Saturday, January 07, 2006

AM Instance Configuration Change Log

(1) add ou=DSAME Users,
(2) add marker class and attributes to dc=jesswitch,dc=com
objectclass:sunManagedOrganization
objectclass:organization
o:jesswitch
objectclass:sunNameSpace sunNameSpaceUniqueAttrs:o,sunPreferredDomain,associatedDomain,sunOrganization
objectclass:sunISManagedOrganization
sunOrganizationAlias:v1280-137-06.mdelabs-mpk.com
inetDomainStatus:Active
sunRegisteredServiceName:iPlanetAMAuthService
sunRegisteredServiceName:iPlanetAMAuthLDAPService
sunRegisteredServiceName:iPlanetPolicyConfigService
sunRegisteredServiceName:iPlanetAMAuthenticationDomainConfigService
sunRegisteredServiceName:iPlanetAMProviderConfigService

(3) assign proxy permission account(cn=puser) to access dc=jesswitch,dc=com
it is done
aci: (target="ldap:///dc=jesswitch,dc=com")(targetattr="*")(version 3.0; acl "
S1IS Proxy user rights"; allow (proxy) userdn = "ldap:///cn=puser,ou=DSAME U
sers,dc=jesswitch,dc=com"; )
(4) assign all permission to account(cn=dsameuser) to access dc=jesswitch,dc=com
it is done by creating an aci
aci: (target="ldap:///dc=jesswitch,dc=com")(targetattr="*")(version 3.0; acl "
S1IS special dsame user rights for all under the root suffix"; allow (all) u
serdn = "ldap:///cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com"; )
(5) assign read & search persmission for account amldapuser to access dc=jesswitch,dc=com
aci: (target="ldap:///dc=jesswitch,dc=com")(targetattr="*")(version 3.0; acl "
S1IS special ldap auth user rights"; allow (read,search) userdn = "ldap:///c
n=amldapuser,ou=DSAME Users,dc=jesswitch,dc=com"; )
(6) deny write permission to cn=amldapuser attributes for those users who
do not have cn=Top-level Admin Role

aci: (target="ldap:///cn=amldapuser,ou=DSAME Users,dc=jesswitch,dc=com")(targe
tattr = "*") (version 3.0; acl "S1IS special ldap auth user modify right"; d
eny (write) roledn != "ldap:///cn=Top-level Admin Role,dc=jesswitch,dc=com";
)

(7) assign all permissions to users with cn=Top-level Admin Role for dc=jesswitch,dc=com

aci: (target="ldap:///dc=jesswitch,dc=com")(targetattr="*")(version 3.0; acl "
S1IS Top-level admin rights"; allow (all) roledn = "ldap:///cn=Top-level Adm
in Role,dc=jesswitch,dc=com"; )

(8) deny delete permissions to anonymous users to cn=Top-level Admin Role for any attributes

aci: (target="ldap:///cn=Top-level Admin Role,dc=jesswitch,dc=com")(targetattr
="*")(version 3.0; acl "S1IS Top-level admin delete right denied"; deny (del
ete) userdn = "ldap:///anyone"; )

(9) deny all permisions to users without cn=Top-level
Admin Role, cn=dsameuser, cn=puser for iplanet-am-saml-user and iplanet-am-saml-password attributes of all iplanet-am-saml-service
since there is no target defined, access control applies to entire
entries

aci: (targetattr="iplanet-am-saml-user || iplanet-am-saml-password")(targetfil
ter="(objectclass=iplanet-am-saml-service)")(version 3.0; acl "S1IS Right to
modify saml user and password"; deny (all) (roledn != "ldap:///cn=Top-level
Admin Role,dc=jesswitch,dc=com") AND (userdn != "ldap:///cn=dsameuser,ou=DS
AME Users,dc=jesswitch,dc=com") AND (userdn != "ldap:///cn=puser,ou=DSAME Us
ers,dc=jesswitch,dc=com"); )

(10) deny all attribute delete permission for All users dc=jesswitch,dc=com

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(entrydn=dc=jesswitch
,dc=com))(targetattr="*")(version 3.0; acl "S1IS Default Organization delete
right denied"; deny (delete) userdn = "ldap:///anyone"; )

(11) assign all attribute read, search permissions to cn=Top-level Help Desk Admin Role for entries under dc=jesswitch,dc=com but entries does not have
nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(!(nsroledn=cn=Top-le
vel Admin Role,dc=jesswitch,dc=com)))(targetattr = "*") (version 3.0; acl "S
1IS Top-level Help Desk Admin Role access allow"; allow (read,search) roledn
= "ldap:///cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com";)

(12) assign userPassword attribute write permission to cn=Top-level Help Desk Admin Role for all entries under dc=jesswitch,dc=com but entries do not have
nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(!(nsroledn=cn=Top-le
vel Admin Role,dc=jesswitch,dc=com)))(targetattr = "userPassword") (version
3.0; acl "S1IS Top-level Help Desk Admin Role access allow"; allow (write) r
oledn = "ldap:///cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com";)

