Monday, December 24, 2012

Linux Server Performance Tuning: Reducing Disk I/O and System Load

When optimizing a high-traffic dedicated Linux server, disk I/O bottlenecks are often the primary cause of sluggish response times and elevated load averages. Here are several practical server-tuning techniques I applied to a heavily loaded production server, resulting in a dramatic reduction in disk I/O and much faster throughput.

Key Optimizations: RAM-backed /tmp mount • Dedicated SSD for MySQL data • FastCGI process management with Nginx + PHP-FPM

1. Mount /tmp as a Ramdisk (tmpfs)

Many web stacks heavily utilize /tmp for transient disk writes:

  • PHP Sessions: Default PHP configurations store active session files in /tmp (session.save_path).
  • MySQL Temporary Tables: Heavy queries with extensive JOIN or GROUP BY clauses frequently write temporary on-disk tables to /tmp (verify your path using mysqladmin variables | grep tmpdir).

Mounting /tmp directly into RAM eliminates spinning disk access for these operations. Add the following entry to your /etc/fstab:

none /tmp tmpfs nr_inodes=200k,mode=01777,nosuid,nodev 0 0

Remount or apply without rebooting:

mount -o remount /tmp

2. Isolate MySQL Datadir to High-Performance Storage (SSD)

Moving the MySQL database directory (/var/lib/mysql) to dedicated high-speed SSD storage removes the database write bottleneck and dramatically lowers IO wait times (%iowait) during peak traffic.

3. Adopt Nginx with PHP-FPM

Switching from Apache's traditional prefork MPM / mod_php handler to Nginx + PHP-FPM significantly cuts memory footprint per connection, handles concurrency gracefully, and frees up system resources for database caching.

Sunday, December 23, 2012

Hardening Web Servers: Nginx Symlink Protection and PHP-FPM Chroot Jails

Securing shared hosting environments and multi-tenant web servers requires preventing unauthorized symlink traversals and isolating application processes. Here are two powerful security features in Nginx and PHP-FPM that significantly harden your stack against cross-account directory traversal attacks.

Security Highlights: Prevent unauthorized symlink following in Nginx • Isolate execution pools in dedicated chroot jails with required pseudo-devices

1. Restricting Symlink Traversal in Nginx

By default, Nginx follows symbolic links without verifying ownership. The disable_symlinks directive allows you to strictly control link traversal:

# Allowed options: off | on | if_not_owner
disable_symlinks if_not_owner;

When set to if_not_owner, Nginx verifies that the symlink and the target file/directory belong to the same owner, effectively blocking unauthorized access to system files or other users' web roots.

2. PHP-FPM Chroot Jails

To provide true isolation, you can lock each PHP-FPM worker pool into its own chroot directory. A quick way to bootstrap a clean environment is by extracting a minimal OS template (such as an OpenVZ minimal template matching your host distribution) into the jail root.

Creating Essential Device Nodes in the Jail

For PHP and system libraries to function correctly (especially DNS resolution, random entropy, and error logging), create the necessary character devices inside the jail directory:

cd /path/to/jail
mkdir -p dev etc usr/share/zoneinfo

mknod -m 666 dev/null c 1 3
mknod -m 666 dev/zero c 1 5
mknod -m 666 dev/random c 1 8
mknod -m 666 dev/urandom c 1 9

Also copy /etc/resolv.conf and /etc/hosts into the jail's etc/ folder so PHP can perform external network queries and DNS resolution.

Friday, December 14, 2012

How to Install Wine with MS Visual C++ and Visual Basic Runtimes on Linux

Running specialized Windows desktop utilities (such as download managers like Orbit Downloader, HiDownload, or Net Transport) on Linux often requires essential Microsoft Visual C++ and Visual Basic runtime libraries that are not packaged by default in vanilla Wine.

Prerequisites: Wine installed via EPEL (CentOS / RHEL) or standard distribution repositories (Ubuntu / Debian).

