| 15 | ''Note: The exact path to the module depends on how the HTTPD installation is laid out.'' |
| 16 | |
| 17 | On Debian using apt-get |
| 18 | {{{ |
| 19 | apt-get install libapache2-mod-python libapache2-mod-python-doc |
| 20 | }}} |
| 21 | (Still on Debian) after you have installed mod_python, you must enable the modules in apache2 (equivalent of the above Load Module directive): |
| 22 | {{{ |
| 23 | a2enmod mod_python |
| 24 | }}} |
| 25 | On Fedora use, using yum: |
| 26 | {{{ |
| 27 | yum install mod_python |
| 28 | }}} |
| 29 | You can test your mod_python installation by adding the following to your httpd.conf. You should remove this when you are done testing for security reasons. Note: mod_python.testhandler is only available in mod_python 3.2+. |
| 30 | {{{ |
| 31 | #!xml |
| 32 | <Location /mpinfo> |
| 33 | SetHandler mod_python |
| 34 | PythonInterpreter main_interpreter |
| 35 | PythonHandler mod_python.testhandler |
| 36 | </Location> |
| 37 | }}} |
| 38 | |
22 | | Note that the option `TracUriRoot` may or may not be necessary in your setup. Try without first, and if the URLs produced by Trac look wrong or if Trac does not seem to recognize the URLs correctly, add the `TracUriRoot` option. |
23 | | |
24 | | Configuring authentication works the same as for [wiki:TracCgi#AddingAuthentication CGI]: |
25 | | {{{ |
26 | | <Location "/projects/myproject/login"> |
| 51 | The option '''`TracUriRoot`''' may or may not be necessary in your setup. Try your configuration without it; if the URLs produced by Trac look wrong, if Trac does not seem to recognize URLs correctly, or you get an odd "No handler matched request to..." error, add the '''`TracUriRoot`''' option. You will notice that the `Location` and '''`TracUriRoot`''' have the same path. |
| 52 | |
| 53 | The options available are |
| 54 | {{{ |
| 55 | # For a single project |
| 56 | PythonOption TracEnv /var/trac/myproject |
| 57 | # For multiple projects |
| 58 | PythonOption TracEnvParentDir /var/trac/myprojects |
| 59 | # For the index of multiple projects |
| 60 | PythonOption TracEnvIndexTemplate /srv/www/htdocs/trac/project_list_template.html |
| 61 | # A space delimitted list, with a "," between key and value pairs. |
| 62 | PythonOption TracTemplateVars key1,val1 key2,val2 |
| 63 | # Useful to get the date in the wanted order |
| 64 | PythonOption TracLocale en_GB.UTF8 |
| 65 | # See description above |
| 66 | PythonOption TracUriRoot /projects/myproject |
| 67 | }}} |
| 68 | |
| 69 | === Python Egg Cache === |
| 70 | |
| 71 | Compressed python eggs like Genshi are normally extracted into a directory named `.python-eggs` in the users home directory. Since apache's home usually is not writable an alternate egg cache directory can be specified like this: |
| 72 | {{{ |
| 73 | PythonOption PYTHON_EGG_CACHE /var/trac/myprojects/egg-cache |
| 74 | }}} |
| 75 | |
| 76 | === Configuring Authentication === |
| 77 | |
| 78 | Creating password files and configuring authentication works similar to the process for [wiki:TracCgi#AddingAuthentication CGI]: |
| 79 | {{{ |
| 80 | #!xml |
| 81 | <Location /projects/myproject/login> |
| 89 | Configuration for mod_ldap authentication in Apache is a bit tricky (httpd 2.2.x and OpenLDAP: slapd 2.3.19) |
| 90 | |
| 91 | 1. You need to load the following modules in Apache httpd.conf |
| 92 | {{{ |
| 93 | LoadModule ldap_module modules/mod_ldap.so |
| 94 | LoadModule authnz_ldap_module modules/mod_authnz_ldap.so |
| 95 | }}} |
| 96 | |
| 97 | 2. Your httpd.conf also needs to look something like: |
| 98 | |
| 99 | {{{ |
| 100 | #!xml |
| 101 | <Location /trac/> |
| 102 | SetHandler mod_python |
| 103 | PythonInterpreter main_interpreter |
| 104 | PythonHandler trac.web.modpython_frontend |
| 105 | PythonOption TracEnv /home/trac/ |
| 106 | PythonOption TracUriRoot /trac/ |
| 107 | Order deny,allow |
| 108 | Deny from all |
| 109 | Allow from 192.168.11.0/24 |
| 110 | AuthType Basic |
| 111 | AuthName "Trac" |
| 112 | AuthBasicProvider "ldap" |
| 113 | AuthLDAPURL "ldap://127.0.0.1/dc=example,dc=co,dc=ke?uid?sub?(objectClass=inetOrgPerson)" |
| 114 | authzldapauthoritative Off |
| 115 | require valid-user |
| 116 | </Location> |
| 117 | }}} |
| 118 | |
| 119 | Or the LDAP interface to a Microsoft Active Directory: |
| 120 | |
| 121 | {{{ |
| 122 | #!xml |
| 123 | <Location /trac/> |
| 124 | SetHandler mod_python |
| 125 | PythonInterpreter main_interpreter |
| 126 | PythonHandler trac.web.modpython_frontend |
