<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-22481</id>
	<title>Nabble - Squid Web Proxy Cache</title>
	<updated>2009-12-07T03:56:14Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/Squid-Web-Proxy-Cache-f22481.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-Web-Proxy-Cache-f22481.html" />
	<subtitle type="html">&lt;a href=&quot;http://www.squid-cache.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;Squid&lt;/a&gt;&amp;nbsp;is a full-featured Web proxy cache. It is free, open-source software, and the result of many contributions by unpaid (and paid) volunteers .
&lt;br&gt;&lt;br&gt;Squid supports proxying and caching of HTTP, FTP, and other URLs; proxying for SSL; cache hierarchies; ICP, HTCP, CARP, Cache Digests; transparent caching; WCCP (Squid v2.3 and above); extensive access controls; HTTP server acceleration; SNMP; caching of DNS lookups.</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26676186</id>
	<title>problem attachments</title>
	<published>2009-12-07T03:56:14Z</published>
	<updated>2009-12-07T03:56:14Z</updated>
	<author>
		<name>espoire20</name>
	</author>
	<content type="html">Hi
&lt;br&gt;&lt;br&gt;I have a small problem I have proxy server installed , i configured squid it's working well .
&lt;br&gt;The issue that i have now when i try to add the attachment file &amp;nbsp;in &amp;nbsp;email on gmail or yahoo &amp;nbsp;i can't &amp;nbsp;added when I take out the proxy from the browser I can add the attachment file
&lt;br&gt;&lt;br&gt;if someone can help me i will be thankful
&lt;br&gt;&lt;br&gt;many thanks&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/problem-attachments-tp26676186p26676186.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26675913</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-07T03:24:48Z</published>
	<updated>2009-12-07T03:24:48Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">fedorischev wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; В сообщении от Monday 07 December 2009 13:00:22 Amos Jeffries написал(а):
&lt;br&gt;&amp;gt;&amp;gt; fedorischev wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Several days ago I find, that Squid3.0STABLE16 eating CPU time by HTTP
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; method CONNECT while request is hitting delay pool. I'm looking for the
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; spare time to post more debugging info on the list.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; WBR.
&lt;br&gt;&amp;gt;&amp;gt; Please try 3.0.STABLE20 and confirm that the problem still exists.
&lt;br&gt;&amp;gt;&amp;gt; There are a few hang and infinite loop errors resolved since *16. Some
&lt;br&gt;&amp;gt;&amp;gt; rather nasty remote DDoS security issues as well.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Amos
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; OK, thank you for tip. I'll try to use 3.0STABLE20 &amp; post the results on the 
&lt;br&gt;&amp;gt; list immediately. Now I'm looking for the linux http downloader software, 
&lt;br&gt;&amp;gt; that may using CONNECT - for squid testing purposes. Unfortunately - no 
&lt;br&gt;&amp;gt; results as yet &amp;nbsp;:)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; WBR.
&lt;/div&gt;&lt;br&gt;I have not tested this, but from a quick check of the code its should work:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;squidclient -m CONNECT -P file host:port
&lt;br&gt;&lt;br&gt;If you create a fake HTTP request and store the request headers in 
&lt;br&gt;&amp;quot;file&amp;quot; the above should send a CONNECT request for &amp;quot;host:port&amp;quot; to Squid 
&lt;br&gt;then pass the contents of &amp;quot;file&amp;quot; through the tunnel same as a downloader 
&lt;br&gt;would.
&lt;br&gt;&lt;br&gt;The only difference from a regular CONNECT is that squidclient will add 
&lt;br&gt;a Content-Length: header which do not usually go on CONNECT requests due 
&lt;br&gt;to their unpredictable nature.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26675913.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26675573</id>
	<title>Could this be a potential problem? Squid stops working and requires restart to work</title>
	<published>2009-12-07T02:53:23Z</published>
	<updated>2009-12-07T02:53:23Z</updated>
	<author>
		<name>Asim Ahmed @ Folio3</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I found this in cache.log when i restarted squid after a halt!
&lt;br&gt;&lt;br&gt;CPU Usage: 79.074 seconds = 48.851 user + 30.223 sys
&lt;br&gt;Maximum Resident Size: 0 KB
&lt;br&gt;Page faults with physical i/o: 0
&lt;br&gt;Memory usage for squid via mallinfo():
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; total space in arena: &amp;nbsp; &amp;nbsp;7452 KB
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Ordinary blocks: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7363 KB &amp;nbsp; &amp;nbsp;285 blks
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Small blocks: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 KB &amp;nbsp; &amp;nbsp; &amp;nbsp;1 blks
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Holding blocks: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 14752 KB &amp;nbsp; &amp;nbsp; 94 blks
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Free Small blocks: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0 KB
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Free Ordinary blocks: &amp;nbsp; &amp;nbsp; &amp;nbsp;88 KB
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total in use: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 22115 KB 297%
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Total free: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;88 KB 1%
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Asim Ahmed Khan
&lt;br&gt;IT Manager,
&lt;br&gt;Folio3 (Pvt.) Ltd. www.folio3.com
&lt;br&gt;Direct: 92-21-4323721-4 Ext 110
&lt;br&gt;Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26675573&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aahmed@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Could-this-be-a-potential-problem--Squid-stops-working-and-requires-restart-to-work-tp26675573p26675573.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26675475</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-07T02:42:01Z</published>
	<updated>2009-12-07T02:42:01Z</updated>
	<author>
		<name>fedorischev</name>
	</author>
	<content type="html">В сообщении от Monday 07 December 2009 13:00:22 Amos Jeffries написал(а):
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; fedorischev wrote:
&lt;br&gt;&amp;gt; &amp;gt; Several days ago I find, that Squid3.0STABLE16 eating CPU time by HTTP
&lt;br&gt;&amp;gt; &amp;gt; method CONNECT while request is hitting delay pool. I'm looking for the
&lt;br&gt;&amp;gt; &amp;gt; spare time to post more debugging info on the list.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; WBR.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Please try 3.0.STABLE20 and confirm that the problem still exists.
&lt;br&gt;&amp;gt; There are a few hang and infinite loop errors resolved since *16. Some
&lt;br&gt;&amp;gt; rather nasty remote DDoS security issues as well.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Amos
&lt;/div&gt;&lt;br&gt;OK, thank you for tip. I'll try to use 3.0STABLE20 &amp; post the results on the 
&lt;br&gt;list immediately. Now I'm looking for the linux http downloader software, 
&lt;br&gt;that may using CONNECT - for squid testing purposes. Unfortunately - no 
&lt;br&gt;results as yet &amp;nbsp;:)
&lt;br&gt;&lt;br&gt;WBR.
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26675475.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26675041</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-07T02:00:22Z</published>
	<updated>2009-12-07T02:00:22Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">fedorischev wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; В сообщении от Friday 04 December 2009 23:51:28 Guy Bashkansky написал(а):
&lt;br&gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The problem: on a certain origin content, Squid reaches 100% CPU
&lt;br&gt;&amp;gt;&amp;gt; periodically, every 10 minutes, so the cache service suffers.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Any clues where to look? &amp;nbsp;Maybe this problem and its solution are known?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The CPU load pattern is something like this, minute-by-minute:
&lt;br&gt;&amp;gt;&amp;gt; 40%, 40%, 60%, 80%, 99%, 99%, 99%, 80%, 60%, 40%, repeat.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt;&amp;gt; Guy
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Several days ago I find, that Squid3.0STABLE16 eating CPU time by HTTP method 
&lt;br&gt;&amp;gt; CONNECT while request is hitting delay pool. I'm looking for the spare time 
&lt;br&gt;&amp;gt; to post more debugging info on the list.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; WBR.
&lt;/div&gt;&lt;br&gt;Please try 3.0.STABLE20 and confirm that the problem still exists.
&lt;br&gt;There are a few hang and infinite loop errors resolved since *16. Some 
&lt;br&gt;rather nasty remote DDoS security issues as well.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26675041.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26674993</id>
	<title>Re: TCP_Denied for when requesting IP as URL over SSL using squid proxy 	server.</title>
	<published>2009-12-07T01:54:39Z</published>
	<updated>2009-12-07T01:54:39Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">kevin band wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm hoping somebody can help me here, because I'm at a loss about what
&lt;br&gt;&amp;gt; to do next.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Basically we have squid running as a proxy server to restrict access
&lt;br&gt;&amp;gt; to just those sites which we've included in our ACL's
&lt;br&gt;&amp;gt; I have noticed recently that it isn't handling HTTPS reqests properly
&lt;br&gt;&amp;gt; if the URL contains an IP address instead of a domain name.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The reason this is a particular problem is that although the users can
&lt;br&gt;&amp;gt; connect to the page using the domain name, something within that
&lt;br&gt;&amp;gt; domain is then forwarding requests to the same web-server using its IP
&lt;br&gt;&amp;gt; address.
&lt;br&gt;&amp;gt; I'm sure I have my ACL's setup correctly because squid will forward
&lt;br&gt;&amp;gt; the request using either URL if I send the requests using HTTP. &amp;nbsp;It
&lt;br&gt;&amp;gt; then times out on the web-server because it only allows https, but at
&lt;br&gt;&amp;gt; least the request is being forwarded to the web-server rather than
&lt;br&gt;&amp;gt; being denied in squid
&lt;/div&gt;&lt;br&gt;The remote web server(s) is rejecting the connections. Probably because 
&lt;br&gt;the SSL certificates require a domain name as part of their 
&lt;br&gt;authentication validation.
&lt;br&gt;&lt;br&gt;It's probably a broken client browser or maybe the website itself 
&lt;br&gt;sending funky page URLs with the raw-IP inside. If you care you need to 
&lt;br&gt;find out which and complain to whoever made the broken bits. Squid is 
&lt;br&gt;just an innocent middleman here.
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Here's an extract from the logs that might explain it better :-
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:15:56:47 +0000] &amp;quot;GET
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://stpaccess.marksandspencer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://stpaccess.marksandspencer.com/&lt;/a&gt;&amp;nbsp;HTTP/1.1&amp;quot; 504 1024 TCP_MISS:NONE
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:15:57:02 +0000] &amp;quot;CONNECT
&lt;br&gt;&amp;gt; stpaccess.marksandspencer.com:443 HTTP/1.0&amp;quot; 200 7783 TCP_MISS:DIRECT
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:16:01:53 +0000] &amp;quot;GET
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://63.130.82.113/Citrix/MetaFrameXP/default/login.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://63.130.82.113/Citrix/MetaFrameXP/default/login.asp&lt;/a&gt;&amp;nbsp;HTTP/1.1&amp;quot;
&lt;br&gt;&amp;gt; 504 1064 TCP_MISS:NONE
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:16:03:13 +0000] &amp;quot;CONNECT
&lt;br&gt;&amp;gt; 63.130.82.113:443 HTTP/1.0&amp;quot; 403 980 TCP_DENIED:NONE
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; And config extracts:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl SSL_ports port 443 563 444
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl Safe_ports port 80 8002 23142 5481 5181 5281 5381 5481 5581
&lt;br&gt;&amp;gt; 5400 5500 &amp;nbsp; &amp;nbsp; &amp;nbsp; # http
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl Safe_ports port 23142 &amp;nbsp; &amp;nbsp; &amp;nbsp; # OPEL project
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl Safe_ports port 21 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# ftp
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl Safe_ports port 443 444 563 # https, snew#s
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl CONNECT method CONNECT
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl regex_ms dstdom_regex &amp;nbsp; -i &amp;quot;/home/security/regex_marksandspencer.txt&amp;quot;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl urlregex_mands url_regex -i
&lt;br&gt;&amp;gt; &amp;quot;/home/security/regex_marksandspencer_ip.txt&amp;quot;
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; acl mands_allowed_nets &amp;nbsp;src &amp;nbsp;&amp;quot;/home/security/mands_allowed_nets.txt&amp;quot;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access allow manager localhost
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access deny manager
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access deny !Safe_ports
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access deny CONNECT !SSL_ports
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access allow regex_ms &amp;nbsp;mands_allowed_nets
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access allow urlregex_mands mands_allowed_nets
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; http_access deny all
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There are actually a lot more ACL's than this, but these are the only
&lt;br&gt;&amp;gt; ones I think are relevant
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; relevant extracts from files linked to ACLs:
&lt;br&gt;&amp;gt; &amp;nbsp; regex_marksandspencer.txt
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; .*marksandspencer.*com
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; regex_marksandspencer_ip.txt
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; .*.63.130.82.113
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Thanks for any help.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Kevin,
&lt;/div&gt;&lt;br&gt;Kevin, meet dstdomain:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;acl markandspencer dstdomain .marksandspencer.com 63.130.82.113
&lt;br&gt;&amp;nbsp; &amp;nbsp;http_access allow markandspencer mands_allowed_nets
&lt;br&gt;&lt;br&gt;10x or more faster than regex. Matching marksandspencer.com, all 
&lt;br&gt;sub-domains and the raw-IP address form.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/TCP_Denied-for-when-requesting-IP-as-URL-over-SSL-using-squid-proxy--server.-tp26674726p26674993.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26674781</id>
	<title>Re: any work arounds for bug 2176</title>
	<published>2009-12-07T01:36:52Z</published>
	<updated>2009-12-07T01:36:52Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">Brett Lymn wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Wed, Dec 02, 2009 at 07:22:57PM +1300, Amos Jeffries wrote:
&lt;br&gt;&amp;gt;&amp;gt; Sorry. I attached it to the bug report.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I manually applied the patch - I couldn't be bothered with patch for a
&lt;br&gt;&amp;gt; simple #if removal. &amp;nbsp;The symptoms have changed. &amp;nbsp;We no longer get an
&lt;br&gt;&amp;gt; auth pop up but at the end of the upload the browser displays:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Bad Request (Invalid Verb)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; and the document is not shown in the list. &amp;nbsp;So, the patch made a
&lt;br&gt;&amp;gt; difference but something else is amiss still.
