source: main/trunk/greenstone2/build-src/packages/wget/README@ 31837

Last change on this file since 31837 was 31837, checked in by ak19, 7 years ago

Added instructions on how to successfully compile up openssl v 1.1.0f on Linux. It requires wget 1.19.x however. And it makes no difference to being required to add in no-check-certificate when downloading from an HTTPS URL.

  • Property svn:keywords set to Author Date Id Revision
File size: 13.1 KB
Line 
1wget - web site mirroring software
2
3This directory contains a version of the GNU wget program that was written by
4Hrvoje Niksic and others and distributed under the GNU General Public Licence
5
6The GNU wget homepage is http://www.cg.tuwien.ac.at/~prikryl/wget.html
7
81) A couple of very small changes were made to this package by Stefan Boddie
9([email protected]). The USE_STDARG preprocessor definition was
10added to the VC++ makefile as it appeared to need it to compile on either
11VC++ 4.2 or VC++ 6.0. A change was also made to prevent backslashes from
12mistakenly being converted to "@5c" on windows.
13
142) 2003/11/27 - [email protected] made a few more small changes to fix
15h_errno bug preventing code from compiling on latest versions of GCC.
16
173) 2004/06/30 - [email protected] replaced version 1.5.3 with version 1.9.
18It compiled as is under Windows XP, using VC++ 6.0, under Linux using GCC 3.2.3
19and GCC 2.95.3. So I haven't made any changes.
20Under Windows, I haven't compiled it with openssl, so it doesn't support
21https://. OpenSSL comes with a warning about it being illegal in some countries
22to distribute cryptographic technology, so I haven't used it. Look at
23wget-1.9/windows/README for Windows compiling instructions if you want to add
24it in.
25
264) 2008/07/03 - [email protected] replaced version 1.9 with version 1.11.4.
27Version 1.9 didn't compile statically with the new libraries which come with
28fedora, so upgrading. Had to apply the patch at
29http://marc.info/?l=wget&m=115131792408685&w=2 to get it to compile under
30windows(VC++ 6.0), and those changes are in the tar.gz file in the repository.
31Again, no ssl in windows wget. The packages/configure and packages/Makefile
32files perform the same operations on wget as before, just the directory name
33has changed from wget/wget-1.9 to wget/wget-1.11.4.
34
35
365) 2013/01/09 - [email protected] Make minor change to src/Makefile.in so the code compiles under minGW cross-compiler running on Linux
37diff -r wget-1.13.4/src/Makefile.in wget-1.13.4.MINGW/src/Makefile.in
381136a1137,1143
39>
40> ifeq ($(GSDLOS),windows)
41> # Compiling wget with MinGW
42> CFLAGS += -DIN6_ARE_ADDR_EQUAL=IN6_ADDR_EQUAL
43> LIBS += -lws2_32
44> endif
45>
46
47These newly added lines should come after the line:
48> CLEANFILES = *~ *.bak core core.[0-9]* build_info.c version.c
49
50and before the command to make 'all':
51> all: config.h
52> $(MAKE) $(AM_MAKEFLAGS) all-am
53
54
556) 2013/01/29 - [email protected] added some #ifdef __ANDROID__ blocks into src/util.c to cope with the fact that this OS lacks localeconv()
56
57diff wget-1.13.4-orig/src/utils.c wget-1.13.4-gs/src/utils.c
58
591466a1467,1470
60> #ifdef __ANDROID__
61> cached_sep =",";
62> cached_grouping = "\x03";
63> #else
641489a1494
65> #endif
66
67[Now the #endif comes around line 1441 or 1459, immediately before:
68> initialized = true;
69> }
70> *sep = cached_sep;
71> *grouping = cached_grouping;]
72
73
747) 2014/10/13 - ak19
75Moved to wget version 1.15.
76Only the changes numbered 5 and 6 above have been ported into it, following Dr Bainbridge's instructions, as they were both changes made to the previous wget version Greenstone used (1.13.4).
77The wget tar file name (wget-1.15-gs) now indicates the version number and that it has been modified for Greenstone, so the Makefile and configure file in build-src/packages/ have been updated to reflect this.
78
798) 2017/07/27 - ak19 ([email protected]) - still using wget version 1.15, but now compiling wget up with OpenSSL support. Wget needs SSL support in order for it to access pages over HTTPS. In future, the web will be using https.
80
81We're now compiling up OpenSSL during the configuration phase since wget needs it to exist during its configure phase. We're building OpenSSL statically, by setting the no-shared flag. The built OpenSSL gets put into gs2build/linux|darwin/openssl, containing lib, include and bin subfolders. When configuring wget, we build wget against our OpenSSl, and make and make install proceed as normal. Refer to gs2build/build-src/packages configure.