| 127 | PythonOption TracEnv /home/trac/ |
| 128 | PythonOption TracUriRoot /trac/ |
| 129 | Order deny,allow |
| 130 | Deny from all |
| 131 | Allow from 192.168.11.0/24 |
| 132 | AuthType Basic |
| 133 | AuthName "Trac" |
| 134 | AuthBasicProvider "ldap" |
| 135 | AuthLDAPURL "ldap://adserver.company.com:3268/DC=company,DC=com?sAMAccountName?sub?(objectClass=user)" |
| 136 | AuthLDAPBindDN ldap-auth-user@company.com |
| 137 | AuthLDAPBindPassword "the_password" |
| 138 | authzldapauthoritative Off |
| 139 | # require valid-user |
| 140 | require ldap-group CN=Trac Users,CN=Users,DC=company,DC=com |
| 141 | </Location> |
| 142 | }}} |
| 143 | |
| 144 | Note 1: This is the case where the LDAP search will get around the multiple OUs, conecting to Global Catalog Server portion of AD (Notice the port is 3268, not the normal LDAP 389). The GCS is basically a "flattened" tree which allows searching for a user without knowing to which OU they belong. |
| 145 | |
| 146 | Note 2: Active Directory requires an authenticating user/password to access records (AuthLDAPBindDN and AuthLDAPBindPassword). |
| 147 | |
| 148 | Note 3: The directive "require ldap-group ..." specifies an AD group whose members are allowed access. |
| 149 | |
| 150 | |
| 151 | |
| 152 | === Setting the !PythonPath === |
| 153 | |
| 227 | This does not seem to work in all cases. What you can do if it does not: |
| 228 | * Try using `<LocationMatch>` instead of `<Location>` |
| 229 | * <Location /> may, in your server setup, refer to the complete host instead of simple the root of the server. This means that everything (including the login directory referenced below) will be sent to python and authentication does not work (i.e. you get the infamous Authentication information missing error). If this applies to you, try using a sub-directory for trac instead of the root (i.e. /web/ and /web/login instead of / and /login). |
| 230 | |
| 231 | For a virtual host that supports multiple projects replace "`TracEnv`" /var/trac/myproject with "`TracEnvParentDir`" /var/trac/ |
| 232 | |
| 233 | Note: !DocumentRoot should not point to your Trac project env. As Asmodai wrote on #trac: "suppose there's a webserver bug that allows disclosure of !DocumentRoot they could then leech the entire Trac environment". |
| 234 | |
| 237 | In general, if you get server error pages, you can either check the Apache error log, or enable the `PythonDebug` option: |
| 238 | {{{ |
| 239 | #!xml |
| 240 | <Location /projects/myproject> |
| 241 | ... |
| 242 | PythonDebug on |
| 243 | </Location> |
| 244 | }}} |
| 245 | |
| 246 | For multiple projects, try restarting the server as well. |
| 247 | |
| 248 | === Expat-related segmentation faults === #expat |
| 249 | |
| 250 | This problem will most certainly hit you on Unix when using Python 2.4. |
| 251 | In Python 2.4, some version of Expat (an XML parser library written in C) is used, |
| 252 | and if Apache is using another version, this results in segmentation faults. |
| 253 | As Trac 0.11 is using Genshi, which will indirectly use Expat, that problem |
| 254 | can now hit you even if everything was working fine before with Trac 0.10. |
| 255 | |
| 256 | See Graham Dumpleton's detailed [http://www.dscpl.com.au/wiki/ModPython/Articles/ExpatCausingApacheCrash explanation and workarounds] for the issue. |
| 257 | |
112 | | |
113 | | If you run trac with mod_python (3.1.3 or 3.1.4) on Windows, |
114 | | uploading attachments will '''not''' work. |
115 | | This is a known problem which we can't solve cleanly at the Trac level. |
116 | | |
117 | | However, there is a workaround for this at the mod_python level, |
118 | | which is to apply the following patch [http://projects.edgewall.com/trac/attachment/ticket/554/util_py.patch attachment:ticket:554:util_py.patch] |
119 | | to the (Lib/site-packages)/modpython/util.py file. |
120 | | |
121 | | If you don't have the `patch` command, that file can be replaced with the [http://svn.apache.org/viewcvs.cgi/httpd/mod_python/trunk/lib/python/mod_python/util.py?rev=103562&view=markup fixed util.py] (fix which, although done prior to the 3.1.4 release, is ''not'' |
122 | | present in 3.1.4). |
| 291 | If you run trac with mod_python < 3.2 on Windows, uploading attachments will '''not''' work. This problem is resolved in mod_python 3.1.4 or later, so please upgrade mod_python to fix this. |
| 292 | |
| 297 | |
| 298 | === SELinux issues === |
| 299 | |