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;Strange. I've never see that one before.
&lt;br&gt;&lt;br&gt;I think another trace of the request-reply sequence is needed to see if 
&lt;br&gt;there is anything different now and what.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/any-work-arounds-for-bug-2176-tp26603291p26674781.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26674726</id>
	<title>TCP_Denied for when requesting IP as URL over SSL using squid proxy  server.</title>
	<published>2009-12-07T01:30:14Z</published>
	<updated>2009-12-07T01:30:14Z</updated>
	<author>
		<name>kevin band-2</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I'm hoping somebody can help me here, because I'm at a loss about what
&lt;br&gt;to do next.
&lt;br&gt;&lt;br&gt;Basically we have squid running as a proxy server to restrict access
&lt;br&gt;to just those sites which we've included in our ACL's
&lt;br&gt;I have noticed recently that it isn't handling HTTPS reqests properly
&lt;br&gt;if the URL contains an IP address instead of a domain name.
&lt;br&gt;&lt;br&gt;The reason this is a particular problem is that although the users can
&lt;br&gt;connect to the page using the domain name, something within that
&lt;br&gt;domain is then forwarding requests to the same web-server using its IP
&lt;br&gt;address.
&lt;br&gt;I'm sure I have my ACL's setup correctly because squid will forward
&lt;br&gt;the request using either URL if I send the requests using HTTP. &amp;nbsp;It
&lt;br&gt;then times out on the web-server because it only allows https, but at
&lt;br&gt;least the request is being forwarded to the web-server rather than
&lt;br&gt;being denied in squid
&lt;br&gt;&lt;br&gt;Here's an extract from the logs that might explain it better :-
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:15:56:47 +0000] &amp;quot;GET
&lt;br&gt;&lt;a href=&quot;http://stpaccess.marksandspencer.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://stpaccess.marksandspencer.com/&lt;/a&gt;&amp;nbsp;HTTP/1.1&amp;quot; 504 1024 TCP_MISS:NONE
&lt;br&gt;&amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:15:57:02 +0000] &amp;quot;CONNECT
&lt;br&gt;stpaccess.marksandspencer.com:443 HTTP/1.0&amp;quot; 200 7783 TCP_MISS:DIRECT
&lt;br&gt;&amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:16:01:53 +0000] &amp;quot;GET
&lt;br&gt;&lt;a href=&quot;http://63.130.82.113/Citrix/MetaFrameXP/default/login.asp&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://63.130.82.113/Citrix/MetaFrameXP/default/login.asp&lt;/a&gt;&amp;nbsp;HTTP/1.1&amp;quot;
&lt;br&gt;504 1064 TCP_MISS:NONE
&lt;br&gt;&amp;nbsp; &amp;nbsp; 158.41.4.44 - - [04/Dec/2009:16:03:13 +0000] &amp;quot;CONNECT
&lt;br&gt;63.130.82.113:443 HTTP/1.0&amp;quot; 403 980 TCP_DENIED:NONE
&lt;br&gt;&lt;br&gt;&lt;br&gt;And config extracts:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; acl SSL_ports port 443 563 444
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl Safe_ports port 80 8002 23142 5481 5181 5281 5381 5481 5581
&lt;br&gt;5400 5500 &amp;nbsp; &amp;nbsp; &amp;nbsp; # http
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl Safe_ports port 23142 &amp;nbsp; &amp;nbsp; &amp;nbsp; # OPEL project
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl Safe_ports port 21 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# ftp
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl Safe_ports port 443 444 563 # https, snew#s
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; acl CONNECT method CONNECT
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; acl regex_ms dstdom_regex &amp;nbsp; -i &amp;quot;/home/security/regex_marksandspencer.txt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl urlregex_mands url_regex -i
&lt;br&gt;&amp;quot;/home/security/regex_marksandspencer_ip.txt&amp;quot;
&lt;br&gt;&amp;nbsp; &amp;nbsp; acl mands_allowed_nets &amp;nbsp;src &amp;nbsp;&amp;quot;/home/security/mands_allowed_nets.txt&amp;quot;
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access allow manager localhost
&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access deny manager
&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access deny !Safe_ports
&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access deny CONNECT !SSL_ports
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access allow regex_ms &amp;nbsp;mands_allowed_nets
&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access allow urlregex_mands mands_allowed_nets
&lt;br&gt;&amp;nbsp; &amp;nbsp; http_access deny all
&lt;br&gt;&lt;br&gt;There are actually a lot more ACL's than this, but these are the only
&lt;br&gt;ones I think are relevant
&lt;br&gt;&lt;br&gt;relevant extracts from files linked to ACLs:
&lt;br&gt;&amp;nbsp; regex_marksandspencer.txt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; .*marksandspencer.*com
&lt;br&gt;&lt;br&gt;&amp;nbsp; regex_marksandspencer_ip.txt
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; .*.63.130.82.113
&lt;br&gt;&lt;br&gt;&lt;br&gt;Thanks for any help.
&lt;br&gt;&lt;br&gt;Kevin,
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/TCP_Denied-for-when-requesting-IP-as-URL-over-SSL-using-squid-proxy--server.-tp26674726p26674726.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26674022</id>
	<title>RE: any work arounds for bug 2176</title>
	<published>2009-12-07T00:21:36Z</published>
	<updated>2009-12-07T00:21:36Z</updated>
	<author>
		<name>bill.allison</name>
	</author>
	<content type="html">As the reporter of this bug, apologies Amos for not responding promptly and thanks Brett for doing so - my excuse is pressure of work. It's particularly on my conscience because we so badly need this fix. Today I have a test instance I can use, and I guess the next step, and my contribution, is apply the patch, tcpdump the result, and report back (unless Brett gets there first ;-) )
&lt;br&gt;&lt;br&gt;Bill A.
&lt;br&gt;&lt;br&gt;-----Original Message-----
&lt;br&gt;From: Brett Lymn [mailto:&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26674022&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;blymn@...&lt;/a&gt;] 
&lt;br&gt;Sent: 07 December 2009 01:39
&lt;br&gt;To: Amos Jeffries
&lt;br&gt;Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26674022&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;Subject: Re: [squid-users] any work arounds for bug 2176
&lt;br&gt;&lt;br&gt;On Wed, Dec 02, 2009 at 07:22:57PM +1300, Amos Jeffries wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Sorry. I attached it to the bug report.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;I manually applied the patch - I couldn't be bothered with patch for a
&lt;br&gt;simple #if removal. &amp;nbsp;The symptoms have changed. &amp;nbsp;We no longer get an
&lt;br&gt;auth pop up but at the end of the upload the browser displays:
&lt;br&gt;&lt;br&gt;Bad Request (Invalid Verb)
&lt;br&gt;&lt;br&gt;and the document is not shown in the list. &amp;nbsp;So, the patch made a
&lt;br&gt;difference but something else is amiss still.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Brett Lymn
&lt;br&gt;&amp;quot;Warning:
&lt;br&gt;The information contained in this email and any attached files is
&lt;br&gt;confidential to BAE Systems Australia. If you are not the intended
&lt;br&gt;recipient, any use, disclosure or copying of this email or any
&lt;br&gt;attachments is expressly prohibited. &amp;nbsp;If you have received this email
&lt;br&gt;in error, please notify us immediately. VIRUS: Every care has been
&lt;br&gt;taken to ensure this email and its attachments are virus free,
&lt;br&gt;however, any loss or damage incurred in using this email is not the
&lt;br&gt;sender's responsibility. &amp;nbsp;It is your responsibility to ensure virus
&lt;br&gt;checks are completed before installing any data sent in this email to
&lt;br&gt;your computer.&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;This message has been scanned for viruses and
&lt;br&gt;dangerous content by MailScanner, and is
&lt;br&gt;believed to be clean.
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/any-work-arounds-for-bug-2176-tp26603291p26674022.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26673696</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-06T23:39:39Z</published>
	<updated>2009-12-06T23:39:39Z</updated>
	<author>
		<name>fedorischev</name>
	</author>
	<content type="html">В сообщении от Friday 04 December 2009 23:51:28 Guy Bashkansky написал(а):
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The problem: on a certain origin content, Squid reaches 100% CPU
&lt;br&gt;&amp;gt; periodically, every 10 minutes, so the cache service suffers.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Any clues where to look? &amp;nbsp;Maybe this problem and its solution are known?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The CPU load pattern is something like this, minute-by-minute:
&lt;br&gt;&amp;gt; 40%, 40%, 60%, 80%, 99%, 99%, 99%, 80%, 60%, 40%, repeat.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Guy
&lt;/div&gt;&lt;br&gt;Several days ago I find, that Squid3.0STABLE16 eating CPU time by HTTP method 
&lt;br&gt;CONNECT while request is hitting delay pool. I'm looking for the spare time 
&lt;br&gt;to post more debugging info on the list.
&lt;br&gt;&lt;br&gt;WBR.