(13) assign all attribute read, search permissions to cn=Top-level Policy Admin Role for all entries under dc=jesswitch,dc=com but entries does not have nsroledn=cn=Top-
level Admin Role,dc=jesswitch,dc=com)

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-
level Admin Role,dc=jesswitch,dc=com))))(targetattr = "*") (version 3.0; acl
"S1IS Top-level Policy Admin Role access allow"; allow (read,search) roledn
= "ldap:///cn=Top-level Policy Admin Role,dc=jesswitch,dc=com";)

(14) deny all attribute add,write, delete permissions to cn=Top-level Policy Admin Role ou=iPlanetAMAuthService,ou=services,*dc=jesswitch,dc=com

aci: (target="ldap:///ou=iPlanetAMAuthService,ou=services,*dc=jesswitch,dc=com
")(targetattr = "*") (version 3.0; acl "S1IS Top-level Policy Admin Role acc
ess Auth Service deny"; deny (add,write,delete) roledn = "ldap:///cn=Top-lev
el Policy Admin Role,dc=jesswitch,dc=com";)

(15) assign all attribute permissions to cn=Top-level Policy Admin Role for all
ou=services,*dc=jesswitch,dc=com

aci: (target="ldap:///ou=services,*dc=jesswitch,dc=com")(targetattr = "*") (ve
rsion 3.0; acl "S1IS Top-level Policy Admin Role access allow"; allow (all)
roledn = "ldap:///cn=Top-level Policy Admin Role,dc=jesswitch,dc=com";)

(16) assign "sunRegisteredServiceName" attribute read,write,search permissions to cn=Top-level Policy Admin Role for entries under dc=jesswitch,dc=com which has objectclass=sunismanagedorganization

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter="(objectclass=sunisma
nagedorganization)")(targetattr = "sunRegisteredServiceName") (version 3.0;
acl "S1IS Top-level Policy Admin Role access allow"; allow (read,write,searc
h) roledn = "ldap:///cn=Top-level Policy Admin Role,dc=jesswitch,dc=com";)

(17) assign read,search,compare permissions to anonymous users to entire
entries whoes attributes are not userPassword || passwordHistory || passwordExpirationTime || passwordExpWarned || passwordRetryCount || retryCountResetTime || accountUnlockTime || passwordAllowChangeTime

aci: (targetattr != "userPassword || passwordHistory || passwordExpirationTime
|| passwordExpWarned || passwordRetryCount || retryCountResetTime || accoun
tUnlockTime || passwordAllowChangeTime ") (version 3.0; acl "Anonymous acces
s"; allow (read, search, compare)userdn = "ldap:///anyone";)

(18) deny self delete permission to users for entire entires and all attributes

aci: (targetattr = "*")(version 3.0; acl "S1IS Deny deleting self"; deny (dele
te) userdn ="ldap:///self";)

(19)deny self write permission to attributes below except entries with
cn=Top-level Admin Role

aci: (targetattr = "objectclass || inetuserstatus || iplanet-am-user-login-sta
tus || iplanet-am-web-agent-access-allow-list || iplanet-am-domain-url-acces
s-allow || iplanet-am-web-agent-access-deny-list || iplanet-am-user-account-
life || iplanet-am-session-max-session-time || iplanet-am-session-max-idle-t
ime || iplanet-am-session-get-valid-sessions || iplanet-am-session-destroy-s
essions || iplanet-am-session-add-session-listener-on-all-sessions || iplane
t-am-user-admin-start-dn || iplanet-am-auth-post-login-process-class")(targe
tfilter=(!(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)))(version 3
.0; acl "S1IS User status self modification denied"; deny (write) userdn ="l
dap:///self";)

(20) assign self write permissions to entire entries except the attributes
below
aci: (targetattr != "iplanet-am-static-group-dn || uid || nsroledn || aci || n
sLookThroughLimit || nsSizeLimit || nsTimeLimit || nsIdleTimeout || memberOf
|| iplanet-am-web-agent-access-allow-list || iplanet-am-domain-url-access-a
llow || iplanet-am-web-agent-access-deny-list")(version 3.0; acl "S1IS Allow
self entry modification except for nsroledn, aci, and resource limit attrib
utes"; allow (write)userdn ="ldap:///self";)

(21)assign self read, search permissions exception attributes below

aci: (targetattr != "aci || nsLookThroughLimit || nsSizeLimit || nsTimeLimit |
| nsIdleTimeout || iplanet-am-domain-url-access-allow")(version 3.0; acl "S1
IS Allow self entry read search except for nsroledn, aci, resource limit and
web agent policy attributes"; allow (read,search)userdn ="ldap:///self";)

