From: Casper.Dik@Holland.Sun.COM (Casper H.S. Dik - Network Security Engineer) Newsgroups: comp.unix.solaris, comp.sys.sun.admin Subject: Solaris 2 Frequently Asked Questions (FAQ) 1.74 Date: 17 Nov 2002 12:44:34 GMT Message-ID: <Solaris2/FAQ_1037537073@uk-usenet.uk.Sun.COM> Reply-To: Casper.Dik@Holland.Sun.COM Summary: This posting contains a list of Frequently Asked Questions (and answers) about Sun Microsystems Solaris 2.x system in general. See also the FAQ archived as Solaris2/Porting. Archive-name: Solaris2/FAQ Version: 1.74 Last-Modified: 2002/11/17 12:43:54 Maintained-by: Casper Dik <Casper.Dik@Holland.Sun.COM> The following is a list of questions that are frequently asked about Solaris 2.x and later. Where the FAQ mentions "Solaris 2.x", it really refers to Solaris 2.x, Solaris 7 and later. You can help make it an even better-quality FAQ by writing a short contribution or update and sending it BY EMAIL ONLY to me. A contribution should consist of a question and an answer, and increasing number of people sends me contributions of the form "I don't know the answer to this, but it must be a FAQ, please answer it for me"; please don't send me those. Thanks! As you may have noted, I have switched employers and work for Sun as of April 1st 1995. Sun is in no way responsible for the contents of this FAQ. The latest Solaris 2 FAQ, including an HTML version, and some other goodies |can be obtained through ftp from <ftp://ftp.science.uva.nl/pub/>. A new version of the FAQ is available with an index separate from |all questions, it's <http://www.science.uva.nl/pub/solaris/solaris2/>. So it's a lot quicker to download. Also, an experimental FAQ search service |at <http://www.science.uva.nl/cgi-bin/sfaq.cgi> is now available. Please note that these addresses have changed because of a reorg. Just |replace "fwi" or "wins" in the old addresses with "science". |The HTML <http://www.science.uva.nl/pub/solaris/solaris2.html> version of the FAQ contains references to most FTP sites and files mentioned in the FAQ. The references to ftp sites are always to either HTML files or directories, never to binary files. I've added an index of questions and marked changed(*) and added questions(+). The FAQ is being reorganized, time permitting. The index is generated automatically, so there may be errors there. Not all questions are in the section they belong in. Suggestions on how best to subdivide/order the FAQ are welcome. 1. GENERAL 1.1) What's Solaris anyway? 1.2) Why should I upgrade? 1.3) Should I move to Solaris 2.x now, or later, or never? 1.4) What is Solaris 2? Is it really SVR4 based? | *1.5) What machines does Solaris 2.x run on? 1.6) Will my old applications from 4.1.x run on Solaris 2? | *1.7) Will my SPARC binaries run unchanged on UltraSPARC machines? 1.8) Will my old applications from SVR3 on the 386 run on Solaris 2/x86? 1.9) Where has the XXX command gone now? 1.10) When I upgrade, should I use SunInstall "upgrade", or start over? 1.11) Is Solaris 2.x reliable/stable enough to use? 1.12) Why do some people dislike Solaris2? 1.13) Why do some people *like* Solaris2? 1.14) What is Sun doing to help me migrate? 1.15) Can I use my SunOS 4 disks on Solaris 2.x? 1.16) How can I enable System V IPC? Ipcs says it isn't configured in. 1.17) Solaris 7 is 64 bit, does that affect Solaris/IA-32? *1.18) Solaris 7 is 64 bit, does this mean I can no longer use my old SPARCs? 1.19) Where can I download Solaris binaries from? | 1.20) What Solaris release am I running on my system? 2. SOURCES OF INFORMATION 2.1) How can I RTFM when I don't have it anymore? 2.2) Why is "man -k" so confused? | *2.3) What Software is available for Solaris 2.x? 2.4) What FTP/WWW sites do I need to know about? 2.5) What other FAQ's do I need to know about? 2.6) What mailing lists should I get? 2.7) What books should I read? 2.8) What hardware is supported by Solaris 2.x for Intel? 2.9) What is Wabi? | *2.10) I'm running into some limits of SunOS 4.x, will upgrading to Solaris 2.x help? 3. SYSTEM ADMINISTRATION 3.1) How much disk space do I need to install Solaris 2? 3.2) How can I convert all my local changes that I've made over the years into their corresponding forms on Solaris 2? 3.3) What are "packages"? 3.4) Why can't I write in/mount over /home? 3.5) Why can't I access CDs or floppies? 3.6) Why are there no passwords in /etc/passwd? 3.7) Why can't I rlogin/telnet in as root? 3.8) How can I have a user without a password? | +3.9) How can I have a "su-only" user? | *3.10) How can I set up anonymous FTP? | 3.11) How can I print from a Solaris 2 (or any System V Release 4) system to a SunOS4.x (or any other BSD) system? | 3.12) How can I print to a non-Postscript/non-ascii printer? | 3.13) How can I print to a networked printer? | 3.14) Why does lp complain about invalid content types? | 3.15) My jobs stay in the queue after printing. | 3.16) Are there any alternatives to the system V spooler? | *3.17) What happened to /dev/MAKEDEV? How do I add devices? | 3.18) Why isn't my tape/cd player or new disk/device recognized? | 3.19) What happened to /etc/rc and /etc/rc.local? | 3.20) Can't I have /etc/rc.local back? | 3.21) Why are there two versions of shutdown? | 3.22) When will somebody publish a package of the BSD (4.3BSD Net2) "init", "getty", and "rc/rc.local", so we can go back to life in the good old days? | 3.23) What has happened to getty? What is pmadm and how do you use it? | 3.24) How do I get the screen to blank when nobody's using it? | 3.25) And what about screendump, screenload and clear_colormap? | 3.26) Where did etherfind go? | 3.27) Can I run SunOS 4.1.x on my SPARC Classic, LX, SS5, SS4, SS20, Voyager, SS1000, SC2000, CS6400, Ultra? | 3.28) The "find" program complains that my root directory doesn't exist? | 3.29) I'm having troubles with high-speed input on the Sparc serial ports. What should I do? | 3.30) How do I make ksh or csh be the login shell for root? | 3.31) What is this message: "automount: No network locking on host, contact administrator to install server change."? | 3.32) I have all kinds of problems with SCSI disks/RAIDs under Solaris 2.x They worked fine under SunOS 4.x. | 3.33) How do I make Solaris2 use my old ADAPTEC ACB-4000 and Emulex MD-21 disk controllers? | 3.34) Should I wait installing the latest Solaris release until there are enough patches? | 3.35) Why are there so many patches for Solaris 2.x? | *3.36) What are the ``mandatory'' patches I keep hearing about? | 3.37) Which patches should I apply? | 3.38) Where do I get patches from? | 3.39) Where can I obtain Solaris 2/x86 driver updates? | 3.40) Why does installing patches take so much space in /var/sadm? | 3.41) Do I need to back out previous versions of a patch? | *3.42) How can I have more than 48 pseudo-ttys? | 3.43) How can I have normal users chown their files? | 3.44) How can I get ps to print %MEM and %CPU? | 3.45) How can I get the DOS and Unix clock to agree on Solaris/x86? | 3.46) How can I increase the number of file descriptors per process? | 3.47) Can I install both SunOS and Solaris on the same machine, and choose between them at boot time? | 3.48) How do I disable banner pages under Solaris? | 3.49) How do I change my hostname? | 3.50) Can I run multiple terminals on the console of Solaris x86 like those supported on Interactive Unix and SCO? | 3.51) How can I prevent daemons from creating mode 666 files? | 3.52) How do I change the terminal type for /dev/console? | 3.53) If I login over the network, my terminal type is set to "sun"/"AT386" How can I change that? In SunOS 4.x the type would have been "network" | 3.54) How can I change the SYSV IPC parameters? | 3.55) How do I enable/disable dtlogin? | 3.56) How do I configure dtlogin? | 3.57) How can I configure a second monitor or change X server options? | 3.58) How can I have more than 128 X windows clients? | *3.59) Xvnc/Xnest/Xvfb can't create a socket in /tmp/.X11-unix. | 3.60) How can I restrict remote access through dtlogin? | 3.61) How do I disable the 2.6+ configuration assistant? | 3.62) How do I convert SunOS 4.x style /etc/passwd to Solaris passwd & shadow. | 3.63) How can I obtain the PROM level without halting my SPARC? | 3.64) How can I use Solaris 2.6+ formatted disks on SunOS 4.x? | 3.65) Can I use soft mounts with NFS? | 3.66) How can I boot a 32 bit kernel when a 64 bit kernel is installed? | 3.67) How can I tell whether I'm running a 32 or 64 bit kernel? | 3.68) How do I get rid of the Solregis pop-up? | 3.69) Where do I get Disksuite for Solaris 8? | 3.70) How do perform an old-fashioned interactive install in Solaris 8? | 3.71) Now that Solaris install from several CDs, how can I jumpstart? | 3.72) How can I grow a UFS filesystem? | 3.73) How do I install without starting OpenWindows? | 3.74) How do I set up Solaris for my time zone and daylight saving rules? | 3.75) I always install my own perl, can I remove the Sun installed one? | 3.76) Where did kgmon go? | +3.77) Why do swap -l, swap -s and /tmp disagree about the amount of swap? | +3.78) How do I secure my Solaris system? 4. NETWORKING 4.1) How do I use DNS w/o using NIS or NIS+? 4.2) What is /etc/nsswitch.conf? 4.3) What does [NOTFOUND=return] in nsswitch.conf mean? 4.4) Can I run a nis/yp server under Solaris 2.x? 4.5) Can I run NIS+ under Solaris 1 (SunOS 4.1.x) 4.6) With NIS+ how do I find out which machine a client is bound to? 4.7) Ypcat doesn't work on the netgroup table on a NIS+ server, why? 4.8) Why is rpc.nisd such a memory pig according to ps? 4.9) How do I tell my NIS+ server to service DNS requests from 4.x clients? 4.10) How can I have multiple addresses per interface? 4.11) Solaris 2.x supports filesystem sizes up to 1TB. Will this give interoperability problems with NFS? 4.12) Where can I get an SNMP agent for Solaris? *4.13) How can I use full-duplex ethernet? 4.14) Where can I get BOOTP/DHCP for Solaris? 4.15) What kind of multicast support does Solaris have? | *4.16) How can I have NAT or a firewall on Solaris? *4.17) Where can I get an IPv6 capable version of tcp wrapper? 5. TROUBLE SHOOTING 5.1) The Solaris 2.x application XX fails with a mysterious error condition. 5.2) In Solaris 2.5 nm is slow or dumps core. 5.3) Why can't I run Answerbook on a standalone machine? 5.4) Why can't I display Answerbook remotely? 5.5) Why can't I run filemgr, I get ``mknod: permission denied''? 5.6) Why do I get isinf undefined when linking with libdps on Solaris 2.3? 5.7) I can't get PPP to work between Solaris 2.3 and other platforms. 5.8) Using compat mode for passwd doesn't work in 2.3? 5.9) Why do I get __builtin_va_alist or __builtin_va_arg_incr undefined? 5.10) When compiling, I get "No DATAMODEL_NATIVE specified"? 5.11) My machine hangs during the boot process. It seems related to ps. 5.12) Syslogd doesn't seem to log anything. 5.13) Syslogd in 2.6 runs with -z <num> -n, what's up? 5.14) I get ``Invalid client credential'' when mounting filesystem on Solaris client from non-Sun fileserver. 5.15) After upgrade to 2.4, ls on NFS mounted directories hangs. 5.16) After installing patch 101945-xx, I have NFS problems (ksh looping). 5.17) I messed up /etc/system, now I can't boot. 5.18) The /etc/path_to_inst file is corrupted, I can't boot. 5.19) TCP/IP connections time out too soon, especially on slow links. 5.20) Sendmail connection to non-Unix hosts don't work. 5.21) Solaris 2.x can't set up any TCP/IP connections to certain hosts. 5.22) I read 5.21, but I still have connectivity problems. 5.23) When reading mail on non-Solaris clients of a Solaris mail server, or with non-Solaris mail readers, some messages get split into multiple messages. 5.24) Mail/mailx often send reply to wrong user or show wrong sender. 5.25) One of my users can't login (one some machines). 5.26) My clients with remote /var (/var/adm) partitions won't boot. 5.27) Vacation doesn't work reliably in a mixed Solaris/SunOS environment. 5.28) I have a lot of <defunct> processes. How do I get rid of them? 5.29) I get /dev/ptmx: No such device when attempting to telnet/rlogin in. | +5.30) I get Could not grant slave pty on telnet/rlogin | 5.31) ld bails out with msync errors. | 5.32) su responds with "Sorry" and doesn't prompt for a password. | 5.33) Why can't I install 2.4 from a non-Sun CD while I could do so with 2.3? | 5.34) ifconfig can't find my network interface | 5.35) I have an application that compiled fine, but when I run it I get: fatal: libfoo.so.2: can't open file: errno=2 or No such file or directory | 5.36) Motif programs dump core almost immediately. | 5.37) cc complains that "language optional software package not installed". | 5.38) thr_create/pthread_create and other thread functions always return -1 | 5.39) Solaris 2.4 is getting slower over time/seems to have a kernel memory leak. | 5.40) Why do I get ``Unable to install/attach driver 'xxx''' messages? | 5.41) I can't run nfs: netdir_getbyname failure, /dev/udp: bind problem | 5.42) Why do I get ``named[]: rt_malloc: memdebug overflow'' errors? | 5.43) The ld command dumps core on Solaris/x86 | 5.44) In Solaris 2.4 my TCP performance is extremely poor. | 5.45) Solaris 2.4 in.tftpd is terribly slow. | 5.46) I get "df: Could not find mount point ..." | 5.47) I changed root's shell, forgotten root's password, and I can't login. | 5.48) How do I boot single user from CD? | 5.49) How do I interrupt the system boot sequence on SPARC? | 5.50) How do I reset the NVRAM to factory defaults? | 5.51) When linking C++ programs, I get "_ex_keylock" undefined. | 5.52) My NFS server hangs when I get filesystem full/over quota errors. | 5.53) OpenWindows fails with "Binding Unix Socket: Invalid argument" | 5.54) Why is Xsun such a memory pig, especially on the SX, S24 and FFB? | 5.55) Solaris 2.5 and Solaris 2.4 patch 101945-34+ have poor TCP performance over slow links. | 5.56) After install x86 patch 101946-29, I have problems with sockets and TCP/IP throughput. | 5.57) The commands du and ls show funny block counts on NFSv3 filesystems. | 5.58) When I halt/reboot my system I get "INIT: failed write of utmpx entry" | 5.59) Patch installation often fails with "checkinstall" errors. | 5.60) Why do I get a CPU-bound rpc.ttdbserverd process? | 5.61) What is /proc? Can I safely remove the large files there? | 5.62) What does "named[XX]: Lame server on 'hostname' ...." mean? | 5.63) I installed Solaris on a new/big disk, but now booting fails. | 5.64) I have a problem with large disk drives. | 5.65) When I try a network install I get: "WARNING: using boot version 8, expected 9" | 5.66) My Ultra shuts down with "WARNING: THERMAL WARNING DETECTED!!!" | 5.67) Power management shuts down my monitor, but it never comes back. | 5.68) I can't seem to disable power management in 2.6! | 5.69) Power management no longer kicks in when xlock runs | 5.70) Orainst 7.3.2 dumps core in 2.5.1 with patches and in 2.6. | 5.71) My dial-on-demand link keeps dialing out, seems DNS related. | 5.72) Processes hang in door_call(), hostname lookups hang. | 5.73) When using Solaris 2.6, many fonts don't show up properly in Netscape 4. | 5.74) When using virtual interfaces in 2.6, the system picks a random source address. How can I fix this? | 5.75) A downloaded binary complains "libresolv.so.2: can't open file" | 5.76) Ypserv/NIS w/ DNS is very unreliable in Solaris 2.6. | 5.77) When trying to install Solaris 2.x on an Ultra-5/Ultra-10/Ultra-60, it can't find "kernel/unix". | 5.78) After the system has been up for a while, freemem is only a couple of MB. | 5.79) A device driver that worked fine under S2.6 stopped loading under S7 | 5.80) I get a lot of "late collisions", what are those? | 5.81) I can't mount an NFS filesystem, I get "RPC: Program not registered". | 5.82) How do I automatically NFS share inserted CD-Roms? | 5.83) I cannot run remote tooltalk sessions on Solaris 8 displays and recently patched older systems. | 5.84) Where is all my memory in use? | 5.85) Tcpd prints "connect (refused) from 0.0.0.0" in Solaris 8 and later? | 5.86) The permissions on /tmp are wrong after a reboot? | +5.87) After upgrading to Solaris 9 vold no longer mounts CDs. 6. SOFTWARE DEVELOPMENT 6.1) Where is the C compiler or where can I get one? | *6.2) Which packages do I need to install to support a C compiler? 6.3) Where has ranlib gone? 6.4) What do I need to compile X11R5? 6.5) I can't compile X11R6 on Solaris 2.4 6.6) X11R6 on Solaris 2.4 won't run. Xinit dies with "User Signal 1". Xterms won't die. Dired doesn't work in emacs-19. 6.7) I get undefined symbols when compiling R6 in Solaris 2.2. 6.8) After compiling X11R6 with gcc 2.7.0, X programs won't find their libraries. 6.9) How can I run X11R6 on my SS4 w/ TCX? 6.10) Can I run X11R6 on my SX, ZX, TCX, Creator, Creator3D or Elite3D? | 6.11) I can't get perl 4.036 to compile or run. 6.12) I can't get sockets to work with perl. 6.13) I have problems compiling MH 6.8.3 6.14) I can't get XV 3.x to compile or run correctly. 6.15) What happened to NIT? What new mechanisms exist for low-level network access? 6.16) Where are all the functions gone that used to be in libc? 6.17) I'm still missing some functions: bcopy, bzero and friends. 6.18) Can I use the source compatibility package to postpone porting? 6.19) Why doesn't readdir work? It chops the first two characters of all filenames. 6.20) Why do I get undefined symbols when linking with curses/termcap? 6.21) Where are the Motif includes and libraries? 6.22) When I call semctl(), my program crashes. It works fine elsewhere. 6.23) Traceroute to Solaris 2.x machines gives many timeouts. 6.24) I have problems linking my application statically. 6.25) I get '"/usr/platform/SUNW,Ultra-1/lib/libc_psr.so.1": not in executable format: format not recognized' from gdb on my Ultra. 6.26) How can I make Gdb work with Sun's C compiler? 6.27) Does Solaris have problems with dates in the year 2000 and after? 6.28) I can't seem to get older gcc releases to work under Solaris 2.6 6.29) Gdb doesn't fully work on Solaris 2.6. 6.30) I can't get gdb to compile with Sun's C compiler 7. KERNEL PARAMETERS 7.1) Where can I find a list of all Solaris kernel parameters? | 7.2) How can I guard my system against stack buffer overflow exploits? 7.3) How can I restrict the number of processes per user? 7.4) What purpose does the maxusers variable serve? 7.5) How can I have a clock resolution better than 10ms? 7.6) How can I have more than 16 groups per user? 7.7) How can I disable _POSIX_CHOWN_RESTRICTED? My users want to chown files? 7.8) How can I make the NFS server ignore unprivileged clients? 8. ACKNOWLEDGEMENTS 1. GENERAL 1.1) What's Solaris anyway? Solaris(tm) is Sun's name for their UNIX-based user environment, including the UNIX(tm) operating system, window system (X11-based), and other stuff too. Solaris 1.x is a retroactive (marketing?) name for SunOS 4.1.x (x>=1), a version of UNIX that is BSD-like with some SVR4 features, along with OpenWindows 3.0. Solaris 2.x (which is what most everybody means by "Solaris") includes SunOS 5.x, which is an SVR4-derived UNIX, along with OpenWindows 3.x, tooltalk, and other stuff. Solaris 7 and later are basically newer revisions of Solaris 2.x with the leading "2." stripped. This FAQ covers Solaris 2.x and later. (See 1.5 for a chart with more info) 1.2) Why should I upgrade? Solaris 2 is more compatible with the rest of the UNIX industry. Other major UNIX vendors including IBM, HP, SGI, SCO, and others are based on System V rather than on BSD (though some of them are on SVR3, not SVR4). All but one commercial PC-based UNIXes are System V based (and mostly SVR4); the only commercial exception is from a small but interesting firm called BSDI. Solaris 2 is where Sun has been putting almost all its development for the last few years now. There will be no new development on SunOS4; already much of Sun's add-on software is only available for Solaris 2. Solaris 2 is the only supported MP OS on all but the old 4/6x0-1x0 w/ Ross 605 modules. All the UltraSPARC systems require Solaris 2.x. Sun software is being released first for Solaris 2.x and usually no longer for SunOS 4.1.x (No Sun JVM for 4.1.x) Solaris 2.3 and above feature a standard X11R5 release of The X Window System, a benefit for those who didn't like NeWS or the V2/V3 OpenWindows server. (It's still called OpenWindows, but it is the X11R5 server with Adobe DPS added in). It is as fast or faster than MIT R5 or XC R6 (depending on the platform) and supports all Sun graphics hardware. Solaris 2 is more standards-compliant than Solaris 1/SunOS 4. Solaris 2.6 is also Y2000 compliant, so upgrading to the latest Solaris release is a must. 1.3) Should I move to Solaris 2.x now, or later, or never? That depends - on you, your situation, your application mix, etc. Some year SunOS4.1.x will go the way of the 3/50 - it'll still be around, but Sun will no longer support it. You don't have to upgrade immediately, but you should be planning your upgrade path by now. If you would rather stay with a BSD-style operating system, you should consider OpenBSD or NetBSD. OpenBSD is regarded as the world's most secure OS, and NetBSD is the world's most portable OS. Both are BSD-style OSes in the spirit of 4.xBSD, which SunOS4 was also derived from. Both run on SPARC, have SunOS emulation, and are Y2K compliant. 1.4) What is Solaris 2? Is it really SVR4 based? Solaris 2 is an "operating environment" that includes the SunOS 5.x operating system and the OpenWindows 3.x window environment. SunOS 5.x is based on USL's SVR4.0. SVR4.0, in turn, was developed jointly by AT&T and Sun while Sun was developing 4.1.0, which is why things like RFS, STREAMS, shared memory, etc., are in SunOS 4.1.x, and why things like vnodes, NFS and XView are in SVR4.0. (RFS, by the way, was dropped effective Solaris 2.3). |*1.5) What machines does Solaris 2.x run on? Solaris 2.0 only ran on desktop SPARCstations and a few other Sun machines. Solaris 2.1 and 2.4 and later come in two flavors, SPARC and "x86". Solaris 2.1 (and 2.2, ...) for SPARC run on all SPARCstations and clones, as well as all models of the Sun-4 family. The old FPU on the 4/110 and 4/2x0 is not supported, so floating point will be SLOW, but it does work. Starting with 2.5 support for machines with kernel architecture "sun4" is dropped. I.e., the machines on which "uname -m" and "arch -k" return "sun4"; not the machines on which those commands return sun4c, sun4m, sun4u or sun4d. The unsupported machine include the sun4/110 (not to be confused with the SS4 @110MHz), sun4/2xx, sun4/3xx and sun4/4xx. These are all VME based deskside/server configurations. All version of the SPARC PROMs should work under Solaris 2.x, but you can run into the following problems: 1) No part of the boot partition may be offset more than 1 GB into the disk, unless you have a PROM with rev 2.6 or better. Note that the number behind the point is not a fraction, it's an integer. Hence 3.0 > 2.25 > 2.10 > 2.9 > 2.1 > 2.0 > 1.6. 2) If booting diskless, you need a link in the /tftpboot directory, "tftpboot -> .". Admintool will make that link automatically. A Solaris port for the PowerPC has been completed, and has been released, effective Solaris 2.5.1. But support for it was dropped almost immediately as it went nowhere. Solaris 2.1, 2.4 and above for x86 have been released to end users. It runs on a wide range of high-end PC-architecture machines. "High-end" means: 16MB of RAM and an 80486 (or 33MHz or faster 80386DX). It will not run on your 4 MB 16MHz 386SX, so don't bother trying! Also, floating point hardware (80387-style) is absolutely required in 2.1. Starting with Solaris 2.4 for x86, a fp CO-processor is no-longer required, though still recommended. With the world moving to PCI, MCA support is now gone and ISA support is dwindling. The following OS revision chart maps the major Solaris releases. Not all HW releases have been included as some are relatively unimportant. Solaris SunOS OpenWin Comments 1.0 4.1.1B 2.0 4.1.1_U1 2.0 sun3 EOL release (not named Solaris) 1.0.1 4.1.2 2.0 6[379]0-1[24]0 MP 1.1 4.1.3 3.0 SP Viking support 1.1C 4.1.3C 3.0 Classic/LX 1.1.1 4.1.3_U1 3.0_U1 4.1.3 + fixes + Classic/LX support 1.1.1 B 4.1.3_U1B 3.0_U1 1.1.1B + SS5/SS20 support 1.1.2 4.1.4 3_414 The "final" 4.x release (SS20 HS11) 2.0 5.0 3.0.1 sun4c only 2.1SPARC 5.1 3.1 Dec '92 2.1 x86 5.1 3.1 May '93 2.2SPARC 5.2 3.2 May '93 2.3SPARC 5.3 3.3 Nov '93 OpenWin 3.3 is X11R5 based: Display PostScript instead of NeWS, no SunView. It is still primarily OPEN LOOK. The Spring 1995 OpenWin will be Motif and COSE-based. Statically linked BCP support 2.3 edition II SPARC Special Solaris 2.3 distribution for Voyager and SparcStation 5 2.3 HW 8/94 SPARC Supports S24 (24 bits color for SS5), POSIX 1003.2, Energy Start power management and SunFastEthernet + patches. 2.4 5.4 3.4 From this moment on, the SPARC and x86 releases are in sync. Q3 '94 Adds motif runtime and headers (not mwm). 