÃû×Ö°²×°¡£Õâ¸öÎļþ±ØÐë¸´ÖÆÎª
/usr/local/etc/smb.conf ²¢½øÐж¨ÖÆ£¬
²ÅÄÜ¿ªÊ¼Ê¹Óà Samba¡£
smb.conf ÎļþÖаüº¬ÁË
Samba µÄÔËÐÐʱÅäÖÃÐÅÏ¢£¬
ÀýÈç¶ÔÓÚ´òÓ¡»úµÄ¶¨Ò壬 ÒÔ¼°Ï£Íû¹²Ïí¸ø &windows;
¿Í»§»úµÄ ¹²ÏíÎļþϵͳ
¡£
Samba Èí¼þ°ü°üº¬ÁËÒ»¸ö³ÆÎª
swat µÄ web ¹ÜÀí¹¤¾ß£¬
ºóÕßÌṩÁËÅäÖà smb.conf ÎļþµÄ¼òµ¥·½·¨¡£
ʹÓà Samba Web ¹ÜÀí¹¤¾ß (SWAT)
Samba Web ¹ÜÀí¹¤¾ß (SWAT) ÊÇÒ»¸öͨ¹ý
inetd ÔËÐеķþÎñ³ÌÐò¡£ Òò´Ë£¬
ÐèÒª°Ñ /etc/inetd.conf ÖÐÏÂÃæ¼¸ÐеÄ×¢ÊÍÈ¥µô£¬
²ÅÄܹ»Ê¹Óà swat
À´ÅäÖà Samba£º
swat stream tcp nowait/400 root /usr/local/sbin/swat swat
Èç ÖÐËù½éÉܵÄÄÇÑù£¬
ÔÚÐÞ¸ÄÁËÕâ¸öÅäÖÃÎļþÖ®ºó£¬ ±ØÐëÈà inetd
ÖØÐ¼ÓÔØÅäÖ㬠²ÅÄÜʹÆäÉúЧ¡£
Ò»µ©ÔÚ inetd.conf ÖÐÆôÓÃÁË
swat£¬ ¾Í¿ÉÒÔÓÃä¯ÀÀÆ÷·ÃÎÊ
connect to ÁË¡£
Äú½«Ê×ÏÈʹÓÃϵͳµÄ root
ÕʺŵǼ¡£
Ö»Òª³É¹¦µØµÇ¼½øÁË
Samba ÅäÖÃÒ³Ãæ£¬
¾Í¿ÉÒÔä¯ÀÀϵͳµÄÎĵµ£¬ »ò´Ó
Globals(È«¾Ö) Ñ¡Ï¿ªÊ¼ÅäÖÃÁË¡£
Globals С½Ú¶ÔÓ¦ÓÚ [global]
С½ÚÖеıäÁ¿£¬ ǰÕßλÓÚ
/usr/local/etc/smb.conf ÖС£
È«¾ÖÅäÖÃ
ÎÞÂÛÊÇʹÓà swat£¬
»¹ÊÇÖ±½Ó±à¼ /usr/local/etc/smb.conf£¬
ͨ³£Ê×ÏÈÒªÅäÖÃµÄ Samba
Ñ¡Ïî¶¼ÊÇ£º
workgroup
NT ÓòÃû»ò¹¤×÷×éÃû£¬
ÆäËû¼ÆËã»ú½«Í¨¹ýÕâЩÃû×ÖÀ´ÕÒµ½·þÎñÆ÷¡£
netbios name
NetBIOS
Õâ¸öÑ¡ÏîÓÃÓÚÉèÖà Samba ·þÎñÆ÷µÄ
NetBIOS Ãû×Ö¡£ ĬÈÏÇé¿öÏ£¬ ÕâÊÇËùÔÚÖ÷»úµÄ DNS Ãû×ֵĵÚÒ»²¿·Ö¡£
server string
Õâ¸öÑ¡ÏîÓÃÓÚÉèÖÃͨ¹ý net view
ÃüÁ ÒÔ¼°Ä³Ð©ÆäËûÍøÂ繤¾ß¿ÉÒԲ鿴µ½µÄ¹ØÓÚ·þÎñÆ÷µÄ˵Ã÷ÐÔÎÄ×Ö¡£
°²È«ÅäÖÃ
ÔÚ
/usr/local/etc/smb.conf ÖеÄÁ½¸ö×îÖØÒªµÄÅäÖã¬
ÊÇÑ¡¶¨µÄ°²È«Ä£ÐÍ£¬ ÒÔ¼°¿Í»§»úÉÏÓû§µÄ¿ÚÁî´æ·Åºó¶Ë¡£
ÏÂÃæµÄÓï¾ä¿ØÖÆÕâЩѡÏ
security
×î³£¼ûµÄÑ¡ÏîÐÎʽÊÇ
security = share ºÍ security
= user¡£ Èç¹ûÄúµÄ¿Í»§»úʹÓÃÓû§Ãû£¬
²¢ÇÒÕâЩÓû§ÃûÓëÄúµÄ &os; »úÆ÷Ò»Ö£¬
Ò»°ãӦѡÔñÓû§¼¶ (user) °²È«¡£ ÕâÊÇĬÈϵݲȫ²ßÂÔ£¬
ËüÒªÇó¿Í»§»úÊ×ÏȵǼ£¬ È»ºó²ÅÄÜ·ÃÎʹ²ÏíµÄ×ÊÔ´¡£
Èç¹û²ÉÓù²Ïí¼¶ (share) °²È«£¬
Ôò¿Í»§»ú²»ÐèÒªÓÃÓÐЧµÄÓû§ÃûºÍ¿ÚÁîµÇ¼·þÎñÆ÷£¬
¾ÍÄܹ»Á¬½Ó¹²ÏíµÄ×ÊÔ´¡£ ÕâÊǽÏÔç°æ±¾µÄ
Samba ÖеÄĬÈÏÖµ¡£
passdb backend
NIS+
LDAP
SQL Êý¾Ý¿â
Samba ÌṩÁËÈô¸ÉÖÖ²»Í¬µÄÑéÖ¤ºó¶ËÄ£ÐÍ¡£
Äú¿ÉÒÔͨ¹ý LDAP¡¢ NIS+¡¢ SQL Êý¾Ý¿â£¬ »ò¾¹ýÐ޸ĵĿÚÁîÎļþ£¬
À´Íê³É¿Í»§¶ËµÄÉí·ÝÑéÖ¤¡£ ĬÈϵÄÑé֤ģʽÊÇ
smbpasswd£¬ ÕâÒ²ÊDZ¾Õ½«½éÉܵÄÈ«²¿ÄÚÈÝ¡£
¼ÙÉèÄúʹÓõÄÊÇĬÈ쵀 smbpasswd
ºó¶Ë£¬ Ôò±ØÐëÊ×ÏÈ´´½¨Ò»¸ö
/usr/local/etc/samba/smbpasswd Îļþ£¬
À´ÔÊÐí Samba ¶Ô¿Í»§½øÐÐÉí·ÝÑéÖ¤¡£
Èç¹ûÄú´òËãÈà &unix; Óû§ÕʺÅÄܹ»´Ó &windows;
¿Í»§»úÉϵǼ£¬ ¿ÉÒÔʹÓÃÏÂÃæµÄÃüÁ
&prompt.root; smbpasswd -a username
Ä¿Ç°ÍÆ¼öʹÓõĺó¶ËÊÇ tdbsam£¬
ÄúӦʹÓÃÏÂÃæµÄÃüÁîÀ´Ìí¼ÓÓû§Õʺţº
&prompt.root; pdbedit username
Çë²Î¿¼
¹Ù·½µÄ Samba HOWTO
ÒÔÁË½â¹ØÓÚÅäÖÃÑ¡ÏîµÄ½øÒ»²½ÐÅÏ¢¡£ °´ÕÕÇ°Ãæ¸ø³öµÄ»ù±¾ÃèÊö£¬
ÄúÓ¦¸ÃÒѾ¿ÉÒÔÆô¶¯
Samba ÁË¡£
Æô¶¯ Samba
net/samba34 port
»áÔö¼ÓÒ»¸öеÄÓÃÓÚ¿ØÖÆ
Samba µÄÆô¶¯½Å±¾¡£ ÒªÆôÓÃÕâ¸ö½Å±¾£¬
ÒÔ±ãÓÃËüÀ´Íê³ÉÆô¶¯¡¢ Í£Ö¹»òÖØÆô
Samba µÄÈÎÎñ£¬ ÐèÒªÔÚ
/etc/rc.conf ÎļþÖмÓÈ룺
samba_enable="YES"
´ËÍ⣬ Ò²¿ÉÒÔ½øÐиüϸÁ£¶ÈµÄ¿ØÖÆ£º
nmbd_enable="YES"
smbd_enable="YES"
ÕâҲͬʱÅäÖÃÁËÔÚϵͳÒýµ¼Ê±Æô¶¯ Samba¡£
ÅäÖúÃÖ®ºó£¬ ¾Í¿ÉÒÔÔÚÈκÎʱºòͨ¹ýÏÂÃæµÄÃüÁîÀ´Æô¶¯
Samba ÁË£º
&prompt.root; /usr/local/etc/rc.d/samba start
Starting SAMBA: removing stale tdbs :
Starting nmbd.
Starting smbd.
Çë²Î¼û ÒÔÁË½â¹ØÓÚʹÓà rc ½Å±¾µÄ½øÒ»²½ÐÅÏ¢¡£
Samba ÊÂʵÉϰüº¬ÁËÈý¸öÏ໥¶ÀÁ¢µÄ·þÎñ³ÌÐò¡£
ÄúÓ¦¸ÃÄܹ»¿´µ½
nmbd ºÍ smbd
Á½¸ö·þÎñ³ÌÐò¶¼ÊÇͨ¹ý samba ½Å±¾Æô¶¯µÄ¡£ Èç¹ûÔÚ
smb.conf ÖÐÆôÓÃÁË winbind Ãû×Ö½âÎö·þÎñ£¬
ÔòÓ¦¸Ã¿ÉÒÔ¿´µ½ winbindd
·þÎñ±»Æô¶¯ÆðÀ´¡£
¿ÉÒÔÔÚÈκÎʱºòͨ¹ýÏÂÃæµÄÃüÁîÀ´Í£Ö¹ÔËÐÐ
Samba£º
&prompt.root; /usr/local/etc/rc.d/samba stop
Samba ÊÇÒ»¸ö¸´ÔÓµÄÈí¼þ°ü£¬
ËüÌṩÁËÓÃÓÚÓë µsoft.windows; ÍøÂç½øÐм¯³ÉµÄ¸÷ʽ¸÷ÑùµÄ¹¦ÄÜ¡£
ÒªÁË½â¹ØÓÚÕâÀïËù½éÉܵĻù±¾°²×°ÒÔÍâµÄÆäËü¹¦ÄÜ£¬
Çë·ÃÎÊ ¡£
Tom
Hukins
Contributed by
ͨ¹ý NTP ½øÐÐʱÖÓͬ²½
NTP
×ÝÀÀ
Ëæ×Åʱ¼äµÄÍÆÒÆ£¬ ¼ÆËã»úµÄʱÖÓ»áÇãÏòÓÚÆ¯ÒÆ¡£
ÍøÂçʱ¼äÐÒé (NTP) ÊÇÒ»ÖÖÈ·±£ÄúµÄʱÖÓ±£³Ö׼ȷµÄ·½·¨¡£
Ðí¶à Internet ·þÎñÒÀÀµ¡¢ »ò¼«´óµØÊÜÒæÓÚ±¾µØ¼ÆËã»úʱÖÓµÄ׼ȷÐÔ¡£
ÀýÈ磬 web ·þÎñÆ÷¿ÉÄÜ»á½ÓÊÕµ½Ò»¸öÇëÇó£¬
ÒªÇóÈç¹ûÎļþÔÚijһʱ¿ÌÖ®ºóÐ޸Ĺý²Å·¢ËÍËü¡£
ÔÚ¾ÖÓòÍø»·¾³ÖУ¬ ¹²ÏíÎļþµÄ¼ÆËã»úÖ®¼äµÄʱÖÓÊÇ·ñͬ²½ÖÁ¹ØÖØÒª£¬
ÒòΪÕâÑù²ÅÄÜʹʱ¼ä´Á±£³ÖÒ»Ö¡£ ÀàËÆ &man.cron.8;
ÕâÑùµÄ³ÌÐò£¬ Ò²ÒÀÀµÓÚÕýÈ·µÄϵͳʱÖÓ£¬ ²ÅÄܹ»×¼È·µØÖ´ÐвÙ×÷¡£
NTP
ntpd
FreeBSD ¸½´øÁË &man.ntpd.8; NTP ·þÎñÆ÷£¬
Ëü¿ÉÒÔÓÃÓÚ²éѯÆäËüµÄ NTP
·þÎñÆ÷£¬ ²¢ÅäÖñ¾µØ¼ÆËã»úµÄʱÖÓ£¬ »òÕßΪÆäËü»úÆ÷Ìṩ·þÎñ¡£
Ñ¡ÔñºÏÊ浀 NTP ·þÎñÆ÷
NTP
Ñ¡Ôñ·þÎñÆ÷
ΪÁËͬ²½ÄúµÄϵͳʱÖÓ£¬
ÐèÒªÊ×ÏÈÕÒµ½ÖÁÉÙÒ»¸ö NTP ·þÎñÆ÷ÒÔ¹©Ê¹Óá£ ÍøÂç¹ÜÀíÔ±£¬
»ò ISP ¶¼¿ÉÄÜ»áÌṩÓÃÓÚÕâÑùÄ¿µÄµÄ NTP
·þÎñÆ÷—Çë²é¿´ËûÃǵÄÎĵµÒÔÁ˽âÊÇ·ñÊÇÕâÑù¡£
ÁíÍ⣬ Ò²ÓÐÒ»¸öÔÚÏßµÄ ¹«¿ªµÄ
NTP ·þÎñÆ÷ÁÐ±í£¬ Äú¿ÉÒÔ´ÓÖÐѡһ¸ö½Ï½üµÄ NTP ·þÎñÆ÷¡£
ÇëÈ·ÈÏÄúÑ¡ÔñµÄ·þÎñÆ÷µÄ·ÃÎʲßÂÔ£¬ Èç¹ûÐèÒªµÄ»°£¬
ÉêÇëÒ»ÏÂËùÐèµÄÐí¿É¡£
Ñ¡Ôñ¶à¸öÏ໥²»Á¬½ÓµÄ NTP ·þÎñÆ÷ÊÇÒ»¸öºÃÖ÷Ò⣬
ÕâÑùÔÚij¸ö·þÎñÆ÷²»¿É´ï£¬ »òÕßʱÖÓ²»¿É¿¿Ê±¾Í¿ÉÒÔÓбðµÄÑ¡Ôñ¡£
ÕâÊÇÒòΪ£¬ &man.ntpd.8;
»áÖÇÄܵØÑ¡ÔñËüÊÕµ½µÄÏìÓ¦—Ëü»á¸üÇãÏòÓÚʹÓÿɿ¿µÄ·þÎñÆ÷¡£
ÅäÖÃÄúµÄ»úÆ÷
NTP
ÅäÖÃ
»ù±¾ÅäÖÃ
ntpdate
Èç¹ûÖ»ÏëÔÚϵͳÆô¶¯Ê±Í¬²½Ê±ÖÓ£¬
Ôò¿ÉÒÔʹÓà &man.ntpdate.8;¡£ ¶ÔÓÚ¾³£ÖØÐÂÆô¶¯£¬
²¢ÇÒ²»ÐèÒª¾³£Í¬²½µÄ×ÀÃæÏµÍ³À´ËµÕâ±È½ÏÊʺϣ¬
µ«¾ø´ó¶àÊý»úÆ÷¶¼Ó¦¸ÃÔËÐÐ &man.ntpd.8;¡£
ÔÚÒýµ¼Ê±Ê¹Óà &man.ntpdate.8; À´ÅäºÏÔËÐÐ &man.ntpd.8;
Ò²ÊÇÒ»¸öºÃÖ÷Òâ¡£ &man.ntpd.8; ½¥½øµØÐÞÕýʱÖÓ£¬
¶ø &man.ntpdate.8; ÔòÖ±½ÓÉèÖÃʱÖÓ£¬
ÎÞÂÛ»úÆ÷µÄµ±Ç°Ê±¼äºÍÕýȷʱ¼äÓжà´óµÄÆ«²î¡£
ÒªÆôÓÃÒýµ¼Ê±µÄ &man.ntpdate.8;£¬ ÐèÒª°Ñ
ntpdate_enable="YES" ¼Óµ½
/etc/rc.conf ÖС£ ´ËÍ⣬
»¹ÐèҪͨ¹ý ntpdate_flags
À´ÉèÖÃͬ²½µÄ·þÎñÆ÷ºÍÑ¡Ï
ËüÃǽ«´«µÝ¸ø &man.ntpdate.8;¡£
Ò»°ãÅäÖÃ
NTP
ntp.conf
NTP ÊÇͨ¹ý
/etc/ntp.conf ÎļþÀ´½øÐÐÅäÖõģ¬
Æä¸ñʽÔÚ &man.ntp.conf.5; ÖнøÐÐÁËÃèÊö¡£
ÏÂÃæÊÇÒ»¸öÀý×Ó£º
server ntplocal.example.com prefer
server timeserver.example.org
server ntp2a.example.net
driftfile /var/db/ntp.drift
ÕâÀ server Ñ¡ÏîÖ¸¶¨ÁËʹÓÃÄÄÒ»¸ö·þÎñÆ÷£¬
ÿһ¸ö·þÎñÆ÷¶¼¶ÀÁ¢Ò»ÐС£ Èç¹ûijһ̨·þÎñÆ÷ÉÏÖ¸¶¨ÁË prefer
(Æ«ºÃ) ²ÎÊý£¬ ÈçÉÏÃæµÄ ntplocal.example.com£¬
Ôò»áÓÅÏÈÑ¡ÔñÕâ¸ö·þÎñÆ÷¡£
Èç¹ûÆ«ºÃµÄ·þÎñÆ÷ºÍÆäËû·þÎñÆ÷µÄÏìÓ¦´æÔÚÏÔÖøµÄ²î±ð£¬
Ôò¶ªÆúËüµÄÏìÓ¦£¬ ·ñÔò½«Ê¹ÓÃÀ´×ÔËüµÄÏìÓ¦£¬
¶ø²»Àí»áÆäËû·þÎñÆ÷¡£ Ò»°ãÀ´Ëµ£¬
prefer ²ÎÊýÓ¦¸Ã±ê×¢Ôڷdz£¾«È·µÄ NTP
ʱԴ£¬ ÀýÈçÄÇЩ°üº¬ÌØÊâµÄʱ¼ä¼à¿ØÓ²¼þµÄ·þÎñÆ÷ÉÏ¡£
¶ø driftfile Ñ¡Ï
ÔòÖ¸¶¨ÁËÓÃÀ´±£´æÏµÍ³Ê±ÖÓÆµÂÊÆ«²îµÄÎļþ¡£
&man.ntpd.8; ³ÌÐòʹÓÃËüÀ´×Ô¶¯µØ²¹³¥Ê±ÖÓµÄ×ÔÈ»Æ¯ÒÆ£¬
´Ó¶øÊ¹Ê±ÖÓ¼´Ê¹ÔÚÇжÏÁËÍâÀ´Ê±Ô´µÄÇé¿öÏ£¬
ÈÔÄܱ£³ÖÏ൱µÄ׼ȷ¶È¡£
ÁíÍ⣬ driftfile
Ñ¡ÏîÒ²±£´æÉÏÒ»´ÎÏìÓ¦ËùʹÓÃµÄ NTP ·þÎñÆ÷µÄÐÅÏ¢¡£
Õâ¸öÎļþ°üº¬ÁË NTP µÄÄÚ²¿ÐÅÏ¢£¬ Ëü²»Ó¦±»ÈÎºÎÆäËû½ø³ÌÐ޸ġ£
¿ØÖÆÄúµÄ·þÎñÆ÷µÄ·ÃÎÊ
ĬÈÏÇé¿öÏ£¬ NTP ·þÎñÆ÷¿ÉÒÔ±»Õû¸ö Internet ÉϵÄÖ÷»ú·ÃÎÊ¡£
Èç¹ûÔÚ /etc/ntp.conf ÖÐÖ¸¶¨ restrict
²ÎÊý£¬ Ôò¿ÉÒÔ¿ØÖÆÔÊÐíÄÄЩ»úÆ÷·ÃÎÊÄúµÄ·þÎñÆ÷¡£
Èç¹ûÏ£Íû¾Ü¾øËùÓеĻúÆ÷·ÃÎÊÄúµÄ NTP
·þÎñÆ÷£¬ Ö»ÐèÔÚ
/etc/ntp.conf ÖмÓÈ룺
restrict default ignore
ÕâÑù×ö»á½ûÖ¹ÄúµÄ·þÎñÆ÷·ÃÎÊÔÚ±¾µØÅäÖÃÖÐÁгöµÄ·þÎñÆ÷¡£
Èç¹ûÄúÐèÒªÁî NTP ·þÎñÆ÷ÓëÍâ½çµÄ NTP
·þÎñÆ÷ͬ²½Ê±¼ä£¬ ÔòÓ¦ÔÊÐíÖ¸¶¨·þÎñÆ÷¡£ Çë²Î¼ûÁª»úÊÖ²á
&man.ntp.conf.5; ÒÔÁË½â½øÒ»²½µÄϸ½Ú¡£
Èç¹ûֻϣÍû×ÓÍøÄڵĻúÆ÷ͨ¹ýÄúµÄ·þÎñÆ÷ͬ²½Ê±ÖÓ£¬
¶ø²»ÔÊÐíËüÃÇÅäÖÃΪ·þÎñÆ÷£¬ »ò×÷Ϊͬ²½Ê±ÖӵĽڵãÀ´Ê±Óã¬
Ôò¼ÓÈë
restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap
ÕâÀ ÐèÒª°Ñ 192.168.1.0 ¸ÄΪÄúÍøÂçÉϵÄ
IP µØÖ·£¬ ²¢°Ñ 255.255.255.0 ¸ÄΪÄúµÄ×ÓÍøÑÚÂë¡£
/etc/ntp.conf ¿ÉÄܰüº¬¶à¸ö
restrict Ñ¡Ïî¡£ ÒªÁË½â½øÒ»²½µÄϸ½Ú£¬
Çë²Î¼û &man.ntp.conf.5; µÄ
Access Control Support(·ÃÎÊ¿ØÖÆÖ§³Ö)
С½Ú¡£
ÔËÐÐ NTP ·þÎñÆ÷
ÒªÈà NTP ·þÎñÆ÷ÔÚϵͳÆô¶¯Ê±ËæÖ®¿ªÆô£¬
ÐèÒª°Ñ ntpd_enable="YES" ¼ÓÈëµ½
/etc/rc.conf ÖС£
Èç¹ûÏ£ÍûÏò &man.ntpd.8; ´«µÝ¸ü¶à²ÎÊý£¬ ÐèÒª±à¼
/etc/rc.conf ÖеÄ
ntpd_flags¡£
ÒªÔÚ²»ÖØÐÂÆô¶¯»úÆ÷µÄǰÌáÏÂÆô¶¯·þÎñÆ÷£¬ ÐèÒªÊÖ¹¤ÔËÐÐ
ntpd£¬ ²¢´øÉÏ
/etc/rc.conf
ÖÐµÄ ntpd_flags ËùÖ¸¶¨µÄ²ÎÊý¡£
ÀýÈ磺
&prompt.root; ntpd -p /var/run/ntpd.pid
ÔÚÁÙʱÐ﵀ Internet Á¬½ÓÉÏʹÓà ntpd
&man.ntpd.8; ³ÌÐòµÄÕý³£¹¤×÷²¢²»ÐèÒªÓÀ¾ÃÐ﵀ Internet Á¬½Ó¡£
È»¶ø£¬ Èç¹ûÄúµÄÁÙʱÐÔÁ¬½ÓÊÇÅäÖÃΪ°´Ð貦ºÅµÄ£¬
ÄÇô·ÀÖ¹ NTP ͨѶƵ·±´¥·¢²¦ºÅ£¬ »ò±£³ÖÁ¬½Ó¾ÍÓбØÒªÁË¡£
Èç¹ûÄúʹÓÃÓû§¼¶ PPP£¬ ¿ÉÒÔʹÓà filter
Óï¾ä£¬ ÔÚ /etc/ppp/ppp.conf ÖнøÐбØÒªµÄÉèÖá£
ÀýÈ磺
set filter dial 0 deny udp src eq 123
# Prevent NTP traffic from initiating dial out
set filter dial 1 permit 0 0
set filter alive 0 deny udp src eq 123
# Prevent incoming NTP traffic from keeping the connection open
set filter alive 1 deny udp dst eq 123
# Prevent outgoing NTP traffic from keeping the connection open
set filter alive 2 permit 0/0 0/0
ÒªÁË½â½øÒ»²½µÄÐÅÏ¢£¬ Çë²Î¿¼ &man.ppp.8; µÄ PACKET
FILTERING(°ü¹ýÂË) С½Ú£¬ ÒÔ¼°
/usr/share/examples/ppp/ ÖеÄÀý×Ó¡£
ijЩ Internet ·ÃÎÊÌṩÉÌ»á×èÖ¹µÍ±àºÅµÄ¶Ë¿Ú£¬
Õâ»áµ¼Ö NTP ÎÞ·¨Õý³£¹¤×÷£¬ ÒòΪÏìÓ¦ÎÞ·¨µ½´ïÄúµÄ»úÆ÷¡£
½øÒ»²½µÄÐÅÏ¢
¹ØÓÚ NTP ·þÎñÆ÷µÄÎĵµ£¬ ¿ÉÒÔÔÚ
/usr/share/doc/ntp/ ÕÒµ½ HTML
¸ñʽµÄ°æ±¾¡£
Tom
Rhodes
Contributed by
ʹÓà syslogd ¼Ç¼Զ³ÌÖ÷»úµÄÈÕÖ¾
´¦ÀíϵͳÈÕÖ¾¶ÔÓÚϵͳ°²È«ºÍ¹ÜÀíÊÇÒ»¸öÖØÒª·½Ãæ¡£
µ±Óжą̀·Ö²¼ÔÚÖÐÐÍ»ò´óÐÍÍøÂçµÄ»úÆ÷£¬ÔÙ»òÕßÊÇ´¦ÓÚ¸÷ÖÖ²»Í¬ÀàÐ͵ÄÍøÂçÖУ¬
¼àÊÓËûÃÇÉÏÃæµÄÈÕÖ¾ÎļþÔòÏԵ÷dz£ÄÑÒÔ²Ù×÷£¬ ÔÚÕâÖÖÇé¿öÏ£¬
ÅäÖÃÔ¶³ÌÈÕÖ¾¼Ç¼ÄÜʹÕû¸ö´¦Àí¹ý³Ì±äµÃ¸ü¼ÓÇáËÉ¡£
¼¯ÖмǼÈÕÖ¾µ½Ò»Ì¨Ö¸¶¨µÄ»úÆ÷Äܹ»¼õÇáһЩÈÕÖ¾Îļþ¹ÜÀíµÄ¸ºµ£¡£
ÈÕÖ¾ÎļþµÄÊÕ¼¯£¬ ºÏ²¢ÓëÑ»·¿ÉÒÔÔÚÒ»´¦ÅäÖã¬
ʹÓà &os; ÔÉúµÄ¹¤¾ß£¬ ±ÈÈç &man.syslogd.8; ºÍ &man.newsyslog.8;¡£
ÔÚÒÔϵÄÅäÖÃʾÀýÖУ¬ Ö÷»ú A£¬ ÃüÃûΪ
logserv.example.com£¬
½«ÓÃÀ´ÊÕ¼¯±¾µØÍøÂçµÄÈÕÖ¾ÐÅÏ¢¡£ Ö÷»ú B£¬
ÃüÃûΪ logclient.example.com
½«°ÑÈÕÖ¾ÐÅÏ¢´«Ë͸ø·þÎñÆ÷¡£ ÔÚÏÖʵÖУ¬
ÕâÁ½¸öÖ÷»ú¶¼ÐèÒªÅäÖÃÕýÈ·µÄÕýÏòºÍ·´ÏòµÄ DNS
»òÕßÔÚ /etc/hosts ÖмǼ¡£
·ñÔò£¬ Êý¾Ý½«±»·þÎñÆ÷¾ÜÊÕ¡£
ÈÕÖ¾·þÎñÆ÷µÄÅäÖÃ
ÈÕÖ¾·þÎñÆ÷ÊÇÅäÖóÉÓÃÀ´½ÓÊÕÔ¶³ÌÖ÷»úÈÕÖ¾ÐÅÏ¢µÄ»úÆ÷¡£
ÔÚ´ó¶àÊýµÄÇé¿öÏÂÕâÊÇΪÁË·½±ãÅäÖ㬠»òÕßÊÇΪÁ˸üºÃµÄ¹ÜÀí¡£
²»ÂÛÊǺÎÔÒò£¬ ÔÚ¼ÌÐøÉîÈë֮ǰÐèÒªÌáһЩ±ØÐèÌõ¼þ¡£
Ò»¸öÕýÈ·ÅäÖõÄÈÕÖ¾·þÎñÆ÷±ØÐë·ûºÏÒÔϼ¸¸ö×î»ù±¾µÄÌõ¼þ£º
·þÎñÆ÷ºÍ¿Í»§¶ËµÄ·À»ðǽ¹æÔòÔÊÐí 514 ¶Ë¿ÚÉϵÄ
UDP ±¨ÎÄͨ¹ý¡£
syslogd ±»ÅäÖóɽÓÊÜ´ÓÔ¶³Ì¿Í»§·¢À´µÄÏûÏ¢¡£
syslogd ·þÎñÆ÷ºÍËùÓеĿͻ§¶Ë¶¼±ØÐëÓÐÅäÓÐÕýÈ·µÄÕýÏòºÍ·´Ïò
DNS£¬ »òÕßÔÚ
/etc/hosts ÖÐÓÐÏàÓ¦ÅäÖá£
ÅäÖÃÈÕÖ¾·þÎñÆ÷£¬ ¿Í»§¶Ë±ØÐëÔÚ
/etc/syslog.conf ÖÐÁгö,
²¢Ö¸¶¨ÈÕÖ¾µÄ facility£º
+logclient.example.com
*.* /var/log/logclient.log
¸ü¶à¹ØÓÚ¸÷ÖÖ±»Ö§³Ö²¢¿ÉÓÃµÄ facility
ÄÜÔÚ &man.syslog.conf.5; ÊÖ²áÒ³ÖÐÕÒµ½¡£
Ò»µ©¼ÓÈëÒÔºó£¬ ËùÓдËÀà facility
ÏûÏ¢¶¼»á±»¼Ç¼µ½ÏÈǰָ¶¨µÄÎļþ
/var/log/logclient.log¡£
Ìṩ·þÎñµÄ»úÆ÷»¹ÐèÒªÔÚÆä
/etc/rc.conf ÖÐÅäÖãº
syslogd_enable="YES"
syslogd_flags="-a logclient.example.com -v -v"
µÚÒ»¸öÑ¡Ïî±íʾÔÚϵͳÆô¶¯Ê±ÆôÓà syslogd
·þÎñ£¬ µÚ¶þ¸öÑ¡Ïî±íʾÔÊÐí·þÎñÆ÷½ÓÊÕÀ´×ÔÖ¸¶¨ÈÕÖ¾Ô´¿Í»§¶ËµÄÊý¾Ý¡£
µÚ¶þÐÐÅäÖÃÖÐ×îºóµÄ²¿·Ö£¬ ʹÓà £¬
±íʾÔö¼ÓÈÕÖ¾ÏûÏ¢µÄÏêϸ³Ì¶È¡£ ÔÚµ÷Õû facility ÅäÖõÄʱºò£¬
Õâ¸öÅäÖ÷dz£ÓÐÓ㬠ÒòΪ¹ÜÀíÔ±Äܹ»¿´µ½ÄÄЩÏûÏ¢½«×÷ΪÄĸö
facility µÄÄÚÈÝÀ´¼Ç¼¡£
¿ÉÒÔͬʱָ¶¨¶à¸ö Ñ¡ÏîÀ´ÔÊÐí¶à¸ö¿Í»§»ú¡£
´ËÍ⣬ »¹¿ÉÒÔÖ¸¶¨ IP
µØÖ·»òÍø¶Î£¬ Çë²ÎÔÄ
&man.syslog.3; Áª»úÊÖ²áÒÔÁ˽â¿ÉÓÃÅäÖõÄÍêÕûÁÐ±í¡£
×îºó£¬ ÈÕÖ¾ÎļþÓ¦¸Ã±»´´½¨¡£ ²»ÂÛÄãÓúÎÖÖ·½·¨´´½¨£¬
±ÈÈç &man.touch.1; ÄܺܺõÄÍê³É´ËÀàÈÎÎñ£º
&prompt.root; touch /var/log/logclient.log
´Ëʱ£¬ Ó¦¸ÃÖØÆô²¢È·ÈÏһϠsyslogd
ÊØ»¤½ø³Ì£º
&prompt.root; /etc/rc.d/syslogd restart
&prompt.root; pgrep syslog
Èç¹û·µ»ØÁËÒ»¸ö PIC µÄ»°£¬
·þÎñ¶ËÓ¦¸Ã±»³É¹¦ÖØÆôÁË, ²¢¼ÌÐø¿ªÊ¼ÅäÖÿͻ§¶Ë¡£
Èç¹û·þÎñ¶ËûÓÐÖØÆôµÄ»°£¬ ÇëÔÚ
/var/log/messages
ÈÕÖ¾ÖвéÔÄÏà¹ØÊä³ö¡£
ÈÕÖ¾¿Í»§¶ËÅäÖÃ
ÈÕÖ¾¿Í»§¶ËÊÇһ̨·¢ËÍÈÕÖ¾ÐÅÏ¢µ½ÈÕÖ¾·þÎñÆ÷µÄ»úÆ÷£¬
²¢ÔÚ±¾µØ±£´æ¿½±´¡£
ÓëÈÕÖ¾·þÎñÆ÷ÀàËÆ£¬ ¿Í»§¶ËÒ²ÐèÒªÂú×ãһЩ×î»ù±¾µÄÌõ¼þ£º
&man.syslogd.8;
±ØÐë±»ÅäÖóɷ¢ËÍÖ¸¶¨ÀàÐ͵ÄÏûÏ¢µ½ÄܽÓÊÕËûÃǵÄÈÕÖ¾·þÎñÆ÷¡£
·À»ðǽ±ØÐëÔÊÐí 514 ¶Ë¿ÚÉ쵀 UDP °üͨ¹ý£»
±ØÐëÅäÖÃÕýÏòÓë·´Ïò DNS£¬
»òÕßÔÚ /etc/hosts ÖÐÓÐÕýÈ·µÄ¼Ç¼¡£
Ïà±È·þÎñÆ÷À´ËµÅäÖÿͻ§¶Ë¸üÇáËÉһЩ¡£
¿Í»§¶ËµÄ»úÆ÷ÔÚ /etc/rc.conf
ÖÐ×öÈçϵÄÉèÖãº
syslogd_enable="YES"
syslogd_flags="-s -v -v"
ºÍÇ°ÃæÀàËÆ£¬ ÕâЩѡÏî»áÔÚϵͳÆô¶¯¹ý³ÌÖÐÆôÓÃ
syslogd ·þÎñ£¬ ²¢Ôö¼ÓÈÕÖ¾ÏûÏ¢µÄÏêϸ³Ì¶È¡£
¶ø
Ñ¡ÏîÔò±íʾ½ûÖ¹·þÎñ½ÓÊÕÀ´×ÔÆäËûÖ÷»úµÄÈÕÖ¾¡£
Facility ÊÇÃèÊöij¸öÏûÏ¢ÓÉϵͳµÄÄIJ¿·ÖÉú³ÉµÄ¡£ ¾ÙÀýÀ´Ëµ£¬
ftp ºÍ ipfw ¶¼ÊÇ facility¡£
µ±ÕâÁ½Ïî·þÎñÉú³ÉÈÕÖ¾ÏûϢʱ£¬ ËüÃÇͨ³£ÔÚÈÕÖ¾ÏûÏ¢Öаüº¬ÁËÕâÁ½ÖÖ¹¤¾ß¡£
Facility ͨ³£´øÓÐÒ»¸öÓÅÏȼ¶»òµÈ¼¶£¬
¾ÍÊÇÓÃÀ´±ê¼ÇÒ»¸öÈÕÖ¾ÏûÏ¢µÄÖØÒª³Ì¶È¡£ ×îÆÕͨµÄΪ
warning ºÍ info¡£
Çë²ÎÔÄ &man.syslog.3; ÊÖ²áÒ³ÒÔ»ñµÃÒ»¸öÍêÕû¿ÉÓõÄ
facility ÓëÓÅÏȼ¶ÁÐ±í¡£
ÈÕÖ¾·þÎñÆ÷±ØÐëÔÚ¿Í»§¶ËµÄ /etc/syslog.conf
ÖÐÖ¸Ã÷¡£ ÔÚ´ËÀýÖУ¬ @
·ûºÅ±»ÓÃÀ´±íʾ·¢ËÍÈÕÖ¾Êý¾Ýµ½Ô¶³ÌµÄ·þÎñÆ÷£¬
¿´ÉÏÈ¥²î²»¶àÈçÏÂÕâÑù£º
*.* @logserv.example.com
Ìí¼Óºó£¬ ±ØÐëÖØÆô syslogd
ʹµÃÉÏÊöÐÞ¸ÄÉúЧ£º
&prompt.root; /etc/rc.d/syslogd restart
²âÊÔÈÕÖ¾ÏûÏ¢ÊÇ·ñÄÜͨ¹ýÍøÂç·¢ËÍ£¬
ÔÚ×¼±¸·¢³öÏûÏ¢µÄ¿Í»§»úÉÏÓà &man.logger.1; À´Ïò
syslogd ·¢³öÐÅÏ¢£º
&prompt.root; logger "Test message from logclient"
Õâ¶ÎÏûÏ¢ÏÖÔÚÓ¦¸Ãͬʱ³öÏÖÔÚ¿Í»§»úµÄ
/var/log/messages ÒÔ¼°ÈÕÖ¾·þÎñÆ÷µÄ
/var/log/logclient.log ÖС£
µ÷ÊÔÈÕÖ¾·þÎñÆ÷
ÔÚijЩÇé¿öÏ£¬ Èç¹ûÈÕÖ¾·þÎñÆ÷ûÓÐÊÕµ½ÏûÏ¢µÄ»°¾ÍÐèÒªµ÷ÊÔÒ»·¬ÁË¡£
Óм¸¸ö¿ÉÄܵÄÔÒò£¬ ×î³£¼ûµÄÁ½¸öÊÇÍøÂçÁ¬½ÓµÄÎÊÌâºÍ
DNS µÄÎÊÌâ¡£ ΪÁ˲âÊÔÕâЩÎÊÌ⣬
ÇëÈ·ÈÏÁ½±ßµÄ»úÆ÷¶¼ÄÜʹÓà /etc/rc.conf
ÖÐËùÉ趨µÄÖ÷»úÃû·ÃÎʵ½¶Ô·½¡£ Èç¹ûÕâ¸öÄÜÕý³£¹¤×÷µÄ»°£¬
ÄÇô¾ÍÐèÒª¶Ô /etc/rc.conf
ÖÐµÄ syslogd_flags Ñ¡Ïî×öЩÐÞ¸ÄÁË¡£
ÔÚÒÔϵÄʾÀýÖУ¬
/var/log/logclient.log Êǿյģ¬
/var/log/message ÖÐҲûÓбíÃ÷ÈκÎʧ°ÜµÄÔÒò¡£
ΪÁËÔö¼Óµ÷ÊÔµÄÊä³ö£¬ ÐÞ¸Ä ayalogd_flags
Ñ¡ÏîÖÁÀàËÆÓÚÈçϵÄʾÀý£¬ ²¢ÖØÆô·þÎñ£º
syslogd_flags="-d -a logclien.example.com -v -v"
&prompt.root; /etc/rc.d/syslogd restart
ÔÚÖØÆô·þÎñÖ®ºó£¬ ÆÁÄ»ÉϽ«Á¢¿ÌÉÁÏÖÀàËÆÕâÑùµÄµ÷ÊÔÊý¾Ý£º
logmsg: pri 56, flags 4, from logserv.example.com, msg syslogd: restart
syslogd: restarted
logmsg: pri 6, flags 4, from logserv.example.com, msg syslogd: kernel boot file is /boot/kernel/kernel
Logging to FILE /var/log/messages
syslogd: kernel boot file is /boot/kernel/kernel
cvthname(192.168.1.10)
validate: dgram from IP 192.168.1.10, port 514, name logclient.example.com;
rejected in rule 0 due to name mismatch.
ºÜÃ÷ÏÔ£¬ÏûÏ¢ÊÇÓÉÓÚÖ÷»úÃû²»Æ¥Åä¶ø±»¾ÜÊյġ£
ÔÚÒ»µãÒ»µãµÄ¼ì²éÁËÅäÖÃÎļþÖ®ºó£¬ ·¢ÏÖÁË
/etc/rc.conf ÖÐÈçÏÂÕâÐÐÓÐÊäÈë´íÎó£º
syslogd_flags="-d -a logclien.example.com -v -v"
ÕâÐÐÓ¦¸Ã°üºÓÐ logclient£¬ ¶ø²»ÊÇ
logclien¡£
ÔÚ×öÁËÕýÈ·µÄÐ޸IJ¢ÖØÆôÖ®ºó±ãÄܼûµ½Ô¤ÆÚµÄЧ¹ûÁË£º
&prompt.root; /etc/rc.d/syslogd restart
logmsg: pri 56, flags 4, from logserv.example.com, msg syslogd: restart
syslogd: restarted
logmsg: pri 6, flags 4, from logserv.example.com, msg syslogd: kernel boot file is /boot/kernel/kernel
syslogd: kernel boot file is /boot/kernel/kernel
logmsg: pri 166, flags 17, from logserv.example.com,
msg Dec 10 20:55:02 <syslog.err> logserv.example.com syslogd: exiting on signal 2
cvthname(192.168.1.10)
validate: dgram from IP 192.168.1.10, port 514, name logclient.example.com;
accepted in rule 0.
logmsg: pri 15, flags 0, from logclient.example.com, msg Dec 11 02:01:28 trhodes: Test message 2
Logging to FILE /var/log/logclient.log
Logging to FILE /var/log/messages
´Ë¿Ì£¬ ÏûÏ¢Äܹ»±»ÕýÈ·½ÓÊÕ²¢±£´æÈëÎļþÁË¡£
°²È«ÐÔ·½ÃæµÄ˼¿¼
¾ÍÏñÆäËûµÄÍøÂç·þÎñÒ»Ñù£¬ ÔÚʵÏÖÅäÖÃ֮ǰÐèÒª¿¼Âǰ²È«ÐÔ¡£
ÓÐʱÈÕÖ¾ÎļþÒ²°üº¬ÁËÃô¸ÐÐÅÏ¢£¬ ±ÈÈç±¾µØÖ÷»úÉÏËùÆôÓõķþÎñ£¬
Óû§ÕʺźÍÅäÖÃÊý¾Ý¡£ ´Ó¿Í»§¶Ë·¢³öµÄÊý¾Ý¾¹ýÍøÂçµ½´ï·þÎñÆ÷£¬
ÕâÆÚ¼ä¼ÈûÓмÓÃÜҲûÓÐÃÜÂë±£»¤¡£ Èç¹ûÓмÓÃÜÐèÒªµÄ»°£¬
¿ÉÒÔʹÓà security/stunnel£¬
Ëü½«ÔÚÒ»¸ö¼ÓÃܵÄËíµÀÖд«ÊäÊý¾Ý¡£
±¾µØ°²È«Ò²Í¬ÑùÊǸöÎÊÌâ¡£ ÈÕÖ¾ÎļþÔÚʹÓÃÖлòÑ»·×ªºó¶¼Ã»Óб»¼ÓÃÜ¡£
±¾µØÓû§¿ÉÄܶÁÈ¡ÕâЩÎļþÒÔ»ñµÃ¶Ôϵͳ¸üÉîÈëµÄÁ˽⡣
¶ÔÓÚÕâÀàÇé¿ö£¬ ¸øÕâЩÎļþÉèÖÃÕýÈ·µÄȨÏÞÊǷdz£ÓбØÒªµÄ¡£
&man.newsyslog.8; ¹¤¾ßÖ§³Ö¸øÐ´´½¨ºÍÑ»·µÄÈÕÖ¾ÉèÖÃȨÏÞ¡£
°ÑÈÕÖ¾ÎļþµÄȨÏÞÉèÖÃΪ 600
ÄÜ×èÖ¹±¾µØÓû§²»±ØÒªµÄ¿ú̽¡£
diff --git a/zh_CN.GB2312/books/handbook/ppp-and-slip/chapter.xml b/zh_CN.GB2312/books/handbook/ppp-and-slip/chapter.xml
index 55bf7c23b6..2d14e538cd 100644
--- a/zh_CN.GB2312/books/handbook/ppp-and-slip/chapter.xml
+++ b/zh_CN.GB2312/books/handbook/ppp-and-slip/chapter.xml
@@ -1,2883 +1,2837 @@
Jim
Mock
Restructured, reorganized, and updated by
PPP ºÍ SLIP
¸ÅÊö
-
- PPP
-
-
- SLIP
-
FreeBSD Óкܶ෽·¨¿ÉÒÔ½«¼ÆËã»úÓë¼ÆËã»úÁ¬½ÓÆðÀ´¡£
ͨ¹ýʹÓò¦ºÅ modem À´½¨Á¢ÍøÂç»ò Internet Á¬½Ó£¬
»òÔÊÐíÆäËûÈËͨ¹ýÄúµÄ»úÆ÷À´Á¬ÉÏÍøÂ磬
- ÕâЩ¶¼ÒªÇóʹÓà PPP »ò SLIP¡£
+ ÕâЩ¶¼ÒªÇóʹÓà PPPPPP »ò SLIP¡£SLIP
ÕâÕ½«Ïêϸ½éÉÜÉèÖÃÕâЩ»ùÓÚ modem µÄͨÐÅ·þÎñµÄ·½·¨¡£
¶ÁÍêÕâÒ»Õ£¬ Äú½«Á˽⣺
ÈçºÎÉèÖÃÓû§¼¶ PPP¡£
ÈçºÎÉèÖÃÄں˼¶ PPP¡£ (½öÏÞ &os; 7.X)¡£
ÈçºÎÉèÖà PPPoE (PPP over
Ethernet)¡£
ÈçºÎÉèÖà PPPoA (PPP over
ATM)¡£
ÈçºÎÅäÖúͰ²×° SLIP ¿Í»§¶ËºÍ·þÎñÆ÷¡£ (½öÏÞ &os; 7.X)¡£
PPP
Óû§¼¶ PPP
PPP
Äں˼¶ PPP
PPP
PPPoE
ÔÚÔĶÁÕâÕÂ֮ǰ£¬ ÄúÓ¦£º
ÊìϤ»ù±¾µÄÍøÂçÊõÓï¡£
Àí½â²¦ºÅÁ¬½ÓºÍ PPP¡¢ SLIP µÄ»ù´¡ÖªÊ¶¡£
Äú¿ÉÄÜÏëÖªµÀÓû§¼¶ PPP ÓëÄں˼¶ PPP Ö®¼äµÄ²»Í¬Ö®´¦¡£ »Ø´ðºÜ¼òµ¥£º
Óû§¼¶ PPP ´¦ÀíÓû§¼¶µÄÊäÈëºÍÊä³öÊý¾Ý£¬ ¶ø²»ÊÇÄں˼¶¡£
ÔÚÄÚºËÓëÓû§ÇøÖ®¼ä¸´ÖÆÊý¾ÝµÄ»¨·ÑÒª´óһЩ£¬
µ«ËüÄÜÌṩ¾ßÓиü¶àÌØÐÔµÄPPPʵÏÖ¡£
Óû§¼¶PPPʹÓà tun
É豸ÓëÍâ½çͨÐŶøÄں˼¶ PPP ʹÓÃ
ppp É豸¡£
ÔÚÕâÕÂÖУ¬ Èç¹ûûÓÐÌØÊâ˵Ã÷£¬
Ôò ppp Ö¸µÄÊÇÓû§Ì¬ PPP£¬
³ý·ÇÐèÒªºÍÆäËü PPP Èí¼þ£¬ ÀýÈç
pppd (½öÏÞ &os; 7.X) ¼ÓÒÔÇø·Ö¡£
ÁíÍ⣬ ÈôûÓжîÍâµÄ×¢Ã÷£¬ ±¾ÕÂËù½éÉܵÄËùÓÐÃüÁî¶¼ÐèÒªÒÔ
root Éí·ÝÀ´ÔËÐÐȨÏÞ¡£
Tom
Rhodes
Updated and enhanced by
Brian
Somers
Originally contributed by
Nik
Clayton
With input from
Dirk
Frömberg
Peter
Childs
ʹÓÃÓû§¼¶ PPP
´Ó &os; 8.0 ¿ªÊ¼£¬ &man.uart.4; Çý¶¯È¡´úÁË
&man.sio.4; Çý¶¯¡£ ÓÃÒÔ±íʾ´®¿ÚµÄÉ豸½ÚµãÓÉ·Ö±ð
/dev/cuadN ¸ÄΪÁË
/dev/cuauN£¬
²¢´Ó
/dev/ttydN ¸ÄΪÁË
/dev/ttyuN¡£
&os; 7.X Óû§ÔÚÉý¼¶Ê±ÐèÒªÒòÓ¦Ö®¶ÔÅäÖÃÎļþ½øÐбØÒªµÄ¸ü¸Ä¡£
Óû§¼¶ PPP
ǰÌáÌõ¼þ
±¾Õ¼ٶ¨Äú¾ß±¸ÈçÏÂÌõ¼þ£º
-
- ISP
-
-
- PPP
-
- ÄúÓÐÒ»¸ö ISP ÌṩµÄÓÃÓÚÁ¬½ÓʹÓà PPP µÄÕʺš£
+ ÄúÓÐÒ»¸ö ISPISP ÌṩµÄÓÃÓÚÁ¬½ÓʹÓà PPPPPP µÄÕʺš£
ÄúÐèÒªÓÐÁ¬½ÓÔÚϵͳÉÏ£¬ ²¢×öÁËÕýÈ·ÅäÖÃµÄ modem£¬
»òÆäËûÄܹ»Á¬½ÓÄú ISP µÄÉ豸¡£
ISP µÄ²¦ºÅºÅÂë¡£
-
- PAP
-
-
- CHAP
-
-
- UNIX
-
-
- login name
-
-
- password
-
- ÄúµÄµÇ¼Ãû³ÆºÍÃÜÂë (¿ÉÄÜÊÇÒ»°ãµÄ UNIX ·ç¸ñµÄµÇ¼ÃûºÍÃÜÂë¶Ô£¬
- Ò²¿ÉÄÜÊÇ PAP »ò CHAP µÇ¼ÃûºÍÃÜÂë¶Ô)¡£
+ ÄúµÄµÇ¼Ãû³ÆºÍÃÜÂë (¿ÉÄÜÊÇÒ»°ãµÄ UNIXUNIX ·ç¸ñµÄµÇ¼ÃûºÍÃÜÂë¶Ô£¬login namepassword
+ Ò²¿ÉÄÜÊÇ PAPPAP »ò CHAPCHAP µÇ¼ÃûºÍÃÜÂë¶Ô)¡£
-
- nameserver
-
-
Ò»¸ö»ò¶à¸öÓòÃû·þÎñÆ÷ IP µØÖ·¡£
ͨ³££¬ Äú»á´ÓISP´¦µÃµ½Á½¸öÕâÑùµÄIPµØÖ·¡£
Èç¹ûÄúÖÁÉٵõ½ÁËÒ»¸ö£¬ ¾Í¿ÉÒÔÔÚÎļþ
ppp.conf ÖмÓÈë enable dns
ÃüÁîʹ ppp ÉèÖÃÓòÃû·þÎñ¡£
- Õâ¸ö¹¦ÄÜÈ¡¾öÓÚ ISP ¶ÔÖ§³Ö DNS ÐÉ̵ľßÌåʵÏÖ¡£
+ Õâ¸ö¹¦ÄÜÈ¡¾öÓÚ ISP ¶ÔÖ§³Ö DNS ÐÉ̵ľßÌåʵÏÖ¡£nameserver
ÏÂÃæµÄÐÅÏ¢ÓÉÄúµÄ ISP Ìṩ£¬ µ«²»ÊDZØÐèµÄ£º
ISPµÄÍø¹ØIPµØÖ·¡£ Íø¹ØÊÇÄú×¼±¸Á¬½Ó£¬ ²¢ÉèΪ
ĬÈÏ·ÓÉ µÄÖ÷»ú¡£
Èç¹ûÄúûÓÐÕâ¸öÐÅÏ¢£¬ Äú¿ÉÒÔÐé¹¹Ò»¸ö£¬
ÔÚÁ¬½Óʱ ISP µÄ PPP ·þÎñÆ÷»á×Ô¶¯¸æËßÄúÕýÈ·µÄÖµ¡£
Õâ¸öÐé¹¹µÄ IP µØÖ·ÔÚ ppp ÖмÇ×ö
HISADDR¡£
×¼±¸Ê¹ÓõÄ×ÓÍøÑÚÂë¡£ Èç¹ûISPûÓÐÌṩ£¬ Ò»°ãʹÓÃ
255.255.255.255 ÊÇûÓÐÎÊÌâµÄ¡£
-
- static IP address (¾²Ì¬ IP µØÖ·)
-
-
Èç¹û ISP ÌṩÁ˾²Ì¬µÄIPµØÖ·ºÍÖ÷»úÃû£¬ ¿ÉÒÔÊäÈëËüÃÇ¡£
- ·´Ö®£¬ ÔòÓ¦ÈöԷ½Ö÷»úÖ¸¶¨ËüÈÏΪºÏÊ浀 IP µØÖ·¡£
+ ·´Ö®£¬ ÔòÓ¦ÈöԷ½Ö÷»úÖ¸¶¨ËüÈÏΪºÏÊ浀 IP µØÖ·¡£static IP address (¾²Ì¬ IP µØÖ·)
Èç¹ûÄú²»ÖªµÀÕâЩÐÅÏ¢£¬ ÇëÓëÄúµÄ ISP ÁªÏµ¡£
ÔÚÕâ½ÚÖУ¬ ËùÓÐ×÷ΪÀý×ÓչʾµÄÅäÖÃÎļþÖж¼ÓÐÐкš£
ÕâЩÐкÅÖ»ÊÇΪÁËʹ½âÊͺÍÌÖÂÛ±äµÃ·½±ã£¬ ÔÚÕæÊµµÄÎļþÖв¢²»´æÔÚ¡£
´ËÍ⣬ ÔÚ±ØÒªÊ±Ó¦Ê¹Óà Tab ºÍ¿Õ¸ñÀ´½øÐÐËõ½ø¡£
PPP×Ô¶¯»¯ÅäÖÃ
PPP
configuration (ÅäÖÃ)
pppºÍpppd(PPPµÄÄں˼¶ÊµÏÖ£¬ ½öÏÞ &os; 7.X)
¶¼Ê¹Óà /etc/ppp Ŀ¼ÖеÄÅäÖÃÎļþ¡£ Óû§¼¶ PPP
µÄÀý×Ó¿ÉÒÔÔÚ
/usr/share/examples/ppp/ ÖÐÕÒµ½¡£
ÅäÖÃpppÒªÇó¸ù¾ÝÄúµÄÐèÒª±à¼¼¸¸öÎļþ¡£
±à¼ÄöÎļþÈ¡¾öÓÚÄúµÄ
IP ÊǾ²Ì¬·ÖÅä (ÿ´Î¶¼Ê¹ÓÃͬһ¸öµØÖ·)
»¹ÊǶ¯Ì¬·ÖÅäµÄ (ÿ´ÎÁ¬½Óµ½ ISP ¶¼»á»ñµÃ²»Í¬µÄ IP µØÖ·)¡£
PPPºÍ¾²Ì¬IPµØÖ·
PPP
with static IP addresses
ÄúÐèÒª±à¼ÅäÖÃÎļþ/etc/ppp/ppp.conf£¬ ÈçÏÂËùʾ¡£
ÒÔðºÅ:½áβµÄÐдӵÚÒ»ÁÐ (ÐÐÊ×)¿ªÊ¼£¬
ÆäËüËùÓеÄÐж¼ÒªÊ¹Óÿոñ»òÖÆ±í·û (Tab) À´Ëõ½ø¡£
1 default:
2 set log Phase Chat LCP IPCP CCP tun command
3 ident user-ppp VERSION (built COMPILATIONDATE)
4 set device /dev/cuau0
5 set speed 115200
6 set dial "ABORT BUSY ABORT NO\\sCARRIER TIMEOUT 5 \
7 \"\" AT OK-AT-OK ATE1Q0 OK \\dATDT\\T TIMEOUT 40 CONNECT"
8 set timeout 180
9 enable dns
10
11 provider:
12 set phone "(123) 456 7890"
13 set authname foo
14 set authkey bar
15 set login "TIMEOUT 10 \"\" \"\" gin:--gin: \\U word: \\P col: ppp"
16 set timeout 300
17 set ifaddr x.x.x.x y.y.y.y 255.255.255.255 0.0.0.0
18 add default HISADDR
ÐÐ1£º
Ö¸¶¨Ä¬ÈϵÄÏî¡£ µ±PPPÔËÐÐʱÕâ¸öÏîÖеÄÃüÁ×Ô¶¯Ö´ÐС£
ÐÐ2£º
ÆôÓõǼ²ÎÊý¡£ ¹¤×÷Õý³£ºó£¬ Ϊ±ÜÃâ²úÉú¹ý¶àµÄÈÕÖ¾Îļþ£¬ ÕâÐÐÓ¦¸Ã¼ò»¯Îª£º
set log phase tun
ÐÐ 3£º
¸æËß PPP ÔõÑùÏò¶Ô·½±êʶ×Ô¼º¡£
Èç¹ûÔÚ½¨Á¢»òʹÓÃÁ¬½ÓʱÓöµ½ÈκÎÂé·³£¬ PPP¾Í»áÏò¶Ô·½Ö÷»ú×ÔÎÒ±êʶ¡£
¶Ô·½Ö÷»ú¹ÜÀíÔ±ÔÚ´¦ÀíÕâ¸öÎÊÌâʱ£¬ ÕâЩÐÅÏ¢»áÓÐÓá£
ÐÐ 4£º
±êÃ÷modemÒªÁ¬½ÓµÄ¶Ë¿ÚºÅ¡£
COM1 ¶ÔÓ¦µÄÉ豸ÊÇ
/dev/cuau0
¶ø COM2
¶ÔÓ¦µÄÔòÊÇ
/dev/cuau1¡£
ÐÐ 5£º
ÉèÖÃÁ¬½ÓµÄËÙ¶È¡£ Èç¹û 115200
ÓÐÎÊÌ⣬ ÊÔÊÔ 38400¡£
ÐÐ 6 & 7£º
-
- PPP
- user PPP
-
-
- ²¦ºÅ×Ö·û´®¡£ Óû§¼¶ PPP ʹÓÃÒ»ÖÖÓë &man.chat.8;³ÌÐòÏàËÆµÄÓï·¨¡£
+ ²¦ºÅ×Ö·û´®¡£ Óû§¼¶ PPPPPPuser PPP ʹÓÃÒ»ÖÖÓë &man.chat.8;³ÌÐòÏàËÆµÄÓï·¨¡£
Çë²Î¿¼Áª»úÊÖ²áÁ˽âÕâÖÖÓïÑÔµÄÏà¹ØÐÅÏ¢¡£
×¢Ò⣬ ΪÁ˱ãÓÚÔĶÁ´ËÃüÁî½øÐÐÁË»»ÐС£ ÈκÎ
ppp.conf ÀïµÄÃüÁî¶¼¿ÉÒÔÕâÑù×ö£¬
ǰÌáÊÇÐеÄ×îºóÒ»¸ö×Ö·û±ØÐëÊÇ \¡£
ÐÐ 8£º
ÉèÖÃÁ¬½ÓµÄʱ¼ä¼ä¸ô¡£ ĬÈÏÊÇ 180 Ã룬 ËùÒÔÕâÒ»ÐÐÊǶàÓàµÄ¡£
ÐÐ 9£º
¸æËßPPPÏò¶Ô·½Ö÷»úÈ·Èϱ¾µØÓòÃû½âÎöÉèÖá£
Èç¹ûÄúÔËÐÐÁ˱¾µØµÄÓòÃû·þÎñÆ÷£¬ ҪעÊÍ»òɾ³ýµôÕâÒ»ÐС£
ÐÐ 10£º
ΪÁ˿ɶÁÐÔµÄÐèÒªÉèÖÃÒ»¸ö¿ÕÐС£ ¿ÕÐлᱻPPPºöÂÔ¡£
ÐÐ 11£º
Ϊ provider
Ö¸¶¨Ò»¸öÏî¡£ ¿ÉÒԸijÉ
ISPµÄÃû×Ö£¬ ÕâÑùÄúÒÔºó¾Í¿ÉÒÔʹÓÃ
À´¿ªÆôÁ¬½Ó¡£
ÐÐ 12£º
ÉèÖÃÌṩÉ̵ĵ绰ºÅÂë¡£ ¶à¸öµç»°ºÅÂë¿ÉÒÔʹÓÃðºÅ (:)
»ò¹ÜµÀ·ûºÅ (|) ¸ô¿ª¡£
ÕâÁ½¸ö×Ö·ûµÄÇø±ðÔÚ&man.ppp.8;µÄÁª»úÊÖ²áÖÐÓнéÉÜ¡£
×ܵÄÀ´½²£¬ Èç¹ûÄúҪѻ·Ê¹ÓÃÕâЩºÅÂ룬 ¿ÉÒÔʹÓÃðºÅ¡£
Èç¹ûÄúÏëʹÓõÚÒ»¸öºÅÂ룬 µ±µÚÒ»¸öºÅÂëʧ°ÜÁËÔÙÓõڶþ¸öºÅÂ룬
¾ÍʹÓùܵÀ·ûºÅ¡£ ÈçËùʾµÄÄÇÑù£¬ Òª¸øÕû¸öµç»°ºÅÂë¼ÓÉÏÒýºÅ(")¡£
Èç¹ûµç»°ºÅÂëÀïÓпոñ£¬ ±ØÐëÓÃÒýºÅ(")½«ÆäÀ¨ÆðÀ´¡£
·ñÔò»áÔì³É¼òµ¥È´ÄÑÒÔ²ì¾õµÄ´íÎó¡£
ÐÐ 13 & 14£º
Ö¸¶¨Óû§ÃûºÍÃÜÂë¡£ µ±Ê¹Óà &unix; ·ç¸ñµÄÃüÁîÌáʾ·ûµÇ¼ʱ£¬
ÕâЩֵ¿ÉÒÔÓôøÓÐ \U \P ²ÎÊýµÄ set login
ÃüÁî½øÐÐÐ޸ġ£ µ±Ê¹ÓÃPAP»òCHAP½øÐÐÁ¬½Óʱ£¬ ÕâЩֵÔÚÑé֤ʹÓá£
ÐÐ 15£º
- PAP
- CHAP
Èç¹ûÄúʹÓõÄÊÇPAP»òÕßCHAP£¬ ÔÚÕâÀï¾Í²»»áÓеǼ¡£
ҪעÊÍ»òɾ³ýµôÕâÒ»ÐС£
- Çë²Î¿¼ PAP ºÍ CHAPÈÏÖ¤
+ Çë²Î¿¼ PAPPAP ºÍ CHAPÈÏÖ¤CHAP
ÒÔÁ˽â¸ü¶àϸ½Ú¡£
µÇ¼ÃüÁîÊǵÄÓï·¨ÊÇchatÀàÐ͵ġ£ ÔÚÕâ¸öÀý×ÓÖÐÊÇÕâÑùµÄ£º
J. Random Provider
login: foo
password: bar
protocol: ppp
ÄúÐèÒª¸Ä±äÕâ¸ö½Å±¾ÒÔÊʺÏÄú×Ô¼ºµÄÐèÒª¡£
µ±ÄúµÚÒ»´ÎдÕâ¸ö½Å±¾Ê±£¬ Ó¦µ±È·±£ÒѾÆôÓÃ
chat
²¢´¦ÓڵǼ״̬£¬
ÕâÑùÄú²ÅÄÜÈ·ÈÏͨÐÅÊÇ·ñÕýÔÚ°´¼Æ»®½øÐС£
ÐÐ16£º
- timeout
-
ÉèÖÃĬÈϵij¬Ê±Ê±¼ä¡£ ÕâÀ Á¬½ÓÈôÔÚ 300
ÃëÄÚÎÞÏìÓ¦½«±»¶Ï¿ª¡£Èç¹ûÄú²»ÏëÉèÖóɳ¬Ê±£¬
- ½«Õâ¸öÖµÉèÖóÉ0£¬ »òÔÚÃüÁîÐÐʹÓà ѡÏî¡£
+ ½«Õâ¸öÖµÉèÖóÉ0£¬ »òÔÚÃüÁîÐÐʹÓà ѡÏî¡£timeout
ÐÐ 17£º
- ISP
-
- ÉèÖýӿڵØÖ·¡£ ÄúÐèÒªÓà ISP Ìṩ¸øÄúµÄ IP µØÖ·Ìæ»»×Ö·û´®
+ ÉèÖýӿڵØÖ·¡£ ÄúÐèÒªÓà ISPISP Ìṩ¸øÄúµÄ IP µØÖ·Ìæ»»×Ö·û´®
x.x.x.x£¬ Óà ISP µÄÍø¹Ø IP
µØÖ· (¼´ÄúÒªÁ¬½ÓµÄÖ÷»ú) Ìæ»»×Ö·û´®
y.y.y.y¡£
Èç¹ûISPûÓиøÄúÌá¹©Íø¹ØµØÖ·£¬ ¿ÉÒÔʹÓÃ
10.0.0.2/0¡£
Èç¹ûÄúÐèҪʹÓÃÒ»¸ö ²Âµ½
µÄµØÖ·£¬
ÇëÈ·±£ÔÚ /etc/ppp/ppp.linkup
ÖÐΪÿ¸ö PPPºÍ¶¯Ì¬IPµØÖ·
Ö¸Áî´´½¨ÁËÕâÒ»Ïî¡£ Èç¹ûûÓÐÕâÒ»ÐУ¬ ppp
½«ÎÞ·¨ÒÔ Ä£Ê½ÔËÐС£
µÚ18ÐУº
Ìí¼ÓÒ»¸öµ½ISPÍø¹ØµÄĬÈÏ·ÓÉ¡£
HISADDRÕâ¸ö¹Ø¼ü×ֻᱻµÚ17ÐÐËùÖ¸¶¨µÄÍø¹ØµØÖ·Ìæ»»¡£
ÕâÐбØÐë³öÏÖÔÚµÚ17ÐÐÖ®ºó£¬ÒÔÃâÔÚ HISADDR
³õʼ»¯Ö®Ç°Ê¹ÓÃËüµÄÖµ¡£
Èç¹ûÄú²»ÏëʹÓà µÄ PPP£¬ÔòÕâÐÐӦŲµ½
ppp.linkup ÎļþÖС£
ÈôÄúÓÐÒ»¸ö¾²Ì¬IPµØÖ·£¬ ÇÒʹÓÃ
ģʽÔËÐÐppp(ÒòΪÔÚÁ¬½Ó֮ǰÒѾÕýÈ·ÉèÖÃÁË·ÓɱíÏî)£¬ ÄǾͲ»ÐèÒªÔÙÏòppp.linkup
Ìí¼ÓÏî¡£ Äú¿ÉÄÜÏ£ÍûÔÚÁ¬½ÓÒÔºó´´½¨Ò»¸öÏîÀ´µ÷ÓóÌÐò¡£ ÕâÔÚÒÔºóµÄsendmailµÄÀý×ÓÖлá½âÊÍ¡£
ʾÀýÅäÖÃÎļþ¿ÉÒÔÔÚĿ¼
/usr/share/examples/ppp/ ÖÐÕÒµ½¡£
PPPºÍ¶¯Ì¬IPµØÖ·
PPP
with dynamic IP addresses
IPCP
Èç¹ûISPû¸øÄúÖ¸¶¨¾²Ì¬µÄIPµØÖ·£¬ pppÒª±»ÅäÖóÉÄܹ»Óë¶Ô·½ÐÉÌÈ·¶¨±¾µØºÍÔ¶³ÌµØÖ·¡£
ÒªÍê³ÉÕâÏ×÷£¬ ÏÈÒª²Â
Ò»¸öIPµØÖ·£¬ È»ºóÔÊÐí
pppÔÚÁ¬½ÓºóʹÓÃIPÅäÖÃÐÒé(IPCP)½øÐÐÕýÈ·ÅäÖá£
ppp.confµÄÅäÖÃÊÇÓë
PPPºÍ¾²Ì¬IPµØÖ·Ò»ÑùµÄ£¬ ³ýÁËÒÔϵĸı䣺
17 set ifaddr 10.0.0.1/0 10.0.0.2/0 255.255.255.255 0.0.0.0
ÔÙ´ÎÇ¿µ÷£¬ ²»Òª°üÀ¨Ðкţ¬ ËüÖ»ÊÇÒ»¸öÒýÓñê¼Ç¡£ ËõÅÅÒ»¸ö¿Õ¸ñÊDZØÐèµÄ¡£
ÐÐ17£º
/ ×Ö·ûºóÃæÊÇ PPP ËùÒªÇóµÄµØÖ·ÑÚÂë¡£
Äú¿ÉÒÔ¸ù¾ÝÐèҪʹÓò»Í¬ IP µØÖ·£¬ µ«ÒÔÉϵÄÀý×ÓÓÀÔ¶ÊÇ¿ÉÐеġ£
×îºóµÄ²ÎÊý(0.0.0.0)¸æËß
PPP´Ó0.0.0.0 ¶ø²»ÊÇ 10.0.0.1 ¿ªÊ¼ÐÉ̵ØÖ·£¬ ¶ÔÓÚÓÐЩISP£¬
ÕâÊDZØÐèµÄ¡£ ²»Òª½« 0.0.0.0
×÷Ϊ set ifaddr µÄµÚÒ»¸ö²ÎÊý£¬
ÒòΪÕâʹµÃ PPP ÔÚ Ä£Ê½Ê±²»ÄÜÉèÖóõʼ·ÓÉ¡£
Èç¹ûÄú²»ÔËÐÐģʽ£¬
¾ÍÐèÒªÔÚ/etc/ppp/ppp.linkupÖд´½¨Ò»¸öÏî¡£
Á¬½Ó½¨Á¢Ö®ºó£¬ ppp.linkup±»ÆôÓᣠÕâʱºò£¬
ppp½«Ö¸ÅɽӿڵØÖ·£¬ ½Ó×ÅÔÙÌí¼Ó·ÓɱíÏ
1 provider:
2 add default HISADDR
ÐÐ 1£º
ΪÁ˽¨Á¢Á¬½Ó£¬
ppp »á°´ÕÕÈçϹæÔòÔÚ
ppp.linkupѰÕÒÏî:Ê×ÏÈ£¬ ÊÔͼѰÕÒÏàͬµÄ±êÇ©
(ÈçͬÔÚppp.confÒ»Ñù£©¡£ Èç¹ûʧ°ÜÁË£¬
ѰÕÒ×÷ÎªÍø¹Ø IP µØÖ·µÄÏ ´ËÏîÊÇËĸö°Ëλ×ֽڵķç¸ñ¡£
Èç¹ûÒÀ¾ÉûÓÐÕÒµ½£¬ ¾ÍѰÕÒ MYADDR Ïî
ÐÐ 2£º
ÕâÐиæËß pppÌí¼ÓÖ¸Ïò
HISADDRµÄĬÈÏ·ÓÉ¡£
HISADDRÓÉͨ¹ýIPCPÐÉ̵õ½µÄIPºÅÌæ»»¡£
²Î¿¼/usr/share/examples/ppp/ppp.conf.sample
ºÍ/usr/share/examples/ppp/ppp.linkup.sample
ÖеÄpmdemandÏîÒÔ»ñȡϸ½Ú»¯µÄÀý×Ó¡£
½ÓÊÕ²¦Èë
PPP
receiving incoming calls
µ±ÒªÅäÖà ppp½ÓÊÜÀ´×ÔLANÉϵÄ
²¦Èëʱ£¬ ÄúÐèÒª¾ö¶¨ÊÇ·ñ½«°üת¸øLAN¡£ Èç¹ûÊǵϰ£¬ Äú¾Í±ØÐë´Ó LAN
×ÓÍøÖиø¶Ô·½·ÖÅäÒ»¸öIP£¬ ÐèÒªÔÚÎļþ /etc/ppp/ppp.conf
ÖÐʹÓÃÃüÁî enable proxy¡£ Äú»¹Ó¦¸ÃÈ·¶¨Îļþ
/etc/rc.conf Öаüº¬ÒÔÏÂÄÚÈÝ£º
gateway_enable="YES"
ʹÓÃÄĸögetty£¿
ÅäÖà FreeBSD µÄ²¦ºÅ·þÎñ
ÃèÊöÁËÈçºÎÓà &man.getty.8; À´Æô¶¯²¦ºÅ·þÎñ¡£
³ýÁË getty Ö®Í⻹ÓÐ mgetty (¿Éͨ¹ý
comms/mgetty+sendfax port
À´°²×°)£¬
ËüÊÇ getty µÄÖÇÄܰ汾£¬ Êǰ´ÕÕ²¦ºÅÏßµÄ˼ÏëÉè¼ÆµÄ¡£
ʹÓà mgetty µÄºÃ´¦ÊÇËüÄÜ»ý¼«µØÓë modem ½øÐÐ
»á»°£¬
Õâ¾ÍÒâζ×ÅÈç¹ûÔÚ/etc/ttysÖеĶ˿ڱ»¹Ø±Õ£¬
ÄúµÄmoderm¾Í²»»á»ØÓ¦²¦Èë¡£
½Ïа汾µÄ mgetty (´Ó
0.99beta Æð) Ò²Ö§³Ö×Ô¶¯¼ì²â PPP Êý¾ÝÁ÷£¬
ÕâÑù¼´±ã¿Í»§¶Ë²»Ê¹Óýű¾Ò²ÄÜ·ÃÎÊ·þÎñÆ÷ÁË¡£
²Î¿¼Mgetty ºÍ
AutoPPPµÄÁª»úÊÖ²áÁ˽â¸ü¶àÐÅÏ¢¡£
PPP ȨÏÞ
ppp ÃüÁîͨ³£±ØÐëÒÔ root
Óû§µÄÉí·ÝÔËÐС£ Èç¹ûÏ£ÍûÒÔÆÕͨÓû§µÄÉí·ÝÆô¶¯ ppp
·þÎñ (¾ÍÏñÏÂÃæÃèÊöµÄÄÇÑù)£¬ ¾Í±ØÐë°Ñ´ËÓû§¼ÓÈë
network ×飬 ʹÆä»ñµÃÔËÐÐ ppp
µÄȨÏÞ¡£
Äú»¹ÐèҪʹÓÃallowÃüÁîʹÓû§ÄÜ·ÃÎÊÅäÖÃÎÄ
¼þµÄÒ»¸ö»ò¶à¸ö²¿·Ö£º
allow users fred mary
Èç¹ûÕâ¸öÃüÁî±»ÓÃÔÚ default
²¿·ÖÖУ¬ Äú¿ÉÒÔÈÃÖ¸¶¨µÄÓû§·ÃÎÊÈκζ«Î÷¡£
¶¯Ì¬IPÓû§µÄPPP Shell
PPP shells
´´½¨Ò»¸öÃûΪ/etc/ppp/ppp-shellÎļþ£¬ ¼ÓÈëÒÔÏÂÄÚÈÝ£º
#!/bin/sh
IDENT=`echo $0 | sed -e 's/^.*-\(.*\)$/\1/'`
CALLEDAS="$IDENT"
TTY=`tty`
if [ x$IDENT = xdialup ]; then
IDENT=`basename $TTY`
fi
echo "PPP for $CALLEDAS on $TTY"
echo "Starting PPP for $IDENT"
exec /usr/sbin/ppp -direct $IDENT
Õâ¸ö½Å±¾ÒªÓпÉÖ´ÐÐÊôÐÔ¡£ È»ºóͨ¹ýÈçÏÂÃüÁî´´½¨Ò»¸öÖ¸Ïò´Ë½Å±¾ÇÒÃûΪ
ppp-dialupµÄ·ûºÅÁ´½Ó£º
&prompt.root; ln -s ppp-shell /etc/ppp/ppp-dialup
ÄúÓ¦¸Ã½«Õâ¸ö½Å±¾×÷ΪËùÓв¦ÈëÓû§µÄ
shell¡£
ÒÔÏÂÊÇÔÚÎļþ /etc/passwd
ÖйØÓÚ PPP Óû§
pchilds µÄÀý×Ó (Çмǣ¬
²»ÒªÖ±½ÓÐÞ¸ÄÕâ¸öÃÜÂëÎļþ£¬ Óà &man.vipw.8; À´ÐÞ¸ÄËü)¡£
pchilds:*:1011:300:Peter Childs PPP:/home/ppp:/etc/ppp/ppp-dialup
´´½¨Ò»¸öÃûΪ /home/ppp
µÄĿ¼×÷Ϊ²¦ÈëÓû§µÄÖ÷Ŀ¼£¬ ÆäÖаüº¬ÒÔÏÂÕâЩ¿ÕÎļþ£º
-r--r--r-- 1 root wheel 0 May 27 02:23 .hushlogin
-r--r--r-- 1 root wheel 0 May 27 02:22 .rhosts
ÕâÑù¾Í¿ÉÒÔ·ÀÖ¹/etc/motd±»ÏÔʾ³öÀ´¡£
¾²Ì¬IPÓû§µÄShell
PPP shells
ÏñÉÏÃæÄÇÑù´´½¨ppp-shellÎļþ£¬
Ϊÿ¸ö¾²Ì¬·ÖÅäIPÓû§´´½¨Ò»¸öµ½ ppp-shellµÄ
·ûºÅÁ´½Ó¡£
ÀýÈ磬 Èç¹ûÄúÏ£ÍûΪÈý¸ö²¦ºÅÓû§£¬
fred£¬ sam£¬ ºÍ
mary ·ÓÉ /24 CIDR µÄÍøÂ磬 ÔòÐèÒª¼üÈëÒÔÏÂÄÚÈÝ£º
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-fred
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-sam
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-mary
ÿ¸öÓû§µÄShell±ØÐë±»Éè³ÉÒ»¸ö·ûºÅÁ´½Ó(ÀýÈçÓû§
maryµÄShellÓ¦¸ÃÊÇ/etc/ppp/ppp-mary)¡£
Ϊ¶¯Ì¬IPÓû§ÉèÖÃppp.conf
/etc/ppp/ppp.confÎļþÓ¦¸Ã°üº¬ÏÂÃæ
ÕâЩÐУº
default:
set debug phase lcp chat
set timeout 0
ttyu0:
set ifaddr 203.14.100.1 203.14.100.20 255.255.255.255
enable proxy
ttyu1:
set ifaddr 203.14.100.1 203.14.100.21 255.255.255.255
enable proxy
Ëõ½øµÃ±ØÐëµÄ¡£
default:ÏîÔÚÿ´Î»á»°Ê±¶¼»á¼ÓÔØ¡£ ÿ¸öÔÚ
/etc/ttys ÖÐÆôÓõÄÐж¼±ØÐëΪÆä´´½¨Ò»¸öÏàËÆÓÚ
ttyu0: µÄÏî¡£ ÿһÐÐÓ¦¸Ã´Ó¶¯Ì¬ IP
µØÖ·³ØÖÐÈ¡µÃΨһµÄIPµØÖ·¡£
Ϊ¾²Ì¬ IP Óû§ÅäÖà ppp.conf
¸ù¾ÝÉÏÃæ /usr/share/examples/ppp/ppp.conf ÎļþµÄÄÚÈÝ£¬
Äú±ØÐëΪÿ¸ö¾²Ì¬²¦ºÅÓû§Ìí¼ÓÒ»¸öÏî¡£ ÎÒÃǼÌÐøÒÔ
fred¡¢ sam
ÒÔ¼° maryΪÀý¡£
fred:
set ifaddr 203.14.100.1 203.14.101.1 255.255.255.255
sam:
set ifaddr 203.14.100.1 203.14.102.1 255.255.255.255
mary:
set ifaddr 203.14.100.1 203.14.103.1 255.255.255.255
Èç¹ûÐèÒª£¬ /etc/ppp/ppp.linkup
Ò²Ó¦¸Ã°üÀ¨Ã¿¸ö¾²Ì¬IPÓû§µÄµÄ·ÓÉÐÅÏ¢¡£
ÏÂÃæÕâÒ»ÐÐΪ¿Í»§Á¬½ÓÌí¼ÓÁ˵½
203.14.101.0/24 ÍøÂçµÄ·ÓÉ¡£
fred:
add 203.14.101.0 netmask 255.255.255.0 HISADDR
sam:
add 203.14.102.0 netmask 255.255.255.0 HISADDR
mary:
add 203.14.103.0 netmask 255.255.255.0 HISADDR
mgettyºÍAutoPPP
mgetty
AutoPPP
LCP
ĬÈÏÇé¿öÏ£¬ comms/mgetty+sendfax port
ÔÚ±àÒëʱÆôÓÃÁË AUTO_PPP Ñ¡Ï
Ëüʹ mgetty Äܹ»¼ì²â PPP Á¬½ÓµÄ LCP ״̬£¬
²¢×Ô¶¯²úÉú PPP shell¡£ ²»¹ý£¬ ÓÉÓÚÔÚĬÈÏÅäÖÃÖеÄ
login/password ÐòÁв¢²»³öÏÖ£¬ Òò´Ë£¬
¾Í±ØÐëʹÓà PAP »ò CHAP À´ÑÏÖØÓû§Éí·Ý¡£
Õâ½Ú¼Ù¶¨Óû§ÒѾÔÚϵͳÖгɹ¦µØ±àÒë²¢°²×°ÁË comms/mgetty+sendfax¡£
È·ÈÏÄúµÄ
/usr/local/etc/mgetty+sendfax/login.config
ÎļþÖаüº¬ÒÔÏÂÄÚÈÝ£º
/AutoPPP/ - - /etc/ppp/ppp-pap-dialup
ÕâÐиæËßmgettyÔËÐÐ
ppp-pap-dialup½Å±¾À´ÕìÌýPPPÁ¬½Ó¡£
´´½¨/etc/ppp/ppp-pap-dialupÎļþдÈëÒÔÏÂÄÚÈÝ (´ËÎļþÓ¦¸ÃÊÇ¿ÉÖ´ÐеÄ)£º
#!/bin/sh
exec /usr/sbin/ppp -direct pap$IDENT
¶ÔÓ¦ÓÚÿ¸öÔÚ/etc/ttysµÄÆôÓÃÐУ¬ ¶¼ÒªÔÚ/etc/ppp/ppp.conf
Öд´½¨ÏàÓ¦µÄÏî¡£ ÕâºÍÉÏÃæµÄ¶¨ÒåÊÇÏàͬµÄ¡£
pap:
enable pap
set ifaddr 203.14.100.1 203.14.100.20-203.14.100.40
enable proxy
ÿ¸öÒÔÕâÖÖ·½Ê½µÇ¼µÄÓû§£¬ ¶¼±ØÐëÔÚ
/etc/ppp/ppp.secret ÎļþÖиø³öÓû§Ãû/¿ÚÁ
»òÕßʹÓÃÒÔÏÂÑ¡Ï À´Í¨¹ý PAP ·½Ê½ÒÔ /etc/passwd
ÎļþÌṩµÄÐÅÏ¢À´Íê³ÉÉí·ÝÑéÖ¤¡£
enable passwdauth
Èç¹ûÄúÏëΪijЩÓû§·ÖÅ侲̬IP£¬
¿ÉÒÔÔÚ /etc/ppp/ppp.secret
Öн«IPºÅ×÷ΪµÚÈý¸ö²ÎÊýÖ¸¶¨¡£ Çë²Î¼û
/usr/share/examples/ppp/ppp.secret.sample
ÖеÄÀý×Ó¡£
MS Extensions
DNS
NetBIOS
PPPMicrosoft extensions
¿ÉÒÔÅäÖÃPPPÒÔÌṩDNSºÍNetBIOSÓòÃû·þÎñÆ÷µØÖ·¡£
ÒªÔÚ PPP 1.x °æ±¾ÖÐÆôÓÃÕâЩÀ©Õ¹£¬ ÐèÒªÔÚ
/etc/ppp/ppp.conf µÄ¶ÔÓ¦ÏîÖмÓÈëÏÂÁÐÅäÖãº
enable msext
set ns 203.14.100.1 203.14.100.2
set nbns 203.14.100.5
PPP°æ±¾2¼°ÒÔÉÏ£º
accept dns
set dns 203.14.100.1 203.14.100.2
set nbns 203.14.100.5
Õ⽫¸æË߿ͻ§¶ËÊ×Ñ¡ÓòÃû·þÎñÆ÷ºÍ±¸ÓÃÓòÃû·þÎñÆ÷¡£
ÔÚ°æ±¾2¼°ÒÔÉϰ汾ÖУ¬ Èç¹ûÊ¡ÂÔÁË
set dns£¬ PPP»áʹÓÃ
/etc/resolv.confÖеÄÖµ¡£
PAP ºÍ CHAP ÑéÖ¤
PAP
CHAP
һЩ ISP ½«ÏµÍ³ÅäÖÃΪʹÓà PAP »ò CHAP »úÖÆÀ´Íê³ÉÁ¬½ÓÑéÖ¤¡£
Èç¹ûÓöµ½ÕâÖÖÇé¿ö£¬ ÔÚÄúÁ¬½Óʱ ISP ¾Í²»»á¿´µ½
login: Ìáʾ·û£¬ ¶øÊÇÁ¢¼´¿ªÊ¼ PPP ¶Ô»°¡£
PAP °²È«ÐÔÒª±È CHAP ²îһЩ£¬ µ«ÔÚÕâÀﰲȫÐÔ²¢²»ÊÇÎÊÌ⣬
ÒòΪÃÜÂë (¼´Ê¹ÓÃÃ÷ÎÄ´«ËÍ) Ö»ÊÇͨ¹ý´®ÐÐÏß´«ËÍ£¬
¹¥»÷Õß²¢Ã»ÓÐÌ«¶à»ú»áÈ¥ ÇÔÌý
Ëü¡£
²Î¿¼ PPP
Ó뾲̬ IP µØÖ· »ò PPP Ó붯̬ IP µØÖ·
С½Ú£¬ ²¢Íê³ÉÏÂÁи͝£º
13 set authname MyUserName
14 set authkey MyPassword
15 set login
µÚ 13 ÐУº
ÕâÒ»ÐÐÖ¸Ã÷ÄúµÄPAP/CHAPÓû§Ãû¡£
ÄúÐèҪΪMyUserNameÊäÈëÕýÈ·µÄÖµ¡£
µÚ 14 ÐУº
password
ÕâÒ»ÐÐÖ¸Ã÷ÄúµÄ PAP/CHAP passwordÃÜÂë¡£
ÄúÐèҪΪ MyPassword ÊäÈëÕýÈ·µÄÖµ¡£
ÁíÍ⣬Äú¿ÉÄÜÏ£Íû¼ÓÈëһЩ¶îÍâµÄÑ¡ÏÀýÈ磺
16 accept PAP
»ò
16 accept CHAP
ÒÔÃ÷È·ÄúµÄÒâͼ£¬ ²»¹ý£¬ ĬÈÏÇé¿öÏ PAP ºÍ CHAP ¶¼»á±»½ÓÊÜ¡£
ÐÐ 15£º
Èç¹ûÄúʹÓõÄÊÇ PAP »ò CHAP£¬ Ò»°ãÀ´Ëµ ISP
¾Í²»»áÒªÇóÄúµÇ¼·þÎñÆ÷ÁË¡£ Õâʱ£¬
¾Í±ØÐë½ûÓà set login
ÉèÖá£
¼´Ê±¸Ä±äÄúµÄppp ÅäÖÃ
Óëºǫ́ÔËÐеÄppp³ÌÐò½øÐжԻ°ÊÇ¿ÉÄܵģ¬
ǰÌáÊÇÉèÖÃÁËÒ»¸öºÏÊʵÄÕï¶Ï¶Ë¿Ú¡£ ×öµ½ÕâÒ»µã£¬ ÐèÒª°ÑÏÂÃæµÄÐмÓÈëµ½ÄúµÄÅäÖÃÖУº
set server /var/run/ppp-tun%d DiagnosticPassword 0177
ÕâÐиæËß PPPÔÚÖ¸¶¨µÄ&unix;ÓòsocketÖÐÕìÌý£¬ µ±Óû§Á¬½ÓʱÐèÒª¸ø³öÖ¸¶¨µÄÃÜÂë¡£
%dÓÃtunÉ豸ºÅÌæ»»¡£
Ò»µ©ÆôÓÃÁËsocket£¬ ¾Í¿ÉÒÔÔڽű¾Öе÷ÓóÌÐò&man.pppctl.8;À´´¦ÀíÕýÔÚÔËÐеÄ
µÄPPP¡£
ʹÓÃPPPÍøÂçµØÖ··Òë
PPP
NAT
PPP ¿ÉÒÔʹÓÃÄÚ½¨µÄ NAT£¬ ¶øÎÞÐèÄÚºËÖ§³Ö¡£
Äú¿ÉÒÔÔÚ /etc/ppp/ppp.conf ÖмÓÈëÈçÏÂÅäÖÃÀ´ÆôÓÃËü£º
nat enable yes
PPP NATÒ²¿ÉÒÔʹÓÃÃüÁîÐÐÑ¡Ïî
-natÆô¶¯¡£ ÔÚ
/etc/rc.conf ÎļþÖÐÒ²ÓÐ
ppp_nat Ï ²¢Ä¬ÈÏÆôÓá£
Èç¹ûÄúʹÓÃÁËÕâ¸öÌØÐÔ£¬ Äú»¹»á·¢ÏÖÔÚ
/etc/ppp/ppp.confÖÐÒÔÏÂ
Ñ¡Ïî¶ÔÓÚÆôÓÃincoming connections forwardingÊÇÓÐÓõģº
nat port tcp 10.0.0.2:ftp ftp
nat port tcp 10.0.0.2:http http
»òÕßÍêÈ«²»ÐÅÈÎÍâÀ´µÄÇëÇó
nat deny_incoming yes
×îºóµÄϵͳÅäÖÃ
PPPconfiguration
ÏÖÔÚÄúÒÑÅäÖÃÁËppp£¬ µ«ÔÚÕæÕý¹¤×÷֮ǰ»¹ÓÐһЩÊÂÇéÒª×ö¡£
¼´ÐÞ¸Ä /etc/rc.conf¡£
´ÓÉÏÒÀ´ÎÍùÏ¿´£¬ È·ÈÏÒѾÕýÈ·µØÅäÖÃÁË
hostname=£¬ ÀýÈ磺
hostname="foo.example.com"
Èç¹ûÄúµÄISPÌṩ¸øÄúÒ»¸ö¾²Ì¬µÄIPºÍÃû×Ö£¬ ½«Õâ¸öÃû×ÖÉèΪhostnameÊÇ×îºÏÊʵġ£
ѰÕÒ network_interfaces ±äÁ¿¡£
Èç¹ûÒªÅäÖÃϵͳͨ¹ý²¦ºÅÁ¬ÈëISP£¬
Ò»¶¨Òª½«tun0É豸¼ÓÈëÕâ¸öÁÐ±í£¬ ·ñÔò¾Íɾ³ýËü¡£
network_interfaces="lo0 tun0"
ifconfig_tun0=
ifconfig_tun0±äÁ¿Ó¦¸ÃÊǿյģ¬ ÇÒÒª´´½¨Ò»¸öÃûΪ
/etc/start_if.tun0µÄÎļþ¡£
Õâ¸öÎļþÓ¦¸Ã°üº¬ÕâÒ»ÐУº
ppp -auto mysystem
´Ë½Å±¾ÔÚÍøÂçÅäÖÃʱ±»Ö´ÐУ¬ ¿ªÆôPPPÊØ»¤½ø³Ì½øÈë×Ô¶¯Ä£Ê½¡£
Èç¹ûÕą̂»ú×ӳ䵱һ¸öLANµÄÍø¹Ø£¬ Äú¿ÉÄÜÏ£ÍûʹÓÃ
¡£ ²Î¿¼Ïà¹ØÁª»úÊÖ²áÁ˽â¸ü¶àϸ½Ú¡£
Îñ±ØÔÚ
/etc/rc.conf ÖУ¬
°Ñ·ÓɳÌÐòÉèÖÃΪ NO£º
router_enable="NO"
routed
²»Æô¶¯ routed ·þÎñ³ÌÐò·Ç³£ÖØÒª£¬ ÒòΪ
routed ×Ü»áɾµôÓÉ ppp
Ëù½¨Á¢µÄĬÈÏ·ÓÉ¡£
´ËÍ⣬ ÎÒÃǽ¨ÒéÄúÈ·ÈÏÒ»ÏÂ
sendmail_flags ÕâÒ»ÐÐÖÐûÓÐÖ¸¶¨
²ÎÊý£¬ ·ñÔò
sendmail ½«»á²»¶ÏµØ³¢ÊÔ²éÕÒÍøÂ磬
¶øÕâÑù×ö½«»áµ¼Ö»úÆ÷²»¶ÏµØ½øÐв¦ºÅ¡£ ¿ÉÒÔ¿¼ÂÇ£º
sendmail_flags="-bd"
sendmail
Ìæ´úµÄ×ö·¨Êǵ±Ã¿´Î PPP Á¬½Ó½¨Á¢Ê±Äú±ØÐëͨ¹ý¼üÈëÒÔÏÂÃüÁîÇ¿ÖÆ
sendmail ÖØÐ¼ì²éÓʼþ¶ÓÁУº
&prompt.root; /usr/sbin/sendmail -q
ÄúÒ²¿ÉÒÔÔÚppp.linkupʹÓÃ!bgÃüÁî×Ô¶¯Íê³ÉÕâЩ¹¤×÷£º
1 provider:
2 delete ALL
3 add 0 0 HISADDR
4 !bg sendmail -bd -q30m
SMTP
Èç¹ûÄú²»Ï²»¶ÕâÑù×ö£¬ ¿ÉÒÔÉèÁ¢Ò»¸ö
dfilter
ÒÔ×èÖ¹ SMTP ´«Êä¡£
²Î¿¼Ïà¹ØÎļþÁ˽â¸ü¶àϸ½Ú¡£
ÏÖÔÚÄúΨһҪ×öµÄÊÂÊÇÖØÐÂÆô¶¯¼ÆËã»ú¡£
ÖØÆôÖ®ºó£¬¿ÉÒÔÊäÈ룺
&prompt.root; ppp
È»ºóÊÇdial providerÒÔ¿ªÆô PPP»á»°¡£
»òÕßÈç¹ûÄúÏëÈÃppp×Ô¶¯½¨Á¢»á»°£¬
ÒòΪÄúÓÐÒ»Ìõ¹ãÓòÍøÁ¬½Ó (ÇÒûÓд´½¨ start_if.tun0
½Å±¾)£¬ ¼üÈ룺
&prompt.root; ppp -auto provider
×ܽá
µ±µÚÒ»´ÎÉèÖÃPPPʱ£¬ ÏÂÃæ¼¸²½ÊDZØÐëµÄ£º
¿Í»§¶Ë£º
È·±£ tun±àÒë½øÁ˽øºË¡£
È·±£ /dev
Ŀ¼ÖÐÃûΪ
tunN
µÄÉ豸ÎļþÊÇ¿ÉÓõġ£
ÔÚ
/etc/ppp/ppp.confÖд´½¨Ò»¸öÏî¡£
pmdemandʾÀýÓ¦¸ÃÊʺÏÓÚ¾ø´ó¶àÊýISP¡£
Èç¹ûÄúʹÓö¯Ì¬IPµØÖ·£¬ ÔÚ/etc/ppp/ppp.linkup´´½¨Ò»¸öÏî¡£
¸üÐÂ/etc/rc.conf
Îļþ¡£
Èç¹ûÄúÒªÇó°´Ð貦ºÅ£¬ ´´½¨Ò»¸östart_if.tun0½Å±¾¡£
·þÎñÆ÷¶Ë£º
È·±£tunÉ豸ÒѱàÒëÈëÄںˡ£
È·±£ /dev
Ŀ¼ÖÐÃûΪ
tunN
µÄÉ豸ÎļþÊÇ¿ÉÓõġ£
ÔÚ/etc/passwdÖд´½¨Ò»¸öÏî
(ʹÓÃ&man.vipw.8;³ÌÐò)¡£
ÔÚÓû§µÄhomeĿ¼´´½¨Ò»¸öÔËÐÐ
ppp -direct direct-server»òÏàËÆÃüÁîµÄprofile¡£
ÔÚ/etc/ppp/ppp.confÖд´½¨Ò»¸öÏî¡£
direct-serverʾÀýÓ¦¸ÃÄÜÂú×ãÒªÇó¡£
ÔÚ
/etc/ppp/ppp.linkupÖд´½¨Ò»¸öÏî¡£
¸üР/etc/rc.conf
Îļþ¡£
Gennady B.
