Sign in

Christoph Lutz

@christophlutz.bsky.social
145 followers 84 following 217 posts

Those who don't jump will never fly. www.0xChris.dev

PostsRepliesMedia
Christoph Lutz @christophlutz.bsky.social · 03/10/2026
arxiv.org/abs/2609.22781
arxiv.org
io_uring in Oracle Database: A Hybrid Storage I/O Architecture at Production Scale
We describe the integration of io_uring into Oracle Database's storage layer and the architectural decisions required to deploy it in a production multi-process RDBMS. Our design uses per-process ring...
030
Reposted by Christoph Lutz
Kamil Stawiarski @ora600pl.bsky.social · 23/09/2026
Burning tokens for useful toys continues. I enjoy using SQLcl but if you (like me) use oradebug for testing, investigating and mostly fun, you will be forced to use SQL*Plus. So I instrumented Codex to create a plugin for SQLcl to call upidbg, kpusvcrh and kpusvc2hst :) github.com/ora600pl/soda
022
Christoph Lutz @christophlutz.bsky.social · 15/09/2026
Interested in how Oracle 26ai protects local auto-login wallets? 👇 t.ly/4re1y
t.ly
Deobfuscating Local Auto-Login Wallets in Oracle 26ai
Deobfuscating Local Auto-Login Wallets in Oracle 26ai
121
Reposted by Christoph Lutz
Martin Berger (berx) @martinberx.bsky.social · 06/09/2026
#POUG2026 is over - post conference blues kicks in. Thank you @luizafrompoland.bsky.social & @ora600pl.bsky.social and all your team for the fabulous event! Big thanks to all the speakers and attendees for content, questions & discussions. You all make this conference unique. See you at #POUG2027
0174
Reposted by Christoph Lutz
Dani Schnider @danischnider.bsky.social · 05/09/2026
Some „basics“ about log writer (LGWR) explained by @christophlutz.bsky.social at #POUG2026, including a live demo with foreground session @franckpachot.bsky.social and log writer @chandlerdba.bsky.social
2102
Christoph Lutz @christophlutz.bsky.social · 01/09/2026
In Oracle 26ai, auto-login wallets are protected by a randomly generated password encrypted with a random 128-bit AES key. Both are stored in the cwallet.sso header, allowing the original ewallet.p12 and its TDE master key to be recovered. Full details: t.ly/hfZXS
t.ly
Deobfuscating Auto-Login Wallets in Oracle 26ai
Deobfuscating Auto-Login Wallets in Oracle 26ai (cwallet.sso)
000
Christoph Lutz @christophlutz.bsky.social · 12/08/2026
www.0xchris.dev/posts/2026-0...
0xchris.dev
Deobfuscating Database Link Passwords in Oracle 26ai
Deobfuscating Database Link Passwords in Oracle 26ai
010
Christoph Lutz @christophlutz.bsky.social · 11/08/2026
The DBMS_CREDENTIAL.CREATE_CREDENTIAL procedure obfuscates passwords by encrypting them with a randomly generated AES-128 key. The encrypted password and its encryption key are then base64 encoded and stored in the data dictionary. Full details: t.ly/mp5bB
t.ly
Deobfuscating Oracle Credential Passwords
Deobfuscating Oracle Credentials Passwords (dbms_credential)
000
Christoph Lutz @christophlutz.bsky.social · 31/07/2026
Had a closer look at the implementation of the CURSORTRACE event... and encountered a few surprises: t.ly/jQG6B
t.ly
Understanding the CURSORTRACE Event
The Oracle library cache is extensively instrumented, but the instrumentation is disabled by default. It can be enabled using the CURSORTRACE event, which is particularly useful for investigating libr...
022
Christoph Lutz @christophlutz.bsky.social · 15/07/2026
Undocumented SYS_CONTEXT parameters: t.ly/822eR
t.ly
Undocumented SYS_CONTEXT Parameters
Undocumented SYS_CONTEXT Parameters
063
Christoph Lutz @christophlutz.bsky.social · 09/06/2026
Ever wondered how exactly Oracle scans child cursors? Going down the rabbit hole 👇 t.ly/5fYsi
t.ly
Child Cursor Scan Mechanics - An Investigation
Child Cursor Scan Mechanics - An Investigation
141
Christoph Lutz @christophlutz.bsky.social · 03/06/2026
A short note on how to identify restricted and undocumented oradebug commands. t.ly/QyOFx
t.ly
Restricted and Undocumented oradebug Commands
Restricted and Undocumented oradebug Commands
030
Christoph Lutz @christophlutz.bsky.social · 01/06/2026
The greatest DBA tool of all time is gdb - change my mind.
100
Christoph Lutz @christophlutz.bsky.social · 20/05/2026
t.ly/8A1p9
t.ly
Default Calculation of TARGET_PDBS
According to My Oracle Support note PALRT1151 (see also source 1) and various sources on the internet, Oracle uses the following formula to derive the default value of the target_pdbs parameter: targe...