2.4 HW 11/94 First SMCC release of 2.4 2.4 HW 3/95 Second SMCC release of 2.4 (includes support for booting from SSA) 2.5 5.5 3.5 UltraSPARC support, PCI support. NFS V3, NFS/TCP, ACLs, CDE, Sendmail V8 name service cache, dynamic PPP Posix threads, doors (new IPC mechanism) many "BSD" type functions back in libc, many "BSD" programs back in /usr/bin. mixed mode BCP support (e.g., apps only dynamically linked against libdl.so) 2.5 HW 1/96 Creator3D support (Creator3D/FFB+ is not supported in 2.5 11/95, though the files are present but of unsupported, "mostly works", beta quality) 2.5.1 Ultra-2 support, Sun Enterprise server support. Large (32bit UID) support. 64bit KAIO (aioread64/aiowrite64), 3.75 GB of virtual memory. Pentium/Pentium Pro optimizations. (upto 25% for certain database apps) Ultra ZX support. Initial and last PowerPC desktop release. 2.5.1 HW 4/97 Support for Starfire (E10000) and Ultra-30 2.5.1 HW 8/97 Support for the Ultra-450 2.5.1 HW 11/97 Support for Ultra-5, Ultra-10 and Ultra-60 as well as Elite3D 2.6 5.6 3.6 Largefiles, JVM + JIT, Hotjava, X11R6, Web based answerbook, BOOTP/DHCP, SNMP agents, VLSM, in-kernel sockets, XNTP, PAM, CDE 1.2 as default desktop. 2.6 HW 3/98 Support for Ultra-5, Ultra-10, Ultra-60 Elite3d and Starfire (E10K) 2.6 HW 5/98 DR Support for Starfire 7 5.7 3.6.1 64-bit OS support, logging UFS. 7 HW 11/99 Added UDF filesystem, consadm, X11R6.4 server 8 5.8 3.6.2 Dropped support for sun4c and Voyager; added IPv6, IPsec, modular debugger (mdb), high granularity interval timers, consadm, /dev/poll, MAP_ANON, forced unmount, extended memory for Intel, in-kernel mnttab, audio mixer, NFS server logging, Starfire Interdomain networking, Kerberos v5 client support, /proc tools core aware, prstat (like top), perl and other free utilities included, Apache, apptrace (symbolic library call traces), loopback file mounts (lofi), Intel CD boot, Intel large IDE disk support, 8 06/00 8 10/00 Sun Blade 100 & Sun Blade 1000 support. 8 01/01 8 04/01 Sun Fire server support, cdrw | 8 02/02 UltraSPARC III cu (aka UltraSPARC III+), | Sun Blade 2000 | 9 5.9 - Solaris 9; supports all hardware from the | Solaris 8 HW releases. | No Intel release at FCS | OpenWindows applications removed. | 1-1 thread library. | iPlanet directory server | IKE, SSH, secure LDAP client, bundled | encryption, bundled Solaris Logical Volume | Manager (formerly Disksuite), including | support for upgrades of systems with DiskSuite, | Live Upgrade 2.0, Multiple page size support, | Solaris 9 resource manager, IPsec for Ipv6, | bundled tcp wrappers, wu-ftpd based FTP server, | Solaris PPP 4.0 (based on ANU PPP), | Extended File Attributes, DNLC improvements, | UFS snapshots, KDC, Netscape 6.2.1 | X11 -nolisten and IPv6 support, Xnest/Xvfb, | Freeware libraries, RSM, perl 5.6.1, | 9 U1 IPQoS, RIPv2, tunneling over IPv6, Memory | Placement Optimization, DISM, Netscape 6.2.3 | 9 U2 First Solaris 9 Intel release, LX50 Support 1.6) Will my old applications from 4.1.x run on Solaris 2? There is quite a bit of support in SunOS 5.x for running 4.1.x binaries in an emulation mode called "Binary Compatibility" (BCP). This works by dynamically linking the 4.1.x binaries with a shared library that emulates the 4.1.x binary interface on top of 5.x, so there is some overhead. In Solaris 2.2 and earlier, the programs needed to be fully dynamically linked. In Solaris 2.3 and 2.4 fully statically linked programs are supported as well. However, they won't obey nsswitch.conf, but use the standard "use NIS if present, fall back to files" approach of SunOS 4.x. Those programs may therefor require a "passwd: compat" line and will only talk to NIS (or NIS+ in emulation mode) or read from files. Starting Solaris 2.5, mixed mode (partly static/partly dynamic) executables are supported. Whether those programs will use /etc/nsswitch.conf depends on precisely how much was dynamically linked. Be aware, though, that Sun may drop the binary compatibility package some year. Try to wean yourself and your users from depending on it, even if it means beating on your software vendors to offer "native" Solaris2 applications. But this will happen later, rather than sooner. Sun has not yet announced End-of-Life of this feature. |*1.7) Will my SPARC binaries run unchanged on UltraSPARC machines? Yes. One of the most important goals of the UltraSPARC project was *full* binary compatibility with existing SPARC hardware and software. If it isn't compatible, it's a bug! There are some things you should keep in mind though: if you broke the rules but got away with it in the previous generations of SPARC machines, your luck may just have run out. When developing the UltraSPARC it was discovered that some code generators didn't leave all "reserved" bits in opcodes zero. Such instructions are either illegal instructions which are trapped and fixed in the UltraSPARC kernel or they are legal V9 instructions which will modify the program behaviour. All such programs can be run through "cleanv8", a program designed <http://www.sun.com/smcc/solaris-migration/tools/tools.html#sunclnv> to correct the bogus instructions. No instructions of the second category have been found, so even without "cleanv8" you should be safe. Another thing is the memory map on UltraSPARC, some applications use an mmap(MAP_FIXED) call with an address that is illegal to use on UltraSPARC. Such calls are inherently non-portable. Such applications are relatively rare. One such applications is MAE, which should work again after "setenv MAE_NOMMAP_ENGINE". A third problem discovered is in device drivers that copy data from/to userland directly, bypassing copyin(9f)/copyout(9f). On V8 SPARCs, such device drivers would work most of the time, but fail mysteriously with panics when the system is stressed and page mappings disappear; but on the UltraSPARC the drivers will fail always. The kernel will panic and will tell you in which module the panic occurred. | Starting with Solaris 2.6, the Solaris device drivers must be MT-Safe. | Starting with Solaris 7, device drivers must come in a 64 bit variant. | Systems only supported on Solaris 8 and later will not boot a 32 bit | kernel. 1.8) Will my old applications from SVR3 on the 386 run on Solaris 2/x86? As with SPARC, there is an emulation mode that should run the majority of well-behaved SVR3 (iBCS) binaries. Most SVR3 stuff appears to work under Solaris 2.4. Applications from any other vendor's standards-conforming 386/486 SVR4 should also run. However, some vendors have made incompatible changes to their SVR4 release and programs linked on those versions may not work. Future versions of Solaris 2.x for Intel will address some/most of those incompatibilities. Unixware is one of the offenders. 1.9) Where has the XXX command gone now? There are too many of these changes to include in this FAQ, but here are some key ones: a. locations are often different whoami /usr/ucb/whoami make /usr/ccs/bin/make hostid /usr/ucb/hostid hostname /usr/ucb/hostname (or use uname -n) Note that the last two commands are back in /usr/bin in Solaris 2.5. b. some old commands don't exist or have replacements pstat -s swap -s (how much swap space?) dkinfo /usr/sbin/prtvtoc raw_dev_name trace truss mount -a mountall exportfs share bar cpio -H bar (read only) This information can be found in the Solaris 2.x Transition Guide - Appendix A (commands), Appendix B (system calls), Appendix C (files). This guide has undergone some changes from 2.0 -> 2.1 and beyond. Several manuals have ended up being combined into this single manual. This manual discusses administrative transition and developer transition issues. The command "whatnow" (for Solaris 2.x) is included in the "Admigration Toolkit" package (see below). The Admigration toolkit can be obtained from: Admigration toolkit <http://www.sun.com/smcc/solaris-migration/> Sample output: % whatnow hostname hostname 4.x command only hostname /usr/ucb/hostname part of SCP package hostname /usr/bin/uname -n alternate command The whatnow command is limited in that it may point to one command which may only implement a subset of the old command (e.g., pstat points to sar, while pstat -s is identical to swap -s) 1.10) When I upgrade, should I use SunInstall "upgrade", or start over? You can't do a SunInstall "upgrade" from 4.1.x to Solaris2. You can use the Admigration toolkit (q.v.) to help you move from SunOS 4.1.x (Solaris 1, actually) to Solaris 2. If you're moving from Solaris 2.x to 2.(x+y) [for small values of y] then you can use "upgrade" to preserve your existing partitions and local changes (including pkgadd!!), though it runs very slowly (about 1.5-2x the time for a reinstall) and does require that you have enough free space in / and /usr - make these big when you first install! If you run out of space in one of your partitions, you can always remove some components. Those will not be upgraded and can be installed elsewhere after initial upgrade (e.g., you can remove OW, Xil, Dxlib, manual pages, etc) There is no need to backout patches before upgrading. In 2.2, the system would back them out for you, in 2.3 it won't back out the patches but removes them without a trace. An upgrade may not work as well as a full install. E.g., the upgrade from 2.x (x<3) to 2.3 will leave aliases for all your ptys in /devices/pseudo. There's no need to upgrade to all intermediate releases. You can go from Solaris 2.5 to Solaris 7 in one step. But be careful in checking release notes, each release typically only supports upgrades from a few earlier releases and not all. When you upgrade a system, you must make sure that you read the release notes completely. Often, you'll need to upgrade to new versions of Veritas, DiskSuite, etc. 1.11) Is Solaris 2.x reliable/stable enough to use? The consensus seems to be that yes, it is. Binary compatibility was much improved in 2.3. That will help transition somewhat. The performance of 2.3 is adequate, though some parts of the system are still slower than SunOS 4.1.x. Solaris 2.3 is much more stable on MP machines than 2.2. The Solaris 2.3 version of OpenWindows is much faster and much more stable than the versions shipped with SunOS 4.1.x. Solaris 2.1 and earlier should really be avoided. Solaris 2.2 should be avoided too, but some people need to stick to it until some applications get ported (2.2 is the last release with NeWS). Solaris 2.3 still has some problems on high-end MP systems with large numbers of interactive users. Solaris 2.4 and Solaris 2.5 have delivered increasingly more stable and more scalable multi processing. 1.12) Why do some people dislike Solaris2? There is a number of reasons why people dislike Solaris. 1) Change. In general people dislike change. Change requires re-learning and retraining. Old system administration practices no longer work. Commands have been replaced by other commands, some commands behave differently. And they ask why the change was necessary. SunOS 4.x worked for them. 2) Lack of migration support. Sun did not provide a lot of tools to ease migration. Many applications wouldn't run in the binary compatibility mode. The source compatibility mode was probably compatible with some OS, but it certainly wasn't SunOS. Lots of public domain and third party stuff that was needed wasn't immediately available for Solaris. NIS+, buggy, resource hungry and unstable replaced NIS in incompatible ways. 3) Missing functionality. When people migrate, at first they don't tend to notice new functionality. Instead, they stumble upon missing functionality such as screenblank, clear_colormap | and the like (but see 3.24). And perhaps worst of all, no C compiler, not even a crippled one. 4) Slow and buggy. The initial Solaris releases didn't perform at all well and were extremely unstable. This has improved drastically, with Solaris 2.5 being stable and quick, even without many patches. 1.13) Why do some people *like* Solaris2? There are improvements in Solaris 2.x. 1) OpenWindows 3.3+ (in Solaris 2.3+). Includes X11R5 and Display PostScript. X11R6 in Solaris 2.6, X11R6.4 from Solaris 7 HW 11/99 onward. 2) Motif & CDE. 3) ANSI-C and POSIX development environment. 4) POSIX threads (2.5) 5) POSIX and X/OPEN command environment 6) UNIX 95 conformance. 7) UNIX 98 conformance (Solaris 7) 8) Posix shared memory and semaphores (2.6) 9) Multi-threaded kernel and real threads. 10) Real-time feature in the kernel 11) Faster clock ticks (optionally 1000Hz in 2.6) 12) Large files (2.6) 13) True multi-processing. 14) Goodies: vold, admintool and Wabi. 15) Easy patch installation/administration through installpatch/patchadd. 16) All software in easy to manage "packages". 17) Power management software & suspend/resume 18) Access control lists 19) NFS Version 3 and NFS over TCP (Solaris 2.5+). 20) A better automounter, autofs (no more /tmp_mnt and symlinks). 21) Jumpstart/autoinstall - hand off installation of clients. 22) Much better MP support. 23) Faster networking (ATM, fastethernet). 24) 64 bit OS (Solaris 7) 25) IPv6 (Solaris 8) 26) IPsec (Solaris 8) 27) Kerberos 5 client support (Solaris 8) 1.14) What is Sun doing to help me migrate? Sun has recently started several projects to aid in the transition. Their WWW starting point is: Solaris Migration Initiative home page <http://www.sun.com/smcc/solaris-migration/> The project is a combination of new and existing efforts and includes: 1) Porting PD software to Solaris 2.x 2) Solaris Migration Tool: (formerly known as Pipeline tool) a tool to help you port your code. 3) Admigration Toolset. Tools to help you convert your SunOS 4 environment and to help you adjust to the new Solaris 2.x environment. 4) Appmap: a tool to simplify application administration in a mixed SunOS 4.x/Solaris 2.x environment 5) Solaris Transition CD 6) Native Solaris NIS 7) LP tools (simplified LP administration through NIS) 1.15) Can I use my SunOS 4 disks on Solaris 2.x? Yes you can. The on disk format in Solaris 2.x isn't different from SunOS 4.1.x, as long as they've been formatted under SunOS 4.1.x. Disks formatted on older fses need to be converted with "fsck -c". If "dumpfs | head" (SunOS 4) or "fstyp -v | head" (Solaris 2) lists "format dynamic" as one of the first lines, the disk does not need to be converted. UIDs > 60002 may give problems when moving disks from SunOS 4.x to Solaris 2.x. This is fixed in a Solaris 2.5.1 which has MAXUID defined as 2147483648. Note too that UID and GID 60001 and 60002 have been defined as nobody and noaccess on Solaris 2.x. If the target SunOS 4 system uses such IDs, you need to renumber them to avoid the collision Moving disks the other way around may give problems: Solaris 2.5 supports on disks ACLs, and when MAXUID in 2.5.1 is increased beyond 65535, that will give added difficulties. 1.16) How can I enable System V IPC? Ipcs says it isn't configured in. There's nothing you need to do to enable System V IPC, but on boot up "ipcs" always says: IPC status from <running system> as of <date> Message Queue facility not in system. Shared Memory facility not in system. Semaphore facility not in system. This just means that no one has yet used the Message Queue/Shared Memory or Semaphore facility yet. They'll be loaded on first use. If you really want to have them loaded at boot time, add the following to /etc/system: forceload: sys/msgsys forceload: sys/semsys forceload: sys/shmsys In Solaris 7, ipcs will report the unloaded facilities as inactive rather than "not present in system". 1.17) Solaris 7 is 64 bit, does that affect Solaris/IA-32? No, Solaris 7 on Intel is still 32 bit; the only visible changes are that all types are now compile environment safe. *1.18) Solaris 7 is 64 bit, does this mean I can no longer use my old SPARCs? No, a 32 bit kernel is still supported on sun4c, sun4m, sun4d and even sun4u hardware using UltraSPARC I, II or IIi processors. The 32 bit kernel is not supported on systems with UltraSPARC IIe and | UltraSPARC III processors or newer (basically, all SPARC hardware that | is only supported by Solaris 8 or later) 1.19) Where can I download Solaris binaries from? The latest Solaris binary release can be physically ordered or download loaded from www.sun.com. <http://www.sun.com/software/solaris/binaries/get.html> |1.20) What Solaris release am I running on my system? Which Solaris release you are running on your system can be determined using the following command: cat /etc/release This will tell you which release you are running and when it was released. The more recent your system, the more info is contained in this file. 2. SOURCES OF INFORMATION 2.1) How can I RTFM when I don't have it anymore? "RTFM" is an old saying: Read The "Fine" Manual. Sun still sells printed manuals, but doesn't automatically distribute them. As with all real UNIX systems, you do get a full set of online "man" pages. A smaller, lighter, bookshelf-friendly :-) set of CDROMs called "The AnswerBook"(tm) contains all the printed documents in machine-readable (PostScript) form, with hypertext capabilities and a keyword search engine. 90% of your introductory questions are answered therein! In Solaris 2.x the Answerbook set gets increasingly more divided into pieces. It is currently split over a number of CDs, currently (2.5.1): Solaris 2.x CD: Solaris 2.x User AnswerBook Solaris Desktop 1.x Wabi 2.x Answerbook Solaris Common Desktop Environment AnswerBook 1.0.x Updates for Solaris Operating Environment 2.x Solaris 2.x on Sun Hardware Answerbook Server Supplement NSKit 1.2 answerbook Solaris 2.x System Administrator AnswerBook (Solaris 2.5.1 Supplemental System Admin AnswerBook) Solaris 2.x Reference Manual AnswerBook Solstice AutoClient & AdminSuite Solstice AutoClient 2.0 AnswerBook Solstice AdminSuite 2.2 AnswerBook Solstice Online Disksuite DiskSuite 4.0 AnswerBook Solstice Backup Solstice Backup 4.2 AnswerBook Solaris 2.x Software Developer Kit All programming manuals. Solaris 2.x Driver Developer Kit Device driver developer manuals. Only the first two CDs ship with the desktop edition, the third is SPARC specific. The last two CDs are part of two separate products; the SDK and DDK. The rest is server only, though the reference manuals are available in nroff source form. There is some overlap between CDs. As distributed with 2.1 and 2.2, the Answerbook search engine runs only with the OpenWindows ("xnews") server, not with MIT X11. In Solaris 2.3 through 2.5.1 answerbook uses X extension DPS. If you are using the MIT server instead of what Sun provides, you'll have to use one of several "answerbook workaround" scripts that are in circulation. The AnswerBook distributed with 2.3 and later runs with the OW3.3 X11R5+DPS server, so it should display on any X11+DPS server, such as on DEC, IBM and SGI workstations. In Solaris 2.6, answerbooks are distributed in SGML format; they are presented through a special web server which is also able to convert old Postscript answerbooks to HTML on the fly. Sun has a site on the web that has many of the answerbooks <http://docs.sun.com> available. Following a link at that site, you can order hardcopy from fatbrain.com or download PDF books for printing or viewing. You should buy (or print from within Answerbook) at least the reference manual and the System and Network Administration books, because if your system becomes disabled you won't be able to run the Answerbook to find out how to fix it... 2.2) Why is "man -k" so confused? Solaris man uses a manual page index file called "windex" in place of the old "whatis" file. You can build this index with catman -w -M <man-page-directory> But, in 2.1, this will result in numerous "line too long" messages and a bogus windex file in /usr/share/man, and a core dump in /usr/openwin/man. (In 2.2, catman works in /usr/share/man, but says "line too long" in /usr/openwin/man). To add injury to insult, "man" normally won't show you a man page if it can't find the windex entry, even though the man page exists. Makewhatis, or better, getNAME, still can't deal with all manual pages from the net. Solaris 8 man will look for the manual page the hard way if it cannot find it in an existing "windex" file. Starting with Solaris 7 manual pages are being converted to SGML format; the formatting is now a lot slower as there's an extra sgml2roff step in between. But wait, there's more! To see the read(2) man page, you can't just type "man 2 read" anymore - it has to be "man -s 2 read". Or, alias man to this little script: #!/bin/sh if [ $# -gt 1 -a "$1" -gt "0" ]; then /bin/man -F -s $* else /bin/man -F $* fi |*2.3) What Software is available for Solaris 2.x? Most commercial software that ran on 4.x either will run in BCP mode, or is available for Solaris 2.x, or is being ported now. Solaris 2.3 BCP mode finally supports statically-linked executables. Solaris 2.5 BCP mode supports mixed mode (part static, part dynamic) executables too. Sun's web pages contain a searchable index <http://catalyst.sun.com/> of commercial software and a link to an outside contractor <http://www.sunfreeware.com> who gathers free and public domain programs. Sun's own software is | also prominently featured at www.sun.com and also provides the freeware companion. A list of freeware (some "public domain", but mostly copyright- but-freely-distributable) [as well as commercial software??] that has been ported to Solaris 2.x is posted monthly to the newsgroup comp.unix.solaris by ric@coronacorp.com (Richard Steinberger). Look for this: Subject: Solaris SW list. Monthly Post. <ftp://sheffield.isl.sri.com/pub/solaris/solaris-sw-list.txt> Some software that invariably needs minor tweaking after an OS upgrade is included here specially. It's almost always necessary to recompile it after an OS upgrade, but if that still doesn't give a working version, make sure you check the archives for the latest version: SymbEL/SE performance monitor <http://www.sun.com/sun-on-net/performance/se3/> Top - a process monitor <ftp://eecs.nwu.edu/pub/top/> Site carrying the latest version of Top <ftp://ftp.groupsys.com/pub/top/> Lsof - list open files <ftp://vic.cc.purdue.edu/pub/tools/unix/lsof/> Identd - a daemon that implements RFC1413 <ftp://ftp.lysator.liu.se/pub/ident/servers/> scsiinfo - a program that lists SCSI devices. <ftp://ftp.cdf.toronto.edu/pub/scsiinfo/> sysinfo - a system hardware information program. <http://www.magnicomp.com/sysinfo/> If you use gcc (versions prior to 2.8 or versions build on Solaris 2.4 and earlier), it is important to remember that you must re-run fixincludes or re-install gcc after an OS upgrade, or you'll be compiling with the old include files which will essentially give you the above programs as if compiled for a previous OS release. 2.4) What FTP/WWW sites do I need to know about? www.sun.com <http://www.sun.com/> Sun's own WWW site, contains pointers to Sunsites, patches and has lots of info, press releases etc, etc. www.sun.com/downloads/ <http://www.sun.com/downloads/> Solaris software catalogue, pointers to free software, downloadable software from Sun, etc, etc. Solaris transition home page <http://www.sun.com/smcc/solaris-migration/> Sun's Solaris 2.x migration support | Sun supplied Solaris freeware | <http://www.sun.com/software/solaris/freeware> Solaris 2.x binaries <http://www.sunfreeware.com> The Unofficial Guide to Solaris <http://sun.icsnet.com> Solaris 2.x/SPARC binaries in pkgadd format <http://sunsite.unc.edu/pub/packages/solaris/sparc/> Solaris 2.x/x86 binaries in pkgadd format <http://sunsite.unc.edu/pub/packages/solaris/i86pc/> SunSites - Sun sponsored sites. Lots of good stuff there. <http://www.sun.com/sunsite/> Sun SITE AskERIC at Syracuse University - Syracuse <http://ericir.sunsite.syr.edu/> Sun SITE Australia at Australian National University - Canberra <http://sunsite.anu.edu.au/> Sun SITE Central Europe at RWTH-Aachen - Germany <http://sunsite.informatik.rwth-aachen.de/> Sun SITE Chile at Universidad de Chile - Santiago <http://sunsite.dcc.uchile.cl/> Sun SITE Czech Republic at Charles University - Prague <http://sunsite.mff.cuni.cz/> Sun SITE Denmark at Aalborg University - Aalborg <http://sunsite.auc.dk/> Sun SITE Digital Library at University of California at Berkeley <http://sunsite.berkeley.edu/> Sun SITE France at Conservatoire National des Arts-et-Metiers - Paris <http://sunsite.cnam.fr/index.html> Sun SITE Hong Kong at University of Science and Tech. - Hong Kong <http://sunsite.ust.hk/> Sun SITE Hungary at Lajos Kossuth University, Debrecen - Hungary <http://sunsite.math.klte.hu/> Sun SITE Italy at University of Milan - Milan <http://sunsite.dsi.unimi.it/index.html> Sun SITE Israel at Hebrew University of Jerusalem - Jerusalem <http://sunsite.huji.ac.il/sunsite.html> Sun SITE Japan at Science University - Tokyo <http://sunsite.sut.ac.jp/> Sun SITE Korea at Seoul National University - Seoul <http://sunsite.snu.ac.kr/> Sun SITE Mexico at Universidad Nacional Autonoma de Mexico - Mexico <http://sunsite.unam.mx/> Sun SITE Nordic at Kungliga Tekniska Högskolan - Stockholm <http://sunsite.kth.se/> Sun SITE Northern Europe at Imperial College - London <http://sunsite.doc.ic.ac.uk/> Sun SITE People's Republic of China at Tsinghua University - Beijing <http://sunsite.net.edu.cn/> Sun SITE Poland at Warsaw University - Warsaw <http://sunsite.icm.edu.pl/> Sun SITE Russia at Moscow State University - Moscow <http://sunsite.cs.msu.su/> Sun SITE Thailand at Assumption University - Bangkok <http://sunsite.au.ac.th/> Sun SITE Spain at Consejo Superior de Investigaciones Cientificas, RedIRIS - Madrid <http://sunsite.rediris.es/index.html> Sun SITE Singapore at National University of Singapore - Singapore <http://sunsite.nus.sg/> Sun SITE South Africa at University of the Witwatersrand - Johannesburg <http://sunsite.wits.ac.za/> Sun SITE USA at University of North Carolina - Chapel Hill <http://sunsite.unc.edu/> Solaris at UMBC - Solaris tips & tricks by Vijay Gill <http://umbc8.umbc.edu/~vijay/solaris/solaris.html> ftp.x.org - the master X11 site ftp://ftp.quintus.com/pub/ - GNU binaries ftp.uu.net - UuNet communication archives (mirrors abovementioned GNU binaries in systems/gnu/solaris2.3) <ftp://ftp.uu.net/systems/gnu/solaris2.3> OpCom. (opcom.sun.ca) - run by Sun Microsystems' OpCom group - lots of stuff. Here is some of the stuff that's online: pub/AMToolkit.