Sunday, March 30, 2008

JBoss Clustering 4.2

Easiest way is use the 'all' server instance that already is configured for clustering in jboss.

If you have not used the 'all' instance then copy these three files from 'all' server to your server instance and it should work:
  • cluster-service.xml (all/deploy directory)
  • jbossha.jar (all/lib directory)
  • jgroups.jar (all/lib directory)

JBoss Monitoring and Performance

JBoss page how to slim your JBoss AS
Tuning JBoss on linux article

Memory and thread Montoring (see chapter 10 in JBoss 4.2 Server configuration guide)

MBean
In the JMX-console: jboss.system:type=ServerInfo MBean (view interesting attributes like FreeMemory, ActiveThreadCount etc.)

Checklist
(Read more about this in the book "JBoss Seam - Simplicity and Power beyond Java EE")
1. Use "Call by reference" (see JBoss Reference)
2. Optimize JVM (start using the -server option)
- Give at least 75 percent of the physical RAM to the JVM ( JAVA_OPT in bin/run.sh)
- set JAVA_OPTS=%JAVA_OPTS% -Xms1024m -Xmx1024m -XX:PermSize=256m -XX:MaxPermSize=512
- Using the same value for Xms and Xmx will force JVM to use specified value (in this case 1GB)
- -Xms2g and -Xmx2g would force JVM use 2G of RAM for example
3. Garbage Collector (use parallel GC) or what might be best for you JVM/application
- Run parallel GC
set JAVA_OPTS=%JAVA_OPTS% -XX:+UseParallelGC -XX:+UseParallelOldGC
4. Reduce logging (see
JBoss page how to slim your JBoss AS)
5. Tuning the HTTP Thread Pool (see JBoss page how to slim your JBoss AS)
6. Client- or Server-Side State Saving (really depends on your application and RAM vs. Mhz)
There are more things you can do like using Second-Level Cache and Clustering.

Tuesday, February 05, 2008

Flying Saucer renderer in JBoss Seam Fix

Used the iText and The Flying Saucer xhtml renderer to generate pdf's in my JBoss Seam application.

Problem: Everything worked fine. A pdf was generated in my app but the application context was somehow corrupt after the pdf generation and I could not continue using the app unless I redeployed it on JBoss AS again. I noticed that this happened after I had instanciated the org.xhtmlrenderer.pdf.ITextRenderer.

Found the fix for this in the JBoss Seam forum (thanks Calvin, you saved my day :)).

------------------------------------------------------------------------
Here's a fix for the problem. Set this system property before instantiating your first instance of ITextRenderer:
Code:
System.setProperty("xr.util-logging.loggingEnabled", "false"); 

The problem seems to be caused by Flying Saucer reconfiguring the log manager by calling LogManager.readConfiguration. Flying Saucer shouldn't really be doing this because it blows away any existing log configuration, but on the other hand it's odd that Seam (or maybe JBoss?) behaves this way when logging is reconfigured.
--Calvin
----------------------------------------------------------------------------
http://www.jboss.com/index.html?module=bb&op=viewtopic&p=4106412#4106412

Monday, January 07, 2008

JBoss Seam debug info

Enable/disable seam debug page and faclet debug

Seam - components.xml (debug = ture/false)

Facelets - web.xml (facelets.DEVELOPMENT = true/false)

Friday, September 14, 2007

Transactions (EJB3)

Transactions in EJB3 and Seam

  • ACID
  • Put all transactions in your EJBs (not in servlets)
  • Container or Bean Managed (default in Seam)
    • Container-managed-transactions (CMTs) preferred in Java EE. The Java EE container will handle comitting, rolling back, starting the transaction, etc. (no coding for the transactions).
      • 6 types of transactions to choose from (default is REQUIRED)
        • MANDATORY
        • REQUIRED
        • REQUIRES_NEW
        • SUPPORTS
        • NOT_SUPPORTED
        • NEVER
      • Example: Set this annotation before a method to use a transaction independent of an already-active transaction. Will attempt to commit in the end of the method.
        @TransactionAttribute(TransactionAttributeType.REQUIRES_NEW)
        public void addUser(User user) {
        em.persist(user);
        }
    • Bean-managed transactions (BMTs) allows a much more fine-grained control of transactions. (It is recommended to not use BMTs unless you cannot achieve the goals you are looking for using the CMT option.

