4 ms·
It's cool that he got so much press in such a short time, but applauding technology choices that allowed him to sustain 8 requests per second (assuming this was
by getsat 14y ago
It's cool that he got so much press in such a short time, but applauding technology choices that allowed him to sustain 8 requests per second (assuming this was over a 12 hour period) is ridiculous.
- redslazer 14y agoI really doubt that these 350k hits were spread neatly over 12 hours.They most likely came as one giant rush. The author would have to confirm. Considering that lots of peoples blogs die because they get 10k visitors from HN. His small $15 vps did fine.
- nodesocket 14y agoThe PHP script is super simple, so lighttpd (which is a great web server, in the same performance realm of nginx) and php-fpm on a shared VPS, is plenty of power and resources. Never seen $found = `grep $udid FILE` using back-ticks in PHP land. Is that the same as the exec() function?
- bbunix 14y agoeffectively the same, more like a system() call... impressively ugly I must say.
- Osiris 14y agoI've seen this used in a PHP git class to call git and capture the results. (Obviously) Just make sure you're not including any user input data in any variables you put in there.
- thwarted 14y agoIt's also grossly insecure unless you sanitize $udid, which thankfully the author of this script does. It's still relatively unsafe, as it invokes external programs through a shell, so you're dependent on the shell's environment, which can diverge on different systems. Last I checked, PHP did not have an easy, obvious way to safely invoke another program. You can do it manually with a mix of pcntl_fork and pcntl_exec, but capturing the output using that is more difficult.
- fooyc 14y agoPHP provides escapeshellcmd / escapeshellarg functions for escaping when building commands. Is there any shell on which those functions are unsafe ? I think they assume cmd.exe on windows and sh on others.
- thwarted 14y agoEscaping is difficult to get right, especially in PHP... witness things like magic quotes that existed for so long. The right thing to do is provide an output capturing API that does not require escaping because it takes a list of strings passed to the exec(2) system call.
- diego 14y agoAll those blogs die because people don't bother to use WP Super Cache or the equivalent. Just for comparison, in 1998/99 I ran an mp3 search engine that handled 200k daily queries at the peak. It was a Pentium with 128MB of memory. The search server was written in C, and it used an inverted index. The system load rarely went over 1.
- nodesocket 14y agoDoesn't IndexTank still run on that Pentium with 128MB of memory? I kid. :)
- nmridul 14y agoYou missed the real catch that he mentioned towards the end - Quoting from the article - "The lesson is really simple. Make it work, put it out. You can make it pretty later, maybe."