Step-by-Step Installation

1. Install Cabextract

The cabextract utility is required by Winetricks to unpack Microsoft cabinet files:

# On Debian / Ubuntu:
sudo apt-get install cabextract -y

# On CentOS / RHEL (requires EPEL):
sudo yum install cabextract -y

2. Download and Run Winetricks

Fetch the official winetricks script and install the required core fonts, Visual C++ 6.0, and Visual Basic 6.0 runtimes:

wget https://raw.githubusercontent.com/Winetricks/winetricks/master/src/winetricks
chmod +x winetricks

sh winetricks corefonts vcrun6 vb6run

Once the runtime components are installed into your ~/.wine prefix, your Windows applications will initialize without missing DLL or runtime errors.

Thursday, September 6, 2012

How to Compile and Configure XCache 2.x on CentOS 6 for PHP Optimization

While Memcached is widely recommended for web caching, opcode caches like XCache often deliver significantly better speed improvements and lower load averages for PHP-driven CMS platforms like Joomla on high-traffic servers.

Environment: CentOS 6.x • PHP 5.x • XCache 2.0.1

1. Compile XCache from Source

Install the PHP development headers and compile the XCache module with the optimizer enabled:

yum install php-devel -y
cd /usr/src
wget http://xcache.lighttpd.net/pub/Releases/2.0.1/xcache-2.0.1.tar.gz
tar -zxf xcache-2.0.1.tar.gz
cd xcache-2.0.1
phpize --clean && phpize
./configure --enable-xcache --enable-xcache-optimizer
chown -R nobody /usr/src/xcache-2.0.1
sudo -u nobody make
make install

2. Configure /etc/php.d/xcache.ini

Create the XCache configuration file. Adjust the zend_extension path depending on whether your architecture is 64-bit (/usr/lib64/php/modules/xcache.so) or 32-bit (/usr/lib/php/modules/xcache.so):

cat << 'EOF' > /etc/php.d/xcache.ini
[xcache-common]
zend_extension=/usr/lib64/php/modules/xcache.so

[xcache.admin]
xcache.admin.enable_auth = Off

[xcache]
xcache.shm_scheme        = "mmap"
xcache.size              = 64M
xcache.count             = 1
xcache.slots             = 8K
xcache.ttl               = 0
xcache.gc_interval       = 0
xcache.var_size          = 32M
xcache.var_count         = 1
xcache.var_slots         = 8K
xcache.var_ttl           = 0
xcache.var_maxttl        = 0
xcache.var_gc_interval   = 300
xcache.readonly_protection = Off
xcache.mmap_path         = "/dev/zero"
xcache.coredump_directory = ""
xcache.experimental      = Off
xcache.cacher            = On
xcache.stat              = On
xcache.optimizer         = On

[xcache.coverager]
xcache.coverager         = Off
xcache.coveragedump_directory = ""
EOF

3. Enable the Web Administration Panel

Copy the administrative GUI into your web root to monitor memory usage and cache hit rates:

cp -R admin /var/www/html/xcache-admin
service httpd restart

You can access the admin dashboard at http://your-server-ip/xcache-admin/index.php to monitor real-time hit ratios.

Tuesday, September 4, 2012

How to Losslessly Optimize JPG, PNG, and GIF Images on Linux Using littleutils

Reducing image file sizes without sacrificing visual quality is one of the highest-impact optimizations for production websites. The littleutils package provides a collection of fast, lightweight command-line utilities—including opt-png, opt-jpg, and opt-gif—that losslessly compress images for faster web delivery.

