BrosTrend S1-V2 8-Port 2.5GbE Fanless Switch Review Slightly More Than a Metal Case

Post Syndicated from Rohit Kumar original https://www.servethehome.com/brostrend-s1-v2-8-port-2-5gbe-fanless-switch-review-mealinear-metal-case/

We check out the BrosTrend S1-V2, which is a slightly upscale MaxLinear-based fanless and low power 8-port 2.5GbE switch

The post BrosTrend S1-V2 8-Port 2.5GbE Fanless Switch Review Slightly More Than a Metal Case appeared first on ServeTheHome.

Mount Mayhem at Netflix: Scaling Containers on Modern CPUs

Post Syndicated from Netflix Technology Blog original https://netflixtechblog.com/mount-mayhem-at-netflix-scaling-containers-on-modern-cpus-f3b09b68beac

Authors: Harshad Sane, Andrew Halaney

Imagine this — you click play on Netflix on a Friday night and behind the scenes hundreds of containers spring to action in a few seconds to answer your call. At Netflix, scaling containers efficiently is critical to delivering a seamless streaming experience to millions of members worldwide. To keep up with responsiveness at this scale, we modernized our container runtime, only to hit a surprising bottleneck: the CPU architecture itself.

Let us walk you through the story of how we diagnosed the problem and what we learned about scaling containers at the hardware level.

The Problem

When application demand requires that we scale up our servers, we get a new instance from AWS. To use this new capacity efficiently, pods are assigned to the node until its resources are considered fully allocated. A node can go from no applications running to being maxed out within moments of being ready to receive these applications.

As we migrated more and more from our old container platform to our new container platform, we started seeing some concerning trends. Some nodes were stalling for long periods of time, with a simple health check timing out after 30 seconds. An initial investigation showed that the mount table length was increasing dramatically in these situations, and reading it alone could take upwards of 30 seconds. Looking at systemd’s stack it was clear that it was busy processing these mount events as well and could lead to complete system lockup. Kubelet also timed out frequently talking to containerd in this period. Examining the mount table made it clear that these mounts were related to container creation.

The affected nodes were almost all r5.metal instances, and were starting applications whose container image contained many layers (50+).

Challenge

Mount Lock Contention

The flamegraph in Figure 1 clearly shows where containerd spent its time. Almost all of the time is spent trying to grab a kernel-level lock as part of the various mount-related activities when assembling the container’s root filesystem!

Figure 1: Flamegraph depicting lock contention

Looking closer, containerd executes the following calls for each layer if using user namespaces:

  1. open_tree() to get a reference to the layer / directory
  2. mount_setattr() to set the idmap to match the container’s user range, shifting the ownership so this container can access the files
  3. move_mount() to create a bind mount on the host with this new idmap applied

These bind mounts are owned by the container’s user range and are then used as the lowerdirs to create the overlayfs-based rootfs for the container. Once the overlayfs rootfs is mounted, the bind mounts are then unmounted since they are not necessary to keep around once the overlayfs is constructed.

If a node is starting many containers at once, every CPU ends up busy trying to execute these mounts and umounts. The kernel VFS has various global locks related to the mount table, and each of these mounts requires taking that lock as we can see in the top of the flamegraph. Any system trying to quickly set up many containers is prone to this, and this is a function of the number of layers in the container image.

For example, assume a node is starting 100 containers, each with 50 layers in its image. Each container will need 50 bind mounts to do the idmap for each layer. The container’s overlayfs mount will be created using those bind mounts as the lower directories, and then all 50 bind mounts can be cleaned up via umount. Containerd actually goes through this process twice, once to determine some user information in the image and once to create the actual rootfs. This means the total number of mount operations on the start up path for our 100 containers is 100 * 2 * (1 + 50 + 50) = 20200 mounts, all of which require grabbing various global mount related locks!

Diagnosis

What’s Different In The New Runtime?

As alluded to in the introduction, Netflix has been undergoing a modernization of its container runtime. In the past a virtual kubelet + docker solution was used, whereas now a kubelet + containerd solution is being used. Both the old runtime and the new runtime used user namespaces, so what’s the difference here?

  1. Old Runtime:
    All containers shared a single host user range. UIDs in image layers were shifted at untar time, so file permissions matched when containers accessed files. This worked because all containers used the same host user.
  2. New Runtime:
    Each container gets a unique host user range, improving security — if a container escapes, it can only affect its own files. To avoid the costly process of untarring and shifting UIDs for every container, the new runtime uses the kernel’s idmap feature. This allows efficient UID mapping per container without copying or changing file ownership, which is why containerd performs many mounts.