(22) assign anonymous read,search,compare permissions to
ou=services,dc=jesswitch,dc=com but not those entries with
objectclass=sunServiceComponent

aci: (target="ldap:///ou=services,dc=jesswitch,dc=com")(targetfilter=(!(object
class=sunServiceComponent)))(targetattr = "*")(version 3.0; acl "S1IS Servic
es anonymous access"; allow (read, search, compare) userdn = "ldap:///anyone
";)

(23) assign anonymous read,search,compare access to ou=iPlanetAMAdminConsoleService
all attributes
aci: (target="ldap:///ou=iPlanetAMAdminConsoleService,*,dc=jesswitch,dc=com")(
targetattr = "*")(version 3.0; acl "S1IS iPlanetAMAdminConsoleService anonym
ous access"; allow (read, search, compare) userdn = "ldap:///anyone";)

(24) assign all permissions to cn=Organization Admin Role to entries
($dn),dc=jesswitch,dc=com and enties do no have
(nsroledn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help DeskAdmin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,dc=j
esswitch,dc=com) and not nsroledn attribute

aci: (target="ldap:///($dn),dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=c
n=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk
Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,dc=j
esswitch,dc=com))))(targetattr != "nsroledn")(version 3.0; acl "S1IS Organiz
ation Admin Role access allow all"; allow (all) roledn = "ldap:///cn=Organiz
ation Admin Role,[$dn],dc=jesswitch,dc=com";)


(25) deny all attribute write,add,delete,compare,proxy permissions
to cn=Organization Admin Role,($dn),dc=jesswitch,dc=com
cn=Organization Admin Role,($dn),dc=jesswitch,dc=com

aci: (target="ldap:///cn=Organization Admin Role,($dn),dc=jesswitch,dc=com")(t
argetattr="*")(version 3.0; acl "S1IS Organization Admin Role access deny";
deny (write,add,delete,compare,proxy) roledn = "ldap:///cn=Organization Admi
n Role,($dn),dc=jesswitch,dc=com";)

(26)

aci: (target="ldap:///($dn),dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=c
n=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk
Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,dc=j
esswitch,dc=com))))(targetattr != "nsroledn")(version 3.0; acl "S1IS Contain
er Admin Role access allow"; allow (all) roledn = "ldap:///cn=Container Admi
n Role,[$dn],dc=jesswitch,dc=com";)

(27)

aci: (target="ldap:///cn=Container Admin Role,($dn),dc=jesswitch,dc=com")(targ
etattr="*")(version 3.0; acl "S1IS Container Admin Role access deny"; deny (
write,add,delete,compare,proxy) roledn = "ldap:///cn=Container Admin Role,($
dn),dc=jesswitch,dc=com";)

(28)

aci: (target="ldap:///dc=jesswitch,dc=com")(targetattr!="nsroledn")(version 3.
0; acl "S1IS Group admin's right to the users he creates"; allow (all) usera
ttr = "iplanet-am-modifiable-by#ROLEDN";)

(29)


aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-
level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin
Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,dc=jesswit
ch,dc=com)(nsroledn=cn=Organization Admin Role,dc=jesswitch,dc=com))))(targe
tattr = "*") (version 3.0; acl "S1IS Organization Help Desk Admin Role acces
s allow"; allow (read,search) roledn = "ldap:///cn=Organization Help Desk Ad
min Role,dc=jesswitch,dc=com";)

(30)

aci: (target="ldap:///dc=jesswitch,dc=com")(targetfilter=(!(|(nsroledn=cn=Top-
level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help Desk Admin
Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,dc=jesswit
ch,dc=com)(nsroledn=cn=Organization Admin Role,dc=jesswitch,dc=com))))(targe
tattr = "userPassword") (version 3.0; acl "S1IS Organization Help Desk Admin
Role access allow"; allow (write) roledn = "ldap:///cn=Organization Help De
sk Admin Role,dc=jesswitch,dc=com";)


(31)

aci: (target="ldap:///ou=People,dc=jesswitch,dc=com")(targetfilter=(!(|(nsrole
dn=cn=Top-level Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Help D
esk Admin Role,dc=jesswitch,dc=com)(nsroledn=cn=Top-level Policy Admin Role,
dc=jesswitch,dc=com)(nsroledn=cn=Organization Admin Role,dc=jesswitch,dc=com
)(nsroledn=cn=Container Admin Role,dc=jesswitch,dc=com))))(targetattr != "ip
lanet-am-web-agent-access-allow-list || iplanet-am-domain-url-access-allow |
| iplanet-am-web-agent-access-deny-list || nsroledn") (version 3.0; acl "S1I
S Group and people container admin role"; allow (all) roledn = "ldap:///cn=o
u=People_dc=jesswitch_dc=com,dc=jesswitch,dc=com";)

(32)

aci: (targetattr = "*")(version 3.0; acl "S1IS Deny write to anonymous user";
deny (add,write,delete) roledn ="ldap:///cn=Deny Write Access,dc=jesswitch,d
c=com";)