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26673696.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26673547</id>
	<title>RE: acl proxy_auth problem</title>
	<published>2009-12-06T23:25:29Z</published>
	<updated>2009-12-06T23:25:29Z</updated>
	<author>
		<name>Georg Roelli</name>
	</author>
	<content type="html">&lt;br&gt;----------------------------------------
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;roellig@...&lt;/a&gt;
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Date: Fri, 4 Dec 2009 13:34:12 +0100
&lt;br&gt;&amp;gt; Subject: RE: [squid-users] acl proxy_auth problem
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; ----------------------------------------
&lt;br&gt;&amp;gt;&amp;gt; Date: Fri, 4 Dec 2009 12:20:34 +1300
&lt;br&gt;&amp;gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid3@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: [squid-users] acl proxy_auth problem
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Georg Roelli wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; ----------------------------------------
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Date: Thu, 3 Dec 2009 10:36:10 +1300
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; From: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid3@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26673547&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Subject: Re: [squid-users] acl proxy_auth problem
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; On Wed, 2 Dec 2009 15:15:15 +0100, Georg Roelli
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Hello
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; My environment: Ubuntu 8.04 LTS, Squid 2.6.18, Samba 3.0.28a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I am looking to find a way to check with an acl if a user is member of a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; specific ad-group. On my Squid Proxy Server, I have successfully set up
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; an
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; SSO authentication with the active directory.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This works fine. Among other things:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; auth_param ntlm program /usr/bin/ntlm_auth
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --helper-protocol=squid-2.5-ntlmssp
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; --require-membership-of=&amp;quot;Domäne\\AD-GroupeA&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Now I start with the definition of the acl's. At first I would like to
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; make a badUrls list which is valid for all users to block some sites.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; This
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; list should not be applied to a group of personal computers (host)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; and/or a
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; specific AD group.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Here is my approach:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; acl auth proxy_auth REQUIRED
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; acl badurls url_regex &amp;quot;/data/squid/badurls.txt&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; acl AllowedClients srcdom_regex -i &amp;quot;/data/squid/allowed_clients.txt&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; acl AllowedGroups proxy_auth -i Domäne/AD-GroupeB
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; http_access allow auth AllowedClients
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; http_access allow auth AllowedGroups
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; http_access deny badurls
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; http_access allow auth
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; http_access deny all
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; The acl with the badurls list and the acl for the AllowedClients are
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; working fine. But with the acl acl AllowedGroups proxy_auth -i
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Domäne/AD-GruppeB I have great problems. I don't know how I can make an
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; acl
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; who check the membership from an AD-Groupe.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; I tested many different types of spelling. Unfortunately without
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; success.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; How can I make an acl using ntlm_auth authentication? Is there a better
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; and
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; easier way to do this?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Thank you for your suggestions.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Kind regards.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://wiki.squid-cache.org/ConfigExamples/Authenticate/NtlmWithGroups&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://wiki.squid-cache.org/ConfigExamples/Authenticate/NtlmWithGroups&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;&amp;gt; Amos
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hello Amos
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thank you for your note.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I have try it and after a have modified the lines in
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; external_acl_type testForNTGroup %LOGIN /usr/lib/squid/wbinfo_group.pl -d
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; acl inGroupX external testForNTGroup obmg
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; http_access allow inGroupX
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; I can restart the squid service without problems. Unfortunately the alc does not work.
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; In a documentation I have found the -d option for wbinfo_group.pl and now I find these messages in the access.log:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; You means cache.log surely?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; [2009/12/03 13:18:16, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63)
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Got NTLMSSP neg_flags=0xa2088205
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Got wag obmg from squid
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Could not convert sid S-1-5-21-986273330-1409306274-1541874228-6339 to gid
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; User: -rog-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Group: -obmg-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; SID: -S-1-5-21-986273330-1409306274-1541874228-6339-
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; GID: --
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Sending ERR to squid
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Do you have any other ideas what dies message exactly means?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; They means the user &amp;quot;rog&amp;quot; exists but was not a registered member of
&lt;br&gt;&amp;gt;&amp;gt; group &amp;quot;obmg&amp;quot;.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Look in the registry (I think on the domain controller) for
&lt;br&gt;&amp;gt;&amp;gt; &amp;quot;S-1-5-21-986273330-1409306274-1541874228-6339&amp;quot; and see what groups it's
&lt;br&gt;&amp;gt;&amp;gt; a member of.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Amos
&lt;br&gt;&amp;gt;&amp;gt; --
&lt;br&gt;&amp;gt;&amp;gt; Please be using
&lt;br&gt;&amp;gt;&amp;gt; Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;gt;&amp;gt; Current Beta Squid 3.1.0.15
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I’m a little bit confused.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I checked in the active directory which object has the SID S-1-5-21-986273330-1409306274-1541874228-6339. It’s the group obmg in my domain. Also, the user rog is a member of the group obmg. When I repeat the test with another domain user, he is member of obmg, I get the same error.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I think the problem isn’t the membership of the user rog, it’s the fact, that wbinfo_grou.pl can’t generate a UID from the SID of the group.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The error was:
&lt;br&gt;&amp;gt; Could not convert sid S-1-5-21-986273330-1409306274-1541874228-6339 to gid
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I made a few tests:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # wbinfo -n obmg
&lt;br&gt;&amp;gt; S-1-5-21-986273330-1409306274-1541874228-6339 Domain Group (2)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # wbinfo -Y S-1-5-21-986273330-1409306274-1541874228-6339
&lt;br&gt;&amp;gt; Could not convert sid S-1-5-21-986273330-1409306274-1541874228-6339 to gid
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; With another group I get the results:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # wbinfo -n inor
&lt;br&gt;&amp;gt; S-1-5-21-986273330-1409306274-1541874228-1059 Domain Group (2)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; # wbinfo -Y S-1-5-21-986273330-1409306274-1541874228-1059
&lt;br&gt;&amp;gt; 10029
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; When I take the group inor for the acl I get those entries in the cache.log and the access to internet works.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [2009/12/04 13:07:34, 3] libsmb/ntlmssp.c:debug_ntlmssp_flags(63)
&lt;br&gt;&amp;gt; Got NTLMSSP neg_flags=0xa2088205
&lt;br&gt;&amp;gt; Got rog inor from squid
&lt;br&gt;&amp;gt; User: -rog-
&lt;br&gt;&amp;gt; Group: -inor-
&lt;br&gt;&amp;gt; SID: -S-1-5-21-986273330-1409306274-1541874228-1059-
&lt;br&gt;&amp;gt; GID: -10029-
&lt;br&gt;&amp;gt; Sending OK to squid
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; So my next question is, why do I get from one group an UID and from the other not? Any ideas?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; G.
&lt;/div&gt;&lt;br&gt;Good morning
&lt;br&gt;&amp;nbsp;
&lt;br&gt;Has anyone a good idea or a hint for me?
&lt;br&gt;&amp;nbsp;
&lt;br&gt;G.
&lt;br&gt;&lt;br&gt;&amp;nbsp; 		 	 &amp;nbsp; 		 &amp;nbsp;
&lt;br&gt;_________________________________________________________________
&lt;br&gt;Ski-Weltcup: Alle Rennen, alle Resultate und News auf MSN Sport
&lt;br&gt;&lt;a href=&quot;http://sport.ch.msn.com/skialpin/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://sport.ch.msn.com/skialpin/&lt;/a&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/acl-proxy_auth-problem-tp26609602p26673547.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26673172</id>
	<title>Re: COSS cache_dir size exceeds largest offset at maximum file size</title>
	<published>2009-12-06T22:37:49Z</published>
	<updated>2009-12-06T22:37:49Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">Jason Healy wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm trying to set up a large COSS cache_dir. &amp;nbsp;I've used COSS in the
&lt;br&gt;&amp;gt; past, but I've never tried to max out on the size of the file (I'm not
&lt;br&gt;&amp;gt; even sure if this is a good idea...)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; When I try to start, squid fails with the following log messages:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 2009/12/05 12:16:00| parse_line: cache_dir coss /squid/small/coss01
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;131072 block-size=8192 max-size=1048576
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;maxfullbufs=256
&lt;br&gt;&amp;gt; 2009/12/05 12:16:00| COSS block-size = 8192 bytes
&lt;br&gt;&amp;gt; 2009/12/05 12:16:00| COSS largest file offset = 4194296 KB
&lt;br&gt;&amp;gt; 2009/12/05 12:16:00| COSS cache_dir size = 134217728 KB
&lt;br&gt;&amp;gt; FATAL: COSS cache_dir size exceeds largest offset
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I think I'm using the &amp;quot;block-size&amp;quot; param correctly to get to the
&lt;br&gt;&amp;gt; maximum size of 131072MB. &amp;nbsp;However, Squid seems to disagree on the
&lt;br&gt;&amp;gt; maximum file offset.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I've compiled using --with-large-*, so I'm not sure what I'm
&lt;br&gt;&amp;gt; missing here:
&lt;/div&gt;&lt;br&gt;You have indeed pushed the envelope right out that to the last single 
&lt;br&gt;byte of the index maximum boundary.
&lt;br&gt;&lt;br&gt;For some reason the safety check that is catching you uses &amp;gt; instead of &amp;gt;=
&lt;br&gt;I'm not sure why. If you want to experiment you could change it manually 
&lt;br&gt;and rebuild. Around line 864 of src/fs/coss/store_dir_coss.c.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/COSS-cache_dir-size-exceeds-largest-offset-at-maximum-file-size-tp26671492p26673172.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26673041</id>
	<title>Re: Any work around for bug 2805</title>
	<published>2009-12-06T22:16:19Z</published>
	<updated>2009-12-06T22:16:19Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">sankar m wrote:
&lt;br&gt;&amp;gt; Dear Sir,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Is there any work around for this bug (2805). Every day, I'm receiving
&lt;br&gt;&amp;gt; at least THREE to FIVE queries related to this problem. Could you
&lt;br&gt;&amp;gt; please help me in this.?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;The cause of the bug is still uknown and unreproducible by anyone other 
&lt;br&gt;than you.
&lt;br&gt;&lt;br&gt;The last comment in the bug tracker details some further information 
&lt;br&gt;needed to track it down. Please assist the fix by providing the 
&lt;br&gt;mentioned info to those who are trying to fix it.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Any-work-around-for-bug-2805-tp26672677p26673041.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26672677</id>
	<title>Any work around for bug 2805</title>
	<published>2009-12-06T21:12:04Z</published>
	<updated>2009-12-06T21:12:04Z</updated>
	<author>
		<name>sankar m</name>
	</author>
	<content type="html">Dear Sir,
&lt;br&gt;&lt;br&gt;Is there any work around for this bug (2805). Every day, I'm receiving
&lt;br&gt;at least THREE to FIVE queries related to this problem. Could you
&lt;br&gt;please help me in this.?
&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;Sankar.M
&lt;br&gt;&lt;br&gt;&lt;br&gt;---------- Forwarded message ----------
&lt;br&gt;From: sankar m &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26672677&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;debianlinux.ss@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: Wed, Nov 4, 2009 at 9:28 AM
&lt;br&gt;Subject: Digest Ldap Authentication got failed for some user accounts
&lt;br&gt;To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26672677&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;Dear Sir,
&lt;br&gt;&lt;br&gt;As per your previous mail, I have filed a bug report and the link is
&lt;br&gt;provided below,
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://bugs.squid-cache.org/show_bug.cgi?id=2805&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bugs.squid-cache.org/show_bug.cgi?id=2805&lt;/a&gt;&lt;br&gt;&lt;br&gt;I am still restarting the squid everyday to avoid &amp;quot;Authentication
&lt;br&gt;failed&amp;quot; issue. Please help me in this.
&lt;br&gt;&lt;br&gt;I am looking forward to hear from you.
&lt;br&gt;&lt;br&gt;Thanks and Regards,
&lt;br&gt;Sankar.M
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Any-work-around-for-bug-2805-tp26672677p26672677.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26672298</id>
	<title>Build failed in Hudson: 3.0-i386-Debian-sid #25</title>
	<published>2009-12-06T20:16:13Z</published>
	<updated>2009-12-06T20:16:13Z</updated>
	<author>
		<name>noc-8</name>
	</author>
	<content type="html">See &amp;lt;&lt;a href=&quot;http://build.squid-cache.org/job/3.0-i386-Debian-sid/25/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://build.squid-cache.org/job/3.0-i386-Debian-sid/25/&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;------------------------------------------
&lt;br&gt;Started by upstream project &amp;quot;3.0-amd64-CentOS-5.3&amp;quot; build number 33
&lt;br&gt;Building remotely on rio.treenet
&lt;br&gt;&lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_0&lt;/a&gt;&amp;nbsp;is permanently redirected to &lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_0/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_0/&lt;/a&gt;&lt;br&gt;bzr: ERROR: Invalid http response for &lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/.bzr/repository/indices/2ac0b245adaec88233f3f214954e0737.tix:&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/.bzr/repository/indices/2ac0b245adaec88233f3f214954e0737.tix:&lt;/a&gt;&amp;nbsp;Unable to handle http code 504: Gateway Time-out
&lt;br&gt;ERROR: Failed to pull
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Development-f22484.html&quot; embed=&quot;fixTarget[22484]&quot; target=&quot;_top&quot; &gt;Squid - Development&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Build-failed-in-Hudson%3A-3.0-i386-Debian-sid--25-tp26672298p26672298.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26671492</id>
	<title>COSS cache_dir size exceeds largest offset at maximum file size</title>
	<published>2009-12-06T17:57:07Z</published>
	<updated>2009-12-06T17:57:07Z</updated>
	<author>
		<name>Jason Healy</name>
	</author>
	<content type="html">Hello,
&lt;br&gt;&lt;br&gt;I'm trying to set up a large COSS cache_dir. &amp;nbsp;I've used COSS in the
&lt;br&gt;past, but I've never tried to max out on the size of the file (I'm not
&lt;br&gt;even sure if this is a good idea...)
