From jw137282@sac.sfbay.sun.com Tue Mar  3 23:03:16 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2473GJP028766
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 3 Mar 2009 23:03:16 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2473Alw024662;
	Tue, 3 Mar 2009 23:03:16 -0800 (PST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KFY00G5DZLDVW00@brm-avmta-1.central.sun.com>; Wed,
 04 Mar 2009 00:03:13 -0700 (MST)
Received: from dm-sfbay-01.sfbay.sun.com ([129.145.155.118])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KFY008PAZLD8E40@brm-avmta-1.central.sun.com>; Wed,
 04 Mar 2009 00:03:13 -0700 (MST)
Received: from sac.sfbay.sun.com (sac.SFBay.Sun.COM [129.146.226.132])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n2473CLG008805; Tue, 03 Mar 2009 23:03:12 -0800 (PST)
Received: from sac.sfbay.sun.com (localhost [127.0.0.1])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2473B0p028746; Tue,
 03 Mar 2009 23:03:11 -0800 (PST)
Received: (from jw137282@localhost)
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8/Submit) id n2473BwM028742; Tue,
 03 Mar 2009 23:03:11 -0800 (PST)
Date: Tue, 03 Mar 2009 23:03:11 -0800 (PST)
From: James Walker <jw137282@sac.sfbay.sun.com>
Subject: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
To: PSARC-ext@sun.com
Cc: lily.li@sun.com
Message-id: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 12551

I'm sponsoring this familiarity case for Lily Li. The requested
release binding is minor. The man page has been posted in the
materials directory.

Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
This information is Copyright 2009 Sun Microsystems
1. Introduction
    1.1. Project/Component Working Name:
	 shmux
    1.2. Name of Document Author/Supplier:
	 Author:  Lily Li
    1.3  Date of This Document:
	03 March, 2009
4. Technical Description
Shmux Check List
1.0 Project Information
  1.1 Name of project/component
    shmux

  1.2 Author of document
    Lily.Li@Sun.COM

2.0 Project Summary
  2.1 Project Description
    shmux is program for executing the same command on many hosts in parallel.
    For each target, a child process is spawned by shmux, and a shell on the
    target obtained one of the supported methods: rsh, ssh, or sh. The output
    produced by the children is received by shmux and either (optionally) output
    in turn to the user using an easy to read format, or written to files for
    later processing making it well suited for use in scripts.

    shmux-1.0.2 will be integrated into the SFW consolidation as part of
    this proposal, and will be installed as SUNWshmux. A minor release
    binding is requested.

  2.2 Release binding
      What is is the release binding?
      (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
      [ ] Major
      [*] Minor
      [ ] Patch or Micro
      [ ] Unknown -- ARC review required

  2.3 Type of project
      Is this case a Linux Familiarity project?
      [*] Yes
      [ ] No

  2.4 Originating Community
    2.4.1 Community Name
      shmux [1]
    
    2.4.2 Community Involvement
      Indicate Sun's involvement in the community
      [ ] Maintainer
      [ ] Contributor
      [*] Monitoring
      
      Will the project team work with the upstream community to resolve
      architectural issues of interest to Sun?
      [*] Yes 
      [ ] No - briefly explain
      
      Will we or are we forking from the community?
      [ ] Yes - ARC review required prior to forking
      [*] No
      
3.0 Technical Description
  3.1 Installation & Sharable
    3.1.1S Solaris Installation - section only required for Solaris Software
      (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
      Does this project follow the Install Locations best practice?
      [*] Yes 
      [ ] No - ARC review required
      
      Does this project install into /usr under [sbin|bin|lib|include|man|share]?
      [*] Yes
      [ ] No or N/A
      
      Does this project install into /opt?
      [ ] Yes - explain below
      [*] No or N/A
      
      Does this project install into a different directory structure?
      [ ] Yes - ARC review required
      [*] No or N/A
      
      Do any of the components of this project conflict with anything under /usr?
      (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
      [ ] Yes - explain below
      [*] No
      
      If conflicts exist then will this project install under /usr/gnu?
      [ ] Yes
      [ ] No - ARC review required
      [*] N/A
      
      Is this project installing into /usr/sfw?
      [ ] Yes - ARC review required
      [*] No
      
    3.1.1W Windows Installation - section only required for Windows Software
      (see http://sac.sfbay/WSARC/2002/494 for details)
      Does this project install software into a 
      <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
      directory?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use the Windows registry?
      [ ] Yes
      [ ] No - ARC review required
      
      Does the project use 
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
      for the registry key?
      [ ] Yes
      [ ] No - ARC review required
      
      Is the project's stored location
      HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
      [ ] Yes
      [ ] No - ARC review required
      
    3.1.2 Share and Sharable
      Does the module include any components that are used or shared by 
      other projects?
      [ ] Yes
      [*] No
    
      If yes are these components packaged to be shared with the other FOSS?
      [ ] Yes
      [ ] No - ARC review required
      [*] N/A
    
      Are these components already in the Solaris WOS?
      [ ] Yes
      [*] No - continue with next section (section 3.2)
    
      If yes are these newer versions being delivered?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the newer versions replacing the existing versions?
      [ ] Yes
      [ ] No - ARC review required

  3.2 Exported Libraries
      Are libraries being delivered by this project?
      [ ] Yes
      [*] No - continue with next section (section 3.3)
      
      Are 64-bit versions of the libraries being delivered?
      [ ] Yes
      [ ] No - ARC review required
    
      Are static versions of the libraries being delivered?
      [ ] Yes - ARC review required
      [ ] No 
      
  3.3 Services and the /etc Directory
      (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
      Does the project integrate anything into /etc/init.d or /etc/rc?.d?
      [ ] Yes - ARC review required
      [*] No
      
      Does the project integrate any new entries into /etc/inittab or
      /etc/inetd.conf?
      [ ] Yes - ARC review required
      [*] No
      
      Does the project integrate any private non-public files into /etc/default
      or /etc/ configuration files?
      [ ] Yes - ARC review required
      [*] No
      
      Does the service manifests method context grant rights above that
      of the noaccess user and basic privilege set?
      [ ] Yes - ARC review required
      [*] No
        
  3.4 Security
    3.4.1 Secure By Default 
      (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
      (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
      (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
       addtional details)
      Are there any network services provided by this project?
      [ ] Yes
      [*] No - continue with the next section (section 3.4.2)
      
      Are network services enabled by default?
      [ ] Yes - ARC review required
      [ ] No
      [ ] N/A
      
      Are network services automatically enabled by the project during installation?
      [ ] Yes - ARC review required
      [ ] No
      [ ] N/A
      
      Are inbound network communications denied by default?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is inbound data checked to prevent content-based attacks?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is the outbound receiver authenticated?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
      Is the receiver authenticated prior to receiving any sensitive outbound communication?
      [ ] Yes
      [ ] No - ARC review required
      [ ] N/A
      
    3.4.2 Authorization
      (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
           for details)
      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [*] No - continue with next section (section 3.4.3)
      
      If yes then are the setuid/setgid privileges handled by the use of roles?
      [ ] Yes
      [ ] No - ARC review required

    3.4.3 Auditing
      (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Does this component contain administrative or security enforcing software?
      [ ] Yes - ARC review required
      [*] No - continue to next section (section 3.4.4)
      
      (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
      Do the components create audit logs detailing what took place including what event
      took place, who was involved, when the event took place?
      [ ] Yes - ARC contract and Audit project team review required
      [ ] No - ARC review required
        
        
    3.4.4 Authentication
      (see http://opensolaris.org/os/community/arc/policies/PAM/)
      Do the components contain any authentication code?
      [ ] Yes
      [*] No - continue to next section (section 3.4.5)
      
      If yes do the components use PAM (plugable authentication modules) for authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes is a single PAM session maintained during authentication?
      [ ] Yes
      [ ] No - ARC review required
      
      If yes are the components sufficiently privileged to allow the requested 
      operations (authentication, password change, process credential manipulation, 
      audit state initialization)?
      [ ] Yes - briefly describe below
      [ ] No - ARC review required
      
    3.4.5 Passwords
      (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
           http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
      Do any of the components for the project deal with passwords?
      [ ] Yes
      [*] No - continue to next section (section 3.4.6)
      
      If yes are these passwords entered via the CLI or environment?
      [ ] Yes - ARC review required
      [ ] No
      
      Are passwords stored within the file system for the component?
      [ ] Yes
      [ ] No - continue to next section (section 3.4.6)
      
      If yes are the permissions on the file such to protect exposing the password(s)?
      [ ] Yes
      [ ] No - ARC review required
      
    3.4.6 General Security Questions
      (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
      Are there any network protocols used by this project?
      [*] Yes
      [ ] No - continue with the next section (section 3.5)
      
      Do the components use standard network protocols?
      [*] Yes
      [ ] No - ARC review required
      
      Do network services for the project make decisions based upon user, host or 
      service identities?
      [ ] Yes - explain below
      [*] No
      [ ] N/A
      
      Do the components make use of secret information during authentication and/or
      authorization?
      [ ] Yes - explain below
      [*] No
      [ ] N/A
  
  3.5 Networking
      Do the components access the network?
      [*] Yes
      [ ] No - continue with the next section (section 3.6)
      
      If yes do the components support IPv6?
      [*] Yes 
      [ ] No - ARC review required
          
  3.6 Core Solaris Components
      Do the components of this project compete with or duplicate core 
      Solaris components?
      [ ] Yes - ARC review required
      [*] No 
      
      Examples of Core Solaris Components include but are not limited to:
      
        Secure By Default
        Authorizations
        PAM -- Plugable Authentication Module
        Privilege
        PRM -- Process Rights Management -- Privilege
        Audit
        xVm -- Virtualization
        zones / Solaris Containers
        PRM -- Process Rights Management
        RBAC -- Role Based Access Control
        TX / Trusted Extensions
        ZFS
        SMF -- Service Management Facility
        FMA -- Fault Management Architecture
        SCF -- Smart Card Facility
        IPsec
        
4.0 Interfaces
  4.1 Exported Interfaces
  
    Interface Name	Classification		Comments
    ----------------	------------------- 	---------------------------
    SUNWshmux		Uncommitted	    	Package
    /usr/bin/shmux	Uncommitted	    	Executable binary file
    
  4.2 Imported Interfaces

    Interface Name	Classification       	Comments
    ---------------	-------------------- 	--------------------------
    OpenSSH		Committed		PSARC/2001/212 (runtime only)
    SUNWpcre		Committed		Perl Regx
    
Appendix A - References
  [1] http://web.taranis.org/shmux/

  OSR ID# 11157
  RFE ID#

6. Resources and Schedule
    6.4. Steering Committee requested information
   	6.4.1. Consolidation C-team Name:
		SFW
    6.5. ARC review type: FastTrack
    6.6. ARC Exposure: open


From gdamore@sun.com Tue Mar  3 23:14:00 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n247DxGI029464
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 3 Mar 2009 23:13:59 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n247DbLv005905
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 4 Mar 2009 15:13:58 +0800 (SGT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KFZ00109036IA00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 03 Mar 2009 23:13:54 -0800 (PST)
Received: from sca-es-mail-1.sun.com ([192.18.43.132])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KFZ007SE0355960@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 03 Mar 2009 23:13:53 -0800 (PST)
Received: from fe-sfbay-10.sun.com ([192.18.43.129])
	by sca-es-mail-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n247Dr3O011591	for
 <PSARC-ext@sun.com>; Tue, 03 Mar 2009 23:13:53 -0800 (PST)
Received: from conversion-daemon.fe-sfbay-10.sun.com by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KFZ00700026PF00@fe-sfbay-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 03 Mar 2009 23:13:53 -0800 (PST)
Received: from [192.168.251.11] ([unknown] [76.93.15.33])
 by fe-sfbay-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KFZ008UR034DAE0@fe-sfbay-10.sun.com>; Tue,
 03 Mar 2009 23:13:52 -0800 (PST)
Date: Tue, 03 Mar 2009 23:13:52 -0800
From: "Garrett D'Amore" <gdamore@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
Sender: Garrett.Damore@sun.com
To: James Walker <jw137282@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Lily.Li@sun.com
Message-id: <49AE2A30.3000503@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 13423

+1.   This seems like it could have been self-review to me, based on the 
answers to the questions.

