Logging Everyone Out
lists.wikimedia.org
lists.wikimedia.org
Given their size on both the web in terms of employees this unusual for Wikimedia. They typically fly under the radar. How many times has Wikipedia ever been down?
I recall AWS, Google, Microsoft having more outages -- mind they probably are considerably bigger but still they're doing something right.
edit: fixed a typo
Largely static? There are edits happening all the time.
This is a much easier service to reliably engineer than something like Twitter. For SRE purposes, Wikipedia is mostly static.
> Wikipedia develops at a rate of over 1.9 edits per second, performed by editors from all over the world. Currently, the English Wikipedia includes 6,167,378 articles and it averages 598 new articles per day.
Doesn't seem to be much, to be honest.
There generally is a bit of a long tail effect. Popular pages get edited a lot, but they also get viewed a lot. It can be expensive when everyone is viewing and editing the same page (Micheal Jackson's death is a famous example that caused downtime, although changes were made to make things more robust so it wouldn't happen again)
If the actual servers go down all that means is that wikipedia is read only and the caching reverse proxies that also receive a push update during modifications would just serve the last version of pages. (except anybody with login cookies, valid or not, would get 500 responses)
The opposite of static would be an e-commerce site where you can't take transactions if the backend is down and you really don't want to oversell your inventory, so you need the inventory management system to be up for the site to "work".
Also, the average wikipedia page probably isn't edited very often.
Even something as simple as HN probably have much much lower value of "usefulness if the service is served completely static from caches", due to upvotes and comments. If the front-page and comments stayed static both during breakfast and lunch, my WFH routine would sadly be impacted...
On the contrary, users get very angry if stuff isn't fresh.
Someone changes trump article to say he is a poopy head. If that gets fixed in 2 seconds, no big deal. If that gets cached, and the edit to fix it doesnt hit the caches for a couple hours, wikipedia is now the top story on CNN.
Generally wikipedia caches are expected to be updated within seconds or minutes at most.
I think my larger points still stand. In comparison, almost all other services at the scale of wikipedia have critical almost-realtime components, and is almost useless without the possibility to authenticate users (which can't really be cached).
Not saying that the people who manage to keep Wikipedia so stable are doing an easy task, just that it's very different from almost all other things on the web.
Assuming things havent changed, each varnish server listens for purges via multicast udp.
You can see per-server stats on purges happening here:
You are right that technically it's SSR, but that's not what's relevant here.
That said, i think they do now use cloudflate's bgp based magic transport ddos protection product to help against ddos
*in the web sense - don’t want to offend any of the real real-time people :-)
These templates can pull information in from outside of the specific Wikipedia instance, like retrieving properties from Wikidata.
Edit: I guess I was wrong, seems like lua modules are only evaluated when there's a change to a page incorporating them:
>The programs are run only when the page is "parsed" (when it or a page it incorporates is changed or previewed), not every time you view the output.
https://en.wiktionary.org/wiki/a
>Lua error: not enough memory
appears on the page 250 times.
Frontend cache gets skipped if you have a session cookie (logged in or have been logged in recently or made an edit logged out). So if you edit something, subsequent views are not hitting the static site, so you would notice if it was down
AWS/Google being down for even a minute or two is a big deal though.
I am under the impression that anyone can build credit and write what they think is correct. Do you check the linked sources and verify as such ?
If it's just an article about the history of pianos or CPUs or something, the probability of misinformation is much lower, the consequences of being misinformed are much lower, and I don't usually bother. Many times I just browse Wikipedia because I want to learn about weird animals or off-the-beaten-path places on Earth or culture or something like that.
(By the way, primary sources also sometimes have their drawbacks as well; they can often be politically motivated, biased and not tell you the full story, and Wikipedia is effectively peer-reviewed for a lot of articles.)
(I knew this likely just a typo, but I genuinely didn't figure out what you meant.)
I do lots of PHP migration work (4 to 5, 5 to 7) and for much of it it just works.
Not much code change is necessary to the the upgraded features of the engine.
Disclaimer: am mediawiki dev. No opinion on if the codebase is "modern" because everyone defines that differently.
(This includes a couple usages of traits, traits is just not something super common in mediawiki, but there are some cases where they are used)
EDIT: Looks like the main blockers are related to moving to Debian 10. https://phabricator.wikimedia.org/T245757
1.34 is the trailing legacy release and requires 7.2.9 or newer. 1.31 LTS, supported into 2021, requires 7.0 or later.
In releases since 1.27 introduced PHP 7 support, the backward version compatibility has been tightening up more aggressively. PHP 7 brought a ton of performance gains that MW had previously relied on HHVM for, which gave them a lot of reasons to shed PHP 5 and start turning more forward-looking.