Sorokopud
Parts originally contributed by
Robert
Huff
ʹÓÃÄں˼¶PPP
Õâ½ÚÄÚÈÝÖ»ÔÚ
&os; 7.X ÉÏ¿ÉÓá£
ÉèÁ¢Äں˼¶PPP
PPP
kernel PPP
ÔÚ¿ªÊ¼ÅäÖà PPP ֮ǰ£¬
ÇëÈ·ÈÏ pppd ÒѾ´æ·ÅÔÚ
/usr/sbin ÖУ¬ ²¢ÇÒ
/etc/ppp Ŀ¼ÊÇ´æÔڵġ£
pppdÄÜÔÚÁ½ÖÖģʽϹ¤×÷£º
×÷Ϊһ¸ö ¿Í»§
—
ÄúҪͨ¹ýPPP´®ÐÐÏß»òmodemÏß°ÑÄúµÄ»úÆ÷Á¬½Óµ½»¥ÁªÍøÉÏ¡£
PPP
server
×÷Ϊ·þÎñÆ÷
—¼ÆËã»úÒѾλÓÚÍøÂçÉÏ£¬ ÇÒ±»ÓÃÓÚͨ¹ýPPPÓëÆäËü¼ÆËã»úÁ¬½Ó¡£
Á½ÖÖÇé¿öÄú¶¼ÐèÒªÉèÁ¢Ò»¸öÑ¡ÏîÎļþ£¬
(/etc/ppp/options »òÕßÊÇ
~/.ppprc Èç¹ûÄúµÄ¼ÆËã»úÓжà¸öÓû§Ê¹ÓÃPPP)¡£
Äú»¹ÐèҪһЩmodem/serialÈí¼þ(comms/kermit¾ÍºÜÊʺÏ)£¬
ʹÄúÄܹ»²¦ºÅ²¢ÓëÔ¶³ÌÖ÷»ú½¨Á¢Á¬½Ó¡£
Trev
Roydhouse
Based on information provided by
ʹÓÃpppd×÷Ϊ¿Í»§¶Ë
PPP
client
Cisco
ÏÂÃæÕâ¸ö /etc/ppp/optionsÑ¡ÏîÎļþÄܹ»±»ÓÃÀ´ÓëCISCOÖÕ¶Ë·þÎñÆ÷µÄ
PPPÏßÁ¬½Ó¡£
crtscts # enable hardware flow control
modem # modem control line
noipdefault # remote PPP server must supply your IP address
# if the remote host does not send your IP during IPCP
# negotiation, remove this option
passive # wait for LCP packets
domain ppp.foo.com # put your domain name here
:remote_ip # put the IP of remote PPP host here
# it will be used to route packets via PPP link
# if you didn't specified the noipdefault option
# change this line to local_ip:remote_ip
defaultroute # put this if you want that PPP server will be your
# default router
Á¬½Ó£º
Kermit
modem
ʹÓà Kermit (»òÆäËû modem
³ÌÐòÀ´²¦ºÅ)£¬ È»ºóÊäÈëÄúµÄÓû§ÃûºÍ¿ÚÁî
(»òÔÚÔ¶³ÌÖ÷»úÉÏÆôÓà PPP ËùÐèµÄÆäËûÐÅÏ¢)¡£
Í˳ö Kermit (²¢²»¹Ò¶ÏÁ¬½Ó)¡£
¼üÈëÏÂÃæÕâÐУº
&prompt.root; /usr/sbin/pppd /dev/tty01 19200
Ò»¶¨ÒªÊ¹ÓÃÕýÈ·µÄËٶȺÍÉ豸Ãû¡£
ÏÖÔÚÄúµÄ¼ÆËã»úÒѾÓÃPPPÁ¬½Ó¡£ Èç¹ûÁ¬½Óʧ°Ü£¬
Äú¿ÉÔÚÎļþ /etc/ppp/options ÖÐÌí¼Ó
Ñ¡Ï ²¢²é¿´¿ØÖÆÌ¨ÐÅÏ¢ÒÔ¸ú×ÙÎÊÌâ¡£
ÏÂÃæÕâ¸ö/etc/ppp/pppup½Å±¾ÄÜ×Ô¶¯Íê³ÉÕâÈý¸ö²½Ö裺
#!/bin/sh
pgrep -l pppd
pid=`pgrep pppd`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
pgrep -l kermit
pid=`pgrep kermit`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
ifconfig ppp0 down
ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.dial
pppd /dev/tty01 19200
Kermit
/etc/ppp/kermit.dial ÊÇÒ»¸ö Kermit
½Å±¾£¬ Ëü»áÍê³É²¦ºÅ£¬ ²¢ÔÚÔ¶³ÌÖ÷»úÉÏÍê³ÉËùÓÐÐèÒªµÄÉí·ÝÑéÖ¤¹ý³Ì
(Õâ·ÝÎĵµµÄ×îºóÓÐÒ»¸ö½Å±¾ÊµÀý)¡£
ʹÓÃÏÂÃæÕâ¸ö½Å±¾/etc/ppp/pppdown¶Ï¿ªPPPÁ¬Ïߣº
#!/bin/sh
pid=`pgrep pppd`
if [ X${pid} != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill -TERM ${pid}
fi
pgrep -l kermit
pid=`pgrep kermit`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
/sbin/ifconfig ppp0 down
/sbin/ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.hup
/etc/ppp/ppptest
ͨ¹ýÖ´ÐÐ/usr/etc/ppp/ppptest£¬
¿´¿´pppd ÊÇ·ñÈÔÔÚÔËÐУº
#!/bin/sh
pid=`pgrep pppd`
if [ X${pid} != "X" ] ; then
echo 'pppd running: PID=' ${pid-NONE}
else
echo 'No pppd running.'
fi
set -x
netstat -n -I ppp0
ifconfig ppp0
Ö´Ðнű¾
/etc/ppp/kermit.hupÒÔ¹ÒÆðmoderm£¬ Õâ¸öÎļþ°üº¬£º
set line /dev/tty01 ; put your modem device here
set speed 19200
set file type binary
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
pau 1
out +++
inp 5 OK
out ATH0\13
echo \13
exit
Ò²¿ÉÒÔÓÃchat
´úÌækermit£º
ÒÔÏÂÁ½¸öÎļþÓÃÒÔ½¨Á¢pppdÁ¬½Ó¡£
/etc/ppp/options£º
/dev/cuad1 115200
crtscts # enable hardware flow control
modem # modem control line
connect "/usr/bin/chat -f /etc/ppp/login.chat.script"
noipdefault # remote PPP serve must supply your IP address
# if the remote host doesn't send your IP during
# IPCP negotiation, remove this option
passive # wait for LCP packets
domain your.domain # put your domain name here
: # put the IP of remote PPP host here
# it will be used to route packets via PPP link
# if you didn't specified the noipdefault option
# change this line to local_ip:remote_ip
defaultroute # put this if you want that PPP server will be
# your default router
/etc/ppp/login.chat.script£º
ÒÔϵÄÄÚÈÝÓ¦¸Ã·ÅÔÚÒ»ÐÐÄÚ¡£
ABORT BUSY ABORT 'NO CARRIER' "" AT OK ATDTphone.number
CONNECT "" TIMEOUT 10 ogin:-\\r-ogin: login-id
TIMEOUT 5 sword: password
Ò»µ©ÕâЩ±»°²×°ÇÒÐÞ¸ÄÕýÈ·£¬ ÄúËùÒª×öµÄ¾ÍÊÇÔËÐÐpppd£¬ ¾ÍÏñÕâÑù£º
&prompt.root; pppd
ʹÓÃpppd×÷Ϊ·þÎñÆ÷
/etc/ppp/optionsÒª°üÀ¨ÏÂÃæÕâЩÄÚÈÝ£º
crtscts # Hardware flow control
netmask 255.255.255.0 # netmask (not required)
192.114.208.20:192.114.208.165 # IP's of local and remote hosts
# local ip must be different from one
# you assigned to the Ethernet (or other)
# interface on your machine.
# remote IP is IP address that will be
# assigned to the remote machine
domain ppp.foo.com # your domain
passive # wait for LCP
modem # modem line
ÏÂÃæÕâ¸ö½Å±¾/etc/ppp/pppserv
ʹpppdÒÔ·þÎñÆ÷·½Ê½Æô¶¯£º
#!/bin/sh
pgrep -l pppd
pid=`pgrep pppd`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
pgrep -l kermit
pid=`pgrep kermit`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
# reset ppp interface
ifconfig ppp0 down
ifconfig ppp0 delete
# enable autoanswer mode
kermit -y /etc/ppp/kermit.ans
# run ppp
pppd /dev/tty01 19200
ʹÓýű¾/etc/ppp/pppservdownÍ£Ö¹·þÎñÆ÷£º
#!/bin/sh
pgrep -l pppd
pid=`pgrep pppd`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
pgrep -l kermit
pid=`pgrep kermit`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
ifconfig ppp0 down
ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.noans
ÏÂÃæµÄ Kermit ½Å±¾
(/etc/ppp/kermit.ans) Äܹ»ÆôÓÃ/½ûÓÃÄú modem
µÄ×Ô¶¯Ó¦´ðģʽ¡£ ÆäÄÚÈÝÀàËÆÏÂÃæÕâÑù£º
set line /dev/tty01
set speed 19200
set file type binary
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
pau 1
out +++
inp 5 OK
out ATH0\13
inp 5 OK
echo \13
out ATS0=1\13 ; change this to out ATS0=0\13 if you want to disable
; autoanswer mode
inp 5 OK
echo \13
exit
Ò»¸öÃûΪ/etc/ppp/kermit.dialµÄ½Å±¾ÓÃÓÚÏòÔ¶³ÌÖ÷»ú
½øÐв¦ºÅºÍÑéÖ¤¡£ ÄúÒª¸ù¾ÝÐèÒª¶¨ÖÆËü¡£ Òª¼ÓÈëÄúµÄµÇѰÃûºÍÃÜÂ룬
Äú»¹Òª¸ù¾Ý modem ºÍÔ¶³ÌÖ÷»úµÄ·´Ó¦ÐÞ¸ÄÊäÈëÓï¾ä¡£
;
; put the com line attached to the modem here:
;
set line /dev/tty01
;
; put the modem speed here:
;
set speed 19200
set file type binary ; full 8 bit file xfer
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
set modem hayes
set dial hangup off
set carrier auto ; Then SET CARRIER if necessary,
set dial display on ; Then SET DIAL if necessary,
set input echo on
set input timeout proceed
set input case ignore
def \%x 0 ; login prompt counter
goto slhup
:slcmd ; put the modem in command mode
echo Put the modem in command mode.
clear ; Clear unread characters from input buffer
pause 1
output +++ ; hayes escape sequence
input 1 OK\13\10 ; wait for OK
if success goto slhup
output \13
pause 1
output at\13
input 1 OK\13\10
if fail goto slcmd ; if modem doesn't answer OK, try again
:slhup ; hang up the phone
clear ; Clear unread characters from input buffer
pause 1
echo Hanging up the phone.
output ath0\13 ; hayes command for on hook
input 2 OK\13\10
if fail goto slcmd ; if no OK answer, put modem in command mode
:sldial ; dial the number
pause 1
echo Dialing.
output atdt9,550311\13\10 ; put phone number here
assign \%x 0 ; zero the time counter
:look
clear ; Clear unread characters from input buffer
increment \%x ; Count the seconds
input 1 {CONNECT }
if success goto sllogin
reinput 1 {NO CARRIER\13\10}
if success goto sldial
reinput 1 {NO DIALTONE\13\10}
if success goto slnodial
reinput 1 {\255}
if success goto slhup
reinput 1 {\127}
if success goto slhup
if < \%x 60 goto look
else goto slhup
:sllogin ; login
assign \%x 0 ; zero the time counter
pause 1
echo Looking for login prompt.
:slloop
increment \%x ; Count the seconds
clear ; Clear unread characters from input buffer
output \13
;
; put your expected login prompt here:
;
input 1 {Username: }
if success goto sluid
reinput 1 {\255}
if success goto slhup
reinput 1 {\127}
if success goto slhup
if < \%x 10 goto slloop ; try 10 times to get a login prompt
else goto slhup ; hang up and start again if 10 failures
:sluid
;
; put your userid here:
;
output ppp-login\13
input 1 {Password: }
;
; put your password here:
;
output ppp-password\13
input 1 {Entering SLIP mode.}
echo
quit
:slnodial
echo \7No dialtone. Check the telephone line!\7
exit 1
; local variables:
; mode: csh
; comment-start: "; "
; comment-start-skip: "; "
; end:
Tom
Rhodes
Contributed by
PPP Á¬½Ó¹ÊÕÏÅųý
PPP
troubleshooting
´Ó &os; 8.0 ¿ªÊ¼£¬ &man.uart.4; Çý¶¯È¡´úÁË
&man.sio.4; Çý¶¯¡£ ÓÃÒÔ±íʾ´®¿ÚµÄÉ豸½ÚµãÓÉ·Ö±ð
/dev/cuadN ¸ÄΪÁË
/dev/cuauN£¬
²¢´Ó
/dev/ttydN ¸ÄΪÁË
/dev/ttyuN¡£
&os; 7.X Óû§ÔÚÉý¼¶Ê±ÐèÒªÒòÓ¦Ö®¶ÔÅäÖÃÎļþ½øÐбØÒªµÄ¸ü¸Ä¡£
±¾½Ú½«½²Êöͨ¹ýmodemÁ¬½ÓʹÓÃPPPʱ¿ÉÄܳöÏÖµÄÎÊÌâ¡£
ÀýÈ磬 Äú¿ÉÄÜÐèҪȷÇеØÖªµÀÄú²¦ÈëµÄϵͳ»á³öÏÖÒ»¸öÔõÑùµÄÃüÁîÐÐÌáʾ·û¡£
ÓÐЩ ISP »áÌṩ sswordÌáʾ·û£¬
¶øÆäËüµÄ¿ÉÄÜ»á³öÏÖ password£»
Èç¹ûûÓиù¾ÝÇé¿öµÄ²»Í¬ÏàÓ¦µØ±àд ppp
½Å±¾£¬ µÇ¼¾Í»áʧ°Ü¡£ Õï¶Ï ppp
×î³£Óõķ½·¨ÊÇÊÖ¶¯½øÐÐÁ¬½Ó¡£ ÒÔϵÄÐÅÏ¢»áÒ»²½Ò»²½µØ´øÄúÍê³ÉÊÖ¶¯Á¬½Ó¡£
¼ì²éÉ豸½Úµã
Èç¹ûʹÓõÄÊǶ¨ÖÆÄںˣ¬ È·ÈÏÔÚÆä±àÒëÅäÖÃÖаüº¬ÏÂÁÐÅäÖãº
device uart
ĬÈ쵀 GENERIC ÄÚºËÖаüº¬ÁË
uart É豸£¬ Òò´ËÈç¹ûÄúʹÓõÄÊÇËüµÄ»°£¬
¾Í²»ÐèÒªµ£ÐÄÁË¡£ Ö»Òª²é¿´ dmesg Êä³öÖÐÊÇ·ñÓÐ modem
É豸£º
&prompt.root; dmesg | grep uart
ÄúÓ¦¸ÃÕÒµ½Óë uart É豸ÓйصÄÊä³ö¡£
ÕâЩ¾ÍÊÇÎÒÃÇÐèÒªµÄ COM ¶Ë¿Ú¡£ Èç¹ûÄúµÄ modem °´ÕÕ±ê×¼´®Ðж˿ڹ¤×÷£¬
Äú¾Í»áÔÚ uart1 »ò COM2
ÉÏÕÒµ½Ëü¡£ Èç¹û modem É豸Á¬½ÓÔÚ uart1
½Ó¿Ú (ÔÚ DOS ÖгÆÎªCOM2)£¬
ÄÇôÄúµÄ modem ½«»áÊÇ /dev/cuau1¡£
ÊÖ¶¯Á¬½Ó
ͨ¹ýÊÖ¶¯¿ØÖÆpppÀ´Á¬½ÓInternet
ÊÇÕï¶ÏÁ¬½Ó¼°»ñÖªISP´¦ÀíPPP¿Í»§¶Ë·½Ê½µÄÒ»¸ö¿ìËÙ£¬ ¼òµ¥µÄ·½·¨¡£
ÈÃÎÒÃÇ´ÓPPP ÃüÁîÐпªÊ¼£¬ ÔÚËùÓеÄÀý×ÓÖÐÎÒÃÇʹÓÃ
example ±íʾÔËÐÐ PPP
·þÎñµÄÖ÷»úÃû¡£ ¼üÈëppp
ÃüÁî´ò¿ª ppp£º
&prompt.root; ppp
ÏÖÔÚÎÒÃÇÒѾ´ò¿ªÁËppp¡£
ppp ON example> set device /dev/cuau1
ÉèÖÃmodemÉ豸£¬ ÔÚ±¾Àý×ÓÖÐÊÇ
cuau1¡£
ppp ON example> set speed 115200
ÉèÖÃÁ¬½ÓËÙ¶È£¬ ÔÚ±¾ÀýÖÐÎÒÃÇʹÓÃ15,200 kbps¡£
ppp ON example> enable dns
ʹpppÅäÖÃÓòÃû·þÎñ£¬
ÔÚÎļþ/etc/resolv.confÖÐÌí¼ÓÓòÃû·þÎñÆ÷ÐС£
Èç¹û ppp²»ÄÜÈ·¶¨ÎÒÃǵÄÖ÷»úÃû£¬ ¿ÉÒÔÔÚÉÔºóÉèÖá£
ppp ON example> term
Çл»µ½ ÖÕ¶Ë
ÑùÎÒÃǾÍÄÜÊÖ¶¯µØ¿ØÖÆÕą̂ modem µÄģʽ¡£
deflink: Entering terminal mode on /dev/cuau1
type '~h' for help
at
OK
atdt123456789
ʹÓÃÃüÁîat³õʼ»¯modem£¬
È»ºóʹÓÃatdtºÍISP¸øÄúµÄºÅÂë½øÐв¦ºÅ¡£
CONNECT
Á¬½ÓÅäÖ㬠Èç¹ûÎÒÃÇÓöµ½ÁËÓëÓ²¼þÎ޹صÄÁ¬½ÓÎÊÌ⣬ ¿ÉÒÔÔÚÕâÀï³¢ÊÔ½â¾ö¡£
ISP Login:myusername
ÕâÀïÌáʾÄúÊäÈëÓû§Ãû£¬ ÊäÈëISPÌṩµÄÓû§ÃûÈ»ºó°´»Ø³µ¡£
ISP Pass:mypassword
ÕâʱÌáʾÎÒÃÇÊäÈëÃÜÂ룬 ÊäÈë
ISPÌṩµÄÃÜÂë¡£
ÈçͬµÇ¼Èë&os;£¬ ÃÜÂë²»»áÏÔʾ¡£
Shell or PPP:ppp
ÓÉÓÚISPµÄ²»Í¬£¬ Õâ¸öÌáʾ·û¿ÉÄܲ»»á³öÏÖ¡£
ÕâÀïÎÒÃÇÐèÒª¿¼ÂÇ£º ÊÇʹÓÃÔËÐÐÓÚÌṩÉÌ¶ËµÄ Shell£¬
»¹ÊÇÆô¶¯ ppp£¿ Õâ±¾ÀýÖУ¬
ÎÒÃÇÑ¡ÔñʹÓà ppp£¬ ÒòΪÎÒÃÇÏ£ÍûµÃµ½ Internet Á¬½Ó¡£
Ppp ON example>
×¢ÒâÔÚÕâ¸öÀý×ÓÖУ¬ µÚÒ»¸ö ÒѾ´óд¡£
Õâ±íʾÎÒÃÇÒѾ³É¹¦µØÁ¬½ÓÉÏÁË ISP¡£
PPp ON example>
ÎÒÃÇÒѾ³É¹¦Í¨¹ýÁË
ISPµÄÑéÖ¤£¬ ÕýÔڵȴý·ÖÅäIPµØÖ·¡£
PPP ON example>
ÎÒÃǵõ½ÁËÒ»¸ö IP
µØÖ·£¬ ³É¹¦µØÍê³ÉÁËÁ¬½Ó¡£
PPP ON example>add default HISADDR
ÕâÑù¾ÍÍê³ÉÁËÌí¼ÓĬÈÏ·ÓÉËùÐèµÄÅäÖᣠÕâÊÇÓëÍâ½çͨÐÅËù±ØÐèµÄ¡£
ÒòΪ֮ǰÎÒÃÇÖ»ÊÇÓë·þÎñÆ÷¶Ë½¨Á¢ÁËÁ¬½Ó¡£ Èç¹ûÓÉÓÚÒÑ´æÔڵķÓɶøµ¼Ö²Ù×÷ʧ°Ü£¬
Äú¿ÉÒÔÔÚ Ç°¼Ó !ºÅ¡£
³ý´ËÖ®Í⣬ ÄúÒ²¿ÉÒÔÔÚÕæÕýÁ¬½Ó֮ǰÉèÖÃÕâЩ (Ö¸ add default HISADDR)£¬
ppp »á¸ù¾ÝÕâÏîÉ趨ÐÉÌÈ¡µÃеķÓÉ¡£
Èç¹ûÒ»ÇÐ˳Àû£¬ ÏÖÔÚÎÒÃÇÓ¦¸ÃÄܵõ½Ò»¸ö»î¶¯µÄ Internet Á¬½Ó£¬
¿ÉÒÔʹÓà CTRL
z ʹÆäתÈëºǫ́¡£ Èç¹ûÄú·¢ÏÖ
PPPÖØÐ±äΪ ppp£¬
Ôò±íʾÁ¬½Ó±»¶Ï¿ª¡£ ´óдµÄ P ±íÃ÷½¨Á¢Á˵½ ISP µÄÁ¬½Ó£¬
¶øÐ¡Ð´µÄ p Ôò±íʾÁ¬½ÓÓÉÓÚijÖÖÔÒò±»¶Ï¿ª£¬ ÕâÓÐÖúÓÚ°ïÖúÎÒÃÇÁ˽âÁ¬½ÓµÄ״̬¡£
ppp Ö»ÓÐÕâÁ½¸ö״̬¡£
Õï¶ÏÅÅ´í
Èç¹ûÄúÓÐÒ»¸ùÖ±Á¬ÏßÇÒËÆºõ²»Äܽ¨Á¢Á¬½Ó£¬ ҪʹÓÃÒԹرÕ×Ö½ÚÁ÷µÄCTS/RTS¡£
ÕâÖÖÇé¿öÒ»°ã·¢ÉúÔÚÁ¬½Ó¼æÈÝ PPP µÄÖÕ¶Ë·þÎñÆ÷ʱ¡£
µ±ËüÏòͨÐÅÁ¬½ÓдÈëÊý¾Ýʱ£¬ PPP¾Í»á¹ÒÆð£¬
Ò»Ö±µÈ´ýÒ»¸öCTS£¬
»òÕßÒ»¸ö²»¿ÉÄܳöÏÖµÄ Clear to Send Ðźš£ Èç¹ûʹÓÃÁËÕâ¸öÑ¡Ï Äú»¹Ó¦Ê¹ÓÃ
Ñ¡Ï
ijЩ´æÔÚȱÏݵÄÓ²¼þÔÚÍê³É¶Ë¶Ô¶Ë·¢ËÍÌØ¶¨×Ö·û£¬ ÌØ±ðÊÇ
XON/XOFF ʱ¿ÉÄÜ»áÓöµ½À§ÄÑ¡£ Çë²Î¼û &man.ppp.8;
Áª»úÊÖ²áÒÔÁË½â¹ØÓÚ¿ÉÓÃÑ¡ÏîµÄ¸ü¶àϸ½Ú£¬ ÒÔ¼°ÈçºÎʹÓÃËüÃÇ¡£
Èç¹ûÄúµÄ modem ±È½Ï¾É£¬ ¾ÍÐèҪʹÓÃ
ÁË¡£ ÆæÅ¼Ð£ÑéµÄĬÈÏÉèÖÃÊÇ none£¬
µ«ÔÚ¾ÉʽµÄ (µ±Á÷Á¿´óÁ¿Ôö¼Óʱ) µ÷ÖÆ½âµ÷Æ÷ºÍijЩ
ISP ±»ÓÃÀ´¾À´í¡£ ÄúÐèҪʹÓÃÕâ¸öÑ¡Ïî²ÅÄÜʹÓÃ
Compuserve ISP¡£
PPP ¿ÉÄܲ¢²»·µ»ØÃüÁîģʽ£¬
Õâͨ³£ÊÇ ISP µÈ´ýÄúÕâÒ»¶Ë·¢ÆðÐÉÌʱ·¢ÉúÁË´íÎó¡£
´Ëʱ£¬ ʹÓà ~p ÃüÁî½«Ç¿ÖÆ ppp ¿ªÊ¼·¢ËÍÅäÖÃÐÅÏ¢¡£
Èç¹ûÄúûÓп´µ½µÇ¼Ìáʾ£¬ ÔòºÜ¿ÉÄÜÐèҪʹÓÃ
PAP »ò
CHAP ÑéÖ¤À´´úÌæÇ°ÃæÀý×ÓÖеÄ
&unix; ·ç¸ñÑéÖ¤¡£ ҪʹÓÃ
PAP »ò CHAP
Ö»ÐèÔÚ½øÈëÖÕ¶Ëģʽ֮ǰ°ÑÏÂÃæµÄÑ¡Ïî¼ÓÈë
PPP£º
ppp ON example> set authname myusername
´Ë´¦ myusername Ó¦¸ÄΪÄúµÄ
ISP ·ÖÅ䏸ÄúµÄÓû§Ãû¡£
ppp ON example> set authkey mypassword
´Ë´¦ mypassword Ó¦¸ÃΪÄúµÄ
ISP ·ÖÅ䏸ÄúµÄ¿ÚÁî¡£
Èç¹ûÁ¬½ÓÕý³££¬ µ«ÎÞ·¨²éÕÒÓòÃû£¬ Çë³¢ÊÔ
&man.ping.8; ij¸ö IP
µØÖ·À´¿´¿´ÊÇ·ñ·µ»ØÁËÐÅÏ¢¡£ Èç¹ûÄú·¢ÏÖ°Ù·ÖÖ®°Ù (100%) ¶ª°ü£¬
ÄÇôÄúºÜ¿ÉÄÜûÓзÖÅäĬÈÏ·ÓÉ¡£ Çë×Ðϸ¼ì²éÑ¡Ïî
ÊÇ·ñÔÚÁ¬½Óʱ±»ÉèÖÃÁË¡£ Èç¹ûÄúÄÜÁ¬½Óµ½Ô¶³ÌµÄ
IP µØÖ·ÔòÓпÉÄÜÓòÃû½âÎö·þÎñÆ÷µÄµØÖ·Ã»Óб»¼ÓÈëµ½
/etc/resolv.conf¡£ Õâ¸öÎļþÓ¦¸ÃÊÇÏÂÃæµÄÑù×Ó£º
domain example.com
nameserver x.x.x.x
nameserver y.y.y.y
´Ë´¦ x.x.x.x ºÍ
y.y.y.y Ó¦¸Ã¸ÄΪÄúµÄ
ISP µÄ DNS ·þÎñÆ÷µÄ
IP µØÖ·¡£
ÕâÒ»ÐÅÏ¢ÔÚÄú×¢²áʱ¿ÉÄÜ»áÌṩ¸øÄú£¬
²»¹ýͨ³£Ö»Ðè¸ø ISP ´ò¸öµç»°¾ÍÄÜÖªµÀÁË¡£
Äú»¹¿ÉÒÔÈà &man.syslog.3; ΪÄúµÄ PPP
Á¬½ÓÌṩÈÕÖ¾¡£ Ö»ÐèÔö¼Ó£º
!ppp
*.* /var/log/ppp.log
µ½ /etc/syslog.conf ÖС£ ¾ø´ó¶àÊýÇé¿öÏ£¬
Õâ¸ö¹¦ÄÜĬÈÏÒѾ´ò¿ªÁË¡£
Jim
Mock
Contributed (from http://node.to/freebsd/how-tos/how-to-freebsd-pppoe.html) by
ʹÓûùÓÚÒÔÌ«ÍøµÄPPP(PPPoE)
PPP
over Ethernet
PPPoE
PPP, over Ethernet (ÒÔÌ«ÍøÉ쵀 PPP)
±¾½Ú½«½éÉÜÈçºÎ½¨Á¢»ùÓÚÒÔÌ«ÍøµÄPPP
(PPPoE)¡£
ÅäÖÃÄÚºË
¶ÔÓÚPPPOE£¬ ²¢Ã»ÓбØÐëµÄÄÚºËÅäÖᣠÈç¹û±ØÐèµÄ netgraph
Ö§³ÖûÓбàÒëÈëÄںˣ¬ Ëü¿ÉÒÔÓÉ ppp ¶¯Ì¬¼ÓÔØ¡£
ÉèÖÃppp.conf
ÒÔÏÂÊÇÒ»¸öppp.confµÄÀý×Ó£º
default:
set log Phase tun command # you can add more detailed logging if you wish
set ifaddr 10.0.0.1/0 10.0.0.2/0
name_of_service_provider:
set device PPPoE:xl1 # replace xl1 with your Ethernet device
set authname YOURLOGINNAME
set authkey YOURPASSWORD
set dial
set login
add default HISADDR
ÔËÐÐppp
ÒÔ root Éí·ÝÖ´ÐУº
&prompt.root; ppp -ddial name_of_service_provider
Æô¶¯Ê±ÔËÐÐppp
ÔÚ /etc/rc.conf ÖмÓÈëÒÔÏÂÄÚÈÝ£º
ppp_enable="YES"
ppp_mode="ddial"
ppp_nat="YES" # if you want to enable nat for your local network, otherwise NO
ppp_profile="name_of_service_provider"
ʹÓà PPPoE ·þÎñ±êÇ©
ÔÚijЩʱºò£¬ ÓбØÒªÊ¹ÓÃÒ»¸ö·þÎñ±êÇ©À´½¨Á¢ÄúµÄÁ¬½Ó¡£
·þÎñ±êÇ©ÓÃÓÚÇø·ÖÍ¬Ò»ÍøÂçÖеIJ»Í¬·þÎñÆ÷¡£
Äú¿ÉÒÔÔÚISPÌṩµÄÎĵµÖÐÕÒµ½±ØÒªµÄ·þÎñ±êÇ©ÐÅÏ¢¡£
Èô²»ÄÜÕÒµ½£¬ ÔòÓ¦ÏòÄúµÄ ISP ѰÇó¼¼ÊõÖ§³Ö¡£
×÷Ϊ×îºóµÄ·½·¨£¬ Äú¿ÉÒÔÊÔÊÔ
Roaring Penguin
PPPoE£¬ Ëü¿ÉÒÔÔÚ Ports Collection ÖÐÕÒµ½¡£
È»¶øÐèҪעÒâµÄÊÇ£¬ Ëü¿ÉÄÜ»áÇå³þ modem µÄ¹Ì¼þ£¬ ²¢Ê¹ÆäÎÞ·¨Õý³£¹¤×÷£¬
Òò´ËÒ»¶¨Òª×Ðϸ¿¼ÂÇÖ®ºóÔÙ×öÕâ¸ö²Ù×÷¡£ ¼òµ¥µØ°²×°ÓÉ·þÎñÌṩÉÌËæ modem
ÌṩµÄ³ÌÐò¡£ Ëæºó£¬ Ñ¡Ôñ
System ²Ëµ¥¡£ ÄúµÄÅäÖÃÎļþÓ¦¸Ã»áÔÚÕâÀïÁгö¡£
Ò»°ãÀ´ËµËüµÄÃû×ÖÓ¦¸ÃÊÇ
ISP¡£
ÅäÖÃÎļþÃû (service tag£¬ ·þÎñ±êÇ©) ½«±»ÓÃÓÚ PPPoE
ÔÚ ppp.conf ÖеÄÅäÖÃÏ
×÷Ϊ·þÎñÉÌ set device ÃüÁîµÄÒ»²¿·Ö (²Î¼û &man.ppp.8;
Áª»úÊÖ²áÒÔÁ˽â¸ü¶àϸ½Ú)¡£ ËüÓ¦¸ÃÀàËÆÏÂÃæµÄÑù×Ó£º
set device PPPoE:xl1:ISP
¼Çס½«xl1»»³Éʵ¼ÊµÄÒÔÌ«ÍøÉ豸¡£
¼Çס½« ISP
»»³ÉÄú¸Õ¸ÕÕÒµ½µÄprofileÃû¡£
»ñµÃ¸ü¶àµÄÐÅÏ¢£¬ Çë²Î¿¼£º
Cheaper
Broadband with FreeBSD on DSL by Renaud
Waldura.
Nutzung von T-DSL und T-Online mit FreeBSD
by Udo Erdelhoff (in German).
´øÓÐÒ»¸ö&tm.3com;
HomeConnect
ADSL ModemµÄPPPOEË«ÖØÁ¬½Ó
Õâ¸ö modem ²»×ñÑ RFC 2516
(A Method for transmitting PPP over Ethernet
(PPPoE)£¬ Æä×÷ÕßΪ L. Mamakos¡¢ K. Lidl¡¢ J. Evarts¡¢
D. Carrel¡¢ D. Simone ÒÔ¼° R. Wheeler)¡£
¶øÊÇʹÓò»Í¬µÄÊý¾Ý°ü¸ñʽ×÷ΪÒÔÌ«ÍøµÄ¿ò¼Ü¡£ ÇëÏò
3Com ±§Ô¹£¬
Èç¹ûÄúÈÏΪËüÓ¦¸Ã×ñÊØ PPPoE µÄ¹æ·¶¡£
ΪÁËÈÃFreeBSDÄܹ»ÓëÕâ¸öÉ豸ͨÐÅ£¬ ±ØÐëÉèÖÃsysctl¡£
ͨ¹ý¸ü¸Ä/etc/sysctl.conf£¬
ÕâÒ»²½¿ÉÒÔÔÚÆô¶¯Ê±×Ô¶¯Íê³É£º
net.graph.nonstandard_pppoe=1
»òÕߣ¬ Ò²¿ÉÒÔÖ±½ÓÖ´ÐÐÏÂÃæµÄÃüÁ
&prompt.root; sysctl net.graph.nonstandard_pppoe=1
ºÜ²»ÐÒ£¬ÓÉÓÚÕâÊÇϵͳȫ¾ÖÉèÖ㬠ÎÞ·¨Í¬Ê±ÓëÕý³£µÄPPP¿Í»§¶Ë(»ò·þÎñÆ÷)
ºÍ&tm.3com;HomeConnect
ADSL ModemͨÐÅ¡£
ʹÓà ATM É쵀 PPP (PPPoA)
PPP
over ATM
PPPoA
»ùÓÚATMµÄPPP
ÒÔϽ«½éÉÜÈçºÎÉèÖûùÓÚATMµÄPPP(PPPoA)¡£
PPPoAÊÇÅ·ÖÞDSLÌṩÉÌµÄÆÕ±éÑ¡Ôñ¡£
ʹÓà Alcatel &speedtouch;USB µÄ PPPoA
Õë¶ÔÕâÒ»É豸µÄ PPPoA Ö§³Ö£¬ ÔÚ
FreeBSD ÖÐÊÇ×÷Ϊ port ÌṩµÄ£¬ ÒòΪÆä¹Ì¼þʹÓÃÁË °¢¶û¿¨ÌØÐí¿ÉÐÒ飬
Òò¶ø²»ÄÜÓë FreeBSD µÄ»ù±¾ÏµÍ³Ò»ÆðÃâ·ÑµØÔÙ·¢²¼¡£
ʹÓà Ports Ì×¼þ ¿ÉÒԷdz£·½±ãµØ°²×°
net/pppoa port£¬
Ö®ºó°´ÕÕËüÌṩµÄָʾ²Ù×÷¾Í¿ÉÒÔÁË¡£
ºÍÐí¶à USB É豸ÀàËÆ£¬ °¢¶û¿¨ÌØµÄ &speedtouch; USB
ÐèÒª´ÓÖ÷»úÉÏÏÂÔØ¹Ì¼þ²ÅÄܹ»Õý³£¹¤×÷¡£ ÔÚ &os; ÖÐÄú¿ÉÒÔ½«´Ë²Ù×÷×Ô¶¯»¯£¬
ÔÚÓÐÉ豸²åµ½Ä³¸ö USB ¿ÚµÄʱºò×Ô¶¯ÏÂÔØ¹Ì¼þ¡£ ¿ÉÒÔÔÚ
/etc/usbd.conf
ÎļþÖмÓÈëÏÂÃæµÄÐÅÏ¢À´ÈÃËü×Ô¶¯Íê³É¹Ì¼þµÄ´«ËÍ¡£ ×¢Ò⣬ ±ØÐëÒÔ
root Óû§µÄÉí·Ý±à¼Ëü¡£
device "Alcatel SpeedTouch USB"
devname "ugen[0-9]+"
vendor 0x06b9
product 0x4061
attach "/usr/local/sbin/modem_run -f /usr/local/libdata/mgmt.o"
ÒªÆô¶¯USBÊØ»¤½ø³Ìusbd£¬
ÔÚ/etc/rc.conf¼ÓÈëÒÔÏÂÐУº
usbd_enable="YES"
Ò²¿ÉÒÔ½«pppÉèÖÃ³ÉÆô¶¯Ê±²¦ºÅ¡£ Ïò
/etc/rc.conf¼ÓÈëÒÔÏÂÕ⼸ÐС£
ͬÑùµØÄúÐèÒªÒÔrootÓû§µÇ¼¡£
ppp_enable="YES"
ppp_mode="ddial"
ppp_profile="adsl"
ΪÁËʹÆäÕý³£¹¤×÷£¬ ÄúÐèҪʹÓÃnet/pppoa
portÌṩµÄppp.confÑùÀý¡£
ʹÓÃmpd
¿ÉÒÔʹÓà mpd À´Á¬½Ó¶àÖÖÀàÐ͵ķþÎñ£¬
ÌØ±ðÊÇ PPTP ·þÎñ¡£ Äú¿ÉÒÔÔÚ Ports Collection ÖÐÕÒµ½
mpd£¬ ËüµÄλÖÃÊÇ
net/mpd¡£ Ðí¶à ADSL modem
ÐèÒªÔÚ modem ºÍ¼ÆËã»úÖ®¼ä½¨Á¢Ò»Ìõ PPTP ËíµÀ£¬
¶ø°¢¶û¿¨ÌØ &speedtouch; Home ÕýÊÇÆäÖеÄÒ»ÖÖ¡£
Ê×ÏÈÐèÒª´Ó port Íê³É°²×°£¬
È»ºó²ÅÄÜÅäÖà mpd À´Âú×ãÄúµÄÐèÒª£¬
²¢Íê³É·þÎñÉ̵ÄÅäÖᣠport »á°ÑһϵÁаüÀ¨ÁËÏêϸע½âµÄÅäÖÃÎļþʵÀý·Åµ½
PREFIX/etc/mpd/¡£
×¢Ò⣬ ÕâÀïµÄ PREFIX ±íʾ ports
°²×°µÄĿ¼£¬ ĬÈÏÇé¿öÏ£¬ Ó¦¸ÃÊÇ
/usr/local/¡£
¹ØÓÚÅäÖà mpd µÄÍêÕû˵Ã÷£¬ »áÒÔ
HTML ¸ñÊ½Ëæ port Ò»Æð°²×°¡£ ÕâЩÎļþ½«·ÅÔÚ
PREFIX/share/doc/mpd/¡£
ÏÂÃæÊÇͨ¹ý mpd Á¬½Ó ADSL
·þÎñµÄÒ»¸ö¼òµ¥Àý×Ó¡£ ÅäÖñ»·Ö±ð·Åµ½ÁËÁ½¸öÎļþÖУ¬ µÚÒ»¸öÊÇ
mpd.conf£º
default:
load adsl
adsl:
new -i ng0 adsl adsl
set bundle authname username
set bundle password password
set bundle disable multilink
set link no pap acfcomp protocomp
set link disable chap
set link accept chap
set link keep-alive 30 10
set ipcp no vjcomp
set ipcp ranges 0.0.0.0/0 0.0.0.0/0
set iface route default
set iface disable on-demand
set iface enable proxy-arp
set iface idle 0
open
usernameÓÃÀ´ÏòÄúµÄISP½øÐÐÑéÖ¤¡£
passwordÓÃÀ´ÏòÄúµÄISP½øÐÐÑéÖ¤¡£
mpd.links°üº¬Á¬½ÓµÄÐÅÏ¢£º
adsl:
set link type pptp
set pptp mode active
set pptp enable originate outcall
set pptp self 10.0.0.1
set pptp peer 10.0.0.138
ÔËÐÐmpdµÄÖ÷»úµÄIPµØÖ·¡£
ADSL modemµÄIPµØÖ·¡£ Alcatel
&speedtouch; Home ĬÈϵÄÊÇ 10.0.0.138¡£
³õʼ»¯Á¬½Ó£º
&prompt.root; mpd -b adsl
Äú¿ÉÒÔͨ¹ýÒÔÏÂÃüÁî²é¿´Á¬½Ó״̬£º
&prompt.user; ifconfig ng0
ng0: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> mtu 1500
inet 216.136.204.117 --> 204.152.186.171 netmask 0xffffffff
ʹÓÃmpdÁ¬½ÓADSL·þÎñÊÇÍÆ¼öµÄ·½Ê½¡£
ʹÓÃpptpclient
Ò²¿ÉÒÔʹÓÃnet/pptpclientÁ¬½ÓÆäËüµÄ
PPPoA¡£
ҪʹÓà net/pptpclient Á¬½Ó
DSL ·þÎñ£¬ ÐèÒª°²×° port »ò package ²¢±à¼
/etc/ppp/ppp.conf¡£ ÄúÐèÒªÓÐ
root ȨÏÞ²ÅÄÜÍê³ÉÕâÁ½Ïî²Ù×÷¡£
ÒÔÏÂÊÇ ppp.conf ÖеÄÒ»¸öʾÀýÏî¡£
²Î¿¼ ppp µÄÁª»úÊÖ²á &man.ppp.8;£¬
ÒÔÁ˽â¸ü¶àÓÐ¹Ø ppp.conf Ñ¡ÏîµÄÐÅÏ¢¡£
adsl:
set log phase chat lcp ipcp ccp tun command
set timeout 0
enable dns
set authname username
set authkey password
set ifaddr 0 0
add default HISADDR
ÄúÔÚ DSL ·þÎñÌṩÉÌÄÇÀïµÄÓû§Ãû
ÄúÕÊ»§µÄ¿ÚÁî¡£
ÓÉÓÚÄú±ØÐ뽫ÕʺÅÃÜÂëÒÔÃ÷Îĵķ½Ê½·ÅÈëppp.conf
ÄúÓ¦¸ÃÈ·±£Ã»ÓÐÈκÎÈËÄÜ¿´µ½´ËÎļþµÄÄÚÈÝ¡£ ÒÔÏÂһϵÁÐÃüÁ»áÈ·±£´ËÎļþÖ»¶Ô
rootÓû§¿É¶Á¡£
Çë²Î¼û &man.chmod.1; ºÍ &man.chown.8; µÄÁª»úÊÖ²áÒÔÁ˽âÓйØÈçºÎ²Ù×÷µÄ½øÒ»²½ÐÅÏ¢¡£
&prompt.root; chown root:wheel /etc/ppp/ppp.conf
&prompt.root; chmod 600 /etc/ppp/ppp.conf
ÒÔϽ«Îªµ½ DSL ·ÓÉÆ÷µÄ»á»°´ò¿ªÒ»¸ö tunnel¡£
ÒÔÌ«ÍøDSL modemÓÐÒ»¸öÉèÖõľÖÓòÍøIPµØÖ·¡£ ÒÔ Alcatel &speedtouch; Home
ΪÀý£¬ Õâ¸öµØÖ·ÊÇ 10.0.0.138¡£
·ÓÉÆ÷µÄÎĵµÓ¦¸Ã»á¸æËßÄúËüʹÓõĵØÖ·¡£
Ö´ÐÐÒÔÏÂÃüÁîÒÔ´ò¿ª tunnel ²¢¿ªÊ¼»á»°£º
&prompt.root; pptp address adsl
ÄúÓ¦¸ÃÔÚÃüÁîµÄ×îºó¼ÓÉÏ(&
)ºÅ£¬ ·ñÔò pptp
ÎÞ·¨·µ»Øµ½ÃüÁîÐÐÌáʾ·û¡£
Òª´´½¨Ò»¸ö tunÐéÄâÉ豸ÓÃÓÚ½ø³Ìpptp
ºÍppp Ö®¼äµÄ½»»¥¡£ Ò»µ©Äú»Øµ½ÁËÃüÁîÐУ¬
»òÕß pptp
½ø³ÌÈ·ÈÏÁËÒ»¸öÁ¬½Ó£¬ Äú¿ÉÒÔÕâÑù¼ì²étunnelÉ豸£º
&prompt.user; ifconfig tun0
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 216.136.204.21 --> 204.152.186.171 netmask 0xffffff00
Opened by PID 918
Èç¹ûÄúÎÞ·¨Á¬½Ó£¬ Ò»°ã¿ÉÒÔͨ¹ýtelnet»òÕßwebä¯ÀÀÆ÷¼ì²é·ÓÉÆ÷(modem)µÄÅäÖá£
Èç¹ûÒÀ¾ÉÎÞ·¨Á¬½Ó£¬ ÄúÓ¦¸Ã¼ì²épptpµÄÊä³ö¼°pppµÄÈÕÖ¾Îļþ
/var/log/ppp.log ÒÔ»ñµÃÏßË÷¡£
Satoshi
Asami
Originally contributed by
Guy
Helmer
With input from
Piero
Serini
ʹÓÃSLIP
SLIP
Õâ½ÚÄÚÈÝÖ»ÔÚ
&os; 7.X ÉÏ¿ÉÓá£
ÉèÖÃ SLIP ¿Í»§¶Ë
SLIP
client (¿Í»§¶Ë)
ÏÂÃæÊÇÔÚ¾²Ì¬Ö÷»úÍøÂçÉÏÅäÖà FreeBSD »úÆ÷ʹÓà SLIP µÄ·½·¨¡£
¶ÔÓÚ¶¯Ì¬Ö÷»úÃû·ÖÅä (ÄúµÄµØÖ·»áËæÃ¿´Î²¦ºÅ¶ø²»Í¬)£¬
Äú¿ÉÄÜÐèÒªÉÔ¸´ÔÓһЩµÄÉèÖá£
Ê×ÏÈ£¬ ÄúÐèҪȷÈϵ÷ÖÆ½âµ÷Æ÷ËùÁ¬½ÓµÄ´®¿Ú¡£
Ðí¶àÈË»áÉèÖÃÒ»¸ö·ûºÅÁ¬½Ó£¬ ÀýÈç
/dev/modem£¬ ÓÃÒÔÖ¸Ïòʵ¼ÊµÄÉ豸Ãû£¬ Èç
/dev/cuadN¡£
ÕâÑùÄú¾Í¿ÉÒÔ¶Ôʵ¼ÊµÄÉ豸Ãû½øÐгéÏó£¬
ÒÔ±¸µ÷ÖÆ½âµ÷Æ÷»»µ½ÆäËû´®¿Úʱ·½±ãµ÷ÕûÖ®Óᣠ²»È»£¬ ÐÞ¸Ä
/etc ºÍ±é²¼ÓÚϵͳÖÐµÄ .kermrc
Îļþ½«ÊÇÒ»¼þºÜÂé·³µÄÊÂÇ飡
/dev/cuad0 ¶ÔÓ¦
COM1£¬ ¶ø /dev/cuad1
Ôò¶ÔÓ¦
COM2£¬ µÈµÈ¡£
È·±£ÄúµÄÄÚºËÎļþ°üº¬ÒÔÏÂÄÚÈÝ£º
device sl
Õâ°üº¬ÔÚGENERICÄںˣ¬ ËùÒÔÕâÓ¦¸Ã²»»áÊǸöÎÊÌ⣬ ³ý·ÇÄú
ÒѾɾ³ýÁËËü¡£
Ö»Ðè×öÒ»´ÎµÄÊÂÇé
°ÑÄú±¾µØÍøÂçÉϵĻúÆ÷¡¢ Íø¹ØÒÔ¼°ÓòÃû·þÎñÆ÷£¬
¶¼¼ÓÈëµ½ /etc/hosts ÎļþÖС£
ÎÒÃǵÄÊÇÏÂÃæÕâ¸öÑù×Ó£º
127.0.0.1 localhost loghost
136.152.64.181 water.CS.Example.EDU water.CS water
136.152.64.1 inr-3.CS.Example.EDU inr-3 slip-gateway
128.32.136.9 ns1.Example.EDU ns1
128.32.136.12 ns2.Example.EDU ns2
ÇëÈ·±£ÔÚÄúµÄ /etc/nsswitch.conf
ÖÐµÄ hosts: С½ÚÀïÃæ£¬ files ÏÈÓÚ
dns ³öÏÖ¡£ Èç¹û²»ÊÇÕâÑùµÄ»°£¬
¿ÉÄÜ»á²úÉúһЩ²»Ï£ÍûµÄÏÖÏó¡£
±à¼/etc/rc.conf¡£
±à¼ÒÔÏÂÕâÐÐÉèÖÃÖ÷»úÃû(hostname)£º
hostname="myname.my.domain"
Ó¦¸ÃÓÃÄúÖ÷»úµÄInternetÈ«Ãû´úÌæ¡£
default route
¸Ä±äÕâÒ»ÐÐÒÔÖ¸Ã÷ĬÈϵÄ·ÓÉ£º
defaultrouter="NO"
¸ÄΪ£º
defaultrouter="slip-gateway"
´´½¨Îļþ/etc/resolv.conf£¬ дÈëÒÔÏÂÄÚÈÝ£º
domain CS.Example.EDU
nameserver 128.32.136.9
nameserver 128.32.136.12
nameserver
domain name
ÕýÈçÄú¿´µ½µÄ£¬ ÕâЩÐÐÉèÖÃÁËÓòÃû·þÎñÆ÷¡£ µ±È»£¬
ʵ¼ÊµÄÓòÃûºÍIPµØÖ·È¡¾öÓÚÄúµÄ»·¾³¡£
ÉèÖÃrootºÍ
toorµÄÃÜÂë(ÆäËüÈκÎûÓÐÃÜÂëµÄÕʺÅ)¡£
ÖØÆô¼ÆËã»ú£¬ È»ºóÈ·ÈÏʹÓÃÁËÕýÈ·µÄÖ÷»úÃû¡£
´´½¨Ò»¸öSLIPÁ¬½Ó
SLIP
connecting with
ÔÚÃüÁîÌáʾ·ûÖ®ºóÊäÈë slip ½øÐв¦ºÅ£¬
ÊäÈëÄúµÄ»úÆ÷ÃûºÍ¿ÚÁî¡£ ¾ßÌåÐèÒªÊäÈëʲô£¬
ÓëÄúµÄ»·¾³ÃÜÇÐÏà¹Ø¡£ Èç¹ûʹÓÃ
Kermit£¬
Ôò¿ÉÒÔʹÓÃÀàËÆÏÂÃæµÄ½Å±¾£º
# kermit setup
set modem hayes
set line /dev/modem
set speed 115200
set parity none
set flow rts/cts
set terminal bytesize 8
set file type binary
# The next macro will dial up and login
define slip dial 643-9600, input 10 =>, if failure stop, -
output slip\x0d, input 10 Username:, if failure stop, -
output silvia\x0d, input 10 Password:, if failure stop, -
output ***\x0d, echo \x0aCONNECTED\x0a
µ±È»£¬ Äú»¹ÐèÒªÐÞ¸ÄÓû§ÃûºÍ¿ÚÁîÀ´Âú×ãʵ¼ÊÐèÒª¡£
Íê³ÉÕâЩ²Ù×÷Ö®ºó£¬ Ö»ÐèÔÚ Kermit
Ìáʾ·ûÖ®ºóÊäÈë slip ¾Í¿ÉÒÔÁ¬½ÓÁË¡£
½«ÃÜÂëÒÔ´¿Îı¾µÄÐÎʽ´æ·ÅÔÚÎļþϵͳÎÞÂÛÈçºÎ¶¼ÊǸö »µ Ö÷Òâ¡£
Ç뿼ÂÇÕâÑù×öµÄ·çÏÕ¡£
ÔÚÕâÀïÍ˳ö Kermit (Ò²¿ÉÒÔÓÃ
Ctrl
z
½«Æä¹ÒÆð)£¬ ÒÔ root Óû§¼üÈ룺
&prompt.root; slattach -h -c -s 115200 /dev/modem
Èç¹ûÄúÄÜpingͨ·ÓÉÆ÷ÁíÒ»¶ËµÄÖ÷»ú£¬ ¾ÍÊÇÁ¬½ÓºÃÁË! Èç¹û²»ÐУ¬
Äú¿ÉÒÔʹÓÃÑ¡Ïî´úÌæ
×÷ΪslattachµÄ²ÎÊý¡£
¹Ø±ÕÁ¬½Ó
°´ÏÂÃæµÄ²½Öè×ö£º
&prompt.root; kill -INT `cat /var/run/slattach.modem.pid`
À´É±µô slattach¡£ ÇмÇÉÏÊö²Ù×÷Ö»ÓÐÒÔ
root Éí·Ý²ÅÄÜÍê³É¡£ ½ÓÏÂÀ´»Øµ½
kermit (Èç¹û֮ǰÊǽ«Ëü¹ÒÆðÁË£¬
ÔòʹÓà fg) ²¢Í˳ö (q)¡£
ÔÚ &man.slattach.8; Áª»úÊÖ²áÖÐÌáµ½£¬
±ØÐëʹÓà ifconfig sl0 down
²ÅÄܽ«½Ó¿Ú±ê¼ÇΪ¹Ø±Õ£¬ µ«ºÍÕâÑù×öËÆºõûÓÐÊ²Ã´Çø±ð¡£
(ifconfig sl0 ÈÔÈ»±¨¸æÍ¬ÑùµÄ¶«Î÷¡£)
ÓÐʱ£¬ ÄúµÄ modem ¿ÉÄÜ»á¾Ü¾ø¹Ò¶Ï¡£
ÕâÖÖÇé¿öÏ£¬ Ö»ÐèÖØÐÂÆô¶¯ kermit
²¢ÔÙ´ÎÍ˳öËü¾Í¿ÉÒÔÁË¡£ Ò»°ãÀ´ËµÊÔ¶þ´Î¾Í¿ÉÒÔÁË¡£
ÎÊÌâ½â´ð
Èç¹û»¹²»ÐУ¬ ¾¡¹Ü·¢Óʼþµ½ &a.net.name; ÓʼþÁбíÀ´ÌáÎÊ¡£
³£¼ûµÄÎÊÌâ°üÀ¨£º
Ö´ÐÐ slattach ʱ²»Ê¹ÓÃ
ºÍÑ¡Ïî
(ÕâÓ¦¸Ã²»ÊǹؼüµÄ£¬ µ«ÓÐЩÓû§±¨¸æÕâÑù×ö½â¾öÁËÎÊÌâ)¡£
ʹÓÃÌæ»»
(ÔÚһЩ×ÖÌåϺÜÄÑ¿´³ö²»Í¬)¡£
ÊÔÊÔifconfig sl0À´²é¿´ÄúµÄ½Ó¿Ú״̬¡£
ÀýÈ磬 Äú¿ÉÒÔÕâÑù×ö£º
&prompt.root; ifconfig sl0
sl0: flags=10<POINTOPOINT>
inet 136.152.64.181 --> 136.152.64.1 netmask ffffff00
Èç¹ûÔÚʹÓà &man.ping.8; ʱµÃµ½ÁË
no route to host ÕâÑùµÄÌáʾ£¬
Ôò˵Ã÷ÄúµÄ·Óɱí¿ÉÄÜÓÐÎÊÌâ¡£ ¿ÉÒÔÓà netstat -r
ÃüÁîÀ´ÏÔʾµ±Ç°µÄ·ÓÉ£º
&prompt.root; netstat -r
Routing tables
Destination Gateway Flags Refs Use IfaceMTU Rtt Netmasks:
(root node)
(root node)
Route Tree for Protocol Family inet:
(root node) =>
default inr-3.Example.EDU UG 8 224515 sl0 - -
localhost.Exampl localhost.Example. UH 5 42127 lo0 - 0.438
inr-3.Example.ED water.CS.Example.E UH 1 0 sl0 - -
water.CS.Example localhost.Example. UGH 34 47641234 lo0 - 0.438
(root node)
ǰÊöµÄÀý×ÓÀ´×ÔÓÚÒ»¸ö·Ç³£·±Ã¦µÄϵͳ¡£
ÄúϵͳÉϵÄÕâЩÊý×Ö»áÒòÍøÂç»î¶¯µÄ²»Í¬¶ø¸Ä±ä¡£
ÉèÖÃSLIP·þÎñÆ÷
SLIP
server
±¾ÎÄÌṩÁËÔÚ FreeBSD ÉÏÉèÖà SLIP ·þÎñ£¬
Ò²¾ÍÊÇÈçºÎÅäÖÃÄúµÄϵͳ£¬ ʹÆäÄÜÔÚÔ¶³Ì SLIP
¿Í»§¶ËµÇ¼ʱ×Ô¶¯µØ¿ªÆôÁ¬½ÓµÄ½¨Òé¡£
ǰÌáÌõ¼þ
TCP/IP networking
ÕâÒ»½Ú¼¼ÊõÐÔºÜÇ¿£¬ ËùÒÔÒªÇóÄúÓÐÒ»¶¨µÄ±³¾°ÖªÊ¶¡£
±¾½Ú¼Ù¶¨ÄúÊìϤ TCP/IP ÍøÂçÐÒ飬 ÌØ±ðÊÇÍøÂçºÍ½ÚµãѰַ¡¢
×ÓÍøÑÚÂë¡¢ ×ÓÍø»®·Ö¡¢ ·ÓÉ¡¢ ·ÓÉÐÒé (ÈçRIP) µÈ֪ʶ¡£
ÔÚ²¦ºÅ·þÎñÆ÷ÉÏÅäÖà SLIP ÐèÒªÕâЩ¸ÅÄîÐÔµÄ֪ʶ¡£
Èç¹ûÄú²»ÊìϤËüÃÇ£¬ ÇëÏÈÔĶÁ Craig Hunt µÄ TCP/IP ÍøÂç¹ÜÀí
ÓÉO'Reilly & Associates, Inc. ³ö°æ (ISBN 0-937175-82-X)£¬
»ò Douglas Comer ÓÐ¹Ø TCP/IP ÐÒéµÄÊé¼®¡£
modem
´ËÍ⻹¼Ù¶¨ÄúÒѾÅäÖúÃÁËÄúµÄµ÷ÖÆ½âµ÷Æ÷ÒÔ¼°ÏàÓ¦µÄϵͳÎļþ£¬
ÒÔÔÊÐíͨ¹ýµ÷ÖÆ½âµ÷Æ÷½øÐеǼ¡£ Èç¹ûÄú»¹Ã»ÓÐΪ´ËÅäÖúÃϵͳ£¬
Çë²Î¼û ÒÔÁË½â¹ØÓÚÈçºÎ½øÐв¦ºÅ·þÎñµÄÅäÖá£
Äú¿ÉÄÜÒ²»áÏë¿´Ò»¿´ &man.sio.4; µÄÁª»úÊֲᣬ
ÒÔÁË½â¹ØÓÚ´®¿ÚÉ豸Çý¶¯µÄ½øÒ»²½ÐÅÏ¢£¬ ÒÔ¼° &man.ttys.5;¡¢
&man.gettytab.5;¡¢ &man.getty.8; & &man.init.8;
ÉϹØÓÚÔõÑùÅäÖÃϵͳÀ´½ÓÊÜÀ´×Ôµ÷ÖÆ½âµ÷Æ÷µÄµÇ¼ÇëÇóµÄ¾ßÌåÇé¿ö£¬
»¹ÓÐ &man.stty.1; ÒÔÁË½â¹ØÓÚÉèÖô®¿Ú²ÎÊý
(ÀýÈç clocal ±íʾ´®¿ÚÖ±Áª) µÈ¡£
¿ìËÙä¯ÀÀ
ʹÓÃFreeBSD×÷ΪSLIP·þÎñÆ÷£¬ ÔÚµäÐÍÅäÖÃʱ£¬ ËüÊÇÕâÑù¹¤×÷µÄ£º
Ò»¸öSLIP¿Í»§²¦ºÅ²¢ÒÔרÓõÄlogin IDµÇ¼µ½FreeBSD SLIP·þÎñÆ÷ϵͳ¡£
Õâ¸öÓû§Ê¹Óà /usr/sbin/sliplogin
×÷Ϊ shell¡£ sliplogin ³ÌÐò»áÔÚÎļþ
/etc/sliphome/slip.hosts ÖвéÕÒÕâ¸öÓû§µÄÏ
Èç¹ûÕÒµ½ÁËÆ¥ÅäÏ ¾Í½«´®ÐÐÏßÁ¬½Óµ½Ò»¸ö¿ÉÓÃµÄ SLIP ½Ó¿Ú£¬
È»ºóÔËÐÐ shell ½Å±¾ /etc/sliphome/slip.login
ÒÔÅäÖÃ SLIP ½Ó¿Ú¡£
Ò»¸öSLIP·þÎñÆ÷µÇ¼µÄÀý×Ó
ÀýÈ磬 Èç¹ûÒ»¸öSLIPÓû§µÄIDÊÇShelmerg£¬
ÔÚ/etc/master.passwdÖÐShelmergµÄÏîÈçϵÄËùʾ£º
Shelmerg:password:1964:89::0:0:Guy Helmer - SLIP:/usr/users/Shelmerg:/usr/sbin/sliplogin
ShelmergµÇ¼ʱ£¬
sliploginÔÚÎļþ
/etc/sliphome/slip.hostsÖÐËÑË÷ÓëÓû§IDÆ¥ÅäµÄÐÐ;ÈçÏÂËùʾ£º
Shelmerg dc-slip sl-helmer 0xfffffc00 autocomp
sliploginÕÒµ½ÕâÌõÇøÅäÐУ¬
²¢½«´®ÐÐÏßÓëÁíÒ»¸ö¿ÉÓõÄSLIP½Ó¿ÚÁ¬ÆðÀ´£¬
È»ºóÖ´ÐÐ/etc/sliphome/slip.login½Å±¾£º
/etc/sliphome/slip.login 0 19200 Shelmerg dc-slip sl-helmer 0xfffffc00 autocomp
Èç¹ûÒ»ÇÐ˳Àû
/etc/sliphome/slip.login ½«ÔÚ
sliplogin °ó¶¨µÄ SLIP ½Ó¿ÚÉÏ·¢³ö
ifconfig (ǰÊöµÄÀý×ÓÖÐÊÇ SLIP ½Ó¿Ú
0£¬ ÕâÊÇ slip.login µÄµÚÒ»¸ö²ÎÊý)£¬
ÒÔÉèÖñ¾µØ IP µØÖ· (dc-slip)¡¢ Ô¶³Ì IP µØÖ·
(sl-helmer)¡¢ ÕâÒ» SLIP
½Ó¿ÚµÄ×ÓÍøÑÚÂë (0xfffffc00)£¬
ÒÔ¼°ÈÎºÎÆäËû±êÖ¾ (autocomp)¡£
Èç¹û·¢Éú´íÎó£¬ sliplogin ͨ³£»áͨ¹ý
syslogd µÄ daemon facility
¼ÇÏÂÓÐÓõÄÐÅÏ¢£¬ ǰÕß»á°ÑÕâЩÐÅÏ¢±£´æµ½
/var/log/messages
(²Î¼û &man.syslogd.8; ºÍ &man.syslog.conf.5; ÒÔ¼°
/etc/syslog.conf µÄÁª»úÊֲᣬ ÒÔÁ˽â
syslogd ÔڼǼʲô£¬
ÒÔ¼°ÕâЩÄÚÈݽ«±»¼ÇÔÚÄÄÀï)¡£
ÄÚºËÅäÖÃ
kernel
configuration
SLIP
&os; µÄĬÈÏÄÚºË (GENERIC)
ÌṩÁË SLIP (&man.sl.4;) Ö§³Ö£» ʹÓö¨ÖƵÄÄÚºËʱ£¬
Äú±ØÐë°ÑÏÂÃæµÄÉèÖüÓÈëµ½ÅäÖÃÎļþ£º
device sl
ĬÈÏÇé¿öÏ£¬ ÄúµÄ &os; ¼ÆËã»ú²»»áת·¢°ü¡£
Èç¹ûÄúÏ£Íû½« FreeBSD SLIP ·þÎñÆ÷×÷Ϊ·ÓÉÆ÷ʹÓã¬
¾ÍÐèÒªÐÞ¸Ä /etc/rc.conf Îļþ£¬
½« gateway_enable ±äÁ¿ÉèΪ
¡£ ÕâÑùÏ´ÎϵͳÒýµ¼Ê±¾ÍÄܹ»±£³ÖÕâÒ»ÅäÖÃÁË¡£
ÒªÁ¢¼´Ó¦ÓÃÕâЩÅäÖ㬠¿ÉÒÔ root
µÄÉí·ÝÔËÐУº
&prompt.root; /etc/rc.d/routing start
Çë²ÎÔÄ ÒÔÁ˽âÈçºÎÅäÖà FreeBSD
Äںˣ¬ ²¢»ñµÃÔÚÖØÐÂÅäÖÃÄں˷½ÃæµÄÖ¸µ¼¡£
SliploginÅäÖÃ
ÕýÈçÏÈǰËùÌáµ½µÄ£¬
/etc/sliphome Ŀ¼ÖÐÓÐÈý¸öÎļþ£¬
ËüÃǹ²Í¬¹¹³É /usr/sbin/sliplogin µÄÅäÖà (²Î¿¼
sliplogin µÄÁª»úÊÖ²á &man.sliplogin.8;)£º
ÓÃÓÚ¶¨Òå SLIP Óû§ºÍÏà¹ØµÄ IP
µØÖ·µÄ slip.hosts¡¢
ͨ³£½öÓÃÓÚÅäÖà SLIP ½Ó¿ÚµÄ slip.login£¬ ÒÔ¼° (¿ÉÑ¡µÄ)
slip.logout£¬ ÓÃÒÔ³·ÏúÓÉ
slip.login ËùÖ´Ðе͝×÷¡£
ÅäÖÃ slip.hosts
/etc/sliphome/slip.hostsÀïµÄÿÐаüº¬ÖÁÉÙËĸöÔªËØ£¬ ÔªËØÖ®¼äÓɿոñ¸ô¿ª£º
SLIPÓû§µÄµÇ¼ID
SLIPÁ¬½ÓµÄ±¾µØµØÖ·(Ö¸SLIP·þÎñÆ÷)
SLIPÁ¬½ÓµÄÔ¶³ÌµØÖ·
ÍøÂçÑÚÍø
±¾µØºÍÔ¶³ÌµØÖ·¿ÉÒÔÊÇÖ÷»úÃû
(ͨ¹ýÎļþ/etc/hosts»òÕßÓòÃû·þÎñ½âÎöΪIPµØÖ·£¬
ÕâÈ¡¾öÓÚÎļþ/etc/nsswitch.conf
ÖеÄÉèÖÃ)£¬ ÍøÂçÑÚÍø¿ÉÒÔÊÇÒ»¸ö
ÄÜͨ¹ýÎļþ/etc/networks½âÎöµÄÃû×Ö¡£
ÔÚÒ»¸öÑùÀýϵͳÖУ¬
/etc/sliphome/slip.hostsÊÇÕâÑùµÄ£º
#
# login local-addr remote-addr mask opt1 opt2
# (normal,compress,noicmp)
#
Shelmerg dc-slip sl-helmerg 0xfffffc00 autocomp
ÔÚÕâÐÐĩβÊÇÒ»»ò¶à¸öÑ¡Ï
—²»Ñ¹Ëõ±¨Í·
— ѹËõ±¨Í·
—Èç¹ûÔ¶³Ì¶ËÔÊÐí£¬ ѹËõ±¨Í·
—½ûÓÃICMPÊý¾Ý°ü
(ÕâÑù¾Í»á¶ªÆúËùÓеÄping
Êý¾Ý°ü£¬ ²»Õ¼ÓÃÄúµÄ´ø¿í)
SLIP
TCP/IP networking
¶ÔSLIPÁ¬½ÓµÄ±¾µØ¼°Ô¶³ÌµØÖ·µÄÑ¡ÔñÈ¡¾öÊÇÄúÊÇ×¼±¸ÔÚSLIP·þÎñÆ÷ÉÏʹÓà TCP/IP
×ÓÍø»¹ÊÇʹÓÃARP´úÀí
(Ëü²¢²»ÊÇÕæÕýµÄ
ARP´úÀí£¬ ¶øÊÇÎÒÃÇÔÚ±¾½ÚÓÃÓÚ½éÉܵÄÊõÓï)¡£
Èç¹ûÄú²»ÄÜÈ·¶¨Ñ¡ÔñºÎÖÖ·½Ê½»òÕßÈçºÎ·ÖÅ䵨ַ£¬ Çë²Î¿¼"ǰÌáÌõ¼þ"()ÀïÁгöµÄTCP/IPÊé¼®
»òÕßÏòÄúµÄIPÍøÂç¹ÜÀíÔ±Çë½Ì¡£
Èç¹û´òËãΪÄúµÄ SLIP ¿Í»§Ê¹ÓÃÒ»¸ö¶ÀÁ¢µÄ×ÓÍø£¬
¾ÍÐèÒªÏÈ´Ó·ÖÅäµÃµ½µÄÍøÂçºÅÖÐÈ¡³öÒ»¸ö×ÓÍøºÅ£¬
È»ºóÔÙÔÚÕâ¸ö×ÓÍøÀï¸øÃ¿¸ö SLIP ¿Í»§·ÖÅä IP µØÖ·¡£
½ÓÏÂÀ´£¬ Äú»¹ÐèҪͨ¹ý SLIP ·þÎñÆ÷ÔÚ×î½üµÄ IP
·ÓÉÆ÷ÉÏÅäÖÃÒ»¸öÖ¸Ïò SLIP ×ÓÍøµÄ¾²Ì¬Â·ÓÉ¡£
Ethernet
Èç¹ûҪʹÓà ´úÀí ARP
µÄ·½Ê½£¬ Äú»¹ÐèÒª´Ó SLIP ·þÎñÆ÷µÄÒÔÌ«×ÓÍøÖÐΪÿ¸ö SLIP ¿Í»§·ÖÅäIPµØÖ·£¬
»¹±ØÐëÐÞ¸Ä/etc/sliphome/slip.login ºÍ
/etc/sliphome/slip.logout½Å±¾ÒÔʹÓÃ
&man.arp.8;À´¹ÜÀíÔÚ SLIP
·þÎñÆ÷ ARP ±íÖÐµÄ ´úÀí ARP
Ïî¡£
slip.login Configuration
µäÐ͵Ä/etc/sliphome/slip.login
ÈçÏÂËùʾ£º
#!/bin/sh -
#
# @(#)slip.login 5.1 (Berkeley) 7/1/90
#
# generic login file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 inet $4 $5 netmask $6
Õâ¸öslip.login½Å±¾½ö½öΪ´øÓÐÏàÓ¦±¾µØ¼°Ô¶³ÌµØÖ·ºÍÑÚÂëµÄSLIP½Ó¿ÚÖ´ÐÐ
ifconfig¡£
Èç¹ûÄú¾ö¶¨Ê¹ÓÃARP´úÀí
·½Ê½(¶ø·ÇΪÄúµÄSLIP¿Í»§Ê¹ÓöÀÁ¢µÄ×ÓÍø)£¬ ÄúµÄ/etc/sliphome/slip.login
Ó¦¸ÃÊÇÕâÑù£º
#!/bin/sh -
#
# @(#)slip.login 5.1 (Berkeley) 7/1/90
#
# generic login file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 inet $4 $5 netmask $6
# Answer ARP requests for the SLIP client with our Ethernet addr
/usr/sbin/arp -s $5 00:11:22:33:44:55 pub
slip.loginмӵÄÐÐarp -s
$5 00:11:22:33:44:55 pub ÔÚ SLIP ·þÎñÆ÷µÄ ARP
±íÖмÓÈëÁËÒ»¸ö±íÏî¡£ Õâ¸öARPÏîʹµÃÿµ±Õâ¸öÒÔÌ«ÍøÉÏµÄÆäËü
IP ½Úµã¶Ô SLIP ¿Í»§¶Ë IP µØÖ·½øÐÐ ARP ÇëÇóʱ£¬
SLIP ·þÎñÆ÷»áÒÔ×ÔÒѵÄÒÔÌ«ÍøMACµØÖ·×÷Ϊ»ØÓ¦¡£
Ethernet (ÒÔÌ«Íø)
MAC address (MAC µØÖ·)
µ±Ê¹ÓÃÒÔÉϵÄÀý×Óʱ£¬ Ò»¶¨Òª½«
ÒÔÌ«ÍøMACµØÖ· £¨00:11:22:33:44:55£©
Ìæ»»³ÉÄúÏµÍ³Íø¿¨µÄMACµØÖ·£¬ ·ñÔòARP´úÀí
½«ÍêÈ«ÎÞ·¨¹¤×÷£¡ Äú¿ÉÒԲ鿴 netstat -i
Êä³ö½á¹ûÒÔÈ¡µÃÒÔÌ«Íø MAC µØÖ·; Êä³öµÄµÚ¶þÐÐÓ¦¸ÃÊÇÕâÑù£º
ed0 1500 <Link>0.2.c1.28.5f.4a 191923 0 129457 0 116
ÕâÐбíÃ÷Õâ¸öϵͳµÄÒÔÌ«ÍøMACµØÖ·ÊÇ00:02:c1:28:5f:4a
—netstat -iÊä³öµÄÒÔÌ«ÍøMACµØÖ·±ØÐë¸Ä³ÉÓÃðºÅ¸ô¿ª£¬ ²¢ÇÒÒªµ¥¸öÊ®Áù½øÊýǰ¼ÓÉÏ¡£
ÕâÊÇ&man.arp.8;ÒªÇóµÄ¸ñʽ; ²Î¿¼&man.arp.8; µÄÁª»úÊÖ²áÒÔ»ñÈ¡ÍêÕûµÄʹÓ÷½·¨¡£
ÔÚ±àд
/etc/sliphome/slip.login ºÍ
/etc/sliphome/slip.logout ʱ£¬ Ò»¶¨ÒªÉèÖÃ
¿ÉÖ´ÐÐ
(execute) λ (»»ÑÔÖ®£¬ chmod 755
/etc/sliphome/slip.login /etc/sliphome/slip.logout)£¬
·ñÔò sliplogin½«ÎÞ·¨Ö´ÐÐËü¡£
slip.logoutÅäÖÃ
/etc/sliphome/slip.logout²¢²»ÊDZØÐèµÄ
(³ý·ÇÄúʹÓÃÁËARP´úÀí
)£¬ Èç¹ûÄú×¼±¸´´½¨Ëü£¬ ÕâÀïÓÐÒ»¸ö»ù±¾µÄ
slip.logout ½Å±¾µÄÀý×Ó£º
#!/bin/sh -
#
# slip.logout
#
# logout file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 down
Èç¹ûʹÓÃÁË ´úÀí ARP
£¬
Ôò¿ÉÄÜÏ£Íû /etc/sliphome/slip.logout
ÔÚÓû§×¢Ïúʱ×Ô¶¯Îª SLIP ¿Í»§¶Ëɾ³ý
ARP Ï
#!/bin/sh -
#
# @(#)slip.logout
#
# logout file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 down
# Quit answering ARP requests for the SLIP client
/usr/sbin/arp -d $5
arp -d $5 ½«É¾³ýÓÉ ´úÀí ARP
slip.login ÔÚ SLIP ¿Í»§³ÌÐòµÇ¼ʱËùÉú³ÉµÄ
ARP Ïî¡£
ÔÙ´ÎÇ¿µ÷£º ½¨Á¢
/etc/sliphome/slip.logout Ö®ºó£¬
Ò»¶¨ÒªÉèÖÿÉÖ´ÐÐλ (Ò²¾ÍÊÇ˵£¬ chmod 755
/etc/sliphome/slip.logout)¡£
·ÓÉ¿¼ÂÇ
SLIP
routing
Èç¹ûûÓÐʹÓà ´úÀí ARP
µÄ·½·¨À´ÔÚÄúµÄ
SLIP ¿Í»§»úºÍÍøÂçµÄÆäÓಿ·Ö (Ò²¿ÉÄÜÊÇ Internet)
Ö®¼ä·ÓÉÊý¾Ý°ü£¬ Äú¿ÉÄÜÐèÒªÔö¼ÓÀëÄú×î½üµÄĬÈÏ·ÓÉÆ÷µÄ¾²Ì¬Â·ÓÉ£¬
ÒÔ±ãͨ¹ý SLIP ·þÎñÆ÷À´ÔÚ SLIP ¿Í»§»ú×ÓÍøÉϽøÐзÓÉ¡£
¾²Ì¬Â·ÓÉ
static routes
ÏòÄú×î½üµÄĬÈÏ·ÓÉÌí¼ÓÒ»¸ö¾²Ì¬Â·ÓÉ¿ÉÒÔ˵ÊǺÜÂé·³
(»òÕß˵ÊDz»¿ÉÄÜ£¬ Èç¹ûÄúûÓÐȨÏÞÕâô×ö)¡£ Èç¹ûÔÚÄúµÄ×éÖ¯ÖÐʹÓöà·ÓÉÆ÷ÍøÂ磬
ÓÐЩ·ÓÉÆ÷ (±ÈÈç Cisco ºÍ Proteon Éú²úµÄ) ²»µ«ÒªÅäÖÃÖ¸Ïò SLIP
×ÓÍøµÄ·ÓÉ£¬ ¶øÇÒ»¹ÐèÒªÅäÖý«ÄÄЩ¾²Ì¬Â·ÓÉ´«¸øÆäËüµÄ·ÓÉÆ÷¡£
ËùÒÔһЩר¼ÒÒâ¼ûºÍÎÊÌâ½â´ð¶ÔÓÚʹ»ùÓÚ¾²Ì¬Â·ÓɱíµÄ·ÓÉÕý³£¹¤×÷ºÜÓбØÒª¡£
diff --git a/zh_TW.Big5/articles/contributing/article.xml b/zh_TW.Big5/articles/contributing/article.xml
index d372acf288..f888dfdf8b 100644
