Saturday, March 18, 2006

Faster zone provisioning using zoneadm clone and Dtrace to monitoring zone

There is a wonderful blog on zone, I am transfering one engineer's
test below:

Faster zone provisioning using zoneadm clone

creating zones in parallel to reduce the time it takes to provision multiple zones, it was suggested that the new zoneadm clone subcommand could be of help. The zoneadm clone subcommand (available from build 33 onwards) copies an installed and configured zone. Cloning a zone is faster than installing a zone, but how much faster? To find out an Engineer did some quick experiments creating and cloning both whole root and sparse root zones on a V480:

Creating a whole root zone:

# zonecfg -z zone1
zone1: No such zone configured
Use 'create' to begin configuring a new zone.
zonecfg:zone1> create -b
zonecfg:zone1> set zonepath=/zones/zone1
zonecfg:zone1> exit
# time zoneadm -z zone1 install
time zoneadm -z zone1 install
Preparing to install zone .
Creating list of files to copy from the global zone.
Copying <123834> files to the zone.
Initializing zone product registry.
Determining zone package initialization order.
Preparing to initialize <986> packages on the zone.
Initialized <986> packages on zone.
Zone is initialized.
Installation of these packages generated errors:
The file contains a log of the zone installation.

real 13m40.647s
user 2m49.840s
sys 4m43.221s

Cloning a whole root zone:

# zonecfg -z zone1 export|sed -e 's/zone1/zone2/'|zonecfg -z zone2
zone2: No such zone configured
Use 'create' to begin configuring a new zone.
# time zoneadm -z zone2 clone zone1
Cloning zonepath /zones/zone1...

real 8m4.615s
user 0m9.780s
sys 2m18.334s

For the whole root zone cloning is almost twice a fast as a regular install.

Creating a sparse root zone:

# zonecfg -z zone2
zone3: No such zone configured
Use 'create' to begin configuring a new zone.
zonecfg:zone3> create
zonecfg:zone3> set zonepath=/zones/zone3
zonecfg:zone3> exit
# time zoneadm -z zone3 install
Preparing to install zone .
Creating list of files to copy from the global zone.
Copying <2535> files to the zone.
Initializing zone product registry.
Determining zone package initialization order.
Preparing to initialize <986> packages on the zone.
Initialized <986> packages on zone.
Zone is initialized.
Installation of these packages generated errors:
The file contains a log of the zone installation.

real 6m3.227s
user 1m45.902s
sys 2m47.717s

Cloning a sparse root zone:

# zonecfg -z zone3 export|sed -e 's/zone3/zone4/'|zonecfg -z zone4
zone4: No such zone configured
Use 'create' to begin configuring a new zone.
# time zoneadm -z zone4 clone zone3
Cloning zonepath /zones/zone3...

real 0m11.535s
user 0m0.706s
sys 0m6.440s

For the sparse root zone, cloning is more than thirty times faster then installing!

So if you need to provision multiple zones of a certain configuration, zoneadm clone is clearly the way to go.

Note that the current clone operation does not (yet) take advantage of ZFS. To see what ZFS can do for zone cloning, have a look at Mike Gerdts' blog: Zone created in 0.922 seconds. Goodness indeed.

T: OpenSolaris Zones
( Mar 18 2006, 07:12:17 PM CET ) Permalink Comments [1]
20050525 Wednesday May 25, 2005
Monitoring zone boot and shutdown using DTrace

Several people have expressed a desire for a way to monitor zone state transitions such as zone boot or shutdown events. Currently there is no way to get notified when a zone is booted or shutdown. One way would be to run zoneadm list -p at regular intervals and parse the output, but this has some drawbacks that make this solution less ideal:

* it is inefficient because you are polling for events,
* you will probably start at least two processes for each polling cycle (zoneadm(1M) and nawk(1)),
* more importantly, you could miss transitions if your polling interval is too large. Since a zone reboot might take only seconds, you would need to poll often in order not to miss a state change.

A better, much more efficient solution can be built using DTrace, the 'Swiss Army knife of system observability'. As mentioned in this message on the DTrace forum, the zone_boot() function looks like a promising way to get notifications when a zone is booted. Listing all FBT probes with the string 'zone_' in their name (dtrace -l fbt|grep zone_) turns up another interesting function: zone_shutdown(). To verify that these probes are fired when a zone is either booted or shutdown, let's enable both probes:

# dtrace -n 'fbt:genunix:zone_boot:entry, fbt:genunix:zone_shutdown:entry {}'
dtrace: description 'fbt:genunix:zone_boot:entry, fbt:genunix:zone_shutdown:entry ' matched 2 probes

When zoneadm -z zone1 boot is executed we see that the zone_boot:entry probe fires:

CPU ID FUNCTION:NAME
0 6722 zone_boot:entry

The zone_shutdown:entry probe fires when the zone is shutdown (either by zoneadm -z zone1 halt or using init 0 from within the zone):

0 6726 zone_shutdown:entry

This gives us the basic 'plumbing' for the monitoring script. By instrumenting the zone_boot() and zone_shutdown() functions with the FBT provider we can wait for zone boot and shutdown with almost zero overhead. Now what is left is finding out the name of the zone that was booted or shutdown. This requires some knowledge of the implementation and access to the source (anyone interested can take a look at the source after OpenSolaris is launched, so stay tuned).

A quick look at the source shows that we can get the zone name by instrumenting a third function, zone_find_all_by_id() that is called by both zone_boot() and zone_shutdown(). This function returns a pointer to a zone_t structure (defined in /usr/include/sys/zone.h). The DTrace script below uses a common DTrace idiom: in the :entry probe we set a thread-local variable trace that is used as a predicate in the :return probes (the :return probes have the information we're after). The FBT provider :return probe stores the function return value in args[1] so we can access the zone name as args[1]->zone_name in fbt:genunix:zonefind_all_by_id:return and save it for later use in fbt:genunix:zone_boot:return and fbt:genunix:zone_shutdown:return.

#!/usr/sbin/dtrace -qs

self string name;

fbt:genunix:zone_boot:entry
{
self->trace = 1;
}

fbt:genunix:zone_boot:return
/self->trace && args[1] == 0/
{
printf("Zone %s booted\n", self->name);
self->trace = 0;
self->name = 0;
}

fbt:genunix:zone_shutdown:entry
{
self->trace = 1;
}

fbt:genunix:zone_shutdown:return
/self->trace && args[1] == 0/
{
printf("Zone %s shutdown\n", self->name);
self->trace = 0;
self->name = 0;
}

fbt:genunix:zone_find_all_by_id:return
/self->trace/
{
self->name = stringof(args[1]->zone_name);
}


Starting the script and booting and shutting down some Zones gives the following result:

# ./zonemon.d
Zone aap booted
Zone noot booted
Zone noot shutdown
Zone noot booted
Zone aap shutdown

Friday, March 17, 2006

Vritual Machine on x86

OS architecture design and implementation comes from
simple structure to classic layered Unix system approach
which Lunix and Windows follows. Furthermore, to simplify
the kernel manageability, Micro kernel architecture was
proposed. However due to performance and scalability,
Solaris modulization design won the game. One interesting
thing is that Mac OS X takes hybrid structure which bridge
the layered BSD kernel design with Microkernel implementation.
Microkernel manages memory, RPC, IPC and Kthread scheduling.
BSD kernel does the CLIs, file systems and all the POSIX APIs.

Traditional layered Solaris Kernel design concludes the concept
of abstracting the HW resource into several execution environments.
With such virtualization techniques, a process is provided with a
virtual copy of underline OS and HW resources.

Therefore the fundamental resource to run virtual machine is to
share the HW with different execution environments. In such way,
Virtual machine is running in the kernel mode and execute at the
user mode. It has relative virtual user and kernel modes. If there is
a process running in a virtual machine, the control will be transfered
from virtual machine monitor to change the register and process program
counter for simulating the system call. Hence the major difference is
the real I/O will take much more time than virtual I/O does. CPU instruction
time will increase due to the multi-processes running within each virtual
machine. Virtual machine model is the best fit for R&D

However, it seems virtual machine can help resolve system compatibility
issues. The two popular favors of the virtual machine are: vmware and
Java VM. Since virtual machines are running on the top of OS, the traditional
OS design and implementation such Solaris Modules, Microkernel, VM are
still applied.

VMware abstracts x86 platform into isolated virtual machines. VMware runs
as user land application on the top of host OS which enable multiple guest
OSs concurrently within each virtual machines. However, the virtualization
layer as the core the vmware is the most expensive design to abstract the
underline resources into various virtual machines as guest OSs. Each vm
has it's own CPU, Memory, devices etc.

JVM is also abtracting the underline OS and HW. It is through class loader
and Java interpreters to execute the byte codes.

In general, the question of the design and utilization of virtual machine
is depends on the level of virtualization which fits in the requirements.
For platform and system level virtualization across different guest
OSs, vmware is the choice. However, if you only want to virtualize the
user land applications specifclly for Java applications, JVM is the right
technical and political answers to acorss different OSs. An important
note, application level virtualization has been done significantly by Sun
ISVs such as Cassat for Java EE virtualization.

Thursday, March 16, 2006

Wireless TCP

Traditional TCP does not serve the wirless connection efficiently due to the conventional TCP design assumption on the congestion control and "friendly design" of the protocols. This leads to the slow start and fast retransmit/fast recovery. High Error Rate, mobility caused packet dropping and TCP's fundermental issue for the time-out of the missing ack casued by congestion means classic TCP does not work for mobile computing.

UDP leaves the reliable and retranmission to the application layer.


Improved TCP (ITCP) such as Indirect TCP using accessing point or FA for Mobile Node. Segementing TCP connection into 2 connections. Snooping TCP uses FA or access buffers all data packets. Mobile TCP uses SH-MI connections and persistent mode to resolve the issues. Selective retransmission is the good solution for the test. Transaction-oriented TCP combine the packes for connection establishment and connection release with user data packets to reduce the packet for 3 ways handshakes (WAP does the similar things). Header compressionn does the work to for gaming apps.