&lt;br&gt;&lt;br&gt;When I try to start, squid fails with the following log messages:
&lt;br&gt;&lt;br&gt;2009/12/05 12:16:00| parse_line: cache_dir coss /squid/small/coss01
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;131072 block-size=8192 max-size=1048576
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;maxfullbufs=256
&lt;br&gt;2009/12/05 12:16:00| COSS block-size = 8192 bytes
&lt;br&gt;2009/12/05 12:16:00| COSS largest file offset = 4194296 KB
&lt;br&gt;2009/12/05 12:16:00| COSS cache_dir size = 134217728 KB
&lt;br&gt;FATAL: COSS cache_dir size exceeds largest offset
&lt;br&gt;&lt;br&gt;I think I'm using the &amp;quot;block-size&amp;quot; param correctly to get to the
&lt;br&gt;maximum size of 131072MB. &amp;nbsp;However, Squid seems to disagree on the
&lt;br&gt;maximum file offset.
&lt;br&gt;&lt;br&gt;I've compiled using --with-large-*, so I'm not sure what I'm
&lt;br&gt;missing here:
&lt;br&gt;&lt;br&gt;`squid -v` says: configure options:
&lt;br&gt;&amp;nbsp; '--prefix=/usr' '--exec_prefix=/usr' '--bindir=/usr/sbin'
&lt;br&gt;&amp;nbsp; '--sbindir=/usr/sbin' '--libexecdir=/usr/lib/squid'
&lt;br&gt;&amp;nbsp; '--sysconfdir=/etc/squid' '--localstatedir=/var/spool/squid'
&lt;br&gt;&amp;nbsp; '--datadir=/usr/share/squid' '--enable-async-io' '--with-pthreads'
&lt;br&gt;&amp;nbsp; '--enable-storeio=ufs,aufs,coss,diskd,null' '--enable-linux-netfilter'
&lt;br&gt;&amp;nbsp; '--enable-arp-acl' '--enable-epoll' '--enable-snmp'
&lt;br&gt;&amp;nbsp; '--enable-removal-policies=lru,heap' '--enable-delay-pools'
&lt;br&gt;&amp;nbsp; '--enable-htcp' '--enable-cache-digests'
&lt;br&gt;&amp;nbsp; '--enable-auth=basic,digest,negotiate'
&lt;br&gt;&amp;nbsp; '--enable-negotiate-auth-helpers=squid_kerb_auth'
&lt;br&gt;&amp;nbsp; '--enable-carp' '--with-large-files' '--with-maxfd=65536'
&lt;br&gt;&amp;nbsp; '--disable-ident-lookups'
&lt;br&gt;&amp;nbsp; '--enable-follow-x-forwarded-for' '--enable-forw-via-db'
&lt;br&gt;&amp;nbsp; '--enable-large-cache-files'
&lt;br&gt;&amp;nbsp; 'sparc-debian-linux' 'build_alias=sparc-debian-linux'
&lt;br&gt;&amp;nbsp; 'host_alias=sparc-debian-linux'
&lt;br&gt;&amp;nbsp; 'target_alias=sparc-debian-linux'
&lt;br&gt;&amp;nbsp; 'CFLAGS=-Wall -g -O2 -pipe -mcpu=niagara' 'LDFLAGS='
&lt;br&gt;&amp;nbsp; 'CPPFLAGS=-O2 -pipe -mcpu=niagara'
&lt;br&gt;&lt;br&gt;This is squid-2.7STABLE7 running on Debian Linux kernel 2.6.31
&lt;br&gt;(SMP/64bit) on a SunFire T2000 (niagara1).
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;&lt;br&gt;Jason
&lt;br&gt;&lt;br&gt;--
&lt;br&gt;Jason Healy &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26671492&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jhealy@...&lt;/a&gt; &amp;nbsp; &amp;nbsp;| &amp;nbsp; &lt;a href=&quot;http://www.logn.net/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.logn.net/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/COSS-cache_dir-size-exceeds-largest-offset-at-maximum-file-size-tp26671492p26671492.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26671442</id>
	<title>Re: any work arounds for bug 2176</title>
	<published>2009-12-06T17:38:32Z</published>
	<updated>2009-12-06T17:38:32Z</updated>
	<author>
		<name>Brett Lymn</name>
	</author>
	<content type="html">On Wed, Dec 02, 2009 at 07:22:57PM +1300, Amos Jeffries wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Sorry. I attached it to the bug report.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;I manually applied the patch - I couldn't be bothered with patch for a
&lt;br&gt;simple #if removal. &amp;nbsp;The symptoms have changed. &amp;nbsp;We no longer get an
&lt;br&gt;auth pop up but at the end of the upload the browser displays:
&lt;br&gt;&lt;br&gt;Bad Request (Invalid Verb)
&lt;br&gt;&lt;br&gt;and the document is not shown in the list. &amp;nbsp;So, the patch made a
&lt;br&gt;difference but something else is amiss still.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Brett Lymn
&lt;br&gt;&amp;quot;Warning:
&lt;br&gt;The information contained in this email and any attached files is
&lt;br&gt;confidential to BAE Systems Australia. If you are not the intended
&lt;br&gt;recipient, any use, disclosure or copying of this email or any
&lt;br&gt;attachments is expressly prohibited. &amp;nbsp;If you have received this email
&lt;br&gt;in error, please notify us immediately. VIRUS: Every care has been
&lt;br&gt;taken to ensure this email and its attachments are virus free,
&lt;br&gt;however, any loss or damage incurred in using this email is not the
&lt;br&gt;sender's responsibility. &amp;nbsp;It is your responsibility to ensure virus
&lt;br&gt;checks are completed before installing any data sent in this email to
&lt;br&gt;your computer.&amp;quot;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/any-work-arounds-for-bug-2176-tp26603291p26671442.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26669439</id>
	<title>Re: Stable Squid version for windows OS</title>
	<published>2009-12-06T13:41:02Z</published>
	<updated>2009-12-06T13:41:02Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">On Sun, 6 Dec 2009 22:31:04 +0100, &amp;quot;Source Systems Technical&amp;quot;
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26669439&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;support@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Good day,
&lt;br&gt;&amp;gt; Can i use squid-3.0.STABLE20 with Windows OS? If not, which version of
&lt;br&gt;&amp;gt; squid
&lt;br&gt;&amp;gt; is more suitable for any version of windows OS?
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://squid.acmeconsulting.it/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://squid.acmeconsulting.it/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;gt; Does squid-cache/proxy support two (2) internet connections at the same
&lt;br&gt;&amp;gt; time
&lt;br&gt;&amp;gt; for a local network?
&lt;br&gt;&lt;br&gt;Squid supports HTTP over TCP. Whatever support the TCP router for the
&lt;br&gt;network provides is used.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Stable-Squid-version-for-windows-OS-tp26669318p26669439.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26669393</id>
	<title>Re: Squid failing to open some websites randomly ...</title>
	<published>2009-12-06T13:38:13Z</published>
	<updated>2009-12-06T13:38:13Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">On Sun, 06 Dec 2009 23:08:28 +0500, &amp;quot;Asim Ahmed @ Folio3&amp;quot;
&lt;br&gt;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26669393&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aahmed@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I am facing a wierd problem with my squid setup. I've installed squid on
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; a Dual Core machine with 2 GB of RAM and plenty of HDD space available.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Problem: When users try to open different websites (specially on bbc 
&lt;br&gt;&amp;gt; domain and on many other sites) they encountered following error: But 
&lt;br&gt;&amp;gt; when i try this URL form a different gateway that does not run squid, 
&lt;br&gt;&amp;gt; page opens successfully. I am running shorewall on this server for 
&lt;br&gt;&amp;gt; NATTING/Firewalling and REDIREC-ting port 80 traffic to squid as 
&lt;br&gt;&amp;gt; follows: (squid running on port 4040) and I've opened port 4040 on 
&lt;br&gt;&amp;gt; systems firewall.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; #ACTION &amp;nbsp; SOURCE &amp;nbsp; &amp;nbsp; DEST &amp;nbsp; &amp;nbsp; PROTO &amp;nbsp; &amp;nbsp;DEST PORT(S) &amp;nbsp; &amp;nbsp; SOURCE &amp;nbsp; &amp;nbsp;
&lt;/div&gt;ORIGINAL
&lt;br&gt;&amp;gt; # &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PORT(S) &amp;nbsp; &amp;nbsp;DEST
&lt;br&gt;&amp;gt; ACCEPT &amp;nbsp; &amp;nbsp;$FW &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;net &amp;nbsp; &amp;nbsp; &amp;nbsp;tcp &amp;nbsp; &amp;nbsp; &amp;nbsp;www
&lt;br&gt;&amp;gt; REDIRECT &amp;nbsp;loc &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4040 &amp;nbsp; &amp;nbsp; tcp &amp;nbsp; &amp;nbsp; &amp;nbsp;www &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-
&lt;br&gt;&amp;gt; 
&lt;br&gt;&lt;br&gt;&lt;br&gt;FWIW, I can't see any reason why it's failing other than a regular old
&lt;br&gt;network connection fail.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;gt; ERROR
&lt;br&gt;&amp;gt; The requested URL could not be retrieved
&lt;br&gt;&amp;gt;
&lt;br&gt;--------------------------------------------------------------------------------
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; The following error was encountered while trying to retrieve the URL: 
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://news.bbc.co.uk/1/hi/world/asia-pacific/8397717.stm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://news.bbc.co.uk/1/hi/world/asia-pacific/8397717.stm&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Connection to 212.58.226.142 failed.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The system returned: (111) Connection refused
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The remote host or network may be down. Please try the request again.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Your cache administrator is root.