* - the Administration Migration (4.1.x to Solaris 2) Toolkit pub/binaries - binaries/man pages for Solaris 2.0 native binaries. pub/newsletter - issues of the monthly OpCom newsletter. pub/docs - assorted documentation, papers, and other information. - all of the RFCs pub/drivers - information related to device driver writing under under Solaris 2.0 as well as a skeleton SCSI driver. ls-lR.Z - compressed recursive listing of files available on the server. pub/tars - compressed tars. pub/tmp - place for uploading things to the server. pub/R5 - the unadultered MIT x11r5 distribution. pub/x11r5 - port of X11r5 to Solaris 2.0, binaries, libraries and headers. A compressed tar of this tree can be found in tars. prep.ai.mit.edu and the GNU mirrors Joe Shamblin's x86 site at Duke <ftp://x86.cs.duke.edu/pub/solaris-x86/bins/> server.berkeley.edu:/pub/x86solaris - x86 stuff | ftp.science.uva.nl pub/solaris - where the Solaris FAQ is kept, including an html version. pub/solaris/auto-install - fully automated auto-install scripts, including an explanation of exactly what a machine needs when booting the installation, automated patch installation and even post-install updates from your install tree, which gives you an easy way to keep all your Solaris machines in sync. 2.5) What other FAQ's do I need to know about? 1) Stokely Consulting's list of Sun FAQs <http://www.stokely.com/unix.sysadm.resources/faqs.s.html#faq.link.sun> 2) The Solaris for Intel FAQ <http://dan.carlsbad.ca.us/faqs/s86faq.html> 3) Obsolete, SunOS 4.x only: Sun Computer Administration Frequently Asked Questions <http://aurora.latech.edu:80/sunadminfaq.html> 4) The "Solaris 2 Porting FAQ" <http://www.cis.ohio-state.edu/hypertext/faq/usenet/Solaris2/porting-FAQ/faq.html> 5) comp.windows.open-look - Anything related to OpenWindows or the OPEN LOOK Graphical User Interface. 6) The Sun-Managers mailing list FAQ <ftp://ftp.cs.toronto.edu/pub/jdd/sun-managers/faq> maintained by John DiMarco <jdd@cdf.toronto.edu>. 7) See also the "Solaris SW list. Monthly Post" above and the "whatlist" file. 2.6) What mailing lists should I get? First, read all the USENET newsgroups with "sun" in their name :-) 1) The Florida SunFlash is a "closed" mailing list for Sun owners. It contains mostly press releases from Sun and third-party vendors. This list contains information on conferences such as the Solaris Developer's Conference as well. It is normally distributed regionally - to find out about a mail point in your area, or for other information send mail to info-sunflash@Sun.COM. Subscription requests should be sent to sunflash-request@Sun.COM. Archives are on solar.nova.edu, ftp.uu.net, sunsite.unc.edu, src.doc.ic.ac.uk and ftp.adelaide.edu.au 2) The Sun Managers list is an unmoderated mailing list for *emergency-only* requests. Subscribe and listen for a while, and read the regularly-posted Policy statement BEFORE sending mail to it, and to get a feel for what kinds of traffic it carries. Send a message with "subscribe sun-managers" in the body to majordomo@sunmanagers.ececs.uc.edu to subscribe. 3) The solaris x86 list. Subscribe/unsubscribe by sending a message with subscribe/unsubscribe in the *BODY* of the message to solaris-x86-request@mlist.eis.com. A digested version of the list is also available. To subscribe send an email message to solaris-x86-digest-request@mlist.eis.com. There's also an archive of this list. <http://www.eis.com/html/listmain.html> 4) The Sun Security Bulletin announcement mailing list. Low volume, announcement only list. Subscribe by mailing security-alert@sun.com with subject "SUBSCRIBE cws user@some.host" 2.7) What books should I read? O'Reilly & Associates specializes in UNIX books. Their "UNIX <http://www.ora.com> In A Nutshell" has been updated for SVR4 and Solaris 2.0. Get their catalog by calling 800-998-9938 (1-707-829-0515) 7AM to 5PM PST. SunSoft Press carries books specific to Solaris 2. Look for the inset with your End User Media Kit that lists the most relevant ones. Prentice-Hall has reprints of much of the AT&T documentation. I'm not sure how much of this you need - a lot of the same material is in the Answerbook (see above). 2.8) What hardware is supported by Solaris 2.x for Intel? The complete list Solaris x86 hardware options can be found on the Solaris Developer Connection site. <http://soldc.sun.com/support/drivers/hcl/> 2.9) What is Wabi? | Wabi was Sun's MS-Windows-under-unix emulator. The Wabi faqs can be obtained by sending an empty message to: wabi-questions@East.Sun.com The list of current Wabi apps can be obtained by mailing: wabi-apps@East.Sun.COM Applications that execute a lot of x86 code, run fastest on Solaris 2.x_86, as no x86 emulation needs to be done. Applications that are more windows intensive will run better on machines with faster graphics hardware. The currently shipping version of Wabi is Wabi 2.2, which ships with Solaris 2.5.1. Wabi only supports MS Windows 3.1 applications. Plans to support Windows 95 have been shelved. Wabi is no longer supported under Solaris 7 Wabi will not be made available for SunOS 4.1.x. Reports indicate that Wabi support will be dropped by Sun and replaced by some other PC on Sun product. |*2.10) I'm running into some limits of SunOS 4.x, will upgrading to Solaris 2.x help? The answer depends on the limit you run into. Solaris 2.x supports filesystems upto 1TB, SunOS 4.x requires ODS 1.0 to support filesystems over 2GB. Solaris 2.6 and later support files > 2GB. Swap partitions and files are still limited to 2GB a piece as long as you run a 32 bit kernel, but you can have multiple 2GB swap partitions/files. Solaris 2.x supports a virtually unlimited number of open filedescriptors, SunOS 4.x only supports 256 (default) or 1024 (with Sun DBE 1.x). Solaris 2.x supports an unlimited number of pseudo terminals. SunOS 4.x supports at most 256. Solaris 2.x supports more SCSI disks. Solaris 2.x limits can be tuned in /etc/system, requiring just a reboot. SunOS 4.x limits need to be tweaked in the config file and a new kernel needs to be built and installed. Solaris 7 and later in 64 bit mode support > 4GB of address space per processes. 64 bit processes in Solaris 7 and later can open more than 256 files using stdio. | Solaris 9 LVM supports logical slices, allowing more than 7 usable | slices/partitions per disk. NOTE: when the above says "unlimited", it just means that there is no "hard" limit, but performance may degrade over certain values. E.g., setting the number of available fds very high, will cause programs that loop closing all fds to be very slow in starting. 3. SYSTEM ADMINISTRATION 3.1) How much disk space do I need to install Solaris 2? The FAQ maintainer's preference is for a merged root, /usr and /opt, especially on smaller systems. But here's a table of sizes for multiple partitionings. Solaris 2.5.1 with root and usr only. Install type root /usr ------------ ---- ---- Core 15 21 EndUser 28 99 Developer 30 192 Entire 72 217 Solaris 2.6 with root and usr only. Install type root /usr ------------ ---- ---- Core 21 25 EndUser 33 181 Developer 38 398 Entire 44 448 Solaris 2.6 with root, var, opt and usr. Install type root /var /opt /usr ------------ ---- ---- ---- ---- Core 21 3 1 25 EndUser 22 6 9 181 Developer 22 9 9 398 Entire 23 10 13 448 The following table is based on teaching and system administration experience. Solaris 2.6 Recommended minimum partition sizes, real world. Install type root /var* /opt** /usr*** ------------ ---- ---- ---- ---- Core 50 150 200 200 EndUser 50 150 200 300 Developer 50 150 200 500 Entire 50 150 200 600 Notes: (*) Even on the smallest systems, it is recommended to leave a great deal of room on /var. This will allow for the limited use of print client spooling, cron, uucp, auditing and growth for the pkgadd database. Setting up as a mail, news, NIS, NIS+ or print server requires substantial additional room on /var. (**) /opt holds all non-OS application software. Sizing is total of all current application software plus size of known future application software plus 20-30%. (***) /usr should be relatively unchanging, except on a developer system. Still, to make it too small will require later balancing acts, therefore the numbers reflect approximately 150MB of extra space. 3.2) How can I convert all my local changes that I've made over the years into their corresponding forms on Solaris 2? 1) Do it by hand. You did document every single change and check it into RCS, didn't you? 2) Automate it, using the AMToolkit (Administration Migration Toolkit) from the OpCom FTP server (q.v.)! 3.3) What are "packages"? A SVR4 mechanism for "standardizing" the installation of optional software. Most vendors are expected to use this format for distributing add-on software for Solaris 2.x. Packages can be installed/deinstalled with pkgadd/pkgrm which are standard SVR4 items, or with swm (CRT) or swmtool (GUI-based) which are provided only in Solaris 2. Note that the "pkg" system keeps lots of files in /var/sadm/install, and in particular the file "contents", which is hundreds of KB, and that there are two copies of it while pkgadd is running, so you needs lots of free space where /var is, typically the root. This file must be kept around if you want, for example, to use pkgrm to remove a package, or pkgchk to verify months later that all of a a package's files are still intact. Summary of pkg* commands: pkginfo <pkg> - test for presence of package. pkgadd -d /<cdrom>/Solaris_2.3 <pkg ...> - add missing packages pkgrm <pkg ...> - remove packages. pkgchk -q <pkg> - test for existence of package pkgchk <options> [pkg] - check installed packages for integrity. 3.4) Why can't I write in/mount over /home? SunOS 5.x is delivered with the "automounter" enabled. The automounter is designed for NFS sites, to simplify maintenance of the list of filesystems that need mounting. However it is a burden for standalone sites. The automounter takes over /home and in effect becomes the NFS server for it, so it no longer behaves like a normal directory. This is normally a Good Thing as it simplifies administration if everybody's home directory is /home/<username>, regardless of their physical location. If you want to continue to use the automounter, edit /etc/auto_master and comment out the line starting with "/home". Then run the "automount" command which will cause automountd to reload the maps. To kill it off for standalone or small networks running Solaris 2.3 or later, you can stop automountd by running "/etc/init.d/autofs stop". Prevent it from starting at boot time by renaming the file /etc/rc2.d/SXXautofs to /etc/rc2.d/sXXautofs, where XX are two digits depending on the OS release. (If you change your mind, just rename it back) In Solaris 2.2, the procedure is different. You need to comment out the three lines in /etc/init.d/nfs.client that start "if" (from the if to the fi!!), and reboot (Solaris 2.2) To learn about it, read the O'Reilly book "Managing NFS and NIS", or ftp the white paper 'The Art of Automounting". from sunsite.unc.edu in the directory /pub/sun-info/white-papers. 3.5) Why can't I access CDs or floppies? Solaris 2.2 introduced a new scheme for automatically mounting removable media. It consists of a program "vold" (volume daemon) which sits around watching for insertions of floppies and CD's, handles ejects, talks to the file manager, and invokes a second program called "rmmount" (removable media mounter) to mount the disk. Note that on most SPARCstations, you must run "volcheck" whenever you insert a floppy, as the floppy hardware doesn't tell SunOS that a floppy was inserted and polling the drive would wear it out pretty quickly. Advantages of this scheme: - no longer need root; users can mount and unmount at will. - can do neat tricks like automagically start "workman" or other Audio CD player when audio CD inserted. - extensible - developers can write their own actions. Drawbacks: - can no longer access /dev/rfd0 to get at floppy; must use longer name like /vol/dev/rdsk/floppy0 - similarly, CD's get mounted on /cdrom/VOLNAME/SLICE, e.g., /cdrom/solaris_2_2/s0 is slice 0 of the Solaris 2 CD (nice that it does mount all the partitions, though!). To read or write a non-filesystem floppy (tar, cpio, etc), put in the diskette and run "volcheck" from the commandline or click "Check for Floppy" in the filemgr to get it noticed; then access /vol/dev/rfd0/unlabeled (e.g. "tar tvf /vol/dev/rfd0/unlabeled"). [Solaris 2.3 and later: /vol/dev/rdiskette0/unlabeled, or /vol/dev/aliases/floppy0.] If you want the old behavior, remove the /etc/rc2.d/S*volmgt link, and reboot. 3.6) Why are there no passwords in /etc/passwd? System V Release 4 includes a feature called "shadow passwords". The encrypted passwords are moved out into a shadow password file (called /etc/shadow in this release) that is NOT publicly readable. The passwd file has always been readable so that, for example, ls -l could figure out who owns what. But having the passwd encryptions readable is a security risk (they can't be decrypted but the bad guy can encrypt common words and names etc. and compare them with the encryptions). The Shadow Password feature is mostly transparent, but if you do any passwd hacking you have to know about it! And DO make sure that /etc/shadow is not publicly readable! 3.7) Why can't I rlogin/telnet in as root? >... when I try to rlogin as root ... >it gives me the message "Not on system console >Connection closed.". What have I left out? Solaris 2 comes out of the box a heck of a lot more secure than Solaris 1. There is no '+' in the hosts.equiv. root logins are not allowed anywhere except the console. All accounts require passwords. In order to allow root logins over the net, you need to edit the /etc/default/login file and comment out or otherwise change the CONSOLE= line. This file's CONSOLE entry can actually be used in a variety of ways: 1) CONSOLE=/dev/console (default) - direct root logins only on console 2) CONSOLE=/dev/ttya - direct root logins only on /dev/ttya 3) CONSOLE= - direct root logins disallowed everywhere 4) #CONSOLE (or delete the line) - root logins allowed everywhere /etc/hosts.equiv is still supported, but there is no default. 3.8) How can I have a user without a password? In addition to removing the password from /etc/shadow, you need to take one of the following steps: Edit /etc/default/login and comment out PASSREQ=YES or change it to PASSREQ=NO. This allows *all* users to remove their password! The second way is to give a particular user no password with the following entry in /etc/shadow: user::9092:9999:9999:::: |+3.9) How can I have a "su-only" user? | Starting with Solaris 8, the RBAC facility allows for users | which cannot log in but which can be su'ed to. These user | accounts are known as "roles". See user_attr(4) and rbac(5) |*3.10) How can I set up anonymous FTP? If you need help, ftp the file "ftp.anon" from ftp://ftp.math.fsu.edu/pub/solaris/ftp.anon. ftpd(1M) is nearly complete when it comes to setting up anonymous ftp. It only leaves out /etc/nsswitch.conf. [S2.3] Additionally, you must make sure that the filesystem ~ftp resides on is not mounted with the nosuid option. This is because the nosuid option also disables the kernel honoring device files which are required in the chroot environment for ~ftp. For security reasons, it is important that no files under ~ftp are owned by ftp. If they are, anonymous users can modify them. In Solaris 2.5 and later, you will need to copy /usr/lib/libmp.so.* as well as provide a /dev/ticlts (for wu-ftpd). | Solaris 9 comes with a new FTP server derived from wu-ftpd; it | is much more configurable. |3.11) How can I print from a Solaris 2 (or any System V Release 4) system to a SunOS4.x (or any other BSD) system? The easiest way would be using the GUI-based Admintool which has a Printer Manager that is supposed to be able to do all this and more. Hmmm, the lp system is totally different than what you're used to. The System V Line Printer System is a lot more, well, flexible. A cynic might say "complicated". Here's a very quick guide -- see the man pages for each of these commands for the details. Let's say your Solaris2 workstation is called "sol" and the 4.1.x server is called "bertha" and you want the printer name to be "printer" (imaginative, eh?). sol# lpsystem -t bsd bertha # says bertha is a bsd system sol# lpadmin -p printer -s bertha -T unknown -I any # creates "printer" on "sol" # to be printed on "bertha" # The following two commands are no longer needed in 2.6 and later: sol# accept printer # allow queuing sol# enable printer # allow printing sol# lpstat -t # check the status Finally, if that's your only printer, make it the default: sol# lpadmin -d printer On some systems you may have to turn on the port monitor. |3.12) How can I print to a non-Postscript/non-ascii printer? The cheapest way to do this is using a printer setup based on Ghostscript. <http://www.cs.wisc.edu/~ghost/index.html> When installing Ghostscript, make sure that it supports your printer *and* make sure that you include support for your specific printer in Ghostscript. Then go to "Setting up a GS printer under Solaris", <http://cfauvcs5.harvard.edu/SetGSprinter4Solaris.html> and follow the instructions there. |3.13) How can I print to a networked printer? Before Solaris 2.6, you either needed special software like JetAdmin or get a printer that supported the BSD print protocol and set your system up as a BSD client. Starting with Solaris 2.6, there's a new lp "model" script, "netstandard". This script allows you to print to remote BSD type printers as well as over raw TCP/IP connections. It's used like this: # Raw TCP lpadmin -p <localname> -m netstandard -o protocol=tcp -o dest=host:port \ -v /dev/null # BSD lpadmin -p <localname> -m netstandard -o protocol=bsd -o dest=host \ -v /dev/null Enable/accept and you're all set. When using netstandard, all filtering is done locally. When configured as a BSD print client, filtering isn't done locally as only print servers should filter jobs. |3.14) Why does lp complain about invalid content types? For better or for worse, you need to know about printer content types. See the man page for "lpadmin". To get transparent mode, try this: sol# lpadmin -I any -p printer |3.15) My jobs stay in the queue after printing. It's a known bug, and looks fixed in 2.5. There's also a number of lpsched patches out for Solaris: 101025-xx (2.2), 101317-xx (2.3), 101959-xx (2.4) and 101960-xx (2.4/x86). Make sure you install those. Regardless of what other patches you apply, if you have a printer connected to your system running Solaris 2.4 or later, and if that printer uses NeWSprint software, you must apply patch 102113-xx. This patch is included on the Solaris CD in 2.4 and later releases. This patch is also required if you are running Solaris 2.3 with kernel jumbo patch 101318-55 or later. Note that this is a NeWSprint patch, not a Solaris patch, and hence it will never be integrated into any Solaris release. "lpstat" on the clients on a regular basis, for some reason this clears the old files from the queue directories. |3.16) Are there any alternatives to the system V spooler? Sun has a new printing product available, "SunSoft Print Client". <http://www.sun.com/smcc/solaris-migration/tools/tools.html#sspc> It is the standard 2.6 print system and co-shipped with 2.5. It has many new features, including printcap-like printer configurations that can be shared via NIS, and currently the ability to be configured so that lpsched does not have to be run anymore on client-only systems (although you still need to run lpsched in order for admintool to work.) Alternatively, you can get a Solaris port of the BSD lpr system from the following FTP site (get lpr-sol2-*.tar.gz): ftp.eng.auburn.edu:/pub/doug or LPRng <http://www.astart.com/LPRng.html> |*3.17) What happened to /dev/MAKEDEV? How do I add devices? Device drivers are linked in dynamically. When you add new devices, just shutdown the system and do boot -r # use drive spec if not default disk to *r*ebuild the /devices and /dev directories. When you're adding a device without rebooting or forgot to do a reconfigure boot, you can run the "configure devices" commands. In Solaris 8 it is as simple as running "devfsadm" without arguments. Older solaris releases don't have "devfsadm" and you need to run a few commands, e.g., if you've just added a SCSI disk, you run the following commands (as the superuser): /usr/sbin/drvconfig /usr/sbin/devlinks /usr/sbin/disks # or /usr/sbin/tapes for tapes /usr/ucb/ucblinks # Compatibility links exit 0 Note that this only works if you already have at least one SCSI disk on the system. (This is because the above just makes symbolic links and things, it does not load up the SCSI driver kernel modules, etc.) | Starting with Solaris 9, the command update_drv(1m) allows you to | reload driver's .conf files without rebooting or unloading the | driver. |3.18) Why isn't my tape/cd player or new disk/device recognized? Devices must be turned on and present when you configure the system. After adding devices you must boot -r with all | the devices turned on. See also 3.17 |3.19) What happened to /etc/rc and /etc/rc.local? They're now fragmented into 12 million tiny little pieces. Look in the following files to get oriented: /etc/inittab - defines which programs init starts and when. /sbin/rcS, /etc/rcS.d/* - booting stuff /sbin/rc2, /etc/rc2.d/*, /sbin/rc3, /etc/rc3.d/* - stuff for multi-user startup. Note that all files in /etc/rc*.d/* are hardlinked from /etc/init.d (with better names), so you should grep in there. There are many "run levels" to the System V init; the run level 3 is normally used for "multi user with networking." When executing the scripts in an /etc/rc?.d directory, the K* scripts are executed first, followed by the S* scripts. Scripts ending in .sh are executed in the same shell and can be used to set environment variables used further on in the same directory. A basic startup script looks like this: #!/bin/sh # Sample init.d script. # Install a copy under /etc/init.d/your-daemon # make links to /etc/rc2.d/Sxxyour-daemon (or rc3.d) # and /etc/rc[01].d/Kxxyour-daemon. # Scripts ending in .sh are executed with the sh "." command. # Scripts not ending in .sh are executed as "sh script" case "$1" in start) #... commands to start daemon .... ;; stop) #... commands to stop daemon .... ;; esac |3.20) Can't I have /etc/rc.local back? No. You can never have rc.local back the way it was. But then, it never really *was* purely a "local" rc file. To have a real "local" rc file with just your changes in it, copy this file into /etc/init.d/rc.local, and ln it to /etc/rc3.d/S99rc.local. Put your startup stuff in the "start" section. #!/sbin/sh # /etc/init.d/rc.local - to be linked into /etc/rc3.d as # S99rc.local -- a place to hang local startup stuff. # started after everything else when going multi-user. # Ian Darwin, Toronto, November, 1992 # As with all system changes, use at own risk! case "$1" in 'start') echo "Starting local services...\c" if [ -f /usr/sbin/mydaemon ]; then /usr/sbin/mydaemon fi echo "" ;; 'stop') echo "$0: Not stopping any services." ;; *) echo "Usage: $0 { start | stop }" ;; esac |3.21) Why are there two versions of shutdown? SVR4 (hence SunOS 5.x) tries to make everybody happy. The traditional (slow) System V "shutdown" runs all the rc0.d/* shell scripts with "stop" as the argument; many of them run ps(!) to look for processes to kill. The UCB "shutdown" tells init to kill all non-single-user processes, which is about two orders of magnitude faster. In old versions of Solaris (2.2 and before) the UCB version did everything it should *except* actually halt or reboot. If you run a database (like Oracle) or INN, you should install a special /etc/rc0.d/K* script and make sure you always shutdown the long way. |3.22) When will somebody publish a package of the BSD (4.3BSD Net2) "init", "getty", and "rc/rc.local", so we can go back to life in the good old days? Getty should be easy and was reportedly done at a number of sites. The port monitor isn't everyones favorite. But given that you can do much more with the SVR4 init, why would you want to change back? It would be much more trouble than it's worth. |3.23) What has happened to getty? What is pmadm and how do you use it? I was hoping you wouldn't ask. PMadm stands for Port Monitor Admin, and it's part of a ridiculously complicated bit of software over-engineering that is destined to make everybody an expert. Best advice for workstations: don't touch it! It works out of the box. For servers, you'll have to read the manual. This should be in admintool in Solaris 2.3 and later. For now, here are some basic instructions from Davy Curry. "Not guaranteed, but they worked for me." To add a terminal to a Solaris system: 1. Do a "pmadm -l" to see what's running. The serial ports on the CPU board are probably already being monitored by "zsmon". PMTAG PMTYPE SVCTAG FLGS ID <PMSPECIFIC> zsmon ttymon ttya u root \ /dev/term/a I - /usr/bin/login - 9600 ldterm,ttcompat ttya \ login: - tvi925 y # 2. If the port you want is not being monitored, you need to create a new port monitor with the command sacadm -a -p PMTAG -t ttymon -c /usr/lib/saf/ttymon -v VERSION where PMTAG is the name of the port monitor, e.g. "zsmon" or "alm1mon", and VERSION is the output of "ttyadm -V". 