summaryrefslogtreecommitdiff
path: root/docs/docbook/projdoc/Compiling.xml
blob: fd890a20ec8ef78305637224e432773f5ce78be4 (plain)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
<chapter id="compiling">
<chapterinfo>
	&author.jelmer;
	<author><surname>Someone; Jerry perhaps?</surname></author>
	
	<pubdate> 22 May 2001 </pubdate>
	<pubdate> 18 March 2003 </pubdate>
</chapterinfo>

<title>How to compile SAMBA</title>

<para>
You can obtain the samba source from the
<ulink url="http://samba.org/">samba website</ulink>. To obtain a development version, 
you can download samba from CVS or using rsync.
</para>

<sect1>
<title>Access Samba source code via CVS</title>

<sect2>
<title>Introduction</title>

<para>
Samba is developed in an open environment.  Developers use CVS
(Concurrent Versioning System) to "checkin" (also known as 
"commit") new source code.  Samba's various CVS branches can
be accessed via anonymous CVS using the instructions
detailed in this chapter.
</para>

<para>
This chapter is a modified version of the instructions found at
<ulink url="http://samba.org/samba/cvs.html">http://samba.org/samba/cvs.html</ulink>
</para>

</sect2>

<sect2>
<title>CVS Access to samba.org</title>

<para>
The machine samba.org runs a publicly accessible CVS 
repository for access to the source code of several packages, 
including samba, rsync, distcc, ccache and jitterbug. There are two main ways
of accessing the CVS server on this host.
</para>

<sect3>
<title>Access via CVSweb</title>

<para>
You can access the source code via your 
favourite WWW browser. This allows you to access the contents of 
individual files in the repository and also to look at the revision 
history and commit logs of individual files. You can also ask for a diff 
listing between any two versions on the repository.
</para>

<para>
Use the URL : <ulink
url="http://samba.org/cgi-bin/cvsweb">http://samba.org/cgi-bin/cvsweb</ulink>
</para>
</sect3>

<sect3>
<title>Access via cvs</title>

<para>
You can also access the source code via a 
normal cvs client.  This gives you much more control over what you can 
do with the repository and allows you to checkout whole source trees 
and keep them up to date via normal cvs commands. This is the 
preferred method of access if you are a developer and not
just a casual browser.
</para>

<para>
To download the latest cvs source code, point your
browser at the URL :
<ulink url="http://www.cyclic.com/">http://www.cyclic.com/</ulink>.
and click on the 'How to get cvs' link. CVS is free software under 
the GNU GPL (as is Samba).  Note that there are several graphical CVS clients
which provide a graphical interface to the sometimes mundane CVS commands.
Links to theses clients are also available from the Cyclic website.
</para>

<para>
To gain access via anonymous cvs use the following steps. 
For this example it is assumed that you want a copy of the 
samba source code. For the other source code repositories 
on this system just substitute the correct package name
</para>

<procedure>
	<title>Retrieving samba using CVS</title>

	<step>
	<para>
	Install a recent copy of cvs. All you really need is a 
	copy of the cvs client binary. 
	</para>
	</step>

	<step>
	<para>
	Run the command 
	</para>

	<para>
	<userinput>cvs -d :pserver:cvs@samba.org:/cvsroot login</userinput>
	</para>
	</step>

	<step>
	
	<para>
	When it asks you for a password type <userinput>cvs</userinput>.
	</para>
	</step>

	<step>
	<para>
	Run the command 
	</para>
	
	<para>
	<userinput>cvs -d :pserver:cvs@samba.org:/cvsroot co samba</userinput>
	</para>
	
	<para>
	This will create a directory called samba containing the 
	latest samba source code (i.e. the HEAD tagged cvs branch). This 
	currently corresponds to the 3.0 development tree. 
	</para>
	
	<para>
	CVS branches other then HEAD can be obtained by using the
	<option>-r</option> and defining a tag name.  A list of branch tag names 
	can be found on the "Development" page of the samba web site.  A common
	request is to obtain the latest 3.0 release code.  This could be done by 
	using the following userinput.
	</para>
	
	<para>
	<userinput>cvs -d :pserver:cvs@samba.org:/cvsroot co -r SAMBA_3_0 samba</userinput>
	</para>
	</step>

	<step>
	<para>
	Whenever you want to merge in the latest code changes use 
	the following command from within the samba directory: 
	</para>
	