Wednesday, March 15, 2006

install skype on Ubuntu

mkdir skype
mv skype_1.2.0.18-1_i386.deb skype_1.2.0.18-1_i386.deb.orig
dpkg-deb –extract skype_1.2.0.18-1_i386.deb.orig skype
dpkg-deb –control skype_1.2.0.18-1_i386.deb.orig skype/DEBIAN
vi skype/DEBIAN/control
Change to:
Depends: libc6 (>= 2.3.2.ds1-4), libgcc1 (>= 1:3.4.1-3), libqt3c102-mt (>= 3:3.3.3.2) | libqt3-mt, libstdc++5 (>= 1:3.3.4-1), libx11-6 | xlibs (>> 4.1.0), libxext6 | xlibs (>> 4.1.0)

dpkg –build skype
mv skype.deb skype_1.2.0.18-1_i386.deb
dpkg -i skype_1.2.0.18-1_i386.deb

Tuesday, March 14, 2006

package parameters for zone scope

SUNW_PKG_ALLZONES, SUNW_PKG_HOLLOW,SUNW_PKG_THISZONE

(1) SUNW_PKG_ALLZONES package parameter describes the zone scope of a package. This parameter defines the following:

*

Whether a package is required to be installed on all zones
*

Whether a package is required to be identical in all zones

The SUNW_PKG_ALLZONES package parameter has two permissible values. These values are true and false. The default value is false.

(2)

The SUNW_PKG_HOLLOW package parameter defines whether a package should be visible in any non-global zone if that package is required to be installed and be identical in all zones.

The SUNW_PKG_HOLLOW package parameter has two permissible values, true or false.

*

If SUNW_PKG_HOLLOW is either not set or set to a value other than true or false, the value false is used.
*

If SUNW_PKG_ALLZONES is set to false, the SUNW_PKG_HOLLOW parameter is ignored.
*

If SUNW_PKG_ALLZONES is set to false, then SUNW_PKG_HOLLOW cannot be set to true.

(3)

The SUNW_PKG_THISZONE package parameter defines whether a package must be installed in the current zone, global or non-global, only. The SUNW_PKG_THISZONE package parameter has two permissible values. These value are true and false. The default value is false.

(4)

If a package is installed with pkgadd -G or has the pkginfo setting SUNW_PKG_THISZONE=true, the package can only be patched with patchadd -G.

Zone and Solaris Harden

harden non-global zones using Solaris Security Toolkit not pkgrm.
harden the global zone using Solaris Security Toolkit so that any
subsequent non-global zones created,will automatically be hardened.

pkgrm is the underlying mechanism to remove software packages from Solaris.
If a package is zone-aware, you would use pkgrm to remove it from the zones.
Depending on what the customer's definition of "hardening" may be, it could be possible to satisfy this requirement without using pkgrm.



Basically, hardening the system should not cause issues.
That is as long as you don't remove basic zones functionality, I'm assuming you'll pkgrm some packages etc.
I'd suggest just trying it on a test system first.
The minumum cluster that zones functionality is deliverd in is SUNWCuser.
But it should be possible to start lower, i.e. SUNWCreq and build up, the following e-mail threads have some further discussion on this very topic.

Open Source and Open Service (OSS)

(1) Open Source vs Open Service (OSS)
Why, What, When and How for Sun and Partner
What are the nature of the problems to resolve ?
What are the related OSS has been visionlized
and implemented in the industry ?
(google, salesforce.com. Microsoft, ibm etc.)
(2) What will be engineering engagement platform for OSS ?
(3) What is the engineering engagement protocol for OSS ?
(4) What will be the engineering engagement execution
language for the OSS ?
(5) What will engineering engagement model for OSS ?
(6) What will be the engineering engagement layered service model
for OSS ?
(7) What will be strength and advantage of OSS vs traditional
engineering engagement ?
(8) What will be the impact to current engineering engagement
routine ?
(9) How to evaluate the performance of engineering engagement for
OSS
(10) How to ensure MDE and Tim's Team differentiate and out perform
engineering engagement for OSS
(11) What are the future work to be done ?

SPARC IV+ and T1 favors

SPARC IV+ and T1 are the different lines of platforms driving
industry requirements.

(1) From uts implementation point of view, sun4v addresses the
future platform architecture down the road from core kernel
implementation to FM architecture design. However, I do not
have specific core structure vs x64 core finity strcuture either.
This is has been fiting CMP SPARC IV+ for a long time since
Sun OS 2.6 from processor set to pid resource management.
This means sun4v requires more virtualization on processor
and core than traditional sun4u architecture and implementation.
(2) In addition, other than the firmware and HW architecture and
implmentation, Niagara address the throughput and latency
from bottom up as CMT promising.
(3) In process management, ABI contuines to offer the standard
for Solaris binary interface as part of ELF format for both platform
independent and processor specific system calls and stack mgt

(4) Network performance and throughput at Device level from traditional bge(7D) support to sustain scalable and throughput based volume
access

(5) Other than core uts processor implementation and system library
io, fpc IPC and px, pcb, vm, ebus, along with genunix implementation
including all loadable kernel modules such as device drivers, core
solaris kernel implementation are reused such as vm and file system
and scheduling as addressed in Solaris 10 core kernel implementation

so on so forth.................................

In general, there are quite of platform specific enhancement done
over T1 processor from kernel perspectives

(6) At user land, it depends on the application provider's architecture
and implementation to the level of utlizing process management
and resource allocation. What are the user land thread model designed
and implemented ? How LWP are created and how kthread is leveraged ?
How lock prmitives are designed at user land ? what thread libirary used
at user land for kthread creation and execution ?

Communication Service with SSO

the comms channels use SSO adapter to provide SSO with MS Exchange.

It is required to quickly get in MS Exchange without having to use
a full Directory Server DN matching the Active Directory DN

The Exchange plugin for the Mail channel uses the SSOAdapter
property "uid" for the IMAP user name and "password" for the password.

Niagara Process Image and ABI ELF format

There has been one thing since I have been working
on Niagara. From solaris process mgt point of view,
process image with ELF format addressed as part
of ABI standard starting the Solaris binary interface.

ELF addresses both platform independent and
processor specific specifications. For processor dependent
ABI standards include the routine sequence
(system calls, stack mgt etc) and Solaris interface for signals,
process initialization etc.

Does this mean Niagara inherit most the SPARC IV+
functional calls and stack mgt, process mgt and signal
interface ?

Monday, March 13, 2006

How to setup cisco VPN client on Ubuntu

1. Install


# sudo su -
# apt-get install build-essential linux-headers-`uname -r`
# echo tun >> /etc/modules
# modprobe tun
# cd VPNCLIENT_SRC_DIR
# ./vpn_install
# /etc/init.d/vpnclient_init start

2. edit sfbay.pcf files in /etc/CiscoSystemsVPNClient/Profiles


Description=Ebay VPN3000
Host=192.18.42.83
AuthType=1
GroupName=vpn
EnableISPConnect=0
ISPConnectType=0
ISPConnect=
ISPCommand=
Username=ll149252
SaveUserPassword=0
EnableBackup=1
BackupServer=ivpn-east.sun.com,ivpn-central.sun.com,ivpn-aus.sun.com
TunnelingMode=1
TCPTunnelingPort=10000
EnableLocalLAN=0
EnableNat=1
CertStore=0
CertName=
CertPath=
CertSubjectName=
CertSerialHash=00000000000000000000000000000000
DHGroup=2
ForceKeepAlives=0

3. connect to VPN

$vpnclient connect sfbay

4. Disconnect VPN

$vpnclient disconnect

kmem(7D) and kstat on NG-Z resource mgt and performance monitoring

(1) Regarding to Platform Computing

kmem(7D) is the device library with 3 open routines below

openkmem which opens /dev/kmem file descriptor
which read through the file by following routines
kemecpy
kstrncpy

For access to the virtual address space of Solaris kernel,
excluding memory associated with an I/O device.

However, kmem(7D)does not have full functionality in
a non-global zone.

(2) Regarding to HPOV

from Solaris process management point of view,
profs presudo file system export the abstraction
of kernel process mgt. There are a few user land
data strcuture to illustrate the performance mgt
needs. In addition kstat (1M) no longer sufficient
for NG-Z use case which address the uts structure
tagged with zoneid.

S10 Resource Mgt and HW resource Mgt

(2) S10 SRM and resource pool
Having resource pools enabled allows one to have virtualized statistics
for things like the CPU kstats, APIs like sysinfo(3C) and
getloadavg(3C) and utilities like mpstat(1M) and vmstat(1M). Basically
if pools are enabled, a zone will see a virtualize view of the relevant
statistics based on the pool the zone is bound to.

(3)FSS and processor resource usage

It's not as fine-grained as using solely FSS but it does provide a
great deal of flexibility including the ability to automatically set
the scheduling class of processes bound to the pool.


HW resource management approach, hypervisor

You can lose a lot of optimization if the
hypervisor abstracts too many hardware details (thread to processor
affinity is one such example). So while the more general purpose
the hypervisor (abstracts the most details) the fewer opportunities
for the OS to optimize (and in some cases they futilely optimize -
like a compulsion for a pointless or destructive activity).

The relevance here is that the abstraction layer presented by
Solaris zones is higher in the stack (near the user space layer)
so all of the platform specific optimizations are available to the
kernel. When you begin to think about the impact of optimizations
such multiple page sizes and memory placement, these details can become
very important. And of course reduced VM pressure from sharing a
common (but secure) buffer cache and shared libraries.

