Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Squid errors

    pfSense Packages
    17
    60
    41.6k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sullrich
      last edited by

      @Cyrandir:

      Has this been comitted yet? I've manually done these changes, and they have really helped out my squid installation! Nice help Emanuel!

      Not as of yet.

      1 Reply Last reply Reply Quote 0
      • M
        Myntric
        last edited by

        No commits as of yet.  I can commit these changes, but I'm in the midst of a rewrite of one of the components to try and make it a little faster in writing the configuration.  It's pretty inefficient at this point.  I'll see what I can do.

        1 Reply Last reply Reply Quote 0
        • E
          EmanuelG
          last edited by

          @Cyrandir:

          Has this been comitted yet? I've manually done these changes, and they have really helped out my squid installation! Nice help Emanuel!

          Hi Cyrandir, it's great I can help, but be aware that the permision changes doesn't survive a reboot, so you can do one of two things:

          1- Modify the /usr/local/etc/rc.d/squid.sh and add the two commands you ran before:
                chgrp squid /dev/pf
                chmod g+rw /dev/pf

          2- Modify the /etc/devfs.conf file and add at the end this lines:
              own pf root:squid
              perm pf 0640

          This is to make sure the changes are re-applied every time your server boots, at least it works well for me.

          Hope this help

          "I hear and I forget. I see and I remember. I do and I understand."
          Confucius

          1 Reply Last reply Reply Quote 0
          • C
            Cyrandir
            last edited by

            Thanks! I'll do that

            1 Reply Last reply Reply Quote 0
            • E
              EmanuelG
              last edited by

              Hi Myntric,

              I'm using the last package you release, and it works really good, but seems like it needs to change perms for squid group to "/var/run/squid.pid".

              Besides, i was thinking that would be nice to have a squid entry in the "Status/Services" page in the GUI.  Is it much dificult? I have no skills in editing php or xml.

              Thanks again for your help!

              "I hear and I forget. I see and I remember. I do and I understand."
              Confucius

              1 Reply Last reply Reply Quote 0
              • C
                Cyrandir
                last edited by

                I agree that a service status entry would be highly useful

                1 Reply Last reply Reply Quote 0
                • ?
                  Guest
                  last edited by

                  This may have already been covered in the lists, but I'm recording them here for posterity as well.  After installing the squid package to my 0.93.2 box I had to make the following changes:

                  mkdir /var/squid/cache
                  chown squid: /var/squid/cache
                  chown squid: /var/squid/logs
                  squid -z -f /usr/local/etc/squid/squid.conf

                  in squid.conf, you have to make the following changes to the ACLs ( I believe this to be a bug in the WebGUI but I haven't looked at the code yet ):

                  ensure that acl all's src is set to 0.0.0.0/255.255.255.0
                  ensure that acl localnet's src is set to your local network (or whatever networks you want to traverse your squid proxy)
                  add the line: http_access allow localnet

                  at this point you can start squid and you should be off and running.

                  1 Reply Last reply Reply Quote 0
                  • M
                    Myntric
                    last edited by

                    The code is actually in there to do the chmod's and such during the install, but it is not executing properly.  I've been working with colin on this.  Due to the complexity with all of the GUI and integration with other items such as SquidGuard, it may come down to where I have to write this in full-fledged PHP and use the packaging system for the install portion, but I'd like to make this version as stable as possible in the meantime.  Thanks for your help!

                    Mike

                    1 Reply Last reply Reply Quote 0
                    • ?
                      Guest
                      last edited by

                      Mike,

                      There's a big bug in the ACL section of the WebGUI.  When adding networks to the allow, section, only one network is captured, and its appended to the "all" ACL rather than the "localnet" ACL.  Any additional networks added are ignored, although they're slumped together one on top of the next in the WebGUI display.  It might be better to either create a file and write networks to that file and have squid.conf point to that file.  Alternatively, you might have the localnet ACL get the networks bound to whichever NIC squid should be bound to.

                      1 Reply Last reply Reply Quote 0
                      • E
                        EmanuelG
                        last edited by

                        @submicron:

                        Mike,

                        There's a big bug in the ACL section of the WebGUI.  When adding networks to the allow, section, only one network is captured, and its appended to the "all" ACL rather than the "localnet" ACL.  Any additional networks added are ignored, although they're slumped together one on top of the next in the WebGUI display.  It might be better to either create a file and write networks to that file and have squid.conf point to that file.  Alternatively, you might have the localnet ACL get the networks bound to whichever NIC squid should be bound to.

                        Also, i have found that if you add "unrestricted IPs" in the ACL of the WebGUI, the are stored in the acl file just as they were writed down in the WebGUI, this means, separated by a semi-colon, insted of one IP address per line, which generate errors when you start the service.  If you edit the acl_unrestricted_ip.acl file, and put one IP address per line, it shows funny in the WebGUI page.

                        Thanks again for this great piece of software!

                        "I hear and I forget. I see and I remember. I do and I understand."
                        Confucius

                        1 Reply Last reply Reply Quote 0
                        • ?
                          Guest
                          last edited by

                          Mike,

                          I know you'll work on these issues when you get time.  Is it better for us to keep posting to this thread or would you rather we file bug reports as we come across issues?

