Седмицата (15–20 декември)

Post Syndicated from Боряна Телбис original https://www.toest.bg/sedmitsata-15-20-dekemvri/

Седмицата (15–20 декември)

Прощавайте, че ще се намеся като един Гринч във вашето дъ моуст уондърфул тайм оф дъ иър. Не че искам да ви развалям Коледата, но в случай че не сте разбрали, ви уведомявам, че с червените ботушки уверено потропваме на изток, дечица веселушки, в посока я Русия, я Северна Корея при по-голям късмет. 

Този път шейната спря пред bTV в опит да се натовари като подарък водещата на сутрешния блок Мария Цънцарова (а може би и колегата ѝ Златимир Йочев – не е ясно към момента на писането на този текст) и да бъде принесена като една коледна жертва на онзи, който си я е поръчал, понеже много е слушкал през годината. Виждали сме, че настоящият шеф на „Новини, актуални предавания и спорт“ в телевизията Асен Иванов има опит с поддържаща роля при поръчки тип „двойка кебапчета с гарнитура“. Може да се окаже, че човекът се оправя добре и с подаръчните ваучери.

Ще се превърне ли Мария Цънцарова от водеща на сутрешен блок в поредното празно столче, зависи от степента на наглост на опразнителите на столчета, но в голяма степен и от обществената и най-вече от гилдийната непримиримост по темата. 

Какво става с колегите на Мария в нюзрума на bTV? Какво става с колегите на Мария по принцип? От седмици е ясно, че на Цънцарова нещо ѝ се готви, защото жълтите медии дадоха тон за песен – а те са ветропоказателите, насочени в правилната посока даже преди да е задухал вятърът (какъв журналистически нюх, какво нещо!). Може би се чака да отмине бурята?

За сметка на това степента на наглост е на завидни нива, като се има предвид, че опитът за премахване от ефир на журналист, който все още не е забравил как се задават въпроси, се прави в ситуация на силно гражданско недоволство и стотици хиляди хора по площадите.

Но пък от друга страна, идва Коледа. Кой ще обърне внимание? Хората са запразнили вече. Ще поломотят някакви жълтопаветни соеволатеползватели в социалните си мрежи, където и бездруго са ограничени в ехо стая от себеподобни – и толкова. 

После ще броим нечетно за Бъдни вечер, щото сме много по традициите, като междувременно телевизиите ще ни покажат 90 начина за приготвяне на боб в гърне. След това ще правим новогодишни равносметки, от които никой не се интересува, и ще гърмим вина и пиратки за ЧНГ, а от януари ще се върнем пресни, росни, свежи пак в играта.

Това е сценарият за новия сезон на риалити формата „Опразнени столчета“ (или кабинети). През него досега минаха Анна Цолова, Миролюба Бенатова, Генка Шикерова, Дарина Сарелска, в различни периоди Виктор Николаев, Мирослава Иванова и още много. 

Има ли достатъчно гориво двигателят на недоволните по площадите, за да задвижи съвсем сериозна промяна, която да не увисне още след следващите избори като празно обещание? Това се пита Емилия Милчева в тазседмичния си текст „Със или без утре – ние решаваме“.

Можем ли да се абонираме за друго бъдеще, се чуди и Е.Т. в новия епизод от поредицата си. 

Как да го разкажем този свят наново, така че да не ни е срам и страх да живеем в него? За това, както и за постистината, за способността да мислиш и решаваш самостоятелно, за четенето и любовта Доротея Василева разговаря с култовата британска писателка Джанет Уинтърсън в специално интервю за „Тоест“. 

Още едно интервю имаме тази седмица. Ако сте пропуснали да гледате разговора на Владислав Севов със Светла Енчева – социоложка, правозащитничка, авторка и редакторка в „Тоест“, в статията може да откриете някои акценти от него, както и цялото видеоинтервю, проведено в рамките на рубриката ни „Тоест разговаряме“.

