Thursday, August 16, 2007

Weka running for Linux and Unix

(1) Under package weka.gui

LookAndFeel.props

(2) uncomment the first configuration

# Look'n'Feel configuration file
# $Revision: 1.1.2.2 $

# the theme to use, none specified or empty means the system default one
Theme=javax.swing.plaf.metal.MetalLookAndFeel
#Theme=com.sun.java.swing.plaf.gtk.GTKLookAndFeel
#Theme=com.sun.java.swing.plaf.motif.MotifLookAndFeel
#Theme=com.sun.java.swing.plaf.windows.WindowsLookAndFeel
#Theme=com.sun.java.swing.plaf.windows.WindowsClassicLookAndFeel

Wednesday, August 15, 2007

Classification Time Complexity

NBTree is O(n^3)
Decision trees is O(n^2)
Naive Bayes is O(n).

Sunday, August 12, 2007

NBTree Algorithmic Time Complexity

NBTree uses cross-validation at each node level to
make a decision to split or construct a naive Bayes
model.

Friday, August 10, 2007

Curse of dynamic programming and stochastic control

(1) Curse of parameteric approximation to cost-to-go function
(2) modeling without closed form objective function

function approximation, iterative optimization, neural network learning, dynamic programming

Curse of dynamic programming and stochastic control

(1) Curse of parameteric approximation to cost-to-go function
(2) modeling without closed form objective function

Monday, August 06, 2007

Attribute Selection With Weka

Uing the tab "Select attributes" in Weka to do some
wrapper-based feature subset selection. I encounter several different
search methods.

Greedy stepwise with parameters
"conservativeForwardSelection" = False
"searchBackwards" = False

It does forward selection starting from an empty set of
attributes. It stops adding attributes as soon as there
is no single addition that improves apon the current
best subset's merit score.


Greedy stepwise with parameter
"conservativeForwardSelection" = True, and
"searchBackwards" = False

It does the same and it will continue to add new features as
long as it does not decrease the merit of the current best subset.


BestFirst with parameter "direction" = Forward
BestFirst is a beam search. It allows backtracking to
explore other promising search paths.

The "More" button in the GenericObjectEditor
when selecting/altering parameters for
search methods in the Explorer.

Thursday, August 02, 2007

Zone and CPU shares

$ pooladm -e
$ pooladm -s
$ pooladm -c

$ poolcfg -c 'create pset pset1 (uint.min = 2 ; uint.max = 2)'
$ poolcfg -c 'create pset pset2 (uint.min = 1 ; uint.max = 1)'

$ poolcfg -c 'create pool pool1'
$ poolcfg -c 'create pool pool2'

$ poolcfg -c 'associate pool pool1 (pset pset1)'
$ poolcfg -c 'associate pool pool2 (pset pset2)'

$ pooladm -c

Assuming, the zones are up & running:
$ poolbind -p pool1 -i machine1
$ poolbind -p pool2 -i machine2
$ poolbind -p pool2 -i machine3
$ poolbind -p pool2 -i machine4
$ poolbind -p pool2 -i machine5

To make the bindings persistent, use
$ zonecfg -z set pool=

Sun Cluster supports Zone

SC3.2 does support treating a zone as a cluster node. See http://docs.sun.com/app/docs/doc/819-6611/6n8k5u1mc?a=view#gdamq

Zone memory limits and SWAP issues

There is no memory limit for Zones. A zone's processes are allowed to
use as much RAM and swap as they want. Resource controls can do this

Fork calls fail when there isn't enough swap space. It returns with error
ENOMEM, which is 12. The second failure in your log below returned a status
of 12.

Sample Size and Dimensionality

Sample size and dimensionality are critical to parametric optimization
of machine learning and prediction. Small datasets with high
dimensionality poses the low ROC problem in research community.

A naive Bayes classifier (Maron, 1961) is a simple probabilistic
classifier based on applying Bayes’ theorem with strong independence
assumptions. Depending on the precise nature of the probability model,
naive Bayes classifiers can be trained very
efficiently in a supervised learning setting. In many practical
applications, parameter estimation for naive Bayes models uses the
method of maximum likelihood. Recent researches on Bayesian
classification problem has shown that there are some theoretical reasons
for the apparently unreasonable efficacy of naive Bayes
classifiers(Zhang, 2004). Because independent variables are assumed,
only the variances of the variables for each class need to be determined
and not the entire covariance matrix. Hence, Naive Bayes classifier
requires small training data for classification prediction.

Support vector machines (SVMs) is another set of supervised learning
methods for classification (Cortes & Vapnik, 1995). It maps input
vectors to a higher dimensional space where a maximal separating
hyperplane is created. Two parallel hyper-planes
are constructed on each side of the hyperplane that separates samples.
The separating hyperplane is the hyperplane that maximizes the distance
between the two parallel hyper-planes. The larger the margin or distance
between these parallel hyper-planes is, The better the generalization
error of the classifier will be. It requires large samples.

TCP monitoring

(1) List all tcp tunnables

ndd /dev/tcp \?

(2) get a tcp tunnable values

ndd -get /dev/tcp tcp_conn_req_max_q0

(3) set a tcp tunnable

ndd -set /dev/tcp tcp_conn_req_max_q0

Tuesday, July 31, 2007

divide my dataset to subsets to perform some experiments on each

You can add an ID attribute to all your data using the AddID filter in
weka.filters.unsupervised.attribute. Following this you can create your
splits explicitly using filters in the weka.filters.unsupervised.instance package (e.g. RemovePercentage, RemoveRange and RemoveFolds) or use the cross-validation (or
percentage split) evaluation options in the Explorer. In order to make
sure that the ID attribute is not used by the learned models you can
use the weka.classifiers.meta.FilteredClassifier in conjunction with
your chosen classifier and the weka.filters.unsupervised.attribute.Remove filter in order to remove the ID attribute just prior to constructing a classifier (and at
testing time too). With the current snapshot of the developer
version of Weka, you can also output additional attributes alongside the
predictions (in your case, the ID attribute).

Applying Quantum Principles to GAs for Multiple Objective Scheduling

Multi-objective scheduling problem has been proposed in literature (T'kindt et. al., 1996). However, conventional meta heuristics-based methods, such as GA algorithms, were studied with single objective function to derive combinatorial optimization.

Recent advances of GAs and multi-objective researches (Han et. al., 2005) applied principles of Quantum Computers to stochastic optimization problems. In addition, Q bit representation and permutation-based GA was advocated by researchers (Li & Wang, 2007). For multi-objective scheduling Q bit GA needs to obtain good approximation for both co-operative and competitive task environment. Moreover, Q bit-based permutation, crossover operators, selection, encoding, generation processes and fitness values are required to explore and exploit the large or high dimensional state spaces. It is a relaxed minimization problem with the Q-bit.

Algorithm evaluation needs to combine a vector of all local objective function values for each job. However, local optimum per job and global optimum for entire task environment indicates further layer of constraint based satisfaction with enumeration of iterative policy and state transitions. Other than the optimization of enumeration, parallelization may need to considered at both system and application level. Furthermore, pipelined processing and data parallelization are critical to reduce both time and space complexities.

Han et. al. (2005). A quantum-inspired genetic algorithm for flow shop scheduling. Springer-Velag.
T'kindt et. al.(1996). Multicriteria Scheduling: Theory, Models and Algorithms. Springer-Velag, 2002.

Enable and Disable dhcpagent

To enable and disable DHCP Agent

sys-unconfig

Thursday, July 26, 2007

Balance Dataset

A dataset with 2 unbalanced classes. 7,500 rows belong to Class A
and 2,500 rows belong to Class B. How do I randomly select rows from
Class A and Class B to balance the dataset


Using weka.filters.supervised.instance.SpreadSubsample with a
value of 1 (uniform) for the distributionSpread parameter.

Tuesday, July 24, 2007

Selective Attribute for classification training

The easiest way to do this would be to first make a copy of the
Instances object (Instances copyt = new Instances(train)) holding your
training data. Then for each instance that has values that you don't
want to train on set them to "missing". I.e. assume i is an instance
and the value at attribute 3 is to be skipped when training naive
Bayes, then i.setMissing(2) would do the trick. Note, that this
approach is specific to the way that naive Bayes works.

BI Feature Selection

A BI Feature selection descritipn:


"The random search method (weka.attributeSelection.RandomSearch)
in the attribute selection package that can be combined with any
feature subset evaluator in order to search for good subsets randomly.
If no start set is supplied, Random search starts from a random point
and reports the best subset found. If a start set is supplied, Random
searches randomly for subsets that are as good or better than the
start point with the same or or fewer attributes."

But heuristically, with some confidence, the 50000
features selected using Chi-squared correlation produce a more
accurate SVM model than 50000 features selected uniformly at random.

Thursday, July 19, 2007

CPU performance counter

(1) AMD Performance Counter, http://developer.amd.com/article_print.jsp?id=90
(2) cpustat and cputrack , trapstat
(3) lib.cpc

ID Problem Formulation

(1) Since I formulated the ID as stochastic DP problem. It owns
properties
of dynamic.
(2) To handle large state space and unknown attack type, the DP problem
transformed into adaptive tuning problem. Adaptiveness in terms of tunning
the networks interactively.