| 300 | If Trac reports something like: ''Cannot get shared lock on db.lock'' |
| 301 | The security context on the repository may need to be set: |
| 302 | |
| 303 | {{{ |
| 304 | chcon -R -h -t httpd_sys_content_t PATH_TO_REPOSITORY |
| 305 | }}} |
| 306 | |
| 307 | See also [[http://subversion.tigris.org/faq.html#reposperms]] |
| 308 | |
| 309 | === FreeBSD issues === |
| 310 | Pay attention to the version of the installed mod_python and sqlite packages. Ports have both the new and old ones, but earlier versions of pysqlite and mod_python won't integrate as the former requires threaded support in python, and the latter requires a threadless install. |
| 311 | |
| 312 | If you compiled and installed apache2, apache wouldn´t support threads (cause it doesn´t work very well on FreeBSD). You could force thread support when running ./configure for apache, using --enable-threads, but this isn´t recommendable. |
| 313 | The best option [[http://modpython.org/pipermail/mod_python/2006-September/021983.html seems to be]] adding to /usr/local/apache2/bin/ennvars the line |
| 314 | |
| 315 | {{{ |
| 316 | export LD_PRELOAD=/usr/lib/libc_r.so |
| 317 | }}} |
| 318 | |
| 319 | === Subversion issues === |
| 320 | |
| 321 | If you get the following Trac Error `Unsupported version control system "svn"` only under mod_python, though it works well on the command-line and even with TracStandalone, chances are that you forgot to add the path to the Python bindings with the [TracModPython#ConfiguringPythonPath PythonPath] directive. (The better way is to add a link to the bindings in the Python `site-packages` directory, or create a `.pth` file in that directory.) |
| 322 | |
| 323 | If this is not the case, it's possible that you're using Subversion libraries that are binary incompatible with the apache ones (an incompatibility of the `apr` libraries is usually the cause). In that case, you also won't be able to use the svn modules for Apache (`mod_dav_svn`). |
| 324 | |
| 325 | You also need a recent version of `mod_python` in order to avoid a runtime error ({{{argument number 2: a 'apr_pool_t *' is expected}}}) due to the default usage of multiple sub-interpreters. 3.2.8 ''should'' work, though it's probably better to use the workaround described in #3371, in order to force the use of the main interpreter: |
| 326 | {{{ |
| 327 | PythonInterpreter main_interpreter |
| 328 | }}} |
| 329 | This is anyway the recommended workaround for other well-known issues seen when using the Python bindings for Subversion within mod_python (#2611, #3455). See in particular Graham Dumpleton's comment in [comment:ticket:3455:9 #3455] explaining the issue. |
| 330 | |
| 331 | === Page layout issues === |
| 332 | |
| 333 | If the formatting of the Trac pages look weird chances are that the style sheets governing the page layout are not handled properly by the web server. Try adding the following lines to your apache configuration: |
| 334 | {{{ |
| 335 | #!xml |
| 336 | Alias /myproject/css "/usr/share/trac/htdocs/css" |
| 337 | <Location /myproject/css> |
| 338 | SetHandler None |
| 339 | </Location> |
| 340 | }}} |
| 341 | |
| 342 | Note: For the above configuration to have any effect it must be put after the configuration of your project root location, i.e. {{{<Location /myproject />}}}. |
| 343 | |
| 344 | === HTTPS issues === |
| 345 | |
| 346 | If you want to run Trac fully under https you might find that it tries to redirect to plain http. In this case just add the following line to your apache configuration: |
| 347 | {{{ |
| 348 | #!xml |
| 349 | <VirtualHost * > |
| 350 | DocumentRoot /var/www/myproject |
| 351 | ServerName trac.mycompany.com |
| 352 | SetEnv HTTPS 1 |
| 353 | .... |
| 354 | </VirtualHost> |
| 355 | }}} |
| 356 | |
| 357 | === Fedora 7 Issues === |
| 358 | Make sure you install the 'python-sqlite2' package as it seems to be required for TracModPython but not for tracd |
| 359 | |
| 360 | |
| 361 | === Segmentation fault with php5-mhash or other php5 modules === |
| 362 | You may encounter segfaults (reported on debian etch) if php5-mhash module is installed. Try to remove it to see if this solves the problem. See debian bug report [[http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=411487]] |
| 363 | |
| 364 | Some people also have troubles when using php5 compiled with its own 3rd party libraries instead of system libraries. Check here [[http://www.djangoproject.com/documentation/modpython/#if-you-get-a-segmentation-fault]] |