Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
_carljm
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
31.
▲
by
_carljm
5y ago
There are now benchmark comparisons with stock CPython in a PERF file in the repo.
32.
▲
by
_carljm
5y ago
Thank you, that’s very kind of you both. To be clear, this is the work of a team, and many others have contributed a lot more than I have to it.
33.
▲
by
_carljm
5y ago
Definitely influenced. There are people on our team who also worked on hhvm.
34.
▲
by
_carljm
5y ago
Haven't tried Pyston, its revival as an active project happened well after Cinder was in production.
35.
▲
by
_carljm
5y ago
We've already upstreamed a lot of changes, including one that makes all coroutines faster in Python 3.10. The big-ticket items in Cinder would be big changes for CPython and need discussion about whether CPython even wants them. You do
36.
▲
by
_carljm
5y ago
There'll be a talk on Cinder at (virtual) PyCon in a couple weeks, there are detailed benchmark numbers in the talk. We've talked about getting them into the repo too, might happen.
37.
▲
by
_carljm
5y ago
We tried PyPy without much success (and we really tried, six month project just to get it to run our codebase.) Our workload is very heavy on the CPython C API, which makes life difficult for PyPy or any other alternative Python implementat
38.
▲
by
_carljm
13y ago
In Python 3, that raises a TypeError.
39.
▲
by
_carljm
14y ago
The advisory and release notes are now fixed to not describe the XML vulnerabilities as DoS.
40.
▲
by
_carljm
14y ago
AFAIK the XML entity expansion attacks are DoS-only, but the other fixed vulnerability (external entities) may be usable in some cases to gain information about local files (again, presuming Django's XML model deserializer is exposed to unt
41.
▲
by
_carljm
14y ago
You're right, thanks for pointing this out. Although (as jacobian mentions) Django's exposure in general to these attacks was quite limited, we still shouldn't describe these XML vulnerabilities as DoS-only. I'm working on updates to the re
42.
▲
by
_carljm
14y ago
The vulnerability we fixed is not just entity expansion, it's also accessing external entities. Although this is a DoS vector, I think it's true that it could be used to gain information about the presence or absence of files on the local f
43.
▲
by
_carljm
14y ago
It's not just billion laughs, this fixes related but different entity-expansion attacks, as well as fetching of external resources (DTDs or entity definitions), which is a totally separate issue from billion laughs.