eBPF: Preventing Garbage HTTP Payloads When Reading Kernel Scatter-Gather Buffers
How our nettap eBPF agent produced garbage HTTP bodies from kernel iov_iter scatter-gather buffers, and the CO-RE plus task-local storage fix that made it correct.
Browse 60 posts in this category
How our nettap eBPF agent produced garbage HTTP bodies from kernel iov_iter scatter-gather buffers, and the CO-RE plus task-local storage fix that made it correct.
The best model isn't the smartest — it's whichever should get the next unit of work. Notes from NVIDIA on routing, local models, and the AI factory.
A production bug survived two confident fixes and green tests. Replaying the captured request exposed the missing state and proved the real fix.
Our v2 release looked clean in HTTP tests until we diffed the SQL workload — an N+1 loop, a startup migration, and 70 ms of extra DB time hiding in plain sight. Here's how to compare two releases without database access.
The trace was sampled out. I found the bug anyway — by filtering recorded traffic on the customer's email instead of a trace ID. Here's how to follow one request across four services with no trace IDs and no OpenTelemetry.
A second run of our AI bug-fixing benchmark shows where captured traffic lifts agents toward 90%, why service maps barely help, and which bugs still fail.
Using 'production-similar' data in pre-production is a major security risk. Learn why traditional masking fails, where hidden PII hides, and how to fix it.
Replay an authenticated flow and the protected calls fail with 403. Here is how proxymock recommendations fix the expired bearer token in one click.
Production traffic is the most complete record of what your system does, and most teams throw it away. One capture powers reproduce, validate, and sandbox.