--- a/zh_TW.Big5/articles/contributing/article.xml
+++ b/zh_TW.Big5/articles/contributing/article.xml
@@ -1,488 +1,483 @@
À°§U FreeBSD
µL½×¬OÓ¤H©Î¬O¦UºØ²Õ´¡A¦pªG§Æ±æ¬° FreeBSD ´£¨ÑÀ°§U¡A³£¥i¥H¦b¥»¤å¤¤§ä¨ì¦X¾Aªº¤èªk¡C
Jordan
Hubbard
ìµÛ¡G
&tm-attrib.freebsd;
&tm-attrib.ieee;
&tm-attrib.general;
$FreeBSD$
$FreeBSD$
°^Äm
§A§Æ±æ´À FreeBSD °µÂI¤°»ò¶Ü¡H¤Ó¦n¤F¡A§ÚÌÅwªï§A¡CFreeBSD
¥¿¬O¦³¿à©ó¼s¤j¨Ï¥ÎªÌªº°^Äm¤~±o¥Hµo®i§§¤jªº¡C§Ṳ́£¶È«D±`·PÁ±z©Ò°µªº°^Äm¡A¦Ó¥B¡A³o¨Ç¤u§@¹ï©ó FreeBSD ªº«ùÄòµo®i¤]¦ÜÃö«n¡C
¤]³\»P±z·Q¹³ªº¤£¦P¡A±z¬J¤£¥²±o¬O¤@¦W¥X¦âªº Programmer¡A¤]µL¶·©M
FreeBSD core team ¦¨û¦³«Ü¦nªº¨p¥æ¡A§ÚÌ·|¤@µø¦P¤¯ªº¹ï«Ý±zªº¤u§@¡C
FreeBSD ªº¶}µo¤Hû¹M¥¬¥þ²y¡A¤j®a§Þ³N±Mªø¦U²§¡A¦~ÄÖ¤À¥¬¤]«D±`¼sªx¡C
µM¦Ó¡A¨C¤Ñ§Ú̳£¦b±¹ï«ùÄò¼W¥[ªº¤u§@¡A¦ÓW©ó¨S¦³¨¬°÷ªº¤H¤â¡A¦]¦¹§ÚÌÀH®ÉÅwªï±zªºÀ°§U¡C
FreeBSD p¹º©Ò³B²zªº¬O¤@Ó§¹¾ãªº§@·~¨t²ÎÀô¹Ò¡A¦Ó¤£¥u¬O¤@Ó kernel ©Î¬O¤@¨Ç¹s´²ªº¤u¨ã¥]¡C
¦]¦¹¡A§Ú̪º TODO «Ý¿ì¥ô°È¦Cªí¸Ì¥]§t¦U¦¡¦U¼Ëªº¤u§@¡G
±q¤å¥ó¡B¨Ï¥ÎªÌ´ú¸Õ¡Bdemo¡A¨ì¨t²Î¦w¸Ëµ{¦¡©M§ó±M·~ªº kernel ¶}µo¡C
¦]¦¹µL½×±zªº§Þ³N¤ô·Ç¦p¦ó¡A±q¨Æ¦óºØ»â°ì¡A³£¥i¥HÀ°§U³oÓp¹º¡C
§Ú̹ªÀy±q¨Æ©M FreeBSD ¬ÛÃö¤u§@ªº¥ø·~©M§ÚÌÁpô¡C
±z»Ýn¤@¨Ç¯S®íªºÂX®i¨Ó¨Ï±zªº²£«~¹BÂà°_¨Ó¶Ü¡H
±z·|µo²{§Úַ̫ܼNµªÀ³±zªº½Ð¨D¡A°£«D¬O¯S§Oµ}©_¥j©Çªº¡C
±z¬O§_¥¿±q¨Æ¬ÛÃöªº¼WÈ·~°È¡H Åý§Ų́ÓÀ°§U±z§a¡A
§Ṳ́]³\¥i¥H¦b¬Y¨Ç¤è±¬Û¤¬¦X§@¡C
¦Û¥Ñ³nÅé¬É¥¿¦b§V¤O¥´¯}¦³ªº®Ø®Ø(¹³¬OÃö©ó³nÅé¶}µo¡B¾P°â©MºûÅ@)¡A
§Ú̧ƱæÀµ½Ð±z¦Ü¤Ö¯àµ¹¥¦¤@¦¸¾÷·|¡C
§Ú̪º»Ý¨D
¤U±¦C¥X¤F¤@¨Ç»Ýn§¹¦¨ªº¥ô°È©M¤lp¹º¡A
¥¦Ì¥Nªí TODO(«Ý¿ì¥ô°È¦Cªí)
¦Cªíªº·N«ä¡A¥H¤Î¨Ï¥ÎªÌªºn¨D¡C
¥¿¦b¶i¦æ¤¤ªº¥ô°È(«Dµ{¦¡¶}µo¤Hû)
«Ü¦h°Ñ¥[ FreeBSD p¹ºªº¤H¤£¬O Programmer¡C
³oÓp¹º¸Ì¦³¤å¥ó¼¶¼gªÌ¡Bºô¶³]p®v¡B¥H¤Î§Þ³N¤ä´©¤Hû¡C
¹ï©ó³o¨Ç¸q¤u¨Ó»¡¡A¥LÌ¥u»Ýn°^Äm¤@¨Ç®É¶¡¡A¨Ã¥B¨ã¦³¾Ç²ßªº·NÄ@¡C
±z¥i¥H®É±`½¾\ FAQ ©M¤â¥U(Handbook)
¡A¦pªGµo²{¦³¸ÑÄÀ¤£²M·¡ªº¦a¤è¡A©Î¬O¤£¦X®É©yªº¤å¥ó¡A¬Æ¦Ü§¹¥þ¤£¥¿½Tªº¦a¤è¡A
³£½Ð§i¶D§ÚÌ¡C·íµM¡AY¯à¶¶¤â§â¥LÌ×¥¿¡A¨Ã§â°É»~±Hµ¹§ÚÌ¡A¨º´N§ó¦n¤F¡C:)
(SGML ¨ä¹ê¨Ã¤£Ãø¾Ç¡A¦ý§Ṳ́]¤£¤Ï¹ï±zª½±µ´£¥æ¤@¯ë ASCII ªº¯Â¤å¦rª©¥»)¡C
À°§U§Ú̧â FreeBSD ¤å¥ó½Ķ¦¨§Aªº¥À»y¡C
¦pªG§Aªº¥À»yª©¥»¤w¸g¦s¦b¤F¡A
¤]¥i¥H½Ķ¤@¨ÇÃB¥~ªº¤å¥ó¡A©ÎªÌÀˬd¨º¨Ç¤w¦³ªº¤å¥ó¬O§_¬°³Ì·sª©¡C
±z¥i¥H¥ý²³æ¬Ý¬Ý FreeBSD ¤å¥óp¹º¤¤¦³Ãö ½Ķ®Éªº±`¨£°ÝÃD¡C
°Ñ¥[½Ķ¤u§@¡A¨Ã¤£¬O»¡±zn©tx¾Ä¾Ô½Ķ©Ò¦³ FreeBSD ¤å¥ó¡C
¨¬°¸q¤u¡An°µ¦h¤Ö¤u§@§¹¥þ¨ú¨M©ó±zªº·NÄ@¡C¤@¥¹¬YÓ¤H¶}©l½Ķ¤F¡A
¤§«á´X¥G¤@©w·|¦³¨ä¥L¤H°Ñ»P¨ì³o¨Ç¤u§@¤¤¨Ó¡C
¦pªG®É¶¡¦³¡A©ÎªÌºë¤O¤£°÷¥h½Ķ¾ã¥÷¤å¥ó¡A¨º¥i¥Hº¥ý¥h½Ķ¦w¸Ë«ü«n¡C
¾\Ū &a.questions; ¨Ã°¸º¸Â½¾\(¬Æ¦Ü¦³³W«ß¦a³o¼Ë°µ) &ng.misc;
¡C»P§O¤H¤À¨É±zªº±M·~ª¾ÃÑ¡A
¨ÃÀ°§U¥L̸ѨM°ÝÃD¡A¬O¥ó¥O¤H´r®®ªº¨Æ±¡¡F
¦³®ÉÔ¡A±z¬Æ¦Ü¥i¥H¦b³oÓ¹Lµ{¤¤¾Ç¨ì¤@¨Ç·sªF¦è¡I
³o¨Ç½×¾Â¦³®É¤]·|¬°±z¿Eµo¥X¤@¨Ç¤£¿ùªº·Qªk¡C
¥¿¦b¶i¦æ¤¤ªº¥ô°È(µ{¦¡¶}µo¤Hû)
¦C¦b³o¸Ìªº¤j³¡¤À¥ô°È³£»Ýn±z§ë¤J¥iÆ[ªº®É¶¡¡A©ÎªÌ»Ýn±z¦b FreeBSD kernel
¤è±¦³Â×´Iªºª¾ÃÑ¡A©ÎªÌ¨âªÌ³£n¡C·íµM³o¸Ì¤]¦³«Ü¦h«nªº¥ô°È¡A¾A¦X¹³¬O
weekend hackers
³oÃþ¥u¥Î¶g¥½´N¥i¥H·d©wªº Hacker¡C
¦pªG±z¥¿¦b¶]ªº¬O FreeBSD -CURRENT ª©¥»¡A¨Ã¥Bºô¸ô³t«×ÁÙ¤£¿ù¡A
¨º»ò¥i¥H¨ì current.FreeBSD.org¡A
³o¥x¨C¤Ñ·|¦³¤@Ó·sª©¥» — ¦pªG±z¦³ªÅ¡A
±z¥i¥H¤T¤£¤®É¤U¸ü¨Ã¦w¸Ë¡A
¨ä¶¡¦pªG¥X¤F¤°»ò°ÝÃD¡A½Ð§i¶D§ÚÌ¡C
¾\Ū &a.bugs;¡C³o¨Ç°ÝÃD¡A©Î³\±z¯à´£¨Ñ¦³«Ø³]©Ê·N¸qªº·N¨£¡A
©ÎªÌÀ°¦£´ú¸Õ¤@¨Ç patch ¡C¦¹¥~¡A¬Æ¦Ü¥i¥H¹Á¸Õ×¥¿¨ä¤¤ªº¤@¨Ç°ÝÃD¡C
¦pªG±zª¾¹D¦³¤@¨Ç×¥¿¤w¸g¦b -CURRENT ¤W¦¨¥\¦a¨Ï¥Î¡A
¦ý¦b¸g¹L¤@¬q®É¶¡(³q±`¬O 2 ¶g¥ª¥k)¤§«á¡A¤´¥¼¦X¨Ö¨ì -STABLE
(³o¨BÆJ´N¬O MFC -- Merged From Current)¡A¨º»ò¥i¥Hµ¹¬ÛÃöªº committer ¤Hûµo«Ê§»ªªº´£¿ô«H¡C
±N²Ä¤T¤è(3rd party)³nÅé¥[¤J¨ìì©l½X¤¤ªº
src/contrib ¥Ø¿ý¡C
½T«O src/contrib ¤¤ªºì©l½X¬O³Ì·sªº¡C
½sĶì©l½X(©Î¬O³¡¤Àì©l½X)®É¡A½Ð§ï¥Î§ó°ªªºÄµ§iµ¥¯Å(warning level)
¥H«K°»¿ù(debug)¥Î¡A¨Ã¦b§¹¦¨´ú¸Õ¡B½T»{¥¿±`§¹²¦¤§«á¡A²M°£³o¨Ç½sĶªºÄµ§iµ¥¯Å¡C
§ó·s¨º¨Ç¦b ports ¤¤¨Ï¥Î¹L®ÉªºªF¦è¡A
¨Ò¦p gets() ©Î¥]§t
malloc.h ©Ò²£¥ÍªºÄµ§i¡C
¦pªG¦³¬° ports §@¤F¥ô¦ó×¥¿¡A
½Ð°O±o±N±zªº patch µoµ¹ì§@ªÌ (³o¼Ë¤U¦¸¤É¯Å®É¡A±zªº¤u§@·|Åܱo»´ÃP¤@¨Ç)¡C
¥ý¨ú±o¥¿¦¡ªº¼Ð·Ç¡A¦p &posix; ªº°Æ¥»¡C
¦b FreeBSD
C99 & POSIX ¼Ð·Ç¬Û®ep¹º ºô¯¸¤W¡A¥i¥H±o¨ì¬ÛÃöÃì±µ¡C
½Ð±N FreeBSD ªº¦æ¬°»P¤Wzªº¼Ð·Ç¶i¦æ¤ñ¸û¡AY©Ò±oµ²ªG»P C99 & POSIX ¼Ð·Ç¤£¦Pªº¸Ü¡A
¯S§O¬O¨º¨Ç²Ó¸`¦a¤èªº·L¤p®t²§¡A½Ðµo¤@ÓÃö©ó¥¦ªº PR (°ÝÃD³ø§i)¡C
¦pªG¥i¯à¡A½Ð«ü¥X¦p¦ó×¥¿¥¦¡A¨ÃÀH PR ´£¥æ patch ¡C
¦pªG±z»{¬°¼Ð·Ç¦³°ÝÃD¡A½Ð¦V³o¨Ç³W®æ¼Ð·Çªº¬ÛÃö¹ÎÅé¡A½Ð¨D¹ï¨ä¶i¦æ«·sªº¦Ò¼{¡C
¬°³o¥÷¦Cªí´£¨Ñ§ó¦h«ØÄ³¡I
¬d¾\¾ãÓ PR ¸ê®Æ®w
°ÝÃD³ø§i¸ê®Æ®w
FreeBSD
PR ¦Cªí ³o¸Ì·|Åã¥Ü¥Ø«e©Ò¦³ PR ªº°ÝÃDª¬ºA¡A¥H¤Î¥Ñ
FreeBSD ¨Ï¥ÎªÌ´£¥æªº§ï¶i«ØÄ³¡C
PR ¸ê®Æ®w¦P®É¥]¬A¤F¶}µo¤Hû©M«D¶}µo¤Hûªº¥ô°È¡C
¬d¬Ý¨º¨Ç©|¥¼¸Ñ¨Mªº PR¡A¨Ã¬Ý¬Ý¬O§_¦³±z·P¿³½ìªº¥ô°È¡C
³o¨ä¤¤¥i¯à¦³¤@¨Ç¬O«D±`²³æªº°ÝÃD¡A¥u»Ýn¬Ý¤@¬Ý¨Ã½T»{ PR ¬O¥¿½Tªº¡C
¥t¥~¤@¨Ç¥i¯à·|«D±`½ÆÂø¡A©ÎªÌ§¹¥þ¥¼ªþ¥ô¦ó×¥¿¡C
º¥ý¬Ý¤@¬Ý¨º¨ÇÁÙ¨S¦³¤H±µ¤âªº PR¡C
¦pªG PR ¤w¸g¤À°tµ¹¤F¨ä¥¦¤H¡A¦ý¬Ý°_¨Ó¬O±z¯à°÷³B²zªº¡A
±z¥i¥H±H«Hµ¹¨ºÓ¤H¡A¨Ã¸ß°Ý±z¬O§_¥i¥H´£¨ÑÀ°§U —
¥LÌ¥i¯à¤w¸g¦³¥i¨Ñ´ú¸Õªº patch ¡A©Î¦³¤@¨Ç¥i¨Ñ°Q½×ªº·N¨£¡C
¥Ñ Ideas
¤¤¿ï¤@¶µ
&os; list of
projects and ideas for volunteers ¦P¼Ë¦a¶}©ñµ¹¦³·NÄ@°Ñ»P
&os; p¹ºªº¤H¡C
³o¥÷²M³æ±N«ùÄò¦a§ó·s¡A¦P®É´£¨Ñ¦UÓ¶µ¥Øªº¸ê°Tµ¹©Ò¦³¤H
¡]¤£½×¬O§_¬°µ{¦¡³]p¤Hû¡^¡C
¦p¦ó´£¨ÑÀ°§U
°ò¥»¤W¥i¥H¤À¬°¥H¤U 5 ºØ¤è¦¡¡G
¿ù»~³ø§i©M·N¨£µoªí
³q±`¡A¤@¯ë
ªº§Þ³N·Qªk©M«ØÄ³À³¸Óµo¨ì &a.hackers;¡C
¦P¼Ë¦a¡A¹ï©ó³o¨ÇªF¦è¦³¿³½ìªº¤H (·íµM¡A
¥L̦P®ÉÁÙn¯à°÷®e§Ô ¤j¶qªº ¶l¥ó¡I)
¥i¥H¦Ò¼{q¾\ &a.hackers;¡C
½Ð°Ñ¾\ FreeBSD
¨Ï¥Î¤â¥U ¥H¤F¸ÑÃö©ó³oÓ¶l»¼½×¾Â¡A
¥H¤Î¨ä¥¦¶l»¼½×¾Âªº¸Ô²Ó±¡ªp¡C
¦pªG±zµo²{¤F bug ©ÎªÌ·Qn´£¥æ¬Y¨Ç×§ï¡A
½Ð³z¹L &man.send-pr.1; µ{¦¡©Î¨Ï¥Î
ºô¶¤¶±
ªº¦^³ø ¨Ó´£¥æ¡C½Ð¸ÕµÛ¶ñ¼g PR ªº¨CÓ¶µ¥Ø¡C
¤@¯ë¨Ó»¡¡A°£«D patch ÀɶW¹L 65 KB¡A§ÚÌ«ØÄ³¦b PR ¤¤ª½±µªþ¤W patch ´N¥i¥H¤F¡C
Y¥iª½±µ®M¥Î patch ¨ìì©l½Xªº¸Ü¡A¨º»ò«ØÄ³¦b PR ªº
Synopsis Äæ¦ìµù©ú [PATCH]¡C
¹ï¤F¡A¦bªþ¤W patch ®É¡A½Ð ¤£n
³z¹L·Æ¹«ªº¡y½Æ»s¡B¶K¤W¡z¨Ó¶i¦æ¡A¦]¬°³o¼Ë°µ·|§â Tab Åܦ¨ªÅ®æ¡A
·|¾ÉP patch ´N¤£¯à¥Î¤F¡C¦pªG patch ¶W¹L 20KB¡A
½Ð¦Ò¼{À£ÁY¥¦¨Ã¨Ï¥Î &man.uuencode.1; ¨Ó¶i¦æ½s½X¡C
¦b¼g§¹ PR ¤§«á¡A±z·|¦¬¨ì¤@«Ê½T»{¶l¥ó¥H¤Î¨Æ¥ó°lÂܽs¸¹¡C
½Ð«O¯d³oÓ½s¸¹¡A¦]¬°¨Æ«á¥i¥H¥Î³o½s¸¹µo«H¨ì &a.bugfollowup;
¨Ó¦^ÂСB´£¨ÑÃö©ó¸Ó¨Æ¥óªº«áÄò¸ê®Æ¡C±z»Ýn°µªº¬O±N½s¸¹©ñ¨ì¶l¥óªº¼ÐÃD¤¤¡A
¨Ò¦p "Re:
kern/3377"¡C
Y¬O¦P¤@°ÝÃDªº¦^ÂФ象AÀ³¸Ó³z¹L³oºØ¤è¦¡¨Ó¶i¦æ¡C
¦pªG±z¦b¤@¬q®É¶¡ (¶W¹L 3 ¤Ñ¬Æ¦Ü 1 ¶g¡A³o¨ú¨M©ó±zªº¶l¥óªA°È)¤§«á¤´µM¨S¦³¦¬¨ì½T»{«H
©ÎªÌ¥Ñ©ó¤@¨Çì¦]µLªk¨Ï¥Î &man.send-pr.1; µ{¦¡¡A
«h¥i¥Hµo«H¨ì &a.bugs; ¨Ó½Ð§O¤HÀ°§A¥N±H¡C
½Ð°Ñ¾\ ³o½g¤å³¹
¤F¸Ñ¦p¦ó¼¶¼g¦nªº°ÝÃD³ø§i¡C
¹ï©ó¤å¥óªº×q
´£¥æ¤å¥ó
¤å¥óªº×§ï¤è±¡A¬O¥Ñ &a.doc; ¨Ó¼f¬d¡C
½Ð°Ñ¾\ FreeBSD Documentation Project Primer
¨ÓÀò±o§¹¾ãªº±Ð¾Ç²Ó¸`¡C
½Ð«ö·Ó ¤¤¤¶²Ðªº¤èªk¨Ï¥Î &man.send-pr.1;
¨Ó´£¥æ·sªº¤å¥ó¡A©ÎªÌ§ïµ½²{¦³ªº¤å¥ó (þ©È¬O«Ü¤pªº§ï¶i¤]¬OÅwªïªº¡I)¡C
¹ï©ó²{¦³ì©l½Xªº×§ï
FreeBSD-CURRENT
¦b²{¦³ì©l½X¤W¶i¦æ×§ï©Î¼W¥[¥\¯à¡A¦b¬YºØµ{«×¤W¬O»Ýn§ó¦h§Þ¥©ªº¨Æ¡A
¨Ã¥BÁÙ¸ò±z¹ï©ó¥Ø«e FreeBSD ªº¶}µo²{ª¬¤F¸Ñµ{«×¦³Ãö¡C
¦³¦hºØ¤è¦¡¥i¥H±o¨ì³QºÙ§@ FreeBSD-CURRENT
ªº FreeBSD ¶}µoª©¥»¡C
½Ð°Ñ¾\ FreeBSD ¨Ï¥Î¤â¥Uªº ¬ÛÃö³¡¥÷ ¡A¨Ó¤F¸Ñ¨Ï¥Î FreeBSD-CURRENT ªº¸Ô±¡¡C
¦bªºì©l½X¤W¶i¦æ×§ï¡A«h³q±`¥i¯àì©l½X¤w¹L®É¡A
©Î»P·sªºª©¥»®t²§¤Ó¤j¦ÓµLªk³Q«·s¾ã¦X¨ì FreeBSD ¤¤¡C
¦pªG±z¦³q &a.announce; ¥H¤Î &a.current; ªº¸Ü¡A
«h¥i¥H³z¹L¥¦Ì¨Ó¤jP¤F¸Ñ¥Ø«eªº¶}µoª¬ºA¡C
Y±z¯à°÷¾¨¶q¥H³Ì·sªºì©l½X¨Ó¶i¦æ±zªº×§ï¡A
«h¤U¤@¨Bn°µªº¨Æ±¡´N¬O²£¥Í±z©Òק諸 diff ÀÉ¡A
¨Ã±N¥¦µoµ¹ FreeBSD ªººûÅ@¤Hû¡C³o¶µ¤u§@¥i¥H³z¹L &man.diff.1;
©R¥O¨Ó§¹¦¨¡C
´£¥æ patch ®É¡A«ØÄ³ &man.diff.1; ®æ¦¡±Ä¥Î unified diff (¥i¥H¥Î diff
-u ¨Ó²£¥Í)¡C¤£¹L¡A¦pªG±z×§ï¤F¤j¶qªºì©l½X¡A
«h¨Ï¥Î diff -c ¨Ó¥Í¦¨ªº context diff
ªº diff ¥i¯à§ó®e©ö¾\Ū¡A¦]¦Ó±ÀÂ˨ϥΡC¤@¯ë¦Ó¨¥¡A¤j³£¬O±Ä¥Î diff -ruN §Y¥i¡C
diff
¨Ò¦p¡G
&prompt.user; diff -c oldfile newfile
©Î
&prompt.user; diff -c -r olddir newdir
±N·|¹ï¯S©w¥Ø¿ý¡A²£¥Í context ªº diff ÀÉ¡C
©ÎªÌ¹³¬O...
&prompt.user; diff -u oldfile newfile
©Î
&prompt.user; diff -u -r olddir newdir
±N²£¥Í¤@¼Ëªº diff ¡A¦ý¬O®æ¦¡¬° unified ¡C
§ó¦hªº²Ó¸`³¡¥÷¡A½Ð°Ñ¾\ &man.diff.1;¡C
¤@¥¹±z¨Ï¥Î &man.diff.1; ¨Ó²£¥Í diff ÀÉ (¥i¥H¨Ï¥Î
&man.patch.1; ©R¥O¨Ó´ú¸Õ¤@¤U)¡A´N¥i¥H´£¥æ¥¦Ì¡A¥H«K³Q FreeBSD ¦¬¿ý¡C
³z¹L¨Ï¥Î
¤¤©Ò¤¶²Ðªº &man.send-pr.1; µ{¦¡´N¥i¥H§¹¦¨³o¶µ¤u§@¡C
½Ðª`·N¡G¤£n¥u§â diff Àɵo¨ì &a.hackers;¡A
§_«h¥¦Ì¥i¯à·|³Q¿ò§Ñ¡I §ÚÌ·|«D±`·P¿E±z´£¥æªº×§ï
(³o¬O¤@Ó¸q¤up¹º¡I)¡F ¦]¬°§Ú̳£«Ü¦£¡A
¦]¦¹¦³®É¤£¤@©w¯à°÷¥ß§Y×¥¿°ÝÃD¡A¦ý PR ¸ê®Æ®w±N¤@ª½«O«ùµÛ³o¨Ç°O¿ý¡A
¦]¦¹¥un¦³¤H¦³¤F®É¶¡¥¦Ì´N¯à³Q§ï¥¿¤F¡C
¦pªG±zªº°ÝÃD³ø§i¤¤¥]¬A patch ¡A¤£n§Ñ¤F¦b¼ÐÃD¥[¤W
[PATCH] ¨Ó±j½Õ¤@¤U¡C
uuencode
¦pªG±z»{¬°¦X¾A (¨Ò¦p¼W¡B§RÀɮשΧó§ïÀɦW)¡A
ÁÙ¥i¥H¦Ò¼{¨Ï¥Î
tar ¨Ó±NÀÉ®×¥´¥]¡AµM«á¥Î &man.uuencode.1;
¨Ó½s½X¡C¦¹¥~¡A¤]¥i¥H¥Î &man.shar.1; ²£¥Íªº¤è¦¡¡C
¦pªG±zªº×§ï¥i¯à¦s¦b¼ç¦bªºª§Ä³¡A¨Ò¦p¡A
±z¤£½T©w¬ÛÃöªºª©Åv°ÝÃD¡A©ÎªÌ·Pı»Ýn¸g¹L§óÄY®æªº´_¼f¤~¥i¥Hµo§G¥¦Ì¡A
«hÀ³ª½±µµoµ¹ &a.core;¡A¦Ó¤£¬O³z¹L &man.send-pr.1; ¨Óµo°e¡C
&a.core; ³o¤p²Õ¦¨û¤j¦h±q¨Æ FreeBSD ªº¤é±`¤u§@¡C
»Ýnª`·Nªº¬O¡A³oÓ¤p²Õ¤]¦]¦¹¤Q¤À¦£¸L¡A
¦]¦¹¥u¦³¦b«D±`¥²nªº®ÉÔ¡A¤~À³¼g«Hµ¹¥LÌ¡C
½Ð°Ñ¦Ò &man.intro.9; ©M &man.style.9; ¥H¤F¸ÑÃö©ó¼¶¼gµ{¦¡½Xªº·®æ°¾¦n¡C
Y¯à¦b°e¥X¬ÛÃöµ{¦¡½X¤§«e¡A¥ý¤F¸Ñ³o¨Ç¡A¨º¹ï¤j®a¨Ó»¡±N¬O·¥¤jªºÀ°§U¡C
·sì©l½X©Î«nªº¥[ȳnÅé¥]
¦pªG±z¥´ºâ´£¨Ñ³W¼Ò¸û¤jªºì©l½X¡A©ÎªÌ¬° FreeBSD ¼W¥[«nªº·s¥\¯à¡A
«h¥i¯à¥²¶·±N¥¦Ì³z¹L uuencode ¶i¦æ½s½X¡A©Î¶Ç¨ì¬YÓ Web ©Î
FTP ¯¸ÂI¡A¥H«K§ó¦hªº¤H¯à°÷±o¨ì¥¦¡C¦pªG±z¨S¦³³o¼Ëªº¥D¾÷¡A
½Ð¨ì¬ÛÃöªº FreeBSD ¶l»¼½×¾Â´£¥X¡A¬Ý¬Ý¬O§_¦³¤HÄ@·NÀ°±z©ñ¸m¥¦Ì¡C
¹ï©ó¤j¶qªºì©l½X¦Ó¨¥¡AÃö©óª©Åvªº°ÝÃDªÖ©w·|³Q´£¥X¡C
FreeBSD °ò¥»¨t²Î¤¤¯à°÷¨Ï¥Îªºª©ÅvÁn©ú¥]¬A¡G
- BSD ª©ÅvÁn©ú
- BSD ª©Åv¡C§Ú̶ɦV©ó¨Ï¥Î³oÃþ±ÂÅvªºì©l½X¡A
+ BSDBSD ª©ÅvÁn©ú ª©Åv¡C§Ú̶ɦV©ó¨Ï¥Î³oÃþ±ÂÅvªºì©l½X¡A
¦]¬°¥¦¡y¤£ªþ¥[¦h¾lªº±ø¥ó¡z¡A¦]¦Ó§ó¯à°÷§l¤Þ°Ó·~¥ø·~¨Ï¥Î¡C
FreeBSD ¨Ã¤£¤Ï¹ï°Ó·~¤½¥q¨Ï¥Î¥¦ªºì©l½X¡A¬Û¤Ï¡A
§ÚÌ¿n·¥¦a¹ªÀy°Ó·~¤½¥q¨Ï¥Î§Ú̪ºì©l½X¡A
·íµM¡A¦pªG¥¦ÌY³Ì²×¯à§â³¡¤Àì©l½X¡A«·s®½Ãص¹ FreeBSD ´N§ó¦n¤F¡C
- GPLGNU General Public License
-
- GNU General Public License
-
- GNU General Public License¡A©Î²ºÙ GPL
¡C
+ GNU General Public License¡A©Î²ºÙ GPL
¡CGPLGNU General Public LicenseGNU General Public License
§Ų́䣫ÜÅwªï¨Ï¥Î³o¼Ë±ÂÅvªºì©l½X¡A
¦]¬°°Ó·~¤½¥q¨Ï¥Î¥¦»Ýn°µ§ó¦hªº¤u§@¡C¤£¹L¡A¥Ñ©ó«Ü¦h¨Ï¥Î
GPL ±ÂÅvªºì©l½X¥Ø«e¬OµLªkÁ×§Kªº (compiler, assembler, text formatterµ¥µ¥)
¡A©Úµ´¨Ï¥Î©Ò¦³±Ä¥Î³o¼Ë±ÂÅvªº³nÅé¬O«Ü¤£©ú´¼ªº¡C
±Ä¥Î GPL ±ÂÅvªºì©l½X·|³Q©ñ¨ìì©l½Xªº¤@¨Ç¯S©wªº¦ì¸m¡A¨Ò¦p
/sys/gnu ©Î
/usr/src/gnu¡A¥H«K¨º¨Ç»{¬° GPL
¥i¯à·|³y¦¨³Â·Ðªº¤H¯à°÷§@¥X¾A·íªº§PÂ_¡C
¨Ï¥Î¨ä¥¦±ÂÅvªºì©l½X¦b¶i¤J FreeBSD ¤§«e¥²¶·¸g¹L·V«ªº´_¼f©M¦Ò¼{¡C
±Ä¥Î¥]§tÄY¼F¨îªº°Ó·~±ÂÅvªºì©l½X¡A¤@¯ë¨Ó»¡·|³Q©Úµ´¡A
¦ý§Ú̹ªÀy³o¨Çì©l½Xªº§@ªÌ¡A³z¹L¦Û¤vªººÞ¹D¨Óµo¥¬¥¦Ì¡C
Yn¦b±zªº¦¨ªG¤W¥[¤J BSD-based
ª©Åvªº¸Ü¡A
½Ð§â¤U¦C¤å¦r©ñ¨ì¨C¥÷ì©l½Xªº³Ì¶}©l³¡¤À¡A
¨Ã¥Î¾A·íªº¤å¦r´À´« %% ¤§¶¡ªº¤å¦r¡C
Copyright (c) %%proper_years_here%%
%%your_name_here%%, %%your_state%% %%your_zip%%.
All rights reserved.
Redistribution and use in source and binary forms, with or without
modification, are permitted provided that the following conditions
are met:
1. Redistributions of source code must retain the above copyright
notice, this list of conditions and the following disclaimer as
the first lines of this file unmodified.
2. Redistributions in binary form must reproduce the above copyright
notice, this list of conditions and the following disclaimer in the
documentation and/or other materials provided with the distribution.
THIS SOFTWARE IS PROVIDED BY %%your_name_here%% ``AS IS'' AND ANY EXPRESS OR
IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES
OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE DISCLAIMED.
IN NO EVENT SHALL %%your_name_here%% BE LIABLE FOR ANY DIRECT, INDIRECT,
INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT
NOT LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF USE,
DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED AND ON ANY
THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT LIABILITY, OR TORT
(INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN ANY WAY OUT OF THE USE OF
THIS SOFTWARE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGE.
$Id$
¬°¤F¤è«K±zªº¨Ï¥Î¡A¦b
/usr/share/examples/etc/bsd-style-copyright
¤]¥i¥H§ä¨ì¦¹±ÂÅvªº°Æ¥»¡C
ÃÙ§U¸êª÷¡BµwÅé©Î Internet mirror
§ÚÌ«D±`Ä@·N±µ¨ü¦UºØ§Î¦¡ªº®½ÃØ¡A¥H¶i¤@¨B©Ý®i FreeBSD p¹º
¡A¦]¬°¦³±zªº¤ä«ù¡A¹³§Ú̳o¼Ëªº¸q¤u§V¤O¤~¯à°÷¦³§ó¤jªº¦¨´N¡I
®½ÃصwÅé¤]«D±`«n¡A¦]¬°³o¼Ë¯à°÷À°§U§Ú̼W¥[¥i¤ä´©ªºµwÅéºØÃþ¡A
¦Ó§Ṳ́¤ªº«Ü¦h¤H¨Ã¨S¦³¨¬°÷ªº¸êª÷¨ÓÁʸm³o¨ÇµwÅé¡C
®½´Ú
FreeBSD °òª÷·|¬O¤@Ó«DÀç§Qªº¡B¦³½Òµ|ÁŧKÅvªº°òª÷·|¡A
¤§©Ò¥H·|«Ø¥ß³oÓ°òª÷·|¡A¬O¬°¤FÅý FreeBSD p¹º¯à°÷¥iªø¥i¤[¡C
¦]¬°¸Ó°òª÷·|ÄÝ 501(c)3 ¹êÅé¡A¤@¯ë¦Ó¨¥®½´Úµ¹°òª÷·|ªº¸Ü¡A¥i¥H§Kú¬ü°êÁp¨¹¦¬¤Jµ|¡A
¥H¤Î¬ìù©Ô¦h¦{¦¬¤Jµ|¡C³q±`¹ï©ó¦³½Òµ|ÁŧKÅvªº¹êÅé¶i¦æ®½Ãتº¸Ü¡A
¥i¥H§é©èÁp¨¹¦¬¤J¤¤À³½Òµ|³¡¤Àªºª÷ÃB¡C
±z¥i¥H§â¤ä²¼±H©¹¡G
The FreeBSD Foundation
7321 Brockway Dr.
Boulder, CO 80303
USA
FreeBSD °òª÷·|²{¦b¥i¥H³z¹L PayPal ±qºô¤W±µ¨ü®½´Ú¡C
¦pªG±z·Q¦V°òª÷·|®½´Ú¡A½Ð°Ñ¾\ FreeBSD °òª÷·| ºô¯¸¡C
Ãö©ó FreeBSD °òª÷·|ªº§ó¦h¸Ô±¡¡A¥i¥H¦b FreeBSD
°òª÷·| -- ¤¶²Ð §ä¨ì¡CnÁpµ¸°òª÷·|¡A
½Ðµo°e¹q¤l¶l¥ó¨ì
bod@FreeBSDFoundation.org¡C
®½ÃصwÅé
®½ÃØ
FreeBSD p¹ºÅwªï¥ô¦ó¤H®½ÃØ¥i¥H¨Ï¥ÎªºµwÅé¡C
¦pªG±z¦³¿³½ì®½ÃصwÅé¡A½ÐÁpô ®½ÃØÁpµ¸¤H¿ì¤½«Ç¡C
¦¨¬° FreeBSD mirror ªººô¯¸
§ÚÌÅwªï·sªº FTP¡BWWW ©Î
cvsup mirror ¯¸¡C¦pªG±z§Æ±æ¦¨¬°³o¼Ëªº mirror ¯¸¡A
½Ð°Ñ¾\ ¦p¦ó¬[³] FreeBSD mirror
¤@¤å¡A¥H¤F¸Ñ¶i¤@¨Bªº±¡ªp¡C
diff --git a/zh_TW.Big5/books/handbook/boot/chapter.xml b/zh_TW.Big5/books/handbook/boot/chapter.xml
index 5400fc8b2c..55e11f129a 100644
--- a/zh_TW.Big5/books/handbook/boot/chapter.xml
+++ b/zh_TW.Big5/books/handbook/boot/chapter.xml
@@ -1,816 +1,812 @@
FreeBSD ¶}¾÷¬yµ{½g
·§z
booting
bootstrap
The process of starting a computer and loading the operating system
is referred to as the bootstrap process
, or simply
booting
. FreeBSD's boot process provides a great deal of
flexibility in customizing what happens when you start the system,
allowing you to select from different operating systems installed on the
same computer, or even different versions of the same operating system
or installed kernel.
This chapter details the configuration options you can set and how
to customize the FreeBSD boot process. This includes everything that
happens until the FreeBSD kernel has started, probed for devices, and
started &man.init.8;. If you are not quite sure when this happens, it
occurs when the text color changes from bright white to grey.
Ū§¹³o³¹¡A±z±N¤F¸Ñ¡G
What the components of the FreeBSD bootstrap system are, and how
they interact.
The options you can give to the components in the FreeBSD
bootstrap to control the boot process.
&man.device.hints.5; ªº°ò¥»·§©À¡C
x86 Only
This chapter only describes the boot process for FreeBSD running
on Intel x86 systems.
Booting °ÝÃD
Turning on a computer and starting the operating system poses an
interesting dilemma. By definition, the computer does not know how to
do anything until the operating system is started. This includes
running programs from the disk. So if the computer can not run a
program from the disk without the operating system, and the operating
system programs are on the disk, how is the operating system
started?
This problem parallels one in the book The Adventures of
Baron Munchausen. A character had fallen part way down a
manhole, and pulled himself out by grabbing his bootstraps, and
lifting. In the early days of computing the term
bootstrap was applied to the mechanism used to
load the operating system, which has become shortened to
booting
.
BIOS
Basic Input/Output SystemBIOS
On x86 hardware the Basic Input/Output System (BIOS) is responsible
for loading the operating system. To do this, the BIOS looks on the
hard disk for the Master Boot Record (MBR), which must be located on a
specific place on the disk. The BIOS has enough knowledge to load and
run the MBR, and assumes that the MBR can then carry out the rest of the
tasks involved in loading the operating system,
possibly with the help of the BIOS.
Master Boot Record (MBR)
Boot Manager
Boot Loader
The code within the MBR is usually referred to as a boot
manager, especially when it interacts with the user. In this case
the boot manager usually has more code in the first
track of the disk or within some OS's file system. (A
boot manager is sometimes also called a boot loader,
but FreeBSD uses that term for a later stage of booting.) Popular boot
managers include boot0 (a.k.a. Boot
Easy, the standard &os; boot manager),
Grub, GAG, and
LILO.
(Only boot0 fits within the MBR.)
If you have only one operating system installed on your disks then
a standard PC MBR will suffice. This MBR searches for the first bootable
(a.k.a. active) slice on the disk, and then runs the code on that slice to
load the remainder of the operating system. The MBR installed by
&man.fdisk.8;, by default, is such an MBR. It is based on
/boot/mbr.
If you have installed multiple operating systems on your disks then
you can install a different boot manager, one that can display a list of
different operating systems, and allows you to choose the one to boot
from. Two of these are discussed in the next subsection.
The remainder of the FreeBSD bootstrap system is divided into three
stages. The first stage is run by the MBR, which knows just enough to
get the computer into a specific state and run the second stage. The
second stage can do a little bit more, before running the third stage.
The third stage finishes the task of loading the operating system. The
work is split into these three stages because the PC standards put
limits on the size of the programs that can be run at stages one and
two. Chaining the tasks together allows FreeBSD to provide a more
flexible loader.
kernel
init
The kernel is then started and it begins to probe for devices
and initialize them for use. Once the kernel boot
process is finished, the kernel passes control to the user process
&man.init.8;, which then makes sure the disks are in a usable state.
&man.init.8; then starts the user-level resource configuration which
mounts file systems, sets up network cards to communicate on the
network, and generally starts all the processes that usually
are run on a FreeBSD system at startup.
The Boot Manager and Boot Stages
Boot Manager
The Boot Manager
Master Boot Record (MBR)
The code in the MBR or boot manager is sometimes referred to as
stage zero of the boot process. This subsection
discusses two of the boot managers previously mentioned:
boot0 and LILO.
The boot0 Boot Manager:
The MBR installed by FreeBSD's installer or &man.boot0cfg.8;, by
default, is based on /boot/boot0.
(The boot0 program is very simple, since the
program in the MBR can only be 446 bytes long because of the slice
table and 0x55AA identifier at the end of the MBR.)
If you have installed boot0 and
multiple operating systems on your hard disks, then you will see a
display similar to this one at boot time:
boot0 Screenshot
F1 DOS
F2 FreeBSD
F3 Linux
F4 ??
F5 Drive 1
Default: F2
Other operating systems, in particular &windows;, have been known
to overwrite an existing MBR with their own. If this happens to you,
or you want to replace your existing MBR with the FreeBSD MBR then use
the following command:
&prompt.root; fdisk -B -b /boot/boot0 device
where device is the device that you
boot from, such as ad0 for the first IDE
disk, ad2 for the first IDE disk on a second
IDE controller, da0 for the first SCSI disk,
and so on. Or, if you want a custom configuration of the MBR,
use &man.boot0cfg.8;.
The LILO Boot Manager:
To install this boot manager so it will also boot FreeBSD, first
start Linux and add the following to your existing
/etc/lilo.conf configuration file:
other=/dev/hdXY
table=/dev/hdX
loader=/boot/chain.b
label=FreeBSD
In the above, specify FreeBSD's primary partition and drive using
Linux specifiers, replacing X with the Linux
drive letter and Y with the Linux primary
partition number. If you are using a SCSI drive, you
will need to change /dev/hd to read something
similar to /dev/sd. The
line can be omitted if you have
both operating systems on the same drive. Now run
/sbin/lilo -v to commit your new changes to the
system; this should be verified by checking its screen messages.
Stage One, /boot/boot1, and Stage Two,
/boot/boot2
Conceptually the first and second stages are part of the same
program, on the same area of the disk. Because of space constraints
they have been split into two, but you would always install them
together. They are copied from the combined file
/boot/boot by the installer or
disklabel (see below).
They are located outside file systems, in the first track of
the boot slice, starting with the first sector. This is where boot0, or any other boot manager,
expects to find a program to run which will
continue the boot process. The number of sectors used is easily
determined from the size of /boot/boot.
boot1 is very simple, since it
can only be 512 bytes
in size, and knows just enough about the FreeBSD
disklabel, which stores information
about the slice, to find and execute boot2.
boot2 is slightly more sophisticated, and understands
the FreeBSD file system enough to find files on it, and can
provide a simple interface to choose the kernel or loader to
run.
Since the loader is
much more sophisticated, and provides a nice easy-to-use
boot configuration, boot2 usually runs
it, but previously it
was tasked to run the kernel directly.
boot2 Screenshot
>> FreeBSD/i386 BOOT
Default: 0:ad(0,a)/kernel
boot:
If you ever need to replace the installed
boot1 and boot2 use
&man.disklabel.8;:
&prompt.root; disklabel -B diskslice
where diskslice is the disk and slice
you boot from, such as ad0s1 for the first
slice on the first IDE disk.
Dangerously Dedicated Mode
If you use just the disk name, such as
ad0, in the &man.disklabel.8; command you
will create a dangerously dedicated disk, without slices. This is
almost certainly not what you want to do, so make sure you double
check the &man.disklabel.8; command before you press
Return.
Stage Three, /boot/loader
boot-loader
The loader is the final stage of the three-stage
bootstrap, and is located on the file system, usually as
/boot/loader.
The loader is intended as a user-friendly method for
configuration, using an easy-to-use built-in command set,
backed up by a more powerful interpreter, with a more complex
command set.
Loader Program Flow
During initialization, the loader will probe for a
console and for disks, and figure out what disk it is
booting from. It will set variables accordingly, and an
interpreter is started where user commands can be passed from
a script or interactively.
loader
loader configuration
The loader will then read
/boot/loader.rc, which by default reads
in /boot/defaults/loader.conf which
sets reasonable defaults for variables and reads
/boot/loader.conf for local changes to
those variables. loader.rc then acts
on these variables, loading whichever modules and kernel are
selected.
Finally, by default, the loader issues a 10 second wait
for key presses, and boots the kernel if it is not interrupted.
If interrupted, the user is presented with a prompt which
understands the easy-to-use command set, where the user may
adjust variables, unload all modules, load modules, and then
finally boot or reboot.
Loader Built-In Commands
These are the most commonly used loader commands. For a
complete discussion of all available commands, please see
&man.loader.8;.
autoboot seconds
Proceeds to boot the kernel if not interrupted
within the time span given, in seconds. It displays a
countdown, and the default time span is 10
seconds.
boot
-options
kernelname
Immediately proceeds to boot the kernel, with the
given options, if any, and with the kernel name given,
if it is.
boot-conf
Goes through the same automatic configuration of
modules based on variables as what happens at boot.
This only makes sense if you use
unload first, and change some
variables, most commonly kernel.
help
topic
Shows help messages read from
/boot/loader.help. If the topic
given is index, then the list of
available topics is given.
include filename
…
Processes the file with the given filename. The
file is read in, and interpreted line by line. An
error immediately stops the include command.
load
type
filename
Loads the kernel, kernel module, or file of the
type given, with the filename given. Any arguments
after filename are passed to the file.
ls
path
Displays a listing of files in the given path, or
the root directory, if the path is not specified. If
is specified, file sizes will be
shown too.
lsdev
Lists all of the devices from which it may be
possible to load modules. If is
specified, more details are printed.
lsmod
Displays loaded modules. If is
specified, more details are shown.
more filename
Displays the files specified, with a pause at each
LINES displayed.
reboot
Immediately reboots the system.
set variable
set
variable=value
Sets the loader's environment variables.
unload
Removes all loaded modules.
Loader Examples
Here are some practical examples of loader usage:
- single-user mode
To simply boot your usual kernel, but in single-user
- mode:
+ mode:single-user mode
boot -s
To unload your usual kernel and modules, and then
load just your old (or another) kernel:
-
- kernel.old
-
unload
load kernel.old
You can use kernel.GENERIC to
refer to the generic kernel that comes on the install
- disk, or kernel.old to refer to
+ disk, or kernel.oldkernel.old to refer to
your previously installed kernel (when you have upgraded
or configured your own kernel, for example).
Use the following to load your usual modules with
another kernel:
unload
set kernel="kernel.old"
boot-conf
To load a kernel configuration script (an automated
script which does the things you would normally do in the
kernel boot-time configurator):
load -t userconfig_script /boot/kernel.conf
Kernel Interaction During Boot
kernel
boot interaction
Once the kernel is loaded by either loader (as usual) or boot2 (bypassing the loader), it
examines its boot flags, if any, and adjusts its behavior as
necessary.
Kernel Boot Flags
kernel
bootflags
Here are the more common boot flags:
during kernel initialization, ask for the device
to mount as the root file system.
boot from CDROM.
run UserConfig, the boot-time kernel
configurator
boot into single-user mode
be more verbose during kernel startup
There are other boot flags, read &man.boot.8; for more
information on them.
Tom
Rhodes
Contributed by
Device Hints
device.hints
This is a FreeBSD 5.0 and later feature which does not
exist in earlier versions.
During initial system startup, the boot &man.loader.8; will read the
&man.device.hints.5; file. This file stores kernel boot information
known as variables, sometimes referred to as device hints
.
These device hints
are used by device drivers for device
configuration.
Device hints may also be specified at the
Stage 3 boot loader prompt. Variables can be added using
set, removed with unset, and viewed
with the show commands. Variables set in the
/boot/device.hints file can be overridden here also. Device hints entered at
the boot loader are not permanent and will be forgotten on the next
reboot.
Once the system is booted, the &man.kenv.1; command can be used to
dump all of the variables.
The syntax for the /boot/device.hints file is one variable per line, using
the standard hash #
as comment markers. Lines are
constructed as follows:
hint.driver.unit.keyword="value"
The syntax for the Stage 3 boot loader is:
set hint.driver.unit.keyword=value
driver is the device driver name, unit
is the device driver unit number, and keyword is the hint
keyword. The keyword may consist of the following options:
at: specifies the bus which the device is attached to.
port: specifies the start address of the I/O
to be used.
irq: specifies the interrupt request number to be used.
drq: specifies the DMA channel number.
maddr: specifies the physical memory address occupied by the
device.
flags: sets various flag bits for the device.
disabled: if set to 1 the device is disabled.
Device drivers may accept (or require) more hints not listed here, viewing
their manual page is recommended. For more information, consult the
&man.device.hints.5;, &man.kenv.1;, &man.loader.conf.5;, and &man.loader.8;
manual pages.
Init: Process Control Initialization
init
Once the kernel has finished booting, it passes control to
the user process &man.init.8;, which is located at
/sbin/init, or the program path specified
in the init_path variable in
loader.
Automatic Reboot Sequence
The automatic reboot sequence makes sure that the
file systems available on the system are consistent. If they
are not, and &man.fsck.8; cannot fix the
inconsistencies, &man.init.8; drops the system
into single-user mode
for the system administrator to take care of the problems
directly.
Single-User Mode
single-user mode
console
This mode can be reached through the automatic reboot
sequence, or by the user booting with the
option or setting the
boot_single variable in
loader.
It can also be reached by calling
&man.shutdown.8; without the reboot
() or halt () options,
from multi-user
mode.
If the system console is set
to insecure in /etc/ttys,
then the system prompts for the root password
before initiating single-user mode.
An Insecure Console in /etc/ttys
# name getty type status comments
#
# If console is marked "insecure", then init will ask for the root password
# when going to single-user mode.
console none unknown off insecure
An insecure console means that you
consider your physical security to the console to be
insecure, and want to make sure only someone who knows the
root password may use single-user mode, and it
does not mean that you want to run your console insecurely. Thus,
if you want security, choose insecure,
not secure.
Multi-User Mode
multi-user mode
If &man.init.8; finds your file systems to be
in order, or once the user has finished in single-user mode, the
system enters multi-user mode, in which it starts the
resource configuration of the system.
Resource Configuration (rc)
rc files
The resource configuration system reads in
configuration defaults from
/etc/defaults/rc.conf, and
system-specific details from
/etc/rc.conf, and then proceeds to
mount the system file systems mentioned in
/etc/fstab, start up networking
services, start up miscellaneous system daemons, and
finally runs the startup scripts of locally installed
packages.
The &man.rc.8; manual page is a good reference to the resource
configuration system, as is examining the scripts
themselves.
Shutdown Sequence
shutdown
Upon controlled shutdown, via &man.shutdown.8;,
&man.init.8; will attempt to run the script
/etc/rc.shutdown, and then proceed to send
all processes the TERM signal, and subsequently
the KILL signal to any that do not terminate
timely.
To power down a FreeBSD machine on architectures and systems
that support power management, simply use the command
shutdown -p now to turn the power off
immediately. To just reboot a FreeBSD system, just use
shutdown -r now. You need to be
root or a member of
operator group to run &man.shutdown.8;.
The &man.halt.8; and &man.reboot.8; commands can also be used,
please refer to their manual pages and to &man.shutdown.8;'s one
for more information.
Power management requires &man.acpi.4; support in the kernel
or loaded as module for FreeBSD 5.X and &man.apm.4;
support for FreeBSD 4.X.
