HNHacker News
TopNewBestAskShowJobs

irusensei

2,187 karma · joined June 10, 2022

ᕙ(⇀‸↼‶)ᕗ
submissionscomments
irusensei··on Btrfs/ZFS/bcachefs under workloads classic benchmarks skip
That would be a shame since there is nothing else over there with the same set of features. Disregarding drama, I'm telling you it’s that good.
irusensei··on Btrfs/ZFS/bcachefs under workloads classic benchmarks skip
I think in a perfect world they should had put someone in between to mediate and curate patches while providing DKMS for urgent patches.

As for BTRFS I think its also pretty good. Its just that I have the impression its development is guided by the needs of its sponsors and sadly for us META doesn't need RAID5.

irusensei··on Btrfs/ZFS/bcachefs under workloads classic benchmarks skip
BCacheFS is the best Linux filesystem now that storage costs a premium.

You can mix devices of different sizes and types on bcachefs. You can have foreground and background devices to balance performance and also different compression settings for foreground and background transactions.

You can set replicas=N to the individual file or directory on bcachefs. For example files you can just re-download or re-build. Likewise you can set a higher number of copies to important files.

irusensei··on Btrfs/ZFS/bcachefs under workloads classic benchmarks skip
That might be the best thing happened to the project since now development can happen at its own pace without the clicky bait influencers.

In fact they delivered the erasure coding for parity raid back in march this year.

The thing is that as soon as you seriously give a chance to Bcachefs you see how good it is. I can only tell you that mixing different device tiers and having a per-file/directory replication setting is a god send specially in these times where storage costs more than gold.

irusensei··on Fujitsu launches made-in-Japan next-generation CPU FUJITSU-MONAKA
If anyone is curious and want to skip all the PR talk:

>Combined with SVE2 vector operations and software optimization,

It’s ARMv9.

irusensei··on Alternatives to MinIO for single-node local S3
I've dabbled in both Garage and RustFS. Both are good but IMO flawed.

Garage is good but has weird tooling and a terrible searchable term. You'll receive lots of garage doors and electrical gate results when searching for issues with it.

The biggest problem with Garage is the metadata on an sqlite. If you have a single file and that sqlite corrupts then all your data is unaddressable and treated as pile of anonymous blocks. If you have multiple servers you can rebuild the metadata but if you have only one server you REALLY need to make sure that file is backed up.

So if you use S3 as a backup you have to keep a backup of your backup.

RustFS is closer to Minio, but I hate the way they log stuff. They basically use journald as a metric database dumping json formatted lines about library calls and how long they took. Its hard to make sense of those logs. Its the kind of log not meant to be human readable but to render on a dashboard.

Why not just publish these as a prometheus endpoint?

Also high CPU usage for no reason. I also noticed RustFS constantly trashing disk and keeping 10% CPU usage while looping some health check I have no idea how to disable (I've tried RUSTFS_SCANNER_ENABLED=false and others with no results). And of course lots of json metrics on journald.

I personally prefer garage because my backup box sit at my office and I like not needing to listen to HDD sounds all day every day while Rustfs loops its health check.

irusensei··on GEFS on OpenBSD: A Early Preview
Is this classic 9front tomfoolery?
irusensei··on iOS 27, iPadOS 27, and macOS 27
Some stuff that is very niche but useful to me such as kerberized NFS has been broken forever. I don't remember if NFSv4 with krb5p ever worked to begin with.
irusensei··on JetKVM Mini
This. I'm not fighting against a state level actor. My concern is some crackhead burglar stealing my stuff and then my personal data ending up in the hands of whoever buys the stolen goods.
irusensei··on JetKVM Mini
>It also solved the issue I had with entering a password on FDE (full disk encryption) systems

I've fixed that with secure boot (my own keys, not Microsoft's) and TPM2. From that host I can run a program named Tang, which operates in conjunction with another program named Clevis.

On hosts without secure boot such as RPis and other ARM SBCs, Clevis will contact Tang at boot time and decrypt the disk.

Incidentally my x86 with secure boot has intel vPro so the KVM is not needed. The remaining sisters have a piece of lost technology used for decades to solve the KVM problem: serial (UART specifically) connections.

Some seasoned sysadmins might have memories of dialing their Sun servers serial ports for remote administration.

irusensei··on Single log line is 49KB+ (ext4) / 110KB+ (btrfs) of systemd-journald disk writes
I'm using a certain object storage implementation post minio enshitification. The software itself is great don't get me wrong but I've noticed their logs are basically unreadable. Its metrics and traces in json data meant to be rendered on a dashboard instead of being read by humans. It's also extremely verbose even at an INFO level.

Maybe just get these on an open telemetry endpoint instead? I also don't get why people send by default json logs to journald as it's clearly meant to be a replacement to syslog which is already a good standard.

irusensei··on The Alpha 21264 CPU: NT's Greatest RISC (1998)
I heard about Alpha in that it while being more powerful than x86 it wasn't as alien as the competition. The boards had PCI slots and looked like normal PCs, it had Windows NT and Linux. So if your Exchange server was not handling the load you moved it to Alpha and it was good.