3. If the port you want is already being monitored, and you want to change something, you need to delete the current instance of the port monitor. To do this, use the command pmadm -r -p PMTAG -s SVCTAG where PMTAG and SVCTAG are as given in the output from "pmadm -l". Note that if the "I" is present in the <PMSPECIFIC> field (as it is above), you need to get rid of it. 4. Now, to create a specific instance of ttymon for a port, issue the command: pmadm -a -p PMTAG -s SVCTAG -i root -fu -v 1 -m \ "`ttyadm -m ldterm,ttcompat -p 'PROMPT' -S YORN -T TERMTYPE \ -d DEVICE -l TTYID -s /usr/bin/login`" Note the assorted quotes; Bourne shell (sh) and Korn (ksh) users leave off the second backslash! In the above: PMTAG is the port monitor name you made with "sacadm", e.g. "zsmon". SVCTAG is the service tag, which can be the name of the port, e.g., "ttya" or "tty21". PROMPT is the prompt you want to print, e.g. "login: ". YORN is "y" to turn software carrier on (you want this for directly connected terminals" and "n" to leave it off (you want this for modems). TERMTYPE is the value you want in $TERM. DEVICE is the name of the device, e.g. "/dev/term/a" or "/dev/term/21". TTYID is the line you want from /etc/ttydefs that sets the baud rate and stuff. I suggest you use one of the "contty" ones for directly connected terminals. 5. To disable ("turn off") a terminal, run pmadm -d -p PMTAG -s SVCTAG To enable ("turn on") a terminal, run pmadm -e -p PMTAG -s SVCTAG Ports are enabled by default when you "create" them as above. For more details, see: Celeste's Tutorial on Solaris 2.x Modems & Terminals <http://www.stokely.com/> |3.24) How do I get the screen to blank when nobody's using it? Under 4.1.x you invoke screenblank in /etc/rc.local, but there's no screenblank in Solaris 2.x. Sun recommends that you have everybody put `xset s on' in their .xinitrc, but this may be hard to police, and in any event it won't work when nobody is logged in. The simplest workaround is to copy /usr/bin/screenblank from 4.1.x and run it in binary compatibility mode. See ``What happened to /etc/rc and /etc/rc.local?'' for how to invoke it. Another possibility is to use xdm or dtlogin. That way the X server will continue to run and the screen will be blanked by it. The 4.1.x screenblank didn't work for us. We use Jef Poskanzer's <http://www.acme.com/software/screenblank/> freeware screenblank. Because of a bug in Solaris 2.3, you'll may have to specify -DHAVE_POLL=0 when compiling this version. Solaris 2.4 comes with power management software for those systems with a soft-switchable power supply. That may suit your needs better than screenblank. In Solaris 2.5 the software can remove the sync signal from your monitor causing newer monitors to go in energy saving standby mode. The Solaris 2.4 version had problems reenabling the monitor or graphics card. The power-management software is on the SMCC Updates CD [2.4 2.5] The power-management software can be used to switch off just the screen, by putting the following in the power.conf file: # Name Threshold(s) Logical Dependent(s) /dev/kbd 600 /dev/mouse 600 /dev/fb 0 0 /dev/kbd /dev/mouse Make sure you mark the "autoshutdown" line with "noshutdown" if you want keep your machine running. The /usr/openwin/bin/dtpower utility can change these settings for you. (Solaris 2.5) |3.25) And what about screendump, screenload and clear_colormap? You can FTP Jef's screenload, screendump, etc., if you need that functionality, and for free you get a pixrect (clone) library. Get one of these: http://www.acme.com/software/raster-pixrect/ ee.lbl.gov:/raster-pixrect_30dec93.tar.Z The 4.1.x versions of these programs will not run under Solaris 2.2 or later. The pixrect BCP library is no longer supported. |3.26) Where did etherfind go? There is a replacement for etherfind, but it has changed name; in fact it's a whole new program. It IS better. To find it, though, you would have to realize that network snooping is not really Ethernet-specific. To end the suspense :-), here it is: % man -k snoop snoop snoop (1m) - capture network packets and inspect them % It works differently - it has an immediate mode, a capture-to-disk mode, and a playback-from-disk mode. Read the man page for details. The capture file format is described in RFC 1761. |3.27) Can I run SunOS 4.1.x on my SPARC Classic, LX, SS5, SS4, SS20, Voyager, SS1000, SC2000, CS6400, Ultra? The Classic, LX and the single processor models of the SS20 are still supported under some version of SunOS 4.1.x. A lot of people wanted these machines but only if they ran SunOS 4.1.x. When the Classic/LX came out, clone manufacturers were able to provide SunOS 4.1.x with it, Sun came out with SunOS 4.1.3C some time later. The Classic, LX, SS4, SS5 and SS20 are supported in the most recent Solaris 1.x release, SunOS 4.1.4 (Solaris 1.1.2). The Classic and LX are supported since 4.1.3C (release for LX & Classic only), the SS20/SS5 since release 4.1.3_U1 rev B (Solaris 1.1.1B). The SS4 and SS20 with HyperSPARC since 4.1.4. Note that none of these OS versions support SuperSPARC MP or any of the new graphics hardware (ZX, TZX, SX, S24). The TCX adapter is only supported as a cgthree, and SunOS 4.x doesn't use all its acceleration features. The Voyager is not supported under SunOS 4.1.x, too many new device drivers have been added plus the suspend resume feature. The XDbus machines SS1000/SC2000 are also not supported under SunOS 4.1.x. Support for their kernel architecture and XDBus is missing in 4.x. The UltraSPARC based machines are not supported under SunOS 4.1.x. The new supervisor mode instructions, the new MMU, buses and devices are not supported under 4.1.x. Sun acquired the Business Systems Division of Cray Research and now supports the Cray CS6400, a 64 SuperSPARC machine that runs a modified version of Solaris 2.x, known as "Cray Solaris". The largest Solaris 2.x machine you can currently buy from Sun is the Sun Enterprise 10000, a machine that supports upto 64 UltraSPARC <http://www.sun.com/datacenter/> cpus, 64 I/O channels and 64 GB of memory at the same time. Fujitsu sells an even larger machine, the AP-3000, <http://www.fujitsu.co.jp/hypertext/Products/Info_process/hpc/ap3000-e/index.html> a system with upto 2048 UltraSPARC cpus @300MHz. |3.28) The "find" program complains that my root directory doesn't exist? Yes! Actually, messages like find : cannot open /: No such file or directory. are due to a bug in the tree walking function (nftw(3)). Fixed in 2.4 and in the 2.3 kernel jumbo patch 101318 (-41 or later) |3.29) I'm having troubles with high-speed input on the Sparc serial ports. What should I do? Try using UUCP. The Solaris 2.x sparc serial driver has trouble receiving data at or above 9600 bps. Symptoms include sluggish response, `NOTICE: zs0: silo overflow' console messages, sending spurious control-Gs to the serial port, and applications that cannot be killed even with `kill -9'. This problem surfaces in many applications, including Kermit and tip. UUCP seems immune, though, because its protocol throttles input sufficiently. People have reported success in later releases of Solaris (2.3+). Solaris 2.5 supports much higher baudrates and hardware flowcontrol in two directions. The latter is also available as a patch for 2.3 (102028) and 2.4 (102845, note that this patch conflicts with patch 102062-08, which should be installed first if at all). The zs device can be set to 38400bps in 2.4 and earlier and 76800 in 2.5 and later. The latest UltraSPARC systems with PCI have a newer serial chip, with the "se" device driver. It can sustain speeds of upto 400k bps. |3.30) How do I make ksh or csh be the login shell for root? Root's shell is /sbin/sh, which is statically linked. Don't just insert a 'c' before "sh" as previously, as that would look for /sbin/csh, which doesn't exist. Don't just change it to /bin/csh, since that's really /usr/bin/csh, which is dynamically linked, because: 1) /usr may not be mounted initially, and then you're in deep (the shared libraries are in /usr!), and 2) There is code in the startup scripts that assumes that everything critical is in /etc/lib, not /usr/lib. Approach with caution! Whenever you change root's shell, make sure you do it using vipw or "passwd -e". Both programs will check for a valid (in the sense of /etc/shells) file. Safer bet - have an alternate root account, like "rootcsh", with uid 0, and /bin/csh as its shell. Put it after root's entry in the passwd file. Only drawback: you now have to remember to change all of root's passwords at the same time. Third bet - in root's .profile, check if /usr is mounted and, if so, exec /bin/ksh or whatever. An even better bet - leave root's shell alone, and use the sudo command for doing things as root. <ftp://ftp.cs.colorado.edu/pub/sysadmin/sudo> |3.31) What is this message: "automount: No network locking on host, contact administrator to install server change."? The other machine (an NFS server) is running 4.1.x and needs a patch from Sun to update its network lock daemon (lockd). If you don't install the patch on the server, file locking will not work on files mounted from "thathost". The lockd jumbo patch fixes a bunch of other lock manager problems, so it may be a Good Thing To Get; however, it may also cause the machine on which the patch is installed to have trouble talking to servers with no patch or older patches, so Be Warned. The lockd patches are: 100988 (4.1.3), 101817 (4.1-4.1.2) 101784 (4.1.3_U1), 102264 (4.1.4) and 100518 (for Online: Disksuite). Make sure you install the latest version of those patches. |3.32) I have all kinds of problems with SCSI disks/RAIDs under Solaris 2.x They worked fine under SunOS 4.x. For a quick fix, append this line to /etc/system and reboot: set scsi_options & ~0x80 This turns off Tagged Command Queuing, a SCSI feature that is improperly implemented in many older drives and can cause problems between Suns and some RAID implementations (for a special note on RAID, see the end of this question) NOTE: this will seriously degrade performance on disks that do properly support tagged command queuing. Setting the SCSI options per broken target is therefor the preferred solution. In Solaris 2.4 and later you can set those options per SCSI bus. See isp(7) and esp(7). For some disks, all you need to do is decrease the maximum number of queued commands: set sd:sd_max_throttle=10 In later Solaris releases you can specify scsi_options per (broken) target or per SCSI bus. See esp(7d), isp(7d), from which this example /kernel/drv/esp.conf file is derived: name="esp" parent="/iommu@f,e0000000/sbus@f,e0001000/espdma@f,400000" reg=0xf,0x800000,0x40 target1-scsi-options=0x58 scsi-options=0x178; Certain hardware RAIDs support a number of different LUNs (logical disks) but share a common set of I/O buffers between them. This can cause SCSI QFULL conditions on devices without any commands queued. Since the algorithm is to retry the command when a previous command is completed, Solaris doesn't handle this situation very well. The workaround is to decrease sd_max_throttle such that there's always at least 1 slot available for each LUN. E.g., if you have 3 LUNs and your RAID supports upto 64 outstanding commands, sd_max_throttle must be at most 31. (Any two LUNs can get 31 requests and you still have two slots over for number 3) Decreasing sd_max_throttle was seen to improve performance due to better load balancing among LUNs on some hardware RAIDs. |3.33) How do I make Solaris2 use my old ADAPTEC ACB-4000 and Emulex MD-21 disk controllers? As with any hardware addition, first try the obvious (boot -r after installing and power-cycling everything). The adaptec is no longer supported; man -s7 sd no longer even lists it! So I guess they go over the cliff. Either that, or take the drives out and put them on a PC, where ST506 MFM drives are still supported. The MD21 should work, though some people report that SCSI doesn't work in 4/260 boxes (bug-id #1118752), but that's fixed in 2.3 and later. |3.34) Should I wait installing the latest Solaris release until there are enough patches? Several things have been done differently during the development of Solaris 2.5 and later. Many internal users run versions of the Solaris release under development no more than one or two weeks old. A number of large customers runs beta releases on production systems, in exchange for virtually unlimited engineering support for those machine. Coupled with some other development policies this has resulted in a release of very high quality that doesn't come with 36 patches on the first release CD, although there are always things found when the release is closed. Patches for older unbundled products are needed for each Solaris release. Recent Solaris releases run most everything without requiring patches. |3.35) Why are there so many patches for Solaris 2.x? Patches are released for three reasons: bug fixes, new hardware support (sometimes also requires new packages) and new features. As releases stay out in the field longer, more bugs are discovered. Many bugs are fixed during the development cycle and are "fixed in the next release". However, for many customers an upgrade is out of the question, so more and more patches get released. In the early Solaris days, patches were often combined into "jumbo" patches. This reduced the number of patches somewhat, but made maintenance more difficult as it would require re-cutting a patch consisting of 50 modules when you fix just one bug in one module. Patches are now only merged if there is a two-way dependency. |*3.36) What are the ``mandatory'' patches I keep hearing about? The mandatory patches weren't mandatory, so they've been relabeled. They're now called ``recommended'' patches. The recommended patches are those patches Sun recommends for trouble free system operation. With those patches installed, your chances on trouble free operation are higher. That doesn't mean you will run into trouble without them. These recommended patches can be anonymously ftp'ed from | official Sun ftp sites and can be downloaded using the web. |3.37) Which patches should I apply? "If it ain't broke, don't fix it." In general you should only apply patches for security related problems. For each and every other patch you must consider two things: have I encountered this bug or am I very likely to encounter this bug in the near future. If neither is true, it is often best not to apply the patch. If you have a working system, why patch it? Patches do occasionally introduce new bugs and not applying patches is the best way to avoid those new bugs. You should, however, install all patches that come with the Solaris 2.x CDs. Those patches have been tested together and supplement the base OS to the supported level. Some systems won't even boot if those patches aren't installed first. Y2000, security and even recommended patches should also be installed and updated on a regular basis. The latest Solaris releases come with packages "pre-patched" as well as a "Maintenance Update" CD. The "MU" CDs are meant to be used on systems with older HW releases; the patches on the MU CDs are already incorporated in the HW releases themselves. The MUs are also available on "SolarisSolve"; to access SolarisSolve, all you need to do is register with "solregis". This service is available to all Solaris users. PatchDiag from Sun helps you keep track of them. <http://sunsolve.sun.com/sunsolve/patchdiag/> Joe Shamblin's excellent PatchReport allows for easy patch <ftp://x86.cs.duke.edu/pub/PatchReport/index.html> diagnostics, downloads and installation. Casper Dik's fastpatch allows for lightning speed patch installation. | <ftp://ftp.science.uva.nl/pub/solaris/auto-install/> |3.38) Where do I get patches from? Sites not sponsored by Sun, accessible for all: ftp://ugle.unit.no/pub/unix/ ftp://ftp.luth.se/pub/unix/sun/ SunSites (carry recommended and security patches): sunsite.unc.edu:/pub/sun-info/sun-patches sunsite.sut.ac.jp:/pub/sun-info/sun-us/sun-patches sunsite.doc.ic.ac.uk:/sun/sunsite-sun-info/sun-patches Sunsolve: sunsolve.sun.com:/pub/patches http://sunsolve.sun.com/ These are Sun's own sites, they has the recommended patches up for anonymous ftp, packaged as one huge 2.x_Recommended.tar.Z file and as individual patches. Starting with Solaris 7, all patches are delivered .zip files, including the 7_Recommended.zip file. Starting with SunSolve CD 2.1.2 ALL Sun patches are shipped on the SunSolve CD. Contract customers can get all patches by ftp from Sunsolve or via e-mail and query one of the online sunsolve-databases on the Internet. |3.39) Where can I obtain Solaris 2/x86 driver updates? The Solaris x86 driver updates can be obtained by HTTP from: http://access1.sun.com/drivers/driverMain.html http://sunsite.unc.edu/pub/sun-info/solaris-x86/sunsoft-drivers The Solaris x86 driver updates can be obtained by anonymous ftp from: ftp.uu.net:/vendor/sun/solaris/ ftp://sunsite.unc.edu/pub/sun-info/solaris-x86/ |3.40) Why does installing patches take so much space in /var/sadm? All the files that are replaced by a patch are stored under /var/sadm/patch/<patch-id>/save so the patch can be safely backed out. Newer patches will save the old files under /var/sadm/pkg/<pkg>/save/<patch-id>/undo.Z, for each package patches. You can remove the <patchdir>/save directory provided you also remove the <patchdir>/.oldfilessaved file. Newer patches will not install a .oldfilessaved file. Alternatively, you can install a patch w/o saving the old files by using the "-d" flag to installpatch. |3.41) Do I need to back out previous versions of a patch? No, unless otherwise stated in the patch README. If the previous patch installation saved the old files, you may want to reclaim that space. Patches can be backed out with (Solaris 2.6+): patchrm <patch-id> or in earlier releases: /var/sadm/patch/<patch-id>/backoutpatch <patch-id> Backoutpatch can take an awful long time, especially when the patch contained a lot of files. This is fixed in later versions of backoutpatch. |*3.42) How can I have more than 48 pseudo-ttys? For Solaris 7 and before, edit /etc/system and add the following line: * System V pseudo terminals set pt_cnt = <num> Halt the system and boot -r. You can essentially have as many as you like, but you'll probably run into some other limit somewhere. More than 3000 are supported. Solaris 2.6 and earlier have telnet/rlogin daemons that do not support more than 3844 sessions each. That restriction is lifted in Solaris 7. Starting with Solaris 8, the number of pseudo terminals grows dynamically on demand. Setting the "pt_cnt" variable is no longer needed. The system still imposes internal limit based on available resources which is, usually, very high. In the rare case when this limit is still inadequate administrator may set pt_cnt variable to override it. If pt_cnt is set to anything less than the system-defined limit, its value is ignored. If administrators want to explicitly limit the maximum number of allocated ptys, they should set pt_max_pty variable which specifies the maximum number of ptys that can be created in the system. The default value 0 means that the maximum is automatically determined by the system based on the amount of memory. There is no need to reboot the system with -r flag after changing | these limit variables on Solaris 8 and later. The changes start | working immediately upon being set, even if they are set on the | running system by adb or some other means. The pty driver creates entries in the /dev/pts directory as needed and these entries are never removed automatically, so they do not indicate the actual amount of ptys allocated by the system. Some die-hard system administrator myths as well as some Sun documentation claim that you have to increase "sad_cnt", "sadcnt" or "nautopush" when adding ptys. There is no truth in this. In the unlikely event that you run out of BSD-style ptys, you can increase them as well. The maximum here is currently 176 for pty[p-z][0-9a-f]. This is somewhat less that the BSD maximum of 256 limited by 8 bit device minor numbers. BSD ttys are awkward to use and all programs I found support SYSV ptys without trouble. * You don't need this. Increasing this value too much usually * just wastes memory. * BSD applications never support more than 256 ptys. * Solaris 2.x supports no more than 176 BSD ptys. set npty = <num> But you're not there yet, you also need to edit /etc/iu.ap and substitute the new value of "npty-1" for the "47" on the following line, in case you do increase the number of BSD style ptys. ptsl 0 47 ldterm ttcompat Halt the system and boot -r. |3.43) How can I have normal users chown their files? Add the following to /etc/system: set rstchown = 0 This will defeat the quota system and may compromise the security of your system. |3.44) How can I get ps to print %MEM and %CPU? Prior to Solaris 2.4, the OS didn't do the bookkeeping necessary to obtain these values. In Solaris 2.4 the code was added to kernel and /usr/ucb/ps can now show these values. Under Solaris 2.3 and earlier your only recourse is using the public domain utility top (See 2.3). |3.45) How can I get the DOS and Unix clock to agree on Solaris/x86? After installation, run the command /usr/sbin/rtc -z $TZ, where $TZ is your timezone. The default root crontab runs /usr/sbin/rtc -c once every day. That way your clock will give the proper time whether you boot Solaris or DOS/Windows. |3.46) How can I increase the number of file descriptors per process? In 2.3 in earlier this requires poking the kernel. In Solaris 2.4+, this can be accomplished by adding the following lines to /etc/system: * set hard limit on file descriptors set rlim_fd_max = 4096 * set soft limit on file descriptors set rlim_fd_cur = 1024 Raising the soft limit past 256 may confuse certain applications, especially BCP applications. Raising the limit past 1024 may confuse applications that use select(). Select() cannot use more than 1024 file descriptors at this time prior to Solaris 7. In Solaris 2.6, the RPC code was rewritten to use poll(), which does work with many more fds than select(). Prior to 2.6, all RPC servers will likely crash and burn if you increase the fd soft limit past 1024. Solaris 7 allows upto 65536 fds passed to select; this is the default for 64 bit applications but it requires recompiling with a larger value for FD_SETSIZE for 32 bit apps. Programs using stdio or even library calls that use stdio may break when they have more than 256 files open as that is the stdio limit. Programs using many filedescriptors should try and reserve a number of low numbered file descriptors for use by stdio. The stdio limit is removed for 64 bit applications in Solaris 7; if you really need more than 256 FILE * in and you can't use Solaris 7+ or need to run in 32 bits, you can use SFIO from AT&T. <http://www.research.att.com/sw/tools/sfio/> |3.47) Can I install both SunOS and Solaris on the same machine, and choose between them at boot time? Yes, that is possible. All partitions other than the system partitions (typically /, /usr, /var and /opt) can be shared by the two OSes. All partitions, including the system partitions, can be mounted and accessed by either OS. The easiest way to set this up is to do separate suninstalls on two different disks. Then just choose the appropriate disk at boot time with the PROM's "boot" command. Setting up both OSes on one disk is a little harder, but not much. You need to partition the disk to allow for both OSes. Almost any partition layout is possible, but one common setup might be: a: / for Solaris 2 b: swap (shared) c: The usual (whole disk) d: / for Solaris 1 e: /usr for Solaris 1 g: /usr for Solaris 2 Again, it's most reliable to use suninstall to do the installations. If for some reason you choose not to use suninstall, make sure you run installboot for both bootable partitions. With this setup, you choose between the two OSes in the PROM's "boot" command as follows: To boot Solaris 2: boot To boot Solaris 1: boot disk:d NOTE: In boot PROM versions <= 2.5, the "disk:d" syntax is not supported, and the PROM cannot boot from root partitions that begin or end beyond 1GB. |3.48) How do I disable banner pages under Solaris? As root, go to directory /etc/lp/interfaces. Edit