Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
arno1
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
arno1
10y ago
It's been already discussed in this thread. The performance impact should be negligible. I am having ~110-150 FPS with my nVidia 560 Ti in CS:GO , 1920x1080. The precise testing haven't been done explicitly to measure increase
32.
▲
by
arno1
10y ago
Currently it is stored in a docker volume. (the data available at /var/lib/docker/volumes path) But changing just one line in a docker-compose.yml file you can mount it wherever you want on your host. See "data:
33.
▲
by
arno1
10y ago
It's absolutely irrelevant since Docker (cgroups) are just the Linux kernel abstraction which helps to isolate resources of the processes. And with this image the general idea is that it comes like a package, with "just take &
34.
▲
by
arno1
10y ago
Cool :) Pity it isn't in English.. :)
35.
▲
by
arno1
10y ago
The same way as every local application is accessing it, via a Unix domain socket /tmp/.X11-unix:/tmp/.X11-unix / DISPLAY=unix$DISPLAY :-) This will give you a frame rate identical to your host, so there is no overh
36.
▲
by
arno1
10y ago
Well, there is a distinct difference between traditional chroot and the Linux control groups and namespaces. If only chroot was enough, noone would be investing their time to the cgroups, namespaces, LXC, Docker, etc... :-)
37.
▲
by
arno1
10y ago
Isolated or separated (from the host system). Both words will work when context is clear. Or it can confuse, when context was not specified, which is in my case. What I actually meant is that I'd rather run an isolated (separated) proc
38.
▲
by
arno1
10y ago
I bet there are dozens or maybe even hundreds of people who run CS in a container. What, I believe, makes the difference is that when one shares with the reproducible results. :-)
39.
▲
by
arno1
10y ago
The important part is to make sure that the ABI didn't change. Since Steam wants Debian-based distro, it then should be enough to keep the same. It's not a perfect way to go, but so far it works though. :-)
40.
▲
by
arno1
10y ago
@ingenter please refer to the docker-compose.yml file of the source repository. To make pulseaudio work in a container, you basically want to pass these volumes from the host to a container: - /etc/localtime:/etc/localti
41.
▲
by
arno1
10y ago
I haven't spotted the decrease. On the opposite, even some increase :-) (Or was that just a placebo effect? :) ) There actually shouldn't be any significant decrease since the Docker's overhead is negligible.
42.
▲
by
arno1
10y ago
Because Docker is enough and it does its job well? :-)
43.
▲
by
arno1
10y ago
I would say, using a Docker would move the vector of attack to a Docker engine and a Linux kernel implementation of cgroups, naming spaces. But it would still help in preventing such bugs as https://github.com/valvesoftware&
44.
▲
by
arno1
10y ago
Thanks @fasterthanlime ! Is there something that the firejail does better than the Docker? I can see the firejail also uses the namespaces and seccomp-bpf.
45.
▲
by
arno1
10y ago
This thread is not about to what extent I trust things. But security-wise, running it in a container is better, than running it without isolation. IMHO. And of course, no one asks getting this image built by the 3rd party, since the Dockerf
46.
▲
by
arno1
10y ago
Yeah, one of the points which pushed me creating this image! I have tested HL engine based games and CS:GO which has its csgo_linux64 binary, causing lots of people to complain they could not run it, since Steam itself is 32-bit one. With t
47.
▲
by
arno1
10y ago
@tormeh look at a Docker just like at a system that gets you the images (in "tar" archives) from the Docker Hub repo (or build them by yourself) and lets you run these "tar" images by leveraging the cgroups (Linux kernel
48.
▲
by
arno1
10y ago
I think it should be pretty obvious why people put things into containers :-) Few main points though, which pushed me making this Docker container: 1. I want to set-up more fences when running the code I don't/can't trust; 2.
49.
▲
by
arno1
10y ago
I haven't come up with a better idea obviously. :-) Suggestions/PR's are greatly welcomed!
50.
▲
Steam in Docker
(hub.docker.com)
194 points
by
arno1
10y ago
|
76 comments
51.
▲
by
arno1
10y ago
I think it is even worse than I thought... I've asked the "true"-random tool to give me 3000 of the really "true" numbers (as it claims) and out of 3000 it has thrown to me ~9% of char(0) and ~9% of char(255) values
52.
▲
by
arno1
10y ago
The values presented are "N bits per character". 8 is the maximum, 0 is the minimum. The less value is the worse. The ugly test results show that "true"-random tool does not perform better than openssl / /dev&#
53.
▲
by
arno1
10y ago
ugly tests 1. ("true"-random) 10 iterations; 32 random bytes | Result Avg Entropy: 4.82 $ echo $(echo -n "("; for i in $(seq 1 10); do echo -n $(./generate_constant_stream |head -c 32 |ent |head -1 |awk '{p
54.
▲
Show HN: A Simple Public Key Value Store on Erlang (Docker)
3 points
by
arno1
11y ago
|
0 comments
55.
▲
USB bootable NixOS – UEFI version
(nixaid.com)
2 points
by
arno1
12y ago
|
0 comments
56.
▲
USB bootable NixOS
(nixaid.com)
1 points
by
arno1
12y ago
|
0 comments
57.
▲
Deploying NixOS on a 256 RAM RamNode VPS
(nixaid.com)
5 points
by
arno1
12y ago
|
0 comments