&lt;br&gt;&amp;gt;
&lt;/div&gt;--------------------------------------------------------------------------------
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Generated Sun, 06 Dec 2009 17:51:35 GMT by LIANA (squid/3.0.STABLE20)
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; My squid.conf is as follows:
&lt;br&gt;&amp;gt; ===================
&lt;br&gt;&amp;gt; acl manager proto cache_object
&lt;br&gt;&amp;gt; acl localhost src 127.0.0.1/32
&lt;br&gt;&amp;gt; acl to_localhost dst 127.0.0.0/8 0.0.0.0/32
&lt;br&gt;&amp;gt; acl folio3Network src 192.168.4.0/24
&lt;br&gt;&amp;gt; acl SSL_ports port 443
&lt;br&gt;&amp;gt; acl Safe_ports port 80 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# http
&lt;br&gt;&amp;gt; acl Safe_ports port 21 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# ftp
&lt;br&gt;&amp;gt; acl Safe_ports port 443 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # https
&lt;br&gt;&amp;gt; acl Safe_ports port 70 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# gopher
&lt;br&gt;&amp;gt; acl Safe_ports port 210 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # wais
&lt;br&gt;&amp;gt; acl Safe_ports port 1025-65535 &amp;nbsp;# unregistered ports
&lt;br&gt;&amp;gt; acl Safe_ports port 280 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # http-mgmt
&lt;br&gt;&amp;gt; acl Safe_ports port 488 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # gss-http
&lt;br&gt;&amp;gt; acl Safe_ports port 591 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # filemaker
&lt;br&gt;&amp;gt; acl Safe_ports port 777 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # multiling http
&lt;br&gt;&amp;gt; acl CONNECT method CONNECT
&lt;br&gt;&amp;gt; acl super_users src &amp;quot;/etc/squid/f3_acls/super_users.acl&amp;quot;
&lt;br&gt;&amp;gt; acl gerrys_users src &amp;quot;/etc/squid/f3_acls/gerrys_groups.acl&amp;quot;
&lt;br&gt;&amp;gt; acl netsat_users src &amp;quot;/etc/squid/f3_acls/netsat_groups.acl&amp;quot;
&lt;br&gt;&amp;gt; acl managers src &amp;quot;/etc/squid/f3_acls/managers.acl&amp;quot;
&lt;br&gt;&amp;gt; acl blocked_sites dstdomain &amp;quot;/etc/squid/f3_acls/blocked_sites.acl&amp;quot;
&lt;br&gt;&amp;gt; acl blocked_request_mt req_mime_type -i 
&lt;br&gt;&amp;gt; &amp;quot;/etc/squid/f3_acls/blocked_mimetypes.acl&amp;quot;
&lt;br&gt;&amp;gt; acl blocked_reply_mt rep_mime_type -i 
&lt;br&gt;&amp;gt; &amp;quot;/etc/squid/f3_acls/blocked_mimetypes.acl&amp;quot;
&lt;br&gt;&amp;gt; acl gaming_sites dstdomain &amp;quot;/etc/squid/f3_acls/gaming_sites.acl&amp;quot;
&lt;br&gt;&amp;gt; acl server_machines src &amp;quot;/etc/squid/f3_acls/server_machines.acl&amp;quot;
&lt;br&gt;&amp;gt; acl working_hours time MTWHF 09:00-12:30
&lt;br&gt;&amp;gt; acl working_hours time MTWHF 14:00-18:30
&lt;br&gt;&amp;gt; acl gaming_hours time MTWHF 21:00-23:59
&lt;br&gt;&amp;gt; acl gaming_hours time MTWHF 01:00-07:00
&lt;br&gt;&amp;gt; http_access allow manager localhost
&lt;br&gt;&amp;gt; http_access deny manager
&lt;br&gt;&amp;gt; http_access deny !Safe_ports
&lt;br&gt;&amp;gt; http_access deny CONNECT !SSL_ports
&lt;br&gt;&amp;gt; http_access allow super_users
&lt;br&gt;&amp;gt; http_access deny working_hours blocked_sites
&lt;br&gt;&amp;gt; http_access deny working_hours blocked_request_mt
&lt;br&gt;&amp;gt; http_access deny !gaming_hours gaming_sites
&lt;br&gt;&amp;gt; http_access allow managers
&lt;br&gt;&amp;gt; http_access allow gerrys_users
&lt;br&gt;&amp;gt; http_access allow server_machines
&lt;br&gt;&amp;gt; http_access allow localhost
&lt;br&gt;&amp;gt; http_access deny all
&lt;br&gt;&amp;gt; http_reply_access deny working_hours blocked_reply_mt
&lt;br&gt;&amp;gt; icp_access allow folio3Network
&lt;br&gt;&amp;gt; icp_access deny all
&lt;br&gt;&amp;gt; htcp_access allow folio3Network
&lt;br&gt;&amp;gt; htcp_access deny all
&lt;br&gt;&amp;gt; http_port 4040 transparent
&lt;br&gt;&amp;gt; hierarchy_stoplist cgi-bin ?
&lt;br&gt;&amp;gt; cache_dir aufs /var/spool/squid 10240 16 256
&lt;br&gt;&amp;gt; access_log /var/log/squid/access.log squid
&lt;br&gt;&amp;gt; refresh_pattern ^ftp: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1440 &amp;nbsp; &amp;nbsp;20% &amp;nbsp; &amp;nbsp; 10080
&lt;br&gt;&amp;gt; refresh_pattern ^gopher: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1440 &amp;nbsp; &amp;nbsp;0% &amp;nbsp; &amp;nbsp; &amp;nbsp;1440
&lt;br&gt;&amp;gt; refresh_pattern (cgi-bin|\?) &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp; &amp;nbsp; 0% &amp;nbsp; &amp;nbsp; &amp;nbsp;0
&lt;/div&gt;&lt;br&gt;Missing '/'s &amp;nbsp; &amp;nbsp;(/cgi-bin/|\?)
&lt;br&gt;&lt;br&gt;&amp;gt; refresh_pattern . &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; 20% &amp;nbsp; &amp;nbsp; 4320
&lt;br&gt;&amp;gt; visible_hostname LIANA
&lt;br&gt;&amp;gt; icp_port 3130
&lt;br&gt;&amp;gt; coredump_dir /var/spool/squid
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Any idea what might be going wrong? Some times I suspect it could be a 
&lt;br&gt;&amp;gt; DNS issue but then why every thing works fine if I turn off squid and 
&lt;br&gt;&amp;gt; browse through shorewall only?
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-failing-to-open-some-websites-randomly-...-tp26667434p26669393.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26669318</id>
	<title>Stable Squid version for windows OS</title>
	<published>2009-12-06T13:31:04Z</published>
	<updated>2009-12-06T13:31:04Z</updated>
	<author>
		<name>Source Systems Technical</name>
	</author>
	<content type="html">Good day,
&lt;br&gt;Can i use squid-3.0.STABLE20 with Windows OS? If not, which version of squid
&lt;br&gt;is more suitable for any version of windows OS?
&lt;br&gt;Does squid-cache/proxy support two (2) internet connections at the same time
&lt;br&gt;for a local network?
&lt;br&gt;Regards,
&lt;br&gt;Yomi.
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Stable-Squid-version-for-windows-OS-tp26669318p26669318.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26667434</id>
	<title>Squid failing to open some websites randomly ...</title>
	<published>2009-12-06T10:08:28Z</published>
	<updated>2009-12-06T10:08:28Z</updated>
	<author>
		<name>Asim Ahmed @ Folio3</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I am facing a wierd problem with my squid setup. I've installed squid on 
&lt;br&gt;a Dual Core machine with 2 GB of RAM and plenty of HDD space available.
&lt;br&gt;&lt;br&gt;Problem: When users try to open different websites (specially on bbc 
&lt;br&gt;domain and on many other sites) they encountered following error: But 
&lt;br&gt;when i try this URL form a different gateway that does not run squid, 
&lt;br&gt;page opens successfully. I am running shorewall on this server for 
&lt;br&gt;NATTING/Firewalling and REDIREC-ting port 80 traffic to squid as 
&lt;br&gt;follows: (squid running on port 4040) and I've opened port 4040 on 
&lt;br&gt;systems firewall.
&lt;br&gt;&lt;br&gt;#ACTION &amp;nbsp; SOURCE &amp;nbsp; &amp;nbsp; DEST &amp;nbsp; &amp;nbsp; PROTO &amp;nbsp; &amp;nbsp;DEST PORT(S) &amp;nbsp; &amp;nbsp; SOURCE &amp;nbsp; &amp;nbsp; ORIGINAL
&lt;br&gt;# &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; PORT(S) &amp;nbsp; &amp;nbsp;DEST
&lt;br&gt;ACCEPT &amp;nbsp; &amp;nbsp;$FW &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;net &amp;nbsp; &amp;nbsp; &amp;nbsp;tcp &amp;nbsp; &amp;nbsp; &amp;nbsp;www
&lt;br&gt;REDIRECT &amp;nbsp;loc &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;4040 &amp;nbsp; &amp;nbsp; tcp &amp;nbsp; &amp;nbsp; &amp;nbsp;www &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;-
&lt;br&gt;&lt;br&gt;ERROR
&lt;br&gt;The requested URL could not be retrieved
&lt;br&gt;--------------------------------------------------------------------------------
&lt;br&gt;The following error was encountered while trying to retrieve the URL: 
&lt;br&gt;&lt;a href=&quot;http://news.bbc.co.uk/1/hi/world/asia-pacific/8397717.stm&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://news.bbc.co.uk/1/hi/world/asia-pacific/8397717.stm&lt;/a&gt;&lt;br&gt;&lt;br&gt;Connection to 212.58.226.142 failed.
&lt;br&gt;&lt;br&gt;The system returned: (111) Connection refused
&lt;br&gt;&lt;br&gt;The remote host or network may be down. Please try the request again.
&lt;br&gt;&lt;br&gt;Your cache administrator is root.
&lt;br&gt;--------------------------------------------------------------------------------
&lt;br&gt;Generated Sun, 06 Dec 2009 17:51:35 GMT by LIANA (squid/3.0.STABLE20)
&lt;br&gt;&lt;br&gt;My squid.conf is as follows:
&lt;br&gt;===================
&lt;br&gt;acl manager proto cache_object
&lt;br&gt;acl localhost src 127.0.0.1/32
&lt;br&gt;acl to_localhost dst 127.0.0.0/8 0.0.0.0/32
&lt;br&gt;acl folio3Network src 192.168.4.0/24
&lt;br&gt;acl SSL_ports port 443
&lt;br&gt;acl Safe_ports port 80 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# http
&lt;br&gt;acl Safe_ports port 21 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# ftp
&lt;br&gt;acl Safe_ports port 443 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # https
&lt;br&gt;acl Safe_ports port 70 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# gopher
&lt;br&gt;acl Safe_ports port 210 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # wais
&lt;br&gt;acl Safe_ports port 1025-65535 &amp;nbsp;# unregistered ports
&lt;br&gt;acl Safe_ports port 280 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # http-mgmt
&lt;br&gt;acl Safe_ports port 488 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # gss-http
&lt;br&gt;acl Safe_ports port 591 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # filemaker
&lt;br&gt;acl Safe_ports port 777 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # multiling http
&lt;br&gt;acl CONNECT method CONNECT
&lt;br&gt;acl super_users src &amp;quot;/etc/squid/f3_acls/super_users.acl&amp;quot;
&lt;br&gt;acl gerrys_users src &amp;quot;/etc/squid/f3_acls/gerrys_groups.acl&amp;quot;
&lt;br&gt;acl netsat_users src &amp;quot;/etc/squid/f3_acls/netsat_groups.acl&amp;quot;
&lt;br&gt;acl managers src &amp;quot;/etc/squid/f3_acls/managers.acl&amp;quot;
&lt;br&gt;acl blocked_sites dstdomain &amp;quot;/etc/squid/f3_acls/blocked_sites.acl&amp;quot;
&lt;br&gt;acl blocked_request_mt req_mime_type -i 
&lt;br&gt;&amp;quot;/etc/squid/f3_acls/blocked_mimetypes.acl&amp;quot;
&lt;br&gt;acl blocked_reply_mt rep_mime_type -i 
&lt;br&gt;&amp;quot;/etc/squid/f3_acls/blocked_mimetypes.acl&amp;quot;
&lt;br&gt;acl gaming_sites dstdomain &amp;quot;/etc/squid/f3_acls/gaming_sites.acl&amp;quot;
&lt;br&gt;acl server_machines src &amp;quot;/etc/squid/f3_acls/server_machines.acl&amp;quot;
&lt;br&gt;acl working_hours time MTWHF 09:00-12:30
&lt;br&gt;acl working_hours time MTWHF 14:00-18:30
&lt;br&gt;acl gaming_hours time MTWHF 21:00-23:59
&lt;br&gt;acl gaming_hours time MTWHF 01:00-07:00
&lt;br&gt;http_access allow manager localhost
&lt;br&gt;http_access deny manager
&lt;br&gt;http_access deny !Safe_ports
&lt;br&gt;http_access deny CONNECT !SSL_ports
&lt;br&gt;http_access allow super_users
&lt;br&gt;http_access deny working_hours blocked_sites
&lt;br&gt;http_access deny working_hours blocked_request_mt
&lt;br&gt;http_access deny !gaming_hours gaming_sites
&lt;br&gt;http_access allow managers
&lt;br&gt;http_access allow gerrys_users
&lt;br&gt;http_access allow server_machines
&lt;br&gt;http_access allow localhost
&lt;br&gt;http_access deny all
&lt;br&gt;http_reply_access deny working_hours blocked_reply_mt
&lt;br&gt;icp_access allow folio3Network
&lt;br&gt;icp_access deny all
&lt;br&gt;htcp_access allow folio3Network
&lt;br&gt;htcp_access deny all
&lt;br&gt;http_port 4040 transparent
&lt;br&gt;hierarchy_stoplist cgi-bin ?