> This was done out of an abundance of caution, after we received one (1) user report of being logged in as someone else.
This _seems_ like a knee-jerk reaction to one data point.
There could be other causes for a user to report that, like a change to the cache key used for serving a users profile giving the _appearance_ that you're logged in as someone else, even though you're not really.
Forcing everyone to re-login could potentially make the system worse, in that you're now overloading parts of the system that has to handle those logins, plus causing all kinds of cache expiry...
I guess there's more to the story and someone who knows the system deeply knew this was the right choice but just reading the reports it seems knee-jerkish.
> Said report coincided with the deployment of a new MediaWiki release which caused other problems around User session objects;
One of the few stories VICE didn't botch entirely: https://youtu.be/_CvWJVtEkUE
There is actually a good article in the Varnish docs around hash collisions: https://varnish-cache.org/docs/4.1/phk/varnish_does_not_hash...
PS. Even though the article says "Varnish does not hash", I suggest everyone to keep reading until the end, when it turns out that they, in fact, do.
I appreciate it a lot, thanks WikiMedia
I was never able to reproduce the glitch.
I wrote this: https://www.mediawiki.org/wiki/Intranet and keep it up to date every now and then. It's probably time for me to look at 1.36. Anyway, the current Parsoid based thing works fine.
The beta go refers to in a version rewritten in PHP to drop the dependency on another service, parsoid, written in JavaScript/node.
That way, if someone is named "Billy" or "Alex", you won't be spending years mistakenly assuming they were a man while they could have been a woman.
This also has the beneficial side effect of covering trans individuals who use a birth name while having another gender identity.
Even more useful for usernames such as yours, "dionian". I do not know if it is your first name, last name or made-up username. So I have no clue what your gender is and I'd default to "they". If I knew, I could call you by the right pronouns.
It's just a slow shift away from assuming everyone on the internet is a man.
Even your reply highlights it. "It's about people." Notice the manner in which you _correct_ my rather anodyne words. The fault is that I did not frame the question as you would have me frame it, and looked at a part of the general phenomenon that is different from you think deserves to be centered on.
You are welcome to your ideology, in any event, and it would be a poor world indeed where one could not act to change the world in accordance with one's conscience.
You've made several substantial changes -- far beyond the scope of a clarification -- and now I'm reluctant to respond at all because who knows what it'll say next.
It is unfortunate that there is an excess of ideology around these issues. It hinders communication by confusing questions about the implementation of an ideology with hate-filled attacks on people.
It does not help the matter that similar attacks are real and exist. On the other hand, such confusion of concerns is a common goal of many who advance their ideologies, so there is a possibility some may deem this confusion desirable.
There are transgender people who want to access their human rights. Transgender people do not choose their gender identity.
While I am agree that there are human rights issues involved in the issues generally, I would say that is not specifically a human right to have others around you adopt this specific practice to support such a person as he, she, or they assert an identity.
I also think globo-corpo neoliberal is a bit redundant, no?
Friedman and Hayek were certainly not globo-corpo, considering that they believed in things like freedom of association, covenants, and other legal protections that work against the likes of Amazon or Wal-mart (who are primarily interested in undermining unions, using strategies to diminish worker cohesion like diversity quotas, and strategies to defang leftism like trans activism).
It is of course also a university-campus phenomenon (especially private universities) but those aren't really "corpo". For that matter, the Wikimedia Foundation is only "corpo" insofar as a 501(c)(3) is technically in fact a corporation — unlikely to be within the meaning of what you intended.
On that note, it is more prominent in the nonprofit sector, perhaps due to volunteers being more predisposed to activism in general. (Mozilla was a bellwether.)
Putting (he/him) in does three things. It invites you to provide your own. It also stops someone from starting a side-argument about you assuming 'he/him' in your response instead of you/your or they/their. Which means that we can talk about what we want to talk about instead of gender politics, if you don't feel like it. Or we can if you need to.
Having everyone declare their gender is a little bit ridiculous, just to serve the desires of a ~1% group who are trying to gain more recognition. I am frankly surprised how people are willing to distort their behavior when they refuse to do so for other groups who are far more downtrampled in their rights in greater percentages. I suppose somehow transsexual people just became popular for some reason.
Frankly, it's a symbol and problem of the modern liberal/democratic mind (at least at the party-level) that these problems rise to the level of national and corporate attention -- and apparently we solved all our other material needs and have time to spend on this in comparison.
Not everyone is American, and not all issues are about American politics.
I find it interesting how much emphasis has been placed on an afterthought that I edited in. A lot of really emotional reactions like yours. I described it as a beneficial side effect and suddenly the whole conversation is about "evil trans people" and "bad liberals".