	<para>
	<userinput>cvs update -d -P</userinput>
	</para>
	</step>
</procedure>
	
</sect3>
</sect2>

</sect1>

<sect1>
	<title>Accessing the samba sources via rsync and ftp</title>

	<para>
	pserver.samba.org also exports unpacked copies of most parts of the CVS
	tree at <ulink url="ftp://pserver.samba.org/pub/unpacked">ftp://pserver.samba.org/pub/unpacked</ulink> and also via anonymous rsync at 
	<ulink url="rsync://pserver.samba.org/ftp/unpacked/">rsync://pserver.samba.org/ftp/unpacked/</ulink>. I recommend using rsync rather than ftp.
	See <ulink url="http://rsync.samba.org/">the rsync homepage</ulink> for more info on rsync.                       
	</para>

	<para>
	The disadvantage of the unpacked trees is that they do not support automatic
	merging of local changes like CVS does.  rsync access is most convenient 
	for an initial install.                       
	</para>
</sect1>

<sect1>
<title>Verifying Samba's PGP signature</title>

<para>
In these days of insecurity, it's strongly recommended that you verify the PGP
signature for any source file before installing it. Even if you're not 
downloading from a mirror site, verifying PGP signatures should be a
standard reflex.
</para>


<para>
With that said, go ahead and download the following files:
</para>

<para><screen>
<prompt>$ </prompt><userinput> wget http://us1.samba.org/samba/ftp/samba-2.2.8a.tar.asc</userinput>
<prompt>$ </prompt><userinput> wget http://us1.samba.org/samba/ftp/samba-pubkey.asc</userinput>
</screen></para>

<para>
The first file is the PGP signature for the Samba source file; the other is the Samba public
PGP key itself. Import the public PGP key with:
</para>

<screen>
	<prompt>$ </prompt><userinput>gpg --import samba-pubkey.asc</userinput>
</screen>

<para>
And verify the Samba source code integrity with:
</para>

<screen>
	<prompt>$ </prompt><userinput>gzip -d samba-2.2.8a.tar.gz</userinput>
	<prompt>$ </prompt><userinput>gpg --verify samba-2.2.8a.tar.asc</userinput>
</screen>

<para>
If you receive a message like, "Good signature from Samba Distribution 
Verification Key..."
then all is well. The warnings about trust relationships can be ignored. An
example of what you would not want to see would be:
</para>

<computeroutput>
     gpg: BAD signature from "Samba Distribution Verification Key"
</computeroutput>

</sect1>

<sect1>
	<title>Building the Binaries</title>
	
	<para>To do this, first run the program <userinput>./configure
	</userinput> in the source directory. This should automatically 
	configure Samba for your operating system. If you have unusual 
	needs then you may wish to run</para>
	
	<para>&rootprompt;<userinput>./configure --help
	</userinput></para>
	
	<para>first to see what special options you can enable.
	Then executing</para>
	
	<para>&rootprompt;<userinput>make</userinput></para>
	
	<para>will create the binaries. Once it's successfully 
	compiled you can use </para>
	
	<para>&rootprompt;<userinput>make install</userinput></para>
	
	<para>to install the binaries and manual pages. You can 
	separately install the binaries and/or man pages using</para>
	
	<para>&rootprompt;<userinput>make installbin
	</userinput></para>
	
	<para>and</para>
	
	<para>&rootprompt;<userinput>make installman
	</userinput></para>

	<para>Note that if you are upgrading for a previous version 
	of Samba you might like to know that the old versions of 
	the binaries will be renamed with a ".old" extension. You 
	can go back to the previous version with</para>
	
	<para>&rootprompt;<userinput>make revert
	</userinput></para>
	
	<para>if you find this version a disaster!</para>

	<sect2>
	<title>Compiling samba with Active Directory support</title>
	
	<para>In order to compile samba with ADS support, you need to have installed
	on your system:</para>
	<itemizedlist>
	
	    <listitem><para>the MIT kerberos development libraries
	    (either install from the sources or use a package). The
	    heimdal libraries will not work.</para></listitem>
	
	    <listitem><para>the OpenLDAP development libraries.</para></listitem>
	    
	</itemizedlist>

	<para>If your kerberos libraries are in a non-standard location then
		remember to add the configure option 
		<option>--with-krb5=<replaceable>DIR</replaceable></option>.</para>

	<para>After you run configure make sure that 
		<filename>include/config.h</filename> it generates contains lines like 
		this:</para>

<para><programlisting>
#define HAVE_KRB5 1
#define HAVE_LDAP 1
</programlisting></para>

	<para>If it doesn't then configure did not find your krb5 libraries or
	your ldap libraries. Look in <filename>config.log</filename> to figure
	out why and fix it.</para>

	<sect3>
	<title>Installing the required packages for Debian</title>

	<para>On Debian you need to install the following packages:</para>
	<para>
		<simplelist>
			<member>libkrb5-dev</member>
			<member>krb5-user</member>
		</simplelist>
	</para>
	</sect3>