Supported Utilities: opt-png (via pngcrush) • opt-jpg • opt-gif (via gifsicle)

1. Installing Required Prerequisites (CentOS / RHEL)

Install the necessary build tools and image compression libraries:

yum groupinstall "Development Tools" -y
yum install libpng-devel libjpeg-turbo-devel gifsicle -y

Compiling pngcrush:

cd /usr/src
wget https://sourceforge.net/projects/pmt/files/pngcrush/1.8.10/pngcrush-1.8.10.tar.gz
tar -zxf pngcrush-1.8.10.tar.gz
cd pngcrush-1.8.10
make
cp pngcrush /usr/local/bin/

2. Compiling littleutils

Download and build the littleutils suite:

cd /usr/src
wget http://downloads.sourceforge.net/project/littleutils/littleutils-source/1.0.27/littleutils-1.0.27.tar.bz2
tar -jxf littleutils-1.0.27.tar.bz2
cd littleutils-1.0.27
./configure --prefix=/usr/local
make
make install
make install-extra

3. Usage Examples

Optimize individual files or batch-compress entire image directories in place:

# Optimize a single PNG image losslessly
opt-png image.png

# Optimize a single JPEG image
opt-jpg photo.jpg

# Optimize all images in a directory
find /var/www/html/images/ -type f -name "*.png" -exec opt-png {} +
find /var/www/html/images/ -type f -name "*.jpg" -exec opt-jpg {} +

Sunday, August 5, 2012

How to Compile and Install the Latest Memcached from Source on Linux

Compiling Memcached directly from source allows you to take advantage of the latest concurrency fixes, memory management optimizations, and binary protocol improvements that may not yet be available in standard distribution package repositories.

Prerequisites: libevent and build development tools.

1. Install Dependencies

Memcached depends on the libevent event notification library:

# On CentOS / RHEL:
yum install libevent-devel gcc make -y

# On Debian / Ubuntu:
apt-get install libevent-dev build-essential -y

2. Download and Build Memcached

Fetch the latest release tarball and compile:

cd /usr/src
wget http://memcached.org/latest -O memcached-latest.tar.gz
tar -zxf memcached-latest.tar.gz
cd memcached-*
./configure --prefix=/usr --sysconfdir=/etc
make
make test
make install

3. Starting the Daemon

Launch Memcached as a non-privileged user (e.g. nobody) with 64MB memory limit listening on localhost:

memcached -d -u nobody -m 64 -p 11211 -l 127.0.0.1

Confirm the service is actively listening:

netstat -tulpn | grep 11211

Friday, August 3, 2012

How to Configure PHP-FPM and Apache 2.4 with mod_proxy_fcgi in Virtualmin (CentOS & Debian)

The Apache 2.4 series introduced mod_proxy_fcgi, enabling Apache to communicate directly with PHP-FPM via TCP/IP sockets without requiring older third-party modules like mod_fastcgi or mod_fcgid. This setup provides superior performance and memory isolation for multi-tenant web servers running Virtualmin.

Environment: Apache 2.4.x • PHP-FPM 5.x • Virtualmin • CentOS 6 / Debian 6

1. Installing PHP-FPM

Install the latest PHP-FPM packages using Remi (CentOS) or Dotdeb (Debian):

# On CentOS:
yum install php-fpm -y

# On Debian:
apt-get install php5-fpm -y

2. Compiling Apache 2.4 from Source (CentOS 6)

If your distribution does not ship Apache 2.4 in its default repositories, compile from source with event MPM and mod_proxy_fcgi:

yum install pcre-devel -y
cd /usr/src
wget https://archive.apache.org/dist/httpd/httpd-2.4.25.tar.bz2
wget https://archive.apache.org/dist/apr/apr-1.5.2.tar.bz2
wget https://archive.apache.org/dist/apr/apr-util-1.5.4.tar.bz2

tar -jxf httpd-2.4.25.tar.bz2
tar -jxf apr-1.5.2.tar.bz2
tar -jxf apr-util-1.5.4.tar.bz2

mv apr-1.5.2 httpd-2.4.25/srclib/apr
mv apr-util-1.5.4 httpd-2.4.25/srclib/apr-util

cd httpd-2.4.25
./configure --prefix=/opt/apache2 --with-mpm=event --enable-rewrite --enable-proxy --enable-proxy-fcgi --enable-ssl --with-included-apr
make && make install

