Received: from malur.postgresql.org ([217.196.149.56]) by arkaria.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1oYh8p-000665-UO for pgsql-hackers@arkaria.postgresql.org; Thu, 15 Sep 2022 05:10:23 +0000 Received: from localhost ([127.0.0.1] helo=malur.postgresql.org) by malur.postgresql.org with esmtp (Exim 4.92) (envelope-from ) id 1oYh8o-0008Vx-P1 for pgsql-hackers@arkaria.postgresql.org; Thu, 15 Sep 2022 05:10:22 +0000 Received: from makus.postgresql.org ([2001:4800:3e1:1::229]) by malur.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1oYh8o-0008Vo-G9 for pgsql-hackers@lists.postgresql.org; Thu, 15 Sep 2022 05:10:22 +0000 Received: from sss.pgh.pa.us ([66.207.139.130]) by makus.postgresql.org with esmtps (TLS1.3:ECDHE_RSA_AES_256_GCM_SHA384:256) (Exim 4.92) (envelope-from ) id 1oYh8m-000646-7Z for pgsql-hackers@postgresql.org; Thu, 15 Sep 2022 05:10:21 +0000 Received: from sss1.sss.pgh.pa.us (localhost [127.0.0.1]) by sss.pgh.pa.us (8.15.2/8.15.2) with ESMTP id 28F5AG1Q3129310; Thu, 15 Sep 2022 01:10:16 -0400 From: Tom Lane To: Andres Freund cc: Thomas Munro , Peter Eisentraut , samay sharma , