4 ms·
You have the same problem with services and libraries when you’re introducing a breaking change. With services you can make non-breaking changes like security p
by zja 3y ago
You have the same problem with services and libraries when you’re introducing a breaking change. With services you can make non-breaking changes like security patches on the server side, without needing to coordinate with a customer.
- LtWorf 3y agoAnd with libraries you can't make breaking changes? The fact that I don't need to recompile everything whenever libcurl or libssl has a security fix proves otherwise.
- fl0ki 3y agoThat's not a great example given OpenSSL versions are famously backwards-incompatible. Older versions get ABI-compatible security patches because people put in the time to backport all of them to every version still supported, in many cases by distro package maintainers. It's exactly the situation libraries should generally avoid, because there are maintainance costs for older versions of the library as well as migration costs for all of its users. https://wiki.openssl.org/index.php/Versioning https://wiki.openssl.org/index.php/Versioning
- LtWorf 3y agoWell given that i upgrade but not downgrade… what's your point?
- fl0ki 3y agoThe point is that someone is paying the cost of maintaining the library's ABI surface area even if it's not you. In a thread specifically for developers considering how to offer an interface to their software, I think it's only fair to recognize the costs of those different approaches. In that regard, OpenSSL is an extremely bad example, or an extremely good example of what not to do.