(33) add o=Internet,dc=jesswitch,dc=com entry with marker class

changes=objectClass: top
objectClass: organization
o: Internet

(34) add cn=Deny Write Access,dc=jesswitch,dc=com role
cn=Top-level Admin Role,dc=jesswitch,dc=com role
cn=Top-level Help Desk Admin Role,dc=jesswitch,dc=com role
cn=Top-level Policy Admin Role,dc=jesswitch,dc=com

(35) add ou=People,dc=jesswitch,dc=com people container

(36) add cn=ou=People_dc=jesswitch_dc=com,dc=jesswitch,dc=com
people container admin role

(37) ou=Groups,dc=jesswitch,dc=com
cn=puser,ou=DSAME Users,dc=jesswitch,dc=com
cn=dsameuser,ou=DSAME Users,dc=jesswitch,dc=com
cn=amldapuser,ou=DSAME Users,dc=jesswitch,dc=com
uid=amAdmin,ou=People,dc=jesswitch,dc=com
with nsRoleDN: cn=Top-level Admin Role,dc=jesswitch,dc=com
uid=anonymous,ou=People,dc=jesswitch,dc=com
with nsRoleDN: cn=Deny Write Access,dc=jesswitch,dc=com
cn=amService-UrlAccessAgent,ou=DSAME Users,dc=jesswitch,dc=com
(38)
cn=ContainerDefaultTemplateRole,dc=jesswitch,dc=com
(39)
ou=ClientData,dc=jesswitch,dc=com
ou=SunAMClientData,ou=ClientData,dc=jesswitch,dc=com
ou=1.0,ou=SunAMClientData,ou=ClientData,dc=jesswitch,dc=com

(40) ou=services,dc=jesswitch,dc=com
ou=DAI,ou=services,dc=jesswitch,dc=com
ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=PluginConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=Instances,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=FilteredRole,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunkeyvalue: searchtemplatename=BasicFilteredRoleSearch
sunkeyvalue: objectclass=iplanet-am-managed-filtered-role
sunkeyvalue: creationtemplatename=BasicFilteredRole

targetDn=ou=PeopleContainer,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunkeyvalue: objectclass=iplanet-am-managed-people-container
sunkeyvalue: creationtemplatename=BasicPeopleContainer
sunkeyvalue: searchtemplatename=BasicPeopleContainerSearch

ou=Agent,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunkeyvalue: searchtemplatename=BasicAgentSearch
sunkeyvalue: servicename=iPlanetAMAgentService
sunkeyvalue: type=100
sunkeyvalue: creationtemplatename=BasicAgent
sunkeyvalue: statusattribute=sunIdentityServerDeviceStatus
sunkeyvalue: parentcontainertype=3
sunkeyvalue: objectclass=sunIdentityServerDevice
sunkeyvalue: parentcontainerdn=agents

ou=AssignableDynamicGroup,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunkeyvalue: creationtemplatename=BasicAssignableDynamicGroup
sunkeyvalue: searchtemplatename=BasicAssignableDynamicGroupSearch
sunkeyvalue: parentcontainerdn=groups
sunkeyvalue: type=12
sunkeyvalue: objectclass=iplanet-am-managed-assignable-group
sunkeyvalue: parentcontainertype=4
ou: AssignableDynamicGroup

ou=Client,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunkeyvalue: searchtemplatename=BasicClientSearch
sunkeyvalue: creationtemplatename=BasicClient

ou=templates,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=StructureTemplates,ou=templates,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
ou=GroupContainer,ou=StructureTemplates,ou=templates,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunserviceid: StructureUmsObjects
sunkeyvalue: priority=0
sunkeyvalue: class=com.iplanet.ums.OrganizationalUnit
sunkeyvalue: name=ou=Groups
sunkeyvalue: filter=(objectClass=iplanet-am-managed-group-container)
sunkeyvalue: template=BasicGroupContainer

ou=DPOrgPolicyAdminRole,ou=StructureTemplates,ou=templates,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
sunserviceid: StructureUmsObjects
sunkeyvalue: filter=(cn=Organization Policy Admin Role)
sunkeyvalue: template=Organization Policy Admin Role
sunkeyvalue: name=cn=Organization Policy Admin Role
sunkeyvalue: class=com.iplanet.ums.ManagedRole

ou=PeopleContainer,ou=StructureTemplates,ou=templates,ou=default,ou=GlobalConfig,ou=1.0,ou=DAI,ou=services,dc=jesswitch,dc=com
objectClass: sunServiceComponent
sunserviceid: StructureUmsObjects
sunkeyvalue: template=BasicPeopleContainer
sunkeyvalue: name=ou=People
sunkeyvalue: priority=0
sunkeyvalue: filter=(ou=People)
sunkeyvalue: class=com.iplanet.ums.PeopleContainer

