Wednesday, February 18, 2009

Have you had any bizarre IM messages from a person with “coho” in his screen name?

I was moving some Visual Studio projects around when an odd AIM window popped up.  It was from someone named “limbercoho” and the message was “Hail, Fellow”.  I usually close unsolicited AIM messages without even looking at them.  There are other ways to get in tougc with me, I view anything unsolicited from AIM or MSN with more than a little suspicion.

At that momemt, my PC was busy moving files around, so I had a some spare bandwidth and decided to see what was going on.  I responded back with “Hail” and it got a little wierd:

limbercoho: Hail, fellow!
me: Hail
limbercoho: hail?
me: Yes?
limbercoho: hell yes?

It didn’t take long to realize that something was just not right.  Going on the assumption that limberoho was some sort of whack job, I decided to do a Google check on that name.  The second hit was on Nixie Pixel’s blog, List of AIM Fish Bots – Salmon, Coho, and Trout.  There is an organization called “Project Upstream” that created the robotic fishbots.

The fishbot takes two random IM users and sends a greeting to each one and then connects each user to each other user.  They don’t see the other person’s screen name, they see a fishbot generated name like LimberCoho or BakedCoho.  Basically a random word plus “coho”.  Previous incarnations used “Salmon” and “Trout”.

Once I figured out what was going on, I IM’d the link from Nixie’s blog.  Understandably, he responded back with “I’m not going to click that link”.  That made sense, I wouldn’t have clicked a link that a stranger had send me.  So I explained what was going on and he asked how to block it.  That would be the annoying part, you can’t block randomly generated names.  There is an opt-out mechanism, but you wouldn’t know about it unless you knew what was going on.  The Project Upstream site does not mention, but someone claiming to be part of Project Upstream posted the instructions The Missing Hat’s LiveJournal site:

Opt-out support introduced
Greetings, hat missers. We are Project Upstream.

We have chosen to provide you with a new ability. You may now send a message such as "$optout" to any of our robotic fish. This will permanently prevent all Project Upstream communications from reaching your account.

Some additional information can be found on the Wikipedia entry for TheGreatHatsby.  That seems easy, but unless you know how to look for that sort of thing, you’ll never figure it out on your own.  It’s an interesting idea, connecting two complete strangers using social networks.  The flaw is that most people are not going to know anything about Project Upstream and and they are going to think that other person is up to no good.  There should be some information about the project in that opening message.  You could make a new friend, but it’s more likely to freak the other person out.

I chatted with the other person for a few minutes and we exchanged Twitter accounts.  It turns out that we really have nothing in common and we doubt that we will keep in touch.  It’s an interesting experiment and I think I’ll stay in it for a while.

The other thing to remember is that you are not directly connected to the other person.  Your message goes to the fishbot and the fishbot relays that message to the other user.  The same would be true for other user.  That’s great because if you don’t want to have an IM conversation with the other person, that person has no way of making contact with you again. 

That does raise an interesting privacy concern in that the fishbot is monitoring both sides of the conversation.  It needs to do that to relay the conversation and to be able to handle the “$optout” request.  But, what are they doing with that information?  The web site for Project Upstream only tells you how to opt in, there is nothing about privacy issues or how to opt out.  Just remember the security issues if you decide to play with a robotic fish.

Wednesday, February 11, 2009

On this episode of “Jon and Kate and an American Chopper”…

On this episode of “Jon and Kate and an American Chopper”, Kate and Paul Sr have it out over how dirty the OCC office appears to be.  Jon struggles to find his place at OCC.  Paulie nearly loses his mind when he takes the girls shopping for new shows.  Mikey and Aaden continue to work on their concept bike.

Paul Sr organizes a dodge ball match between the OCC camera crew and the Gosselin camera crew.  Hilarity ensues when Kate shows off her new tattoo and Jon tells her “That’s not the Korean word for love", but it’s kind of similar.”

Tuesday, February 10, 2009

Resetting the mouse cursor

Some app on my XP development PC left the mouse cursor stuck in the “move” state.  The mouse was behaving correctly, but it was stuck in move image, the one with the four direction arrows.  Normally, the mouse cursor is application specific.  One the apps is coloring outside the lines and the cursor image was stuck for all of the running applications.  I’m using a beta version of a Twitter client app, it’s the obvious suspect, but I still need to prove that.

I couldn’t figure out which app was doing this and I was in the middle of editing some code and I didn’t want to break my concentration by restarting everything.  So I decided to address the symptom and not the problem.  The question is how to do you reset the mouse cursor?

First, I tried the simple solution and just removed the mouse.  It’s plugged into a USB port on my monitor so I just turned off the monitor and turned it back on.  After coming back on, the mouse still had the wrong cursor.  What I did next was to bring up the Mouse applet in the control panel.  I selected the “Pointers” tab and it was obvious that something was a little off.  On this tab, you can select the theme to associate with the nouse cursors and the preview display shows the “move” cursor image for each possible mouse cursor image. 

I selected another theme and then went back to the current theme.  Now the preview showed the correct images.  I clicked the “Apply” button and the mouse was back to normal.  There’s probably a command line for doing this, but I’m not going to spend the cycles looking for it unless this happens again.