The properties of problem formulation has been addressed in the problem
formulation section. I have mathematical proof for the above items. It has been
further addressed in the methodology section of the formal paper.

As for the time constraints, do you mean I need time to implement the
entire mathematical framework as a software ? If so, it is true that I need to implement it
myself since existing tools such as MatLab only handle traditional weights tuning for fixed
neuro networks. In addition, no RL toolbox yet. This research counts on my own implementation for proposed algorithmic operations. As for the dataset preprocessing, it will not be issue for
me since I/O formating is ok for me.

False alarm ratio is only evaluated from known attacks from research
point of review. In real time system operation, it can not be proved by research framework.
This is the motivation 67to come up with "Tuning" framework for online detection in order to
reduce the false alarm ratio.Hence, false alarm problem is relaxed as the problem of "Tuning" of DP 5tproblem. This is one 1of the major advantagesyt of this research proposal.

Dataset is only critical for traditional neuro learning but not this
research. parameter is not restricted for this research either. All these are traditional neuro
learning problem. That is 238x3ethe motivation to propose RL based "Tuning" framework. This is one of major advantages of this
research proposal. For the specific host and network attack (spoofing
and memory overflow)
I have mathematical proof for this research. For the implementation, I
have to start with arbitrary
parameters and architecture. It is important to know that there is no
readily training set of state
and ROC function in DP context. The possible way is to evaluate the ROC
function by simulation
state decisions. Afterwards, using RL based interactive algorithm to
improve the ROC value. That
is the most key point of the research design.

Versioning Manager Output

Singleton VersioningManager can output any JComponent to the console

NB Back End Threaded Progresses

(1) Runnable for backend long run processes and Progress Handle management
Runnable allRunnable = new Runnable() {
WorkspaceMgr mgr = null;
Workspace ws = PerforceConfig.getDefault().getDefaultWorkspace();
ProgressHandle handle = null;

public void run() {
try {
handle = ProgressHandleFactory.createHandle(NbBundle.getMessage(PerforceAnnotator.class, "CTL_PopupMenuItem_ViewAllChangelist"));
mgr = new WorkspaceMgr(ws);
handle.start();
showAllChangelist(changes);
SwingUtilities.invokeLater(new Runnable() {

public void run() {
ChangelistView comp = ChangelistView.findInstance();
VersioningOutputManager.getInstance().addComponent(NbBundle.getMessage(PerforceAnnotator.class, "CTL_PopupMenuItem_ViewAllChangelist"), comp);
comp.setContext(ctx, changes);
comp.setDisplayName(NbBundle.getMessage(PerforceAnnotator.class, "CTL_PopupMenuItem_ViewAllChangelist"));
//comp.open();
comp.requestActive();
}
});
} catch (WorkspaceException ex) {
Exceptions.printStackTrace(ex);
} finally {
handle.finish();
}
}
};

(2) UI current thread context

if (cmd.equals(NbBundle.getMessage(PerforceAnnotator.class, "CTL_PopupMenuItem_ViewAllChangelist"))) {
RequestProcessor.getDefault().post(allRunnable);
}

(3) So, current thread, spawn thread for progress bar and backend process, back to UI population

Performance Analysis and Methodology

Performance analysis and methodologies are very broad topics. It is about optimization. Performance as a set of Bellman equations to solve. Traditional states and performance functions
enumerations does not address the performance evaluation issues
since a traditional MDP problem results in large state transitions
or high dimensional performance feature extractions. For a networking
only related problem formulation may involved into 30+ performance
parameters and for Solaris kernel, it involves 100+ parameters.
Hence, dynamic and adaptive performance analysis and associated
resource utilization analysis may reach the optimum
performance function evaluation with fast convergence.

It is involved with Performance Metrics (Parameters, feature extractions), Performance Functions, Performance Evaluations, Performance Learning, Performance Instrumentation, Performance Management and Adaptive Tuning etc. It really depends on specific issues to formulate the specific problem into adequate function, models to resolve the performance issues.

In addition, from CS analysis and design methods such as dynamic programming, divide by conquer, greedy and amortization. They are popular techniques to address performance from subproblem to global problems. However, to achieve end-to-end performance gains such as network tuning, global optimum may be the most concerns instead of local optimum. In addition, queuing theory has been widely adopts for traditional SMP based performance management and capacity planning.
Core based parallelism and pipelining introducing many new issues down
the road. Is queuing still works well for parallelism paradigm, if not
what will be the optimization, if yes, what will be proper queue
partitioning etc


In general quantitative methods should be the main theme of the analysis
and evaluation. It is hard to generalize as a whole but specific to
the target problem formulations.

P4 Annotation For Security Compliance Auditing

P4 annotate is the solution to discover the code change per version and who submit the change

Friday, July 13, 2007

P4 job

(1) P4 job specification can be customized
(2) create p4 job with the above specification
(3) lookup jobs assigned to specific developers
(4) developer edit src and submit the changelist
(5) developer run "fix" to associated submitted "changeNo" with job to ensure job is in closed state

P4 Labeling

It is not encourage to use label but changelist.

P4 branch

(1) Branch can be created with "integrate" for the "From Files" to "To Files" following by "submit"
However, Branch is the best practice to create branch. Because, with branches,
integrate -b branchname -r (bi-direction population can happen)
(2) any working branch can only populate the change with "integrate" with "submit" again. All conflicts willl be reported during submission phases.
(3) resolve action will be taken by user

HTTP/S for Performance Management Analysis/Report

First, it is a common engineering practice for
agent to collect data for analysis and report
layers in system management space. It happens
to all industrial players.
In addition, three tier performance management
architecture is also considered as the best
practice to scale to large data center performance
management. It can be further processing for event
collaboration for even larger performance
management crossing data centers.

Second, HTTPS is a security compliant requirement.
It is part of compliance practice.

The only limitation is that it is coming from
hosts and server domain management. If goes to
small devices management such as fans or power controller
The only methods now is SNMP or SNMP/S.

Crypto on T2000

Crytpo framework supports SCA6000 crypto provider for all NG zones, if it's configured.changes to the crypto framework config can only be done from the Global zone. You can list the providers from within the non-global zone but cannot change.

Thursday, July 05, 2007

Solaris Resource Management

From resource control, prcess level
control will pass in pid which is run
time only. So we create project to
assigned user progress to modify the
resource control per project based without
knowing pid. Of course, I want to try
pid too.


(1)Create a project
# projadd -U progress -p 8888 openedge
(2) projmod -c "It is project for resource control on openedge database" openedge
(3)List projects created
# project -l
ksh: project: not found
# projects -l
system (System built-in project, project id 0)
projid : 0
comment: ""
users : (none)
groups : (none)
attribs:
user.root (System built-in project, project id 1)
projid : 1
comment: ""
users : (none)
groups : (none)
attribs:
noproject (System built-in project, project id 2)
projid : 2
comment: ""
users : (none)
groups : (none)
attribs:
default (System built-in project, project id 3
projid : 3
comment: ""
users : (none)
groups : (none)
attribs:
group.staff (System built-in project, project id 10)
projid : 10
comment: ""
users : (none)
groups : (none)
attribs:
openedge (Project we created with designated id 8888)
projid : 8888
comment: "It is project for resource control on openedge database"
users : progress
groups : (none)
attribs:
(3) check project membership


id -p

# id -p
uid=0(root) gid=0(root) projid=1(user.root)

You can see root belongs to built-in project id1 which is user.root

# prstat -J
PID USERNAME SIZE RSS STATE PRI NICE TIME CPU PROCESS/NLWP
707 noaccess 222M 133M sleep 59 0 0:01:47 0.0% java/55
1025 root 4776K 4232K cpu8 59 0 0:00:00 0.0% prstat/1
118 root 5216K 4728K sleep 59 0 0:00:02 0.0% nscd/26
117 root 4640K 4008K sleep 59 0 0:00:00 0.0% picld/4
125 root 2592K 2080K sleep 59 0 0:00:00 0.0% syseventd/14
258 daemon 2752K 2432K sleep 59 0 0:00:00 0.0% statd/1
371 root 4856K 1672K sleep 59 0 0:00:00 0.0% automountd/2
97 root 2552K 2176K sleep 59 0 0:00:00 0.0% snmpdx/1
55 root 9160K 7528K sleep 59 0 0:00:01 0.0% snmpd/1
308 root 2080K 1224K sleep 59 0 0:00:00 0.0% smcboot/1
259 daemon 2432K 2136K sleep 60 -20 0:00:00 0.0% nfs4cbd/2
249 root 2728K 1632K sleep 59 0 0:00:00 0.0% cron/1
9 root 11M 10M sleep 59 0 0:00:19 0.0% svc.configd/17
7 root 19M 17M sleep 59 0 0:00:08 0.0% svc.startd/12
136 daemon 4680K 3528K sleep 59 0 0:00:00 0.0% kcfd/5
PROJID NPROC SIZE RSS MEMORY TIME CPU PROJECT
1 5 10M 9488K 0.0% 0:00:00 0.0% user.root
3 1 1376K 1280K 0.0% 0:00:00 0.0% default
0 37 390M 257M 0.7% 0:02:21 0.0% system


Total: 43 processes, 218 lwps, load averages: 0.01, 0.01, 0.01

# id -p root
uid=0(root) gid=0(root) projid=1(user.root)
# id -p daemon
uid=1(daemon) gid=1(other) projid=3(default)
# id -p noaccess
uid=60002(noaccess) gid=60002(noaccess) projid=3(default)


svcadm enable system/pools:default (resource pools framework)
svcadm enable system/pools/dynamic:default (dynamic resource pools)
svcadm enable svc:/system/pools:default (enable DRP service)

Check if pool services and dynamic pool service are enabled

# svcs *pool*
STATE STIME FMRI
online 11:10:01 svc:/system/pools:default
online 11:11:05 svc:/system/pools/dynamic:default

Share Memory setting in Soalris 10 or +

(1) If it is a shared memory issue, it may not be zone specific but S10 specific. Since it
/etc/system is not good practice but following S10 resource control practices
(2) Using prctl to project or even process based control. However, you need to create
project and assign user which running the process to the project. I have experienced
some bugs before to do this assignment. However, to login as the user then su to
root to assign the project
(3) projmod -s -K "project.max-shm-memory=(privileged, 8GB, deny) xxx

You may need to run it in global zone first before moving into local zone.

