Sunday, April 7, 2013

Google Redirect Rewrite memory usage

Image courtesy of Open Clip Art Library
I previously found out that you can pretty easily rewrite url's for Squid. Today I noticed Squid launches a bunch of child processes to do the url rewriting. I got curious about the memory usage. I had a feeling that the Perl version would not consume as much memory as PHP and it appears it is indeed so.

I tested both PHP and Perl versions to see how much memory they would consume. First I checked the memory usage of the PHP version after browsing a bit. Then I changed squid.conf to use the Perl version and again checked the memory usage. Squid had just launched one googlerewriter child process, so I browsed some more and then checked again. I'm guessing Squid starts the processes when it actually needs them.(ps. Documentation confirmes this) Anyway some processes then appeared to have been launched.

Fields

MAJFL
Major page fault: The number of major page faults that have occurred with this process
TRS (kB)
Text resident set: The amount of physical memory devoted to executable code
DRS (kB)
Data resident set: The amount of physical memory devoted to other than executable code
RSS (kB)
Resident set size: The portion of a process's memory that is held in RAM. The rest of the memory exists in swap or the filesystem (never loaded or previously unloaded parts of the executable).

Even for a tiny script php version caused some page faults and it's using way too much memory for the task it's doing.

PHP

$ ps faxv
  PID TTY      STAT   TIME  MAJFL   TRS   DRS   RSS %MEM COMMAND
13098 ?        Ss     0:00      0  5047 12668  2608  0.0 /usr/sbin/squid -a 3128 -f /etc/squid/squid.conf
13100 ?        S      0:01      5  5047 35240 25052  0.4  \_ (squid-1) -a 3128 -f /etc/squid/squid.conf
13101 ?        S      0:00      0     5  3942   992  0.0      \_ (logfile-daemon) /var/log/squid/access.log
13102 ?        S      0:00      1     2  3793   740  0.0      \_ (unlinkd)
13109 ?        S      0:00     50  3385 43962  7812  0.1      \_ /usr/bin/php /usr/local/bin/googlerewriter.php
13111 ?        S      0:00      0  3385 43962  7816  0.1      \_ /usr/bin/php /usr/local/bin/googlerewriter.php
13115 ?        S      0:00      0  3385 43962  7816  0.1      \_ /usr/bin/php /usr/local/bin/googlerewriter.php
13116 ?        S      0:00      0  3385 43962  7812  0.1      \_ /usr/bin/php /usr/local/bin/googlerewriter.php
13117 ?        S      0:00      0  3385 43962  7816  0.1      \_ /usr/bin/php /usr/local/bin/googlerewriter.php

$ top
  PID USER      PR  NI  VIRT  RES  SHR S  %CPU %MEM    TIME+  COMMAND
15552 squid     20   0 47348 7812 5428 S   0.0  0.1   0:00.05 googlerewriter.
15735 squid     20   0 47348 7816 5428 S   0.0  0.1   0:00.03 googlerewriter.
15736 squid     20   0 47348 7816 5428 S   0.0  0.1   0:00.03 googlerewriter.
15741 squid     20   0 47348 7816 5428 S   0.0  0.1   0:00.03 googlerewriter.
The resident set size of the Perl version is 31% that of the PHP version, or in other words the PHP version is using 3 times as much memory per process. By using the Perl version you'd save at least 5.2MiB. Not that this matters much on my current proxy server, but for an embedded server it would matter.

Perl

$ ps faxv
  PID TTY      STAT   TIME  MAJFL   TRS   DRS   RSS %MEM COMMAND
13382 ?        Ss     0:00      0  5047 12668  2608  0.0 /usr/sbin/squid -a 3128 -f /etc/squid/squid.conf
13384 ?        S      0:01      0  5047 37988 25308  0.4  \_ (squid-1) -a 3128 -f /etc/squid/squid.conf
13387 ?        S      0:00      0     5  3942   992  0.0      \_ (logfile-daemon) /var/log/squid/access.log
13388 ?        S      0:00      0     2  3793   740  0.0      \_ (unlinkd)
13396 ?        S      0:00      0     3  8700  2460  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl
13426 ?        S      0:00      0     3  8700  2376  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl
13427 ?        S      0:00      0     3  8700  2372  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl
13429 ?        S      0:00      0     3  8700  2460  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl
13430 ?        S      0:00      0     3  8700  2460  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl
13431 ?        S      0:00      0     3  8700  2460  0.0      \_ /usr/bin/perl /usr/local/bin/googlerewriter.pl

$ top
  PID USER      PR  NI  VIRT  RES  SHR S  %CPU %MEM    TIME+  COMMAND
13396 squid     20   0  8704 2460 1724 S   0.0  0.0   0:00.19 googlerewriter.
13429 squid     20   0  8704 2460 1724 S   0.0  0.0   0:00.03 googlerewriter.
13430 squid     20   0  8704 2460 1724 S   0.0  0.0   0:00.02 googlerewriter.
13431 squid     20   0  8704 2460 1724 S   0.0  0.0   0:00.02 googlerewriter.
13426 squid     20   0  8704 2376 1716 S   0.0  0.0   0:00.04 googlerewriter.
13427 squid     20   0  8704 2372 1716 S   0.0  0.0   0:00.03 googlerewriter.

