HN user

alsadi

148 karma
Posts14
Comments95
View on HN

Many things have changed since the old days. In PEP 3333 sendfile is exposed as opposed to PEP 333 (so in the WSGI days they had no way of doing it, but in ASGI they can do it).

The assumption that nginx is always there no longer hold, specially in microservices, ex. Running behind haproxy (does not service static files) or running bechind cloud provides like AWS ALB.

As I pointed out in my other comment, serving a static file should be a single call to a kernel routine called sendfile (sendfile in c or in python io.sendfile or loop.sendfile). No loop, no memory copy, no further context switch.

Again if you think I was not fair to fastapi, suggest a change to the fastapi part. Do not cripple the competing solution.

If you want believe the time is wasted by the introduction of uvicorn layer as opposed to pure python implementation, I can run the fastapi in pure python ASGI without that layer, it would be worse. Because you uvicorn is one of the best implements.

I made it like that to be as fair as possible and as simple as possible. I've done other experiments with same results. If you think I was not fair to the fastapi part feel free to edit the fastapi part in the form of github gist. And give me the link.

I do agree. When I first see it I knew that. Comparing two sequences (actual dom and dom) to find diff is like O(n^2) and the assumption that dom ops is expensive is a lie (premature optimization). Dom ops on ids and classes and fragments is very fast. In most cases a slow dom is always a developer fault failing to use fragments.

Kazakhstan forces their citizens to install government-issued certificate to use SSL.

So why debian/ubuntu vulnteer to remove this layer? Why doing the equivalent of installing random certs for every gov/isp on every user?

Yes, government can force someone to install it, but it won't use force on every single person.

Those arguments are invalid. Because debian/ubuntu fail to use https regimes like egypt/syria can track people who try install tor and they can cherry-pick block repos based on package name.

I'm sorry for not liking your favorite color and distro. Please deal with it.

And btw they don't digitally sign their package too (they sign separated meta data file having checksum which is not equivalent of embeding signature inside the package and validate it).

Compare that to yum/rpm which use secure https and signed rpm and signed metadata (both the medium and the payload are secured)

The logo on the right is the arabic letters of the word Algorithmi (al-Khwarizmi) the persian muslim scholar after him algorithms and logarithms were named

Many comments mistaken redhat as an OS company? They are not. IBM did not buy redhat to get RHEL.

They bought it for the hybrid cloud as clearly stated.

Redhat has openstack platform, cloud formation/manage iq, openshift, ansible, ceph, glusterfs, codeenvy (behind eclipse che),... Etc