Core and LDOM Performance Management

Core and LDOM based system operations introduces parametric
modeling and approximation optimization problems from
traditional execution time to throughput, IPC, parallelism
and pipelining. This is applied to OS modeling and
performance management. It impacts the predictive
monitoring, analysis and reporting. This has been my
engineering interests since I worked in
system management and integration spaces.

Tuesday, July 03, 2007

From CMT perspective, out T1, AMD, Intel x86 platforms does introduce variance from traditional
SMP platforms. First, from HW platform point of view, physical processor structures changed to core
based, Second from Solaris point of view, kernel CPU structures, CPC counters, CPUTrack, CPUStat
Kstat changed (including all core changes), Third, from system management point of SNMP MIBII
database structure changed. This will impact current system management parametric model learning and system management view design.
From LDOM perspective, more virtualization based predictive modeling and reporting design needs to
be enhanced to predict and measure physical resources, kernel CPU structures, CPC counters and MIB
structures.

In general, to have system management to be earlier CMT and LDOM adaptor, they could need some level of support from Sun. This is just a proactive assessments.

Friday, June 29, 2007

Load Generation Appliance

Spirent AVALANCHE LOAD TESTING APPLIANCE

http://www.spirentfederal.com/

Monday, June 25, 2007

S12 Compliation flag

S12 update compilation flag: -xarch=v9 is deprecated, use -m64 to create 64-bit programs

Wednesday, June 20, 2007

Long Pause GC ?

GC can be well tunned from 1.5.x above.

http://www.sun.com/bigadmin/content/submitted/cms_gc_logs.html
http://java.sun.com/performance/reference/whitepapers/tuning.html
http://twiki.sfbay.sun.com/pub/MDE/ISVESystemsProjects/TS-2885-14.pdf

Interesting military Security Training, Open Solaris

http://www.gcn.com/print/26_09/43562-1.html

NB Debug Thread Dead Lock

It seems SMP helps NB debugger for current build

Tuesday, June 19, 2007

Workspace Management

Main Menu Action is triggered by "Annotator"

(1) CreateWorkspaceAction -- Currently Setup Workspace and save the extra UpdateWorkspace Action
This action is triggered by "Annotator" getAction routine
(2) Needs Remove Workspace Action to remove current Preferences cache and Remote depot.
This action is triggered by "Annotator" getAction routine
(3)

Monday, June 18, 2007

NB Short Build

cvs -d :pserver:leiliu@cvsnetbeansorg.sfbay.sun.com:/cvs login
cvs -d :pserver:leiliu@cvsnetbeansorg.sfbay.sun.com:/cvs co -P standard_nowww

cvs -d :pserver:leiliu@cvs.netbeans.org:/cvs login
cvs -d :pserver:leiliu@cvs.netbeans.org:/cvs co -P standard_nowww


ant -Dcluster.config=standard

or may need to try ant build-nozip first.


With CVS functions

ant -Dcluster.config=basic

NB cached .netbeans dir caused problem

(1) It is recommended to clean up the .netbeans dir under $HOME in order to have new build working
fully.
(2) a short build

cvs -d :pserver:leiliu@cvsnetbeansorg.sfbay.sun.com:/cvs login
cvs -d :pserver:leiliu@cvsnetbeansorg.sfbay.sun.com:/cvs co -P standard_nowww

cvs -d :pserver:leiliu@cvs.netbeans.org:/cvs login
cvs -d :pserver:leiliu@cvs.netbeans.org:/cvs co -P standard_nowww


ant -Dcluster.config=standard

or may need to try ant build-nozip first.

Saturday, June 16, 2007

NB Plugin

1. rename cvsmodule as perforce
2. change all project and service meta data ->>>>> Here is PerforceVCS
3. replace.sh cvs -> perforce, CVS -> Perforce
4. PerforceRoot change back to CVSRoot first.

We can get a build now.

Change Menu action name: Each Action has

public String getName() {
return NbBundle.getBundle(CreateWorkspaceAction.class).getString("CTL_MenuItem_XX_Label");
}

CTL_MenuItem_XX_Label is located in Bundle.properties file of each action package

Friday, June 15, 2007

Problem of Broadcom Wireless Controller on S11 with Acer Ferrari 3400 laptop

I have ferrari 3400 latop with S11 OS kernel 5.11 snv_64a i86pc i386 i86pc

(1) Locate Wireless Controller as Broadcom BCM4306 802.11b/g Wireless LAN Controller


# /usr/X11/bin/scanpci -v


pci bus 0x0000 cardnum 0x09 function 0x00: vendor 0x14e4 device 0x4320
Broadcom Corporation BCM4306 802.11b/g Wireless LAN Controller
CardVendor 0x185f card 0x1220 (Wistron NeWeb Corp. TravelMate 290E WLAN Mini-PCI Card)
STATUS 0x0000 COMMAND 0x0006
CLASS 0x02 0x80 0x00 REVISION 0x03
BIST 0x00 HEADER 0x00 LATENCY 0x40 CACHE 0x00
BASE0 0xd0014000 addr 0xd0014000 MEM
MAX_LAT 0x00 MIN_GNT 0x00 INT_PIN 0x01 INT_LINE 0x0a
BYTE_0 0x01 BYTE_1 0x00 BYTE_2 0xc2 BYTE_3 0x07


(2) modinfo | grep bcm

Found the driver is not loaded

(3) Manually loaded driver

modload /kernel/drv/amd64/bcmndis


# modinfo | grep bcm
201 fffffffff7a39000 a3598 222 1 bcmndis (bcmndis(ndis wrapper 1.6))


(4) # grep bcm /etc/driver_aliases
bcmndis "pci14e4,4320"
bcmndis "pci14e4,1a"

(5) update_drv -a -i '"pci14e4,1a"' bcmndis
("pci14e4,1a") already in use as a driver or alias

(6)
dladm show-link
bcmndis0 type: legacy mtu: 1500 device: bcmndis0
bge0 type: non-vlan mtu: 1500 device: bge0


(7) ifconfig bcmndis0 plumb

(8) ifconfig -a
lo0: flags=2001000849 mtu 8232 index 1
inet 127.0.0.1 netmask ff000000
bge0: flags=201004843 mtu 1500 index 2
inet 192.168.1.100 netmask ffffff00 broadcast 192.168.1.255
ether 0:c0:9f:9e:41:5
ip.tun0: flags=10010008d1 mtu 1366 index 3
inet tunnel src 192.168.1.100 tunnel dst 192.18.32.151
tunnel security settings esp (aes-cbc/hmac-md5)
tunnel hop limit 60
inet 129.150.13.3 --> 129.145.40.124 netmask ffffffff
bcmndis0: flags=201000842 mtu 1500 index 4
inet 0.0.0.0 netmask 0
ether 0:b:6b:4c:4a:ec
(9)
wificonfig -i bcmndis0 scan
essid bssid type encryption signallevel


It failed to discovered any router or access point.



However, if we boot as 32 bit kernel then it works

Adaptive Buffer Tuning for Data Intensive Algebraic Operations in Purpose of Parallel and Distributed Processing

Both pervasive directional graphs and intensive algebraic operations require buffer management for stochastic data processes with constrained computing resources. Algebraic computation states in final stages tend to be readily identified within finite time horizon by sensing very abrupt transitions in system and network state spaces. But in early stages of constraints, these changes are hard to predict and difficult to distinguish from usual state fluctuations. Dynamic buffer allocation and replacement are the major techniques to construct structures for algebraic operations to ensure finite resource assesses. Hence, dynamic buffering function and control optimization are the major primitives to construct utilities for stochastic system processes to ensure converged resource accesses. To provide adaptation to large dimensional states, this research proposes a formal model-free buffer utility framework rooted from reinforcement learning methods and dynamic programming techniques to provide self organization of buffers to exploit parallel based buffer tuning processes. To time and space complexity reduction within the large state spaces, dynamic hidden neurons with incremental tuning is proposed for non-linear value function approximation to derive optimization procedures for optimal algebraic computational policies. For numeric and information evaluation, convergence analysis and error estimation are presented. Finally, a simulation test-bed and tuning results are deliberated.