За какво още си „поговорихме“ тази седмица в „Тоест“: 

Това беше поведение на човек, видимо освободен от нуждата да доказва каквото и да било на когото и да било.

Оставям го така наникъде, за да ви напомня, че това е едно от най-хубавите чувства, които има да се чувстват на тоя свят.

  • За литература в рубриката ни „На второ четене“, където този път гастролира романът „Галаад“ в една брилянтна рецензия от Антония Апостолова. И от нея ще ви оставя нещо:

Вярвам, че съществува придобита невинност, която заслужава същата почит като детската невинност.

Да, „Галаад“ е роман за придобитата невинност, за спасението чрез вярата и търсенето на благодат. И за заедността, защото „нещо, което не съществува в отношение с нещо друго, не може да се каже, че из­общо съществува“.

За финал и на бюлетина, и на годината идва стихотворението на месеца, което този път е от японския поет и писател Кенджи Миядзава и е преведено от Елвира Цветанова. В него е всичко, което искам да ви пожелая; в него, честно казано, е и човекът, който искам да бъда. 

Благодаря ви от името на целия екип на „Тоест“, че ни четете и подкрепяте. Имаме нужда да продължите да го правите, защото медията ни съществува единствено и само благодарение на даренията от читатели.

Бъдете здрави! А пък за останалото – каквото дадат…

Code Orange: Fail Small — Our resilience plan following recent incidents

Post Syndicated from Dane Knecht original https://blog.cloudflare.com/fail-small-resilience-plan/

On November 18, 2025, Cloudflare’s network experienced significant failures to deliver network traffic for approximately two hours and ten minutes. Nearly three weeks later, on December 5, 2025, our network again failed to serve traffic for 28% of applications behind our network for about 25 minutes.

We published detailed post-mortem blog posts following both incidents, but we know that we have more to do to earn back your trust. Today we are sharing details about the work underway at Cloudflare to prevent outages like these from happening again.

We are calling the plan “Code Orange: Fail Small”, which reflects our goal of making our network more resilient to errors or mistakes that could lead to a major outage. A “Code Orange” means the work on this project is prioritized above all else. For context, we declared a “Code Orange” at Cloudflare once before, following another major incident that required top priority from everyone across the company. We feel the recent events require the same focus.  Code Orange is our way to enable that to happen, allowing teams to work cross-functionally as necessary to get the job done while pausing any other work.

The Code Orange work is organized into three main areas:

  • Require controlled rollouts for any configuration change that is propagated to the network, just like we do today for software binary releases.

  • Review, improve, and test failure modes of all systems handling network traffic to ensure they exhibit well-defined behavior under all conditions, including unexpected error states.

  • Change our internal “break glass”* procedures, and remove any circular dependencies so that we, and our customers, can act fast and access all systems without issue during an incident.

These projects will deliver iterative improvements as they proceed, rather than one “big bang” change at their conclusion. Every individual update will contribute to more resiliency at Cloudflare. By the end, we expect Cloudflare’s network to be much more resilient, including for issues such as those that triggered the global incidents we experienced in the last two months.

We understand that these incidents are painful for our customers and the Internet as a whole. We’re deeply embarrassed by them, which is why this work is the first priority for everyone here at Cloudflare.

* Break glass procedures at Cloudflare allow certain individuals to elevate their privilege under certain circumstances to perform urgent actions to resolve high severity scenarios.

What went wrong?

In the first incident, users visiting a customer site on Cloudflare saw error pages that indicated Cloudflare could not deliver a response to their request. In the second, they saw blank pages.

Both outages followed a similar pattern. In the moments leading up to each incident we instantaneously deployed a configuration change in our data centers in hundreds of cities around the world.

The November change was an automatic update to our Bot Management classifier. We run various artificial intelligence models that learn from the traffic flowing through our network to build detections that identify bots. We constantly update those systems to stay ahead of bad actors trying to evade our security protection to reach customer sites.