Figure 2 below is a simplified example of how this idmap feature looks like:

Figure 2: idmap feature

Why Does Instance Type Matter?

As noted earlier, the issue was predominantly occurring on r5.metal instances. Once we identified the root issue we could easily reproduce by creating a container image with many layers and sending hundreds of workloads using the image to a test node.

To better understand why this bottleneck was more profound on some instances compared to others, we benchmarked container launches on different AWS instance types:

  • r5.metal (5th gen Intel, dual-socket, multiple NUMA domains)
  • m7i.metal-24xl (7th gen Intel, single-socket, single NUMA domain)
  • m7a.24xlarge (7th gen AMD, single-socket, single NUMA domain)

Baseline Results

Figure 3 shows the baseline results from scaling containers on each instance type

  • At low concurrency (≤ ~20 containers), all platforms performed similarly
  • As concurrency increased, r5.metal began to fail around 100 containers
  • 7th generation AWS instances maintained lower launch times and higher success rates as concurrency grew
  • m7a instances showed the most consistent scaling behavior with the lowest failure rates even at high concurrency

Deep Dive

Using perf record and custom microbenchmarks, we can see the hottest code path was in the Linux kernel’s Virtual Filesystem (VFS) path lookup code — specifically, a tight spin loop waiting on a sequence lock in path_init(). The CPU spent most of its time executing the pause instruction, indicating many threads were spinning, waiting for the global lock, as shown in the disassembly snippet below

path_init():
…
mov mount_lock,%eax
test $0x1,%al
je 7c
pause
…

Using Intel’s Topdown Microarchitecture Analysis (TMA), we observed:

  • 95.5% of pipeline slots were stalled on contested accesses (tma_contested_accesses).
  • 57% of slots were due to false sharing (multiple cores accessing the same cache line).
  • Cache line bouncing and lock contention were the primary culprits.

Given a high amount of time being spent in contested accesses, the natural thinking from a perspective of hardware variations led to investigation of NUMA and Hyperthreading impact coming from the architecture to this subset

NUMA Effects

Non-Uniform Memory Access (NUMA) is a system design where each processor has its own local memory for faster access but relies on an interconnect to access the memory attached to a remote processor. Introduced in the 1990s to improve scalability in multiprocessor systems, NUMA boosts performance but also introduces higher latency when a CPU needs to access memory attached to another processor. Figure 4 is a simple image describing local vs remote access patterns of a NUMA architecture

Figure 4: Source: https://pmem.io/images/posts/numa_overview.png

AWS instances come in a variety of shapes and sizes. To obtain the largest core count, we tested the 2-socket 5th generation metal instances (r5.metal), on which containers were orchestrated by the titus agent. Modern dual-socket architectures implement NUMA design, leading to faster local but higher remote access latencies. Although container orchestration can maintain locality, global locks can easily run into high latency effects due to remote synchronization. In order to test the impact of NUMA, we tested an AWS 48xl sized instance with 2 NUMA nodes or sockets versus an AWS 24xl sized instance, which represents a single NUMA node or socket. As seen from Figure 5, the extra hop introduces high latencies and hence failures very quickly.

Figure 5: Numa Impact

Hyperthreading Effects

  • Hyperthreading (HT): Disabling HT on m7i.metal-24xl (Intel) improved container launch latencies by 20–30% as seen in Figure 6, since hyperthreads compete for shared execution resources, worsening the lock contention. When hyperthreading is enabled, each physical CPU core is split into two logical CPUs (hyperthreads) that share most of the core’s execution resources, such as caches, execution units, and memory bandwidth. While this can improve throughput for workloads that are not fully utilizing the core, it introduces significant challenges for workloads that rely heavily on global locks. By disabling hyperthreading, each thread runs on its own physical core, eliminating this competition for shared resources between hyperthreads. As a result, threads can acquire and release global locks more quickly, reducing overall contention and improving latency for operations that generally share underlying resources.
Figure 6: Hyperthreading impact

Why Does Hardware Architecture Matter?

Centralized Cache Architectures

Some modern server CPUs use a mesh-style interconnect to link cores and cache slices, with each intersection managing cache coherence for a subset of memory addresses. In these designs, all communication passes through a central queueing structure, which can only handle one request for a given address at a time. When a global lock (like the mount lock) is under heavy contention, all atomic operations targeting that lock are funneled through this single queue, causing requests to pile up and resulting in memory stalls and latency spikes.

In some well-known mesh-based architectures as shown in Figure 7 below, this central queue is called the “Table of Requests” (TOR), and it can become a surprising bottleneck when many threads are fighting for the same lock. If you’ve ever wondered why certain CPUs seem to “pause for breath” under heavy contention, this is often the culprit.