Friday, January 06, 2006

Class Loader

(1) All app has at least 3 class loader

a. bootstrap class loader (C implemented ClassLoader part of JVM for rt.jar)

therefore, Integer.class.getClassLoader() always return "null"

Java Implementation Class Loader
b. extension class loader ( does not use class path) extended from URLClassLoader

Normally, do not place jar in extenstion class dir jre/lib/ext

c. system (application) class loader use class patth extended from URLClassLoader

(2) Class Loader is parent/child relationship

any class loader exception bootstrap class loader has a parent class loader

whenerver current class loader is asked to load foo.class, it ask it's
parent system (app) class loader, extension class loader and bootstrap ]
class loader. If any of the parent loaded the class, it will not be loaded
again.

For class loading, the rule is that always do "delegate" class loading.
Delegate to parent first. Otherwise customer class loader may accidently
load a version of system class that bypass the important security check
The good customer class loaders are Applet, Servlet, and RMI stubs


Any customer class loader can be written for special purpose. However,
customer class loader should carry out specialized secutiry check. For
instance, a class loader can refuse to load a class has not been marked
with "Paid"

(3) to load a class by current class loader

foo.class.forName()


However, if your library create your own Class.forName(), or current application
is loaded by different classloader than the classloader loaded the foo.class
or loaded class is not visiable from the class loader that load library

Thread curThread = Thread.currentThread();
ClassLoader loader = curThread.getContextClassLoader();
Class clazz = loader.loadClass(className);

(4) a class loader to load encrypted classes

public fooClassLoader extends ClassLoader

{

protected Class findClass(String name) throws ClassNotFindException
{
byte[] classBytes = loadClassByBytes(name); // load byte code

Class clazz = defineClass(name, classBytes,0 classBytes.length); // present byte code to JVM, defineClass is in the supper ClassLoader class

if(clazz == null)
throw new ClassNotFoundException(name);

return clazz;

}

}

Socket Interruption

To interrupt a sockect operation

SocketChannel channel = SocketChannel.open(new InetSocketAddress("localhost",8999));
try
{
in = new Scanner(channel);
while(true)
{
}

}
finally

{

channel.close();

}

Socket half close is to have client
to
socket.shutdownOuput() to close output stream
but socket still can read from input stream

Data Structure

(1) Array and ArrayList are expensive for updates (insert and remove)
any change will cause the all move of the structure
However, LinkedList resolve the issue but CiruclarArrayQueue is more efficient than LinkedList. But CircularArrayQueue is bounded. For unbound operation linkedList
is better
(2) LinkedList is different from common Collection. It is ordered collection.

(3) ListIterator has add(), previous and hasPrevious cursor type methods which
Iterator does not have LinkedList does not have either

ListIterator has traversing features

(4) 2 protocols to access Collection

get and set
Iterator and ListInterator

get and set fits Arrays

(5) HashSet Hashtable HashMap for fast access unorder strcuture without knowing location LinkedList is for order structure with known position
TreeSet improved as sorted collection
(6)LinkedHashset, LinkedHashMap improved by ordering
LinkedHashMap is the perfect for LRU cache implemenation
since it is by accessing order instead of insert order

(6) Collection views

lighweight wrapper view

asList();
nCopies();

Subranges view for numbers

subList, subMap

Unmodifiable Views

unmodifiableList

Synchronized View is limited better to used CocurrentHashMap()

Checked View for debug

Thursday, January 05, 2006

Multi-thread

(1) a thread is terminated
by being interrupted. InterruptedException
run method returns
(2) call to new Threan(runnable).start() to trigger the execution of the thread
(3) to request a thread to terminated, interrupt() method is used
if interrupt() is called on a blocking thread such as sleep or wait,
the blocking thread will be terminated by InterruptedException will thrown
However, the interrupted thread will decide how to react to the InterruptedException. Normally, it is used to terminated the thread
(4) Therefore, thread handling code should check interrupted status

while(!Thread.currentThread().isInterrupted() && hasMoreWork())
{
doMoreWork();
}
However in the loop with sleep() do not need to check isInterrupted()
since interrupt() the blocking thread will throw InterruptedException
(5) Do not ignore InterruptedException
try
{
}catch(InterruptedException e)
{
Thread.currentThread().interrupt();
}

or

void doWork() throws InterruptedException
{
}

(6)Thread state
New new Thread(runnable)
Runnable thread.start() is called
Blocked sleep(), block on I/O, wait for lock, wait for condition, wait()
Dead run() returns or uncaught exception terminate the thread

Please Thread.yield() is a static method. It only yield current executing thread but can not do for specific thread.

