7 ms·
Linux 3.7 released
- autotravis 14y ago>'"Fast Open" is a optimization to the process of stablishing a TCP connection that allows the elimination of one round time trip from certain kinds of TCP conversations. Fast Open could result in speed improvements of between 4% and 41% in the page load times on popular web sites.' Interesting... anyone know more about this?
- kzrdude 14y agoRecommended LWN article: TCP Fast Open: expediting web services http://lwn.net/Articles/508865/ http://lwn.net/Articles/508865/
- gghh 14y agothank you, interesting link. Does TCP Fast Open have anything to do with the "slow start", which a few major websites are known to violate[1][2] ? just out of curiosity. It doesn't look so, at a first glance. [1] http://en.wikipedia.org/wiki/Slow-start http://en.wikipedia.org/wiki/Slow-start [2] http://blog.benstrong.com/2010/11/google-and-microsoft-cheat-on-slow.html?m=1 http://blog.benstrong.com/2010/11/google-and-microsoft-cheat...
- Contero 14y agoIt sounds like it would allow a client to send data (HTTP request) before the server has acknowledged that the TCP connection is open.
- pm90 14y agoNot really. Slow start is a precaution to avoid the network from getting congested; whereas TCP fast open is essentially trying to reduce the completion time of small TCP requests.
- ck2 14y agohttp://en.wikipedia.org/wiki/TCP_Fast_Open http://en.wikipedia.org/wiki/TCP_Fast_Open I guess CentOS will get this in 2020, sigh, still waiting for initrwnd 10 support.
- Nux 14y agoIf all you need is the kernel, then you can use the one provided by the elrepo.org project.
- stusmall 14y agoAlso building your own isn't too difficult.
- andreaso 14y agoBuilding a kernel of your own is fairly trivial. The potentially less trivial part is keeping it up-to-date with security fixes, etc. Not impossible by any means, but it does require a bit of a commitment in time, build environment, etc.
- sp332 14y agoWouldn't this conflict with TCP cookies, which were (partially) added to the kernel just a little while ago?
- marshray 14y agoNo, it uses a different TCP options header. In fact, many of the security considerations are the same.
- sp332 14y agoOK, interesting. TCP cookies allocate (practically) no resources to a TCP connection until the three-way handshake is complete, whereas Fast Open can start receiving data before the handshake even finishes. But even if you only do Fast Open on hosts that you have previously completed a normal 3-way handshake with, attackers will just do one full handshake at the beginning of the attack and then switch to SYN flooding.
- JoshTriplett 14y agoLWN had a detailed article about it: https://lwn.net/Articles/508865/ https://lwn.net/Articles/508865/
- mixmastamyk 14y agoHow long until this comes to Windows and OSX clients? Until then it doesn't seem that this will get much use. Didn't find anything on a preliminary google search.
- aartur 14y agoOptimization of file deletion in ext4 gives nice results (from a commit message): > X86 before (linux 3.6-rc4): > # time rm -f test1 > real 0m2.710s > user 0m0.000s > sys 0m1.530s > X86 after: > # time rm -f test1 > real 0m0.644s > user 0m0.003s > sys 0m0.060s The commit affects 5 lines only. EDIT. Not sure if this optimization applies to filesystems mounted with standard journaling options...
- unwind 14y agoSounds nice, good find! I dug up the commit: http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git;a=commit;h=18888cf0883c286f238d44ee565530fe82752f06 http://git.kernel.org/?p=linux/kernel/git/torvalds/linux.git... which seems to be a bit older than I would have expected. Of course, this being Linux, "old" means it's from September 19th.
- caf 14y agoThe merge window for 3.7 opened on September 30th, so it's not that old.
- devastor 14y agoWhat journaling options did you use?
- georgemcbay 14y agoPro: Eliminates the sinking feeling I get when an rm with wildcards is "taking too long". Con: All my files are gone before I can frantically ctrl-c to save some of them.
- jug6ernaut 14y agoARM x64, wow. Is this really necessary? Or just a prelude to some new applications? When i think of ARM i think of Mobile Phones, total ram isn't an issue(yet?) Are there other advantages?
- stonemetal 14y agoAMD has announced that they are going to start shipping 64bit ARM systems in the near future(a year or two out). http://www.anandtech.com/show/6418/amd-will-build-64bit-arm-based-opteron-cpus-for-servers-production-in-2014 http://www.anandtech.com/show/6418/amd-will-build-64bit-arm-...