During the December incident, while trying to protect our customers from a vulnerability in the popular open source framework React, we deployed a change to a security tool used by our security analysts to improve our signatures. Similar to the urgency of new bot management updates, we needed to get ahead of the attackers who wanted to exploit the vulnerability. That change triggered the start of the incident.

This pattern exposed a serious gap in how we deploy configuration changes at Cloudflare, versus how we release software updates. When we release software version updates, we do so in a controlled and monitored fashion. For each new binary release, the deployment must successfully complete multiple gates before it can serve worldwide traffic. We deploy first to employee traffic, before carefully rolling out the change to increasing percentages of customers worldwide, starting with free users. If we detect an anomaly at any stage, we can revert the release without any human intervention.

We have not applied that methodology to configuration changes. Unlike releasing the core software that powers our network, when we make configuration changes, we are modifying the values of how that software behaves and we can do so instantly. We give this power to our customers too: If you make a change to a setting in Cloudflare, it will propagate globally in seconds.

While that speed has advantages, it also comes with risks that we need to address. The past two incidents have demonstrated that we need to treat any change that is applied to how we serve traffic in our network with the same level of tested caution that we apply to changes to the software itself.

We will change how we deploy configuration updates at Cloudflare

Our ability to deploy configuration changes globally within seconds was the core commonality across the two incidents. In both events, a wrong configuration took down our network in seconds.

Introducing controlled rollouts of our configuration, just as we already do for software releases, is the most important workstream of our Code Orange plan.

Configuration changes at Cloudflare propagate to the network very quickly. When a user creates a new DNS record, or creates a new security rule, it reaches 90% of servers on the network within seconds. This is powered by a software component that we internally call Quicksilver.

Quicksilver is also used for any configuration change required by our own teams. The speed is a feature: we can react and globally update our network behavior very quickly. However, in both incidents this caused a breaking change to propagate to the entire network in seconds rather than passing through gates to test it.

While the ability to deploy changes to our network on a near-instant basis is useful in many cases, it is rarely necessary. Work is underway to treat configuration the same way that we treat code by introducing controlled deployments within Quicksilver to any configuration change.

We release software updates to our network multiple times per day through what we call our Health Mediated Deployment (HMD) system. In this framework, every team at Cloudflare that owns a service (a piece of software deployed into our network) must define the metrics that indicate a deployment has succeeded or failed, the rollout plan, and the steps to take if it does not succeed.

Different services will have slightly different variables. Some might need longer wait times before proceeding to more data centers, while others might have lower tolerances for error rates even if it causes false positive signals.

Once deployed, our HMD toolkit begins to carefully progress against that plan while monitoring each step before proceeding. If any step fails, the rollback will automatically begin and the team can be paged if needed.

By the end of Code Orange, configuration updates will follow this same process. We expect this to allow us to quickly catch the kinds of issues that occurred in these past two incidents long before they become widespread problems.

How will we address failure modes between services?

While we are optimistic that better control over configuration changes will catch more problems before they become incidents, we know that mistakes can and will occur. During both incidents, errors in one part of our network became problems in most of our technology stack, including the control plane that customers rely on to configure how they use Cloudflare.

We need to think about careful, graduated rollouts not just in terms of geographic progression (spreading to more of our data centers) or in terms of population progression (spreading to employees and customer types). We also need to plan for safer deployments that contain failures from service progression (spreading from one product like our Bot Management service to an unrelated one like our dashboard).

To that end, we are in the process of reviewing the interface contracts between every critical product and service that comprise our network to ensure that we a) assume failure will occur between each interface and b) handle that failure in the absolute most reasonable way possible. 

To go back to our Bot Management service failure, there were at least two key interfaces where, if we had assumed failure was going to happen, we could have handled it gracefully to the point that it was unlikely any customer would have been impacted. The first was in the interface that read the corrupted config file. Instead of panicking, there should have been a sane set of validated defaults which would have allowed traffic to pass through our network, while we would have, at worst, lost the realtime fine-tuning that feeds into our bot detection machine-learning models.