Figure 7: Public document from one of the major CPU vendors Source:https://www.intel.com/content/dam/developer/articles/technical/ddio-analysis-performance-monitoring/Figure1.png

Distributed Cache Architectures

Some modern server CPUs use a distributed, chiplet-based architecture (Figure 8), where multiple core complexes, each with their own local last-level cache — are connected via a high-speed interconnect fabric. In these designs, cache coherence is managed within each core complex, and traffic between complexes is handled by a scalable control fabric. Unlike mesh-based architectures with centralized queueing structures, this distributed approach spreads contention across multiple domains, making severe stalls from global lock contention less likely. For those interested in the technical details, public documentation from major CPU vendors provides deeper insight into these distributed cache and chiplet designs.

Figure 8: Public document from one of the major CPU vendors, Source: (AMD EPYC 9004 Genoa Chiplet Architecture 8x CCD — ServeTheHome)

Here is a comparison of the same workload run on m7i (centralized cache architecture) vs m7a (distributed cache architecture). Note that, in order to make it closely comparable, Hyperthreading (HT) was disabled on m7i, given previous regression seen in Figure 6, and experiments were run using same core counts. The result clearly shows a fairly consistent difference in performance of approximately 20% as shown in Figure 9

Figure 9: Architectural impact between m7i and m7a

Microbenchmark Results

To prove the above theory related to NUMA, HT and micro-architecture, we developed a small microbenchmark which basically invokes a given number of threads that then spins on a globally contended lock. Running the benchmark at increasing thread counts reveals the latency characteristics of the system under different scenarios. For example, Figure 10 below is the microbenchmark results with NUMA, HT and different microarchitectures.

Figure 10: Global lock contention benchmark results

Results from this custom synthetic benchmark (pause_bench) confirmed:

  • On r5.metal, eliminating NUMA by only using a single socket significantly drops latency at high thread counts
  • On m7i.metal-24xl, disabling hyperthreading further improves scaling
  • On m7a.24xlarge, performance scales the best, demonstrating that a distributed cache architecture handles cache-line contention in this case of global locks more gracefully.

Improving Software Architecture

While understanding the impacts of the hardware architecture is important for assessing possible mitigations, the root cause here is contention over a global lock. Working with containerd upstream we came to two possible solutions:

  1. Use the newer kernel mount API’s fsconfig() lowerdir+ support to supply the idmap’ed lowerdirs as fd’s instead of filesystem paths. This avoids the move_mount() syscall mentioned prior which requires global locks to mount each layer to the mount table
  2. Map the common parent directory of all the layers. This makes the number of mount operations go from O(n) to O(1) per container, where n is the number of layers in the image

Since using the newer API requires using a new kernel, we opted to make the latter change to benefit more of the community. With that in place, no longer do we see containerd’s flamegraph being dominated by mount-related operations. In fact, as seen in Figure 11 below we had to highlight them in purple below to see them at all!

Figure 11: Optimized solution

Conclusion

Our journey migrating to a modern kubelet + containerd runtime at Netflix revealed just how deeply intertwined software and hardware architecture can be when operating at scale. While kubelet/containerd’s usage of unique container users brought significant security gains, it also surfaced new bottlenecks rooted in kernel and CPU architecture — particularly when launching hundreds of many layered container images in parallel. Our investigation highlighted that not all hardware is created equal for this workload: centralized cache management amplified cache contention while distributed cache design smoothly scaled under load.

Ultimately, the best solution combined hardware awareness with software improvements. For an immediate mitigation we chose to route these workloads to CPU architectures that scaled better under these conditions. By changing the software design to minimize per-layer mount operations, we eliminated the global lock as a launch-time bottleneck — unlocking faster, more reliable scaling regardless of the underlying CPU architecture. This experience underscores the importance of holistic performance engineering: understanding and optimizing both the software stack and the hardware it runs on is key to delivering seamless user experiences at Netflix scale.

We trust these insights will assist others in navigating the evolving container ecosystem, transforming potential challenges into opportunities for building robust, high-performance platforms.

Special thanks to the Titus and Performance Engineering teams at Netflix.


Mount Mayhem at Netflix: Scaling Containers on Modern CPUs was originally published in Netflix TechBlog on Medium, where people are continuing the conversation by highlighting and responding to this story.

