Python Bytes - #498 A Tiny Episode

Episode Date: September 29, 2026

Topics covered in this episode: MemTensor / MemoryOS PyPI package hijacked via a malicious build backend TinyMongo Jev: what to know One innocent dict read makes attribute access permanently slower... Extras Joke Watch on YouTube About the show Sponsored by us! Support our work through: Our courses at Talk Python Consulting from Six Feet Up Connect with the hosts Michael: Mastodon / BlueSky / X / LinkedIn Calvin: Mastodon / BlueSky / X / LinkedIn Show: Mastodon / BlueSky / X Join us on YouTube at pythonbytes.fm/live to be part of the audience. Usually Tuesday at 7am PT. Older video versions available there too. Finally, if you want an artisanal, hand-crafted digest of every week of the show notes in email form? Add your name and email to our friends of the show list, we'll never share it. Calvin #1: MemTensor / MemoryOS PyPI package hijacked via a malicious build backend On Sept 23 an attacker published backdoored MemoryOS 2.0.34 on PyPI and three bad versions (0.1.21, 0.1.23, 0.1.25) of MemTensor's OpenClaw plugin on npm. PyPI had no clean release that day, so 2.0.34 was the newest. They pushed commits to MemTensor's own GitHub Actions release pipelines. On PyPI that was a custom Poetry build backend, and on npm a tweaked validation script. Both used BASH_ENV to hand the publish token to the attacker before the real publish ran. SafeDep couldn't confirm how the attacker got push access. Runs on import, not install: A Go implant called sckit starts when the library loads, so --ignore-scripts won't save you. It harvests credentials from your home directory (npm and PyPI tokens, GitHub tokens, SSH keys, cloud CLI tokens, .env files) and sends them to skyleen[.]fr servers. It's a worm: It uses stolen tokens to copy itself into other repos and packages, so the victim list could grow. If you installed it: Downgrade to MemoryOS 2.0.33 (plugin 0.1.20) and rotate every credential reachable from $HOME. Also kill any running sckit stage0 process and check repos you can push to for a stray runtime-update.yml workflow or .sckit/ directory. Michael #2: TinyMongo Want to use a MongoDB data interface, but swap out the storage engine? Memory for testing/caching JSON/TinyDB simple JSON files SQLite for durable, high-perf reads with WAL SQLIte shared for high write apps DuckDB + Parquet for analytics apps Postgres + MariaDB for multi-machine client/server Great for teaching, examples, and simple deployments Amazing story of paired AI development Will completely run talkpython.fm after weeks of shared work together (in SQLite mode). Calvin #3: Jev: what to know What it is: Jev is a model from TypeSafe AI that answers with typed results (yes/no probabilities, scores, picks from your options) instead of prose. Real Python published a hands-on tutorial on 2026-09-24 and the buzz on hacker news is almost deafening. It's proprietary: Jev is a hosted, closed-weight model. There are no weights to download and no self-hosting. Everything called "open Jev" is an independent reimplementation, not TypeSafe's model. Your data leaves your machine: Every call sends your input text to a third-party API. In the tutorial that path goes through OpenRouter to TypeSafe. Think twice before sending customer messages, tickets or anything sensitive. Cost and stability are open questions: The tutorial calls Jev "cheap, but not free" and says it's fast and cheap "at the moment." It also says whether that stays true is "something to keep an eye on." Credit to Real Python: It's a good, practical intro. It shows the Noul, Score and Choice primitives, and its point that instruction wording matters more than thresholds is useful advice for any model. The tutorial itself says similar results are possible with a well-prompted LLM. Open options to look at instead: JevK5 (https://github.com/allebee/jevk5): Apache-2.0 weights and code, 4B or 9B parameters, and it accepts TypeSafe-style requests. SemIf, formerly OpenJev (https://github.com/TheoLeeCJ/openjev): MIT-licensed, small models, and it can run CPU-only. openjev-sglang (https://github.com/ekzhang/openjev-sglang): a Jev-compatible endpoint running Qwen3.6-35B-A3B, but no license is stated, so check before commercial use. The catch: These copy Jev's interface, not its model or training. Results will differ, and I haven't run any of them. Benchmarks are self-reported, and JevK5 is English-only. Michael #4: One innocent dict read makes attribute access permanently slower Timofei Ivankov benchmarks a CPython internals surprise: since 3.11, attribute access skips the instance dict entirely. A specialized opcode reads the attri.bute at a fixed byte offset in the object's inline values array. Read obj.__dict__ once, though, and the dict gets materialized, the object loses that specialized path for the rest of its life, and a million-iteration loop goes from 33 ms to 51 ms on CPython 3.14. vars() and copy.copy() trigger the same thing, so a debugging print or a shallow copy in code touching your hot objects quietly makes every later attribute access roughly 1.5x slower. The slowdown is permanent and nothing about it looks like a performance decision: ordinary code far from the hot loop can trigger it, and the function that gets slower never changes. Materializing dict produces a split table, and the LOAD_ATTR_WITH_HINT fallback declines split tables, so the object ends up with no specialization at all vars(), 'x' in o.dict, and copy.copy() all materialize it; copy.copy is the realistic trap since nobody treats a shallow copy as a performance decision slots instances read attributes at exactly the same speed and cannot fall into the trap since there is no dict to materialize On the free-threaded build both effects grow: atomic incref on reads plus an object lock on writes push the penalty from 17.6 to 25.4 ns Credit: this item was surfaced by the PyCoder's Weekly newsletter Extras Calvin: whatsnewt - a TUI text adventure through what's new in Python 3.15; playful but niche. Joke: Shipping a button in 2026…

Transcript
Discussion (0)
Starting point is 00:00:00 Hello and welcome to Python Bytes, where we deliver Python news and headlines directly to your earbuds. This is unbelievably. Episode 498 coming up on episode 500, recorded September 29th, 2026. I'm Michael Kennedy. And I'm Calvin Indyx Parker. Check us out on all the socials. We put all the links if you want to interact with us there at the top of the show. This episode is brought to you by us.
Starting point is 00:00:23 So be sure to check out six feet up if you have an amazing you would like some people who have done a lot of problem solving the Python. space for many, many years. Reach out to Calvin and learn about Python. Got some courses over at Talk Python. They had new things coming. Nothing to announce yet, but a lot of work has been going lately on a new thing over there. So I'm very excited. Check out the newsletter. Just visit the homepage. Like newsletter. We got lots of cool things to send to you there. And with that, you have scary news. Are you going to scare us? Hopefully not too much. It's not quite October, although I do see lots and lots of decorations out in the stores these days for Halloween. But there is unfortunately
Starting point is 00:01:02 A jump scare, right? A little bit, yeah. There's been a supply chain attack and there's no shortage of these over the last couple of years probably due to the proliferation of AI and the tools that attackers can use to build these different exploits.
Starting point is 00:01:15 This one is around MIMTensor and memory OS. So some people may not be affected by this but I think the real true story here is to follow how it's done and to protect your CI pipelines ultimately. So on September 23rd, an attacker published a backdoor into memory OS. So if you're using OpenClaw or if you have installed a memory OS skill into your agentic harness,
Starting point is 00:01:41 you could be susceptible to this. So look for these various versions, 0.1.21 on the plugin. That's the bad versions and 0.1.23 and 25. and then the Memory OS version 0.2, no, sorry, 2.0.34, the newest one that was released last week, those are problematic. They are going to launch a Go process in the background. Even working around like the import path stuff won't get around this because it will launch this. What looks like a legitimate named thing, SCK-I-T, you may misview it as SciKit. but it's actually SCKIT, it gets a Go library that loads in the background. And what it does, scourge your system for credentials,
Starting point is 00:02:27 post them to a command and control server, kind of the standard play there. And then it attempts to inject itself into other CI pipelines as a worm. So this one's not just an exploit that's gonna exfiltrate your credentials, they're actually looking to exfiltrate them, exploit them, and then turn them into a worm
Starting point is 00:02:44 to gather more and more of them, whatever projects you're basically working on. So it traverses your home directory looking for Pi Pi tokens, GitHub tokens, you name it, and then sends them to a nefarious server someplace. Those then locate itself and try and go again. So if you are on these various versions of these various packages, make sure you downgrade to the safe versions. There's 2.0.33 of memoryOS and 0.1.20 of the plugin and rotate every possible credential you have that's reachable from your home
Starting point is 00:03:17 directory. Make sure you kill any SCK-I-T processes that are running because that is where it is talking to the command and control server. So unfortunate news, no fun. The write-up from SafeDep, which is linked to from the show notes here, has a really good take on basically how they got in. There are a couple spots where they don't know how they got some of the tokens. They assume maybe social engineering or a leak of a GitHub token someplace. But the, the various projects have put in some fixes into their CI pipelines to hopefully prevent future attacks like this from happening. And you probably could learn something, a thing or two for your own CI pipelines to harden your processes as well. That is a jump scare. Yeah, less than fun.
Starting point is 00:04:03 Less than fun. No one loves to hear that news on a Tuesday morning. But I think everyone needs to be aware and protect their CI pipelines. Because again, this is how they got in. They basically use the GitHub Actions pipelines. Not the GitHub Actions is in. itself vulnerable to these things, it just enables these kinds of things. It's the other practices that are what made this possible. I remember how scary it was that there were worms on the internet, especially back when firewalls. What's a firewall? That's what a company. That's what giant companies do. Yeah. So there's on the webpage, they also link into the issue from the memory OS folks and the open club plug-in repositories. Again, I think it's a good
Starting point is 00:04:47 responsible write-up of what happened. The repositories themselves don't have a lot of information on them, but this article does. Yeah. It's just, it's scary, you know, having very cool what we can do as developers, but at the same time, the responsibility of, oh my gosh, something, something got through and it didn't just affect me. Yeah. It did just affect my users, but everybody who might have used something I created now, it's like taken over all of there. You're like, oh my gosh, that's a serious fire. So, I mean, it's a common complaint. Like, why can't we just dump files? into a web route like we used to and deploy CGI applications. Because that was very dangerous, we just didn't know it yet because of the various vectors for
Starting point is 00:05:27 exploit and attack. Deploying software safely requires a thoughtful and intentional process. Yeah. And to some degree, safety and isolation of your computer that makes that software. Very true. So yeah, pay attention to a lot of the sandboxing and containers and things like that that help you with those processes. Would you say you got to pay attention to like tiny little issues?
Starting point is 00:05:47 Tiny things could, you know, be an interesting way to go. I want to talk about tiny Mongo. Are you familiar with this? I am not, actually. I'm quite curious. My son actually was in a MongoDB hackathon over the weekend, so maybe he might be interested in this. Well, this would have been absolutely awesome for that. I mean, maybe if it was about MongoDB, no.
Starting point is 00:06:06 But I've covered this before, actually gives me a chance to highlight a cool little search feature of our, if you search some of them, you can actually say, only show me the episodes that exactly covered this. So way back in 2017, nine years ago, we covered Tiny Mongo. So the guy behind this, Stephen, I had posted way back when I'd posted some issue saying, this thing is cool. So let me tell you what Tiny Mongo is. And then I'll tell you why it's back on the show after nine years. So Tiny Mongo is what SQLite is to Postgres.
Starting point is 00:06:38 Tiny Mongo is to MongoDB. Okay. In process, local file. But it goes, I know, it goes a little farther than SQL. light, as you'll see, in some really interesting ways, but it uses well-known, durable back-ins for the most part. So you can choose a really well-known, well-tested, well-trusted backend for this. But basically think, in process, I want something without a server now as part of this news item is very, very fast. So Stephen reached out, or Stephen looked at this GitHub issue and
Starting point is 00:07:10 decided, all right, I'm going to fix it. So the issue I filed a while ago was, this is really cool. it supports a subset of MongoDB, but not enough. Okay? So I was using, gosh, when I posted the issue, I think I was using Mongo Engine. When he replied to the issue, I was using... What one was it? I was using a Pidentic Base 1, Beanie. And then, by the time he actually got the thing working,
Starting point is 00:07:33 I was using just raw MongoDB queries. But I said, look, this is cool, but I can't use it with anything based on these ORMs because the ORMs have a certain set of, like, startup things they do. like ensure these collections exist, ensure this index exists. You know, it's like testing different things as just part of the standard setup, you know, like it scaffolds the index automatically and stuff. And those things weren't working. So I said, would you be willing to put in enough structure, maybe even if they're no-ops,
Starting point is 00:08:02 that I could actually run a, quote, real application on top of Tiny Mongo? Because there's all sorts of cool reasons you might want this. Like if you're doing a tutorial or a workshop, you don't want to have to start out and go, now kids the first thing we're going to start is by setting up a network server and securing it like no no there goes the day you're like okay well we're not doing the workshop anymore right like but if you have something like SQL light you can just say this is the connection string this is the UVPip install command now let's keep going and it's but it's the same program you just change the connection string basically to get like a real server right like to switch over to real manga or whatever
Starting point is 00:08:39 so stephen took that idea and just totally ran with it and came back to me and said, hey, look, what do I need? How about this? You know, this, this last question was asked in the time of AI, the time of really smart coding agents, right? Just the before times and there's now. Exactly. So I think this actually represents a really super interesting collaboration between me and Stephen. So, Stefan, sorry. So he said, well, what do I need? I said, well, how about this? Why don't I just see if I can get Talk Python to run on top of this? just as it is. And I just said, all right, well, I'm going to take Mongo out. I'm going to stop talking to the real Mongo. And I'm going to put tiny Mongo in and get it to rut. And there were all these issues like, yeah, it technically works, but this thing is a thousand times slower in this way. I wasn't expecting that. Yeah, well, it almost worked. Once we got it working, it was like, okay, now it works, but it's like, these five things are insanely slow, or this type of query is not actually supported, or limit doesn't actually limit it in the DB, it pulls it all back, and then it, like, limits it's, you know, those kind of weird little, like, it's fine, but if you've got hundreds of thousands or millions of records, you're like, no, this is not going to fly, right? This is out of control. So we went through all those, and now it's, it's like really quite close to MongoDB performance.
Starting point is 00:09:58 Michael, would you recommend this for production usage or is it still more for exploring, playing, teaching? I would recommend it. I think it's safe. I'll tell you why. I'll tell you why. I think it's, I would recommend it if you would consider SQL Lite as your backend for production, which I think actually is a viable. Yeah, it's very safe. It has restrictions on like parallel writers and stuff, but I do think it's quite safe. I agree. If you would consider SQL Light as a back end, then I think this, I would recommend this as a back end. Yes, as we'll see. Okay. So, let's go down.
Starting point is 00:10:33 I mean, what's cool about it is the way you write is you just like write regular code and you just import tiny Mongo as pie manga, which is the standard way of creating a thing. And you give it, you know, a connection string sort of deal that is like this file instead of this database. And then you just write regular queries against it, all right? So what's really neat down here somewhere is all the different backends it has. So like SQLite, it might be really. uses the SQLite version for this, I'm not sure, is you have an in-memory version. So it never even writes to disk.
Starting point is 00:11:04 Like, I'm doing unit tests or I'm just firing up this code, this data I'm going to think about it, and then throw it away, right? That's pretty cool. It has this JSON back-in, which is its sort of default way. I haven't done it. This was not really able to totally solve the Talk Python runtime, I think, or it was like too slow or something, but switching to SQL Lite. So basically it uses SQL Lite with all of the SQLite transactions,
Starting point is 00:11:27 write-ahead log stuff and all that kind of stuff. And that's a really good production story. And then look at this, Calvin, sharded SQLite. I'm more curious about the next one, which is DuckDB. Yeah. So you're going to ask. Yeah, because there you've got real JSON support possibly. Yeah, Stefan is a huge fan of DuckDB and those kinds of things.
Starting point is 00:11:46 So this is duct DB and parquet files as the back end, which is pretty interesting. So if you're doing data sciencey things and you were doing Mongo type of queries, this is the way. This is a pretty good one. And then also it has a way to say, like, you know, point that over at Postgres and Maria DB if you'd rather have something that's kind of like Mongo, but you don't actually run Mongo. I mean, you literally talk to it as if it was Mongo. Yeah, I'm unsure about that use case.
Starting point is 00:12:12 I think I might just run Mongo. I would too. I would totally too. But I think the SQL Light one, it's really good. We got it really, really dialed. So I actually linked to one of the issues. There's a bunch of issues over there. So I had some issues.
Starting point is 00:12:26 Stephen added him and sort of referenced me. And we just went back and forth. And I would say, hey, Claude, I'd open up, I had a branch for Talk Python. I'd open it up and said, hey, Claude, check out this GitHub issue. Can you try to implement it on top of this thing? And it would do it. And so, well, I found all these issues. I said, okay, file some issues.
Starting point is 00:12:43 Then Stephen would have Codex look at it, fix it up, reply it. And we would just, like, pass it back and forth. And the reason that's interesting is I'm not giving him the Talk Python code base. And I ended up running on Talk Python training, which like 300,000 lines of Python code and got it working there as well. But I'm not giving him that code. But he was able to literally prototype both from performance and correctness perspective running on both those code bases by just bouncing back and forth. Well, my AI did your spike and it found that it ran like this and this worked and this didn't. And so, okay, I fixed this
Starting point is 00:13:18 this, try it again. And we just went back and forth for like over and over for days and got it really, really dialed. And I thought that was, that itself is worth covering here. Yeah, like that work for. Yeah. Yeah, it's very interesting. Obviously, my prompts were like, you will not put any proprietary information, any secrets, any source code example. You will put all generic, you know what I mean? But at the same time, it totally worked.
Starting point is 00:13:41 And it was really cool. But I think this is a super interesting thing because until this recent work, this version 1.3.1 that got released, there was no sequel light equivalent for MongoDB. And now I think there legitimately is. not 100% coverage, but it's quite high. It runs multiple real-time apps. Yeah, I like that. Especially for the education market, being able to teach someone really quickly without having to install and serve, and that's a huge barrier for a lot of people. Yeah. It looks really good. I'm really excited about it. Thank you, Stefan, for doing this work. And there might be a follow-up at some point as well. And what a great, like, story for open source. Yeah, exactly. A really cool
Starting point is 00:14:20 way to get some actual hands-on experience on real projects by sort of paint. ponging, get-up issues back and forth. It was crazy. Speaking of crazy, I've heard this. This topic is set in the world on fire. Well, and I wanted to bring it to light to get some people some exposure to it. If you've not heard of Jev yet, you're probably living under a rock someplace. And that's okay.
Starting point is 00:14:43 But the folks at Real Python did a tutorial of how to get started with Jev in Python. For those of you who don't know, Jev is a model from a company called TypeSafe AI that answers. typed results like yes-nows, probabilities, scores, and pick from options instead of you talking with it. So you don't chat with Jev. You don't come into Jev and say, hey, build me an app or tell me a bear story or whatever the thing you may want. Propose to Jev sets of information, evaluation, the kind of result you want, and then Jev can, in parallel, evaluate those things, either scoring them, giving them yes-nows.
Starting point is 00:15:23 I mean, the docs from the tutorial are basically a customer service example where the customer says, I've tried contacting support like three times, can I please get escalated? And so then the Jev for that basically is, here's how you know if the person is telling a truth or not. So they have a yes-no or true fall. And there's some custom various data types to go along with it. So what's nice is that the real Python article will get you started with Jev. So you'll understand the data types. You'll understand like what Jeb's about, that you can't just chat with it.
Starting point is 00:15:52 But I think, and then the buzz is real. I've heard tons and tons of people talking about it. It looks like the invites are back open again. I was actually able to sign up for Jev this morning and try it out. But it is proprietary. Jev is a hosted closed weight model. There are no weights to download. There's no self-hosting of this thing.
Starting point is 00:16:11 Everything called OpenJV is an independent implementation and not TypeSafe model, which means your data leaves your machine. So I don't know how much you trust type Safe AI who we don't know I don't know who they are Where they're posted what their business models are obviously it's not free you have to use you have to put a credit card down to use this model and try it out But every call send your input to the text input text you put in there to a third party so be careful like much like you just mentioned how you were sanitizing your inputs for Working back and forth on the tiny Mongo project with Stefan be careful what you send into this one because you don't control it just as much as you control what you send to Anthropic or Open AI. Those are pretty well-established companies with a good business model and they seem to be running on, you know, credibility and reputation. You have to,
Starting point is 00:17:02 you have to do your research and know what you're going to be sending over there. So think twice before sending customer messages, tickets or anything sensitive. The other thing is like costs and stability are a question, right? So basically Jev bills themselves as very cheap. And it is very cheap. Like you can, and very fast, you can have it sort through, I heard someone tell me an example, like look through my inbox of a million messages, categorizing them for like needs immediate attention, is about a customer, et cetera, et cetera, and it can build you a table and sort that table in just milliseconds. It's that fast. I want to give people an option here. It's a good practical intro. It shows how to use the null, the score, the choice primitives, but there are open options out there.
Starting point is 00:17:44 I know I keep caveating this like episode, this section of the episode, there are some open options to look at instead. For example, JevK5. It's an Apache 2O licensed weights and code. So that's kind of my frontrunner right now. I've not tried it, but it does accept TypeSafe style requests. These are API compatible, but they are not the Jev model. So you're going to get different potential results. There's also one called SimF, which was formerly called Open Jev. I'm sure lots of takedown notice. came flying back and forth as all these alternatives came out that were also called something something Jev another one's open jev sg lang again the catch here is these are not the jev model they are close there was actually a really interesting um jev and 25 lines of python a little bit tongue and cheek
Starting point is 00:18:32 post that also came out about this but what they did here was use the quinn three model and told it to act like jev and for most things i think it gave reasonable results but also that the very end. This was a real tongue-in-cheek post that kind of poking fun at the the hype that is Jev right now. So I want to put that out there for folks to be just mostly aware of the fact that you're sending your data to a proprietary company and be careful what you're sending to it unless you totally trust it and have a business agreement with that organization beyond putting your credit card into a credit card field. So I hope folks are vigilant as they go forth and try these things. The hype is real. Oh my gosh. You couldn't.
Starting point is 00:19:14 again, move last week without hearing about Jev in some meeting and some, some article and some topic. It's a very interesting way and a very interesting usage. It's a very, I think it's a great pattern for reducing token spend and usage on other models in collaboration and combination with other models, but you need to understand what it really means in action. It's a super cool thing. You're right. It absolutely is blown. Jev was blowing up. I had to watch some YouTube videos this week. I'm missing something because there's a lot of this thing. I've never heard of going on around and around.
Starting point is 00:19:49 When you sign up for a Jev account, it makes you take a pop quiz to ask you whether or not you can chat with Jev. I won't give you the answer because if you don't know, you shouldn't probably be using Jev. If you got to ask, it's not for you. Yeah. I was going to say that there's never been a time, I think, where we're sending as much detailed information to other companies and other places as the last couple years.
Starting point is 00:20:13 Be careful out there, folks. It's real. But the reason we're doing it is because it's so productive and so useful, right? It is. I mean, the patterns, I think in looking at some of those open weight options, if you can put in place, again, I'll stress, probably why I stress things last week was around e-vals. Building good e-vals for your CI pipeline to run against these models,
Starting point is 00:20:35 whether they're classifiers like Jev or whether they're LLMs, like the Quinn or other open-waist models, means you can swap back and forth with confidence. And if you can do that, you can use one of these open weights models, open source, even versions of these models with more confidence on your own GPUs. These things will run on even very small CPU, GPU.
Starting point is 00:20:54 I think there was a Quinn 306B model that they're using in the parody article. That runs on like a Raspberry Pi. You can get those anywhere. Nice. But I'm not using Anthropic for something. I've been using GLM-5-3 Flash, and that's been super, super neat.
Starting point is 00:21:08 But I want to talk about an age of innocence that may be over here. This is an article. I don't typically cover articles I typically more, but it kind of pulls out. It highlights a really important thing that the reason I pull up
Starting point is 00:21:20 is because it kind of broke my understanding of Python performance tips for one particular axes. So this is by Timothy Eivinkov. So cool to write this up. I think it might have had a little writing help, but that's okay. So here's the headline is reading DunderDict
Starting point is 00:21:38 once, one time. Reading Dunderdict of an object permanently de-optimizes attribute access. What? Why is that? Why is that not good? I also wonder just pointing this comes from pie coders. The permanence of it is the striking bit. Permanently, for the rest of that object's life cycle,
Starting point is 00:21:57 its performance is broken. Okay. So here's an old performance tip. And I'll tell you the one that I used that I thought was amazing. And it was amazing. If I have a loop, and in this hot, let's call it a hot loop here, that's just an example, a million times around, we're just going to do the same thing. Like, we're going to say, creating an attribute, self.
Starting point is 00:22:14 Value, access self. That value, in the loop, increment plus equals on the self dot value. Well, traditionally, that would go into the Dunder Dict, find the value, pull that value out, change it, store it back into the Dunder Dict, right? That was the backing store for its fields, which is weird, but that's how it worked. So here's what you do. Instead of doing that interchange over and over and over, do it on a local variable. Create a value, do all your work on a local variable in the function, and then at the end,
Starting point is 00:22:44 set the value to the class, right? Create value, and then eventually say self-daval value equals value, right? Super simple. That used to make a big difference. And now it does still a little bit, does a little bit, so it technically works. However, if you do this enough times, it turns out that the new specializing adaptive interpreter notices that and it drops the load adder, which is the bytecode instruction that reads the field from the dictionary, eventually it drops it and it starts processing it different, right? And so what it does is it actually starts to look at just, well, where in the offset, like a fixed byte offset into the object's storage for this, which is like, wow, okay, pretty cool.
Starting point is 00:23:31 So that's, I think, since 13, really interesting. and you can see the different aspects. It turns out that it's even more significant, this change of the problem they're suggesting or pointing out or that's not really a problem. It's just breaks in optimization. The breakage is stronger in a free-threaded world and the article goes into why.
Starting point is 00:23:50 So check this out. If you just say, like maybe this is like a debugging thing or whatever, you just say print dunderdict of the object and then you go have that function run, all of a sudden it's 50 milliseconds instead of 30 milliseconds. 1.5 times slower. What do you think? It's intense to get down to that level.
Starting point is 00:24:09 It is, but there's a bunch of little simple things that you're like, I could read the fields or I could just say Star Star Dunderdig and do this and that. And it turns out that that actually, it didn't used to make any difference. But because of the specializing adaptive interpreter, now it does. Right. So like if you just ask VARs of an object or if you ask if a field, is in the dictionary. Well, here's the really tricky one. A shallow copy. All right. Like, well, that's a totally reasonable thing. I'm going to make, I'm going to clone this before I
Starting point is 00:24:40 hand it back or something. Well, that clone that you did, he can attribute access. It access it. Yeah, it makes it 50% slower. I've definitely done that, mostly when I'm debugging or triaging code or kind of walking through the interpreter because it's easy to access. I can't think it too many times where I would have tried to do it in code. You could see how it's a, it's an easy workaround. It's like, oh, it's just right there. I'm going to reach for it. Yeah, exactly. So these, the first three, like, are kind of debugging ones. But this last shallow copy, this is a legitimate thing, right, that you might do. And so here's a, here's the, this is the part that I didn't get because the world has changed. And I haven't been like prototyping everything at that level. I'm, I'm a big fan of Dunder Slots. It means you can't dynamically add stuff to your class. But more importantly, used to mean that this whole dictionary mechanism was no longer used. And it basically used an offset into, a list that was just in each instance. So it honestly made things a lot better in terms of memory and in terms of attribute access
Starting point is 00:25:40 was significantly faster. Well, apparently, slots makes no difference anymore. Yeah. Because the specializing adaptive interpreter, at least in this use case, right? This is like a, I'm accessing the same thing a lot of times, right? It could be, you know, profiling is tricky. Performance is tricky. But basically the specializing adaptive interpreter for hot pass slots versus.
Starting point is 00:26:02 not, didn't really matter. And I didn't know about slots until I read Luciano's book Fluent Python. That's where I discovered that. And now you're saying it really doesn't matter anymore because of the new bits in there. Yeah, exactly. So I believe I might have learned about it as well from Luciano's book. So yeah, 311 and beyond, there's a lot of the faster C-Python thing, changed some of these things.
Starting point is 00:26:26 And it changed how this, especially with the specializing adaptive interpreter, changed a lot about how this dictionary and access, and that's the whole story, slots, dictionary access, optimizing or not optimizing it, and so on. So I thought this was an interesting dive into something that's, you know, everyone uses classes, objects, even if they're not big OOPPB folks, you still create objects. I mean, do you have a number? You know what I mean? Well, it's just, and it's convenient, but I think if you were, again, performance debugging, and triaging and you ran into this you've been surprised yes I would I would certainly say so I would say so Michael would you would you want an interesting way
Starting point is 00:27:06 to find out what's new or what's newt in Python so I get this extra here I wanted to share this is cool I've seen this now I thought I had not see I've seen this is cool this is a dungeon crawler called what's newt and it but what it does is it runs you through the what's new in Python and this this version is specific for 315 you can't run it with prior versions because it actually uses the features in 315 to check that you've completed the challenge in the dungeon. So I've got the dungeon up right here, so I'll just read off real quick. So this one starts off with the first room of the interpreter and the one nobody sees. Slips of paper are wedged into every crack of the masonry.phth files. Hundreds of them,
Starting point is 00:27:49 each one adding a directory to the path. A few begin with the words import, and those have scorch marks, rightfully so a brass plaque has bolted to the wall a new file sits on the lectern beneath it unwritten and so at this point you have a puzzle which is what runs before your program does and it has a link actually in the terminal that is a hyperlink it's a nice little t ui app and when you click on that it'll open up the related pep to basically give you a hint for it so if you want to solve it you just type solve i'll kind of here i'll type solve it'll open up an editor first time this kick my butt because that does not have vii key bindings in there so i had to like use my arrow keys you probably had almost just like a caveman
Starting point is 00:28:33 and so based on the the pep uh 829 it added in the new namespace a callable syntax for bringing in a callable into your pt h file or the new sys dot path for example so through deprecating the word import and now 350 adds is file format that can only name a callable here's how you write it and when you click check It's like solved. A reader can now see what starts up without executing it. The site modules batches every static sys dot path extension first and then only runs the start-up callable so that a dot-start file can rely on the path being complete. Please press enter when you're finished reading.