Mobile awared Resource Discovery with ad-hoc network

Scalability & Latency

1.Traditionally, physical entities such as a computer, network or storage system are considered as resource. With service oriented architecture, in addition to traditional physical resource, virtual services provide the consistent functionalities across the network.
2.Service Discovery: It is important for service consumer to identify service and characteristics of the service in order to understand the interfaces and authorized identity for services accessing.
3.Traditionally, service discovery is accomplished by service registry.
4.User tends to discover a service based on the knowledge of the service
5.Auto service discovery, search, selection, matching, composition and interoperation, invocation and execution requires a service description which is crucial
6.Functional classification or categories of the service is important for efficient way of querying and indexing a specific service
7.Discover, locating the network accessible capabilities, to support heterogeneous environment, standard RDS protocol and standard mechanism for expressing resource is required
8.Client normally query resource by properties such as capabilities, quality, terms, and configuration etc. Therefore the description language is demanded for resource discovery
9.Discovery is lightweight and non-authorized operation with no resource commitment. In addition, the aggregation of resource information for the purpose of large and distributed resource set needs to handle the overheads
10.Due to the boundary of the network, both physical resources and virtual services may not be reachable. The discovery model based on the network structure will not be effective. Specially for mobile aware provider and consumer applications and services, service transmission should continue with mobility. (1) Multi-cast Model (2)Directory Server Model (3) Hierarchical Directory Server Model which Directory Server located at each virtual logical boundary. The information aggregated all services in the Top level logical container. Requester unicasts the discovery queries to the server and queries will be forwarded the hierarchy. However, hierarchical model requires the deployment of the directory servers running in the upper and lower layer structure domains. The directory server in turns has to be configured in such hierarchical manner. But one thing for sure, applications in each local network does not require global network connection.
11.Flooding based unstructured P2P discovery model does not scale in terms of message overhead. Some proposed the optimized model to reduce the network traffic but increase the cost of query latency. DHT based system shows scalability and efficiency but can not handle complex query. Avoid overhead of resource discovery queries over the network, semantics-based P2P query forwarding strategy is valuable. Only forwarding query to semantically related nodes. RFD is used for resource and query expression. After the related node is identified, the original RDF query is applied to retrieve the designated information.

Sunday, March 12, 2006

Process and Address Space

Address space is the kernel abstraction of managing the memory
pages allocation for the process. Process needs memory address
space to store text instruction, data segment,heap as tmp process
space and stack

HW context: platform specific process execution environment
such as registers ------ CPU
address space ------------Memory

SW context: process credentials, open file lists, PIDs, signal disposition, signal handler, scheduling class and priority, process state,

Most of the process has stdin, stdout, stderr which define the source and destination
of input and output char streams for the process.

Solaris kernel, a process is composed of LWP and kthread. It is a kernel data strcution
linked to the process structure. This threading model seperate the user land threads with
kernel threads.

User land thread is created by routine call: thr_create(3T) or pthread_create(3T) from
libthread.so and libpthread.so. User thread has it's own scheduling and priority scheme
which different from kernel scheduling class and priority. It is done by calling into
thread library dispatcher and switch routines periodically at predefined preemption points.
User land thread is scheduled by linking on to a available LWP. It is required for a user
land thread to be executed. However, user thread is created does not mean LWP is created.
It must be specified as user thread to have kernel to create LWP from THR_NEW_LWP or THR_BOUND
flag. But for a threaded process with many bound LWPs with kernel thread will cause performance
impact.

In addition, thr_setconcurrency(3T) informs kernel that how may threads programmer wishes to run.
Without specification from code, thread library will maintain the reasonable number of LWPs for user land thread execution.

System should balance the case which there are too many LWPs or no enough LWPs to run.
Too many LWP cause kernel overhead to manage and too less LWPs cause many runnable user
land threads wait for resources for execution.

As traditional process modlel, exec or fork create new process.

In a multi thread process model, all HW context are not shared among user land threads
However, SW context such as address space, PIDs, credentials, signal hanlders etc. are shared.

ABI & ELF & Process Image

With ELF format within ABI standard, kernel and OS tools create
executable object which can be loaded into memory and created as
process for scheduling and execution.

As program becomes a binary executable object as it is complied
and linked with OS program language specific compiler. As the
executable object is exec(1), dynamic linking process starts with
the lib.so.1(1) is called to link with other shared objects from
libc.so.1 (dynamic link library) for instruction execution. Please
note that all references in the program are resolved via ld.so.1

However, static link can be achieved via -B static flag with compilation
which force all references are included at build time. But as dynamic
link process needs libc.so.1, static link process requires libc.a
Building 64 bit app can not be done with static link since there
is no static archieved libaray (libc.a) released with OS.

A program is compiled as ELF format executable object.
ELF defines the format for process on disk and in memory (process image)
ELF format is the part of ABI standard states the OS binary interface
for compiled and executed programs.

ELF addresses both platform independent and processor specific
specifications. For processor dependent ABI standards include the
function-calling squence (system calls, stack mgt etc) and OS
interface for signals, process initialization etc.

S10 PCB Structure

Two major abstraction of Solaris (Process and File)

(1) Process is basic unit of scheduling and execution on the Solaris
(2) Multi-threaded Process architecture: process, LWP and kernel thread
(3) Solaris kernel process model: procfs, signals,process group,session mgt
(4) Solaris kernel maintain system wide process table for PID and related data
(5) Solaris process abstraction includes traditional unix process model for
HW state and OS maintained SW context. Additionaly, supports multi-thread
execution within a single process. Each thread shares the process state
and can be scheduled and executed on a processor independently of other
threads within the same process
(6) Solaris invents Time Sharing scheduling policy and round robin approach
for process schediling scheme and alogrithm

In addition to Solaris unique process architecture design, a good tool is
been evolved for process monitoring. Procfs is the pseudo file system export
the Process Abstraction Model to user with a file system like interface for
extraction of process data.

Saturday, March 11, 2006

S10 Well Known Processes

(1) Memory scheduler

proc_sched

(2) init process

proc_init

(3) pageout deamon

proc_pageout

(4) fsflush

proc_fsflush

S10 zones vs IBM LPARs

- Platform Availability - Zones is SPARC, x86 and x64 - with
OpenSolaris, who knows what else, LPARs are extremely vendor specific

- Performance overhead - Zones offer 0 perf overhead for applications,
as there is no virtualization layer (ala hypervisor) that apps have to
punch through. The overall system overhead for Zones is minimal, due to
all the resource sharing. Contrast this architecturally against LPARs.

- Managebability - LPARs do nothing for manageability of the datacenter,
all they do is consolidate the hardware footprint. For a large %age of
apps, Zones resolve a large part of the management headache

- Obserability - this is *key*. If an app in a LPAR is not behaving,
there is no way for someone inside that OS instance to see whats going
on around itself. You cant call someone up who can check the entire
platform to try and diagnose the problem. With Zones, the global zone
admin has full visibility into all the local zones, and into the entire
hardware platform, no virtualization.

Friday, March 10, 2006

MN Discovery and IP routing

1. CN sends a IP packet with as specific MN as destination address and CN as source address
2. CN router does know where MN is but just route IP packet to the router which is responsible for MN's HN
3. HA intercept the packets, HA knows that MN is not at HN now and forward the packet into the subnet with encapsulated and tunnelled to the COA. New header in front of old IP address will show
that HA is the source and COA is the target address
4. FA stract the orginal packet and send the data to MN with CN as the source

MN received the packet as it was from CN to MN directly

Donwlink data flow would be simple as MN send packet to CN in case of CN is not mobile

In case of mobile CN, 1-4 will be repeated

Monday, February 27, 2006

Solaris 10 bootcamp

http://avata.central/workshop/bootcamp/

#1 Solaris 10 platform Site for Container and DTrace

Next to the admin guide, we recently started releasing short how to guides on sun.com:
http://www.sun.com/software/solaris/reference_resources.jsp
and
http://www.sun.com/software/solaris/howtoguides/containersLowRes.jsp
talks about pools and zones.

Niagara Emlxs(7D) fibre channel Panic for stopping CPU context switch

It seems the fibre channel nexus driver with SCSA interface for the emlxs(7D) fibre channel adapter is doing auto request sense and tagged queueing which raises packet timeout. As the first thread to initiat a system panic records and renders the system quiescent by stopping other processors.

In turns cause Sun4v specific xt_sync to wait for x-trap to finish. In addition, due to the panic uts forces other processors o trap into panic idle so they will no not receive cross-calls.

If we should do detach and attach again to see how system react to the HW interrupts.


