Zobrazujú sa príspevky s označením compilation. Zobraziť všetky príspevky
Zobrazujú sa príspevky s označením compilation. Zobraziť všetky príspevky

nedeľa 25. marca 2012

Installation/upgrade/settings/hints summary

As I needed to reinstall whole system, I wrote down some notes as summary from beginning up to last post plus some new hints.

1. Minimal install
I started with version 9.0-Release. Than you don't have problems to upgrade to latest major version. Etc. from 8.2 to 9.0.
The post about installation is in this article.

2. Post install settings
a)Post install settings include steps from articles part1, part2, part3.
If you have already your settings in your current system and you would like to transfer them, just backup configuration files and put them into new system in the same place. Don't forget to install all ports/packages as before.

b)Edit your "make.conf" for instance like this. Do it before anything else, because from this point you will compile ports so let them be compiled with customized way.

c)HINT:Edit loader.conf. First important option we need to adjust is boot delay. By default the delay is 10s. Just put this line into "/boot/loader.conf":
autoboot_delay="1"

d)Install cvsup and create ports tree/source code. Don't forget to refuse what you don't need. I added to refuse file also:
src/games

Later we will cut off unnecessary features for compilation. We won't compile games so we don't need to download them.

e)HINT:As you recall about mutli-threaded source compilation, we can do this for ports compilation as well with very simple way.
cd /usr/ports/Mk/
vi bsd.port.mk
FORCE_MAKE_JOBS=yes
MAKE_JOBS_NUMBER=5

Why 5?As I've noticed, every time you upgrade ports tree, the "bsd.port.mk" is overwritten. So be aware of this. Of course there is workaround,I have to find it.

f)Install helpful ports like mc, vim...and adjust their configuration.

3. Compilation prepare of your own kernel/world
The aim is to skip everything unnecessary in compilation.

a)Make your own kernel config. Edit GENERIC in currently downloaded source! GENERICs may be different in content among major versions.

b)HINT:Adjust "world" compilation by refusing some stuff. This is my example:
cd /etc
touch src.conf
vi src.conf and what I have there:
WITHOUT_ATM=
WITHOUT_BLUETOOTH=
WITHOUT_CALENDAR=
WITHOUT_CVS=
WITHOUT_CTM=
WITHOUT_DICT=
WITHOUT_FLOPPY=
WITHOUT_GAMES=
WITHOUT_HTML=
WITHOUT_IDEA=
WITHOUT_INFO=
WITHOUT_IPFILTER=
WITHOUT_IPFW=
WITHOUT_LEGACY_CONSOLE=
WITHOUT_NCP=
WITHOUT_PORTSNAP=
WITHOUT_PPP=
WITHOUT_ROUTED=

c)HINT:Install "screen". Screen creates virtual terminals which you can detach and reconnect without loss of content or process output...
For example you can run the compilation in virtual terminal, detach terminal so switch back to normal shell, do your work and time to time switch to virtual terminal to check the process status. You can do the same with ssh connection, open terminal, run command, log off and another day log in back to remote machine, reconnect to virtual terminal and continue with work.
cd /usr/ports/sysutils/screen
make install clean

Usage example:
I want to create virtual terminal with name "MCBSD": screen -S MCBSD
I do something in new terminal and I want to switch back to normal shell:
Ctrl+a+d - this is for detach
I want to list the running terminals: screen -ls
I want to reconnect back to MCBSD terminal: screen -r MCBSD
I'm in the MCBSD terminal and want to terminate this terminal because I don't need it anymore: Ctrl+d

d)Edit "make.conf" to not to compile modules.

4. Compilation of your own kernel/world
-do a backup of config files
cd /usr/src
make buildworld
make buildkernel KERNCONF=[your_kernel]
make installkernel KERNCONF=[your_kernel]
-reboot to single user mode. On boot screen option something like "boot prompt". Type: "boot -s"
mount -a
cd /usr/src
mergemaster -p - leave everything in tmp folder
make installworld
mergemaster - leave everything in tmp folder
-Check differences between tmp and current files.
-manually copy files from tmp folder to final destination if needed.
make delete-old
make delete-old-libs - be careful, google first about it or don't do it
reboot
-if everything works fine, done
-You can reinstall all your ports, this is what I do.

 5. Reinstall ports/packages
It's not necessary if everything goes well. But I do it.
HINT:Install "portmaster". You will need it anyway (or another port-mgmt).
cd /usr/ports/ports-mgmt/portmaster
make install clean
man portmaster

To reinstall all ports with creating packages after compilation which saves time further. Will write about.
portmaster -a -f -g
Packages are stored in "usr/ports/packages".