3. Virtualmin Apache VirtualHost Integration

To route PHP requests from Virtualmin virtual hosts to their respective PHP-FPM pools via mod_proxy_fcgi, configure the VirtualHost directive:

<VirtualHost *:80>
    ServerName example.com
    DocumentRoot /home/example/public_html

    ProxyPassMatch ^/(.*\.php(/.*)?)$ fcgi://127.0.0.1:9000/home/example/public_html/$1

    <Directory /home/example/public_html>
        Options -Indexes +FollowSymLinks
        AllowOverride All
        Require all granted
    </Directory>
</VirtualHost>

This allows each virtual server in Virtualmin to leverage isolated PHP-FPM user pools with event-driven concurrency.

Tuesday, July 31, 2012

How to Install and Configure Munin 2.0 with Nginx and FastCGI on CentOS 6

Munin 2.0 introduced dynamic CGI graph and HTML generation, allowing monitoring dashboards to scale efficiently without requiring static graph regeneration during every 5-minute cron cycle. Here is how to compile Munin 2.0 from source and integrate it with Nginx using spawn-fcgi on CentOS 6.

Stack: Munin 2.0.x • Nginx • FastCGI (spawn-fcgi) • CentOS 6 / RHEL 6

1. Installing Build Dependencies

Install Perl module prerequisites and development tools:

yum groupinstall 'Development Tools' -y
yum install perl-CGI perl-FCGI perl-File-Copy-Recursive perl-Module-Build perl-Cache-Cache git spawn-fcgi -y
groupadd munin
useradd munin -g munin -s /sbin/nologin -d /var/www/html/munin

2. Compiling Munin 2.0 from Source

cd /usr/src
git clone git://github.com/munin-monitoring/munin.git
cd munin
git checkout tags/2.0.0
make
make install

3. Spawning FastCGI Processes for Graph and HTML Generation

Munin 2.0 relies on two FastCGI workers: one for HTML page rendering and one for real-time RRD graph generation.

spawn-fcgi -s /var/run/munin/fcgi-graph.sock -u munin -g munin -- /var/www/html/munin/cgi/munin-cgi-graph
spawn-fcgi -s /var/run/munin/fcgi-html.sock -u munin -g munin -- /var/www/html/munin/cgi/munin-cgi-html

4. Nginx Server Configuration

Configure Nginx to proxy requests to the Munin FastCGI sockets:

location ^~ /cgi-bin/munin-cgi-graph/ {
    access_log off;
    fastcgi_split_path_info ^(/cgi-bin/munin-cgi-graph)(.*);
    fastcgi_param PATH_INFO $fastcgi_path_info;
    fastcgi_pass unix:/var/run/munin/fcgi-graph.sock;
    include fastcgi_params;
}

location /munin/static/ {
    alias /etc/munin/static/;
}

location /munin/ {
    fastcgi_split_path_info ^(/munin)(.*);
    fastcgi_param PATH_INFO $fastcgi_path_info;
    fastcgi_pass unix:/var/run/munin/fcgi-html.sock;
    include fastcgi_params;
}

5. Testing

Execute the Munin cron job under the munin system user to build the initial state:

sudo -u munin munin-cron

Sunday, July 8, 2012

Setting Up an IKEv2 VPN with StrongSwan Between a NATed Linux Client and Server

Configuring a secure, roadwarrior-style IKEv2 IPsec VPN using StrongSwan allows a client behind a residential NAT router (such as a standard home DSL/Cable modem) to establish an encrypted tunnel to a remote dedicated server.