Saturday, April 6, 2013

Faster browsing aka Google Redirect Rewrite

Image courtesy of Open Clip Art Library
Once again I got annoyed by having to wait for Google to redirect me. I also think it's none of Google's business to know which sites I do visit especially if they can't be quick about it. So I decided to get rid of the delay.
I checked if there's a plugin for that and it seems there is. You can install Remove Google Redirects from Chrome Web Store. Being a paranoid weirdo like I am that still wasn't enough. I already had a Squid proxy that I had configured to make it so that you couldn't even know that some websites were blocked by my ISP(Sonera). It made sense to try and figure out if there was a trick that I could do with squid that allows me to get rid of the middle man(Google) in the redirect process.

And behold for the creators of Squid have indeed been so wise as to add a way to mangle the urls. All I had to do was to write a script that takes the url, checks if it's a google redirect url and if so, parses the url to get the actual url where we want to go and return that. The example on Squid feature page was a good place to start and this is what I came up with:

Perl Version


#!/usr/bin/perl

use URI;
use URI::QueryParam;

$|=1;
while (<>) {
    chomp;
    @X = split;
    $url = $X[1];
    #check if this is a google redirect url
    if ($url =~ /\/\/.*\.google\.[^\/]+\/url/) {
        my $uri = URI->new($url);
        $url = $uri->query_param("url");
        print $X[0]." 302:$url\n";
    } else {
        print $X[0]." \n";
    }
}
I had to install a couple of Perl modules while I was trying to refamiliarize myself with Perl so I wanted make a PHP version of the same helper. With PHP I wouldn't have to install any extra modules when some day I decide to use this on some other machine. I usually have PHP installed everywhere.

PHP Version


#!/usr/bin/php
<?php

function convertUrlQuery($query) {
    $queryParts = explode('&', $query);

    $params = array();
    foreach ($queryParts as $param) {
        $item = explode('=', $param);
        $params[$item[0]] = $item[1];
    }

    return $params;
}
while(1){
    $line = trim(fgets(STDIN)); // reads one line from STDIN
    $params = explode(" ", $line);
    $pattern = '/\/\/.*\.google\.[^\/]+\/url/';

    if (preg_match($pattern, $params[1], $matches, PREG_OFFSET_CAPTURE, 3)) {
        $parts = parse_url($params[1]);
        $query = convertUrlQuery($parts['query']);
        $url = urldecode($query['url']);
        echo $params[0]." 302:$url\n";
    } else {
        echo $params[0]." \n";
    }
}


In the end I like that with Perl I didn't have to write any functions for simple things like url parsing, but unless I package this as an installable package I could not just drop it in and expect it to work since I had to install the extra stuff as modules.(Yes I could have written my own implementation, but I'm not that much into reinventing the wheel. Also I was a bit impatient to get the script ready so I could see the results) With the PHP version I could just drop it in and as long as I had PHP installed it would work.

I strongly recommend adding a line in squid.conf It really makes a difference.

url_rewrite_program /path/to/googleredirectrewriter

Tuesday, April 2, 2013

Setting up Prestashop file permissions on Fedora

Sometimes I need to write important things somewhere I can find them. That's the case again with setting up Prestashop file permissions on a SElinux enabled system such as Fedora.


cd prestashop
chown -R apache:sebastian
# allow user and group search directories and set the new files inherit the group of parent folder 
find . -type d -exec chmod ug+xs {} \;
# don't allow others to do anything and allow my group to read and write all, don't allow apache to write anything
chmod -R u-w,o-rwxs,g+rw .
# set permissions of newly created files so that others cannot do anything them
umask o-rwx
# set selinux context so that apache can access everything
chcon -t httpd_sys_content_t -R .
# set selinux context and permissions so that apache can write into places it needs to be able to write
chcon -t httpd_sys_rw_content_t -R config cache log img mails modules translations upload download sitemap.xml
chmod -R u+rw config cache log img mails modules translations upload download sitemap.xml

Wednesday, March 27, 2013

This page was not left blank after all

Like a break after a paragraph, a blank page is something you would expect after a chapter, after the table of contents and before appendices. Blank pages make it easier to read the content for which it acts as a separator.

For some reason a practice of adding disclaimers to the blank pages has been gaining popularity. Some are even promoting it. What is the reason for this? Are people getting too stupid to figure out on their own that a blank page is there just to separate content? It is possible that I'm just suffering from Baader-Meinhof Phenomenon again, but I'm sure that books used to contain a lot of blank pages without needing disclaimers on them.

I like to immerse myself when I'm reading and just consume the words as quickly as I am able to. Sometimes I find myself reading a line that has no relevance to the work I'm reading. There are a few variations, but it usually reads something like:


This page intentionally left blank


It's a lie. Actually it's not even a sentence(lack of a verb). The page ceases to be blank after it is written on. I'ts distracting. I's like a speaker keeping on talking without interruption instead of taking a pause to emphasize some point or to give some time for thinking. It's kind of like replacing every possible pause with verbal fillers. It's unnecessary and confusing. 