Sorry it didn’t work out

My work email inbox had a lot of spam this morning.  The messages were very similar in content with subtle variations in the sender and subject fields.  Nothing unusual there.  The odds are that someone got hit with a virus and my email address was in their address book.  That’s the tax we pay for free transmission of email.  Okay people, move along, there’s nothing to see here.

As collateral damage, I also received an automated error message from someone else’s email server.  That person got spammed from the first guy’s virus and the spam email used my email address as the sender.  Once again, typical tactics.  I usually delete these messages without even looking at them, but the error message caught me eye.  The message contained the following text:

Hi. This is the qmail-send program at something.something.something.net.
I'm afraid I wasn't able to deliver your message to the following addresses.
This is a permanent error; I've given up. Sorry it didn't work out.

<somebody@alaska.net>:
qmail-spawn unable to open message. (#4.3.0) I'm not going to try again; this message has been in the queue too long.

--- Below this line is a copy of the message.

Return-Path: <theguywithavirus@yahoo.co.uk>

The email addresses were changed to protect the innocent.  I found that text to be greatly amusing.  I’m working on a some error handling code for one our products and I am going to find a way to work in the text “This is a permanent error; I've given up. Sorry it didn't work out.”.  It’s a subtle bit of humor and for the use case that I working on, entirely appropriate.

Wednesday, January 14, 2009

Dealing with static electricity during winter

Lately I’ve had bad luck plugging in USB devices into my home development PC. I would go to sync up my Zen (or since Christmas, my iPod Touch) and bad things would happen.  As soon as the USB cable touched the device, the PC would reboot.  I hate it when that happens.  I learned to touch some metal object to ground myself, but that didn’t always work.

It’s pretty dry in my house during winter.  Walking across the carpet, I seem to pick up a critical amount of static electricity.  Oddly enough, the reboot never happened when I sync’ed  my daughters' iPods to the family PC that we all share.  Same dry air, nearly the same carpet.  But different PC hardware.  The family PC is a basic Dell Core Duo box.  Nothing fancy, but good enough. 

My machine is one that I had custom built.  Roughly the same CPU, just the AMD flavor, but with more bells and whistles.  I wanted dual NICs, RAID 5, FireWire, beefier PSU, and a quieter case.  I wrote about that machine a while back, it’s worked out pretty well so far.

It seems that it was the case that’s doing me in.  I’ve been a big fan of Antec cases, and this case is a Sonata II.  Nice design and very easy to work.  It has the extra touches that you would want, like a dust filter in front of the fan that pulls air into the case.  But it appears that that there are grounding issues with the USB connectors on the front panel.  I did a few quick searches through the series of tubes and found way too many hits for “antec sonata usb ground static” to be coincidental.

The obvious solution would be connect a wire to the front panel that has the USB ports and ground it to the case.  That will be a weekend project because the internal drive bays block access to the front panel.  In the meanwhile, I’m taking the lazy way out.  I had a spare 4 port USB hub that Microsoft gave out at DevConnections a few months back and I connected it to one of the USB ports on the motherboard shield at the back of the PC.  Those ports are grounded.  I also an running a vaporizer in my office when I’m working.  I need to get a humidifier, but the vaporizer was handy.

Between those two hacks, the static discharge problem appears to have been eliminated.  I’m not thrilled with Antec at the moment.  These are premium cases (or at least more expensive than the budget cases) and you would think that all of the ports would be grounded.  After skimming through the various message boards about this problem with multiple Antec cases, I wonder this will be my last Antec case.

Tuesday, January 06, 2009

What to do when an antivirus vendor has flagged your software as a virus

I usually don’t talk about where I work, this is my personal blog and where I work really doesn’t matter to the content of blog posts.  This post is a little different, it’s work related and knowing where I work adds some needed context.  I’m a senior software engineer for Tyler Technologies, in their VersaTrans Solution. The VersaTrans product line provides school transportation software and services for the K-12 schools.

About a month ago, I came into work to find people waiting at my cubical.  That’s usually not a good way to start off a morning, and it wasn’t.  Apparently McAfee pushed out a virus definition file out the night before and it was flagging our software as a trojan.  Two of our executable files were being flagged.  Our customers were calling in to our technical support department, and they were understandably concerned.  The McAfee antivirus software wanted to quarantine our applications.  That would prevent our customers from using our applications, which is not a good thing.  They use our bus routing and planning software on a daily basis.  Not being able to use our software can cause a lot of problems for a school’s transportation department.  We needed to immediately resolve this.  I usually don’t get involved with technical support issues, but I had the bandwidth to immediately jump on this problem.

The immediate order of business was to replicate the actions of the A/V software.  We wanted to make sure that our software was being actually being flagged before we reported it to McAfee.  We don’t use any of the McAfee products in house, so one of our QA specialists (David) started downloading a trial copy of McAfee’s Enterprise solution.  This is the application that our clients were reporting that they were using.  David would install that copy into a virtual machine and test it in an isolated environment.