diff --git a/zh_TW.Big5/books/handbook/cutting-edge/chapter.xml b/zh_TW.Big5/books/handbook/cutting-edge/chapter.xml
index d595f24567..08ea2f4dd1 100644
--- a/zh_TW.Big5/books/handbook/cutting-edge/chapter.xml
+++ b/zh_TW.Big5/books/handbook/cutting-edge/chapter.xml
@@ -1,1619 +1,1570 @@
Jim
Mock
Restructured, reorganized, and parts updated by
Jordan
Hubbard
Original work by
Poul-Henning
Kamp
John
Polstra
Nik
Clayton
§ó·s¡B¤É¯Å FreeBSD
·§z
&os; ¬OÓ«ùÄòµo®iªº§@·~¨t²Î¡C¹ï©ó³ßÅw°l¨D·sÂA¡B¨ë¿Eªº¨Ï¥ÎªÌ¦Ó¨¥¡A
¦³«Ü¦h¤èªk¥i¥H¨Ï±zªº¨t²Î»´ÃP§ó·s¬°³Ì·sª©¡C
ª`·N¡G¨Ã«D¨CÓ¤H³£¾A¦X³o»ò°µ¡I¡@¥»³¹¥Dn¬O¨ó§U±z¨M©w¨ì©³n¸ò¶}µoª©¥»¡A
©Î¬On¨Ï¥Î¸ûéwªºÄÀ¥Xª©¡C
Ū§¹³o³¹¡A±z±N¤F¸Ñ¡J
&os.stable; »P &os.current;¡@³o¨â¤À¤äªº¤£¦P¤§³B¡F
¦p¦ó¥H
CSup,
CVSup,
CVS ©Î
CTM ¨Ó§ó·s§Aªº¨t²Î
¦p¦ó¥H make buildworld
µ¥«ü¥O¨Ó«·s½sĶ¡B¦w¸Ë¾ãÓ base system¡C
¦b¶}©l¾\Ū³o³¹¤§«e¡A±z»Ýn¡J
¥ý³]¦n§Aªººô¸ô()¡C
ª¾¹D¦p¦ó³z¹L port/package ¦w¸Ë³nÅé()¡C
&os.current; vs. &os.stable;
-CURRENT
-STABLE
FreeBSD ¦³¨âÓµo®i¤À¤ä¡G&os.current; ¤Î
&os.stable;¡C¥»¸`±N·|³°Äò¤¶²Ð¡A¨Ã¤¶²Ð¥¦Ì¤À§O¤S¬O¦p¦ó§ó·s¡C
º¥ý¡A¥ý¤¶²Ð &os.current;¡A±µµÛ¦A¤¶²Ð &os.stable;¡C
¨Ï¥Î³Ì·sªº &os; CURRENT
³o¸Ì¦A¦¸±j½Õ¡A&os.current; ¬O &os; ¶}µoªº ³Ì«e½u
¡C
&os.current; ¨Ï¥ÎªÌ¶·¦³¸û±jªº§Þ³N¯à¤O¡A
¦Ó¥BÀ³¸Ón¦³¯à¤O¦Û¤v¸Ñ¨M§xÃøªº¨t²Î°ÝÃD¡C Y±z¬O &os; ·s¤â¡A
¨º»ò½Ð¦b¦w¸Ë«e³Ì¦n¥ý¤T«ä¡C
¤°»ò¬O &os.current;¡H
snapshot
&os.current; ¬O &os; ªº³Ì·sª©¡C¥¦¥]§t¡G
¤´¦b¬ãµo¶¥¬q¡B¹êÅç©Ê½èªº×§ï¡B¹L´ç®É´Áªº¾÷¨î¡A
³o¨ÇªF¦è¦b¤U¤@¦¸¥¿¦¡ relase ªºª©¥»¥i¯à·|¦³¡A¤]¥i¯à¤£·|¦³ªº¡C
¾¨ºÞ¦³³\¦h &os; ¶}µoªÌ¨C¤Ñ³£·|½sĶ &os.current; source code¡A
¦ý¦³®É³o¨Çì©l½X¬OµLªk½sͦ¨¥\¡C ÁöµM¡A³o¨Ç°ÝÃD³q±`·|¾¨§Ö¸Ñ¨M¡A
¦ý &os.current; ¨ì©³¬O±a¨Ó¯E§T©Î¬O¦h¤F·Qn¥Îªº·s¥\¯à¡B§ïµ½¡A
³oÂI¥Dn¨ú¨M©ó±z§ó·sì©l½Xªº®É¾÷¬°¦ó¦Ó©w¡I
½Ö»Ýn &os.current;¡H
&os.current; ¾A¦X¤U¦C³o¤TÃþ¤H¡G
&os; ªÀ¸s¦¨û¡G¿n·¥±Mª`©ó source tree ªº¬Y¤@³¡¥÷¡A
¥H¤Î»{¬°«O«ù¬° current(³Ì·sª¬ºA)
¬°µ´¹ï»Ý¨Dªº¤H¡C
&os; ªÀ¸s¦¨û¡G¬°¤F½T«O &os.current;
¯à°÷¾¨¥i¯à¦aºû«ù¦b³Ìéwªºª¬ºA¡A
¦Ó¥D°Êªá®É¶¡¸Ñ¨M°ÝÃDªº´ú¸ÕªÌ¡C ¦¹¥~¡AÁÙ¦³¹ï &os;
¯à´£¥X¨ãÅ髨ij¥H¤Î§ïµ½¤è¦V¡A¨Ã´£¥X patch ×¥¿Àɪº¤H¡C
¥u¬OÃö¤ß©ÎªÌ·Q°Ñ¦Ò(¤ñ¦p¡A¥u¬O¾\Ū¡A
¦Ó«D°õ¦æ)ªº¤H¡C
³o¨Ç¤H¦³®É¤]·|°µ¨Çµù¸Ñ¡A©Î°^Ämì©l½X¡C
&os.current; ¨Ã¤£¬O ¤°»ò¡H
°l¨D³Ì·s¥\¯à¡C Å¥»¡¸Ì±¦³¨Ç«Ü»Åªº·s¥\¯à¡A
¨Ã§Æ±æ¦¨¬°±z©P³òªº¤H¤¤²Ä¤@Ó¹Á¸Õªº¤H¡A
¦]¦¹±N &os.current; µø¬°¨ú±o·mÂAª©ªº±¶®|¡C
¾¨ºÞ¡A±z¯à°÷¦]¦¹º¥ýÁA¸Ñ¨ì³Ì·sªº¥\¯à¡A
¦ý³o¤]·N¨ýµÛY¥X²{·sªº bug ®É¡A±z¤]¬Oº·í¨ä½Ä¡C
×´_ bug ªº³t¦¨ªk¡C ¦]¬° &os.current;
ªº¥ô¦óª©¥»¦b×´_¤wª¾ bug ªº¦P®É¡A¤S¥i¯à·|²£¥Í·sªº bug¡C
µL©Ò¤£¦bªº officially supported
¡C
§ÚÌ·|ºÉ¤O¨ó§U¤Wz &os.current; ªº¨º¤TºØÃþ§Oªº
legitimate
¨Ï¥ÎªÌ¡A
¦ý§Ų́S®É¶¡¬°¥LÌ´£¨Ñ§Þ³N¤ä´©¡C
³o¤£¥Nªí§Ú̫ܴc¦H¡A©Î¬O¤£·QÀ°§U¤H(Y¬Oªº¸Ü¡A
§Ṳ́]¤£·|¬° &os; §V¤O¤F)
¡A¹ê¦b¬O¦]¬°§Ṳ́À¨¥F³N¡AµLªk¨C¤Ñ¦^µª¼Æ¦ÊÓ°ÝÃD¡A
¦Ó¦P®ÉÄ~Äò¶}µo &os;¡C
¥i¥H½T©wªº¤@ÂI´N¬O¡A
¦b§ïµ½ &os; ©Î¬O¦^µª¤j¶q¦³Ãö¹êÅç½Xªº°ÝÃD¤§¶¡¡A
Yn°µÓ¿ï¾Üªº¸Ü¡A¶}µoªÌ·|¿ï¾Ü«eªÌ¡C
¨Ï¥Î &os.current;
-
- -CURRENT
- using
-
- ¥[¤J &a.current.name; ¤Î &a.cvsall.name; ½×¾Â¡C
+ ¥[¤J &a.current.name;-CURRENTusing ¤Î &a.cvsall.name; ½×¾Â¡C
³o¤£³æ¥u¬OÓ«ØÄ³¡A¤]¬O ¥²¶· §@ªº¡C
Y±z¨Sq¾\ &a.current.name;
¡A¨º»ò´N·|¿ù¹L§O¤H¹ï¥Ø«e¨t²Îª¬ºAªº»¡©ú¡A¦Ó¬\¯Ó¦b§O¤H¤w¸Ñªº°ÝÃD¡C
§ó«nªº¬O¡A¥i¯à·|¿ù¥¢¤@¨Ç¹ï¤v¨©ÒºÞ¨t²Î¦w¦M¬Û·í«nªº¤½§i¡C
¦b &a.cvsall.name; ¤W«h¥i¥H¬Ý¨ì¨CÓ commit ¬ö¿ý¡A
¦]¬°³o¨Ç°O¿ý·|³s±a¼vÅT¨ä¥L¬ÛÃö¸ê°T¡C
nq¾\³o¨Ç½×¾Â©Î¨ä¥L½×¾Â¡A½Ð°Ñ¦Ò &a.mailman.lists.link;
¨ÃÂI¿ï·Qq¾\ªº³¡¤À§Y¥i¡C ¦Ü©ó¨ä¥L«áÄò¨BÆJ¦p¦ó¶i¦æ¡A
¦b¨º¸Ì·|¦³»¡©ú¡C
±q &os; mirror ¯¸
¨ú±oì©l½X¡C ¦³¨âºØ¤è¦¡¥i¥H¹F¦¨¡G
-
- cvsup
-
-
- cron
-
-
- -CURRENT
- Syncing with CVSup
-
-
- ¥H csup ©Î
+ ¥H csupcvsup ©Î
cvsup µ{¦¡·f°t¦ì©ó
/usr/share/examples/cvsup ÀɦW¬°
standard-supfile ªº
supfile¡C
³o¬O¤j®a³Ì±`±ÀÂ˪º¤è¦¡¡A¦]¬°¥¦¥i¥HÅý±z§â¾ãÓ tree ³£§ì¦^¨Ó¡A
¤§«á´N¥u¨ú¦³§ó·sªº³¡¤À§Y¥i¡C
¦¹¥~¡A³\¦h¤H·|§â csup ©Î
cvsup ©ñ¨ì
- cron ¥H©w´Á¦Û°Ê§ó·s¡C
+ croncron ¥H©w´Á¦Û°Ê§ó·s¡C
±z¶·n¦Ûq«ezªº supfile ½d¨ÒÀÉ¡A
¨Ã°w¹ï¦Û¨ºô¸ôÀô¹Ò¥H½Õ¾ã csup
- ©Î cvsup ¬ÛÃö³]©w¡C
+ ©Î cvsup-CURRENTSyncing with CVSup ¬ÛÃö³]©w¡C
-
- -CURRENT
- Syncing with CTM
-
-
¨Ï¥Î CTM ¤u¨ã¡C Yºô¸ôÀô¹Ò¤£¨Î
+ linkend="ctm">CTM-CURRENTSyncing with CTM ¤u¨ã¡C Yºô¸ôÀô¹Ò¤£¨Î
(¤Wºô¶O¥Î¶Q¡A©Î¥u¯à¥Î email ¦Ó¤w)
CTM ·|¤ñ¸û¾A¦X±zªº»Ý¨D¡C
µM¦Ó¡A³o¤]¦³¤@¨Çª§Ä³¨Ã¥B±`§ì¨ì¤@¨Ç¦³°ÝÃDªºÀɮסC ¦]¦¹¡A
«Ü¤Ö¤H·|¥Î¥¦¡C ³o¤]µù©w¤F¤£¯àªø´Á¨Ì¿à³oÓ§ó·s¤è¦¡¡C
Y¬O¨Ï¥Î 9600 bps modem ©ÎÀW¼e§ó¤jªº¤WºôªÌ¡A«ØÄ³¨Ï¥Î
CVSup
¡C
Y§ì source code ¬On¥Î¨Ó¶]ªº¡A¦Ó¤£¶È¥u¬O¬Ý¬Ý¦Ó¤w¡A
¨º»ò´N§ì ¾ãÓ &os.current;¡A¦Ó¤£n¥u§ì³¡¤À¡C
¦]¬°¤j³¡¤Àªº source code ³£·|¬Û¨Ì¨ì¨ä¥L source code Àô¸`³¡¤À¡A
Y¬O±z¥u½s͍䤤¤@³¡¥÷¡A«OÃÒ·|«Ü³Â·Ð¡C
-
- -CURRENT
- compiling
-
- ¦b½sĶ &os.current; ¤§«e¡A½Ð¥J²Ó¾\Ū
+ ¦b½sĶ &os.current;-CURRENTcompiling ¤§«e¡A½Ð¥J²Ó¾\Ū
/usr/src ¤ºªº Makefile¡C
¾¨ºÞ¥u¬O¤É¯Å³¡¤ÀªF¦è¦Ó¤w¡A±z¦Ü¤Ö¤]n¥ý
¸Ë·sªº kernel ¥H¤Î«·s½sĶ world¡C ¦¹¥~¡A¦h¦h¾\Ū
&a.current; ¥H¤Î /usr/src/UPDATING
¤]¬O¥²¶·ªº¡A
¤~¯àª¾¹D¥Ø«e¶i«×¬O«ç¼Ë¥H¤Î¤U¤@ª©·|¦³¤°»ò·sªF¦è¡C
¼ö¦å¡IY±z¥¿¦b¶] &os.current;¡A
§Ú̫ܷQª¾¹D±z¹ï©ó¥¦ªº·Qªk¬O¤°»ò¡A¤×¨ä¬O¥[±jþ¨Ç¥\¯à¡A
©Î¸Ó×¥¿þ¨Ç¿ù»~ªº«ØÄ³¡C ¦pªG±z¦b«ØÄ³®É¯àªþ¤W¬ÛÃöµ{¦¡½Xªº¸Ü¡A
¨º¯u¬O¤Ó´Î¤F¡I
¨Ï¥Î³Ì·sªº &os; STABLE
¤°»ò¬O &os.stable;¡H
-STABLE
&os.stable; ¬O§Ú̪º¶}µo¤À¤ä¡A¥Dnªºµo¦æª©´N¥Ñ¦¹¦Ó¨Ó¡C
³oÓ¤À¤ä·|¥H¤£¦P³t«×§@×§ïÅܤơA¨Ã¥B°²³]³o¨Ç¬O²Ä¤@¦¸¶i¤J &os.current;
¶i¦æ´ú¸Õ¡C µM¦Ó¡A³o ¤´µM ÄÝ©ó¶}µo¤¤ªº¤À¤ä¡A
¤]´N¬O»¡¦b¬Y¨Ç®ÉÔ¡A&os.stable; ¥i¯à·|¡B¤]¥i¯à¤£·|²Å¦X¤@¨Ç¯S®í»Ý¨D¡C
¥¦¥u¤£¹L¬O¥t¤@Ó¶}µo¤À¤ä¦Ó¤w¡A¥i¯à¤£¤Ó¾A¦X¤@¯ë¨Ï¥ÎªÌ¡C
½Ö»Ýn &os.stable;¡H
Y±z¦³¿³½ì¥h°lÂÜ¡B°^Äm FreeBSD ¶}µo¹Lµ{©Î§@¨Ç°^Äm¡A
¤×¨ä¬O·|¸ò FreeBSD ±µ¤U¨Óªº ÃöÁä©Ê
µo¦æ¦³Ãö¡A
À³¸Ó¦Ò¼{±Ä¥Î &os.stable;¡C
ÁöµM¦w¥þº|¬}ªº×¸É¤]·|¶i¤J &os.stable; ¤À¤ä¡A
¦ý¤£¥²¶È¶È¦]¦¹¦Ó »Ýn ¥h¥Î &os.stable;¡C
FreeBSD ¨C¶µ security advisory(¦w¥þ¤½§i)
³£·|¸Ñ»¡¦p¦ó¥h×´_¦³¨ü¨ì¼vÅTªºª©¥»
µM¦Ó¡A³o¤]¤£¤@©w¬O¥¿½T¡A§Ṳ́£¥i¯à¥Ã»·¤ä´© FreeBSD
©õ¤éªº¦UºØµo¦æª©¥»¡A¾¨ºÞ¨CÓµo¦æª©µo§G¤§«á¡A³£¤´·|«ùÄò¤ä´©¼Æ¦~¤§¤[¡C
Y±ýÁA¸Ñ FreeBSD ¥Ø«e¹ï©óª©ªº¤ä´©¬Fµ¦²Ó¸`¡A½Ð°Ñ¾\ http://www.FreeBSD.org/security/
¡C
¡AY¶È¦]¬°¦w¥þ¦]¯À¦Ó¥h±Ä¥Î¶}µo¤À¤ä¡AÁöµM·|¸Ñ¨M²{¦³¤wª¾°ÝÃD¡A
¦ý¤]¥i¯à±a¨Ó¤@¨Ç¼çÂ꺰ÝÃD¡C
¾¨ºÞ§Ú̺ɤO½T«O &os.stable; ¤À¤ä¦b¥ô¦ó®ÉÔ§¡¯à¥¿½T½sĶ¡B¹B§@¡A
¦ý¨S¤H¯à°÷¾á«O¥¦ÀH®É³£¥i¥H²Å¦X¤Wz¥Øªº¡C ¦¹¥~¡AÁöµMì©l½X¦b¶i¤J
&os.stable; ¤§«e¡A³£·|¥ý¦b &os.current; ¶}µo§¹²¦¡A¦ý¨Ï¥Î &os.current;
ªº¤H²¦³º»·¤ñ &os.stable; ¨Ï¥ÎªÌ¨Óªº¤Ö¡A©Ò¥H³q±`¦³¨Ç°ÝÃD¡A¥i¯à¦b
&os.current; ¤ñ¸û¨S¤Hª`·N¨ì¡AÀHµÛ &os.stable;
¨Ï¥ÎªÌªº¼sªx¨Ï¥Î¤~·|¯B²{¡C
¥Ñ©ó¤Wz³o¨Ç²z¥Ñ¡A§Ų́䣱ÀÂË ª¼¥Ø°lÀH
&os.stable;¡A¦Ó¥B§ó«nªº¬O¡A§O¦bì©l½X©|¥¼¸g§¹¾ã´ú¸Õ¤§«e¡A
´N½Ä°Ê§â production server Âಾ¨ì &os.stable; Àô¹Ò¡C
Y±z¨S¦³³o¨Ç¦hªº®É¶¡¡Bºë¯«ªº¸Ü¡A¨º±ÀÂ˱z¨Ï¥Î³Ì·sªº FreeBSD
µo¦æª©§Y¥i¡A¨Ã±Ä¥Î¨ä©Ò´£¨Ñªº binary §ó·s¾÷¨î¨Ó§¹¦¨¤É¯ÅÂಾ¡C
¨Ï¥Î &os.stable;
-
- -STABLE
- using
-
-
- q¾\ &a.stable.name; list¡C ¥i¥HÅý±zÀH®ÉÁA¸Ñ &os.stable;
+ q¾\ &a.stable.name;-STABLEusing list¡C ¥i¥HÅý±zÀH®ÉÁA¸Ñ &os.stable;
ªº³nÅé½sĶ®Éªº¬Û¨ÌÃö«Y¡A¥H¤Î¨ä¥L»Ý¯S§Oª`·Nªº°ÝÃD¡C
¶}µoªÌ¦b¦Ò¼{¤@¨Ç¦³ª§Ä³ªº×¥¿©Î§ó·s®É¡A´N·|¥ý¦b³o¸Ìµo«H»¡©ú¡A
µ¹¨Ï¥ÎªÌ¦³¾÷·|¥i¥H¤ÏÀ³¡A
¬Ý¥L̹ï©Ò´£ªº§ó§ï¬O§_¦³¤°»ò«ØÄ³©Î°ÝÃD¡C
¦Ó &a.cvsall.name; list ³oÃä¥i¥H¬Ý¨ì¨CÓ commit log¡A
¨ä¤¤¥]¬A¤F³\¦h¤¤ªÖªº¸ê°T¡A¨Ò¦p¤@¨Ç¥i¯àµo¥ÍªºÃä»Ú®ÄÀ³µ¥µ¥¡C
·Qn¥[¤J³o¨Ç³q«H½×¾Âªº¸Ü¡A¥un¨ì &a.mailman.lists.link;
ÂI¤U·Qq¾\ªº list §Y¥i¡C ¨ä¾lªº¨BÆJ¦bºô¶¤W·|¦³»¡©ú¡C
Y¥´ºân¦w¸Ë¤@Ó¥þ·sªº¨t²Î¡A¨Ã¥B§Æ±æ¸Ë &os.stable;
¨C¤ë©w´Áªº snapshot¡A¨º»ò½Ð°Ñ¾\ Snapshots ºô¶¥HÁA¸Ñ¬ÛÃö²Ó¸`¡C
¦¹¥~¡A¤]¥i±q mirror ¯¸
¨Ó¦w¸Ë³Ì·sªº &os.stable; µo¦æª©¡A¨Ã³z¹L¤U¦Cªºªº»¡©ú¨Ó§ó·s¨ì³Ì·sªº
&os.stable; ì©l½X¡C
Y¤w¸Ëªº¬O &os; ¥H«eªºª©¥»¡A¦Ó·Q³z¹Lì©l½X¤è¦¡¨Ó¤É¯Å¡A
¨º»ò¤]¬O¥i¥H§Q¥Î &os; mirror ¯¸
¨Ó§¹¦¨¡C ¥H¤U¤¶²Ð¨âºØ¤è¦¡¡G
-
- cvsup
-
-
- cron
-
-
- -STABLE
- syncing with CVSup
-
- ¥H csup ©Î
+ ¥H csupcvsup ©Î
cvsup µ{¦¡·f°t¦ì©ó
/usr/share/examples/cvsup ÀɦW¬°
stable-supfile ªº
supfile¡C ³o¬O¤j®a³Ì±`±ÀÂ˪º¤è¦¡¡A
¦]¬°¥¦¥i¥HÅý§A§â¾ãÓ tree ³£§ì¦^¨Ó¡A
¤§«á´N¥u¨ú¦³§ó·sªº³¡¤À§Y¥i¡C
¦¹¥~¡A³\¦h¤H·|§â csup ©Î
- cvsup ©ñ¨ì cron
+ cvsup ©ñ¨ì croncron
¥H©w´Á¦Û°Ê§ó·s¡C ±z¶·n¦Ûq«ezªº
supfile ½d¨ÒÀÉ¡A¨Ã°w¹ï¦Û¨ºô¸ôÀô¹Ò¥H½Õ¾ã
csup ©Î
- cvsup ¬ÛÃö³]©w¡C
+ cvsup-STABLEsyncing with CVSup ¬ÛÃö³]©w¡C
-
- -STABLE
- syncing with CTM
-
-
¨Ï¥Î CTM §ó·s¤u¨ã¡C
+ linkend="ctm">CTM-STABLEsyncing with CTM §ó·s¤u¨ã¡C
Yºô¸ô¤£§Ö©Îºô¸ô¶O¥Î¶Q¡A¨º»ò¥i¥H¦Ò¼{±Ä¥Î¡C
¤@¯ë¦Ó¨¥¡AY±`»Ý¦s¨ú³Ì·sì©l½X¡A¦Ó¤£p¸ûºô¸ôÀW¼eªº¸Ü¡A
¥i¥H¨Ï¥Î csup ©Î cvsup
©Î ftp¡C §_«h¡A´N¦Ò¼{
CTM¡C
-
- -STABLE
- compiling
-
-
- ¦b½sĶ &os.stable; ¤§«e¡A½Ð¥ý¥J²Ó¾\Ū
+ ¦b½sĶ &os.stable;-STABLEcompiling ¤§«e¡A½Ð¥ý¥J²Ó¾\Ū
/usr/src ¤ºªº Makefile
ÀÉ¡C ¾¨ºÞ¥u¬O¤É¯Å³¡¤ÀªF¦è¦Ó¤w¡A±z¦Ü¤Ö¤]n¥ý ¸Ë·sªº kernel ¥H¤Î«·s½sĶ world¡C
¦¹¥~¡A¦h¦h¾\Ū &a.stable; ¥H¤Î
/usr/src/UPDATING ¤]¬O¥²³Æªº¡A
³o¼Ë¤~¯àª¾¹D¥Ø«e¶i«×¬O«ç¼Ë¡A¥H¤Î¤U¤@ª©·|¦³þ¨Ç·sªF¦è¡C
§ó·s§Aªº Source
&os; p¹ºì©l½X¦³³\¦h³z¹Lºô¸ô(©Î email)ªº¤è¦¡¨Ó§ó·s¡A
µL½×¬O§ó·s¨º¤@¶ô»â°ì¡A³o¨Ç¥þ¥Ñ±z¦Û¦æ¨M©w¡C §ÚÌ¥Dn´£¨Ñªº¬O Anonymous CVS¡BCVSup
¡BCTM¡C
ÁöµM¥i¥H¥u§ó·s³¡¤Àì©l½X¡A¦ý°ß¤@¤ä´©ªº§ó·s¬yµ{¬O§ó·s¾ãÓ tree¡A
¨Ã¥B«½s userland(¤ñ¦p¡G¥Ñ¨Ï¥ÎªÌ¥h°õ¦æªº©Ò¦³µ{¦¡¡A¹³¬O
/bin¡B/sbin ¤ºªºµ{¦¡)¥H¤Î
kernel ì©l½X¡C
Y¥u§ó·s³¡¤Àªº source tree¡B©Î¥u¦³ kernel ³¡¤À¡B©Î¥u¦³ userland
³¡¤À¡A³q±`·|³y¦¨¤@¨Ç¿ù»~¡A¹³¬O¡G½sĶ¿ù»~¡Bkernel panic¡B¸ê®Æ·´·lµ¥
¡C
CVS
anonymous
Anonymous CVS ¤Î
CVSup §¡¬O±Ä pull
¼Ò¦¡¨Ó§ó·sì©l½X¡C ¥H CVSup ¬°¨Ò¡A
¨Ï¥ÎªÌ(©Î cron script)·|°õ¦æ cvsup
µ{¦¡¡A«áªÌ·|»P¬Y¤@¥x cvsupd ¦øªA¾¹§@¨Ç¤¬°Ê¡A
¥H§ó·s¬ÛÃöì©l½XÀɮסC ±z©Ò¦¬¨ì§ó·s·|¬O·í®É³Ì·sªº¡A
¦Ó¥B¥u·|¦¬¨ì»Ý§ó·sªº³¡¤À¡C ¦¹¥~¡A¤]¥i¥H«Ü»´ÃP¥h³]©wn§ó·sªº½d³ò¡C
§ó·s·|¥Ñ¦øªA¾¹¸ò¥»¾÷¤ñ¹ï¤§«á¡A¥á¥X·í®É±z©Ò»Ýnªº§ó·sÀÉ®×µ¹§A¡C
Anonymous CVS ªº·§©À¬Û¹ï©ó
CVSup ¨Ó±o§ó²³æ¨Ç¡A¦]¬°¥¦¥u¬O
CVS ªº©µ¦ù¦Ó¤w¡A¤@¼ËÅý§A¥i±q»·ºÝªº
CVS repository ¨ú¥X³Ì·sì©l½X¡C µM¦Ó CVSup
¦b³o¤è±·|§ó¦³®Ä²v¡A¤£¹L Anonymous CVS
¹ï·s¤â¦Ó¨¥¡A¬O¥Î°_¨Ó¤ñ¸û²³æ¡C
CTM
¥t¤@ºØ¤è¦¡«h¬O CTM¡C
¥¦¨Ã¤£¬O¥H¥æ½Í¦¡¤¶±¨Ó¤ñ¹ï±z©Ò¾Ö¦³ªº sources ©M¦øªA¾¹¤Wªº sources
©Î¬O±z¨ú±oªº§ó·s³¡¥÷¡C ¬Û¤Ïªº¡A·|¦³¤@Ó script
ÀɱMªù¥Î¨Ó¿ëÃÑÅܧó¹LªºÀɮסA³oÓµ{¦¡¬O¥Ñ CTM ¦øªA¾¹¨Ó°õ¦æ¡A
¨C¤Ñ·|¤ñ¹ï¼Æ¦¸¡A¨Ã§â¨â¦¸°õ¦æ´Á¶¡¤ºÅܧó¹LªºÀÉ®×¥[¥HÀ£ÁY¡A
¨Ãµ¹¥¦Ì¤@ӧǸ¹¡AµM«á´N¥[¥H½s½X(¥u¥Î printable ASCII ¦r¤¸)¡A
¨Ã¥H email ªº¤è¦¡±H¥X¡C ·í±z¦¬¨ì¥¦ªº®ÉÔ¡A³o¨Ç CTM deltas
´N¥i¥H¥Ñ &man.ctm.rmail.1; µ{¦¡¨Ó³B²z¡A¸Óµ{¦¡·|¦Û°Ê¸Ñ½X¡B½T»{¡B
®M¥Î³o¨ÇÅܧó¡C ³oµ{§Ç¤ñ CVSup ¨Ó»¡¬O§Ö±o¦h¤F¡A
¦Ó¥B¡A³oÓ¼Ò¦¡¹ï§Ú̪º¦øªA¾¹¨Ó»¡¬O¤ñ¸û»´ÃPªº¡A¦]¬°³o¬O¤@Ó
push ªº¼Ò¦¡¡A¦Ó«D pull
ªº¼Ò¦¡¡C
·íµM¡A³o¼Ë°µ¤]·|±a¨Ó¤@¨Ç¤£«K¡C Y¤£¤p¤ß§â±z³¡¥÷ªºµ{¦¡²M°£±¼¤F¡A
CVSup ·|°»´ú¥X¨Ó¡A¨Ã¦Û°Ê¬°±z§â¤£¨¬ªº³¡¥÷¸É»ô¡C
CTM ¨Ã¤£·|¬°±z°µ³o¨Ç°Ê§@¡C
Y²M±¼¤F±zªº³¡¥÷ source (¦Ó¥B¨S³Æ¥÷)¡A±z¥i¥H±qÀY¶}©l(±q³Ì·sªº CVS
base delta
)¨Ã¥Î CTM ¨Ó««Ø¥¦Ì
¡A©Î¬O¥Î Anonymous CVS ¨Ó§¹¦¨¡A
¥un§â¤£¥¿½Tªº¦a¤è¬å±¼¡A¦A«·s°µ¦P¨Bªº°Ê§@§Y¥i¡C
«·s½sĶ world
Rebuilding world
¦b§ó·s &os; ªº source tree ¨ì³Ì·s¤§«á(µL½×¬O &os.stable;¡B
&os.current; µ¥µ¥)¡A±µ¤U¨Ó´N¥i¥H¥Î³o¨Ç source tree ¨Ó«·s½s͍t²Î
¡C
°µ¦n³Æ¥÷
¦b§@¥ô¦ó¤j°Ê§@ ¤§«e
n°O±o¥ý§â¨t²Î§@³Æ¥÷ªº«n©ÊµL¶·±j½Õ¡C ¾¨ºÞ«·s½sĶ world ¬O
(¥un¦³·Ó¤å¥ó«ü¥Ü¥h§@ªº¸Ü)¤@¥ó«Ü²³æªº¨Æ±¡¡A¦ý¥X¿ù¤]¬O¦b©ÒÃø§Kªº¡C
¥t¥~¡A§O¤H¦b source tree ¤£·V·d²Vªº¿ù»~¡A¤]¥i¯à·|³y¦¨¨t²ÎµLªk¶}¾÷
¡C
½Ð½T»{¦Û¤v¤w§@§´¬ÛÃö³Æ¥÷¡A¨Ã¥B¤âÃ䦳 fixit ºÏ¤ù©Î¶}¾÷¥úºÐ¡C
±z¥i¯à¥Ã»·¤]¥Î¤£¨ì³o¨ÇªF¦è¡A
¦ý¦w¥þ²Ä¤@Á`¤ñ¨Æ«á»¡©êºp¨Ó±o¦n§a¡I
q¾\¬ÛÃöªº Mailing List
mailing list
&os.stable; ¥H¤Î &os.current; ¤À¤ä¡A¥»½è¤W´N¬OÄÝ©ó
¶}µo¶¥¬q¡C ¬° &os; §@°^Ämªº¤]³£¬O¤H¡A°¸º¸¤]·|¥Ç¿ù»~¡C
¦³®ÉÔ³o¨Ç¿ù»~¨ÃµL¤jê¡A¥u¬O·|Åý¨t²Î²£¥Í·sªº¿ù»~ĵ§i¦Ó¤w¡C
¦³®É«h¬O¨aÃø¡A¥i¯à·|¾ÉP¤£¯à¶}¾÷©ÎÀɮרt²Îªº·´·l(©Î§óÁV)¡C
Y¹J¨ìÃþ¦ü°ÝÃD¡A¶K«Ê¼ÐÃD¬° heads up(ª`·N)
¶}ÀYªº«H¨ì¬ÛÃöªº mailing list¡A¨ÃÁ¿²M·¡°ÝÃDÂI¥H¤Î·|¼vÅTþ¨Ç¨t²Î¡C
¦b°ÝÃDÀò¸Ñ¨M«á¡A¦A¶K¼ÐÃD¬° all clear(¤w¸Ñ¨M)
¶}ÀYªºÁn©ú«H¡C
Y¥Îªº¬O &os.stable; ©Î &os.current;¡A«o¤S¤£¾\Ū &a.stable; ©Î
&a.current; ªº°Q½×¡A¨º»ò·|¬O¦Û§ä³Â·Ð¦Ó¤w¡C
¤£n¥Î make world
¤@°ï¦´ÁªºÂ¤å¥ó³£·|«ØÄ³»¡¨Ï¥Î make world¡C
³o¼Ë°µ·|¸õ¹L¤@¨Ç«n¨BÆJ¡A«ØÄ³¥u¦³¦b§Aª¾¹D¦Û¤v¦b§@¤°»ò¡A¦A³o»ò°µ¡C
¦bµ´¤j¦h¼Æªº±¡ªp¤U¡A½Ð¤£n¶Ã¥Î make world¡A
¦Ó¸Ó§ï¥Î¤U±¤¶²Ðªº¤è¦¡¡C
§ó·s¨t²Îªº¼Ð·Ç¤è¦¡
n¤É¯Å¨t²Î«e¡A¤@©wn¥ý¬d¾\ /usr/src/UPDATING
¤å¥ó¡A¥HÁA¸Ñ buildworld ¤§«e»Ýn§@þ¨Ç¨Æ±¡©Îª`·N¨Æ¶µ¡A
µM«á¤~¥Î¤U¦C¨BÆJ¡G
&prompt.root; make buildworld
&prompt.root; make buildkernel
&prompt.root; make installkernel
&prompt.root; reboot
¦b¤Ö¼Æª¬ªp¡A¥i¯à»Ýn¥ý¦b buildworld
¨BÆJ¤§«e¥ý§@ mergemaster -p ¤~¯à§¹¦¨¡C
¦Ü©ó¦ó®É»Ýn©Î¤£»Ýn¡A½Ð°Ñ¾\ UPDATING ¤ºªº»¡©ú¡C
¤@¯ë¨Ó»¡¡A¥un¤£¬O¶i¦æ¸óª©¸¹(major)ªº &os; ª©¥»¤É¯Å¡A
´N¥i²¤¹L³o¨BÆJ¡C
§¹¦¨ installkernel ¤§«á¡A»Ýn«¶}¾÷¨Ã¤Á¨ì
single user ¼Ò¦¡(Á|¨Ò¡G¤]¥i¥H¦b loader ´£¥Ü²Å¸¹«á±¥[¤W
boot -s)¡C ±µ¤U¨Ó°õ¦æ¡G
&prompt.root; mergemaster -p
&prompt.root; make installworld
&prompt.root; mergemaster
&prompt.root; reboot
Read Further Explanations
¤Wz¨BÆJ¥u¬O¨ó§U±z¤É¯ÅªºÂ²³æ»¡©ú¦Ó¤w¡AYn²M·¡ÁA¸Ñ¨C¤@¨BÆJ¡A
¤×¨ä¬OY±ý¦Û¦æ¥´³y kernel ³]©w¡A´N§ó¸Ó¾\Ū¤U±ªº¤º®e¡C
¾\Ū /usr/src/UPDATING
¦b§@¥ô¦ó¨Æ±¡¤§«e¡A½Ð°È¥²¥ý¾\Ū
/usr/src/UPDATING (©Î¦b source code ¤ºÃþ¦üªº¤å¥ó)
¡C ³o¥÷¤å¥ó·|¼g¨ì¥i¯à¾D¹Jªº°ÝÃD¡A©Î«ü©w¨º¨Ç·|°õ¦æªº«ü¥O¶¶§Ç¬°¦ó¡C
¦pªG§A¾÷¾¹²{¦bªº UPDATING
¤å¥ó»P³oÃ䪺´yz¦³½Ä¬ð¡B¥Ù¬Þ¤§³B¡A¨º»ò½Ð¥H¾÷¾¹¤Wªº
UPDATING ¬°·Ç¡C
µM¦Ó¡A¦p¦P¥ý«e©Òz¡A³æ³æ¥u¾a¾\Ū UPDATING
¨Ã¤£¯à§¹¥þ¨ú¥N mailing list¡C ³o¨âªÌ³£¬O¤¬¸Éªº¡A¦Ó¤£¬Û±Æ¥¸¡C
Àˬd /etc/make.conf
make.conf
Àˬd
/usr/share/examples/etc/make.conf
¥H¤Î
/etc/make.conf¡C ²Ä¤@¥÷¤å¥ó¤D¬O¤@¨Ç¨t²Î¹w³]È
– ¤£¹L¡A¤j³¡¤À³£³Qµù¸Ñ°_¨Ó¡C ¬°¤F¦b«·s½sͮɝà°÷¨Ï¥Î³o¨Ç¡A
½Ð§â³o¨Ç³]©w¥[¨ì /etc/make.conf¡C ½Ðª`·N¦b
/etc/make.conf ªº¥ô¦ó³]©w¤]·|¼vÅT¨ì¨C¦¸¨Ï¥Î
make ªºµ²ªG¡A
¦]¦¹³]©w¤@¨Ç¾A¦X¦Û¤v¨t²Îªº¿ï¶µ·|¬O¤£¿ùªº§@ªk¡C
¤@¯ë¨Ï¥ÎªÌ³q±`·|±q
/usr/share/examples/etc/make.conf ½Æ»s
CFLAGS ¥H¤Î NO_PROFILE
¤§Ãþªº³]©w¨ì /etc/make.conf¡A¨Ã¸Ñ°£¬ÛÃöµù¸Ñ¦L°O
¡C
¦¹¥~¡A¤]¥i¥H¸Õ¸Õ¬Ý¨ä¥L³]©w (COPTFLAGS¡B
NOPORTDOCS µ¥µ¥)¡A¬O§_²Å¦X¦Û¤v©Ò»Ý¡C
§ó·s /etc ¤ºªº³]©wÀÉ
¦b /etc ¥Ø¿ý·|¦³¨t²Îªº¬ÛÃö³]©wÀÉ¡A
¥H¤Î¶}¾÷®Éªº¦U¶µªA°È±Ò°Ê script¡C ¦³¨Ç script ÀH FreeBSD
ª©¥»ªº¤£¦P¦Ó¦³¨Ç®t²§¡C
¨ä¤¤¦³¨Ç³]©wÀÉ·|¦b¨C¤é¹B§@ªº¨t²Î¸Ì¤]·|¥Î¨ì¡C ¤×¨ä¬O
/etc/group¡C
¦³®ÉÔ¦b make installworld ¦w¸Ë¹Lµ{¤¤¡A
·|»Ýn¥ý«Ø¥ß¬Y¨Ç¯S©w±b¸¹©Î¸s²Õ¡C ¦b¶i¦æ¤É¯Å¤§«e¡A¥¦Ì¥i¯à¨Ã¤£¦s¦b¡A
¦]¦¹¤É¯Å®É´N·|³y¦¨°ÝÃD¡C ¦³®ÉÔ make buildworld
·|¥ýÀˬd³o¨Ç©Ò»Ýªº±b¸¹©Î¸s²Õ¬O§_¤w¦³¦s¦b¡C
Á|Ó³o¼Ëªº¨Ò¤l¡A¹³¬O¬Y¦¸¤É¯Å¤§«á¥²¶··s¼W smmsp
±b¸¹¡C Y¨Ï¥ÎªÌ©|¥¼·s¼W¸Ó±b¸¹´Nn§¹¦¨¤É¯Å¾Þ§@ªº¸Ü¡A
·|¦b &man.mtree.8; ¹Á¸Õ«Ø¥ß /var/spool/clientmqueue
®Éµo¥Í¥¢±Ñ¡C
¸Ñªk¬O¦b buildworld ¶¥¬q¤§«e¡A¥ý°õ¦æ &man.mergemaster.8; ¨Ã·f°t
¿ï¶µ¡C ¥¦·|¤ñ¹ï¨º¨Ç°õ¦æ
buildworld ©Î
installworld ©Ò»Ý¤§ÃöÁä³]©wÀÉ¡C
Y§A©Ò¥Îªº¬O¦´Á¤´¥¼¤ä´© ªº
mergemaster ª©¥»¡A¨º»òª½±µ¨Ï¥Î source tree
¤ºªº·sª©§Y¥i¡G
&prompt.root; cd /usr/src/usr.sbin/mergemaster
&prompt.root; ./mergemaster.sh -p
Y±z¬O°¾°õ¨g(paranoid)¡A
¥i¥H¹³¤U±³o¼Ë¥h¸ÕµÛÀˬd¨t²Î¤W¦³þ¨ÇÀÉ®×ÄÝ©ó¤w§ï¦W©Î³Q§R°£ªº¸s²Õ
¡G
&prompt.root; find / -group GID -print
³o·|Åã¥Ü©Ò¦³²Å¦Xn§äªº GID ¸s²Õ
(¥i¥H¬O¸s²Õ¦WºÙ¡A©ÎªÌ¬O¸s²Õªº¼Æ¦r¥N¸¹)ªº©Ò¦³ÀɮסC
¤Á´«¨ì Single User ¼Ò¦¡
single-user mode
±z¥i¯à·|·Q¦b single user ¼Ò¦¡¤U½s͍t²Î¡C
°£¤F¥i¥H©úÅã§ó§Ö§¹¦¨¤§¥~¡A¦w¸Ë¹Lµ{¤¤±N·|²o¯A³\¦h«nªº¨t²ÎÀɮסA
¥]¬A©Ò¦³¨t²Î binaries¡Blibraries¡Binclude ÀÉ®×µ¥¡C
Y¦b¹B§@¤¤ªº¨t²Î(¤×¨ä¦³³\¦h¨Ï¥ÎªÌ¦b¥Îªº®ÉÔ)¤º§ó§ï³o¨ÇÀɮסA
¨ºÂ²ª½¬O¦Û§ä³Â·Ðªº§@ªk¡C
multi-user mode
¥t¤@ºØ¼Ò¦¡¬O¥ý¦b multi-user ¼Ò¦¡¤U½sͦn¨t²Î¡AµM«á¦A¤Á¨ì single user
¼Ò¦¡¥h¦w¸Ë¡C Y±z¤ñ¸û³ßÅw³oºØ¤è¦¡¡A¥u»Ý¦b build(½s͹Lµ{) §¹¦¨¤§«á¡A
¦A¥h°õ¦æ¤U±ªº¨BÆJ§Y¥i¡C ¤@ª½¨ì¥i¤Á´« single user ¼Ò¦¡®É¡A¦A¥h°õ¦æ
installkernel ©Î
installworld §Y¥i¡C
¤Á´«¬° root ¨¥÷¥´¡G
&prompt.root; shutdown now
³o¼Ë´N·|±q쥻ªº multi-user ¼Ò¦¡¤Á´«¨ì single user ¼Ò¦¡¡C
°£¦¹¤§¥~¤]¥i¥H«¶}¾÷¡A±µµÛ¦b¶}¾÷¿ï³æ³B¿ï¾Ü
single user
¿ï¶µ¡C ¦p¦¹¤@¨Ó´N·|¶i¤J single user ¼Ò¦¡¡A
µM«á¦b shell ´£¥Ü²Å¸¹³B¿é¤J¡G
&prompt.root; fsck -p
&prompt.root; mount -u /
&prompt.root; mount -a -t ufs
&prompt.root; swapon -a
³o¼Ë·|¥ýÀˬdÀɮרt²Î¡A¨Ã«·s±N /
§ï¥H¥iŪ¼gªº¼Ò¦¡±¾¸ü¡A¥H¤Î /etc/fstab
¤º©Ò³]©wªº¨ä¥L UFS Àɮרt²Î¡A³Ì«á±Ò¥Î swap ºÏ°Ï¡C
Y CMOS ®ÉÄÁ¬O³]¬°·í¦a®É¶¡¡A¦Ó«D GMT ®É°Ï(Y &man.date.1;
«ü¥O¨SÅã¥Ü¥¿½Tªº®É¶¡¡B®É°Ï)¡A¨º¥i¯à»Ýn¦A¿é¤J¤U¦C«ü¥O¡G
&prompt.root; adjkerntz -i
³o¨BÆJ¥i¥H½T»{±zªº·í¦a®É°Ï³]©w¬O§_¥¿½T —
§_«h¤é«á·|³y¦¨¤@¨Ç°ÝÃD¡C
²¾°£ /usr/obj
¦b«·s½s͍t²Îªº¹Lµ{¤¤¡A½s͵²ªG·|©ñ¨ì(¹w³]±¡ªp)
/usr/obj ¤º¡C ³o¸Ì±ªº¥Ø¿ý·|¹ïÀ³¨ì
/usr/src ªº¥Ø¿ýµ²ºc¡C
¬å±¼³o¥Ø¿ý¡A¥i¥HÅý¥H«áªº make buildworld
¹Lµ{§ó§Ö¤@¨Ç¡A¦Ó¥B¥iÁ×§K¥H«e½sĶªºªF¦è¸ò²{¦bªº²V²c¦b¤@°_ªº¬Û¨Ì¿ù¶Ã
¡C
¦Ó¦³¨Ç /usr/obj ¤ºªºÀÉ®×¥i¯à·|³]©w¤£¥i§ó°Êªº
flag(²Ó¸`½Ð°Ñ¾\ &man.chflags.1;)¡A¦Ó¥²¶·¥ý®³±¼³o¨Ç flag ³]©w¤~¦æ
¡C
&prompt.root; cd /usr/obj
&prompt.root; chflags -R noschg *
&prompt.root; rm -rf *
«·s½sĶ Base System
«O¯d½sĶªº¬ö¿ý
«ØÄ³¾i¦¨¦n²ßºD¡A§â°õ¦æ &man.make.1; ®É²£¥Íªº¬ö¿ý¦s°_¨Ó¡C
³o¼ËY¦³þÃä¥X¿ù¡A´N·|¦³¿ù»~°T®§ªº¬ö¿ý¡C ÁöµM³æ³æ³o¼Ë¡A
§A¥i¯à¤£ª¾¹D¦p¦ó¤ÀªR¬OþÃä¥X¤F§Ã¡A¦ýY§â§A°ÝÃD°O¿ý¶K¨ì &os; ¬ÛÃöªº
mailing list ´N¥i¥H¦³¤H¥i¥HÀ°¦£¬Ý¬O«ç»ò¤@¦^¨Æ±¡¡C
³Ì²³æªº¤è¬O´N¬O¥Î &man.script.1; «ü¥O¡A¨Ã¥[¤W°Ñ¼Æ
(§A·Q¦s©ñ°O¿ýªºÀɮצì¸m¡BÀɦW)§Y¥i¡C
³o¨BÆJÀ³¸Ó¦b«·s½s͍t²Î®É´Nn§@¡AµM«á¦b§¹¦¨½sĶ«á¿é¤J
exit §Y¥iÂ÷¶}¡C
&prompt.root; script /var/tmp/mw.out
Script started, output file is /var/tmp/mw.out
&prompt.root; make TARGET
… compile, compile, compile …
&prompt.root; exit
Script done, …
¹ï¤F¡AÁÙ¦³¤@ÂI¾¨¶q§O§âÀɮצs¨ì
/tmp ¥Ø¿ý¤º¡C ¦]¬°«¶}¾÷¤§«á¡A
³o¥Ø¿ý¤ºªºªF¦è³£·|³Q²MªÅ¡C ¤ñ¸û§´µ½ªº¦a¤è¬O
/var/tmp (¦p¤W¨Ò©Ò¥Ü) ©ÎªÌ¬O
root ªº®a¥Ø¿ý¡C
½sĶ Base System
º¥ý½Ð¥ý¤Á´«¨ì /usr/src ¥Ø¿ý¡G
&prompt.root; cd /usr/src
(·íµM¡A°£«D§A§â source code ©ñ¨ì¨ä¥L¦a¤è¡AY¯u¬O³o¼Ë¡A
´N¤Á´«¨ì¨ºÓ¥Ø¿ý§Y¥i)¡C
make
¨Ï¥Î &man.make.1; «ü¥O¨Ó«·s½sĶ world¡C
³o«ü¥O·|±q Makefile ÀÉ(³oÀÉ·|¼g &os;
ªºµ{¦¡¸Ó¦p¦ó«·s½sĶ¡B¥Hþ¨Ç¶¶§Ç¨Ó½s͵¥µ¥)¥hŪ¨ú¬ÛÃö«ü¥O¡C
¤@¯ë¤U«ü¥Oªº®æ¦¡¦p¤U¡G
&prompt.root; make -x -DVARIABLE target
¦b³oÓ¨Ò¤l¡A
¬O§A·Q¶Çµ¹ &man.make.1; ªº¿ï¶µ¡A²Ó¸`»¡©ú½Ð°Ñ¾\ &man.make.1; »¡©ú¡A
¸Ì±¦³¬ÛÃö½d¨Ò»¡©ú¡C
«h¬O§âÅܼƳ]©w¶Çµ¹ Makefile¡C ³o¨ÇÅܼƷ|±±¨î
Makefile ªº¦æ¬°¡C ³o¨Ç³]©w»P
/etc/make.conf ªºÅܼƳ]©w¬O¤@¼Ë¡A
¥u¬O¥t¤@ºØ³]©w¤è¦¡¦Ó¤w¡C
&prompt.root; make -DNO_PROFILE target
¤W±ªº¨Ò¤l«h¬O¥t¤@ºØ³]©w¤è¦¡¡A¤]´N¬Oþ¨Ç¤£n¡C
³oÓ¨Ò¤l¤¤ªº·N«ä¬O¤£¥h½sĶ profiled libraries¡A®ÄªG´N¦p¦P³]©w¦b
/etc/make.conf ªº
NO_PROFILE= true # Avoid compiling profiled libraries
target «h¬O§i¶D &man.make.1;
¸Ó¥h°µþ¨Ç¡C ¨CÓ Makefile ³£·|©w¸q¤£¦Pªº
targets
¡AµM«á¨Ì±z©Òµ¹ªº target ´N·|¨M©w·|°µþ¨Ç°Ê§@
¡C
Some targets are listed in the
Makefile, but are not meant for you to run.
Instead, they are used by the build process to break out the
steps necessary to rebuild the system into a number of
sub-steps.
Most of the time you will not need to pass any parameters to
&man.make.1;, and so your command like will look like
this:
&prompt.root; make target
Where target will be one of
many build options. The first target should always be
buildworld.
As the names imply, buildworld
builds a complete new tree under /usr/obj,
and installworld, another target, installs this tree on
the current machine.
Having separate options is very useful for two reasons. First, it allows you
to do the build safe in the knowledge that no components of
your running system will be affected. The build is
self hosted
. Because of this, you can safely
run buildworld on a machine running
in multi-user mode with no fear of ill-effects. It is still
recommended that you run the
installworld part in single user
mode, though.
Secondly, it allows you to use NFS mounts to upgrade
multiple machines on your network. If you have three machines,
A, B and C that you want to upgrade, run make
buildworld and make installworld on
A. B and C should then NFS mount /usr/src
and /usr/obj from A, and you can then run
make installworld to install the results of
the build on B and C.
Although the world target still exists,
you are strongly encouraged not to use it.
Run
&prompt.root; make buildworld
It is possible to specify a option to
make which will cause it to spawn several
simultaneous processes. This is most useful on multi-CPU machines.
However, since much of the compiling process is IO bound rather
than CPU bound it is also useful on single CPU machines.
On a typical single-CPU machine you would run:
&prompt.root; make -j4 buildworld
&man.make.1; will then have up to 4 processes running at any one
time. Empirical evidence posted to the mailing lists shows this
generally gives the best performance benefit.
If you have a multi-CPU machine and you are using an SMP
configured kernel try values between 6 and 10 and see how they speed
things up.
Timings
rebuilding world
timings
Many factors influence the build time, but fairly recent
machines may only take a one or two hours to build
the &os.stable; tree, with no tricks or shortcuts used during the
process. A &os.current; tree will take somewhat longer.
Compile and Install a New Kernel
kernel
compiling
To take full advantage of your new system you should recompile the
kernel. This is practically a necessity, as certain memory structures
may have changed, and programs like &man.ps.1; and &man.top.1; will
fail to work until the kernel and source code versions are the
same.
The simplest, safest way to do this is to build and install a
kernel based on GENERIC. While
GENERIC may not have all the necessary devices
for your system, it should contain everything necessary to boot your
system back to single user mode. This is a good test that the new
system works properly. After booting from
GENERIC and verifying that your system works you
can then build a new kernel based on your normal kernel configuration
file.
On &os; it is important to build world before building a
new kernel.
If you want to build a custom kernel, and already have a configuration
file, just use KERNCONF=MYKERNEL
like this:
&prompt.root; cd /usr/src
&prompt.root; make buildkernel KERNCONF=MYKERNEL
&prompt.root; make installkernel KERNCONF=MYKERNEL
Note that if you have raised kern.securelevel
above 1 and you have set either the
noschg or similar flags to your kernel binary, you
might find it necessary to drop into single user mode to use
installkernel. Otherwise you should be able
to run both these commands from multi user mode without
problems. See &man.init.8; for details about
kern.securelevel and &man.chflags.1; for details
about the various file flags.
Reboot into Single User Mode
single-user mode
You should reboot into single user mode to test the new kernel
works. Do this by following the instructions in
.
Install the New System Binaries
If you were building a version of &os; recent enough to have
used make buildworld then you should now use
installworld to install the new system
binaries.
Run
&prompt.root; cd /usr/src
&prompt.root; make installworld
If you specified variables on the make
buildworld command line, you must specify the same
variables in the make installworld command
line. This does not necessarily hold true for other options;
for example, must never be used with
installworld.
For example, if you ran:
&prompt.root; make -DNO_PROFILE buildworld
you must install the results with:
&prompt.root; make -DNO_PROFILE installworld
otherwise it would try to install profiled libraries that
had not been built during the make buildworld
phase.
Update Files Not Updated by make installworld
Remaking the world will not update certain directories (in
particular, /etc, /var and
/usr) with new or changed configuration files.
The simplest way to update these files is to use
&man.mergemaster.8;, though it is possible to do it manually
if you would prefer to do that. Regardless of which way you
choose, be sure to make a backup of /etc in
case anything goes wrong.
Tom
Rhodes
Contributed by
mergemaster
mergemaster
The &man.mergemaster.8; utility is a Bourne script that will
aid you in determining the differences between your configuration files
in /etc, and the configuration files in
the source tree /usr/src/etc. This is
the recommended solution for keeping the system configuration files up to date
with those located in the source tree.
To begin simply type mergemaster at your prompt, and
watch it start going. mergemaster will then build a
temporary root environment, from / down, and populate
it with various system configuration files. Those files are then compared
to the ones currently installed in your system. At this point, files that
differ will be shown in &man.diff.1; format, with the sign
representing added or modified lines, and representing
lines that will be either removed completely, or replaced with a new line.
See the &man.diff.1; manual page for more information about the &man.diff.1;
syntax and how file differences are shown.
&man.mergemaster.8; will then show you each file that displays variances,
and at this point you will have the option of either deleting the new file (referred
to as the temporary file), installing the temporary file in its unmodified state,
merging the temporary file with the currently installed file, or viewing the
&man.diff.1; results again.
Choosing to delete the temporary file will tell &man.mergemaster.8; that we
wish to keep our current file unchanged, and to delete the new version.
This option is not recommended, unless you see no
reason to change the current file. You can get help at any time by
typing ? at the &man.mergemaster.8; prompt. If the user
chooses to skip a file, it will be presented again after all other files
have been dealt with.
Choosing to install the unmodified temporary file will replace the
current file with the new one. For most unmodified files, this is the best
option.
Choosing to merge the file will present you with a text editor,
and the contents of both files. You can now merge them by
reviewing both files side by side on the screen, and choosing parts from
both to create a finished product. When the files are compared side by side,
the l key will select the left contents and the
r key will select contents from your right.
The final output will be a file consisting of both parts, which can then be
installed. This option is customarily used for files where settings have been
modified by the user.
Choosing to view the &man.diff.1; results again will show you the file differences
just like &man.mergemaster.8; did before prompting you for an option.
After &man.mergemaster.8; is done with the system files you will be
prompted for other options. &man.mergemaster.8; may ask if you want to rebuild
the password file and will finish up with an option to
remove left-over temporary files.
Manual Update
If you wish to do the update manually, however,
you cannot just copy over the files from
/usr/src/etc to /etc and
have it work. Some of these files must be installed
first. This is because the /usr/src/etc
directory is not a copy of what your
/etc directory should look like. In addition,
there are files that should be in /etc that are
not in /usr/src/etc.
If you are using &man.mergemaster.8; (as recommended),
you can skip forward to the next
section.
The simplest way to do this by hand is to install the
files into a new directory, and then work through them looking
for differences.
Backup Your Existing /etc
Although, in theory, nothing is going to touch this directory
automatically, it is always better to be sure. So copy your
existing /etc directory somewhere safe.
Something like:
&prompt.root; cp -Rp /etc /etc.old
does a recursive copy,
preserves times, ownerships on files and suchlike.
You need to build a dummy set of directories to install the new
/etc and other files into.
/var/tmp/root is a reasonable choice, and
there are a number of subdirectories required under this as
well.
&prompt.root; mkdir /var/tmp/root
&prompt.root; cd /usr/src/etc
&prompt.root; make DESTDIR=/var/tmp/root distrib-dirs distribution
This will build the necessary directory structure and install the
files. A lot of the subdirectories that have been created under
/var/tmp/root are empty and should be deleted.
The simplest way to do this is to:
&prompt.root; cd /var/tmp/root
&prompt.root; find -d . -type d | xargs rmdir 2>/dev/null
This will remove all empty directories. (Standard error is
redirected to /dev/null to prevent the warnings
about the directories that are not empty.)
/var/tmp/root now contains all the files that
should be placed in appropriate locations below
/. You now have to go through each of these
files, determining how they differ with your existing files.
Note that some of the files that will have been installed in
/var/tmp/root have a leading .
. At the
time of writing the only files like this are shell startup files in
/var/tmp/root/ and
/var/tmp/root/root/, although there may be others
(depending on when you are reading this). Make sure you use
ls -a to catch them.
The simplest way to do this is to use &man.diff.1; to compare the
two files:
&prompt.root; diff /etc/shells /var/tmp/root/etc/shells
This will show you the differences between your
/etc/shells file and the new
/var/tmp/root/etc/shells file. Use these to decide whether to
merge in changes that you have made or whether to copy over your old
file.
Name the New Root Directory
(/var/tmp/root) with a Time Stamp, so You Can
Easily Compare Differences Between Versions
Frequently rebuilding the world means that you have to update
/etc frequently as well, which can be a bit of
a chore.
You can speed this process up by keeping a copy of the last set
of changed files that you merged into /etc.
The following procedure gives one idea of how to do this.
Make the world as normal. When you want to update
/etc and the other directories, give the
target directory a name based on the current date. If you were
doing this on the 14th of February 1998 you could do the
following:
&prompt.root; mkdir /var/tmp/root-19980214
&prompt.root; cd /usr/src/etc
&prompt.root; make DESTDIR=/var/tmp/root-19980214 \
distrib-dirs distribution
Merge in the changes from this directory as outlined
above.
Do not remove the
/var/tmp/root-19980214 directory when you
have finished.
When you have downloaded the latest version of the source
and remade it, follow step 1. This will give you a new
directory, which might be called
/var/tmp/root-19980221 (if you wait a week
between doing updates).
You can now see the differences that have been made in the
intervening week using &man.diff.1; to create a recursive diff
between the two directories:
&prompt.root; cd /var/tmp
&prompt.root; diff -r root-19980214 root-19980221
Typically, this will be a much smaller set of differences
than those between
/var/tmp/root-19980221/etc and
/etc. Because the set of differences is
smaller, it is easier to migrate those changes across into your
/etc directory.
You can now remove the older of the two
/var/tmp/root-* directories:
&prompt.root; rm -rf /var/tmp/root-19980214
Repeat this process every time you need to merge in changes
to /etc.
You can use &man.date.1; to automate the generation of the
directory names:
&prompt.root; mkdir /var/tmp/root-`date "+%Y%m%d"`
Rebooting
You are now done. After you have verified that everything appears
to be in the right place you can reboot the system. A simple
&man.shutdown.8; should do it:
&prompt.root; shutdown -r now
Finished
You should now have successfully upgraded your &os; system.
Congratulations.
If things went slightly wrong, it is easy to rebuild a particular
piece of the system. For example, if you accidentally deleted
/etc/magic as part of the upgrade or merge of
/etc, the &man.file.1; command will stop working.
In this case, the fix would be to run:
&prompt.root; cd /usr/src/usr.bin/file
&prompt.root; make all install
Questions
Do I need to re-make the world for every change?
There is no easy answer to this one, as it depends on the
nature of the change. For example, if you just ran CVSup, and
it has shown the following files as being updated:
src/games/cribbage/instr.c
src/games/sail/pl_main.c
src/release/sysinstall/config.c
src/release/sysinstall/media.c
src/share/mk/bsd.port.mk
it probably is not worth rebuilding the entire world.
You could just go to the appropriate sub-directories and
make all install, and that's about it. But
if something major changed, for example
src/lib/libc/stdlib then you should either
re-make the world, or at least those parts of it that are
statically linked (as well as anything else you might have added
that is statically linked).
At the end of the day, it is your call. You might be happy
re-making the world every fortnight say, and let changes
accumulate over that fortnight. Or you might want to re-make
just those things that have changed, and be confident you can
spot all the dependencies.
And, of course, this all depends on how often you want to
upgrade, and whether you are tracking &os.stable; or
&os.current;.
My compile failed with lots of signal 11
signal 11 (or other signal
number) errors. What has happened?
This is normally indicative of hardware problems.
(Re)making the world is an effective way to stress test your
hardware, and will frequently throw up memory problems. These
normally manifest themselves as the compiler mysteriously dying
on receipt of strange signals.
A sure indicator of this is if you can restart the make and
it dies at a different point in the process.
In this instance there is little you can do except start
swapping around the components in your machine to determine
which one is failing.
Can I remove /usr/obj when I have
finished?
The short answer is yes.
/usr/obj contains all the object files
that were produced during the compilation phase. Normally, one
of the first steps in the make buildworld process is to
remove this directory and start afresh. In this case, keeping
/usr/obj around after you have finished
makes little sense, and will free up a large chunk of disk space
(currently about 340 MB).
However, if you know what you are doing you can have
make buildworld skip this step. This will make subsequent
builds run much faster, since most of sources will not need to
be recompiled. The flip side of this is that subtle dependency
problems can creep in, causing your build to fail in odd ways.
This frequently generates noise on the &os; mailing lists,
when one person complains that their build has failed, not
realizing that it is because they have tried to cut
corners.
Can interrupted builds be resumed?
This depends on how far through the process you got before
you found a problem.
In general (and this is not a hard and
fast rule) the make buildworld process builds new
copies of essential tools (such as &man.gcc.1;, and
&man.make.1;) and the system libraries. These tools and
libraries are then installed. The new tools and libraries are
then used to rebuild themselves, and are installed again. The
entire system (now including regular user programs, such as
&man.ls.1; or &man.grep.1;) is then rebuilt with the new
system files.
If you are at the last stage, and you know it (because you
have looked through the output that you were storing) then you
can (fairly safely) do:
… fix the problem …
&prompt.root; cd /usr/src
&prompt.root; make -DNO_CLEAN all
This will not undo the work of the previous
make buildworld.
If you see the message:
--------------------------------------------------------------
Building everything..
--------------------------------------------------------------
in the make buildworld output then it is
probably fairly safe to do so.
If you do not see that message, or you are not sure, then it
is always better to be safe than sorry, and restart the build
from scratch.
How can I speed up making the world?
Run in single user mode.
Put the /usr/src and
/usr/obj directories on separate
file systems held on separate disks. If possible, put these
disks on separate disk controllers.
Better still, put these file systems across multiple
disks using the &man.ccd.4; (concatenated disk
driver) device.
Turn off profiling (set NO_PROFILE=true
in
/etc/make.conf). You almost certainly
do not need it.
Also in /etc/make.conf, set
CFLAGS to something like . The optimization is much
slower, and the optimization difference between
and is normally
negligible. lets the compiler use
pipes rather than temporary files for communication, which
saves disk access (at the expense of memory).
Pass the option to &man.make.1; to
run multiple processes in parallel. This usually helps
regardless of whether you have a single or a multi processor
machine.
The file system holding
/usr/src can be mounted (or remounted)
with the option. This prevents the
file system from recording the file access time. You probably
do not need this information anyway.
&prompt.root; mount -u -o noatime /usr/src
The example assumes /usr/src is
on its own file system. If it is not (if it is a part of
/usr for example) then you will
need to use that file system mount point, and not
/usr/src.
The file system holding /usr/obj can
be mounted (or remounted) with the
option. This causes disk writes to happen asynchronously.
In other words, the write completes immediately, and the
data is written to the disk a few seconds later. This
allows writes to be clustered together, and can be a
dramatic performance boost.
Keep in mind that this option makes your file system
more fragile. With this option there is an increased
chance that, should power fail, the file system will be in
an unrecoverable state when the machine restarts.
If /usr/obj is the only thing on
this file system then it is not a problem. If you have
other, valuable data on the same file system then ensure
your backups are fresh before you enable this
option.
&prompt.root; mount -u -o async /usr/obj
As above, if /usr/obj is not on
its own file system, replace it in the example with the
name of the appropriate mount point.
What do I do if something goes wrong?
Make absolutely sure your environment has no
extraneous cruft from earlier builds. This is simple
enough.
&prompt.root; chflags -R noschg /usr/obj/usr
&prompt.root; rm -rf /usr/obj/usr
&prompt.root; cd /usr/src
&prompt.root; make cleandir
&prompt.root; make cleandir
Yes, make cleandir really should
be run twice.
Then restart the whole process, starting
with make buildworld.
If you still have problems, send the error and the
output of uname -a to &a.questions;.
Be prepared to answer other questions about your
setup!
Mike
Meyer
Contributed by
Tracking for Multiple Machines
NFS
installing multiple machines
If you have multiple machines that you want to track the
same source tree, then having all of them download sources and
rebuild everything seems like a waste of resources: disk space,
network bandwidth, and CPU cycles. It is, and the solution is
to have one machine do most of the work, while the rest of the
machines mount that work via NFS. This section outlines a
method of doing so.
Preliminaries
First, identify a set of machines that is going to run
the same set of binaries, which we will call a
build set. Each machine can have a
custom kernel, but they will be running the same userland
binaries. From that set, choose a machine to be the
build machine. It is going to be the
machine that the world and kernel are built on. Ideally, it
should be a fast machine that has sufficient spare CPU to
run make buildworld and
make buildkernel. You will also want to
choose a machine to be the test
machine, which will test software updates before they
are put into production. This must be a
machine that you can afford to have down for an extended
period of time. It can be the build machine, but need not be.
All the machines in this build set need to mount
/usr/obj and
/usr/src from the same machine, and at
the same point. Ideally, those are on two different drives
on the build machine, but they can be NFS mounted on that machine
as well. If you have multiple build sets,
/usr/src should be on one build machine, and
NFS mounted on the rest.
Finally make sure that
/etc/make.conf on all the machines in
the build set agrees with the build machine. That means that
the build machine must build all the parts of the base
system that any machine in the build set is going to
install. Also, each build machine should have its kernel
name set with KERNCONF in
/etc/make.conf, and the build machine
should list them all in KERNCONF, listing
its own kernel first. The build machine must have the kernel
configuration files for each machine in
/usr/src/sys/arch/conf
if it is going to build their kernels.
The Base System
Now that all that is done, you are ready to build
everything. Build the kernel and world as described in on the build machine,
but do not install anything. After the build has finished, go
to the test machine, and install the kernel you just
built. If this machine mounts /usr/src
and /usr/obj via NFS, when you reboot
to single user you will need to enable the network and mount
them. The easiest way to do this is to boot to multi-user,
then run shutdown now to go to single user
mode. Once there, you can install the new kernel and world and run
mergemaster just as you normally would. When
done, reboot to return to normal multi-user operations for this
machine.
After you are certain that everything on the test
machine is working properly, use the same procedure to
install the new software on each of the other machines in
the build set.
Ports
The same ideas can be used for the ports tree. The first
critical step is mounting /usr/ports from
the same machine to all the machines in the build set. You can
then set up /etc/make.conf properly to share
distfiles. You should set DISTDIR to a
common shared directory that is writable by whichever user
root is mapped to by your NFS mounts. Each
machine should set WRKDIRPREFIX to a
local build directory. Finally, if you are going to be
building and distributing packages, you should set
PACKAGES to a directory similar to
DISTDIR.
diff --git a/zh_TW.Big5/books/handbook/l10n/chapter.xml b/zh_TW.Big5/books/handbook/l10n/chapter.xml
index 4029f6e690..ec34ee2791 100644
--- a/zh_TW.Big5/books/handbook/l10n/chapter.xml
+++ b/zh_TW.Big5/books/handbook/l10n/chapter.xml
@@ -1,908 +1,905 @@
Andrey
Chernov
Contributed by
Michael C.
Wu
Rewritten by
»y¨t³]©w - I18N/L10N ¥Îªk»P³]©w
·§z
¥Ñ©ó FreeBSD ¬O¤À§G¥þ¥@¬Éªº¨Ï¥ÎªÌ¤Î§Ó¤u©Ò¤ä«ùªºpµe¡A¥»³¹¥Dn±´°Qªº¬O
FreeBSD ªº°ê»Ú¤Æ¡B¥»¤g¤ÆÄ³ÃD¡A¥H«KÅý¥À»y¤£¬O^»y¨tªº¤H¤]¯à¶¶§Q§¹¦¨¦U¶µ¤u§@¡C
¦b§@·~¨t²Î¡BÀ³¥Îµ{¦¡¨âºØ¼h±¡A¥Dn³£¬O³z¹L i18n ¼Ð·Ç¨Ó¹ê§@ªº¡A©Ò¥H¡A
³o¸Ì§Ú̱N·|¤¶²Ð¤jP¹B§@¤è¦¡¡C
Ū§¹³o³¹¡A±z±N¤F¸Ñ¡J
¦UºØ¤£¦Pªº»y¨¥»P¦a°Ï³]©w¦p¦ó¦b§@·~¨t²Î¤W¶i¦æ½s½X¡C
¦p¦ó³]©wµn¤J¥Îªº shell »y¨tÀô¹Ò¡C
¦p¦ó±N§Aªº console ³]¬°^»y¥H¥~ªº»y¨t³]©w¡C
¦p¦ó¨Ï¥Î¤£¦P»y¨tªº³]©w¡A¨ÓÅý X Window ¹B§@§ó¿Ë¤Á¡C
þÃä¥i¥H§ä¨ì§ó¦h»P i18n ³W®æ¬Û®eªºÀ³¥Îµ{¦¡³W®æ¸ê®Æ¡C
¦b¶}©l¾\Ū³o³¹¤§«e¡A±z»Ýn¡J
ª¾¹D¦p¦ó¥H ports/packages ¨Ó¦w¸ËÀ³¥Îµ{¦¡()¡C
L10N °ò¦·§©À
¤°»ò¬O I18N/L10N?
internationalization
localization
localization
µ{¦¡¶}µo¤Hû²ßºD§â internationalization ÁY¼g¬° I18N¡A¤¤¶¡ªº¼Æ¦r 18 ¤D¬O³Ì«e»P³Ì«á±¦r¥À¤§¶¡ªº¦r¥ÀÓ¼ÆÁ`©M¡A
¦Ó L10N ¤]¬O¥H¤@¼Ëªº¤è¦¡¡A¬O localization
ªºÁY¼g¡C
¥un¦³²Å¦X I18N/L10N ³W®æ¡B¨ó©wªºÀ³¥Îµ{¦¡¡A´N¥i¥HÅý¨Ï¥ÎªÌ¨Ì¦U¦Û»y¨t¦Ó§@³]©w¡C
I18N À³¥Îµ{¦¡¬O¥H I18N ¶}µo¤u¨ã¨Ó¶i¦æ¶}µoªº¡A
¥¦¥i¥HÅýµ{¦¡¶}µo¤Hû³z¹L¼g²³æªº¤å¦rÀÉ¡A´N¥i¥H§â°õ¦æµe±¤Wªº¿ï³æ¡B°T®§Â½Ä¶¬°¦U»y¨tªºª©¥»¡C
§Ú̱j¯P«ØÄ³µ{¦¡¶}µo¤Hû¿í´`³oÓ¹CÀ¸³W«h¡C
¬°¦ó¸Ó¨Ï¥Î I18N/L10N¡H
¥un¦³²Å¦X I18N/L10N ¼Ð·Ç¡A´N¥i¥H»´ÃP¦a¬Ý¡B¿é¤J¡B³B²z«D^¤åªº¸ê®Æ¡C
I18N ¤ä´©þ¨Ç»y¨t¡H
I18N ©M L10N ¨Ã«D FreeBSD ©Ò¯S¦³ªº¡A¥Ø«e³o¥@¬É¤Wªº´X¥G¥ô¤@¥Dn»y¨t³£¦³¤ä´©¡A
¹³¬O¡G¤¤¤å¡B¼w¤å¡B¤é¤å¡BÁú¤å¡Bªk¤å¡B«X¤å¡B¶V«n¤åµ¥µ¥¡C
¨Ï¥Î»y¨t³]©w(Localization)
I18N ©M L10N ¨Ã«D FreeBSD ©Ò¯S¦³ªº¡A¦Ó¬O¦@³qªº¹CÀ¸³W«h¡C
§Ú̹ªÀy§A¦b FreeBSD ¥@¬É¤¤¦P¼Ë¿í¦u³o¶µ¹CÀ¸³W«h¡C
locale
Locale ³]©w¥Ñ¤TÓ³¡¤À©Ò²Õ¦¨¡G»y¨¥¥N½X(Language Code)¡B°ê½X(Country Code)¡B½s½X(Encoding)¡C
©Ò¥H¡ALocale ªº³]©w¦WºÙ´N¬O¥Ñ³o¤TÓ¤@°_²Õ¦¨¡G
»y¨¥¥N½X_°ê½X.½s½X
»y¨¥¡B°ê½X
language codes
country codes
¨Ï¥ÎªÌ¥²¶·n¥ýª¾¹D³o¨Ç¯S©wªº°ê½X¡B»y¨¥¥N½X(°ê½X·|§i¶DÀ³¥Îµ{¦¡¸Ó¨Ï¥Îþ¤@ºØ»y¨¥)¡A
¤~¯àÅý FreeBSD ©Î¨ä¥L¤ä´© I18N ªº &unix; Ãþ¨t²Î§@ locale ¬ÛÃö³]©w¡C
¦¹¥~¡Aºô¶ÂsÄý¾¹(borwser)¡BSMTP/POP ¥D¾÷¡BWeb ¥D¾÷µ¥¤]³£¥H³o¬[ºc¬°¥D¡C
¤U±¬O¦p¦ó¨Ï¥Î¡y»y¨¥¥N½X¡B°ê½X¡zªº¨Ò¤l¡G
»y¨¥¥N½X/°ê½X
²¤¶
en_US
^¤å(¬ü°ê)
ru_RU
«X¤å(«X°ê)
zh_TW
¥¿Å餤¤å(¥xÆW)
½s½X
encodings
ASCII
¦³¨Ç»y¨¥¨Ã«D±Ä¥Î ASCII ½s½X¡A¥i¯à¬O¡G 8-bit¡Bwide
©Î multibyte ¦r¤¸¡A¸Ô±¡½Ð°Ñ¾\ &man.multibyte.3;¡C
¸û¥j¦ªºµ{¦¡¥i¯àµLªk¥¿½T§P§O¡B©Î»~§P¬°¯S®í±±¨î¦r¤¸¡C¦Ó¸û·sªºµ{¦¡³£¥i¥H¿ë»{
8-bit ¦r¤¸¡C ¥Ñ©ó¦Uµ{¦¡ªº§@ªk¤£¤@¡A¨Ï¥ÎªÌ¥i¯à»Ýn¦b½s͵{¦¡®É¡A¥[¤W
wide ©Î multibyte ¦r¤¸ªº¤ä´©³]©w¡A©Î¬O¥¿½T½Õ¾ã¤~¦æ¡C
n¿é¤J¡B³B²z wide ©Î multibyte ¦r¤¸ªº¸Ü¡A¥i¦h¦h§Q¥Î FreeBSD Ports Collection ¤º¦³¦U°ê»y¨¥ª©¥»ªºµ{¦¡¡C
¸Ô±¡½Ð°Ñ¾\ FreeBSD ¦U port ¤¤ªº I18N ¬ÛÃö¤å¥ó¡C
Specifically, the user needs to look at the application
documentation to decide on how to configure it correctly or to
pass correct values into the configure/Makefile/compiler.
Some things to keep in mind are:
Language specific single C chars character sets
(see &man.multibyte.3;), e.g.
ISO8859-1, ISO8859-15, KOI8-R, CP437.
Wide or multibyte encodings, e.g. EUC, Big5.
You can check the active list of character sets at the
IANA Registry.
&os; use X11-compatible locale encodings instead.
I18N Applications
In the FreeBSD Ports and Package system, I18N applications
have been named with I18N in their names for
easy identification. However, they do not always support the
language needed.
Setting Locale
Usually it is sufficient to export the value of the locale name
as LANG in the login shell. This could be done in
the user's ~/.login_conf file or in the
startup file of the user's shell (~/.profile,
~/.bashrc, ~/.cshrc).
There is no need to set the locale subsets such as
LC_CTYPE, LC_CTIME. Please
refer to language-specific FreeBSD documentation for more
information.
You should set the following two environment variables in your configuration
files:
- POSIX
- LANG for &posix; &man.setlocale.3; family
+ LANG for &posix;POSIX &man.setlocale.3; family
functions
- MIME
-
- MM_CHARSET for applications' MIME character
+ MM_CHARSET for applications' MIMEMIME character
set
This includes the user shell configuration, the specific application
configuration, and the X11 configuration.
Setting Locale Methods
locale
login class
There are two methods for setting locale, and both are
described below. The first (recommended one) is by assigning
the environment variables in login
class, and the second is by adding the environment
variable assignments to the system's shell startup file.
Login Classes Method
This method allows environment variables needed for locale
name and MIME character sets to be assigned once for every
possible shell instead of adding specific shell assignments to
each shell's startup file. User
Level Setup can be done by an user himself and Administrator Level Setup require
superuser privileges.
User Level Setup
Here is a minimal example of a
.login_conf file in user's home
directory which has both variables set for Latin-1
encoding:
me:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:
Traditional ChineseBIG-5 encoding
Here is an example of a
.login_conf that sets the variables
for Traditional Chinese in BIG-5 encoding. Notice the many
more variables set because some software does not respect
locale variables correctly for Chinese, Japanese, and Korean.
#Users who do not wish to use monetary units or time formats
#of Taiwan can manually change each variable
me:\
:lang=zh_TW.Big5:\
:lc_all=zh_TW.Big:\
:lc_collate=zh_TW.Big5:\
:lc_ctype=zh_TW.Big5:\
:lc_messages=zh_TW.Big5:\
:lc_monetary=zh_TW.Big5:\
:lc_numeric=zh_TW.Big5:\
:lc_time=zh_TW.Big5:\
:charset=big5:\
:xmodifiers="@im=xcin": #Setting the XIM Input Server
See Administrator Level
Setup and &man.login.conf.5; for more details.
Administrator Level Setup
Verify that the user's login class in
/etc/login.conf sets the correct
language. Make sure these settings
appear in /etc/login.conf:
language_name:accounts_title:\
:charset=MIME_charset:\
:lang=locale_name:\
:tc=default:
So sticking with our previous example using Latin-1, it
would look like this:
german:German Users Accounts:\
:charset=ISO-8859-1:\
:lang=de_DE.ISO8859-1:\
:tc=default:
Before changing users Login Classes execute
the following command
&prompt.root; cap_mkdb /etc/login.conf
to make new configuration in
/etc/login.conf visible to the system.
Changing Login Classes with &man.vipw.8;
vipw
Use vipw to add new users, and make
the entry look like this:
user:password:1111:11:language:0:0:User Name:/home/user:/bin/sh
Changing Login Classes with &man.adduser.8;
adduser
login class
Use adduser to add new users, and do
the following:
Set defaultclass =
language in
/etc/adduser.conf. Keep in mind
you must enter a default class for
all users of other languages in this case.
An alternative variant is answering the specified
language each time that
Enter login class: default []:
appears from &man.adduser.8;.
Another alternative is to use the following for each
user of a different language that you wish to
add:
&prompt.root; adduser -class language
Changing Login Classes with &man.pw.8;
pw
If you use &man.pw.8; for adding new users, call it in
this form:
&prompt.root; pw useradd user_name -L language
Shell Startup File Method
This method is not recommended because it requires a
different setup for each possible shell program chosen. Use
the Login Class Method
instead.
MIME
locale
To add the locale name and MIME character set, just set
the two environment variables shown below in the
/etc/profile and/or
/etc/csh.login shell startup files. We
will use the German language as an example below:
In /etc/profile:
LANG=de_DE.ISO8859-1; export LANG
MM_CHARSET=ISO-8859-1; export MM_CHARSET
Or in /etc/csh.login:
setenv LANG de_DE.ISO8859-1
setenv MM_CHARSET ISO-8859-1
Alternatively, you can add the above instructions to
/usr/share/skel/dot.profile (similar to
what was used in /etc/profile above), or
/usr/share/skel/dot.login (similar to
what was used in /etc/csh.login
above).
For X11:
In $HOME/.xinitrc:
LANG=de_DE.ISO8859-1; export LANG
Or:
setenv LANG de_DE.ISO8859-1
Depending on your shell (see above).
Console Setup
For all single C chars character sets, set the correct
console fonts in /etc/rc.conf for the
language in question with:
font8x16=font_name
font8x14=font_name
font8x8=font_name
The font_name here is taken from
the /usr/share/syscons/fonts directory,
without the .fnt suffix.
sysinstall
keymap
screenmap
Also be sure to set the correct keymap and screenmap for your
single C chars character set through
sysinstall (/stand/sysinstall
in &os; versions older than 5.2).
Once inside sysinstall, choose Configure, then
Console. Alternatively, you can add the
following to /etc/rc.conf:
scrnmap=screenmap_name
keymap=keymap_name
keychange="fkey_number sequence"
The screenmap_name here is taken
from the /usr/share/syscons/scrnmaps
directory, without the .scm suffix. A
screenmap with a corresponding mapped font is usually needed as a
workaround for expanding bit 8 to bit 9 on a VGA adapter's font
character matrix in pseudographics area, i.e., to move letters out
of that area if screen font uses a bit 8 column.
If you have the moused daemon
enabled by setting the following
in your /etc/rc.conf:
moused_enable="YES"
then examine the mouse cursor information in the next
paragraph.
moused
By default the mouse cursor of the &man.syscons.4; driver occupies the
0xd0-0xd3 range in the character set. If your language uses this
range, you need to move the cursor's range outside of it. To enable
the workaround for &os;, add the following line to
/etc/rc.conf:
mousechar_start=3
The keymap_name here is taken from
the /usr/share/syscons/keymaps directory,
without the .kbd suffix. If you are
uncertain which keymap to use, you use can &man.kbdmap.1; to test
keymaps without rebooting.
The keychange is usually needed to program
function keys to match the selected terminal type because
function key sequences cannot be defined in the key map.
Also be sure to set the correct console terminal type in
/etc/ttys for all ttyv*
entries. Current pre-defined correspondences are:
Character Set
Terminal Type
ISO8859-1 or ISO8859-15
cons25l1
ISO8859-2
cons25l2
ISO8859-7
cons25l7
KOI8-R
cons25r
KOI8-U
cons25u
CP437 (VGA default)
cons25
US-ASCII
cons25w
For wide or multibyte characters languages, use the correct
FreeBSD port in your
/usr/ports/language
directory. Some ports appear as console while the system sees it
as serial vtty's, hence you must reserve enough vtty's for both
X11 and the pseudo-serial console. Here is a partial list of
applications for using other languages in console:
Language
Location
Traditional Chinese (BIG-5)
chinese/big5con
Japanese
japanese/kon2-16dot or
japanese/mule-freewnn
Korean
korean/han
X11 Setup
Although X11 is not part of the FreeBSD Project, we have
included some information here for FreeBSD users. For more
details, refer to the &xorg;
web site or whichever X11 Server you use.
In ~/.Xresources, you can additionally
tune application specific I18N settings (e.g., fonts, menus,
etc.).
Displaying Fonts
X11 True Type font server
Install &xorg; server
(x11-servers/xorg-server)
or &xfree86; server
(x11-servers/XFree86-4-Server),
then install the language &truetype; fonts. Setting the correct
locale should allow you to view your selected language in menus
and such.
Inputting Non-English Characters
X11 Input Method (XIM)
The X11 Input Method (XIM) Protocol is a new standard for
all X11 clients. All X11 applications should be written as XIM
clients that take input from XIM Input servers. There are
several XIM servers available for different languages.
Printer Setup
Some single C chars character sets are usually hardware
coded into printers. Wide or multibyte
character sets require special setup and we recommend using
apsfilter. You may also convert the
document to &postscript; or PDF formats using language specific
converters.
Kernel and File Systems
The FreeBSD fast filesystem (FFS) is 8-bit clean, so it can be used
with any single C chars character set (see &man.multibyte.3;),
but there is no character set
name stored in the filesystem; i.e., it is raw 8-bit and does not
know anything about encoding order. Officially, FFS does not
support any form of wide or multibyte character sets yet. However, some
wide or multibyte character sets have independent patches for FFS
enabling such support. They are only temporary unportable
solutions or hacks and we have decided to not include them in the
source tree. Refer to respective languages' web sites for more
information and the patch files.
DOS
Unicode
The FreeBSD &ms-dos; filesystem has the configurable ability to
convert between &ms-dos;, Unicode character sets and chosen
FreeBSD filesystem character sets. See &man.mount.msdos.8; for
details.
Compiling I18N Programs
Many FreeBSD Ports have been ported with I18N support. Some
of them are marked with -I18N in the port name. These and many
other programs have built in support for I18N and need no special
consideration.
MySQL
However, some applications such as
MySQL need to be have the
Makefile configured with the specific
charset. This is usually done in the
Makefile or done by passing a value to
configure in the source.
Localizing FreeBSD to Specific Languages
Andrey
Chernov
Originally contributed by
Russian Language (KOI8-R Encoding)
localization
Russian
For more information about KOI8-R encoding, see the KOI8-R References
(Russian Net Character Set).
Locale Setup
Put the following lines into your
~/.login_conf file:
me:My Account:\
:charset=KOI8-R:\
:lang=ru_RU.KOI8-R:
See earlier in this chapter for examples of setting up the
locale.
Console Setup
Add the following line
to your /etc/rc.conf file:
mousechar_start=3
Also, use following settings in
/etc/rc.conf:
keymap="ru.koi8-r"
scrnmap="koi8-r2cp866"
font8x16="cp866b-8x16"
font8x14="cp866-8x14"
font8x8="cp866-8x8"
For each ttyv* entry in
/etc/ttys, use
cons25r as the terminal type.
See earlier in this chapter for examples of setting up the
console.
Printer Setup
printers
Since most printers with Russian characters come with
hardware code page CP866, a special output filter is needed
to convert from KOI8-R to CP866. Such a filter is installed by
default as /usr/libexec/lpr/ru/koi2alt.
A Russian printer /etc/printcap entry
should look like:
lp|Russian local line printer:\
:sh:of=/usr/libexec/lpr/ru/koi2alt:\
:lp=/dev/lpt0:sd=/var/spool/output/lpd:lf=/var/log/lpd-errs:
See &man.printcap.5; for a detailed description.
&ms-dos; FS and Russian Filenames
The following example &man.fstab.5; entry enables support
for Russian filenames in mounted &ms-dos; filesystems:
/dev/ad0s2 /dos/c msdos rw,-Wkoi2dos,-Lru_RU.KOI8-R 0 0
The option selects the locale name
used, and sets the character conversion
table. To use the option, be sure to
mount /usr before the &ms-dos; partition
because the conversion tables are located in
/usr/libdata/msdosfs. For more
information, see the &man.mount.msdos.8; manual
page.
X11 Setup
Do non-X locale
setup first as described.
If you use &xorg;,
install
x11-fonts/xorg-fonts-cyrillic
package.
Check the "Files" section
in your /etc/X11/xorg.conf file.
The following
lines must be added before any other
FontPath entries:
FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/misc"
FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/75dpi"
FontPath "/usr/X11R6/lib/X11/fonts/cyrillic/100dpi"
If you use a high resolution video mode, swap the 75 dpi
and 100 dpi lines.
To activate a Russian keyboard, add the following to the
"Keyboard" section of your
xorg.conf file.
Option "XkbLayout" "us,ru"
Option "XkbOptions" "grp:toggle"
Also make sure that XkbDisable is
turned off (commented out) there.
For grp:caps_toggle
the RUS/LAT switch will be CapsLock.
The old CapsLock function is still
available via ShiftCapsLock (in LAT mode
only). For grp:toggle
the RUS/LAT switch will be Right Alt.
grp:caps_toggle does not work in
&xorg; for unknown reason.
If you have &windows;
keys on your keyboard,
and notice that some non-alphabetical keys are mapped
incorrectly in RUS mode, add the following line in your
xorg.conf file.
Option "XkbVariant" ",winkeys"
The Russian XKB keyboard may not work with non-localized
applications.
Minimally localized applications
should call a XtSetLanguageProc (NULL, NULL,
NULL); function early in the program.
See
KOI8-R for X Window for more instructions on
localizing X11 applications.
Traditional Chinese Localization for Taiwan
localization
Traditional Chinese
The FreeBSD-Taiwan Project has an Chinese HOWTO for
FreeBSD at
using many Chinese ports.
Current editor for the FreeBSD Chinese HOWTO is
Shen Chuan-Hsing statue@freebsd.sinica.edu.tw.
Chuan-Hsing Shen statue@freebsd.sinica.edu.tw has
created the
Chinese FreeBSD Collection (CFC) using FreeBSD-Taiwan's
zh-L10N-tut. The packages and the script files
are available at .
German Language Localization (for All ISO 8859-1
Languages)
localization
German
Slaven Rezic eserte@cs.tu-berlin.de wrote a
tutorial how to use umlauts on a FreeBSD machine. The tutorial
is written in German and available at
.
Japanese and Korean Language Localization
localization
Japanese
localization
Korean
For Japanese, refer to
,
and for Korean, refer to
.