Okay, there might be situations where the author has not made it clear that the previous segment has ended, but then it's the matter of the author not doing a good enough job or you're reading something like poetry. A disclaimer at this point won't help you very much in any case. Sometimes it's distracting enough for someone to stop reading and instead write a blog article about it. So do everyone a favor and don't put empty page disclaimers, maybe then someone else is spared from an article like this.

What's wrong with a simple page number?

Wednesday, June 13, 2012

An open letter - Re: Welcome to the Aalto Talk with Linus Torvalds!

Hi.

Since this is a topic I have thought about writing on my blog and discuss with people, this shall be an open letter with a copy on my blog, Semantics(http://semantiikkaa.blogspot.fi/).

I feel that traditional valedictions(http://en.wikipedia.org/wiki/Valediction) are boring, don't accurately represent my attitude and don't deliver what I want to say. To be honest, they are quite archaic and mostly submissive to the point that it's ridiculous and when taken literally even false. Even an insincere person can type the word "sincerely". Honesty is important to me as is accurate self expression, thus "May the Force be with you" is a farewell that is most suited for me, not only because I'm a huge science fiction fan. I will never be anyone's humble servant, but I do wish a methaphorical Force be present in everyone's life. That something which drives us (to do better).

http://en.wikipedia.org/wiki/May_the_Force_be_with_you


ps. Sometimes I end my letters with:

Live long and prosper,
Sebastian Mäki

12.06.2012 21:53, Zaira Mammadova kirjoitti:
Hi Sebastian, 

Thank you! 

Out of curiosity, what does "may the Force be with you"? :)

-Zaira

Wednesday, June 6, 2012

Osuuspankki hack

Last night I tried accessing the website of my bank in order to check my balance. I was in for a surprise. The front page https://www.op.fi was redirected by javascript to https://www.op.fi/op and then back again in an endless loop. As I have some experience in these matters, it seemed to me like a prank some malicious hacker might have done, on their way out of the system. I was starting to seriously suspect my bank's online systems had been compromised.

I started searching for any news regarding this in the morning with no success. I was amazed by the lack of any news or people complaining online. Only after I saw this article, I thought I might have possibly found the reason for last night's suspicious script-behaviour:



“ 31.5.2012
OP-verkkopalvelun käyttöä tuetaan tietyillä selainohjelmilla ja niiden versioilla. Tuettuihin selaimiin tulee muutoksia 6.6.2012.
6.6. 2012 alkaen OP-verkkopalveluiden käyttöä tuetaan seuraavilla selaimilla:
Internet Explorer 7, 8 ja 9
Firefox 11 ja 12
Opera 11
Safari 5
Google Chrome
Suosittelemme tietoturvan ja sivujen yleisen toimivuuden vuoksi uusimpien selainversioiden käyttöä. Selainohjelmiston päivittäminen on tärkeää OP-verkkopalveluiden turvallisen käytön kannalta.
  • OP-verkkopalvelun käytön tekniset edellytykset (PDF 28 kB) (PDF 13 kB)
  • Lue lisää selaimista ja niiden päivittämisestä
”
Basically what they are saying is that from this date froward the bank's online service will be supported by these browsers. Even here was no mention of the blunder and/or compromised system that took place last night.

What to learn: Land users on a page that informs what's happening. Don't leave your system in a state that screams blackhats are doing pranks here. It's even more embarrassing if the very people who are responsible for the system leave it in a state that an attacker would. At least some hacks happened last night and I'm sure it's not good even if in this case hack meant an untalented professional.

What to learn, for the users: Expect that your bank has hired your neighbour's son to do your banking systems.

Tuesday, March 6, 2012

The future, cancelled?

So the thing is, I really want the human kind to get to the point where it can inhabit other planets. This place is getting crowded and it seems that it's either space or world war 3, 4, 5 etc from here on. In case someone didn't know, today we are blasting humans off the map with the excuse being that that other guy was possibly a terrorist. Collateral damage? So what? Less people to share these limited resources with. Good riddance. Governments lie and murder. Instead of healthcare we now just treat illnesses. Wars are waged because it's good business in the short term for the conqueror. Policies are made mostly to serve the financial system rather than people. It's not going to be long now when hospitals all over the world will treat only the rich. Rejuvenating technologies that can to prolong the lifespan of a human will be banned when they are effective enough and known by the public. Execution in the style of Logan's Run will be a norm. All who lived too long would be a threat to humankind.

I might not be an optimist, but I am a dreamer. Technology has often presented solutions to difficult situations,  people in difficult situations have been extra motivated to come up with solutions. It would be wonderful if we all learned how to behave before heading to the stars, but in case we don't, maybe we can learn when we head to the stars. Making sure that prolonging the lifespan would not be criminalized would allow us to grow wiser and more patient btw. I saw a news article about spider silk that I think could make bigger and more durable solar sails possible. I wonder if it's sails or some other method of propulsion that will first take us exploring the final frontier.

Tip me if you like what you're reading