Thursday, 10:00am.  I decided to save some time and upload a copy of our application to my home PC.  I have a copy of the home version of the McAfee A/V product.  It comes free as part of my FiOs package.  I’ve been planning on removing it and replacing it with one of the free A/V products, but fortunately it was still installed.  Sure enough, the app was flagged as “BackDoor-AWQ.svr.gen.e”, which is some type of generic server type of trojan that was added to version 5460 of the McAfee A/V database.  Version 5460 was the one that had been just pushed out to all of McAfee’s clients.  David would eventually duplicate the A/V hit, but it would take a while.  Armed with immediate proof from my home PC, I could proceed to the next step.  By the way, it can be very handy to be able securely access your home PC from your office PC.

10:15am.  I made my initial call to McAfee.  I went was passed to several CSRs, most of them refused to provide any identification other than their first name.  With each CSR, I was asked for a “grant number”, which was some form of customer identifier.  With each CSR I needed to explain that I was not calling as a McAfee customer, but as a representative of Tyler Technologies and they were false identifying our software as malware.  Each CSR tried to redirect me to their home product support.  With each CSR, I would request to speak with their supervisor when it became obvious that I would not get the support.

10:30am. I spoke with “Mike”, who identified himself as Corporate Service Program Supervisor.  He refused to escalate the issue or provide a last name and phone number.  Once again, I asked to speak to his supervisor.  He did not want to do this and we went back and forth a few times and I was persistent.  He finally transferred me to their Consumer Customer Department and provided that phone number (866-622-3911) with great reluctance.

10:30-10:42am.  Waited on hold.

While I was on hold, our sales department sent out a mass email to all of our clients.  The email explained that McAfee was falsely identifying our application as a virus and they should not be alarmed and that we were working with McAfee to remedy the situation.  As soon as you can reliably identify that some version of your software is being falsely flagged as a virus, contact your customers.  Trust me, they will appreciate it.

10:42am. Spoke to another CSR who couldn’t help resolve the problem, but could transfer me to someone who would be able to help.

10:45-11:00am.  Waited on hold.

11:01-11:30am. I reached a CSR named Juan at the Dallas office of McAfee.  Juan’s title is Tier III Customer Service and he provided me with his direct phone number and email address.  He asked me to submit a copy of the file being flagged to a web site that they provide for online scanning of files.  This is McAfee Avert® Labs WebImmune and is located at https://www.webimmune.net/default.asp.   I registered an account on their site and tried to upload the Routing and Planning (RP) executable known to trigger the McAfee scanner.  I was unable to upload the file because the RP executable is 7.7MB in size and WebImmue would only accept files up to 3MB in size.  Our executable is pre-compressed and there isn’t any other method of shrinking the size down to below 3MB.  This 3MB limitation basically defeats the purpose of having that site.

I then tried emailing the file to Juan, but our own email server blocked the email because of the file attachment.  That’s bad on our part, but there is more than one way to email a file.

11:45am.  I emailed the file to Juan via my personal Hotmail account.  It took a while to make it to Juan, but by 3:00PM, I had an email confirmation from Juan that he had received the file.

11:58am.  I received an email from Juan with the following text:

Mr. Miller,

I just received an email in regards to the issue that you are currently facing.

An issue that was incorrectly indentifying some large applications executables files as Backdoor.awq.svr.gen.e has been resolved.

Attached is an ED to suppress this detection. We have tested the ED against the limited number of files we have received thus far. If the ED doesn't work and DAT 5461 hasn't shipped then please gather a sample (FTP site in pwd protected zip if larger than 3mb) and escalate via MSTeg.

I forwarded the message to David in QA.  David had set up a virtual machine with a trial version of the McAfee Enterprise virus scanner and could duplicate the problem using the 5460 DAT file.  The “ED” supplied by Juan did not fix the problem, but I am not 100% certain that we had installed it correctly.  Their ED file did not come with any instructions on how to install it and we I promptly notified Juan that it was still a problem for us.

3:00pm.  Juan emailed me to notify me that he had received the RP executable from my Hotmail account and he requested a copy of the other executable that was being falsely identified (Ascii Scheduler).  I immediately sent him that file from my Hotmail account.  I did not receive emails from Juan (or any other McAfee representative) after that point.  Both files share about 98% of the same code, I was pretty sure if they fixed the scanner for one of them, it would be fixed for the other.  Especially since we were not the only company affected.  Juan wouldn’t tell me who else had been false identified, but he hinted that they were big companies and they were not happy.

Friday 9:00am.  I was told by our QA Manage that DAT version 5461 was pushed out by McAfee overnight and it no longer flags our files as false positives.  We received many happy emails from clients thanking us for the prompt attention paid to the matter.