CVS Server Setup on Solaris 10

(1) download cvs binary
(2) init cvs repository
a. create repository root directory /usr/local/cvs-repository
b. create a Solaris system user/group as: cvs/cvs
c. grant ownership of /usr/local/cvs-repository to Solaris user/group cvs/cvs
d. cvs -d /usr/local/cvs-repository init
This will create repository CVSROOT under /usr/local/cvs-repository
(3) create cvs user/password
a. create a password file as "passwd" under CVSROOT directory
b. user pl file below to create encoded password for cvs user
c. assign password to solaris user "cvs"

The CVS password file is CVSROOT/passwd in the repository. It was not
created by default when you ran cvs init, because CVS doesn't know for
sure that you'll be using pserver. Even if the password file had been
created, CVS would have no way of knowing what usernames and passwords
to create. So, you'll have to create one yourself; here's a sample
CVSRoot/passwd file:

::
Here is the perl script to generate encoded password
#!/usr/bin/perl

srand (time());
my $randletter = "(int (rand (26)) + (int (rand (1) + .5) % 2 ? 65 : 97))";
my $salt = sprintf ("%c%c", eval $randletter, eval $randletter);
my $plaintext = shift;
my $crypttext = crypt ($plaintext, $salt);

print "${crypttext}\n";


I keep the preceding script in /usr/local/bin/pass.pl:

pass.pl "passwd"

output : Urmh23wFp1aOs

Then use the output passwd adding line in CVSROOT/passwd file

cvs:Urmh23wFp1aOs:cvs

(Here we create cvs user and solaris user same as "cvs")


The format is as simple as it looks. Each line is:

::

c. in the /etc/inetd.conf add one line as

cvspserver stream tcp nowait root /opt/sfw/bin/cvs cvs --allow-root=/usr/local/cvs-repository pserver


d. On Solaris 10 inetd.conf change does not take effect other than SFM service profile.
using "inetconv" command to convert the inetd.conf as /var/svc/manifest/network/rpc/100235_1-rpc_ticotsord.xml
In addition, add online in /etc/services to give permission
cvspserver 2401/tcp
e. this service file will be auto started by SFM daemon
f. verify pserver service is started
# svcs | grep cvs
online 14:18:27 svc:/network/cvspserver/tcp:default
g. use login test

cvs -d :pserver:cvs@:/usr/local/cvs-repository login

Thursday, June 14, 2007

Kernel Module Load and Network setup

1. all amd64 drivers

/kernel/drv/amd64

2. acer 3400, bcmndis is the WIFI driver

3. modinfo | grep bcmndis

to check if the module is loaded

4. modload bcmndis

5. ifconfig bcmndis0 plumb

6. wificonfig -i bcmndis0 scan

7. setup connection with wificonfig

8. there is link to update broadcom driver

http://blogs.sun.com/pradhap/entry/ferrari_4000_flash_install

Wednesday, June 13, 2007

Setup Acer Solaris x86 WIFI

Acer Aspire 9300, Solaris X86, Atheros Wifi NIC
Submitted by spp on Tue, 2006-10-31 12:22.

Got the Atheros 802.11abg NIC working on my new Acer laptop under Solaris X86. I tried to follow the instructions at the atheros driver page, but they are a little out of date. The atheros driver has been integrated into OpenSolaris, so only one or two instructions are correct. However, it did put me on the right track.

First we need to make sure the driver is attached and we can start the interface

1. Find the vendor and device IDs
#/usr/X11/bin/scanpci
pci bus 0x0004 cardnum 0x05 function 0x00: vendor 0x168c device 0x001a
Atheros Communications, Inc. AR5005G 902.11abg NIC
2. Check in /etc/driver_aliases for Atheros (ath) mappings. Format of file is 'alias "pciXXXX,YYYY"' where XXXX is "vendor 0xXXXX" and YYYY is "device 0xYYYY" minus any beginning zeros.
#grep ath /etc/driver_aliases
ath "pci168c,13"
ath "pci168c,1014"
3. update the driver to include the new device (note that the single quotes are needed in order to pass through the double quotes
#update_drv -a -i '"pci168c,1a"' ath
4. now, plumb the interface
#ifconfig ath0 plumb
5. either now, or before the plumb, you can find out what wifi access points are available
#wificonfig scan
essid bssid type encryption signallevel
you should see a list here

At this point, the instructions say that if you aren't running authentication, you can just use "ifconfig ath0 dhcp", but I am using encryption, so I moved on to trying to use wificonfig. Unfortunately, there are some mistakes here (possibly out of date and changed, not strictly incorrect). The biggest issue I found was that the instructions always reference using "-i [interface]", but that option isn't valid for most of the configuration (and the error message doesn't really make it easy to see).

1. create a profile to store my ESSID and WEP information in (write-only profile, non-readable). Names changed for security... not that wepkey# has to be the actual WEP key, not the passphrase, which makes life significantly more difficult.
#wificonfig createprofile home essid=HOME encryption=WEP wepkey1=10hexkey
2. activate the profile
#wificonfig connect home
wificonfig: connecting to profile 'home'
3. Now, like the earlier instructions, you can start dhcp
#ifconfig ath0 dhcp
4. And, make sure we have connection
#ifconfig ath0
ath0: flags=201004843 mtu 1500 index 3
inet 192.168.21.100 netmask ffffff00 broadcast 192.168.21.255
ether 0:16:cf:6f:a:92

Tuesday, June 12, 2007

LDAPv3 Unauthenticated binding

LDAPv3 specifications have introduced a unituitive feature with regards to authentication : the unauthenticated bind.
When an LDAP application provides a DN but no password, the Bind request is succesfull, BUT the user is not authenticated and has the same access rights as an Anonymous user.

Note that DS 6.0 now has a configuration parameter to disable unauthenticated Binds, and remove this unconventional authentication "feature" of LDAPv3.

LDOM Virtual Disk

LDom vdisks are not SCSI disks . Therefore, the missing SCSI target ID
and disks have the name cNdNsN.

Bind raw or block disk to disk service

bind a raw disk (/dev/rdsk/c1t1d0)
bind to a block disk (/dev/dsk/c1t1d0) to a disk service.

Zones and ZFS Pool

Two zones created on a cluster in node 1 in a ZFS pool, since I need to have the zones in an installed state on each node in the cluster. There is a way to bypass having to install the zones on each node in the cluster? It is using shared storage and moving the zfs pools back and forth.

Just three simple steps

1. zonecfg -z zone1 export>myfile
2. failover the storage with the root path to the second node
3. get myfily over to the second node
4 configure the zone with zonecfg export -f myfile
5 attach the zone with -F

NB Build and run

export ANT_OPTS="-Xmx196m"


mkdir netbeans
cd netbeans
cvs -d :pserver:leiliu@cvs.netbeans.org:/shared/data/ccvs/repository -q co nbbuild
ant -f nbbuild/build.xml checkout
ant -f nbbuild/build.xml

netbeans/nbbuild/netbeans/bin/netbeans to invoke IDE

FIPS compliance Security Crypto Module

Federal Information Processing Standards (FIPS) are publicly announced standards developed by the United States Federal government for use by all non-military government agencies and by government contractors. Many FIPS standards are modified versions of standards used in the wider community (ANSI, IEEE, ISO, etc.)


The National Institute of Standards and Technology (NIST) issued the 140 Publication Series to coordinate the requirements and standards for cryptographic modules which include both hardware and software components for use by departments and agencies of the United States federal government. FIPS 140 does not purport to provide sufficient conditions to guarantee that a module conforming to its requirements is secure, still less that a system built using such modules is secure. The requirements cover not only the cryptographic modules themselves but also their documentation and (at the highest security level) some aspects of the comments contained in the source code.

http://en.wikipedia.org/wiki/FIPS_140
http://en.wikipedia.org/wiki/Federal_Information_Processing_Standard

Sun's Cryptographic Accelerator 6000 provides exactly such a storage mechanism and API/tool set. The Cryptographic Accelerator is available for Solaris (SPARC and x86/x64) and Linux and is FIPS 140-2 Level 3 certified. It's key storage mechanism is also RF shielded and tamper-proof. It's probably one of the fastest cards on the market for accelerating SSL, IPsec/IKE and other general crypto and it's inexpensive (less than $1500 list).

http://www.sun.com/products/networking/sslaccel/suncryptoaccel6000/details.xml

Monday, June 11, 2007

ld: fatal: symbol is multiply-defined:

ld: fatal: symbol `bar' is multiply-defined:
(file foo.o and file bar.o);
ld: fatal: File processing errors. No output written to int.o

foo.c and bar.c have conflicting definitions for the symbol bar. Because the link-editor cannot determine which should dominate, the link-edit usually terminates with an error message. You can use the link-editor's -z muldefs option to suppress this error condition, and allow the first symbol definition to be taken.

resolve with compiling flag with

-z muldefs

LDOM Items

(1) SPARC only for Niagara Platforms Solaris DOM0 and Any OSs DOMU
(2) x86, Solaris DOM0, and any OS domU
(3) x86, other OS DOM0 is not verified yet.