A email from mailing list

>
> Did anyone else see something similar to this on Solaris 10 3/05 HW2 s10s_hw2wos_05 SPARC on T2000?
> Any suggestions?
>
> Regards,
> Jignesh
>
> Feb 25 01:31:59 bcu3510-1 emlxs: [ID 349649 kern.info] [1.0126]emlxs0: NOTICE: 910: Packet timeout. (chip a
> bort: sbp=60015d1e858 iotag=1e42 tmo=60)
> Feb 25 01:31:59 bcu3510-1 scsi: [ID 107833 kern.warning] WARNING: /pci@7c0/pci@0/pci@1/pci@0,2/SUNW,emlxs@1
> /fp@0,0/ssd@w226000c0ffa98fc0,1 (ssd10):
> Feb 25 01:31:59 bcu3510-1 SCSI transport failed: reason 'timeout': retrying command
> Feb 25 01:56:14 bcu3510-1 emlxs: [ID 349649 kern.info] [1.0126]emlxs0: NOTICE: 910: Packet timeout. (chip a
> bort: sbp=600154995e8 iotag=34a7 tmo=60)
> Feb 25 02:00:24 bcu3510-1 emlxs: [ID 349649 kern.info] [1.0126]emlxs0: NOTICE: 910: Packet timeout. (chip a
> bort: sbp=3003f4cd168 iotag=3328 tmo=60)
> Feb 25 06:31:09 bcu3510-1 unix: [ID 547063 kern.notice] Cross trap sync timeout at cpu_sync.xword[0]: 0x100
> 000000000000
> Feb 25 06:31:09 bcu3510-1 unix: [ID 350512 kern.notice] panic: failed to stop cpu0
> Feb 25 06:31:09 bcu3510-1 unix: [ID 836849 kern.notice]
> Feb 25 06:31:09 bcu3510-1 ^Mpanic[cpu23]/thread=30001f4a6c0:
> Feb 25 06:31:09 bcu3510-1 unix: [ID 990398 kern.notice] xt_sync: timeout
> Feb 25 06:31:09 bcu3510-1 unix: [ID 100000 kern.notice]
> Feb 25 06:31:09 bcu3510-1 genunix: [ID 723222 kern.notice] 000002a101c461d0 unix:xt_sync+17c (d8e29fb05044,
> 2a101c46280, 0, 0, d8e29dd37a18, d8e29dd37a20)
> Feb 25 06:31:09 bcu3510-1 genunix: [ID 179002 kern.notice] %l0-3: 0000000000000001 8000000000000000 00000
> 00000000000 000002a101c46280
> Feb 25 06:31:09 bcu3510-1 %l4-7: 000000000184d800 0000000001038800 0100000000000000 0000000001dcd650
> Feb 25 06:31:09 bcu3510-1 genunix: [ID 723222 kern.notice] 000002a101c462c0 unix:hat_unload_callback+808 (7
> 0000000000, 2a101c465f0, 0, 0, 0, 300005b9e08)
>
>

Saturday, February 25, 2006

Grid Data Management

Virtual data abstraction

(1) data model federation
(2) data transformation
(3) replication
(4) data mediation

Archiving, Annotation, Meta data service

Friday, February 24, 2006

AM 6.x DIT

----------Role Management-----------------


(1) Add static service role with no permission


cn=ITStaticRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=No Permission Description
iplanet-am-role-type=3
cn=ITStaticRole
objectClass=top
objectClass=iplanet-am-managed-role
objectClass=ldapsubentry
objectClass=nssimpleroledefinition
objectClass=nsmanagedroledefinition
objectClass=nsroledefinition


(2) ITStatic Administrative Role with no permission


cn=ITStaticAdminRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=No Permission Description
iplanet-am-role-managed-container-dn=o=ITOrg,dc=jesswitch,dc=com
iplanet-am-role-type=2
cn=ITStaticAdminRole
objectClass=top
objectClass=iplanet-am-managed-role
objectClass=ldapsubentry
objectClass=nssimpleroledefinition
objectClass=nsmanagedroledefinition
objectClass=nsroledefinition


(3) add static service role with admin permission


cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=Organization Policy Admin Description
iplanet-am-role-type=3
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (all) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter="(objectclass=sunismanagedorganization)")(targetattr = "sunRegisteredServiceName") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (read,write,search) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=iPlanetAMAuthService,ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access Auth Service deny"; deny (add,write,delete) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Organization Admin Role,o=ITOrg,dc=jesswitch,dc=com))))(targetattr = "*")(version 3.0; acl "Organization Policy Admin access allow"; allow (read,search) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
cn=ITStaticServiceAdminPermissionRole
objectClass=top
objectClass=iplanet-am-managed-role
objectClass=ldapsubentry
objectClass=nssimpleroledefinition
objectClass=nsmanagedroledefinition
objectClass=nsroledefinition

o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=modify
inetDomainStatus=Active
o=ITOrg
objectClass=sunISManagedOrganization
objectClass=sunNameSpace
objectClass=top
objectClass=sunManagedOrganization
objectClass=organization

cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=modify
iplanet-am-role-aci-description=Organization Policy Admin Description
iplanet-am-role-type=3
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (all) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter="(objectclass=sunismanagedorganization)")(targetattr = "sunRegisteredServiceName") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (read,write,search) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=iPlanetAMAuthService,ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access Auth Service deny"; deny (add,write,delete) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Organization Admin Role,o=ITOrg,dc=jesswitch,dc=com))))(targetattr = "*")(version 3.0; acl "Organization Policy Admin access allow"; allow (read,search) roledn = "ldap:///cn=ITStaticServiceAdminPermissionRole,o=ITOrg,dc=jesswitch,dc=com";)
cn=ITStaticServiceAdminPermissionRole
objectClass=top
objectClass=iplanet-am-managed-role
objectClass=ldapsubentry
objectClass=nssimpleroledefinition
objectClass=nsmanagedroledefinition
objectClass=nsroledefinition
iplanet-am-role-display-options=actionpeoplecontainerproperties=viewproperties
iplanet-am-role-display-options=actionroleproperties=viewproperties
iplanet-am-role-display-options=actiongroupproperties=viewproperties
iplanet-am-role-display-options=actiongroupcontainerproperties=viewproperties
iplanet-am-role-display-options=actionorganizationalunitproperties=viewproperties
iplanet-am-role-display-options=actionpolicyproperties=fullaccessobject
iplanet-am-role-display-options=actionentityproperties=viewproperties
iplanet-am-role-display-options=actionserviceproperties=fullaccessobject
iplanet-am-role-display-options=actionorganizationproperties=viewproperties
iplanet-am-role-display-options=actionuserproperties=modifyproperties


(4) Add Service Filtered Role with no admin permission


cn=ITFilteredRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=No Permission Description
iplanet-am-role-type=3
nsRoleFilter=(&(uid=*)(uid=inetuser))
cn=ITFilteredRole
objectClass=nsfilteredroledefinition
objectClass=nscomplexroledefinition
objectClass=top
objectClass=ldapsubentry
objectClass=iplanet-am-managed-filtered-role
objectClass=nsroledefinition
objectClass=iplanet-am-managed-role

(5) Add filtered admin permission service role

cn=ITFilteredServiceAdminRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=Organization Admin Description
iplanet-am-role-type=3
nsRoleFilter=(&(uid=*)(objectclass=inetuser))
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///cn=ITFilteredServiceAdminRole,o=ITOrg,dc=jesswitch,dc=com")(targetattr="*")(version 3.0; acl "S1IS Organization Admin Role access deny"; deny (write,add,delete,compare,proxy) roledn = "ldap:///cn=ITFilteredServiceAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com))))(targetattr = "nsroledn")(targattrfilters="add=nsroledn:(nsroledn=*,o=ITOrg,dc=jesswitch,dc=com),del=nsroledn:(nsroledn=*,o=ITOrg,dc=jesswitch,dc=com)")(version 3.0; acl "S1IS Organization Admin Role access allow"; allow (all) roledn = "ldap:///cn=ITFilteredServiceAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com))))(targetattr != "nsroledn")(version 3.0; acl "S1IS Organization Admin Role access allow all"; allow (all) roledn = "ldap:///cn=ITFilteredServiceAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
cn=ITFilteredServiceAdminRole
objectClass=nsfilteredroledefinition
objectClass=nscomplexroledefinition
objectClass=top
objectClass=ldapsubentry
objectClass=iplanet-am-managed-filtered-role
objectClass=nsroledefinition
objectClass=iplanet-am-managed-role

o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=modify
inetDomainStatus=Active
o=ITOrg
objectClass=sunISManagedOrganization
objectClass=sunNameSpace
objectClass=top
objectClass=sunManagedOrganization
objectClass=organization


(6) add filtered administrative role

cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=add
iplanet-am-role-aci-description=Organization Policy Admin Description
iplanet-am-role-managed-container-dn=o=ITOrg,dc=jesswitch,dc=com
iplanet-am-role-type=2
nsRoleFilter=(&(uid=*)(objectclass=inetuser))
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter="(objectclass=sunismanagedorganization)")(targetattr = "sunRegisteredServiceName") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (read,write,search) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Organization Admin Role,o=ITOrg,dc=jesswitch,dc=com))))(targetattr = "*")(version 3.0; acl "Organization Policy Admin access allow"; allow (read,search) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=iPlanetAMAuthService,ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access Auth Service deny"; deny (add,write,delete) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (all) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
cn=ITFilteredAdminRole
objectClass=nsfilteredroledefinition
objectClass=nscomplexroledefinition
objectClass=top
objectClass=ldapsubentry
objectClass=iplanet-am-managed-filtered-role
objectClass=nsroledefinition
objectClass=iplanet-am-managed-role

o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=modify
inetDomainStatus=Active
o=ITOrg
objectClass=sunISManagedOrganization
objectClass=sunNameSpace
objectClass=top
objectClass=sunManagedOrganization
objectClass=organization

cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com
persistentSearch-changeType=modify
iplanet-am-role-aci-description=Organization Policy Admin Description
iplanet-am-role-managed-container-dn=o=ITOrg,dc=jesswitch,dc=com
iplanet-am-role-type=2
nsRoleFilter=(&(uid=*)(objectclass=inetuser))
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter="(objectclass=sunismanagedorganization)")(targetattr = "sunRegisteredServiceName") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (read,write,search) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///o=ITOrg,dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Organization Admin Role,o=ITOrg,dc=jesswitch,dc=com))))(targetattr = "*")(version 3.0; acl "Organization Policy Admin access allow"; allow (read,search) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=iPlanetAMAuthService,ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access Auth Service deny"; deny (add,write,delete) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
iplanet-am-role-aci-list=o=ITOrg,dc=jesswitch,dc=com:aci: (target="ldap:///ou=services,*o=ITOrg,dc=jesswitch,dc=com")(targetattr = "*") (version 3.0; acl "Organization Policy Admin Role access allow"; allow (all) roledn = "ldap:///cn=ITFilteredAdminRole,o=ITOrg,dc=jesswitch,dc=com";)
cn=ITFilteredAdminRole
objectClass=nsfilteredroledefinition
objectClass=nscomplexroledefinition
objectClass=top
objectClass=ldapsubentry
objectClass=iplanet-am-managed-filtered-role
objectClass=nsroledefinition
objectClass=iplanet-am-managed-role
iplanet-am-role-display-options=actionpeoplecontainerproperties=viewproperties
iplanet-am-role-display-options=actionroleproperties=viewproperties
iplanet-am-role-display-options=actiongroupproperties=viewproperties
iplanet-am-role-display-options=actiongroupcontainerproperties=viewproperties
iplanet-am-role-display-options=actionorganizationalunitproperties=viewproperties
iplanet-am-role-display-options=actionpolicyproperties=fullaccessobject
iplanet-am-role-display-options=actionentityproperties=viewproperties
iplanet-am-role-display-options=actionserviceproperties=fullaccessobject
iplanet-am-role-display-options=actionorganizationproperties=viewproperties
iplanet-am-role-display-options=actionuserproperties=modifyproperties


(7) assign service to role

Niagara PICe bus initalization error

As S10 FMA trace reports, Fire Fabric ereport as a leaf PCIe device sends
an error message to root complex, the nexus driver publishes this ereport.

