Monday, December 24, 2012

Linux Server Performance Tuning: Reducing Disk I/O and System Load

When optimizing a high-traffic dedicated Linux server, disk I/O bottlenecks are often the primary cause of sluggish response times and elevated load averages. Here are several practical server-tuning techniques I applied to a heavily loaded production server, resulting in a dramatic reduction in disk I/O and much faster throughput.

Key Optimizations: RAM-backed /tmp mount • Dedicated SSD for MySQL data • FastCGI process management with Nginx + PHP-FPM

1. Mount /tmp as a Ramdisk (tmpfs)

Many web stacks heavily utilize /tmp for transient disk writes:

  • PHP Sessions: Default PHP configurations store active session files in /tmp (session.save_path).
  • MySQL Temporary Tables: Heavy queries with extensive JOIN or GROUP BY clauses frequently write temporary on-disk tables to /tmp (verify your path using mysqladmin variables | grep tmpdir).

Mounting /tmp directly into RAM eliminates spinning disk access for these operations. Add the following entry to your /etc/fstab:

none /tmp tmpfs nr_inodes=200k,mode=01777,nosuid,nodev 0 0

Remount or apply without rebooting:

mount -o remount /tmp

2. Isolate MySQL Datadir to High-Performance Storage (SSD)

Moving the MySQL database directory (/var/lib/mysql) to dedicated high-speed SSD storage removes the database write bottleneck and dramatically lowers IO wait times (%iowait) during peak traffic.

3. Adopt Nginx with PHP-FPM

Switching from Apache's traditional prefork MPM / mod_php handler to Nginx + PHP-FPM significantly cuts memory footprint per connection, handles concurrency gracefully, and frees up system resources for database caching.

Sunday, December 23, 2012

Hardening Web Servers: Nginx Symlink Protection and PHP-FPM Chroot Jails

Securing shared hosting environments and multi-tenant web servers requires preventing unauthorized symlink traversals and isolating application processes. Here are two powerful security features in Nginx and PHP-FPM that significantly harden your stack against cross-account directory traversal attacks.

Security Highlights: Prevent unauthorized symlink following in Nginx • Isolate execution pools in dedicated chroot jails with required pseudo-devices

1. Restricting Symlink Traversal in Nginx

By default, Nginx follows symbolic links without verifying ownership. The disable_symlinks directive allows you to strictly control link traversal:

# Allowed options: off | on | if_not_owner
disable_symlinks if_not_owner;

When set to if_not_owner, Nginx verifies that the symlink and the target file/directory belong to the same owner, effectively blocking unauthorized access to system files or other users' web roots.

2. PHP-FPM Chroot Jails

To provide true isolation, you can lock each PHP-FPM worker pool into its own chroot directory. A quick way to bootstrap a clean environment is by extracting a minimal OS template (such as an OpenVZ minimal template matching your host distribution) into the jail root.

Creating Essential Device Nodes in the Jail

For PHP and system libraries to function correctly (especially DNS resolution, random entropy, and error logging), create the necessary character devices inside the jail directory:

cd /path/to/jail
mkdir -p dev etc usr/share/zoneinfo

mknod -m 666 dev/null c 1 3
mknod -m 666 dev/zero c 1 5
mknod -m 666 dev/random c 1 8
mknod -m 666 dev/urandom c 1 9

Also copy /etc/resolv.conf and /etc/hosts into the jail's etc/ folder so PHP can perform external network queries and DNS resolution.

Friday, December 14, 2012

How to Install Wine with MS Visual C++ and Visual Basic Runtimes on Linux

Running specialized Windows desktop utilities (such as download managers like Orbit Downloader, HiDownload, or Net Transport) on Linux often requires essential Microsoft Visual C++ and Visual Basic runtime libraries that are not packaged by default in vanilla Wine.

Prerequisites: Wine installed via EPEL (CentOS / RHEL) or standard distribution repositories (Ubuntu / Debian).

Step-by-Step Installation

1. Install Cabextract

The cabextract utility is required by Winetricks to unpack Microsoft cabinet files:

# On Debian / Ubuntu:
sudo apt-get install cabextract -y

# On CentOS / RHEL (requires EPEL):
sudo yum install cabextract -y

2. Download and Run Winetricks

Fetch the official winetricks script and install the required core fonts, Visual C++ 6.0, and Visual Basic 6.0 runtimes:

wget https://raw.githubusercontent.com/Winetricks/winetricks/master/src/winetricks
chmod +x winetricks

sh winetricks corefonts vcrun6 vb6run

Once the runtime components are installed into your ~/.wine prefix, your Windows applications will initialize without missing DLL or runtime errors.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...