So what do you do if this happens to you?  I recommend doing the following when a customer reports that your software is being flagged as a virus:

  • Ask the customer for the product name and version number of the antivirus software.  If possible, get the version number and date of the virus database used by the software.  Start taking detailed notes during this process.  You want an audit trail to give your boss to explain where your day went, plus it gives you ammunition when you get stuck with a CSR that wont help your or escalate your call.
  • Ask for the name of the virus or trojan that your software is being flagged as.
  • Get the version number of your executable that is being flagged as a virus.
  • Get a trial version of the A/V software and attempt to duplicate the false positive match.  If you can not duplicate the results, ask the client to send a password encrypted zip archive of the executable being flagged.  You have to consider the possibility that the client’s machine has been infected with a virus and that your application was infected on the client’s machine.  By sending it in a password encrypted zip file, it should pass through the client’s email server and your server without flagging any additional virus checks.
  • Submit your executable to the A/V vendors online support.  Most of them have a web page for submitting a questionable file.  You wont get a fast response back, but when you call their support, they will ask you to do this step so you might as well get it out of the way.
  • Call the A/V vendor and ask for support.  Do not identify yourself as a customer of their A/V software, but as an ISV who has been falsely identified by their software.  If you identify yourself as a customer, you may get shunted down lower priority support queue.  If you have an expensive support contract, that would be different.  Basically, just use the best tools at your disposal.
  • Ask for the CSR’s name and phone number, with extension.  Tell them that you need this information to provide an audit trail for your supervisor.  Be polite but persistent.  If they can not help you, ask for their supervisor and just work your way up their chain of command until you get a CSR that can help you.
  • Stay polite and professional with the CSR.  It’s not their fault that their software is falsely identifying your software as a virus.  They are more likely to expedite a remedy if you are not beating up on them.  It’s likely that you are not the only one being affected by this.
  • When you have a CSR that can help you, work out a plan with target times for how to resolve this.  Let them know that you will be in phone and email contact with them until the matter is resolved.  Basically, you want to get the file or files to them and have enough time for them to test the files and work out a solution.  You do not want to be waiting for hours just to get them the file.  You will want acknowledgement when they have received the file and when they have duplicated the problem.  Your goal is to get them to issue out a new virus update file on the same day.
  • Once you get the problem resolved, send a “thank you” email to the CSR that helped resolve the problem.  If the problem ever occurs again, you want to be able to start with that CSR and not have to waste time going up the CSR tree.

Having to go through all of this was not how I planned on spending my day. I lost the better part of the day dealing with McAfee’s mistake when I could have been working on my own mistakes.  This kind of stuff happens and it’s good to have a plan for dealing with it.

Renabling maintenance plans on SQL Server 2005

We have a couple of SQL Server boxes that we use in our department and of them has some mission critical databases.  Our defect tracking and source control databases are the big ones, but there are a few others.  We back them up and then copy them to a folder on a netwrk share.  From the network share, the files get backup up to tape and are stored offsite.

On the database server, I have a maintenance plan that runs each night and backups the critical databases.  It runs at 2am.  At 5am, I have a scheduled task run on the database server that does the following:

  1. Purges the old backups and compresses copies of the backups.
  2. Copies the latest backup of each database to a new folder.
  3. Compresses the backups using 7-Zip.
  4. Compresses our technical spec documents.
  5. Backup the MSQL database that has our department’s wiki.  We are a .NET shop, but I really like how the MediaWiki software works, so we use that. Getting that to work a 64-bit Windows Server is a story best left for another day.
  6. Copy the compressed backups to the network share.

So that has been working without any hitches for about 12 months.  We did a spot check of the backups last week and noticed that it stopped working a few weeks ago.  After a bit of poking around with how the scheduled task was scheduled, running it manually, and so forth, I ended up at the database server.

I tried to view the maintenance plan that handles the backups and I was presented with the following error message:

'Agent XPs' component is turned off as part of the security configuration for this server. A system administrator can enable the use of 'Agent XPs' by using sp_configure. For more information about enabling 'Agent XPs', see "Surface Area Configuration" in SQL Server Books Online. (ObjectExplorer)

That’s not good.  But easily fixable.  I Google’d the first sentence and found a fix on the first page Enabling "Agent XPs" on SQL 2005 in a post by Jeff Story on the Tree Rat Fishing blog.  In short if you run the following T-SQL commands, you’ll get the functionality back:

sp_configure 'show advanced options', 1;
GO
RECONFIGURE;
GO
sp_configure 'Agent XPs', 1;
GO
RECONFIGURE
GO

I still don’t know what disabled Agent XPs, my guess was a Service Pack update for SQL Server or someone messing around with the server.  I’m thinking of setting up a developer dashboard page to display stuff like when were the database backups done, what projects were built for QA.  Not knowing that the backups were not performed was a giant flaw in the backup plan.  We were lucky on this one.

Wednesday, December 03, 2008

Dealing with meetings that run late and run into your meeting

Raymond Chen just posted a great post on his The New Old Thing blog about getting people out of a meeting room when their time is up.  You either barge right in and say “Oops! Sorry about that” and then back right out.  Or you just sit right down and apologize for being late for your own meeting.

If you are in a meeting and your time is up, it’s just proper etiquette to end the meeting if that room is booked for another meeting.  While your topic may be more important for the next meeting, making other people wait will push back everyone’s schedule.  It can ripple through the company and come back and bite you on the Blackberry..  It’s just a poor business decision to make everyone else wait.

Either politely ask if the next meeting can be be delayed a few minutes, or just book another meeting at another time to finish your stuff up.  With so many meetings include people calling in for remote offices, you really need to make an effort to keep your meeting on track.

If your one hour status meeting always seems to run 90 minutes, then you have a time management problem.  Either your meeting isn’t staying on topic, or the scope of the meeting doesn’t fit the time allotted.  Cut back on the scope or just book the room for 90 minutes.

