Re: Request for feedback: OpenEXR v2.2.1 .so version changes

Richard Addison-Wood <[email protected]> Fri, 22 Dec 2017 10:52:26 +1300
Newsgroups gmane.comp.video.openexr.devel
Message-ID <[email protected]>
This is a multi-part message in MIME format.
--===============8900523192379780968==
Content-Type: multipart/alternative;
 boundary="------------4A721025610F66FF56F9F2FF"
Content-Language: en-US

This is a multi-part message in MIME format.
--------------4A721025610F66FF56F9F2FF
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 8bit

How about both options a and b?

On 12/22/17 05:56, Wayne Wooten wrote:
>
>  The Pixar team would prefer option A as well.
>   —Wayne
>
> On December 21, 2017 at 8:48:15 AM, Larry Gritz ([email protected] 
> <mailto:[email protected]>) wrote:
>
>> I don't have a strong opinion, but the widely used convention is that 
>> you should bump the so version when link compatibility changes. I'm 
>> ok with (a), I don't think I've yet seen 2.2.1 in the wild.
>>
>>
>>> On Dec 20, 2017, at 11:31 PM, Francois Chardavoine 
>>> <[email protected] <mailto:[email protected]>> wrote:
>>>
>>> It has been brought to our attention that the decision to increment 
>>> the so version as part of the 2.2.1 release may be problematic:
>>> https://github.com/openexr/openexr/issues/250
>>>
>>> It would be great to get any additional community commentary on 
>>> this. The .so version was bumped up mainly as an (admittedly 
>>> conservative) precautionary measure, since it had been a long time 
>>> since the previous release. Given that these are security 
>>> vulnerability fixes, it's understandable that there might be in some 
>>> cases a desire to be able to drop in replacement builds of OpenEXR 
>>> without recompiling the host application.
>>>
>>> Two options we can take are:
>>>
>>>   * a)- patch the currently tagged 2.2.1 to no longer include an .so
>>>     version change. This could be controversial unless we get
>>>     feedback that no one has adopted 2.2.1 in any significant way
>>>     yet (to avoid confusion around "what version of 2.2.1 did you use?")
>>>   * b)- release a 2.2.2 version which is identical to 2.2.1, except
>>>     with the older so version. This is somewhat inelegant, but
>>>     likely cleaner than option a).
>>>
>>>
>>> Does the community have any strong positions on this either way?
>>> Francois.
>>
>> --
>> Larry Gritz
>> [email protected] <mailto:[email protected]>
>>
>>
>>
>>
>> _______________________________________________
>> Openexr-devel mailing list
>> [email protected] <mailto:[email protected]>
>> https://lists.nongnu.org/mailman/listinfo/openexr-devel
>
>
> _______________________________________________
> Openexr-devel mailing list
> [email protected]
> https://lists.nongnu.org/mailman/listinfo/openexr-devel


--------------4A721025610F66FF56F9F2FF
Content-Type: text/html; charset=utf-8
Content-Transfer-Encoding: 8bit

<html>
  <head>
    <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
  </head>
  <body text="#000000" bgcolor="#FFFFFF">
    How about both options a and b?<br>
    <br>
    <div class="moz-cite-prefix">On 12/22/17 05:56, Wayne Wooten wrote:<br>
    </div>
    <blockquote type="cite"
cite="mid:CAD49JLHX61QbKsfzutYonUVFxyN4Snpw=UwkJAE-G-CRHPXXGA@mail.gmail.com">
      <meta http-equiv="Content-Type" content="text/html; charset=utf-8">
      <style>body{font-family:Helvetica,Arial;font-size:13px}</style>
      <div id="bloop_customfont"
style="font-family:Helvetica,Arial;font-size:13px;color:rgba(0,0,0,1.0);margin:0px;line-height:auto"><br>
      </div>
       