    -- Garrett

James Walker wrote:
> I'm sponsoring this familiarity case for Lily Li. The requested
> release binding is minor. The man page has been posted in the
> materials directory.
>
> Template Version: @(#)sac_nextcase 1.68 02/23/09 SMI
> This information is Copyright 2009 Sun Microsystems
> 1. Introduction
>     1.1. Project/Component Working Name:
> 	 shmux
>     1.2. Name of Document Author/Supplier:
> 	 Author:  Lily Li
>     1.3  Date of This Document:
> 	03 March, 2009
> 4. Technical Description
> Shmux Check List
> 1.0 Project Information
>   1.1 Name of project/component
>     shmux
>
>   1.2 Author of document
>     Lily.Li@Sun.COM
>
> 2.0 Project Summary
>   2.1 Project Description
>     shmux is program for executing the same command on many hosts in parallel.
>     For each target, a child process is spawned by shmux, and a shell on the
>     target obtained one of the supported methods: rsh, ssh, or sh. The output
>     produced by the children is received by shmux and either (optionally) output
>     in turn to the user using an easy to read format, or written to files for
>     later processing making it well suited for use in scripts.
>
>     shmux-1.0.2 will be integrated into the SFW consolidation as part of
>     this proposal, and will be installed as SUNWshmux. A minor release
>     binding is requested.
>
>   2.2 Release binding
>       What is is the release binding?
>       (see http://opensolaris.org/os/community/arc/policies/release-taxonomy/)
>       [ ] Major
>       [*] Minor
>       [ ] Patch or Micro
>       [ ] Unknown -- ARC review required
>
>   2.3 Type of project
>       Is this case a Linux Familiarity project?
>       [*] Yes
>       [ ] No
>
>   2.4 Originating Community
>     2.4.1 Community Name
>       shmux [1]
>     
>     2.4.2 Community Involvement
>       Indicate Sun's involvement in the community
>       [ ] Maintainer
>       [ ] Contributor
>       [*] Monitoring
>       
>       Will the project team work with the upstream community to resolve
>       architectural issues of interest to Sun?
>       [*] Yes 
>       [ ] No - briefly explain
>       
>       Will we or are we forking from the community?
>       [ ] Yes - ARC review required prior to forking
>       [*] No
>       
> 3.0 Technical Description
>   3.1 Installation & Sharable
>     3.1.1S Solaris Installation - section only required for Solaris Software
>       (see http://opensolaris.org/os/community/arc/policies/install-locations/ for details)
>       Does this project follow the Install Locations best practice?
>       [*] Yes 
>       [ ] No - ARC review required
>       
>       Does this project install into /usr under [sbin|bin|lib|include|man|share]?
>       [*] Yes
>       [ ] No or N/A
>       
>       Does this project install into /opt?
>       [ ] Yes - explain below
>       [*] No or N/A
>       
>       Does this project install into a different directory structure?
>       [ ] Yes - ARC review required
>       [*] No or N/A
>       
>       Do any of the components of this project conflict with anything under /usr?
>       (see http://opensolaris.org/os/community/arc/caselog/2007/047/ for details)
>       [ ] Yes - explain below
>       [*] No
>       
>       If conflicts exist then will this project install under /usr/gnu?
>       [ ] Yes
>       [ ] No - ARC review required
>       [*] N/A
>       
>       Is this project installing into /usr/sfw?
>       [ ] Yes - ARC review required
>       [*] No
>       
>     3.1.1W Windows Installation - section only required for Windows Software
>       (see http://sac.sfbay/WSARC/2002/494 for details)
>       Does this project install software into a 
>       <system drive>:\Program Files\Sun\<product> or <system drive>:\Sun\<product>
>       directory?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Does the project use the Windows registry?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Does the project use 
>       HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product>\<version>
>       for the registry key?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       Is the project's stored location
>       HKEY_LOCAL_MACHINE\SOFTWARE\Sun Microsystems\<product id>\<version id>\Path?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>     3.1.2 Share and Sharable
>       Does the module include any components that are used or shared by 
>       other projects?
>       [ ] Yes
>       [*] No
>     
>       If yes are these components packaged to be shared with the other FOSS?
>       [ ] Yes
>       [ ] No - ARC review required
>       [*] N/A
>     
>       Are these components already in the Solaris WOS?
>       [ ] Yes
>       [*] No - continue with next section (section 3.2)
>     
>       If yes are these newer versions being delivered?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes are the newer versions replacing the existing versions?
>       [ ] Yes
>       [ ] No - ARC review required
>
>   3.2 Exported Libraries
>       Are libraries being delivered by this project?
>       [ ] Yes
>       [*] No - continue with next section (section 3.3)
>       
>       Are 64-bit versions of the libraries being delivered?
>       [ ] Yes
>       [ ] No - ARC review required
>     
>       Are static versions of the libraries being delivered?
>       [ ] Yes - ARC review required
>       [ ] No 
>       
>   3.3 Services and the /etc Directory
>       (see http://opensolaris.org/os/community/arc/policies/SMF-policy/)
>       Does the project integrate anything into /etc/init.d or /etc/rc?.d?
>       [ ] Yes - ARC review required
>       [*] No
>       
>       Does the project integrate any new entries into /etc/inittab or
>       /etc/inetd.conf?
>       [ ] Yes - ARC review required
>       [*] No
>       
>       Does the project integrate any private non-public files into /etc/default
>       or /etc/ configuration files?
>       [ ] Yes - ARC review required
>       [*] No
>       
>       Does the service manifests method context grant rights above that
>       of the noaccess user and basic privilege set?
>       [ ] Yes - ARC review required
>       [*] No
>         
>   3.4 Security
>     3.4.1 Secure By Default 
>       (see http://opensolaris.org/os/community/arc/policies/secure-by-default/ for details)
>       (see http://www.opensolaris.org/os/community/arc/policies/NITS-policy/ for details)
>       (see parts of http://opensolaris.org/os/community/arc/policies/SMF-policy/ for
>        addtional details)
>       Are there any network services provided by this project?
>       [ ] Yes
>       [*] No - continue with the next section (section 3.4.2)
>       
>       Are network services enabled by default?
>       [ ] Yes - ARC review required
>       [ ] No
>       [ ] N/A
>       
>       Are network services automatically enabled by the project during installation?
>       [ ] Yes - ARC review required
>       [ ] No
>       [ ] N/A
>       
>       Are inbound network communications denied by default?
>       [ ] Yes
>       [ ] No - ARC review required
>       [ ] N/A
>       
>       Is inbound data checked to prevent content-based attacks?
>       [ ] Yes
>       [ ] No - ARC review required
>       [ ] N/A
>       
>       Is the outbound receiver authenticated?
>       [ ] Yes
>       [ ] No - ARC review required
>       [ ] N/A
>       
>       Is the receiver authenticated prior to receiving any sensitive outbound communication?
>       [ ] Yes
>       [ ] No - ARC review required
>       [ ] N/A
>       
>     3.4.2 Authorization
>       (see http://opensolaris.org/os/community/arc/bestpractices/rbac-intro/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/ and
> 	   http://opensolaris.org/os/community/arc/bestpractices/rbac-profiles/
>            for details)
>       Are there any setuid/setgid privileged binaries in the project?
>       [ ] Yes - ARC review required
>       [*] No - continue with next section (section 3.4.3)
>       
>       If yes then are the setuid/setgid privileges handled by the use of roles?
>       [ ] Yes
>       [ ] No - ARC review required
>
>     3.4.3 Auditing
>       (see http://opensolaris.org/os/community/arc/policies/audit-policy/ for details)
>       (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
>       Does this component contain administrative or security enforcing software?
>       [ ] Yes - ARC review required
>       [*] No - continue to next section (section 3.4.4)
>       
>       (see http://opensolaris.org/os/community/arc/caselog/2003/397 for details)
>       Do the components create audit logs detailing what took place including what event
>       took place, who was involved, when the event took place?
>       [ ] Yes - ARC contract and Audit project team review required
>       [ ] No - ARC review required
>         
>         
>     3.4.4 Authentication
>       (see http://opensolaris.org/os/community/arc/policies/PAM/)
>       Do the components contain any authentication code?
>       [ ] Yes
>       [*] No - continue to next section (section 3.4.5)
>       
>       If yes do the components use PAM (plugable authentication modules) for authentication?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes is a single PAM session maintained during authentication?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>       If yes are the components sufficiently privileged to allow the requested 
>       operations (authentication, password change, process credential manipulation, 
>       audit state initialization)?
>       [ ] Yes - briefly describe below
>       [ ] No - ARC review required
>       
>     3.4.5 Passwords
>       (see http://opensolaris.org/os/community/arc/bestpractices/passwords-cli/ and
>            http://opensolaris.org/os/community/arc/bestpractices/passwords-files/ for details)
>       Do any of the components for the project deal with passwords?
>       [ ] Yes
>       [*] No - continue to next section (section 3.4.6)
>       
>       If yes are these passwords entered via the CLI or environment?
>       [ ] Yes - ARC review required
>       [ ] No
>       
>       Are passwords stored within the file system for the component?
>       [ ] Yes
>       [ ] No - continue to next section (section 3.4.6)
>       
>       If yes are the permissions on the file such to protect exposing the password(s)?
>       [ ] Yes
>       [ ] No - ARC review required
>       
>     3.4.6 General Security Questions
>       (see http://opensolaris.org/os/community/arc/bestpractices/security-questions/ for details)
>       Are there any network protocols used by this project?
>       [*] Yes
>       [ ] No - continue with the next section (section 3.5)
>       
>       Do the components use standard network protocols?
>       [*] Yes
>       [ ] No - ARC review required
>       
>       Do network services for the project make decisions based upon user, host or 
>       service identities?
>       [ ] Yes - explain below
>       [*] No
>       [ ] N/A
>       
>       Do the components make use of secret information during authentication and/or
>       authorization?
>       [ ] Yes - explain below
>       [*] No
>       [ ] N/A
>   
>   3.5 Networking
>       Do the components access the network?
>       [*] Yes
>       [ ] No - continue with the next section (section 3.6)
>       
>       If yes do the components support IPv6?
>       [*] Yes 
>       [ ] No - ARC review required
>           
>   3.6 Core Solaris Components
>       Do the components of this project compete with or duplicate core 
>       Solaris components?
>       [ ] Yes - ARC review required
>       [*] No 
>       
>       Examples of Core Solaris Components include but are not limited to:
>       
>         Secure By Default
>         Authorizations
>         PAM -- Plugable Authentication Module
>         Privilege
>         PRM -- Process Rights Management -- Privilege
>         Audit
>         xVm -- Virtualization
>         zones / Solaris Containers
>         PRM -- Process Rights Management
>         RBAC -- Role Based Access Control
>         TX / Trusted Extensions
>         ZFS
>         SMF -- Service Management Facility
>         FMA -- Fault Management Architecture
>         SCF -- Smart Card Facility
>         IPsec
>         
> 4.0 Interfaces
>   4.1 Exported Interfaces
>   
>     Interface Name	Classification		Comments
>     ----------------	------------------- 	---------------------------
>     SUNWshmux		Uncommitted	    	Package
>     /usr/bin/shmux	Uncommitted	    	Executable binary file
>     
>   4.2 Imported Interfaces
>
>     Interface Name	Classification       	Comments
>     ---------------	-------------------- 	--------------------------
>     OpenSSH		Committed		PSARC/2001/212 (runtime only)
>     SUNWpcre		Committed		Perl Regx
>     
> Appendix A - References
>   [1] http://web.taranis.org/shmux/
>
>   OSR ID# 11157
>   RFE ID#
>
> 6. Resources and Schedule
>     6.4. Steering Committee requested information
>    	6.4.1. Consolidation C-team Name:
> 		SFW
>     6.5. ARC review type: FastTrack
>     6.6. ARC Exposure: open
>
>   


From carlsonj@phorcys.east.sun.com Wed Mar  4 06:17:43 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n24EHg8o002276
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Mar 2009 06:17:42 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n24EHe0x054411;
	Wed, 4 Mar 2009 07:17:40 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KFZ00E0HJPFUX00@brm-avmta-1.central.sun.com>; Wed,
 04 Mar 2009 07:17:39 -0700 (MST)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KFZ00FY4JPD4LD0@brm-avmta-1.central.sun.com>; Wed,
 04 Mar 2009 07:17:37 -0700 (MST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n24EHUaP002906; Wed,
 04 Mar 2009 09:17:30 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n24EHUol002903; Wed,
 04 Mar 2009 09:17:30 -0500 (EST)
Date: Wed, 04 Mar 2009 09:17:30 -0500
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
To: James Walker <jw137282@sac.sfbay.sun.com>
Cc: PSARC-ext@sun.com, Lily.Li@sun.com
Message-id: <18862.36218.789866.874548@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
Status: RO
Content-Length: 983

James Walker writes:
>     shmux is program for executing the same command on many hosts in parallel.
>     For each target, a child process is spawned by shmux, and a shell on the
>     target obtained one of the supported methods: rsh, ssh, or sh. The output
>     produced by the children is received by shmux and either (optionally) output
>     in turn to the user using an easy to read format, or written to files for
>     later processing making it well suited for use in scripts.
[...]
>       Are there any setuid/setgid privileged binaries in the project?
>       [ ] Yes - ARC review required
>       [*] No - continue with next section (section 3.4.3)

If there are no setuid binaries involved, then how exactly does the
"ping" (-p) option work?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Lily.Li@sun.com Wed Mar  4 18:18:16 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n252IFeA021545
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 4 Mar 2009 18:18:16 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n252IDna002466
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Thu, 5 Mar 2009 02:18:15 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG000G03H2EEI00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@Sun.COM); Wed, 04 Mar 2009 19:18:14 -0700 (MST)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG000A5IH2DW350@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@Sun.COM); Wed,
 04 Mar 2009 19:18:14 -0700 (MST)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n252ICUF004938	for
 <PSARC-ext@Sun.COM>; Thu, 05 Mar 2009 02:18:12 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KG000200GQKBI00@mail-apac.sun.com> for PSARC-ext@Sun.COM
 (ORCPT PSARC-ext@Sun.COM); Thu, 05 Mar 2009 10:18:12 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.17])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KG000LUQH2AYDF0@mail-apac.sun.com>; Thu,
 05 Mar 2009 10:18:12 +0800 (SGT)
Date: Thu, 05 Mar 2009 10:18:07 +0800
From: Lily Li <Lily.Li@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18862.36218.789866.874548@gargle.gargle.HOWL>
Sender: Lily.Li@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>, PSARC-ext@sun.com
Reply-to: Lily.Li@sun.com
Message-id: <49AF365F.8060201@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
 <18862.36218.789866.874548@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 6537

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
  <meta content="text/html;charset=ISO-8859-1" http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
Hi James,<br>
<br>
Thanks for your review!<br>
<br>
James Carlson wrote:
<blockquote cite="mid:18862.36218.789866.874548@gargle.gargle.HOWL"
 type="cite">
  <pre wrap="">James Walker writes:
  </pre>
  <blockquote type="cite">
    <pre wrap="">    shmux is program for executing the same command on many hosts in parallel.
    For each target, a child process is spawned by shmux, and a shell on the
    target obtained one of the supported methods: rsh, ssh, or sh. The output
    produced by the children is received by shmux and either (optionally) output
    in turn to the user using an easy to read format, or written to files for
    later processing making it well suited for use in scripts.
    </pre>
  </blockquote>
  <pre wrap=""><!---->[...]
  </pre>
  <blockquote type="cite">
    <pre wrap="">      Are there any setuid/setgid privileged binaries in the project?
      [ ] Yes - ARC review required
      [*] No - continue with next section (section 3.4.3)
    </pre>
  </blockquote>
  <pre wrap=""><!---->
If there are no setuid binaries involved, then how exactly does the
"ping" (-p) option work?

  </pre>
</blockquote>
In fact, shmux use 'fping' instead of 'ping' to test if the target is
alive or not, and it only does ping test when '-p' option is
provided(see below, in shmux manpage). And checking with fping source
codes, 'fping' also does not use 'ping' inside, it uses socket call.<br>
<br>
&nbsp;&nbsp;&nbsp;&nbsp; -p&nbsp;&nbsp; Ping targets to verify they are alive before doing any-<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; thing.&nbsp;&nbsp; The&nbsp; target names must be unique or bad things<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; will happen.<br>
<br>
So there will be the following scenarios:<br>
<br>
<font color="#3333ff"><b>1. with fping on localhost:</b></font><br>
<br>
-bash-3.2$ cat /etc/release <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Solaris Express Community Edition snv_109 X86<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Copyright 2009 Sun Microsystems, Inc.&nbsp; All Rights Reserved.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Use is subject to license terms.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Assembled 23 February 2009<br>
-bash-3.2$ pkginfo|grep -i fping<br>
system&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SUNWfping&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; fping - a program to ping
hosts in parallel<br>
system&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; SUNWfpingr&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; fping - a program to ping
hosts in parallel (Root)<br>
<br>
<b>1.1 with setuid to fping</b>, run shmux by normal user or root;
without setuid to fping, but run shmux by root, the output is:<br>
<br>
<br>
bash-3.2# id<br>
uid=0(root) gid=0(root)<br>
bash-3.2# shmux -p -r rsh -c "uname -a" pollen<br>
pollen: SunOS pollen 5.11 snv_109 i86pc i386 i86pc<br>
<br>
1 target processed in 0 second.<br>
Summary: 1 success<br>
<br>
<b>1.2 without setuid to fping</b>, and run shmux by normal user, the
output is:<br>
<br>
-bash-3.2$ id<br>
uid=201400(ll200400) gid=10(staff)<br>
-bash-3.2$ shmux -p -r rsh -c "uname -a" pollen<br>
<font color="#ff0000">&nbsp;shmux! fping: can't create raw socket :
Permission denied<br>
&nbsp;shmux! Child for fping exited with status 4<br>
&nbsp;shmux! pollen assumed to be alive (missing from fping results)</font><br>
pollen: SunOS pollen 5.11 snv_109 i86pc i386 i86pc<br>
<br>
1 target processed in 1 second.<br>
Summary: 1 success<br>
<br>
<b><font color="#3333ff">2. without fping on localhost</font></b>, run
shmux by normal user or root, the output is:<br>
<br>
-bash-3.00$ cat /etc/release <br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Solaris 10 5/09 s10x_u7wos_05 X86<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Copyright 2009 Sun Microsystems, Inc.&nbsp; All Rights Reserved.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Use is subject to license terms.<br>
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Assembled 18 February 2009<br>
-bash-3.00$ pkginfo|grep -i fping<br>
<br>
-bash-3.00$ shmux -p -r rsh -c "uname -a" pollen<br>
<font color="#ff0000">&nbsp;shmux! Fatal error for fping: execv(fping): No
such file or directory<br>
&nbsp;shmux! pollen assumed to be alive (missing from fping results)</font><br>
pollen: SunOS pollen 5.11 snv_109 i86pc i386 i86pc<br>
<br>
1 target processed in 1 second.<br>
Summary: 1 success<br>
<br>
For target that is not ping'able, the output is:<br>
<br>
with normal user:<br>
<br>
-bash-3.2$ time shmux -p -r rsh -c "uname -a" starter<br>
<font color="#ff0000">&nbsp; shmux! fping: can't create raw socket :
Permission denied<br>
&nbsp; shmux! Child for fping exited with status 4<br>
&nbsp; shmux! starter assumed to be alive (missing from fping results)<br>
starter! starter.sfbay.sun.com: No route to host<br>
&nbsp; shmux! Child for starter exited with status 1</font><br>
<br>
1 target processed in 226 seconds.<br>
Summary: 1 error<br>
Error&nbsp;&nbsp;&nbsp; : starter<br>
<br>
with root:<br>
<br>
bash-3.2# shmux -p -r rsh -c "uname -a" starter<br>
<font color="#ff0000">&nbsp; shmux! ICMP Host Unreachable from
129.146.17.140 for ICMP Echo sent to starter (10.6.10.119)<br>
&nbsp; shmux! starter is unreachable</font><br>
<br>
1 target processed in 4 seconds.<br>
Summary: 1 failure<br>
Failed&nbsp;&nbsp; : starter<br>
<br>
As a result, shmux depends on whether the fping has been installed with
setuid or not, it does not have setuid itself.<br>
<br>
If anything else, please let me know.<br>
<br>
Thanks,<br>
Lily<br>
<br>
</body>
</html>