To wait for a specific thread to die using thread.join()

Daemon thread is to server other threads. Daemon Thread vs. User Thread

To interrupt many threads in one shot, using ThreadGroup or executors


Two fundamental cocurrent programming issues


race condition

(1) Every Object has implicit lock and implicit condition, synchronize (auto lock/unlock and condition)since object has implicit lock and implicit condition. Thread enters synchronized method auto acquire the lock of the object. However, sychronize only has a single condition

public syncrhonize void doWork() throws InterruptedException
{
while(condition variable)
wait();
execute();
notifyAll(); // every important so that no dead lock
}

(2) A explicit lock, new ReentrantLock() mannual lock(), condition and unlock()
A calling thread can repeatly acquires the lock if it is the owner of the lock
Lock protect the critical section of the code and allow only one thread
executed at a time. Condition Object is used for the thread entering the
protected critical section

objLock.lock(); // if (objLock.tryLock(100, MiliSecond)) so that it quick return
try
{
// both condition test and obj manipulation
// should be in critical section for lock protection
while(!condition variable)
okCondition.await();
doMoreWork();
okCondition.signalAll();
}
finally
{
objLock.unlock();
}
private objLock = new ReenterLock(); // construct the lock for critical section
private Condition okCondition = objLock.newCondition(); // so that it could have many conditions

(3) singalAll() to unblock the waiting threads, Condition Object only
has signalAll(), signal(), await() in order to diff from Object's
wait() and notifyAll()

(4) synchronized block: Java Object diff from Monitor
a. does not have to all private fields
b. methods does not have to all sychronize
c. lock has only one condition

synchronized(obj)
{
critical section
}
private Object obj = new Object();

(5) To make a object field thread safe

a. the field is volatile
b. field is final and it is accessed after constuctor is completed
c. field access is protected by a lock such as synchronize or implicit lock

(6) If there are many reader but less writer

ReentrantReadWriteLock rwl = new ReentrantReadWriteLock ();

public double read()
{
readLock.lock();
try {}
finally { readLock.unlock();}

}

public void write()
{
writeLock.lock();
try{}
finally { writeLock.unlock();}
}




(7)ConcurrentLinkedQueue (non-blocking queue) and ConcurrentHashMap is the most efficient cache and return weakly consistent interators

(8) Copy in Write Array is for large amound of writer to the data structure but
reader read the most latest collection. However the interator is old therefore
the read data may be stale.
(9) Callable task executed asynchronized with return Object, has exeception
Runnable task executed asynchronized no return no exception no paramemters
Future holds the async computation results

Callable computation = ......; // long run task
FutureTask task = new FutureTask(computation);// create future task and use it to start a thread
Thread t = new Thread(task);
t.start();
...........
Integer result = task.get();

(10) for all short live thread using thread pool with Executor.newCachedThreadPool()

ExecutorService pool = Executors.newCachedThreadPool();
Callable computation = .......;// long run task
Future result = pool.submit(computation);

......
pool.shutdown();

ExecutorCompletionService service = new ExecutorCompletionService(executor);
for(Callable task:tasks)
service.submit(task);
for(int i =; i < tasks.size(); i++)
count += service.take().get();
(11) Thread Collaboration (CyclicBarrier, CountDownLatch, Exchanger, SynchronousQueue, Semaphore)

serialVersionUID

object is identified by SHA finger print. However, stand alone serialver can help
to generate serialVersionUID so that the different version of serializable object
can be used for the readObject and writeObject

Serialization

singleton and enum serialization does require readResolve

StringBuffer and StringBuilder

StringBuffer can handle multi-thread modification to string buffer,
However StringBuild is for single thread and arrayList based mod
is more efficient

Unicode I/O

(1) InputStream and OutputStream are raw bytes I/O which does not fit for Unicode base I/o processing
(2) Reader and Writer are the choices for the Unicode based read and write
(3) nio Charset does encode and decode between byte[] and unicode string, nio byteBuffer does the help for decode too

Proxy to create new classes implement a set of interfaces at runtime

As we do not know which interfaces to be implemented at compile time. Proxy can be used to implement a specific interfaces at run time.

(1) Bean box solution is poor in performance
(2) proxy is better solution to create new classes with specified interfaces
The generated proxy classes

1. implements all operations specified in the interfaces
2. all methods in Object class such as equals(), toString(), clone() etc

In summary, implement InvocationHandler, create new handler, create new Proxy
and do the work. There after, invocation handler will be invoked.