(1) A faulty PCI device off of a pci-pci bridge could see ereport.io.pci.mdpe
and ereport.io.pci.target-mdpe

(2) Faulty PCI device could see ereport.io.pci.sec-rserr

(3) A defective PCI device driver may cause ereport.io.pci.sec-dpe

In general, it seems the above HW issue raises interrupt for handler
of PCIE fabric block and dump the "Fatal PCIe Fabric Error has occurred"


Thanks

Lei
>>>
>>>
>>> ------------------------------------------------------------------------
>>>
>>> Configuring devices.
>>> >>> SUNW-MSG-ID: SUNOS-8000-0G, TYPE: Error, VER: 1, SEVERITY: Major
>>> EVENT-TIME: 0x43ebc150.0x1dcd5ca8 (0x333e1920bc)
>>> PLATFORM: SUNW,Sun-Fire-T200, CSN: -, HOSTNAME:
>>> SOURCE: SunOS, REV: 5.10 Generic_118822-25
>>> DESC: Errors have been detected that require a reboot to ensure system
>>> integrity. See http://www.sun.com/msg/SUNOS-8000-0G for more information.
>>> AUTO-RESPONSE: Solaris will attempt to save and diagnose the error telemetry
>>> IMPACT: The system will sync files, save a crash dump if needed, and reboot
>>> REC-ACTION: Save the error summary below in case telemetry cannot be saved
>>>
>>> ereport.io.fire.fabric ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0" ] msg_code=31 req_id=402 cap_off=44 aer_off=100
>>> sts_reg=4110 sts_sreg=0 dev_sts_reg=6 aer_ce=0 aer_ue=0 aer_sev=60010 aer_h1=
>>> 4000001 aer_h2=3 aer_h3=4010000 aer_h4=40100 saer_ue=1080 saer_sev=1340
>>> saer_h1=1f061030 saer_h2=f0 saer_h3=ff114040 saer_h4=0 severity=9
>>>
>>> ereport.io.pci.mdpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0" ] pci-status=110 pci-command=547
>>>
>>> ereport.io.pci.target-mdpe ena=333e08995805c01 detector=[ version=0 scheme=
>>> "dev" device-path="/pci@7c0" ]
>>>
>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>
>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>
>>> ereport.io.pci.mdpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-status=110 pci-command=547
>>>
>>> ereport.io.pci.target-mdpe ena=333e08995805c01 detector=[ version=0 scheme=
>>> "dev" device-path="/pci@7c0/pci@0" ]
>>>
>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>
>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>
>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0/pci@1/pci@0,2" ] pci-sec-status=c2a0 pci-bdg-ctrl=
>>> 23
>>>
>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0/pci@0/pci@1/pci@0,2" ] pci-sec-status=c2a0 pci-bdg-ctrl=
>>> 23
>>> ereport.io.fire.fabric ena=333e2133d405c01 detector=[ version=0 scheme="dev"
>>> device-path="/pci@7c0" ] msg_code=33 req_id=402 cap_off=44 aer_off=100
>>> sts_reg=10 sts_sreg=0 dev_sts_reg=0 aer_ce=0 aer_ue=0 aer_sev=60010 aer_h1=
>>> 4000001 aer_h2=3 aer_h3=4010000 aer_h4=40100 saer_ue=1000 saer_sev=1340
>>> saer_h1=1f061030 saer_h2=f0 saer_h3=ff114040 saer_h4=0 severity=9
>>>
>>>
>>> panic[cpu23]/thread=2a100f1dcc0: Fatal PCIe Fabric Error has occurred
>>>
>>>
>>> 000002a100f85d70 px:px_err_fabric_intr+c0 (300005afe00, 31, 300008c42e0, 402, 300008d8f20, 402000000000000)
>>> %l0-3: 00000300008c1bd8 00000000ffffffff fffffffffffffffe 0000000000000000
>>> %l4-7: 000000000183e800 0000000001271800 0000000000000000 00000300008c42f0
>>> 000002a100f85e50 px:px_msiq_intr+1a4 (300008e9da8, 0, 1269f54, 0, 300005afe00, 300008d8f20)
>>> %l0-3: 00000300008c1bd8 00000300005bd7a0 0000000000000000 000002a100f85f10
>>> %l4-7: 000002a100f85f40 00000300008d8f20 0000000000000000 0000000000000031
>>> 000002a100f85f50 unix:current_thread+140 (16, 800000, 7fffe7, 7fffe7, 0, 12)
>>> %l0-3: 000000000100994c 000002a100f1d021 000000000000000e 00000000000007f9
>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000002a100f1d8d0
>>> 000002a100f1d970 unix:cpu_halt+c0 (0, 17, 30001a68000, 16, 30001a68000, 1)
>>> %l0-3: 00000000018450f8 0000000000000001 0000000000000002 0000000000000000
>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000000000103735c
>>> 000002a100f1da20 unix:idle+128 (1814800, 0, 30001a68000, ffffffffffffffff, 17, 1813400)
>>> %l0-3: 0000060001d4f600 000000000000001b 0000000000000000 ffffffffffffffff
>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000000000103735c
>>>
>>>
>>>
>>> ------------------------------------------------------------------------
>>>
>>> Subject:
>>> [Fwd: RE: Sun Niagara System problem]
>>> From:
>>> Prameet Chhabra
>>> Date:
>>> Tue, 21 Feb 2006 13:35:50 -0800
>>> To:
>>> Steve Katzman
>>>
>>> To:
>>> Steve Katzman
>>>
>>>
>>> Steve,
>>>
>>> looks like it is the newest version that they are using, can you get me help on this one.
>>>
>>> thanks
>>> Prameet
>>>
>>> -------- Original Message --------
>>> Subject: RE: Sun Niagara System problem
>>> Date: Tue, 21 Feb 2006 16:24:00 -0500
>>> From: Eddie Ng
>>> To: Prameet.Chhabra@Sun.COM , pete salerno
>>>
>>> Yes, we did use the latest version which is 01/06.
>>> I found out the requirement o/s version on Sun site.
>>> Yes, we know that there was a preinstalled version of Solaris 10 on one of the disk, we didn't use that disk, because we normally have a special configuration of file systems and tools for our test system.
>>> I had initial success of installing the o/s at first, but after a reboot, the error message started to appear, I also tried to use the preinstalled version, but same problem occurs, I couldn't get far enough for the installation wizard to come up.
>>>
>>> Thank you,
>>>
>>> Edward Ng
>>> Ulticom, Inc.
>>> System Administrator
>>> 1020 Briggs Rd
>>> Mount Laurel, NJ 08054
>>> 856-638-2608
>>> eddie.ng@ulticom.com
>>>
>>> -----Original Message-----
>>> From: Prameet Chhabra [mailto:Prameet.Chhabra@Sun.COM]
>>> Sent: Tuesday, February 21, 2006 4:12 PM
>>> To: Eddie Ng; pete salerno
>>> Subject: Re: Sun Niagara System problem
>>>
>>>
>>> Eddie,
>>>
>>> Did the box come up with any Solaris preloaded it should and why did you need to
>>> install Solaris?....Just out of curiosity what version of Solaris are you
>>> using....? the reason I ask you is because some older version of Solaris 10
>>> (i.e. not the hardware-specific release HW2) doesn't have the sun4v components
>>> and won't work for the T2000. so that could be the reason.
>>>
>>> thanks
>>> Prameet
>>>
>>> Eddie Ng wrote:
>>>
>>>> Sun Niagara System Hostid: 83d936ca
>>>> Good day Prameet, thank you for your information.
>>>> we were trying to install the latest version of Solaris 10 on this system, we had success at first, but when we rebooted the system, the os won't come up, we tried to reinstalled the os but was unsuccessful due to error message from the console. I've unplug the system and then tried again, no success.
>>>> I've attached the error message from the console, please investigate and let us know our course of action.
>>>>
>>>> Thank you,
>>>>
>>>> Edward Ng
>>>> Ulticom, Inc.
>>>> System Administrator
>>>> 1020 Briggs Rd
>>>> Mount Laurel, NJ 08054
>>>> 856-638-2608
>>>> eddie.ng@ulticom.com
>>>>
>>>>
>>>> ------------------------------------------------------------------------
>>>>
>>>> Configuring devices.
>>>> >>>> SUNW-MSG-ID: SUNOS-8000-0G, TYPE: Error, VER: 1, SEVERITY: Major
>>>> EVENT-TIME: 0x43ebc150.0x1dcd5ca8 (0x333e1920bc)
>>>> PLATFORM: SUNW,Sun-Fire-T200, CSN: -, HOSTNAME:
>>>> SOURCE: SunOS, REV: 5.10 Generic_118822-25
>>>> DESC: Errors have been detected that require a reboot to ensure system
>>>> integrity. See http://www.sun.com/msg/SUNOS-8000-0G for more information.
>>>> AUTO-RESPONSE: Solaris will attempt to save and diagnose the error telemetry
>>>> IMPACT: The system will sync files, save a crash dump if needed, and reboot
>>>> REC-ACTION: Save the error summary below in case telemetry cannot be saved
>>>>
>>>> ereport.io.fire.fabric ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0" ] msg_code=31 req_id=402 cap_off=44 aer_off=100
>>>> sts_reg=4110 sts_sreg=0 dev_sts_reg=6 aer_ce=0 aer_ue=0 aer_sev=60010 aer_h1=
>>>> 4000001 aer_h2=3 aer_h3=4010000 aer_h4=40100 saer_ue=1080 saer_sev=1340
>>>> saer_h1=1f061030 saer_h2=f0 saer_h3=ff114040 saer_h4=0 severity=9
>>>>
>>>> ereport.io.pci.mdpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0" ] pci-status=110 pci-command=547
>>>>
>>>> ereport.io.pci.target-mdpe ena=333e08995805c01 detector=[ version=0 scheme=
>>>> "dev" device-path="/pci@7c0" ]
>>>>
>>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>>
>>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>>
>>>> ereport.io.pci.mdpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-status=110 pci-command=547
>>>>
>>>> ereport.io.pci.target-mdpe ena=333e08995805c01 detector=[ version=0 scheme=
>>>> "dev" device-path="/pci@7c0/pci@0" ]
>>>>
>>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>>
>>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0/pci@1" ] pci-sec-status=c000 pci-bdg-ctrl=3
>>>>
>>>> ereport.io.pci.sec-dpe ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0/pci@1/pci@0,2" ] pci-sec-status=c2a0 pci-bdg-ctrl=
>>>> 23
>>>>
>>>> ereport.io.pci.sec-rserr ena=333e08995805c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0/pci@0/pci@1/pci@0,2" ] pci-sec-status=c2a0 pci-bdg-ctrl=
>>>> 23
>>>> ereport.io.fire.fabric ena=333e2133d405c01 detector=[ version=0 scheme="dev"
>>>> device-path="/pci@7c0" ] msg_code=33 req_id=402 cap_off=44 aer_off=100
>>>> sts_reg=10 sts_sreg=0 dev_sts_reg=0 aer_ce=0 aer_ue=0 aer_sev=60010 aer_h1=
>>>> 4000001 aer_h2=3 aer_h3=4010000 aer_h4=40100 saer_ue=1000 saer_sev=1340
>>>> saer_h1=1f061030 saer_h2=f0 saer_h3=ff114040 saer_h4=0 severity=9
>>>>
>>>>
>>>> panic[cpu23]/thread=2a100f1dcc0: Fatal PCIe Fabric Error has occurred
>>>>
>>>>
>>>> 000002a100f85d70 px:px_err_fabric_intr+c0 (300005afe00, 31, 300008c42e0, 402, 300008d8f20, 402000000000000)
>>>> %l0-3: 00000300008c1bd8 00000000ffffffff fffffffffffffffe 0000000000000000
>>>> %l4-7: 000000000183e800 0000000001271800 0000000000000000 00000300008c42f0
>>>> 000002a100f85e50 px:px_msiq_intr+1a4 (300008e9da8, 0, 1269f54, 0, 300005afe00, 300008d8f20)
>>>> %l0-3: 00000300008c1bd8 00000300005bd7a0 0000000000000000 000002a100f85f10
>>>> %l4-7: 000002a100f85f40 00000300008d8f20 0000000000000000 0000000000000031
>>>> 000002a100f85f50 unix:current_thread+140 (16, 800000, 7fffe7, 7fffe7, 0, 12)
>>>> %l0-3: 000000000100994c 000002a100f1d021 000000000000000e 00000000000007f9
>>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000002a100f1d8d0
>>>> 000002a100f1d970 unix:cpu_halt+c0 (0, 17, 30001a68000, 16, 30001a68000, 1)
>>>> %l0-3: 00000000018450f8 0000000000000001 0000000000000002 0000000000000000
>>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000000000103735c
>>>> 000002a100f1da20 unix:idle+128 (1814800, 0, 30001a68000, ffffffffffffffff, 17, 1813400)
>>>> %l0-3: 0000060001d4f600 000000000000001b 0000000000000000 ffffffffffffffff
>>>> %l4-7: 0000000000000000 0000000000000000 0000000000000000 000000000103735c
>>>
>>>
>>>
>>>
>>
>

