Three measurements of the same thing, in the order they were made. On Tuesday, on an Intel i5-13500, a Linux that nobody had told what processor it was running on, because bhyve had not passed the word along, took 816 nanoseconds for a system call and defended against everything on the way. FreeBSD on the same chip answered the same call in 52, and nothing tried on it since, on that machine or the next, has moved its figure by more than two nanoseconds. Yesterday, on one AMD machine with two drives and nothing tuned on either side, FreeBSD answered in 49.9 and Debian 13 with the Linux 6.12 kernel in 143.9, booted from the drive beside it and told everything. This morning, with lmbench, which warms the cache for a second and takes the median of 101 batches, the system call read 51.7 against 160.9, and a token handed to a second process and back read 2.18 microseconds against 5.41. The effective clock, read by lmbench's own mhz, was 4198 MHz on both. Linux moved between 144 and 816 depending on what it had been told about the silicon. FreeBSD did not move.
Two days ago the first of those three was asked to come down.
It had gone up on Tuesday with three columns, one of them a Linux guest under bhyve, and the essay beneath it said in a section called The Limit that the three columns were not a fair race and that the Linux figure needed a run on bare metal before anybody quoted it as a figure for the Linux kernel. The first comment suggested I pull the slide and start over. The second called it fake news. A third proposed, with considerable care, a protocol for an experiment about something else. Between them they had read the headline and the teaser; one had got as far as the picture. All three spoke with the settled confidence of people who have reviewed a thing.
I want to take that confidence seriously, because it is the interesting part. The numbers turned out to be the easy part.
What was asked, and what had been read
The first request was for a control: the same kernel on the same hardware without a hypervisor in the way, or else the slide should go. It is a reasonable request. It is also, almost word for word, the request the essay made of itself three paragraphs from the end, in the section whose whole purpose is to say where the measurement stops. A reader who had reached that section would have found the control already on the list. A reader who had not would find it in the comments, which is where he put it.
The second contribution was a label. Fake news is eight letters, and the eight letters do a surprising amount of work: they move the argument from the measurement to the motive, and a motive cannot be rerun. A label of that kind never arrives with a number attached, because a number would make it a claim, and a claim can be checked.
The third was a protocol, and a good one: lmbench, a one-second warm-up, 101 batches, a pinned core, the SMT sibling idle, three boots a side. Its author had read the first paragraph, which mentions Tanenbaum and Torvalds, and from it had reconstructed a different essay, one about microkernels, for which his protocol would have been exactly right. He proposed L4Linux against native Linux. The piece compared FreeBSD with Linux. Same instruments, different question; and the instruments, as it happens, are the ones the essay was already using, since lat_syscall null is getppid and lat_pipe is a round trip between two processes.
One objection in the whole thread came from reading, and it was right. A sentence in the essay attached a 1997 figure from Dresden to QNX, and the figure belongs to L4Linux. The reader who found it had opened the text and followed a citation. It was corrected the same morning, and it stands corrected in the article. That is what reading does. It finds the error that is actually there.
The jail they suspected
The FreeBSD column on Tuesday had been measured inside a jail, and one reader took that as the catch. From the Linux side of the fence it is an understandable reading. A container there is an assembly: namespaces for what the process may see, control groups for what it may consume, a daemon to manage the assembly, an image format and a registry to feed it, and each of those pieces has a cost, small but countable, and a project of its own.
A jail is a different animal, and an older one. It arrived in FreeBSD 4.0 on 14 March 2000, from Poul-Henning Kamp, with the paper he wrote with Robert Watson that year explaining what it was for: confining the omnipotent root. There is one kernel. The jail is a filter the kernel applies to a process tree: what it may see of the file system, which addresses it may bind, which sysctls it may touch, whether its root is really root. No second kernel, no daemon, no registry, no image format. The image is a ZFS clone of the base system and occupies no space until it differs. The configuration is one file, and the one on the machine that produced Tuesday's number runs to seventeen lines.
