Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
benou
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
9 ms
·
31.
▲
by
benou
4y ago
I was going to mention it too! The really cool thing about reservoir sampling is that it can be done "online" (ie process input incrementally) which makes it super useful when you want to compute statistical properties of somethi
32.
▲
by
benou
4y ago
What you're looking for is RDMA. It was mostly restricted to Infiniband (IB) back in the days, but nowadays you probably want RoCEv2. You can look at iWARP too but I think nowadays RoCE won. In any case, the standard software API for R
33.
▲
by
benou
4y ago
Looks similar to Equalization payments [1] already used in several places in the world. It looks to me that this being organized by the state should be more fair and efficient, but the additional "local connection" you get is a ni
34.
▲
by
benou
5y ago
Personally I think one of the real usecase for smartnic is isolation: for a cloud provider, you can rent a bare metal instance and run all your networking security stack (think encapsulation, filtering, throttling etc) on the smartnic. IOW
35.
▲
by
benou
5y ago
eBPF is much more than a glorified strace(): with eBPF you can basically inserts your own code in a lot of places in the kernel. This can be packet-processing code to modify the way packets are routed, filtered, altered, or it can be used t
36.
▲
by
benou
5y ago
I timed a very simple loop in C: "for (volatile int i=0; i<N; i++);" (handful of arithmetic, compare and branch instructions) with N=1e9 and it was 70% the speed of native which looks really good. I'd love to see LINPACK n
37.
▲
by
benou
5y ago
because almost all of the others are unfixable shitty laptops? Old Thinkpads are really serviceable, I am still using my X61 because I could update so much of its internals. This is not the case of anything else apart from frame.work, which
38.
▲
by
benou
5y ago
Yes. But VPP also supports Wireguard, and when doing apple-to-apple comparisons, the performance difference between Wireguard vs IPsec AES-256-GCM is close to 2x. See https://fosdem.org/2021/schedule/event/sdn
39.
▲
by
benou
5y ago
Speed gains maybe not, however on current x86 platform there is a 2x perf difference between AES-256-GCM and Chacha20-Poly1305, so even if we get "only" 2x I'd be delighted.
40.
▲
by
benou
5y ago
Here is an example for VPP, ~8Gbps/core of IPsec forwarding with AES-256-GCM and IMIX traffic on Skylake @2.3GHz: https://docs.fd.io/csit/master/report/vpp_performance_tests/... Note that thanks to
41.
▲
by
benou
5y ago
I am not challenging that Wireguard is a great technology, but I disagree it is faster than IPsec: it is fast compared to slow IPsec implementation such as the one you have in Linux. However, AES is hw-accelerated in most systems those days
42.
▲
by
benou
5y ago
I'm sorry to hear that but keep in mind the job market is very different from one location to another and from one sector to another. The BBC is talking about truck drivers in the UK and it is hardly a surprise: UK used to rely heavily
43.
▲
by
benou
5y ago
It is only time consuming if you let it be: I have been there too, hosting each service in a different OpenVZ jails (before containers were a thing) and doing hyper complex stuff... Nowadays I simplify to the extreme (refrain to run somethi
44.
▲
by
benou
5y ago
I think it was fixed 2 weeks after the announcement: https://gmplib.org/repo/gmp/rev/5f32dbc41afc I am more reading this as 'we just enabled compilation for Apple M1 but it is highly experimental, use at
45.
▲
by
benou
5y ago
I guess you refer to what happened in Denmark? If so, your summary sounds wrong to me. US leveraging Denmark spying infra to spy on other EU states would be more accurate. I am not saying the Danes were not aware of the risks when they gave
46.
▲
by
benou
6y ago
I am also self-hosting using the excellent yunohost.org it allows me to painlessly maintain my email and nextcloud instance. To solve the issue you mentioned (disaster recovery), I am using rsync.net borg service. Another 'trick'
47.
▲
by
benou
6y ago
For some usecases you can even use docker for lightweight chroots for ARM, MIPS, POWER8 etc. At least for me it covers a lot of grounds (eg. developing for my RPi on my x86 laptop, recompiling a kernel for my ARM-based HTPC etc.) See https
48.
▲
by
benou
6y ago
You do not do that. Instead you optimize the short, critical part. Of course it does not apply to everything, you need a few hotspots, but it is quite common: audio/video codecs, scientific computation, games, crypto... And even networ
49.
▲
by
benou
6y ago
We demonstrated 1 Tb/s back in 2017 on a high-end dual-socket Broadwell server, and the performance increased steadily since then (thanks to both HW and SW). It is hard to compare w/o knowing packet sizes (64-bytes? IMIX? 1500-byt
50.
▲
by
benou
6y ago
Disclaimer: I am part of the team working on this, although not directly involved. AMA.
51.
▲
40G encrypted container networking with Calico/VPP on commodity hardware
(medium.com)
6 points
by
benou
6y ago
|
1 comments
52.
▲
by
benou
7y ago
> which you would notice hasn’t improved much per core Not sure which data you refer to? I just made a comparison on a single-threaded integer-heavy code between my old Core2 Duo and a Skylake, and just got x16 normalized perf improvemen
53.
▲
by
benou
7y ago
Disclaimer: I work on VPP. The typical usecase are virtual network functions: think virtual switches/routers used to interconnect VMs or containers, or containerized VPN gateways etc. It is also used for high-performance L3-L4 load-bal
54.
▲
by
benou
7y ago
> am I missing some packet header overhead ? Yes: Ethernet adds 20 bytes: 8 byte preamble/start of frame delimiter + 12 byte interframe gap => the "on-the-wire" size is actually 84-bytes => 20Gbps/84-bytes = 29.
55.
▲
by
benou
7y ago
It is interesting how many comments focus on anecdotal evidence ("it is very hard to live without a car where I live so it can't be done anywhere") or on exceptions ("what if you cannot walk because you're too old?&
56.
▲
by
benou
7y ago
Bitwise operations: PRI = (facility << 3) | level In term of readability, it becomes clear if you use octal and not decimal representation: the last digit is security level whereas the others are facility number.
57.
▲
by
benou
7y ago
Sounds like ArsTechnica: https://arstechnica.com/cars/2016/05/death-by-gps/
58.
▲
by
benou
7y ago
Note that this is precisely what is written at the bottom of the 1st drawing: > Représentation de la bete féroce nomée hiene qui fait un affreux ravage Translation (my apologizes if it is not that good): Representation of the ferocious b
59.
▲
by
benou
7y ago
This is already supported in HyperV VM, and the concept is old: it is called ballooning. Basically a driver in the Linux guest (hv_balloon for HyperV, but you have the same things for KVM, VMWare etc.) can artificially "inflates"
60.
▲
by
benou
7y ago
Count me in. Regarding the networking issue, I sort of solved it by using VMBus between my VM and Windows. Shameless plug: https://github.com/bganne/hvnc
More ›