Sunday, June 10, 2007

fatal: relocation error: R_AMD64_PC32

I am developing a c simulation tool. I am invoking one of dynamic library
(my home grown library named as: randlib.so)

It has a function as

double unifrand(double, double, long*);

In my simulation application, I invoke the above function with

seed = 1236537;
ran_no = unifrnd(0.0,1.0,&seed);

I have flag below to build

cc -m64 -o dist/Debug/Sun12-Solaris-x86/simperturbation build/Debug/Sun12-Solaris-x86/estimator.o build/Debug/Sun12-Solaris-x86/spoptimze.o -R/SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86 -R/usr/sfw/lib/64 -lm /SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86/randlib.so


However, during runtime, I have error blow:

ld.so.1: simperturbation: fatal: relocation error: R_AMD64_PC32: file /SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86/randlib.so: symbol unifrnd: value 0x2800112fedf does not fit


If I run list dynamic dependencies with the target simulation application binary,

ldd simperturbation
libm.so.2 => /lib/64/libm.so.2
randlib.so => /SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86/randlib.so
libc.so.1 => /lib/64/libc.so.1


As I compiled the DLL with -Kpic flag. It works

The URL below helps.

http://blogs.sun.com/rie/entry/my_relocations_don_t_fit

binary & library Info and In question

(1) file
(2) ldd

Stochastic Systems

governing variables -> system behavior

random variables -> stochastic system

large number: Not large until the change does not impact the system behavior

Complier flag for simulation Tool

1. Flag for 64 bit memory model of x86 platform architecture
2. Dynamic Library
3. Dynamic Link
4. Math Library
5. Runtime Search Path
6. -I include directory

cc -m64 -c -g +w -I/SunStudioProjects/randlib -o build/Debug/Sun12-Solaris-x86/spoptimze.o spoptimze.c

cc -m64 -o dist/Debug/Sun12-Solaris-x86/simperturbation build/Debug/Sun12-Solaris-x86/estimator.o build/Debug/Sun12-Solaris-x86/spoptimze.o -R/SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86 -lm /SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86/randlib.so

Complier flag for simulation Tool

1. Flag for 64 bit memory model of x86 platform architecture
2. Dynamic Library
3. Dynamic Link

cc -m64 -o dist/Debug/Sun12-Solaris-x86/simperturbation build/Debug/Sun12-Solaris-x86/estimator.o build/Debug/Sun12-Solaris-x86/spoptimze.o -R/SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86 -lm /SunStudioProjects/randlib/dist/Debug/Sun12-Solaris-x86/randlib.so

Saturday, June 09, 2007

Social Network

CEpedia and Koda are typical Sun Social network

NIO or IO

It seems block or non-blocking address the FD limitation previously existing on the server. There is a work around to improve the FD limitation. However, from server socket processing with sequential by nature. I tend to suggest to take blocking IO for normal mid-large workload but small-mid workload take unblocking approach since it functionally replicate Queuing algorithms

Inetmenu good for Laptop

It is a good tool to assign IP for laptop

It requires root to run then get IP from DHCP server or Wireless Access Points.

S11 NV build Laptop

(1). Solaris Express, Developer version build installation
(2). If it is under SWAN, it will bypass a lot of setup to go straight with default
NIS process.
(3). It requires sys-unconfig process if you want change other things. Do not enable DHCP here
but use inetmenu

However, sys-unconfig will not give you option to change host name

So, it is important to get hostname change process.

To change the hostname on a Solaris system:

1. Change the hostname in /etc/nodename
2. Run uname -S new_hostname to change the nodename for your current session.
3. Change the hostname in /etc/hostname.network_interface (e.g. /etc/hostname.hme0)
4. Run hostname new_hostname to change the hostname for your current session.
5. Change the hostname in /etc/hosts
6. Change the hostname in /etc/net/*/hosts (/etc/net/ticlts/hosts, /etc/net/ticots/hosts, /etc/net/ticotsord/hosts)
for directory in ticlts ticots ticotsord
do
cd /etc/net/$directory
sed 's/old_hostname/new_hostname/g' hosts > hosts.new
mv hosts.new hosts
done
Solaris 7 or later additional instructions:
7. Change the hostname in DUMPADM_SAVDIR= line in /etc/dumpadm.conf

Solaris 10 additional instructions:
8. Change the hostname in /etc/inet/ipnodes



However, all x86 updates. should visit community software (csw package download)
http://www.blastwave.org/packages.php

blastwave.org


This includes wget, pkg-get, tetex etc.

WTS 2007 Paper Publication

Exchange information on advances in mobile communications and wireless networking technology, management, applications, and security in a very pleasant Southern California conference environment with leaders and experts from industry, governmental agencies, and universities around the world at the Wireless Telecommunications Symposium.

WTS 2007 will focus on The Future of Wireless Communications. Planned highlights of WTS 2007 include:

* An IEEE Communications Society Co-Sponsored Welcoming Dinner with Internet Pioneer Vinton G. Cerf, Vice President and Chief Internet Evangelist at Google, as guest speaker
* Addresses and presentations by some of the most respected executives and researchers in the wireless communications industry
* Panel discussions including Future Directions in Wireless Communications Research, Wireless Network Security, New Wireless Communications Ventures, Wireless Communications Investments, Mobile Wireless Services and Business, Wireless Communications Business Strategy, Advances in Satellite Communications, and The Future of Deep Space Communications
* A tutorial on Portable Emergency Networks and a Wireless Network Security Workshop
* Presentations of accepted academic and practitioner applied research papers; a poster paper session; a doctoral students session
* A tour of Universal Studios Hollywood followed by a reception at CityWalk


Peer-reviewed proceedings will be published by the IEEE and will be available on its Xplore online publication system. A CD containing the invited speakers' presentations and accepted applied research papers will be distributed to registrants at the conference. Applicable student papers are welcome. Awards will be given for the outstanding undergraduate and graduate papers submitted.


http://www.csupomona.edu/~wtsi/doc/WTS_2007-Accepted_Paper_Program.htm


My Paper on Lock contention is located by IEEE Explorer

ICACT2007 Paper publication

http://www.icact.org/program/program.asp#3


It is Feb 2007



My Paper stated as Index and SOA Performance


Please visit IEEE Explorer

Thursday, December 07, 2006

Friday, November 10, 2006

Hash Distribution Algorithm

For a hash-based distribution algorithm, the most difficult part is to define what hash function would avoid re-distribution. To reduce entry re-distribution, it is also possible to configure the proxy with the maximum number of distribution "slots" upfront, say 10 slots, then associate multiple slots with each service instance.

S1,S2,S3 --> SVC1
S4,S5,S6 --> SVC2
S7, S8, S7, S10 --> SVC3

When the amount of entries stored on SVC1 exceed some limits, a new service instance is set up (say SVC4), one (or more) slots formerly managed by SVC1 are moved to SVC4 (the content of SVC1 is re-distributed to SVC1 and SVC4) and the proxy configuration is changed accordingly, for instance

S1,S2 --> SVC1
S3 --> SVC4
S4,S5,S6 --> SVC2
S7, S8, S7, S10 --> SVC3

This does not solve the re-distribution problem. However, it is much easier to deal with this issue as the number of entries to be re-distributed is much smaller compared to a configuration where the max number of slots has not been planned upfront.

sunkeyvalue

Which I think is not an option in that case since the sunkeyvalue attribute is meant to be generic place holder for any key value pair and needs to be mulivalued.

The other thing, the value of this attribute being XML, it contains a special character which forces the value to be base64 encoded in LDIF (and thus in the DB representation of the entry). This increases the size of the value by at least 30%, thus the size of the data to write.

Directory Server 6 made serious improvement over this use case and the replication historical information will be lighter than with 5.2...

DN Binding with Empty Password

Bind with a DN and an empty password is a valid LDAP operation per the
LDAP v3 specifications (RFC 2251) and results in the user being
identified but not authenticated and not authorized...
The result is that the bind is successful but the connection is treated
as an anonymous operation.

Note that this behavior is now discouraged in RFC 4513 and Directory
Server 6 has a configuration parameter to accept or reject these requests.

Tuesday, November 07, 2006

DS Instance Life cycle

"Disorderly shutdown" message is logged when DS starts and does not find the guardian file that DS writes when it closes the database properly.

Then the server starts and opens the database in recovery mode. If it doesn't start at all, without starting the recovery, it might be a corruption of the config file (dse.ldif). There should be 2 other copies of the dse.ldif in the config directory: dse.ldif.bak (the previous version), dse.ldif.startok (the last one used to start the server). A working dse.ldif can be rebuilt from these files.

If it does go through the recovery mode but fails to recover the database, then you're in trouble. It means that either the DB files are corrupted or the transaction log file is.

One way to quickly recover the server can be to make a backup of another server with the same configuration (other master) and restore it on this server.

Friday, October 27, 2006

Configuring Multiple NIC interfaces in one Zone

In configuring your zone, just "add net" for each device like below (
could certainly access multiple disks this way but there are still uncleared
issues) :

zonecfg -z myzone
create
set zonepath=/zfspool/fs/myzone
set autoboot=true
############### see below ###########
add net
set address=129.148.20.2
set physical=ipge1
end
add net
set address=129.148.30.2
set physical=ipge2
end
################ see above ##############
....
verify
commit

Tuesday, October 24, 2006

Sun Fire System Auto Reboot

on OBP, use setenv
ok> setenv auto-boot? true

on Solaris use eeprom(1)
% eeprom auto-boot?=true

Saturday, October 14, 2006

ZFS Ignore fsflush

ZFS ignores the fsflush. Here's a snippet of the code in zfs_sync():

/*
* SYNC_ATTR is used by fsflush() to force old filesystems like UFS
* to sync metadata, which they would otherwise cache indefinitely.
* Semantically, the only requirement is that the sync be initiated.
* The DMU syncs out txgs frequently, so there's nothing to do.
*/
if (flag & SYNC_ATTR)
return (0);

However, for a user initiated sync(1m) and sync(2) ZFS does force
all outstanding data/transactions synchronously to disk .
This goes beyond the requirement of sync(2) which says IO is inititiated
but not waited on (ie asynchronous).