What a jail does to a system call is therefore nothing at all, because the call never reaches the part of the kernel that knows the jail exists. getppid reads a field in the process structure and returns. It does not consult the prison. I measured it this morning anyway, because a sentence like that one deserves a number beside it: the same lmbench binary, pinned to the same core, gives 51.0 nanoseconds inside a jail and 51.3 on the host, and the pipe round trip 2.16 microseconds against 2.18, which is the noise.
The advantage over the heavy answer, the one that became the industry's default, is the part worth dwelling on. The heavy answer to isolation is a virtual machine: a second kernel, booted, scheduled, patched, and paying for its own page tables, so that one tenant cannot see another. It works, and it costs a kernel per tenant. The jail gives the isolation that most workloads actually need, process, file system, network and privilege, from the kernel already running, and it starts as fast as the service inside it. Podman, to be fair to the other side, took the daemon out of the Linux container and was right to; what remains underneath is still the assembled set, maintained by separate projects, which is where the seams come from. A jail has no seams to maintain, because one group wrote the whole of it into one kernel and has kept it there for twenty-six years.
The hypervisor they blamed
The 816 nanoseconds in the Linux column were blamed on bhyve, and that too is the natural reading from the Linux side, where virtualisation is where the taxes live. bhyve has been in the FreeBSD base system since 10.0, January 2014. It drives the processor's virtualisation extensions directly, and under those extensions a system call does not leave the guest. The syscall instruction never causes an exit: the guest kernel handles it entirely inside its own address space, and the hypervisor is never told it happened. Whatever the guest spends on entry, it spends on itself.
What the guest spent, the essay had explained. It had not been passed the register, IA32_ARCH_CAPABILITIES, that tells a kernel the silicon is immune to Meltdown and MDS, so it did the correct and expensive thing and turned on page table isolation and buffer clearing, on the exact path the benchmark walked. That is a kernel deciding what it owes a processor on incomplete information. The bare-metal rerun then showed the same decision made with complete information: same box, both kernels told everything, and Linux still paid ninety nanoseconds a call for a set of countermeasures (STIBP always on, Safe RET, the untrained return thunk, RSB filling) that FreeBSD on the same chip declines to apply. Declines is the word. Set hw.ibrs_disable to 0 and hw.ibrs_active stays at 0, because that kernel holds those measures inapplicable to that processor. The hypervisor was never in the path. The reader who blamed it had not asked how a system call leaves a guest. He had assumed that it must, which is what the Linux experience of virtualisation teaches, and which is why the question was worth measuring in the first place.
The measurement, done their way
So I did it their way, all of it, on the one spare box I had: an AMD Ryzen 5 3600 with two NVMe drives, FreeBSD 15.0 on one and Debian 13 on the other, switched by rewriting the boot code in the protective MBR of whichever disk was to stay quiet (most of an afternoon went on a boot loader that wanted a keypress nobody was there to give, which is the kind of detail that never makes the slide).
The control first, with the critic's own programme, unchanged: 49.9 against 143.9. A variant that leaves the C library out and issues the syscall instruction from inline assembly, identical machine code on both sides: 48.9 against 135.1, so the compiler and libc are out of it. Linux with mitigations=off, which nobody runs and which I ran once to see what the gap is made of: 53.8. The gap is made of countermeasures.
Then the protocol, as proposed: lmbench from one tarball, built with clang 19.1.7 on each side, pinned to one core, a second of warm-up and 101 batches, three runs a side. 51.7 against 160.9 for the system call, 2.18 against 5.41 microseconds for the pipe. Spread under one per cent. SMT switched off on Linux: 160.7 and 5.45, which is to say no change. A second FreeBSD boot: 51.0 to 51.3, inside the first. The box is AMD and the request was for Intel, and I had no spare Intel standing about; the piece argues an order, and an order that holds on a second architecture is a stronger thing than a decimal on the first.