Non-English FreeBSD Documentation
Some FreeBSD contributors have translated parts of FreeBSD to
other languages. They are available through links on the main site or in
/usr/share/doc.
diff --git a/zh_TW.Big5/books/handbook/mail/chapter.xml b/zh_TW.Big5/books/handbook/mail/chapter.xml
index 5d93615541..37966654b2 100644
--- a/zh_TW.Big5/books/handbook/mail/chapter.xml
+++ b/zh_TW.Big5/books/handbook/mail/chapter.xml
@@ -1,2300 +1,2299 @@
Bill
Lloyd
Original work by
Jim
Mock
Rewritten by
¹q¤l¶l¥ó
·§z
email
¹q¤l¶l¥ó
©ÎªÌ«UºÙªº email¡A
¤D¬O²{¤µ¨Ï¥Î³Ì¼sªxªº·¾³q¤è¦¡¤§¤@¡C ¥»³¹¥Dn¤¶²Ð¦p¦ó¦b &os; ¤W¦w¸Ë¡B
³]©w email ªA°È¡A¥H¤Î¦p¦ó¦b &os; ¦¬µo«H¥ó¡F µM¦Ó³o¨Ã¤£¬O§¹¾ãªº°Ñ¦Ò¤â¥U¡A
¹ê»Ú¤W³\¦h»Ý¦Ò¶qªº«n¨Æ¶µ¨Ã¥¼´£¤Î¡AY±ýÁA¸Ñ²Ó¸`½Ð°Ñ¾\ ¤ºªº°Ñ¦Ò®ÑÄy¡C
Ū§¹³o³¹¡A±z±N¤F¸Ñ¡J
þ¨Ç³nÅ餸¥ó»P¦¬µo¹q¤l¶l¥ó¦³Ãö¡C
FreeBSD ¤ºªº sendmail
°ò¥»³]©wÀɦbþ¡C
»·ºÝ«H½c»P¥»¾÷«H½cªº°Ï§O¡C
¦p¦óªý¾× spammer(©U§£¶l¥ó»s³yªÌ)«Dªk¹B¥Î±zªº¶l¥ó¦øªA¾¹§@¬°
relay(Âàµo¤¤Ä~ÂI)¡C
¦p¦ó¦w¸Ë¡B³]©w¨ä¥L Mail Transfer Agent(MTA) ¨Ó¨ú¥N
sendmail¡C
¦p¦ó³B²z±`¨£ªº¶l¥ó¦øªA¾¹°ÝÃD¡C
¦p¦ó¨Ï¥Î UUCP ¨Ó¶i¦æ SMTP¡C
¦p¦ó³]©w¨t²Î¡A¨Ï¨ä¥u¯àµo°e¶l¥ó¡C
¦p¦ó¦b¼·±µ¤WºôÀô¹Ò¤¤¡A¦¬µo¶l¥ó¡C
¦p¦ó³]©w SMTP ÅçÃÒ¡A¥H¥[±j¦w¥þ©Ê¡C
¦p¦ó¦w¸Ë¡B¨Ï¥Î Mail User Agent(MUA) µ{¦¡¡A¤ñ¦p
mutt ¨Ó¦¬µo¶l¥ó¡C
¦p¦ó±q»·ºÝ POP ©Î IMAP
¥D¾÷¥h¤U¸ü¶l¥ó¡C
¦p¦ó¦b¦¬«H¤è±¡A¦Û°Ê®M¥Î¶l¥ó¹LÂo¡C
¦b¶}©l¾\Ū³o³¹¤§«e¡A±z»Ýn¡J
¥ý³]¦n§Aªººô¸ô
()¡C
¯à¥¿½T¬°¶l¥ó¦øªA¾¹³]©w DNS
()¡C
ª¾¹D¦p¦ó³z¹L port/package ¦w¸Ë³nÅé
()¡C
¨Ï¥Î¹q¤l¶l¥ó
POP
IMAP
DNS
¦b email ¥æ´«ªº¹Lµ{¤¤¦³ 5 Ó¥Dn³¡¤À¡A¤À§O¬O¡GMUA¡BMTA¡B
DNS¡B
»·ºÝ©Î¥»¾÷ªº«H½c¡A·íµMÁÙ¦³ ¶l¥ó¥D¾÷¥»¨
¡C
MUA µ{¦¡
¥]¬A¤@¨Ç¤å¦r¤¶±ªºµ{¦¡¡A¹³¬O
mutt¡B
pine¡Belm¡B
and mail¡A¥H¤Î GUI ¤¶±ªºµ{¦¡¡A
¹³¬O balsa¡B
xfmail µ¥µ¥¡C ¦¹¥~¡AÁÙ¦³§ó
½ÆÂøªº
¹³¬O WWW ÂsÄý¾¹¡C
³o¨Çµ{¦¡·|¶l¥ó³B²z¥æµ¹ ¶l¥ó¥D¾÷
¡A©ÎªÌ³z¹L©I¥s
MTA(Y¦³ªº¸Ü)©ÎªÌ¬O³z¹L
TCP ¨Ó¶Ç»¼¶l¥ó¡C
Mailhost Server Daemon
mail server daemons
sendmail
mail server daemons
postfix
mail server daemons
qmail
mail server daemons
exim
&os; ships with sendmail by
default, but also support numerous other mail server daemons,
just some of which include:
exim;
postfix;
qmail.
The server daemon usually has two functions—it is responsible
for receiving incoming mail as well as delivering outgoing mail. It is
not responsible for the collection of mail using protocols
such as POP or IMAP to
read your email, nor does it allow connecting to local
mbox or Maildir mailboxes. You may require
an additional daemon for
that.
Older versions of sendmail
have some serious security issues which may result in an
attacker gaining local and/or remote access to your machine.
Make sure that you are running a current version to avoid
these problems. Optionally, install an alternative
MTA from the &os;
Ports Collection.
Email and DNS
The Domain Name System (DNS) and its daemon
named play a large role in the delivery of
email. In order to deliver mail from your site to another, the
server daemon will look up the remote site in the DNS to determine the
host that will receive mail for the destination. This process
also occurs when mail is sent from a remote host to your mail
server.
MX record
DNS is responsible for mapping
hostnames to IP addresses, as well as for storing information
specific to mail delivery, known as MX records. The MX (Mail
eXchanger) record specifies which host, or hosts, will receive
mail for a particular domain. If you do not have an MX record
for your hostname or domain, the mail will be delivered
directly to your host provided you have an A record pointing
your hostname to your IP address.
You may view the MX records for any domain by using the
&man.host.1; command, as seen in the example below:
&prompt.user; host -t mx FreeBSD.org
FreeBSD.org mail is handled (pri=10) by mx1.FreeBSD.org
Receiving Mail
email
receiving
Receiving mail for your domain is done by the mail host. It
will collect all mail sent to your domain and store it
either in mbox (the default method for storing mail) or Maildir format, depending
on your configuration.
Once mail has been stored, it may either be read locally using
applications such as &man.mail.1; or
mutt, or remotely accessed and
collected using protocols such as
POP or IMAP.
This means that should you only
wish to read mail locally, you are not required to install a
POP or IMAP server.
Accessing remote mailboxes using POP and IMAP
POP
IMAP
In order to access mailboxes remotely, you are required to
have access to a POP or IMAP
server. These protocols allow users to connect to their mailboxes from
remote locations with ease. Though both
POP and IMAP allow users
to remotely access mailboxes, IMAP offers
many advantages, some of which are:
IMAP can store messages on a remote
server as well as fetch them.
IMAP supports concurrent updates.
IMAP can be extremely useful over
low-speed links as it allows users to fetch the structure
of messages without downloading them; it can also
perform tasks such as searching on the server in
order to minimize data transfer between clients and
servers.
In order to install a POP or
IMAP server, the following steps should be
performed:
Choose an IMAP or
POP server that best suits your needs.
The following POP and
IMAP servers are well known and serve
as some good examples:
qpopper;
teapop;
imap-uw;
courier-imap;
Install the POP or
IMAP daemon of your choosing from the
ports
collection.
Where required, modify /etc/inetd.conf
to load the POP or
IMAP server.
It should be noted that both POP and
IMAP transmit information, including
username and password credentials in clear-text. This means
that if you wish to secure the transmission of information
across these protocols, you should consider tunneling
sessions over &man.ssh.1;. Tunneling sessions is
described in .
Accessing local mailboxes
Mailboxes may be accessed locally by directly utilizing
MUAs on the server on which the mailbox
resides. This can be done using applications such as
mutt or &man.mail.1;.
The Mail Host
mail host
The mail host is the name given to a server that is
responsible for delivering and receiving mail for your host, and
possibly your network.
Christopher
Shumway
Contributed by
sendmail Configuration
sendmail
&man.sendmail.8; is the default Mail Transfer Agent (MTA) in
FreeBSD. sendmail's job is to accept
mail from Mail User Agents (MUA) and deliver it
to the appropriate mailer as defined by its configuration file.
sendmail can also accept network
connections and deliver mail to local mailboxes or deliver it to
another program.
sendmail uses the following
configuration files:
/etc/mail/access
/etc/mail/aliases
/etc/mail/local-host-names
/etc/mail/mailer.conf
/etc/mail/mailertable
/etc/mail/sendmail.cf
/etc/mail/virtusertable
Filename
Function
/etc/mail/access
sendmail access database
file
/etc/mail/aliases
Mailbox aliases
/etc/mail/local-host-names
Lists of hosts sendmail
accepts mail for
/etc/mail/mailer.conf
Mailer program configuration
/etc/mail/mailertable
Mailer delivery table
/etc/mail/sendmail.cf
sendmail master
configuration file
/etc/mail/virtusertable
Virtual users and domain tables
/etc/mail/access
The access database defines what host(s) or IP addresses
have access to the local mail server and what kind of access
they have. Hosts can be listed as ,
, or simply passed
to sendmail's error handling routine with a given mailer error.
Hosts that are listed as , which is the
default, are allowed to send mail to this host as long as the
mail's final destination is the local machine. Hosts that are
listed as are rejected for all mail
connections. Hosts that have the option
for their hostname are allowed to send mail for any destination
through this mail server.
Configuring the sendmail
Access Database
cyberspammer.com 550 We do not accept mail from spammers
FREE.STEALTH.MAILER@ 550 We do not accept mail from spammers
another.source.of.spam REJECT
okay.cyberspammer.com OK
128.32 RELAY
In this example we have five entries. Mail senders that
match the left hand side of the table are affected by the action
on the right side of the table. The first two examples give an
error code to sendmail's error
handling routine. The message is printed to the remote host when
a mail matches the left hand side of the table. The next entry
rejects mail from a specific host on the Internet,
another.source.of.spam. The next entry accepts
mail connections from a host
okay.cyberspammer.com, which is more exact than
the cyberspammer.com line above. More specific
matches override less exact matches. The last entry allows
relaying of electronic mail from hosts with an IP address that
begins with 128.32. These hosts would be able
to send mail through this mail server that are destined for other
mail servers.
When this file is updated, you need to run
make in /etc/mail/ to
update the database.
/etc/mail/aliases
The aliases database contains a list of virtual mailboxes
that are expanded to other user(s), files, programs or other
aliases. Here are a few examples that can be used in
/etc/mail/aliases:
Mail Aliases
root: localuser
ftp-bugs: joe,eric,paul
bit.bucket: /dev/null
procmail: "|/usr/local/bin/procmail"
The file format is simple; the mailbox name on the left
side of the colon is expanded to the target(s) on the right.
The
first example simply expands the mailbox root
to the mailbox localuser, which is then
looked up again in the aliases database. If no match is found,
then the message is delivered to the local user
localuser. The next example shows a mail
list. Mail to the mailbox ftp-bugs is
expanded to the three local mailboxes joe,
eric, and paul. Note
that a remote mailbox could be specified as user@example.com. The
next example shows writing mail to a file, in this case
/dev/null. The last example shows sending
mail to a program, in this case the mail message is written to the
standard input of /usr/local/bin/procmail
through a &unix; pipe.
When this file is updated, you need to run
make in /etc/mail/ to
update the database.
/etc/mail/local-host-names
This is a list of hostnames &man.sendmail.8; is to accept as
the local host name. Place any domains or hosts that
sendmail is to be receiving mail for.
For example, if this mail server was to accept mail for the
domain example.com and the host
mail.example.com, its
local-host-names might look something like
this:
example.com
mail.example.com
When this file is updated, &man.sendmail.8; needs to be
restarted to read the changes.
/etc/mail/sendmail.cf
sendmail's master configuration
file, sendmail.cf controls the overall
behavior of sendmail, including everything
from rewriting e-mail addresses to printing rejection messages to
remote mail servers. Naturally, with such a diverse role, this
configuration file is quite complex and its details are a bit
out of the scope of this section. Fortunately, this file rarely
needs to be changed for standard mail servers.
The master sendmail configuration
file can be built from &man.m4.1; macros that define the features
and behavior of sendmail. Please see
/usr/src/contrib/sendmail/cf/README for
some of the details.
When changes to this file are made,
sendmail needs to be restarted for
the changes to take effect.
/etc/mail/virtusertable
The virtusertable maps mail addresses for
virtual domains and
mailboxes to real mailboxes. These mailboxes can be local,
remote, aliases defined in
/etc/mail/aliases or files.
Example Virtual Domain Mail Map
root@example.com root
postmaster@example.com postmaster@noc.example.net
@example.com joe
In the above example, we have a mapping for a domain
example.com. This file is processed in a
first match order down the file. The first item maps
root@example.com to the local mailbox root. The next entry maps
postmaster@example.com to the mailbox postmaster on the host
noc.example.net. Finally, if nothing from example.com has
matched so far, it will match the last mapping, which matches
every other mail message addressed to someone at
example.com.
This will be mapped to the local mailbox joe.
Andrew
Boothman
Written by
Gregory
Neil Shapiro
Information taken from e-mails written by
Changing Your Mail Transfer Agent
email
change mta
As already mentioned, FreeBSD comes with
sendmail already installed as your
MTA (Mail Transfer Agent). Therefore by default it is
in charge of your outgoing and incoming mail.
However, for a variety of reasons, some system
administrators want to change their system's MTA. These
reasons range from simply wanting to try out another MTA to
needing a specific feature or package which relies on another
mailer. Fortunately, whatever the reason, FreeBSD makes it
easy to make the change.
Install a New MTA
You have a wide choice of MTAs available. A good
starting point is the
FreeBSD Ports Collection where
you will be able to find many. Of course you are free to use
any MTA you want from any location, as long as you can make
it run under FreeBSD.
Start by installing your new MTA. Once it is installed
it gives you a chance to decide if it really fulfills your
needs, and also gives you the opportunity to configure your
new software before getting it to take over from
sendmail. When doing this, you
should be sure that installing the new software will not attempt
to overwrite system binaries such as
/usr/bin/sendmail. Otherwise, your new
mail software has essentially been put into service before
you have configured it.
Please refer to your chosen MTA's documentation for
information on how to configure the software you have
chosen.
Disable sendmail
The procedure used to start
sendmail changed significantly
between 4.5-RELEASE, 4.6-RELEASE, and later releases.
Therefore, the procedure used to disable it is subtly
different.
If you disable sendmail's
outgoing mail service, it is important that you replace it
with an alternative mail delivery system. If
you choose not to, system functions such as &man.periodic.8;
will be unable to deliver their results by e-mail as they
would normally expect to. Many parts of your system may
expect to have a functional
sendmail-compatible system. If
applications continue to use
sendmail's binaries to try to send
e-mail after you have disabled them, mail could go into an
inactive sendmail queue, and
never be delivered.
FreeBSD 4.5-STABLE before 2002/4/4 and Earlier
(Including 4.5-RELEASE and Earlier)
Enter:
sendmail_enable="NO"
into /etc/rc.conf. This will disable
sendmail's incoming mail service,
but if /etc/mail/mailer.conf (see below)
is not changed, sendmail will
still be used to send e-mail.
FreeBSD 4.5-STABLE after 2002/4/4
(Including 4.6-RELEASE and Later)
In order to completely disable
sendmail, including the outgoing
mail service, you must use
sendmail_enable="NONE"
in /etc/rc.conf.
If you only want to disable
sendmail's incoming mail service,
you should set
sendmail_enable="NO"
in /etc/rc.conf. However, if
incoming mail is disabled, local delivery will still
function. More information on
sendmail's startup options is
available from the &man.rc.sendmail.8; manual page.
FreeBSD 5.0-STABLE and Later
In order to completely disable
sendmail, including the outgoing
mail service, you must use
sendmail_enable="NO"
sendmail_submit_enable="NO"
sendmail_outbound_enable="NO"
sendmail_msp_queue_enable="NO"
in /etc/rc.conf.
If you only want to disable
sendmail's incoming mail service,
you should set
sendmail_enable="NO"
in /etc/rc.conf. More information on
sendmail's startup options is
available from the &man.rc.sendmail.8; manual page.
Running Your New MTA on Boot
You may have a choice of two methods for running your
new MTA on boot, again depending on what version of FreeBSD
you are running.
FreeBSD 4.5-STABLE before 2002/4/11
(Including 4.5-RELEASE and Earlier)
Add a script to
/usr/local/etc/rc.d/ that
ends in .sh and is executable by
root. The script should accept start and
stop parameters. At startup time the
system scripts will execute the command
/usr/local/etc/rc.d/supermailer.sh start
which you can also use to manually start the server. At
shutdown time, the system scripts will use the
stop option, running the command
/usr/local/etc/rc.d/supermailer.sh stop
which you can also use to manually stop the server
while the system is running.
FreeBSD 4.5-STABLE after 2002/4/11
(Including 4.6-RELEASE and Later)
With later versions of FreeBSD, you can use the
above method or you can set
mta_start_script="filename"
in /etc/rc.conf, where
filename is the name of some
script that you want executed at boot to start your
MTA.
Replacing sendmail as
the System's Default Mailer
The program sendmail is so ubiquitous
as standard software on &unix; systems that some software
just assumes it is already installed and configured.
For this reason, many alternative MTA's provide their own compatible
implementations of the sendmail
command-line interface; this facilitates using them as
drop-in
replacements for sendmail.
Therefore, if you are using an alternative mailer,
you will need to make sure that software trying to execute
standard sendmail binaries such as
/usr/bin/sendmail actually executes
your chosen mailer instead. Fortunately, FreeBSD provides
a system called &man.mailwrapper.8; that does this job for
you.
When sendmail is operating as installed, you will
find something like the following
in /etc/mail/mailer.conf:
sendmail /usr/libexec/sendmail/sendmail
send-mail /usr/libexec/sendmail/sendmail
mailq /usr/libexec/sendmail/sendmail
newaliases /usr/libexec/sendmail/sendmail
hoststat /usr/libexec/sendmail/sendmail
purgestat /usr/libexec/sendmail/sendmail
This means that when any of these common commands
(such as sendmail itself) are run,
the system actually invokes a copy of mailwrapper named sendmail, which
checks mailer.conf and
executes /usr/libexec/sendmail/sendmail
instead. This system makes it easy to change what binaries
are actually executed when these default sendmail functions
are invoked.
Therefore if you wanted
/usr/local/supermailer/bin/sendmail-compat
to be run instead of sendmail, you could change
/etc/mail/mailer.conf to read:
sendmail /usr/local/supermailer/bin/sendmail-compat
send-mail /usr/local/supermailer/bin/sendmail-compat
mailq /usr/local/supermailer/bin/mailq-compat
newaliases /usr/local/supermailer/bin/newaliases-compat
hoststat /usr/local/supermailer/bin/hoststat-compat
purgestat /usr/local/supermailer/bin/purgestat-compat
Finishing
Once you have everything configured the way you want it, you should
either kill the sendmail processes that
you no longer need and start the processes belonging to your new
software, or simply reboot. Rebooting will also
give you the opportunity to ensure that you have correctly
configured your system to start your new MTA automatically on boot.
Troubleshooting
email
troubleshooting
Why do I have to use the FQDN for hosts on my site?
You will probably find that the host is actually in a
different domain; for example, if you are in
foo.bar.edu and you wish to reach
a host called mumble in the bar.edu domain, you will have to
refer to it by the fully-qualified domain name, mumble.bar.edu, instead of just
mumble.
Traditionally, this was allowed by BSD BIND
BIND resolvers.
However the current version of BIND
that ships with FreeBSD no longer provides default abbreviations
for non-fully qualified domain names other than the domain you
are in. So an unqualified host mumble must
either be found as mumble.foo.bar.edu, or it will be searched
for in the root domain.
This is different from the previous behavior, where the
search continued across mumble.bar.edu, and mumble.edu. Have a look at RFC 1535
for why this was considered bad practice, or even a security
hole.
As a good workaround, you can place the line:
search foo.bar.edu bar.edu
instead of the previous:
domain foo.bar.edu
into your /etc/resolv.conf. However, make
sure that the search order does not go beyond the
boundary between local and public administration
,
as RFC 1535 calls it.
sendmail says mail
loops back to myself
This is answered in the
sendmail FAQ as follows:
I'm getting these error messages:
553 MX list for domain.net points back to relay.domain.net
554 <user@domain.net>... Local configuration error
How can I solve this problem?
You have asked mail to the domain (e.g., domain.net) to be
forwarded to a specific host (in this case, relay.domain.net)
by using an MXMX record
record, but the relay machine does not recognize
itself as domain.net. Add domain.net to /etc/mail/local-host-names
[known as /etc/sendmail.cw prior to version 8.10]
(if you are using FEATURE(use_cw_file)) or add Cw domain.net
to /etc/mail/sendmail.cf.
The sendmail FAQ can be found at
and is
recommended reading if you want to do any
tweaking
of your mail setup.
How can I run a mail server on a dial-up PPP
PPP host?
You want to connect a FreeBSD box on a LAN to the
Internet. The FreeBSD box will be a mail gateway for the LAN.
The PPP connection is non-dedicated.
There are at least two ways to do this. One way is to use
UUCPUUCP.
Another way is to get a full-time Internet server to provide secondary
MXMX record
services for your domain. For example, if your company's domain is
example.com and your Internet service provider has
set example.net up to provide secondary MX services
to your domain:
example.com. MX 10 example.com.
MX 20 example.net.
Only one host should be specified as the final recipient
(add Cw example.com in
/etc/mail/sendmail.cf on example.com).
When the sending sendmail is trying to
deliver the mail it will try to connect to you (example.com) over the modem
link. It will most likely time out because you are not online.
The program sendmail will automatically deliver it to the
secondary MX site, i.e. your Internet provider (example.net). The secondary MX
site will then periodically try to connect to
your host and deliver the mail to the primary MX host (example.com).
You might want to use something like this as a login
script:
#!/bin/sh
# Put me in /usr/local/bin/pppmyisp
( sleep 60 ; /usr/sbin/sendmail -q ) &
/usr/sbin/ppp -direct pppmyisp
If you are going to create a separate login script for a
user you could use sendmail -qRexample.com
instead in the script above. This will force all mail in your
queue for example.com to be processed immediately.
A further refinement of the situation is as follows:
Message stolen from the &a.isp;.
> we provide the secondary MX for a customer. The customer connects to
> our services several times a day automatically to get the mails to
> his primary MX (We do not call his site when a mail for his domains
> arrived). Our sendmail sends the mailqueue every 30 minutes. At the
> moment he has to stay 30 minutes online to be sure that all mail is
> gone to the primary MX.
>
> Is there a command that would initiate sendmail to send all the mails
> now? The user has not root-privileges on our machine of course.
In the privacy flags
section of sendmail.cf, there is a
definition Opgoaway,restrictqrun
Remove restrictqrun to allow non-root users to start the queue processing.
You might also like to rearrange the MXs. We are the 1st MX for our
customers like this, and we have defined:
# If we are the best MX for a host, try directly instead of generating
# local config error.
OwTrue
That way a remote site will deliver straight to you, without trying
the customer connection. You then send to your customer. Only works for
hosts
, so you need to get your customer to name their mail
machine customer.com
as well as
hostname.customer.com
in the DNS. Just put an A record in
the DNS for customer.com
.
Why do I keep getting Relaying
Denied errors when sending mail from other
hosts?
In default FreeBSD installations,
sendmail is configured to only
send mail from the host it is running on. For example, if
a POP server is available, then users
will be able to check mail from school, work, or other
remote locations but they still will not be able to send
outgoing emails from outside locations. Typically, a few
moments after the attempt, an email will be sent from
MAILER-DAEMON with a
5.7 Relaying Denied error
message.
There are several ways to get around this. The most
straightforward solution is to put your ISP's address in
a relay-domains file at
/etc/mail/relay-domains. A quick way
to do this would be:
&prompt.root; echo "your.isp.example.com" > /etc/mail/relay-domains
After creating or editing this file you must restart
sendmail. This works great if
you are a server administrator and do not wish to send mail
locally, or would like to use a point and click
client/system on another machine or even another ISP. It
is also very useful if you only have one or two email
accounts set up. If there is a large number of addresses
to add, you can simply open this file in your favorite
text editor and then add the domains, one per line:
your.isp.example.com
other.isp.example.net
users-isp.example.org
www.example.org
Now any mail sent through your system, by any host in
this list (provided the user has an account on your
system), will succeed. This is a very nice way to allow
users to send mail from your system remotely without
allowing people to send SPAM through your system.
Advanced Topics
The following section covers more involved topics such as mail
configuration and setting up mail for your entire domain.
Basic Configuration
email
configuration
Out of the box, you should be able to send email to external
hosts as long as you have set up
/etc/resolv.conf or are running your own
name server. If you would like to have mail for your host
delivered to the MTA (e.g., sendmail) on your own FreeBSD host, there are two methods:
Run your own name server and have your own domain. For
example, FreeBSD.org
Get mail delivered directly to your host. This is done by
delivering mail directly to the current DNS name for your
machine. For example, example.FreeBSD.org.
SMTP
Regardless of which of the above you choose, in order to have
mail delivered directly to your host, it must have a permanent
static IP address (not a dynamic address, as with most PPP dial-up configurations). If you are behind a
firewall, it must pass SMTP traffic on to you. If you want to
receive mail directly at your host, you need to be sure of either of two
things:
- MX record
- Make sure that the (lowest-numbered) MX record in your DNS points to your
+ Make sure that the (lowest-numbered) MX recordMX record in your DNS points to your
host's IP address.
Make sure there is no MX entry in your DNS for your
host.
Either of the above will allow you to receive mail directly at
your host.
Try this:
&prompt.root; hostname
example.FreeBSD.org
&prompt.root; host example.FreeBSD.org
example.FreeBSD.org has address 204.216.27.XX
If that is what you see, mail directly to
yourlogin@example.FreeBSD.org should work without
problems (assuming sendmail is
running correctly on example.FreeBSD.org).
If instead you see something like this:
&prompt.root; host example.FreeBSD.org
example.FreeBSD.org has address 204.216.27.XX
example.FreeBSD.org mail is handled (pri=10) by hub.FreeBSD.org
All mail sent to your host (example.FreeBSD.org) will end up being
collected on hub under the same username instead
of being sent directly to your host.
The above information is handled by your DNS server. The DNS
record that carries mail routing information is the
Mail eXchange entry. If
no MX record exists, mail will be delivered directly to the host by
way of its IP address.
The MX entry for freefall.FreeBSD.org at one time looked like
this:
freefall MX 30 mail.crl.net
freefall MX 40 agora.rdrop.com
freefall MX 10 freefall.FreeBSD.org
freefall MX 20 who.cdrom.com
As you can see, freefall had many MX entries.
The lowest MX number is the host that receives mail directly if
available; if it is not accessible for some reason, the others
(sometimes called backup MXes
) accept messages
temporarily, and pass it along when a lower-numbered host becomes
available, eventually to the lowest-numbered host.
Alternate MX sites should have separate Internet connections
from your own in order to be most useful. Your ISP or another
friendly site should have no problem providing this service for
you.
Mail for Your Domain
In order to set up a mailhost
(a.k.a. mail
server) you need to have any mail sent to various workstations
directed to it. Basically, you want to claim
any
mail for any hostname in your domain (in this case *.FreeBSD.org) and divert it to your mail
server so your users can receive their mail on
the master mail server.
DNS
To make life easiest, a user account with the same
username should exist on both machines. Use
&man.adduser.8; to do this.
The mailhost you will be using must be the designated mail
exchanger for each workstation on the network. This is done in
your DNS configuration like so:
example.FreeBSD.org A 204.216.27.XX ; Workstation
MX 10 hub.FreeBSD.org ; Mailhost
This will redirect mail for the workstation to the mailhost no
matter where the A record points. The mail is sent to the MX
host.
You cannot do this yourself unless you are running a DNS
server. If you are not, or cannot run your own DNS server, talk
to your ISP or whoever provides your DNS.
If you are doing virtual email hosting, the following
information will come in handy. For this example, we
will assume you have a customer with his own domain, in this
case customer1.org, and you want
all the mail for customer1.org
sent to your mailhost, mail.myhost.com. The entry in your DNS
should look like this:
customer1.org MX 10 mail.myhost.com
You do not need an A record for customer1.org if you only
want to handle email for that domain.
Be aware that pinging customer1.org will not work unless
an A record exists for it.
The last thing that you must do is tell
sendmail on your mailhost what domains
and/or hostnames it should be accepting mail for. There are a few
different ways this can be done. Either of the following will
work:
Add the hosts to your
/etc/mail/local-host-names file if you are using the
FEATURE(use_cw_file). If you are using
a version of sendmail earlier than 8.10, the file is
/etc/sendmail.cw.
Add a Cwyour.host.com line to your
/etc/sendmail.cf or
/etc/mail/sendmail.cf if you are using
sendmail 8.10 or higher.
SMTP with UUCP
The sendmail configuration that ships with FreeBSD is
designed for sites that connect directly to the Internet. Sites
that wish to exchange their mail via UUCP must install another
sendmail configuration file.
Tweaking /etc/mail/sendmail.cf manually
is an advanced topic. sendmail version 8 generates config files
via &man.m4.1; preprocessing, where the actual configuration
occurs on a higher abstraction level. The &man.m4.1;
configuration files can be found under
/usr/share/sendmail/cf. The file
README in the cf
directory can serve as a basic introduction to &man.m4.1;
configuration.
The best way to support UUCP delivery is to use the
mailertable feature. This creates a database
that sendmail can use to make routing decisions.
First, you have to create your .mc
file. The directory
/usr/share/sendmail/cf/cf contains a
few examples. Assuming you have named your file
foo.mc, all you need to do in order to
convert it into a valid sendmail.cf
is:
&prompt.root; cd /etc/mail
&prompt.root; make foo.cf
&prompt.root; cp foo.cf /etc/mail/sendmail.cf
A typical .mc file might look
like:
VERSIONID(`Your version number') OSTYPE(bsd4.4)
FEATURE(accept_unresolvable_domains)
FEATURE(nocanonify)
FEATURE(mailertable, `hash -o /etc/mail/mailertable')
define(`UUCP_RELAY', your.uucp.relay)
define(`UUCP_MAX_SIZE', 200000)
define(`confDONT_PROBE_INTERFACES')
MAILER(local)
MAILER(smtp)
MAILER(uucp)
Cw your.alias.host.name
Cw youruucpnodename.UUCP
The lines containing
accept_unresolvable_domains,
nocanonify, and
confDONT_PROBE_INTERFACES features will
prevent any usage of the DNS during mail delivery. The
UUCP_RELAY clause is needed to support UUCP
delivery. Simply put an Internet hostname there that is able to
handle .UUCP pseudo-domain addresses; most likely, you will
enter the mail relay of your ISP there.
Once you have this, you need an
/etc/mail/mailertable file. If you have
only one link to the outside that is used for all your mails,
the following file will suffice:
#
# makemap hash /etc/mail/mailertable.db < /etc/mail/mailertable
. uucp-dom:your.uucp.relay
A more complex example might look like this:
#
# makemap hash /etc/mail/mailertable.db < /etc/mail/mailertable
#
horus.interface-business.de uucp-dom:horus
.interface-business.de uucp-dom:if-bus
interface-business.de uucp-dom:if-bus
.heep.sax.de smtp8:%1
horus.UUCP uucp-dom:horus
if-bus.UUCP uucp-dom:if-bus
. uucp-dom:
The first three lines handle special cases where
domain-addressed mail should not be sent out to the default
route, but instead to some UUCP neighbor in order to
shortcut
the delivery path. The next line handles
mail to the local Ethernet domain that can be delivered using
SMTP. Finally, the UUCP neighbors are mentioned in the .UUCP
pseudo-domain notation, to allow for a
uucp-neighbor
!recipient
override of the default rules. The last line is always a single
dot, matching everything else, with UUCP delivery to a UUCP
neighbor that serves as your universal mail gateway to the
world. All of the node names behind the
uucp-dom: keyword must be valid UUCP
neighbors, as you can verify using the command
uuname.
As a reminder that this file needs to be converted into a
DBM database file before use. The command line to accomplish
this is best placed as a comment at the top of the mailertable file.
You always have to execute this command each time you change
your mailertable file.
Final hint: if you are uncertain whether some particular
mail routing would work, remember the
option to sendmail. It starts sendmail in address test
mode; simply enter 3,0, followed
by the address you wish to test for the mail routing. The last
line tells you the used internal mail agent, the destination
host this agent will be called with, and the (possibly
translated) address. Leave this mode by typing CtrlD.
&prompt.user; sendmail -bt
ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
Enter <ruleset> <address>
> 3,0 foo@example.com
canonify input: foo @ example . com
...
parse returns: $# uucp-dom $@ your.uucp.relay $: foo < @ example . com . >
> ^D
Bill
Moran
Contributed by
Setting Up to Send Only
There are many instances where you may only want to send
mail through a relay. Some examples are:
Your computer is a desktop machine, but you want
to use programs such as &man.send-pr.1;. To do so, you should use
your ISP's mail relay.
The computer is a server that does not handle mail
locally, but needs to pass off all mail to a relay for
processing.
Just about any MTA is capable of filling
this particular niche. Unfortunately, it can be very difficult
to properly configure a full-featured MTA
just to handle offloading mail. Programs such as
sendmail and
postfix are largely overkill for
this use.
Additionally, if you are using a typical Internet access
service, your agreement may forbid you from running a
mail server
.
The easiest way to fulfill those needs is to install the
mail/ssmtp port. Execute
the following commands as root:
&prompt.root; cd /usr/ports/mail/ssmtp
&prompt.root; make install replace clean
Once installed,
mail/ssmtp can be configured
with a four-line file located at
/usr/local/etc/ssmtp/ssmtp.conf:
root=yourrealemail@example.com
mailhub=mail.example.com
rewriteDomain=example.com
hostname=_HOSTNAME_
Make sure you use your real email address for
root. Enter your ISP's outgoing mail relay
in place of mail.example.com (some ISPs call
this the outgoing mail server
or
SMTP server
).
Make sure you disable sendmail,
including the outgoing mail service. See
for details.
mail/ssmtp has some
other options available. See the example configuration file in
/usr/local/etc/ssmtp or the manual page of
ssmtp for some examples and more
information.
Setting up ssmtp in this manner
will allow any software on your computer that needs to send
mail to function properly, while not violating your ISP's usage
policy or allowing your computer to be hijacked for spamming.
Using Mail with a Dialup Connection
If you have a static IP address, you should not need to
adjust anything from the defaults. Set your host name to your
assigned Internet name and sendmail will do the rest.
If you have a dynamically assigned IP number and use a
dialup PPP connection to the Internet, you will probably have a
mailbox on your ISPs mail server. Let's assume your ISP's domain
is example.net, and that your
user name is user, you have called your
machine bsd.home, and your ISP has
told you that you may use relay.example.net as a mail relay.
In order to retrieve mail from your mailbox, you must
install a retrieval agent. The
fetchmail utility is a good choice as
it supports many different protocols. This program is available
as a package or from the Ports Collection (mail/fetchmail). Usually, your ISP will
provide POP. If you are using user PPP, you can
automatically fetch your mail when an Internet connection is
established with the following entry in
/etc/ppp/ppp.linkup:
MYADDR:
!bg su user -c fetchmail
If you are using sendmail (as
shown below) to deliver mail to non-local accounts, you probably
want to have sendmail process your
mailqueue as soon as your Internet connection is established.
To do this, put this command after the
fetchmail command in
/etc/ppp/ppp.linkup:
!bg su user -c "sendmail -q"
Assume that you have an account for
user on bsd.home. In the home directory of
user on bsd.home, create a
.fetchmailrc file:
poll example.net protocol pop3 fetchall pass MySecret
This file should not be readable by anyone except
user as it contains the password
MySecret.
In order to send mail with the correct
from: header, you must tell
sendmail to use
user@example.net rather than
user@bsd.home. You may also wish to tell
sendmail to send all mail via relay.example.net, allowing quicker mail
transmission.
The following .mc file should
suffice:
VERSIONID(`bsd.home.mc version 1.0')
OSTYPE(bsd4.4)dnl
FEATURE(nouucp)dnl
MAILER(local)dnl
MAILER(smtp)dnl
Cwlocalhost
Cwbsd.home
MASQUERADE_AS(`example.net')dnl
FEATURE(allmasquerade)dnl
FEATURE(masquerade_envelope)dnl
FEATURE(nocanonify)dnl
FEATURE(nodns)dnl
define(`SMART_HOST', `relay.example.net')
Dmbsd.home
define(`confDOMAIN_NAME',`bsd.home')dnl
define(`confDELIVERY_MODE',`deferred')dnl
Refer to the previous section for details of how to turn
this .mc file into a
sendmail.cf file. Also, do not forget to
restart sendmail after updating
sendmail.cf.
James
Gorham
Written by
SMTP Authentication
Having SMTP Authentication in place on
your mail server has a number of benefits.
SMTP Authentication can add another layer
of security to sendmail, and has the benefit of giving mobile
users who switch hosts the ability to use the same mail server
without the need to reconfigure their mail client settings
each time.
Install security/cyrus-sasl2
from the ports. You can find this port in
security/cyrus-sasl2. The
security/cyrus-sasl2 port
supports a number of compile-time options. For the SMTP
Authentication method we will be using here, make sure that
the option is not disabled.
After installing security/cyrus-sasl2,
edit /usr/local/lib/sasl2/Sendmail.conf
(or create it if it does not exist) and add the following
line:
pwcheck_method: saslauthd
Next, install security/cyrus-sasl2-saslauthd,
edit /etc/rc.conf to add the following
line:
saslauthd_enable="YES"
and finally start the saslauthd daemon:
&prompt.root; /usr/local/etc/rc.d/saslauthd start
This daemon serves as a broker for sendmail to
authenticate against your FreeBSD passwd
database. This saves the trouble of creating a new set of usernames
and passwords for each user that needs to use
SMTP authentication, and keeps the login
and mail password the same.
Now edit /etc/make.conf and add the
following lines:
SENDMAIL_CFLAGS=-I/usr/local/include/sasl -DSASL
SENDMAIL_LDFLAGS=-L/usr/local/lib
SENDMAIL_LDADD=-lsasl2
These lines will give sendmail
the proper configuration options for linking
to cyrus-sasl2 at compile time.
Make sure that cyrus-sasl2
has been installed before recompiling
sendmail.
Recompile sendmail by executing the following commands:
&prompt.root; cd /usr/src/lib/libsmutil
&prompt.root; make cleandir && make obj && make
&prompt.root; cd /usr/src/lib/libsm
&prompt.root; make cleandir && make obj && make
&prompt.root; cd /usr/src/usr.sbin/sendmail
&prompt.root; make cleandir && make obj && make && make install
The compile of sendmail should not have any problems
if /usr/src has not been changed extensively
and the shared libraries it needs are available.
After sendmail has been compiled
and reinstalled, edit your /etc/mail/freebsd.mc
file (or whichever file you use as your .mc file. Many administrators
choose to use the output from &man.hostname.1; as the .mc file for
uniqueness). Add these lines to it:
dnl set SASL options
TRUST_AUTH_MECH(`GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN')dnl
define(`confAUTH_MECHANISMS', `GSSAPI DIGEST-MD5 CRAM-MD5 LOGIN')dnl
These options configure the different methods available to
sendmail for authenticating users.
If you would like to use a method other than
pwcheck, please see the
included documentation.
Finally, run &man.make.1; while in /etc/mail.
That will run your new .mc file and create a .cf file named
freebsd.cf (or whatever name you have used
for your .mc file). Then use the
command make install restart, which will
copy the file to sendmail.cf, and will
properly restart sendmail.
For more information about this process, you should refer
to /etc/mail/Makefile.
If all has gone correctly, you should be able to enter your login
information into the mail client and send a test message.
For further investigation, set the of
sendmail to 13 and watch
/var/log/maillog for any errors.
For more information, please see the sendmail
page regarding
SMTP authentication.
Marc
Silver
Contributed by
Mail User Agents
Mail User Agents
A Mail User Agent (MUA) is an application
that is used to send and receive email. Furthermore, as email
evolves
and becomes more complex,
MUA's are becoming increasingly powerful in the
way they interact with email; this gives users increased
functionality and flexibility. &os; contains support for
numerous mail user agents, all of which can be easily installed
using the FreeBSD Ports Collection.
Users may choose between graphical email clients such as
evolution or
balsa, console based clients such as
mutt, pine
or mail, or the web interfaces used by some
large organizations.
mail
&man.mail.1; is the default Mail User Agent
(MUA) in &os;. It is a
console based MUA that offers all the basic
functionality required to send and receive text-based email,
though it is limited in interaction abilities with attachments
and can only support local mailboxes.
Although mail does not natively support
interaction with POP or
IMAP servers, these mailboxes may be
downloaded to a local mbox file using an
application such as fetchmail, which
will be discussed later in this chapter ().
In order to send and receive email, simply invoke the
mail command as per the following
example:
&prompt.user; mail
The contents of the user mailbox in
/var/mail are
automatically read by the mail utility.
Should the mailbox be empty, the utility exits with a
message indicating that no mails could be found. Once the
mailbox has been read, the application interface is started, and
a list of messages will be displayed. Messages are automatically
numbered, as can be seen in the following example:
Mail version 8.1 6/6/93. Type ? for help.
"/var/mail/marcs": 3 messages 3 new
>N 1 root@localhost Mon Mar 8 14:05 14/510 "test"
N 2 root@localhost Mon Mar 8 14:05 14/509 "user account"
N 3 root@localhost Mon Mar 8 14:05 14/509 "sample"
Messages can now be read by using the t
mail command, suffixed by the message number
that should be displayed. In this example, we will read the
first email:
& t 1
Message 1:
From root@localhost Mon Mar 8 14:05:52 2004
X-Original-To: marcs@localhost
Delivered-To: marcs@localhost
To: marcs@localhost
Subject: test
Date: Mon, 8 Mar 2004 14:05:52 +0200 (SAST)
From: root@localhost (Charlie Root)
This is a test message, please reply if you receive it.
As can be seen in the example above, the t
key will cause the message to be displayed with full headers.
To display the list of messages again, the h
key should be used.
If the email requires a response, you may use
mail to reply, by using either the
R or r mail
keys. The R key instructs
mail to reply only to the sender of the
email, while r replies not only to the sender,
but also to other recipients of the message. You may also
suffix these commands with the mail number which you would like
make a reply to. Once this has been done, the response should
be entered, and the end of the message should be marked by a
single . on a new line. An example can be seen
below:
& R 1
To: root@localhost
Subject: Re: test
Thank you, I did get your email.
.
EOT
In order to send new email, the m
key should be used, followed by the
recipient email address. Multiple recipients may also be
specified by separating each address with the ,
delimiter. The subject of the message may then be entered,
followed by the message contents. The end of the message should
be specified by putting a single . on a new
line.
& mail root@localhost
Subject: I mastered mail
Now I can send and receive email using mail ... :)
.
EOT
While inside the mail utility, the
? command may be used to display help at any
time, the &man.mail.1; manual page should also be consulted for
more help with mail.
As previously mentioned, the &man.mail.1; command was not
originally designed to handle attachments, and thus deals with
them very poorly. Newer MUAs such as
mutt handle attachments in a much
more intelligent way. But should you still wish to use the
mail command, the converters/mpack port may be of
considerable use.
mutt
mutt is a small yet very
powerful Mail User Agent, with excellent features,
just some of which include:
The ability to thread messages;
PGP support for digital signing and encryption of
email;
MIME Support;
Maildir Support;
Highly customizable.
All of these features help to make
mutt one of the most advanced mail
user agents available. See for more
information on mutt.
The stable version of mutt may be
installed using the mail/mutt port, while the current
development version may be installed via the mail/mutt-devel port. After the port
has been installed, mutt can be
started by issuing the following command:
&prompt.user; mutt
mutt will automatically read the
contents of the user mailbox in /var/mail and display the contents
if applicable. If no mails are found in the user mailbox, then
mutt will wait for commands from the
user. The example below shows mutt
displaying a list of messages:
In order to read an email, simply select it using the cursor
keys, and press the Enter key. An example of
mutt displaying email can be seen
below:
As with the &man.mail.1; command,
mutt allows users to reply only to
the sender of the message as well as to all recipients. To
reply only to the sender of the email, use the
r keyboard shortcut. To send a group reply,
which will be sent to the original sender as well as all the
message recipients, use the g shortcut.
mutt makes use of the
&man.vi.1; command as an editor for creating and replying to
emails. This may be customized by the user by creating or
editing their own .muttrc file in their home directory and setting the
editor variable or by setting the
EDITOR environment variable. See
for more
information about configuring
mutt.
In order to compose a new mail message, press
m. After a valid subject has been given,
mutt will start &man.vi.1; and the
mail can be written. Once the contents of the mail are
complete, save and quit from vi and
mutt will resume, displaying a
summary screen of the mail that is to be delivered. In order to
send the mail, press y. An example of the
summary screen can be seen below:
mutt also contains extensive
help, which can be accessed from most of the menus by pressing
the ? key. The top line also displays the
keyboard shortcuts where appropriate.
pine
pine is aimed at a beginner
user, but also includes some advanced features.
The pine software has had several remote vulnerabilities
discovered in the past, which allowed remote attackers to
execute arbitrary code as users on the local system, by the
action of sending a specially-prepared email. All such
known problems have been fixed, but the
pine code is written in a very insecure style and the &os;
Security Officer believes there are likely to be other
undiscovered vulnerabilities. You install
pine at your own risk.
The current version of pine may
be installed using the mail/pine4 port. Once the port has
installed, pine can be started by
issuing the following command:
&prompt.user; pine
The first time that pine is run
it displays a greeting page with a brief introduction, as well
as a request from the pine
development team to send an anonymous email message allowing
them to judge how many users are using their client. To send
this anonymous message, press Enter, or
alternatively press E to exit the greeting
without sending an anonymous message. An example of the
greeting page can be seen below:
Users are then presented with the main menu, which can be
easily navigated using the cursor keys. This main menu provides
shortcuts for the composing new mails, browsing of mail directories,
and even the administration of address book entries. Below the
main menu, relevant keyboard shortcuts to perform functions
specific to the task at hand are shown.
The default directory opened by pine
is the inbox. To view the message index, press
I, or select the MESSAGE INDEX
option as seen below:
The message index shows messages in the current directory,
and can be navigated by using the cursor keys. Highlighted
messages can be read by pressing the
Enter key.
In the screenshot below, a sample message is displayed by
pine. Keyboard shortcuts are
displayed as a reference at the bottom of the screen. An
example of one of these shortcuts is the r key,
which tells the MUA to reply to the current
message being displayed.
Replying to an email in pine is
done using the pico editor, which is
installed by default with pine.
The pico utility makes it easy to
navigate around the message and is slightly more forgiving on
novice users than &man.vi.1; or &man.mail.1;. Once the reply
is complete, the message can be sent by pressing
CtrlX
. The pine application
will ask for confirmation.
The pine application can be
customized using the SETUP option from the main
menu. Consult
for more information.
Marc
Silver
Contributed by
Using fetchmail
fetchmail
fetchmail is a full-featured
IMAP and POP client which
allows users to automatically download mail from remote
IMAP and POP servers and
save it into local mailboxes; there it can be accessed more easily.
fetchmail can be installed using the
mail/fetchmail port, and
offers various features, some of which include:
Support of POP3,
APOP, KPOP,
IMAP, ETRN and
ODMR protocols.
Ability to forward mail using SMTP, which
allows filtering, forwarding, and aliasing to function
normally.
May be run in daemon mode to check periodically for new
messages.
Can retrieve multiple mailboxes and forward them based
on configuration, to different local users.
While it is outside the scope of this document to explain
all of fetchmail's features, some
basic features will be explained. The
fetchmail utility requires a
configuration file known as .fetchmailrc,
in order to run correctly. This file includes server information
as well as login credentials. Due to the sensitive nature of the
contents of this file, it is advisable to make it readable only by the owner,
with the following command:
&prompt.user; chmod 600 .fetchmailrc
The following .fetchmailrc serves as an
example for downloading a single user mailbox using
POP. It tells
fetchmail to connect to example.com using a username of
joesoap and a password of
XXX. This example assumes that the user
joesoap is also a user on the local
system.
poll example.com protocol pop3 username "joesoap" password "XXX"
The next example connects to multiple POP
and IMAP servers and redirects to different
local usernames where applicable:
poll example.com proto pop3:
user "joesoap", with password "XXX", is "jsoap" here;
user "andrea", with password "XXXX";
poll example2.net proto imap:
user "john", with password "XXXXX", is "myth" here;
The fetchmail utility can be run in daemon
mode by running it with the flag, followed
by the interval (in seconds) that
fetchmail should poll servers listed
in the .fetchmailrc file. The following
example would cause fetchmail to poll
every 600 seconds:
&prompt.user; fetchmail -d 600
More information on fetchmail can
be found at .
Marc
Silver
Contributed by
Using procmail
procmail
The procmail utility is an
incredibly powerful application used to filter incoming mail.
It allows users to define rules
which can be
matched to incoming mails to perform specific functions or to
reroute mail to alternative mailboxes and/or email addresses.
procmail can be installed using the
mail/procmail port. Once
installed, it can be directly integrated into most
MTAs; consult your MTA
documentation for more information. Alternatively,
procmail can be integrated by adding
the following line to a .forward in the home
directory of the user utilizing
procmail features:
"|exec /usr/local/bin/procmail || exit 75"
The following section will display some basic
procmail rules, as well as brief
descriptions on what they do. These rules, and others must be
inserted into a .procmailrc file, which
must reside in the user's home directory.
The majority of these rules can also be found in the
&man.procmailex.5; manual page.
Forward all mail from user@example.com to an
external address of goodmail@example2.com:
:0
* ^From.*user@example.com
! goodmail@example2.com
Forward all mails shorter than 1000 bytes to an external
address of goodmail@example2.com:
:0
* < 1000
! goodmail@example2.com
Send all mail sent to alternate@example.com
into a mailbox called alternate:
:0
* ^TOalternate@example.com
alternate
Send all mail with a subject of Spam
to
/dev/null:
:0
^Subject:.*Spam
/dev/null
A useful recipe that parses incoming &os;.org mailing lists
and places each list in its own mailbox:
:0
* ^Sender:.owner-freebsd-\/[^@]+@FreeBSD.ORG
{
LISTNAME=${MATCH}
:0
* LISTNAME??^\/[^@]+
FreeBSD-${MATCH}
}
diff --git a/zh_TW.Big5/books/handbook/network-servers/chapter.xml b/zh_TW.Big5/books/handbook/network-servers/chapter.xml
index 92a98f24de..5588e07fc1 100644
--- a/zh_TW.Big5/books/handbook/network-servers/chapter.xml
+++ b/zh_TW.Big5/books/handbook/network-servers/chapter.xml
@@ -1,5202 +1,5185 @@
Murray
Stokely
Reorganized by
Network Servers
·§z
This chapter will cover some of the more frequently used
network services on &unix; systems. We will cover how to
install, configure, test, and maintain many different types of
network services. Example configuration files are included
throughout this chapter for you to benefit from.
After reading this chapter, you will know:
How to manage the inetd
daemon.
How to set up a network file system.
How to set up a network information server for sharing
user accounts.
How to set up automatic network settings using DHCP.
How to set up a domain name server.
How to set up the Apache HTTP Server.
How to set up a File Transfer Protocol (FTP) Server.
How to set up a file and print server for &windows;
clients using Samba.
How to synchronize the time and date, and set up a
time server, with the NTP protocol.
Before reading this chapter, you should:
Understand the basics of the
/etc/rc scripts.
Be familiar with basic network terminology.
Know how to install additional third-party
software ().
Chern
Lee
Contributed by
The inetd Super-Server
Overview
&man.inetd.8; is referred to as the Internet
Super-Server
because it manages connections for
several services. When a
connection is received by inetd, it
determines which program the connection is destined for, spawns
the particular process and delegates the socket to it (the program
is invoked with the service socket as its standard input, output
and error descriptors). Running
one instance of inetd reduces the
overall system load as compared to running each daemon
individually in stand-alone mode.
Primarily, inetd is used to
spawn other daemons, but several trivial protocols are handled
directly, such as chargen,
auth, and
daytime.
This section will cover the basics in configuring
inetd through its command-line
options and its configuration file,
/etc/inetd.conf.
Settings
inetd is initialized through
the /etc/rc.conf system. The
inetd_enable option is set to
NO by default, but is often times turned on
by sysinstall with the medium
security profile. Placing:
inetd_enable="YES" or
inetd_enable="NO" into
/etc/rc.conf can enable or disable
inetd starting at boot time.
Additionally, different command-line options can be passed
to inetd via the
inetd_flags option.
Command-Line Options
inetd synopsis:
-d
Turn on debugging.
-l
Turn on logging of successful connections.
-w
Turn on TCP Wrapping for external services (on by
default).
-W
Turn on TCP Wrapping for internal services which are
built into inetd (on by
default).
-c maximum
Specify the default maximum number of simultaneous
invocations of each service; the default is unlimited.
May be overridden on a per-service basis with the
parameter.
-C rate
Specify the default maximum number of times a
service can be invoked from a single IP address in one
minute; the default is unlimited. May be overridden on a
per-service basis with the
parameter.
-R rate
Specify the maximum number of times a service can be
invoked in one minute; the default is 256. A rate of 0
allows an unlimited number of invocations.
-a
Specify one specific IP address to bind to.
Alternatively, a hostname can be specified, in which case
the IPv4 or IPv6 address which corresponds to that
hostname is used. Usually a hostname is specified when
inetd is run inside a
&man.jail.8;, in which case the hostname corresponds to
the &man.jail.8; environment.
When hostname specification is used and both IPv4
and IPv6 bindings are desired, one entry with the
appropriate protocol type for each binding is required
for each service in
/etc/inetd.conf. For example, a
TCP-based service would need two entries, one using
tcp4 for the protocol and the other
using tcp6.
-p
Specify an alternate file in which to store the
process ID.
These options can be passed to
inetd using the
inetd_flags option in
/etc/rc.conf. By default,
inetd_flags is set to
-wW, which turns on TCP wrapping for
inetd's internal and external
services. For novice users, these parameters usually do not
need to be modified or even entered in
/etc/rc.conf.
An external service is a daemon outside of
inetd, which is invoked when a
connection is received for it. On the other hand, an
internal service is one that
inetd has the facility of
offering within itself.
inetd.conf
Configuration of inetd is
controlled through the /etc/inetd.conf
file.
When a modification is made to
/etc/inetd.conf,
inetd can be forced to re-read its
configuration file by sending a HangUP signal to the
inetd process as shown:
Sending inetd a HangUP Signal
&prompt.root; kill -HUP `cat /var/run/inetd.pid`
Each line of the configuration file specifies an
individual daemon. Comments in the file are preceded by a
#
. The format of
/etc/inetd.conf is as follows:
service-name
socket-type
protocol
{wait|nowait}[/max-child[/max-connections-per-ip-per-minute]]
user[:group][/login-class]
server-program
server-program-arguments
An example entry for the ftpd daemon
using IPv4:
ftp stream tcp nowait root /usr/libexec/ftpd ftpd -l
service-name
This is the service name of the particular daemon.
It must correspond to a service listed in
/etc/services. This determines
which port inetd must listen
to. If a new service is being created, it must be
placed in /etc/services
first.
socket-type
Either stream,
dgram, raw, or
seqpacket. stream
must be used for connection-based, TCP daemons, while
dgram is used for daemons utilizing
the UDP transport protocol.
protocol
One of the following:
Protocol
Explanation
tcp, tcp4
TCP IPv4
udp, udp4
UDP IPv4
tcp6
TCP IPv6
udp6
UDP IPv6
tcp46
Both TCP IPv4 and v6
udp46
Both UDP IPv4 and v6
{wait|nowait}[/max-child[/max-connections-per-ip-per-minute]]
indicates whether the
daemon invoked from inetd is
able to handle its own socket or not.
socket types must use the
option, while stream socket
daemons, which are usually multi-threaded, should use
. usually
hands off multiple sockets to a single daemon, while
spawns a child daemon for each
new socket.
The maximum number of child daemons
inetd may spawn can be set
using the option. If a limit
of ten instances of a particular daemon is needed, a
/10 would be placed after
.
In addition to , another
option limiting the maximum connections from a single
place to a particular daemon can be enabled.
does
just this. A value of ten here would limit any particular
IP address connecting to a particular service to ten
attempts per minute. This is useful to prevent
intentional or unintentional resource consumption and
Denial of Service (DoS) attacks to a machine.
In this field, or
is mandatory.
and
are
optional.
A stream-type multi-threaded daemon without any
or
limits
would simply be: nowait.
The same daemon with a maximum limit of ten daemons
would read: nowait/10.
Additionally, the same setup with a limit of twenty
connections per IP address per minute and a maximum
total limit of ten child daemons would read:
nowait/10/20.
These options are all utilized by the default
settings of the fingerd daemon,
as seen here:
finger stream tcp nowait/3/10 nobody /usr/libexec/fingerd fingerd -s
user
This is the username that the particular daemon
should run as. Most commonly, daemons run as the
root user. For security purposes, it is
common to find some servers running as the
daemon user, or the least privileged
nobody user.
server-program
The full path of the daemon to be executed when a
connection is received. If the daemon is a service
provided by inetd internally,
then should be
used.
server-program-arguments
This works in conjunction with
by specifying the
arguments, starting with argv[0],
passed to the daemon on invocation. If
mydaemon -d is the command line,
mydaemon -d would be the value of
. Again, if
the daemon is an internal service, use
here.
Security
Depending on the security profile chosen at install, many
of inetd's daemons may be enabled
by default. If there is no apparent need for a particular
daemon, disable it! Place a #
in front of the
daemon in question in /etc/inetd.conf,
and then send a hangup
signal to inetd. Some daemons, such as
fingerd, may not be desired at all
because they provide an attacker with too much
information.
Some daemons are not security-conscious and have long, or
non-existent timeouts for connection attempts. This allows an
attacker to slowly send connections to a particular daemon,
thus saturating available resources. It may be a good idea to
place and
limitations on certain
daemons.
By default, TCP wrapping is turned on. Consult the
&man.hosts.access.5; manual page for more information on placing
TCP restrictions on various inetd
invoked daemons.
Miscellaneous
daytime,
time,
echo,
discard,
chargen, and
auth are all internally provided
services of inetd.
The auth service provides
identity (ident,
identd) network services, and is
configurable to a certain degree.
Consult the &man.inetd.8; manual page for more in-depth
information.
Tom
Rhodes
Reorganized and enhanced by
Bill
Swingle
Written by
Network File System (NFS)
NFS
Among the many different file systems that FreeBSD supports
is the Network File System, also known as NFS. NFS allows a system to share directories and
files with others over a network. By using NFS, users and programs can
access files on remote systems almost as if they were local
files.
Some of the most notable benefits that
NFS can provide are:
Local workstations use less disk space because commonly
used data can be stored on a single machine and still remain
accessible to others over the network.
There is no need for users to have separate home
directories on every network machine. Home directories
could be set up on the NFS server and
made available throughout the network.
Storage devices such as floppy disks, CDROM drives, and
&iomegazip; drives can be used by other machines on the network.
This may reduce the number of removable media drives
throughout the network.
How NFS Works
NFS consists of at least two main
parts: a server and one or more clients. The client remotely
accesses the data that is stored on the server machine. In
order for this to function properly a few processes have to be
configured and running.
Under &os; 4.X, the portmap
utility is used in place of the
rpcbind utility. Thus, in &os; 4.X
the user is required to replace every instance of
rpcbind with
portmap in the forthcoming
examples.
The server has to be running the following daemons:
NFS
server
file server
UNIX clients
rpcbind
portmap
mountd
nfsd
Daemon
Description
nfsd
The NFS daemon which services
requests from the NFS
clients.
mountd
The NFS mount daemon which carries out
the requests that &man.nfsd.8; passes on to it.
rpcbind
This daemon allows
NFS clients to discover which port
the NFS server is using.
The client can also run a daemon, known as
nfsiod. The
nfsiod daemon services the requests
from the NFS server. This is optional, and
improves performance, but is not required for normal and
correct operation. See the &man.nfsiod.8; manual page for
more information.
Configuring NFS
NFS
configuration
NFS configuration is a relatively
straightforward process. The processes that need to be
running can all start at boot time with a few modifications to
your /etc/rc.conf file.
On the NFS server, make sure that the
following options are configured in the
/etc/rc.conf file:
rpcbind_enable="YES"
nfs_server_enable="YES"
mountd_flags="-r"
mountd runs automatically
whenever the NFS server is enabled.
On the client, make sure this option is present in
/etc/rc.conf:
nfs_client_enable="YES"
The /etc/exports file specifies which
file systems NFS should export (sometimes
referred to as share
). Each line in
/etc/exports specifies a file system to be
exported and which machines have access to that file system.
Along with what machines have access to that file system,
access options may also be specified. There are many such
options that can be used in this file but only a few will be
mentioned here. You can easily discover other options by
reading over the &man.exports.5; manual page.
Here are a few example /etc/exports
entries:
NFS
export examples
The following examples give an idea of how to export
file systems, although the settings may be different depending
on your environment and network configuration. For instance,
to export the /cdrom directory to three
example machines that have the same domain name as the server
(hence the lack of a domain name for each) or have entries in
your /etc/hosts file. The
flag makes the exported file system
read-only. With this flag, the remote system will not be able
to write any changes to the exported file system.
/cdrom -ro host1 host2 host3
The following line exports /home to
three hosts by IP address. This is a useful setup if you have
a private network without a DNS server
configured. Optionally the /etc/hosts
file could be configured for internal hostnames; please review
&man.hosts.5; for more information. The
flag allows the subdirectories to be
mount points. In other words, it will not mount the
subdirectories but permit the client to mount only the
directories that are required or needed.
/home -alldirs 10.0.0.2 10.0.0.3 10.0.0.4
The following line exports /a so that
two clients from different domains may access the file system.
The flag allows the
root user on the remote system to write
data on the exported file system as root.
If the -maproot=root flag is not specified,
then even if a user has root access on
the remote system, he will not be able to modify files on
the exported file system.
/a -maproot=root host.example.com box.example.org
In order for a client to access an exported file system,
the client must have permission to do so. Make sure the
client is listed in your /etc/exports
file.
In /etc/exports, each line represents
the export information for one file system to one host. A
remote host can only be specified once per file system, and may
only have one default entry. For example, assume that
/usr is a single file system. The
following /etc/exports would be
invalid:
# Invalid when /usr is one file system
/usr/src client
/usr/ports client
One file system, /usr, has two lines
specifying exports to the same host, client.
The correct format for this situation is:
/usr/src /usr/ports client
The properties of one file system exported to a given host
must all occur on one line. Lines without a client specified
are treated as a single host. This limits how you can export
file systems, but for most people this is not an issue.
The following is an example of a valid export list, where
/usr and /exports
are local file systems:
# Export src and ports to client01 and client02, but only
# client01 has root privileges on it
/usr/src /usr/ports -maproot=root client01
/usr/src /usr/ports client02
# The client machines have root and can mount anywhere
# on /exports. Anyone in the world can mount /exports/obj read-only
/exports -alldirs -maproot=root client01 client02
/exports/obj -ro
You must restart
mountd whenever you modify
/etc/exports so the changes can take effect.
This can be accomplished by sending the HUP signal
to the mountd process:
&prompt.root; kill -HUP `cat /var/run/mountd.pid`
Alternatively, a reboot will make FreeBSD set everything
up properly. A reboot is not necessary though.
Executing the following commands as root
should start everything up.
On the NFS server:
&prompt.root; rpcbind
&prompt.root; nfsd -u -t -n 4
&prompt.root; mountd -r
On the NFS client:
&prompt.root; nfsiod -n 4
Now everything should be ready to actually mount a remote file
system. In these examples the
server's name will be server and the client's
name will be client. If you only want to
temporarily mount a remote file system or would rather test the
configuration, just execute a command like this as root on the
client:
NFS
mounting
&prompt.root; mount server:/home /mnt
This will mount the /home directory
on the server at /mnt on the client. If
everything is set up correctly you should be able to enter
/mnt on the client and see all the files
that are on the server.
If you want to automatically mount a remote file system
each time the computer boots, add the file system to the
/etc/fstab file. Here is an example:
server:/home /mnt nfs rw 0 0
The &man.fstab.5; manual page lists all the available
options.
Practical Uses
NFS has many practical uses. Some of
the more common ones are listed below:
NFS
uses
Set several machines to share a CDROM or other media
among them. This is cheaper and often a more convenient
method to install software on multiple machines.
On large networks, it might be more convenient to
configure a central NFS server in which
to store all the user home directories. These home
directories can then be exported to the network so that
users would always have the same home directory,
regardless of which workstation they log in to.
Several machines could have a common
/usr/ports/distfiles directory. That
way, when you need to install a port on several machines,
you can quickly access the source without downloading it
on each machine.
Wylie
Stilwell
Contributed by
Chern
Lee
Rewritten by
Automatic Mounts with amd
amd
automatic mounter daemon
&man.amd.8; (the automatic mounter daemon)
automatically mounts a
remote file system whenever a file or directory within that
file system is accessed. Filesystems that are inactive for a
period of time will also be automatically unmounted by
amd. Using
amd provides a simple alternative
to permanent mounts, as permanent mounts are usually listed in
/etc/fstab.
amd operates by attaching
itself as an NFS server to the /host and
/net directories. When a file is accessed
within one of these directories, amd
looks up the corresponding remote mount and automatically mounts
it. /net is used to mount an exported
file system from an IP address, while /host
is used to mount an export from a remote hostname.
An access to a file within
/host/foobar/usr would tell
amd to attempt to mount the
/usr export on the host
foobar.
Mounting an Export with amd
You can view the available mounts of a remote host with
the showmount command. For example, to
view the mounts of a host named foobar, you
can use:
&prompt.user; showmount -e foobar
Exports list on foobar:
/usr 10.10.10.0
/a 10.10.10.0
&prompt.user; cd /host/foobar/usr
As seen in the example, the showmount shows
/usr as an export. When changing directories to
/host/foobar/usr, amd
attempts to resolve the hostname foobar and
automatically mount the desired export.
amd can be started by the
startup scripts by placing the following lines in
/etc/rc.conf:
amd_enable="YES"
Additionally, custom flags can be passed to
amd from the
amd_flags option. By default,
amd_flags is set to:
amd_flags="-a /.amd_mnt -l syslog /host /etc/amd.map /net /etc/amd.map"
The /etc/amd.map file defines the
default options that exports are mounted with. The
/etc/amd.conf file defines some of the more
advanced features of amd.
Consult the &man.amd.8; and &man.amd.conf.5; manual pages for more
information.
John
Lind
Contributed by
Problems Integrating with Other Systems
Certain Ethernet adapters for ISA PC systems have limitations
which can lead to serious network problems, particularly with NFS.
This difficulty is not specific to FreeBSD, but FreeBSD systems
are affected by it.
The problem nearly always occurs when (FreeBSD) PC systems are
networked with high-performance workstations, such as those made
by Silicon Graphics, Inc., and Sun Microsystems, Inc. The NFS
mount will work fine, and some operations may succeed, but
suddenly the server will seem to become unresponsive to the
client, even though requests to and from other systems continue to
be processed. This happens to the client system, whether the
client is the FreeBSD system or the workstation. On many systems,
there is no way to shut down the client gracefully once this
problem has manifested itself. The only solution is often to
reset the client, because the NFS situation cannot be
resolved.
Though the correct
solution is to get a
higher performance and capacity Ethernet adapter for the
FreeBSD system, there is a simple workaround that will allow
satisfactory operation. If the FreeBSD system is the
server, include the option
on the mount from the client. If the
FreeBSD system is the client, then mount
the NFS file system with the option .
These options may be specified using the fourth field of the
fstab entry on the client for automatic
mounts, or by using the parameter of the
&man.mount.8; command for manual mounts.
It should be noted that there is a different problem,
sometimes mistaken for this one, when the NFS servers and
clients are on different networks. If that is the case, make
certain that your routers are routing the
necessary UDP information, or you will not get anywhere, no
matter what else you are doing.
In the following examples, fastws is the host
(interface) name of a high-performance workstation, and
freebox is the host (interface) name of a FreeBSD
system with a lower-performance Ethernet adapter. Also,
/sharedfs will be the exported NFS
file system (see &man.exports.5;), and
/project will be the mount point on the
client for the exported file system. In all cases, note that
additional options, such as or
and may be desirable in
your application.
Examples for the FreeBSD system (freebox)
as the client in /etc/fstab on
freebox:
fastws:/sharedfs /project nfs rw,-r=1024 0 0
As a manual mount command on freebox:
&prompt.root; mount -t nfs -o -r=1024 fastws:/sharedfs /project
Examples for the FreeBSD system as the server in
/etc/fstab on
fastws:
freebox:/sharedfs /project nfs rw,-w=1024 0 0
As a manual mount command on fastws:
&prompt.root; mount -t nfs -o -w=1024 freebox:/sharedfs /project
Nearly any 16-bit Ethernet adapter will allow operation
without the above restrictions on the read or write size.
For anyone who cares, here is what happens when the
failure occurs, which also explains why it is unrecoverable.
NFS typically works with a block
size of
8 K (though it may do fragments of smaller sizes). Since
the maximum Ethernet packet is around 1500 bytes, the NFS
block
gets split into multiple Ethernet
packets, even though it is still a single unit to the
upper-level code, and must be received, assembled, and
acknowledged as a unit. The
high-performance workstations can pump out the packets which
comprise the NFS unit one right after the other, just as close
together as the standard allows. On the smaller, lower
capacity cards, the later packets overrun the earlier packets
of the same unit before they can be transferred to the host
and the unit as a whole cannot be reconstructed or
acknowledged. As a result, the workstation will time out and
try again, but it will try again with the entire 8 K
unit, and the process will be repeated, ad infinitum.
By keeping the unit size below the Ethernet packet size
limitation, we ensure that any complete Ethernet packet
received can be acknowledged individually, avoiding the
deadlock situation.
Overruns may still occur when a high-performance
workstations is slamming data out to a PC system, but with the
better cards, such overruns are not guaranteed on NFS
units
. When an overrun occurs, the units
affected will be retransmitted, and there will be a fair
chance that they will be received, assembled, and
acknowledged.
Bill
Swingle
Written by
Eric
Ogren
Enhanced by
Udo
Erdelhoff
Network Information System (NIS/YP)
What Is It?
NIS
Solaris
HP-UX
AIX
Linux
NetBSD
OpenBSD
NIS,
which stands for Network Information Services, was developed
by Sun Microsystems to centralize administration of &unix;
(originally &sunos;) systems. It has now essentially become
an industry standard; all major &unix; like systems
(&solaris;, HP-UX, &aix;, Linux, NetBSD, OpenBSD, FreeBSD,
etc) support NIS.
yellow pagesNIS
NIS
was formerly known as Yellow Pages, but because of trademark
issues, Sun changed the name. The old term (and yp) is still
often seen and used.
NIS
domains
It is a RPC-based client/server system that allows a group
of machines within an NIS domain to share a common set of
configuration files. This permits a system administrator to
set up NIS client systems with only minimal configuration data
and add, remove or modify configuration data from a single
location.
Windows NT
It is similar to the &windowsnt; domain system; although
the internal implementation of the two are not at all similar,
the basic functionality can be compared.
Terms/Processes You Should Know
There are several terms and several important user
processes that you will come across when attempting to
implement NIS on FreeBSD, whether you are trying to create an
NIS server or act as an NIS client:
rpcbind
portmap
Term
Description
NIS domainname
An NIS master server and all of its clients
(including its slave servers) have a NIS domainname.
Similar to an &windowsnt; domain name, the NIS
domainname does not have anything to do with
DNS.
rpcbind
Must be running in order to enable
RPC (Remote Procedure Call, a
network protocol used by NIS). If
rpcbind is not running, it
will be impossible to run an NIS server, or to act as
an NIS client (Under &os; 4.X
portmap is used in place of
rpcbind).
ypbind
Binds
an NIS client to its NIS
server. It will take the NIS domainname from the
system, and using RPC, connect to
the server. ypbind is the
core of client-server communication in an NIS
environment; if ypbind dies
on a client machine, it will not be able to access the
NIS server.
ypserv
Should only be running on NIS servers; this is
the NIS server process itself. If &man.ypserv.8;
dies, then the server will no longer be able to
respond to NIS requests (hopefully, there is a slave
server to take over for it). There are some
implementations of NIS (but not the FreeBSD one), that
do not try to reconnect to another server if the
server it used before dies. Often, the only thing
that helps in this case is to restart the server
process (or even the whole server) or the
ypbind process on the
client.
rpc.yppasswdd
Another process that should only be running on
NIS master servers; this is a daemon that will allow NIS
clients to change their NIS passwords. If this daemon
is not running, users will have to login to the NIS
master server and change their passwords there.
How Does It Work?
There are three types of hosts in an NIS environment:
master servers, slave servers, and clients. Servers act as a
central repository for host configuration information. Master
servers hold the authoritative copy of this information, while
slave servers mirror this information for redundancy. Clients
rely on the servers to provide this information to
them.
Information in many files can be shared in this manner.
The master.passwd,
group, and hosts
files are commonly shared via NIS. Whenever a process on a
client needs information that would normally be found in these
files locally, it makes a query to the NIS server that it is
bound to instead.
Machine Types
-
- NIS
- master server
-
- A NIS master server. This
+ A NIS master serverNISmaster server. This
server, analogous to a &windowsnt; primary domain
controller, maintains the files used by all of the NIS
clients. The passwd,
group, and other various files used
by the NIS clients live on the master server.
It is possible for one machine to be an NIS
master server for more than one NIS domain. However,
this will not be covered in this introduction, which
assumes a relatively small-scale NIS
environment.
-
- NIS
- slave server
-
-
- NIS slave servers. Similar to
+ NIS slave serversNISslave server. Similar to
the &windowsnt; backup domain controllers, NIS slave
servers maintain copies of the NIS master's data files.
NIS slave servers provide the redundancy, which is
needed in important environments. They also help to
balance the load of the master server: NIS Clients
always attach to the NIS server whose response they get
first, and this includes slave-server-replies.
-
- NIS
- client
-
-
- NIS clients. NIS clients, like
+ NIS clientsNISclient. NIS clients, like
most &windowsnt; workstations, authenticate against the
NIS server (or the &windowsnt; domain controller in the
&windowsnt; workstations case) to log on.
Using NIS/YP
This section will deal with setting up a sample NIS
environment.
This section assumes that you are running
FreeBSD 3.3 or later. The instructions given here will
probably work for any version of FreeBSD
greater than 3.0, but there are no guarantees that this is
true.
Planning
Let us assume that you are the administrator of a small
university lab. This lab, which consists of 15 FreeBSD
machines, currently has no centralized point of
administration; each machine has its own
/etc/passwd and
/etc/master.passwd. These files are
kept in sync with each other only through manual
intervention; currently, when you add a user to the lab, you
must run adduser on all 15 machines.
Clearly, this has to change, so you have decided to convert
the lab to use NIS, using two of the machines as
servers.
Therefore, the configuration of the lab now looks something
like:
Machine name
IP address
Machine role
ellington
10.0.0.2
NIS master
coltrane
10.0.0.3
NIS slave
basie
10.0.0.4
Faculty workstation
bird
10.0.0.5
Client machine
cli[1-11]
10.0.0.[6-17]
Other client machines
If you are setting up a NIS scheme for the first time, it
is a good idea to think through how you want to go about it. No
matter what the size of your network, there are a few decisions
that need to be made.
Choosing a NIS Domain Name
NIS
domainname
This might not be the domainname
that
you are used to. It is more accurately called the
NIS domainname
. When a client broadcasts
its requests for info, it includes the name of the NIS
domain that it is part of. This is how multiple servers
on one network can tell which server should answer which
request. Think of the NIS domainname as the name for a
group of hosts that are related in some way.
Some organizations choose to use their Internet
domainname for their NIS domainname. This is not
recommended as it can cause confusion when trying to debug
network problems. The NIS domainname should be unique
within your network and it is helpful if it describes the
group of machines it represents. For example, the Art
department at Acme Inc. might be in the
acme-art
NIS domain. For this example,
assume you have chosen the name
test-domain.
SunOS
However, some operating systems (notably &sunos;) use
their NIS domain name as their Internet domain name. If one
or more machines on your network have this restriction, you
must use the Internet domain name as
your NIS domain name.
Physical Server Requirements
There are several things to keep in mind when choosing
a machine to use as a NIS server. One of the unfortunate
things about NIS is the level of dependency the clients
have on the server. If a client cannot contact the server
for its NIS domain, very often the machine becomes
unusable. The lack of user and group information causes
most systems to temporarily freeze up. With this in mind
you should make sure to choose a machine that will not be
prone to being rebooted regularly, or one that might be
used for development. The NIS server should ideally be a
stand alone machine whose sole purpose in life is to be an
NIS server. If you have a network that is not very
heavily used, it is acceptable to put the NIS server on a
machine running other services, just keep in mind that if
the NIS server becomes unavailable, it will affect
all of your NIS clients
adversely.
NIS Servers
The canonical copies of all NIS information are stored
on a single machine called the NIS master server. The
databases used to store the information are called NIS maps.
In FreeBSD, these maps are stored in
/var/yp/[domainname] where
[domainname] is the name of the NIS
domain being served. A single NIS server can support
several domains at once, therefore it is possible to have
several such directories, one for each supported domain.
Each domain will have its own independent set of
maps.
NIS master and slave servers handle all NIS requests
with the ypserv daemon.
ypserv is responsible for receiving
incoming requests from NIS clients, translating the
requested domain and map name to a path to the corresponding
database file and transmitting data from the database back
to the client.
Setting Up a NIS Master Server
NIS
server configuration
Setting up a master NIS server can be relatively
straight forward, depending on your needs. FreeBSD comes
with support for NIS out-of-the-box. All you need is to
add the following lines to
/etc/rc.conf, and FreeBSD will do the
rest for you.
nisdomainname="test-domain"
This line will set the NIS domainname to
test-domain
upon network setup (e.g. after reboot).
nis_server_enable="YES"
This will tell FreeBSD to start up the NIS server processes
when the networking is next brought up.
nis_yppasswdd_enable="YES"
This will enable the rpc.yppasswdd
daemon which, as mentioned above, will allow users to
change their NIS password from a client machine.
Depending on your NIS setup, you may need to add
further entries. See the section about NIS
servers that are also NIS clients, below, for
details.
Now, all you have to do is to run the command
/etc/netstart as superuser. It will
set up everything for you, using the values you defined in
/etc/rc.conf.
Initializing the NIS Maps
NIS
maps
The NIS maps are database files,
that are kept in the /var/yp
directory. They are generated from configuration files in
the /etc directory of the NIS master,
with one exception: the
/etc/master.passwd file. This is for
a good reason, you do not want to propagate passwords to
your root and other administrative
accounts to all the servers in the NIS domain. Therefore,
before we initialize the NIS maps, you should:
&prompt.root; cp /etc/master.passwd /var/yp/master.passwd
&prompt.root; cd /var/yp
&prompt.root; vi master.passwd
You should remove all entries regarding system
accounts (bin,
tty, kmem,
games, etc), as well as any accounts
that you do not want to be propagated to the NIS clients
(for example root and any other UID 0
(superuser) accounts).
Make sure the
/var/yp/master.passwd is neither group
nor world readable (mode 600)! Use the
chmod command, if appropriate.
Tru64 UNIX
When you have finished, it is time to initialize the
NIS maps! FreeBSD includes a script named
ypinit to do this for you (see its
manual page for more information). Note that this script
is available on most &unix; Operating Systems, but not on
all. On Digital UNIX/Compaq Tru64 UNIX it is called
ypsetup. Because we are generating
maps for an NIS master, we are going to pass the
option to ypinit.
To generate the NIS maps, assuming you already performed
the steps above, run:
ellington&prompt.root; ypinit -m test-domain
Server Type: MASTER Domain: test-domain
Creating an YP server will require that you answer a few questions.
Questions will all be asked at the beginning of the procedure.
Do you want this procedure to quit on non-fatal errors? [y/n: n] n
Ok, please remember to go back and redo manually whatever fails.
If you don't, something might not work.
At this point, we have to construct a list of this domains YP servers.
rod.darktech.org is already known as master server.
Please continue to add any slave servers, one per line. When you are
done with the list, type a <control D>.
master server : ellington
next host to add: coltrane
next host to add: ^D
The current list of NIS servers looks like this:
ellington
coltrane
Is this correct? [y/n: y] y
[..output from map generation..]
NIS Map update completed.
ellington has been setup as an YP master server without any errors.
ypinit should have created
/var/yp/Makefile from
/var/yp/Makefile.dist.