The second interface was between the core software that runs our network and the Bot Management module itself. In the event that our bot management module failed (as it did), we should not have dropped traffic by default. Instead, we could have come up with, yet again, a more sane default of allowing the traffic to pass with a passable classification.

How will we solve emergencies faster?

During the incidents, it took us too long to resolve the problem. In both cases, this was worsened by our security systems preventing team members from accessing the tools they needed to fix the problem, and in some cases, circular dependencies slowed us down as some internal systems also became unavailable.

As a security company, all our tools are behind authentication layers with fine-grained access controls to ensure customer data is safe and to prevent unauthorized access. This is the right thing to do, but at the same time, our current processes and systems slowed us down when speed was a top priority.

Circular dependencies also affected our customer experience. For example, during the November 18 incident, Turnstile, our no CAPTCHA bot solution, became unavailable. As we use Turnstile on the login flow to the Cloudflare dashboard, customers who did not have active sessions, or API service tokens, were not able to log in to Cloudflare in the moment of most need to make critical changes.

Our team will be reviewing and improving all of the break glass procedures and technology to ensure that, when necessary, we can access the right tools as fast as possible while maintaining our security requirements. This includes reviewing and removing circular dependencies, or being able to “bypass” them quickly in the event there is an incident. We will also increase the frequency of our training exercises, so that processes are well understood by all teams prior to any potential disaster scenario in the future. 

When will we be done?

While we haven’t captured in this post all the work being undertaken internally, the workstreams detailed above describe the top priorities the teams are being asked to focus on. Each of these workstreams maps to a detailed plan touching nearly every product and engineering team at Cloudflare. We have a lot of work to do.

By the end of Q1, and largely before then, we will:

  • Ensure all production systems are covered by Health Mediated Deployments (HMD) for configuration management.

  • Update our systems to adhere to proper failure modes as appropriate for each product set.

  • Ensure we have processes in place so the right people have the right access to provide proper remediation during an emergency.

Some of these goals will be evergreen. We will always need to better handle circular dependencies as we launch new software and our break glass procedures will need to update to reflect how our security technology changes over time.

We failed our users and the Internet as a whole in these past two incidents. We have work to do to make it right. We plan to share updates as this work proceeds and appreciate the questions and feedback we have received from our customers and partners.

Metasploit Wrap-Up 12/19/2025

Post Syndicated from Spencer McIntyre original https://www.rapid7.com/blog/post/metasploit-wrap-up-12-19-2025

React2Shell Payload Improvements

Last week Metasploit released an exploit for the React2Shell vulnerability, and this week we have made a couple of improvements to the payloads that it uses. The first improvement affects all Metasploit modules. When an exploit is used, an initial payload is selected using some basic logic that effectively would make a selection from the first available in alphabetical order. Now Metasploit will prefer a default of x86 Meterpreters for Windows systems (since 32-bit payloads work on both 32-bit and 64-bit versions of Windows) and x64 Meterpreters for all other platforms including Linux. In the context of React2Shell, this means the payload now defaults to x64 for Linux instead of AARCH64.

Another improvement that only affects this exploit was the change of the default payload to one leveraging Node.js which is more likely to be present than the wget binary that was required. These defaults should hopefully help users get started with this high-impact exploit with more ease, but of course any compatible payload can still be selected.

Stay tuned for the Metasploit annual wrap-up and roadmap announcement coming up!