Starting point is 00:29:12 And then it takes you into do you want to go north-south, east, west on your journey and learn more and tracks your progress so you can see what scores I've gotten, how many puzzles I've solved. I believe if you go east, it's a very lazy path. Yeah, so that's super fun. I've not spent enough time reading the what's new in newer versions of Python, kind of like you alluded to in the last article, because we just use Python. And a lot of times I'm not leveraging some of these new features, but this is a fun way to learn what they are. I forgot to throw that in there. Oh, it is very fun. This is from Barry Warsaw, right? I believe so. That's a good question. I believe so. What's new? It is.
Starting point is 00:29:49 You're right. It is Barry Warsaw. Yep. Good job, Barry. Nice work, Barry. I love it. I'm here for it. And especially with the hype around dungeon crawler Carl right now, this is appropriate, very
Starting point is 00:30:00 appropriate. Bring me back to the days of muds. I used to put them multi-user dungeons. I mean, me and my friends, we would spend tons of time in these places back in high school. People got to remember when I was in high school, there literally was no web. Not like it was bad. We're dinosaurs roaming. The World Wide Web, I know.
Starting point is 00:30:19 The whole thing was created in 1993 when I was in college. So before that, you're like, well, we got Telnet. What are we going to do, folks? Yep. Muds. That's what we're going to do. We're going to use Gofer. It's a lot like this.
Starting point is 00:30:31 Yeah, gopher, Archie. Yep. Telnet. Oh, my gosh. News groups? Like, you get your newsreader out. What's so ironic is it was so amazing. And it seems so futuristic.
Starting point is 00:30:42 I bought things off of news groups. Like, going in through. Talnet and then getting the news groups and I bought an expansion card for my HP48GX. Incredible. All right. Well, from the past to the future, well, to the present, which feels actually legitimately a future. Tell me about the future.
Starting point is 00:30:58 Things used to be so simple. You mentioned throwing just a set of files to a folder and you may be behind a C panel so you can admin your website. I don't know. Oh, that was almost too modern for me, C panel. Yeah. Yeah, just FTP. I'm sorry.
Starting point is 00:31:12 Not even SFTV, just straight. Just open FTP. So I want to come back and do one more, Kai Lint it, because I couldn't help myself, Calvin. I saw, oh my God, I saw this one when we talked about the big data video. So here's more homework for folks. This is the perfect encapsulation of just how stuff gets so complicated for such a simple thing. So here's this 10-minute video tells the story of multiple mini-persones. throughout that we experience as software developers and data scientists and so on.
Starting point is 00:31:49 Trying to build tools, just a simple thing. You know, it starts with, okay, I need you to build a dashboard with a single button that does, I don't know, you know, whatever the button does, right? Pretty soon there's this guy over the shoulder and says, what are you doing with a regular database? You need a graph database. He goes, I don't need a graph database for 200,000 users. He goes, what if we had 200,000, 21 users?
Starting point is 00:32:18 He goes, gosh. His delivery is genius in this one. It's so good. So good. My highlight was the Pearl guy. Pearl, Pearl, you know, devil shows up on his shoulder. Yeah, it does. Yeah, there's this other guy is like, well, we need a DDD, you know, domain driven design
Starting point is 00:32:37 bounded context for the button. We need Docker builds for the button. It just goes on and on. just, oh, it is absolutely good. And the pearl guy somewhere or farther it is like, I could have built this with a single pearl script and a cron job back in, you know, whenever. But you portrays them perfectly. I mean, if you've been around any amount of time in this world, you're going to laugh. Yeah, yeah, yeah. It's so good. So everyone, I leave you with a delightful, too realistic look at how software is built these days. Yeah. Well, this was
Starting point is 00:33:11 really, really a good episode, Calvin. here. Yeah, catch you later.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.