Sunday, September 02, 2007

EJB3 EntityManager

Persisting Entities
  • entityManager.persist(object);
  • Can automatically generate a primary key
  • Throws IllegalArgumentException if its parameter is not an entity type
  • Throws TransactionRequiredException (Thrown by the persistence provider when a transaction is required but is not active).
  • If the Entity Manager is an extended persistent context, it is legal to call persist() outside a transaction scope.
Finding entities
  • There are 3 ways to find entities
    • find(), getReference() and createQuery()
  • The find() and getReference() methods works in the same way, they take the entity's class as a parameter and the primary key (Long).
find(Class entityClass, Object primaryKey);
getReference(Class entityClass, Object primaryKey);

Example:
Person person = null;
person = entityManager.find(Person.class, 5);
  • Two differences between find() and getReference() methods
    1. find() returns null if the entity is not found and the getReference() method throws a EntityNotFoundException.
    2. find() method initializes the state, based on the lazy-loading policies of each property, getReference() does not do that.
  • Both methods throws IllegalArgumentExceptions and they can be invoked outside the scope of transaction, but the object returned will be detached (unless entity manger is an extended persistent context).
  • With the createQuery() method it is possible to use EJB QL, HQL.
  • Summary: all the objects found using these three methods will remain managed as long as the persistent context in which you accessed them remains active.
Updating entities
  • To update an object while it is while it is managed by the persistent context is very easy. All updates on returned object (from find(), getReference(), createQuery()) will be synchronized automatically (depending on the flush mode). This is true as long as an active persistence context is still associated with the transaction. (Read more about Transaction Attribute (defaults to Required) but can be set in either ejb-jar deployment descriptor or on the EJB's bean class using @TransactionAttribute)
Merging entities
  • To merge state changes made to a detached entity back into persistent storage.
Example (person is a detached entity):
Person copy = entityManager.merge(person);
  • There are two different scenarios for the merge method, depending on if the entity manager is already managing the person entity with the same ID or not.
    • If the entity manager isn't managing the person entity with same ID, a full copy of the person parameter is made and returned from the merge() method. Now this copy will be managed by the entity manager and any additional setter methods called on it will be synchronized with the database (when flush).
    • If the entity manager is already managing the person entity with the same ID, then the contents of the person parameter is copied into this managed object instance. The merge() operation will return this managed instance and the person parameter will remain detached and unmanaged.
Removing entities
  • entityManager.remove(person);
    • person instance will not be managed any longer and will become detached
    • Associated entities may also be removed based on cascading rules
    • remove() can only be undone using persist() again
Refresh entity
  • Use entityManager.refresh(person) if you are concerned that the managed person entity is not up-to-date with the database. Will overwrite any changes of the managed entity with the one in the database.
  • Related entities may also be refreshed based on the setup cascading policy.
Contains
  • Use entityManager.contains(person) if you want to know if "person" is currently managed by the persistent context.
Clear
  • Use entityManager.clear() if you want to detach all managed entity instances from a persistence context. (Any changes made to managed entities are lost). Avoid this by calling flush() before clear().
FlushModeType
  • Flush is made automatically before any query (besides find() and getReference()) by the entity manager.
  • Change default behaviour by using Flushmode.COMMIT instead of default AUTO.
  • Using COMMIT means that changes are flushed only when the transaction commits, not before any query.
  • Set FlushType by calling the entityManager.setFlushType() method

Transactions (read more here)

Saturday, September 01, 2007

Monitoring JBoss Tool

Hyperic HQ — Systems Management Software

Have not tried this, but will for sure have a closer look when I have got time.

http://www.hyperic.com/downloads
/

Tuesday, August 28, 2007

Use JBoss loader

In file:
server\default\deploy\jbossweb-tomcat55.sar\META-INF\jboss-service.xml

Change this attribute to "true" to use the JBoss loader, this was needed for our application to be able to read resources from the classpath.

true

Saturday, August 04, 2007

Exceptions

hibernate.PersistentObjectException: detached entity passed to persist

Solution:
object = entityManager.merge(object);

Changes to "object" will be synchronized to database when flushed next time. Force flush using entitityManager.flush()

Tuesday, July 24, 2007

HQL (Hibernate Query Language)

  • Joins (SQL) (INNER, OUTER - Wikipedia)
    • inner join essentially combines the records from two tables A and B based on a given join predicate (considered default join)
    • left outer join for tables A and B always contains all records of the "left" table (A)
    • right outer join - Every record from the "right" table (B) will be in the joined table at least once.

