Introducing OpenBSD's httpd [pdf]
openbsd.org
openbsd.org
Now it's this new httpd that is lighter than bloated nginx.
So, maybe nginx and apache and all the other webservers out there are too big and bloated and sloppy, despite being written by smart people and used to deliver many many performant websites. That's possible.
But it is also possible that, because programmers love to start from scratch and reinvent the wheel rather than reading and understanding other people's code and rather than researching other domains, they tend to create weak web servers and tout them as "lightweight" until eventually they either die or evolve to be useful to people who actually understand the nuances of serving resources over the web, at which point they get accused of "featuritis" and the cycle repeats.
(See also http://www.joelonsoftware.com/articles/fog0000000020.html)
That sounds absolutely reasonable and like a good policy.
Confs look familiar, and it's lightweight and will be secure. Perfect.
It's young; not expected to be base until this fall. Give it a few months and you'll see it in there.
For this httpd, it seems like the problem they were solving is that they needed an httpd, and the result is about what I'd expect from the OpenBSD folks.
As a random guess, is it because Apache focuses on features, nginx on speed, and OpenBSD wanted a focus on security?
OpenBSD was stuck on Apache 1.3 for ages because the license changes for Apache 2.0+ was incompatible. They also ended up maintaining their own fork for quite a while because patches to improve security were not being accepted upstream (I think)
Nginx:
License is fine, but it's getting feature bloat and the local patchset was getting unwieldy.
Conclusion: roll your own httpd that way you don't have to deal with this anymore.
What situation?
- We also introduced new safer APIs like reallocarray()
- I wrote a big diff for nginx to adopt reallocarray() other such techniques
- And it got rejected.[1] https://github.com/robertbachmann/openbsd-libc/blob/master/s...
say, a packet filter, for example...
They're not appropriating it. They're just creating another reverse proxy.
- They need a web-server in base.
- They demand security.
- He submitted a patch for nginx to embrace new secure methods.
- It was rejected.
- Because a base server is required in base, and they don't want to maintain a fork of nginx for base: "Introducing HTTPD".