From carlsonj@phorcys.east.sun.com Thu Mar  5 04:44:12 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n25CiBtr017112
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 5 Mar 2009 04:44:11 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n25Ci3Zd015640;
	Thu, 5 Mar 2009 12:44:08 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG100D03A1HEQ00@brm-avmta-1.central.sun.com>; Thu,
 05 Mar 2009 05:44:05 -0700 (MST)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG100926A1GF430@brm-avmta-1.central.sun.com>; Thu,
 05 Mar 2009 05:44:05 -0700 (MST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n25ChwFo007310; Thu,
 05 Mar 2009 07:43:58 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n25ChwmI007307; Thu,
 05 Mar 2009 07:43:58 -0500 (EST)
Date: Thu, 05 Mar 2009 07:43:58 -0500
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49AF365F.8060201@sun.com>
To: Lily.Li@sun.com
Cc: James Walker <jw137282@sac.sfbay.sun.com>, PSARC-ext@sun.com
Message-id: <18863.51470.178298.799990@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
 <18862.36218.789866.874548@gargle.gargle.HOWL> <49AF365F.8060201@sun.com>
Status: RO
Content-Length: 2535

Lily Li writes:
> <blockquote cite="mid:18862.36218.789866.874548@gargle.gargle.HOWL"

Please use plain text in ARC messages, if at all possible.

> If there are no setuid binaries involved, then how exactly does the
> "ping" (-p) option work?
> 
>   </pre>
> </blockquote>
> In fact, shmux use 'fping' instead of 'ping' to test if the target is
> alive or not, and it only does ping test when '-p' option is
> provided(see below, in shmux manpage). And checking with fping source
> codes, 'fping' also does not use 'ping' inside, it uses socket call.<br>

OK, then, my question is still the same: how does that work?

% fping zhadum
fping: can't create raw socket : Permission denied
% 

'fping' (as currently delivered on Solaris and OpenSolaris) requires
privileges that ordinary users don't have.  How do you plan to make
shmux work reliably?

> -bash-3.2$ shmux -p -r rsh -c "uname -a" pollen<br>
> <font color="#ff0000">&nbsp;shmux! fping: can't create raw socket :
> Permission denied<br>

Right; it doesn't work.

> -bash-3.00$ shmux -p -r rsh -c "uname -a" pollen<br>
> <font color="#ff0000">&nbsp;shmux! Fatal error for fping: execv(fping): No
> such file or directory<br>

I'm having trouble reading through the HTML, but that doesn't look
right at all.  If you depend on fping being installed, then you should
have a package dependency on SUNWfping so you can _guarantee_ that it
is present.  It shouldn't just break apart in the user's hands.

> As a result, shmux depends on whether the fping has been installed with
> setuid or not, it does not have setuid itself.<br>

Users can't set the 'setuid' bit on /usr/bin/fping in any reliable
way.  The permission bits for packaged software are controlled by
packaging.  Moreover, given the nature of the program, they almost
certainly should *not* set that bit.

In other words, if it doesn't ship in a way that's functional for your
purposes, then you can't depend on users hacking around the problem.

One complicated way out of this would be to file a bug against fping
(perhaps some options should work by default but don't), and then make
integration of shmux dependent on that fix.

Another much simpler answer would be to change the code to use regular
/usr/sbin/ping, which *does* have the right privileges and *does* work
for ordinary users.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Lily.Li@sun.com Thu Mar  5 19:40:28 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n263eROS022751
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 5 Mar 2009 19:40:27 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n263eIUk013840
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 6 Mar 2009 03:40:26 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG200I05FJCR600@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Thu, 05 Mar 2009 19:40:24 -0800 (PST)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG200HRJFJB6WA0@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Thu,
 05 Mar 2009 19:40:24 -0800 (PST)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n263eMR1028146	for
 <PSARC-ext@sun.com>; Fri, 06 Mar 2009 03:40:22 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KG200I00FEREC00@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 06 Mar 2009 11:40:22 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.15])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KG200GCQFJ4XK60@mail-apac.sun.com>; Fri,
 06 Mar 2009 11:40:20 +0800 (SGT)
Date: Fri, 06 Mar 2009 11:40:13 +0800
From: Lily Li <Lily.Li@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18863.51470.178298.799990@gargle.gargle.HOWL>
Sender: Lily.Li@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>, PSARC-ext@sun.com
Reply-to: Lily.Li@sun.com
Message-id: <49B09B1D.9000607@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
 <18862.36218.789866.874548@gargle.gargle.HOWL> <49AF365F.8060201@sun.com>
 <18863.51470.178298.799990@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 4876

James Carlson wrote:
> Lily Li writes:
>   
>> <blockquote cite="mid:18862.36218.789866.874548@gargle.gargle.HOWL"
>>     
>
> Please use plain text in ARC messages, if at all possible.
>
>   
Yes, I should have. I just wanted to make it easier to read by marking 
those error messages of the output in red. Anyway, I will always send 
ARC mails in plain text later on.
>> If there are no setuid binaries involved, then how exactly does the
>> "ping" (-p) option work?
>>
>>   </pre>
>> </blockquote>
>> In fact, shmux use 'fping' instead of 'ping' to test if the target is
>> alive or not, and it only does ping test when '-p' option is
>> provided(see below, in shmux manpage). And checking with fping source
>> codes, 'fping' also does not use 'ping' inside, it uses socket call.<br>
>>     
>
> OK, then, my question is still the same: how does that work?
>
> % fping zhadum
> fping: can't create raw socket : Permission denied
> % 
>
> 'fping' (as currently delivered on Solaris and OpenSolaris) requires
> privileges that ordinary users don't have.  How do you plan to make
> shmux work reliably?
>   
I have three basic opinions on this as below:

- shmux still works without fping(ie. it will not do ping if no '-p' 
option specified), but to take full advantage of /shmux/ you will need 
to have fping <http://www.fping.com/> installed.
- all other features of shmux do not need root privilege
- I found with the integration of fping(as of snv_103), the fping is 
installed without setuid by default, so we only can run fping by root, 
ie, it is basically useless to normal users. So I strongly suggest to 
file a bug of fping to make it changed.
>> -bash-3.2$ shmux -p -r rsh -c "uname -a" pollen<br>
>> <font color="#ff0000">&nbsp;shmux! fping: can't create raw socket :
>> Permission denied<br>
>>     
>
> Right; it doesn't work.
>
>   
>> -bash-3.00$ shmux -p -r rsh -c "uname -a" pollen<br>
>> <font color="#ff0000">&nbsp;shmux! Fatal error for fping: execv(fping): No
>> such file or directory<br>
>>     
>
> I'm having trouble reading through the HTML, 
Sorry for this!
> but that doesn't look
> right at all.  If you depend on fping being installed, then you should
> have a package dependency on SUNWfping so you can _guarantee_ that it
> is present.  It shouldn't just break apart in the user's hands.
>
>   
OK, it should be better to add SUNWfping dependency to the 
pkgdefs/SUNWshmux/depend file.

BTW, the INSTALL of shmux(see below) states it depends on fping, ssh and 
pcre for full features. fping is used for ping test by '-p' option, ssh 
is used for shell by '-r' option, and 'pcre' is used for analyzing 
output by '-a' option. 'ssh' is optional, other two supported methods 
are sh and rsh. Should I add all these three dependencies?

-- shmux dependencies

shmux will make use of the following programs if they are available on the
system (and found in the PATH).  They are not required but allow using
certain optional features of shmux.  See the man page for details.

+ fping: http://www.fping.com/
+ ssh: http://www.openssh.org/, ...

Also, if you want Perl Compatible Regular Expression support, you'll need
the PCRE library:

+ pcre: http://www.pcre.org/
>> As a result, shmux depends on whether the fping has been installed with
>> setuid or not, it does not have setuid itself.<br>
>>     
>
> Users can't set the 'setuid' bit on /usr/bin/fping in any reliable
> way.  The permission bits for packaged software are controlled by
> packaging.  Moreover, given the nature of the program, they almost
> certainly should *not* set that bit.
>
>   
Yes, I know.
> In other words, if it doesn't ship in a way that's functional for your
> purposes, then you can't depend on users hacking around the problem.
>
> One complicated way out of this would be to file a bug against fping
>   
It's reasonable.
> (perhaps some options should work by default but don't), 
 From the manpage of fping(see below), it seems a MUST to set uid or run 
by root:

RESTRICTIONS
     If certain options are used (i.e, a low value for -i and -t,
     and  a  high  value for -r) it is possible to flood the net-
     work. This program must be installed as setuid root in order
     to open up a raw socket, or must be run by root.
> and then make
> integration of shmux dependent on that fix.
>
>   
Should I wait until the bug is fixed?
> Another much simpler answer would be to change the code to use regular
> /usr/sbin/ping, which *does* have the right privileges and *does* work
> for ordinary users.
>
>   
I think shmux makes good use of fping based on the following two 
differences:
- you can specify any number of targets on the command line
- instead of sending to one target until it times out or replies, fping 
will send out a ping packet and move on to the next target in a 
round-robin fashion

Anything else, please let me know.

Thanks,
Lily

From Lily.Li@sun.com Fri Mar  6 01:20:24 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n269KOoK004143
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 6 Mar 2009 01:20:24 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n269KN4f010211
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 6 Mar 2009 01:20:24 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG200I1RV9ZDQ00@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 06 Mar 2009 01:20:23 -0800 (PST)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG200I0CV9WFR00@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 06 Mar 2009 01:20:21 -0800 (PST)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n269KKEF017447	for
 <PSARC-ext@sun.com>; Fri, 06 Mar 2009 09:20:20 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KG200E00V6C8K00@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 06 Mar 2009 17:20:20 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.15])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KG2008ZFV9PIK10@mail-apac.sun.com>; Fri,
 06 Mar 2009 17:20:17 +0800 (SGT)
Date: Fri, 06 Mar 2009 17:20:11 +0800
From: Lily Li <Lily.Li@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B09B1D.9000607@sun.com>
Sender: Lily.Li@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: James Walker <jw137282@sac.sfbay.sun.com>, PSARC-ext@sun.com
Reply-to: Lily.Li@sun.com
Message-id: <49B0EACB.2000409@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903040703.n2473BwM028742@sac.sfbay.sun.com>
 <18862.36218.789866.874548@gargle.gargle.HOWL> <49AF365F.8060201@sun.com>
 <18863.51470.178298.799990@gargle.gargle.HOWL> <49B09B1D.9000607@sun.com>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 6072

Hi James,

After checking with the SUNWfping and SUNWfpingr packages again, I found 
the newest manpage of fping in solaris_nevada contains the restriction 
as below:

RESTRICTIONS
     Successful execution of this program  requires  that  it  be
     granted the net_icmpaccess privilege.

So in fact, now the solaris/fping uses RBAC instead of setting uid of 
the binary file directly. If normal user wants to use fping, he/she must 
have been granted "net_icmpaccess" privilege(but as NIS user, we do not 
have this privilege in general).

-bash-3.2$ grep fping /etc/security/exec_attr
Network Management:solaris:cmd:::/usr/bin/fping:privs=net_icmpaccess

-bash-3.2$ id
uid=201400(ll200400) gid=10(staff)

-bash-3.2$ ppriv -De fping -h
fping[18609]: missing privilege "net_icmpaccess" (euid = 201400, syscall 
= 230) needed at secpolicy_net_icmpaccess+0x24
fping: can't create raw socket : Permission denied

As a result, it seems not necessary to file a bug against fping.

Thanks,
Lily

Lily Li wrote:
> James Carlson wrote:
>> Lily Li writes:
>>  
>>> <blockquote cite="mid:18862.36218.789866.874548@gargle.gargle.HOWL"
>>>     
>>
>> Please use plain text in ARC messages, if at all possible.
>>
>>   
> Yes, I should have. I just wanted to make it easier to read by marking 
> those error messages of the output in red. Anyway, I will always send 
> ARC mails in plain text later on.
>>> If there are no setuid binaries involved, then how exactly does the
>>> "ping" (-p) option work?
>>>
>>>   </pre>
>>> </blockquote>
>>> In fact, shmux use 'fping' instead of 'ping' to test if the target is
>>> alive or not, and it only does ping test when '-p' option is
>>> provided(see below, in shmux manpage). And checking with fping source
>>> codes, 'fping' also does not use 'ping' inside, it uses socket 
>>> call.<br>
>>>     
>>
>> OK, then, my question is still the same: how does that work?
>>
>> % fping zhadum
>> fping: can't create raw socket : Permission denied
>> %
>> 'fping' (as currently delivered on Solaris and OpenSolaris) requires
>> privileges that ordinary users don't have.  How do you plan to make
>> shmux work reliably?
>>   
> I have three basic opinions on this as below:
>
> - shmux still works without fping(ie. it will not do ping if no '-p' 
> option specified), but to take full advantage of /shmux/ you will need 
> to have fping <http://www.fping.com/> installed.
> - all other features of shmux do not need root privilege
> - I found with the integration of fping(as of snv_103), the fping is 
> installed without setuid by default, so we only can run fping by root, 
> ie, it is basically useless to normal users. So I strongly suggest to 
> file a bug of fping to make it changed.
>>> -bash-3.2$ shmux -p -r rsh -c "uname -a" pollen<br>
>>> <font color="#ff0000">&nbsp;shmux! fping: can't create raw socket :
>>> Permission denied<br>
>>>     
>>
>> Right; it doesn't work.
>>
>>  
>>> -bash-3.00$ shmux -p -r rsh -c "uname -a" pollen<br>
>>> <font color="#ff0000">&nbsp;shmux! Fatal error for fping: 
>>> execv(fping): No
>>> such file or directory<br>
>>>     
>>
>> I'm having trouble reading through the HTML, 
> Sorry for this!
>> but that doesn't look
>> right at all.  If you depend on fping being installed, then you should
>> have a package dependency on SUNWfping so you can _guarantee_ that it
>> is present.  It shouldn't just break apart in the user's hands.
>>
>>   
> OK, it should be better to add SUNWfping dependency to the 
> pkgdefs/SUNWshmux/depend file.
>
> BTW, the INSTALL of shmux(see below) states it depends on fping, ssh 
> and pcre for full features. fping is used for ping test by '-p' 
> option, ssh is used for shell by '-r' option, and 'pcre' is used for 
> analyzing output by '-a' option. 'ssh' is optional, other two 
> supported methods are sh and rsh. Should I add all these three 
> dependencies?
>
> -- shmux dependencies
>
> shmux will make use of the following programs if they are available on 
> the
> system (and found in the PATH).  They are not required but allow using
> certain optional features of shmux.  See the man page for details.
>
> + fping: http://www.fping.com/
> + ssh: http://www.openssh.org/, ...
>
> Also, if you want Perl Compatible Regular Expression support, you'll need
> the PCRE library:
>
> + pcre: http://www.pcre.org/
>>> As a result, shmux depends on whether the fping has been installed with
>>> setuid or not, it does not have setuid itself.<br>
>>>     
>>
>> Users can't set the 'setuid' bit on /usr/bin/fping in any reliable
>> way.  The permission bits for packaged software are controlled by
>> packaging.  Moreover, given the nature of the program, they almost
>> certainly should *not* set that bit.
>>
>>   
> Yes, I know.
>> In other words, if it doesn't ship in a way that's functional for your
>> purposes, then you can't depend on users hacking around the problem.
>>
>> One complicated way out of this would be to file a bug against fping
>>   
> It's reasonable.
>> (perhaps some options should work by default but don't), 
> From the manpage of fping(see below), it seems a MUST to set uid or 
> run by root:
>
> RESTRICTIONS
>     If certain options are used (i.e, a low value for -i and -t,
>     and  a  high  value for -r) it is possible to flood the net-
>     work. This program must be installed as setuid root in order
>     to open up a raw socket, or must be run by root.
>> and then make
>> integration of shmux dependent on that fix.
>>
>>   
> Should I wait until the bug is fixed?
>> Another much simpler answer would be to change the code to use regular
>> /usr/sbin/ping, which *does* have the right privileges and *does* work
>> for ordinary users.
>>
>>   
> I think shmux makes good use of fping based on the following two 
> differences:
> - you can specify any number of targets on the command line
> - instead of sending to one target until it times out or replies, 
> fping will send out a ping packet and move on to the next target in a 
> round-robin fashion
>
> Anything else, please let me know.
>
> Thanks,
> Lily
>