$ cpuset -l 2 ./lat_syscall -W 1000000 -N 101 null
Simple syscall: 0.0517 microseconds
$ cpuset -l 2 ./lat_pipe -W 1000000 -N 101
Pipe latency: 2.1807 microseconds
# taskset -c 2 ./lat_syscall -W 1000000 -N 101 null
Simple syscall: 0.1609 microseconds
# taskset -c 2 ./lat_pipe -W 1000000 -N 101
Pipe latency: 5.4253 microseconds
Four more measurements, two of them designed by the people who objected, and the same order every time, by a factor of three on the call and two and a half on the pipe. Nothing moved.
Authority without the object
Which leaves the confidence, and the confidence is the philosophical part.
A review is a claim about an object; without the object it is a claim about the reviewer.
John Stuart Mill put the working rule down in 1859, in the chapter of On Liberty about the liberty of discussion: "He who knows only his own side of the case, knows little of that. His reasons may be good, and no one may have been able to refute them. But if he is equally unable to refute the reasons on the opposite side; if he does not so much as know what they are, he has no ground for preferring either opinion." The debating societies kept the rule as a procedure: you restate the other side's case to its satisfaction before you are allowed to attack it. The comment thread has no such procedure, and the figures on how it behaves without one are not flattering.
In 2016 a group at Columbia and Inria followed 2.8 million shares of articles from five news sites on Twitter for a month and matched them against the clicks. Fifty-nine per cent of the shared links were never clicked at all, which is the paper's own word for it. (The press reported it as sharing without reading, which the paper does not say; the finding is quieter and worse: for most links the teaser was the entire text anyone saw.) Twitter itself, in 2020, tried a small fence: a prompt saying headlines do not tell the full story, shown before a retweet of an unopened article. Article opens before sharing rose by forty per cent, which tells you the previous number.
Those are the readers. The reviewers are a different population, and for them the finding I would put on the slide is Dan Kahan's. In 2017 his group gave 1,111 adults the same two-by-two table twice, once as the result of a skin cream trial and once as the result of a gun control measure. On the skin cream, numeracy helped: the better you were with numbers, the more often you read the table right. On the gun control measure, numeracy made it worse: the more numerate the subject, the further his reading of the identical table moved towards his side. Skill with numbers was being spent, selectively, on reaching the conclusion the reader had brought with him; motivated numeracy, he called it.
I cannot think of a better description of what happened to the Linux column. Nobody contested the FreeBSD column. Nobody contested the macOS column. The objections came for the one number that touched an identity, and they came from people who can read a table.
Why it should work that way is the oldest result in the field. Leon Festinger described it in 1957: hold a belief, meet a fact that contradicts it, and the discomfort has to go somewhere. Changing the belief is the expensive exit. The cheap exits are to doubt the fact, to doubt the person who brought it, or to find other people who doubt it with you, and a comment thread offers all three within arm's reach. "Disingenuous" and "fake" are the second exit in a single word. "As others have commented" is the third.
The belief in question is a group membership, which is what makes the cure so cheap. Henri Tajfel showed in 1971 that people will favour their own side over a group assigned by a coin toss, with nothing at stake and nobody to impress; a kernel is a good deal more than a coin toss. It is the thing a person has run, defended and been paid for over twenty years. The uncomfortable corollary came from Kahan's group in 2012, in a paper on climate risk that transfers without modification: the more scientifically literate and numerate the subjects, the further apart the two cultural camps stood. Education did not close the gap. It gave each side better tools for holding its own end of it. The IT world is as educated a public as exists, and I would not expect it to be less exposed on that account; in my experience it is rather more so, and it does seem to have grown over the years, though that last part is an impression and I hold it as one.
And the reading itself has been measured, which is where the cover comes in. Jakob Nielsen's group instrumented browsers in 2008 and found that a visitor has time for at most 28 per cent of the words on an ordinary page, and more usually a fifth. A piece of three thousand words loses most of its visitors somewhere in the second paragraph. What they take away is the headline, the picture and whatever number sat on it, and that is the material the review is then written from.
So a thread like this one is three mechanisms stacked: a number that threatens an identity, a reader who had seen the cover and the first lines, and a medium that rewards the shortest reply. None of the three needs a villain. All three need an object that nobody opened.