- binarycrusader 14y agoBetter performance, and yes, it won't be long now before mobile devices ship with more than 4GB of memory. Don't forget AMD's announcement about ARM64 based servers.
- mbell 14y agoARM64 isn't required for > 4GB physical memory. The cortex-a15 can already address up to 1TB and is already shipping. Only the per process limit is locked to 4GB on a 32 bit core.
- binarycrusader 14y agoI think you're splitting hairs. In fairness, I didn't explicitly call that out, but as soon as you have more than 4GB of memory, there's going to be an application that wants to use more than 4GB. So yes, 64-bit is necessary in my opinion. Especially when you consider the server market.
- mbell 14y ago> but as soon as you have more than 4GB of memory, there's going to be an application that wants to use more than 4GB Maybe, but my desktop has 32GB of ram, has a 64bit CPU, and I've rarely seen a single process use 4GB of memory unless it was leaking memory. My laptop has 8GB of ram, also 64bit, and I'm pretty sure I've never had a single process use 4GB. The only exception I can think of was doing some silly data manipulation, e.g. doing the initial build of a property graph of the entire Boston area transit system. I bet some high end games or video/photo editing software would use more than 4GB. Point is, those are all pretty niche situations, I'd bet the majority of memory usage on an average person's computer comes from browser processes, few hundred MB each if that and office applications, also a few hundred MB. Those processes add up though, so having more ram is usually a really good thing even if no processes uses even close to 4GB. I also challenge the need in server loads. I'd bet the vast majority of applications never use 4GB either on the app server or the database server. Most of what gets discussed here on HN are large high scalability applications that you wouldn't host on ARM cores anyway. We often forget that the vast majority of website are tiny and low traffic.
- sdafdasdfasdf 14y agofrom "TCP Fast Open: expediting web services": http://lwn.net/Articles/508865/ http://lwn.net/Articles/508865/ > Furthermore, the server should periodically change the encryption key used to generate the TFO cookies, so as to prevent attackers harvesting many cookies over time to use in a coordinated attack against the server. What is going to do this? I hope this is built-in somehow.
- marshray 14y agoIt looks like the key will be accessible via the proc filesystem. But it's anyone's guess how many distros will faithfully schedule a cron job to rotate the key. EDIT: Looks like the key is chosen at kernel module "late init" time. I think this is before any init scripts have had the opportunity to add back any entropy persisted from previous boots. So the entropy in the kernel pool is minimal. It may be plausible for a remote attacker to guess the key for a bunch of servers. Also, if the key is not rotated by cron, it provides a single-packet method for a remote attacker to observe that a server has been rebooted since he last checked. This will give a good indication of how often security patches have been applied. http://git.kernel.org/linus/1046716368979dee857a2b8a91c4a8833f21b9cb http://git.kernel.org/linus/1046716368979dee857a2b8a91c4a883... http://git.kernel.org/linus/168a8f58059a22feb9e9a2dcc1b8053dbbbc12ef http://git.kernel.org/linus/168a8f58059a22feb9e9a2dcc1b8053d... http://git.kernel.org/linus/8336886f786fdacbc19b719c1f7ea91eb70706d4 http://git.kernel.org/linus/8336886f786fdacbc19b719c1f7ea91e...
- aleyan 14y agoMight be better to have the keys rotated after a certain number of TFO cookies are generated rather than on a time-based schedule. This will prevent attackers from trying to make a huge number of requests in a set period of time.
- marshray 14y agoThe TFO cookie is only generated once per client "source IP" and is good until the key is changed on the server. (Scare quotes because at the source IP may be spoofed). For an attacker to learn a cookie that's valid for a given victim "source IP", he only needs to be passive observer somewhere along the route. Even if we believe that's very hard in most cases, if it's possible at all, he has the mother-of-all anonymous reflected DoS amplifiers. http://tools.ietf.org/html/draft-ietf-tcpm-fastopen-02#section-6.2 http://tools.ietf.org/html/draft-ietf-tcpm-fastopen-02#secti... So, yeah, using a key that's rotated after a short amount of time -or- number of uses (whichever comes first) seems like a good idea.
