3 ms·
This change is a sign of Node's shift from improving the core to making modules work better. I see it that way, at least. Isaac is the author of npm after all.
by rhdoenges 15y ago
This change is a sign of Node's shift from improving the core to making modules work better. I see it that way, at least. Isaac is the author of npm after all.
- baudehlo 15y agoUnfortunately the core is missing some significant features, whereas modules work pretty well already (though I can see room for doing pre-compiled binary modules like "PPM" does for Perl on Windows).
- Animus7 15y agoHonest question: have you actually tried working with modules and dependencies in Node? It's better now, but it's still not pleasant and often installing a module starts with debugging. And what's the core missing, would you say? Personally, I thought the cluster stuff was already getting heavy.
- baudehlo 15y ago> Honest question: have you actually tried working with modules and dependencies in Node? It's better now, but it's still not pleasant and often installing a module starts with debugging. Yes. And you're right, but then it's not often that much better than other languages. Personally I'd rather they get the core language finished first (though their concept of "finished" and mine seem to differ). > And what's the core missing, would you say? Personally, I thought the cluster stuff was already getting heavy. There's no way to lock a file (making file writes completely fragile). There's no way to seek() in a file. There's no way to open a file with O_EXCL set (meaning lockless file writing is impossible). There's no temp file functionality in core, and without O_EXCL the solutions available for this on npm are utterly broken. There's still major bugs in the Crypto routines (they take Strings instead of Buffers in various places)... Honestly I could go on.
- IsaacSchlueter 15y agoYou can open a file with O_EXCL if you pass in the open flags as a number. (You can find them on require("constants"), and they need to be binary-OR'ed together.) This isn't documented. It should be. It should probably also be exposed in a cleaner way. Most of the rest of what you describe is APIs that need to be polished and refined a bit. The boundaries are well defined at this point, though. We probably won't add another builtin module at this point, or dramatically expand what any of them can do. (I don't consider seek() dramatic, it's just tricky to get right given JavaScript's annoying Number problems.)
- baudehlo 15y ago> You can open a file with O_EXCL if you pass in the open flags as a number. (You can find them on require("constants"), and they need to be binary-OR'ed together.) This isn't documented. It should be. It should probably also be exposed in a cleaner way. That's great to know. Obviously I'm just following the docs. > Most of the rest of what you describe is APIs that need to be polished and refined a bit My concern is merely that there have been a number of statements put out saying "we won't be adding anything more to the API", and that we are basically almost at 1.0, at which point there won't ever be anything added to the core API. Lack of flock() is huge (you can't write to an existing file safely without it - and Node developers are doing that all the time, including your own NPM). Lack of an ability to create temporary files safely seems a fundamental weakness - especially when so many Node apps are dealing with file uploads - that's a disaster waiting to happen. We are going to be dealing with Node.js security bugs because of these issues for a VERY long time.
- IsaacSchlueter 15y agoO_EXCL is in for 0.8: https://github.com/bnoordhuis/node/compare/O_EXCL https://github.com/bnoordhuis/node/compare/O_EXCL flock() is not trivial to do in a portable way. For a unix-only flock(), check out the fs-ext addon. Same for mktemp. I wouldn't be opposed to either being in core if it could be done in a clean way, but this is just adding another knob that can be done with an addon easily enough. If you care more about having flock() than about writing portable programs, then that's what the fs-ext addon is for. > We are going to be dealing with Node.js security bugs because of these issues for a VERY long time. Of course we'll be "dealing with Node.js security bugs for a VERY long time", because we'll be using Node.js for a very long time. Software is buggy, and many bugs are security hazards. We'll be dealing with "Unix security bugs" and "C security bugs" and "Java security bugs" forever as well. Please do not make vague suggestions about security issues. Either you've found an issue, and should be submitting it, or you haven't, and are just spreading fud.
- baudehlo 15y agoDownvotes, really? I don't hate on Node - I develop a very popular open source server in it. But it has some fundamental weaknesses in terms of how finished it is, and most of the core developers don't think those missing things need adding before calling it 1.0 and the API gets set in stone.