At the last place I worked, our daily team staff meetings were “stand up” meetings.  We all stood in a quite away near our workspace, and we just stood and talked for a few minutes.  No beverages were allowed and off topic conversations were verboten.  This fails when you have remote team mates, then you would need to book a small room and everyone just stares at the conference phone.  The no sitting down and no beverage rules are still in effect.

I still think that Dave Barry said it best:

Meetings are an addictive, highly self-indulgent activity that corporations and other large organizations habitually engage in only because they cannot actually masturbate.

Sunday, November 23, 2008

Some odd TiVo issues

I have  couple a couple of Series2 TiVo DVRs and they just received the TiVo Fall 2008 Service Update for 9.3.2.  It’s basically a few tweaks to the UI, but the odd thing was that I needed to manually restart the TiVo.  Usually the TiVo restarts itself after getting a new system update.  Very odd, but hopefully just a one time glitch.

My in-laws have a TiVO HD and sometime last week it decided to stop recording the shows on the season passes.  I went over and took a look.  The season passes were in order and when you selected view upcoming episodes, the shows would be listed, but not listed as being recorded.  Very odd.  The fix was simple, but annoying.  I selected each season pass and saved it without making any changes.  After saving the pass, the correct shows were marked as going to be recorded.  Fortunately they only had a handful of season passes, it took a minute or two to update all of them. 

After fixing the season passes, I tried to bring up YouTube on the TiVo HD.  When I selected YouTube from the menu, the TiVo froze and stopped responding.  I gave it a few minutes to figure it on it’s own and I restarted their TiVo the hard way.  Thanks to TiVo not having a reset button, I had to unplug and plug it back in again.  After waiting a few minutes to boot abck up, it was back to normal.

That was the first time I have ever had to reboot a TiVo, their software has been very stable.  As with my Series2 units, I’m hoping that this was a one time glitch caused by system updates being pushed down the to TiVo.

Thursday, November 20, 2008

Fast way to resize a virtual disk with VMware ESX Server

We’re starting some SharePoint development and I needed to create a development environment on Windows Server 2003.  So I created a new virtual machine (VM) of Server 2003 on our VMware ESX box and gave it a 1GB of RAM and 8GB of disk space.  I installed the OS and configured it for Windows SharePoint Services (WSS) and then installed Visual Studio 2008.  That left us with about 1.5GB of disk space.  Oops, time to resize the drive.

The beauty of working with virtual machines is that it’s relatively easy to increase or decrease the memory and disk storage.  In this case, I wanted to add another 4GB to the virtual disk.  I powered down the virtual machine and went into the “Virtual Machine Properties” from the VMware Infrastructure Client (VIC).  I selected the hard drive and it provided a entry field for the new size.  I increased the size to 12GB, adding an additional 4GB.

That takes us part way there.  I increased the size if the virtual disk from 8GB to 12GB, but it still has an 8GB partition, the OS wont see the additional space.  I saw all some tips on that Series of Tubes that recommended downloading Linux boot disks and boot the the VM from the Linux CD images as an .ISO file.

Meh, that’s too much work.  I took a simpler path.  I powered down another Server 2003 VM that was already running on the ESX box and added new VM’s virtual disk as a second virtual drive.  I booted up the second VM and opened up a command shell.  From the command shell, I ran the diskpart utility to extend the partition.  I did the following commands through diskpart:

diskpart


Microsoft DiskPart version 5.1.3565

         
Copyright (C) 1999-2003 Microsoft Corporation.

On computer: XXXXX



DISKPART> list volume

 

  Volume ###  Ltr  Label        Fs     Type        Size     Status     Info

  ----------  ---  -----------  -----  ----------  -------  ---------  --------

  Volume 0     E                       DVD-ROM         0 B
  Volume 1     C NTFS   Partition     12 GB  Healthy    Boot
  Volume 2     D NTFS   Partition    8 GB  Healthy


 

 

DISKPART> select volume 2
 
Volume 2 is the selected volume.
 
DISKPART> extend

 

DISKPART> exit

      
Leaving DiskPart...


I basically typed that in from memory, some of the numbers may be off, but it shows how to extend the size of the partition.  After exiting out of diskpart, I then shut down the second VM.  Next, I removed the virtual drive that belongs to the new VM.  Remember to select remove only and not remove and delete.  At this point I was able to power both VM’s back up.  The second VM will be slightly confused about the missing drive, but it was back to normal.  The new VM took some time to check out the resized partition after I logged back in.  With my VM, it declared it to be new hardware and wanted to reboot.  After it rebooted, it was happy and recognized that it had a 12GB partition.

Tuesday, October 21, 2008

DevTrack woes with build 1833 of mfc80.dll

We use TechExcel’s DevTrack tool to track our defects and project modifications.  A few weeks ago, one of our QA specialists installed SQL Server 2008 Express.  That broke DevTrack.  After SQL Express 2008 was installed, DevTrack would crash after loading.  After contacting DevTrack support, we were advised that the mfc80.dll installed with SQL Express was causing the problem. 