When created, this file assumes that you are operating
in a single server NIS environment with only FreeBSD
machines. Since test-domain has
a slave server as well, you must edit
/var/yp/Makefile:
ellington&prompt.root; vi /var/yp/Makefile
You should comment out the line that says
NOPUSH = "True"
(if it is not commented out already).
Setting up a NIS Slave Server
NIS
slave server
Setting up an NIS slave server is even more simple than
setting up the master. Log on to the slave server and edit the
file /etc/rc.conf as you did before.
The only difference is that we now must use the
option when running ypinit.
The option requires the name of the NIS
master be passed to it as well, so our command line looks
like:
coltrane&prompt.root; ypinit -s ellington test-domain
Server Type: SLAVE Domain: test-domain Master: ellington
Creating an YP server will require that you answer a few questions.
Questions will all be asked at the beginning of the procedure.
Do you want this procedure to quit on non-fatal errors? [y/n: n] n
Ok, please remember to go back and redo manually whatever fails.
If you don't, something might not work.
There will be no further questions. The remainder of the procedure
should take a few minutes, to copy the databases from ellington.
Transferring netgroup...
ypxfr: Exiting: Map successfully transferred
Transferring netgroup.byuser...
ypxfr: Exiting: Map successfully transferred
Transferring netgroup.byhost...
ypxfr: Exiting: Map successfully transferred
Transferring master.passwd.byuid...
ypxfr: Exiting: Map successfully transferred
Transferring passwd.byuid...
ypxfr: Exiting: Map successfully transferred
Transferring passwd.byname...
ypxfr: Exiting: Map successfully transferred
Transferring group.bygid...
ypxfr: Exiting: Map successfully transferred
Transferring group.byname...
ypxfr: Exiting: Map successfully transferred
Transferring services.byname...
ypxfr: Exiting: Map successfully transferred
Transferring rpc.bynumber...
ypxfr: Exiting: Map successfully transferred
Transferring rpc.byname...
ypxfr: Exiting: Map successfully transferred
Transferring protocols.byname...
ypxfr: Exiting: Map successfully transferred
Transferring master.passwd.byname...
ypxfr: Exiting: Map successfully transferred
Transferring networks.byname...
ypxfr: Exiting: Map successfully transferred
Transferring networks.byaddr...
ypxfr: Exiting: Map successfully transferred
Transferring netid.byname...
ypxfr: Exiting: Map successfully transferred
Transferring hosts.byaddr...
ypxfr: Exiting: Map successfully transferred
Transferring protocols.bynumber...
ypxfr: Exiting: Map successfully transferred
Transferring ypservers...
ypxfr: Exiting: Map successfully transferred
Transferring hosts.byname...
ypxfr: Exiting: Map successfully transferred
coltrane has been setup as an YP slave server without any errors.
Don't forget to update map ypservers on ellington.
You should now have a directory called
/var/yp/test-domain. Copies of the NIS
master server's maps should be in this directory. You will
need to make sure that these stay updated. The following
/etc/crontab entries on your slave
servers should do the job:
20 * * * * root /usr/libexec/ypxfr passwd.byname
21 * * * * root /usr/libexec/ypxfr passwd.byuid
These two lines force the slave to sync its maps with
the maps on the master server. Although these entries are
not mandatory, since the master server attempts to ensure
any changes to its NIS maps are communicated to its slaves
and because password information is vital to systems
depending on the server, it is a good idea to force the
updates. This is more important on busy networks where map
updates might not always complete.
Now, run the command /etc/netstart on the
slave server as well, which again starts the NIS server.
NIS Clients
An NIS client establishes what is called a binding to a
particular NIS server using the
ypbind daemon.
ypbind checks the system's default
domain (as set by the domainname command),
and begins broadcasting RPC requests on the local network.
These requests specify the name of the domain for which
ypbind is attempting to establish a binding.
If a server that has been configured to serve the requested
domain receives one of the broadcasts, it will respond to
ypbind, which will record the server's
address. If there are several servers available (a master and
several slaves, for example), ypbind will
use the address of the first one to respond. From that point
on, the client system will direct all of its NIS requests to
that server. ypbind will
occasionally ping
the server to make sure it is
still up and running. If it fails to receive a reply to one of
its pings within a reasonable amount of time,
ypbind will mark the domain as unbound and
begin broadcasting again in the hopes of locating another
server.
Setting Up a NIS Client
NIS
client configuration
Setting up a FreeBSD machine to be a NIS client is fairly
straightforward.
Edit the file /etc/rc.conf and
add the following lines in order to set the NIS domainname
and start ypbind upon network
startup:
nisdomainname="test-domain"
nis_client_enable="YES"
To import all possible password entries from the NIS
server, remove all user accounts from your
/etc/master.passwd file and use
vipw to add the following line to
the end of the file:
+:::::::::
This line will afford anyone with a valid account in
the NIS server's password maps an account. There are
many ways to configure your NIS client by changing this
line. See the netgroups
section below for more information.
For more detailed reading see O'Reilly's book on
Managing NFS and NIS.
You should keep at least one local account (i.e.
not imported via NIS) in your
/etc/master.passwd and this
account should also be a member of the group
wheel. If there is something
wrong with NIS, this account can be used to log in
remotely, become root, and fix things.
To import all possible group entries from the NIS
server, add this line to your
/etc/group file:
+:*::
After completing these steps, you should be able to run
ypcat passwd and see the NIS server's
passwd map.
NIS Security
In general, any remote user can issue an RPC to
&man.ypserv.8; and retrieve the contents of your NIS maps,
provided the remote user knows your domainname. To prevent
such unauthorized transactions, &man.ypserv.8; supports a
feature called securenets
which can be used to
restrict access to a given set of hosts. At startup,
&man.ypserv.8; will attempt to load the securenets information
from a file called
/var/yp/securenets.
This path varies depending on the path specified with the
option. This file contains entries that
consist of a network specification and a network mask separated
by white space. Lines starting with #
are
considered to be comments. A sample securenets file might look
like this:
# allow connections from local host -- mandatory
127.0.0.1 255.255.255.255
# allow connections from any host
# on the 192.168.128.0 network
192.168.128.0 255.255.255.0
# allow connections from any host
# between 10.0.0.0 to 10.0.15.255
# this includes the machines in the testlab
10.0.0.0 255.255.240.0
If &man.ypserv.8; receives a request from an address that
matches one of these rules, it will process the request
normally. If the address fails to match a rule, the request
will be ignored and a warning message will be logged. If the
/var/yp/securenets file does not exist,
ypserv will allow connections from any
host.
The ypserv program also has support for
Wietse Venema's TCP Wrapper package.
This allows the administrator to use the
TCP Wrapper configuration files for
access control instead of
/var/yp/securenets.
While both of these access control mechanisms provide some
security, they, like the privileged port test, are
vulnerable to IP spoofing
attacks. All
NIS-related traffic should be blocked at your firewall.
Servers using /var/yp/securenets
may fail to serve legitimate NIS clients with archaic TCP/IP
implementations. Some of these implementations set all
host bits to zero when doing broadcasts and/or fail to
observe the subnet mask when calculating the broadcast
address. While some of these problems can be fixed by
changing the client configuration, other problems may force
the retirement of the client systems in question or the
abandonment of /var/yp/securenets.
Using /var/yp/securenets on a
server with such an archaic implementation of TCP/IP is a
really bad idea and will lead to loss of NIS functionality
for large parts of your network.
TCP Wrappers
The use of the TCP Wrapper
package increases the latency of your NIS server. The
additional delay may be long enough to cause timeouts in
client programs, especially in busy networks or with slow
NIS servers. If one or more of your client systems
suffers from these symptoms, you should convert the client
systems in question into NIS slave servers and force them
to bind to themselves.
Barring Some Users from Logging On
In our lab, there is a machine basie that
is supposed to be a faculty only workstation. We do not want
to take this machine out of the NIS domain, yet the
passwd file on the master NIS server
contains accounts for both faculty and students. What can we
do?
There is a way to bar specific users from logging on to a
machine, even if they are present in the NIS database. To do
this, all you must do is add
-username to the
end of the /etc/master.passwd file on the
client machine, where username is
the username of the user you wish to bar from logging in.
This should preferably be done using vipw,
since vipw will sanity check your changes
to /etc/master.passwd, as well as
automatically rebuild the password database when you finish
editing. For example, if we wanted to bar user
bill from logging on to
basie we would:
basie&prompt.root; vipw
[add -bill to the end, exit]
vipw: rebuilding the database...
vipw: done
basie&prompt.root; cat /etc/master.passwd
root:[password]:0:0::0:0:The super-user:/root:/bin/csh
toor:[password]:0:0::0:0:The other super-user:/root:/bin/sh
daemon:*:1:1::0:0:Owner of many system processes:/root:/sbin/nologin
operator:*:2:5::0:0:System &:/:/sbin/nologin
bin:*:3:7::0:0:Binaries Commands and Source,,,:/:/sbin/nologin
tty:*:4:65533::0:0:Tty Sandbox:/:/sbin/nologin
kmem:*:5:65533::0:0:KMem Sandbox:/:/sbin/nologin
games:*:7:13::0:0:Games pseudo-user:/usr/games:/sbin/nologin
news:*:8:8::0:0:News Subsystem:/:/sbin/nologin
man:*:9:9::0:0:Mister Man Pages:/usr/share/man:/sbin/nologin
bind:*:53:53::0:0:Bind Sandbox:/:/sbin/nologin
uucp:*:66:66::0:0:UUCP pseudo-user:/var/spool/uucppublic:/usr/libexec/uucp/uucico
xten:*:67:67::0:0:X-10 daemon:/usr/local/xten:/sbin/nologin
pop:*:68:6::0:0:Post Office Owner:/nonexistent:/sbin/nologin
nobody:*:65534:65534::0:0:Unprivileged user:/nonexistent:/sbin/nologin
+:::::::::
-bill
basie&prompt.root;
Udo
Erdelhoff
Contributed by
Using Netgroups
netgroups
The method shown in the previous section works reasonably
well if you need special rules for a very small number of
users and/or machines. On larger networks, you
will forget to bar some users from logging
onto sensitive machines, or you may even have to modify each
machine separately, thus losing the main benefit of NIS:
centralized administration.
The NIS developers' solution for this problem is called
netgroups. Their purpose and semantics
can be compared to the normal groups used by &unix; file
systems. The main differences are the lack of a numeric ID
and the ability to define a netgroup by including both user
accounts and other netgroups.
Netgroups were developed to handle large, complex networks
with hundreds of users and machines. On one hand, this is
a Good Thing if you are forced to deal with such a situation.
On the other hand, this complexity makes it almost impossible to
explain netgroups with really simple examples. The example
used in the remainder of this section demonstrates this
problem.
Let us assume that your successful introduction of NIS in
your laboratory caught your superiors' interest. Your next
job is to extend your NIS domain to cover some of the other
machines on campus. The two tables contain the names of the
new users and new machines as well as brief descriptions of
them.
User Name(s)
Description
alpha, beta
Normal employees of the IT department
charlie, delta
The new apprentices of the IT department
echo, foxtrott, golf, ...
Ordinary employees
able, baker, ...
The current interns
Machine Name(s)
Description
war, death,
famine,
pollution
Your most important servers. Only the IT
employees are allowed to log onto these
machines.
pride, greed,
envy, wrath,
lust, sloth
Less important servers. All members of the IT
department are allowed to login onto these
machines.
one, two,
three, four,
...
Ordinary workstations. Only the
real employees are allowed to use
these machines.
trashcan
A very old machine without any critical data.
Even the intern is allowed to use this box.
If you tried to implement these restrictions by separately
blocking each user, you would have to add one
-user line to
each system's passwd for each user who is
not allowed to login onto that system. If you forget just one
entry, you could be in trouble. It may be feasible to do this
correctly during the initial setup, however you
will eventually forget to add the lines
for new users during day-to-day operations. After all, Murphy
was an optimist.
Handling this situation with netgroups offers several
advantages. Each user need not be handled separately; you
assign a user to one or more netgroups and allow or forbid
logins for all members of the netgroup. If you add a new
machine, you will only have to define login restrictions for
netgroups. If a new user is added, you will only have to add
the user to one or more netgroups. Those changes are
independent of each other: no more for each combination
of user and machine do...
If your NIS setup is planned
carefully, you will only have to modify exactly one central
configuration file to grant or deny access to machines.
The first step is the initialization of the NIS map
netgroup. FreeBSD's &man.ypinit.8; does not create this map by
default, but its NIS implementation will support it once it has
been created. To create an empty map, simply type
ellington&prompt.root; vi /var/yp/netgroup
and start adding content. For our example, we need at
least four netgroups: IT employees, IT apprentices, normal
employees and interns.
IT_EMP (,alpha,test-domain) (,beta,test-domain)
IT_APP (,charlie,test-domain) (,delta,test-domain)
USERS (,echo,test-domain) (,foxtrott,test-domain) \
(,golf,test-domain)
INTERNS (,able,test-domain) (,baker,test-domain)
IT_EMP, IT_APP etc.
are the names of the netgroups. Each bracketed group adds
one or more user accounts to it. The three fields inside a
group are:
The name of the host(s) where the following items are
valid. If you do not specify a hostname, the entry is
valid on all hosts. If you do specify a hostname, you
will enter a realm of darkness, horror and utter confusion.
The name of the account that belongs to this
netgroup.
The NIS domain for the account. You can import
accounts from other NIS domains into your netgroup if you
are one of the unlucky fellows with more than one NIS
domain.
Each of these fields can contain wildcards. See
&man.netgroup.5; for details.
netgroups
Netgroup names longer than 8 characters should not be
used, especially if you have machines running other
operating systems within your NIS domain. The names are
case sensitive; using capital letters for your netgroup
names is an easy way to distinguish between user, machine
and netgroup names.
Some NIS clients (other than FreeBSD) cannot handle
netgroups with a large number of entries. For example, some
older versions of &sunos; start to cause trouble if a netgroup
contains more than 15 entries. You can
circumvent this limit by creating several sub-netgroups with
15 users or less and a real netgroup that consists of the
sub-netgroups:
BIGGRP1 (,joe1,domain) (,joe2,domain) (,joe3,domain) [...]
BIGGRP2 (,joe16,domain) (,joe17,domain) [...]
BIGGRP3 (,joe31,domain) (,joe32,domain)
BIGGROUP BIGGRP1 BIGGRP2 BIGGRP3
You can repeat this process if you need more than 225
users within a single netgroup.
Activating and distributing your new NIS map is
easy:
ellington&prompt.root; cd /var/yp
ellington&prompt.root; make
This will generate the three NIS maps
netgroup,
netgroup.byhost and
netgroup.byuser. Use &man.ypcat.1; to
check if your new NIS maps are available:
ellington&prompt.user; ypcat -k netgroup
ellington&prompt.user; ypcat -k netgroup.byhost
ellington&prompt.user; ypcat -k netgroup.byuser
The output of the first command should resemble the
contents of /var/yp/netgroup. The second
command will not produce output if you have not specified
host-specific netgroups. The third command can be used to
get the list of netgroups for a user.
The client setup is quite simple. To configure the server
war, you only have to start
&man.vipw.8; and replace the line
+:::::::::
with
+@IT_EMP:::::::::
Now, only the data for the users defined in the netgroup
IT_EMP is imported into
war's password database and only
these users are allowed to login.
Unfortunately, this limitation also applies to the
~ function of the shell and all routines
converting between user names and numerical user IDs. In
other words, cd
~user will not work,
ls -l will show the numerical ID instead of
the username and find . -user joe -print
will fail with No such user. To fix
this, you will have to import all user entries
without allowing them to login onto your
servers.
This can be achieved by adding another line to
/etc/master.passwd. This line should
contain:
+:::::::::/sbin/nologin, meaning
Import all entries but replace the shell with
/sbin/nologin in the imported
entries
. You can replace any field in the
passwd entry by placing a default value in
your /etc/master.passwd.
Make sure that the line
+:::::::::/sbin/nologin is placed after
+@IT_EMP:::::::::. Otherwise, all user
accounts imported from NIS will have /sbin/nologin as their
login shell.
After this change, you will only have to change one NIS
map if a new employee joins the IT department. You could use
a similar approach for the less important servers by replacing
the old +::::::::: in their local version
of /etc/master.passwd with something like
this:
+@IT_EMP:::::::::
+@IT_APP:::::::::
+:::::::::/sbin/nologin
The corresponding lines for the normal workstations
could be:
+@IT_EMP:::::::::
+@USERS:::::::::
+:::::::::/sbin/nologin
And everything would be fine until there is a policy
change a few weeks later: The IT department starts hiring
interns. The IT interns are allowed to use the normal
workstations and the less important servers; and the IT
apprentices are allowed to login onto the main servers. You
add a new netgroup IT_INTERN, add the new
IT interns to this netgroup and start to change the
configuration on each and every machine... As the old saying
goes: Errors in centralized planning lead to global
mess
.
NIS' ability to create netgroups from other netgroups can
be used to prevent situations like these. One possibility
is the creation of role-based netgroups. For example, you
could create a netgroup called
BIGSRV to define the login
restrictions for the important servers, another netgroup
called SMALLSRV for the less
important servers and a third netgroup called
USERBOX for the normal
workstations. Each of these netgroups contains the netgroups
that are allowed to login onto these machines. The new
entries for your NIS map netgroup should look like this:
BIGSRV IT_EMP IT_APP
SMALLSRV IT_EMP IT_APP ITINTERN
USERBOX IT_EMP ITINTERN USERS
This method of defining login restrictions works
reasonably well if you can define groups of machines with
identical restrictions. Unfortunately, this is the exception
and not the rule. Most of the time, you will need the ability
to define login restrictions on a per-machine basis.
Machine-specific netgroup definitions are the other
possibility to deal with the policy change outlined above. In
this scenario, the /etc/master.passwd of
each box contains two lines starting with +
.
The first of them adds a netgroup with the accounts allowed to
login onto this machine, the second one adds all other
accounts with /sbin/nologin as shell. It
is a good idea to use the ALL-CAPS
version of
the machine name as the name of the netgroup. In other words,
the lines should look like this:
+@BOXNAME:::::::::
+:::::::::/sbin/nologin
Once you have completed this task for all your machines,
you will not have to modify the local versions of
/etc/master.passwd ever again. All
further changes can be handled by modifying the NIS map. Here
is an example of a possible netgroup map for this
scenario with some additional goodies:
# Define groups of users first
IT_EMP (,alpha,test-domain) (,beta,test-domain)
IT_APP (,charlie,test-domain) (,delta,test-domain)
DEPT1 (,echo,test-domain) (,foxtrott,test-domain)
DEPT2 (,golf,test-domain) (,hotel,test-domain)
DEPT3 (,india,test-domain) (,juliet,test-domain)
ITINTERN (,kilo,test-domain) (,lima,test-domain)
D_INTERNS (,able,test-domain) (,baker,test-domain)
#
# Now, define some groups based on roles
USERS DEPT1 DEPT2 DEPT3
BIGSRV IT_EMP IT_APP
SMALLSRV IT_EMP IT_APP ITINTERN
USERBOX IT_EMP ITINTERN USERS
#
# And a groups for a special tasks
# Allow echo and golf to access our anti-virus-machine
SECURITY IT_EMP (,echo,test-domain) (,golf,test-domain)
#
# machine-based netgroups
# Our main servers
WAR BIGSRV
FAMINE BIGSRV
# User india needs access to this server
POLLUTION BIGSRV (,india,test-domain)
#
# This one is really important and needs more access restrictions
DEATH IT_EMP
#
# The anti-virus-machine mentioned above
ONE SECURITY
#
# Restrict a machine to a single user
TWO (,hotel,test-domain)
# [...more groups to follow]
If you are using some kind of database to manage your user
accounts, you should be able to create the first part of the
map with your database's report tools. This way, new users
will automatically have access to the boxes.
One last word of caution: It may not always be advisable
to use machine-based netgroups. If you are deploying a couple of
dozen or even hundreds of identical machines for student labs,
you should use role-based netgroups instead of machine-based
netgroups to keep the size of the NIS map within reasonable
limits.
Important Things to Remember
There are still a couple of things that you will need to do
differently now that you are in an NIS environment.
Every time you wish to add a user to the lab, you
must add it to the master NIS server only,
and you must remember to rebuild the NIS
maps. If you forget to do this, the new user will
not be able to login anywhere except on the NIS master.
For example, if we needed to add a new user
jsmith to the lab, we would:
&prompt.root; pw useradd jsmith
&prompt.root; cd /var/yp
&prompt.root; make test-domain
You could also run adduser jsmith instead
of pw useradd jsmith.
Keep the administration accounts out of the
NIS maps. You do not want to be propagating
administrative accounts and passwords to machines that
will have users that should not have access to those
accounts.
Keep the NIS master and slave secure, and
minimize their downtime. If somebody either
hacks or simply turns off these machines, they have
effectively rendered many people without the ability to
login to the lab.
This is the chief weakness of any centralized administration
system. If you do
not protect your NIS servers, you will have a lot of angry
users!
NIS v1 Compatibility
FreeBSD's ypserv has some
support for serving NIS v1 clients. FreeBSD's NIS
implementation only uses the NIS v2 protocol, however other
implementations include support for the v1 protocol for
backwards compatibility with older systems. The
ypbind daemons supplied with these
systems will try to establish a binding to an NIS v1 server
even though they may never actually need it (and they may
persist in broadcasting in search of one even after they
receive a response from a v2 server). Note that while support
for normal client calls is provided, this version of
ypserv does not handle v1 map
transfer requests; consequently, it cannot be used as a master
or slave in conjunction with older NIS servers that only
support the v1 protocol. Fortunately, there probably are not
any such servers still in use today.
NIS Servers That Are Also NIS Clients
Care must be taken when running
ypserv in a multi-server domain
where the server machines are also NIS clients. It is
generally a good idea to force the servers to bind to
themselves rather than allowing them to broadcast bind
requests and possibly become bound to each other. Strange
failure modes can result if one server goes down and others
are dependent upon it. Eventually all the clients will time
out and attempt to bind to other servers, but the delay
involved can be considerable and the failure mode is still
present since the servers might bind to each other all over
again.
You can force a host to bind to a particular server by running
ypbind with the
flag. If you do not want to do this manually each time you
reboot your NIS server, you can add the following lines to
your /etc/rc.conf:
nis_client_enable="YES" # run client stuff as well
nis_client_flags="-S NIS domain,server"
See &man.ypbind.8; for further information.
Password Formats
NIS
password formats
One of the most common issues that people run into when trying
to implement NIS is password format compatibility. If your NIS
server is using DES encrypted passwords, it will only support
clients that are also using DES. For example, if you have
&solaris; NIS clients in your network, then you will almost certainly
need to use DES encrypted passwords.
To check which format your servers
and clients are using, look at /etc/login.conf.
If the host is configured to use DES encrypted passwords, then the
default class will contain an entry like this:
default:\
:passwd_format=des:\
:copyright=/etc/COPYRIGHT:\
[Further entries elided]
Other possible values for the passwd_format
capability include blf and md5
(for Blowfish and MD5 encrypted passwords, respectively).
If you have made changes to
/etc/login.conf, you will also need to
rebuild the login capability database, which is achieved by
running the following command as
root:
&prompt.root; cap_mkdb /etc/login.conf
The format of passwords already in
/etc/master.passwd will not be updated
until a user changes his password for the first time
after the login capability database is
rebuilt.
Next, in order to ensure that passwords are encrypted with
the format that you have chosen, you should also check that
the crypt_default in
/etc/auth.conf gives precedence to your
chosen password format. To do this, place the format that you
have chosen first in the list. For example, when using DES
encrypted passwords, the entry would be:
crypt_default = des blf md5
Having followed the above steps on each of the &os; based
NIS servers and clients, you can be sure that they all agree
on which password format is used within your network. If you
have trouble authenticating on an NIS client, this is a pretty
good place to start looking for possible problems. Remember:
if you want to deploy an NIS server for a heterogenous
network, you will probably have to use DES on all systems
because it is the lowest common standard.
Greg
Sutter
Written by
Automatic Network Configuration (DHCP)
What Is DHCP?
Dynamic Host Configuration Protocol
DHCP
Internet Software Consortium (ISC)
DHCP, the Dynamic Host Configuration Protocol, describes
the means by which a system can connect to a network and obtain the
necessary information for communication upon that network. FreeBSD
versions prior to 6.0 use the ISC (Internet Software
Consortium) DHCP client (&man.dhclient.8;) implementation.
Later versions use the OpenBSD dhclient
taken from OpenBSD 3.7. All
information here regarding dhclient is for
use with either of the ISC or OpenBSD DHCP clients. The DHCP
server is the one included in the ISC distribution.
What This Section Covers
This section describes both the client-side components of the ISC and OpenBSD DHCP client and
server-side components of the ISC DHCP system. The
client-side program, dhclient, comes
integrated within FreeBSD, and the server-side portion is
available from the net/isc-dhcp3-server port. The
&man.dhclient.8;, &man.dhcp-options.5;, and
&man.dhclient.conf.5; manual pages, in addition to the
references below, are useful resources.
How It Works
UDP
When dhclient, the DHCP client, is
executed on the client machine, it begins broadcasting
requests for configuration information. By default, these
requests are on UDP port 68. The server replies on UDP 67,
giving the client an IP address and other relevant network
information such as netmask, router, and DNS servers. All of
this information comes in the form of a DHCP
lease
and is only valid for a certain time
(configured by the DHCP server maintainer). In this manner,
stale IP addresses for clients no longer connected to the
network can be automatically reclaimed.
DHCP clients can obtain a great deal of information from
the server. An exhaustive list may be found in
&man.dhcp-options.5;.
FreeBSD Integration
&os; fully integrates the ISC or OpenBSD DHCP client,
dhclient (according to the &os; version you run). DHCP client support is provided
within both the installer and the base system, obviating the need
for detailed knowledge of network configurations on any network
that runs a DHCP server. dhclient has been
included in all FreeBSD distributions since 3.2.
sysinstall
DHCP is supported by
sysinstall. When configuring a
network interface within
sysinstall, the second question
asked is: Do you want to try DHCP configuration of
the interface?
. Answering affirmatively will
execute dhclient, and if successful, will
fill in the network configuration information
automatically.
There are two things you must do to have your system use
DHCP upon startup:
DHCP
requirements
Make sure that the bpf
device is compiled into your kernel. To do this, add
device bpf (pseudo-device
bpf under &os; 4.X) to your kernel
configuration file, and rebuild the kernel. For more
information about building kernels, see . The
bpf device is already part of
the GENERIC kernel that is supplied
with FreeBSD, so if you do not have a custom kernel, you
should not need to create one in order to get DHCP
working.
For those who are particularly security conscious,
you should be warned that bpf
is also the device that allows packet sniffers to work
correctly (although they still have to be run as
root). bpf
is required to use DHCP, but if
you are very sensitive about security, you probably
should not add bpf to your
kernel in the expectation that at some point in the
future you will be using DHCP.
Edit your /etc/rc.conf to
include the following:
ifconfig_fxp0="DHCP"
Be sure to replace fxp0 with the
designation for the interface that you wish to dynamically
configure, as described in
.
If you are using a different location for
dhclient, or if you wish to pass additional
flags to dhclient, also include the
following (editing as necessary):
dhcp_program="/sbin/dhclient"
dhcp_flags=""
DHCP
server
The DHCP server, dhcpd, is included
as part of the net/isc-dhcp3-server port in the ports
collection. This port contains the ISC DHCP server and
documentation.
Files
DHCP
configuration files
/etc/dhclient.conf
dhclient requires a configuration file,
/etc/dhclient.conf. Typically the file
contains only comments, the defaults being reasonably sane. This
configuration file is described by the &man.dhclient.conf.5;
manual page.
/sbin/dhclient
dhclient is statically linked and
resides in /sbin. The &man.dhclient.8;
manual page gives more information about
dhclient.
/sbin/dhclient-script
dhclient-script is the FreeBSD-specific
DHCP client configuration script. It is described in
&man.dhclient-script.8;, but should not need any user
modification to function properly.
/var/db/dhclient.leases
The DHCP client keeps a database of valid leases in this
file, which is written as a log. &man.dhclient.leases.5;
gives a slightly longer description.
Further Reading
The DHCP protocol is fully described in
RFC 2131.
An informational resource has also been set up at
.
Installing and Configuring a DHCP Server
What This Section Covers
This section provides information on how to configure
a FreeBSD system to act as a DHCP server using the ISC
(Internet Software Consortium) implementation of the DHCP
suite.
The server portion of the suite is not provided as part of
FreeBSD, and so you will need to install the
net/isc-dhcp3-server
port to provide this service. See for
more information on using the Ports Collection.
DHCP Server Installation
DHCP
installation
In order to configure your FreeBSD system as a DHCP
server, you will need to ensure that the &man.bpf.4;
device is compiled into your kernel. To do this, add
device bpf (pseudo-device
bpf under &os; 4.X) to your kernel
configuration file, and rebuild the kernel. For more
information about building kernels, see .
The bpf device is already
part of the GENERIC kernel that is
supplied with FreeBSD, so you do not need to create a custom
kernel in order to get DHCP working.
Those who are particularly security conscious
should note that bpf
is also the device that allows packet sniffers to work
correctly (although such programs still need privileged
access). bpf
is required to use DHCP, but if
you are very sensitive about security, you probably
should not include bpf in your
kernel purely because you expect to use DHCP at some
point in the future.
The next thing that you will need to do is edit the sample
dhcpd.conf which was installed by the
net/isc-dhcp3-server port.
By default, this will be
/usr/local/etc/dhcpd.conf.sample, and you
should copy this to
/usr/local/etc/dhcpd.conf before proceeding
to make changes.
Configuring the DHCP Server
DHCP
dhcpd.conf
dhcpd.conf is
comprised of declarations regarding subnets and hosts, and is
perhaps most easily explained using an example :
option domain-name "example.com";
option domain-name-servers 192.168.4.100;
option subnet-mask 255.255.255.0;
default-lease-time 3600;
max-lease-time 86400;
ddns-update-style none;
subnet 192.168.4.0 netmask 255.255.255.0 {
range 192.168.4.129 192.168.4.254;
option routers 192.168.4.1;
}
host mailhost {
hardware ethernet 02:03:04:05:06:07;
fixed-address mailhost.example.com;
}
This option specifies the domain that will be provided
to clients as the default search domain. See
&man.resolv.conf.5; for more information on what this
means.
This option specifies a comma separated list of DNS
servers that the client should use.
The netmask that will be provided to clients.
A client may request a specific length of time that a
lease will be valid. Otherwise the server will assign
a lease with this expiry value (in seconds).
This is the maximum length of time that the server will
lease for. Should a client request a longer lease, a lease
will be issued, although it will only be valid for
max-lease-time seconds.
This option specifies whether the DHCP server should
attempt to update DNS when a lease is accepted or released.
In the ISC implementation, this option is
required.
This denotes which IP addresses should be used in
the pool reserved for allocating to clients. IP
addresses between, and including, the ones stated are
handed out to clients.
Declares the default gateway that will be provided to
clients.
The hardware MAC address of a host (so that the DHCP server
can recognize a host when it makes a request).
Specifies that the host should always be given the
same IP address. Note that using a hostname is
correct here, since the DHCP server will resolve the
hostname itself before returning the lease
information.
Once you have finished writing your
dhcpd.conf, you can proceed to start the
server by issuing the following command:
&prompt.root; /usr/local/etc/rc.d/isc-dhcpd.sh start
Should you need to make changes to the configuration of your
server in the future, it is important to note that sending a
SIGHUP signal to
dhcpd does not
result in the configuration being reloaded, as it does with most
daemons. You will need to send a SIGTERM
signal to stop the process, and then restart it using the command
above.
Files
DHCP
configuration files
/usr/local/sbin/dhcpd
dhcpd is statically linked and
resides in /usr/local/sbin. The
&man.dhcpd.8; manual page installed with the
port gives more information about
dhcpd.
/usr/local/etc/dhcpd.conf
dhcpd requires a configuration
file, /usr/local/etc/dhcpd.conf before it
will start providing service to clients. This file needs to
contain all the information that should be provided to clients
that are being serviced, along with information regarding the
operation of the server. This configuration file is described
by the &man.dhcpd.conf.5; manual page installed
by the port.
/var/db/dhcpd.leases
The DHCP server keeps a database of leases it has issued
in this file, which is written as a log. The manual page
&man.dhcpd.leases.5;, installed by the port
gives a slightly longer description.
/usr/local/sbin/dhcrelay
dhcrelay is used in advanced
environments where one DHCP server forwards a request from a
client to another DHCP server on a separate network. If you
require this functionality, then install the net/isc-dhcp3-relay port. The
&man.dhcrelay.8; manual page provided with the
port contains more detail.
Chern
Lee
Contributed by
Domain Name System (DNS)
Overview
BIND
FreeBSD utilizes, by default, a version of BIND (Berkeley
Internet Name Domain), which is the most common implementation
of the DNS protocol. DNS is the protocol through which names
are mapped to IP addresses, and vice versa. For example, a
query for www.FreeBSD.org will
receive a reply with the IP address of The FreeBSD Project's
web server, whereas, a query for ftp.FreeBSD.org will return the IP
address of the corresponding FTP machine. Likewise, the
opposite can happen. A query for an IP address can resolve
its hostname. It is not necessary to run a name server to
perform DNS lookups on a system.
DNS
DNS is coordinated across the Internet through a somewhat
complex system of authoritative root name servers, and other
smaller-scale name servers who host and cache individual domain
information.
This document refers to BIND 8.x, as it is the stable version
used in &os;. Versions of &os; 5.3 and beyond include
BIND9 and the configuration instructions
may be found later in this chapter. Users of &os; 5.2
and other previous versions may install BIND9
from the net/bind9 port.
RFC1034 and RFC1035 dictate the DNS protocol.
Currently, BIND is maintained by the
Internet Software Consortium .
Terminology
To understand this document, some terms related to DNS must be
understood.
resolver
reverse DNS
root zone
Term
Definition
Forward DNS
Mapping of hostnames to IP addresses
Origin
Refers to the domain covered in a particular zone
file
named, BIND, name server
Common names for the BIND name server package within
FreeBSD
Resolver
A system process through which a
machine queries a name server for zone information
Reverse DNS
The opposite of forward DNS; mapping of IP addresses to
hostnames
Root zone
The beginning of the Internet zone hierarchy.
All zones fall under the root zone, similar to how
all files in a file system fall under the root directory.
Zone
An individual domain, subdomain, or portion of the DNS administered by
the same authority
zones
examples
Examples of zones:
. is the root zone
org. is a zone under the root zone
example.org. is a
zone under the org. zone
foo.example.org. is
a subdomain, a zone under the example.org. zone
1.2.3.in-addr.arpa is a zone referencing
all IP addresses which fall under the 3.2.1.* IP space.
As one can see, the more specific part of a hostname
appears to its left. For example, example.org. is more specific than
org., as org. is more
specific than the root zone. The layout of each part of a
hostname is much like a file system: the
/dev directory falls within the root, and
so on.
Reasons to Run a Name Server
Name servers usually come in two forms: an authoritative
name server, and a caching name server.
An authoritative name server is needed when:
one wants to serve DNS information to the
world, replying authoritatively to queries.
a domain, such as example.org, is
registered and IP addresses need to be assigned to hostnames
under it.
an IP address block requires reverse DNS entries (IP to
hostname).
a backup name server, called a slave, must reply to queries
when the primary is down or inaccessible.
A caching name server is needed when:
a local DNS server may cache and respond more quickly
than querying an outside name server.
a reduction in overall network traffic is desired (DNS
traffic has been measured to account for 5% or more of total
Internet traffic).
When one queries for www.FreeBSD.org, the resolver usually
queries the uplink ISP's name server, and retrieves the reply.
With a local, caching DNS server, the query only has to be
made once to the outside world by the caching DNS server.
Every additional query will not have to look to the outside of
the local network, since the information is cached
locally.
How It Works
In FreeBSD, the BIND daemon is called
named for obvious reasons.
File
Description
named
the BIND daemon
ndc
name daemon control program
/etc/namedb
directory where BIND zone information resides
/etc/namedb/named.conf
daemon configuration file
Zone files are usually contained within the
/etc/namedb
directory, and contain the DNS zone information
served by the name server.
Starting BIND
BIND
starting
Since BIND is installed by default, configuring it all is
relatively simple.
To ensure the named daemon is
started at boot, put the following line in
/etc/rc.conf:
named_enable="YES"
To start the daemon manually (after configuring it):
&prompt.root; ndc start
Configuration Files
BIND
configuration files
Using make-localhost
Be sure to:
&prompt.root; cd /etc/namedb
&prompt.root; sh make-localhost
to properly create the local reverse DNS zone file in
/etc/namedb/master/localhost.rev.
/etc/namedb/named.conf
// $FreeBSD$
//
// Refer to the named(8) manual page for details. If you are ever going
// to setup a primary server, make sure you've understood the hairy
// details of how DNS is working. Even with simple mistakes, you can
// break connectivity for affected parties, or cause huge amount of
// useless Internet traffic.
options {
directory "/etc/namedb";
// In addition to the "forwarders" clause, you can force your name
// server to never initiate queries of its own, but always ask its
// forwarders only, by enabling the following line:
//
// forward only;
// If you've got a DNS server around at your upstream provider, enter
// its IP address here, and enable the line below. This will make you
// benefit from its cache, thus reduce overall DNS traffic in the
Internet.
/*
forwarders {
127.0.0.1;
};
*/
Just as the comment says, to benefit from an uplink's cache,
forwarders can be enabled here. Under normal
circumstances, a name server will recursively query the Internet
looking at certain name servers until it finds the answer it is
looking for. Having this enabled will have it query the uplink's
name server (or name server provided) first, taking advantage of
its cache. If the uplink name server in question is a heavily
trafficked, fast name server, enabling this may be worthwhile.
127.0.0.1
will not work here.
Change this IP address to a name server at your uplink.
/*
* If there is a firewall between you and name servers you want
* to talk to, you might need to uncomment the query-source
* directive below. Previous versions of BIND always asked
* questions using port 53, but BIND 8.1 uses an unprivileged
* port by default.
*/
// query-source address * port 53;
/*
* If running in a sandbox, you may have to specify a different
* location for the dumpfile.
*/
// dump-file "s/named_dump.db";
};
// Note: the following will be supported in a future release.
/*
host { any; } {
topology {
127.0.0.0/8;
};
};
*/
// Setting up secondaries is way easier and the rough picture for this
// is explained below.
//
// If you enable a local name server, don't forget to enter 127.0.0.1
// into your /etc/resolv.conf so this server will be queried first.
// Also, make sure to enable it in /etc/rc.conf.
zone "." {
type hint;
file "named.root";
};
zone "0.0.127.IN-ADDR.ARPA" {
type master;
file "localhost.rev";
};
// NB: Do not use the IP addresses below, they are faked, and only
// serve demonstration/documentation purposes!
//
// Example secondary config entries. It can be convenient to become
// a secondary at least for the zone where your own domain is in. Ask
// your network administrator for the IP address of the responsible
// primary.
//
// Never forget to include the reverse lookup (IN-ADDR.ARPA) zone!
// (This is the first bytes of the respective IP address, in reverse
// order, with ".IN-ADDR.ARPA" appended.)
//
// Before starting to setup a primary zone, better make sure you fully
// understand how DNS and BIND works, however. There are sometimes
// unobvious pitfalls. Setting up a secondary is comparably simpler.
//
// NB: Don't blindly enable the examples below. :-) Use actual names
// and addresses instead.
//
// NOTE!!! FreeBSD runs BIND in a sandbox (see named_flags in rc.conf).
// The directory containing the secondary zones must be write accessible
// to BIND. The following sequence is suggested:
//
// mkdir /etc/namedb/s
// chown bind:bind /etc/namedb/s
// chmod 750 /etc/namedb/s
For more information on running BIND in a sandbox, see
Running named in a sandbox.
/*
zone "example.com" {
type slave;
file "s/example.com.bak";
masters {
192.168.1.1;
};
};
zone "0.168.192.in-addr.arpa" {
type slave;
file "s/0.168.192.in-addr.arpa.bak";
masters {
192.168.1.1;
};
};
*/
In named.conf, these are examples of slave
entries for a forward and reverse zone.
For each new zone served, a new zone entry must be added to
named.conf.
For example, the simplest zone entry for
example.org can look like:
zone "example.org" {
type master;
file "example.org";
};
The zone is a master, as indicated by the
statement, holding its zone information in
/etc/namedb/example.org indicated by
the statement.
zone "example.org" {
type slave;
file "example.org";
};
In the slave case, the zone information is transferred from
the master name server for the particular zone, and saved in the
file specified. If and when the master server dies or is
unreachable, the slave name server will have the transferred
zone information and will be able to serve it.
Zone Files
An example master zone file for example.org (existing within
/etc/namedb/example.org) is as follows:
$TTL 3600
example.org. IN SOA ns1.example.org. admin.example.org. (
5 ; Serial
10800 ; Refresh
3600 ; Retry
604800 ; Expire
86400 ) ; Minimum TTL
; DNS Servers
@ IN NS ns1.example.org.
@ IN NS ns2.example.org.
; Machine Names
localhost IN A 127.0.0.1
ns1 IN A 3.2.1.2
ns2 IN A 3.2.1.3
mail IN A 3.2.1.10
@ IN A 3.2.1.30
; Aliases
www IN CNAME @
; MX Record
@ IN MX 10 mail.example.org.
Note that every hostname ending in a .
is an
exact hostname, whereas everything without a trailing
.
is referenced to the origin. For example,
www is translated into
www.origin.
In our fictitious zone file, our origin is
example.org., so www
would translate to www.example.org.
The format of a zone file follows:
recordname IN recordtype value
DNS
records
The most commonly used DNS records:
SOA
start of zone authority
NS
an authoritative name server
A
a host address
CNAME
the canonical name for an alias
MX
mail exchanger
PTR
a domain name pointer (used in reverse DNS)
example.org. IN SOA ns1.example.org. admin.example.org. (
5 ; Serial
10800 ; Refresh after 3 hours
3600 ; Retry after 1 hour
604800 ; Expire after 1 week
86400 ) ; Minimum TTL of 1 day
example.org.
the domain name, also the origin for this
zone file.
ns1.example.org.
the primary/authoritative name server for this
zone.
admin.example.org.
the responsible person for this zone,
email address with @
replaced. (admin@example.org becomes
admin.example.org)
5
the serial number of the file. This
must be incremented each time the zone file is
modified. Nowadays, many admins prefer a
yyyymmddrr format for the serial
number. 2001041002 would mean
last modified 04/10/2001, the latter
02 being the second time the zone
file has been modified this day. The serial number
is important as it alerts slave name servers for a
zone when it is updated.
@ IN NS ns1.example.org.
This is an NS entry. Every name server that is going to reply
authoritatively for the zone must have one of these entries.
The @ as seen here could have been
example.org.
The @ translates to the origin.
localhost IN A 127.0.0.1
ns1 IN A 3.2.1.2
ns2 IN A 3.2.1.3
mail IN A 3.2.1.10
@ IN A 3.2.1.30
The A record indicates machine names. As seen above,
ns1.example.org would resolve
to 3.2.1.2. Again, the
origin symbol, @, is used here, thus
meaning example.org would
resolve to 3.2.1.30.
www IN CNAME @
The canonical name record is usually used for giving aliases
to a machine. In the example, www is
aliased to the machine addressed to the origin, or
example.org
(3.2.1.30).
CNAMEs can be used to provide alias
hostnames, or round robin one hostname among multiple
machines.
MX record
@ IN MX 10 mail.example.org.
The MX record indicates which mail
servers are responsible for handling incoming mail for the
zone. mail.example.org is the
hostname of the mail server, and 10 being the priority of
that mail server.
One can have several mail servers, with priorities of 3, 2,
1. A mail server attempting to deliver to example.org would first try the
highest priority MX, then the second highest, etc, until the
mail can be properly delivered.
For in-addr.arpa zone files (reverse DNS), the same format is
used, except with PTR entries instead of
A or CNAME.
$TTL 3600
1.2.3.in-addr.arpa. IN SOA ns1.example.org. admin.example.org. (
5 ; Serial
10800 ; Refresh
3600 ; Retry
604800 ; Expire
3600 ) ; Minimum
@ IN NS ns1.example.org.
@ IN NS ns2.example.org.
2 IN PTR ns1.example.org.
3 IN PTR ns2.example.org.
10 IN PTR mail.example.org.
30 IN PTR example.org.
This file gives the proper IP address to hostname
mappings of our above fictitious domain.
Caching Name Server
BIND
caching name server
A caching name server is a name server that is not
authoritative for any zones. It simply asks queries of its
own, and remembers them for later use. To set one up, just
configure the name server as usual, omitting any inclusions of
zones.
Running named in a Sandbox
BIND
running in a sandbox
chroot
For added security you may want to run &man.named.8; as an
unprivileged user, and configure it to &man.chroot.8; into a
sandbox directory. This makes everything outside of the
sandbox inaccessible to the named
daemon. Should named be
compromised, this will help to reduce the damage that can be
caused. By default, FreeBSD has a user and a group called
bind, intended for this use.
Various people would recommend that instead of configuring
named to chroot, you
should run named inside a &man.jail.8;.
This section does not attempt to cover this situation.
Since named will not be able to
access anything outside of the sandbox (such as shared
libraries, log sockets, and so on), there are a number of steps
that need to be followed in order to allow
named to function correctly. In the
following checklist, it is assumed that the path to the sandbox
is /etc/namedb and that you have made no
prior modifications to the contents of this directory. Perform
the following steps as root:
Create all directories that named
expects to see:
&prompt.root; cd /etc/namedb
&prompt.root; mkdir -p bin dev etc var/tmp var/run master slave
&prompt.root; chown bind:bind slave var/*
named only needs write access to
these directories, so that is all we give it.
Rearrange and create basic zone and configuration files:
&prompt.root; cp /etc/localtime etc
&prompt.root; mv named.conf etc && ln -sf etc/named.conf
&prompt.root; mv named.root master
&prompt.root; sh make-localhost
&prompt.root; cat > master/named.localhost
$ORIGIN localhost.
$TTL 6h
@ IN SOA localhost. postmaster.localhost. (
1 ; serial
3600 ; refresh
1800 ; retry
604800 ; expiration
3600 ) ; minimum
IN NS localhost.
IN A 127.0.0.1
^D
This allows named to log the
correct time to &man.syslogd.8;.
syslog
log files
named
If you are running a version of &os; prior to 4.9-RELEASE, build a statically linked copy of
named-xfer, and copy it into the sandbox:
&prompt.root; cd /usr/src/lib/libisc
&prompt.root; make cleandir && make cleandir && make depend && make all
&prompt.root; cd /usr/src/lib/libbind
&prompt.root; make cleandir && make cleandir && make depend && make all
&prompt.root; cd /usr/src/libexec/named-xfer
&prompt.root; make cleandir && make cleandir && make depend && make NOSHARED=yes all
&prompt.root; cp named-xfer /etc/namedb/bin && chmod 555 /etc/namedb/bin/named-xfer
After your statically linked
named-xfer is installed some cleaning up
is required, to avoid leaving stale copies of libraries or
programs in your source tree:
&prompt.root; cd /usr/src/lib/libisc
&prompt.root; make cleandir
&prompt.root; cd /usr/src/lib/libbind
&prompt.root; make cleandir
&prompt.root; cd /usr/src/libexec/named-xfer
&prompt.root; make cleandir
This step has been reported to fail occasionally. If this
happens to you, then issue the command:
&prompt.root; cd /usr/src && make cleandir && make cleandir
and delete your /usr/obj tree:
&prompt.root; rm -fr /usr/obj && mkdir /usr/obj
This will clean out any cruft
from your
source tree, and retrying the steps above should then work.
If you are running &os; version 4.9-RELEASE or later,
then the copy of named-xfer in
/usr/libexec is statically linked by
default, and you can simply use &man.cp.1; to copy it into
your sandbox.
Make a dev/null that
named can see and write to:
&prompt.root; cd /etc/namedb/dev && mknod null c 2 2
&prompt.root; chmod 666 null
Symlink /var/run/ndc to
/etc/namedb/var/run/ndc:
&prompt.root; ln -sf /etc/namedb/var/run/ndc /var/run/ndc
This simply avoids having to specify the
option to &man.ndc.8; every time you
run it. Since the contents of
/var/run are deleted on boot, it may
be useful to add this command to
root's &man.crontab.5;, using the
option.
syslog
log files
named
Configure &man.syslogd.8; to create an extra
log socket that
named can write to. To do this,
add -l /etc/namedb/dev/log to the
syslogd_flags variable in
/etc/rc.conf.
chroot
Arrange to have named start
and chroot itself to the sandbox by
adding the following to
/etc/rc.conf:
named_enable="YES"
named_flags="-u bind -g bind -t /etc/namedb /etc/named.conf"
Note that the configuration file
/etc/named.conf is denoted by a full
pathname relative to the sandbox, i.e. in
the line above, the file referred to is actually
/etc/namedb/etc/named.conf.
The next step is to edit
/etc/namedb/etc/named.conf so that
named knows which zones to load and
where to find them on the disk. There follows a commented
example (anything not specifically commented here is no
different from the setup for a DNS server not running in a
sandbox):
options {
directory "/";
named-xfer "/bin/named-xfer";
version ""; // Don't reveal BIND version
query-source address * port 53;
};
// ndc control socket
controls {
unix "/var/run/ndc" perm 0600 owner 0 group 0;
};
// Zones follow:
zone "localhost" IN {
type master;
file "master/named.localhost";
allow-transfer { localhost; };
notify no;
};
zone "0.0.127.in-addr.arpa" IN {
type master;
file "master/localhost.rev";
allow-transfer { localhost; };
notify no;
};
zone "." IN {
type hint;
file "master/named.root";
};
zone "private.example.net" in {
type master;
file "master/private.example.net.db";
allow-transfer { 192.168.10.0/24; };
};
zone "10.168.192.in-addr.arpa" in {
type slave;
masters { 192.168.10.2; };
file "slave/192.168.10.db";
};
The
directory statement is specified as
/, since all files that
named needs are within this
directory (recall that this is equivalent to a
normal
user's
/etc/namedb).
Specifies the full path
to the named-xfer binary (from
named's frame of reference). This
is necessary since named is
compiled to look for named-xfer in
/usr/libexec by default.
Specifies the filename (relative
to the directory statement above) where
named can find the zone file for this
zone.
Specifies the filename
(relative to the directory statement above)
where named should write a copy of
the zone file for this zone after successfully transferring it
from the master server. This is why we needed to change the
ownership of the directory slave to
bind in the setup stages above.
After completing the steps above, either reboot your
server or restart &man.syslogd.8; and start &man.named.8;, making
sure to use the new options specified in
syslogd_flags and
named_flags. You should now be running a
sandboxed copy of named!
Security
Although BIND is the most common implementation of DNS,
there is always the issue of security. Possible and
exploitable security holes are sometimes found.
It is a good idea to read CERT's security advisories and
to subscribe to the &a.security-notifications;
to stay up to date with the current Internet and FreeBSD security
issues.
If a problem arises, keeping sources up to date and
having a fresh build of named would
not hurt.
Further Reading
BIND/named manual pages:
&man.ndc.8; &man.named.8; &man.named.conf.5;
Official ISC BIND
Page
BIND FAQ
O'Reilly
DNS and BIND 4th Edition
RFC1034
- Domain Names - Concepts and Facilities
RFC1035
- Domain Names - Implementation and Specification
Tom
Rhodes
Written by
BIND9 and &os;
bind9
setting up
The release of &os; 5.3 brought the
BIND9 DNS server software
into the distribution. New security features, a new file system
layout and automated &man.chroot.8; configuration came with the
import. This section has been written in two parts, the first
will discuss new features and their configuration; the latter
will cover upgrades to aid in move to &os; 5.3. From this
moment on, the server will be referred to simply as
&man.named.8; in place of BIND. This section
skips over the terminology described in the previous section as
well as some of the theoretical discussions; thus, it is
recommended that the previous section be consulted before reading
any further here.
Configuration files for named currently
reside in
/var/named/etc/namedb/ and
will need modification before use. This is where most of the
configuration will be performed.
Configuration of a Master Zone
To configure a master zone visit
/var/named/etc/namedb/
and run the following command:
&prompt.root; sh make-localhost
If all went well a new file should exist in the
master directory. The
filenames should be localhost.rev for
the local domain name and localhost-v6.rev
for IPv6 configurations. As the default
configuration file, configuration for its use will already
be present in the named.conf file.
Configuration of a Slave Zone
Configuration for extra domains or sub domains may be
done properly by setting them as a slave zone. In most cases,
the master/localhost.rev file could just be
copied over into the slave
directory and modified. Once completed, the files need
to be properly added in named.conf such
as in the following configuration for
example.com:
zone "example.com" {
type slave;
file "slave/example.com";
masters {
10.0.0.1;
};
};
zone "0.168.192.in-addr.arpa" {
type slave;
file "slave/0.168.192.in-addr.arpa";
masters {
10.0.0.1;
};
};
Note well that in this example, the master
IP address is the primary domain server
from which the zones are transferred; it does not necessary serve
as DNS server itself.
System Initialization Configuration
In order for the named daemon to start
when the system is booted, the following option must be present
in the rc.conf file:
named_enable="YES"
While other options exist, this is the bare minimal
requirement. Consult the &man.rc.conf.5; manual page for
a list of the other options. If nothing is entered in the
rc.conf file then named
may be started on the command line by invoking:
&prompt.root; /etc/rc.d/named start
BIND9 Security
While &os; automatically drops named
into a &man.chroot.8; environment; there are several other
security mechanisms in place which could help to lure off
possible DNS service attacks.
Query Access Control Lists
A query access control list can be used to restrict
queries against the zones. The configuration works by
defining the network inside of the acl
token and then listing IP addresses in
the zone configuration. To permit domains to query the
example host, just define it like this:
acl "example.com" {
192.168.0.0/24;
};
zone "example.com" {
type slave;
file "slave/example.com";
masters {
10.0.0.1;
};
allow-query { example.com; };
};
zone "0.168.192.in-addr.arpa" {
type slave;
file "slave/0.168.192.in-addr.arpa";
masters {
10.0.0.1;
};
allow-query { example.com; };
};
Restrict Version
Permitting version lookups on the DNS
server could be opening the doors for an attacker. A
malicious user may use this information to hunt up known
exploits or bugs to utilize against the host.
Setting a false version will not protect the server
from exploits. Only upgrading to a version that is not
vulnerable will protect your server.
A false version string can be placed the
options section of
named.conf:
options {
directory "/etc/namedb";
pid-file "/var/run/named/pid";
dump-file "/var/dump/named_dump.db";
statistics-file "/var/stats/named.stats";
version "None of your business";
};
Murray
Stokely
Contributed by
Apache HTTP Server
web servers
setting up
Apache
Overview
&os; is used to run some of the busiest web sites in the
world. The majority of web servers on the Internet are using
the Apache HTTP Server.
Apache software packages should be
included on your FreeBSD installation media. If you did not
install Apache when you first
installed FreeBSD, then you can install it from the www/apache13 or www/apache20 port.
Once Apache has been installed
successfully, it must be configured.
This section covers version 1.3.X of the
Apache HTTP Server as that is the
most widely used version for &os;. Apache 2.X introduces many
new technologies but they are not discussed here. For more
information about Apache 2.X, please see .
Configuration
Apache
configuration file
The main Apache HTTP Server configuration file is
installed as
/usr/local/etc/apache/httpd.conf on &os;.
This file is a typical &unix; text configuration file with
comment lines beginning with the #
character. A comprehensive description of all possible
configuration options is outside the scope of this book, so
only the most frequently modified directives will be described
here.
ServerRoot "/usr/local"
This specifies the default directory hierarchy for
the Apache installation. Binaries are stored in the
bin and
sbin subdirectories
of the server root, and configuration files are stored in
etc/apache.
ServerAdmin you@your.address
The address to which problems with the server should
be emailed. This address appears on some
server-generated pages, such as error documents.
ServerName www.example.com
ServerName allows you to set a host name which is
sent back to clients for your server if it is different
to the one that the host is configured with (i.e., use www
instead of the host's real name).
DocumentRoot "/usr/local/www/data"
DocumentRoot: The directory out of which you will
serve your documents. By default, all requests are taken
from this directory, but symbolic links and aliases may
be used to point to other locations.
It is always a good idea to make backup copies of your
Apache configuration file before making changes. Once you are
satisfied with your initial configuration you are ready to
start running Apache.
Running Apache
Apache
starting or stopping
Apache does not run from the
inetd super server as many other
network servers do. It is configured to run standalone for
better performance for incoming HTTP requests from client web
browsers. A shell script wrapper is included to make
starting, stopping, and restarting the server as simple as
possible. To start up Apache for
the first time, just run:
&prompt.root; /usr/local/sbin/apachectl start
You can stop the server at any time by typing:
&prompt.root; /usr/local/sbin/apachectl stop
After making changes to the configuration file for any
reason, you will need to restart the server:
&prompt.root; /usr/local/sbin/apachectl restart
To restart Apache without
aborting current connections, run:
&prompt.root; /usr/local/sbin/apachectl graceful
Additional information available at
&man.apachectl.8; manual page.
To launch Apache at system
startup, add the following line to
/etc/rc.conf:
apache_enable="YES"
If you would like to supply additional command line
options for the Apache
httpd program started at system boot, you
may specify them with an additional line in
rc.conf:
apache_flags=""
Now that the web server is running, you can view your web
site by pointing a web browser to
http://localhost/. The default web page
that is displayed is
/usr/local/www/data/index.html.
Virtual Hosting
Apache supports two different
types of Virtual Hosting. The first method is Name-based
Virtual Hosting. Name-based virtual hosting uses the clients
HTTP/1.1 headers to figure out the hostname. This allows many
different domains to share the same IP address.
To setup Apache to use
Name-based Virtual Hosting add an entry like the following to
your httpd.conf:
NameVirtualHost *
If your webserver was named www.domain.tld and
you wanted to setup a virtual domain for
www.someotherdomain.tld then you would add
the following entries to
httpd.conf:
<VirtualHost *>
ServerName www.domain.tld
DocumentRoot /www/domain.tld
</VirtualHost>
<VirtualHost *>
ServerName www.someotherdomain.tld
DocumentRoot /www/someotherdomain.tld
</VirtualHost>
Replace the addresses with the addresses you want to use
and the path to the documents with what you are using.
For more information about setting up virtual hosts,
please consult the official Apache
documentation at: .
Apache Modules
Apache
modules
There are many different Apache modules available to add
functionality to the basic server. The FreeBSD Ports
Collection provides an easy way to install
Apache together with some of the
more popular add-on modules.
mod_ssl
web servers
secure
SSL
cryptography
The mod_ssl module uses the OpenSSL library to provide
strong cryptography via the Secure Sockets Layer (SSL v2/v3)
and Transport Layer Security (TLS v1) protocols. This
module provides everything necessary to request a signed
certificate from a trusted certificate signing authority so
that you can run a secure web server on &os;.
If you have not yet installed
Apache, then a version of Apache
1.3.X that includes mod_ssl may be installed with the www/apache13-modssl port. SSL
support is also available for Apache 2.X in the
www/apache20 port,
where it is enabled by default.
Dynamic Websites with Perl & PHP
In the past few years, more businesses have turned to the
Internet in order to enhance their revenue and increase
exposure. This has also increased the need for interactive
web content. While some companies, such as µsoft;, have
introduced solutions into their proprietary products, the
open source community answered the call. Two options for
dynamic web content include mod_perl & mod_php.
mod_perl
mod_perl
Perl
The Apache/Perl integration project brings together the
full power of the Perl programming language and the Apache
HTTP Server. With the mod_perl module it is possible to
write Apache modules entirely in Perl. In addition, the
persistent interpreter embedded in the server avoids the
overhead of starting an external interpreter and the penalty
of Perl start-up time.
mod_perl is available a few
different ways. To use mod_perl
remember that mod_perl 1.0 only
works with Apache 1.3 and
mod_perl 2.0 only works with
Apache 2.
mod_perl 1.0 is available in
www/mod_perl and a
statically compiled version is available in
www/apache13-modperl.
mod_perl 2.0 is avaliable in
www/mod_perl2.
Tom
Rhodes
Written by
mod_php
mod_php
PHP
PHP, also known as PHP:
Hypertext Preprocessor
is a general-purpose scripting
language that is especially suited for Web development.
Capable of being embedded into HTML its
syntax draws upon C, &java;, and Perl with the intention of
allowing web developers to write dynamically generated
webpages quickly.
To gain support for PHP5 for the
Apache web server, begin by
installing the
www/mod_php5
port.
This will install and configure the modules required
to support dynamic PHP applications. Check
to ensure the following lines have been added to
/usr/local/etc/apache/httpd.conf:
LoadModule php5_module libexec/apache/libphp5.so
AddModule mod_php5.c
<IfModule mod_php5.c>
DirectoryIndex index.php index.html
</IfModule>
<IfModule mod_php5.c>
AddType application/x-httpd-php .php
AddType application/x-httpd-php-source .phps
</IfModule>
Once completed, a simple call to the
apachectl command for a graceful
restart is needed to load the PHP
module:
&prompt.root; apachectl graceful
The PHP support in &os; is extremely
modular so the base install is very limited. It is very easy
to add support using the
lang/php5-extensions port.
This port provides a menu driven interface to
PHP extension installation.
Alternatively, individual extensions can be installed using
the appropriate port.
For instance, to add support for the
MySQL database server to
PHP5, simply install the
databases/php5-mysql
port.
After installing an extension, the
Apache server must be reloaded to
pick up the new configuration changes.
&prompt.root; apachectl graceful
Murray
Stokely
Contributed by
File Transfer Protocol (FTP)
FTP servers
Overview
The File Transfer Protocol (FTP) provides users with a
simple way to transfer files to and from an FTP server. &os;
includes FTP
server software, ftpd, in the base
system. This makes setting up and administering an FTP server on FreeBSD
very straightforward.
Configuration
The most important configuration step is deciding which
accounts will be allowed access to the FTP server. A normal
FreeBSD system has a number of system accounts used for
various daemons, but unknown users should not be allowed to
log in with these accounts. The
/etc/ftpusers file is a list of users
disallowed any FTP access. By default, it includes the
aforementioned system accounts, but it is possible to add
specific users here that should not be allowed access to
FTP.
You may want to restrict the access of some users without
preventing them completely from using FTP. This can be
accomplished with the /etc/ftpchroot
file. This file lists users and groups subject to FTP access
restrictions. The &man.ftpchroot.5; manual page has all of
the details so it will not be described in detail here.
FTP
anonymous
If you would like to enable anonymous FTP access to your
server, then you must create a user named
ftp on your &os; system. Users will then
be able to log on to your FTP server with a username of
ftp or anonymous and
with any password (by convention an email address for the user
should be used as the password). The FTP server will call
&man.chroot.2; when an anonymous user logs in, to restrict
access to only the home directory of the
ftp user.
There are two text files that specify welcome messages to
be displayed to FTP clients. The contents of the file
/etc/ftpwelcome will be displayed to
users before they reach the login prompt. After a successful
login, the contents of the file
/etc/ftpmotd will be displayed. Note
that the path to this file is relative to the login environment, so the
file ~ftp/etc/ftpmotd would be displayed
for anonymous users.
Once the FTP server has been configured properly, it must
be enabled in /etc/inetd.conf. All that
is required here is to remove the comment symbol
#
from in front of the existing
ftpd line :
ftp stream tcp nowait root /usr/libexec/ftpd ftpd -l
As explained in , a
HangUP Signal must be sent to inetd
after this configuration file is changed.
You can now log on to your FTP server by typing:
&prompt.user; ftp localhost
Maintaining
syslog
log files
FTP
The ftpd daemon uses
&man.syslog.3; to log messages. By default, the system log
daemon will put messages related to FTP in the
/var/log/xferlog file. The location of
the FTP log can be modified by changing the following line in
/etc/syslog.conf:
ftp.info /var/log/xferlog
FTP
anonymous
Be aware of the potential problems involved with running
an anonymous FTP server. In particular, you should think
twice about allowing anonymous users to upload files. You may
find that your FTP site becomes a forum for the trade of
unlicensed commercial software or worse. If you do need to
allow anonymous FTP uploads, then you should set up the
permissions so that these files can not be read by other
anonymous users until they have been reviewed.
Murray
Stokely
Contributed by
File and Print Services for µsoft.windows; clients (Samba)
Samba server
Microsoft Windows
file server
Windows clients
print server
Windows clients
Overview
Samba is a popular open source
software package that provides file and print services for
µsoft.windows; clients. Such clients can connect to and
use FreeBSD filespace as if it was a local disk drive, or
FreeBSD printers as if they were local printers.
Samba software packages should
be included on your FreeBSD installation media. If you did
not install Samba when you first
installed FreeBSD, then you can install it from the net/samba3 port or package.
Configuration
A default Samba configuration
file is installed as
/usr/local/etc/smb.conf.default. This
file must be copied to
/usr/local/etc/smb.conf and customized
before Samba can be used.
The smb.conf file contains runtime
configuration information for
Samba, such as definitions of the
printers and file system shares
that you would
like to share with &windows; clients. The
Samba package includes a web based
tool called swat which provides a
simple way of configuring the smb.conf
file.
Using the Samba Web Administration Tool (SWAT)
The Samba Web Administration Tool (SWAT) runs as a
daemon from inetd. Therefore, the
following line in /etc/inetd.conf
should be uncommented before swat can be
used to configure Samba:
swat stream tcp nowait/400 root /usr/local/sbin/swat
As explained in , a
HangUP Signal must be sent to
inetd after this configuration
file is changed.
Once swat has been enabled in
inetd.conf, you can use a browser to
connect to . You will
first have to log on with the system root account.
Once you have successfully logged on to the main
Samba configuration page, you can
browse the system documentation, or begin by clicking on the
Globals tab. The Globals section corresponds to the
variables that are set in the [global]
section of
/usr/local/etc/smb.conf.
Global Settings
Whether you are using swat or
editing /usr/local/etc/smb.conf
directly, the first directives you are likely to encounter
when configuring Samba
are:
workgroup
NT Domain-Name or Workgroup-Name for the computers
that will be accessing this server.
netbios name
NetBIOS
This sets the NetBIOS name by which a Samba server
is known. By default it is the same as the first
component of the host's DNS name.
server string
This sets the string that will be displayed with
the net view command and some other
networking tools that seek to display descriptive text
about the server.
Security Settings
Two of the most important settings in
/usr/local/etc/smb.conf are the
security model chosen, and the backend password format for
client users. The following directives control these
options:
security
The two most common options here are
security = share and security
= user. If your clients use usernames that
are the same as their usernames on your &os; machine
then you will want to use user level security. This
is the default security policy and it requires clients
to first log on before they can access shared
resources.
In share level security, client do not need to log
onto the server with a valid username and password
before attempting to connect to a shared resource.
This was the default security model for older versions
of Samba.
passdb backend
- NIS+
- LDAP
- SQL database
-
Samba has several
different backend authentication models. You can
- authenticate clients with LDAP, NIS+, a SQL database,
+ authenticate clients with LDAPLDAP,
+ NIS+NIS+, a SQL databaseSQL database,
or a modified password file. The default
authentication method is smbpasswd,
and that is all that will be covered here.
Assuming that the default smbpasswd
backend is used, the
/usr/local/private/smbpasswd file must
be created to allow Samba to
authenticate clients. If you would like to give all of
your &unix; user accounts access from &windows; clients, use the
following command:
&prompt.root; grep -v "^#" /etc/passwd | make_smbpasswd > /usr/local/private/smbpasswd
&prompt.root; chmod 600 /usr/local/private/smbpasswd
Please see the Samba
documentation for additional information about configuration
options. With the basics outlined here, you should have
everything you need to start running
Samba.
Starting Samba
To enable Samba when your
system boots, add the following line to
/etc/rc.conf:
samba_enable="YES"
You can then start Samba at any
time by typing:
&prompt.root; /usr/local/etc/rc.d/samba.sh start
Starting SAMBA: removing stale tdbs :
Starting nmbd.
Starting smbd.
Samba actually consists of
three separate daemons. You should see that both the
nmbd and smbd daemons
are started by the samba.sh script. If
you enabled winbind name resolution services in
smb.conf, then you will also see that
the winbindd daemon is started.
You can stop Samba at any time
by typing :
&prompt.root; /usr/local/etc/rc.d/samba.sh stop
Samba is a complex software
suite with functionality that allows broad integration with
µsoft.windows; networks. For more information about
functionality beyond the basic installation described here,
please see .
Tom
Hukins
Contributed by
Clock Synchronization with NTP
NTP
Overview
Over time, a computer's clock is prone to drift. The
Network Time Protocol (NTP) is one way to ensure your clock stays
accurate.
Many Internet services rely on, or greatly benefit from,
computers' clocks being accurate. For example, a web server
may receive requests to send a file if it has been modified since a
certain time. In a local area network environment, it is
essential that computers sharing files from the same file
server have synchronized clocks so that file timestamps stay
consistent. Services such as &man.cron.8; also rely on
an accurate system clock to run commands at the specified
times.
NTP
ntpd
FreeBSD ships with the &man.ntpd.8; NTP server which can be used to query
other NTP
servers to set the clock on your machine or provide time
services to others.
Choosing Appropriate NTP Servers
NTP
choosing servers
In order to synchronize your clock, you will need to find
one or more NTP servers to use. Your network
administrator or ISP may have set up an NTP server for this
purpose—check their documentation to see if this is the
case. There is an online
list of publicly accessible NTP servers which you can
use to find an NTP server near to you. Make sure you are
aware of the policy for any servers you choose, and ask for
permission if required.
Choosing several unconnected NTP servers is a good idea in
case one of the servers you are using becomes unreachable or
its clock is unreliable. &man.ntpd.8; uses the responses it
receives from other servers intelligently—it will favor
unreliable servers less than reliable ones.
Configuring Your Machine
NTP
configuration
Basic Configuration
ntpdate
If you only wish to synchronize your clock when the
machine boots up, you can use &man.ntpdate.8;. This may be
appropriate for some desktop machines which are frequently
rebooted and only require infrequent synchronization, but
most machines should run &man.ntpd.8;.
Using &man.ntpdate.8; at boot time is also a good idea
for machines that run &man.ntpd.8;. The &man.ntpd.8;
program changes the clock gradually, whereas &man.ntpdate.8;
sets the clock, no matter how great the difference between a
machine's current clock setting and the correct time.
To enable &man.ntpdate.8; at boot time, add
ntpdate_enable="YES" to
/etc/rc.conf. You will also need to
specify all servers you wish to synchronize with and any
flags to be passed to &man.ntpdate.8; in
ntpdate_flags.
General Configuration
NTP
ntp.conf
NTP is configured by the
/etc/ntp.conf file in the format
described in &man.ntp.conf.5;. Here is a simple
example:
server ntplocal.example.com prefer
server timeserver.example.org
server ntp2a.example.net
driftfile /var/db/ntp.drift
The server option specifies which
servers are to be used, with one server listed on each line.
If a server is specified with the prefer
argument, as with ntplocal.example.com, that server is
preferred over other servers. A response from a preferred
server will be discarded if it differs significantly from
other servers' responses, otherwise it will be used without
any consideration to other responses. The
prefer argument is normally used for NTP
servers that are known to be highly accurate, such as those
with special time monitoring hardware.
The driftfile option specifies which
file is used to store the system clock's frequency offset.
The &man.ntpd.8; program uses this to automatically
compensate for the clock's natural drift, allowing it to
maintain a reasonably correct setting even if it is cut off
from all external time sources for a period of time.
The driftfile option specifies which
file is used to store information about previous responses
from the NTP servers you are using. This file contains
internal information for NTP. It should not be modified by
any other process.
Controlling Access to Your Server
By default, your NTP server will be accessible to all
hosts on the Internet. The restrict
option in /etc/ntp.conf allows you to
control which machines can access your server.
If you want to deny all machines from accessing your NTP
server, add the following line to
/etc/ntp.conf:
restrict default ignore
If you only want to allow machines within your own
network to synchronize their clocks with your server, but
ensure they are not allowed to configure the server or used
as peers to synchronize against, add
restrict 192.168.1.0 mask 255.255.255.0 nomodify notrap
instead, where 192.168.1.0 is
an IP address on your network and 255.255.255.0 is your network's
netmask.
/etc/ntp.conf can contain multiple
restrict options. For more details, see
the Access Control Support subsection of
&man.ntp.conf.5;.
Running the NTP Server
To ensure the NTP server is started at boot time, add the
line ntpd_enable="YES" to
/etc/rc.conf. If you wish to pass
additional flags to &man.ntpd.8;, edit the
ntpd_flags parameter in
/etc/rc.conf.
To start the server without rebooting your machine, run
ntpd being sure to specify any additional
parameters from ntpd_flags in
/etc/rc.conf. For example:
&prompt.root; ntpd -p /var/run/ntpd.pid
Under &os; 4.X,
you have to replace every instance of ntpd
with xntpd in the options above.
Using ntpd with a Temporary Internet
Connection
The &man.ntpd.8; program does not need a permanent
connection to the Internet to function properly. However, if
you have a temporary connection that is configured to dial out
on demand, it is a good idea to prevent NTP traffic from
triggering a dial out or keeping the connection alive. If you
are using user PPP, you can use filter
directives in /etc/ppp/ppp.conf. For
example:
set filter dial 0 deny udp src eq 123
# Prevent NTP traffic from initiating dial out
set filter dial 1 permit 0 0
set filter alive 0 deny udp src eq 123
# Prevent incoming NTP traffic from keeping the connection open
set filter alive 1 deny udp dst eq 123
# Prevent outgoing NTP traffic from keeping the connection open
set filter alive 2 permit 0/0 0/0
For more details see the PACKET
FILTERING section in &man.ppp.8; and the examples in
/usr/share/examples/ppp/.
Some Internet access providers block low-numbered ports,
preventing NTP from functioning since replies never
reach your machine.
Further Information
Documentation for the NTP server can be found in
/usr/share/doc/ntp/ in HTML
format.
diff --git a/zh_TW.Big5/books/handbook/ppp-and-slip/chapter.xml b/zh_TW.Big5/books/handbook/ppp-and-slip/chapter.xml
index 234cd31fd2..d7d20829a5 100644
--- a/zh_TW.Big5/books/handbook/ppp-and-slip/chapter.xml
+++ b/zh_TW.Big5/books/handbook/ppp-and-slip/chapter.xml
@@ -1,3233 +1,3193 @@
Jim
Mock
Restructured, reorganized, and updated by
PPP and SLIP
Synopsis
PPP
SLIP
FreeBSD has a number of ways to link one computer to
another. To establish a network or Internet connection through a
dial-up modem, or to allow others to do so through you, requires
the use of PPP or SLIP. This chapter describes setting up
these modem-based communication services in detail.
After reading this chapter, you will know:
How to set up user PPP.
How to set up kernel PPP.
How to set up PPPoE (PPP over
Ethernet).
How to set up PPPoA (PPP over
ATM).
How to configure and set up a SLIP client and
server.
PPP
user PPP
PPP
kernel PPP
PPP
over Ethernet
Before reading this chapter, you should:
Be familiar with basic network terminology.
Understand the basics and purpose of a dialup connection
and PPP and/or SLIP.
You may be wondering what the main difference is between user
PPP and kernel PPP. The answer is simple: user PPP processes the
inbound and outbound data in userland rather than in the kernel.
This is expensive in terms of copying the data between the kernel
and userland, but allows a far more feature-rich PPP implementation.
User PPP uses the tun device to communicate
with the outside world whereas kernel PPP uses the
ppp device.
Throughout in this chapter, user PPP will simply be
referred to as ppp unless a distinction needs to be made between it
and any other PPP software such as pppd.
Unless otherwise stated, all of the commands explained in this
chapter should be executed as root.
Tom
Rhodes
Updated and enhanced by
Brian
Somers
Originally contributed by
Nik
Clayton
With input from
Dirk
Frömberg
Peter
Childs
Using User PPP
User PPP
Assumptions
This document assumes you have the following:
-
- ISP
-
-
- PPP
-
- An account with an Internet Service Provider (ISP) which
- you connect to using PPP.
+ An account with an Internet Service Provider (ISP)ISP which
+ you connect to using PPPPPP.
You have a modem or
other device connected to your system and configured
correctly which allows you to connect to your ISP.
The dial-up number(s) of your ISP.
-
- PAP
-
-
- CHAP
-
-
- UNIX
-
-
- login name
-
-
- password
-
- Your login name and password. (Either a
- regular &unix; style login and password pair, or a PAP or CHAP
+ Your login namelogin name and passwordpassword. (Either a
+ regular &unix;UNIX style login and password pair, or a
+ PAPPAP or CHAPCHAP
login and password pair.)
-
- nameserver
-
-
- The IP address of one or more name servers.
+ The IP address of one or more name serversnameserver.
Normally, you will be given two IP addresses by your ISP to
use for this. If they have not given you at least one, then
you can use the enable dns command in
ppp.conf and
ppp will set the name servers for
you. This feature depends on your ISPs PPP implementation
supporting DNS negotiation.
The following information may be supplied by your ISP, but
is not completely necessary:
The IP address of your ISP's gateway. The gateway is
the machine to which you will connect and will be set up as
your default route. If you do not have
this information, we can make one up and your ISP's PPP
server will tell us the correct value when we connect.
This IP number is referred to as
HISADDR by
ppp.
The netmask you should use. If your ISP has not
provided you with one, you can safely use 255.255.255.255.
-
- static IP address
-
-
- If your ISP provides you with a static IP address and
+ If your ISP provides you with a static IP addressstatic IP address and
hostname, you can enter it. Otherwise, we simply let the
peer assign whatever IP address it sees fit.
If you do not have any of the required information, contact
your ISP.
Throughout this section, many of the examples showing
the contents of configuration files are numbered by line.
These numbers serve to aid in the presentation and
discussion only and are not meant to be placed in the actual
file. Proper indentation with tab and space characters is
also important.
Creating PPP Device Nodes
PPPcreating device nodes
Under normal circumstances, most users will only need
one tun device
(/dev/tun0). References to
tun0 below may be changed to
tunN
where N is any unit number
corresponding to your system.
For FreeBSD installations that do not have &man.devfs.5; enabled
(FreeBSD 4.X and earlier), the existence of the
tun0 device should be verified (this is not
necessary if &man.devfs.5; is enabled as device nodes will be created
on demand).
The easiest way to make sure that the
tun0 device is configured correctly
is to remake the device. To remake the device, do the
following:
&prompt.root; cd /dev
&prompt.root; sh MAKEDEV tun0
If you need 16 tunnel devices in your kernel, you will need
to create them. This can be done by executing the following
commands:
&prompt.root; cd /dev
&prompt.root; sh MAKEDEV tun15
Automatic PPP Configuration
PPPconfiguration
Both ppp and pppd
(the kernel level implementation of PPP) use the configuration
files located in the /etc/ppp directory.
Examples for user ppp can be found in
/usr/share/examples/ppp/.
Configuring ppp requires that you edit a
number of files, depending on your requirements. What you put
in them depends to some extent on whether your ISP allocates IP
addresses statically (i.e., you get given one IP address, and
always use that one) or dynamically (i.e., your IP address
changes each time you connect to your ISP).
PPP and Static IP Addresses
PPPwith static IP addresses
You will need to edit the
/etc/ppp/ppp.conf configuration file. It
should look similar to the example below.
Lines that end in a : start in
the first column (beginning of the line)— all other
lines should be indented as shown using spaces or
tabs.
1 default:
2 set log Phase Chat LCP IPCP CCP tun command
3 ident user-ppp VERSION (built COMPILATIONDATE)
4 set device /dev/cuaa0
5 set speed 115200
6 set dial "ABORT BUSY ABORT NO\\sCARRIER TIMEOUT 5 \
7 \"\" AT OK-AT-OK ATE1Q0 OK \\dATDT\\T TIMEOUT 40 CONNECT"
8 set timeout 180
9 enable dns
10
11 provider:
12 set phone "(123) 456 7890"
13 set authname foo
14 set authkey bar
15 set login "TIMEOUT 10 \"\" \"\" gin:--gin: \\U word: \\P col: ppp"
16 set timeout 300
17 set ifaddr x.x.x.x y.y.y.y 255.255.255.255 0.0.0.0
18 add default HISADDR
Line 1:
Identifies the default entry. Commands in this
entry are executed automatically when ppp is run.