Tuesday, January 30, 2007

JFokus

Intro: Open Source now and in the future
Simon Phipps, Sun

Talked about the benefits with Open Source. And how it is hard to gain value from taking a snapshot and adding own functionalities without giving the new source code back to the community. You would become the "Regression test slave" as Phipps expressed it. Open Source: "Earn the living by giving back".

Talked a bit about:
ODF (OpenDocument Format)
OpenOffice.org.

Software Patents, compared them to the fact that:
"American have guns because American have guns" and so do they have Patents.

Interoperability is a buzz word that Phipps did not really believed in. He did not have very hight thought of Web Services. So he wanted to introduce a new buzz word "Substitutability". It should be easy to throw out a piece of software and put in a new piece without suffering.


- Open Standards
- OpenSolaris
- OpenSPARC.net




Introduction to Java EE 5 and EJB 3

Mike Keith - Wrote "Pro EJB 3" Book.

This was mainly an introduction to EJB3s and a comparison to EJB 2.1.

Mike showed how EJB3s are simplified by using:
- Annotations
- Dependency Injection
- Simplified Web Services
- New Java Persistence API


JPA - Java Persistence API
Mike Keith

JPA was created as part of EJB3 within the JSR 220
Released May 2006 as part of Java EE 5

Key points
- javax.persistence

- Annotations makes everything much easier, but it is still possible to use XML. (@Entity, @Id etc.)

- Persistence Context - Think of a hash table where all entities are a set of "managed" entity instances.

- EntitiyManager API
-- persist() - Insert a state of an entity into the DB
-- remove(), find(), merge() etc .
The entityManager is injected into the object using it.

- Queries - Dynamic and Static
-- Query API - getResultList() etc.


- ORM

- JPA can used in Java SE as well.

Recommended tools in Eclipse: Dali JPA Tools


Secure Coding Antipatterns: Avoiding vulnerabilities

Marting Englund, Sun

Went through 6 antipatterns - things not to do while coding java thinking about security. Many examples was related to for example applets where the user have access to the source code, but how often are they used in security related solutions these days. Anyway, the 6 antipatterns were:

1. Assuming Objects are Immutable
- Attacker can change signers of a class
How to prevent: Make a copy of mutable output and input parameters (deep cloning)

2. Checks on untrusted source
- Use subclass, e.g. extend File
How to prevent: Create a new object from the untrusted source. Is it really a File object or was it a subclass.

3. Ignoring Changes to Superclasses
All changes propagate to the subclass which might open security holes.

4. Neglecting to validate inputs
- Embedded requests bypassing security checks
Requests examples: GET http://.... or Queries
Good solution: Public method that takes care of all the security (validation) and then calls the Native method.

5. Misusing Public Static variables
- Attackers can replace values whenever, the variable becomes public in the whole JVM.
Good Solution: Use private static or even better Enum.

6. Believe a constructor exception destroys the object
Solution: Use intitialized flag, check the flag in all relevant methods


Following these 6 anitpatterns should make your code more secure. Not really sure it is needed all the time though.


check out:

java.sun.com/security/seccodeguide.html (a new version to be released soon)




Thursday, June 22, 2006

My SOA mind map

My way to remember what SOA is about

SOA Basic Design Principles (ASIG)

  • Abstraction – Reduce and factor out details to focus on higher conceptual representation of an object (OO principle)
  • Standardization – The service need to use open standards and communicate in a formulized way
  • Independence – Each service needs to be a black box! The service will run independent of each other and could be deployed on different environments.
  • Generalization – The service needs to be fine grained enough to be efficient but course grained enough to be reusable.