Wednesday, February 22, 2006

Solaris Porcess management & Process Virtual Address Space

Solaris process
stack --- local variable
=================================
heap --- dynamic allocated
data section --- global variable
Binary(text section)

Data Grid & Data Access Grid Service

Structured Data in RDBMS, XML and structured assemblied binary.

Data manipulation, processing and analysis --- large scale, distribute data

requires data integration need for accessing, movement and computation

Data generation, postporcessing and analysis

(1) Data Mining
(2) Integrated Data Access
Current data federation is not enough
(3) structure is required for data sharing

Collaboration data, grid service data and profile data

Saturday, February 18, 2006

Reliable Delivery

Direct output

(1) every system call executed by a job is sent home for execution at the shadow
(2) job's responsibility to commit before exit

All the above are the direct ouput

Need indirect output to resolve the issue

(3) grid console does not interactive

console---> agent ----> server

It allows execution continuing even after console and agent disconnected


More flexible coupling is for p-p network

Delivery Tx and Half Tx

File system: fsync


Delivery transaction (ordinary two phase commit)

f1---> f1.t--->f1.p--->f1

(1) Begin delivery transaction f1-->f1.t
(2) write data to f1.t
(3) run fsync, f1.t --> f1.p
(4) commit tx, f1.p --> f1

Half transaction to ensure the series of operations commited once only
There is no abort but carried forward. They are idempotent operation

fsync issued by client and client receive ack for the commit then
the half transaction is completed

remote execution output reliability

Operation fault-free

execution node ---> file system ----> storage
remote execution requires reliable protocols such as two phase commit

Friday, February 17, 2006

Ontario CPC

Niagara performance counter back endd
defines the event0 and event 1 pertaining
to pic0 and pic1

104 static const struct nametable Niagara_names0[] = {
105 {0x0, "SB_full"},
106 {0x1, "FP_instr_cnt"},
107 {0x2, "IC_miss"},
108 {0x3, "DC_miss"},
109 {0x4, "ITLB_miss"},
110 {0x5, "DTLB_miss"},
111 {0x6, "L2_imiss"},
112 {0x7, "L2_dmiss_ld"},
113 {NT_END, ""}
114 };
115
116 static const struct nametable *Niagara_names[2] = {
117 Niagara_names0,
118 Niagara_names1
119 };
120

job/task parallel and layer of grid computing

Job parallel

job is graphy hirerically

(1) early binding
(2) mid binding
(3) late binding

Task parallel is

(1) fault tolerant

(2) TCP connection with send/Ack protocols

(3) Worker autonmously pulls work

Seperate the allocation and assignment

Ontario Fan and Sensor with SC and traitional PICL tree model

Traditional, SPARC ships SUNWpiclr,PICL owns the uts common and ontario
specific PICL classes of tree model. Both plugins and library PICL property
mutation and accessing are controlled by picld(1M). In addition, life cycle is also
managed by picld(1M) via S10 fm. For a general report, prtpicl(1M) does the work.
Following the env model, they are published as a collection of system fans and cpu fans. It is a completed event driven publishing and event registration model to notify the events.

In Ontario, SC console, showenvironment,showfru does print the system env model.
Please note that the level of fan and sensor tree node does separate the system fans,
cpu fans etc. and published with associated fan slots.

Thursday, February 16, 2006

AM Fun

remote-auth.dtd specifies the authentication
protcols between client and server

(1) Should customized app SSOTokenListener
do the AuthContext clean up for AM in case of
SSO timeout and destroy events or AM instance
does the work

(2) if we communicate with /amserver/authservice
and follow the remote-auth.dtd, how to deal with
encided ir encrypted data such as if we
succeeded for the authentication. I mean without
SDK

(3) AM group only for policy now. Does not with services

(4) readm service schema change, for instance load
customized login module, sample does not work

This impacts the loginModule and post authentication registration
to realm, policy etc.

Extended Accounting and DTrace

The current challenge is how to provide the billing
strategy. Each customer will be operating in it's own Solaris
Container, but there is no obvious way to measure the utilisation by
container.

DTRACE is the obvious choice to enable the customer
to create such a billing infrastructure. Simple calculation of the number of CPU-Seconds and read/write IO's by container over a period of time is the desired result.

The uts core exacct usage and recording routines(exacct) and associated
D fbt probes (fbt:genunix::entry) requires getacct(2), putacct(2), and
wracct(2) system calls which is on top of exacctsys to trap into kernel
instead of call back.

Specifically, the fbt provider will do the work
to probe the uts structure such as proc_usage_t,task_usage_t
and flow_usage_t.

Wednesday, February 15, 2006

programmtically login

(1) From AuthContext

new AuthContext("orgname").login("authtype.indextype","auth name");


(2) token vaildation for login request


(3) From service point of view without API

http://:/authservice

But it requires remote-auth.dtd

programmtically logout

AM Authentication service and session mgt does provide
the logout

(1) From SSO session management API


SSOTokenManager.destroy(token)


(2) From Authentication Context State Mgt API

To clean up all authentication state management infor
AuthContext(token).logout()

(3) Service point of view

http://:/amserver/Logout

Tuesday, February 14, 2006

Post Authentication and AM previliged query user ? amadmin or proxy account

Writing a Post Authentication class for a customer with AM 7.0
I need to obtain an admin-level connection to AMStore to
manipulate AMUser object instances. To reuse existing AM SDK
configuration files to get the amadmin dn and password,
instead of providing my own config file.