                          1 Reply Last reply Reply Quote 0
                          • M
                            Myntric
                            last edited by

                            @submicron:

                            Mike,

                            I know you'll work on these issues when you get time.  Is it better for us to keep posting to this thread or would you rather we file bug reports as we come across issues?

                            I think the this thread for now will work best for me.  Thanks!

                            Mike

                            1 Reply Last reply Reply Quote 0
                            • B
                              BBMitch
                              last edited by

                              I just installed Squid 2.5.11_3 on 0.90 - I know, there's a newer release… ;-)
                              After install, I did this:
                              chgrp squid /dev/pf
                              chmod g+rw /dev/pf
                              /usr/local/sbin/squid -z -f /usr/local/etc/squid/squid.conf
                              Navigated to: Services->Squid
                              Proxy Listening Interface: LAN
                              Transparent Proxy: CHECKED
                              Log Enabled: CHECKED
                              Visible Hostname: XXX.com
                              Cache Administrator Email: support@XXX.com
                              Error Message Language: English
                              And then pressed save:
                              Warning: fopen(/usr/local/etc/squid/advanced/acls/src_subnets.acl): failed to open stream: No such file or directory in /usr/local/pkg/squid_ng.inc on line 487 Warning: fwrite(): supplied argument is not a valid stream resource in /usr/local/pkg/squid_ng.inc on line 488 Warning: fclose(): supplied argument is not a valid stream resource in /usr/local/pkg/squid_ng.inc on line 489 Warning: Cannot modify header information - headers already sent by (output started at /usr/local/pkg/squid_ng.inc:487) in /usr/local/www/pkg_edit.php on line 183

                              Are the missing files (I checked) not a part of the package?
                              I have set squid up on an older version before - no problems there - did I miss something or is it in a state of flux at the moment?

                              Thanks!

                              1 Reply Last reply Reply Quote 0
                              • J
                                Jesse7
                                last edited by

                                I just installed .94  I havn't had a chance to get .94.4 yet but I got pretty much the same thing.  I changed some options and clicked save and an error similar to that appeared.  I was on the first tab of the setup page.  I got similar errors from the second tab after changing an option or two and perhaps from the third tab also.  On the tab you enter ip and domain ips etc after hitting save I got no errors.

                                I refreshed all the pages I changed settings on and they seemed to be set to what I changed them too.

                                I didn't bother posting it here because I'm not on the most current version.

                                1 Reply Last reply Reply Quote 0
                                • M
                                  Myntric
                                  last edited by

                                  Interesting.  The last commit was a few weeks ago and while quite a bit was changed, I was under the impression that the default install worked.  The package is definitely in a state of flux at the moment.  In speaking with Colin, it seems that the best way to design a flexible Squid package and allow the integration with SquidGuard, HAVP, ClamAV, or whatever is to code in pure PHP while using the packaging system simply for the install/deinstall and such.  This would allow much more flexibility. I've started the process and don't expect to have a commit for little while, but am plugging away and trying to support both packages now.  I'll check into this issue and see if I can fix it and commit a new version.  I'll let everyone know if I do.  Thanks!

                                  1 Reply Last reply Reply Quote 0
                                  • S
                                    sullrich
                                    last edited by

                                    This actually was a server error.  Or package sync script stopped copying changes from CVS.

                                    At any rate, everything is fixed now and the squid stuff should be on the latest version on the server now.

                                    1 Reply Last reply Reply Quote 0
                                    • ?
                                      Guest
                                      last edited by

                                      I'm guessing that the correct answer is to uninstall and then re-install the squid package?

                                      1 Reply Last reply Reply Quote 0
                                      • S
                                        sullrich
                                        last edited by

                                        @submicron:

                                        I'm guessing that the correct answer is to uninstall and then re-install the squid package?

                                        Yep.

                                        1 Reply Last reply Reply Quote 0
                                        • B
                                          BBMitch
                                          last edited by

                                          Just did a remove and install…
                                          At the bottom of the package install screen in black on the grey background was this text:
                                          Parse error: parse error, unexpected T_STRING in /etc/inc/pkg-utils.inc(426) : eval()'d code on line 1

                                          Tried the same task again, got the same message about missing includes etc. when I pressed save on the first page of the config... perhaps the cause was the error above?

                                          Thanks!
                                          Still running 0.90 on that box - will upgrade to 94.4 today

                                          1 Reply Last reply Reply Quote 0
                                          • J
                                            Jesse7
                                            last edited by

                                            @submicron:

                                            I'm guessing that the correct answer is to uninstall and then re-install the squid package?

                                            My install was 100% fresh.  The first thing I did was install squid and start to configure it.

                                            I am thinking I havn't seen these errors before or not I remember,  is because I have just used the upgrade option each time (except this time).  And it keeps all my settings even when you get the error.

                                            1 Reply Last reply Reply Quote 0
                                            • First post
                                              Last post
                                            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.