Избори за Народно събрание 2026 – секциите в чужбина са силно ограничени

Post Syndicated from Боян Юруков original https://yurukov.net/blog/2026/izbori2026-ik/

На 25-ти февруари парламента с гласовете на ГЕРБ, Възраждане, ИТН и част от ДСП-НН и БСП беше отхвърлено ветото на промените в Изборния кодекс. Тези промени намаляваха броя секции в страни извън ЕС, които може да се създадат извън дипломатическите представителства на 20. От обсъжданията и силната покрепа на Пеевски при първото гласуване и осигуряването на подкрепа при последното, става ясно, че целта е да се ограничат гласовете в Турция, Великобритания и САЩ.

Също така отлагат за пореден път с три години въвеждането на избирателен район Чужбина, който трябваше да бъде с 4 депутати специално представляващи българите зад граница. Към настоящия момент гласовете в чужбина се причисляват „служебно“ към избран от ЦИК район, изкривявайки значително волята на гласувалите там. Промените на Избирателния кодекс бяха обнародвани на 27-ми февруари. Още същия ден ЦИК измени решението си за разпределението на мандатите. Под новото решение ще намерите линк към старото и може да сравните. Веднага след това определи и местата, където автоматично ще се отварят секции зад граница. Правилото е, че в последните пет години трябва да са гласували поне 100 души в някоя от секциите на това място. Това означава, че се взимат предвид изборите за български и европейски парламент през юни 2024, изборите за парламент през октомври 2024, април 2023, октомври 2022 и юли 2021, както и смесените избори за парламент и президент през ноември 2021. Общо 7 вота.

В решението си ЦИК определя 372 секции на 58 места. За сравнение за октомври 2024-та определиха над два пъти повече такива секции – 783. Забелязва се веднага, че в Турция са превидили 4 места, във Великобритания – 2, а в САЩ – 4. Това са все посолства и консулства. В действителност, на база активността в последните пет години, секциите отворени по този начин трябва да са съответно 123, 107 и 85. Причината за това е, че предложението на ИТН подкрепено от ГЕРБ, ДПС-НН и Възраждане създава умишлено правен хаос, в който няма яснота как да се приложи правилото за 100-те гласували. Най-логичното би било да се вземат 20-те секции извън консулствта с най-много гласували. Това обаче не е описано изрично и ЦИК са решили просто да не спазят чл. 14, ал. 2, т. 2 от ИК.

Това, което буди притеснение обаче е, че в доста други страни секциите са намалени значително. Пример за това е Канада, където ЦИК решава да отвори секции само в Отава и Торонто. Над 100 гласували само при изборите през 2024-та има в Брамптън, Ванкувър, Вон, Калгари и всяка от 5-те секции в Монреал поотделно. Аналогично в Австралия искат секция само в посолството в Канабера, но над 100 гласа през юни 2021-ва е имало и в Мелбърн, Сидни и Пърт. Други държави с подобни „пропуски“ са Албания, Молдова, Норвегия, Северна Македония, Южна Африка, Сърбия и Швейцария. Не определят секции в Исландия, Нова Зеландия, Сингапур и Чешка република макар в последните 5 да е имало секции с повече от 100 гласували. Причината за това е друга аспект от промените в Изборния кодекс публикивани вчера – правилото за „поне 100 гласували“ вече се прилага само за страни от Европейския съюз“. Това допълнително утежнава процеса за гласуване на десетки хиляди българи спрямо постигнатия напредък в последните години.

Единственият избор за тези държави е да подават повече заявления за гласуване. Дори във Великобритания, САЩ и Турция това има значение, защото изглежда ще сме свидетели на състезание къде да има секция. Повечето заявления ще покажат за пореден път как има желаещи да гласуват и подобни мерки ограничават конституционните права на български граждани.

Както писах в предишната си статия, според хонограмата на ЦИК след няколко часа изтича срокът, в който следва да публикуват електронния формуляр за подаване на заявления. Когато излезе ще публикувам нова статия със съвети и ще изпратя напомняне да подават заявления на над 3000-те хиляди абонирали се за новини за поровеждането на изборите в чужбина.

Седмицата (23–28 февруари)

Post Syndicated from Йовко Ламбрев original https://www.toest.bg/sedmitsata-23-28-fevruari/

Седмицата (23–28 февруари)

Два месеца от все още новата 2026 година са вече история. Една шеста от годината отлетя неусетно. Точно толкова е отрязъкът от време и между назначаването на служебното правителство на Андрей Гюров и предсрочните парламентарни избори на 19 април. Време, през което част от играчите на политическата сцена ще се изправят и на главите си, за да отблъснат колкото е възможно повече хора от идеята да гласуват. Така ще могат за пореден път да си напазаруват влияние евтино и да прескочат чертата за оставане в играта. За сметка на всички нас, които трябва да направим и невъзможното да убедим още други като нас да гласуват – въпреки всичко. Защото е време за друго политическо поколение с различна политическа култура. И защото всички имаме право на надежда и по-смислено бъдеще.