From gww@eng.sun.com Fri Mar  6 07:18:00 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n26FI0ZR014767
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 6 Mar 2009 07:18:00 -0800 (PST)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n26FHwYF010263
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Fri, 6 Mar 2009 08:17:59 -0700 (MST)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG300D0HBTZT800@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Fri, 06 Mar 2009 08:17:59 -0700 (MST)
Received: from dm-eng-02.sfbay.sun.com ([129.146.11.32])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG300D27BTXCU00@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Fri,
 06 Mar 2009 08:17:57 -0700 (MST)
Received: from marduk.eng.sun.com (marduk.SFBay.Sun.COM [129.146.108.224])
	by dm-eng-02.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2)
 with ESMTP id n26FHtD9044428; Fri, 06 Mar 2009 07:17:55 -0800 (PST)
Received: from marduk.eng.sun.com (localhost [127.0.0.1])
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11) with ESMTP id n26FG160026982; Fri,
 06 Mar 2009 07:16:01 -0800 (PST)
Received: (from gww@localhost)
	by marduk.eng.sun.com (8.13.6+Sun/8.12.11/Submit) id n26FG1u8026981; Fri,
 06 Mar 2009 07:16:01 -0800 (PST)
Date: Fri, 06 Mar 2009 07:16:01 -0800 (PST)
From: Gary Winiger <gww@eng.sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
To: James.D.Carlson@sun.com, Lily.Li@sun.com
Cc: jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
Content-transfer-encoding: 7BIT
X-Sun-Charset: US-ASCII
X-PMX-Version: 5.4.1.325704
Status: RO
Content-Length: 885

> So in fact, now the solaris/fping uses RBAC instead of setting uid of 
> the binary file directly. If normal user wants to use fping, he/she must 
> have been granted "net_icmpaccess" privilege(but as NIS user, we do not 
> have this privilege in general).
> 
> -bash-3.2$ grep fping /etc/security/exec_attr
> Network Management:solaris:cmd:::/usr/bin/fping:privs=net_icmpaccess
> 
> -bash-3.2$ id
> uid=201400(ll200400) gid=10(staff)
> 
> -bash-3.2$ ppriv -De fping -h
> fping[18609]: missing privilege "net_icmpaccess" (euid = 201400, syscall 
> = 230) needed at secpolicy_net_icmpaccess+0x24
> fping: can't create raw socket : Permission denied
> 
> As a result, it seems not necessary to file a bug against fping.

	Are you then saying that shmux will pfexec /usr/bin/fping so
	that administrators with the Network Management Rights Profile
	can use shmux to call fping?

Gary..

From carlsonj@phorcys.east.sun.com Fri Mar  6 07:39:04 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n26Fd45N016404
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 6 Mar 2009 07:39:04 -0800 (PST)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n26Fcqnp026016;
	Fri, 6 Mar 2009 08:39:02 -0700 (MST)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG30050PCT1QC00@nwk-avmta-2.sfbay.sun.com>; Fri,
 06 Mar 2009 07:39:01 -0800 (PST)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG3001D9CSN7270@nwk-avmta-2.sfbay.sun.com>; Fri,
 06 Mar 2009 07:38:48 -0800 (PST)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n26FcdU6012300; Fri,
 06 Mar 2009 10:38:39 -0500 (EST)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n26FccRB012297; Fri,
 06 Mar 2009 10:38:38 -0500 (EST)
Date: Fri, 06 Mar 2009 10:38:38 -0500
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
To: Gary Winiger <gww@eng.sun.com>
Cc: Lily.Li@sun.com, jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <18865.17278.944209.539995@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
Status: RO
Content-Length: 1349

Gary Winiger writes:
> > -bash-3.2$ ppriv -De fping -h
> > fping[18609]: missing privilege "net_icmpaccess" (euid = 201400, syscall 
> > = 230) needed at secpolicy_net_icmpaccess+0x24
> > fping: can't create raw socket : Permission denied
> > 
> > As a result, it seems not necessary to file a bug against fping.
> 
> 	Are you then saying that shmux will pfexec /usr/bin/fping so
> 	that administrators with the Network Management Rights Profile
> 	can use shmux to call fping?

Having to grant a rights profile just so that people can use this
shmux utility strikes me as an extremely poor answer.

There's no clear reason this utility needs to use fping.  It likely
shouldn't be using it.  The reason fping has restricted access on
Solaris (and isn't either setuid or in any "normal" profile) is that
it's considered _dangerous_.  The regular 'ping' utility appears to
have all of the functionality that this shmux feature needs, and it
doesn't require the user to have any special privileges.

I strongly recommend either:

  - Fixing this utility so that it invokes "ping".

or:

  - Just removing the silly "-p" option.

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Nicolas.Williams@sun.com Fri Mar  6 08:07:02 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n26G72Qe014482
	for <psarc-ext@sac.sfbay.sun.com>; Fri, 6 Mar 2009 08:07:02 -0800 (PST)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n26G6vhN020136;
	Fri, 6 Mar 2009 08:06:59 -0800 (PST)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG30020NE3MEU00@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 06 Mar 2009 08:06:58 -0800 (PST)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG300CU4E3LJFA0@nwk-avmta-1.sfbay.Sun.COM>; Fri,
 06 Mar 2009 08:06:57 -0800 (PST)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n26G5NAt017255;
 Fri, 06 Mar 2009 10:05:23 -0600 (CST)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n26G5N5L017254; Fri,
 06 Mar 2009 10:05:23 -0600 (CST)
Date: Fri, 06 Mar 2009 10:05:23 -0600
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18865.17278.944209.539995@gargle.gargle.HOWL>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, Lily.Li@sun.com,
        jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <20090306160523.GN9992@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 578

On Fri, Mar 06, 2009 at 10:38:38AM -0500, James Carlson wrote:
> I strongly recommend either:
> 
>   - Fixing this utility so that it invokes "ping".
> 
> or:
> 
>   - Just removing the silly "-p" option.

A tool like shmux that can't talk to its targets in parallel so that one
unreachable target need not slow everything down is not worthy of
integrating.  If shmux can do that then it doesn't need a -p option.

Thus I'm for "removing the silly "-p" option."

(shmux does need a connect timeout option, but that's another story.
I've not looked to see if has one.)

Nico
-- 

From Lily.Li@Sun.COM Mon Mar  9 04:44:33 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n29BiR8c006250
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Mar 2009 04:44:32 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n29BiB8L013109
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Mar 2009 19:44:16 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG800903LXSMR00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Mar 2009 05:44:16 -0600 (MDT)
Received: from sineb-mail-1.sun.com ([192.18.19.6])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG8008E3LXQK100@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Mar 2009 05:44:15 -0600 (MDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-1.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n29BiEGr023994	for
 <PSARC-ext@sun.com>; Mon, 09 Mar 2009 11:44:14 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KG800C00LUUOJ00@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Mar 2009 19:44:14 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.13])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KG8008DULXOX9H0@mail-apac.sun.com>; Mon,
 09 Mar 2009 19:44:14 +0800 (SGT)
Date: Mon, 09 Mar 2009 19:44:09 +0800
From: Lily Li <Lily.Li@Sun.COM>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18865.17278.944209.539995@gargle.gargle.HOWL>
Sender: Lily.Li@Sun.COM
To: James Carlson <James.D.Carlson@Sun.COM>, Gary Winiger <gww@eng.sun.com>,
        Nicolas.Williams@Sun.COM
Cc: jw137282@sac.sfbay.sun.com, PSARC-ext@Sun.COM
Reply-to: Lily.Li@Sun.COM
Message-id: <49B50109.6070504@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 3678

Many thanks for discussing the ping issue of shmux, James, Gary and Nico!

James Carlson wrote:
> Gary Winiger writes:
>   
>>> -bash-3.2$ ppriv -De fping -h
>>> fping[18609]: missing privilege "net_icmpaccess" (euid = 201400, syscall 
>>> = 230) needed at secpolicy_net_icmpaccess+0x24
>>> fping: can't create raw socket : Permission denied
>>>
>>> As a result, it seems not necessary to file a bug against fping.
>>>       
>> 	Are you then saying that shmux will pfexec /usr/bin/fping so
>> 	that administrators with the Network Management Rights Profile
>> 	can use shmux to call fping?
>>     
No. I meant we do not need to file a bug against fping to make it setuid 
because it had been integrated as a RBAC command already.

And I had thought we could just integrate the shmux "as is", ie. remain 
'fping' and '-p' option, two reasons:
- ordinary users(who do not have permission to run fping) still can use 
all other features of shmux except the optional '-p', moreover, even 
with '-p', the output of shmux will still be expected.
- after all, for root or those users who had been granted the 
permission, they can run shmux with '-p' option as they will.
>
> Having to grant a rights profile just so that people can use this
> shmux utility strikes me as an extremely poor answer.
>
> There's no clear reason this utility needs to use fping.  It likely
> shouldn't be using it.  The reason fping has restricted access on
> Solaris (and isn't either setuid or in any "normal" profile) is that
> it's considered _dangerous_.  The regular 'ping' utility appears to
> have all of the functionality that this shmux feature needs, and it
> doesn't require the user to have any special privileges.
>
> I strongly recommend either:
>
>   - Fixing this utility so that it invokes "ping".
>
> or:
>
>   - Just removing the silly "-p" option.
>
>
>   
> On Fri, Mar 06, 2009 at 10:38:38AM -0500, James Carlson wrote:
>   
> A tool like shmux that can't talk to its targets in parallel so that one
> unreachable target need not slow everything down is not worthy of
> integrating.  If shmux can do that then it doesn't need a -p option.
>
> Thus I'm for "removing the silly "-p" option."
>
>   
I'd like to remove the '-p' option by adding a patch, if you all think 
it is better for integrating shmux to solaris.
> (shmux does need a connect timeout option, 
Yes, it has! Current shmux has three types of timeout: timeout of ping, 
timeout of test and timeout of execution, please refer to the shmux 
manpage(http://web.taranis.org/shmux/man/shmux.1.html):

       Before executing the specified /command/, *shmux* will option-­
       ally  ping  each  target to ensure that it can be reached,
       and/or run a dummy test /command/ to make sure that the tar-­
       get  not only is alive, but that it is possible to cleanly
       execute a command on it.  Both these tests  are  typically
       run  with  a  fairly  short  timeout  to  quickly  dismiss
       unavailable targets rather than waiting for  the  standard
       (longer) network timeout.

       *-P* /timeout/
              Defines  the  initial  target  ping timeout in mil-­
              liseconds, see /fping(8)/.  (Implies *-p*.)

       *-T* /timeout (default 15s)/
              Defines the test timeout in seconds.  (Implies *-t*.)

       *-C* /timeout/
              Specify a timeout for the command being executed on
              targets.  This should be a  number  followed  by  a
              time  unit.   The  following  are valid time units:
              s(econds), m(inutes), h(our), d(ays), w(eeks).

> but that's another story.
> I've not looked to see if has one.)
>
> Nico
> -- 

From carlsonj@phorcys.east.sun.com Mon Mar  9 06:25:11 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n29DPAOn007309
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Mar 2009 06:25:10 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n29DOod4028111;
	Mon, 9 Mar 2009 13:25:00 GMT
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG800H07QLLVZ00@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Mar 2009 06:24:57 -0700 (PDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG8006V7QLIW7B0@nwk-avmta-2.sfbay.sun.com>; Mon,
 09 Mar 2009 06:24:55 -0700 (PDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n29DOhGb017212; Mon,
 09 Mar 2009 09:24:43 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n29DOhQS017209; Mon,
 09 Mar 2009 09:24:43 -0400 (EDT)
Date: Mon, 09 Mar 2009 09:24:42 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B50109.6070504@sun.com>
To: Lily.Li@sun.com
Cc: Gary Winiger <gww@eng.sun.com>, Nicolas.Williams@sun.com,
        jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <18869.6298.983581.170660@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
Status: RO
Content-Length: 4232

Lily Li writes:
> And I had thought we could just integrate the shmux "as is", ie. remain 
> 'fping' and '-p' option, two reasons:
> - ordinary users(who do not have permission to run fping) still can use 
> all other features of shmux except the optional '-p', moreover, even 
> with '-p', the output of shmux will still be expected.
> - after all, for root or those users who had been granted the 
> permission, they can run shmux with '-p' option as they will.

How does this compare with the use of shmux on other platforms?  Is it
expected that "-p" is an unusual option that will require extra
privileges to invoke?

How are you proposing that it will work on Solaris?  If I'm assigned
the 'Network Management' profile, will that be enough (i.e., will
'shmux' automatically do the 'pfexec' for me when it runs fping?), or
do I need something else to make it work?

Do I really need to be all-powerful root in order to use "-p"?

> > On Fri, Mar 06, 2009 at 10:38:38AM -0500, James Carlson wrote:
> >   
> > A tool like shmux that can't talk to its targets in parallel so that one
> > unreachable target need not slow everything down is not worthy of
> > integrating.  If shmux can do that then it doesn't need a -p option.
> >
> > Thus I'm for "removing the silly "-p" option."
> >
> >   
> I'd like to remove the '-p' option by adding a patch, if you all think 
> it is better for integrating shmux to solaris.

I didn't actually write the text quoted above (it's misattributed to
me, and was apparently written by Nico).

However, I do think it requires some thought.  I don't agree that
invoking the shmux "-p" option should require any special work on the
user's part, nor do I agree that it ought to require any elevated
privileges.

It appears to be an option intended for use by *ordinary* users.  If
it doesn't in fact work that way, then it's broken, and the porting
effort to OpenSolaris is necessarily incomplete.

Thus, there are a few possible solutions, and I'd like to hear from
the project team on how they'd like to go forward.  The solutions I
can imagine are:

  - The project team determines that the "-p" option doesn't actually
    do anything useful in real networks, and thus it's just removed.

  - The project team determines that there's something else that the
    implementation could do (such as timing out quickly on connect()
    and/or using non-blocking connections) to make implementation of
    "-p" worthless, and thus removes it and contributes bits upstream.