New module content (2)

N-able N-Central Authentication Bypass and XXE Scanner

Authors: Valentin Lobstein [email protected] and Zach Hanley (Horizon3.ai)

Type: Auxiliary

Pull request: #20713 contributed by Chocapikk 

Path: scanner/http/nable_ncentral_auth_bypass_xxe

AttackerKB reference: CVE-2025-11700

Description: This adds an auxiliary module that exploits two CVEs affecting N-able N-Central. CVE-2025-9316, an Unauthenticated Session Bypass and CVE-2025-11700 a XXE (XML External Entity) vulnerability. The module combines both vulnerabilities to achieve unauthenticated file read on affected N-Central instances (versions < 2025.4.0.9).

Grav CMS Twig SSTI Authenticated Sandbox Bypass RCE

Author: Tarek Nakkouch

Type: Exploit

Pull request: #20749 contributed by nakkouchtarek 

Path: multi/http/grav_twig_ssti_sandbox_bypass_rce

AttackerKB reference: CVE-2025-66301

Description: This adds an exploit module for a Server-Side Template Injection (SSTI) vulnerability (CVE-2025-66294) in Grav CMS, versions prior to 1.8.0-beta.27 , that allows bypassing the Twig sandbox to achieve remote code execution. To inject the malicious payload into a form’s process section, this module leverages CVE-2025-66301, a broken access control flaw in the /admin/pages/{page_name} endpoint.

Enhancements and features (2)

  • #20424 from cdelafuente-r7 – Updates how vulnerabilities and services are reported by adding a resource field to both models. It also add a parents field to make layered services possible. An optional resource field can now be provided and the existing service field has been updated to also accept an option hash.
  • #20771 from zeroSteiner – Updates Metasploit’s default payload selection logic to preference x86 payloads over AARCH64 payloads.
  • #20773 from jheysel-r7 – This updates the exploit for React2Shell with a better default payload.

Documentation

You can find the latest Metasploit documentation on our docsite at docs.metasploit.com.

Get it

As always, you can update to the latest Metasploit Framework with msfupdate and you can get more details on the changes since the last blog post from GitHub:

If you are a git user, you can clone the Metasploit Framework repo (master branch) for the latest. To install fresh without using git, you can use the open-source-only Nightly Installers or the commercial edition Metasploit Pro

FreeBSD laptop progress

Post Syndicated from jzb original https://lwn.net/Articles/1051394/

The FreeBSD Foundation has a blog
post
about the progress it has made in 2025 on the Laptop Support
& Usability Project
for FreeBSD. The foundation committed
$750,000 to the project in 2025 and has made progress on graphics
drivers, Wi-Fi 4 and 5 support, audio improvements, sleep states,
and more.

The installer for FreeBSD has gained a couple of new features that
benefit laptop users. In 15.0 the installer now supports downloading
and installing firmware packages after the FreeBSD base system
installation is complete. Coming in 15.1 it will be possible to
install the KDE graphical desktop environment during the installation
process. Grateful thanks to Bjoern Zeeb and Alfonso Siciliano
respectively. […]

The project continues into 2026 with a similar sized investment and
scope. Key targets include completing work on sleep states (modern
standby and hibernate), adding support for graphics drivers up to
Linux 6.18, Wi-Fi 6 support, USB4 and Thunderbolt support, HDMI
improvements, UVC webcam support, and Bluetooth improvements.

A substantial testing program will also start in January, aiming to
test all the functionality together across a range of
hardware. Community testers are very welcome to help out, the
Foundation will release a blog post and send an invite to help to the
Desktop mailing list some time in January 2026.

За спорта, НСБ, една „подпорна стена“ и защо поне веднъж не се прави законно

Post Syndicated from Боян Юруков original https://yurukov.net/blog/2025/nsb-2/

Стената от над два метра построена набързо без разрешение

Преди бях писал доста за ситуацията в спортен комплекс Диана в Дианабад, София. Повод за това беше един конкретен парцел със стара къща, която беше бутната, за да се направи автомивка. Тогавашния спортен министър Кралев директно заяви, че искал да си мие колите на министерството там, а районния кмет Георгиев ходотайстваше из протестиращите живущи из района да не правим проблеми, защото „много хубаво щяло да стане“. В действителност целта беше да дадат автомивката на Сталийски – приятелят на Борисов, за да обслужва заведнието му построено отново в същия комплекс, което е на метри от въпросната автомива. Тогава той държеше за жълти стотинки и големия открит басейн.