Now you have fresh system waiting to be backed-up.
This is perfect stage when you can do a backup of whole system.
Every time you will need to install or reinstall computer/server or create new server or even a jail, you will do a restore and in few minutes(bit longer) you have a fresh system ready to go.


nedeľa 4. marca 2012

FreeBSD system upgrade/kernel upgrade 2

1. Kernel hardening
Let's check hierarchy of files we need.
I assume you have source in your computer according this post.
cd /usr/src/sys/amd64/conf
You can copy files I'll write about to /root/kernel etc.
GENERIC: 
-full default kernel configuration used for standard installation
NOTES:
-additional options with explanations which you can stick to your own kernel
-Notes in amd64 dir. are just for amd64 architecture. There are another "Notes" in "/usr/src/sys/conf" dir. which should be valid for all architectures. Notice that "universal" "Notes" are much bigger than arch. specific.
MY_OWN_KERNEL:
-according to post I have sym link of my own kernel configuration from home directory to this location
-do not edit GENERIC. Copy GENERIC to your own named file.

What you should do before you start:
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!
- check if your source tree is one you want to have. Make sure you are downloading right version of source via "cvsup" file.
- be aware, mainly with major upgrade, GENERIC and other files may change. Imagine you have old renamed GENERIC in your home dir. and new in the source tree. This inconsistency may cause real problems.
- be aware, with mainly with major upgrade (from one release to another), also "world" is changing. Serious problems may happen if you have old "world" and new kernel and modules. It has happened to me, and getting all in to the "working" state is really annoying, time consuming, googling...
- with updating kernel due to adding/removing options, there shouldn't be problem with "world" but be aware there can be association with it or other part of source.
- most of the problems during compilation and afterward reboot are created by INCONSISTENCY.
- as time goes, you'll forget what have you changed in kernel configuration. Maybe in further time, you will add new peripheral or you will need something what you have disabled in kernel configuration. So be aware, if something is not working, the problem can be the issue you don't have enabled adequate support in kernel
- Have prepared backup plan in case you can't boot. Etc. you can bump into problem after reboot with mounting issues. Disks have different names as in "/etc/fstab". Download live linux CD or FreeBSD live CD.
!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!! 

What to have in kernel and what not:
After first clean installation, or before upgrade, check "dmesg" command. With this report you know which peripherals you have. So logically, in kernel, you can remove the rest, simply said.
Hardware you have permanently should be compiled within kernel, rest can be compiled as modules. On the internet, you find many diverse opinions about it.
Components compiled within kernel are considered to work faster. I don't think there is noticeable difference.
Another opinion is, that modules are more susceptible to modifications by intruders etc., as they are loading after reboot or on fly as separated files. So it's security issue.
Here is the brief of my KERNEL.

MY_OWN_KERNEL:
##############
cpu             HAMMER - in amd64 there is no other option
ident           MY_OWN_KERNEL - name of your configuration
makeoptions     DEBUG=-g
#
options         SCHED_ULE
...
...
device          pci
#From SCHED_ULE to pci, I suggest to leave it as it is. They ensure main #function of the system. But if you are sure you don't need something, #comment out particular line. Etc. IPV6, NFS, MSDOSFS, CD9660...
added: options         COMPAT_LINUX32 -  instead of module
removed: floppy
ATA controllers: leaved
SCSI controllers: removed
ATA/SCSI peripherals: leaved
RAID controllers: removed
Keyboard + PS/2: leaved
AGP: removed
PCMCIA: removed
SERIAL: removed
PARALLEL PORT: removed
NICs: all removed except: miibus, alc, ale - leave miibus and NIC you have
ISA NICs: removed
WLAN: all removed except:
wlan
IEEE80211_DEBUG
IEEE80211_AMPDU_AGE
IEEE80211_SUPPORT_MESH
wlan_wep
wlan_ccmp
wlan_tkip
wlan_amrr
ipw + iwi + iwn - mine. Leave your NIC
Pseudo devices: leaved
device          bpf: leaved
USB support: leaved
...
All after USB support I removed. Sound as well, I'll use module for it.
############## 

Looking back, notice I removed a lot I don't need. Kernel is now much lighter.      

2. Kernel additional features 
What I can see interesting from amd64 "NOTES" to implement to kernel:
-watchdog (software/hw)
-device polling
-VESA
-I2C
-LINPROCFS
What I can see interesting from general "NOTES" to implement to kernel:
-disk encryption
-IPSEC
-ALTQ
-PF of course
-bridge interface
-link aggregation
-IPSEC interface
-IPFIREWALL - I use PF
-QUOTA

With traditional way, as you compile kernel, you compile modules in the same time. There are hundreds of modules, together they have cca 300MB I think.
There is is way how to compile kernel and modules separately. In next post.

Last post about upgrade will be about separate compilation kernel/modules, "make.conf" adjustment, multi-thread compilation, compilation using ram-disk.