  - The project team determines that "-p" really is needed, and finds
    some alternate way to implement it on Solaris, such as invoking
    regular 'ping' or creating some "safe fping" wrapper that is in
    turn given setuid.

> > (shmux does need a connect timeout option, 
> Yes, it has! Current shmux has three types of timeout: timeout of ping, 
> timeout of test and timeout of execution, please refer to the shmux 
> manpage(http://web.taranis.org/shmux/man/shmux.1.html):

No, it doesn't.  None of the timeouts you cited relates to the
connect(3SOCKET) operation itself.  The utility is just missing this
basic feature.

The -C option specifies the timeout for the entire command.  This
timer continues running after connect() succeeds, and thus must be set
to a long time.  The -T timeout is for the "echo" test.  Again, it
continues running after connect() succeeds, and thus must be
relatively long, though it *might* be short enough to be useful with
regular connection failures.  The -P timeout relates to ping, which
has nothing to do with connect().

Nico's contention (and I happen to agree with it) is that it's
completely pointless to do a "ping" test if you can do a connect()
with a short time-out and if you otherwise design the utility "right."
(Where "right" means that you open all of your connections in
non-blocking mode, then wait for them to complete using poll/select
[poll on write] with some short timer.  That way, you won't get
blocked on any one failing connection.)

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Lily.Li@sun.com Mon Mar  9 22:12:14 2009
Received: from newsunmail1brm.central.sun.com (newsunmail1brm.Central.Sun.COM [129.147.62.245])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2A5CETd016450
	for <psarc-ext@sac.sfbay.sun.com>; Mon, 9 Mar 2009 22:12:14 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by newsunmail1brm.central.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2A5C56u005076
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Mon, 9 Mar 2009 23:12:13 -0600 (MDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KG900307YFWUJ00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Mon, 09 Mar 2009 22:11:56 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KG900A8SYFV1YC0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Mon,
 09 Mar 2009 22:11:56 -0700 (PDT)
Received: from fe-apac-06.sun.com
 (fe-apac-06.sun.com [192.18.19.177] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2A5BtOI024762	for
 <PSARC-ext@sun.com>; Tue, 10 Mar 2009 05:11:55 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KG900H00Y8BO300@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Mar 2009 13:11:55 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.19])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KG9004UOYFNNPJ0@mail-apac.sun.com>; Tue,
 10 Mar 2009 13:11:55 +0800 (SGT)
Date: Tue, 10 Mar 2009 13:11:44 +0800
From: Lily Li <Lily.Li@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18869.6298.983581.170660@gargle.gargle.HOWL>
Sender: Lily.Li@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: Gary Winiger <gww@eng.sun.com>, Nicolas.Williams@sun.com,
        jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Reply-to: Lily.Li@sun.com
Message-id: <49B5F690.4050705@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 8BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 7319

James Carlson wrote:
> Lily Li writes:
>   
>> And I had thought we could just integrate the shmux "as is", ie. remain 
>> 'fping' and '-p' option, two reasons:
>> - ordinary users(who do not have permission to run fping) still can use 
>> all other features of shmux except the optional '-p', moreover, even 
>> with '-p', the output of shmux will still be expected.
>> - after all, for root or those users who had been granted the 
>> permission, they can run shmux with '-p' option as they will.
>>     
>
> How does this compare with the use of shmux on other platforms?  Is it
> expected that "-p" is an unusual option that will require extra
> privileges to invoke?
>
>   
I searched some info on shmux with other linux systems, it seems they 
have '-p' option too. Please see the Linux manpage on shmux: 
http://linux.die.net/man/1/shmux, and I download shmux rpm for readhat 
or fedora, and still found '-p' from its manpage inside. I have not got 
a chance to run shmux on Fedora, I will have a try later.
Someone said:
>  And it seems that it has fping as a hidden RUN_DEPENDS (use -*P* switch),
>  but wh ship it as only executable by root..

Yes, *shmux* can use fping; i was aware of it. (Frankly, I use *shmux*
without fping for more than 2 years without any trouble.)
To make it fully functional, you are right, fping has to be a
dependancy.
> How are you proposing that it will work on Solaris?  
I mean for root user, the shmux fully works for sure; for ordinary user, 
if they run shmux with '-p', they may got error info as below, but 
anyway, they also got the result what they wanted(stingme and pacifica2 
are alive, only starter is dead), in other words, the fail of fping will 
not effect the final result at all.

-bash-3.2$ shmux -mvpt -r rsh -c "uname -a" stingme starter pacifica2
    shmux: Pinging 3 targets...
    shmux! fping: can't create raw socket : Permission denied
    shmux! Child for fping exited with status 4
    shmux! stingme assumed to be alive (missing from fping results)
    shmux! starter assumed to be alive (missing from fping results)
    shmux! pacifica2 assumed to be alive (missing from fping results)
pacifica2: SunOS pacifica2 5.11 snv_108 sun4u sparc SUNW,Sun-Fire-280R
    shmux: Child for pacifica2 exited (with status 0)
  stingme: SunOS stingme 5.11 snv_108 i86pc i386 i86pc
    shmux: Child for stingme exited (with status 0)
    shmux! Test timed out for starter

3 targets processed in 15 seconds.
Summary: 1 failure, 2 successes
Failed   : starter

bash-3.2# id
uid=0(root) gid=0(root)
bash-3.2# shmux -mvpt -r rsh -c "uname -a" stingme starter pacifica2
    shmux: Pinging 3 targets...
    shmux! ICMP Host Unreachable from 129.146.17.140 for ICMP Echo sent 
to starter (10.6.10.119)
    shmux: stingme is alive
    shmux: pacifica2 is alive
    shmux! starter is unreachable
  stingme: SunOS stingme 5.11 snv_108 i86pc i386 i86pc
    shmux: Child for stingme exited (with status 0)
pacifica2: SunOS pacifica2 5.11 snv_108 sun4u sparc SUNW,Sun-Fire-280R
    shmux: Child for pacifica2 exited (with status 0)

3 targets processed in 5 seconds.
Summary: 1 failure, 2 successes
Failed   : starter
> If I'm assigned
> the 'Network Management' profile, will that be enough (i.e., will
> 'shmux' automatically do the 'pfexec' for me when it runs fping?),
I did not try this.
>  or
> do I need something else to make it work?
>
>   
I tried to do the following however(in this example, lilyli is a local 
user, as the usermod cannot change information supplied by the network 
nameservice):

-bash-3.2$ id
uid=235128(lilyli) gid=10(staff)
-bash-3.2$ grep lilyli /etc/user_attr
-bash-3.2$ ppriv -De fping pacifica2
fping[21068]: missing privilege "net_icmpaccess" (euid = 235128, syscall 
= 230) needed at secpolicy_net_icmpaccess+0x24
fping: can't create raw socket : Permission denied
-bash-3.2$ echo $?
4

bash-3.2# id
uid=0(root) gid=0(root)
bash-3.2# usermod -K defaultpriv=basic,net_icmpaccess lilyli

then re-login as lilyli:

-bash-3.2$ id
uid=235128(lilyli) gid=10(staff)
-bash-3.2$ grep lilyli /etc/user_attr
lilyli::::type=normal;defaultpriv=basic,net_icmpaccess
-bash-3.2$ ppriv -De fping pacifica2
pacifica2 is alive
-bash-3.2$ echo $?
0
> Do I really need to be all-powerful root in order to use "-p"?
>
>   
No.
>>> On Fri, Mar 06, 2009 at 10:38:38AM -0500, James Carlson wrote:
>>>   
>>> A tool like shmux that can't talk to its targets in parallel so that one
>>> unreachable target need not slow everything down is not worthy of
>>> integrating.  If shmux can do that then it doesn't need a -p option.
>>>
>>> Thus I'm for "removing the silly "-p" option."
>>>
>>>   
>>>       
>> I'd like to remove the '-p' option by adding a patch, if you all think 
>> it is better for integrating shmux to solaris.
>>     
>
> I didn't actually write the text quoted above (it's misattributed to
> me, and was apparently written by Nico).
>
> However, I do think it requires some thought.  I don't agree that
> invoking the shmux "-p" option should require any special work on the
> user's part, nor do I agree that it ought to require any elevated
> privileges.
>
>   
I know you want to see, ordinary user can use shmux '-p' without any 
those error output caused by fping.

So I have a question: fping cannot used by ordinary user if he/she is 
not granted needed privilege, what's the worth of integrating fping to 
solaris since we have ping already?
> It appears to be an option intended for use by *ordinary* users.  If
> it doesn't in fact work that way, then it's broken, and the porting
> effort to OpenSolaris is necessarily incomplete.
>
> Thus, there are a few possible solutions, and I'd like to hear from
> the project team on how they'd like to go forward.  The solutions I
> can imagine are:
>
>   - The project team determines that the "-p" option doesn't actually
>     do anything useful in real networks, and thus it's just removed.
>
>   
- What's your "The project team" meant? project team for shmux? As a 
package porting task in Solaris QE, I selected shmux to port, so 
basically, I am the only one member of "The project team".
- Checking with the source codes of shmux-1.0.2, the main purpose of 
'-p' is to check if the target is alive within a shorter timer, see the 
manpage info below.

       Before executing the specified /command/, *shmux* will option­
       ally  ping  each  target to ensure that it can be reached,
       and/or run a dummy test /command/ to make sure that the tar­
       get  not only is alive, but that it is possible to cleanly
       execute a command on it.  Both these tests  are  typically
       run  with  a  fairly  short  timeout  to  quickly  dismiss
       unavailable targets rather than waiting for  the  standard
       (longer) network timeout.

>   - The project team determines that there's something else that the
>     implementation could do (such as timing out quickly on connect()
>     and/or using non-blocking connections) to make implementation of
>     "-p" worthless, and thus removes it and contributes bits upstream.
>
>   - The project team determines that "-p" really is needed, and finds
>     some alternate way to implement it on Solaris, such as invoking
>     regular 'ping' or creating some "safe fping" wrapper that is in
>     turn given setuid.
>   

From carlsonj@phorcys.east.sun.com Tue Mar 10 14:54:20 2009
Received: from sunmail4.singapore.sun.com (sunmail4.Singapore.Sun.COM [129.158.71.19])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2ALsJC0024051
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Mar 2009 14:54:20 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail4.singapore.sun.com (8.13.4+Sun/8.13.3/ENSMAIL,v2.2) with ESMTP id n2ALsFfd020662;
	Wed, 11 Mar 2009 05:54:17 +0800 (SGT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGB00B0B8UDNQ00@brm-avmta-1.central.sun.com>; Tue,
 10 Mar 2009 15:54:13 -0600 (MDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGB002T58UCV3D0@brm-avmta-1.central.sun.com>; Tue,
 10 Mar 2009 15:54:12 -0600 (MDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n2ALsADx024579; Tue,
 10 Mar 2009 17:54:10 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n2ALsAZx024576; Tue,
 10 Mar 2009 17:54:10 -0400 (EDT)
Date: Tue, 10 Mar 2009 17:54:09 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B5F690.4050705@sun.com>
To: Lily.Li@sun.com
Cc: Gary Winiger <gww@eng.sun.com>, Nicolas.Williams@sun.com,
        jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <18870.57729.900067.812592@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=iso-8859-1
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
Content-Transfer-Encoding: 8bit
X-MIME-Autoconverted: from quoted-printable to 8bit by sac.sfbay.sun.com id n2ALsJC0024051
Status: RO
Content-Length: 3019

Lily Li writes:
> James Carlson wrote:
> > However, I do think it requires some thought.  I don't agree that
> > invoking the shmux "-p" option should require any special work on the
> > user's part, nor do I agree that it ought to require any elevated
> > privileges.
> >
> >   
> I know you want to see, ordinary user can use shmux '-p' without any 
> those error output caused by fping.
> 
> So I have a question: fping cannot used by ordinary user if he/she is 
> not granted needed privilege, what's the worth of integrating fping to 
> solaris since we have ping already?

I think you're asking a great question.

We made fping a "special" utility on OpenSolaris because it has
options that allow pinging at a high data rate and over large numbers
of hosts.  There are several possible issues here:

 - Maybe our earlier decision about fping was wrong, and this utility
   is _right_ to use it.

 - Maybe this utility shouldn't be using fping like this and should
   instead be running independent short timers for pinging each host.
   (Using fping to ping them all means that you'll block as long as it
   takes to discover that the last one is down.)

 - Maybe it just shouldn't do anything like ping at all, and should
   use the connect() timers as we've suggested.

My guess is the third one's correct: the use of ping here is just a
hack, and isn't right.

> >   - The project team determines that the "-p" option doesn't actually
> >     do anything useful in real networks, and thus it's just removed.
> >
> >   
> - What's your "The project team" meant? project team for shmux?

It means you and whoever you might be working with, perhaps including
the upstream provider of the source.

It's an ARC expression: it means "the team of people (perhaps just
one) working on this project."

> As a 
> package porting task in Solaris QE, I selected shmux to port, so 
> basically, I am the only one member of "The project team".

OK.

> - Checking with the source codes of shmux-1.0.2, the main purpose of 
> '-p' is to check if the target is alive within a shorter timer, see the 
> manpage info below.
> 
>        Before executing the specified /command/, *shmux* will option­
>        ally  ping  each  target to ensure that it can be reached,
>        and/or run a dummy test /command/ to make sure that the tar­
>        get  not only is alive, but that it is possible to cleanly
>        execute a command on it.  Both these tests  are  typically
>        run  with  a  fairly  short  timeout  to  quickly  dismiss
>        unavailable targets rather than waiting for  the  standard
>        (longer) network timeout.

Right.  And what if that design is wrong (for all systems that use
TCP/IP) and just plain conflicts with the security constraints for
fping (for OpenSolaris)?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677


From Nicolas.Williams@sun.com Tue Mar 10 15:08:48 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2AM8lGo025082
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Mar 2009 15:08:48 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n2AM8ax4013616;
	Tue, 10 Mar 2009 22:08:44 GMT
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGB00H059IH1Q00@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 10 Mar 2009 15:08:41 -0700 (PDT)
Received: from binky.Central.Sun.COM ([129.153.128.104])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGB00BQI9IGXL50@nwk-avmta-1.sfbay.Sun.COM>; Tue,
 10 Mar 2009 15:08:40 -0700 (PDT)
Received: from binky.Central.Sun.COM (localhost [127.0.0.1])
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3) with ESMTP id n2AM6x7p020430;
 Tue, 10 Mar 2009 17:06:59 -0500 (CDT)
Received: (from nw141292@localhost)
	by binky.Central.Sun.COM (8.14.3+Sun/8.14.3/Submit) id n2AM6xdT020429; Tue,
 10 Mar 2009 17:06:59 -0500 (CDT)
Date: Tue, 10 Mar 2009 17:06:59 -0500
From: Nicolas Williams <Nicolas.Williams@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18870.57729.900067.812592@gargle.gargle.HOWL>
To: James Carlson <James.D.Carlson@sun.com>
Cc: Lily.Li@sun.com, Gary Winiger <gww@eng.sun.com>,
        jw137282@sac.sfbay.sun.com, PSARC-ext@sun.com
Message-id: <20090310220659.GG9992@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=iso-8859-1
Content-transfer-encoding: 8BIT
Content-disposition: inline
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL>
X-Authentication-warning: binky.Central.Sun.COM: nw141292 set sender to
 Nicolas.Williams@sun.com using -f
User-Agent: Mutt/1.5.7i
Status: RO
Content-Length: 3320

On Tue, Mar 10, 2009 at 05:54:09PM -0400, James Carlson wrote:
> Lily Li writes:
> > So I have a question: fping cannot used by ordinary user if he/she is 
> > not granted needed privilege, what's the worth of integrating fping to 
> > solaris since we have ping already?
> 
> I think you're asking a great question.
> 
> We made fping a "special" utility on OpenSolaris because it has
> options that allow pinging at a high data rate and over large numbers
> of hosts.  There are several possible issues here:
> 
>  - Maybe our earlier decision about fping was wrong,

Quite possibly.  Users can just as easily connect() asynchronously as
many times and so cause as many packets to be sent as fping would have,
to as many hosts (fping can send packets that are much larger than TCP
SYN packets, but a user interested in DoSing someone can make up for
that by sending more packets).