82
83We weren't compiling up wget statically before either, so we're still not doing so. But if that will be necessary in future, see the section on COMPILING WGET UP STATICALLY further below.
84
85To compile up wget (statically or not) with openssl, a helpful page was
86https://stackoverflow.com/questions/9817337/compiling-wget-with-static-linking-self-compiled-openssl-library-linking-issu
87Note, however, that since the CPPFLAGS and LDFLAGS are now set to point to our OpenSSL during the configure stage, the make command needn't additionally set them as well, contrary to the instruction for make on the stackoverflow page. So we just need to do the usual make, make install once the configure is done against OpenSSL.
88
89The existing version of wget, 1.15, works with HTTPS when compiled against OpenSSL. However, this version of the binary needs to be run with the --no-check-certificate flag on to access https pages without a security certificate.
90
91e.g. ./wget --no-check-certificate http://englishhistory.net/tudor/citizens/
92
93The system wget on Ubuntu 16.04 is version 1.17.1 and does not require this flag. Pre-compiled windows binaries are available for version 1.11.4 and also don't require the flag. We'd like both unix and windows operating systems to behave similarly, ideally. However, no matter which version of wget we compile up on Unix, 1.15, 1.17 or 1.19, and no matter which compiled version of openssl (1.0.2x or 1.1.0x) we've built it against, the wget binary we generate on unix always requires --no-check-certificate. So this will indeed be different from the wget 1.17+ binary we've downloaded for Windows.
94
95* http://nebm.ist.utl.pt/~glopes/wget/
96Prebuilt Windows wget binaries (for 32 and 64 bit) version 1.11.4 that includes SSL support
97* http://gnuwin32.sourceforge.net/packages/wget.htm
98GNU's prebuilt Windows binaries of wget v 1.11.4. May not have been built with SSL support.
99
100The wget 1.11.4 we have, compiled without SSL does not work on https pages.
101Neither does the wget from http://nebm.ist.utl.pt/~glopes/wget/, even after including the --no-check-certificate flag in the wget command. So we'll need to upgrade the wget binary on Windows to a later version too.
102
103
1049) We're now shifting to wget-1.17.1 which is installed on Ubuntu 16.04, and for which a windows binary compiled with OpenSSL is available. Both the linux system version and windows binary work on https urls without the --no-check-certificate flag being necessary. However, the compiled up Linux version still needs this flag, see under PROBLEM.
105
106This way our perl code can launch wget as before, without always passing that additional flag. Hopefully the output in the Download pane will be the same so that the donwload parsing will work.
107
108LINUX CHANGES:
109- Grabbed wget-1.17.1.tar.gz from https://ftp.gnu.org/gnu/wget/
110- Made the modifications in steps 5 and 6 above and re-tarred as wget-1.17.1-gs.tar.gz, with corresponding changes in build-src/packages' configure, Makefile.in and Makefile
111- The configure step has now changed for wget v 1.17.1. Refer to build-src/packages/configure
112
113The configure step requires setting
114* --with-libssl-prefix to $bindir/openssl, so the wget build process can find openssl's include and lib folders. (Whereas the --with-ssl indicates what type of ssl we're using, which is openssl in our case.)
115* configuring had initially failed, reporting that OPENSSL_CFLAGS and OPENSSL_LIBS need to be set if not wanting to use whatever pkg-config may find. To set LIBS variables, use one of these forms: LIBS="-L/path/to/lib" or LIBS="/path/to/lib/lib.a" or LIBS="-lssl". To combine all three, separate with spaces. See http://trac.greenstone.org/changeset/30948 and https://github.com/tatsuhiro-t/spdylay/issues/43
116
117PROBLEM AND SOLUTION WITH WGETRC
118Can turn off requiring a certificate check for https URLs in wgetrc conf file, as explained here:
119https://superuser.com/questions/508696/wget-without-no-check-certificate
120And the location of wgetrc: https://www.gnu.org/software/wget/manual/html_node/Wgetrc-Location.html (for now setting the env var WGETRC in $GSDLHOME/setup.bash, which points to $GSDLHOME/bin/linux). Then the locally built linux wget 1.17.1 works, and so would v 1.15.
121
122However, the linux system wget and windows wget binary v 1.17.1 are not setting thisvariable in their wgetrc file, so how is the certificate check off for them by default? The windows wget binary v 1.15 does require the no-check-certificate flag, but v 1.17.1 works out of the box. So why does the 1.17.1 version I built on linux behave like the 1.15 on Windows binary (and built on Linux), which required the flag?