It also seems faith in IA64 was the meteor that killed most of these self developed RISC architectures.

irusensei··on IP and DNS Leaks in WebKit Affecting Proxy Browsers and iCloud Private Relay
Apple private relay is very flawed but on the other hand most sites that view connections originating from VPN as suspicious seem to be ok with Apple Private Relay. If you have VPN on your router private relay on top of it could be a good way to do ip address laundering.
irusensei··on NetBSD 11.0
> Improved support for vintage and misc. hardware: alpha evbppc hp300 hppa m68k mac68k macppc mips x68k

It is interesting to see that as Linux drops support for legacy computers NetBSD still welcomes them. This is a NetBSD thing as it's not so much for FreeBSD.

As of now NetBSD is probably the go-to operating system for vintage hardware.

irusensei··on Data centers trigger voter backlash
This goes to every LinkedIn brain idiot spouting recycled nonsense about the new Industrial Revolution and that white collar jobs are going away. These blabbering idiots never read a story book to understand the time period, that people displaced by industrialization were uneducated illiterate farm workers in a period in time before democracy.

Jump today most countries stable enough to build infrastructure are democracies and the white collar people you are demonizing do vote and that immense investment in infrastructure is not really easy to relocate.

irusensei··on What we call "age verification" is actually mass surveillance
They don't exist because the organizations who lobbied governments were YOTI, Persona, K-ID and others who have a vested interest in collecting data and rent seek by latching through regulations like diseased ticks.
irusensei··on What we call "age verification" is actually mass surveillance
>The government issues an eID to your wallet

So people in dubious legal circumstances are locked out the internet?

irusensei··on Steam Machine launches today
I doubt it will ever be because Apple doesn’t understand the non casual gaming market.
irusensei··on Ubiquiti: Enterprise NAS, Built on ZFS
Can’t wrap my head around how their firewall rules work. Default rule and there is no way to change it.

And lately the interface has been so convoluted and nonsensical. DNS records sure now “policies”, you can only assign very essential rules like setting routing rules to known objects based on MAC address - the ui doesn’t allow you to pick an IP address.

I wanted to create a special routing rules to allow a container using macvlans to always leave through ISP2. Since this is a macvlan the interface MAC address was different every time the system started. Mind you “ip x.x.x.x goes through link 2” is one of those basic things firewalls and routers do since forever but if the object doesn’t exist on their automated inventory then forget it.

irusensei··on Ubiquiti: Enterprise NAS, Built on ZFS
I guess routers and access points are easy to replace with a normal OS but I’m yet to see a managed l2 or l3 switch that runs user provider OS. I’d ditch anything in an eye blink if there was some kind of fully open source network stack that can be controlled through infrastructure code. Affordable that is, not including that Nvidia thingie.
irusensei··on Ubiquiti: Enterprise NAS, Built on ZFS
Is the firmware open though?
irusensei··on Ubiquiti: Enterprise NAS, Built on ZFS
Still sucks that you need to verify if your kernel update is compatible with the external module.
irusensei··on macOS needs its grid back
Seems MacOS Snow Leopard is for the Apple people what Windows 7 is for Windows people.
irusensei··on Age verification for social media, the beginning of the end for a free internet?
"I'm sorry but I can't fulfill requests that might potentially harm young sebastian."
irusensei··on A 10 year old Xeon is all you need
Small fans need to spin faster so these can be very high pitch even if you stuff some Noctua 40mm fans into it.
irusensei··on Please Do Not Vibe Fuck Up This Software
As much as I would love to see Anthropic going down in flames I think that developer doesn’t deserve to be targeted by such a low effort social media farming post.

I am nothing but grateful for Samba and Rsync.

irusensei··on Notes from the Mistral AI Now Summit
Please don't run Chinese models for KYC operations.
irusensei··on GitHub bans security researcher who posted zero-day Windows exploits
Most companies providing corporate security consulting I had to deal in the past are operating on a checklist.
irusensei··on Mounting git commits as folders with NFS (2023)
I really wanted NFSv4 ACLs but Linux doesn't like it while FreeBSD doesn't make use of my hardware (intel p/e cores) in the most efficient way.
irusensei··on Mounting git commits as folders with NFS (2023)
To be fair setting up a KDC and then distributing krb5.conf and idmap.conf files is not such a hard task.

Then it's not unencrypted anymore because sec=krb5p handles signing and encryption. I have better throughput using sec=krb5p than with samba signing and encryption. I don't know if it's because Samba uses GNUTLS but the transfer speeds are always awful.

My beefs with NFS is MacOS being extremely quirk with settings. That and the extremely misleading error messages.

>Dev1: Here's a great idea! Let's run an insecure network server in Kernel space!

>Dev2: OMG! You're so smart! Let's also exclude any encryption!!!

If it wasn't such a cool idea they wouldn't be doing it again, this time with direct access to memory: https://docs.kernel.org/filesystems/smb/ksmbd.html

Page 1 of 25Next →