Posts

gettimeofday() should never be used to measure time

gettimeofday() and time() should only be used to get the current time if the current wall-clock time is actually what you want. They should never be used to measure time or schedule an event X time into the future. What's the problem? gettimeofday() returns the current wall clock time and timezone. time() returns a subset of this info (only whole seconds, and not timezone). Using these functions in order to measure the passage of time (how long an operation took) therefore seems like a no-brainer. After all, in real life you measure by checking your watch before and after the operation. The differences are: 1. Nobody sneaks in and changes your wristwatch when you're not looking You usually aren't running NTP on your wristwatch, so it probably won't jump a second or two (or 15 minutes) in a random direction because it happened to sync up against a proper clock at that point. Good NTP implementations try to not make...

tlssh - a replacement for SSH

I've started writing a replacement for SSH. Why? Because SSH has some drawbacks that sometimes annoy me. I also wanted an authentication scheme that's more similar to SSL/TLS than what SSH does. With tlssh you don't specify username or password, you simply connect to the server using a client-side certificate to log in as the user specified in the certificate. No interaction until you reach the shell prompt on the server. Of course you can log in using a public key with SSH, but it's only a public/private key pair, there's none of the PKI that SSL has. Specifically, what I was missing in SSH was: Expiring keys, both login-keys and server certificates CRL s (Certificate Revocation Lists) - wouldn't it be nice to just revoke the all certificates that were on a compromised machine and they'll suddenly be unusable everywhere? (I will add OCSP too. Same thing but more "online") Pureness. Not all th...

The rules of multicast

Image
The first rule of multicast is you don't talk about multicast Most networks don't do multicast routing, which means most network guys don't have much experience with it. Sure they know that it exists, and it's probably used on their layer 2, but they don't do multicast routing. These "rules" list some things that you should know when configuring or troubleshooting multicast. The second rules of multicast is you do not forward packets coming from a non-RPF interface If a multicast packet is received, and it's not the multicast RPF interface, it's dropped. The table can be viewed with "show ip mroute", and it will clearly show what interface is acceptable. Here's an example of group 239.0.0.1: R1#show ip mroute 239.0.0.1 [...] (*, 239.0.0.1), 00:00:08/stopped, RP 1.0.0.1, flags: S Incoming interface: Null, RPF nbr 0.0.0.0 Outgoing interface list: FastEthernet1/0, Forward/S...

It's duplex mismatch

Image
Print it out and put it next to your monitor. It will help you troubleshoot network problems.

Redirecting to the closest site using Javascript

I'm sure this problem has been solved this way many times before, but I haven't seen it while idly browsing around sites about scalability and load balancing. So here it is, a Javascript solution to the closest-site problem . For static content optimizing for latency is easy and cheap. Just put your files in a CDN such as Amazon CloudFront and you're done. Low (lower) latency all over the world. Done. For dynamic content it's a bit harder. You can set up several data centers (sites) and try to redirect the user to their closest site. But how do you find out what site is the closest one, and how do you redirect the user to the right one? There are several solutions to this, such as using anycast BGP or source-aware DNS. But they have big drawbacks. DNS based solutions depend on the users resolver to be close to the user and that the ip2location database is correct. BGP-based solutions depend on you having access to BGP (and the staf...

10 years of maintaining an open source program

Arping 0.1 was released 10 years ago last month or so. It's since been included as a package in Debian GNU/Linux, Ubuntu, OpenBSD, FreeBSD and NetBSD, Gentoo and some other smaller and bigger OSs and distributions. It's interesting that not one of these asked or even let me know, which is kind of fun. I only noticed because I ego-googled. A couple of German magazines did ask before putting it on their CDs. I told them that it's GPL so they can do what they want, but thanked them for letting me know. Linux Journal could have told me though. Arping was rewritten for libnet 1.1 as Arping 2.x. I fixed the IRIX port of libnet 1.1 just so that I could get Arping to work on it. I get bug reports or feature requests every now and then. Most build errors are due to someone not having libnet and/or libpcap installed. The new version (2.09) checks for these dependencies and present a friendly error message in case they're missi...

Clipboard sniffer

Yes clipboard, not keyboard. I've made a clipboard sniffer for X called ClipSniff. It periodically saves whatever is in the clipboard (both the "PRIMARY" and the "CLIPBOARD") into a sqlite database. git clone http://github.com/ThomasHabets/clipsniff.git It wasn't that hard when you knew where to look. You just: Connect to the X server. XOpenDisplay() Create a window (you don't need to display it). XCreateSimpleWindow() Ask the X server who owns the PRIMARY and CLIPBOARD atoms, and ask that window to send you the data. XInternAtom() , XConvertSelection() Wait for the reply event. Loop of NextEvent() Helpful links when coding Xlib Minimal XGetWindowProperty Example Xlib Programming Manual (O'Reilly & Associates, Inc.) X Selections, Cut Buffers, and Kill Rings (jwz) X Windows Copy-Paste mini HOWTO (Stelios Xathakis)