SOA Features (FRISC)

  • Flexibility – Loosely coupled services are very flexible as they can be used in a number of systems
  • Reusability – The holy grail of system development. The ability to develop application components in a way that they can be reused by other applications.
  • Interoperability – Standardized way of communication between business services.
  • Scalability – Services are independent of each other and so can easily be scaled individually where required.
  • Cost efficient – Reuse of existing business services reduce need for duplication and development and testing in new applications that re-uses these services (e.g. Service to get Postcodes)

Tuesday, June 06, 2006

JAXP and JAXB

6/6/6 The number of the beast -- Get to know JAXB.

The introduction
Java Architecture for XML binding (Article, Sun March 2003)

My short version of this article

JAXP - Java API for XML Processing
  • Provides SAX and DOM
    • Used to scan XML documents and break it up to pieces that are made available to the application.
  • Differences Between SAX and DOM
    • SAX starts from the beginning of the document and passes each piece to the application as it finds it. Nothing is stored in memory.
    • DOM creates a tree of objects in memory that hte application can navigate through and access and manipulate data.
    • Difference - SAX cannot update data to the XML file but in DOM we can.
JAXB - Java Architecture for XML binding
  • Another Java API that can make it easier to access XML documents
  • Check out the example (Accessing an XML Document, JAXP and JAXB) or just be happy with the fact that: "Using JAXB instead of JAXP, there is no need to create and use a parser using and no need to write a content handler with callback methods. What this means is that developers can access and process XML data without having to know XML or XML processing".
  • Using JAXB, you would:
    • Unmarshal the document into Java content objects. The Java content objects represent the content and organization of the XML document, and are directly available to your program.
  • What is a schema?
    • A schema is an XML specification that governs the allowable components of an XML document and the relationships between the components.
  • JAXB requires that the XML document you want to access has a schema, and that schema is written in the W3C XML Schema Language
  • Binding a schema means generating (using a binding compiler) a set of Java classes that represents the schema. The binding compiler generates a set of interfaces and a set of classes that implement the interfaces. (Eg: books.xsd would generate BookType.java, BookTypeImpl.java etc.)
  • Unmarshalling an XML document means creating a tree of content objects that represents the content and organization of the document. The content objects are instances of the classes produced by the binding compiler. See example (how to unmarshal the XML document)

Tuesday, May 30, 2006

Use SSL with Tomcat 5.5

Quick Tomcat SSL configuartion
1. $CATALINA_HOME or $CATALINA_BASE must be set in your environment, check in command prompt in windows
C:\echo %CATALINA_HOME%

2. Create a keystore using the keytool found in java/bin directory, check if you JAVA_HOME environment variable is set
C:\echo %JAVA_HOME%
If JAVA_HOME is not set, go to control panel -> system -> advanced and environment variables and add it and let it point to your java home directory.
When it is set this command should execute the keygenerator
C:\%JAVA_HOME%\bin\keytool -genkey -alias tomcat -keyalg RSA

If you are having any conflict or some keystore already exists you can specify where your new keystore should be placed like this:
C:\%JAVA_HOME%\bin\keytool -genkey -alias tomcat -keyalg RSA -keystore \temp\keystore

And specify a password value of "changeit" for both the keystore and the key

Important: Tomcat will by default look for a keystore named .keystore in the logged in user's home directory and it will also use the password "changeit" by default to open the keystore and for the generated key. This can however be configured in tomcat's server.xml file. But the password for the keystore and the key must be the same.

3. Edit server.xml in tomcat

This is what I did in the server.xml found in %CATALINA_HOME%\conf

Just uncomment the SSL snippet and add keystoreFile and keystorePass if you are using something else than "changeit"

<d;!-- Define a SSL HTTP/1.1 Connector on port 8443 -->
<d;Connector port="8443" maxHttpHeaderSize="8192"
maxThreads="150" minSpareThreads="25" maxSpareThreads="75"
enableLookups="false" disableUploadTimeout="true"
acceptCount="100" scheme="https" secure="true"
clientAuth="false" sslProtocol="TLS"
keystoreFile="C:\temp\keystore"
keystorePass="mysecretpassword" />



4. Restart Tomcat and try
https://localhost:8443
This shoud give you the ordinary startup page if everything worked as it should


Check this link for all details
http://tomcat.apache.org/tomcat-5.5-doc/ssl-howto.html

/Crille