	<sect3>
	<title>Installing the required packages for RedHat</title>

	<para>On RedHat this means you should have at least: </para>
	<para>
		<simplelist>
			<member>krb5-workstation (for kinit)</member>
			<member>krb5-libs (for linking with)</member>
			<member>krb5-devel (because you are compiling from source)</member>
		</simplelist>
	</para>

	<para>in addition to the standard development environment.</para>

	<para>Note that these are not standard on a RedHat install, and you may need
	to get them off CD2.</para>

	</sect3>
	
	</sect2>
			  
</sect1>

<sect1>
	<title>Starting the &smbd; and &nmbd;</title>

	<para>You must choose to start &smbd; and &nmbd; either
	as daemons or from <application>inetd</application>Don't try
	to do both!  Either you can put them in <filename>
	inetd.conf</filename> and have them started on demand
	by <application>inetd</application>, or you can start them as
	daemons either from the command line or in <filename>
	/etc/rc.local</filename>. See the man pages for details
	on the command line options. Take particular care to read
	the bit about what user you need to be in order to start
	Samba.  In many cases you must be root.</para>

	<para>The main advantage of starting &smbd;
	and &nmbd; using the recommended daemon method
	is that they will respond slightly more quickly to an initial connection
	request.</para>

	<sect2>
		<title>Starting from inetd.conf</title>

		<note>
		<para>The following will be different if 
		you use NIS, NIS+ or LDAP to distribute services maps.</para>
		</note>
		
		<para>Look at your <filename>/etc/services</filename>. 
		What is defined at port 139/tcp. If nothing is defined 
		then add a line like this:</para>

		<para><programlisting>netbios-ssn     139/tcp</programlisting></para>

		<para>similarly for 137/udp you should have an entry like:</para>

		<para><programlisting>netbios-ns	137/udp</programlisting></para>

		<para>Next edit your <filename>/etc/inetd.conf</filename> 
		and add two lines something like this:</para>

		<para><programlisting>
		netbios-ssn stream tcp nowait root /usr/local/samba/bin/smbd smbd 
		netbios-ns dgram udp wait root /usr/local/samba/bin/nmbd nmbd 
		</programlisting></para>

		<para>The exact syntax of <filename>/etc/inetd.conf</filename> 
		varies between unixes. Look at the other entries in inetd.conf 
		for a guide.</para>

		<note><para>Some unixes already have entries like netbios_ns 
		(note the underscore) in <filename>/etc/services</filename>. 
		You must either edit <filename>/etc/services</filename> or
		<filename>/etc/inetd.conf</filename> to make them consistent.
		</para></note>

		<note><para>On many systems you may need to use the 
		<parameter>interfaces</parameter> option in &smb.conf; to specify the IP
		address and netmask of your interfaces. Run 
		<application>ifconfig</application> 
		as root if you don't know what the broadcast is for your
		net. &nmbd; tries to determine it at run 
		time, but fails on some unixes. 
		</para></note>

		<warning><para>Many unixes only accept around 5 
		parameters on the command line in <filename>inetd.conf</filename>. 
		This means you shouldn't use spaces between the options and 
		arguments, or you should use a script, and start the script 
		from <command>inetd</command>.</para></warning>

		<para>Restart <application>inetd</application>, perhaps just send 
			it a HUP. If you have installed an earlier version of &nmbd; then
			you may need to kill &nmbd; as well.</para>
	</sect2>
	
	<sect2>
		<title>Alternative: starting it as a daemon</title>

		<para>To start the server as a daemon you should create 
		a script something like this one, perhaps calling 
		it <filename>startsmb</filename>.</para>

		<para><programlisting>
		#!/bin/sh
		/usr/local/samba/bin/smbd -D 
		/usr/local/samba/bin/nmbd -D 
		</programlisting></para>

		<para>then make it executable with <command>chmod 
		+x startsmb</command></para>

		<para>You can then run <command>startsmb</command> by 
		hand or execute it from <filename>/etc/rc.local</filename>
		</para>

		<para>To kill it send a kill signal to the processes 
			&nmbd; and &smbd;.</para>

		<note><para>If you use the SVR4 style init system then 
		you may like to look at the <filename>examples/svr4-startup</filename>
		script to make Samba fit into that system.</para></note>
	</sect2>
</sect1>

<sect1>
<title>Common Errors</title>

<para><quote>
I'm using gcc 3 and I've compiled Samba-3 from the CVS and the 
binaries are very large files (40 Mb and 20 Mb). I've the same result with
<option>--enable-shared</option>  ?
</quote>
</para>

<para>
The dwarf format used by GCC 3 for storing debugging symbols is very inefficient.	
Strip the binaries, don't compile with -g or compile with -gstabs.
</para>

</sect1>

</chapter>