Line 2:
Enables logging parameters. When the configuration
is working satisfactorily, this line should be reduced
to saying
set log phase tun
in order to avoid excessive log file sizes.
Line 3:
Tells PPP how to identify itself to the peer.
PPP identifies itself to the peer if it has any trouble
negotiating and setting up the link, providing information
that the peers administrator may find useful when
investigating such problems.
Line 4:
Identifies the device to which the modem is
connected. COM1 is
/dev/cuaa0 and
COM2 is
/dev/cuaa1.
Line 5:
Sets the speed you want to connect at. If 115200
does not work (it should with any reasonably new modem),
try 38400 instead.
Line 6 & 7:
- PPPuser PPP
-
- The dial string. User PPP uses an expect-send
+ The dial string. User PPPPPPuser PPP uses an expect-send
syntax similar to the &man.chat.8; program. Refer to
the manual page for information on the features of this
language.
Note that this command continues onto the next line
for readability. Any command in
ppp.conf may do this if the last
character on the line is a ``\'' character.
Line 8:
Sets the idle timeout for the link. 180 seconds
is the default, so this line is purely cosmetic.
Line 9:
Tells PPP to ask the peer to confirm the local
resolver settings. If you run a local name server, this
line should be commented out or removed.
Line 10:
A blank line for readability. Blank lines are ignored
by PPP.
Line 11:
Identifies an entry for a provider called
provider
. This could be changed
to the name of your ISP so
that later you can use the
to start the connection.
Line 12:
Sets the phone number for this provider. Multiple
phone numbers may be specified using the colon
(:) or pipe character
(|)as a separator. The difference
between the two separators is described in &man.ppp.8;.
To summarize, if you want to rotate through the numbers,
use a colon. If you want to always attempt to dial the
first number first and only use the other numbers if the
first number fails, use the pipe character. Always
quote the entire set of phone numbers as shown.
You must enclose the phone number in quotation marks
(") if there is any intention on using
spaces in the phone number. This can cause a simple, yet
subtle error.
Line 13 & 14:
Identifies the user name and password. When
connecting using a &unix; style login prompt, these
values are referred to by the set
login command using the \U and \P
variables. When connecting using PAP or CHAP, these
values are used at authentication time.
Line 15:
- PAP
- CHAP
If you are using PAP or CHAP, there will be no login
at this point, and this line should be commented out or
- removed. See PAP and CHAP
+ removed. See PAPPAP and CHAPCHAP
authentication for further details.
The login string is of the same chat-like syntax as
the dial string. In this example, the string works for
a service whose login session looks like this:
J. Random Provider
login: foo
password: bar
protocol: ppp
You will need to alter this script to suit your
own needs. When you write this script for the first
time, you should ensure that you have enabled
chat
logging so you can determine if
the conversation is going as expected.
Line 16:
- timeout
-
- Sets the default idle timeout (in seconds) for the
+ Sets the default idle timeouttimeout (in seconds) for the
connection. Here, the connection will be closed
automatically after 300 seconds of inactivity. If you
never want to timeout, set this value to zero or use
the command line switch.
Line 17:
- ISP
-
Sets the interface addresses. The string
x.x.x.x should be
replaced by the IP address that your provider has
allocated to you. The string
y.y.y.y should be
replaced by the IP address that your ISP indicated
for their gateway (the machine to which you
- connect). If your ISP has not given you a gateway
+ connect). If your ISPISP has not given you a gateway
address, use 10.0.0.2/0. If you need to
use a guessed
address, make sure that
you create an entry in
/etc/ppp/ppp.linkup as per the
instructions for PPP and Dynamic IP
addresses. If this line is omitted,
ppp cannot run in
mode.
Line 18:
Adds a default route to your ISP's gateway. The
special word HISADDR is replaced with
the gateway address specified on line 17. It is
important that this line appears after line 17,
otherwise HISADDR will not yet be
initialized.
If you do not wish to run ppp in ,
this line should be moved to the
ppp.linkup file.
It is not necessary to add an entry to
ppp.linkup when you have a static IP
address and are running ppp in mode as your
routing table entries are already correct before you connect.
You may however wish to create an entry to invoke programs after
connection. This is explained later with the sendmail
example.
Example configuration files can be found in the
/usr/share/examples/ppp/ directory.
PPP and Dynamic IP Addresses
PPPwith dynamic IP addresses
IPCP
If your service provider does not assign static IP
addresses, ppp can be configured to
negotiate the local and remote addresses. This is done by
guessing
an IP address and allowing
ppp to set it up correctly using the IP
Configuration Protocol (IPCP) after connecting. The
ppp.conf configuration is the same as
PPP and Static IP
Addresses, with the following change:
17 set ifaddr 10.0.0.1/0 10.0.0.2/0 255.255.255.255
Again, do not include the line number, it is just for
reference. Indentation of at least one space is
required.
Line 17:
The number after the / character
is the number of bits of the address that ppp will
insist on. You may wish to use IP numbers more
appropriate to your circumstances, but the above example
will always work.
The last argument (0.0.0.0) tells
PPP to start negotiations using address 0.0.0.0 rather than 10.0.0.1 and is necessary for some
ISPs. Do not use 0.0.0.0 as the first
argument to set ifaddr as it prevents
PPP from setting up an initial route in
mode.
If you are not running in mode, you
will need to create an entry in
/etc/ppp/ppp.linkup.
ppp.linkup is used after a connection has
been established. At this point, ppp will
have assigned the interface addresses and it will now be
possible to add the routing table entries:
1 provider:
2 add default HISADDR
Line 1:
On establishing a connection,
ppp will look for an entry in
ppp.linkup according to the
following rules: First, try to match the same label
as we used in ppp.conf. If
that fails, look for an entry for the IP address of
our gateway. This entry is a four-octet IP style
label. If we still have not found an entry, look
for the MYADDR entry.
Line 2:
This line tells ppp to add a
default route that points to
HISADDR.
HISADDR will be replaced with the
IP number of the gateway as negotiated by the
IPCP.
See the pmdemand entry in the files
/usr/share/examples/ppp/ppp.conf.sample
and
/usr/share/examples/ppp/ppp.linkup.sample
for a detailed example.
Receiving Incoming Calls
PPPreceiving
incoming calls
When you configure ppp to
receive incoming calls on a machine connected to a LAN, you
must decide if you wish to forward packets to the LAN. If you
do, you should allocate the peer an IP number from your LAN's
subnet, and use the command enable proxy in
your /etc/ppp/ppp.conf file. You should
also confirm that the /etc/rc.conf file
contains the following:
gateway_enable="YES"
Which getty?
Configuring FreeBSD for Dial-up
Services provides a good description on enabling
dial-up services using &man.getty.8;.
An alternative to getty is mgetty,
a smarter version of getty designed
with dial-up lines in mind.
The advantages of using mgetty is
that it actively talks to modems,
meaning if port is turned off in
/etc/ttys then your modem will not answer
the phone.
Later versions of mgetty (from
0.99beta onwards) also support the automatic detection of
PPP streams, allowing your clients script-less access to
your server.
Refer to Mgetty and
AutoPPP for more information on
mgetty.
PPP Permissions
The ppp command must normally be
run as the root user. If however,
you wish to allow ppp to run in
server mode as a normal user by executing
ppp as described below, that user
must be given permission to run ppp
by adding them to the network group
in /etc/group.
You will also need to give them access to one or more
sections of the configuration file using the
allow command:
allow users fred mary
If this command is used in the default
section, it gives the specified users access to
everything.
PPP Shells for Dynamic-IP Users
PPP shells
Create a file called
/etc/ppp/ppp-shell containing the
following:
#!/bin/sh
IDENT=`echo $0 | sed -e 's/^.*-\(.*\)$/\1/'`
CALLEDAS="$IDENT"
TTY=`tty`
if [ x$IDENT = xdialup ]; then
IDENT=`basename $TTY`
fi
echo "PPP for $CALLEDAS on $TTY"
echo "Starting PPP for $IDENT"
exec /usr/sbin/ppp -direct $IDENT
This script should be executable. Now make a symbolic
link called ppp-dialup to this script
using the following commands:
&prompt.root; ln -s ppp-shell /etc/ppp/ppp-dialup
You should use this script as the
shell for all of your dialup users.
This is an example from /etc/passwd
for a dialup PPP user with username
pchilds (remember do not directly edit
the password file, use &man.vipw.8;).
pchilds:*:1011:300:Peter Childs PPP:/home/ppp:/etc/ppp/ppp-dialup
Create a /home/ppp directory that
is world readable containing the following 0 byte
files:
-r--r--r-- 1 root wheel 0 May 27 02:23 .hushlogin
-r--r--r-- 1 root wheel 0 May 27 02:22 .rhosts
which prevents /etc/motd from being
displayed.
PPP Shells for Static-IP Users
PPP shells
Create the ppp-shell file as above,
and for each account with statically assigned IPs create a
symbolic link to ppp-shell.
For example, if you have three dialup customers,
fred, sam, and
mary, that you route class C networks
for, you would type the following:
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-fred
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-sam
&prompt.root; ln -s /etc/ppp/ppp-shell /etc/ppp/ppp-mary
Each of these users dialup accounts should have their
shell set to the symbolic link created above (for example,
mary's shell should be
/etc/ppp/ppp-mary).
Setting Up ppp.conf for Dynamic-IP Users
The /etc/ppp/ppp.conf file should
contain something along the lines of:
default:
set debug phase lcp chat
set timeout 0
ttyd0:
set ifaddr 203.14.100.1 203.14.100.20 255.255.255.255
enable proxy
ttyd1:
set ifaddr 203.14.100.1 203.14.100.21 255.255.255.255
enable proxy
The indenting is important.
The default: section is loaded for
each session. For each dialup line enabled in
/etc/ttys create an entry similar to
the one for ttyd0: above. Each line
should get a unique IP address from your pool of IP
addresses for dynamic users.
Setting Up ppp.conf for Static-IP
Users
Along with the contents of the sample
/usr/share/examples/ppp/ppp.conf
above you should add a section for each of the
statically assigned dialup users. We will continue with
our fred, sam,
and mary example.
fred:
set ifaddr 203.14.100.1 203.14.101.1 255.255.255.255
sam:
set ifaddr 203.14.100.1 203.14.102.1 255.255.255.255
mary:
set ifaddr 203.14.100.1 203.14.103.1 255.255.255.255
The file /etc/ppp/ppp.linkup
should also contain routing information for each static
IP user if required. The line below would add a route
for the 203.14.101.0
class C via the client's ppp link.
fred:
add 203.14.101.0 netmask 255.255.255.0 HISADDR
sam:
add 203.14.102.0 netmask 255.255.255.0 HISADDR
mary:
add 203.14.103.0 netmask 255.255.255.0 HISADDR
mgetty and AutoPPP
mgetty
AutoPPP
LCP
Configuring and compiling mgetty
with the AUTO_PPP option enabled
allows mgetty to detect the LCP phase
of PPP connections and automatically spawn off a ppp
shell. However, since the default login/password
sequence does not occur it is necessary to authenticate
users using either PAP or CHAP.
This section assumes the user has successfully
configured, compiled, and installed a version of
mgetty with the
AUTO_PPP option (v0.99beta or
later).
Make sure your
/usr/local/etc/mgetty+sendfax/login.config
file has the following in it:
/AutoPPP/ - - /etc/ppp/ppp-pap-dialup
This will tell mgetty to run the
ppp-pap-dialup script for detected
PPP connections.
Create a file called
/etc/ppp/ppp-pap-dialup containing the
following (the file should be executable):
#!/bin/sh
exec /usr/sbin/ppp -direct pap$IDENT
For each dialup line enabled in
/etc/ttys, create a corresponding entry
in /etc/ppp/ppp.conf. This will
happily co-exist with the definitions we created
above.
pap:
enable pap
set ifaddr 203.14.100.1 203.14.100.20-203.14.100.40
enable proxy
Each user logging in with this method will need to have
a username/password in
/etc/ppp/ppp.secret file, or
alternatively add the following option to authenticate users
via PAP from the /etc/passwd file.
enable passwdauth
If you wish to assign some users a static IP number,
you can specify the number as the third argument in
/etc/ppp/ppp.secret. See
/usr/share/examples/ppp/ppp.secret.sample
for examples.
MS Extensions
DNS
NetBIOS
PPPMicrosoft extensions
It is possible to configure PPP to supply DNS and
NetBIOS nameserver addresses on demand.
To enable these extensions with PPP version 1.x, the
following lines might be added to the relevant section of
/etc/ppp/ppp.conf.
enable msext
set ns 203.14.100.1 203.14.100.2
set nbns 203.14.100.5
And for PPP version 2 and above:
accept dns
set dns 203.14.100.1 203.14.100.2
set nbns 203.14.100.5
This will tell the clients the primary and secondary
name server addresses, and a NetBIOS nameserver host.
In version 2 and above, if the
set dns line is omitted, PPP will use the
values found in /etc/resolv.conf.
PAP and CHAP Authentication
PAP
CHAP
Some ISPs set their system up so that the authentication
part of your connection is done using either of the PAP or
CHAP authentication mechanisms. If this is the case, your ISP
will not give a login: prompt when you
connect, but will start talking PPP immediately.
PAP is less secure than CHAP, but security is not normally
an issue here as passwords, although being sent as plain text
with PAP, are being transmitted down a serial line only.
There is not much room for crackers to
eavesdrop
.
Referring back to the PPP
and Static IP addresses or PPP and Dynamic IP addresses
sections, the following alterations must be made:
13 set authname MyUserName
14 set authkey MyPassword
15 set login
Line 13:
This line specifies your PAP/CHAP user name. You
will need to insert the correct value for
MyUserName.
Line 14:
- password
-
- This line specifies your PAP/CHAP password. You
+ This line specifies your PAP/CHAP passwordpassword. You
will need to insert the correct value for
MyPassword. You may want to
add an additional line, such as:
16 accept PAP
or
16 accept CHAP
to make it obvious that this is the intention, but
PAP and CHAP are both accepted by default.
Line 15:
Your ISP will not normally require that you log into
the server if you are using PAP or CHAP. You must
therefore disable your set login
string.
Changing Your ppp Configuration on the
Fly
It is possible to talk to the ppp
program while it is running in the background, but only if a
suitable diagnostic port has been set up. To do this, add the
following line to your configuration:
set server /var/run/ppp-tun%d DiagnosticPassword 0177
This will tell PPP to listen to the specified
&unix; domain socket, asking clients for the specified
password before allowing access. The
%d in the name is replaced with the
tun device number that is in
use.
Once a socket has been set up, the &man.pppctl.8;
program may be used in scripts that wish to manipulate the
running program.
Using PPP Network Address Translation Capability
PPPNAT
PPP has ability to use internal NAT without kernel diverting
capabilities. This functionality may be enabled by the following
line in /etc/ppp/ppp.conf:
nat enable yes
Alternatively, PPP NAT may be enabled by command-line
option -nat. There is also
/etc/rc.conf knob named
ppp_nat, which is enabled by default.
If you use this feature, you may also find useful
the following /etc/ppp/ppp.conf options
to enable incoming connections forwarding:
nat port tcp 10.0.0.2:ftp ftp
nat port tcp 10.0.0.2:http http
or do not trust the outside at all
nat deny_incoming yes
Final System Configuration
PPPconfiguration
You now have ppp configured, but there
are a few more things to do before it is ready to work. They
all involve editing the /etc/rc.conf
file.
Working from the top down in this file, make sure the
hostname= line is set, e.g.:
hostname="foo.example.com"
If your ISP has supplied you with a static IP address and
name, it is probably best that you use this name as your host
name.
Look for the network_interfaces variable.
If you want to configure your system to dial your ISP on demand,
make sure the tun0 device is added to
the list, otherwise remove it.
network_interfaces="lo0 tun0"
ifconfig_tun0=
The ifconfig_tun0 variable should be
empty, and a file called
/etc/start_if.tun0 should be created.
This file should contain the line:
ppp -auto mysystem
This script is executed at network configuration time,
starting your ppp daemon in automatic mode. If you have a LAN
for which this machine is a gateway, you may also wish to use
the switch. Refer to the manual page
for further details.
Make sure that the router program is set to NO with
the following line in your
/etc/rc.conf:
router_enable="NO"
routed
It is important that the routed daemon is
not started, as
routed tends to delete the default routing
table entries created by ppp.
It is probably worth your while ensuring that the
sendmail_flags line does not include the
option, otherwise
sendmail will attempt to do a network lookup
every now and then, possibly causing your machine to dial out.
You may try:
sendmail_flags="-bd"
sendmail
The downside of this is that you must force
sendmail to re-examine the mail queue
whenever the ppp link is up by typing:
&prompt.root; /usr/sbin/sendmail -q
You may wish to use the !bg command in
ppp.linkup to do this automatically:
1 provider:
2 delete ALL
3 add 0 0 HISADDR
4 !bg sendmail -bd -q30m
SMTP
If you do not like this, it is possible to set up a
dfilter
to block SMTP traffic. Refer to the
sample files for further details.
All that is left is to reboot the machine. After rebooting,
you can now either type:
&prompt.root; ppp
and then dial provider to start the PPP
session, or, if you want ppp to establish
sessions automatically when there is outbound traffic (and
you have not created the start_if.tun0
script), type:
&prompt.root; ppp -auto provider
Summary
To recap, the following steps are necessary when setting up
ppp for the first time:
Client side:
Ensure that the tun device is
built into your kernel.
Ensure that the
tunN device
file is available in the /dev
directory.
Create an entry in
/etc/ppp/ppp.conf. The
pmdemand example should suffice for
most ISPs.
If you have a dynamic IP address, create an entry in
/etc/ppp/ppp.linkup.
Update your /etc/rc.conf
file.
Create a start_if.tun0 script if
you require demand dialing.
Server side:
Ensure that the tun device is
built into your kernel.
Ensure that the
tunN device
file is available in the /dev
directory.
Create an entry in /etc/passwd
(using the &man.vipw.8; program).
Create a profile in this users home directory that runs
ppp -direct direct-server or
similar.
Create an entry in
/etc/ppp/ppp.conf. The
direct-server example should
suffice.
Create an entry in
/etc/ppp/ppp.linkup.
Update your /etc/rc.conf
file.
Gennady B.
Sorokopud
Parts originally contributed by
Robert
Huff
Using Kernel PPP
Setting Up Kernel PPP
PPPkernel PPP
Before you start setting up PPP on your machine, make sure
that pppd is located in
/usr/sbin and the directory
/etc/ppp exists.
pppd can work in two modes:
As a client
— you want to connect your
machine to the outside world via a PPP serial connection or
modem line.
- PPPserver
-
- As a server
— your machine is located on
+ As a server
PPPserver — your machine is located on
the network, and is used to connect other computers using
PPP.
In both cases you will need to set up an options file
(/etc/ppp/options or
~/.ppprc if you have more than one user on
your machine that uses PPP).
You will also need some modem/serial software (preferably
comms/kermit), so you can dial and
establish a connection with the remote host.
Trev
Roydhouse
Based on information provided by
Using pppd as a Client
PPPclient
Cisco
The following /etc/ppp/options might be
used to connect to a Cisco terminal server PPP line.
crtscts # enable hardware flow control
modem # modem control line
noipdefault # remote PPP server must supply your IP address
# if the remote host does not send your IP during IPCP
# negotiation, remove this option
passive # wait for LCP packets
domain ppp.foo.com # put your domain name here
:<remote_ip> # put the IP of remote PPP host here
# it will be used to route packets via PPP link
# if you didn't specified the noipdefault option
# change this line to <local_ip>:<remote_ip>
defaultroute # put this if you want that PPP server will be your
# default router
To connect:
Kermit
modem
Dial to the remote host using Kermit (or some other modem
program), and enter your user name and password (or whatever
is needed to enable PPP on the remote host).
Exit Kermit (without
hanging up the line).
Enter the following:
&prompt.root; /usr/src/usr.sbin/pppd.new/pppd /dev/tty01 19200
Be sure to use the appropriate speed and device name.
Now your computer is connected with PPP. If the connection
fails, you can add the option to the
/etc/ppp/options file, and check console messages
to track the problem.
Following /etc/ppp/pppup script will make
all 3 stages automatic:
#!/bin/sh
ps ax |grep pppd |grep -v grep
pid=`ps ax |grep pppd |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
ps ax |grep kermit |grep -v grep
pid=`ps ax |grep kermit |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
ifconfig ppp0 down
ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.dial
pppd /dev/tty01 19200
Kermit
/etc/ppp/kermit.dial is a Kermit
script that dials and makes all necessary authorization on the
remote host (an example of such a script is attached to the end
of this document).
Use the following /etc/ppp/pppdown script
to disconnect the PPP line:
#!/bin/sh
pid=`ps ax |grep pppd |grep -v grep|awk '{print $1;}'`
if [ X${pid} != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill -TERM ${pid}
fi
ps ax |grep kermit |grep -v grep
pid=`ps ax |grep kermit |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
/sbin/ifconfig ppp0 down
/sbin/ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.hup
/etc/ppp/ppptest
Check to see if pppd is still running by executing
/usr/etc/ppp/ppptest, which should look like
this:
#!/bin/sh
pid=`ps ax| grep pppd |grep -v grep|awk '{print $1;}'`
if [ X${pid} != "X" ] ; then
echo 'pppd running: PID=' ${pid-NONE}
else
echo 'No pppd running.'
fi
set -x
netstat -n -I ppp0
ifconfig ppp0
To hang up the modem, execute
/etc/ppp/kermit.hup, which should
contain:
set line /dev/tty01 ; put your modem device here
set speed 19200
set file type binary
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
pau 1
out +++
inp 5 OK
out ATH0\13
echo \13
exit
Here is an alternate method using chat
instead of kermit:
The following two files are sufficient to accomplish a
pppd connection.
/etc/ppp/options:
/dev/cuaa1 115200
crtscts # enable hardware flow control
modem # modem control line
connect "/usr/bin/chat -f /etc/ppp/login.chat.script"
noipdefault # remote PPP serve must supply your IP address
# if the remote host doesn't send your IP during
# IPCP negotiation, remove this option
passive # wait for LCP packets
domain <your.domain> # put your domain name here
: # put the IP of remote PPP host here
# it will be used to route packets via PPP link
# if you didn't specified the noipdefault option
# change this line to <local_ip>:<remote_ip>
defaultroute # put this if you want that PPP server will be
# your default router
/etc/ppp/login.chat.script:
The following should go on a single line.
ABORT BUSY ABORT 'NO CARRIER' "" AT OK ATDT<phone.number>
CONNECT "" TIMEOUT 10 ogin:-\\r-ogin: <login-id>
TIMEOUT 5 sword: <password>
Once these are installed and modified correctly, all you need
to do is run pppd, like so:
&prompt.root; pppd
Using pppd as a Server
/etc/ppp/options should contain something
similar to the following:
crtscts # Hardware flow control
netmask 255.255.255.0 # netmask (not required)
192.114.208.20:192.114.208.165 # IP's of local and remote hosts
# local ip must be different from one
# you assigned to the Ethernet (or other)
# interface on your machine.
# remote IP is IP address that will be
# assigned to the remote machine
domain ppp.foo.com # your domain
passive # wait for LCP
modem # modem line
The following /etc/ppp/pppserv script
will tell pppd to behave as a
server:
#!/bin/sh
ps ax |grep pppd |grep -v grep
pid=`ps ax |grep pppd |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
ps ax |grep kermit |grep -v grep
pid=`ps ax |grep kermit |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
# reset ppp interface
ifconfig ppp0 down
ifconfig ppp0 delete
# enable autoanswer mode
kermit -y /etc/ppp/kermit.ans
# run ppp
pppd /dev/tty01 19200
Use this /etc/ppp/pppservdown script to
stop the server:
#!/bin/sh
ps ax |grep pppd |grep -v grep
pid=`ps ax |grep pppd |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing pppd, PID=' ${pid}
kill ${pid}
fi
ps ax |grep kermit |grep -v grep
pid=`ps ax |grep kermit |grep -v grep|awk '{print $1;}'`
if [ "X${pid}" != "X" ] ; then
echo 'killing kermit, PID=' ${pid}
kill -9 ${pid}
fi
ifconfig ppp0 down
ifconfig ppp0 delete
kermit -y /etc/ppp/kermit.noans
The following Kermit script
(/etc/ppp/kermit.ans) will enable/disable
autoanswer mode on your modem. It should look like this:
set line /dev/tty01
set speed 19200
set file type binary
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
pau 1
out +++
inp 5 OK
out ATH0\13
inp 5 OK
echo \13
out ATS0=1\13 ; change this to out ATS0=0\13 if you want to disable
; autoanswer mode
inp 5 OK
echo \13
exit
A script named /etc/ppp/kermit.dial is
used for dialing and authenticating on the remote host. You will
need to customize it for your needs. Put your login and password
in this script; you will also need to change the input statement
depending on responses from your modem and remote host.
;
; put the com line attached to the modem here:
;
set line /dev/tty01
;
; put the modem speed here:
;
set speed 19200
set file type binary ; full 8 bit file xfer
set file names literal
set win 8
set rec pack 1024
set send pack 1024
set block 3
set term bytesize 8
set command bytesize 8
set flow none
set modem hayes
set dial hangup off
set carrier auto ; Then SET CARRIER if necessary,
set dial display on ; Then SET DIAL if necessary,
set input echo on
set input timeout proceed
set input case ignore
def \%x 0 ; login prompt counter
goto slhup
:slcmd ; put the modem in command mode
echo Put the modem in command mode.
clear ; Clear unread characters from input buffer
pause 1
output +++ ; hayes escape sequence
input 1 OK\13\10 ; wait for OK
if success goto slhup
output \13
pause 1
output at\13
input 1 OK\13\10
if fail goto slcmd ; if modem doesn't answer OK, try again
:slhup ; hang up the phone
clear ; Clear unread characters from input buffer
pause 1
echo Hanging up the phone.
output ath0\13 ; hayes command for on hook
input 2 OK\13\10
if fail goto slcmd ; if no OK answer, put modem in command mode
:sldial ; dial the number
pause 1
echo Dialing.
output atdt9,550311\13\10 ; put phone number here
assign \%x 0 ; zero the time counter
:look
clear ; Clear unread characters from input buffer
increment \%x ; Count the seconds
input 1 {CONNECT }
if success goto sllogin
reinput 1 {NO CARRIER\13\10}
if success goto sldial
reinput 1 {NO DIALTONE\13\10}
if success goto slnodial
reinput 1 {\255}
if success goto slhup
reinput 1 {\127}
if success goto slhup
if < \%x 60 goto look
else goto slhup
:sllogin ; login
assign \%x 0 ; zero the time counter
pause 1
echo Looking for login prompt.
:slloop
increment \%x ; Count the seconds
clear ; Clear unread characters from input buffer
output \13
;
; put your expected login prompt here:
;
input 1 {Username: }
if success goto sluid
reinput 1 {\255}
if success goto slhup
reinput 1 {\127}
if success goto slhup
if < \%x 10 goto slloop ; try 10 times to get a login prompt
else goto slhup ; hang up and start again if 10 failures
:sluid
;
; put your userid here:
;
output ppp-login\13
input 1 {Password: }
;
; put your password here:
;
output ppp-password\13
input 1 {Entering SLIP mode.}
echo
quit
:slnodial
echo \7No dialtone. Check the telephone line!\7
exit 1
; local variables:
; mode: csh
; comment-start: "; "
; comment-start-skip: "; "
; end:
Tom
Rhodes
Contributed by
Troubleshooting PPP Connections
PPPtroubleshooting
This section covers a few issues which may arise when
using PPP over a modem connection. For instance, perhaps you
need to know exactly what prompts the system you are dialing
into will present. Some ISPs present the
ssword prompt, and others will present
password; if the ppp
script is not written accordingly, the login attempt will
fail. The most common way to debug ppp
connections is by connecting manually. The following
information will walk you through a manual connection step by
step.
Check the Device Nodes
If you reconfigured your kernel then you recall the
sio device. If you did not
configure your kernel, there is no reason to worry. Just
check the dmesg output for the modem
device with:
&prompt.root; dmesg | grep sio
You should get some pertinent output about the
sio devices. These are the COM
ports we need. If your modem acts like a standard serial
port then you should see it listed on
sio1, or COM2. If so, you are not
required to rebuild the kernel, you just need to make the
serial device. You can do this by changing your directory
to /dev and running the
MAKEDEV script like above. Now make
the serial devices with:
&prompt.root; sh MAKEDEV cuaa0 cuaa1 cuaa2 cuaa3
which will create the serial devices for your system.
When matching up sio modem is on sio1 or
COM2 if you are in DOS, then your
modem device would be /dev/cuaa1.
Connecting Manually
Connecting to the Internet by manually controlling
ppp is quick, easy, and a great way to
debug a connection or just get information on how your
ISP treats ppp client
connections. Lets start PPP from
the command line. Note that in all of our examples we will
use example as the hostname of the
machine running PPP. You start
ppp by just typing
ppp:
&prompt.root; ppp
We have now started ppp.
ppp ON example> set device /dev/cuaa1
We set our modem device, in this case it is
cuaa1.
ppp ON example> set speed 115200
Set the connection speed, in this case we
are using 115,200 kbps.
ppp ON example> enable dns
Tell ppp to configure our
resolver and add the nameserver lines to
/etc/resolv.conf. If ppp
cannot determine our hostname, we can set one manually later.
ppp ON example> term
Switch to terminal
mode so that we can manually
control the modem.
deflink: Entering terminal mode on /dev/cuaa1
type '~h' for help
at
OK
atdt123456789
Use at to initialize the modem,
then use atdt and the number for your
ISP to begin the dial in process.
CONNECT
Confirmation of the connection, if we are going to have
any connection problems, unrelated to hardware, here is where
we will attempt to resolve them.
ISP Login:myusername
Here you are prompted for a username, return the
prompt with the username that was provided by the
ISP.
ISP Pass:mypassword
This time we are prompted for a password, just
reply with the password that was provided by the
ISP. Just like logging into
&os;, the password will not echo.
Shell or PPP:ppp
Depending on your ISP this prompt
may never appear. Here we are being asked if we wish to
use a shell on the provider, or to start
ppp. In this example, we have chosen
to use ppp as we want an Internet
connection.
Ppp ON example>
Notice that in this example the first
has been capitalized. This shows that we have successfully
connected to the ISP.
PPp ON example>
We have successfully authenticated with our
ISP and are waiting for the
assigned IP address.
PPP ON example>
We have made an agreement on an IP
address and successfully completed our connection.
PPP ON example>add default HISADDR
Here we add our default route, we need to do this before
we can talk to the outside world as currently the only
established connection is with the peer. If this fails due to
existing routes you can put a bang character
! in front of the .
Alternatively, you can set this before making the actual
connection and it will negotiate a new route
accordingly.
If everything went good we should now have an active
connection to the Internet, which could be thrown into the
background using CTRL
z If you notice the
PPP return to ppp then
we have lost our connection. This is good to know because it
shows our connection status. Capital P's show that we have a
connection to the ISP and lowercase p's
show that the connection has been lost for whatever reason.
ppp only has these 2 states.
Debugging
If you have a direct line and cannot seem to make a
connection, then turn hardware flow
CTS/RTS to off with the . This is mainly the case if you are
connected to some PPP capable
terminal servers, where PPP hangs
when it tries to write data to your communication link, so
it would be waiting for a CTS, or Clear
To Send signal which may never come. If you use this option
however, you should also use the
option, which may be required to defeat hardware dependent
on passing certain characters from end to end, most of the
time XON/XOFF. See the &man.ppp.8; manual page for more
information on this option, and how it is used.
If you have an older modem, you may need to use the
. Parity is set at none
be default, but is used for error checking (with a large
increase in traffic) on older modems and some
ISPs. You may need this option for
the Compuserve ISP.
PPP may not return to the
command mode, which is usually a negotiation error where
the ISP is waiting for your side to start
negotiating. At this point, using the ~p
command will force ppp to start sending the configuration
information.
If you never obtain a login prompt, then most likely you
need to use PAP or
CHAP authentication instead of the
&unix; style in the example above. To use
PAP or CHAP just add
the following options to PPP
before going into terminal mode:
ppp ON example> set authname myusername
Where myusername should be
replaced with the username that was assigned by the
ISP.
ppp ON example> set authkey mypassword
Where mypassword should be
replaced with the password that was assigned by the
ISP.
If you connect fine, but cannot seem to find any domain
name, try to use &man.ping.8; with an IP
address and see if you can get any return information. If
you experience 100 percent (100%) packet loss, then it is most
likely that you were not assigned a default route. Double
check that the option
was set during the connection. If you can connect to a
remote IP address then it is possible
that a resolver address has not been added to the
/etc/resolv.conf. This file should
look like:
domain example.com
nameserver x.x.x.x
nameserver y.y.y.y
Where x.x.x.x and
y.y.y.y should be replaced with
the IP address of your
ISP's DNS servers. This information may
or may not have been provided when you signed up, but a
quick call to your ISP should remedy
that.
You could also have &man.syslog.3; provide a logging
function for your PPP connection.
Just add:
!ppp
*.* /var/log/ppp.log
to /etc/syslog.conf. In most cases, this
functionality already exists.
Jim
Mock
Contributed (from http://node.to/freebsd/how-tos/how-to-freebsd-pppoe.html) by
Using PPP over Ethernet (PPPoE)
PPPover Ethernet
PPPoE
PPP, over Ethernet
This section describes how to set up PPP over Ethernet
(PPPoE).
Configuring the Kernel
No kernel configuration is necessary for PPPoE any longer. If
the necessary netgraph support is not built into the kernel, it will
be dynamically loaded by ppp.
Setting Up ppp.conf
Here is an example of a working
ppp.conf:
default:
set log Phase tun command # you can add more detailed logging if you wish
set ifaddr 10.0.0.1/0 10.0.0.2/0
name_of_service_provider:
set device PPPoE:xl1 # replace xl1 with your Ethernet device
set authname YOURLOGINNAME
set authkey YOURPASSWORD
set dial
set login
add default HISADDR
Running ppp
As root, you can run:
&prompt.root; ppp -ddial name_of_service_provider
Starting ppp at Boot
Add the following to your /etc/rc.conf
file:
ppp_enable="YES"
ppp_mode="ddial"
ppp_nat="YES" # if you want to enable nat for your local network, otherwise NO
ppp_profile="name_of_service_provider"
Using a PPPoE Service Tag
Sometimes it will be necessary to use a service tag to establish
your connection. Service tags are used to distinguish between
different PPPoE servers attached to a given network.
You should have been given any required service tag information
in the documentation provided by your ISP. If you cannot locate
it there, ask your ISP's tech support personnel.
As a last resort, you could try the method suggested by the
Roaring Penguin
PPPoE program which can be found in the Ports Collection. Bear in mind however,
this may de-program your modem and render it useless, so
think twice before doing it. Simply install the program shipped
with the modem by your provider. Then, access the
System menu from the program. The name of your
profile should be listed there. It is usually
ISP.
The profile name (service tag) will be used in the PPPoE
configuration entry in ppp.conf as the provider
part of the set device command (see the &man.ppp.8;
manual page for full details). It should look like this:
set device PPPoE:xl1:ISP
Do not forget to change xl1
to the proper device for your Ethernet card.
Do not forget to change ISP
to the profile you have just found above.
For additional information, see:
Cheaper
Broadband with FreeBSD on DSL by Renaud
Waldura.
Nutzung von T-DSL und T-Online mit FreeBSD
by Udo Erdelhoff (in German).
PPPoE with a &tm.3com; HomeConnect ADSL Modem Dual Link
This modem does not follow RFC 2516
(A Method for transmitting PPP over Ethernet
(PPPoE), written by L. Mamakos, K. Lidl, J. Evarts,
D. Carrel, D. Simone, and R. Wheeler). Instead, different packet
type codes have been used for the Ethernet frames. Please complain
to 3Com if you think it
should comply with the PPPoE specification.
In order to make FreeBSD capable of communicating with this
device, a sysctl must be set. This can be done automatically at
boot time by updating /etc/sysctl.conf:
net.graph.nonstandard_pppoe=1
or can be done immediately with the command:
&prompt.root; sysctl net.graph.nonstandard_pppoe=1
Unfortunately, because this is a system-wide setting, it is
not possible to talk to a normal PPPoE client or server and a
&tm.3com; HomeConnect ADSL Modem at the same time.
Using PPP over ATM (PPPoA)
PPPover ATM
PPPoA
PPP, over ATM
The following describes how to set up PPP over ATM (PPPoA).
PPPoA is a popular choice among European DSL providers.
Using PPPoA with the Alcatel &speedtouch; USB
PPPoA support for this device is supplied as a port in
FreeBSD because the firmware is distributed under Alcatel's
license agreement and can not be redistributed freely
with the base system of FreeBSD.
To install the software, simply use the Ports Collection. Install the
net/pppoa port and follow the
instructions provided with it.
Like many USB devices, the Alcatel &speedtouch; USB needs to
download firmware from the host computer to operate properly.
It is possible to automate this process in &os; so that this
transfer takes place whenever the device is plugged into a USB
port. The following information can be added to the
/etc/usbd.conf file to enable this
automatic firmware transfer. This file must be edited as the
root user.
device "Alcatel SpeedTouch USB"
devname "ugen[0-9]+"
vendor 0x06b9
product 0x4061
attach "/usr/local/sbin/modem_run -f /usr/local/libdata/mgmt.o"
To enable the USB daemon, usbd,
put the following the line into
/etc/rc.conf:
usbd_enable="YES"
It is also possible to set up
ppp to dial up at startup. To do
this add the following lines to
/etc/rc.conf. Again, for this procedure
you will need to be logged in as the root
user.
ppp_enable="YES"
ppp_mode="ddial"
ppp_profile="adsl"
For this to work correctly you will need to have used the
sample ppp.conf which is supplied with the
net/pppoa port.
Using mpd
You can use mpd to connect to a
variety of services, in particular PPTP services. You can find
mpd in the Ports Collection,
net/mpd. Many ADSL modems
require that a PPTP tunnel is created between the modem and
computer, one such modem is the Alcatel &speedtouch;
Home.
First you must install the port, and then you can
configure mpd to suit your
requirements and provider settings. The port places a set of
sample configuration files which are well documented in
PREFIX/etc/mpd/.
Note here that PREFIX means the directory
into which your ports are installed, this defaults to
/usr/local/. A complete guide to
configure mpd is available in
HTML format once the port has been installed. It is placed in
PREFIX/share/doc/mpd/.
Here is a sample configuration for connecting to an ADSL
service with mpd. The configuration
is spread over two files, first the
mpd.conf:
default:
load adsl
adsl:
new -i ng0 adsl adsl
set bundle authname username
set bundle password password
set bundle disable multilink
set link no pap acfcomp protocomp
set link disable chap
set link accept chap
set link keep-alive 30 10
set ipcp no vjcomp
set ipcp ranges 0.0.0.0/0 0.0.0.0/0
set iface route default
set iface disable on-demand
set iface enable proxy-arp
set iface idle 0
open
The username used to authenticate with your ISP.
The password used to authenticate with your ISP.
The mpd.links file contains information about
the link, or links, you wish to establish. An example
mpd.links to accompany the above example is given
beneath:
adsl:
set link type pptp
set pptp mode active
set pptp enable originate outcall
set pptp self 10.0.0.1
set pptp peer 10.0.0.138
The IP address of your &os; computer which you will be
using mpd from.
The IP address of your ADSL modem. For the Alcatel
&speedtouch; Home this address defaults to 10.0.0.138.
It is possible to initialize the connection easily by issuing the
following command as root:
&prompt.root; mpd -b adsl
You can see the status of the connection with the following
command:
&prompt.user; ifconfig ng0
ng0: flags=88d1<UP,POINTOPOINT,RUNNING,NOARP,SIMPLEX,MULTICAST> mtu 1500
inet 216.136.204.117 --> 204.152.186.171 netmask 0xffffffff
Using mpd is the recommended way to
connect to an ADSL service with &os;.
Using pptpclient
It is also possible to use FreeBSD to connect to other PPPoA
services using
net/pptpclient.
To use net/pptpclient to
connect to a DSL service, install the port or package and edit your
/etc/ppp/ppp.conf. You will need to be
root to perform both of these operations. An
example section of ppp.conf is given
below. For further information on ppp.conf
options consult the ppp manual page,
&man.ppp.8;.
adsl:
set log phase chat lcp ipcp ccp tun command
set timeout 0
enable dns
set authname username
set authkey password
set ifaddr 0 0
add default HISADDR
The username of your account with the DSL provider.
The password for your account.
Because you must put your account's password in the
ppp.conf file in plain text form you should
make sure than nobody can read the contents of this file. The
following series of commands will make sure the file is only
readable by the root account. Refer to the
manual pages for &man.chmod.1; and &man.chown.8; for further
information.
&prompt.root; chown root:wheel /etc/ppp/ppp.conf
&prompt.root; chmod 600 /etc/ppp/ppp.conf
This will open a tunnel for a PPP session to your DSL router.
Ethernet DSL modems have a preconfigured LAN IP address which you
connect to. In the case of the Alcatel &speedtouch; Home this address is
10.0.0.138. Your router documentation
should tell you which address your device uses. To open the tunnel and
start a PPP session execute the following
command:
&prompt.root; pptp address adsl
You may wish to add an ampersand (&
) to the
end of the previous command because pptp
will not return your prompt to you otherwise.
A tun virtual tunnel device will be
created for interaction between the pptp
and ppp processes. Once you have been
returned to your prompt, or the pptp
process has confirmed a connection you can examine the tunnel like
so:
&prompt.user; ifconfig tun0
tun0: flags=8051<UP,POINTOPOINT,RUNNING,MULTICAST> mtu 1500
inet 216.136.204.21 --> 204.152.186.171 netmask 0xffffff00
Opened by PID 918
If you are unable to connect, check the configuration of
your router, which is usually accessible via
telnet or with a web browser. If you still
cannot connect you should examine the output of the
pptp command and the contents of the
ppp log file,
/var/log/ppp.log for clues.
Satoshi
Asami
Originally contributed by
Guy
Helmer
With input from
Piero
Serini
Using SLIP
SLIP
Setting Up a SLIP Client
SLIPclient
The following is one way to set up a FreeBSD machine for SLIP
on a static host network. For dynamic hostname assignments (your
address changes each time you dial up), you probably need to
have a more complex setup.
First, determine which serial port your modem is connected to.
Many people set up a symbolic link, such as
/dev/modem, to point to the real device name,
/dev/cuaaN (or /dev/cuadN under &os; 6.X). This allows you to
abstract the actual device name should you ever need to move
the modem to a different port. It can become quite cumbersome when you
need to fix a bunch of files in /etc and
.kermrc files all over the system!
/dev/cuaa0 (or /dev/cuad0 under &os; 6.X) is
COM1, cuaa1 (or /dev/cuad1) is
COM2, etc.
Make sure you have the following in your kernel configuration
file:
device sl
Under &os; 4.X, use instead the following
line:
pseudo-device sl 1
It is included in the GENERIC kernel, so
this should not be a problem unless you have deleted it.
Things You Have to Do Only Once
Add your home machine, the gateway and nameservers to
your /etc/hosts file. Ours looks like
this:
127.0.0.1 localhost loghost
136.152.64.181 water.CS.Example.EDU water.CS water
136.152.64.1 inr-3.CS.Example.EDU inr-3 slip-gateway
128.32.136.9 ns1.Example.EDU ns1
128.32.136.12 ns2.Example.EDU ns2
Make sure you have hosts before
bind in your
/etc/host.conf on FreeBSD versions
prior to 5.0. Since FreeBSD 5.0, the system uses
the file /etc/nsswitch.conf instead,
make sure you have files before
dns in the line
of this file. Without these parameters funny
things may happen.
Edit the /etc/rc.conf file.
Set your hostname by editing the line that
says:
hostname="myname.my.domain"
Your machine's full Internet hostname should be
placed here.
default route
- Designate the default router by changing the
+ Designate the default routerdefault route by changing the
line:
defaultrouter="NO"
to:
defaultrouter="slip-gateway"
Make a file /etc/resolv.conf which
contains:
domain CS.Example.EDU
nameserver 128.32.136.9
nameserver 128.32.136.12
nameserver
domain name
As you can see, these set up the nameserver hosts. Of
course, the actual domain names and addresses depend on your
environment.
Set the password for root and
toor (and any other
accounts that do not have a password).
Reboot your machine and make sure it comes up with the
correct hostname.
Making a SLIP Connection
SLIPconnecting with
Dial up, type slip at the prompt,
enter your machine name and password. What is required to
be entered depends on your environment. If you use
Kermit, you can try a script like this:
# kermit setup
set modem hayes
set line /dev/modem
set speed 115200
set parity none
set flow rts/cts
set terminal bytesize 8
set file type binary
# The next macro will dial up and login
define slip dial 643-9600, input 10 =>, if failure stop, -
output slip\x0d, input 10 Username:, if failure stop, -
output silvia\x0d, input 10 Password:, if failure stop, -
output ***\x0d, echo \x0aCONNECTED\x0a
Of course, you have to change the username and password
to fit yours. After doing so, you can just type
slip from the Kermit prompt to
connect.
Leaving your password in plain text anywhere in the
filesystem is generally a bad idea.
Do it at your own risk.
Leave the Kermit there (you can suspend it by
Ctrl
z
) and as root, type:
&prompt.root; slattach -h -c -s 115200 /dev/modem
If you are able to ping hosts on the
other side of the router, you are connected! If it does not
work, you might want to try instead of
as an argument to
slattach.
How to Shutdown the Connection
Do the following:
&prompt.root; kill -INT `cat /var/run/slattach.modem.pid`
to kill slattach. Keep in mind you must be
root to do the above. Then go back to
kermit (by running fg if you suspended it) and
exit from
it (q).
The &man.slattach.8; manual page says you have
to use ifconfig sl0 down
to mark the interface down, but this does not
seem to make any difference.
(ifconfig sl0 reports the same thing.)
Some times, your modem might refuse to drop the carrier.
In that case, simply start kermit and quit
it again. It usually goes out on the second try.
Troubleshooting
If it does not work, feel free to ask on &a.net.name; mailing list. The things that
people tripped over so far:
Not using or in
slattach (This should not be fatal,
but some users have reported that this solves their
problems.)
Using instead of
(might be hard to see the difference on
some fonts).
Try ifconfig sl0 to see your
interface status. For example, you might get:
&prompt.root; ifconfig sl0
sl0: flags=10<POINTOPOINT>
inet 136.152.64.181 --> 136.152.64.1 netmask ffffff00
If you get no route to host
messages from &man.ping.8;, there may be a problem with your
routing table. You can use the netstat -r
command to display the current routes :
&prompt.root; netstat -r
Routing tables
Destination Gateway Flags Refs Use IfaceMTU Rtt Netmasks:
(root node)
(root node)
Route Tree for Protocol Family inet:
(root node) =>
default inr-3.Example.EDU UG 8 224515 sl0 - -
localhost.Exampl localhost.Example. UH 5 42127 lo0 - 0.438
inr-3.Example.ED water.CS.Example.E UH 1 0 sl0 - -
water.CS.Example localhost.Example. UGH 34 47641234 lo0 - 0.438
(root node)
The preceding examples are from a relatively busy system.
The numbers on your system will vary depending on
network activity.
Setting Up a SLIP Server
SLIPserver
This document provides suggestions for setting up SLIP Server
services on a FreeBSD system, which typically means configuring
your system to automatically startup connections upon login for
remote SLIP clients.
Prerequisites
TCP/IP networking
This section is very technical in nature, so background
knowledge is required. It is assumed that you are familiar with
the TCP/IP network protocol, and in particular, network and node
addressing, network address masks, subnetting, routing, and
routing protocols, such as RIP. Configuring SLIP services on a
dial-up server requires a knowledge of these concepts, and if
you are not familiar with them, please read a copy of either
Craig Hunt's TCP/IP Network Administration
published by O'Reilly & Associates, Inc. (ISBN Number
0-937175-82-X), or Douglas Comer's books on the TCP/IP
protocol.
modem
It is further assumed that you have already set up your
modem(s) and configured the appropriate system files to allow
logins through your modems. If you have not prepared your
system for this yet, please see for details on dialup services
configuration.
You may also want to check the manual pages for &man.sio.4; for
information on the serial port device driver and &man.ttys.5;,
&man.gettytab.5;, &man.getty.8;, & &man.init.8; for
information relevant to configuring the system to accept logins
on modems, and perhaps &man.stty.1; for information on setting
serial port parameters (such as clocal for
directly-connected serial interfaces).
Quick Overview
In its typical configuration, using FreeBSD as a SLIP server
works as follows: a SLIP user dials up your FreeBSD SLIP Server
system and logs in with a special SLIP login ID that uses
/usr/sbin/sliplogin as the special user's
shell. The sliplogin program browses the
file /etc/sliphome/slip.hosts to find a
matching line for the special user, and if it finds a match,
connects the serial line to an available SLIP interface and then
runs the shell script
/etc/sliphome/slip.login to configure the
SLIP interface.
An Example of a SLIP Server Login
For example, if a SLIP user ID were
Shelmerg, Shelmerg's
entry in /etc/master.passwd would look
something like this:
Shelmerg:password:1964:89::0:0:Guy Helmer - SLIP:/usr/users/Shelmerg:/usr/sbin/sliplogin
When Shelmerg logs in,
sliplogin will search
/etc/sliphome/slip.hosts for a line that
had a matching user ID; for example, there may be a line in
/etc/sliphome/slip.hosts that
reads:
Shelmerg dc-slip sl-helmer 0xfffffc00 autocomp
sliplogin will find that matching line,
hook the serial line into the next available SLIP interface,
and then execute /etc/sliphome/slip.login
like this:
/etc/sliphome/slip.login 0 19200 Shelmerg dc-slip sl-helmer 0xfffffc00 autocomp
If all goes well,
/etc/sliphome/slip.login will issue an
ifconfig for the SLIP interface to which
sliplogin attached itself (SLIP interface
0, in the above example, which was the first parameter in the
list given to slip.login) to set the
local IP address (dc-slip), remote IP address
(sl-helmer), network mask for the SLIP
interface (0xfffffc00), and
any additional flags (autocomp). If
something goes wrong, sliplogin usually
logs good informational messages via the
syslogd daemon facility, which usually logs
to /var/log/messages (see the manual
pages for &man.syslogd.8; and &man.syslog.conf.5; and perhaps
check /etc/syslog.conf to see to what
syslogd is logging and where it is
logging to).
Kernel Configuration
kernelconfiguration
SLIP
&os;'s default kernel (GENERIC)
comes with SLIP (&man.sl.4;) support; in case of a custom
kernel, you have to add the following line to your kernel
configuration file:
device sl
Under &os; 4.X, use instead the following
line:
pseudo-device sl 2
The number at the end of the line is the maximum
number of SLIP connections that may be operating
simultaneously. Since &os; 5.0, the &man.sl.4;
driver is auto-cloning
.
By default, your &os; machine will not forward packets.
If you want your FreeBSD SLIP Server to act as a router, you
will have to edit the /etc/rc.conf file and
change the setting of the gateway_enable variable to
.
You will then need to reboot for the new settings to take
effect.
Please refer to on
Configuring the FreeBSD Kernel for help in
reconfiguring your kernel.
Sliplogin Configuration
As mentioned earlier, there are three files in the
/etc/sliphome directory that are part of
the configuration for /usr/sbin/sliplogin
(see &man.sliplogin.8; for the actual manual page for
sliplogin): slip.hosts,
which defines the SLIP users and their associated IP
addresses; slip.login, which usually just
configures the SLIP interface; and (optionally)
slip.logout, which undoes
slip.login's effects when the serial
connection is terminated.
slip.hosts Configuration
/etc/sliphome/slip.hosts contains
lines which have at least four items separated by
whitespace:
SLIP user's login ID
Local address (local to the SLIP server) of the SLIP
link
Remote address of the SLIP link
Network mask
The local and remote addresses may be host names
(resolved to IP addresses by
/etc/hosts or by the domain name
service, depending on your specifications in the file
/etc/nsswitch.conf,
or in /etc/host.conf
if you use FreeBSD 4.X), and the network mask may be
a name that can be resolved by a lookup into
/etc/networks. On a sample system,
/etc/sliphome/slip.hosts looks like
this:
#
# login local-addr remote-addr mask opt1 opt2
# (normal,compress,noicmp)
#
Shelmerg dc-slip sl-helmerg 0xfffffc00 autocomp
At the end of the line is one or more of the
options:
— no header
compression
— compress
headers
— compress headers if
the remote end allows it
— disable ICMP packets
(so any ping
packets will be dropped instead
of using up your bandwidth)
SLIP
TCP/IP networking
Your choice of local and remote addresses for your SLIP
links depends on whether you are going to dedicate a TCP/IP
subnet or if you are going to use proxy ARP
on
your SLIP server (it is not true
proxy ARP, but
that is the terminology used in this section to describe it).
If you are not sure which method to select or how to assign IP
addresses, please refer to the TCP/IP books referenced in
the SLIP Prerequisites ()
and/or consult your IP network manager.
If you are going to use a separate subnet for your SLIP
clients, you will need to allocate the subnet number out of
your assigned IP network number and assign each of your SLIP
client's IP numbers out of that subnet. Then, you will
probably need to configure a static route to the SLIP
subnet via your SLIP server on your nearest IP router.
Ethernet
Otherwise, if you will use the proxy ARP
method, you will need to assign your SLIP client's IP
addresses out of your SLIP server's Ethernet subnet, and you
will also need to adjust your
/etc/sliphome/slip.login and
/etc/sliphome/slip.logout scripts to use
&man.arp.8; to manage the proxy-ARP entries in the SLIP
server's ARP table.
slip.login Configuration
The typical /etc/sliphome/slip.login
file looks like this:
#!/bin/sh -
#
# @(#)slip.login 5.1 (Berkeley) 7/1/90
#
# generic login file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 inet $4 $5 netmask $6
This slip.login file merely runs
ifconfig for the appropriate SLIP interface
with the local and remote addresses and network mask of the
SLIP interface.
If you have decided to use the proxy ARP
method (instead of using a separate subnet for your SLIP
clients), your /etc/sliphome/slip.login
file will need to look something like this:
#!/bin/sh -
#
# @(#)slip.login 5.1 (Berkeley) 7/1/90
#
# generic login file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 inet $4 $5 netmask $6
# Answer ARP requests for the SLIP client with our Ethernet addr
/usr/sbin/arp -s $5 00:11:22:33:44:55 pub
The additional line in this
slip.login, arp -s
$5 00:11:22:33:44:55 pub, creates an ARP entry
in the SLIP server's ARP table. This ARP entry causes the
SLIP server to respond with the SLIP server's Ethernet MAC
address whenever another IP node on the Ethernet asks to
speak to the SLIP client's IP address.
EthernetMAC address
When using the example above, be sure to replace the
Ethernet MAC address (00:11:22:33:44:55) with the MAC address of
your system's Ethernet card, or your proxy ARP
will definitely not work! You can discover your SLIP server's
Ethernet MAC address by looking at the results of running
netstat -i; the second line of the output
should look something like:
ed0 1500 <Link>0.2.c1.28.5f.4a 191923 0 129457 0 116
This indicates that this particular system's Ethernet MAC
address is 00:02:c1:28:5f:4a
— the periods in the Ethernet MAC address given by
netstat -i must be changed to colons and
leading zeros should be added to each single-digit hexadecimal
number to convert the address into the form that &man.arp.8;
desires; see the manual page on &man.arp.8; for complete
information on usage.
When you create
/etc/sliphome/slip.login and
/etc/sliphome/slip.logout, the
execute
bit (i.e., chmod 755
/etc/sliphome/slip.login /etc/sliphome/slip.logout)
must be set, or sliplogin will be unable
to execute it.
slip.logout Configuration
/etc/sliphome/slip.logout is not
strictly needed (unless you are implementing proxy
ARP
), but if you decide to create it, this is an
example of a basic
slip.logout script:
#!/bin/sh -
#
# slip.logout
#
# logout file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 down
If you are using proxy ARP
, you will want to
have /etc/sliphome/slip.logout remove the
ARP entry for the SLIP client:
#!/bin/sh -
#
# @(#)slip.logout
#
# logout file for a slip line. sliplogin invokes this with
# the parameters:
# 1 2 3 4 5 6 7-n
# slipunit ttyspeed loginname local-addr remote-addr mask opt-args
#
/sbin/ifconfig sl$1 down
# Quit answering ARP requests for the SLIP client
/usr/sbin/arp -d $5
The arp -d $5 removes the ARP entry
that the proxy ARP
slip.login added when the SLIP client
logged in.
It bears repeating: make sure
/etc/sliphome/slip.logout has the execute
bit set after you create it (i.e., chmod 755
/etc/sliphome/slip.logout).
Routing Considerations
SLIP
routing
If you are not using the proxy ARP
method for
routing packets between your SLIP clients and the rest of your
network (and perhaps the Internet), you will probably
have to add static routes to your closest default router(s) to
route your SLIP clients subnet via your SLIP server.
Static Routes
static routes
Adding static routes to your nearest default routers
can be troublesome (or impossible if you do not have
authority to do so...). If you have a multiple-router
network in your organization, some routers, such as those
made by Cisco and Proteon, may not only need to be
configured with the static route to the SLIP subnet, but
also need to be told which static routes to tell other
routers about, so some expertise and
troubleshooting/tweaking may be necessary to get
static-route-based routing to work.
Running &gated;
&gated;
&gated; is proprietary software now and
will not be available as source code to the public anymore
(more info on the &gated; website). This
section only exists to ensure backwards compatibility for
those that are still using an older version.
An alternative to the headaches of static routes is to
install &gated; on your FreeBSD SLIP server
and configure it to use the appropriate routing protocols
(RIP/OSPF/BGP/EGP) to tell other routers about your SLIP
subnet.
You will need to write a /etc/gated.conf
file to configure your &gated;; here is a sample, similar to
what the author used on a FreeBSD SLIP server:
#
# gated configuration file for dc.dsu.edu; for gated version 3.5alpha5
# Only broadcast RIP information for xxx.xxx.yy out the ed Ethernet interface
#
#
# tracing options
#
traceoptions "/var/tmp/gated.output" replace size 100k files 2 general ;
rip yes {
interface sl noripout noripin ;
interface ed ripin ripout version 1 ;
traceoptions route ;
} ;
#
# Turn on a bunch of tracing info for the interface to the kernel:
kernel {
traceoptions remnants request routes info interface ;
} ;
#
# Propagate the route to xxx.xxx.yy out the Ethernet interface via RIP
#
export proto rip interface ed {
proto direct {
xxx.xxx.yy mask 255.255.252.0 metric 1; # SLIP connections
} ;
} ;
#
# Accept routes from RIP via ed Ethernet interfaces
import proto rip interface ed {
all ;
} ;
RIP
The above sample gated.conf file
broadcasts routing information regarding the SLIP subnet
xxx.xxx.yy via RIP onto the
Ethernet; if you are using a different Ethernet driver than
the ed driver, you will need to
change the references to the ed
interface appropriately. This sample file also sets up
tracing to /var/tmp/gated.output for
debugging &gated;'s activity; you can
certainly turn off the tracing options if
&gated; works correctly for you. You will need to
change the xxx.xxx.yy's into the
network address of your own SLIP subnet (be sure to change the
net mask in the proto direct clause as
well).
Once you have installed and configured
&gated; on your system, you will need to
tell the FreeBSD startup scripts to run
&gated; in place of
routed. The easiest way to accomplish
this is to set the router and
router_flags variables in
/etc/rc.conf. Please see the manual
page for &gated; for information on
command-line parameters.
diff --git a/zh_TW.Big5/books/handbook/printing/chapter.xml b/zh_TW.Big5/books/handbook/printing/chapter.xml
index acec03c739..4e07ddb9f0 100644
--- a/zh_TW.Big5/books/handbook/printing/chapter.xml
+++ b/zh_TW.Big5/books/handbook/printing/chapter.xml
@@ -1,4834 +1,4803 @@
Sean
Kelly
Contributed by
Jim
Mock
Restructured and updated by
¦C¦L
·§z
LPD spooling system
LPD ½w½Ä¨t²Î
printing
¦C¦L
FreeBSD ¥i¥H©M¦U¦¡¦U¼Ëªº¦Lªí¾÷·f°t¦C¦L¡A
±q³Ì¦Ñªº¼²°w¦¡¦Lªí¾÷¨ì³Ì·sªº¹p®g¦Lªí¾÷³£¨S°ÝÃD¡A
Åý±zªºÀ³¥Îµ{¦¡¥i¥H²£¥Í¥X°ª«~½èªº¤å¥ó¦C¦L¿é¥X¡C
¤]¥i¥H§â FreeBSD ³]©w¦¨¤@¥xºô¸ô¦C¦L¦øªA¾¹¡F³o®ÉÔªº FreeBSD
¯à±µ¦¬¨ä¥L¹q¸£°e¨Óªº¦C¦L¤u§@¡A¥]¬A¨ä¥L FreeBSD ªº¹q¸£¡B&windows;
ªº¹q¸£¥H¤Î &macos; ªº¹q¸£¡C FreeBSD
·|½T«O¦P®É¥u¦³¤@¥ó¤å¥ó¥¿¦b¦C¦L¡A¦Ó¥B¥i¥H²ÎpþӨϥΪ̤ξ÷¾¹¦L±o³Ì¦h¡A
ÁÙ¦³´N¬O¦L¥X±µ¤U¨Ó¬O½Öªº¤å¥ó³oÃþªº¼ÐÃD
¶µ¥¡C
Ū§¹³o³¹¡A±z±N¤F¸Ñ¡G
¦p¦ó³]©w FreeBSD ªº¦C¦L¦h¤u½w½Ä³B²z¾¹¡C
¦p¦ó¦w¸Ë¦C¦L¹LÂo¾¹¥H¤À§O³B²z¯S®íªº¦C¦L¤u§@¡A
¥]¬A§â¦¬¨ìªº¤å¥óÂà´«¦¨±zªº¦Lªí¾÷¬Ý±oÀ´ªº¦C¦L®æ¦¡µ¥¡C
¤F¸Ñ¦p¦ó¦b±z¦C¦L®É¶¶«K¦L¥X¶º©Î¼ÐÃD¡C
¦p¦ó§Q¥Î§O¥x¹q¸£¤Wªº¦Lªí¾÷¦C¦L¡C
¦p¦ó§Q¥Îª½±µ±µ¦bºô¸ô¤Wªº¦Lªí¾÷¦C¦L¡C
¦p¦ó±±¨î¦Lªí¾÷ªºÅv¡A¥]¬A¨î¦C¦L¤u§@ªºÀɮפj¤p¡A
¥H¤Î¤£¤¹³\¯S©w¨Ï¥ÎªÌ¦C¦Lµ¥¡C
¦p¦ó°O¤U¦Lªí¾÷ªº²Îp¸ê®Æ¡A¥H¤Î¦U±b¸¹ªº¦Lªí¾÷¨Ï¥Î¶q¡C
¦p¦ó¸Ñ¨M¦C¦L®É¹J¨ìªº°ÝÃD¡C
¦b¶}©l¾\Ū³o³¹¤§«e¡A±z»Ýn¡J
n¦³³]©w¡B½sĶ kernel ªº°ò¦·§©À
()¡C
¤¶²Ð
n¦b FreeBSD ¤W¨Ï¥Î¦Lªí¾÷¡A±z»Ýn³]©w¦n Berkeley
¦æ¦C¦¡¦Lªí¾÷¦C¦L½w½Ä¨t²Î¡A¤SºÙ¬° LPD
¦C¦L½w½Ä¨t²Î¡A©ÎªÌ´N¥s¥L LPD §a¡C
³o¬O FreeBSD ¼Ð·Çªº¦Lªí¾÷±±¨î¨t²Î¡A¥»³¹·|¤¶²Ð¨Ã±Ð±z¦p¦ó³]©w
LPD¡C
¦pªG±z¤w¸g¹ï LPD
©Î¬O¨ä¥L¦C¦L½w½Ä¨t²Î«Ü¼ô±x¤F¡A
±z¥i¥Hª½±µ¸õ¨ì°ò¥»³]©w¡C
LPD ±±¨îµÛ¥D¾÷¤W¦Lªí¾÷ªº¤@¤Á¡C
¥¦t³d³o¨Ç¤u§@¡G
±±¨î¥»¾÷¤Îºô¸ô¦Lªí¾÷ªº¨Ï¥Î¡C
- print jobs
-
- Åý¨Ï¥ÎªÌ¥i¥H¦C¦L¤å¥ó¡A°e¥Xªº¤å¥óºÙ¬°¤u§@¡C
+ Åý¨Ï¥ÎªÌ¥i¥H¦C¦L¤å¥ó¡A°e¥Xªº¤å¥óºÙ¬°¤u§@¡Cprint jobs
¬°¨C¥x¦Lªí¾÷·Ç³Æ¤@Ó¦î¦C¡A
Á×§K¦hӨϥΪ̦P®É¨Ï¥Î¦P¤@¥x¦Lªí¾÷¡C
¦C¦L header pages (¤SºÙ¬°
banner or burst
pages)¡A¤è«K¨Ï¥ÎªÌ¦b¥X¯È¹h¤¤§ä¨ì¦Û¤w¦C¦Lªº¤å¥ó¡C
§â±µ¦b¦ê¦C°ð¤Wªº¦Lªí¾÷ªº³q°T°Ñ¼Æ³]©w¦n¡C
§Q¥Îºô¸ô¶Ç°e¦C¦L¤u§@µ¹§O¥x¥D¾÷¤Wªº
LPD¡C
°õ¦æ¯S§Oªº¹LÂoµ{¦¡±N¦C¦L¤u§@®æ¦¡¤Æ¥H°t¦X¤£¦Pªº¦C¦L»y¨¥©Î¦Lªí¾÷¡C
²Îp¦Lªí¾÷ªº¨Ï¥Î±¡ªp¡C
Âǥѳ]©wÀÉ (/etc/printcap) ¥H¤Î¹LÂoµ{¦¡ªºÀ°§U¡A
±z¥i¥HÅý¤j¦h¼Æªº¦Lªí¾÷°t¦X LPD
¹F¦¨¤Wz¥þ³¡©Î³¡¥÷ªº¥\¯à¡C
¬°¤°»ò»Ýn¨Ï¥Î¦h¤u½w½Ä³B²z¾¹
¦pªG±zªº¨t²Î¬OÓ¤H¨Ï¥Î¡A
¤£»Ýn±±¨î¦s¨úÅv¡B¦C¦L¼ÐÃD¶©ÎªÌ²Îp¨Ï¥Î±¡ªpµ¥¥\¯à®É¡A
±z¥i¯à·|ı±o«Ü©_©Ç¬°¤°»òÁÙ»Ýn¥hºÞ³oÓ¦h¤u½w½Ä³B²z¾¹¡C
·íµMnª½±µ±±¨î¦Lªí¾÷¥i¦æªº¡A
¤£¹LµL½×¦p¦ó±zÁÙ¬O»Ýn¦h¤u½w½Ä³B²z¾¹¡A¦]¬°¡G
LPD ¥i¥H¦bI´º (background)
¦C¦L¡A±z¤£»Ýn¦b¨ºÃäµ¥¤å¥ó°e¨ì¦Lªí¾÷¡C
- &tex;
-
LPD ¥i¥H«Ü»´ÃP¦a¥Î¹LÂo¾¹¼W¥[¤é´Á /
- ®É¶¡©ó¶º©Î¬O§â¯S§OªºÀɮ׮榡 (¹³¬O &tex; DVI ÀÉ)
+ ®É¶¡©ó¶º©Î¬O§â¯S§OªºÀɮ׮榡 (¹³¬O &tex;&tex; DVI ÀÉ)
Âà´«¦¨¦Lªí¾÷¬Ý±oÀ´ªºªº®æ¦¡¡A±z¤£»Ýn¤â°Ê¥h°µ³o¨Ç¨BÆJ¡C
³\¦h§K¶O©Î°Ó·~³nÅé´£¨Ñªº¦C¦L¥\¯à³q±`³£¬O©M¦h¤u½w½Ä³B²z¾¹·¾³q¡C
³z¹L³]©w½w½Ä¨t²Î¡A¤ä´©±z²{¦³©Î¬O§Y±Nn¦w¸Ëªº¨ä¥L³nÅé±NÅܱo§ó®e©ö¡C
°ò¦³]©w
n¥Î¦Lªí¾÷·f°t LPD
¦h¤u½w½Ä¨t²Î¡A±z»Ýn¦³¦Lªí¾÷³oÓµwÅé¥H¤Î
LPD ³o®M³nÅé¡C
¥»¤â¥U´£¨Ñ¤F¨â¶¥¬qªº³]©w»¡©ú¡G
¾\Ū ²©ö¦Lªí¾÷³]©w
¨Ó¾Ç²ß¦p¦ó³s±µ¦Lªí¾÷¡BÅý¦Lªí¾÷©M LPD
·¾³q¥H¤Î¦C¦L¯Â¤å¦r¤å¥ó¡C
¾\Ū ¶i¶¥¦Lªí¾÷³]©w
¨Ó¾Ç²ß¦p¦ó¦C¦L¦UºØ¯S®í®æ¦¡¤å¥ó¡B¦C¦Lº¶¡Bºô¸ô¦C¦L¡B
±±¨î¦Lªí¾÷Åv¥H¤Î²Îp¨Ï¥Îª¬ªpµ¥¡C
²©ö¦Lªí¾÷³]©w
¥»³¹¸`·|§i¶D±z¦p¦ó³]©w¦Lªí¾÷³]³Æ©M
LPD ³nÅé¥H¨Ï¥Î¦Lªí¾÷¡A
°ò¥»±Ð¾Ç¤º®e¡G
µwÅé³]©w
·|´£¥Ü¦p¦ó±N¦Lªí¾÷±µ¤W¹q¸£ªº³s±µ°ð¡C
³nÅé³]©w
·|¥Ü½d¦p¦ó¼g LPD ½w½Ä¾¹³]©wÀÉ
(/etc/printcap)¡C
¦pªG±zn§â¦Lªí¾÷³]©w±µ¦¬ºô¸ô¦C¦L¸ê®Æ¦Ó¤£¬O¥»¾÷ºÝªº¸Ü¡A½Ð°Ñ¦Ò
¦Lªí¾÷¤Îºô¸ô¸ê®Æ¶Ç¿é¤¶±¡C
³oÓ³¹¸`ÁöµM¥s°µÂ²©ö¦Lªí¾÷³]©w
¡A
¹ê»Ú¤WÁÙ¬O¦³ÂI½ÆÂøªº¡C ³Ì§xÃøªº³¡¥÷¬OÅý§Aªº¦Lªí¾÷©M¹q¸£¤Wªº
LPD ½w½Ä¾¹¯à°÷¥¿±`¹B§@¡C
¤@¥¹¦Lªí¾÷¥i¥H¥¿±`¤u§@¤§«á¡A
¹³¬O¦Lº¶©Î¬O°µ¦C¦L²Îp³o¨Ç¶i¶¥ªº¥\¯à´N¤£Ãø°µ¨ì¤F¡C
µwÅé³]©w
¥»³¹¸`°Q½×¦UºØ³s±µ¦Lªí¾÷¨ì PC ªº¤è¦¡¡C
³o¸Ì·|´£¨ì¤£¦PºØÃþªº³s±µ°ð©M³s±µ½u¡A
¥H¤Î¬°¤FÅý FreeBSD ¯à©M¦Lªí¾÷·¾³q±z¥i¯à·|»Ýn¶}±Òªº®Ö¤ß°Ñ¼Æµ¥¡C
¦pªG±z¤w¸g§â¦Lªí¾÷±µ¤W¹q¸£¡A
¦Ó¥B¦b¨ä¥L§@·~¨t²Î¤W¦³¦¨¥\¦C¦L¹Lªº¸Ü¡A¥i¥Hª½±µ¸õ¦Ü
³nÅé³]©w¡C
³s±µ°ð©M±Æ½u
¥«°âÓ¤H¹q¸£¦Lªí¾÷¤@¯ë¨Ó»¡¤£¥X³o¤TºØ¬É±¡G
-
- printers
- serial
-
- §Ç¦C (Serial)
+ §Ç¦C (Serial)printersserial
¬É±¡A¤SºÙ¬° RS-232 ©Î COM °ð¡A
¥Î±z¹q¸£¤Wªº§Ç¦C°ð¶Ç°e¸ê®Æ¨ì¦Lªí¾÷¡C
§Ç¦C¬É±¼sªxªº¬°¹q¸£·~¬É©Ò±Ä¥Î¡A
©Ò¥H±Æ½u®e©ö¨ú±o¡An³]©w³s½u¨Ã¤£§xÃø¡C
µM¦Ó§Ç¦C¤¶±¦³®ÉÔ·|»Ýn¨Ï¥Î¸û¯S§Oªº±Æ½u¡A
³o®ÉÔ´N¦³¥i¯à»Ýn³]©w¤@¨Ç¸û¬°½ÆÂøªº³q°T°Ñ¼Æ¤F¡C
¤j³¡¥÷ PC §Ç¦C°ðªº¶Ç¿é³t«×³Ì°ª¥u¨ì 115200 bps¡A
¦]¦¹·Qn¥Î§Ç¦C°ð¨Ó¦C¦L¤j¹Ï¬O¤£¤Á¹ê»Úªº¡C
-
- printers
- parallel
-
-
- ¨Ã¦C (Parallel)
+ ¨Ã¦C (Parallel)printersparallel
¬É±§Q¥Î¹q¸£ªº¨Ã¦C°ð±N¸ê®Æ°e¨ì¦Lªí¾÷¡C
¨Ã¦C°ð¤ñ RS-232 §Ç¦C°ðÁÙ§Ö¡A¤]¬O¤@ºØ¹q¸£·~¬É±`¥Îªº¬É±¡C
³oºØ¬É±ªº±Æ½u«D±`®e©ö¨ú±o¡A¦ý¬O¸ûÃø¥Î¤â¤u¥´³y¡C
³q±`¨Ó»¡¨Ã¦C¬É±¨Ã¨S¦³¤°»ò³q°T°Ñ¼Æ»Ýn«ü©w¡A
©Ò¥H³]©w°_¨Ó¶W¯Å®e©ö¡C
-
- centronics
- parallel printers
-
- ¨Ã¦C°ð¬É±¦³®ÉÔ¤]·|³QºÙ¬° Centronics
+ ¨Ã¦C°ð¬É±¦³®ÉÔ¤]·|³QºÙ¬° Centronics
centronicsparallel printers
¬É±¡A³o¬O¦Lªí¾÷ªº±µÀYªº¦WºÙ¡C
-
- printers
- USB
-
-
- USB ¬É±¡A¤]´N¬O³q¥Î§Ç¦C¶×¬y±Æ¡A¶Ç¿é³t²v¤ñ¨Ã¦C¬É±©Î¬O
+ USBprintersUSB ¬É±¡A¤]´N¬O³q¥Î§Ç¦C¶×¬y±Æ¡A¶Ç¿é³t²v¤ñ¨Ã¦C¬É±©Î¬O
RS-232 §Ç¦C¬É±³£¨Ó±o§Ö¡A¦Ó¥B USB ±Æ½u³æ¯Â¤S«K©y¡C
¹ï¦C¦L¤u§@¦Ó¨¥¡AUSB ¤ñ RS-232
§Ç¦C°ð©Î¬O¨Ã¦C°ð³£¨Ó±o¦n¡A¦ý¬O¦b
&unix; ¨t²Î¤Wªº¤ä´©«×¸û®t¡C ÁʶR¦P®É¨ã¦³ USB
¤Î¨Ã¦C°ð¨âºØ¬É±ªº¦Lªí¾÷¥i¥HÁ×§K±¼³oºØ°ÝÃD¡C
¤@¯ë¦Ó¨¥¡A¨Ã¦C¬É±¥u¯à´£¨Ñ³æ¦V¶Ç¿é
(¹q¸£¦Ü¦Lªí¾÷)¡A¦Ón¥Î USB ¤~¯à´£¨ÑÂù¦V¡C µM¦Ó¦b FreeBSD
¤U¡A¨Ï¥Î¸û·sªº¨Ã¦C°ð (EPP ©M ECP) ¥H¤Î¦Lªí¾÷¡A¦A°t¦X¨Ï¥Î
IEEE-1284 ¬Û®e±Æ½u¤]¥i¥H°µ¨ìÂù¦V·¾³q¡C
PostScript
¹q¸£©M¦Lªí¾÷¤§¶¡ÂǥѨæC°ð¦æ¶iÂù¦V·¾³qªº¤è¦¡¦³¨âºØ¡C
²Ä¤@ºØ¬O¨Ï¥Î¯S»sªº¡B¯à©M¯S©w¦Lªí¾÷·¾³qªº FreeBSD ¦Lªí¾÷ÅX°Êµ{¦¡¡C
³oºØ¤è¦¡¦b¼Q¾¥¦Lªí¾÷¤W«Ü±`¨£¡A¥Î¨Ó¦^³ø¾¥¤ô¦s¶q¥H¤Î¨ä¥Lª¬ºA¸ê°Tµ¥¡C
²Ä¤GºØ¤èªk¬O¥Î &postscript;¡A¦pªG¦Lªí¾÷¦³¤ä´©ªº¸Ü¡C
&postscript; jobs are
actually programs sent to the printer; they need not produce
paper at all and may return results directly to the computer.
&postscript; also uses two-way communication to tell the
computer about problems, such as errors in the &postscript;
program or paper jams. Your users may be appreciative of such
information. Furthermore, the best way to do effective
accounting with a &postscript; printer requires two-way
communication: you ask the printer for its page count (how
many pages it has printed in its lifetime), then send the
user's job, then ask again for its page count. Subtract the
two values and you know how much paper to charge to the
user.
Parallel Ports
To hook up a printer using a parallel interface, connect
the Centronics cable between the printer and the computer.
The instructions that came with the printer, the computer, or
both should give you complete guidance.
Remember which parallel port you used on the computer.
The first parallel port is ppc0 to
FreeBSD; the second is ppc1, and so
on. The printer device name uses the same scheme:
/dev/lpt0 for the printer on the first
parallel ports etc.
Serial Ports
To hook up a printer using a serial interface, connect the
proper serial cable between the printer and the computer. The
instructions that came with the printer, the computer, or both
should give you complete guidance.
If you are unsure what the proper serial
cable
is, you may wish to try one of the following
alternatives:
A modem cable connects each pin
of the connector on one end of the cable straight through
to its corresponding pin of the connector on the other
end. This type of cable is also known as a
DTE-to-DCE
cable.
- null-modem cable
-
- A null-modem cable connects some
+ A null-modemnull-modem cable cable connects some
pins straight through, swaps others (send data to receive
data, for example), and shorts some internally in each
connector hood. This type of cable is also known as a
DTE-to-DTE
cable.
A serial printer cable, required
for some unusual printers, is like the null-modem cable,
but sends some signals to their counterparts instead of
being internally shorted.
baud rate
parity
flow control protocol
You should also set up the communications parameters for
the printer, usually through front-panel controls or DIP
switches on the printer. Choose the highest
bps (bits per second, sometimes
baud rate) that both your computer
and the printer can support. Choose 7 or 8 data bits; none,
even, or odd parity; and 1 or 2 stop bits. Also choose a flow
control protocol: either none, or XON/XOFF (also known as
in-band
or software
) flow control.
Remember these settings for the software configuration that
follows.
Software Setup
This section describes the software setup necessary to print
with the LPD spooling system in FreeBSD.
Here is an outline of the steps involved:
Configure your kernel, if necessary, for the port you
are using for the printer; section Kernel Configuration tells
you what you need to do.
Set the communications mode for the parallel port, if
you are using a parallel port; section Setting the
Communication Mode for the Parallel Port gives
details.
Test if the operating system can send data to the printer.
Section Checking Printer
Communications gives some suggestions on how to do
this.
Set up LPD for the printer by
modifying the file
/etc/printcap. You will find out how
to do this later in this chapter.
Kernel Configuration
The operating system kernel is compiled to work with a
specific set of devices. The serial or parallel interface for
your printer is a part of that set. Therefore, it might be
necessary to add support for an additional serial or parallel
port if your kernel is not already configured for one.