&lt;br&gt;cache_dir aufs /var/spool/squid 10240 16 256
&lt;br&gt;access_log /var/log/squid/access.log squid
&lt;br&gt;refresh_pattern ^ftp: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 1440 &amp;nbsp; &amp;nbsp;20% &amp;nbsp; &amp;nbsp; 10080
&lt;br&gt;refresh_pattern ^gopher: &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1440 &amp;nbsp; &amp;nbsp;0% &amp;nbsp; &amp;nbsp; &amp;nbsp;1440
&lt;br&gt;refresh_pattern (cgi-bin|\?) &amp;nbsp; &amp;nbsp;0 &amp;nbsp; &amp;nbsp; &amp;nbsp; 0% &amp;nbsp; &amp;nbsp; &amp;nbsp;0
&lt;br&gt;refresh_pattern . &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 0 &amp;nbsp; &amp;nbsp; &amp;nbsp; 20% &amp;nbsp; &amp;nbsp; 4320
&lt;br&gt;visible_hostname LIANA
&lt;br&gt;icp_port 3130
&lt;br&gt;coredump_dir /var/spool/squid
&lt;br&gt;&lt;br&gt;Any idea what might be going wrong? Some times I suspect it could be a 
&lt;br&gt;DNS issue but then why every thing works fine if I turn off squid and 
&lt;br&gt;browse through shorewall only?
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Asim Ahmed Khan
&lt;br&gt;IT Manager,
&lt;br&gt;Folio3 (Pvt.) Ltd. www.folio3.com
&lt;br&gt;Direct: 92-21-4323721-4 Ext 110
&lt;br&gt;Email: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26667434&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;aahmed@...&lt;/a&gt;
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-failing-to-open-some-websites-randomly-...-tp26667434p26667434.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26666804</id>
	<title>RE: squid ceasing to function when interface goes down</title>
	<published>2009-12-06T08:59:14Z</published>
	<updated>2009-12-06T08:59:14Z</updated>
	<author>
		<name>tyler-53</name>
	</author>
	<content type="html">&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -------- Original Message --------
&lt;br&gt;&amp;gt; Subject: Re: [squid-users] squid ceasing to function when interface
&lt;br&gt;&amp;gt; goes down
&lt;br&gt;&amp;gt; From: Jose Ildefonso Camargo Tolosa &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666804&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;ildefonso.camargo@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Date: Sun, December 06, 2009 10:44 am
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666804&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tyler@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666804&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi!
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; This could come a little &amp;quot;off-topic&amp;quot;, but: which VPN are you using? if
&lt;br&gt;&amp;gt; you happen to be using OpenVPN, try adding the option &amp;quot;persist-tun&amp;quot;,
&lt;br&gt;&amp;gt; also, there is a chance that you can make squid actually restart when
&lt;br&gt;&amp;gt; the VPN goes down and up again (by using the &amp;quot;down&amp;quot; and &amp;quot;up&amp;quot; options,
&lt;br&gt;&amp;gt; that calls down and up scripts).
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Anyway, please keep us informed!
&lt;/div&gt;All of those are already done.
&lt;br&gt;&lt;br&gt;I've reset the cache. &amp;nbsp;rm -rf /var/cache/squid/* and let it rebuild it. 
&lt;br&gt;The cache seemed the only difference between this installation and two
&lt;br&gt;other ones with the same configs that remain stable... &amp;nbsp;If that doesn't
&lt;br&gt;work, I may need to replace the server.
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-ceasing-to-function-when-interface-goes-down-tp26645662p26666804.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26666694</id>
	<title>Re: squid ceasing to function when interface goes down</title>
	<published>2009-12-06T08:44:44Z</published>
	<updated>2009-12-06T08:44:44Z</updated>
	<author>
		<name>Jose Ildefonso Camargo Tolosa</name>
	</author>
	<content type="html">Hi!
&lt;br&gt;&lt;br&gt;This could come a little &amp;quot;off-topic&amp;quot;, but: which VPN are you using? if
&lt;br&gt;you happen to be using OpenVPN, try adding the option &amp;quot;persist-tun&amp;quot;,
&lt;br&gt;also, there is a chance that you can make squid actually restart when
&lt;br&gt;the VPN goes down and up again (by using the &amp;quot;down&amp;quot; and &amp;quot;up&amp;quot; options,
&lt;br&gt;that calls down and up scripts).
&lt;br&gt;&lt;br&gt;Anyway, please keep us informed!
&lt;br&gt;&lt;br&gt;I hope this helps,
&lt;br&gt;&lt;br&gt;Ildefonso Camargo
&lt;br&gt;&lt;br&gt;On Mon, Dec 7, 2009 at 11:22 AM, &amp;nbsp;&amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666694&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;tyler@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; -------- Original Message --------
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: [squid-users] squid ceasing to function when interface
&lt;br&gt;&amp;gt;&amp;gt; goes down
&lt;br&gt;&amp;gt;&amp;gt; From: Amos Jeffries &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666694&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid3@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Date: Sat, December 05, 2009 5:02 pm
&lt;br&gt;&amp;gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666694&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt;   1) server_persistent_connections off. This should prevent Squid using
&lt;br&gt;&amp;gt;&amp;gt; any connections to the parent which are possibly hung.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;   2) Make sure ICMP is built in and going so Squid can actively measure
&lt;br&gt;&amp;gt;&amp;gt; the network link to the parent. This is a simpler up-detection
&lt;br&gt;&amp;gt;&amp;gt; replacement for ICP which you have disabled by using &amp;quot;no-query&amp;quot;.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I had hoped this had solved the problem, however this morning I woke to
&lt;br&gt;&amp;gt; endless 404's and screaming customers like usual.  nothing in cache.log.
&lt;br&gt;&amp;gt;  what is going on here!?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-ceasing-to-function-when-interface-goes-down-tp26645662p26666694.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26666147</id>
	<title>RE: squid ceasing to function when interface goes down</title>
	<published>2009-12-06T07:52:01Z</published>
	<updated>2009-12-06T07:52:01Z</updated>
	<author>
		<name>tyler-53</name>
	</author>
	<content type="html">&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; -------- Original Message --------
&lt;br&gt;&amp;gt; Subject: Re: [squid-users] squid ceasing to function when interface
&lt;br&gt;&amp;gt; goes down
&lt;br&gt;&amp;gt; From: Amos Jeffries &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666147&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid3@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Date: Sat, December 05, 2009 5:02 pm
&lt;br&gt;&amp;gt; To: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26666147&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid-users@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;nbsp; 1) server_persistent_connections off. This should prevent Squid using 
&lt;br&gt;&amp;gt; any connections to the parent which are possibly hung.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;nbsp; 2) Make sure ICMP is built in and going so Squid can actively measure 
&lt;br&gt;&amp;gt; the network link to the parent. This is a simpler up-detection 
&lt;br&gt;&amp;gt; replacement for ICP which you have disabled by using &amp;quot;no-query&amp;quot;.
&lt;/div&gt;&lt;br&gt;&lt;br&gt;I had hoped this had solved the problem, however this morning I woke to
&lt;br&gt;endless 404's and screaming customers like usual. &amp;nbsp;nothing in cache.log.
&lt;br&gt;&amp;nbsp;what is going on here!?
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-ceasing-to-function-when-interface-goes-down-tp26645662p26666147.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26666073</id>
	<title>Squid does not work after origin's server DirectoryIndex change</title>
	<published>2009-12-06T07:44:37Z</published>
	<updated>2009-12-06T07:44:37Z</updated>
	<author>
		<name>Adam Squids</name>
	</author>
	<content type="html">I had index.html redirecting to &lt;a href=&quot;http://www.domain.com/online/1.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.domain.com/online/1.html&lt;/a&gt;&amp;nbsp;in
&lt;br&gt;my origin server. Now I changed Apache configs and set DirectoryIndex
&lt;br&gt;to be /online/1.html. When I browse straight to my origin, it works
&lt;br&gt;fine. When I browse via my squid server I get &amp;nbsp;ERR_READ_ERROR 104
&lt;br&gt;&lt;br&gt;I assume that in this case, 'connection reset by peer', peer==Apache
&lt;br&gt;origin. How come I can access it when I browse straight to it ? and it
&lt;br&gt;even works perfectly?
&lt;br&gt;What should I look for in cache.log ? I did not find anything aspecially odd :)
&lt;br&gt;&lt;br&gt;Many thanks,
&lt;br&gt;&lt;br&gt;Adam
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-does-not-work-after-origin%27s-server-DirectoryIndex-change-tp26666073p26666073.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26665614</id>
	<title>Hudson build is back to normal: 3.1-i386-Debian-sid #48</title>
	<published>2009-12-06T06:44:39Z</published>
	<updated>2009-12-06T06:44:39Z</updated>
	<author>
		<name>noc-8</name>
	</author>
	<content type="html">See &amp;lt;&lt;a href=&quot;http://build.squid-cache.org/job/3.1-i386-Debian-sid/48/changes&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://build.squid-cache.org/job/3.1-i386-Debian-sid/48/changes&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Development-f22484.html&quot; embed=&quot;fixTarget[22484]&quot; target=&quot;_top&quot; &gt;Squid - Development&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Build-failed-in-Hudson%3A-3.1-i386-Debian-sid--47-tp26662298p26665614.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26665446</id>
	<title>squid receives (null) instead of http</title>
	<published>2009-12-06T06:20:05Z</published>
	<updated>2009-12-06T06:20:05Z</updated>
	<author>
		<name>Arthur Titeica</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;Recently I see lots of the following in my squid logs
&lt;br&gt;&lt;br&gt;1259130624.131 &amp;nbsp; &amp;nbsp; &amp;nbsp;0 89.42.191.44 NONE/400 3172 GET
&lt;br&gt;(null)://example.com/Contab/Rapoarte/Rapoarte_obisnuite.asp?strCategorie=ContPart
&lt;br&gt;- NONE/- text/html
&lt;br&gt;&lt;br&gt;1259141404.195 &amp;nbsp; &amp;nbsp; &amp;nbsp;0 89.122.203.185 NONE/400 3200 POST
&lt;br&gt;(null)://example.com/Contab/NoteContabile/NoteContabUpd.asp?op=MODPOZ&amp;NotaContabId=185
&lt;br&gt;- NONE /- text/html
&lt;br&gt;&lt;br&gt;&lt;br&gt;Squid is: Squid Cache: Version 3.1.0.14-20091120 on Ubuntu Server 9.04
&lt;br&gt;x86 and the clients are Windows mostly with IE8 but also with older IE,
&lt;br&gt;Opera and Firefox.
&lt;br&gt;&lt;br&gt;Squid is acting as a reverse proxy in this case and it has worked like
&lt;br&gt;that for at least an year now. Only recently I started seeing these kind
&lt;br&gt;of errors. The client receives the usual squid error and a client
&lt;br&gt;refresh solves it in general.
&lt;br&gt;&lt;br&gt;Regards,
&lt;br&gt;&lt;br&gt;Arthur
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (564 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26665446/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-receives-%28null%29-instead-of-http-tp26665446p26665446.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26663753</id>
	<title>Re: can't compile 3.1.0.15</title>
	<published>2009-12-06T02:47:09Z</published>
	<updated>2009-12-06T02:47:09Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">Landy Landy wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I'm trying to upgrade from 3.1.0.14 to 3.1.0.15 but I'm getting an error when compiling: 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; c MessageRep.cc &amp;nbsp;-fPIC -DPIC -o .libs/MessageRep.o
&lt;br&gt;&amp;gt; cc1plus: warnings being treated as errors
&lt;br&gt;&amp;gt; MessageRep.cc: In member function âlibecap::Name Adaptation::Ecap::FirstLineRep::protocol() constâ:
&lt;br&gt;&amp;gt; MessageRep.cc:120: warning: enumeration value âPROTO_ICYâ not handled in switch
&lt;br&gt;&amp;gt; make[4]: *** [MessageRep.lo] Error 1
&lt;br&gt;&amp;gt; make[4]: Leaving directory `/workingdir/squid-3.1.0.15/src/adaptation/ecap'
&lt;br&gt;&amp;gt; make[3]: *** [all-recursive] Error 1
&lt;br&gt;&amp;gt; make[3]: Leaving directory `/workingdir/squid-3.1.0.15/src/adaptation'
&lt;br&gt;&amp;gt; make[2]: *** [all-recursive] Error 1
&lt;br&gt;&amp;gt; make[2]: Leaving directory `/workingdir/squid-3.1.0.15/src'
&lt;br&gt;&amp;gt; make[1]: *** [all] Error 2
&lt;br&gt;&amp;gt; make[1]: Leaving directory `/workingdir/squid-3.1.0.15/src'
&lt;br&gt;&amp;gt; make: *** [all-recursive] Error 1
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; These are the options I'm using:
&lt;br&gt;&amp;gt; ./configure --prefix=/usr/local/squid \
&lt;br&gt;&amp;gt; --sysconfdir=/etc/squid3.1 \
&lt;br&gt;&amp;gt; --enable-delay-pools \
&lt;br&gt;&amp;gt; --enable-kill-parent-hack \
&lt;br&gt;&amp;gt; --disable-htcp \
&lt;br&gt;&amp;gt; --enable-default-err-language=Spanish \
&lt;br&gt;&amp;gt; --enable-linux-netfilter \
&lt;br&gt;&amp;gt; --disable-ident-lookups \
&lt;br&gt;&amp;gt; --localstatedir=/var/log/squid3.1 \
&lt;br&gt;&amp;gt; --enable-stacktraces \
&lt;br&gt;&amp;gt; --with-default-user=proxy \
&lt;br&gt;&amp;gt; --with-large-files \
&lt;br&gt;&amp;gt; --enable-icap-client \
&lt;br&gt;&amp;gt; --enable-ecap \
&lt;br&gt;&amp;gt; --enable-async-io \
&lt;br&gt;&amp;gt; --enable-storeio=&amp;quot;aufs&amp;quot; \
&lt;br&gt;&amp;gt; --enable-removal-policies=&amp;quot;heap,lru&amp;quot; \
&lt;br&gt;&amp;gt; --with-maxfd=16384
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; These options worked with 3.1.0.14 don't know why is not compiling 3.1.0.15.
