3 ms·
For some definition of "serious" I think the gains from a readable implementation in your working language far outweigh performance or correctness concerns. To
by jrandm 7y ago
For some definition of "serious" I think the gains from a readable implementation in your working language far outweigh performance or correctness concerns.
To put it another way, I'm rarely parsing data for it to be directly optimized into a machine language. I'm parsing data to extract parts I care about and then work with those parts. The more consistent this process is the easier it is to debug and fix. If my whole parsing/using-the-parsed-data pipeline is in the same language, say Javascript, then I am still only ever debugging the same language and runtime environment (eg: node v12 on whatever \*nix).
In a practical example, YARA[0] is (confusingly) used as both a format[1] and specific implementation[2] for sharing malware detection rules. ClamAV[3] is a popular open source antivirus engine that added YARA-the-format support a few years ago[4]. If you look at their grammar[5] file as well, you can see that one uses GNU Bison 3.0.4 the other uses 3.0.5. One is 3754 lines long, the other is 1849. We can expect these to behave differently. At a certain point, say because of how regular expressions are handled[6], it becomes easier to maintain your own parser than to deal with quirks/whims of someone else's implementation (generated or not).
[0]: https://en.wikipedia.org/wiki/YARA https://en.wikipedia.org/wiki/YARA
[1]: https://yara.readthedocs.io/en/latest/writingrules.html https://yara.readthedocs.io/en/latest/writingrules.html
[2]: https://github.com/VirusTotal/yara/blob/master/libyara/hex_grammar.c https://github.com/VirusTotal/yara/blob/master/libyara/hex_g...
[3]: https://www.clamav.net https://www.clamav.net
[4]: https://blog.clamav.net/2015/06/clamav-099b-meets-yara.html https://blog.clamav.net/2015/06/clamav-099b-meets-yara.html
[5]: https://github.com/Cisco-Talos/clamav-devel/blob/898c08f08b5bc6acfa00d1d1f8950779b2545add/libclamav/yara_grammar.c https://github.com/Cisco-Talos/clamav-devel/blob/898c08f08b5...
[6]: "In previous versions of YARA, external libraries like PCRE and RE2 were used to perform regular expression matching, but starting with version 2.0 YARA uses its own regular expression engine. This new engine implements most features found in PCRE, except a few of them" from https://yara.readthedocs.io/en/latest/writingrules.html#regular-expressions https://yara.readthedocs.io/en/latest/writingrules.html#regu... ; if the regular expression grammar and/or symbol set isn't consistent the things parsing the files won't necessarily be either