С протести и разкрития какво се случва строежът беше спрян. Тогава беше установено също, че са построили подпорна стена, която е незаконна, тъй като е над 120 см. и няма изрично позволение. За това видяхме писмо от строителен надзор, но без последствия. Бяха излели и много бетон въпреки наличието само на едно скрито от Фандъкова разрешение за поставяне. На нито един от многобройките сигнали след това, че все още има опасна незаконна стена не беше отговорено. Така си стоеше почти пет години.

Стари снимки на строежа на автомивката на Кралев и Сталийски през 2021-ва

Преди няколко седмици това се промени. Хора с джипове и охрана започнаха да оглеждат обекта и решихме, че пак се готви подобна схема. Започнаха да разчистват мястото. Подадох отново сигнал за незаконната стена и въпроси до общината и министерството какво става.

Междувременно открих конкурс на страницата на Национални спорни бази за точно това място – щели да правят игрища за падел. Такива вече има няколко от другата страна на комплекса – близо до общинските имоти, които ГЕРБ-НН иска да преотстъпва на за още жилищни сгради. В случая пак е добре, че това, което се планира е свързано със спорта. Проблем, разбира се, е че оставяйки настрана кой държи и какво прави с практически неизползваните други игрища отсреща на комплектса, за тях също няма разрешение за строеж превид цялата инфраструктура, стълбове и стени, които са изградени. Осветлението и пиянските компании създават проблеми на всички живеещи наоколо и за това също има сигнали, включително до НСБ. Сегашните кортове, впрочем, са на мястото да игрището, където Борисов риташе футбол и заради който НСО бяха официално забранили полета на дронове. Но поне темата сега пак е спорт.

Впрочем, наемът ще е вероятно 900 лв. на месец за 750 кв.м. площ, което е абсурдно малко. За аналогична сума се дава малкия гараж/сервиз поместен в трафопоста непосредствено до обсъжданото място. Говорят за инсвестиция от 150000 лв., но за такава не може да става дума при условие, че няма разрешение за строеж, т.е. няма какво да се облагородява на мястото. Всичко, което ще бъде изградено с – или по-вероятно без нужните разрешения за поставяне – задължително трябва да се премахне след края на договора и най-вече след максималния 5 годишен срок на разрешението за поставяне. Точката с инвестициите често се използва за оправдаване на отдаване на държавни имоти почти даром на частни интереси, особено предвид, че често тези инвестиции са практически безотчетни, невъзможни за доказване и/или по надути фактури за бързо амортизируеми бараки или други елементи. Не е нужно да гледаме по-далеч от ресторанта на Сталийски, където минаха с подобно обяснение. Но поне става дума за спорт в случая според заявките им та нека оставим това настрана.

„Ремонта“ на стената поръчан от районния кмет въпреки, че е незаконна

Трябва обаче да е законно. Проблемът с незаконната стена остава. На сигнал до райния кмет той отговаря, че наистина стената е над 120 см. и наистина е изградена покрай разрешение за поставяне. Т.е. липсва друго разрешение и е незаконна. В същия отговор обаче пуска предписание да се обезопаси като се довърши и излее още бетон. Като причина посочва стърчащата арматура, за която сигнализираме години наред. Сега обаче ефективно задължава НСБ да лее още бетон. Няма отговор на искането да бъде отменено предписанието като незаконосъобразно.

Този отговор и предписание обаче са изготвени и пристигат следобеда на 12-ти декември. По обяд на същия ден НСБ отварят оферите за отдаване под наем на мястото. Още не се знае кой е спечелил. НСБ отговориха, че ще стане ясно до края на годината. Сутринта на същия ден на мястото вече се слага арматура и се готви за леене на бетон. Поредицата от събития и действия на НСБ, районната администрация и работниците с неизвестен поръчител най-малкото създава впечатление, че вече всичко е решено и платено отдавна, а каквото е нужно се узаконява и скрива в последствие.