- elux 14y agoKernel newbies is down: http://www.isup.me/http://kernelnewbies.org/Linux_3.7 http://www.isup.me/http://kernelnewbies.org/Linux_3.7 Cached version: http://webcache.googleusercontent.com/search?q=cache:vjkg-vG3p8QJ:kernelnewbies.org/Linux_3.7+&cd=1&hl=en&ct=clnk http://webcache.googleusercontent.com/search?q=cache:vjkg-vG...
- jey 14y agoperf trace will show the events associated with the target, initially syscalls, but other system events like pagefaults, task lifetime events, scheduling events, etc. I'm excited.
- tocomment 14y agoCan you explain this a bit more? It sounds interesting.
- VMG 14y agoThis allows developers to see what their programs are doing in more detail. They can then use that information to optimize their code.
- tocomment 14y agoThere's nothing similar in older linuxes?
- majke 14y agoLinux is suffering from a lack of a good debugging API. There is a decent progress in the kernel debugging and profiling tools, but for userspace no changes were made for a long time. "ptrace" is the main userspace debugging API, used behind tools like "strace" or "gdb", but it's old and clumsy. Quite new "perf" tool, on the other hand, allows user to get various CPU/Kernel stats mostly useful for profiling. Before "perf" you could only try to emulate your program using "valgrind" to get, say cache misses. The command "perf trace", seems to move "perf" more into the "ptrace" domain. This is indeed exciting.
- rgbrgb 14y agoHow long does this stuff usually take to get into a more comercial release? When will we see it in Ubuntu? Android?
- chrisguitarguy 14y agohttp://en.wikipedia.org/wiki/List_of_Ubuntu_releases#Table_of_versions http://en.wikipedia.org/wiki/List_of_Ubuntu_releases#Table_o... Ubuntu 12.04 uses version 3.2, 12.10 is on kernel 3.5.
- vladev 14y agoArch Linux will probably get it in a couple of weeks. Android, on the other hand, will take much longer. It's sad as there are so many goodies in this for ARM, especially the multi-platform support. This will make updating Android version a lot easier (for manufacturers, hackers). Right now the one of the bigger issues is updating the kernels (and the closed drivers, to be honest).
- thevdude 14y ago:( I just upgraded my arch a few days ago to 3.6.9, and now I'll have to do it again.
- pmr_ 14y agoIf upgrading is not for you, ArchLinux is not for you. You should run a full pacman -Syyu at least once a week and clean up .pacsave files at least once a month. Probably even more often if you are on testing.
- Adaptive 14y agoYou can always blacklist a package (such as linux) in /etc/pacman.conf to avoid upgrading it during pacman -Syu, for example. I had to do this during a power regression in the kernel. However this isn't a long term arch strategy. Note also that arch has LTS kernels, should you prefer.
- polarrat 14y agoSorry for being such a noob. But could someone please tell me the difference between "linux" and other linux builds like Ubuntu, RedHat etc?
- qnk 14y agoLinux is just the kernel and all different distributions (Ubuntu et al) are based on it. Think of it as if the Twitter Api was the kernel and all different clients like Twiterrific or Tweebot were the distributions (Ubuntu, Fedora, etc...). Distributions are implementations of the kernel with lots of extra features and improvements.
- rkalla 14y agoIf you've never been in the Linux world, can certainly see how this is confusing. This announcement is for the Linux kernel. The different Linux distributions (Ubuntu, Redhat, etc.) all bundle different versions of the Linux kernel and umpteen number of packages around that to create a cohesive Desktop or Server experience. The kernel is the one core, similar piece between ALL of the distros. It is the desktops, package managers, etc. that differs between the distros.
- Nitramp 14y agoLinux is an operating system kernel, the most basic layer of software managing the system and talking to your hardware. Linux exposes a standardized interface to the so called 'user space', where programs like Chrome or Apache etc run. The Linux kernel is important, but only a small part of a whole operating system - it's the lowest layer, but there are lots of layers on top of it, including all the programs that the average user uses. Ubuntu, Red Hat, and other Linux _distributions_ bundle a Linux kernel, common software packages, and utilities to manage these together. So there are many Linux distributions, but only one Linux kernel.
- LeonidasXIV 14y agoLinux is the kernel and Ubuntu, Red Hat are distributions that ship said kernel, together with a couple thousand other software packages.
- SkyMarshal 14y ago
- darkstalker 14y agoI think this is important: "JFS: TRIM support". This just added another choice of filesystem for SSD drives.
- jcastro 14y agoHas anyone used this or a prerelease with the btrfs fsync improvements? I'm interested to see if dpkg performance is usable now.