Their suggested work around?  They asked us to overwrite the version of mfc80.dll (8.0.50727.1833) located in one of the SQL Express folders with an older one (8.0.50727.762).  Ok, there is something wrong this picture.  You don’t replace a dll in another application’s folder.  That violates the integrity of the installation of the other application.  You have no idea of what the possible consequences will be for that application.  It could work fine, it could blow up in your face, or something in between.

The problem is that when DevTrack requests mfc80.dll, it’s being redirected through the WinSxS policy files to the latest and greatest version, version 8.0.50727.1833.  And there is something in MFC 1833 that just kills DevTrack.  The problem isn’t specific to DevTrack, apparently Corel’s WinDVD has the same problem.  I read a thread about people hacking the WinSxS policy files to force calls to mfc80.dll to use an older version.  That might work under XP, but will really break things under Vista.

I thought the Side-by-Side assembly model was supposed to eliminate “DLL Hell”.  For DevTrack to work, they have two choices.  They can patch their code so that it doesn’t crash with the 1833 version of mfc80.dll, or they can install their own local copy and not use the WinSxS version.  We’ve been waiting for a few weeks for a solution, that’s been a real frustrating point.

Monday, October 20, 2008

Installation is not configuration

Christopher Painter has a good post about the problems inherent with with having installers run SQL scripts.  Having an installer communicate with a database server just opens the door to all sorts of issues.  Just handling the connection to the server requires making sure that you have all of the required bits installed and that you can locate, and connect to the server.  None of that code is rocket science, we’ve been using it for years. I just don’t think having it in an installer is the right place for that type of code.

The problem is that you are running that code from inside a relatively fragile box, your installer.  Most installer authoring tools provide rudimentary support for running SQL scripts at install time.  They work just fine when all of your ducks are lined up in a row.   However your clients may be missing an odd duck or two, and you end up with fragile code wrapped inside a DLL that your installer will call.

I’ve always treated the installer package as just part of the actual installation process for the end user.  The main task of the installer is to get the bits of your application in place and handle any prerequisite runtime library your code may need.  When it comes to initializing or updating a database, I leave that to the main application and/or it’s support utilities.  if a SQL script is flawed and or doesn’t handle some edge condition that only one customer has, you can break the install.

By using a full blown application to handle the database task, your life (and your customer’s life) becomes much easier.  By running your own application, you have (or should have) a much richer environment for developing code.  You have complete control over the UI and you do not have to be concerned with trying match the UI style of the installer.   Also the testing and debugging of the database utility code becomes much easier as no longer need to account for the installer.

You also have the ability to run the application at any time after the install, without having to invoke the installer.  If it turns out the problem was a SQL script that didn’t work for that customer, you can immediately email or post online an updated SQL script, without forcing the user to run the installation process again.

We use a mixture of script based installers and Windows Installers and none of them make any attempt to run a SQL script.  I wrote a database utility application that gets launched after an install.  I wrote it when our company supported the MSDE, back in the day of SQL Server 7.  Back then, Microsoft provided absolutely zero for tools to manage the MSDE.  So this utility, by necessity needed to be able to attach and detach databases, back up and restore databases, manage the server and database logins, and perform schema updates. 

Over the years, this utility has matured and is very easy for the end user to use.  We provide all of schema updates in a single, compressed file.  For the use to apply an update the database schema, they just run my utility and it reads the update file and it knows which updates have already been applied and only runs the ones it needs to.

All very easy for the end use, but it would have been a nightmare to get that level of functionality running as part of the installer.  As soon as you add an outside dependency (in this case, the database server), you have added a point of failure that you will have absolutely no control over.

Friday, October 17, 2008

Strange 64-bit error with LayoutKind.Explicit

I have a C# service that collects data from another company that we do business with.  They send the data in a binary format from one of their C++ applications.  To read their data with .NET, I needed to marshal their data to a set of structs defined in C#.  I created a structure that looked something like this. 

    [StructLayout(LayoutKind.Explicit, Size = 48)]
public struct SampleHeader
{
[MarshalAs(UnmanagedType.ByValArray, SizeConst = 8)]
[FieldOffset(0)]
public byte[] RecordType;

[MarshalAs(UnmanagedType.U4)]
[FieldOffset(8)]
public uint Version;

[MarshalAs(UnmanagedType.ByValArray, SizeConst = 8)]
[FieldOffset(12)]
public byte[] SystemCode;

[MarshalAs(UnmanagedType.U4)]
[FieldOffset(20)]
public uint LocalID;

[MarshalAs(UnmanagedType.U4)]
[FieldOffset(24)]
public uint HostID;
}



The actual struct had more fields, but this is enough to show the the problem. During development and testing, the code worked fine. Until we tried it on a 64-bit edition of Windows Server 2003. That's when it broke. As soon as I instantiated an instance of this struct, the service would throw an error. Something like this:



System.TypeLoadException: 
Could not load type 'SampleNameSpace.SampleHeader'
from assembly ''Sample, Version=1.2.3.4, Culture=neutral, PublicKeyToken=null'
because it contains an object field at offset 12 that is incorrectly aligned or overlapped by a non-object field.