010
Christoph Lutz @christophlutz.bsky.social · 19/05/2026
A little script and some background information on how to extract v$ definitions directly from the oracle binary. t.ly/NT6L7
t.ly
Extracting Fixed View Definitions From The Oracle Binary
Extracing Fixed View Definitions From The Oracle Binary
000
Reposted by Christoph Lutz
avelio.ch @avelio.ch · 13/05/2026
Avelio is live! 🚀 We are your Swiss partner for Oracle on‑premises database operations. Our mission: Optimised. Automated. Always Available. From proactive monitoring to 24/7 SLA‑backed support. Your business deserves reliability. Find out more: avelio.ch #Oracle #DatabaseManagement
094
Christoph Lutz @christophlutz.bsky.social · 07/05/2026
A closer look at how Oracle 26ai determines and caps the maximum granule size t.ly/MEKOU
t.ly
SGA Changes in Oracle 26ai - Maximum Granule Size
SGA Changes in Oracle 26ai - Maximum Granule Size
030
Christoph Lutz @christophlutz.bsky.social · 05/05/2026
t.ly/FFWYd
t.ly
SGA Changes in Oracle 26ai - Subpools and Durations
SGA changes in Oracle 26ai - subpools and durations
085
Christoph Lutz @christophlutz.bsky.social · 20/04/2026
1/2 Interesting and undocumented changes in SGA management in Oracle 26ai: - Up to 31 subpools in the shared pool (max seven in 19c defined by _kghdsidx_count) - Subpools are split into thee durations (there were only two in 19c)
162
Christoph Lutz @christophlutz.bsky.social · 14/04/2026
t.ly/iOYIx
t.ly
Bypassing oradebug Restrictions
Bypassing oradebug restrictions
020
Christoph Lutz @christophlutz.bsky.social · 18/03/2026
Pipelined or parallel? In Adaptive Scalable mode LGWR can assign redo writes to worker processes in different ways. More details in the post below 👇 t.ly/HJi5d
t.ly
Adaptive Scalable LGWR Pipelined vs Parallel Redo Writes
An earlier post explained the decision-making heuristics when LGWR transitions from single to scalable mode. Here, we examine how it handles redo writes in scalable mode with multiple LG worker proces...
011
Christoph Lutz @christophlutz.bsky.social · 04/03/2026
blog.tohojo.dk/2026/02/the-...
blog.tohojo.dk
The inner workings of TCP zero-copy
000
Christoph Lutz @christophlutz.bsky.social · 03/03/2026
When does lgwr transition from single to scalable mode? t.ly/Ohe7a
t.ly
Adaptive Scalable LGWR Mode Switch Threshold Single->Scalable
Oracle fundamentally reworked and redesigned the LGWR architecture in 12c. In earlier versions, LGWR ran as a single process, whereas Oracle 12c and later can dynamically switch between a single LGWR ...
023
Christoph Lutz @christophlutz.bsky.social · 13/02/2026
Everybody should get rid of tnsnames.ora and use Easy Connect instead. Change my mind.
030
Christoph Lutz @christophlutz.bsky.social · 10/02/2026
Just discovered this new blog series by @ludovico.bsky.social explaining Data Guard enhancements in 26ai - must read👇 www.ludovicocaldara.net/dba/dg-26ai-...
ludovicocaldara.net
Mini-blog series: Oracle Data Guard 26ai new features
Oracle AI Database 26ai is here for Linux x86_64—packed with new features for Data Guard! Stay tuned for quick blog posts on key changes.
051
Christoph Lutz @christophlutz.bsky.social · 12/01/2026
I felt like taking a closer look at this new datapatch feature and ended up making some interesting discoveries 🙂 t.ly/Tufob
t.ly
Datapatch And The "force_terminate_blocking_sessions" Option — A Look Behind The Scenes
If you’ve ever executed Datapatch on a busy system, chances are you’ve experienced intermittent delays or hangs, and in some situations maybe even errors such as ORA-4021 (“timeout occurred ...
171
Christoph Lutz @christophlutz.bsky.social · 14/12/2025
rovarma.com/articles/fro...
rovarma.com
From profiling to kernel patch: the journey to an eBPF performance fix | Ritesh Oedayrajsingh Varma
A story about how an innocent profiling session led to a change to the Linux kernel that makes eBPF map-in-map updates much faster.
000
Christoph Lutz @christophlutz.bsky.social · 10/12/2025
Woot! By a happy twist of fate, a ticket for the 39th Chaos Communication Congress came may way ... 😀 See you in Hamburg! @ccc.de Thanks @krischan.bsky.social!
120
Christoph Lutz @christophlutz.bsky.social · 28/11/2025
justoffbyone.com/posts/math-o...
justoffbyone.com
The Math of Why You Can't Focus at Work
Interruptions, recovery time, and task size: three numbers that determine if you'll get real work done. Interactive visualizations show the math behind bad days.