Подготовка за запечатване на почвения слой и леене на плоча от НСБ, което отричат. Снимка преди час.

В последната седмица пък поготвиха цялото място за бетониране и запечатване на почвата. Отново без каквото и да е разрешение. Нито изнесоха горния почвен слой, нито има табела за строеж, нито обезопасяване на площадката. Леенето на бетон надхвърля дори опита на районния кмет да узакони подпорната стена. Бързат докато строителен надзор не гледа.

Междувременно звъннах на НСБ представяйки се за заинтересован от конкурса. Попитах дали има проблеми с мястото, дали има разрешение за поставяне като искат да правят игрище, дали наистина стената е незаконна. Казаха, че нямат нищо и не знаят за стената, но като мине конкурса отговорност на наемателя ще е да вади и узаконява каквото е нужно, а явно и да понася разходите и щетите от сегашното състояние. Този отговор е повече от странен предвид, че НСБ като собственик е единственият, който може да изважда разрешения за това място. Именно на тяхно име е и от тяхно име е строежът на ресторанта, където Котараците и Борисов си правиха редовни срещи. Впрочем, ако се чудите защо на картата долу имотът е отбелязан като частен, това е защото НСБ не са вписали никакъв акт за собственост в имотния регистър, както и за много други спортни обекти. Така по косвени сведения Кадастърът я определя като частна.

Известна собственост на имотите в и около спортен комплекс Диана

Днес директорът на НСБ Пламен Манолов ми отговори на част от въпросите. Настоява, че сигналите и търденията ми до сега са били тенденциозни – особено това, че спорния комплекс бил само за спорт, но се е вслушал в тях и ще прави спортна площадка. Не отговаря за установената за незаконна стена, а само, че всичко ще бъде със съответните разрешителни. Ще разберем за кой е предопределена в следващите седмици. В същото време няма обществена поръчка и не е ясно кой всъщност инкогнито лее бетон на даданото място, няма разрешение за това и работниците попитани на място смутено не отговарят. Всъщност, за разлика от други държавни фирми НСБ са една от малкото, които няма никакви обществени поръчки. Празни са съответните секции на сайта им, решенията са трудни за намиране, изчезват или се изменят на страницата им.

Прекрасно е, че комплексът ще се използва повече за спорт. Както бях писал преди време – по-голямата част от територията е за други дейности включително автосервиз в бивш трафопост, складове и магазини, ресторант и кафе, платен паркинг, който не издава касови бележки и почти сигурно не отчита оборот и прочие. Защо обаче трябва да се прави незаконно всичко това? Защо не се узаконят нещата и не стане всичко на светло вместо да се укриват документи и изпълнители? Всичко напомня как преди години членове на борда на НСБ ми звъняха с молба да съм спрял със статиите по темата и да се ровя в темата със Сталийски и Борисов. Сега поне получавам официални отговори от тях. Дано отговорят и за прожекторите тормозещи живеещите около съществуващите площадки за падел, а районната община – защо години не отговаря на сигнали докато някому не е угодно това.

[$] A visualizer for BPF program state

Post Syndicated from daroc original https://lwn.net/Articles/1050585/

The BPF verifier is complicated. It needs to
check every possible path that a
BPF program’s execution could take. The fact that its determination of whether a
BPF program is safe is based on the whole lifetime of the program, instead of
simple local factors, means that the cause of a verification
failure is not always obvious. Ihor Solodrai and Jordan Rome gave a presentation
(slides)
at the

2025 Linux Plumbers Conference
in Tokyo about
the
BPF verifier visualizer
that they have been building
to make diagnosing verification failures easier.

The collective thoughts of the interwebz