Having your pronouns available is beneficial to more than just trans people. It benefits everyone, avoids mistakes and makes conversations more accurate. It also breaks the myth that there are no women online and that there are no computer-savvy women. It also brings visibility to non-binary people who are otherwise invisible.
>Preferred gender pronouns or personal gender pronouns (often abbreviated as PGP) refer to the set of third-person pronouns that an individual prefers that others use in order to identify that person's gender (or lack thereof). In English, when declaring one's preferred pronouns, a person will often state the subject and object pronouns along with the possessive adjectives—for example, "she, her, hers", "he, him, his", or "they, them, theirs"—although sometimes, only the subject and object pronouns are stated ("he, him", "she, her", "they, them").
Here we have "he/him". Sometimes I see "he/him/his" or "she/her/hers", "they/them/theirs", etc.
I doubt people are mixing and matching among the different types. In other words, I've never seen someone prefer "he/them/hers".
Seems like we can standardize this to just one type (e.g. the subject pronoun). A simple "he", "she", or "they" will do the trick.
Yes, I bikeshedded it. Sue me.
It is my personal policy to not correct people who misgender me in most cases, especially if that is the only thing I would be saying (I will sometimes clarify if it is part of a larger comment, but I try to be gentle about it). I would rather put that info somewhere and let them have the chance to learn of it without me having to correct someone.
Different people have different reasons for noting their pronouns. Some do it because it is trendy. Some do it because they have genuinely been misidentified in online spaces. Some do it to show themselves as allies to certain groups.
Without him saying why he did it, no one here can genuinely tell you why he chose to do so.
If you care so very little about this issue, why bother replying to me to suggest I shouldn't? If you really don't care, then you shouldn't even be reading this crap. There is plenty of other stuff to read elsewhere that isn't on this subject.
But it leads to the question of why it matters - should it? If we treat all equally, should it matter? I don't see myself as female, but neither a 'man', as I don't much relate to common cultural depictions of men, which I find distasteful. I am what I am, names won't change that so I don't care. Why do you?
BTW I know a few trans people and I suspect most of them would roll their eyes at this excessive care not to offend anyone with wrong pronouns. They expect people to get it right but it's no disaster if someone got it wrong. None of them are snowflakes. Consideration towards trans people needs more basic considerations such as not being called a freak on public transport (this happened to a tgirl I know).
In theory, it shouldn't. In practice, it does.
People who think I am male speak to me differently than when they know I am a woman. Since I am trying to establish an adequate income, my experience is that if people have an issue with me being a woman, it's better for that to be sorted before they interact with me, not after.
If someone is willing to meet me in person, thinks I'm male and then meets me and sees I'm a woman, that's likely to go badly. I don't want to waste my time on that, much less risk facing potential drama because of it.
The reality is it ends up mattering whether I want it to matter or not. So I try to make it the least drama I can arrange given the tools available to me. I find that a quiet heads up is better than trying to hide my gender and is also better than putting people on the spot and correcting them in "public" and in a way that will make them feel attacked for simply not knowing.
If this is a problem, it needs tackling much more than the facile overlay of pronouns.
Now, just from my experience, and I'm just reporting...
> speak to me differently than when they know I am a woman
This has never happened to me. Always been treated equally either way. Maybe I've been lucky.
> ...and then meets me and sees I'm a woman
I have the occasional reverse happen. It has never, ever, caused any problem. Which does not invalidate your experience, I'm just giving mine.
Part of the reason is I've been on HN eleven years and there is abundant opportunity for people to discover my gender organically in comments here.
Different tools are appropriate in different situations.
It also happened a couple of days ago again. The cause is not known: https://translate.googleusercontent.com/translate_c?depth=1&...
There exist services where you can pay $5 per search to avoid this the history.
The other times just weren't noticed, posted, or upvoted on HN.
Not logging anyone out while updating a suite of REST-ful applications: ho hum.
If the site doesn't work without being logged in you could frustrate users and they might just use a different product instead of searching for their login after being logged in for a year or longer.
Eg a web application: you can substantially rewrite a web application, without invalidating logged in sessions.
The point here is that the logged in sessions were suspected of being unauthorized. The unauthorized sessions had to be turfed, and the clearest way of being sure that all unauthorized sessions are turfed is to delete all the sessions.
Of course, some those with unauthorized access will also try to log in to resume that unauthorized access, but presumably there is some trap laid for that.
Maybe for the accounts suspected of having been breached, there will be a mandatory password recovery procedure or whatever. Or they will monitor for suspicious logins from different IP addresses.