123
124
125WINDOWS WGET BINARIES WITH OPENSSL SUPPORT
126Windows binaries for wget 1.7.11 and other versions, built with openSSL support, are at:
127https://eternallybored.org/misc/wget/
128
129I downloaded the 32 bit version "wget-1.17.1-win32.zip" from there (at https://eternallybored.org/misc/wget/releases/old/wget-1.17.1-win32.zip)
130
131Unzipping wouldn't succeed, nor copying the zip's wget.exe directly, both producing a windows error message.
132To successfully extract: use 7zip to view the contents of the zip, then rename the wget.exe to wget.not, then copy out the wget.not file and rename it back.
133
134This version of wget on Windows 64 bit worked successfully to retrieve the https page of the Tudors site, and without the --no-check-certificate flag.
135
136# http://osxdaily.com/2012/05/22/install-wget-mac-os-x/
137# https://lists.gnu.org/archive/html/bug-wget/2014-12/msg00104.html
138
139Alternatives for Windows:
140Source:
141- https://soliloquyforthefallen.net/?p=238
142- https://github.com/wertarbyte/wget/tree/master/windows (README at end)
143Binaries:
144- https://stackoverflow.com/questions/14344921/wget-for-windows-7-trusted-source
145
146
147COMBINING GREENSTONE's GPL with OpenSSL LICENSES
148OpenSSL is under a double license, see https://www.openssl.org/source/license.html
149The licenses for GPL and OpenSSL are incompatible, see https://www.gnu.org/licenses/license-list.en.html#OpenSSL
150but you can combine it this way: https://opensource.stackexchange.com/questions/2233/gpl-v3-with-openssl-exception?rq=1
151which is what we've done for GS2 and GS3.
152
153
154TO COMPILE WGET STATICALLY
155First refer to https://stackoverflow.com/questions/9817337/compiling-wget-with-static-linking-self-compiled-openssl-library-linking-issu
156
157If compiling wget up statically, then, in the LDFLAGS prepended to wget's configure command, append -static. Further, the gcc command that gets run needs to have -lpthread in its library listing at the end. The order of the libraries listed also needs to change for static compilation to be successful:
158-lprce -lpthread -ldl <remaining -llibs>
159
160However, warnings appear when compiling wget statically, as it does not make sense to create some programs statically since they may be stuck including a local context (e.g. something related to DNS warnings in compiling up a previous component statically). Linking against some libraries to create a static binary may not make sense either. For instance -ldl, the dynamic loading or linking library, may not make sense if the binary created is static. This seems to imply that wget makes more sense if compiled up as a shared object, .so, than as a static one, .a.
161
162
163TO COMPILE WGET WITH OPENSSL v 1.1.0f
164At present, we're compiling Wget 1.17 with openSSL v1.0.2l.
165
166To compile with OpenSSL 1.1.0x, you'll need
167* Wget v. 1.19
168* -lpthread prepended to $LIBS.
169
170Note: Also need to update build-src/packages/Makefile.in's distclean command to remove the extra folder "share" and file "openssl.cnf.dist" generated when building openssl v 1.1.0f.
171
172So the wget compile command will look like:
173
174LIBS="-lpthread $LIBS" OPENSSL_CFLAGS="-I/Scratch/ak19/gs3-svn-13July2017/gs2build/build-src/packages/openssl/include" OPENSSL_LIBS="-L/Scratch/ak19/gs3-svn-13July2017/gs2build/build-src/packages/openssl/lib -lssl -lcrypto" ./configure --prefix=/Scratch/ak19/gs3-svn-13July2017/gs2build/build-src/packages/wget --with-ssl=openssl --with-openssl=auto --with-libssl-prefix="/Scratch/ak19/gs3-svn-13July2017/gs2build/build-src/packages/openssl" --bindir="/Scratch/ak19/gs3-svn-13July2017/gs2build/bin/linux" -disable-nls
175
176
177
178
179TO DO:
180+ If I delete the gs2build/bin/linux/openssl folder, the built wget still works fine without it. Dr Bainbridge confirmed that this is because, wget is built against OpenSSL's static libraries and therefore no longer needs the OpenSSL stuff we build and have been putting into gs2build/bin/linux/openssl. So we no longer need to put the built OpenSSL there.
181
182- Add a tick box in GLI > File > Preferences for turning on No Check Certificate over https, this should then replace our wgetrc file and env variable set in GS2's setup.bash. By default leave this flag unticked, so downloading won't work over https. Need to store this user setting in GLI's config.xml. Ensure that when the download over https failed, it results in an error.
183
184- If the downloading error count > 0:
185At the bottom of GLI > Download Pane > View Log > download error log - when we get errors:
186You have the option of adjusting your proxy server settings (go through the Configure Proxy button)
187For https certificate authentication, you have the option of turning off checking the certificate in the Connections tab of File > Preferences
188
189Check the warnings on windows. If it's no longer always warning, then do the stuff above on warning too, not just on error.
Note: See TracBrowser for help on using the repository browser.