>                                                      and this utility
>    is _right_ to use it.

But I don't think shmux should be using fping, even if the ARC made an
incorrect decision re: fping being setuid-0 or in a profile granted to
all users by default.

>  - Maybe this utility shouldn't be using fping like this and should
>    instead be running independent short timers for pinging each host.
>    (Using fping to ping them all means that you'll block as long as it
>    takes to discover that the last one is down.)

Well, no, you could be parsing fping's output in real-time, but shmux
can't finish until fping finishes -- not a problem.

>  - Maybe it just shouldn't do anything like ping at all, and should
>    use the connect() timers as we've suggested.
> 
> My guess is the third one's correct: the use of ping here is just a
> hack, and isn't right.

Yes, you and I have said as much before and we're saying it again.  Just
async connect(3SOCKET) + poll(2)ing (or better, Solaris event ports, or
libevent to be portable) with timeout.

But the i-team here might not have the resources to fix shmux to do the
right thing.  If we agree that not allowing normal users to use fping
was a mistake, then shmux could be integrated as is with a bug opened in
the upstream community to have the -p option deprecated/replaced
with a design that does async connect() + timeouts.  That would be the
pragmatic solution.

> > - Checking with the source codes of shmux-1.0.2, the main purpose of 
> > '-p' is to check if the target is alive within a shorter timer, see the 
> > manpage info below.
> > 
> >        Before executing the specified /command/, *shmux* will option­
> >        ally  ping  each  target to ensure that it can be reached,
> >        and/or run a dummy test /command/ to make sure that the tar­
> >        get  not only is alive, but that it is possible to cleanly
> >        execute a command on it.  Both these tests  are  typically
> >        run  with  a  fairly  short  timeout  to  quickly  dismiss
> >        unavailable targets rather than waiting for  the  standard
> >        (longer) network timeout.
> 
> Right.  And what if that design is wrong (for all systems that use
> TCP/IP) and just plain conflicts with the security constraints for
> fping (for OpenSolaris)?

That design is wrong.  It also conflicts with how fping was integrated,
but that too was a mistakte (see above).

Nico
-- 

From Scott.Rotondo@sun.com Tue Mar 10 16:26:29 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2ANQSnW020202
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Mar 2009 16:26:28 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2ANQRbD008770
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 10 Mar 2009 16:26:28 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGB0090RD44J800@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Mar 2009 16:26:28 -0700 (PDT)
Received: from brmea-mail-4.sun.com ([192.18.98.36])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGB0059LD43D410@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Mar 2009 16:26:27 -0700 (PDT)
Received: from fe-amer-09.sun.com ([192.18.109.79])
	by brmea-mail-4.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2ANQReu016449	for
 <PSARC-ext@sun.com>; Tue, 10 Mar 2009 23:26:27 +0000 (GMT)
Received: from conversion-daemon.mail-amer.sun.com by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KGB00B00CNM1Y00@mail-amer.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Mar 2009 17:26:27 -0600 (MDT)
Received: from [129.146.108.62] ([unknown] [129.146.108.62])
 by mail-amer.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KGB00N3CD424R80@mail-amer.sun.com>; Tue,
 10 Mar 2009 17:26:27 -0600 (MDT)
Date: Tue, 10 Mar 2009 16:26:26 -0700
From: Scott Rotondo <Scott.Rotondo@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <20090310220659.GG9992@Sun.COM>
Sender: Scott.Rotondo@sun.com
To: Nicolas Williams <Nicolas.Williams@sun.com>
Cc: James Carlson <James.D.Carlson@sun.com>, Lily.Li@sun.com,
        Gary Winiger <gww@eng.sun.com>, jw137282@sac.sfbay.sun.com,
        PSARC-ext@sun.com
Message-id: <49B6F722.3010700@sun.com>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL> <20090310220659.GG9992@Sun.COM>
User-Agent: Thunderbird 2.0.0.12 (X11/20080422)
Status: RO
Content-Length: 751

Nicolas Williams wrote:
> 
> But the i-team here might not have the resources to fix shmux to do the
> right thing.  If we agree that not allowing normal users to use fping
> was a mistake, then shmux could be integrated as is with a bug opened in
> the upstream community to have the -p option deprecated/replaced
> with a design that does async connect() + timeouts.  That would be the
> pragmatic solution.

Assuming that consensus emerges that modifying shmux is the right 
solution, is it so critical to have shmux in Solaris now that we can't 
wait for it to be fixed before integrating?

	Scott

-- 
Scott Rotondo
Principal Engineer, Solaris Security Technologies
President, Trusted Computing Group
Phone/FAX: +1 408 850 3655 (Internal x68278)

From Joep.Vesseur@sun.com Tue Mar 10 17:26:59 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2B0Qx9x022198
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Mar 2009 17:26:59 -0700 (PDT)
Received: from nwk-avmta-1.SFBay.Sun.COM (nwk-avmta-1.SFBay.Sun.COM [129.146.11.74])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2B0QwOA005821
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 10 Mar 2009 17:26:58 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-1.sfbay.Sun.COM by
 nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGB00L03FWYH300@nwk-avmta-1.sfbay.Sun.COM> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Mar 2009 17:26:58 -0700 (PDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by nwk-avmta-1.sfbay.Sun.COM
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGB005NOFWWDG70@nwk-avmta-1.sfbay.Sun.COM> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Mar 2009 17:26:57 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2B0QuZc019937	for
 <PSARC-ext@sun.com>; Wed, 11 Mar 2009 00:26:56 +0000 (GMT)
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KGB00H00FVENA00@fe-emea-09.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Mar 2009 00:26:56 +0000 (GMT)
Received: from [10.16.117.32] ([unknown] [10.16.117.32])
 by fe-emea-09.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KGB00C0XFWV1ED0@fe-emea-09.sun.com>;
 Wed, 11 Mar 2009 00:26:56 +0000 (GMT)
Date: Wed, 11 Mar 2009 01:27:28 +0100
From: Joep Vesseur <Joep.Vesseur@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B6F722.3010700@sun.com>
Sender: Joep.Vesseur@sun.com
To: Scott Rotondo <Scott.Rotondo@sun.com>
Cc: Nicolas Williams <Nicolas.Williams@sun.com>,
        James Carlson <James.D.Carlson@sun.com>, Lily.Li@sun.com,
        Gary Winiger <gww@eng.sun.com>, jw137282@sac.sfbay.sun.com,
        PSARC-ext@sun.com
Message-id: <49B70570.1050909@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
X-Enigmail-Version: 0.95.1
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL> <20090310220659.GG9992@Sun.COM>
 <49B6F722.3010700@sun.com>
User-Agent: Thunderbird 2.0.0.18 (X11/20090209)
Status: RO
Content-Length: 1050

On 03/11/09 00:26, Scott Rotondo wrote:
> Nicolas Williams wrote:
>>
>> But the i-team here might not have the resources to fix shmux to do the
>> right thing.  If we agree that not allowing normal users to use fping
>> was a mistake, then shmux could be integrated as is with a bug opened in
>> the upstream community to have the -p option deprecated/replaced
>> with a design that does async connect() + timeouts.  That would be the
>> pragmatic solution.
> 
> Assuming that consensus emerges that modifying shmux is the right
> solution, is it so critical to have shmux in Solaris now that we can't
> wait for it to be fixed before integrating?

As an aside from an observer, I notice that there are Solaris packages
available from the shmux website. Doesn't it make more sense to ask the
maintainer to submit shmux to the contrib repo?

Based on the discussion here, right now, I doubt it meets the integration
standards for inclusion in the WOS (as it stands right now; I don't want
to downplay the usefulness the tool itself might have).

Joep

From Lily.Li@sun.com Tue Mar 10 20:38:26 2009
Received: from sunmail2sca.sfbay.sun.com (sunmail2sca.SFBay.Sun.COM [129.145.155.234])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2B3cQLw018391
	for <psarc-ext@sac.sfbay.sun.com>; Tue, 10 Mar 2009 20:38:26 -0700 (PDT)
Received: from nwk-avmta-2.sfbay.sun.com (nwk-avmta-2.SFBay.Sun.COM [129.145.155.6])
	by sunmail2sca.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2B3cPmc023083
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Tue, 10 Mar 2009 20:38:26 -0700 (PDT)
Received: from pmxchannel-daemon.nwk-avmta-2.sfbay.sun.com by
 nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGB00K07OS1VQ00@nwk-avmta-2.sfbay.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Tue, 10 Mar 2009 20:38:25 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
 by nwk-avmta-2.sfbay.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGB0082DORT62D0@nwk-avmta-2.sfbay.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Tue,
 10 Mar 2009 20:38:18 -0700 (PDT)
Received: from fe-apac-05.sun.com
 (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n2B3cHuU022265	for
 <PSARC-ext@sun.com>; Wed, 11 Mar 2009 03:38:17 +0000 (GMT)
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KGB00500O2OH900@mail-apac.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Mar 2009 11:38:17 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.17])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-3.01 64bit
 (built Dec 23 2008)) with ESMTPSA id <0KGB00LUGORK4XJ0@mail-apac.sun.com>; Wed,
 11 Mar 2009 11:38:10 +0800 (SGT)
Date: Wed, 11 Mar 2009 11:38:04 +0800
From: Lily Li <Lily.Li@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B70570.1050909@Sun.COM>
Sender: Lily.Li@sun.com
To: Joep Vesseur <Joep.Vesseur@sun.com>
Cc: Scott Rotondo <Scott.Rotondo@sun.com>,
        Nicolas Williams <Nicolas.Williams@sun.com>,
        James Carlson <James.D.Carlson@sun.com>,
        Gary Winiger <gww@eng.sun.com>, jw137282@sac.sfbay.sun.com,
        PSARC-ext@sun.com
Reply-to: Lily.Li@sun.com
Message-id: <49B7321C.5070406@sun.com>
Organization: SUN China
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL> <20090310220659.GG9992@Sun.COM>
 <49B6F722.3010700@sun.com> <49B70570.1050909@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 1932

Joep Vesseur wrote:
> On 03/11/09 00:26, Scott Rotondo wrote:
>   
>> Nicolas Williams wrote:
>>     
>>> But the i-team here might not have the resources to fix shmux to do the
>>> right thing.  If we agree that not allowing normal users to use fping
>>> was a mistake, then shmux could be integrated as is with a bug opened in
>>> the upstream community to have the -p option deprecated/replaced
>>> with a design that does async connect() + timeouts.  That would be the
>>> pragmatic solution.
>>>       
It's right!
>> Assuming that consensus emerges that modifying shmux is the right
>> solution, is it so critical to have shmux in Solaris now that we can't
>> wait for it to be fixed before integrating?
>>     
>
>   
IMO, it should be acceptable to integrate the shmux as is for now, as it 
is useful to us after all(my daily work is mainly for nfs test, I always 
need to check/run something on many hosts, so this tool will be great 
help for me :) ), and we can update the package once the new version is 
available.
> As an aside from an observer, I notice that there are Solaris packages
> available from the shmux website. 
Yes, I ever downloaded and installed those packages on solaris directly, 
they all work like we build and install from the source codes.
> Doesn't it make more sense to ask the
> maintainer to submit shmux to the contrib repo?
>
>   
I'm not sure whether he would like to do. But anyway, I will send a mail 
to him to confirm. BTW, do you want the maintainer to submit the 
modified shmux based on our requirement instead of the current one?
> Based on the discussion here, right now, I doubt it meets the integration
> standards for inclusion in the WOS (as it stands right now; I don't want
> to downplay the usefulness the tool itself might have).
>
> Joep
>   
Thanks all again for focusing on this issue! Please continue to send out 
any ideas you have to push this program.

Thanks,
Lily

From carlsonj@phorcys.east.sun.com Wed Mar 11 06:47:39 2009
Received: from sunmail3mpk.sfbay.sun.com (sunmail3mpk.SFBay.Sun.COM [129.146.11.52])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2BDldcR029096
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Mar 2009 06:47:39 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail3mpk.sfbay.sun.com (8.13.7+Sun/8.13.7/ENSMAIL,v2.2) with ESMTP id n2BDlM7a014350;
	Wed, 11 Mar 2009 06:47:35 -0700 (PDT)
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGC00H3DGZA1J00@brm-avmta-1.central.sun.com>; Wed,
 11 Mar 2009 07:47:34 -0600 (MDT)
Received: from phorcys.east.sun.com ([129.148.174.143])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGC003INGZ9PAA0@brm-avmta-1.central.sun.com>; Wed,
 11 Mar 2009 07:47:33 -0600 (MDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n2BDlUd2024342; Wed,
 11 Mar 2009 09:47:30 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n2BDlTrs024339; Wed,
 11 Mar 2009 09:47:29 -0400 (EDT)
Date: Wed, 11 Mar 2009 09:47:29 -0400
From: James Carlson <james.d.carlson@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <49B7321C.5070406@sun.com>
To: Lily.Li@sun.com
Cc: Joep Vesseur <Joep.Vesseur@sun.com>, Scott Rotondo <Scott.Rotondo@sun.com>,
        Nicolas Williams <Nicolas.Williams@sun.com>,
        Gary Winiger <gww@eng.sun.com>, jw137282@sac.sfbay.sun.com,
        PSARC-ext@sun.com
Message-id: <18871.49393.628597.852188@gargle.gargle.HOWL>
MIME-version: 1.0
X-Mailer: VM 7.01 under Emacs 21.3.1
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL> <20090310220659.GG9992@Sun.COM>
 <49B6F722.3010700@sun.com> <49B70570.1050909@Sun.COM>
 <49B7321C.5070406@sun.com>
Status: RO
Content-Length: 3615

Lily Li writes:
> Joep Vesseur wrote:
> > On 03/11/09 00:26, Scott Rotondo wrote:
> >   
> >> Nicolas Williams wrote:
> >>     
> >>> But the i-team here might not have the resources to fix shmux to do the
> >>> right thing.  If we agree that not allowing normal users to use fping
> >>> was a mistake, then shmux could be integrated as is with a bug opened in
> >>> the upstream community to have the -p option deprecated/replaced
> >>> with a design that does async connect() + timeouts.  That would be the
> >>> pragmatic solution.
> >>>       
> It's right!

I agree that simply redefining the "-p" and "-P" options to do the
Right (and obvious) Thing with async connect() is likely the best
answer.

The stumbling block for me is proceeding with integration even though
we _know_ that some of the documented features are broken-as-designed
on OpenSolaris, and that by shipping this we're just letting customers
walk into the problem at their convenience.

Doing this provides OpenSolaris with a competitive disadvantage when
compared to Linux.  Users will discover that we ship shmux, but it's
not as good as on Linux, because some of the features don't work on
OpenSolaris but do work on Linux.

> IMO, it should be acceptable to integrate the shmux as is for now, as it 
> is useful to us after all(my daily work is mainly for nfs test, I always 
> need to check/run something on many hosts, so this tool will be great 
> help for me :) ), and we can update the package once the new version is 
> available.

Partially functional is great for open source projects.  I'm not
convinced that it's right for OpenSolaris.

> I'm not sure whether he would like to do. But anyway, I will send a mail 
> to him to confirm. BTW, do you want the maintainer to submit the 
> modified shmux based on our requirement instead of the current one?

If the upstream maintainer won't do it (or, in the worst case, doesn't
agree with the change), and if we really want this utility to be part
of OpenSolaris, then we'll need to do it.