How to programmatically get the amadmin DN and password ?
DN is easy to retrieve in AMConfig.properties. But what
about password ? Is there a public or private API for doing this ?

Although you can get the user name and password and generate the admin SSOToken,
the recommended way to get the admin SSOToken is as follows:

SSOToken token = (SSOToken) AccessController.doPrivileged(
com.sun.identity.security.AdminTokenAction.getInstance());


However why not to have API for proxy authentication and authorization instead of
querying amadmin identity for identity management ?

Need Answer
Writing a Post Authentication class for a customer with AM 7.0
I need to obtain an admin-level connection to AMStore to
manipulate AMUser object instances. To reuse existing AM SDK
configuration files to get the amadmin dn and password,
instead of providing my own config file.

How to programmatically get the amadmin DN and password ?
DN is easy to retrieve in AMConfig.properties. But what
about password ? Is there a public or private API for doing this ?

Although you can get the user name and password and generate the admin SSOToken,
the recommended way to get the admin SSOToken is as follows:

SSOToken token = (SSOToken) AccessController.doPrivileged(
com.sun.identity.security.AdminTokenAction.getInstance());


However why not to have API for proxy authentication and authorization instead of
querying amadmin identity for identity management ?

Need Answer

Monday, February 13, 2006

ndd(1M) and uts network driver link speed

ndd(1M) does support uts implementation for

hme(7D), bge(7D), dmfg(7D), eri(7D), rge

Besides functions defined to support ndd(1M),
there are variables are defined to use for
configuring link-operation for all the above
interfaces in the system. These parameters
may be changed per interface using ndd (1M)

However, only rge and bge does create kstats(1M)
corresponding functions and structures to
NDD parameters.

Evenmore, all these parameters may also be specified
as properties using the .conf file mechanism f
or each interface.

Therefore, for e1000g(7D) interface


/kernel/drv/e1000g.conf

32–bit driver configuration file.
/kernel/drv/sparcv9/e1000g

SPARC e1000g driver binary.
/kernel/drv/amd64/e1000g

64-bit x86 e1000g driver binary.
/kernel/drv/e1000g

32-bit x86 e1000g driver binary.


For e1000g(7D)

kernel/drv/e1000g.conf

32–bit driver configuration file.
/kernel/drv/sparcv9/e1000g

SPARC e1000g driver binary.
/kernel/drv/amd64/e1000g

64-bit x86 e1000g driver binary.
/kernel/drv/e1000g

32-bit x86 e1000g driver binary.

Grid Resource Discovery

Query the distributed state of the Grid and identify the resource characteristics and state matching the selection

Determine the distribute resource state

Seperate the resource discovery and resource allocation

Grid Resource Management

Resource Mgt is mutual agreement between a resource provider and a resource consumer
by provider agrees to supply caps for a specific task on half of consumer

What, How , When,

via a specialized QoS interface

(1) Task Submission: What task to do

Commit to to perform but
not Commit when, how and what other works

(2) Workload Mgt: How task to be done

Commit to a agreement of QoS by Provisioning
(3) On Demand Accessing: Advanced Reservation

(4) Coscheduling: make resource available by co-ordinatingm on-demand requirement


(5) Resource Brokering:

Friday, February 10, 2006

AM7 role management

(1) Static Role Creation






PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>










(2) create filtered role







PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>








(|(objectclass=inetOrgPerson)(uid=*))





(2) Realm Role Service Registration







PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI
DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>





iceName="iPlanetAMSessionService" >


125



35




3



5






(3) add user to role






PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>







uid=ituser1,ou=people,dc=jesswitch,dc=com





(1) user service registration to role






PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>









en_US



PST




en



Active







(2) admin service to realm role







PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>









false



5




100



25






(2) assign auth config service to realm






PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>





"iPlanetAMAuthConfiguration" >



ldapService






(3) assign disco service to realm role






PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>





"sunIdentityServerDiscoveryService" >






(8) service registration, there will no diff from
static role and filtered role.







PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI DTD//EN"
"jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>








125



35




3



5



amadmin realm role service registration

(1) Case Sensitiveness may need to be enforced
by underline IdRepo instead of AM layer

Not iplanetAMSessionService but iPlanetAMSessionService

(2) There may be one bug in the code for sub realm role service
registration. If the service is not registered under
the sub-realm, the service registration to the role
under the sub realm will show no error from amadmin
console and amadmin.error log.
(3) There may be another bug is that the amadmin writes
to the IdRepo and creates the role based CoS template
for the service registration.


But the corrected thing is that the service should be
registered under realm before the service is registered
under the role. The good thing is that both amadmin.error
and amadmin console output can be used to troubleshooting




>



>>
>>
>>
>>
>>
>>
>> >> PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI
>> DTD//EN"
>> "jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>> >
>>
>>
>>
>>
>>
>> >> iceName="iPlanetAMSessionService" >
>>
>>
>> 125
>>

>>
>>
>> 35
>>

>>
>>
>>
>> 3
>>

>>
>>
>> 5
>>

>>

>>

>>

>>
>> (2) amadmin error output
>> # /opt/SUNWam/bin/amadmin --runasdn amadmin --verbose --password ll51>
>> Info 107: Calling XML PARSER
>> Info 108: XML file to parse:jesswitchAssignSessionServiceToRealmRole.xml
>> Info 101: Processing jesswitchAssignSessionServiceToRealmRole.xml
>> Info 111: Requests generated by amadmin
>> Request Description: Assign Service to Identity in Realm /itrealm
>> iplanet-am-session-max-idle-time =
>> 35
>> iplanet-am-session-max-session-time =
>> 125
>> iplanet-am-session-quota-limit =
>> 5
>> iplanet-am-session-max-caching-time =
>> 3
>>
>> Identity Request:
>> Assign Service iplanetAMSessionService to itrole of IdType: role in
>> Realm /itrealm
>> iplanet-am-session-max-idle-time = [35]
>> iplanet-am-session-max-session-time = [125]
>> iplanet-am-session-quota-limit = [5]
>> iplanet-am-session-max-caching-time = [3]
>> Error 10: Cannot process requests:
>> Service iplanetAMSessionService not registered.
>>
>>
>> (3) amadmin.error log
>>
>> mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm"2006-02-09
>> 21:22:06" "IdentityRequests|Service iplanetAMSessionService not
>> registered." amAdmin.error AMADMIN-2
>> dc=jesswitch,dc=com "Not Available" INFO
>> "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com"
>> 10.6.137.48 "cn=dsameuser,ou=DSAME
>> Users,dc=jesswitch,dc=com" v1280-137-08 "2006-02-09
>> 21:22:06" "Error 10: Cannot process requests:
>> com.iplanet.am.admin.cli.AdminException: Service
>> iplanetAMSessionService not registered." amAdmin.error "Not
>> Available" dc=jesswitch,dc=com "Not Available" INFO
>> "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com"
>> 10.6.137.48 "cn=dsameuser,ou=DSAME
>> Users,dc=jesswitch,dc=com" 10.6.137.48
>>


--


Lei Liu (Larry)
Member of Technical Staff
Horizontal Technology
Software MAX
Mailstop: UNWK 12-209
Address: 7777 Gateway Boulevard, Bldg 12 Newark, CA 94560
Phone: (510) 574-7187 (x37187)
Email: lei.liu@sun.com, ttoulliu2002@gmail.com
Fax: (510) 574-6074
Blog:http://ttoulliu2002.blogspot.com
Skype: ttoulliu2002

Dennis:

Thanks for the reply. Hope you do not mind if
I have questions below for you.

(1) Case Sensitiveness may need to be enforced
by underline IdRepo instead of AM layer
(2) There may be one bug in the code for sub realm role service
registration. If the service is not registered under
the sub-realm, the service registration to the role
under the sub realm will show no error from amadmin
console and amadmin.error log.
(3) There may be another bug is that the amadmin writes
to the IdRepo and creates the role based CoS template
for the service registration.

Thanks

Lei



Dennis Seah wrote:

> in your XML, can you replace iplanetAMSessionService
> with iPlanetAMSessionService
>
> and try again?
>
> THANK YOU !
>
>
> Lei Liu wrote:
>
>> Hi:
>>
>> I have amadmin data file below for service registration.
>> I have the session service registered under sub realm.
>> But it can not be registered for the sub realm role.
>>
>>
>> (1) It does not work. amAdmin error is attached too.
>>
>>
>>
>>
>>
>>
>> >> PUBLIC "-//iPlanet//Sun Java System Access Manager 2005Q4 Admin CLI
>> DTD//EN"
>> "jar://com/iplanet/am/admin/cli/amAdmin.dtd"
>> >
>>
>>
>>
>>
>>
>> >> iceName="iplanetAMSessionService" >
>>
>>
>> 125
>>

>>
>>
>> 35
>>

>>
>>
>>
>> 3
>>

>>
>>
>> 5
>>

>>

>>

>>

>>
>> (2) amadmin error output
>> # /opt/SUNWam/bin/amadmin --runasdn amadmin --verbose --password ll51>
>> Info 107: Calling XML PARSER
>> Info 108: XML file to parse:jesswitchAssignSessionServiceToRealmRole.xml
>> Info 101: Processing jesswitchAssignSessionServiceToRealmRole.xml
>> Info 111: Requests generated by amadmin
>> Request Description: Assign Service to Identity in Realm /itrealm
>> iplanet-am-session-max-idle-time =
>> 35
>> iplanet-am-session-max-session-time =
>> 125
>> iplanet-am-session-quota-limit =
>> 5
>> iplanet-am-session-max-caching-time =
>> 3
>>
>> Identity Request:
>> Assign Service iplanetAMSessionService to itrole of IdType: role in Realm /itrealm
>> iplanet-am-session-max-idle-time = [35]
>> iplanet-am-session-max-session-time = [125]
>> iplanet-am-session-quota-limit = [5]
>> iplanet-am-session-max-caching-time = [3]
>> Error 10: Cannot process requests:
>> Service iplanetAMSessionService not registered.
>>
>>
>> (3) amadmin.error log
>>
>> mmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmmm"2006-02-09 21:22:06" "IdentityRequests|Service iplanetAMSessionService not registered." amAdmin.error AMADMIN-2 dc=jesswitch,dc=com "Not Available" INFO "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com" 10.6.137.48 "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com" v1280-137-08 "2006-02-09 21:22:06" "Error 10: Cannot process requests: com.iplanet.am.admin.cli.AdminException: Service iplanetAMSessionService not registered." amAdmin.error "Not Available" dc=jesswitch,dc=com "Not Available" INFO "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com" 10.6.137.48 "cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com" 10.6.137.48
>>

Thursday, February 09, 2006

prsadm on Niagara platforms

For processor resource management, better practice would be
applying SRM model to create processor pool in order to better
control the resource. S10 kernel abstracts the platform specifics
which it should be transparent to user land and system mangement.