To get it to fail, all I needed to do was to create a SampleHeader like this:



SampleHeader sh = new SampleHeader();



That didn't make any sense.  I couldn’t see any reason why it would work in 32-bit land, but not in 64-bit.  Since it was complaining about the “SystemCode” field, I commented out the other fields and played with the field offsets.  If I changed the offset from 12 to 16, I could create a SampleHeader object without any runtime errors.  Mind you, I could actually use it in my code, those offsets had to match the data my service was receiving.



So I went to plan “B”, getting rid of the explicitly laid out struct.  I created a new one without the StructLayout, MarshalAs, and FieldOffset attributes.  It looked like this:



    public struct SampleHeader
{
public byte[] RecordType;
public uint Version;
public byte[] SystemCode;
public uint LocalID;
public uint HostID;
}



Pretty much the same thing, except .NET defined the field alignments.  Instead of using marshalling to copy the data, I just used the BitConverter class.  I had already put the received data into a byte[] array, that made it easy to use BitConverter.  For this struct, I only needed the LocalID and HostID fields, so the following code was all that I needed:



    MyHeader.LocalID = BitConverter.ToUInt32(RawData, 20);
MyHeader.HostID = BitConverter.ToUInt32(RawData, 24);



This replaced the marshalling code that looked like this:



    GCHandle handle = GCHandle.Alloc(RawData, GCHandleType.Pinned);
SampleHeader MyHeader = (NewStuff)Marshal.PtrToStructure(handle.AddrOfPinnedObject(), typeof(SampleHeader));
handle.Free();



I still don’t understand why Windows 64-bit  requires fields in a struct to be aligned on 4 byte boundaries, but the replacement code works and is easier to follow.

Tuesday, October 14, 2008

Restoring missing Build Events in Delphi 2007

If you have a Delphi 2007 project that was ported from Delphi 2006, then you may be missing the build event project options.  The .dproj file that Delphi 2006 creates is does not have a final XML element named PropertyGroup that Delphi 2007 uses.  Without that final PropertyGroup, Delphi 2007 will not enable Build Events as an option.  If you manually edit your .dproj file, just the following lines:

<PropertyGroup>
</PropertyGroup>


So that the .dproj files looks like this at the end of the file:



<PropertyGroup>
</PropertyGroup>
</Project>


After making that change, the next time you open that project with Delphi 2007 and select Options from the Project menu, you’ll see Build Events listed.  This only appears to happen if you migrate a Delphi 2006 project over to Delphi 2007.  If you create the project from scratch, you’ll see Build Events list.  That’s how I was able to determine what was missing, I just created a new project and compared the .dproj files.

Saturday, September 06, 2008

"Everything That Happens Will Happen Today" by Byrne and Eno

David Byrne and Brian Eno have a new album out, "Everything That Happens Will Happen Today".  It's available exclusively through their web site, http://www.everythingthathappens.com/.  You can listen to the entire album on their site, or by using their streaming player right below this text.

I've been listening to it while writing this post and it's pretty good. It's a nice mix of Eno's music and Byrne's lyrics and singing.

You can order the album from their website in various formats. They have 320kbps MP3 and FLAC, without any DRM. for $8.99. Yu can also get it as a CD plus the downloadable versions for $11.99. There is a deluxe package for $69.99 with all sorts of stuff for the diehard Byrne and Eno fans. It's cool that they are selling it themselves. If they sold it through a record label on iTunes, they would get a tiny fraction of the $0.99 a song that iTunes charges.

This is their first collaboration since 1978's My Life in the Bush of Ghosts.

Friday, September 05, 2008

Old School modeming

The always entertaining DadHacker has a great post on how he used to write code in the old days at 300 baud.   When he was in school, he had to submit course source code by punch card.  That’s a death by a thousand paper cuts.  To avoid having to use punch cards, he would dial in over the ancestor to the Internet and edit the code at 300 baud.   You should read his post to see all the steps he had to do.  It would have made Rube Goldberg proud.

He gets extra bonus points for using a terminal emulator that he wrote himself.  Double extra bonus points for writing it on a machine that didn’t have a UART chip.  UART chips are used to hand communications over a serial port.  The UART handles the timing and buffer requirement of sending bits over the wire.  Not having one, means you have to handle all of the ugly details yourself.  That means you can’t just write code that says “send this sequence of bits over there, at 300 baud”.  You had to write the code to control the timing of 300 baud and sends the bits at that rate and handle all of the flags and registers being set by the serial hardware.

I remember 300 baud.  At that speed (or lack of speed), you could watch the characters come in and fill the screen.  I had a Commodore 64 and my first modem was the Commodore 1650.  300 baud and pulse dialing, that was life online in 1985.  Over the years, I kept getting faster and faster modems.  I went from 300 baud to 1200 baud on the Commodore 64.  Stayed at 1200 on my Commodore 128.  I jumped to 2400 baud when I got my first Amiga.  I went from 2400 to 19,200 when I moved to the PC platform.  Then it moved to 33,600 and finally 56,200 before I jumped to broadband. 