Wednesday, October 11, 2006

Mount ISO file on Solaris

- make the ISO image file available as a block device with
lofiadm(1M), e.g.

# lofiadm -a /var/tmp/sol-10-u1-companion-ga.iso
/dev/lofi/1

- mount the block device, e.g.

# mount -r -F hsfs /dev/lofi/1 /mnt

- when you're done, umount the file and delete the device with

# lofiadm -d /dev/lofi/1

JVM tunnables for JVM on x410

Java HotSpot(TM) 32-bit Server VM on Windows, version 1.5.0_06

http://www.spec.org/jbb2005/results/res2006q1/jbb2005-20060117-00061.txt

Java HotSpot(TM) 32-bit Server VM on Solaris, version 1.5.0_08

http://www.spec.org/jbb2005/results/res2006q2/jbb2005-20060512-00112.txt

Monday, October 09, 2006

ZFS on Solaris 11

Find disk and slice

format --> select disk --> partition ---> print


# format
Searching for disks...done


AVAILABLE DISK SELECTIONS:
0. c0t0d0
/pci@0,600000/pci@1/pci@8/pci@0/scsi@1/sd@0,0
1. c0t1d0
/pci@0,600000/pci@1/pci@8/pci@0/scsi@1/sd@1,0
Specify disk (enter its number): 1
selecting c0t1d0
[disk formatted]


FORMAT MENU:
disk - select a disk
type - select (define) a disk type
partition - select (define) a partition table
current - describe the current disk
format - format and analyze the disk
repair - repair a defective sector
label - write label to the disk
analyze - surface analysis
defect - defect list management
backup - search for backup labels
verify - read and display labels
save - save new disk/partition definitions
inquiry - show vendor, product and revision
volname - set 8-character volume name
! - execute , then return
quit
format> partition


PARTITION MENU:
0 - change `0' partition
1 - change `1' partition
2 - change `2' partition
3 - change `3' partition
4 - change `4' partition
5 - change `5' partition
6 - change `6' partition
7 - change `7' partition
select - select a predefined table
modify - modify a predefined partition table
name - name the current table
print - display the current table
label - write partition map and label to the disk
! - execute , then return
quit

partition> print
Current partition table (original):
Total disk cylinders available: 14087 + 2 (reserved cylinders)

Part Tag Flag Cylinders Size Blocks
0 root wm 2 - 1135 5.50GB (1134/0/0) 11539584
1 swap wu 1155 - 2309 5.60GB (1155/0/0) 11753280
2 backup wm 0 - 14086 68.35GB (14087/0/0) 143349312
3 unassigned wm 2310 - 3464 5.60GB (1155/0/0) 11753280
4 unassigned wm 3465 - 4619 5.60GB (1155/0/0) 11753280
5 unassigned wm 4620 - 5774 5.60GB (1155/0/0) 11753280
6 unassigned wm 5775 - 12931 34.73GB (7157/0/0) 72829632
7 home wm 12932 - 14086 5.60GB (1155/0/0) 11753280

(2) use c0t1d0s6 for zfs

(3) create v device pool

# zpool create ktspool c0t1d0s6

(4) list the pool
# zpool list
NAME SIZE USED AVAIL CAP HEALTH ALTROOT
ktspool 34,5G 33,5K 34,5G 0% ONLINE -
(5) check pool status
# zpool status
pool: ktspool
state: ONLINE
scrub: none requested
(6) ktspool file system was created. verify file system

# df -kh
Filesystem size used avail capacity Mounted on
/dev/dsk/c0t0d0s0 9,8G 3,6G 6,2G 37% /
/devices 0K 0K 0K 0% /devices
ctfs 0K 0K 0K 0% /system/contract
proc 0K 0K 0K 0% /proc
mnttab 0K 0K 0K 0% /etc/mnttab
swap 14G 1,1M 14G 1% /etc/svc/volatile
objfs 0K 0K 0K 0% /system/object
fd 0K 0K 0K 0% /dev/fd
swap 14G 8K 14G 1% /tmp
swap 14G 48K 14G 1% /var/run
/dev/dsk/c0t0d0s7 50G 56M 49G 1% /export/home
ktspool 34G 9K 34G 1% /ktspool

(7) create a new file system as ktspool/kts

zfs create ktspool/kts

(8) verify the file system creation

# df -kh
Filesystem size used avail capacity Mounted on
/dev/dsk/c0t0d0s0 9,8G 3,6G 6,2G 37% /
/devices 0K 0K 0K 0% /devices
ctfs 0K 0K 0K 0% /system/contract
proc 0K 0K 0K 0% /proc
mnttab 0K 0K 0K 0% /etc/mnttab
swap 14G 1,1M 14G 1% /etc/svc/volatile
objfs 0K 0K 0K 0% /system/object
fd 0K 0K 0K 0% /dev/fd
swap 14G 8K 14G 1% /tmp
swap 14G 48K 14G 1% /var/run
/dev/dsk/c0t0d0s7 50G 56M 49G 1% /export/home
ktspool 34G 9K 34G 1% /ktspool
ktspool/kts 34G 9K 34G 1% /ktspool/kts

(9) change the mount point of the zfs file system to /kabirazfs

zfs set mountpoint=/kabirazfs ktspool/kts

(10) verify the new mounted point

# df -kh
Filesystem size used avail capacity Mounted on
/dev/dsk/c0t0d0s0 9,8G 3,6G 6,2G 37% /
/devices 0K 0K 0K 0% /devices
ctfs 0K 0K 0K 0% /system/contract
proc 0K 0K 0K 0% /proc
mnttab 0K 0K 0K 0% /etc/mnttab
swap 14G 1,1M 14G 1% /etc/svc/volatile
objfs 0K 0K 0K 0% /system/object
fd 0K 0K 0K 0% /dev/fd
swap 14G 8K 14G 1% /tmp
swap 14G 48K 14G 1% /var/run
/dev/dsk/c0t0d0s7 50G 56M 49G 1% /export/home
ktspool 34G 9K 34G 1% /ktspool
ktspool/kts 34G 9K 34G 1% /kabirazfs


Also can see /kabirazfs is created under "/"


(11) zpool iostat -x 5


(12) check zfs properties setting. such as compression is disabled

# zfs get all ktspool/kts
NAME PROPERTY VALUE SOURCE
ktspool/kts type filesystem -
ktspool/kts creation lun oct 9 19:08 2006 -
ktspool/kts used 9,50K -
ktspool/kts available 34,2G -
ktspool/kts referenced 9,50K -
ktspool/kts compressratio 1.00x -
ktspool/kts mounted yes -
ktspool/kts quota none default
ktspool/kts reservation none default
ktspool/kts recordsize 128K default
ktspool/kts mountpoint /kabirazfs local
ktspool/kts sharenfs off default
ktspool/kts checksum on default
ktspool/kts compression off default
ktspool/kts atime on default
ktspool/kts devices on default
ktspool/kts exec on default
ktspool/kts setuid on default
ktspool/kts readonly off default
ktspool/kts zoned off default
ktspool/kts snapdir hidden default
ktspool/kts aclmode groupmask default
ktspool/kts aclinherit secure default

OpComm2006

Friday, October 06, 2006

Classic Relational Algebra Algorithm

The algebra on sets of tuples or relations could be used to express typical queries about those relations (1) Union (2) set difference (3) Cartesian Product (4) selection
(5) projection (6) aggregation (7) renaming


set operation(union, intersection, difference), selection, projection, Cartesian product, natural join, theta-join, renaming, duplicated elimination, aggregation, grouping, sorting, extended projection,outerjoin (naturla, left, right)


Intersection, theta join, natural join are dependent operations.
Union, differences, production, selection, projection, renaming are independent operations

Tuesday, October 03, 2006

R&D Conference Presentation in China

Software R&D is boomed in China. People respect R&D there.

NFS Service in NGZ

One cannot do NFS in NGZ but Solution to get NFS Service in NGZ

One can make the GZ an NFS sever and just use loopback from GZ to NGZ instead, this can simulate NFS. Since this is a loopback it should be faster and more efficient than using NFS. Just something to ponder? It might work. Now if your requirement is to put the NFS server in a NGZ, you cannot do that today. Maybe it will be addressed in an update depending on demand?