the file that corresponds to the printer name. Change the line that reads 'nobanner="no"' to 'nobanner="yes"'. To effect this change on future printers, edit the scripts in /usr/lib/lp/model. That directory contains the template scripts copied over to /etc/lp/interfaces. |3.49) How do I change my hostname? The supported way to change your hostname is: # /usr/sbin/sys-unconfig The system will halt and on subsequent boot will ask for its name and other networking parameters again. You may wish to save a copy of /etc/nsswitch.conf beforehand as that file is overwritten by the configuration process. Note that sys-unconfig is not supported on diskless or dataless workstations. On those, you'll need to edit files by hand. See the sys-unconfig(1M) for a list of the files that need changing. |3.50) Can I run multiple terminals on the console of Solaris x86 like those supported on Interactive Unix and SCO? Yes. In Solaris x86 2.1, these worked 'out of the box'. In Solaris x86 2.4 thru 7, they are no longer configured during the installation, but they still work if configured afterwards by hand. Sun apparently disabled them in this way because they are no longer officially supported, but fortunately, they did not actually remove them from the kernel, so you can configure them back in yourself as follows. In Solaris 8 they're gone. First verify the device's major number with grep: # grep -i chanmux /etc/name_to_major chanmux <num> Add the /dev entries, substituting whatever you found with grep for <number>: mknod /dev/vt01 c <number> 1 mknod /dev/vt02 c <number> 2 etc... add the following to /etc/inittab (after the co entry): v1:234:respawn:/usr/lib/saf/ttymon -g -h -p "VT1 Login: " -T AT386 -d /dev/vt01 -l console v2:234:respawn:/usr/lib/saf/ttymon -g -h -p "VT2 Login: " -T AT386 -d /dev/vt02 -l console etc... To get init to reread inittab, either reboot, or issue the command: /usr/sbin/init q Now, Alt-PrintScreen F1 switches to VT1, Alt-PrintScreen F2 switches to VT2, etc, Alt-PrintScreen P switches to previous screen in cyclic sequence, Alt-PrintScreen N switches to next screen in cyclic sequence. Alt-PrintScreen H switches to console screen (and not Alt-PrintScreen F8 as on Interactive Unix) |3.51) How can I prevent daemons from creating mode 666 files? Prior to Solaris 8, all daemons inherited the umask 0 from init. In Solaris 8, the default was changed from 0 to 022, a saner value. It is now settable in /etc/default/init (CMASK=value). The old behaviour is most problematic for a service like ftp, which in a standard configuration leaves all uploaded files with mode 666. To get daemons to use another umask execute the following commands in /bin/sh and reboot: umask 022 # make sure umask.sh gets created with the proper mode echo "umask 022" > /etc/init.d/umask.sh for d in /etc/rc?.d do ln /etc/init.d/umask.sh $d/S00umask.sh done Note: the trailing ".sh" of the scriptname is important, if you don't specify it, the script will will be executed in a sub-shell, not in the main shell that executes all other scripts. In Solaris 2.6 and later, in.ftpd(1M) allows setting its umask in /etc/default/ftpd. |3.52) How do I change the terminal type for /dev/console? Change the "-T sun" in the following line in /etc/inittab to "-T <termtype>": co:234:respawn:/usr/lib/saf/ttymon -g -h \ -p "`uname -n` console login: " -T sun \ -d /dev/console -l console -m ldterm,ttcompat (Line broken for readability) |3.53) If I login over the network, my terminal type is set to "sun"/"AT386" How can I change that? In SunOS 4.x the type would have been "network" If no terminal type is specified in the network (telnet/rlogin) protocol, the standard startup scripts (/etc/profile, /etc/.login) will set the terminal type to the default console type (sun for SPARCs, AT386 for x86). To get the SunOS 4.x. behaviour back, all you need to do is set the type to "network", if not previously set. |3.54) How can I change the SYSV IPC parameters? The following parameters can be used to change the number of semaphores, the amount of shared memory and the number of IPC messages. They're set in /etc/system, as usual. set semsys:seminfo_semusz = <value> set semsys:seminfo_semopm = <value> set semsys:seminfo_semume = <value> set semsys:seminfo_semaem = <value> set semsys:seminfo_semmap = <value> set semsys:seminfo_semvmx = <value> set semsys:seminfo_semmsl = <value> set semsys:seminfo_semmni = <value> set semsys:seminfo_semmns = <value> set semsys:seminfo_semmnu = <value> set shmsys:shminfo_shmmin = <value> set shmsys:shminfo_shmseg = <value> set shmsys:shminfo_shmmax = <value> set shmsys:shminfo_shmmni = <value> set msgsys:msginfo_msgseg = <value> set msgsys:msginfo_msgssz = <value> set msgsys:msginfo_msgtql = <value> set msgsys:msginfo_msgmap = <value> set msgsys:msginfo_msgmax = <value> set msgsys:msginfo_msgmnb = <value> set msgsys:msginfo_msgmni = <value> |3.55) How do I enable/disable dtlogin? Whether dtlogin is started or not is settable with /usr/dt/bin/dtconfig As dtlogin itself explain when invoked without arguments: /usr/dt/bin/dtconfig -d (disable auto-start) /usr/dt/bin/dtconfig -e (enable auto-start) /usr/dt/bin/dtconfig -kill (kill dtlogin) /usr/dt/bin/dtconfig -reset (reset dtlogin) /usr/dt/bin/dtconfig -p (printer action update) /usr/dt/bin/dtconfig -inetd (inetd.conf /usr/dt daemons) /usr/dt/bin/dtconfig -inetd.ow (inetd.conf /usr/openwin daemons) |3.56) How do I configure dtlogin? The standard CDE configuration files live in /usr/dt/config. You're not supposed to edit them there, but copy the files you want to modify to /etc/dt/config and edit them there. The /etc/dt directory does not exist, you must create it. Customizing dtgreet, the login widget, is done through /etc/dt/config/C/Xresources; near the end you'll find the following: !! To disable options in dtgreet window, uncomment the appropriate !! line below. !Dtlogin*options_noWindows*sensitive: False !Dtlogin*remote_host_menu*sensitive: False !Dtlogin*options_languages*sensitive: False !Dtlogin*session_menus*sensitive: False !Dtlogin*options_restartServer*sensitive: False !! To disable options under remote login option menu, uncomment the !! appropriate line below. !Dtlogin*remote_login_host*sensitive: False !Dtlogin*choose_login_host*sensitive: False By removing the ! in front of the !Dtlogin you can disable the following menu items, respectively: 1) Command Line Login 2) Remote Login 3) Language choice 4) Session choice 5) Reset Login Screen 6) Under the "Remote Login" menu, "Enter Hostname ..." 7) Under the "Remote Login" menu, "Choose Host From List ..." Two undocumented options, "options_failsafe" and "options_last_dt", can be used to disable the Failsafe and Last Session choices, though the default will continue to be "Last Session". By commenting out the following lines by prepending them with a exclamation mark (!), you can disable the CDE environment login (and force users to use the other choices) Dtlogin*altDts: 1 Dtlogin*altDtName1: Common Desktop Environment (CDE) Dtlogin*altDtKey1: /usr/dt/bin/dtwm Dtlogin*altDtStart1: /usr/dt/bin/Xsession Dtlogin*altDtLogo1: Dtlogo The OpenWindows Desktop can be disable by creating an empty "/etc/dt/config/C/Xresources.d/Xresources.ow" file. Other desktops can be added by creating files like Xresources.ow in the Xresources.d directory. |3.57) How can I configure a second monitor or change X server options? First, you simply plug in the second framebuffer; plug in the monitor, make sure you have the correct device drivers installed and do a reconfiguration boot. The X server is started through the dt/config Xservers file; you'll need to modify it when you change your X server configuration: # Never edit the /usr/dt/config files in place mkdir -m 755 -p /etc/dt/config cp /usr/dt/config/Xservers /etc/dt/config Edit the Xservers file and change the line with "local_uid@console" to suit your needs; the Xsun(1) describes what arguments to pass. Here are some examples (lines split for clarity): # FFB as left monitor, PGX (m64) to the right (two ways) :0 Local local_uid@console root /usr/openwin/bin/Xsun :0 -nobanner \ -dev /dev/fbs/ffb0 -dev /dev/fbs/m640 :0 Local local_uid@console root /usr/openwin/bin/Xsun :0 -nobanner \ -dev /dev/fbs/m640 -dev /dev/fbs/ffb0 left # FFB, PGX (m64) underneath :0 Local local_uid@console root /usr/openwin/bin/Xsun :0 -nobanner \ -dev /dev/fbs/m640 -dev /dev/fbs/ffb0 top # 2x FFB, using a default 24 bit visual instead of the standard 8 :0 Local local_uid@console root /usr/openwin/bin/Xsun :0 -nobanner \ -dev /dev/fbs/ffb0 defdepth 24 -dev /dev/fbs/ffb1 defdepth 24 |3.58) How can I have more than 128 X windows clients? When you get the following errors, you've run out of X sockets. Xlib: connection to :0.0 refused by server Xlib: maximum number of clients reached By default, the X server has a limit of just 128. In order to increase this limit, you need to run at least Solaris 8 or an earlier release with the Xserver patch applies that fixes bug: 4185418 the X server should support more connections Then change the Xservers configuration file and add the "-clients 1024" option to the X commandline. |*3.59) Xvnc/Xnest/Xvfb can't create a socket in /tmp/.X11-unix. The permissions to the /tmp/.X11-* directories have been restricted for security reasons. In order to still run unprivileged programs such as Xvnc/Xnest/Xvfb, you need to start those programs with the "-pn" option. You can no longer use displays of the form ":<num>"; only displays with the full hostname will still work: "<hostname>:<num>". | The Solaris 9 versions of Xnest/Xvfb are able to create these sockets | as they also run set-gid. |3.60) How can I restrict remote access through dtlogin? Copy to /usr/dt/config/Xaccess file to /etc/dt/config. Comment out the following lines if you want to fully restrict access: * # grant service to all remote displays * CHOOSER BROADCAST #any indirect host can get a chooser The dtlogin(1x) manual page explains how to have more fine grained control. |3.61) How do I disable the 2.6+ configuration assistant? In the file /platform/i86pc/boot/solaris/bootenv.rc, set the property "auto-boot-timeout" to -1 and the configuration assistant will be disabled. If you need to change your hardware, you need to undo that change before installing the hardware and rebooting. |3.62) How do I convert SunOS 4.x style /etc/passwd to Solaris passwd & shadow. Add the entries you want to copy to the Solaris /etc/passwd file. Then run "pwconv" which will split out the /etc/shadow fields. |3.63) How can I obtain the PROM level without halting my SPARC? prtconf -V |3.64) How can I use Solaris 2.6+ formatted disks on SunOS 4.x? Solaris 2.6 increased the default maxcontig parameter, so mounting 2.6 disks on 4.1.x no longer works. You can change this with tunefs, without rerunning newfs: tunefs -a 7 <disk> |3.65) Can I use soft mounts with NFS? Technically, you can, but it's like saying: "please set fire to my server and take the backups with you too; I don't care about my data at all." So, DON'T. |3.66) How can I boot a 32 bit kernel when a 64 bit kernel is installed? Sun hardware released after Solaris 8 no longer supports 32 bit booting; you can only run 64 bit kernels on those. This applies to all Ultra-III systems as well as the Sun Blade 100 and other UltraSPARC-IIe systems. In order to boot a 32 bit kernel on other 64-bit capable systems, type "boot kernel/unix" at the "ok" prompt. Setting the "boot-file" in the EEPROM to "kernel/unix" makes it the default kernel. Alternatively, you can move away the sparcv9/unix file in which case the boot loader will fall back to the 32 bit kernel. Patch installation may restore that file, though. Beware: when specifying "boot -s", or any boot command with flag arguments, the standard default kernel/sparcv9/unix kernel will be booted; you need to specify "boot kernel/unix -s". |3.67) How can I tell whether I'm running a 32 or 64 bit kernel? The command "isainfo" was provided for precisely that reason; 64% isainfo -kv 64-bit sparcv9 kernel modules 32% isainfo -kv 32-bit sparc kernel modules Solaris 2.6 and earlier releases are always 32 bit and lack the "isainfo" command. |3.68) How do I get rid of the Solregis pop-up? Some people are annoyed by the Solregis pop-up, especially if you do not want all users to register. Create /etc/default/solregis and put the following in it: DISABLE=1 This prevents the solregis program from starting. The manual lists a method to disable it on a per-user basis. Registering with solregis gives access to SolarisSolve; this enables you to fetch the Maintenance Updates. You can also remove the SUNWsregu package or don't install it in the first place. |3.69) Where do I get Disksuite for Solaris 8? You already have it. It's on the Solaris2of2 CD in the Solaris_8/EA directory. |3.70) How do perform an old-fashioned interactive install in Solaris 8? Boot from the Solaris1of2 CD and not from the webstart CD. |3.71) Now that Solaris install from several CDs, how can I jumpstart? In order to create a jumpstart image containing all the Solaris software, you first create an image like before from the Solaris 1of2 CD. Then you mount the Solaris2of2 CD and run Solaris_*/Tools/add_to_install_server /path/to/image/directory If you want, you can also add the langcd to the install image. |3.72) How can I grow a UFS filesystem? You can grow but not shrink a UFS filesystem if you manage to increase the size of the partition it lives in, with the following command: /usr/lib/fs/ufs/mkfs -G -M /current/mount /dev/rdsk/cXtYdZsA newsize Specifying the current mount point and raw device as well as the new size in 512 byte blocks. You can do this even when the filesystem is mounted and in use. |3.73) How do I install without starting OpenWindows? boot {net|cdrom} - install w |3.74) How do I set up Solaris for my time zone and daylight saving rules? You don't need to adjust your clock. Internally, Solaris uses Universal Time and is unaffected by time zone and daylight saving. However, you may need to adjust the TZ line in /etc/default/init to match your location, so that programs can read and display time stamps appropriately for your location. For example, you should use the line: TZ=Australia/Broken_Hill if you are in Broken Hill, Australia. After you change the TZ line in /etc/default/init, reboot to propagate the change to all processes. A TZ setting like Australia/Broken_Hill operates by referring to a file /usr/share/lib/zoneinfo/Australia/Broken_Hill that contains compiled data about the history of time zone and daylight saving changes at that location. You can run the time zone compiler yourself with a command like the following: # In Solaris 8 and later: cd /usr/share/lib/zoneinfo/src cd /usr/share/lib/zoneinfo /usr/sbin/zic africa asia australasia europe northamerica southamerica This command generates compiled time zone files for all the locations mentioned in the text files 'africa', 'asia', etc. This is a much larger set than the set of compiled time zone files shipped by default in Solaris. If you're in an unusual location, you'll need to run zic to get the proper time zone file; e.g. you must run zic to get TZ=Antarctica/South_Pole to work. Time zones and daylight saving rules change every now and then, so the files in /usr/share/lib/zoneinfo are periodically updated by Sun, and you may need to install a time zone patch (e.g. patch 103834 for Solaris 2.5.1) to bring things up to date for your location. Or you can install the most recent version of the time zone text files from the public domain time zone database <ftp://elsie.nci.nih.gov/pub/>, and compile the files yourself with zic. You can also use a POSIX TZ setting like TZ=CET-1CEST,M3.5.0/2,M10.5.0/3 as described in the environ(5) man page, but this is more confusing and is easy to get wrong, and it mishandles time stamps preceding the most recent time zone or daylight saving rule change. |3.75) I always install my own perl, can I remove the Sun installed one? Sun is planning to build software that is tested against the version of perl supplied with the OS. The answer is NO, you cannot remove perl. You can remove the /usr/bin/perl link, as Sun supplied software will only depend on /usr/perl5/bin/perl being present. |3.76) Where did kgmon go? The kgmon has been obsolete by lockstat. Lockstat has similar functionality: lockstat -kgIW sleep 5 |+3.77) Why do swap -l, swap -s and /tmp disagree about the amount of swap? | First of all, let's get the tmpfs issue (/tmp, /var/run) out of | the way. The tmpfs filesystem is a filesystem that takes memory | from the virtual memory pool. What it lists as size of swap is the | sum of the space currently taken by the filesystem and the available | swap space unless the size is limited with the size=xxxx option. | In other words, the "size" of a tmpfs filesystem has nothing to | do with the size of swap; at most with the available swap. | The second confusing issue is what "swap" really is. Solaris | defines swap as the sum total of physical memory not otherwise | used and physical swap. This is confusing to some who believe that | swap is just the physical swap space. | The "swap -l" command will list the swap devices and files configured | and how much of them is already in use. | The "swap -s" command will list the size of virtual swap. Physical | swap added to the physical memory. On systems with plenty of memory, | "swap -l" will typically show little or no swap space use but "swap -s" | will show a lot of swap space used. |+3.78) How do I secure my Solaris system? | Arguably the best tested tools are those currently supplied by | Sun's own blueprints. <http://www.sun.com/blueprints/> | The Sun Blue Print team develops and tests solutions for many | facets of security, including security high-end systems. | Look for the Solaris Security Toolkit (aka "JASS"). | Special products, such as Clustering software, E10K SSPs, | and others, need tailored security work. The blueprints program | provides it. | SANS <http://www.sans.org> | security solutions for Solaris are only suitable for | low-end systems and are known to break Sun's high end servers. 4. NETWORKING 4.1) How do I use DNS w/o using NIS or NIS+? Under SunOS 4.1 it was next to impossible to run DNS name resolution without either a kludge fix or the NIS (V2 I guess). Under Solaris 2.1 it is incredibly simple, but you must ignore what the manual (SunOS 5.1 Administering NIS+ and DNS) says (the manual is fixed in Solaris 2.2). All that is required to make a non-NIS host use the DNS for name resolution is to change the host: line in the /etc/nsswitch.conf file to the following: hosts: files dns (i.e., when looking for hosts, look in /etc/hosts first, if not found there, try DNS, if still not found then give up) and set up a correct version of /etc/resolv.conf to tell the resolver routines (like gethostbyname) how to contact the DNS nameserver. You must have the names of machines which are somehow contacted during boot in the files in /etc and files must appear first in the hosts: line, otherwise the machine will hang during boot (at least ours did). Make sure that /etc/netconfig is as it was shipped. (In Solaris 2.3 and earlier, it will use "switch.so,tcpip.so" for ip, in Solaris 2.4 it just uses "-") 4.2) What is /etc/nsswitch.conf? An idea whose time has come (it came to Ultrix a few years ago). You can control which of the "resolver" services are read from NIS (formerly YP), which from NIS+, which from the files in /etc, and which are from DNS (but only "hosts" can come from DNS). A common example would be: hosts: nis files which means ask NIS for host info and, if it's not found, try the local machine's host table as a fallback. Advice: if you're not using NIS or DNS, SunInstall probably put the right version in. If you are, ensure that hosts and passwd come from the network. However, many of the other services seldom if ever change. When was that last time *you* added a line in /etc/protocols? If your workstation has a local disk, it may be better to have programs on your machine look up these services locally, so use "files". Terminology: Sun worried over the term "resolver", which technically means any "get info" routine (getpwent(3), gethostbyname(3), etc), but is also specifically attached to the DNS resolver. Therefore they used the term "source" to mean the things after the colon (files/DNS/NIS/NIS+) and "database" to mean the thing before the colon (passwd/group/hosts/services/netgroup etc). A complete discussion can be found in nsswitch.conf(4). 4.3) What does [NOTFOUND=return] in nsswitch.conf mean? Type "man nsswitch.conf" for more info. There is too much detail to summarize here. Briefly, [NOTFOUND=return] means that the name service whose entry it *follows* should be considered authoritative (so that if it's up and it says such a name doesn't exist, believe it and return instead of continuing to hunt for an answer). 4.4) Can I run a nis/yp server under Solaris 2.x? A number of options have been made available over time for running ypserv on Solaris: 1) NSkit 1.0. A version of SunOS 4.x NIS executables made to work on Solaris 2.x. Fully included in patch 101363-08. 2) NSkit 1.1. Native, available from OPcom, but never left beta stage. Didn't do DNS lookups well (the entire server hangs until a DNS request is answered). 3) NSkit 1.2. Native. Freely available from the Solaris 2.x migration initiative home page. Supports multi-homed hosts, async DNS lookups and shadow password maps. Also shipped with the 2.5 server kit. 4) SUNWypr/SUNWypu native Solaris packages. Shipped with Solaris 2.6 and later as part of the base OS CD. NSkit 1.2 is available for SPARC and x86. 4.5) Can I run NIS+ under Solaris 1 (SunOS 4.1.x) Sort of, with the NIS+ server implementation for Solaris 1.x that used to come on the Solaris 2.x CD, upto Solaris 2.3. This is a server side only implementation and requires NIS+ to run in YP compatibility mode. This server doesn't seem to be supported anymore. 4.6) With NIS+ how do I find out which machine a client is bound to? NIS+ clients do not hard bind to nis+ servers in the same way that NIS clients bind to NIS servers. The clients have a list of NIS+ servers within the cold-start file. When they need to do a lookup they do a type of broadcast called a "manycast" and talk to the first server that responds. This way they can be sure to use the lightest loaded server for the request. 4.7) Ypcat doesn't work on the netgroup table on a NIS+ server, why? Yes, that is a known problem. The only operations allowed from a NIS client side on the netgroup table are the ypmatches, but not ypcat (i.e. no support for yp_first(), yp_next() or yp_all() calls). The netgroup table is kind of unique in this. The reason for this is that the netgroup table format changed quite significantly in NIS+ and the NIS+ server would take a big performance hit in converting the netgroups table to YP (key-value) format. 4.8) Why is rpc.nisd such a memory pig according to ps? The good news is that it's not memory OR swap space you're being shown by 'ps'. Instead it's showing you the process ADDRESS space which includes 256 MB of address space reserved for the NIS+ transaction log. Given the cost of moving things around in memory and the fact that we have 4 GB of address space to play with it, this is a good idea. You've just got to stop thinking small. THINK BIG. It's only 1/16th of the total process address space being used. And if you ever exceed the 256 MB size of the transaction log you're doing something VERY wrong. 4.9) How do I tell my NIS+ server to service DNS requests from 4.x clients? Start rpc.nisd with the -B switch. This can be done editing the server's /etc/init.d/rpc file and change 'EMULYP="-Y"' to EMULYP="-Y -B" 4.10) How can I have multiple addresses per interface? Solaris 2.x provides a feature in ifconfig that allows having more than one IP address per interfaces. Undocumented but existing prior to 2.5, documented in 2.5 and later. Syntax: # This command is only required in later releases ifconfig IF:N plumb ifconfig IF:N ip-address up where "IF" is an interface (e.g., le0) and N is a number between 1 and <MAX>. Removing the pseudo interface and associated address is done with ifconfig IF:N 0.0.0.0 down # In newer release you must use the following command, but # beware that this unplumbs your real interface on older # releases, so try the above command first. ifconfig IF:N unplumb As with physical interfaces, all you need to do is make the appropriate /etc/hostname.IF:X file. The maximum number of virtual interfaces, <MAX> above, is 255 in Solaris releases prior to 2.6. Solaris 2.6 and Solaris 2.5.1 with the Solaris Internet Server Supplement (SISS) allow you to set this value with ndd, upto a hard maximum of 8192. /usr/sbin/ndd -set /dev/ip ip_addrs_per_if 4000 There's no limit inspired by the code; so if you bring out adb you can increase the maximum even further. 