> > our psradm -n/-f commands are woefully inadequate ... someone needs to
> > expand them to include simple things like ranges "psradm -f 1..15",
> > "psradm -f 1..3 5..7 9..11 13..15" ... this would make up for a lot
> > of the nuisance of these tools with large numbers of virtual
> > processors
>
> psradm has ranges. Try "psradm -f 1-31" on a Niagara.

Java EE and .Net

There several important messages draw for the survey data

(1) It seems the top 2 driven factors which has dramatic impact of the success
of both Java and Enterprise Java:

Th success of the conventional RDBMS
The success of Traditional Internet Computing Model

(2) A big attention to Java EE connector and JMS which indicates
catch less than 40% usage. Event worse for WS-technology.
In addition, Java Messaging Model was not compelling againist
.Net


It indicates Enterprise Java is still considered as traditional
multi-tiered application development technology. There is still
a chance to loose the leadership from integration point of view which
could result in further slip in the multi-tiered application domain itself.
Microsoft owns large market share in integration domains. This
also count in IBM's mainframe integration strategy.


(3) How to maintain the endorsement on Java EE from RDBMS vendors ?
How to keep the hype on the Internet Computing Model and Deliver
highly performed platforms to the Internet world ?
How to get market share from WS and Integration domain ?

is where could be the turning point for Java and Enterprise Java Technology.

Wednesday, February 08, 2006

Autonomous Policy Neogotiations

With the autonomy of the policy negotiation, it requires one participant
to understand access control requirements restricted by counter party.
Therefore, there is an interactive process of policy disclosure underneath.
However, the mutual trust limits by the sensitive of the policy to
authorized disclosure which includes public and private ones as asset of
the parties needs to be protected as common resource. The policy expression
would require more flexibilities for the policy automation management. This
includes the authorization and obligation policies. There are also high level
abstract human readable policies and low level detailed machine readable policies.


In addition, service consumer and provider do not have existing relationship on
the policy constraints as the protected resources are initially accessed.
It means it requires a discovery scheme for policy negotiation to be
initiated.


Moreover, traditional CA signed certificate based disclosure requires third party
authorities for establish the trust. In order to eliminate the external
dependencies, the designated policy agreement is to built on a robust bilateral
negotiation protocol with finer grained control over the separated sequence
of actions to incrementally solving the coalition which results in partial
acceptance and counter offers. It should cover both explicit and constructive
negotiation use cases.


Furthermore, traditional access control does requires
user registration with predefined access control policies to local PDP
and identity is authorized by SP which may protected by different PDPs.
Therefore, traditional centralized identity management approaches give less or zero
negotiation for service consumer privacy polices. Even it address the
common needs of enterprise computing but it is less sufficient to
policy simplification and co-ordinating across multiple PDPs. More important,
for those entities without existing relationship, access control does not
applied to identity. In general, we need to define the protocol for
conjunct policy agreements not only for service providers but also consumers.


In spite of the above considerations, a wide range of mobile devices
gradually become popular consumer service accessing apparatus. However,
with the relative limited processing power and memory space on the mobile
client devices, the zero-less overheated elite policy management entities
are demanded to represent the each party for handshaking. Due to the nature
of wireless transport and readability of the data transferring, the accuracy of the
data communications is one of the concerns. Hence, the efficient, reliable
and secured protocol is demanded for the broad based mobile communication
service provider and consumer trust authorization and access control with
policy negotiation.


On the another hand, different hardware, software and device vendors provide
different hardware platform architecture, operating environments from OS kernel,
programming platforms to device drivers. This requires a cross platform policy
negotiation framework employed with industrial standards. However, it means
heavy loaded enterprise policy languages and standards should be translated
to cater to the wide range of usage.

In the large distributed computing environment, administrative policies
are created and persistented in different policy repositories.
Policy conflicts arised from the conflicted requirements or errors.
And constraint satisfaction are the normal scenoior during the real work policy
negotiation.It is up to a proper protocol of disagreement solving to refine
the agreement in order to derive the conclusion to grant or deny the requests.

Even more, with the shift of the computing paradigm from traditional
hosting computation to usage based utility computing such as grid computing,
the policy negotiation does not depends on service consumer and provider but also
the dynamic usage of the resources. In addition the content applied to policies
could be generated at run time. It requires the policy management should be
dynamic replaceable and enabled. In addition, in the open distributed systems,
there is no security domain to applied without existing relationship. This
includes the release of both known resources and dynamic generated resources.



In general, an automous policy negotiation utility in purpose of an adaptive
policy automation management framework is proposed for a serial inventions
and publications with a blueprint of specific interoperability with efficient,
portable and reliable protocol for policy discovery, policy and credential delivery,
lightweight policy presentation footprint,policy automated component and entities,
policy protection, conflict detection and resolution (both specification time
and run time),constraint meta policy,policy prioritization, policy decomposition,
failure handling, industry standard integration,dynamic policy computation,dynamic
content classification, policy mapping, policy verification and policy analyzer.

cpu time for page fault, the modified page numbers

MMU page fault exception does address major, minor and protection
faults as it requires interrupted in order for a process to
trap in kernel. DTrace built-in probe offers a high level overview
on the latency and count metrics such as maj_fault probe, as_fault probe.
If you want to aggregate the all latency caused by page in not only because of
page fault, try pagin probe.

However, if you want have grained level instrumentation, Please consider
instrument unix module function calls such as pagefault entry, as_fault_* entry,
anon_map_privatepages,anon_private etc. and also segement driver fault in case.
Dtrace fbt provider does address the need.

Monday, February 06, 2006

Performance Counter and Core

Since SPARC III, HW counter, High resoluation timer and virtual clock address the most
efficient to deliver the most accurate performance data. However, it will be a major limitation
to access performance within NG-Zone with the introduction of the S10 container technology.
Therefore, the traditional counter approach may be challenged by the latest virtualization and
partition service requirements.

However, system monitoring is driven by serveral major factors:
status check, performance tunning, debugging and troubleshooting

Majority system management is not required by debugging and tunning level performance resolutions.

In addition, all HW counter requires kernel based accessing. libcpc(3LIB) is one of the performance coutner library for uts cpu_t structure. The same issues as libkstat(3LIB), cpustat(1M) , cputrack(1M) CLI call routines and realetd user land structure associated with chip_id, cpuid, status which lacks of core support. Moreover, the same libkstat(3LIB) kstat_data_lookup for kstat_t and kstat_named_t are required to be handled.

I could not see the major gain for libcpc(3LIB) either in terms of the limitation of performance counter,core support, and dependency on libkstat(3LIB).

Just for sharing, libkstat(3LIB) requires execute Kernel
static library call routines as /on/usr/src/cmd to
open /dev/kstat and kstat_lookup to uses existing
common user land kstat_t strcutre Afterwards,
kstat_data_lookup should be invoked to downcast
to kstat_named_t in order to retrieve the exported
templated cpu_info structure for "core_id" and
KSTAT_DATA_LONE value.

It just reinvent the same call routines as any (1M) CLI at user
lande. I did not see any value of doing so. In addition, HP and
BMC will have their own user lander structure and object model
to abstract and management objects.

The major work for HP OV and BMC patrol should focus on is to
design the object class to redegin the object model for MIB II
in order to fit the architecture needs.

Sunday, February 05, 2006

realm and services

AM does have CoS role based template services are global services which across
different realms such as user, session and discovery services

However, amadmin console service, policy configuration, globalization and password reset service are realm specific services

Saturday, February 04, 2006

System Boot

(1) bootstrap code is stored in firmware ROM and EPROM.
(2) bootstrap runs post test and run a bit code to read
a single block at a fix location (block 0, boot sector)
from disk into memory and begin it's execute the code
from boot block.
this code is very simple only lnow the addresas on disk
and length of reminder of the bootstrap program
(4) full bootstrap, it will traverse the file system to find
the OS kernel, load it into memory and start it's execution

Friday, February 03, 2006

Virtualization

It is to mitigate workload management problems by reintroducing a single co-hesive system view onto the distributed IT infrastructure

(1) it is more than just LB
(2) Trends of applications and infrastructure
a. Serial apps: openMP, MainFrames, DAS
b. Client server: Java EE, open system, DAS
c. P2P, reliable messaging, Cluster, DAS
d. service virtualization service registration, discovery, Grid
(3) In SV, applications are encapsulated as services, distributed framwork to disseminate the work across service instances. It allows developers to assemble
building blocks from different application domains
SV decouples apps from HW
(4) In IV, is to infrastrcure to deliver JIT compute and storage capacity
automation, finer control at end-user service level-- utility

Wednesday, February 01, 2006

amadmin.template vs amadmin on AM7

On a fresh deployed AM instance
I could not find amadmin shell
but only found amadmin.template
What can cause the issue ? wrong
deployment ?