100
Christoph Lutz @christophlutz.bsky.social · 23/11/2025
#POUG2026 dress code 😜 www.galaxus.ch/en/page/woul... @pougorg.bsky.social
180
Christoph Lutz @christophlutz.bsky.social · 05/11/2025
1/11 Everything changes... turns out the age-old rule that lgwr writes out the log buffer when it's 1/3 full no longer applies in recent Oracle versions. Observations below from 19.26 (with RAC on Exadata). 👇
120
Christoph Lutz @christophlutz.bsky.social · 31/10/2025
Week end fun: snooping inter-process messaging (ksbasend) in Oracle with bpftrace. 🤓 t.ly/_yDy7
020
Christoph Lutz @christophlutz.bsky.social · 20/10/2025
thehackernews.com/2025/10/link...
thehackernews.com
LinkPro Linux Rootkit Uses eBPF to Hide and Activates via Magic TCP Packets
Synacktiv uncovered LinkPro, a Golang rootkit using eBPF hide/knock modules activated by TCP window 54321.
000
Christoph Lutz @christophlutz.bsky.social · 16/10/2025
This, so much! 👇
030
Christoph Lutz @christophlutz.bsky.social · 11/10/2025
www.deep-kondah.com/deep-dive-in...
deep-kondah.com
Unraveling eBPF Ring Buffers
The goal of this post is to provide an in-depth discussion of BPF ring buffers, covering their internals, including memory allocation, user-space mapping, locking mechanisms, and efficient data sharin...
010
Christoph Lutz @christophlutz.bsky.social · 05/10/2025
When you plan to geek out over some oracle internals, but end up ftrace’ing bpf the entire week end to chase a funny bug that only occurs on exadata with capacity on demand ...
010
Reposted by Christoph Lutz
Jonathan Lewis @jloracle.bsky.social · 28/09/2025
There's a problem on the oracle-l listserver at present about an insert taking far too much time (and CPU). It's a known issue and there are 47 statistics in v$sysstat (19.11) with names like 'ASSM%' to help diagnose it. How many do you think are described in the database reference manual? None.
041
Christoph Lutz @christophlutz.bsky.social · 21/09/2025
Yet another adaptive lgwr optimization: on Exadata X10+, pipelined log writes may defer redo writes until a suitably sized write batch has accumulated in the log buffer. The deferral can involve spinning in a tight loop up to 25 times (maximum hard-coded in kcrfw_defer_write).
120
Christoph Lutz @christophlutz.bsky.social · 18/09/2025
Nested loops, baby 😜
010
Christoph Lutz @christophlutz.bsky.social · 13/09/2025
050
Reposted by Christoph Lutz
Swiss Oracle User Group @soug.ch · 10/09/2025
In den nächsten Tagen veröffentlichen wir nicht nur die Agenda, sondern am Tag nach dem SOUG Day planen wir noch ein Special für Euch! Schaut rein und meldet Euch an unter soug.ch.
SOUGDay 2025 Zürich - Anmeldung unter soug.ch möglich
033
Christoph Lutz @christophlutz.bsky.social · 04/09/2025
So glad that all new features are documented so well... NOT 😜 Manually enabling and disabling adaptive lgwr evaluation trace for pipelined / overlapped redo writes:
000
Christoph Lutz @christophlutz.bsky.social · 03/09/2025
POUG journey started… not even at the airport and lufthansa’s delay notification leaves no hope of making the connecting flight in MUC 🙈
030
Christoph Lutz @christophlutz.bsky.social · 31/08/2025
So 23ai replaces ksesecl0(func, loc, err) with kseseclv(err, func, loc, ...) ... Why is it always just a few days before POUG that this kind of low-level discoveries surface? 🙄
230
Reposted by Christoph Lutz
Tanel Poder @tanelpoder.com · 13/08/2025
A new tool in 0x.tools family: xtop - Top for Wall-Clock Time. It uses eBPF/xcapture v3 and gives you "x-ray vision" into Linux system activity. It will be available on next Tuesday 19 Aug at 1pm EDT when I also run a live demo webinar! tanelpoder.com/posts/xtop-t...
1199
Christoph Lutz @christophlutz.bsky.social · 12/08/2025
"Slide n of 142".. this is getting out of control... 🙈
010
Christoph Lutz @christophlutz.bsky.social · 06/08/2025
Today's discovery (19.26): Oracle derives different log parallelism defaults, depending on platform. Max number of public redo strands is: Exadata: CPU_COUNT <= 256: 16 CPU_COUNT> 256: CPU_COUNT/16 Non-Exadata: CPU_COUNT <= 32: 2 CPU_COUNT > 32: CPU_COUNT/16 Max limit: 256
000
Christoph Lutz @christophlutz.bsky.social · 05/08/2025
Oh my, looks like the "ms" in "kso_sched_delay_avg_ms" actually means "microseconds" ... 🤷‍♂️
130
Christoph Lutz @christophlutz.bsky.social · 04/08/2025
1/6 The "redo synch time overhead" in Oracle is the difference between a FG's log file sync (LFS) wait end time and LGWR's redo write completion time. LGWR and LG workers track the redo write completion times in the "write info array" in the SGA.
100
Christoph Lutz @christophlutz.bsky.social · 03/08/2025
lgwr: You have the control gdb: I have the control
000