Object proxy = Proxy.newInstance(classLoader, interfaces, invocationHandler)

Here the specific interfaces can be sepcified for the create proxy class.
invocation hander can do
(1) route the call to remote servers
(2) associate the events with actions --- interfaces and invocationHandler
(3) do tracing on

Simple and Dynamic on fly

Inner class

(1) only inner class can be private
(2) inner class is to access outer object private fields
(3) if requires inner class at local method, then local inner class is created.
of course, local inner class can access outer class field and method local variables. To be carefull about the param passed in local method. the variable used
for local inner class should be final variable so that the variable can not be modified
as it is inited
(4) anonymous inner class does the callback event action handling nicly. It is a step further with local inner class however, it does not define object name and object constructor but using super class ActionListener
(5) static inner class is used as we do not need inner class accessing outer class

Clone is required

Clone is the required

(1) object does have mutable fields specifically for those reference to the mutable
objects
(2) if the deep copy is required

(3) serialization is the alternative however it is too expensive

Method pointer & Interface & Callbacks

(1) Method pointer ---- Method reflection are the same goal from C to Java
(2) Interfaces & inner classes are the better option in terms of performance specifically for those call backs

CMT Core and SRM processor set binding

I am with a CMT 8 core server. ISV product has pricing model per Core.
Current SRM does address cpu resource control via cpu resource pool
bound to NG-Zone. However it is to create processor-set with the number
of processors allocated. How is the sequence of processor related to
the CMT core ? How to associate the processor set with the Core ?

poolcfg -c 'create pset pset_gfe411-1 (uint pset.min=4; uint pset.max=4)'

static import

static import is good for

(1) math
(2) constant such as System.out

Reflection of Generic Array expanding

(1) Traditionally, arrycopy is used to expande array.

static Object[] badWay (Object[] a)
{
int length = a.length * 11/ 10 + 10;
Object[] newA = new Object[length];
System.arrayCopy(a,0,newA,0,a.length);
return newA;

}

it return Object[] only without type info.

However, Array reflection API does it return Object

static Object goodWay (Object a)
{
Class clz = a.getClass();
if(!clz.isArray()) return null;
Class componentType = cl.getComponentType();
int length = Array.getLength(a);
int newLength = length * 11 / 10 + 10;
Object newArray = Array.newInstance(componentType, newLength);
System.arraycopy(a,0,newArray,0,length);
return newArray;
}

Wednesday, January 04, 2006

Solaris(TM) hostname resolution for aliase and multiple hostname

Hostnames are listed in the hosts database, which may be contained in the /etc/hosts and /etc/inet/ipnodes files, the Network Information Service (NIS) hosts map, the Internet domain name server, or a combination of these. Each host has one official name (the first name in the database entry), and optionally one or more nicknames. Either official hostnames or nicknames may be specified in hostname.

The hosts file is a local database that associates the names of hosts with their Internet Protocol (IP) addresses. The hosts file can be used in conjunction with, or instead of, other hosts databases, including the Domain Name System (DNS), the NIS hosts map, the NIS+ hosts table, or information from an LDAP server. Programs use library interfaces to access information in the hosts file.

The hosts file has one entry for each IP address of each host. If a host has more than one IP address, it will have one entry for each, on consecutive lines. The format of each line is:

IP-address official-host-name nicknames . . .

Items are separated by any number of SPACE and/or TAB characters. The first item on a line is the host's IP address. The second entry is the host's official name. Subsequent entries on the same line are alternative names for the same machine, or “nicknames.” Nicknames are optional.

For a host with more than one IP address, consecutive entries for these addresses may contain the same or differing nicknames. Different nicknames are useful for assigning distinct names to different addresses.

A call to gethostbyname(3NSL) returns a hostent structure containing the union of all addresses and nicknames from each line containing a matching official name or nickname

Important thing to know the order of the reolved by nsswitch.conf

The operating system uses a number of databases of information about hosts, ipnodes, users (passwd and shadow), and groups. Data for these can come from a variety of sources: hostnames and host addresses, for example, can be found in /etc/hosts, NIS, NIS+, LDAP, or DNS. Zero or more sources may be used for each database; the sources and their lookup order are specified in the /etc/nsswitch.conf file.

resolve.conf is specific to DNS only
The resolver is a set of routines that provide access to the Internet Domain Name System.

In summary, (1) add ip and hostname or alias in the /etc/host file
(2) check nsswitch.conf has right order to lookup name
under swan, files nis instead of nis files
(3) resolv.conf only for DNS cases

Tuesday, January 03, 2006

Solaris 10 network configuration

(1)


To change the Ethernet address for interface ce1, use the
following command:

ifconfig ce1 ether aa:1:2:3:4:5


allocates a specific logical interface associated with the
physical interface ce1. The command

ifconfig ce1 addif 192.168.200.1/24 up


(3) Solaris TCP/IP allows multiple logical interfaces to be
associated with a physical network interface. This allows a
single machine to be assigned multiple IP addresses, even
though it may have only one network interface. Physical net-
work interfaces have names of the form driver-name
physical-unit-number, while logical interfaces have names of
the form driver-name physical-unit-number:logical-unit-
number. A physical interface is configured into the system
using the plumb command. For example:

ifconfig ce1 plumb


(4) If your workstation is not attached to an Ethernet, the net-
work interface, for example, ce1, should be marked "down"
as follows:

ifconfig ce1 down


(5)To delete a logical interface, use the unplumb or removeif


ifconfig ce1 down unplumb

Real Time Transaction Services on Solaris 10 CMT Platform

Overview

A real time services are the services where the correctness of the services depending on the timelines and predictability of the services as well as the results of computing. This white paper discusses the domain problems and challenges to the industry to provide quality of real time services. To resolve those problems, this paper proposes the cost effective high throughput real time solution to provide real time system and infrastructure. To examine the real world use cases, Kabira KTS and Sun UltraSPARC T1 processor based Sun Fire T1000 and T2000 are presented. The evaluation test architecture, framework and test cases are illustrated. In addition, this paper steps you through performance management methodology specific to Sun CMT platforms. This paper is targeted to real time system architects, developers, performance engineers and data center service providers to architect, design, implement and deliver compelling real time services.

Background

Real time services require high throughput and low latency for interprocess communication and synchronization, a fast interrupt response time, asynchronous input and output, memory management capabilities, file synchronization, and facilities for satisfying timing requirements etc.

Traditional processor design has long emphasized the performance of a single hardware thread of execution, and focused on providing high levels of instruction-level parallelism (ILP). These increasingly complex processor designs have been driven to very high clock rates (frequencies), often at the cost of increased power consumption and heat production. Unfortunately, the impact of memory latency has meant that even the fastest single-threaded processors spend most of their time stalled, waiting for memory. Complicating this tendency, many of today’s complex commercial workloads are simply unable to take advantage of instruction-level parallelism, instead benefiting from thread-level parallelism (TLP).



Solution Description

Throughput refers to transaction, amount of data transferred via data bus or processing unit within one second, transaction count that the computer system can process in given time. To maximizing the overall throughput of key commercial workloads rather than the speed of a single thread of execution, Chip multi-threading (CMT) processor technology is the key to provide a new thread-rich environment that drives application throughput and processor resource utilization while effectively masking memory access latencies.

Sun UltraSPARC T1 processor is based on CoolThreads(TM) Technology. Combining chip multi-processing and hardware multi-threading with an efficient instruction pipeline, UltraSPARC T1 processor drastically improves computational density and greatly reduce power density.

Providing multiple physical-instruction execution pipelines and several active thread contexts per pipeline.
Effectively masking memory access latencies in multi-thread environment
Providing improved scalability for many multi-thread applications.
“Symmetric Multiprocessing” (SMP) on a chip for developers
Applications scaling well on SMP platforms will do so in UltraSPARC T1 platforms.
A twelve-way associative unified Level 2 (L2) on-chip cache.
Memory latency that is uniform across all cores
Low-latency Double Data Rate 2 (DDR2) memory to reduce stalls.
Improving throughput while using less power and dissipating less heat than conventional CMP platforms.
With CoolThreads, each CPU core can run up to four threads simultaneously
Scaling well for Multi-threaded applications, Multi-process applications and Multi-instance applications

Sun servers with UltraSPARC T1 processors can be configured with four, six, or eight processor cores. Each core employs a 64-bit execution pipeline with four logical processors capable of processing four active execution contexts referred to as threads. This means that the thirty two logical processors in an eight-core processor can process up to thirty two active execution contexts. In addition, UltraSPARC T1 processor, combined with the Solaris 10 Operating System, have provided the foundation for real time computing hosted within a power and space-efficient environment. Furthermore, Solaris container and resource management This allows real time applications to take advantage of the latest technologies while at the same time reducing power, HVAC and space demands.

Solaris Container consists of a group of technologies that work together to efficiently manage system resources, virtualize the environment, and provide a complete, isolated, and secure runtime environment for applications. Solaris containers include two important technologies: Solaris Zones partitioning technology and resource management tools. Solaris Zones enable an administrator to create separate environments for applications on a single system, while the resource management framework allows for the allocation, management, and accounting of system resources such as CPU and memory.

Solaris Zones is a unique partitioning technology used to create an isolated and secure environment for running applications. Zones provides isolation to enhance security and reliability.
Resource Management enables system resources such as CPU resources to be dedicated to specific applications. Resource pools provide the capability to separate workloads so that consumption of CPU resources do not overlap, and also provide a persistent configuration mechanism for processor sets and scheduling class assignment.

Kabira Transaction Switch achieves mainframe level performance, supporting tens of thousands of Transactions Per Second (TPS) on a scalable, continuously available system. The KTS massively parallel threading architecture makes maximum use of the thirty two virtual threads in the UltraSPARC T1 processor. It uses full-featured, Solaris ten on 64-bit SPARC servers rather than using expensive proprietary equipment. When demand increases, the system can scale up linearly with the addition of another blade, or scale out with the addition of another chassis. Kabira leverages this technology to provide eight times the performance of the traditional CMP based platform per socket.

AS annotation framework conf call

It has been expected for the AS annotation framework
conf call. It has been scheduled for 1 hour call.
on Friday