4.11) Solaris 2.x supports filesystem sizes up to 1TB. Will this give interoperability problems with NFS? No, you can share those filesystems with SunOS 4.x and other machines just fine. The NFS protocol rarely transmits the size of the underlying filesystems. The only programs on SunOS 4 clients that may give trouble are du and df, but normal filesystem use is just fine. 4.12) Where can I get an SNMP agent for Solaris? There are several agents available, including one from Sun. ftp.ece.ucdavis.edu:/pub/snmp Solstice Enterprise Agents, hit the "software download" icon <http://www.sun.com/software/solstice/products/ent.agents> Sun SNMP agents <ftp://zippy.telcom.arizona.edu/pub/snm/patches/snmpd2.2.3/> Solaris 2.6 ships with an SNMP agent. *4.13) How can I use full-duplex ethernet? | Sun's hme and later fast ethernet adaptors support full-duplex ethernet. There are several ways of changing the default settings and force full-duplex mode; you may need to alter your switch settings as well. | The problem with changing this setting is that it disables auto | negotiation. Usually, this causes switches to fall back to half-duplex | mode unless they are also configured to use full duplex mode. | It is usual best to leave the settings alone and have both switch and | Sun auto-negotiate unless problems arise. Setting through /etc/system set hme:hme_adv_autoneg_cap=0 set hme:hme_adv_100hdx_cap=0 set hme:hme_adv_100fdx_cap=1 Setting with ndd ndd -set /dev/hme adv_100hdx_cap 0 ndd -set /dev/hme adv_100fdx_cap 1 ndd -set /dev/hme adv_autoneg_cap 0 In case you have multiple instances, you need to select the specific hme instance first, e.g., use the following to select hme1: ndd -set /dev/hme instance 1 If you need to query the device, you can interrogate various variables such as ``link_status'', ``link_speed'', etc. Setting "adv_autoneg_cap", not necessarily changing it, will cause re-negotiating of link speed/duplex settings. The dfme device cannot configured using /etc/system but are configured either with ndd (but on per-device nodes /dev/dfme0, dev/dfme1) or by editing dfme.conf. 4.14) Where can I get BOOTP/DHCP for Solaris? Solaris 2.6 ships with BOOTP/DHCP support. For older releases, you have to look into public domain servers, such as those from the Internet Consortium. <ftp://ftp.isc.org/pub/dhcp/> 4.15) What kind of multicast support does Solaris have? All versions of Solaris have IGMPv1 support, which is sufficient for multicast client support. Various unsupported patches for IGMPv2 <ftp://playground.sun.com/pub/multicast/> support have been made available over the years; that support is integrated in Solaris 2.6. You will need to get and install mrouted yourself. |*4.16) How can I have NAT or a firewall on Solaris? There are several NAT and firewall solutions. Sun has recently made SunScreen lite available for free from | Sun's home page and as part of Solaris 8. | Solaris 9 ships with the full edition of SunScreen 3.2. Alternatively, there's Darren Reed's ipfilter package. <http://coombs.anu.edu.au/~avalon/> *4.17) Where can I get an IPv6 capable version of tcp wrapper? The IPv6 capable version of tcp wrapper is available at Wietse's site in the /pub/ipv6 directory. <ftp://ftp.porcupine.org/pub/ipv6/> Make sure you configure it with -DHAVE_IPV6. | Solaris 9 has this version of tcp wrappers bundled with the system. 5. TROUBLE SHOOTING 5.1) The Solaris 2.x application XX fails with a mysterious error condition. Try truss(1). truss -f -o file cmd args ... will put a trace of all system calls in "file". This often helps as a first step in diagnosing many failure modes, such as insufficient permissions on certain files etc.. 5.2) In Solaris 2.5 nm is slow or dumps core. A bug introduced in the 2.5 locale libraries make strcoll() return bogus values when confronted with empty strings. This bogus empty string comparison makes that strcoll no longer defines a strict order on strings, that confuses the hell out of qsort which promptly crashes. Workaround: set LC_COLLATE to "C" (Note that xview applications will usually reset LC_COLLATE to LC_ALL, so in cmdtool/shelltool windows, LC_COLLATE needs to be set again.) 5.3) Why can't I run Answerbook on a standalone machine? This is a bug in OpenWindows. Using xhost + or starting "openwin -noauth" works around this problem. This is only recommended for stand-alone machines with no dial-in users. [ S 2.3 ] 5.4) Why can't I display Answerbook remotely? Displaying answerbook requires support for the DPS extension in the X server. The DPS extension is supported by most common Unix workstations, but not by most PC/X offerings and is often an extra cost item for X terminals. A number of people have reported success using ghostview as a replacement for the answerbook viewer, but this has the unfortunate side effect of not supporting the hypertext links in the documents. A better solution is to install a client side Display PostScript extension. Adobe has defined such a client side extension and call it DPS-NX. Bluestone sells a version. <http://www.bluestone.com/> Solaris 2.6 and later come with an answerbook HTTP server which can be used with any web browser. 5.5) Why can't I run filemgr, I get ``mknod: permission denied''? This is a symptom of a bug in filemgr in Solaris 2.3. Either apply patch #101514 or run the following commands at system start-up: mkdir /tmp/.removable chmod a+rwxt /tmp/.removable 5.6) Why do I get isinf undefined when linking with libdps on Solaris 2.3? That's a bug in libdps (fixed in 2.4). Sun compiles and links its software with its own compilers. The isinf() function is shipped with the SunPRO compilers, but not defined in any Solaris 2.3 library. A workaround exists, and consists of adding the following to your program: #include <ieeefp.h> int isinf(double x) { return !finite(x) && x==x; } 5.7) I can't get PPP to work between Solaris 2.3 and other platforms. The PPP shipped with Solaris 2.3 doesn't interoperate with other PPP implementations. Patch #101425 fixes this. 5.8) Using compat mode for passwd doesn't work in 2.3? You need patch #101448. 5.9) Why do I get __builtin_va_alist or __builtin_va_arg_incr undefined? You're using gcc without properly installing the gcc fixed include files. Or you ran fixincludes after installing gcc w/o moving the gcc supplied varargs.h and stdarg.h files out of the way and moving them back again later. This often happens when people install gcc from a binary distribution. If there's a tmp directory in gcc's include directory, fixincludes didn't complete. You should have run "just-fixinc" instead. Another possible cause is that you're using ``gcc -I/usr/include.'' Reinstall gcc or upgrade to gcc 2.8.0 or later, which doesn't require a reinstallation after every OS upgrade, if you run Solaris 2.5 or later. 5.10) When compiling, I get "No DATAMODEL_NATIVE specified"? There are two typical causes for this; one is compiling with a bad install of gcc (See 5.9). The other possible cause is installing BIND 4.x or 8.x header files, e.g., by running "make install". You can check this with "pkgchk SUNWhea"; if this returns any errors, you need to recover the damaged include file from the original installation media. 5.11) My machine hangs during the boot process. It seems related to ps. When the system boots, the first invocation of ps will try to recreate /tmp/ps_data. To this end ps scans the /dev tree. Under some circumstances, a loop exists in /dev and ps will run forever. Most of the time this loop is caused by the symbolic link /dev/bd.off. While this link usually points to /dev/term/b, it sometimes get truncated and points to /dev instead. Fix: rm -f /dev/bd.off; ln -s /dev/term/b /dev/bd.off Use truss(1) to determine whether this is really the cause of your problem. 5.12) Syslogd doesn't seem to log anything. Make sure you have /usr/ccs/bin/m4 installed. It's in package SUNWbtool (m4 is included in SUNWcsu in 2.4 and later). Other causes are bugs in Solaris 2.3 and various revisions of patches. E.g., syslogd is broken in all 101318 patches between level -42 and -50. It works again in 101318-54. For 2.4, you may need patch 102534-xx and/or 102697-xx. In Solaris 2.6, syslogd again seems to be crash prone. You need 106439 (sparc) or 106440 (x86), rev -02 or later. 5.13) Syslogd in 2.6 runs with -z <num> -n, what's up? In some cases, syslogd as a multi-threaded applications needs to do a restart using exec. It uses two internal options to pass on some state information. 5.14) I get ``Invalid client credential'' when mounting filesystem on Solaris client from non-Sun fileserver. Some vendors still ship a version of RPC/NFS that allows at most 8 groups in the client credentials. Root on Solaris is by default in 10 groups. As a result, the Solaris 2.x mount command will send AUTH_UNIX credentials that are too big to cope with for the remote mount daemon resulting in the ``Invalid client credential'' error. Workaround: put root and all your users in 8 or less groups. NOTE: You must logout and login again for changes in the number of groups to take effect. (or exit root's shell and re-su) 5.15) After upgrade to 2.4, ls on NFS mounted directories hangs. Starting with Solaris 2.4, a kernel workaround to limit NFS readdir requests to 1024 bytes was disabled by default. This breaks interoperability with buggy old NFS implementations (such as SunOS 3.2, Ultrix and NeXT) There are two workarounds. The first one works and is: mount all filesystems from such servers with rsize=1024. The second one, which requires a patch for bugid #1193696 (101945-29 or later for SPARC, 101946-24 or later for x86) Edit /etc/system and add: set nfs:nfs_shrinkreaddir = 1 and reboot. 5.16) After installing patch 101945-xx, I have NFS problems (ksh looping). Patch 101945-17 introduced an bug in the NFS client code that makes that programs using NFS locking will sometimes go in an interruptible read. (I.e., you can kill the program that hangs) Truss will show the program sleeping in read(2) while top will show it eating CPU. The ksh seems to have this quite a lot. There's also a lot of network traffic. Fix: install a patch for bug-id #1198278 on your NFS clients. (101945-29 or later for SPARC, 101946-24 or later for x86) Workaround: mount NFS filesystems with "noac", but this costs performance. 5.17) I messed up /etc/system, now I can't boot. Boot with -as. The kernel will ask you all sorts of questions, including the name of the system file. Use the previous /etc/system file or specify /dev/null. 5.18) The /etc/path_to_inst file is corrupted, I can't boot. You will need to remove the file and then boot with -a and it will ask you to rebuild the path_to_inst file. It is possible that you still can't boot after that: if you've added/removed controllers/disks, the numbering of the controllers may have changed. You may need to find the new name of /usr and then edit /etc/vfstab to change all the disk names. 5.19) TCP/IP connections time out too soon, especially on slow links. The tcp/ip abort interval in Solaris 2.x is too short, the default value is 2 minutes. The result is that when an ACK isn't received in *2* minutes, the connection is closed. This is most often seen by sendmail, which will log sendmail: SYSERR: collect: read timeout on connection from ... You can fix this by running following command which increases the timeout to 8 minutes (unit is millisec), which is the Solaris 2.4+ (and patched 2.3) default. /usr/sbin/ndd -set /dev/tcp tcp_ip_abort_interval 480000 | This command should be placed in a script rc2.d script. (See 3.19) (See 5.21 for another possible cause) 5.20) Sendmail connection to non-Unix hosts don't work. With the introduction of sendmail V8 for Solaris 2.x in patch form and in Solaris 2.5, a bug in sendmail.cf has suddenly started to play up. The end-of-line character is not defined for the ethernet mailer, causing sendmail to send bare newlines in violation of the SMTP protocol which requires CR-NL.To fix, find the following line in sendmail.cf: Mether, P=[TCP], F=msDFMuCX, S=11, R=21, A=TCP $h and change it to: Mether, P=[TCP], F=msDFMuCX, S=11, R=21, A=TCP $h, E=\r\n To be on the safe side, check all lines starting with "M" that contain P=[TCP] or P=[IPC]. They all should use "E=\r\n". This bug is also fixed in the latest Solaris 2.x sendmail patches. 5.21) Solaris 2.x can't set up any TCP/IP connections to certain hosts. Solaris 2.x sets the don't fragment bit on all packets it send as part of MTU path discovery. The Solaris 2.x implementation is RFC compliant, but the MTU path discovery protocol will fail when there are broken routers in the path. Typical symptom is not being able to connect from a Solaris 2.x hosts but having no trouble from other hosts or being able to start a TCP/IP connection but not move any significant amount of data. /usr/sbin/ndd -set /dev/ip ip_path_mtu_discovery 0 (See also 5.19) 5.22) I read 5.21, but I still have connectivity problems. Solaris 2.x will still send large packets over such links but without the don't fragment bit set. On a number of occasions, I've come across links that don't properly handle such packets. They're not fragmented, they're silently dropped instead. So if the fix in 5.21 doesn't work you can resort to the following drastic measure which negatively impacts network performance: /usr/sbin/ndd -set /dev/tcp tcp_mss_max 536 536 is the standard packet size that is guaranteed to work by virtue of the fact that most system will communicate outside the local net with packets that big. If the connection then starts to work, it's time to find the largest value that works. It's also worth mentioning that the "ip_path_mtu_discovery" needs to be applied at both sides of a connection to fully work, applied at one side it will only affect outgoing large packets. (I.e., downloads from the site will succeed but uploads from a other Solaris 2.x machine w/o the workaround applied may still fail). The "tcp_mss_max" workaround need only be applied at one side. If you need the "tcp_mss_max" workaround for some sites, there is a problem on the link between you and those sites. Get it fixed. Traceroute will tell you where the problem lies. Try traceroute host size, for varying sizes. If traceroute without a size parameter works, but traceroute with a size parameter of 1460 fails at some hop, the connection between that hop and the next is broken. 5.23) When reading mail on non-Solaris clients of a Solaris mail server, or with non-Solaris mail readers, some messages get split into multiple messages. Solaris 2.x uses the "Content-Length:" header to tell the MUAs where messages should be split. Unfortunately, no-one else understands this convention. Instead, the old convention, ``split on "From " lines'' is used most of the time. Those mail readers expect extra lines with "From" to be escaped with ">". Workaround: add "E" to the mailerflags of the local mailer. Edit /etc/mail/sendmail.cf on your Solaris machines, add E to F= on the line that reads: Mlocal, P=/bin/mail, F=flsSDFMmnP, S=10, R=20, A=mail -d $u so that it becomes: Mlocal, P=/bin/mail, F=EflsSDFMmnP, S=10, R=20, A=mail -d $u 5.24) Mail/mailx often send reply to wrong user or show wrong sender. Mail/mailx use UUCP from line to determine sender, it should use the From: header only. To achieve this you can use the undocumented "from" mail variable in your .mailrc: "set from". To make this the default behavior, add "set from" to /etc/mail/mailx.rc. 5.25) One of my users can't login (one some machines). In the shadow table/file/map there is a field that indicates how long an account may be inactive before it is expired. On login, the entry in /var/adm/lastlog, the inactive expire time and the current date are compared. If the system determines that the user is expired, he will get "Login incorrect", indiscernible from a normal incorrect login. The fix is to change the user's shadow entry. 5.26) My clients with remote /var (/var/adm) partitions won't boot. Remote, but unshared filesystems, such as /, /var, /var/adm, etc. should be mounted with the llock option. Solaris 2.x does this automatically for remote /, but not for remote /var or /var/adm. If you don't specify llock, the system will hang when it tries to do stuff to the *[wu]tmp files, early in the boot process. And lpsched may fail if it can't lock /var/spool/lp/SCHEDLOCK. Workaround: Add the (undocumented) llock option to the mount options for /var and/or /var/adm. (It should be fixed in /etc/rcS.d/S70buildmnttab.sh) 5.27) Vacation doesn't work reliably in a mixed Solaris/SunOS environment. Vacation was moved from /usr/ucb (in SunOS 4.x) to /usr/bin. Unfortunately, the full pathname must be specified in your .forward. Workaround: add a link to /usr/ucb/vacation in /usr/bin on SunOS 4 machines, and add a link to /usr/bin/vacation in /usr/ucb on SunOS 5 machines. 5.28) I have a lot of <defunct> processes. How do I get rid of them? In general, defunct processes are caused by a parent process not reaping its children. Find out which process is the parent process of all those zombies (ps -e). It's that process that has a bug. In Solaris 2.3 (and presumably earlier) there is a bug in the pseudo tty modules that makes them hang in close. This causes processes to hang forever while exiting. Fix: Apply patch 101415-02 (for 2.3). In all Solaris 2 releases prior to 2.5 (also fixed in the latest 2.4 kernel jumbo patch), init (process 1) calls sync() every five minutes which can hang init for some considerable time. This can cause a lot of zombies accumulating with process 1 as parent, but occurs only in rare circumstances. 5.29) I get /dev/ptmx: No such device when attempting to telnet/rlogin in. | You need to increase the number of pseudo ttys (See 3.42). |+5.30) I get Could not grant slave pty on telnet/rlogin | In Solaris 8 and later you must make sure you have syseventd/devfsadmd | running or the automatic pty node creation does not work. | In older releases this probably means that you changed "pt_cnt" but | didn't reboot with the "-r" flag. To recover, run "drvconfig; devlinks". |5.31) ld bails out with msync errors. You probably use a Cray as fileserver. It doesn't support all NFS operations ld wants to perform. Install the following patch: 101409-04: SunOS 5.3: Jumbo linker patch [ Solaris 2.3 ] |5.32) su responds with "Sorry" and doesn't prompt for a password. Su won't run under a shell compiled under SunOS 4.1.x. Recompile your shell (tcsh/bash) under Solaris 2.x. |5.33) Why can't I install 2.4 from a non-Sun CD while I could do so with 2.3? Several changes were made to the "sd" driver between 2.3 and 2.4. In particular, the code that resets the drive to the 512 block size is no longer called in the case of a data overrun. Accordingly, it is not currently possible to install 2.4 from a local non-Sun CDROM drive. Your best bet for the short term may be to either borrow a SunCD (locally or maybe from your Sun Rep) or to mount the CD remotely on a machine that is already up and running and can handle your non-Sun CDROM, and perform a network installation. This is not a problem for non-SPARC versions of Solaris 2.x. CDROMs that have been modified to use a 512 byte blocksize by default will work fine. The Sun CD-ROM FAQ explains how to patch Solaris 2.x for using a <http://saturn.tlug.org/suncdfaq/> non-Sun CD-ROM drive for booting/installation. It also includes other information about using CD-ROM drives on Sun. |5.34) ifconfig can't find my network interface Only network devices configured with an address at boot are visible to ifconfig (i.e., if /etc/hostname.IFN exists). To make a interface visible to ifconfig do: ifconfig ifN plumb |5.35) I have an application that compiled fine, but when I run it I get: fatal: libfoo.so.2: can't open file: errno=2 or No such file or directory You need to add -R<wherethelibraryis> to the link command line. E.g.,: cc -L/usr/dt/lib -L/usr/openwin/lib \ -R/usr/dt/lib -R/usr/openwin/lib \ xprog.c -lXm -lXt -lX11 |5.36) Motif programs dump core almost immediately. You must specify the Motif library on the command line before other X libraries. WRONG: cc .... -lXt -lXm RIGHT: cc .... -lXm -lXt |5.37) cc complains that "language optional software package not installed". There is no C compiler included in Solaris 2.x. The /usr/ucb/cc script you are executing is a wrapper for the SunSoft C compiler which calls the native C compiler with the /usr/ucb includes and libraries. You need to get yourself a C compiler. Alternatively, you may have forgotten to put the proper link from /usr/ccs/bin/ucbcc to /opt/SUNWspro/SCxxxx/cc in place. See also 6.1. If you do have a real compiler somewhere else, either put it earlier in your path [PATH=/opt/SUNWspro/bin:....:/usr/ucb] or if it is named something other than "cc", make a link as appropriate. [PATH=/usr/local/bin:...:/usr/ucb ; ln -s ./gcc /usr/local/bin/cc] It's best to not have /usr/ucb in your PATH anyway. |5.38) thr_create/pthread_create and other thread functions always return -1 If you use SunPRO C 3.0 or later, you need to specify the commandline option ``-mt'' when compiling and linking. If you and earlier version of SunPRO C or when using gcc, you'll need to specify -D_REENTRANT on compile command lines and -lthread/-lpthread on the link command line. -lthread/-lpthread should precede -lc. Compilers implicitly add -lc at the end of the link command line; you do not have to add it yourself. |5.39) Solaris 2.4 is getting slower over time/seems to have a kernel memory leak. There are two possible causes for this kernel memory leak. There's a bug in the volume management device driver that when unloaded leaks memory: fix with patch 101907-05 (sparc) or 101908-07 (x86). This bug especially affects systems *not* running vold, as it is triggered when the kernel decides to unload unused device drivers. The NFS client cache will cache too much. A simple workaround is to add ``set nrnode = 1000'' to /etc/system and reboot. You may want to make this larger or smaller depending on how much memory you have. A good rule of thumb is about 20-30 rnodes per MB of memory. Another possible candidate is an overflow in /tmp or other swap based (tmpfs) filesystems. Check with df/du. |5.40) Why do I get ``Unable to install/attach driver 'xxx''' messages? The kernel complains that it can't load device drivers for devices you don't have. They're harmless, ignore them. |5.41) I can't run nfs: netdir_getbyname failure, /dev/udp: bind problem For some reason the nfs service has disappeared from your /etc/services file, NIS map or NIS+ table. You need to have an entry like: nfsd 2049/udp nfs # NFS server daemon (clts) nfsd 2049/tcp nfs # NFS server daemon (cots) If you use NIS+, you must make sure that the NIS+ entry is readable for the machine executing nfsd. If you used your SunOS 4.x services file, that would explain it: SunOS 4.x doesn't have an entry for nfsd in /etc/services, Solaris 2.x requires one. This will usually not happen until you upgrade to Solaris 2.4 or a later revision. Solaris 2.3 and earlier would always consult /etc/services, regardless of what nsswitch.conf said. /etc/services does contain the right NFS entries. Solaris 2.4 and earlier don't have an entry for NFS over tcp, so this error is also likely to occur on 2.5+ NFS servers that are NIS/NIS+ clients of 2.4- servers. In 2.5 the error message will look like: nfsd: Cannot get address for transport udp host \1 service nfs nfsd: Cannot establish NFS service over /dev/udp: transport setup problem. nfsd: Cannot get address for transport tcp host \1 service nfs nfsd: Cannot establish NFS service over /dev/tcp: transport setup problem. |5.42) Why do I get ``named[]: rt_malloc: memdebug overflow'' errors? That's caused by a bug in the Solaris 2.4 named. You need to install the appropriate one of the following patches: 102479-01: SunOS 5.4: memory leak/mismanagement in in.named 102480-01: SunOS 5.4_x86: memory leak/mismanagement in in.named The latest version of these patches include bind 4.9.3: 102479-12: SunOS 5.4: libresolv, in.named, named-xfer, nslookup ... 