Няма друга по-важна цел през следващите седем седмици.

И в този ред на мисли защо да не започнем нетрадиционно редакционния обзор на седмицата, а именно със стихотворението на месеца? Този път то е на Мирела Иванова, озаглавено е „Игра с поговорки“ и пулсира в синхрон с все тази същата позната ни трескавост, с която толкова свикнахме напоследък.

Игра с поговорки
С настървено старание –
сякаш се отдължавам –
непрестанно попълвам ведомостта
с малките изпитания.
Спешното на „Токуда“, ступорът
пред разританите в антрето чехли,
нелепото падане на заледения
тротоар, леденият игнор
на всевластните анонимни сенки,
безсилният, всепомитащ плач
на детето ми всеки ден,
всяка нощ… Малките изпитания –
малки дяволи, зъбят се, хилят се,
Седмицата (23–28 февруари)

Иначе, от началото на 2026 г. политическата сцена у нас сякаш е застинала в очакване, докато Румен Радев превръща мълчанието си в злато. Според актуални социологически данни бившият президент трупа обществено одобрение просто като отказва да участва в информационния шум. Докато повечето му политически опоненти приличат на „дебютантки на бал“, очакващи покана за танц, Радев залага на тактическо дистанциране от ежедневните скандали – от „Петрохангейт“ до споровете за съдебната реформа. Тази стратегия му позволява да остане „вкаменен като статуя“ и да не поема рискове, докато разочарованите избиратели проектират върху него коренно различни надежди: от юмрук срещу корупцията до „равнис“ по Москва. Прочетете повече в седмичния вътрешнополитически анализ на Емилия Милчева.

Мълчанието на Радев струва злато
Наблюдаваме феномена „Румен Радев на Шрьодингер“. Докато мълчи, той едновременно е срещу корупцията и мафията в правосъдието, за диалог с Русия, против еврото, за ЕС… Това ще свърши с обявяването на партийните му листи. И после? Коментар от Емилия Милчева.
Седмицата (23–28 февруари)

След края на Мюнхенската конференция по сигурността светът продължава да изглежда по-фрагментиран от всякога. И докато големите европейски държави трескаво търсят формулата за „стратегическа автономия“, България се оказва в деликатна позиция – между амбицията да бъде част от ядрото и риска да остане в сивата зона на новите геополитически линии на разделение. В анализа си за „Тоест“ Александър Малинов търси отговори на въпросите какво означава за нас пренареждането на приоритетите в Европа, каква е цената на политическото колебание и защо тишината от София по ключови теми се чува все по-силно в Брюксел.

Накъде след „Мюнхен 2026“? Отворените въпроси пред Европа и България
Мюнхенската конференция по сигурността затвърди усещането (де да беше само такова), че старият трансатлантически баланс се разпада. Вече всички сме на една вълна по този въпрос. Но докато Европа търси автономия, България рискува да остане между линиите на разделението. От Александър Малинов.
Седмицата (23–28 февруари)

Седмицата донесе лоша новина за все по-оредяващото медийно многообразие в България. Заради бюджетни ограничения редакциите на „Свободна Европа“ у нас и в Румъния спират работа на 31 март. Българският екип търси алтернативен начин да продължи работа и след закриването. А всички в редакцията на „Тоест“ здраво стискаме палци гласовете на колегите от „Свободна Европа“ да не заглъхнат.

Къде изчезна смисълът на образованието, е въпрос, който си задаваме непрекъснато и по различни поводи. А в новия си текст за „Тоест“ Светла Енчева изследва белезите, които и държавното образование, и неговите алтернативи оставят на подрастващите. И ако класната стая освен място за предаване на знания е и инструмент за социално инженерство, с което се произвеждат „винтчета“ вместо личности, дали бягството към домашното образование не заменя един капан с друг? Възможно ли е образование, което да не превръща детето нито в „още една тухла в стената“, нито в заложник на родителските предразсъдъци? Светла търси отговора в пролуката между обществения интерес и личната независимост, напомняйки, че в тази битка най-често залогът е самото дете.

Образованието – между държавата и семейството
Зад разделението между училищното и домашното образование стоят различни идеологии. И двете обаче могат да стигнат до опасни крайности, ако забравят най-важното: правото на детето на образование, което го подготвя за света. Тема с продължение от Светла Енчева.
Седмицата (23–28 февруари)

Оставаме на същата тема и с най-новата статия на Донка Дойчева-Попова. Тя разговаря с Нели Керемидчиева – радетелка за модернизацията на родното образование и съоснователка на фестивала „Възможното образование“. Нели споделя за трудния път на една тиха, но категорична революция – от прожекциите на първите преведени филми, променили нагласите на много родители, до изграждането на общност и нови образователни пространства, в които личността и връзката между хората са поставени над сухата фактология и оценките.