As we've come to a stumbling block here, and I haven't been able to
convince myself that shipping something with known architectural
defects that break the project's documented features but something
that works for some usage cases is "good enough," I think I can offer
a solution of sorts.

That solution would be to derail this fast-track, offer the following
TCR, and then vote to approve (I hope we can address this in ARC
business today):

	TCR 1.	The utility must be modified to remove its dependence
		on fping and should (to preserve the user interface)
		re-use the existing "-p" and "-P" options to control
		the behavior of connect(), using non-blocking
		sockets, poll/select for write, and short timers.

That way, we finish the back-and-forth discussion, we get a clear
decision from the other ARC members (both on the imposition of the TCR
and on the approval of the project) so that it's not just me arguing
this point, and the project team can then decide how to go forward; it
can either seek to have the ARC overridden or find some means to
comply.

Since I think the discussion has gone on long enough, I'll derail.  I
offer the TCR above, and now's the point for other ARC members to chip
in: do you agree with the TCR?  (Should it be a TCA instead, or
perhaps reworded?)  If you do agree with the TCR, would you be ready
to vote on the project?

-- 
James Carlson, Solaris Networking              <james.d.carlson@sun.com>
Sun Microsystems / 35 Network Drive        71.232W   Vox +1 781 442 2084
MS UBUR02-212 / Burlington MA 01803-2757   42.496N   Fax +1 781 442 1677

From Darren.Moffat@sun.com Wed Mar 11 06:57:03 2009
Received: from sunmail5.uk.sun.com (sunmail5.UK.Sun.COM [129.156.85.165])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2BDv2SG029664
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 11 Mar 2009 06:57:03 -0700 (PDT)
Received: from brm-avmta-1.central.sun.com (brm-avmta-1.Central.Sun.COM [129.147.4.11])
	by sunmail5.uk.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n2BDuksB015753
	for <@sunmail2sca.sfbay.sun.com:PSARC-ext@sun.com>; Wed, 11 Mar 2009 13:57:02 GMT
Received: from pmxchannel-daemon.brm-avmta-1.central.sun.com by
 brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 id <0KGC00H13HEZVK00@brm-avmta-1.central.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Mar 2009 07:56:59 -0600 (MDT)
Received: from gmp-eb-inf-1.sun.com ([192.18.6.21])
 by brm-avmta-1.central.sun.com
 (Sun Java System Messaging Server 6.2-3.04 (built Jul 15 2005))
 with ESMTP id <0KGC003M7HEYPXB0@brm-avmta-1.central.sun.com> for
 PSARC-ext@sun.com (ORCPT PSARC-ext@sun.com); Wed,
 11 Mar 2009 07:56:59 -0600 (MDT)
Received: from fe-emea-10.sun.com (gmp-eb-lb-2-fe3.eu.sun.com [192.18.6.12])
	by gmp-eb-inf-1.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2BDuwDU010110	for
 <PSARC-ext@sun.com>; Wed, 11 Mar 2009 13:56:58 +0000 (GMT)
Received: from conversion-daemon.fe-emea-10.sun.com by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 id <0KGC00400GQEPZ00@fe-emea-10.sun.com> for PSARC-ext@sun.com
 (ORCPT PSARC-ext@sun.com); Wed, 11 Mar 2009 13:56:58 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-10.sun.com
 (Sun Java(tm) System Messaging Server 7.0-3.01 64bit (built Dec 23 2008))
 with ESMTPSA id <0KGC00A4EHEPQ400@fe-emea-10.sun.com>; Wed,
 11 Mar 2009 13:56:50 +0000 (GMT)
Date: Wed, 11 Mar 2009 13:56:49 +0000
From: Darren J Moffat <Darren.Moffat@sun.com>
Subject: Re: shmux [PSARC/2009/150 FastTrack timeout 03/10/2009]
In-reply-to: <18871.49393.628597.852188@gargle.gargle.HOWL>
Sender: Darren.Moffat@sun.com
To: James Carlson <James.D.Carlson@sun.com>
Cc: Lily.Li@sun.com, Joep Vesseur <Joep.Vesseur@sun.com>,
        Gary Winiger <gww@eng.sun.com>, PSARC-ext@sun.com,
        Scott Rotondo <Scott.Rotondo@sun.com>, jw137282@sac.sfbay.sun.com
Message-id: <49B7C321.5090407@Sun.COM>
MIME-version: 1.0
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
X-PMX-Version: 5.4.1.325704
References: <200903061516.n26FG1u8026981@marduk.eng.sun.com>
 <18865.17278.944209.539995@gargle.gargle.HOWL> <49B50109.6070504@sun.com>
 <18869.6298.983581.170660@gargle.gargle.HOWL> <49B5F690.4050705@sun.com>
 <18870.57729.900067.812592@gargle.gargle.HOWL> <20090310220659.GG9992@Sun.COM>
 <49B6F722.3010700@sun.com> <49B70570.1050909@Sun.COM>
 <49B7321C.5070406@sun.com> <18871.49393.628597.852188@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 1693

James Carlson wrote:
> That solution would be to derail this fast-track, offer the following
> TCR, and then vote to approve (I hope we can address this in ARC
> business today):
> 
> 	TCR 1.	The utility must be modified to remove its dependence
> 		on fping and should (to preserve the user interface)
> 		re-use the existing "-p" and "-P" options to control
> 		the behavior of connect(), using non-blocking
> 		sockets, poll/select for write, and short timers.
> 
> That way, we finish the back-and-forth discussion, we get a clear
> decision from the other ARC members (both on the imposition of the TCR
> and on the approval of the project) so that it's not just me arguing
> this point, and the project team can then decide how to go forward; it
> can either seek to have the ARC overridden or find some means to
> comply.
> 
> Since I think the discussion has gone on long enough, I'll derail.  I
> offer the TCR above, and now's the point for other ARC members to chip
> in: do you agree with the TCR?  (Should it be a TCA instead, or
> perhaps reworded?)  If you do agree with the TCR, would you be ready
> to vote on the project?

I won't be at the meeting today (since it is a "late" one and that means 
very late for me in the UK).

I agree with Jim's position and agree with the wording of the TCR.  I 
vote to approve with the TCR.

I'd also suggest (though not require) some "boilerplate" text in the 
opinion reminding people that "porting" external to OpenSolaris open 
source sometimes requires actual porting work to make the component 
being imported work instead of just a compile as is.  Importing external 
open source is free like a puppy is free.

-- 
Darren J Moffat

From carlsonj@phorcys.east.sun.com Wed Mar 25 14:19:30 2009
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2PLJUqj028202
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 25 Mar 2009 14:19:30 -0700 (PDT)
Received: from phorcys.east.sun.com (localhost [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n2PLJGEB017626
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 25 Mar 2009 17:19:16 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n2PLJGV4017623;
	Wed, 25 Mar 2009 17:19:16 -0400 (EDT)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18890.40916.294628.27661@gargle.gargle.HOWL>
Date: Wed, 25 Mar 2009 17:19:16 -0400
From: James Carlson <james.d.carlson@sun.com>
To: psarc-ext@sac.sfbay.sun.com
Subject: Opinion for review: 2009/150 shmux
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 4584

ARC members: please review and submit any comments by 04/01/2009.



 sun
   microsystems              Systems Architecture Committee

_________________________________________________________________

Subject:       shmux

Submitted by:  Lily Li

File:          PSARC/2009/150/opinion.ms

Date:          March 11th, 2009

Committee:     James D. Carlson, Kais Belgaied,  Mark  Carl-
               son,  Richard  Matthews, Darren Moffat, Glenn
               Skinner.

Product Approval Committee:

               Solaris PAC
               solaris-pac@sun.com

1.  Summary

This project proposes to integrate "shmux," an  open  source
utility that automates remote shell access, into Solaris and
OpenSolaris.

2.  Decision & Precedence Information

The project is approved as specified in reference  [1],  but
as  modified  by  the  required  technical changes listed in
Appendix A below.

The project may deliver in a patch/micro release of  Solaris
or OpenSolaris via the SFW consolidation.

3.  Interfaces

The project exports the following interfaces.

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|/usr/bin/shmux|  Uncommitted   |  executable location  |
|shmux         |  Uncommitted   |  command line syntax  |
|commands      |  Volatile      |  interactive mode     |
|exit codes    |  Uncommitted   |                       |
|SHMUX_*       |  Uncommitted   |  environment variables|
|SUNWshmux     |  Uncommitted   |  package name         |
|______________|________________|_______________________|

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 2 -

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|______________|________________|_______________________|

4.  Opinion

The only substantive issue discussed during ARC  review  was
in  regard  to the -p and -P command line options, described
in reference [2].  These  options  are  designed  to  invoke
fping to check for server liveness before attempting connec-
tion.

This design leads to a list of problems.   First,  fping  on
Solaris  cannot  be  used  by  an  ordinary user, because it
requires elevated privileges to use raw sockets.  This means
that  it would not work right by default on Solaris or Open-
Solaris,  even  though  the  same  option  presently   works
correctly on Linux.

This issue led to a discussion of other problems related  to
this  design.   The  success of "ping" (ICMP) bears no rela-
tionship to the success  of  a  subsequent  TCP  connection.
They are different protocols.  Moreover, one can easily test
the success of TCP connections by using non-blocking sockets
and  short  timers.   The  project team did not dispute this
contention and this discussion led to the  technical  change
required, described below.

An ARC member suggested on the mailing list that  advice  be
sent  to  the  management teams regarding the cost of "free"
software, which led to the advice given in section 6 below.

5.  Minority Opinion(s)

None

6.  Advisory Information

The Solaris PAC and the management of project teams involved
in  importing  open  source software are reminded that "free
software" is sometimes "free" in the same  way  a  puppy  is
free.  It may not be sufficient to import the package as-is.

7.  Appendices

7.1.  Appendix A: Technical Changes Required

     1.   The  utility  must  be  modified  to  remove   its

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 3 -

          dependence  on  fping  and should (to preserve the
          user interface) re-use the existing "-p" and  "-P"
          options  to  control  the  behavior  of connect(),
          using non-blocking sockets, poll/select for write,
          and short timers as necessary.

7.2.  Appendix B: Technical Changes Advised

None

7.3.  Appendix C: Reference Material

Unless stated otherwise, path names are relative to the case
directory PSARC/2009/150.

1.   Project proposal
     File:  proposal.txt

2.   shmux draft man page
     File:  materials/shmux.1.txt

PSARC/2009/150               Copyright 2009 Sun Microsystems


From Darren.Moffat@Sun.COM Thu Mar 26 02:21:15 2009
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n2Q9LEX8000383
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 26 Mar 2009 02:21:14 -0700 (PDT)
Received: from gmp-eb-inf-2.sun.com (gmp-eb-inf-2.EU.Sun.COM [192.18.6.24])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n2Q9LEvU021304
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 26 Mar 2009 02:21:14 -0700 (PDT)
Received: from fe-emea-09.sun.com (gmp-eb-lb-1-fe3.eu.sun.com [192.18.6.10])
	by gmp-eb-inf-2.sun.com (8.13.7+Sun/8.12.9) with ESMTP id n2Q9L8BD028703
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 26 Mar 2009 09:21:08 GMT
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Received: from conversion-daemon.fe-emea-09.sun.com by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KH300F00VZQCH00@fe-emea-09.sun.com> for psarc-ext@sac.sfbay.sun.com; Thu,
 26 Mar 2009 09:21:08 +0000 (GMT)
Received: from [129.156.173.21] ([unknown] [129.156.173.21])
 by fe-emea-09.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 with ESMTPSA id <0KH300ALUWMQVV20@fe-emea-09.sun.com> for
 psarc-ext@sac.sfbay.sun.com; Thu, 26 Mar 2009 09:20:52 +0000 (GMT)
Date: Thu, 26 Mar 2009 09:20:50 +0000
From: Darren J Moffat <Darren.Moffat@Sun.COM>
Subject: Re: Opinion for review: 2009/150 shmux
In-reply-to: <18890.40916.294628.27661@gargle.gargle.HOWL>
Sender: Darren.Moffat@Sun.COM
To: James Carlson <James.D.Carlson@Sun.COM>
Cc: psarc-ext@sac.sfbay.sun.com
Message-id: <49CB48F2.4030201@Sun.COM>
References: <18890.40916.294628.27661@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.18 (X11/20081201)
Status: RO
Content-Length: 219

James Carlson wrote:
> ARC members: please review and submit any comments by 04/01/2009.

I'm happy with the opinion text, it accurately reflects how I viewed the 
discussion and the resulting TCR.

-- 
Darren J Moffat

From Lily.Li@Sun.COM Wed Apr  1 20:41:11 2009
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n323fARQ001325
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 1 Apr 2009 20:41:10 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n323f9AG030371
	for <psarc-ext@sac.sfbay.sun.com>; Wed, 1 Apr 2009 20:41:10 -0700 (PDT)
Received: from fe-apac-05.sun.com (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n323f3K2010560
	for <psarc-ext@sac.sfbay.sun.com>; Thu, 2 Apr 2009 03:41:04 GMT
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KHG00I00F73D800@mail-apac.sun.com> for psarc-ext@sac.sfbay.sun.com; Thu,
 02 Apr 2009 11:41:03 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.10])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KHG00B37FKEX880@mail-apac.sun.com> for
 psarc-ext@sac.sfbay.sun.com; Thu, 02 Apr 2009 11:41:03 +0800 (SGT)
Date: Thu, 02 Apr 2009 11:40:59 +0800
From: Lily Li <Lily.Li@Sun.COM>
Subject: Re: Opinion for review: 2009/150 shmux
In-reply-to: <49CB48F2.4030201@Sun.COM>
Sender: Lily.Li@Sun.COM
To: psarc-ext@sac.sfbay.sun.com
Cc: Darren J Moffat <Darren.Moffat@Sun.COM>,
        James Carlson <James.D.Carlson@Sun.COM>,
        Henry Deng - Sun Microsystems - Beijing China <Henry.Deng@Sun.COM>,
        Jim Walker <James.Walker@Sun.COM>
Reply-to: Lily.Li@Sun.COM
Message-id: <49D433CB.9040502@sun.com>
Organization: SUN China
References: <18890.40916.294628.27661@gargle.gargle.HOWL>
 <49CB48F2.4030201@Sun.COM>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 777

Hi All,

Does anyone have more comments on this?

Now I agree to make a patch to shmux package for doing what is being 
asked in the Technical Change Request.

Jim Walker, when the code changes is prepared and package is tested, is 
it correct that I only need to back to the "7. I-Team Code Review" step 
of the package porting process, then do ARC review again? Whether the 
code review request need to be sent to any alias else except 
ospkgporting@sun.com and sfwnv-discuss@opensolaris.org?

Anything else, please let me know.

Thanks,
Lily

Darren J Moffat wrote:
> James Carlson wrote:
>> ARC members: please review and submit any comments by 04/01/2009.
>
> I'm happy with the opinion text, it accurately reflects how I viewed 
> the discussion and the resulting TCR.
>

From sac-owner Fri Apr 10 11:57:12 2009
Received: from dm-east-01.east.sun.com (dm-east-01.East.Sun.COM [129.148.9.192])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3AIvCCZ002647
	for <sac-review@sac.sfbay.sun.com>; Fri, 10 Apr 2009 11:57:12 -0700 (PDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-01.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3AIvCZU002625
	for <sac-review@sac.sfbay.sun.com>; Fri, 10 Apr 2009 14:57:12 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n3AIuj02007004
	for <sac-review@sac.sfbay.sun.com>; Fri, 10 Apr 2009 14:56:45 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n3AIujeI007001;
	Fri, 10 Apr 2009 14:56:45 -0400 (EDT)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18911.38509.420195.706131@gargle.gargle.HOWL>
Date: Fri, 10 Apr 2009 14:56:45 -0400
From: James Carlson <james.d.carlson@sun.com>
To: sac-review@sac.sfbay.sun.com
Subject: Opinion for review: PSARC 2009/150 shmux
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 4582

SAC members: please review and submit any comments by 4/17/2009.


 sun
   microsystems              Systems Architecture Committee

_________________________________________________________________

Subject:       shmux

Submitted by:  Lily Li

File:          PSARC/2009/150/opinion.ms

Date:          March 11th, 2009

Committee:     James D. Carlson, Kais Belgaied,  Mark  Carl-
               son,  Richard  Matthews, Darren Moffat, Glenn
               Skinner.