The third piece of the picture is older. Leonid Rozenblit and Frank Keil found in 2002 that people rate their understanding of how things work far above what they can produce when asked to write the mechanism down, an illusion of explanatory depth, and Philip Fernbach and colleagues showed in 2013 that asking people to explain the mechanism moderates the view, while asking them for their reasons leaves it where it was. "A jail is a container" and "a hypervisor taxes a system call" are mechanisms nobody in the thread was asked to explain before ruling on them. Asked, they would have had to open the text, where the mechanism was.
And then the arithmetic, which is the part I find hardest to forgive the medium for. A counter-proof cost two drives, a boot loader, several reboots, two protocols and the better part of a day. A label cost two words. The thread pays the two words in reach, because the label is short and sure, and the proof is long and has decimals in it. Anyone is free to bring a counter-measurement. Almost nobody does, because it is expensive, and the cheaper moves (the dislike, the reframe to fake and clickbait) are available at no cost to anyone who has read the headline. Neither is worth a serious debate's attention, and both get it, because the debate is scored by the people who stopped at the cover.
The readers and the analysts in the thread asked for a method and got a run. The excited asked for the slide.
The strongest objection
Three objections to all of the above, and the first one lands.
The teaser is a claim on its own. A table with 816 in it travels without the section that qualifies it, and the reviewer of the teaser was reviewing what most readers would ever see. Ullrich Ecker, Stephan Lewandowsky and colleagues showed in 2014 that a misleading headline shapes memory and inference even after the body corrects it; the body does not get a vote with readers who never reach it. I accept that in full. The post now carries a hint pointing at The Limit, and the process that produced the post has a rule it did not have on Monday: every limitation in the essay appears in the teaser, at least in a sentence.
Triage at the cover is rational. Nobody can read every essay, an expert's time is finite, and the cover is the contract an author offers. If the cover carries the claim, it carries the objection, and I drew the cover.
And the bill Linux pays buys something. On the Tuesday the table went up, researchers at VUSec and Sant'Anna lifted the embargo on Branch Target Reuse, a Spectre-v2 variant that pulls a root password hash out of a fully patched Intel machine, with its default protections on, in minutes, through stale predictor state left behind by a JIT. The Linux patches for CVE-2026-64507 and CVE-2026-64508 were merged the same week. A kernel that assumes the worst about a branch predictor is not being silly. FreeBSD's refusal to carry the expensive set on this particular Zen 2 part is a judgement, judgements can be wrong, and that is why the number is published with the sysctl beside it, so that whoever disagrees can read the judgement off the running system.
The limit
Five things, and the first is the one I would raise myself.
One thread is one thread. Three comments are an anecdote about three people on one afternoon, and the studies above describe populations, which is why they are there.
What each critic had read is my inference from what he wrote. A man who proposes the control the essay already lists has, on the balance of probability, not reached that list; it remains a probability.
The crowd found the one real error, and the corridor did not. Reading from the comments has a hit rate above zero, and the essay is better for it.
The rerun is AMD and the piece was Intel; two FreeBSD boots and one Linux boot stand where the protocol asked for three; the jail figure is a single run.
And I am not a neutral party to any of it. I measured and published, and I am the one explaining why the critics were wrong, which is the position in the room least entitled to the benefit of the doubt. That is what the numbers are for.
The point
The number went up on Tuesday. It has since been measured by the critic's programme, by the analyst's protocol, in the configuration nobody runs, and on a second architecture that shares nothing with the first, and the order has not moved. What moved was the reviewing, from the text to the cover, which is a shorter walk and tells you less about the text.
The slide stays.
A Linux guest told nothing about its chip took 816 ns a call; on bare metal, told everything, 144. FreeBSD took about 50 on both boxes, in a jail and out of it. Three people asked for the number to come down, having read the headline and the teaser; measured four more ways since, by their programme and their protocol, the order has not moved. A review is a claim about an object; without the object it is a claim about the reviewer.