[squid-users] FATAL: Received Segment Violation...dying.

2010-05-25 Thread sameer khan


Hey

squid is just dying with fatal error:

FATAL: Received Segment Violation...dying.
2010/05/25 17:52:52| storeDirWriteCleanLogs: Starting...
2010/05/25 17:52:52| WARNING: Closing open FD   29
2010/05/25 17:52:52| commSetEvents: epoll_ctl(EPOLL_CTL_DEL): failed on fd=29: 
(1) Operation not permitted
2010/05/25 17:52:52| WARNING: Closing open FD   30
2010/05/25 17:52:52| commSetEvents: epoll_ctl(EPOLL_CTL_DEL): failed on fd=30: 
(1) Operation not permitted
2010/05/25 17:52:53| 65536 entries written so far.
2010/05/25 17:52:53|    131072 entries written so far.
2010/05/25 17:52:53|    196608 entries written so far.
2010/05/25 17:52:53|    262144 entries written so far.
2010/05/25 17:52:53|    327680 entries written so far.
2010/05/25 17:52:53|    393216 entries written so far.
2010/05/25 17:52:53|    458752 entries written so far.
2010/05/25 17:52:53|    524288 entries written so far.
2010/05/25 17:52:53|    589824 entries written so far.
2010/05/25 17:52:53|    655360 entries written so far.
2010/05/25 17:52:54|    720896 entries written so far.
2010/05/25 17:52:54|    786432 entries written so far.
2010/05/25 17:52:54|    851968 entries written so far.
2010/05/25 17:52:54|    917504 entries written so far.
2010/05/25 17:52:54|    983040 entries written so far.
2010/05/25 17:52:54|   1048576 entries written so far.
2010/05/25 17:52:54|   1114112 entries written so far.
2010/05/25 17:52:54|   1179648 entries written so far.
2010/05/25 17:52:54|   1245184 entries written so far.
2010/05/25 17:52:54|   1310720 entries written so far.
2010/05/25 17:52:55|   1376256 entries written so far.
2010/05/25 17:52:55|   1441792 entries written so far.
2010/05/25 17:52:55|   1507328 entries written so far.
2010/05/25 17:52:55|   1572864 entries written so far.
2010/05/25 17:52:55|   1638400 entries written so far.
2010/05/25 17:52:55|   1703936 entries written so far.
2010/05/25 17:52:55|   1769472 entries written so far.
2010/05/25 17:52:55|   1835008 entries written so far.
2010/05/25 17:52:55|   1900544 entries written so far.
2010/05/25 17:52:55|   1966080 entries written so far.
2010/05/25 17:52:55|   2031616 entries written so far.
2010/05/25 17:52:56|   2097152 entries written so far.
2010/05/25 17:52:56|   2162688 entries written so far.
2010/05/25 17:52:56|   2228224 entries written so far.
2010/05/25 17:52:56|   2293760 entries written so far.
2010/05/25 17:53:03|   Finished.  Wrote 2338090 entries.
2010/05/25 17:53:03|   Took 10.2 seconds (228705.3 entries/sec).
CPU Usage: 12716.239 seconds = 6215.796 user + 6500.442 sys
Maximum Resident Size: 0 KB
Page faults with physical i/o: 17950
Memory usage for squid via mallinfo():
    total space in arena:  580484 KB
    Ordinary blocks:   579739 KB    287 blks
    Small blocks:   0 KB  4 blks
    Holding blocks: 57608 KB  3 blks
    Free Small blocks:  0 KB
    Free Ordinary blocks: 745 KB
    Total in use:  637347 KB 100%
    Total free:   745 KB 0%
2010/05/25 17:53:07| Starting Squid Cache version 2.7.STABLE6 for 
x86_64-unknown-linux-gnu...
2010/05/25 17:53:07| Process ID 4412
2010/05/25 17:53:07| With 65535 file descriptors available
2010/05/25 17:53:07| Using epoll for the IO loop
2010/05/25 17:53:07| Performing DNS Tests...
2010/05/25 17:53:07| Successful DNS name lookup tests...
2010/05/25 17:53:07| DNS Socket created at 0.0.0.0, port 26621, FD 6
2010/05/25 17:53:07| Adding nameserver 127.0.0.1 from /etc/resolv.conf
2010/05/25 17:53:07| helperOpenServers: Starting 10 'storeurl.pl' processes
2010/05/25 17:53:07| Unlinkd pipe opened on FD 20
2010/05/25 17:53:07| Swap maxSize 565248000 + 3145728 KB, estimated 43722594 
objects
2010/05/25 17:53:07| Target number of buckets: 2186129
2010/05/25 17:53:07| Using 4194304 Store buckets
2010/05/25 17:53:07| Max Mem  size: 3145728 KB
2010/05/25 17:53:07| Max Swap size: 565248000 KB
2010/05/25 17:53:07| Local cache digest enabled; rebuild/rewrite every 
3600/3600 sec
2010/05/25 17:53:07| Store logging disabled
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda1 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda2 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda3 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda4 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb1 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb2 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb3 
(CLEAN)
2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb4 
(CLEAN)
2010/05/25 17:53:07| Using Least Load store dir selection
2010/05/25 17:53:07| Set Current Directory to /usr/local/squid/var/cache
2010/05/25 17:53:07| Loaded Icons.
2010/05/25 17:53:07| Accepting transparently proxied HTTP connections at 
0.0.0.0, port 