Topology: Client: Ubuntu (behind NAT) • Server: CentOS with StrongSwan 4.6.x (Public IP) • Protocol: IKEv2 with X.509 certificates

1. Server Configuration (/etc/ipsec.conf)

Define the IKEv2 connection on the server. The server listens on its public IP, provisions virtual IPs to clients from 10.10.3.0/24, and routes default internet traffic:

conn win7
    left=SERVER.IP.ADD.RESS
    leftcert=server.cert
    leftid=@server.domain.com
    leftsubnet=0.0.0.0/0
    right=%any
    rightsourceip=10.10.3.0/24
    keyexchange=ikev2
    auto=add
    leftfirewall=yes

2. Client Configuration (/etc/ipsec.conf)

On the client machine behind NAT, set left=%defaultroute and request an IP dynamically from the server via leftsourceip=%config:

conn ike
    left=%defaultroute
    leftsourceip=%config
    leftcert=client.cert
    leftid=@client.domain.com
    leftfirewall=yes
    right=SERVER.IP.ADD.RESS
    rightsubnet=0.0.0.0/0
    rightid=@server.domain.com
    auto=add

3. Initiating the Connection

Start the IPsec tunnel from the client:

ipsec up ike

Check the status to verify security associations (SAs):

ipsec statusall

Tuesday, July 3, 2012

How to Fix Postfix SASL Authentication Failure and Chroot Errors with saslauthd

When configuring Cyrus SASL (saslauthd) to authenticate SMTP users in Postfix on CentOS / RHEL with Virtualmin, you may encounter persistent user/password authentication failures even when credentials are valid.

Environment: CentOS 6.x / RHEL • Virtualmin • Postfix • Cyrus SASL (saslauthd)

1. Identifying the Symptom: /var/log/maillog

Checking /var/log/maillog often reveals that Postfix cannot communicate with the SASL authentication daemon:

warning: SASL authentication failure: cannot connect to saslauthd server: No such file or directory

2. The Chroot Trap and Secondary SMTP Failures

A common workaround suggested in forums is moving or binding the saslauthd socket into the Postfix spool directory (e.g. /var/spool/postfix/var/run/saslauthd). While that may resolve socket visibility, running Postfix processes inside a chroot jail introduces a severe secondary failure: outbound emails will fail to send entirely.

You will see delivery attempts stall in the active queue with errors like:

postfix/qmgr: from=<root@domain.com>, size=421, nrcpt=1 (queue active)
postfix/smtp: fatal: unknown service: smtp/tcp
postfix/qmgr: warning: private/smtp socket: malformed response
postfix/qmgr: warning: transport smtp failure -- see a previous warning/fatal/panic logfile record for the problem description
postfix/master: warning: process /usr/libexec/postfix/smtp pid 29443 exit status 1
postfix/master: warning: /usr/libexec/postfix/smtp: bad command startup -- throttling
postfix/error: to=<user@example.com>, relay=none, delay=1.1, delays=0.1/1/0/0.03, dsn=4.3.0, status=deferred (unknown mail transport error)

Root Cause: When the Postfix smtp client daemon runs chrooted, it cannot access /etc/services to resolve the network port name smtp/tcp, causing the transport to abort and defer all outgoing mail.

3. The Permanent Solution: Disable Chroot for SMTP

To resolve both the SASL socket communication and the transport errors cleanly, configure the Postfix smtp process to run unchrooted.

Step 1: Edit master.cf

Open /etc/postfix/master.cf in your text editor:

nano /etc/postfix/master.cf

Locate the smtp service definition:

# ==========================================================================
# service type  private unpriv  chroot  wakeup  maxproc command + args
#               (yes)   (yes)   (yes)   (never) (100)
# ==========================================================================
smtp      unix  -       -       -       -       -       smtp

The 5th column controls chroot. A hyphen (-) defaults to enabled (yes). Change the 5th column from - (or y) to n:

smtp      unix  -       -       n       -       -       smtp

Step 2: Restart Services

Restart both saslauthd and postfix so the configuration changes take effect:

service saslauthd restart
service postfix restart

4. Verification

Once services are restarted, monitor the mail log while sending a test message or authenticating a mail client:

tail -f /var/log/maillog

SASL authentication will succeed immediately without socket connection errors, and the mail queue will flush smoothly without transport or chroot exceptions.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...