Оптимизмът на невъзможните неща. Разговор с Нели Керемидчиева
Образованието може и трябва да бъде различно и все повече хора започват да вярват в това. Разговор на Донка Дойчева-Попова с Нели Керемидчиева за демократичното образование, за силата на общността и за упорития оптимизъм, който превръща невъзможното във възможно.
Седмицата (23–28 февруари)

Замисляли ли сте се колко често разговорите за архитектура са всъщност разговори за обществото? В предстоящия епизод на „Тоест разговаряме“ Владислав Севов ще търси смисъла отвъд фасадите именно с арх. Анета Василева – доктор по история и теория на архитектурата, преподавателка в УАСГ и авторка на множество критически текстове, писани през последните над 15 години за различни издания, в т.ч. и за „Тоест“. Формален повод за разговора ще бъде и новата ѝ книга „Неудобната модерност. Българската архитектура след Втората световна война“ (изд. „Жанет 45“), която предстои да излезе в най-скоро време.

Другата събота Анета и Владислав ще ни превеждат визуалния език на архитектурата в думи. Ще разберем защо в дигиталната ера книгата се оказва по-силната медия за съхраняване на паметта и защо писането за архитектура е акт на обществена отговорност. Двамата ще коментират важния въпрос кога архитектът е просто изпълнител и кога е длъжен да заеме позиция.

Гледайте „Тоест разговаряме“ с Анета Василева на 7 март 2026 г. от 16:00 часа в YouTube Live, като преди това може да довършите изречението „Градът за хората е…“ и да зададете предварителен въпрос на Анета в нашата анкета.

След като в първата част на своя текст за рубриката „Ориент кафе“ Атанас Шиников ни въведе в света на арабските приложения за запознанства, във втората продължаваме да лъкатушим между вярата и алгоритмите, търсейки отговора на въпроса могат ли онлайн запознанствата да бъдат „халал“. И как оцеляват моралните императиви на исляма във време, в което „суайпването“ наляво и надясно стана част от ежедневието на необвързаните. Не пропускайте да прочетете продължението на статията за „Тиндър/Миндър“ и за битката за сърцата в дигиталния Ориент.

Тиндър/Миндър, халал, сайтове и приложения за запознанства (продължение)
След като се разходихме из арабските сайтове и приложения за запознанства, време е да потърсим мнението на традиционните религиозни учени за тях. Атанас Шиников отново има с какво да ни изненада.
Седмицата (23–28 февруари)

Тръгвайки от провокацията на поредната голяма класация, Миглена Николчина, Еньо Стоянов, Николай Генов и Чавдар Парушев деконструират мита за обективността в гейминдустрията чрез характерното за тях дълбоко философско и естетическо изследване на видеоигрите като поле на социално общуване. Потопете се в „Награди, класации, списъци – какво (не) казват те за видеоигрите?“ – един текст за всички, които търсят смисъла зад екрана на конзолата си.

Награди, класации, списъци – какво (не) казват те за видеоигрите?
Тръгвайки от една поредна класация на „най-добрите“ видеоигри, Миглена, Еньо, Николай и Чавдар (Северина завършва докторската си дисертация по философия, но скоро ще е на линия) постепенно стигат до идеята да разработят – без да класират – 100-те игри на „Игромислие“ за 2026 година.
Седмицата (23–28 февруари)

И накрая – две страхотни новини за българската литература. Три години след като романът „Времеубежище“ на Георги Господинов в превод на английски език от Анджела Родел спечели международната литературна награда „Букър“, в дългия списък с номинирани книги за 2026 г. попадна и второ заглавие от български автор – „Остайница“ от Рене Карабаш в превод на Изидора Анжел. Романът ни сблъсква със суровата традиция на албанските жени, които заживяват като мъже, за да избягат от оковите на вековния патриархален закон. „Остайница“ е разказ за високата цена на свободата в свят, в който единственият начин да оцелееш е да се отречеш от собствената си природа.