Re: [squid-users] Squid3 on ubuntu 10.4 problem using acl whitelist in external file

2010-05-25 Thread MM Gillon
Hi Amos, I have added your improvements to my squid.conf. Below is my revised 
squid.conf  Thanks. Margaret G.


#Recommended minimum configuration:
acl manager proto cache_object
acl localhost src 127.0.0.1/32
acl to_localhost dst 127.0.0.0/8
acl localnet src 192.168.100.0/24 192.168.101.0/24
acl SSL_ports port 443
acl Safe_ports port 80  # http
acl Safe_ports port 21  # ftp
acl Safe_ports port 443 # https
acl Safe_ports port 70  # gopher
acl Safe_ports port 210 # wais
acl Safe_ports port 1025-65535  # unregistered ports
acl Safe_ports port 280 # http-mgmt
acl Safe_ports port 488 # gss-http
acl Safe_ports port 591 # filemaker
acl Safe_ports port 777 # multiling http

acl CONNECT method CONNECT

http_access allow manager localhost
http_access deny manager
http_access deny !Safe_ports

http_access deny to_localhost
icp_access deny all
htcp_access deny all

http_port 3128
hierarchy_stoplist cgi-bin ?
access_log /var/log/squid3/access.log squid


#Suggested default:
refresh_pattern ^ftp:   144020% 10080
refresh_pattern ^gopher:14400%  1440
refresh_pattern -i (/cgi-bin/|\?) 0 0% 0
refresh_pattern .   0   20% 4320
# Leave coredumps in the first cache dir
coredump_dir /var/spool/squid3

acl whitelist dstdomain /etc/squid3/whitelist.txt

# Allow localnet machines to whitelisted sites
http_access allow localnet whitelist

# block all other access
http_access deny all


Re: [squid-users] FATAL: Received Segment Violation...dying.

2010-05-25 Thread George Herbert
You will have to set up the system to collect a core dump, you need
that to tell where in the code it seg faulted.


On Tue, May 25, 2010 at 5:56 AM, sameer khan khanza...@hotmail.com wrote:


 Hey

 squid is just dying with fatal error:

 FATAL: Received Segment Violation...dying.
 2010/05/25 17:52:52| storeDirWriteCleanLogs: Starting...
 2010/05/25 17:52:52| WARNING: Closing open FD   29
 2010/05/25 17:52:52| commSetEvents: epoll_ctl(EPOLL_CTL_DEL): failed on 
 fd=29: (1) Operation not permitted
 2010/05/25 17:52:52| WARNING: Closing open FD   30
 2010/05/25 17:52:52| commSetEvents: epoll_ctl(EPOLL_CTL_DEL): failed on 
 fd=30: (1) Operation not permitted
 2010/05/25 17:52:53| 65536 entries written so far.
 2010/05/25 17:52:53|    131072 entries written so far.
 2010/05/25 17:52:53|    196608 entries written so far.
 2010/05/25 17:52:53|    262144 entries written so far.
 2010/05/25 17:52:53|    327680 entries written so far.
 2010/05/25 17:52:53|    393216 entries written so far.
 2010/05/25 17:52:53|    458752 entries written so far.
 2010/05/25 17:52:53|    524288 entries written so far.
 2010/05/25 17:52:53|    589824 entries written so far.
 2010/05/25 17:52:53|    655360 entries written so far.
 2010/05/25 17:52:54|    720896 entries written so far.
 2010/05/25 17:52:54|    786432 entries written so far.
 2010/05/25 17:52:54|    851968 entries written so far.
 2010/05/25 17:52:54|    917504 entries written so far.
 2010/05/25 17:52:54|    983040 entries written so far.
 2010/05/25 17:52:54|   1048576 entries written so far.
 2010/05/25 17:52:54|   1114112 entries written so far.
 2010/05/25 17:52:54|   1179648 entries written so far.
 2010/05/25 17:52:54|   1245184 entries written so far.
 2010/05/25 17:52:54|   1310720 entries written so far.
 2010/05/25 17:52:55|   1376256 entries written so far.
 2010/05/25 17:52:55|   1441792 entries written so far.
 2010/05/25 17:52:55|   1507328 entries written so far.
 2010/05/25 17:52:55|   1572864 entries written so far.
 2010/05/25 17:52:55|   1638400 entries written so far.
 2010/05/25 17:52:55|   1703936 entries written so far.
 2010/05/25 17:52:55|   1769472 entries written so far.
 2010/05/25 17:52:55|   1835008 entries written so far.
 2010/05/25 17:52:55|   1900544 entries written so far.
 2010/05/25 17:52:55|   1966080 entries written so far.
 2010/05/25 17:52:55|   2031616 entries written so far.
 2010/05/25 17:52:56|   2097152 entries written so far.
 2010/05/25 17:52:56|   2162688 entries written so far.
 2010/05/25 17:52:56|   2228224 entries written so far.
 2010/05/25 17:52:56|   2293760 entries written so far.
 2010/05/25 17:53:03|   Finished.  Wrote 2338090 entries.
 2010/05/25 17:53:03|   Took 10.2 seconds (228705.3 entries/sec).
 CPU Usage: 12716.239 seconds = 6215.796 user + 6500.442 sys
 Maximum Resident Size: 0 KB
 Page faults with physical i/o: 17950
 Memory usage for squid via mallinfo():
     total space in arena:  580484 KB
     Ordinary blocks:   579739 KB    287 blks
     Small blocks:   0 KB  4 blks
     Holding blocks: 57608 KB  3 blks
     Free Small blocks:  0 KB
     Free Ordinary blocks: 745 KB
     Total in use:  637347 KB 100%
     Total free:   745 KB 0%
 2010/05/25 17:53:07| Starting Squid Cache version 2.7.STABLE6 for 
 x86_64-unknown-linux-gnu...
 2010/05/25 17:53:07| Process ID 4412
 2010/05/25 17:53:07| With 65535 file descriptors available
 2010/05/25 17:53:07| Using epoll for the IO loop
 2010/05/25 17:53:07| Performing DNS Tests...
 2010/05/25 17:53:07| Successful DNS name lookup tests...
 2010/05/25 17:53:07| DNS Socket created at 0.0.0.0, port 26621, FD 6
 2010/05/25 17:53:07| Adding nameserver 127.0.0.1 from /etc/resolv.conf
 2010/05/25 17:53:07| helperOpenServers: Starting 10 'storeurl.pl' processes
 2010/05/25 17:53:07| Unlinkd pipe opened on FD 20
 2010/05/25 17:53:07| Swap maxSize 565248000 + 3145728 KB, estimated 43722594 
 objects
 2010/05/25 17:53:07| Target number of buckets: 2186129
 2010/05/25 17:53:07| Using 4194304 Store buckets
 2010/05/25 17:53:07| Max Mem  size: 3145728 KB
 2010/05/25 17:53:07| Max Swap size: 565248000 KB
 2010/05/25 17:53:07| Local cache digest enabled; rebuild/rewrite every 
 3600/3600 sec
 2010/05/25 17:53:07| Store logging disabled
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda1 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda2 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda3 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sda4 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb1 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb2 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in /usr/local/squid/var/cache/sdb3 
 (CLEAN)
 2010/05/25 17:53:07| Rebuilding storage in 

[squid-users] Unexpected restart of Squid

2010-05-25 Thread flm

Hi all,
My squid cache.log indicates a lot of unexpected lines like :
Starting Squid Cache version 2.7.Stable6 for ...