I remember buying a serial port card for my 486sx just to get a 16550 UART to use instead of the cheesy 8250 UART that was on the motherboard.  The 8250 had a one byte buffer and you would start dropping characters at speeds higher than 9600 baud.  The 16550 had a 16 byte buffer. That doesn’t sound large, but it was enough to let you handle much higher baud rates.  The Commodore 64 didn’t even have a UART, it emulated one and the CPU had to do all of the processing.  That was good to only 2400 baud before it would fall apart,

Getting a faster modem was one of those devices where you saw a clear and immediate improvement.  I still have the last modem I bought back in the early 90’s.  It was a US Robotics V.Everything Courier modem, an external one.  A giant black slab, squatting on top my PC.  It had firmware that could be “flashed” to a new version.  I think I did it it about three or four times.  Each it got faster and more reliable.  I real man’s mode,  It ate through line noise and spat out clean bits.  Even though I have no need of it, I refuse to get rid of it.  It’s the oldest bit of functional computer equipment that I own.  My current home PC doesn’t even have a serial port, I would have to get some odd USB to Serial dohickey if I even wanted to use it.

Thursday, August 21, 2008

Refreshing a SOAP WSDL import file with Delphi

I’m consuming a web service from a Delphi desktop app and both the web service and the desktop app are being developed at the same time.   Because the WSDL generated by the web service can change, I need to refresh the service interface code that the Delphi code uses to access the web service.  It corresponds to the web references class that a .NET app would use to consume a web service.

You typically create the web service interface code by bringing up the WSDL Import Wizard from the File->New->Other menu in Delphi.  You get a dialog that prompts you for the location of the WSDL file or URL.  From the WSDL, it generates a unit with interfaces defined for the classes and objects exposed by the web service.  It creates the file with the name of the service, plus “.pas”.

It works pretty well, but if you need to refresh that file due to changes in the web service, you don’t need to use that wizard to update the file.  There is a command line tool that will generate a new output file from a specificied WSDL.  This tool is named WSDLImp.exe, and is located in the bin folder of your Delphi installation.

The typical syntax is

WSDLImp.exe -P http://localhost/somefolder/someservice.asmx?WSDL




That will generate a file named someservice.pas.  If you want to specify a different name for the file, you can use the “-=” command line parameter like this"





WSDLImp.exe -P -= http://localhost/somefolder/someservice.asmx?WSDL=myservice.pas




That will create the file myservice.pas.  Very handy if you want to use a different name than the default.  Now when you update the service interface, you can just run WSDLImp to reimport the web service interface.

Using the test form from remote connections for .NET web services

I’m working on a web service using C# and targeting the .NET 2.0 Framework.  Nothing terribly fancy, but it has some code to log the caller’s IP address (via HttpContext.Current.Request.UserHostAddress).  While testing the code, I like using the test form functionality that .NET provides with web services.  By design, it only works locally.  If you try to use the test form from a remote machine, you’ll get the error:

The test form is only available for requests from the local machine

That’s fine, when you expose a web service you don’t want to make it too easy for people to start poking at your web service methods with a pointy stick.  Still, I wanted to test it from another machine and it saves time being able to enter in different values without having to code up a test framework.  Plus, I wanted to make sure that my code was reliably picking up the caller’s IP address.

After just a tiny bit of searching in the series of tubes, I found how to easily enable the web service test form for remote connections.  Juan Ignacio Gelos posted what you need to add to the web service web.config file to enable the test form.

<configuration>
<system.web>
<webServices>
<protocols>
<add name="HttpGet"/>
<add name="HttpPost"/>
</protocols>
</webServices>
</system.web>
</configuration>



You are still limited to run methods that have simple data types as input, but it’s very handy for testing.  Since this setting lives in web.config, it’s easy to remove it when I run a build.  I’m using FinalBuilder on a dedicated build box and it’s easy to clean up .config files so that developer settings get scrubbed before the files get packages into an installer.

Wednesday, August 13, 2008

Using Delphi in a team

I was just reading

Tuesday, August 12, 2008

Get ready to say good bye to Google Page Creator

When I get some spare time, I plan on revamping the layout of this blog.  Right now, it’s an ugly mess of hacks placed in Blogger templates.  I want to make use of external CSS and Javascript files, but Blogger doesn’t allow you to upload those types of files.  Since of the design goals for this blog is to run it for free, I wanted to have a way of hosting CSS and Javascript files without having to use a paid hosting account.

I read a cool blog article writen by Lars Gersmann on how to add WordPress style calendar pages to Blogger based blogs to jazz up the blog post timestamp.  Lars provided the links the .css and .js files, hosted on his Google Page Creator account.  That looked vaguely familiar, I have a Google Page Creator account gathering virtual dust out in the cloud.  I logged in my Google Pages account and saw an announcement that Google was pulling the plug on Google Page Creator.  if you don’t have a Google Page Creator account now and go to the site, Google Page Creator, you’ll see one of the messages.

On August 4th, Google posted an announcement that they would be shutting down Google Page Creator later this year in favor of Google Sites.  Both sites let you create simple web sites very easily, but Google Sites, will not let you host your own .css or .js files.  Sometime later this year, Google will be shutting down Google Page Creator and I’m assuming that any site left there will be purged.  Google Page Creator was part of Labs.Google.com, which basically means it was a beta project with no guarantee that it would be around as a permanent fixture.