Остайница от Рене Карабаш
„Читателят е поставен в епицентъра на кръвните отмъщения в Албания, там където смъртта следва като сянка и наровете никога не узряват. Подобно на романите на Исмаил Кадаре, книгата разгръща сериозните патриархални теми по тези земи и размишлява върху липсата на Бог в човека. Тази интересна и разтърсваща книга заслужава голямо внимание, защото вярвам, че има силата да върне човешкото в човека.“ – Владимир Зарев Романът отвежда читателя при суровия Канун на Леке Дукагини, който все още властва в изолирани местности на Балканите. В него жени стават заклети девиции се превръщат в мъже, като режат косите им и ги обличат в мъжки дрехи. Кръвните вражди между фамилиите са ежедневие, любовта е равна на смърт, а жената е равна на двадесет вола. На нищо повече. Честта се измерва с „два пръста над челото“. В този патриархат смъртта е постоянна гостенка почти на всеки дом. И това не е мит, а истина, която пълзи на не повече от 600 км от България. Тази истина не е чужда, това е нашата истина. Историята на човека и изборите, които прави, последвани от необратимите последствия от тях. Книгата ни среща с Бекиа, едно момиче, което отчаяно иска да бъде син на баща си, който е искал да има момче. Докъде може да стигнеш, за да се превърнеш в син? Грях ли е да избягаш от смъртта? Грешка ли е да се отдадеш на страстта с цената на нечий друг живот? Това е история за човека отвъд пола, отвъд думите ”син” и ”дъщеря”, ”мъж” и ”жена”, за човека, събрал гнева и милостта на Господ в своите 21 грама душа. Романът е написан в постмодерния стил на писане „поток на съзнанието“ който подмята читателя като вълна назад в миналото и напред в настоящето. Всичко, което читателят трябва да направи, за да не се удави в него е да се отпусне и да се остави да бъде носен до самия край, ако изобщо една такава история може да има край.
Седмицата (23–28 февруари)

А най-новият роман на Георги Господинов „Градинарят и смъртта“ в превод на френски език от Мари Врина-Николов тази седмица влезе в краткия списък за европейската награда „Жан Моне“.

За мнозина този уикенд ще бъде по-дълъг, ако са си позволили в понеделник да са в отпуск, защото във вторник е националният празник на България. По този повод искам да припомня един текст на Зорница Христова отпреди осем години. Това е всъщност първата поява на Зорница в „Тоест“ – от времето, когато медията имаше зад гърба си едва един месец съществуване. И до днес обаче текстът ѝ „Трети март“ продължава да е актуален.

Трети март
Зорница Христова • Обичам родината, казва съседът, но мразя държавата. Вярвам му. В момента окачва знаме на балкона. А пък и двете чувства са лесни за споделяне. Само че… какво е родина? Природата и историята? Малко от традиционната кухня? Фолклорът? Значи родината е това, което не зависи от нас. А държавата – онова, което зависи.
Седмицата (23–28 февруари)

Преди да ви оставя насаме с нашите статии, нека припомня, че издръжката на „Тоест“ зависи от вашата редовна финансова подкрепа. Подкрепете ни!

Приятно четене!

Metasploit Wrap-Up 02/27/2026

Post Syndicated from Jacquie Harris original https://www.rapid7.com/blog/post/pt-metasploit-wrap-up-02-27-2026

No Prob-ollama

This release brings some serious firepower with multiple new exploit modules and critical vulnerability support! The standout additions are the Ollama path traversal RCE (CVE-2024-37032), a sophisticated exploit chaining arbitrary file writes into unauthenticated root RCE, and the Grandstream GXP1600 stack overflow (CVE-2026-2329), which targets VoIP devices with accompanying credential harvesting and SIP interception post-modules. 

The BeyondTrust PRA/RS module got upgraded with support for the new CVE-2026-1731 command injection vulnerability along with legacy CVE support. On the evasion front, there’s fresh ARM64 RC4 encryption support with sleep-based detection bypass. Classic vulnerability modules like Unreal IRCd and vsftpd backdoors got quality-of-life improvements with proper check methods and multiple exploitation targets. Several auxiliary scanners (LDAP ESC, GraphQL introspection) also received critical bugfix updates eliminating false positives and crashes.

New module content (7)

Linux RC4 Packer with In-Memory Execution

Author: Massimo Bertocchi

Type: Evasion

Pull request: #20964 contributed by litemars

Path: linux/aarch64/rc4_packer

Description: First Linux evasion module for arm64, a packer using rc4 encryption, in memory execution of the elf binary, and sleep evasion.

BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) unauthenticated Remote Code Execution

Authors: Harsh Jaiswal and Jonah Burgess (CryptoCat)

Type: Exploit

Pull request: #20978 contributed by jburgess-r7

Path: linux/http/beyondtrust_pra_rs_command_injection

AttackerKB reference: CVE-2026-1731

Description: This adds a new module for unauthenticated command injection in BeyondTrust PRA/RS (CVE-2026-1731). This change also introduces a new library for BeyondTrust familiar helper functions; existing modules have been ported to use it.