Monday, October 02, 2006

Denial of Service on X.509

(1)
Vulnerability Note VU#423396
X.509 certificate verification may be vulnerable to resource exhaustion:
http://www.kb.cert.org/vuls/id/423396
(2)
NISCC Vulnerability Advisory
729618/NISCC/PARASITIC-KEYS
Denial-of-Service Condition Affecting X.509 Certificates Verification:
http://www.niscc.gov.uk/niscc/docs/re-20060928-00661.pdf?lang=en
(3)
After x unsuccessful logins, it is possible in till deactivate the account. B
But is it possible to send an email to some Administrator that the account was deactivated.
(4)
DS is using NSS library (Mozilla) which is listed as
not vulnerable in the 729618/NISCC/PARASITIC-KEYS document

Thursday, September 28, 2006

Database Research

(7) Parallelism for traditional small and mid data set is ok. However, for large data set it may be overkilled in interms of paralleling each sub queries for large volume of co-current accessing.
(8) How to speed up the data accessing of archieving data does parallelization work ? Does archiving have indexing ? if not a sequential scan is required, can this be done over parallelization ?
(9) How to move large amount of data throughout the memory hierarchy of parallel computers ?
(10) Future system needs to deal with search whose part of data does come from archives
(11) Current data storage is used as read/write cache. New algorithm is required for the 3 level system buffering management
(12) Current Tx model is good for short Tx. However, for long run Tx, We need entire new approach to handel data integrity and recovering
(13)Space efficient Algorithm for Versioning and configuration model for DB to handle versions of objects
(14) Extend existing data model to include much more semantic information of data.
(15) Browsing with interrogation the nature of the process that merge data for hetergenerous and distributed database
(16) Current distributed DBMS algorithm for query processing, cocurrency control and support for multiple copies were designed for a few sites. They must be rethink for 1000, 10000 sites
(17) local cache, local replication of remote desktop become important, efficient cache maintenance is an open problem.
(18)

O Page and manual SSO login

Implementing a POC for a customer. For this POC we're trying to automate the complete authentication process within AM. We've written a servlet that is deployed in the same war-file (and context) as Access Manager and that handles authentication (using com.sun.identity.authentication.authcontext and is creating the token (using com.iplanet.sso.SSOTokenManager): so we don't redirect to /UI/Login if the SSOToken is invalid!

After establishing the session we want to redirect the user to a site that is protected by a policy agent (using response.redirect(targetUrl)). However, SSO fails and a user needs to authenticate again. It seems that the normal AM cookies (iPlanetDirectoryPro - created when you login using /UI/Login) are not automatically created.

One final thing: setup is okay - we did sanity checks using policy agents and that works fine.

Questions:
1. Can some give me some hints and tips on how to create a valid session, SSO token and the according cookies using just the API?

The expected usage of this kind of flow is ideally through a policy
agent protecting a resource,
which detects missing SSOToken and authenticates on its own. Looks like
you are trying to do
that automatically without user intervention. In that case you can use
zero page login ( more details
in auth arch document pg 24-26), so you dont have to worry about setting
domain cookies etc.

In your approach you would have to set the cookie yourself on the
response. sample code to do that may
be like:

try {
ServiceSchemaManager scm = new ServiceSchemaManager(
"iPlanetAMPlatformService", token);

ServiceSchema platformSchema = scm.getGlobalSchema();
Set cookieDomains = (Set)platformSchema.getAttributeDefaults().
get("iplanet-am-platform-cookie-domains");
String value = token.getTokenID().toString();
String cookieName = SystemProperties.get(
"com.iplanet.am.cookie.name");

Cookie cookie = CookieUtils.newCookie(cookieName, value,
"/");
response.addCookie(cookie);

Iterator iter = cookieDomains.iterator();
Cookie cookie = null;
while (iter.hasNext()) {
String cookieDom = (String) iter.next();
cookie =
com.iplanet.services.util.CookieUtils.newCookie(cookieName, value,
"/", cookieDom );
response.addCookie(cookie);
loadBalancerCookie = setlbCookie(cookieDom);
if (loadBalancerCookie != null) {
response.addCookie(loadBalancerCookie);
}
}
}
} catch (Exception e) {

}
}

JES MF Reference

Even if technical, a good starting point is the JES-MF engineering site at
http://twiki.france/twiki/bin/view/JESMF20/WebHome

JES UWC Health check via Layer 7 Switch

In a typical JES Communications Suite installation, we install Communications Express (also known as UWC) to provide a web interface for Mail, Calendar and Address Books.

UWC is a Web Application running in a web server. And UWC is relying on the HTTP interface provided by the Messaging Server (not in web server but specific daemon: mshttpd) to display some pages.
Both processes are binding on the same IP address but UWC is using port 80 and mshttpd is using port 81.

The problem I'm facing is how to link these 2 applications in the N2120 configuration. Because if mshttpd is down, users are still redirecting to the running UWC on the same box but as mshttpd is not running, some pages (after login) cannot be displayed and the message displayed in the browser is "Bad Gateway. Processing of this request was delegated to a server not functioning properly".

To Do:

The problem lies in the fact that UWC returns a HTTP status code 200 OK. What you need to do is create a check that checks for a certain string,instead of the http status code.

How to install another instance JDK with strong encry policy

How to install another instance JDK with strong encry policy

* downloaded JDK 1.4.2 from
http://java.sun.com/j2se/1.4.2/SAPsite/download.html (64bit)

* unpack to /opt

* create a softlink from /opt/j2sdk1.4.2 to /opt/java1.4

* installed the policy manually in /opt/java1.4

* mount /opt as lofs

* start sapinst

Sapinst will detect, that the policy is already there and will not try to
install it again.

Wednesday, September 27, 2006

JDK access issue from sparse zone

In the Global zone, there is already a copy of JDK installed (by default
in Solaris 10). All the java links are setup properly in /usr.
However, as this is a sparse zone, /usr is inherited i.e. read-only.
Installing JDK anywhere in the sparse zone, while solves the problem,
will still require the user to change the appropriate links/PATHs/etc to
ensure the right JDK gets called.

Sunday, September 24, 2006

USDT per JScript

Java Script with DTrace


http://blogs.sun.com/brendan/entry/dtrace_meets_javascript

System vendor configuration--- CRITICAL vs OPTIMAL

It does not limited to disk but
apply to any key performance measurement within
a system.

As a system vendor, we need to consider ISV and
even end user vertical work load, system architecture
and deployment consideration from data center
operation point of view. To do so, we can make
a realistic assessment on total cost of ownership
at the end point. It is good for competitive analysis
at the end point and architecture selection at end
user level.

However, I am wondering if it is required for a system
vendor to implement a end-to-end HW configuration or
stay at a critical point but leave the further specific
HW and SW HA deployment as alternatives ?

Specifically, I tend to think we need to provide CRITICAL
instead of OPTIMAL configurations in order to leave
flexible and overheads to end deployment to make a
choice.

Regarding to CRITICAL vs OPTIMAL, we can classify the
default configurations so that systems meet customer
demands.

Saturday, August 26, 2006

Workload characterization

Cluster analysis such as k means and mini spanning tree categorize the natural groups of workload for performance modeling and cap planning

Thursday, August 24, 2006

T2000 interrupt bound

I have a T2000 server which experienced LOW CPU
usage. As you can see with the load generated,
CPU usage always 25% and interrupts are executed
by a fixed processor 24. All 64 threads of the user
land process (a single JVM process, multi-thread) only
thread number 33 is taking system and user land
resources and all other threads are in LOCK mode
and many VCX happen on these processors.

I have all ipge setting on /etc/system. I also have
all IP module setting in place. I am trying to verify
if it is system specific issue. That's why I am looking
for different system for a test.

Thursday, August 10, 2006

Disk Management on Solaris

(1) see how may disk

AVAILABLE DISK SELECTIONS:
0. c3t0d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@0,0
1. c3t1d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@1,0
Specify disk (enter its number):


There are 2 disks

(2) see how disk is used

# df -kh
Filesystem size used avail capacity Mounted on
/dev/dsk/c3t0d0s0 11G 7.8G 2.7G 75% /
/devices 0K 0K 0K 0% /devices
ctfs 0K 0K 0K 0% /system/contract
proc 0K 0K 0K 0% /proc
mnttab 0K 0K 0K 0% /etc/mnttab
swap 5.6G 1008K 5.6G 1% /etc/svc/volatile
objfs 0K 0K 0K 0% /system/object/platform/sun4v/lib/libc_psr/libc_psr_hwcap1.so.1
11G 7.8G 2.7G 75% /platform/sun4v/lib/libc_psr.so.1/platform/sun4v/lib/sparcv9/libc_psr/libc_psr_hwcap1.so.1
11G 7.8G 2.7G 75% /platform/sun4v/lib/sparcv9/libc_psr.so.1
fd 0K 0K 0K 0% /dev/fd
/dev/dsk/c3t0d0s5 5.8G 3.0G 2.7G 53% /var
swap 6.7G 1.1G 5.6G 16% /tmp
swap 5.6G 48K 5.6G 1% /var/run
/dev/lofi/1 330M 330M 0K 100% /tmp/s10install

you can see only disk0 c3t0d0 is in use


(3) See used disk partition


*# format*
Searching for disks...done


AVAILABLE DISK SELECTIONS:
0. c3t0d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@0,0
1. c3t1d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@1,0
*Specify disk (enter its number): 0*
selecting c3t0d0
[disk formatted]
Warning: Current Disk has mounted partitions.
/dev/dsk/c3t0d0s0 is currently mounted on /. Please see umount(1M).
/dev/dsk/c3t0d0s1 is currently used by swap. Please see swap(1M).
/dev/dsk/c3t0d0s5 is currently mounted on /var. Please see umount(1M).