I don't know why my squid process go missing. It happens about 40 to 50 a
day
The line just before Starting Squid are for exemple :
storeLateRelease: released xx objects
or
storeUpdateCopy: Error at xxx
or
ipcacheParse: No address records in response to 'xx'

Could you advice me how can I troubleshoot this issue ?

Regards
-- 
View this message in context: 
http://squid-web-proxy-cache.1019090.n4.nabble.com/Unexpected-restart-of-Squid-tp2230515p2230515.html
Sent from the Squid - Users mailing list archive at Nabble.com.


Re: [squid-users] squid ssl and keystores

2010-05-25 Thread Henrik Nordström
mån 2010-05-24 klockan 12:42 +0200 skrev Edoardo COSTA SANSEVERINO:

 I got squid working flawlessly with a couple of apache ssl websites but 
 now I have to get it working with tomcat/ssl which uses a Java KeyStore 
 file.

Not sure what format that is, but you need to export the data somehow..

A little google says that there is a keytool command you can use for
exporting certificates from a java keystore.

  keytool -export -rfc -alias jane -file janecertfile.pem

But I am not entirely sure this exports the private key. Searching a
little more and it seems that it does not. But found a good resource
including tools to help you:

http://conshell.net/wiki/index.php/Keytool_to_OpenSSL_Conversion_tips


Regards
Henrik



Re: [squid-users] Unexpected restart of Squid

2010-05-25 Thread Henrik Nordström
tis 2010-05-25 klockan 11:56 -0700 skrev flm:
 Hi all,
 My squid cache.log indicates a lot of unexpected lines like :
 Starting Squid Cache version 2.7.Stable6 for ...
 
 I don't know why my squid process go missing. It happens about 40 to 50 a
 day
 The line just before Starting Squid are for exemple :
 storeLateRelease: released xx objects
 or
 storeUpdateCopy: Error at xxx
 or
 ipcacheParse: No address records in response to 'xx'
 
 Could you advice me how can I troubleshoot this issue ?

Begin by upgrading to a more current release. Current 2.7 is
2.7.STABLE9.

But usually the cause to squid silently dying with no messages is that
some of it's log files hit the magical 2GB barrier and your Squid is not
compiled with large file support. This assuming you are NOT using the -C
command line option which silences most crashes..

Regards
Henrik




[squid-users] url-rewrite PHP script issue under Ubuntu 10.04

2010-05-25 Thread Horacio H.
Hi !

I was wondering if someone else has noticed a similar behavior:

I wrote an URL-rewrite script with PHP as explained at
http://wiki.squid-cache.org/ConfigExamples/PhpRedirectors. The
script was running without complains under Squid 2.7.Stable9 and
Ubuntu 9.04, then I upgraded Ubuntu to 10.04 and warning messages
started to show up:

2010/05/15 16:48:28| WARNING: url_rewriter #XX (FD XX) exited  
(repeat n-times)
2010/05/15 16:48:28| Too few url_rewriter processes are running
2010/05/15 16:48:28| Starting new helpers

Things I've tried to solve the issue without success:

- Simplified the PHP script to the minimum (finally just using the
wiki's example).
- A clean installation of Ubuntu 10.04.
- Downgraded PHP package from 5.3 to 5.2.
- Recompiled Squid (just in case).

Perl scripts are not afected, so I rewrited/transalted the script. The
service is up again but a big question mark was left over my head.

I know it's not a Squid's issue per se, but at least the wiki may need
to be updated before other people get stuck at this point...

Thanks for reading.

---
squid.conf:
---
url_rewrite_program  /etc/squid/phpredir
url_rewrite_children 32

-
phpredir:
-
#!/usr/bin/php
?php
$temp = array();
while ( $input = fgets(STDIN) ) {
 $temp = split(' ', $input);
 $output = $temp[0] . \n;
 echo $output;
}


Re: [squid-users] url-rewrite PHP script issue under Ubuntu 10.04

2010-05-25 Thread Amos Jeffries
On Tue, 25 May 2010 18:49:16 -0500, Horacio H. pokehor...@gmail.com
wrote:
 Hi !
 