GrandStream GXP1600 Unauthenticated Remote Code Execution

Author: sfewer-r7

Type: Exploit

Pull request: #20983 contributed by sfewer-r7

Path: linux/http/grandstream_gxp1600_unauth_rce

AttackerKB reference: CVE-2026-2329

Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices.  The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.

Ollama Model Registry Path Traversal RCE

Authors: Sagi Tzadik [email protected] and Valentin Lobstein [email protected]

Type: Exploit

Pull request: #21006 contributed by Chocapikk

Path: linux/http/ollama_rce_cve_2024_37032

AttackerKB reference: CVE-2024-37032

Description: This adds a new exploit module for Ollama (CVE-2024-37032). Ollama’s pull mechanism accepts arbitrary path traversal sequences, allowing an attacker to load a rogue OCI registry and write arbitrary files. The exploit does this by writing .so files into the target, then forcing Ollama to spawn a new process where the malicious library is loaded.

Linux WSL via Startup Folder Persistence

Author: h00die

Type: Exploit

Pull request: #20819 contributed by h00die

Path: linux/persistence/wsl/startup_folder

Description: This adds a new persistence module for WSL that writes a payload to the user’s startup folder. The module creates a persistence for Windows; however, the initial access needs to be in Linux.

Windows Registry Active Setup Persistence

Author: h00die

Type: Exploit

Pull request: #20841 contributed by h00die

Path: windows/persistence/registry_active_setup

Description: This adds new persistence for Windows, which uses the Windows feature Active Setup. The module abuse is used to launch our payload, with 2 caveats. 1) You downgrade from admin to user permissions, 2) it only launches the payload once per user.

GrandStream GXP1600 proxy SIP traffic

Author: sfewer-r7

Type: Post

Pull request: #20983 contributed by sfewer-r7

Path: linux/capture/grandstream_gxp1600_sip

Description: Adds three new modules: one exploit and two post modules, all targeting the Grandstream GXP1600 series of VoIP devices.  The exploit module uses CVE-2026-2329 to gain a root session, and the post modules leverage that access to perform credential stealing and packet capture.

Enhancements and features (9)

  • #20859 from dledda-r7 – Splits the exe.rb into separate, more consistent files. Each file responds to a combination of platform and architecture, offering a better granular approach.

  • #20938 from Chocapikk – Improves the check method in the beyondtrust_pra_rs_unauth_rrce to properly detect older versions that are also vulnerable but report the version in a different way.

  • #20950 from g0tmi1k – Updates the vsftp_234_backdoor module to add shell and Meterpreter payloads, improve checking, and increase the output for better traoubleshooting.

  • #20951 from g0tmi1k – Moves default payload into DefaultOptions in Remote for Mac module. This makes it more consistent with other existing modules.

  • #20952 from g0tmi1k – Enhances the unix/irc/unreal_ircd_3281_backdoor module to increase payload options, including adding a native Meterpreter session, adds debugging logic inside the module, and more verbose output.

  • #20988 from adfoster-r7 – Improved SolarWinds exploit module to automatically pick the correct SRVHOST value.

  • #20992 from adfoster-r7 – Adds a check method to the ms17-010 scanner module to improve the metadata associated with automation workflows.

  • #21010 from Nayeraneru – This adds reporting for GitLab services.

  • #21014 from adfoster-r7 – Fixes a crash when running the ldap esc vulnerable cert finder against a target when LDAP binding fails.

Bugs fixed (1)

  • #21012 from adfoster-r7 – Improves the GraphQL Introspection Scanner module to correctly handle invalid responses and false positives.

Documentation added (3)

  • #20832 from DataExplorerX – Adds comprehensive documentation for the linux/samba/chain_reply module targeting CVE-2010-2063.

  • #20990 from jheysel-r7 – This adds and an AI Usage Policy to GSoC Ideas Page as requested by GSoC.

  • #21005 from h00die – This adds example of GNU inetutils auth bypass module against a Synology NAS to existing documentation.

You can always find more documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

Buying Servers in 2026 is Tough but Here Are Our Buyer’s Tips

Post Syndicated from Patrick Kennedy original https://www.servethehome.com/buying-servers-in-2026-buyers-guide-tips-amd-dell-hpe-asrock-rack-asus-supermicro/

We go into our 2026 Server Buyer’s Guide with tips on navigating a tough year in server pricing trends and provide ideas on coming out ahead

The post Buying Servers in 2026 is Tough but Here Are Our Buyer’s Tips appeared first on ServeTheHome.

The collective thoughts of the interwebz