102480-10: SunOS 5.4_x86: libresolv, in.named, named-xfer, nslookup ... |5.43) The ld command dumps core on Solaris/x86 Solaris 2.4/x86 ld dumps core when passed the "-s" option. Workaround: Link without the -s option and use strip on the resulting executable. |5.44) In Solaris 2.4 my TCP performance is extremely poor. Patch 101969-05 broke TCP/IP throughput. You need to backout this patch or obsolete it with the kernel jumbo patch (101945-27 or later). The latter is recommended. On Solaris 2.4 x86, later kernel jumbo patches (101946-29) triggered bugs in some of the ethernet cards. This manifests itself as extremely poor TCP throughput. On such systems, you need to install DU10 or later. |5.45) Solaris 2.4 in.tftpd is terribly slow. In Solaris 2.4 a bug was introduced that makes tftpboot chroot, while it still needs to open a socket. The first request still gets a response, but all other requests meet with a 5 second delay. Workaround: mkdir /tftpboot/dev mknod /tftpboot/dev/udp c 11 41 chmod 755 /tftpboot/dev; chmod 666 /tftpboot/dev/udp This is fixed with patch 102773-01 (sparc) and 102774-01 (x86). |5.46) I get "df: Could not find mount point ..." If the mount point starts with /cdrom, there's a bug in the way /etc/mnttab gets updated for HSFS CDroms in Solaris 2.4. Edit /etc/mnttab and remove the dev= entry for those mountpoints that give you trouble. If the mount point name starts with /net/HOSTNAME, where HOSTNAME is some other host, it's probably Sun bug 1207057. Try patch 102785-01 or later (SunOS 5.4) or 102783-01 or later (SunOS 5.3). But if HOSTNAME is the current host, it's probably Sun bug 1220440; unfortunately, this bug is still open as of Jan 2nd 1996. |5.47) I changed root's shell, forgotten root's password, and I can't login. If root no longer has a valid shell, your only recourse is to boot single user *from CD*. You need to mount the root file system and fix <mntpoint>/etc/passwd. If you run NIS or NIS+, you have an easier solution; just add an account with uid 0 but with a different username and a valid shell. Use that account to fix the problem with the root account. |5.48) How do I boot single user from CD? In order to recover from some problems, you will need to boot single user from CDrom. On SPARC systems with Openboot PROMs, this is done through: ok boot cdrom -s On all systems, you can boot an interactive installation in the window system and escape to a shell window. This method has the advantage of usually mounting your filesystems under /a. |5.49) How do I interrupt the system boot sequence on SPARC? As opposed to Solaris Intel system which always prompt during boot-up, Solaris SPARC systems will boot without asking. To interrupt booting, use the key sequence "Stop-A" (or L1-A) on a Sun keyboard, using "Stop" as if it's a modifier (shift/control) key. On systems with a serial console, send a BREAK; most terminals and emulators support this. |5.50) How do I reset the NVRAM to factory defaults? During bootup, press down Stop and then N, holding them down at the same time. On SPARC systems with USB keyboards, this will have no effect. Those systems can be reset by quickly toggling the front panel power button, as if double, after the power LED has started flashing and you hear an audible beep. clicking on a mouse, after |5.51) When linking C++ programs, I get "_ex_keylock" undefined. You installed a patch for your C++ compiler (101910 (SPARC) or 102486 (x86)) but forgot to install the required companion patch for libC.so.5. Fix: install patch 101242-10 (SPARC) or 102859-01 (x86) or later. This fix is included in Solaris 2.5+. |5.52) My NFS server hangs when I get filesystem full/over quota errors. Solaris 2.4 has a combination of problems that make running with quotas of or with near-full disks almost impossible. The problems include writing message to /dev/console, which requires switching of interrupts and make the machine appear dead, clients caching upto 2MB of failed writes and retrying them, hammering the server to death. Fix: kernel patch 101945-32 (sparc)/101946-29 (x86) or later. Needs to be applied on clients as well as servers. |5.53) OpenWindows fails with "Binding Unix Socket: Invalid argument" This usually only happens on diskless/dataless clients. You installed a new kernel jumbo patch on the server that exports /usr to the client and failed to read the note in the patch readme that says: NOTE: If this patch is applied to a server, it should also be applied to dataless clients that also mount /usr from that server. Failure to do so will generate this error message when openwin is started on the client: "Binding Unix socket: Invalid argument". The fix is to apply the same kernel jumbo patch to the client. |5.54) Why is Xsun such a memory pig, especially on the SX, S24 and FFB? Ps counts the mappings for the framebuffer as memory. Especially on the FFB where a number of different mappings of the device address space is used to optimize access this can cause large amounts of memory, but not physical memory, to be mapped and shown by ps. It's not unusual for the FFB+ (Creator3D) to show a 500MB process size for the X server. Solaris 2.3 FCS also has a number of Xsun memory leaks when using the SX. Get the SX patches or upgrade to a later release of Solaris 2.x. /usr/proc/bin/pmap (new in 2.5) will show the exact mappings used by Xsun. "pmap -x" (new in 2.6) will even show how much of each mapping is shared/private resident, etc. If Xsun has a memory leak, you'll see a huge "[heap]" with pmap. |5.55) Solaris 2.5 and Solaris 2.4 patch 101945-34+ have poor TCP performance over slow links. Solaris 2.5 and Solaris 2.4 kernel patch 101945-34 and later have a bug in their TCP retransmission algorithm that cause excessive retransmissions over slow links, Sun's bug ID is #1233827. A work around for this bug is running the following commands at system boot, e.g., by adding them to /etc/init.d/inetinit (values are in milliseconds): # DO NOT USE THESE CHANGES ON PATCHED SYSTEMS /usr/sbin/ndd -set /dev/tcp tcp_rexmit_interval_min 3000 /usr/sbin/ndd -set /dev/tcp tcp_rexmit_interval_initial 3000 someone else suggested different changes, because with the above retransmits when you do lose a packet take a long time. The following uses a smaller value for the minimal retransmit interval but also limits the outgoing packet size to 536 bytes, so retransmitted packets are smaller and lost packets too. # DO NOT USE THESE CHANGES ON PATCHED SYSTEMS /usr/sbin/ndd -set /dev/tcp tcp_rexmit_interval_min 1000 /usr/sbin/ndd -set /dev/tcp tcp_rexmit_interval_initial 3000 /usr/sbin/ndd -set /dev/tcp tcp_mss_max 536 Patches for this bug have been released, as listed below. You should not combine the patches with the tcp_rexmit_interval setting listed here (patches listed are the first revisions with the fixes; newer versions fixing more problems have been released and can be applied instead) 101945-42: SunOS 5.4: patch for kernel 103169-06: SunOS 5.5: ip driver and ifconfig fixes 103447-03: SunOS 5.5: tcp patch 103448-03: SunOS 5.5_x86: tcp patch 103170-06: SunOS 5.5_x86: ip driver and ifconfig fixes 103582-01: SunOS 5.5.1: /kernel/drv/tcp patch 103630-01: SunOS 5.5.1: ip and ifconfig patch 103631-01: SunOS 5.5.1_x86: ip and ifconfig patch 103581-01: SunOS 5.5.1_x86: /kernel/drv/tcp patch 103632-01: SunOS 5.5.1_ppc: ip and ifconfig patch 103583-01: SunOS 5.5.1_ppc: /kernel/drv/tcp patch |5.56) After install x86 patch 101946-29, I have problems with sockets and TCP/IP throughput. These are two unrelated problems. To fix the socket problem, either copy "sockmod" from an earlier kernel patch such as 101946-12 or install patch 101946-35. The performance problem is a device driver problem that doesn't affect all ethernet cards. To fix this problem, you need to install DU10 or later. |5.57) The commands du and ls show funny block counts on NFSv3 filesystems. The first release of Solaris 2.5 NFS V3 has a bug in calculating the block allocations returned by stat. The server returns a value that is 16 times the right value and the client returns a value 16 times smaller to stat(). The net effect is that unpatched Solaris 2.5 machines look like they're having no problems with each other. But on clients with the bug, files on servers returning the right value will have a block count 16 times too small. This breaks NFS v3 swap files in Solaris 2.5, as swap files will seem to have holes in them and swap will refuse to use them. If you see this problem, your client needs patching. On correct clients served by buggy servers, files will appear to have 16 times as many blocks allocated as they should have. This will generally do no more damage than overly large du(1) or "ls -s" output. There are two ways to fix this: one is to upgrade to Solaris 2.5.1 or later, the second way is to install a patch for bug #1234858. The fix for that bug is current included in the 2.5 kernel update patch (103093/SPARC, 103094/x86). It is important that these patches are installed on clients and servers alike, especially on 2.5 clients using NFS swap files. |5.58) When I halt/reboot my system I get "INIT: failed write of utmpx entry" When the system shuts down, init(1m) updates /var/adm/utmp* to reflect that fact. If you have a separate /var filesystem, this operation will happen *after* /var is unmounted and init complains: INIT: failed write of utmpx entry:"s6" INIT: failed write of utmpx entry:"rb" You can safely ignore these messages. |5.59) Patch installation often fails with "checkinstall" errors. When installing a patch, the Solaris 2.5+ patch installation procedure will execute the script "checkinstall" with uid nobody. If any of the patch files or if any part of the path leading up to the patch directory cannot be read by nobody, an error similar to the following will appear: patchadd . # or ./installpatch . Generating list of files to be patched... Verifying sufficient filesystem capacity (exhaustive method) ... Installing patch packages... pkgadd: ERROR: checkinstall script did not complete successfully .... You can workaround this in two ways, one is to make sure that the user "nobody" can read all patch files and execute a "pwd" in the patch directory or add an account "install" to /etc/passwd: install:x:0:1:installpatch braindamage:/:/bin/true Installpatch and patchadd use "nobody" as a fallback if it cannot find the "install" user. |5.60) Why do I get a CPU-bound rpc.ttdbserverd process? rpc.ttdbserverd is the RPC-based ToolTalk database server. It creates and manages database files kept in TT_DB directories. See ttdbserverd(1M). The problem is usually caused by corrupted entries in some TT_DB directory. The solution is therefore to kill the running rpc.ttdbserverd, and to completely remove all local TT_DB directories. rpc.ttdbserverd will be restarted from inetd when it is needed again. And it will rebuild the TT_DB directories automatically. By default these TT_DB directories are created in the top directory of every filesystem, however one can use /etc/tt/partition_map to tell ttdbserverd where to put them. See partition_map(4) for more details. A second possible cause is running out of filedescriptors, which can be fixed by upping the soft limit on the number of filedescriptors rpc.ttdbserverd starts with. |5.61) What is /proc? Can I safely remove the large files there? The /proc filesystem is a memory image of each process; it's a virtual filesystem that occupies no disk space. /proc is used for programs such as ps(1) and top(public domain) and all the tools in /usr/proc/bin that can be used to examine process state. The only way to remove /proc is to unmount it, but that will break a lot of useful programs. |5.62) What does "named[XX]: Lame server on 'hostname' ...." mean? The new named as shipped in Sun's latest bind patches prints message about all kinds of configuration problems. This particular message indicates that named has learned from a nameserver that a particular domain is served by a particular nameserver. When asked, however, that nameserver denies all knowledge of the particular domain. This is known as a "lame delegation", a reference that points nowhere. If the lame server isn't yours, there's nothing you can do about it. |5.63) I installed Solaris on a new/big disk, but now booting fails. Due to limitations in Openboot PROMs, you can't boot any of the 32bit SPARCs (sun4c, sun4m, sun4d) from a root partition that has parts lying beyond the 2GB mark on a SCSI disk. On systems with really old PROMs (revision 2.5 or less) you need to make the root partition smaller than 1GB. The Ultra PROMs are capable of this, but Solaris prior to version 2.6 also has a bug which effectively prevents Ultras from booting from large root partitions too. Patch 103640-08 or later fixes this for Solaris 2.5.1, so later 2.5.1 HW releases should be OK too. Typical error messages include: bootblk: can't find the boot program boot: cannot find misc/krtld Short read. 0x2000 chars read Read error. |5.64) I have a problem with large disk drives. Various releases of Solaris have different upper limits in the size of the IDE disks they support. For SCSI, there are really no such limits, though older versions of format do not support really large raids. All releases support IDE disks <= 8GB; support for those disks is primarily a BIOS issue on Intel. Support for IDE disks between 8 and 32 GB was added in Solaris 7/SPARC and Solaris 8/Intel. Note the difference in release between architectures. Support for IDE disks over 32 GB was added to Solaris 8 10/00 for both SPARC and Intel. Solaris releases that support IDE disks upto 8GB will truncate larger disks to 8GB. To use such disks to the max after upgrading to a later release of Solaris/SPARC requires zeroing the disk label with dd before relabeling it. Solaris releases that support disks between 8GB and 32 GB will truncate the disk to "real size modulo 32GB". I.e., a 40GB or 72GB disk becomes a 8GB one, a 33GB or 65GB disk becomes 1GB, etc. SPARC/IDE systems have no OpenBoot issues with disks over 8GB and can boot fine from beyond the 8GB/32GB mark. Solaris/Intel didn't support IDE disks > 8GB until release 8; BIOS permitting, Solaris 8 can even boot from beyond the 8GB mark. Older Solaris/Intel releases have a hard time coping with such big disks. |5.65) When I try a network install I get: "WARNING: using boot version 8, expected 9" This error message, with varying version numbers, occurs when a system is booted using an inetboot file for a different revision. This commonly happens when a netinstall image is upgraded without running "add_install_client" again. To fix this, you either need to remove and re-add your install client or copy the proper inetboot files to /tftpboot. |5.66) My Ultra shuts down with "WARNING: THERMAL WARNING DETECTED!!!" The Ultras have environmental sensors that will cause system or board shutdowns in case of overheating. The typical cause of this warning is a blocked airflow or a broken CPU fan. |5.67) Power management shuts down my monitor, but it never comes back. This is caused by a bug in the cgsix device driver; install the appropriate patch (105492 for 2.6) |5.68) I can't seem to disable power management in 2.6! The Solaris 2.6 Xserver insists on always doing power management of the monitor. You need to remove the power management package to get it to stop. |5.69) Power management no longer kicks in when xlock runs Set the XLock.enablesaver resource to "true". By default, xlock disables the X screen saver. The CDE screenlock needs to be set to "blank". |5.70) Orainst 7.3.2 dumps core in 2.5.1 with patches and in 2.6. Oracle has identified a bug in orainst which is triggered by changes made to Solaris. Upgrade to Oracle 7.3.3 or later. |5.71) My dial-on-demand link keeps dialing out, seems DNS related. The nscd (name service cache daemon) tries to keep a hotlist of hosts; these hosts are refreshed regularly so they won't get removed from the cache. This feature should be disabled on systems with dial-on-demand links. Edit /etc/nscd.conf and make the hot-count line for hosts read like this: keep-hot-count hosts 0 |5.72) Processes hang in door_call(), hostname lookups hang. The door_call() on /etc/.name_service_door, is a fast IPC mechanism used to call the name service cache daemon. Usually, nscd speeds things up. However, on systems that do a lot of DNS lookups, all such lookups are single threaded through nscd. Nscd itself is multi-threaded, but the resolver library uses one big global lock. On such systems, performance is often best served by disabling the nscd host cache by editing /etc/nscd.conf like this: enable-cache hosts no |5.73) When using Solaris 2.6, many fonts don't show up properly in Netscape 4. You should install patch 105633-05 or later which fixes the 2.6 font rendering problems. |5.74) When using virtual interfaces in 2.6, the system picks a random source address. How can I fix this? You need to apply a patch: 105786-05: SunOS 5.6: /kernel/drv/ip patch 105787-04: SunOS 5.6_x86: /kernel/drv/ip patch |5.75) A downloaded binary complains "libresolv.so.2: can't open file" Because of various security problems, a new version of BIND was released as a Solaris patch. This patch wasn't binary compatible, so a new resolver library version needed to be made. The binary you downloaded was build on a system with the patch installed, your system lacks the patch or is running a release that is too old. The patch is available for Solaris 2.3 and up and is part of the recommended patch set. |5.76) Ypserv/NIS w/ DNS is very unreliable in Solaris 2.6. This is a known problem, install the following patches: 105552-02: SunOS 5.6: /usr/sbin/rpc.nisd_resolv patch 105553-02: SunOS 5.6_x86: /usr/sbin/rpc.nisd_resolv patch |5.77) When trying to install Solaris 2.x on an Ultra-5/Ultra-10/Ultra-60, it can't find "kernel/unix". The Ultra-5, Ultra-10 and Ultra-60 require Solaris 2.5.1 HW 11/97 or Solaris 2.6 HW 3/98 or later. You can't boot them from older installation media. |5.78) After the system has been up for a while, freemem is only a couple of MB. This is normal. When the system operates, it will gather more and more cached data. E.g., every file ever read will be cached until the memory is needed for some other purpose. Free memory is wasted memory. |5.79) A device driver that worked fine under S2.6 stopped loading under S7 There are two possible causes. It is possible that you're trying to load a 32 bit driver on a 64 bit kernel; that doesn't work as 32 bit and 64 bit code are not compatible in one address space. Drivers that use MT-Unsafe interfaces or that claim to be MT-Unsafe also no longer load in Solaris 7. In both cases, /var/adm/messages should give a pointer to the actual cause |5.80) I get a lot of "late collisions", what are those? Late collisions are usually caused by an ethernet switch and a ethernet host disagreeing on whether to run full-duplex or half-duplex. When a Sun complains about "late collisions", it runs in half-duplex mode but the switch it is connected to thinks it should run in full-duplex mode. In full-duplex mode, collisions cannot occur. |5.81) I can't mount an NFS filesystem, I get "RPC: Program not registered". When the system boots, the NFS server is not enabled unless there are NFS exports listed in /etc/dfs/dfstab. To start the nfs server after adding an entry to dfstab, issue the following command: # /etc/init.d/nfs.server start Note that it isn't currently possible to start the nfs server using the "nfs.server" script unless there are entries in /etc/dfs/dfstab. If you want to do automatic sharing of CDs through vold, you need to export at least one other filesystem if you're running Solaris 2.6 or earlier. |5.82) How do I automatically NFS share inserted CD-Roms? You need to add the following line to /etc/rmmount.conf: share cdrom* -o ro If the system isn't already acting as an NFS server, you'll need to run # /etc/init.d/nfs.server start In Solaris 2.6 and below, you will need to share something in /etc/dfs/dfstab, otherwise mountd and nfsd won't be started. |5.83) I cannot run remote tooltalk sessions on Solaris 8 displays and recently patched older systems. In order to prevent a number of tooltalk security problems, a new method of tooltalk authentication was introduced. This method uses a shared secret authentication system, using $HOME/.TTauthority. This new authentication scheme is the default. Both systems that don't share home directories and systems with older tooltalk client software won't be able to connect. In the case of different home directories/user ids, you will need to transfer TTauthority information. This works much like $HOME/.Xauthority information. The new command to use is ttauth(1) In the case of older client software, you will need to install the relevant ToolTalk patches. These are available for Solaris 2.4 onwards. |5.84) Where is all my memory in use? The Solaris kernel operates on the assumption that "free memory is wasted memory". Pages used for file I/O will not be added to the free list unless they become unreferenced (i.e., the file they belong to is both closed and removed). Such pages are available for re-use but are kept as a disk cache. After some period of operation, Solaris will reach a point where all memory has been used in the past and freemem will be reported as a low number from that point on. In Solaris 8 the filesystem cache was changed significantly; as a result of these changes, cached pages are now reported as free memory even though they still hold cached file data. |5.85) Tcpd prints "connect (refused) from 0.0.0.0" in Solaris 8 and later? The default inetd configuration in Solaris 8 and later have changed the service type for most services from tcp/udp to tcp6/udp6. You'll either need to change them back to tcp/udp or better, upgrade your tcp wrappers to an IPv6 capable version as described in 4.17. |5.86) The permissions on /tmp are wrong after a reboot? The tmpfs filesystems takes on the permissions from the underlying mount point. In order to fix /tmp, you need to boot single user and execute the following two commands: chmod 1777 /tmp chown root:sys /tmp |+5.87) After upgrading to Solaris 9 vold no longer mounts CDs. | Starting with Solaris 9, vold requires an RPC service in inetd.conf: | 100155/1 tli rpc/ticotsord wait root /usr/lib/smedia/rpc.smserverd \ | rpc.smserverd | Note that rpc/ticotsord services are not reachable from the network | so even if it had a security hole it would not be remotely | exploitable. 6. SOFTWARE DEVELOPMENT 6.1) Where is the C compiler or where can I get one? Where have you been? :-) Sun has dropped their old K&R C compiler, supposedly to create a market for multiple compiler suppliers to provide better performance and features. Here are some of the contenders: 1) SunPro C: <http://www.sun.com/sunsoft/> SunPro, SMCC, and various distributors sell a new ANSI-standard C compiler on the unbundled (extra cost) SPARCcompiler/SPARCworks CD-ROM. There are some other nice tools there too, like a "make tool" and a visual diff (interactive diff). You have to license and pay per concurrent user. 2) Apogee compilers <http://www.apogee.com/> Apogee sells C, C++, f77 and f90 compilers, mainly for SPARC. These compiler include the KAP preprocessors from Kuck and Associates. 3) Cygnus GCC: <http://www.cygnus.com/> Cygnus Support and the Free Software Foundation make the GNU C compiler for Solaris, a free software product. Source code and ready-to-run binaries can be installed from the CDware CD (Volume 4 or 5). Like all GNU software, there are no restrictions on who can use it, how many people can use it at a time, what machines it can be run on, or how many copies you can install, run, give away, or sell. Cygnus sells technical support for these tools, under annual support contracts. The Cygnus distribution includes: gcc (ansi C compiler), gdb (good debugger), byacc (yacc repl), flex (lex repl), gprof, makeinfo, texindex, info, patch, cc (a link to gcc) The Cygnus compiler on uunet is starting to show its age a bit. If you want to compile X11R5, you can get the latest version of GCC in source code, from the usual places (prep.ai.mit.edu or one of the many mirrored copies of it). Build and install that compiler using the Cygnus gcc binaries. Or get tech support from Cygnus; they produce a new version for their customers every three months, and will fix any bug you find. 4) Gcc. Gcc is available from the GNU archives in source form. You need gcc 2.3.3 or later, and you should prefer gcc 2.8.0 or later as it works better with Solaris 2.x include files. You should not use GNU as or GNU ld. Make sure you run just-fixinc if you use a binary distribution. Better is to get a binary version and use that to bootstrap gcc from source. GNU software is available from: ftp://prep.ai.mit.edu/pub/ gatekeeper.dec.com:/pub/GNU ftp.uu.net:/systems/gnu ftp://wuarchive.wustl.edu/mirrors/ nic.funet.fi:/pub/gnu When you install gcc, don't make the mistake of installing GNU binutils or GNU libc, they are not as capable as their counterparts you get with Solaris 2.x. 5) Info on other compiler vendors will be added if you send us some. |*6.2) Which packages do I need to install to support a C compiler? Solaris ships with everything you need, with the exception of the compiler itself. Solaris ships with the include files, make, an assembler, linker and libraries. All this stuff lives in /usr/ccs/bin (add it to your PATH before /usr/ucb if that's in your PATH as well) /usr/ccs/lib and /usr/include. If you still can't find it, make sure you have the following packages installed on your system: for tools (sccs, lex, yacc, make, nm, truss, ld, as): | SUNWbtool, SUNWsprot, SUNWtoo, SUNWcpp for libraries & headers: SUNWhea, SUNWarc, SUNWlibm, SUNWlibms SUNWdfbh, SUNWcg6h, SUNWxwinc, SUNWolinc, | SUNWxglh, SUNWlibC, SUNWzlib, SUNWscpu for 64 bit development: SUNWarcx, SUNWbtoox, SUNWdplx, SUNWscpux, SUNWsprox, | SUNWtoox, SUNWlmsx, SUNWlmx, SUNWlibCx, SUNWzlibx for ucb compat: SUNWsra, SUNWsrh These packages are all on the Solaris 2.x CDs, except that some packages may only exist in some releases and not in others. Some packages may be on separate CDs, such as the "Desktop/CDE" CD, but all are part of the Solaris "bundle". | Some of the above packages may do not exist in all Solaris releases. 6.3) Where has ranlib gone? The functionality provided by ranlib in SunOS 4.1.x is now merged into ar. It is no longer necessary to run ranlib on archive libraries. Fix makefiles that require ranlib by replacing it with "/bin/true". A no-op ranlib has been reintroduced in 2.5. 