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;3.1.0.15 add support for SHOUTcast traffic. eCAP does not have the code 
&lt;br&gt;to handle it yet.
&lt;br&gt;&lt;br&gt;Band-aid patch just applied to 3.1:
&lt;br&gt;&lt;a href=&quot;http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-9822.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.squid-cache.org/Versions/v3/3.1/changesets/squid-3.1-9822.patch&lt;/a&gt;&lt;br&gt;&lt;br&gt;This should get it building, though I'm not sure of what will happen to 
&lt;br&gt;eCAP when ICY passes through it.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/can%27t-compile-3.1.0.15-tp26661923p26663753.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26663696</id>
	<title>Re: squid failing every 5 minutes</title>
	<published>2009-12-06T02:36:27Z</published>
	<updated>2009-12-06T02:36:27Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">Landy Landy wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hello.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I'm reposting about squid stoping and restarting every 5 minutes. I didn't get any more responses about it last time I posted and havent find a solution to the problem.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Here's part of syslog:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 21:50:38 optimum-router squid[4769]: Squid Parent: child process 11973 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 21:50:41 optimum-router squid[4769]: Squid Parent: child process 12061 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 21:55:35 optimum-router squid[4769]: Squid Parent: child process 12061 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 21:55:38 optimum-router squid[4769]: Squid Parent: child process 12183 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:00:35 optimum-router squid[4769]: Squid Parent: child process 12183 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:00:38 optimum-router squid[4769]: Squid Parent: child process 12252 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:05:36 optimum-router squid[4769]: Squid Parent: child process 12252 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:05:39 optimum-router squid[4769]: Squid Parent: child process 12313 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:07:58 optimum-router squid[12391]: Squid Parent: child process 12393 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:10:36 optimum-router squid[12391]: Squid Parent: child process 12393 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:10:39 optimum-router squid[12391]: Squid Parent: child process 12522 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:15:41 optimum-router squid[12391]: Squid Parent: child process 12522 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:15:44 optimum-router squid[12391]: Squid Parent: child process 31594 started
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:20:35 optimum-router squid[12391]: Squid Parent: child process 31594 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:20:38 optimum-router squid[12391]: Squid Parent: child process 5466 started
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:25:36 optimum-router squid[12391]: Squid Parent: child process 5466 exited due to signal 6 with status 0
&lt;br&gt;&amp;gt; Dec &amp;nbsp;5 22:25:39 optimum-router squid[12391]: Squid Parent: child process 13301 started
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; And here's cache.log 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 2009/12/05 22:15:55| IpIntercept.cc(137) NetfilterInterception: &amp;nbsp;NF getsockopt(SO_ORIGINAL_DST) failed on FD 14: (2) No such file or directory
&lt;br&gt;&amp;gt; 2009/12/05 22:15:55| IpIntercept.cc(137) NetfilterInterception: &amp;nbsp;NF getsockopt(SO_ORIGINAL_DST) failed on FD 15: (2) No such file or directory
&lt;/div&gt;&lt;br&gt;First problem: the above errors are due to non-NATed traffic arriving at 
&lt;br&gt;a squid port flagged with &amp;quot;intercept&amp;quot; or &amp;quot;transparent&amp;quot;.
&lt;br&gt;&lt;br&gt;This is not a safe situation. You should have different ports for NAT 
&lt;br&gt;intercepted traffic and normal traffic.
&lt;br&gt;&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; (squid)(death+0x4b)[0x818b8cb]
&lt;br&gt;&amp;gt; [0xb7fb3420]
&lt;br&gt;&amp;gt; /usr/local/lib/ecap_adapter_gzip.so(_ZN7Adapter7Xaction17noteVbContentDoneEb+0x61)[0xb7aba411]
&lt;br&gt;&amp;gt; (squid)(_ZN10Adaptation4Ecap10XactionRep23noteBodyProductionEndedE8RefCountI8BodyPipeE+0x61)[0x81fdd61]
&lt;br&gt;&amp;gt; (squid)(_ZN12UnaryMemFunTI12BodyConsumer8RefCountI8BodyPipeEE6doDialEv+0x48)[0x80f1208]
&lt;br&gt;&amp;gt; (squid)(_ZN9JobDialer4dialER9AsyncCall+0x51)[0x8199661]
&lt;br&gt;&amp;gt; (squid)(_ZN10AsyncCallTI18BodyConsumerDialerE4fireEv+0x18)[0x80f1138]
&lt;br&gt;&amp;gt; (squid)(_ZN9AsyncCall4makeEv+0x17b)[0x819888b]
&lt;br&gt;&amp;gt; (squid)(_ZN14AsyncCallQueue8fireNextEv+0xf9)[0x819b4a9]
&lt;br&gt;&amp;gt; (squid)(_ZN14AsyncCallQueue4fireEv+0x28)[0x819b5a8]
&lt;br&gt;&amp;gt; (squid)(_ZN9EventLoop13dispatchCallsEv+0x13)[0x81096c3]
&lt;br&gt;&amp;gt; (squid)(_ZN9EventLoop7runOnceEv+0xf6)[0x81098b6]
&lt;br&gt;&amp;gt; (squid)(_ZN9EventLoop3runEv+0x28)[0x8109988]
&lt;br&gt;&amp;gt; (squid)(_Z9SquidMainiPPc+0x4b5)[0x8151e75]
&lt;br&gt;&amp;gt; (squid)(main+0x27)[0x81522f7]
&lt;br&gt;&amp;gt; /lib/tls/i686/cmov/libc.so.6(__libc_start_main+0xc8)[0xb7cfaea8]
&lt;br&gt;&amp;gt; (squid)(__gxx_personality_v0+0x155)[0x80bd081]
&lt;br&gt;&amp;gt; FATAL: Received Segment Violation...dying.
&lt;br&gt;&amp;gt; 2009/12/05 22:20:35| storeDirWriteCleanLogs: Starting...
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;eCAP adapter is crashing when Squid runs it's end-of-object handler.
&lt;br&gt;&lt;br&gt;Also, a bug in Squid is causing Squid to fail catching the error and die 
&lt;br&gt;itself.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-failing-every-5-minutes-tp26661683p26663696.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26663629</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-06T02:25:39Z</published>
	<updated>2009-12-06T02:25:39Z</updated>
	<author>
		<name>Amos Jeffries-2</name>
	</author>
	<content type="html">Guy Bashkansky wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Amos, thanks for the links. &amp;nbsp;I've looked at the mailing list and the
&lt;br&gt;&amp;gt; open bugs, and could not find something similar to what I see, with
&lt;br&gt;&amp;gt; the 10 minutes period.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; We're using a customized version of Squid 2.4 STABLE6, and it's not in
&lt;br&gt;&amp;gt; my power to upgrade it to any later version... &amp;nbsp;It runs on FreeBSD
&lt;br&gt;&amp;gt; 6.2-RELEASE-p9 amd64 servers.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I know I need some profiling/debugging information to determine where
&lt;br&gt;&amp;gt; CPU spends its cycles, but on these servers most usual tools are
&lt;br&gt;&amp;gt; either absent or not working very well:
&lt;br&gt;&amp;gt; There's no 'oprofile' for FreeBSD, 'pmcstat' fails to run (no lib?),
&lt;br&gt;&amp;gt; 'gprof' does not give info beyond parseConfigFile() even in my custom
&lt;br&gt;&amp;gt; profiling-enabled version with -N, 'gdb' does not recognize debug
&lt;br&gt;&amp;gt; info, and 'strace' is not installed.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; I've found 'truss' command to be working and traced system calls made
&lt;br&gt;&amp;gt; by the squid process, trying to recognize some patterns -- noticed
&lt;br&gt;&amp;gt; that during CPU load spike write() sometimes returns EPIPE, 'Broken
&lt;br&gt;&amp;gt; pipe'.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Does my version (2.4 STABLE6) ring any bells?
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;br&gt;Sorry, 2.4 was ancient history when I joined the project. All I know 
&lt;br&gt;about it is the list of features added that release.
&lt;br&gt;&lt;br&gt;Amos
&lt;br&gt;-- 
&lt;br&gt;Please be using
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;nbsp; &amp;nbsp;Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26663629.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26662298</id>
	<title>Build failed in Hudson: 3.1-i386-Debian-sid #47</title>
	<published>2009-12-05T20:57:00Z</published>
	<updated>2009-12-05T20:57:00Z</updated>
	<author>
		<name>noc-8</name>
	</author>
	<content type="html">See &amp;lt;&lt;a href=&quot;http://build.squid-cache.org/job/3.1-i386-Debian-sid/47/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://build.squid-cache.org/job/3.1-i386-Debian-sid/47/&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;------------------------------------------
&lt;br&gt;Started by upstream project &amp;quot;3.1-amd64-CentOS-5.3&amp;quot; build number 59
&lt;br&gt;Building remotely on rio.treenet
&lt;br&gt;&lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1&lt;/a&gt;&amp;nbsp;is permanently redirected to &lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1/&lt;/a&gt;&lt;br&gt;bzr: ERROR: Invalid http response for &lt;a href=&quot;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1/.bzr/branch/tags:&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bzr.squid-cache.org/bzr/squid3/branches/SQUID_3_1/.bzr/branch/tags:&lt;/a&gt;&amp;nbsp;Unable to handle http code 504: Gateway Time-out
&lt;br&gt;ERROR: Failed to pull
&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Development-f22484.html&quot; embed=&quot;fixTarget[22484]&quot; target=&quot;_top&quot; &gt;Squid - Development&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Build-failed-in-Hudson%3A-3.1-i386-Debian-sid--47-tp26662298p26662298.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26662280</id>
	<title>Hudson build is back to normal: 3.1-amd64-CentOS-5.3 #59</title>
	<published>2009-12-05T20:51:00Z</published>
	<updated>2009-12-05T20:51:00Z</updated>
	<author>
		<name>noc-8</name>
	</author>
	<content type="html">See &amp;lt;&lt;a href=&quot;http://build.squid-cache.org/job/3.1-amd64-CentOS-5.3/59/changes&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://build.squid-cache.org/job/3.1-amd64-CentOS-5.3/59/changes&lt;/a&gt;&amp;gt;
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Development-f22484.html&quot; embed=&quot;fixTarget[22484]&quot; target=&quot;_top&quot; &gt;Squid - Development&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Build-failed-in-Hudson%3A-3.1-amd64-CentOS-5.3--58-tp26590450p26662280.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26661923</id>
	<title>can't compile 3.1.0.15</title>
	<published>2009-12-05T19:24:04Z</published>
	<updated>2009-12-05T19:24:04Z</updated>
	<author>
		<name>Landy Landy</name>
	</author>
	<content type="html">I'm trying to upgrade from 3.1.0.14 to 3.1.0.15 but I'm getting an error when compiling: 
&lt;br&gt;&lt;br&gt;c MessageRep.cc &amp;nbsp;-fPIC -DPIC -o .libs/MessageRep.o
&lt;br&gt;cc1plus: warnings being treated as errors
&lt;br&gt;MessageRep.cc: In member function âlibecap::Name Adaptation::Ecap::FirstLineRep::protocol() constâ:
&lt;br&gt;MessageRep.cc:120: warning: enumeration value âPROTO_ICYâ not handled in switch
&lt;br&gt;make[4]: *** [MessageRep.lo] Error 1
&lt;br&gt;make[4]: Leaving directory `/workingdir/squid-3.1.0.15/src/adaptation/ecap'
&lt;br&gt;make[3]: *** [all-recursive] Error 1
&lt;br&gt;make[3]: Leaving directory `/workingdir/squid-3.1.0.15/src/adaptation'
&lt;br&gt;make[2]: *** [all-recursive] Error 1
&lt;br&gt;make[2]: Leaving directory `/workingdir/squid-3.1.0.15/src'
&lt;br&gt;make[1]: *** [all] Error 2
&lt;br&gt;make[1]: Leaving directory `/workingdir/squid-3.1.0.15/src'
&lt;br&gt;make: *** [all-recursive] Error 1
&lt;br&gt;&lt;br&gt;&lt;br&gt;These are the options I'm using:
&lt;br&gt;./configure --prefix=/usr/local/squid \
&lt;br&gt;--sysconfdir=/etc/squid3.1 \
&lt;br&gt;--enable-delay-pools \
&lt;br&gt;--enable-kill-parent-hack \
&lt;br&gt;--disable-htcp \
&lt;br&gt;--enable-default-err-language=Spanish \
&lt;br&gt;--enable-linux-netfilter \
&lt;br&gt;--disable-ident-lookups \
&lt;br&gt;--localstatedir=/var/log/squid3.1 \
&lt;br&gt;--enable-stacktraces \
&lt;br&gt;--with-default-user=proxy \
&lt;br&gt;--with-large-files \
&lt;br&gt;--enable-icap-client \
&lt;br&gt;--enable-ecap \
&lt;br&gt;--enable-async-io \
&lt;br&gt;--enable-storeio=&amp;quot;aufs&amp;quot; \
&lt;br&gt;--enable-removal-policies=&amp;quot;heap,lru&amp;quot; \
&lt;br&gt;--with-maxfd=16384
&lt;br&gt;&lt;br&gt;&lt;br&gt;These options worked with 3.1.0.14 don't know why is not compiling 3.1.0.15.