      <div> The Pixar team would prefer option A as well.</div>
      <div> </div>
      <div>  —Wayne<br>
        <br>
        <p class="airmail_on">On December 21, 2017 at 8:48:15 AM, Larry
          Gritz (<a href="mailto:[email protected]"
            moz-do-not-send="true">[email protected]</a>) wrote:</p>
        <blockquote type="cite" class="clean_bq"><span>
            <div style="word-wrap:break-word" class="">
              <div>
                <title></title>
                I don't have a strong opinion, but the widely used
                convention is
                that you should bump the so version when link
                compatibility
                changes. I'm ok with (a), I don't think I've yet seen
                2.2.1 in the
                wild.
                <div class=""><br class="">
                  <div class=""><br class="">
                    <div>
                      <blockquote type="cite" class="">
                        <div class="">On Dec 20, 2017, at 11:31 PM,
                          Francois Chardavoine
                          &lt;<a href="mailto:[email protected]"
                            class="" moz-do-not-send="true">[email protected]</a>&gt;
                          wrote:</div>
                        <br class="Apple-interchange-newline">
                        <div class="">
                          <div dir="ltr" class="">
                            <div class="">It has been brought to our
                              attention that the
                              decision to increment the so version as
                              part of the 2.2.1 release
                              may be problematic:</div>
                            <div class=""><a
                                href="https://github.com/openexr/openexr/issues/250"
                                class="" moz-do-not-send="true">https://github.com/openexr/openexr/issues/250</a><br
                                class="">
                            </div>
                            <div class=""><br class="">
                            </div>
                            It would be great to get any additional
                            community commentary on
                            this. The .so version was bumped up mainly
                            as an (admittedly
                            conservative) precautionary measure, since
                            it had been a long time
                            since the previous release. Given that these
                            are security
                            vulnerability fixes, it's understandable
                            that there might be in
                            some cases a desire to be able to drop in
                            replacement builds of
                            OpenEXR without recompiling the host
                            application.
                            <div class=""><br class="">
                            </div>
                            <div class="">Two options we can take are:</div>
                            <div class="">
                              <ul class="">
                                <li class="">a)- patch the currently
                                  tagged 2.2.1 to no longer
                                  include an .so version change. This
                                  could be controversial unless
                                  we get feedback that no one has
                                  adopted 2.2.1 in any significant
                                  way yet (to avoid confusion around
                                  "what version of 2.2.1 did you
                                  use?")<br class="">
                                </li>
                                <li class="">b)- release a 2.2.2 version
                                  which is identical to
                                  2.2.1, except with the older so
                                  version. This is somewhat
                                  inelegant, but likely cleaner than
                                  option a).<br class="">
                                </li>
                              </ul>
                            </div>
                            <div class=""><br class="">
                            </div>
                            <div class="">Does the community have any
                              strong positions on this
                              either way?</div>
                            <div class="">Francois.</div>
                          </div>
                        </div>
                      </blockquote>
                    </div>
                    <br class="">
                    <div class="">
                      <div style="word-wrap:break-word" class="">
                        <div
style="color:rgb(0,0,0);font-family:Helvetica;font-size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">--</div>
                        <div
style="color:rgb(0,0,0);font-family:Helvetica;font-size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px">Larry
                          Gritz</div>
                        <div
style="color:rgb(0,0,0);font-family:Helvetica;font-size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"><a
                            href="mailto:[email protected]" class=""
                            moz-do-not-send="true">[email protected]</a></div>
                        <div
style="color:rgb(0,0,0);font-family:Helvetica;font-size:14px;font-style:normal;font-variant-caps:normal;font-weight:normal;letter-spacing:normal;text-align:start;text-indent:0px;text-transform:none;white-space:normal;word-spacing:0px"
                          class=""><br class="">
                        </div>
                        <br class="Apple-interchange-newline">
                      </div>
                      <br class="Apple-interchange-newline">
                    </div>
                    <br class="">
                  </div>
                </div>
                _______________________________________________
                <br>
                Openexr-devel mailing list
                <br>
                <a href="mailto:[email protected]"
                  moz-do-not-send="true">[email protected]</a>
                <br>
                <a
                  href="https://lists.nongnu.org/mailman/listinfo/openexr-devel"
                  moz-do-not-send="true">https://lists.nongnu.org/mailman/listinfo/openexr-devel</a>
                <br>
              </div>
            </div>
          </span></blockquote>
      </div>
      <br>
      <fieldset class="mimeAttachmentHeader"></fieldset>
      <br>
      <pre wrap="">_______________________________________________
Openexr-devel mailing list
<a class="moz-txt-link-abbreviated" href="mailto:[email protected]">[email protected]</a>
<a class="moz-txt-link-freetext" href="https://lists.nongnu.org/mailman/listinfo/openexr-devel">https://lists.nongnu.org/mailman/listinfo/openexr-devel</a>
</pre>
    </blockquote>
    <br>
  </body>
</html>

--------------4A721025610F66FF56F9F2FF--


--===============8900523192379780968==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Openexr-devel mailing list
[email protected]
https://lists.nongnu.org/mailman/listinfo/openexr-devel

--===============8900523192379780968==--