To find out if the kernel you are currently using supports
a serial interface, type:
&prompt.root; grep sioN /var/run/dmesg.boot
Where N is the number of the
serial port, starting from zero. If you see output similar to
the following:
sio2 at port 0x3e8-0x3ef irq 5 on isa
sio2: type 16550A
then the kernel supports the port.
To find out if the kernel supports a parallel interface,
type:
&prompt.root; grep ppcN /var/run/dmesg.boot
Where N is the number of the
parallel port, starting from zero. If you see output similar
to the following:
ppc0: <Parallel port> at port 0x378-0x37f irq 7 on isa0
ppc0: SMC-like chipset (ECP/EPP/PS2/NIBBLE) in COMPATIBLE mode
ppc0: FIFO with 16/16/8 bytes threshold
then the kernel supports the port.
You might have to reconfigure your kernel in order for the
operating system to recognize and use the parallel or serial
port you are using for the printer.
To add support for a serial port, see the section on
kernel configuration. To add support for a parallel port, see
that section and the section that
follows.
Setting the Communication Mode for the Parallel
Port
When you are using the parallel interface, you can choose
whether FreeBSD should use interrupt-driven or polled
communication with the printer. The generic printer
device driver (&man.lpt.4;) on FreeBSD
uses the &man.ppbus.4; system, which controls the port
chipset with the &man.ppc.4; driver.
The interrupt-driven method is
the default with the GENERIC kernel. With this method,
the operating system uses an IRQ line to determine when
the printer is ready for data.
The polled method directs the
operating system to repeatedly ask the printer if it is
ready for more data. When it responds ready, the kernel
sends more data.
The interrupt-driven method is usually somewhat faster
but uses up a precious IRQ line. Some newer HP printers
are claimed not to work correctly in interrupt mode,
apparently due to some (not yet exactly understood) timing
problem. These printers need polled mode. You should use
whichever one works. Some printers will work in both
modes, but are painfully slow in interrupt mode.
You can set the communications mode in two ways: by
configuring the kernel or by using the &man.lptcontrol.8;
program.
To set the communications mode by configuring
the kernel:
Edit your kernel configuration file. Look for
an ppc0 entry. If you are setting up
the second parallel port, use ppc1
instead. Use ppc2 for the third port,
and so on.
If you want interrupt-driven mode, edit the following line:
hint.ppc.0.irq="N"
in the /boot/device.hints file
and replace N with the right
IRQ number. The kernel configuration file must
also contain the &man.ppc.4; driver:
device ppc
If you want polled mode, remove in your
/boot/device.hints file, the
following line:
hint.ppc.0.irq="N"
In some cases, this is not enough to put the
port in polled mode under FreeBSD. Most of
time it comes from &man.acpi.4; driver, this latter
is able to probe and attach devices, and therefore,
control the access mode to the printer port. You
should check your &man.acpi.4; configuration to
correct this problem.
Save the file. Then configure, build, and install the
kernel, then reboot. See kernel configuration for
more details.
To set the communications mode with
&man.lptcontrol.8;:
Type:
&prompt.root; lptcontrol -i -d /dev/lptN
to set interrupt-driven mode for
lptN.
Type:
&prompt.root; lptcontrol -p -d /dev/lptN
to set polled-mode for
lptN.
You could put these commands in your
/etc/rc.local file to set the mode each
time your system boots. See &man.lptcontrol.8; for more
information.
Checking Printer Communications
Before proceeding to configure the spooling system, you
should make sure the operating system can successfully send
data to your printer. It is a lot easier to debug printer
communication and the spooling system separately.
To test the printer, we will send some text to it. For
printers that can immediately print characters sent to them,
the program &man.lptest.1; is perfect: it generates all 96
printable ASCII characters in 96 lines.
PostScript
For a &postscript; (or other language-based) printer, we
will need a more sophisticated test. A small &postscript;
program, such as the following, will suffice:
%!PS
100 100 moveto 300 300 lineto stroke
310 310 moveto /Helvetica findfont 12 scalefont setfont
(Is this thing working?) show
showpage
The above &postscript; code can be placed into a file and
used as shown in the examples appearing in the following
sections.
PCL
When this document refers to a printer language, it is
assuming a language like &postscript;, and not Hewlett
Packard's PCL. Although PCL has great functionality, you
can intermingle plain text with its escape sequences.
&postscript; cannot directly print plain text, and that is the
kind of printer language for which we must make special
accommodations.
Checking a Parallel Printer
printers
parallel
This section tells you how to check if FreeBSD can
communicate with a printer connected to a parallel
port.
To test a printer on a parallel
port:
Become root with &man.su.1;.
Send data to the printer.
If the printer can print plain text, then use
&man.lptest.1;. Type:
&prompt.root; lptest > /dev/lptN
Where N is the number
of the parallel port, starting from zero.
If the printer understands &postscript; or other
printer language, then send a small program to the
printer. Type:
&prompt.root; cat > /dev/lptN
Then, line by line, type the program
carefully as you cannot edit a
line once you have pressed RETURN
or ENTER. When you have finished
entering the program, press
CONTROL+D, or whatever your end
of file key is.
Alternatively, you can put the program in a file
and type:
&prompt.root; cat file > /dev/lptN
Where file is the
name of the file containing the program you want to
send to the printer.
You should see something print. Do not worry if the
text does not look right; we will fix such things
later.
Checking a Serial Printer
printers
serial
This section tells you how to check if FreeBSD can
communicate with a printer on a serial port.
To test a printer on a serial
port:
Become root with &man.su.1;.
Edit the file /etc/remote. Add
the following entry:
printer:dv=/dev/port:br#bps-rate:pa=parity
bits-per-second
serial port
parity
Where port is the device
entry for the serial port (ttyd0,
ttyd1, etc.),
bps-rate is the
bits-per-second rate at which the printer communicates,
and parity is the parity
required by the printer (either even,
odd, none, or
zero).
Here is a sample entry for a printer connected via
a serial line to the third serial port at 19200 bps with
no parity:
printer:dv=/dev/ttyd2:br#19200:pa=none
Connect to the printer with &man.tip.1;.
Type:
&prompt.root; tip printer
If this step does not work, edit the file
/etc/remote again and try using
/dev/cuaaN
instead of
/dev/ttydN.
Send data to the printer.
If the printer can print plain text, then use
&man.lptest.1;. Type:
&prompt.user; $lptest
If the printer understands &postscript; or other
printer language, then send a small program to the
printer. Type the program, line by line,
very carefully as backspacing
or other editing keys may be significant to the
printer. You may also need to type a special
end-of-file key for the printer so it knows it
received the whole program. For &postscript;
printers, press CONTROL+D.
Alternatively, you can put the program in a file
and type:
&prompt.user; >file
Where file is the
name of the file containing the program. After
&man.tip.1; sends the file, press any required
end-of-file key.
You should see something print. Do not worry if the
text does not look right; we will fix that later.
Enabling the Spooler: the /etc/printcap
File
At this point, your printer should be hooked up, your kernel
configured to communicate with it (if necessary), and you have
been able to send some simple data to the printer. Now, we are
ready to configure LPD to control access
to your printer.
You configure LPD by editing the file
/etc/printcap. The
LPD spooling system
reads this file each time the spooler is used, so updates to the
file take immediate effect.
printers
capabilities
The format of the &man.printcap.5; file is straightforward.
Use your favorite text editor to make changes to
/etc/printcap. The format is identical to
other capability files like
/usr/share/misc/termcap and
/etc/remote. For complete information
about the format, see the &man.cgetent.3;.
The simple spooler configuration consists of the following
steps:
Pick a name (and a few convenient aliases) for the
printer, and put them in the
/etc/printcap file; see the
Naming the Printer
section for more information on naming.
- header pages
-
- Turn off header pages (which are on by default) by
+ Turn off header pagesheader pages (which are on by default) by
inserting the sh capability; see the
Suppressing Header
Pages section for more information.
Make a spooling directory, and specify its location with
the sd capability; see the Making the Spooling
Directory section for more information.
Set the /dev entry to use for the
printer, and note it in /etc/printcap
with the lp capability; see the Identifying the Printer
Device for more information. Also, if the printer is
on a serial port, set up the communication parameters with
the ms# capability which is discussed in the Configuring Spooler
Communications Parameters section.
Install a plain text input filter; see the Installing the Text
Filter section for details.
Test the setup by printing something with the
&man.lpr.1; command. More details are available in the
Trying It Out and
Troubleshooting
sections.
Language-based printers, such as &postscript; printers,
cannot directly print plain text. The simple setup outlined
above and described in the following sections assumes that if
you are installing such a printer you will print only files
that the printer can understand.
Users often expect that they can print plain text to any of
the printers installed on your system. Programs that interface
to LPD to do their printing usually
make the same assumption.
If you are installing such a printer and want to be able to
print jobs in the printer language and
print plain text jobs, you are strongly urged to add an
additional step to the simple setup outlined above: install an
automatic plain-text-to-&postscript; (or other printer language)
conversion program. The section entitled Accommodating Plain
Text Jobs on &postscript; Printers tells how to do
this.
Naming the Printer
The first (easy) step is to pick a name for your printer.
It really does not matter whether you choose functional or
whimsical names since you can also provide a number of aliases
for the printer.
At least one of the printers specified in the
/etc/printcap should have the alias
lp. This is the default printer's name.
If users do not have the PRINTER environment
variable nor specify a printer name on the command line of any
of the LPD commands,
then lp will be the
default printer they get to use.
Also, it is common practice to make the last alias for a
printer be a full description of the printer, including make
and model.
Once you have picked a name and some common aliases, put
them in the /etc/printcap file. The name
of the printer should start in the leftmost column. Separate
each alias with a vertical bar and put a colon after the last
alias.
In the following example, we start with a skeletal
/etc/printcap that defines two printers
(a Diablo 630 line printer and a Panasonic KX-P4455 &postscript;
laser printer):
#
# /etc/printcap for host rose
#
rattan|line|diablo|lp|Diablo 630 Line Printer:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:
In this example, the first printer is named
rattan and has as aliases
line, diablo,
lp, and Diablo 630 Line
Printer. Since it has the alias
lp, it is also the default printer. The
second is named bamboo, and has as aliases
ps, PS,
S, panasonic, and
Panasonic KX-P4455 PostScript v51.4.
Making the Spooling Directory
printer spool
print jobs
The next step in the simple spooler setup is to make a
spooling directory, a directory where
print jobs reside until they are printed, and where a number
of other spooler support files live.
Because of the variable nature of spooling directories, it
is customary to put these directories under
/var/spool. It is not necessary to
backup the contents of spooling directories, either.
Recreating them is as simple as running &man.mkdir.1;.
It is also customary to make the directory with a name
that is identical to the name of the printer, as shown
below:
&prompt.root; mkdir /var/spool/printer-name
However, if you have a lot of printers on your network,
you might want to put the spooling directories under a single
directory that you reserve just for printing with
LPD. We
will do this for our two example printers
rattan and
bamboo:
&prompt.root; mkdir /var/spool/lpd
&prompt.root; mkdir /var/spool/lpd/rattan
&prompt.root; mkdir /var/spool/lpd/bamboo
If you are concerned about the privacy of jobs that
users print, you might want to protect the spooling
directory so it is not publicly accessible. Spooling
directories should be owned and be readable, writable, and
searchable by user daemon and group daemon, and no one else.
We will do this for our example printers:
&prompt.root; chown daemon:daemon /var/spool/lpd/rattan
&prompt.root; chown daemon:daemon /var/spool/lpd/bamboo
&prompt.root; chmod 770 /var/spool/lpd/rattan
&prompt.root; chmod 770 /var/spool/lpd/bamboo
Finally, you need to tell LPD
about these directories
using the /etc/printcap file. You
specify the pathname of the spooling directory with the
sd capability:
#
# /etc/printcap for host rose - added spooling directories
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:
Note that the name of the printer starts in the first
column but all other entries describing the printer should be
indented and each line end escaped with a
backslash.
If you do not specify a spooling directory with
sd, the spooling system will use
/var/spool/lpd as a default.
Identifying the Printer Device
In the
Entries for the Ports
section, we identified which entry in the
/dev directory FreeBSD will use to
communicate with the printer. Now, we tell
LPD that
information. When the spooling system has a job to print, it
will open the specified device on behalf of the filter program
(which is responsible for passing data to the printer).
List the /dev entry pathname in the
/etc/printcap file using the
lp capability.
In our running example, let us assume that
rattan is on the first parallel port, and
bamboo is on a sixth serial port; here are
the additions to /etc/printcap:
#
# /etc/printcap for host rose - identified what devices to use
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:\
:lp=/dev/ttyd5:
If you do not specify the lp capability
for a printer in your /etc/printcap file,
LPD uses /dev/lp
as a default.
/dev/lp currently does not exist in
FreeBSD.
If the printer you are installing is connected to a
parallel port, skip to the section entitled, Installing the Text
Filter. Otherwise, be sure to follow the instructions
in the next section.
Configuring Spooler Communication Parameters
printers
serial
For printers on serial ports, LPD
can set up the bps rate,
parity, and other serial communication parameters on behalf of
the filter program that sends data to the printer. This is
advantageous since:
It lets you try different communication parameters by
simply editing the /etc/printcap
file; you do not have to recompile the filter
program.
It enables the spooling system to use the same filter
program for multiple printers which may have different
serial communication settings.
The following /etc/printcap
capabilities control serial communication parameters of the
device listed in the lp capability:
br#bps-rate
Sets the communications speed of the device to
bps-rate, where
bps-rate can be 50, 75, 110,
134, 150, 200, 300, 600, 1200, 1800, 2400, 4800, 9600,
19200, 38400, 57600, or 115200 bits-per-second.
ms#stty-mode
Sets the options for the terminal device after
opening the device. &man.stty.1; explains the
available options.
When LPD opens the device
specified by the lp capability, it sets
the characteristics of the device to those specified with
the ms# capability. Of particular
interest will be the parenb,
parodd, cs5,
cs6, cs7,
cs8, cstopb,
crtscts, and ixon
modes, which are explained in the &man.stty.1;
manual page.
Let us add to our example printer on the sixth serial
port. We will set the bps rate to 38400. For the mode,
we will set no parity with -parenb,
8-bit characters with cs8,
no modem control with clocal and
hardware flow control with crtscts:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:
Installing the Text Filter
printing
filters
We are now ready to tell LPD
what text filter to use to
send jobs to the printer. A text filter,
also known as an input filter, is a
program that LPD runs when it
has a job to print. When LPD
runs the text filter for a printer, it sets the filter's
standard input to the job to print, and its standard output to
the printer device specified with the lp
capability. The filter is expected to read the job from
standard input, perform any necessary translation for the
printer, and write the results to standard output, which will
get printed. For more information on the text filter, see
the Filters
section.
For our simple printer setup, the text filter can be a
small shell script that just executes
/bin/cat to send the job to the printer.
FreeBSD comes with another filter called
lpf that handles backspacing and
underlining for printers that might not deal with such
character streams well. And, of course, you can use any other
filter program you want. The filter lpf is
described in detail in section entitled lpf: a Text
Filter.
First, let us make the shell script
/usr/local/libexec/if-simple be a simple
text filter. Put the following text into that file with your
favorite text editor:
#!/bin/sh
#
# if-simple - Simple text input filter for lpd
# Installed in /usr/local/libexec/if-simple
#
# Simply copies stdin to stdout. Ignores all filter arguments.
/bin/cat && exit 0
exit 2
Make the file executable:
&prompt.root; chmod 555 /usr/local/libexec/if-simple
And then tell LPD to use it by specifying it with the
if capability in
/etc/printcap. We will add it to the two
printers we have so far in the example
/etc/printcap:
#
# /etc/printcap for host rose - added text filter
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\ :lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:\
:if=/usr/local/libexec/if-simple:
A copy of the if-simple script
can be found in the /usr/share/examples/printing
directory.
Turn on LPD
&man.lpd.8; is run from /etc/rc,
controlled by the lpd_enable variable. This
variable defaults to NO. If you have not done
so already, add the line:
lpd_enable="YES"
to /etc/rc.conf, and then either restart
your machine, or just run &man.lpd.8;.
&prompt.root; lpd
Trying It Out
You have reached the end of the simple
LPD setup.
Unfortunately, congratulations are not quite yet in order,
since we still have to test the setup and correct any
problems. To test the setup, try printing something. To
print with the LPD system, you
use the command &man.lpr.1;,
which submits a job for printing.
You can combine &man.lpr.1; with the &man.lptest.1;
program, introduced in section Checking Printer
Communications to generate some test text.
To test the simple LPD
setup:
Type:
&prompt.root; lptest 20 5 | lpr -Pprinter-name
Where printer-name is a the
name of a printer (or an alias) specified in
/etc/printcap. To test the default
printer, type &man.lpr.1; without any
argument. Again, if you are testing a printer that expects
&postscript;, send a &postscript; program in that language instead
of using &man.lptest.1;. You can do so by putting the program
in a file and typing lpr
file.
For a &postscript; printer, you should get the results of
the program. If you are using &man.lptest.1;, then your
results should look like the following:
!"#$%&'()*+,-./01234
"#$%&'()*+,-./012345
#$%&'()*+,-./0123456
$%&'()*+,-./01234567
%&'()*+,-./012345678
To further test the printer, try downloading larger
programs (for language-based printers) or running
&man.lptest.1; with different arguments. For example,
lptest 80 60 will produce 60 lines of 80
characters each.
If the printer did not work, see the Troubleshooting
section.
Advanced Printer Setup
This section describes filters for printing specially formatted
files, header pages, printing across networks, and restricting and
accounting for printer usage.
Filters
printing
filters
Although LPD handles network protocols,
queuing, access control,
and other aspects of printing, most of the real
work happens in the filters. Filters are
programs that communicate with the printer and handle its device
dependencies and special requirements. In the simple printer setup,
we installed a plain text filter—an extremely simple one that
should work with most printers (section Installing the Text
Filter).
However, in order to take advantage of format conversion, printer
accounting, specific printer quirks, and so on, you should understand
how filters work. It will ultimately be the filter's responsibility
to handle these aspects. And the bad news is that most of the time
you have to provide filters yourself. The good
news is that many are generally available; when they are not, they are
usually easy to write.
Also, FreeBSD comes with one,
/usr/libexec/lpr/lpf, that works with many
printers that can print plain text. (It handles backspacing and tabs
in the file, and does accounting, but that is about all it does.)
There are also several filters and filter components in the FreeBSD
Ports Collection.
Here is what you will find in this section:
Section How Filters
Work, tries to give an overview of a filter's role in the
printing process. You should read this section to get an
understanding of what is happening under the hood
when LPD uses filters. This knowledge
could help you anticipate
and debug problems you might encounter as you install more and
more filters on each of your printers.
LPD expects every printer to be
able to print plain text by
default. This presents a problem for &postscript; (or other
language-based printers) which cannot directly print plain text.
Section Accommodating
Plain Text Jobs on &postscript; Printers tells you what you
should do to overcome this problem. You should read this
section if you have a &postscript; printer.
&postscript; is a popular output format for many programs.
Some people even write &postscript; code directly. Unfortunately,
&postscript; printers are expensive. Section Simulating &postscript; on
Non &postscript; Printers tells how you can further modify
a printer's text filter to accept and print &postscript; data on a
non &postscript; printer. You should read
this section if you do not have a &postscript; printer.
Section Conversion
Filters tells about a way you can automate the conversion
of specific file formats, such as graphic or typesetting data,
into formats your printer can understand. After reading this
section, you should be able to set up your printers such that
users can type lpr -t to print troff data, or
lpr -d to print &tex; DVI data, or lpr
-v to print raster image data, and so forth. I
recommend reading this section.
Section Output
Filters tells all about a not often used feature of
LPD:
output filters. Unless you are printing header pages (see Header Pages),
you can probably skip that section altogether.
Section lpf: a Text
Filter describes lpf, a fairly
complete if simple text filter for line printers (and laser
printers that act like line printers) that comes with FreeBSD. If
you need a quick way to get printer accounting working for plain
text, or if you have a printer which emits smoke when it sees
backspace characters, you should definitely consider
lpf.
A copy of the various scripts described below can be
found in the /usr/share/examples/printing
directory.
How Filters Work
As mentioned before, a filter is an executable program started
by LPD to handle the device-dependent part of
communicating with the printer.
When LPD wants to print a file in a
job, it starts a filter
program. It sets the filter's standard input to the file to print,
its standard output to the printer, and its standard error to the
error logging file (specified in the lf
capability in /etc/printcap, or
/dev/console by default).
troff
Which filter LPD starts and the
filter's arguments depend on
what is listed in the /etc/printcap file and
what arguments the user specified for the job on the
&man.lpr.1; command line. For example, if the user typed
lpr -t, LPD would
start the troff filter, listed
in the tf capability for the destination printer.
If the user wanted to print plain text, it would start the
if filter (this is mostly true: see Output Filters for
details).
There are three kinds of filters you can specify in
/etc/printcap:
The text filter, confusingly called the
input filter in
LPD documentation, handles
regular text printing. Think of it as the default filter.
LPD
expects every printer to be able to print plain text by default,
and it is the text filter's job to make sure backspaces, tabs,
or other special characters do not confuse the printer. If you
are in an environment where you have to account for printer
usage, the text filter must also account for pages printed,
usually by counting the number of lines printed and comparing
that to the number of lines per page the printer supports. The
text filter is started with the following argument list:
filter-name
-c
-wwidth
-llength
-iindent
-n login
-h host
acct-file
where
appears if the job is submitted with lpr
-l
width
is the value from the pw (page
width) capability specified in
/etc/printcap, default 132
length
is the value from the pl (page
length) capability, default 66
indent
is the amount of the indentation from lpr
-i, default 0
login
is the account name of the user printing the
file
host
is the host name from which the job was
submitted
acct-file
is the name of the accounting file from the
af capability.
-
- printing
- filters
-
-
- A conversion filter converts a specific
+ A conversion filterprintingfilters converts a specific
file format into one the printer can render onto paper. For
example, ditroff typesetting data cannot be directly printed,
but you can install a conversion filter for ditroff files to
convert the ditroff data into a form the printer can digest and
print. Section Conversion
Filters tells all about them. Conversion filters also
need to do accounting, if you need printer accounting.
Conversion filters are started with the following arguments:
filter-name
-xpixel-width
-ypixel-height
-n login
-h host
acct-file
where pixel-width is the value
from the px capability (default 0) and
pixel-height is the value from the
py capability (default 0).
The output filter is used only if there
is no text filter, or if header pages are enabled. In my
experience, output filters are rarely used. Section Output Filters describe
them. There are only two arguments to an output filter:
filter-name
-wwidth
-llength
which are identical to the text filters and
arguments.
Filters should also exit with the
following exit status:
exit 0
If the filter printed the file successfully.
exit 1
If the filter failed to print the file but wants
LPD to
try to print the file again. LPD
will restart a filter if it exits with this status.
exit 2
If the filter failed to print the file and does not want
LPD to try again.
LPD will throw out the file.
The text filter that comes with the FreeBSD release,
/usr/libexec/lpr/lpf, takes advantage of the
page width and length arguments to determine when to send a form
feed and how to account for printer usage. It uses the login, host,
and accounting file arguments to make the accounting entries.
If you are shopping for filters, see if they are LPD-compatible.
If they are, they must support the argument lists described above.
If you plan on writing filters for general use, then have them
support the same argument lists and exit codes.
Accommodating Plain Text Jobs on &postscript; Printers
print jobs
If you are the only user of your computer and &postscript; (or
other language-based) printer, and you promise to never send plain
text to your printer and to never use features of various programs
that will want to send plain text to your printer, then you do not
need to worry about this section at all.
But, if you would like to send both &postscript; and plain text
jobs to the printer, then you are urged to augment your printer
setup. To do so, we have the text filter detect if the arriving job
is plain text or &postscript;. All &postscript; jobs must start with
%! (for other printer languages, see your printer
documentation). If those are the first two characters in the job,
we have &postscript;, and can pass the rest of the job directly. If
those are not the first two characters in the file, then the filter
will convert the text into &postscript; and print the result.
How do we do this?
printers
serial
If you have got a serial printer, a great way to do it is to
install lprps. lprps is a
&postscript; printer filter which performs two-way communication with
the printer. It updates the printer's status file with verbose
information from the printer, so users and administrators can see
exactly what the state of the printer is (such as toner
low or paper jam). But more
importantly, it includes a program called psif
which detects whether the incoming job is plain text and calls
textps (another program that comes with
lprps) to convert it to &postscript;. It then uses
lprps to send the job to the printer.
lprps is part of the FreeBSD Ports Collection
(see The Ports Collection). You can
fetch, build and install it yourself, of course. After installing
lprps, just specify the pathname to the
psif program that is part of
lprps. If you installed lprps
from the Ports Collection, use the following in the serial
&postscript; printer's entry in
/etc/printcap:
:if=/usr/local/libexec/psif:
You should also specify the rw capability;
that tells LPD to open the printer in
read-write mode.
If you have a parallel &postscript; printer (and therefore cannot
use two-way communication with the printer, which
lprps needs), you can use the following shell
script as the text filter:
#!/bin/sh
#
# psif - Print PostScript or plain text on a PostScript printer
# Script version; NOT the version that comes with lprps
# Installed in /usr/local/libexec/psif
#
IFS="" read -r first_line
first_two_chars=`expr "$first_line" : '\(..\)'`
if [ "$first_two_chars" = "%!" ]; then
#
# PostScript job, print it.
#
echo "$first_line" && cat && printf "\004" && exit 0
exit 2
else
#
# Plain text, convert it, then print it.
#
( echo "$first_line"; cat ) | /usr/local/bin/textps && printf "\004" && exit 0
exit 2
fi
In the above script, textps is a program we
installed separately to convert plain text to &postscript;. You can
use any text-to-&postscript; program you wish. The FreeBSD Ports
Collection (see The Ports Collection)
includes a full featured text-to-&postscript; program called
a2ps that you might want to investigate.
Simulating &postscript; on Non &postscript; Printers
PostScript
emulating
Ghostscript
&postscript; is the de facto standard for
high quality typesetting and printing. &postscript; is, however, an
expensive standard. Thankfully, Aladdin
Enterprises has a free &postscript; work-alike called
Ghostscript that runs with FreeBSD.
Ghostscript can read most &postscript; files and can render their
pages onto a variety of devices, including many brands of
non-PostScript printers. By installing Ghostscript and using a
special text filter for your printer, you can make your
non &postscript; printer act like a real &postscript; printer.
Ghostscript is in the FreeBSD Ports Collection, if you
would like to install it from there. You can fetch, build, and
install it quite easily yourself, as well.
To simulate &postscript;, we have the text filter detect if it is
printing a &postscript; file. If it is not, then the filter will pass
the file directly to the printer; otherwise, it will use Ghostscript
to first convert the file into a format the printer will
understand.
Here is an example: the following script is a text filter
for Hewlett Packard DeskJet 500 printers. For other printers,
substitute the argument to the
gs (Ghostscript) command. (Type gs
-h to get a list of devices the current installation of
Ghostscript supports.)
#!/bin/sh
#
# ifhp - Print Ghostscript-simulated PostScript on a DeskJet 500
# Installed in /usr/local/libexec/ifhp
#
# Treat LF as CR+LF (to avoid the "staircase effect" on HP/PCL
# printers):
#
printf "\033&k2G" || exit 2
#
# Read first two characters of the file
#
IFS="" read -r first_line
first_two_chars=`expr "$first_line" : '\(..\)'`
if [ "$first_two_chars" = "%!" ]; then
#
# It is PostScript; use Ghostscript to scan-convert and print it.
#
/usr/local/bin/gs -dSAFER -dNOPAUSE -q -sDEVICE=djet500 \
-sOutputFile=- - && exit 0
else
#
# Plain text or HP/PCL, so just print it directly; print a form feed
# at the end to eject the last page.
#
echo "$first_line" && cat && printf "\033&l0H" &&
exit 0
fi
exit 2
Finally, you need to notify LPD of
the filter via the if capability:
:if=/usr/local/libexec/ifhp:
That is it. You can type lpr plain.text and
lpr whatever.ps and both should print
successfully.
Conversion Filters
After completing the simple setup described in Simple Printer Setup, the first
thing you will probably want to do is install conversion filters for
your favorite file formats (besides plain ASCII text).
Why Install Conversion Filters?
&tex;
printing DVI files
Conversion filters make printing various kinds of files easy.
As an example, suppose we do a lot of work with the &tex;
typesetting system, and we have a &postscript; printer. Every time
we generate a DVI file from &tex;, we cannot print it directly until
we convert the DVI file into &postscript;. The command sequence
goes like this:
&prompt.user; dvips seaweed-analysis.dvi
&prompt.user; lpr seaweed-analysis.ps
By installing a conversion filter for DVI files, we can skip
the hand conversion step each time by having
LPD do it for us.
Now, each time we get a DVI file, we are just one step away from
printing it:
&prompt.user; lpr -d seaweed-analysis.dvi
We got LPD to do the DVI file
conversion for us by specifying
the option. Section Formatting and Conversion
Options lists the conversion options.
For each of the conversion options you want a printer to
support, install a conversion filter and
specify its pathname in /etc/printcap. A
conversion filter is like the text filter for the simple printer
setup (see section Installing
the Text Filter) except that instead of printing plain
text, the filter converts the file into a format the printer can
understand.
Which Conversion Filters Should I Install?
You should install the conversion filters you expect to use.
If you print a lot of DVI data, then a DVI conversion filter is in
order. If you have got plenty of troff to print out, then you
probably want a troff filter.
The following table summarizes the filters that
LPD works
with, their capability entries for the
/etc/printcap file, and how to invoke them
with the lpr command:
File type
/etc/printcap capability
lpr option
cifplot
cf
DVI
df
plot
gf
ditroff
nf
FORTRAN text
rf
troff
tf
raster
vf
plain text
if
none, , or
In our example, using lpr -d means the
printer needs a df capability in its entry in
/etc/printcap.
FORTRAN
Despite what others might contend, formats like FORTRAN text
and plot are probably obsolete. At your site, you can give new
meanings to these or any of the formatting options just by
installing custom filters. For example, suppose you would like to
directly print Printerleaf files (files from the Interleaf desktop
publishing program), but will never print plot files. You could
install a Printerleaf conversion filter under the
gf capability and then educate your users that
lpr -g mean print Printerleaf
files.
Installing Conversion Filters
Since conversion filters are programs you install outside of
the base FreeBSD installation, they should probably go under
/usr/local. The directory
/usr/local/libexec is a popular location,
since they are specialized programs that only
LPD will run;
regular users should not ever need to run them.
To enable a conversion filter, specify its pathname under the
appropriate capability for the destination printer in
/etc/printcap.
In our example, we will add the DVI conversion filter to the
entry for the printer named bamboo. Here is
the example /etc/printcap file again, with
the new df capability for the printer
bamboo.
#
# /etc/printcap for host rose - added df filter for bamboo
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:rw:\
:if=/usr/local/libexec/psif:\
:df=/usr/local/libexec/psdf:
The DVI filter is a shell script named
/usr/local/libexec/psdf. Here is that
script:
#!/bin/sh
#
# psdf - DVI to PostScript printer filter
# Installed in /usr/local/libexec/psdf
#
# Invoked by lpd when user runs lpr -d
#
exec /usr/local/bin/dvips -f | /usr/local/libexec/lprps "$@"
This script runs dvips in filter mode (the
argument) on standard input, which is the job
to print. It then starts the &postscript; printer filter
lprps (see section Accommodating Plain
Text Jobs on &postscript; Printers) with the arguments
LPD
passed to this script. lprps will use those
arguments to account for the pages printed.
More Conversion Filter Examples
Since there is no fixed set of steps to install conversion
filters, let me instead provide more examples. Use these as
guidance to making your own filters. Use them directly, if
appropriate.
This example script is a raster (well, GIF file, actually)
conversion filter for a Hewlett Packard LaserJet III-Si
printer:
#!/bin/sh
#
# hpvf - Convert GIF files into HP/PCL, then print
# Installed in /usr/local/libexec/hpvf
PATH=/usr/X11R6/bin:$PATH; export PATH
giftopnm | ppmtopgm | pgmtopbm | pbmtolj -resolution 300 \
&& exit 0 \
|| exit 2
It works by converting the GIF file into a portable anymap,
converting that into a portable graymap, converting that into a
portable bitmap, and converting that into LaserJet/PCL-compatible
data.
Here is the /etc/printcap file with an
entry for a printer using the above filter:
#
# /etc/printcap for host orchid
#
teak|hp|laserjet|Hewlett Packard LaserJet 3Si:\
:lp=/dev/lpt0:sh:sd=/var/spool/lpd/teak:mx#0:\
:if=/usr/local/libexec/hpif:\
:vf=/usr/local/libexec/hpvf:
The following script is a conversion filter for troff data
from the groff typesetting system for the &postscript; printer named
bamboo:
#!/bin/sh
#
# pstf - Convert groff's troff data into PS, then print.
# Installed in /usr/local/libexec/pstf
#
exec grops | /usr/local/libexec/lprps "$@"
The above script makes use of lprps again
to handle the communication with the printer. If the printer were
on a parallel port, we would use this script instead:
#!/bin/sh
#
# pstf - Convert groff's troff data into PS, then print.
# Installed in /usr/local/libexec/pstf
#
exec grops
That is it. Here is the entry we need to add to
/etc/printcap to enable the filter:
:tf=/usr/local/libexec/pstf:
Here is an example that might make old hands at FORTRAN blush.
It is a FORTRAN-text filter for any printer that can directly
print plain text. We will install it for the printer
teak:
#!/bin/sh
#
# hprf - FORTRAN text filter for LaserJet 3si:
# Installed in /usr/local/libexec/hprf
#
printf "\033&k2G" && fpr && printf "\033&l0H" &&
exit 0
exit 2
And we will add this line to the
/etc/printcap for the printer
teak to enable this filter:
:rf=/usr/local/libexec/hprf:
Here is one final, somewhat complex example. We will add a
DVI filter to the LaserJet printer teak
introduced earlier. First, the easy part: updating
/etc/printcap with the location of the DVI
filter:
:df=/usr/local/libexec/hpdf:
Now, for the hard part: making the filter. For that, we need
a DVI-to-LaserJet/PCL conversion program. The FreeBSD Ports
Collection (see The Ports Collection)
has one: dvi2xx is the name of the package.
Installing this package gives us the program we need,
dvilj2p, which converts DVI into LaserJet IIp,
LaserJet III, and LaserJet 2000 compatible codes.
dvilj2p makes the filter
hpdf quite complex since
dvilj2p cannot read from standard input. It
wants to work with a filename. What is worse, the filename has to
end in .dvi so using
/dev/fd/0 for standard input is problematic.
We can get around that problem by linking (symbolically) a
temporary file name (one that ends in .dvi)
to /dev/fd/0, thereby forcing
dvilj2p to read from standard input.
The only other fly in the ointment is the fact that we cannot
use /tmp for the temporary link. Symbolic
links are owned by user and group bin. The
filter runs as user daemon. And the
/tmp directory has the sticky bit set. The
filter can create the link, but it will not be able clean up when
done and remove it since the link will belong to a different
user.
Instead, the filter will make the symbolic link in the current
working directory, which is the spooling directory (specified by
the sd capability in
/etc/printcap). This is a perfect place for
filters to do their work, especially since there is (sometimes)
more free disk space in the spooling directory than under
/tmp.
Here, finally, is the filter:
#!/bin/sh
#
# hpdf - Print DVI data on HP/PCL printer
# Installed in /usr/local/libexec/hpdf
PATH=/usr/local/bin:$PATH; export PATH
#
# Define a function to clean up our temporary files. These exist
# in the current directory, which will be the spooling directory
# for the printer.
#
cleanup() {
rm -f hpdf$$.dvi
}
#
# Define a function to handle fatal errors: print the given message
# and exit 2. Exiting with 2 tells LPD to do not try to reprint the
# job.
#
fatal() {
echo "$@" 1>&2
cleanup
exit 2
}
#
# If user removes the job, LPD will send SIGINT, so trap SIGINT
# (and a few other signals) to clean up after ourselves.
#
trap cleanup 1 2 15
#
# Make sure we are not colliding with any existing files.
#
cleanup
#
# Link the DVI input file to standard input (the file to print).
#
ln -s /dev/fd/0 hpdf$$.dvi || fatal "Cannot symlink /dev/fd/0"
#
# Make LF = CR+LF
#
printf "\033&k2G" || fatal "Cannot initialize printer"
#
# Convert and print. Return value from dvilj2p does not seem to be
# reliable, so we ignore it.
#
dvilj2p -M1 -q -e- dfhp$$.dvi
#
# Clean up and exit
#
cleanup
exit 0
Automated Conversion: an Alternative to Conversion
Filters
All these conversion filters accomplish a lot for your
printing environment, but at the cost forcing the user to specify
(on the &man.lpr.1; command line) which one to use.
If your users are not particularly computer literate, having to
specify a filter option will become annoying. What is worse,
though, is that an incorrectly specified filter option may run a
filter on the wrong type of file and cause your printer to spew
out hundreds of sheets of paper.
Rather than install conversion filters at all, you might want
to try having the text filter (since it is the default filter)
detect the type of file it has been asked to print and then
automatically run the right conversion filter. Tools such as
file can be of help here. Of course, it will
be hard to determine the differences between
some file types—and, of course, you can
still provide conversion filters just for them.
apsfilter
printing
filters
apsfilter
The FreeBSD Ports Collection has a text filter that performs
automatic conversion called apsfilter. It can
detect plain text, &postscript;, and DVI files, run the proper
conversions, and print.
Output Filters
The LPD spooling system supports one
other type of filter that
we have not yet explored: an output filter. An output filter is
intended for printing plain text only, like the text filter, but
with many simplifications. If you are using an output filter but no
text filter, then:
LPD starts an output filter once
for the entire job instead
of once for each file in the job.
LPD does not make any provision
to identify the start or the
end of files within the job for the output filter.
LPD does not pass the user's
login or host to the filter, so
it is not intended to do accounting. In fact, it gets only two
arguments:
filter-name
-wwidth
-llength
Where width is from the
pw capability and
length is from the
pl capability for the printer in
question.
Do not be seduced by an output filter's simplicity. If you
would like each file in a job to start on a different page an output
filter will not work. Use a text filter (also
known as an input filter); see section Installing the Text Filter.
Furthermore, an output filter is actually more
complex in that it has to examine the byte stream being
sent to it for special flag characters and must send signals to
itself on behalf of LPD.
However, an output filter is necessary if
you want header pages and need to send escape sequences or other
initialization strings to be able to print the header page. (But it
is also futile if you want to charge header
pages to the requesting user's account, since
LPD does not give any
user or host information to the output filter.)
On a single printer, LPD
allows both an output filter and text or other filters. In
such cases, LPD will start the
output filter
to print the header page (see section Header Pages)
only. LPD then expects the
output filter to stop
itself by sending two bytes to the filter: ASCII 031
followed by ASCII 001. When an output filter sees these two bytes
(031, 001), it should stop by sending SIGSTOP
to itself. When
LPD's
done running other filters, it will restart the output filter by
sending SIGCONT to it.
If there is an output filter but no text
filter and LPD is working on a plain
text job, LPD uses the output
filter to do the job. As stated before, the output filter will
print each file of the job in sequence with no intervening form
feeds or other paper advancement, and this is probably
not what you want. In almost all cases, you
need a text filter.
The program lpf, which we introduced earlier
as a text filter, can also run as an output filter. If you need a
quick-and-dirty output filter but do not want to write the byte
detection and signal sending code, try lpf. You
can also wrap lpf in a shell script to handle any
initialization codes the printer might require.
lpf: a Text Filter
The program /usr/libexec/lpr/lpf that comes
with FreeBSD binary distribution is a text filter (input filter)
that can indent output (job submitted with lpr
-i), allow literal characters to pass (job submitted
with lpr -l), adjust the printing position for
backspaces and tabs in the job, and account for pages printed. It
can also act like an output filter.
lpf is suitable for many printing
environments. And although it has no capability to send
initialization sequences to a printer, it is easy to write a shell
script to do the needed initialization and then execute
lpf.
page accounting
accounting
printer
In order for lpf to do page accounting
correctly, it needs correct values filled in for the
pw and pl capabilities in the
/etc/printcap file. It uses these values to
determine how much text can fit on a page and how many pages were in
a user's job. For more information on printer accounting, see Accounting for Printer
Usage.
Networked Printing
printers
network
network printing
FreeBSD supports networked printing: sending jobs to remote
printers. Networked printing generally refers to two different
things:
Accessing a printer attached to a remote host. You install a
printer that has a conventional serial or parallel interface on
one host. Then, you set up LPD to
enable access to the printer
from other hosts on the network. Section Printers Installed on
Remote Hosts tells how to do this.
Accessing a printer attached directly to a network. The
printer has a network interface in addition (or in place of) a
more conventional serial or parallel interface. Such a printer
might work as follows:
It might understand the LPD
protocol and can even queue
jobs from remote hosts. In this case, it acts just like a
regular host running LPD. Follow
the same procedure in
section Printers
Installed on Remote Hosts to set up such a
printer.
It might support a data stream network connection. In this
case, you attach
the printer to one host on the
network by making that host responsible for spooling jobs and
sending them to the printer. Section Printers with
Networked Data Stream Interfaces gives some
suggestions on installing such printers.
Printers Installed on Remote Hosts
The LPD spooling system has built-in
support for sending jobs to
other hosts also running LPD (or are
compatible with LPD). This
feature enables you to install a printer on one host and make it
accessible from other hosts. It also works with printers that have
network interfaces that understand the
LPD protocol.
To enable this kind of remote printing, first install a printer
on one host, the printer host, using the simple
printer setup described in the Simple
Printer Setup section. Do any advanced setup in Advanced Printer Setup that you
need. Make sure to test the printer and see if it works with the
features of LPD you have enabled.
Also ensure that the
local host has authorization to use the
LPD
service in the remote host (see Restricting Jobs
from Remote Printers).
printers
network
network printing
If you are using a printer with a network interface that is
compatible with LPD, then the
printer host in
the discussion below is the printer itself, and the
printer name is the name you configured for the
printer. See the documentation that accompanied your printer and/or
printer-network interface.
If you are using a Hewlett Packard Laserjet then the printer
name text will automatically perform the LF to
CRLF conversion for you, so you will not require the
hpif script.
Then, on the other hosts you want to have access to the printer,
make an entry in their /etc/printcap files with
the following:
Name the entry anything you want. For simplicity, though,
you probably want to use the same name and aliases as on the
printer host.
Leave the lp capability blank, explicitly
(:lp=:).
Make a spooling directory and specify its location in the
sd capability. LPD
will store jobs here
before they get sent to the printer host.
Place the name of the printer host in the
rm capability.
Place the printer name on the printer
host in the rp
capability.
That is it. You do not need to list conversion filters, page
dimensions, or anything else in the
/etc/printcap file.
Here is an example. The host rose has two
printers, bamboo and rattan.
We will enable users on the host orchid to print
to those printers.
Here is the /etc/printcap file for
orchid (back from section Enabling Header
Pages). It already had the entry for the printer
teak; we have added entries for the two printers
on the host rose:
#
# /etc/printcap for host orchid - added (remote) printers on rose
#
#
# teak is local; it is connected directly to orchid:
#
teak|hp|laserjet|Hewlett Packard LaserJet 3Si:\
:lp=/dev/lpt0:sd=/var/spool/lpd/teak:mx#0:\
:if=/usr/local/libexec/ifhp:\
:vf=/usr/local/libexec/vfhp:\
:of=/usr/local/libexec/ofhp:
#
# rattan is connected to rose; send jobs for rattan to rose:
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:lp=:rm=rose:rp=rattan:sd=/var/spool/lpd/rattan:
#
# bamboo is connected to rose as well:
#
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:lp=:rm=rose:rp=bamboo:sd=/var/spool/lpd/bamboo:
Then, we just need to make spooling directories on
orchid:
&prompt.root; mkdir -p /var/spool/lpd/rattan /var/spool/lpd/bamboo
&prompt.root; chmod 770 /var/spool/lpd/rattan /var/spool/lpd/bamboo
&prompt.root; chown daemon:daemon /var/spool/lpd/rattan /var/spool/lpd/bamboo
Now, users on orchid can print to
rattan and bamboo. If, for
example, a user on orchid typed
&prompt.user; lpr -P bamboo -d sushi-review.dvi
the LPD system on orchid
would copy the job to the spooling
directory /var/spool/lpd/bamboo and note that it was a
DVI job. As soon as the host rose has room in its
bamboo spooling directory, the two
LPDs would transfer the
file to rose. The file would wait in rose's
queue until it was finally printed. It would be converted from DVI to
&postscript; (since bamboo is a &postscript; printer) on
rose.
Printers with Networked Data Stream Interfaces
Often, when you buy a network interface card for a printer, you
can get two versions: one which emulates a spooler (the more
expensive version), or one which just lets you send data to it as if
you were using a serial or parallel port (the cheaper version).
This section tells how to use the cheaper version. For the more
expensive one, see the previous section Printers Installed on
Remote Hosts.
The format of the /etc/printcap file lets
you specify what serial or parallel interface to use, and (if you
are using a serial interface), what baud rate, whether to use flow
control, delays for tabs, conversion of newlines, and more. But
there is no way to specify a connection to a printer that is
listening on a TCP/IP or other network port.
To send data to a networked printer, you need to develop a
communications program that can be called by the text and conversion
filters. Here is one such example: the script
netprint takes all data on standard input and
sends it to a network-attached printer. We specify the hostname of
the printer as the first argument and the port number to which to
connect as the second argument to netprint. Note
that this supports one-way communication only (FreeBSD to printer);
many network printers support two-way communication, and you might
want to take advantage of that (to get printer status, perform
accounting, etc.).
#!/usr/bin/perl
#
# netprint - Text filter for printer attached to network
# Installed in /usr/local/libexec/netprint
#
$#ARGV eq 1 || die "Usage: $0 <printer-hostname> <port-number>";
$printer_host = $ARGV[0];
$printer_port = $ARGV[1];
require 'sys/socket.ph';
($ignore, $ignore, $protocol) = getprotobyname('tcp');
($ignore, $ignore, $ignore, $ignore, $address)
= gethostbyname($printer_host);
$sockaddr = pack('S n a4 x8', &AF_INET, $printer_port, $address);
socket(PRINTER, &PF_INET, &SOCK_STREAM, $protocol)
|| die "Can't create TCP/IP stream socket: $!";
connect(PRINTER, $sockaddr) || die "Can't contact $printer_host: $!";
while (<STDIN>) { print PRINTER; }
exit 0;
We can then use this script in various filters. Suppose we had
a Diablo 750-N line printer connected to the network. The printer
accepts data to print on port number 5100. The host name of the
printer is scrivener. Here is the text filter for the
printer:
#!/bin/sh
#
# diablo-if-net - Text filter for Diablo printer `scrivener' listening
# on port 5100. Installed in /usr/local/libexec/diablo-if-net
#
exec /usr/libexec/lpr/lpf "$@" | /usr/local/libexec/netprint scrivener 5100
Restricting Printer Usage
printers
restricting access to
This section gives information on restricting printer usage. The
LPD system lets you control who can access
a printer, both locally or
remotely, whether they can print multiple copies, how large their jobs
can be, and how large the printer queues can get.
Restricting Multiple Copies
The LPD system makes it easy for
users to print multiple copies
of a file. Users can print jobs with lpr -#5
(for example) and get five copies of each file in the job. Whether
this is a good thing is up to you.
If you feel multiple copies cause unnecessary wear and tear on
your printers, you can disable the option to
&man.lpr.1; by adding the sc capability to the
/etc/printcap file. When users submit jobs
with the option, they will see:
lpr: multiple copies are not allowed
Note that if you have set up access to a printer remotely (see
section Printers
Installed on Remote Hosts), you need the
sc capability on the remote
/etc/printcap files as well, or else users will
still be able to submit multiple-copy jobs by using another
host.
Here is an example. This is the
/etc/printcap file for the host
rose. The printer rattan is
quite hearty, so we will allow multiple copies, but the laser
printer bamboo is a bit more delicate, so we will
disable multiple copies by adding the sc
capability:
#
# /etc/printcap for host rose - restrict multiple copies on bamboo
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:sc:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:rw:\
:if=/usr/local/libexec/psif:\
:df=/usr/local/libexec/psdf:
Now, we also need to add the sc capability on
the host orchid's
/etc/printcap (and while we are at it, let us
disable multiple copies for the printer
teak):
#
# /etc/printcap for host orchid - no multiple copies for local
# printer teak or remote printer bamboo
teak|hp|laserjet|Hewlett Packard LaserJet 3Si:\
:lp=/dev/lpt0:sd=/var/spool/lpd/teak:mx#0:sc:\
:if=/usr/local/libexec/ifhp:\
:vf=/usr/local/libexec/vfhp:\
:of=/usr/local/libexec/ofhp:
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:lp=:rm=rose:rp=rattan:sd=/var/spool/lpd/rattan:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:lp=:rm=rose:rp=bamboo:sd=/var/spool/lpd/bamboo:sc:
By using the sc capability, we prevent the
use of lpr -#, but that still does not prevent
users from running &man.lpr.1;
multiple times, or from submitting the same file multiple times in
one job like this:
&prompt.user; lpr forsale.sign forsale.sign forsale.sign forsale.sign forsale.sign
There are many ways to prevent this abuse (including ignoring
it) which you are free to explore.
Restricting Access to Printers
You can control who can print to what printers by using the &unix;
group mechanism and the rg capability in
/etc/printcap. Just place the users you want
to have access to a printer in a certain group, and then name that
group in the rg capability.
Users outside the group (including root)
will be greeted with
lpr: Not a member of the restricted group
if they try to print to the controlled printer.
As with the sc (suppress multiple copies)
capability, you need to specify rg on remote
hosts that also have access to your printers, if you feel it is
appropriate (see section Printers Installed on
Remote Hosts).
For example, we will let anyone access the printer
rattan, but only those in group
artists can use bamboo. Here
is the familiar /etc/printcap for host
rose:
#
# /etc/printcap for host rose - restricted group for bamboo
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:sc:rg=artists:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:rw:\
:if=/usr/local/libexec/psif:\
:df=/usr/local/libexec/psdf:
Let us leave the other example
/etc/printcap file (for the host
orchid) alone. Of course, anyone on
orchid can print to bamboo. It
might be the case that we only allow certain logins on
orchid anyway, and want them to have access to the
printer. Or not.
There can be only one restricted group per printer.
Controlling Sizes of Jobs Submitted
print jobs
If you have many users accessing the printers, you probably need
to put an upper limit on the sizes of the files users can submit to
print. After all, there is only so much free space on the
filesystem that houses the spooling directories, and you also need
to make sure there is room for the jobs of other users.
print jobs
controlling
LPD enables you to limit the maximum
byte size a file in a job
can be with the mx capability. The units are in
BUFSIZ blocks, which are 1024 bytes. If you put
a zero for this
capability, there will be no limit on file size; however, if no
mx capability is specified, then a default limit
of 1000 blocks will be used.
The limit applies to files in a job, and
not the total job size.
LPD will not refuse a file that is
larger than the limit you
place on a printer. Instead, it will queue as much of the file up
to the limit, which will then get printed. The rest will be
discarded. Whether this is correct behavior is up for
debate.
Let us add limits to our example printers
rattan and bamboo. Since
those artists' &postscript; files tend to be large, we will limit them
to five megabytes. We will put no limit on the plain text line
printer:
#
# /etc/printcap for host rose
#
#
# No limit on job size:
#
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:mx#0:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:
#
# Limit of five megabytes:
#
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:sc:rg=artists:mx#5000:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:rw:\
:if=/usr/local/libexec/psif:\
:df=/usr/local/libexec/psdf:
Again, the limits apply to the local users only. If you have
set up access to your printers remotely, remote users will not get
those limits. You will need to specify the mx
capability in the remote /etc/printcap files as
well. See section Printers Installed on
Remote Hosts for more information on remote
printing.
There is another specialized way to limit job sizes from remote
printers; see section Restricting Jobs
from Remote Printers.
Restricting Jobs from Remote Printers
The LPD spooling system provides
several ways to restrict print
jobs submitted from remote hosts:
Host restrictions
You can control from which remote hosts a local
LPD accepts requests with the files
/etc/hosts.equiv and
/etc/hosts.lpd.
LPD checks to see if an
incoming request is from a host listed in either one of these
files. If not, LPD refuses the
request.
The format of these files is simple: one host name per
line. Note that the file
/etc/hosts.equiv is also used by the
&man.ruserok.3; protocol, and affects programs like
&man.rsh.1; and &man.rcp.1;, so be careful.
For example, here is the
/etc/hosts.lpd file on the host
rose:
orchid
violet
madrigal.fishbaum.de
This means rose will accept requests from
the hosts orchid, violet,
and madrigal.fishbaum.de. If any
other host tries to access rose's
LPD, the job will be refused.
Size restrictions
You can control how much free space there needs to remain
on the filesystem where a spooling directory resides. Make a
file called minfree in the spooling
directory for the local printer. Insert in that file a number
representing how many disk blocks (512 bytes) of free space
there has to be for a remote job to be accepted.
This lets you insure that remote users will not fill your
filesystem. You can also use it to give a certain priority to
local users: they will be able to queue jobs long after the
free disk space has fallen below the amount specified in the
minfree file.
For example, let us add a minfree
file for the printer bamboo. We examine
/etc/printcap to find the spooling
directory for this printer; here is bamboo's
entry:
bamboo|ps|PS|S|panasonic|Panasonic KX-P4455 PostScript v51.4:\
:sh:sd=/var/spool/lpd/bamboo:sc:rg=artists:mx#5000:\
:lp=/dev/ttyd5:ms#-parenb cs8 clocal crtscts:rw:mx#5000:\
:if=/usr/local/libexec/psif:\
:df=/usr/local/libexec/psdf:
The spooling directory is given in the sd
capability. We will make three megabytes (which is 6144 disk blocks)
the amount of free disk space that must exist on the filesystem for
LPD to accept remote jobs:
&prompt.root; echo 6144 > /var/spool/lpd/bamboo/minfree
User restrictions
You can control which remote users can print to local
printers by specifying the rs capability in
/etc/printcap. When
rs appears in the entry for a
locally-attached printer, LPD will
accept jobs from remote
hosts if the user submitting the job also
has an account of the same login name on the local host.
Otherwise, LPD refuses the job.
This capability is particularly useful in an environment
where there are (for example) different departments sharing a
network, and some users transcend departmental boundaries. By
giving them accounts on your systems, they can use your
printers from their own departmental systems. If you would
rather allow them to use only your
printers and not your computer resources, you can give them
token
accounts, with no home directory and a
useless shell like /usr/bin/false.
Accounting for Printer Usage
accounting
printer
So, you need to charge for printouts. And why not? Paper and ink
cost money. And then there are maintenance costs—printers are
loaded with moving parts and tend to break down. You have examined
your printers, usage patterns, and maintenance fees and have come up
with a per-page (or per-foot, per-meter, or per-whatever) cost. Now,
how do you actually start accounting for printouts?
Well, the bad news is the LPD spooling
system does not provide
much help in this department. Accounting is highly dependent on the
kind of printer in use, the formats being printed, and
your requirements in charging for printer
usage.
To implement accounting, you have to modify a printer's text
filter (to charge for plain text jobs) and the conversion filters (to
charge for other file formats), to count pages or query the printer
for pages printed. You cannot get away with using the simple output
filter, since it cannot do accounting. See section Filters.
Generally, there are two ways to do accounting:
Periodic accounting is the more common
way, possibly because it is easier. Whenever someone prints a
job, the filter logs the user, host, and number of pages to an
accounting file. Every month, semester, year, or whatever time
period you prefer, you collect the accounting files for the
various printers, tally up the pages printed by users, and charge
for usage. Then you truncate all the logging files, starting with
a clean slate for the next period.
Timely accounting is less common,
probably because it is more difficult. This method has the
filters charge users for printouts as soon as they use the
printers. Like disk quotas, the accounting is immediate. You can
prevent users from printing when their account goes in the red,
and might provide a way for users to check and adjust their
print quotas.
But this method requires some database
code to track users and their quotas.
The LPD spooling system supports both
methods easily: since you
have to provide the filters (well, most of the time), you also have to
provide the accounting code. But there is a bright side: you have
enormous flexibility in your accounting methods. For example, you
choose whether to use periodic or timely accounting. You choose what
information to log: user names, host names, job types, pages printed,
square footage of paper used, how long the job took to print, and so
forth. And you do so by modifying the filters to save this
information.
Quick and Dirty Printer Accounting
FreeBSD comes with two programs that can get you set up with
simple periodic accounting right away. They are the text filter
lpf, described in section lpf: a Text Filter, and
&man.pac.8;, a program to gather and total
entries from printer accounting files.
As mentioned in the section on filters (Filters),
LPD starts
the text and the conversion filters with the name of the accounting
file to use on the filter command line. The filters can use this
argument to know where to write an accounting file entry. The name
of this file comes from the af capability in
/etc/printcap, and if not specified as an
absolute path, is relative to the spooling directory.
LPD starts lpf
with page width and length
arguments (from the pw and pl
capabilities). lpf uses these arguments to
determine how much paper will be used. After sending the file to
the printer, it then writes an accounting entry in the accounting
file. The entries look like this:
2.00 rose:andy
3.00 rose:kelly
3.00 orchid:mary
5.00 orchid:mary
2.00 orchid:zhang
You should use a separate accounting file for each printer, as
lpf has no file locking logic built into it, and
two lpfs might corrupt each other's entries if
they were to write to the same file at the same time. An easy way
to insure a separate accounting file for each printer is to use
af=acct in /etc/printcap.
Then, each accounting file will be in the spooling directory for a
printer, in a file named acct.
When you are ready to charge users for printouts, run the
&man.pac.8; program. Just change to the spooling directory for
the printer you want to collect on and type pac.
You will get a dollar-centric summary like the following:
Login pages/feet runs price
orchid:kelly 5.00 1 $ 0.10
orchid:mary 31.00 3 $ 0.62
orchid:zhang 9.00 1 $ 0.18
rose:andy 2.00 1 $ 0.04
rose:kelly 177.00 104 $ 3.54
rose:mary 87.00 32 $ 1.74
rose:root 26.00 12 $ 0.52
total 337.00 154 $ 6.74
These are the arguments &man.pac.8; expects:
Which printer to summarize.
This option works only if there is an absolute path in the
af capability in
/etc/printcap.
Sort the output by cost instead of alphabetically by user
name.
Ignore host name in the accounting files. With this
option, user smith on host
alpha is the same user
smith on host gamma.
Without, they are different users.
Compute charges with price
dollars per page or per foot instead of the price from the
pc capability in
/etc/printcap, or two cents (the
default). You can specify price as
a floating point number.
Reverse the sort order.
Make an accounting summary file and truncate the
accounting file.
name
…
Print accounting information for the given user
names only.
In the default summary that &man.pac.8; produces, you see the
number of pages printed by each user from various hosts. If, at
your site, host does not matter (because users can use any host),
run pac -m, to produce the following
summary:
Login pages/feet runs price
andy 2.00 1 $ 0.04
kelly 182.00 105 $ 3.64
mary 118.00 35 $ 2.36
root 26.00 12 $ 0.52
zhang 9.00 1 $ 0.18
total 337.00 154 $ 6.74
To compute the dollar amount due,
&man.pac.8; uses the pc capability in the
/etc/printcap file (default of 200, or 2 cents
per page). Specify, in hundredths of cents, the price per page or
per foot you want to charge for printouts in this capability. You
can override this value when you run &man.pac.8; with the
option. The units for the
option are in dollars, though, not hundredths of cents. For
example,
&prompt.root; pac -p1.50
makes each page cost one dollar and fifty cents. You can really
rake in the profits by using this option.
Finally, running pac -s will save the summary
information in a summary accounting file, which is named the same as
the printer's accounting file, but with _sum
appended to the name. It then truncates the accounting file. When
you run &man.pac.8; again, it rereads the
summary file to get starting totals, then adds information from the
regular accounting file.
How Can You Count Pages Printed?
In order to perform even remotely accurate accounting, you need
to be able to determine how much paper a job uses. This is the
essential problem of printer accounting.
For plain text jobs, the problem is not that hard to solve: you
count how many lines are in a job and compare it to how many lines
per page your printer supports. Do not forget to take into account
backspaces in the file which overprint lines, or long logical lines
that wrap onto one or more additional physical lines.
The text filter lpf (introduced in lpf: a Text Filter) takes
into account these things when it does accounting. If you are
writing a text filter which needs to do accounting, you might want
to examine lpf's source code.
How do you handle other file formats, though?
Well, for DVI-to-LaserJet or DVI-to-&postscript; conversion, you
can have your filter parse the diagnostic output of
dvilj or dvips and look to see
how many pages were converted. You might be able to do similar
things with other file formats and conversion programs.
But these methods suffer from the fact that the printer may not
actually print all those pages. For example, it could jam, run out
of toner, or explode—and the user would still get
charged.
So, what can you do?
There is only one sure way to do
accurate accounting. Get a printer that can
tell you how much paper it uses, and attach it via a serial line or
a network connection. Nearly all &postscript; printers support this
notion. Other makes and models do as well (networked Imagen laser
printers, for example). Modify the filters for these printers to
get the page usage after they print each job and have them log
accounting information based on that value
only. There is no line counting nor
error-prone file examination required.
Of course, you can always be generous and make all printouts
free.
Using Printers
printers
usage
This section tells you how to use printers you have set up with
FreeBSD. Here is an overview of the user-level commands:
&man.lpr.1;
Print jobs
&man.lpq.1;
Check printer queues
&man.lprm.1;
Remove jobs from a printer's queue
There is also an administrative command, &man.lpc.8;,
described in the section Administering Printers, used to
control printers and their queues.
All three of the commands &man.lpr.1;, &man.lprm.1;, and &man.lpq.1;
accept an option to specify on which
printer/queue to operate, as listed in the
/etc/printcap file. This enables you to submit,
remove, and check on jobs for various printers. If you do not use the
option, then these commands use the printer
specified in the PRINTER environment variable. Finally,
if you do not have a PRINTER environment variable, these
commands default to the printer named lp.
Hereafter, the terminology default printer
means the printer named in the PRINTER environment
variable, or the printer named lp when there is no
PRINTER environment variable.
Printing Jobs
To print files, type:
&prompt.user; lpr filename ...
printing
This prints each of the listed files to the default printer. If
you list no files, &man.lpr.1; reads data to
print from standard input. For example, this command prints some
important system files:
&prompt.user; lpr /etc/host.conf /etc/hosts.equiv
To select a specific printer, type:
&prompt.user; lpr -P printer-name filename ...
This example prints a long listing of the current directory to the
printer named rattan:
&prompt.user; ls -l | lpr -P rattan
Because no files were listed for the
&man.lpr.1; command, lpr read the data to print
from standard input, which was the output of the ls
-l command.
The &man.lpr.1; command can also accept a wide variety of options
to control formatting, apply file conversions, generate multiple
copies, and so forth. For more information, see the section Printing Options.
Checking Jobs
print jobs
When you print with &man.lpr.1;, the data you wish to print is put
together in a package called a print job
, which is sent
to the LPD spooling system. Each printer
has a queue of jobs, and
your job waits in that queue along with other jobs from yourself and
from other users. The printer prints those jobs in a first-come,
first-served order.
To display the queue for the default printer, type &man.lpq.1;.
For a specific printer, use the option. For
example, the command
&prompt.user; lpq -P bamboo
shows the queue for the printer named bamboo. Here
is an example of the output of the lpq
command:
bamboo is ready and printing
Rank Owner Job Files Total Size
active kelly 9 /etc/host.conf, /etc/hosts.equiv 88 bytes
2nd kelly 10 (standard input) 1635 bytes
3rd mary 11 ... 78519 bytes
This shows three jobs in the queue for bamboo.
The first job, submitted by user kelly, got assigned job
number
9. Every job for a printer gets a unique job number.
Most of the time you can ignore the job number, but you will need it
if you want to cancel the job; see section Removing Jobs for details.
Job number nine consists of two files; multiple files given on the
&man.lpr.1; command line are treated as part of a single job. It
is the currently active job (note the word active
under the Rank
column), which means the printer should
be currently printing that job. The second job consists of data
passed as the standard input to the &man.lpr.1; command. The third
job came from user mary; it is a much larger
job. The pathname of the file she is trying to print is too long to
fit, so the &man.lpq.1; command just shows three dots.
The very first line of the output from &man.lpq.1; is also useful:
it tells what the printer is currently doing (or at least what
LPD thinks the printer is doing).
The &man.lpq.1; command also support a option
to generate a detailed long listing. Here is an example of
lpq -l:
waiting for bamboo to become ready (offline ?)
kelly: 1st [job 009rose]
/etc/host.conf 73 bytes
/etc/hosts.equiv 15 bytes
kelly: 2nd [job 010rose]
(standard input) 1635 bytes
mary: 3rd [job 011rose]
/home/orchid/mary/research/venus/alpha-regio/mapping 78519 bytes
Removing Jobs
If you change your mind about printing a job, you can remove the
job from the queue with the &man.lprm.1; command. Often, you can
even use &man.lprm.1; to remove an active job, but some or all of the
job might still get printed.
To remove a job from the default printer, first use
&man.lpq.1; to find the job number. Then type:
&prompt.user; lprm job-number
To remove the job from a specific printer, add the
option. The following command removes job number
10 from the queue for the printer bamboo:
&prompt.user; lprm -P bamboo 10
The &man.lprm.1; command has a few shortcuts:
lprm -
Removes all jobs (for the default printer) belonging to
you.
lprm user
Removes all jobs (for the default printer) belonging to
user. The superuser can remove other
users' jobs; you can remove only your own jobs.
lprm
With no job number, user name, or
appearing on the command line,
&man.lprm.1; removes the currently active job on the
default printer, if it belongs to you. The superuser can remove
any active job.
Just use the option with the above shortcuts
to operate on a specific printer instead of the default. For example,
the following command removes all jobs for the current user in the
queue for the printer named rattan:
&prompt.user; lprm -P rattan -
If you are working in a networked environment, &man.lprm.1; will
let you remove jobs only from the
host from which the jobs were submitted, even if the same printer is
available from other hosts. The following command sequence
demonstrates this:
&prompt.user; lpr -P rattan myfile
&prompt.user; rlogin orchid
&prompt.user; lpq -P rattan
Rank Owner Job Files Total Size
active seeyan 12 ... 49123 bytes
2nd kelly 13 myfile 12 bytes
&prompt.user; lprm -P rattan 13
rose: Permission denied
&prompt.user; logout
&prompt.user; lprm -P rattan 13
dfA013rose dequeued
cfA013rose dequeued
Beyond Plain Text: Printing Options
The &man.lpr.1; command supports a number of options that control
formatting text, converting graphic and other file formats, producing
multiple copies, handling of the job, and more. This section
describes the options.
Formatting and Conversion Options
The following &man.lpr.1; options control formatting of the
files in the job. Use these options if the job does not contain
plain text or if you want plain text formatted through the
&man.pr.1; utility.
&tex;
For example, the following command prints a DVI file (from the
&tex; typesetting system) named fish-report.dvi
to the printer named bamboo:
&prompt.user; lpr -P bamboo -d fish-report.dvi
These options apply to every file in the job, so you cannot mix
(say) DVI and ditroff files together in a job. Instead, submit the
files as separate jobs, using a different conversion option for each
job.
All of these options except and
require conversion filters installed for the
destination printer. For example, the option
requires the DVI conversion filter. Section Conversion
Filters gives details.
Print cifplot files.
Print DVI files.
Print FORTRAN text files.
Print plot data.
Indent the output by number
columns; if you omit number, indent
by 8 columns. This option works only with certain conversion
filters.
Do not put any space between the and
the number.
Print literal text data, including control
characters.
Print ditroff (device independent troff) data.
-p
Format plain text with &man.pr.1; before printing. See
&man.pr.1; for more information.
Use title on the
&man.pr.1; header instead of the file name. This option has
effect only when used with the
option.
Print troff data.
Print raster data.
Here is an example: this command prints a nicely formatted
version of the &man.ls.1; manual page on the default printer:
&prompt.user; zcat /usr/share/man/man1/ls.1.gz | troff -t -man | lpr -t
The &man.zcat.1; command uncompresses the source of the
&man.ls.1; manual page and passes it to the &man.troff.1;
command, which formats that source and makes GNU troff
output and passes it to &man.lpr.1;, which submits the job
to the LPD spooler. Because we
used the
option to &man.lpr.1;, the spooler will convert the GNU
troff output into a format the default printer can
understand when it prints the job.
Job Handling Options
The following options to &man.lpr.1; tell
LPD to handle the job
specially:
-# copies
Produce a number of copies of
each file in the job instead of just one copy. An
administrator may disable this option to reduce printer
wear-and-tear and encourage photocopier usage. See section
Restricting
Multiple Copies.
This example prints three copies of
parser.c followed by three copies of
parser.h to the default printer:
&prompt.user; lpr -#3 parser.c parser.h
-m
Send mail after completing the print job. With this
option, the LPD system will send
mail to your account when it
finishes handling your job. In its message, it will tell you
if the job completed successfully or if there was an error,
and (often) what the error was.
-s
Do not copy the files to the spooling directory, but make
symbolic links to them instead.
If you are printing a large job, you probably want to use
this option. It saves space in the spooling directory (your
job might overflow the free space on the filesystem where the
spooling directory resides). It saves time as well since
LPD
will not have to copy each and every byte of your job to the
spooling directory.
There is a drawback, though: since
LPD will refer to the
original files directly, you cannot modify or remove them
until they have been printed.
If you are printing to a remote printer,
LPD will
eventually have to copy files from the local host to the
remote host, so the option will save
space only on the local spooling directory, not the remote.
It is still useful, though.
-r
Remove the files in the job after copying them to the
spooling directory, or after printing them with the
option. Be careful with this
option!
Header Page Options
These options to &man.lpr.1; adjust the text that normally
appears on a job's header page. If header pages are suppressed for
the destination printer, these options have no effect. See section
Header Pages
for information about setting up header pages.
-C text
Replace the hostname on the header page with
text. The hostname is normally the
name of the host from which the job was submitted.
-J text
Replace the job name on the header page with
text. The job name is normally the
name of the first file of the job, or
stdin if you are printing standard
input.
-h
Do not print any header page.
At some sites, this option may have no effect due to the
way header pages are generated. See Header
Pages for details.
Administering Printers
As an administrator for your printers, you have had to install,
set up, and test them. Using the &man.lpc.8; command, you
can interact with your printers in yet more ways. With &man.lpc.8;,
you can
Start and stop the printers
Enable and disable their queues
Rearrange the order of the jobs in each queue.
First, a note about terminology: if a printer is
stopped, it will not print anything in its queue.
Users can still submit jobs, which will wait in the queue until the
printer is started or the queue is
cleared.
If a queue is disabled, no user (except
root) can submit jobs for the printer. An
enabled queue allows jobs to be submitted. A
printer can be started for a disabled queue, in
which case it will continue to print jobs in the queue until the queue
is empty.
In general, you have to have root privileges
to use the &man.lpc.8; command. Ordinary users can use the &man.lpc.8;
command to get printer status and to restart a hung printer only.
Here is a summary of the &man.lpc.8; commands. Most of the
commands take a printer-name argument to
tell on which printer to operate. You can use all
for the printer-name to mean all printers
listed in /etc/printcap.
abort
printer-name
Cancel the current job and stop the printer. Users can
still submit jobs if the queue is enabled.
clean
printer-name
Remove old files from the printer's spooling directory.
Occasionally, the files that make up a job are not properly
removed by LPD, particularly if
there have been errors during
printing or a lot of administrative activity. This command
finds files that do not belong in the spooling directory and
removes them.
disable
printer-name
Disable queuing of new jobs. If the printer is running, it
will continue to print any jobs remaining in the queue. The
superuser (root) can always submit jobs,
even to a disabled queue.
This command is useful while you are testing a new printer
or filter installation: disable the queue and submit jobs as
root. Other users will not be able to submit
jobs until you complete your testing and re-enable the queue with
the enable command.
down printer-name
message
Take a printer down. Equivalent to
disable followed by stop.
The message appears as the printer's
status whenever a user checks the printer's queue with
&man.lpq.1; or status with lpc
status.
enable
printer-name
Enable the queue for a printer. Users can submit jobs but
the printer will not print anything until it is started.
help
command-name
Print help on the command
command-name. With no
command-name, print a summary of the
commands available.
restart
printer-name
Start the printer. Ordinary users can use this command if
some extraordinary circumstance hangs
LPD, but they cannot start
a printer stopped with either the stop or
down commands. The
restart command is equivalent to
abort followed by
start.
start
printer-name
Start the printer. The printer will print jobs in its
queue.
stop
printer-name
Stop the printer. The printer will finish the current job
and will not print anything else in its queue. Even though the
printer is stopped, users can still submit jobs to an enabled
queue.
topq printer-name
job-or-username
Rearrange the queue for
printer-name by placing the jobs with
the listed job numbers or the jobs
belonging to username at the top of
the queue. For this command, you cannot use
all as the
printer-name.
up
printer-name
Bring a printer up; the opposite of the
down command. Equivalent to
start followed by
enable.
&man.lpc.8; accepts the above commands on the command line. If
you do not enter any commands, &man.lpc.8; enters an interactive mode,
where you can enter commands until you type exit,
quit, or end-of-file.
Alternatives to the Standard Spooler
If you have been reading straight through this manual, by now you
have learned just about everything there is to know about the
LPD
spooling system that comes with FreeBSD. You can probably appreciate
many of its shortcomings, which naturally leads to the question:
What other spooling systems are out there (and work with
FreeBSD)?
LPRng
LPRng
LPRng, which purportedly means
LPR: the Next
Generation
is a complete rewrite of PLP. Patrick Powell
and Justin Mason (the principal maintainer of PLP) collaborated to
make LPRng. The main site for
LPRng is .
CUPS
CUPS
CUPS, the Common UNIX Printing
System, provides a portable printing layer for &unix;-based
operating systems. It has been developed by Easy Software
Products to promote a standard printing solution for all &unix;
vendors and users.
CUPS uses the Internet Printing
Protocol (IPP) as the basis for managing
print jobs and queues. The Line Printer Daemon
(LPD), Server Message Block
(SMB), and AppSocket (a.k.a. JetDirect)
protocols are also supported with reduced functionality. CUPS
adds network printer browsing and PostScript Printer Description
(PPD) based printing options to support
real-world printing under &unix;.
The main site for CUPS is .
Troubleshooting
After performing the simple test with &man.lptest.1;, you might
have gotten one of the following results instead of the correct
printout:
It worked, after awhile; or, it did not eject a full
sheet.
The printer printed the above, but it sat for awhile and
did nothing. In fact, you might have needed to press a
PRINT REMAINING or FORM FEED button on the printer to get any
results to appear.
If this is the case, the printer was probably waiting to
see if there was any more data for your job before it printed
anything. To fix this problem, you can have the text filter
send a FORM FEED character (or whatever is necessary) to the
printer. This is usually sufficient to have the printer
immediately print any text remaining in its internal buffer.
It is also useful to make sure each print job ends on a full
sheet, so the next job does not start somewhere on the middle
of the last page of the previous job.
The following replacement for the shell script
/usr/local/libexec/if-simple prints a
form feed after it sends the job to the printer:
#!/bin/sh
#
# if-simple - Simple text input filter for lpd
# Installed in /usr/local/libexec/if-simple
#
# Simply copies stdin to stdout. Ignores all filter arguments.
# Writes a form feed character (\f) after printing job.
/bin/cat && printf "\f" && exit 0
exit 2
It produced the staircase effect.
You got the following on paper:
!"#$%&'()*+,-./01234
"#$%&'()*+,-./012345
#$%&'()*+,-./0123456
MS-DOS
OS/2
ASCII
You have become another victim of the staircase
effect, caused by conflicting interpretations of
what characters should indicate a new line. &unix; style
operating systems use a single character: ASCII code 10, the
line feed (LF). &ms-dos;, &os2;, and others uses a pair of
characters, ASCII code 10 and ASCII code
13 (the carriage return or CR). Many printers use the &ms-dos;
convention for representing new-lines.
When you print with FreeBSD, your text used just the line
feed character. The printer, upon seeing a line feed
character, advanced the paper one line, but maintained the
same horizontal position on the page for the next character
to print. That is what the carriage return is for: to move
the location of the next character to print to the left edge
of the paper.
Here is what FreeBSD wants your printer to do:
Printer received CR
Printer prints CR
Printer received LF
Printer prints CR + LF
Here are some ways to achieve this:
Use the printer's configuration switches or control
panel to alter its interpretation of these characters.
Check your printer's manual to find out how to do
this.
If you boot your system into other operating systems
besides FreeBSD, you may have to
reconfigure the printer to use a an
interpretation for CR and LF characters that those other
operating systems use. You might prefer one of the other
solutions, below.
Have FreeBSD's serial line driver automatically
convert LF to CR+LF. Of course, this works with printers
on serial ports only. To enable this
feature, use the ms# capability and
set the onlcr mode
in the /etc/printcap file
for the printer.
Send an escape code to the
printer to have it temporarily treat LF characters
differently. Consult your printer's manual for escape
codes that your printer might support. When you find the
proper escape code, modify the text filter to send the
code first, then send the print job.
PCL
Here is an example text filter for printers that
understand the Hewlett-Packard PCL escape codes. This
filter makes the printer treat LF characters as a LF and
CR; then it sends the job; then it sends a form feed to
eject the last page of the job. It should work with
nearly all Hewlett Packard printers.
#!/bin/sh
#
# hpif - Simple text input filter for lpd for HP-PCL based printers
# Installed in /usr/local/libexec/hpif
#
# Simply copies stdin to stdout. Ignores all filter arguments.
# Tells printer to treat LF as CR+LF. Ejects the page when done.
printf "\033&k2G" && cat && printf "\033&l0H" && exit 0
exit 2
Here is an example /etc/printcap
from a host called orchid. It has a single printer
attached to its first parallel port, a Hewlett Packard
LaserJet 3Si named teak. It is using the
above script as its text filter:
#
# /etc/printcap for host orchid
#
teak|hp|laserjet|Hewlett Packard LaserJet 3Si:\
:lp=/dev/lpt0:sh:sd=/var/spool/lpd/teak:mx#0:\
:if=/usr/local/libexec/hpif:
It overprinted each line.
The printer never advanced a line. All of the lines of
text were printed on top of each other on one line.
This problem is the opposite
of the
staircase effect, described above, and is much rarer.
Somewhere, the LF characters that FreeBSD uses to end a line
are being treated as CR characters to return the print
location to the left edge of the paper, but not also down a
line.
Use the printer's configuration switches or control panel
to enforce the following interpretation of LF and CR
characters:
Printer receives
Printer prints
CR
CR
LF
CR + LF
The printer lost characters.
While printing, the printer did not print a few characters
in each line. The problem might have gotten worse as the
printer ran, losing more and more characters.
The problem is that the printer cannot keep up with the
speed at which the computer sends data over a serial line
(this problem should not occur with printers on parallel
ports). There are two ways to overcome the problem:
If the printer supports XON/XOFF flow control, have
FreeBSD use it by specifying the ixon mode
in the ms# capability.
If the printer supports carrier flow control, specify
the crtscts mode in the
ms# capability.
Make sure the cable connecting the printer to the computer
is correctly wired for carrier flow control.
It printed garbage.
The printer printed what appeared to be random garbage,
but not the desired text.
This is usually another symptom of incorrect
communications parameters with a serial printer. Double-check
the bps rate in the br capability, and the
parity setting in the
ms# capability; make sure the printer is
using the same settings as specified in the
/etc/printcap file.
Nothing happened.
If nothing happened, the problem is probably within
FreeBSD and not the hardware. Add the log file
(lf) capability to the entry for the
printer you are debugging in the
/etc/printcap file. For example, here is
the entry for rattan, with the
lf capability:
rattan|line|diablo|lp|Diablo 630 Line Printer:\
:sh:sd=/var/spool/lpd/rattan:\
:lp=/dev/lpt0:\
:if=/usr/local/libexec/if-simple:\
:lf=/var/log/rattan.log
Then, try printing again. Check the log file (in our
example, /var/log/rattan.log) to see any
error messages that might appear. Based on the messages you
see, try to correct the problem.
If you do not specify a lf capability,
LPD uses
/dev/console as a default.