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/can%27t-compile-3.1.0.15-tp26661923p26661923.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26661843</id>
	<title>Re: Squid at 100% CPU with 10 minutes period</title>
	<published>2009-12-05T19:06:01Z</published>
	<updated>2009-12-05T19:06:01Z</updated>
	<author>
		<name>Guy Bashkansky</name>
	</author>
	<content type="html">Amos, thanks for the links. &amp;nbsp;I've looked at the mailing list and the
&lt;br&gt;open bugs, and could not find something similar to what I see, with
&lt;br&gt;the 10 minutes period.
&lt;br&gt;&lt;br&gt;We're using a customized version of Squid 2.4 STABLE6, and it's not in
&lt;br&gt;my power to upgrade it to any later version... &amp;nbsp;It runs on FreeBSD
&lt;br&gt;6.2-RELEASE-p9 amd64 servers.
&lt;br&gt;&lt;br&gt;I know I need some profiling/debugging information to determine where
&lt;br&gt;CPU spends its cycles, but on these servers most usual tools are
&lt;br&gt;either absent or not working very well:
&lt;br&gt;There's no 'oprofile' for FreeBSD, 'pmcstat' fails to run (no lib?),
&lt;br&gt;'gprof' does not give info beyond parseConfigFile() even in my custom
&lt;br&gt;profiling-enabled version with -N, 'gdb' does not recognize debug
&lt;br&gt;info, and 'strace' is not installed.
&lt;br&gt;&lt;br&gt;I've found 'truss' command to be working and traced system calls made
&lt;br&gt;by the squid process, trying to recognize some patterns -- noticed
&lt;br&gt;that during CPU load spike write() sometimes returns EPIPE, 'Broken
&lt;br&gt;pipe'.
&lt;br&gt;&lt;br&gt;Does my version (2.4 STABLE6) ring any bells?
&lt;br&gt;&lt;br&gt;&lt;br&gt;On Sat, Dec 5, 2009 at 3:33 AM, Amos Jeffries &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26661843&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;squid3@...&lt;/a&gt;&amp;gt; wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Guy Bashkansky wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Amos,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Where can I find a list of the solved &amp;quot;Squid uses 100% CPU&amp;quot; bugs?  It
&lt;br&gt;&amp;gt;&amp;gt; would help me figure out which one I may be experiencing.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Sorry for being gruff.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The mailing list queries:
&lt;br&gt;&amp;gt;  &lt;a href=&quot;http://squid.markmail.org/search/?q=squid+uses+100%25+cpu&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://squid.markmail.org/search/?q=squid+uses+100%25+cpu&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The remaining open bugs mentioning
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://bugs.squid-cache.org/buglist.cgi?quicksearch=100%25+CPU&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://bugs.squid-cache.org/buglist.cgi?quicksearch=100%25+CPU&lt;/a&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The closed ones are hard to find as they have been re-named to say what the actual problems was.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Which release and version of squid is this?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; When I attach gdb to the running squid process, it does not find
&lt;br&gt;&amp;gt;&amp;gt; debugging info, despite compiling with -g flag (maybe a gdb setup
&lt;br&gt;&amp;gt;&amp;gt; problem, nm does show symbols).
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; When I try to use gprof for profiling (squid compiled with -pg),
&lt;br&gt;&amp;gt;&amp;gt; squid.gmon contains only the initial configuration functions
&lt;br&gt;&amp;gt;&amp;gt; profiling.  I stop squid with -k shutdown signal so it exits normally
&lt;br&gt;&amp;gt;&amp;gt; (which is necessary to produce squid.gmon).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Squid needs to be started with -N to prevent forking a child daemon that does all the actual work. The main process can then be traced.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Amos
&lt;br&gt;&amp;gt; --
&lt;br&gt;&amp;gt; Please be using
&lt;br&gt;&amp;gt;  Current Stable Squid 2.7.STABLE7 or 3.0.STABLE20
&lt;br&gt;&amp;gt;  Current Beta Squid 3.1.0.15
&lt;br&gt;&lt;/div&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Squid-at-100--CPU-with-10-minutes-period-tp26649100p26661843.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26661683</id>
	<title>squid failing every 5 minutes</title>
	<published>2009-12-05T18:29:59Z</published>
	<updated>2009-12-05T18:29:59Z</updated>
	<author>
		<name>Landy Landy</name>
	</author>
	<content type="html">Hello.
&lt;br&gt;&lt;br&gt;I'm reposting about squid stoping and restarting every 5 minutes. I didn't get any more responses about it last time I posted and havent find a solution to the problem.
&lt;br&gt;&lt;br&gt;Here's part of syslog:
&lt;br&gt;&lt;br&gt;Dec &amp;nbsp;5 21:50:38 optimum-router squid[4769]: Squid Parent: child process 11973 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 21:50:41 optimum-router squid[4769]: Squid Parent: child process 12061 started
&lt;br&gt;Dec &amp;nbsp;5 21:55:35 optimum-router squid[4769]: Squid Parent: child process 12061 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 21:55:38 optimum-router squid[4769]: Squid Parent: child process 12183 started
&lt;br&gt;Dec &amp;nbsp;5 22:00:35 optimum-router squid[4769]: Squid Parent: child process 12183 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:00:38 optimum-router squid[4769]: Squid Parent: child process 12252 started
&lt;br&gt;Dec &amp;nbsp;5 22:05:36 optimum-router squid[4769]: Squid Parent: child process 12252 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:05:39 optimum-router squid[4769]: Squid Parent: child process 12313 started
&lt;br&gt;Dec &amp;nbsp;5 22:07:58 optimum-router squid[12391]: Squid Parent: child process 12393 started
&lt;br&gt;Dec &amp;nbsp;5 22:10:36 optimum-router squid[12391]: Squid Parent: child process 12393 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:10:39 optimum-router squid[12391]: Squid Parent: child process 12522 started
&lt;br&gt;Dec &amp;nbsp;5 22:15:41 optimum-router squid[12391]: Squid Parent: child process 12522 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:15:44 optimum-router squid[12391]: Squid Parent: child process 31594 started
&lt;br&gt;Dec &amp;nbsp;5 22:20:35 optimum-router squid[12391]: Squid Parent: child process 31594 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:20:38 optimum-router squid[12391]: Squid Parent: child process 5466 started
&lt;br&gt;&lt;br&gt;Dec &amp;nbsp;5 22:25:36 optimum-router squid[12391]: Squid Parent: child process 5466 exited due to signal 6 with status 0
&lt;br&gt;Dec &amp;nbsp;5 22:25:39 optimum-router squid[12391]: Squid Parent: child process 13301 started
&lt;br&gt;&lt;br&gt;&lt;br&gt;And here's cache.log 
&lt;br&gt;&lt;br&gt;2009/12/05 22:15:55| IpIntercept.cc(137) NetfilterInterception: &amp;nbsp;NF getsockopt(SO_ORIGINAL_DST) failed on FD 14: (2) No such file or directory
&lt;br&gt;2009/12/05 22:15:55| IpIntercept.cc(137) NetfilterInterception: &amp;nbsp;NF getsockopt(SO_ORIGINAL_DST) failed on FD 15: (2) No such file or directory
&lt;br&gt;(squid)(death+0x4b)[0x818b8cb]
&lt;br&gt;[0xb7fb3420]
&lt;br&gt;/usr/local/lib/ecap_adapter_gzip.so(_ZN7Adapter7Xaction17noteVbContentDoneEb+0x61)[0xb7aba411]
&lt;br&gt;(squid)(_ZN10Adaptation4Ecap10XactionRep23noteBodyProductionEndedE8RefCountI8BodyPipeE+0x61)[0x81fdd61]
&lt;br&gt;(squid)(_ZN12UnaryMemFunTI12BodyConsumer8RefCountI8BodyPipeEE6doDialEv+0x48)[0x80f1208]
&lt;br&gt;(squid)(_ZN9JobDialer4dialER9AsyncCall+0x51)[0x8199661]
&lt;br&gt;(squid)(_ZN10AsyncCallTI18BodyConsumerDialerE4fireEv+0x18)[0x80f1138]
&lt;br&gt;(squid)(_ZN9AsyncCall4makeEv+0x17b)[0x819888b]
&lt;br&gt;(squid)(_ZN14AsyncCallQueue8fireNextEv+0xf9)[0x819b4a9]
&lt;br&gt;(squid)(_ZN14AsyncCallQueue4fireEv+0x28)[0x819b5a8]
&lt;br&gt;(squid)(_ZN9EventLoop13dispatchCallsEv+0x13)[0x81096c3]
&lt;br&gt;(squid)(_ZN9EventLoop7runOnceEv+0xf6)[0x81098b6]
&lt;br&gt;(squid)(_ZN9EventLoop3runEv+0x28)[0x8109988]
&lt;br&gt;(squid)(_Z9SquidMainiPPc+0x4b5)[0x8151e75]
&lt;br&gt;(squid)(main+0x27)[0x81522f7]
&lt;br&gt;/lib/tls/i686/cmov/libc.so.6(__libc_start_main+0xc8)[0xb7cfaea8]
&lt;br&gt;(squid)(__gxx_personality_v0+0x155)[0x80bd081]
&lt;br&gt;FATAL: Received Segment Violation...dying.
&lt;br&gt;2009/12/05 22:20:35| storeDirWriteCleanLogs: Starting...
&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; 
&lt;br&gt;&lt;p&gt;From forum: &lt;a href=&quot;http://old.nabble.com/Squid---Users-f22482.html&quot; embed=&quot;fixTarget[22482]&quot; target=&quot;_top&quot; &gt;Squid - Users&lt;/a&gt;&lt;/p&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/squid-failing-every-5-minutes-tp26661683p26661683.html" />
</entry>

</feed>