 I was wondering if someone else has noticed a similar behavior:
 
 I wrote an URL-rewrite script with PHP as explained at
 http://wiki.squid-cache.org/ConfigExamples/PhpRedirectors. The
 script was running without complains under Squid 2.7.Stable9 and
 Ubuntu 9.04, then I upgraded Ubuntu to 10.04 and warning messages
 started to show up:
 
 2010/05/15 16:48:28| WARNING: url_rewriter #XX (FD XX) exited  
 (repeat n-times)
 2010/05/15 16:48:28| Too few url_rewriter processes are running
 2010/05/15 16:48:28| Starting new helpers
 
 Things I've tried to solve the issue without success:
 
 - Simplified the PHP script to the minimum (finally just using the
 wiki's example).
 - A clean installation of Ubuntu 10.04.
 - Downgraded PHP package from 5.3 to 5.2.
 - Recompiled Squid (just in case).
 
 Perl scripts are not afected, so I rewrited/transalted the script. The
 service is up again but a big question mark was left over my head.
 
 I know it's not a Squid's issue per se, but at least the wiki may need
 to be updated before other people get stuck at this point...

Hi Horacio,
 Being a great PHP fan myself with a lot of helpers I've been fighting
this problem for a year or so now.

The issue centers around the automatic run timeouts PHP has.

Under several of the 5.0-5.2 releases the background engine has either not
obeyed the php.ini settings correctly or not obeyed run-time overrides
correctly. I pushed through and supported many alterations to Squid-3.2
which help minimize the problem, but...

As far as I can tell so far the new 5.3 engine seems not to obey either
run-time or configured settings and sticks rigidly to a 60sec timeout. 
While technically helpers can be of any language, this recent behaviour
change of PHP 5.3 makes it completely useless as a Squid helper for even
small installations.

I'd advise some other scripting language for now, or if you must the very
latest squid-3.x code (http://www.squid-cache.org/Versions/v3/HEAD/) will
be important to prevent Squid constantly restarting as its helpers
self-destruct. Even then the constantly unavailable helpers make Squid a
bit slow and hang on many requests while they are restarted.

Amos



[squid-users] Squid + Tproxy + Bridge on Kernel 2.6.34 - Workaround

2010-05-25 Thread senthilkumaar2021

Hi,

Squid + Tproxy + Bridge Setup on latest kernel - version 2.6.34

I had followed all the steps that had given in the
http://wiki.squid-cache.org/Features/Tproxy4

Kernel - 2.6.34
iptable - 1.4.8
ebtable - 2.0.9-1

But clients were unable to browse and no errors in cache.log. Error -
Network Unreachable. The error had returned by browser not squid proxy.

Workaround :-

After adding the following rules, clients are able to browse.

# ip rule add dev device name fwmark 1 lookup 100

example

# ip rule add dev eth0 fwmark 1 lookup 100

NOTE : Repeat the above for each interface except  lo 

Source - https://lists.balabit.hu/pipermail/tproxy/2010-January/001212.html

Based on the above source this issue had identified on kernel version -
2.6.32. But still not yet fixed.

I have CC ed this mail to netfilter mailing lists also.

Hope this helps

Thanks,
Senthil





[squid-users] Too many logon when auto redirect script

2010-05-25 Thread Niti Lohwithee
Hi All,

I have a Redhat ES 5.3 with squid verion 3.1.1.  I also use the NCSA
authentication to control the user to access to the internet.
This box has been enabled a simple auto script for redirect namely
cace.pac on apache as the following:


 function FindProxyForURL(url, host) {
 if (dnsDomainIs( host,xx.com))
return DIRECT;
 if (url.substring(0, 5) == http: ||
url.substring(0, 6) == https:||
url.substring(0, 4) == ftp:)
  return PROXY proxy..com; DIRECT;
 }


When the user set directly to proxy.xxx.com at browser, squid asked
for the user/password for only one timm of new session.   However, if
the user set at browser and point to auto redirect script, the brower
aske to many pop up for entering user name and password for new
session.For example, the squid ask to enter the password for
google.com as 2 time, Another website is 3-4 time.

Any help would be appreciated.

Regards and Thanks
Niti : )





-- 
##
Mr niti lowhithee
email mr.n...@gmail.com
##