Re: Re: [PEPr] +1 for XML::XML_Feed_Parser
| From: | Justin Patrin | Date: | Mon, 24 Oct 2005 18:11:50 +0000 |
| Subject: | Re: Re: [PEPr] +1 for XML::XML_Feed_Parser | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-40278@lists.php.net to get a copy of this message | ||
On 10/24/05, Sergio Carvalho <sergio.carvalho@portugalmail.com> wrote:
> Justin Patrin wrote:
> > I didn't say it was a huge difference. The difference between $a++ and
> > ++$a is also not that big, but it makes a difference. Add up all the
> > little tricks and you can get significant speedups. At least I have
> > shown, for all to see, that what I've been saying is true (although I
> > shouldn't have had to since other well-known developers also vouched
> > for this and you should have been able to test it yourself as well).
>
> Premature optimization is the root of all evil. Don't collect tricks for
> optimization. Design correctly, write readable code, and profile.
> Optimize on hotspots only. And never, ever, fret about optimization
> tricks. You'll put people on a defensive stance.
I understand. I was asked to prove my point, though, and I did. This
maxim only partially applies here anyway. Premature optimization is
mostly evil when it make syour code more complex and/or harder to
read/maintain. In the case of whether or not you use ' or " or where
you put your ++ that's more just good practice. But I digress. The
speedup isn't my major point.
>
> > And you're still ignoring that concatenation is easier to audit. *All*
> > syntax highlighters will highlight concatenation. Only some highlight
> > in-string vars correctly. Besides that, it's also simpler to be able
> > to skip over single quoted vars when looking for things like XSS or
> > SQL injection attacks. It also means that there are no special chars
> > in the string to watch out for.
>
> Here is your strong point. Readability, and thus ease of auditing, is a
> major point to go for. You'd easily win this argument if you dropped the
> performance point and aimed at readability.
>
Yes, readability and auditability are the better reasons for this.
> > Using " is also more error-prone when dealing with complicated vars
> > (and it can't be used for *really* complicated ones). On top of this
> > it tends to promote bad array syntax ($arr[key] instead of
> > $arr['key']).
> >
> > For all of these reasons (and probably some I'm missing) ' should be
> > preferred over ".
>
> A good list of security and readability reasons could probably go in the
> coding guidelines as a recomendation, no?
>
Yes, that would be good.
--
Justin Patrin