Re: Re: [PEPr] +1 for XML::XML_Feed_Parser

From: Date: Mon, 24 Oct 2005 18:11:50 +0000
Subject: Re: Re: [PEPr] +1 for XML::XML_Feed_Parser
References: 1 2 3 4 5 6 7 8 9 10  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-40278@lists.php.net to get a copy of this message
On 10/24/05, Sergio Carvalho <sergio.carvalho@portugalmail.com> wrote: > Justin Patrin wrote: > > I didn't say it was a huge difference. The difference between $a++ and > > ++$a is also not that big, but it makes a difference. Add up all the > > little tricks and you can get significant speedups. At least I have > > shown, for all to see, that what I've been saying is true (although I > > shouldn't have had to since other well-known developers also vouched > > for this and you should have been able to test it yourself as well). > > Premature optimization is the root of all evil. Don't collect tricks for > optimization. Design correctly, write readable code, and profile. > Optimize on hotspots only. And never, ever, fret about optimization > tricks. You'll put people on a defensive stance. I understand. I was asked to prove my point, though, and I did. This maxim only partially applies here anyway. Premature optimization is mostly evil when it make syour code more complex and/or harder to read/maintain. In the case of whether or not you use ' or " or where you put your ++ that's more just good practice. But I digress. The speedup isn't my major point. > > > And you're still ignoring that concatenation is easier to audit. *All* > > syntax highlighters will highlight concatenation. Only some highlight > > in-string vars correctly. Besides that, it's also simpler to be able > > to skip over single quoted vars when looking for things like XSS or > > SQL injection attacks. It also means that there are no special chars > > in the string to watch out for. > > Here is your strong point. Readability, and thus ease of auditing, is a > major point to go for. You'd easily win this argument if you dropped the > performance point and aimed at readability. > Yes, readability and auditability are the better reasons for this. > > Using " is also more error-prone when dealing with complicated vars > > (and it can't be used for *really* complicated ones). On top of this > > it tends to promote bad array syntax ($arr[key] instead of > > $arr['key']). > > > > For all of these reasons (and probably some I'm missing) ' should be > > preferred over ". > > A good list of security and readability reasons could probably go in the > coding guidelines as a recomendation, no? > Yes, that would be good. -- Justin Patrin

« previous php.pear.dev (#40278) next »