Product Approval Committee:

               Solaris PAC
               solaris-pac@sun.com

1.  Summary

This project proposes to integrate "shmux," an  open  source
utility that automates remote shell access, into Solaris and
OpenSolaris.

2.  Decision & Precedence Information

The project is approved as specified in reference  [1],  but
as  modified  by  the  required  technical changes listed in
Appendix A below.

The project may deliver in a patch/micro release of  Solaris
or OpenSolaris via the SFW consolidation.

3.  Interfaces

The project exports the following interfaces.

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|/usr/bin/shmux|  Uncommitted   |  executable location  |
|shmux         |  Uncommitted   |  command line syntax  |
|commands      |  Volatile      |  interactive mode     |
|exit codes    |  Uncommitted   |                       |
|SHMUX_*       |  Uncommitted   |  environment variables|
|SUNWshmux     |  Uncommitted   |  package name         |
|______________|________________|_______________________|

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 2 -

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|______________|________________|_______________________|

4.  Opinion

The only substantive issue discussed during ARC  review  was
in  regard  to the -p and -P command line options, described
in reference [2].  These  options  are  designed  to  invoke
fping to check for server liveness before attempting connec-
tion.

This design leads to a list of problems.   First,  fping  on
Solaris  cannot  be  used  by  an  ordinary user, because it
requires elevated privileges to use raw sockets.  This means
that  it would not work right by default on Solaris or Open-
Solaris,  even  though  the  same  option  presently   works
correctly on Linux.

This issue led to a discussion of other problems related  to
this  design.   The  success of "ping" (ICMP) bears no rela-
tionship to the success  of  a  subsequent  TCP  connection.
They are different protocols.  Moreover, one can easily test
the success of TCP connections by using non-blocking sockets
and  short  timers.   The  project team did not dispute this
contention and this discussion led to the  technical  change
required, described below.

An ARC member suggested on the mailing list that  advice  be
sent  to  the  management teams regarding the cost of "free"
software, which led to the advice given in section 6 below.

5.  Minority Opinion(s)

None

6.  Advisory Information

The Solaris PAC and the management of project teams involved
in  importing  open  source software are reminded that "free
software" is sometimes "free" in the same  way  a  puppy  is
free.  It may not be sufficient to import the package as-is.

7.  Appendices

7.1.  Appendix A: Technical Changes Required

     1.   The  utility  must  be  modified  to  remove   its

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 3 -

          dependence  on  fping  and should (to preserve the
          user interface) re-use the existing "-p" and  "-P"
          options  to  control  the  behavior  of connect(),
          using non-blocking sockets, poll/select for write,
          and short timers as necessary.

7.2.  Appendix B: Technical Changes Advised

None

7.3.  Appendix C: Reference Material

Unless stated otherwise, path names are relative to the case
directory PSARC/2009/150.

1.   Project proposal
     File:  proposal.txt

2.   shmux draft man page
     File:  materials/shmux.1.txt

PSARC/2009/150               Copyright 2009 Sun Microsystems


From sac-owner Fri Apr 17 01:19:35 2009
Received: from dm-sfbay-01.sfbay.sun.com (dm-sfbay-01.SFBay.Sun.COM [129.145.155.118])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n3H8JZUU008110
	for <sac-review@sac.sfbay.sun.com>; Fri, 17 Apr 2009 01:19:35 -0700 (PDT)
Received: from sineb-mail-2.sun.com ([192.18.19.7])
	by dm-sfbay-01.sfbay.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n3H8JYXD005132
	for <sac-review@sac.sfbay.sun.com>; Fri, 17 Apr 2009 01:19:35 -0700 (PDT)
Received: from fe-apac-05.sun.com (fe-apac-05.sun.com [192.18.19.176] (may be forged))
	by sineb-mail-2.sun.com (8.13.6+Sun/8.12.9) with ESMTP id n3H8JTqX020305
	for <sac-review@sac.sfbay.sun.com>; Fri, 17 Apr 2009 08:19:29 GMT
MIME-version: 1.0
Content-transfer-encoding: 7BIT
Content-type: text/plain; format=flowed; charset=ISO-8859-1
Received: from conversion-daemon.mail-apac.sun.com by mail-apac.sun.com
 (Sun Java(tm) System Messaging Server 7.0-5.01 64bit (built Feb 19 2009))
 id <0KI800000KBYW700@mail-apac.sun.com> for sac-review@sac.sfbay.sun.com; Fri,
 17 Apr 2009 16:19:29 +0800 (SGT)
Received: from xiaobai.local ([unknown] [129.150.144.16])
 by mail-apac.sun.com (Sun Java(tm) System Messaging Server 7.0-5.01 64bit
 (built Feb 19 2009)) with ESMTPSA id <0KI8005IYKGF58D0@mail-apac.sun.com> for
 sac-review@sac.sfbay.sun.com; Fri, 17 Apr 2009 16:19:29 +0800 (SGT)
Date: Fri, 17 Apr 2009 16:19:23 +0800
From: Lily Li <Lily.Li@Sun.COM>
Subject: Re: Opinion for review: PSARC 2009/150 shmux
In-reply-to: <18911.38509.420195.706131@gargle.gargle.HOWL>
Sender: Lily.Li@Sun.COM
To: James Carlson <James.D.Carlson@Sun.COM>
Cc: sac-review@sac.sfbay.sun.com, Jim Walker <James.Walker@Sun.COM>
Reply-to: Lily.Li@Sun.COM
Message-id: <49E83B8B.4080703@sun.com>
Organization: SUN China
References: <18911.38509.420195.706131@gargle.gargle.HOWL>
User-Agent: Thunderbird 2.0.0.6 (Macintosh/20070728)
Status: RO
Content-Length: 4933

Hi All,

The timeout for this review is approaching. Any comments? Many Thanks!

Lily

James Carlson wrote:
> SAC members: please review and submit any comments by 4/17/2009.
>
>
>  sun
>    microsystems              Systems Architecture Committee
>
> _________________________________________________________________
>
> Subject:       shmux
>
> Submitted by:  Lily Li
>
> File:          PSARC/2009/150/opinion.ms
>
> Date:          March 11th, 2009
>
> Committee:     James D. Carlson, Kais Belgaied,  Mark  Carl-
>                son,  Richard  Matthews, Darren Moffat, Glenn
>                Skinner.
>
> Product Approval Committee:
>
>                Solaris PAC
>                solaris-pac@sun.com
>
> 1.  Summary
>
> This project proposes to integrate "shmux," an  open  source
> utility that automates remote shell access, into Solaris and
> OpenSolaris.
>
> 2.  Decision & Precedence Information
>
> The project is approved as specified in reference  [1],  but
> as  modified  by  the  required  technical changes listed in
> Appendix A below.
>
> The project may deliver in a patch/micro release of  Solaris
> or OpenSolaris via the SFW consolidation.
>
> 3.  Interfaces
>
> The project exports the following interfaces.
>
> _________________________________________________________
> |                  Interfaces Exported                  |
> |______________|________________|_______________________|
> |Interface     |  Classification|  Comments             |
> |______________|________________|_______________________|
> |/usr/bin/shmux|  Uncommitted   |  executable location  |
> |shmux         |  Uncommitted   |  command line syntax  |
> |commands      |  Volatile      |  interactive mode     |
> |exit codes    |  Uncommitted   |                       |
> |SHMUX_*       |  Uncommitted   |  environment variables|
> |SUNWshmux     |  Uncommitted   |  package name         |
> |______________|________________|_______________________|
>
> PSARC/2009/150               Copyright 2009 Sun Microsystems
>
>                            - 2 -
>
> _________________________________________________________
> |                  Interfaces Exported                  |
> |______________|________________|_______________________|
> |Interface     |  Classification|  Comments             |
> |______________|________________|_______________________|
> |______________|________________|_______________________|
>
> 4.  Opinion
>
> The only substantive issue discussed during ARC  review  was
> in  regard  to the -p and -P command line options, described
> in reference [2].  These  options  are  designed  to  invoke
> fping to check for server liveness before attempting connec-
> tion.
>
> This design leads to a list of problems.   First,  fping  on
> Solaris  cannot  be  used  by  an  ordinary user, because it
> requires elevated privileges to use raw sockets.  This means
> that  it would not work right by default on Solaris or Open-
> Solaris,  even  though  the  same  option  presently   works
> correctly on Linux.
>
> This issue led to a discussion of other problems related  to
> this  design.   The  success of "ping" (ICMP) bears no rela-
> tionship to the success  of  a  subsequent  TCP  connection.
> They are different protocols.  Moreover, one can easily test
> the success of TCP connections by using non-blocking sockets
> and  short  timers.   The  project team did not dispute this
> contention and this discussion led to the  technical  change
> required, described below.
>
> An ARC member suggested on the mailing list that  advice  be
> sent  to  the  management teams regarding the cost of "free"
> software, which led to the advice given in section 6 below.
>
> 5.  Minority Opinion(s)
>
> None
>
> 6.  Advisory Information
>
> The Solaris PAC and the management of project teams involved
> in  importing  open  source software are reminded that "free
> software" is sometimes "free" in the same  way  a  puppy  is
> free.  It may not be sufficient to import the package as-is.
>
> 7.  Appendices
>
> 7.1.  Appendix A: Technical Changes Required
>
>      1.   The  utility  must  be  modified  to  remove   its
>
> PSARC/2009/150               Copyright 2009 Sun Microsystems
>
>                            - 3 -
>
>           dependence  on  fping  and should (to preserve the
>           user interface) re-use the existing "-p" and  "-P"
>           options  to  control  the  behavior  of connect(),
>           using non-blocking sockets, poll/select for write,
>           and short timers as necessary.
>
> 7.2.  Appendix B: Technical Changes Advised
>
> None
>
> 7.3.  Appendix C: Reference Material
>
> Unless stated otherwise, path names are relative to the case
> directory PSARC/2009/150.
>
> 1.   Project proposal
>      File:  proposal.txt
>
> 2.   shmux draft man page
>      File:  materials/shmux.1.txt
>
> PSARC/2009/150               Copyright 2009 Sun Microsystems
>
>
>   

From sac-owner Mon May  4 11:43:26 2009
Received: from dm-east-02.east.sun.com (dm-east-02.East.Sun.COM [129.148.13.5])
	by sac.sfbay.sun.com (8.13.8+Sun/8.13.8) with ESMTP id n44IhPrA022559
	for <sac-opinion@sac.sfbay.sun.com>; Mon, 4 May 2009 11:43:25 -0700 (PDT)
Received: from phorcys.east.sun.com (phorcys.East.Sun.COM [129.148.174.143])
	by dm-east-02.east.sun.com (8.13.8+Sun/8.13.8/ENSMAIL,v2.2) with ESMTP id n44IhO3p057038;
	Mon, 4 May 2009 14:43:24 -0400 (EDT)
Received: from phorcys.east.sun.com (phorcys.local [127.0.0.1])
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3) with ESMTP id n44IgcmB016276;
	Mon, 4 May 2009 14:42:38 -0400 (EDT)
Received: (from carlsonj@localhost)
	by phorcys.east.sun.com (8.14.3+Sun/8.14.3/Submit) id n44IgcJU016273;
	Mon, 4 May 2009 14:42:38 -0400 (EDT)
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Transfer-Encoding: 7bit
Message-ID: <18943.14110.791012.702132@gargle.gargle.HOWL>
Date: Mon, 4 May 2009 14:42:38 -0400
From: James Carlson <james.d.carlson@sun.com>
To: sac-opinion@sac.sfbay.sun.com
cc: solaris-pac@sun.com
Subject: Opinion: 2009/150 shmux
X-Mailer: VM 7.01 under Emacs 21.3.1
Status: RO
Content-Length: 4516


 sun
   microsystems              Systems Architecture Committee

_________________________________________________________________

Subject:       shmux

Submitted by:  Lily Li

File:          PSARC/2009/150/opinion.ms

Date:          March 11th, 2009

Committee:     James D. Carlson, Kais Belgaied,  Mark  Carl-
               son,  Richard  Matthews, Darren Moffat, Glenn
               Skinner.

Product Approval Committee:

               Solaris PAC
               solaris-pac@sun.com

1.  Summary

This project proposes to integrate "shmux," an  open  source
utility that automates remote shell access, into Solaris and
OpenSolaris.

2.  Decision & Precedence Information

The project is approved as specified in reference  [1],  but
as  modified  by  the  required  technical changes listed in
Appendix A below.

The project may deliver in a patch/micro release of  Solaris
or OpenSolaris via the SFW consolidation.

3.  Interfaces

The project exports the following interfaces.

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|/usr/bin/shmux|  Uncommitted   |  executable location  |
|shmux         |  Uncommitted   |  command line syntax  |
|commands      |  Volatile      |  interactive mode     |
|exit codes    |  Uncommitted   |                       |
|SHMUX_*       |  Uncommitted   |  environment variables|
|SUNWshmux     |  Uncommitted   |  package name         |
|______________|________________|_______________________|

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 2 -

_________________________________________________________
|                  Interfaces Exported                  |
|______________|________________|_______________________|
|Interface     |  Classification|  Comments             |
|______________|________________|_______________________|
|______________|________________|_______________________|

4.  Opinion

The only substantive issue discussed during ARC  review  was
in  regard  to the -p and -P command line options, described
in reference [2].  These  options  are  designed  to  invoke
fping to check for server liveness before attempting connec-
tion.

This design leads to a list of problems.   First,  fping  on
Solaris  cannot  be  used  by  an  ordinary user, because it
requires elevated privileges to use raw sockets.  This means
that  it would not work right by default on Solaris or Open-
Solaris,  even  though  the  same  option  presently   works
correctly on Linux.

This issue led to a discussion of other problems related  to
this  design.   The  success of "ping" (ICMP) bears no rela-
tionship to the success  of  a  subsequent  TCP  connection.
They are different protocols.  Moreover, one can easily test
the success of TCP connections by using non-blocking sockets
and  short  timers.   The  project team did not dispute this
contention and this discussion led to the  technical  change
required, described below.

An ARC member suggested on the mailing list that  advice  be
sent  to  the  management teams regarding the cost of "free"
software, which led to the advice given in section 6 below.

5.  Minority Opinion(s)

None

6.  Advisory Information

The Solaris PAC and the management of project teams involved
in  importing  open  source software are reminded that "free
software" is sometimes "free" in the same  way  a  puppy  is
free.  It may not be sufficient to import the package as-is.

7.  Appendices

7.1.  Appendix A: Technical Changes Required

     1.   The  utility  must  be  modified  to  remove   its

PSARC/2009/150               Copyright 2009 Sun Microsystems

                           - 3 -

          dependence  on  fping  and should (to preserve the
          user interface) re-use the existing "-p" and  "-P"
          options  to  control  the  behavior  of connect(),
          using non-blocking sockets, poll/select for write,
          and short timers as necessary.

7.2.  Appendix B: Technical Changes Advised

None

7.3.  Appendix C: Reference Material

Unless stated otherwise, path names are relative to the case
directory PSARC/2009/150.

1.   Project proposal
     File:  proposal.txt

2.   shmux draft man page
     File:  materials/shmux.1.txt

PSARC/2009/150               Copyright 2009 Sun Microsystems