6.4) What do I need to compile X11R5? There are several "patch kits" for X11R5 under Solaris 2.1. Most of them require gcc 2.3.3 or later and unless you are running gcc 2.8.0 or later you must have run "fixincludes" when you install the gcc software. The recommended patchkit is R5.SunOS5.patch.tar.Z available from ftp://ftp.x.org/. It works with gcc (2.3.3 or later) and SunPRO C. X11R6 compiles out-of-the-box on Solaris 2.3. 6.5) I can't compile X11R6 on Solaris 2.4 There are several possible problems when compiling X11R6 on Solaris 2.4, all are solved after applying R6 fixes upto and including fix-12. These problems are: The compilation of xc/programs/Xserver/Xext/shm.c will fail with a redefinition of shmat(). Compilation errors when using SC 2.0.x. See also 6.6 6.6) X11R6 on Solaris 2.4 won't run. Xinit dies with "User Signal 1". Xterms won't die. Dired doesn't work in emacs-19. Some changes in libc.so and libthread.so break the way libthread is linked with libX11.so. The most noticeable symptoms are failing signal handling in xinit, xterms that don't die after the inferior shell process exits and emacs-19 hanging after starting dired. Apply all fixes upto fix-12 to the X11R6 sources. Remember to change OSMinorVersion to 4 in xc/config/cf/sun.cf as well and use "make Everything" or "make World", not just "make". Make sure you change the right OSMinorVersion in sun.cf, the first one is the x86 minor version, the second one is SPARC one. Change the one appropriate for your system or change both. The resulting R6 will not run on Solaris 2.3 or earlier. If you want to have the same set of binaries for Solaris 2.3 and 2.4, you need to disable threaded X altogether by changing "#define ThreadedX YES" to "#define ThreadedX NO" in sun.cf. Note that you must reinstall the X libraries with "make install" before things start working. There is no need to reinstall anything but libX11.so. Xterm, emacs etc., should start working after the change to libX11 is installed. Check your newly installed libX11 with dump -Lv libX11.so.6. If it still shows libthread as "NEEDED", the rebuild didn't work correctly. Double check your changes. (If you previously used the patch from the FAQ, make sure you remove it before applying fix-12.) For multi-threaded X to work it necessary to install patch 101925-02 to fix problems in header files [2.4]. Unless you are running gcc 2.8.0 or later, you need to reinstall gcc or re-run just-fixinc after installing that patch. 6.7) I get undefined symbols when compiling R6 in Solaris 2.2. Solaris 2.2 doesn't have the full thread support required by X11R6. Compile R6 without multi-thread support or upgrade to 2.3 or later. 6.8) After compiling X11R6 with gcc 2.7.0, X programs won't find their libraries. Someone at GNU made a bad mistake by adding a the following misfeature to gcc 2.7.0: in the absence of -R options, specify a -R option for each -L option on the commandline. While this looks "neat" on the surface, this makes ld ignore LD_RUN_PATH, which is the mechanism used by R6 to set the RPATH. It also introduces a security hole, as it sets a relative RPATH for all X executables, including the set-uid ones. Workaround: remove the following bit from the gcc-lib/.../2.7.0/specs file: %{!static:%{!R*:%{L*:-R %*}}} then rebuild X. This is fixed in gcc 2.7.1 6.9) How can I run X11R6 on my SS4 w/ TCX? Although it is possible to switch the TCX to dumb cg3 mode and run X11R6 on that, Matt Landau of the X consortium said the following on the matter: "But why would you want an accelerated 24-bit framebuffer to behave like a dumb 8-bit framebuffer under Solaris 2? "OpenWindows versions 3.3 and 3.4 (bundled with Solaris 2.3 and Solaris 2.4 respectively) are perfectly reasonable R5-based implementations of X, with a perfectly good R5 server that also does DPS and takes advantage of the TCX. They have none of the brokenness associated with the old X11/NeWS server from OpenWindows versions 3.2 and before. "Of course, if you want R6 libraries and apps, you can build R6 and run R6 applications against the OpenWindows 3.4 server, and still get full benefit of the TCX. Works just fine." 6.10) Can I run X11R6 on my SX, ZX, TCX, Creator, Creator3D or Elite3D? X11R6.4 and earlier do not support any of Sun's new framebuffers, including all PCI framebuffers. Run Sun's Xsun instead, it works fine. |6.11) I can't get perl 4.036 to compile or run. You really should be using perl 5; perl 4.036 hasn't been updated since 1992 and is considered "dead". Run Configure, and use the solaris_2_0 hints, *don't* use the solaris_2_1 hints and don't use the config.sh you may already have. First you must make sure Configure and make don't find /usr/ucb/cc. (It must use gcc or the native C compiler: /opt/SUNWspro/bin/cc) Some questions need a special answer. Are your system (especially dbm) libraries compiled with gcc? [y] y yes: gcc 2.3.3 or later uses the standard calling conventions, same as Sun's C. Any additional cc flags? [ -traditional -Dvolatile=__volatile__ -I/usr/ucbinclude] -traditional -Dvolatile=__volatile__ Remove /usr/ucbinclude. Any additional libraries? [-lsocket -lnsl -ldbm -lmalloc -lm -lucb] -lsocket -lnsl -lm Don't include -ldbm, -lmalloc and -lucb. Perl 5 compiles out of the box and comes preinstalled with Solaris 8 and later. 6.12) I can't get sockets to work with perl. Some of the socket constants have changed. E.g., SOCK_STREAM now has a value of 2, whereas SunOS 4.x uses a value of 1. Use perl5 modules and the symbolic values they define instead. 6.13) I have problems compiling MH 6.8.3 The MH config file for Solaris that comes with MH 6.8.3 should work OK, but there are some other problems: One of the Solaris 2.x headers conflicts with mhn.c and inc doesn't know how to separate messages based on the Content-Length header. A fix for both problems can be found in: | <ftp://ftp.science.uva.nl/pub/solaris/mh-6.8.3-diff> 6.14) I can't get XV 3.x to compile or run correctly. You need to get xv-3.x from ftp.cis.upenn.edu:/pub/xv. Don't use xv-3.01 from ftp.x.org. The latest version, xv-3.10, compiles fine w/o any of the ucb stuff. 6.15) What happened to NIT? What new mechanisms exist for low-level network access? See man page DLPI(7). Try NFSWATCH 4.2 for sample code using DLPI. It is available by ftp from: ftp.ecn.purdue.edu:/pub/davy/nfswatch4.3.tar.gz and gatekeeper.dec.com:/pub/net/ip/nfs/nfswatch4.3.tar.gz Better yet, FTP the paper "How to Use DLPI in Solaris 2.x" by Neal Nuckolls of Sun Internet Engineering. Look in these FTP directories: ftp://opcom.sun.ca/pub/drivers/ http://www.freebird.org/hints/papers/{dlpi,npi,tpi}.ps.Z 6.16) Where are all the functions gone that used to be in libc? The C library has exploded. The manual page may give an indication where to find a specific function. Those libraries are essentially split over two directories: /usr/lib /usr/ccs/lib. Important libraries: /usr/lib: libsocket - socket functions libnsl - network services library /usr/ccs/lib: libgen - regular expression functions libcurses - the SysVR4 curses/terminfo library. In Solaris 7 the contents of /usr/ccs/lib was moved back to /usr/lib. See Intro(3) for more details. 6.17) I'm still missing some functions: bcopy, bzero and friends. They are in /usr/ucblib/libucb.so. The b* functions are replaced with the ANSI-C equivalents. Look in the Solaris porting FAQ for more details. In Solaris 2.5, they're back in libc.so, together with many other commonly used BSD functions. 6.18) Can I use the source compatibility package to postpone porting? Not really. The Source code compatibility package is compatible with BSD 4.2, not SunOS 4.1.x. The consensus is that the library is broken beyond usability. If you use libucb to pick up some functions you need, it is often best to specify it *after* all other libraries and after libc with: -lc -L/usr/ucblib -R/usr/ucblib -lucb or preferably: -lc /usr/ucblib/libucb.a 6.19) Why doesn't readdir work? It chops the first two characters of all filenames. You're probably linking with libucb and didn't read question 6.18. (Readdir in libucb.so wants you to include sys/dir.h, but many SunOS 4.1.x programs included <dirent.h>, consequently, you're mixing native <dirent.h> struct dirent with libucb readdir(). The symptom of this mixup is that the first two characters of each filename are missing. Make sure you use a native compiler (default /opt/SUNWspro/bin/cc, which may not be in your PATH), and not /usr/ucb/cc. 6.20) Why do I get undefined symbols when linking with curses/termcap? It is easy to mixup the BSD libcurses and the SVR4 libcurses. One lives in /usr/ucblib, the other in /usr/ccs/lib, when you've installed SUNWarc. Note that when you specify: -L/usr/ucblib -lucb -L/usr/ccs/lib -lcurses you will pick the *ucb* version of libcurses, not the SVR4 version. If you always put libucb last, as recommended in 6.18, you will have no such problem. 6.21) Where are the Motif includes and libraries? Starting with Solaris 2.4, the package SUNWmfrun is included with the base OS. It is installed under the directory /usr/dt, where all the CDE stuff is installed (dt stands for desktop). There are no Motif imake templates nor is mwm shipped with the base OS; only the mwm -like Dtwm is shipped. Remember that you must link with -R/usr/dt/lib. 6.22) When I call semctl(), my program crashes. It works fine elsewhere. The fourth argument to semctl() is a "union semun" that you need to define yourself. That your programs works on other systems is sheer luck. The argument passing convention on SPARC/V8 cause your luck to run out. Instead of passing the contents of small structs and unions in registers, a copy of the struct/union is made on the stack and a pointer to that struct is passed. In short, on SPARC, passing a union containing an integer and just an integer, both by value, is not the same thing. On other systems it sometimes is. Wrong, but it may work on other systems: semctl(sem_fd, 0, SETVAL, 1); Right: union semun { int val; struct semid_ds *buf; ushort *array; } arg; arg.val = 1; semctl(sem_fd, 0, SETVAL, arg); 6.23) Traceroute to Solaris 2.x machines gives many timeouts. Solaris 2.4 and later (and Solaris 2.3 w/ high rev kernel jumbo patches) limit the number of ICMP error message to one per 500 milliseconds. To switch off this feature, use: /usr/sbin/ndd -set /dev/ip ip_icmp_err_interval 0 In Solaris 8 the rate limiting mechanism was changed and traceroute will get all responses now as the new mechanism accepts short burst even though the rate limit is still in effect. 6.24) I have problems linking my application statically. In Solaris 2.x static linking is not supported for any of the system libraries. All the functions that use /etc/nsswitch.conf (getXXXbyYYY, getpwXXX, etc) require the dynamic linker to load the code to load these functions. It is not possible to write configurable/extensible functions in such a way that dynamic linking is not required. E.g., you can add your own nsswitch.conf backend which would not be known to programs statically linked to only the standard backend code. Programs that link statically against any of the OS libraries may not run in the next release and are not ABI compliant. Programs that link statically don't get some dynamic performance enhancements found in the shared libraries: using hardware multiply/divide on systems that support it; using fast mem*() operations on UltraSPARC etc. And you won't pick up performance enhancements in next releases: e.g., Solaris 2.5 comes with a 4x faster fread/fwrite and the "Name Server Cache Daemon". If you don't care about ABI compliance, i.e., you won't ship your program as a product and don't care that you may need to recompile after an OS upgrade, here are some of your options: Link statically against all but libdl: cc -Bstatic .... -Bdynamic -ldl -Bstatic Link against dl* stubs (gethostbyXXX, getpwXXX etc won't work any longer): char *dlopen() { return 0;} int dlclose() { return 0;} char *dlsym() { return 0;} char *dlerror() { return "dynamic linking not loaded";} If you don't want any dependencies on /usr, link against the dynamic libs in /etc/lib: cc -Bstatic ... -Bdynamic -R/etc/lib -Wl,-I/etc/lib/ld.so.1 -ldl -Bstatic .... If you still get undefined symbols, check with ldd for all your libraries if they have any dynamic dependencies. E.g., % ldd /usr/lib/libsocket.so.1 libnsl.so.1 => /usr/lib/libnsl.so.1 libdl.so.1 => /usr/lib/libdl.so.1 libc.so.1 => /usr/lib/libc.so.1 libintl.so.1 => /usr/lib/libintl.so.1 libw.so.1 => /usr/lib/libw.so.1 tells you that if you want to link libsocket statically, you need to link with -lnsl -ldl -lc -lintl and -lw as well. There is no way to statically link 64 bit executables; no 64 bit archive libraries are shipped with Solaris. 6.25) I get '"/usr/platform/SUNW,Ultra-1/lib/libc_psr.so.1": not in executable format: format not recognized' from gdb on my Ultra. gdb needs to be updated to understand the "V8+" executable format. Either install gdb 4.16 or later, or update the gdb 4.15.1 distribution with the following patch to bfd/elf32-sparc.c and include/elf/common.h: *** gdb-4.15.1/bfd/elf32-sparc.c Fri Nov 3 12:30:15 1995 --- elf32-sparc.c Thu Nov 23 14:44:37 1995 *************** *** 1486,1491 **** --- 1486,1492 ---- #define TARGET_BIG_NAME "elf32-sparc" #define ELF_ARCH bfd_arch_sparc #define ELF_MACHINE_CODE EM_SPARC + #define ELF_MACHINE_ALT1 EM_SPARC32PLUS #define ELF_MAXPAGESIZE 0x10000 #define elf_backend_create_dynamic_sections \ _bfd_elf_create_dynamic_sections *** gdb-4.15.1/include/elf/common.h Fri Nov 3 20:20:25 1995 --- common.h Thu Nov 23 14:20:07 1995 *************** *** 83,88 **** --- 83,91 ---- #define EM_SPARC64 11 /* SPARC v9 (not official) 64-bit */ #define EM_PARISC 15 /* HPPA */ + + #define EM_SPARC32PLUS 18 /* Sun SPARC 32+ */ + #define EM_PPC 20 /* PowerPC */ /* If it is necessary to assign new unofficial EM_* values, please pick large 6.26) How can I make Gdb work with Sun's C compiler? Sun's C compiler only stores symbolic debugging information in the .o files. Gdb wants to find that information in the executable. You can force the symbols in the executable by passing the "-xs" commandline option to Sun's C compiler. 6.27) Does Solaris have problems with dates in the year 2000 and after? Internally, Solaris maintains time as the number of seconds since 1970-01-01 00:00:00 UTC (not counting leap seconds). This counter won't have any problem with dates in the year 2000; since it is maintained as a 32-bit signed integer value in 32 bit kernels and applications, it will work correctly through 2038-01-19 03:14:07 UTC. 64-bit Solaris uses a 64 bit time value which will last longer than the current estimated age of the universe; but 32 bit applications, such as most Solaris 7 applications, still use 32 bit time. Also, 64-bit applications may have trouble with time stamps outside the 32-bit range. For example, Solaris 7 supports only 32-bit time stamps on ordinary files, the 64-bit ctime and asctime functions have undefined behavior for time stamps after the year 9999, and the 64-bit localtime function has undefined behavior for huge time stamps (time stamps after the year INT_MAX + 1900 == 2147485547). Though the Solaris kernel itself shouldn't have any problems with the year 2000, applications themselves may have problems, partly because some application writers unwisely chose to represent dates using two-digit years, and partly because some application writers mistakenly thought that localtime returns the year modulo 100, when it actually returns the year minus 1900. These kinds of problems are rarer in Solaris than with typical mainframe applications, but they sometimes do occur. A year 2000 project at Sun is reviewing all libraries, unbundled <http://www.sun.com/y2000/> software, and some 3rd party apps in search of potential year 2000 problems, so that they are resolved well before the big day. Solaris 2.6 and Solaris 7 are meant to be year-2000 compliant. However, some y2000 bugs have been found after Solaris 2.6 was released. A few more bugs were found after Solaris 7 was released. Y2000 patches are available from SunSolve Online, free of charge. If you have the following supported SMCC hardware, you must also patch your PROM monitor to get year-2000 compliance: - SPARCserver 1000, 1000E, 2000, 2000E - Sun Enterprise 3000, 4000, 5000, 6000, with PROM version 3.2.9 or earlier The SPARCservers will need to have their OBP PROMs swapped. The PROM bugs do not affect day-to-day operation or booting, only output from diagnostics and self-tests is affected. All other supported SMCC hardware should be OK as is. (Note that the older 68000-based hardware is no longer supported.) Sun-maintained Solaris applications with known year-2000 problems as of Solaris 2.5.1 (unpatched) include the following. * SCCS files store only the last two digits of the year, so standard SCCS stops working after 1999. Sun works around this problem by having SCCS interpret two digit years to be in the date range 1969-2068; this means the revised SCCS will stop working after 2068. * The Solaris 1 `date' command can't set the clock past 1999. This bug is partly fixed in Solaris 2 `date', which supports both 2-digit and 4-digit years; however, in Solaris 2 you should use 4-digit years when setting the date, to avoid some remaining bugs with 2-digit year handling. * The following programs are known to have minor bugs related to using year-1900 instead of year modulo 100 when generating diagnostics, temporary file names, and the like: atq fsck listen passwd sar timex ufsdump uucico uustat uuxqt xterm * The -me, -mm, and -ms troff macro packages all assume that the current date is before January 1, 2000. * `sortbib' mishandles bibliographies containing 2-digit years that span the year-2000 boundary. * `ckdate' rejects years after 1999. * Problems have been reported with installing Solaris on machines whose hardware date is past 1999. * The filemgr `find after' and `find before' operations have only 2-digit inputs for years, and mishandle dates after 1999. * cm (the calendar manager) mishandles dates after 2000-02-29. * In Openstep, NSCalendarDate, NSDate*, Mail, and Preference need enhancements and fixes for years past 1999. In addition, user applications that invoke `getdate' and `strptime' on 2-digit years are advised to check their assumptions carefully. Patches for year 2000 problems will be made available for all releases not EOLed at January 1, 1995, in keeping with the 5 year support window. This includes the Solaris releases 2.5.1, 2.5, 2.4 and 2.3 as well as SunOS 4.1.3_U1B and 4.1.4. Solaris 2.x Y2000 patches can be freely downloaded from Sun's public patch page. <http://sunsolve.Sun.COM/pub-cgi/us/pubpatchpage.pl> 6.28) I can't seem to get older gcc releases to work under Solaris 2.6 As with all new Solaris releases, you need to reinstall gcc after upgrading, unless your are running gcc 2.8.0 or later. Unfortunately, Solaris 2.6 include files don't get properly fixed by fixincludes. To fix this, apply the following patch to fixinc.svr4 before building gcc. *** ./fixinc.svr4.org Thu Jun 15 23:03:29 1995 --- ./fixinc.svr4 Thu Sep 4 13:41:29 1997 *************** *** 189,194 **** --- 189,195 ---- s/__STDC__[ ][ ]*==[ ][ ]*1/defined (__STRICT_ANSI__)/g s/__STDC__[ ][ ]*!=[ ][ ]*0/defined (__STRICT_ANSI__)/g s/__STDC__ - 0 == 0/!defined (__STRICT_ANSI__)/g + s/__STDC__ - 0 == 1/defined (__STRICT_ANSI__)/g /^typedef[ ][ ]*[unsigned ]*long[ ][ ]*[u_]*longlong_t;/s/long/long long/ ' $2/$file > $2/$file.sed mv $2/$file.sed $2/$file 6.29) Gdb doesn't fully work on Solaris 2.6. Solaris 2.6 defines a new interface for interaction between the debugger and the runtime linker. Previous releases don't support any such interface, so debuggers would use unpublished hooks. The following patch to gdb 4.16 fixes this problem. --- ./gdb/solib.c.org Sat Mar 30 06:58:51 1996 +++ ./gdb/solib.c Sat Sep 6 14:48:18 1997 @@ -67,6 +67,7 @@ #ifdef SVR4_SHARED_LIBS static char *solib_break_names[] = { + "rtld_db_dlactivity", "r_debug_state", "_r_debug_state", "_dl_debug_state", 6.30) I can't get gdb to compile with Sun's C compiler Older versions of Solaris didn't declare __builtin_alloca; the prototype provided for it with gdb doesn't agree with the one supplied with current Solaris versions. --- ./libiberty/alloca-norm.h.org Thu Jun 29 04:15:41 1995 +++ ./libiberty/alloca-norm.h Sat Sep 6 14:50:35 1997 @@ -5,7 +5,7 @@ #else /* not __GNUC__ */ #ifdef sparc #include <alloca.h> -extern char *__builtin_alloca(); /* Stupid include file doesn't declare it */ +extern void *__builtin_alloca(); /* Stupid include file doesn't declare it */ #else #ifdef __STDC__ PTR alloca (size_t); 7. KERNEL PARAMETERS 7.1) Where can I find a list of all Solaris kernel parameters? The most important kernel parameters can be found in the tunable parameters guide. <http://docs.sun.com:80/ab2/coll.709.2/SOLTUNEPARAMREF/> It's focus is Solaris 8 but sufficient history is included to make the guide extremely useful for earlier releases. There is also a large number of kernel variables of which the main purpose is debugging and testing or even disabling of new(er) algorithms that are seen to be risky. Such variables are typically not documented, except in workarounds when problems do arise. |7.2) How can I guard my system against stack buffer overflow exploits? By default, the Solaris kernel maps the system stack RWX; this behaviour is mandated by the SPARC V8 ABI. Since an non-executable stack gets in the way of certain classes of security bug exploits, a feature was added to Solaris 2.6 that allows system administrators to remove the "X" protection from the stack. To enable this feature, add the following to /etc/system: * Foil certain classes of bug exploits set noexec_user_stack = 1 * Log attempted exploits set noexec_user_stack_log = 1 This is no general "cure-all" protection for buffer overflow exploits. It may also break certain SPARC V8 ABI conforming programs. This feature also requires hardware support; it is only available on UltraSPARC (sun4u), sun4d and sun4m systems. The SPARC V9 ABI no longer maps the stack executable, so 64 bit applications have less to worry about. 32-bit applications running on a 64-bit kernel are not so lucky. 7.3) How can I restrict the number of processes per user? Set the following in /etc/system: set maxuprc = <num> 7.4) What purpose does the maxusers variable serve? The maxusers variable has nothing to do with the number of user allowed on a system. It's one big knob that scales a number of other parameters simultaneously. The standard settings and derivations are more or less as follows, using /etc/system syntax: * The big knob, scales automatically set maxusers = <amount of available physical memory in MB> * Maximum number of allowable processes; currently at most 30000 set max_nprocs = 10 + 16 * maxusers * Max processes per user (5 are reserved for the super user) set maxuprc = max_nprocs - 5; * Number of quota structures (need one per user per filesystem * w/ quotas) set ndquot = maxusers * NMOUNT / 4 + max_nprocs * Maximum size of the directory name lookup cache (DNLC) set ncsize = 4 * (max_nprocs + maxusers) + 320 set ufs_ninode = ncsize 7.5) How can I have a clock resolution better than 10ms? Starting with Solaris 2.6, this can be achieved with the following entry in /etc/system: set hires_tick = 1 This will set the system hz value to 1000. In principle, you can also set "hz" directly, but that is not supported nor recommended: * Get 0.1 ms clock resolution/timer granularity set hz = 10000 Solaris 8 introduces the cyclic subsystem; this allows for timers of much better granularity without burdening the system with a high interrupt rate. High resolution timers are available to root only using timer_create(3rt) with a clock_id of CLOCK_HIGHRES. 7.6) How can I have more than 16 groups per user? The number of groups per user can be increased to at most 32: set ngroups_max = 32 This setting may give rise to NFS interoperability problems, as typical NFS servers only support 16 groups when using AUTH_SYS/AUTH_UNIX. The other NFS authentication mechanisms map "netids" to usernames on the servers and can support more than 16 groups. 7.7) How can I disable _POSIX_CHOWN_RESTRICTED? My users want to chown files? Add the following to /etc/system: set rstchown = 0 Note that this defeats quotas. 7.8) How can I make the NFS server ignore unprivileged clients? In a restricted environment, i.e., an environment where the administrator controls root access, you can enhance NFS security by setting the "NFS_PORTMON" variable. This variable is set in /etc/system, like this: * Prior to Solaris 2.5 set nfs:nfs_portmon = 1 * Solaris 2.5 and later set nfssrv:nfs_portmon = 1 8. ACKNOWLEDGEMENTS Most of this material is either written by me or sent to me directly. Some of it is cribbed shamelessly from USENET postings in several groups. Thanks to all people who contributed to this FAQ, you know who you are. The list is too long to be included in this FAQ. --- End of Solaris 2.x FAQ -- Maintained by Casper Dik <Casper.Dik@Holland.Sun.COM> --- -- Expressed in this posting are my opinions. They are in no way related to opinions held by my employer, Sun Microsystems. Statements on Sun products included here are not gospel and may be fiction rather than truth.