FORMAT MENU:
disk - select a disk
type - select (define) a disk type
partition - select (define) a partition table
current - describe the current disk
format - format and analyze the disk
repair - repair a defective sector
label - write label to the disk
analyze - surface analysis
defect - defect list management
backup - search for backup labels
verify - read and display labels
save - save new disk/partition definitions
inquiry - show vendor, product and revision
volname - set 8-character volume name
! - execute , then return
quit
*format> partition

*
PARTITION MENU:
0 - change `0' partition
1 - change `1' partition
2 - change `2' partition
3 - change `3' partition
4 - change `4' partition
5 - change `5' partition
6 - change `6' partition
7 - change `7' partition
select - select a predefined table
modify - modify a predefined partition table
name - name the current table
print - display the current table
label - write partition map and label to the disk
! - execute , then return
quit
*partition> print*
Current partition table (original):
Total disk cylinders available: 14087 + 2 (reserved cylinders)

Part Tag Flag Cylinders Size Blocks
0 root wm 403 - 2616 10.74GB (2214/0/0) 22529664
1 swap wu 0 - 402 1.96GB (403/0/0) 4100928
2 backup wm 0 - 14086 68.35GB (14087/0/0) 143349312
3 unassigned wm 0 0 (0/0/0) 0
4 unassigned wm 0 0 (0/0/0) 0
5 var wm 2617 - 3824 5.86GB (1208/0/0) 12292608
6 unassigned wm 0 0 (0/0/0) 0
7 unassigned wm 0 0 (0/0/0) 0


(4) see how is the free disk paritioned

*# format*
Searching for disks...done


AVAILABLE DISK SELECTIONS:
0. c3t0d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@0,0
1. c3t1d0
/pci@7c0/pci@0/pci@1/pci@0,2/LSILogic,sas@2/sd@1,0
*Specify disk (enter its number): 1*
selecting c3t1d0
[disk formatted]
*format> partition*


PARTITION MENU:
0 - change `0' partition
1 - change `1' partition
2 - change `2' partition
3 - change `3' partition
4 - change `4' partition
5 - change `5' partition
6 - change `6' partition
7 - change `7' partition
select - select a predefined table
modify - modify a predefined partition table
name - name the current table
print - display the current table
label - write partition map and label to the disk
! - execute , then return
quit
*partition> print*
Current partition table (original):
Total disk cylinders available: 14087 + 2 (reserved cylinders)

Part Tag Flag Cylinders Size Blocks
0 root wm 0 - 25 129.19MB (26/0/0) 264576
1 swap wu 26 - 51 129.19MB (26/0/0) 264576
2 backup wu 0 - 14086 68.35GB (14087/0/0) 143349312
3 unassigned wm 0 0 (0/0/0) 0
4 unassigned wm 0 0 (0/0/0) 0
5 unassigned wm 0 0 (0/0/0) 0
* 6 usr wm 52 - 14086 68.10GB (14035/0/0) 142820160*
7 unassigned wm 0 0 (0/0/0) 0


(5) create mount point for disk1

create a directory $(dir Name)

mount /dev/dsk/c3t1d0s6 $(dirName)


so disk can be accessable now.

Monday, August 07, 2006

plockstat hit bug for the second call

I am on T2000 with S10 U3 bits of KernelID = Generic_118833-18

# plockstat -x aggsize=500m -x dynvarsize=200m -x bufresize=auto -p 654
^C
Mutex block

Count nsec Lock Caller
--------------------------------------------------------------------- ----------
Segmentation Fault(coredump)


The core file is below:

----------------- lwp# 1 / thread# 1 --------------------
ffffffff7ee39a50 strlen (100003faa, ffffffff7ffff6e8, ffffffff7eea0ed4, ffffffff7fffed99, 0, 100003fa9) + 50
ffffffff7eea4fdc snprintf (ffffffff7ffffa10, 0, 100003fa8, 0, ffffffff7ffff740, 100003000) + 88
0000000100001cd8 ???????? (1003bff20, ff2b9bec, ffffffff7ffffa10, 28, 1, 1d)
0000000100001ff4 ???????? (10040e4d8, 10040e4f8, 2, 10040e4d8, 10040e4c8, 100106990)
ffffffff7f225664 dt_aggregate_walk_sorted (10010b500, 100001de8, 0, ffffffff7f224f08, 0, 1004395c0) + a4
0000000100002e9c main (100001, 100106000, 100000, 100001000, 100107228, 100106) + ad0
000000010000159c _start (0, 0, 0, 0, 0, 0) + 17c
----------------- lwp# 2 / thread# 2 --------------------
ffffffff7eece820 _write (102, ffffffff725fbf48, 8, 0, ffffffff7e300000, 0) + c
ffffffff7f252768 dt_proc_control (0, 1fc000, 8, ffffffff725fbf48, 1, 1) + 1f0
ffffffff7eecd2d8 _lwp_start (0, 0, 0, 0, 0, 0)

Saturday, July 29, 2006

OS internal & many of many

How OS internal addresses platform virtualization and abstraction , real-time, embedded system, dependability,transaction management, availability, DSM,simulation, organism, structure design and trust computing for core system resource abstraction,energy management, firmware enhancement, zfs,CMT and open standard support, streaming support,high end computing etc.

For in-depth analysis, design and implementation,I may consider to land at theoretical computation, synchronous and asynchronous modeling,algorithmic operations on parallel formulation,and complexity proofs etc.

Thursday, July 27, 2006

IPC SystemV and POSIX IPCs

(1) semaphores, shared memory, message queue, System V and POSIX has different kernel implementation
(2) other IPC implementation such as mmap(2), named pipes, solaris doors

Wednesday, July 26, 2006

Power law of data center on SOA Management

Service techniques eventualy do transform into management
adapatation which in turn become an overall system and
os computation.

Is this the power law illustrated in data centers ?

http://searchwebservices.techtarget.com/originalContent/0,289142,sid26_gci1204593,00.html

Monday, July 24, 2006

Web2.0 & System Vendor

With respect to traditional tiered enterprise application and service analysis and design, I would have your point of views. Adherent to Web2.0, other than the dominant asynchronous industrial theme Ajax, blog and RSS present the diversified schemes. However, paralleling with the above presentation, heuristic notation of semantic web,in addition to mobility, Web 2.0 does make sense for conventional service providers and system vendors with the machine knowledge.

Hence, existing industrial crowds to Web 2.0 would enrich the subset of Grid infrastructure, access grid which presents the data grid to human actors Web semantics and description rules will provide learning and interactive interfaces to service entities such as machines.

Web2.0 & System Vendor

With respect to traditional tiered enterprise application
and service analysis and design, I would have your point
of views. Adherent to Web2.0, other than the dominant
asynchronous industrial theme Ajax, blog and RSS present
the diversified schemes. However, paralleling with the
above presentation, heuristic notation of semantic web,
in addition to mobility, Web 2.0 does make sense for
conventional service providers and system vendors
with the machine knowledge.

Hence, existing industrial crowds to Web 2.0 would enrich
the subset of Grid infrastructure, access grid which presents
the data grid to human actors Web semantics and description
rules will provide learning and interactive interfaces to
service entities such as machines.

Thursday, July 13, 2006

DDoS for mobile ad hoc peer-to-peer networks

R&D tasks has been done with MVS, Tandem before. Open systems will not be the destiny since parallelism and pipelining still motivate me. As one kind of virtualization technology, Java is appealing.

The key entity of the engineering activities is to contribute to the greedy security with mini spanning directed graph with asymmetric communication link.

With the associative environmental setting of distributed or even parallel communications,traditional centralized attack and detection goals or utilities have been challenged to yield the proximity in term of false positive ratio within the continuous and stochastic task environment. As for content aware defense, the locality and uniformity of key distribution needs further in depth discovery with the mobility, wireless sensors to extract the abstract vector of attributes in purpose of obtaining the relaxation to the proximity.

Wednesday, July 12, 2006

Layer 3 protocol algorithms with SOA XML packets

Pertaining to OSI reference model designated to conventional fixed infrastructure, complex networking, from small world to scale free established network layer routing, proves optimal routing performance measurement. Industrial practices implement the traditional optimization achieved upon traditional link-state and distance-vector algorithmic operations.

Both proactive and reactive path location strategy represent the industrial and engineering activities. Specifically, kernel land from Solaris, user land module from network layer devices such as router and even lower layer switch, packet based tunneling at critical super nodes over hierarchical topological deployment. In addition, an adaptive layer 3 protocol analysis and design would be considered for extension of the reserved 8 bit header to enable the routing control such that the path scheduling and planning algorithms could be interactive with earlier routes. Greedy security routing could be implemented with mini protocol enhancement. However, holding the setting of the classic end-to-end argument within computer science discipline, application layer processes hosted at user land would argue the complex learning or reasoning based packet routing and policy enforcement with the trade-off of processing overhead. Furthermore, taking dynamic and mobile computing, specially ad-hoc or peer-to-peer networks into account, less or no infrastructure with absence of head node, the routing from node level and network level to overlay level will argue the user land model, algorithm and protocol design and implementation.

Hence, packet switch networks tend to hold co-existence of the modular approach design aligned with computer science design principle.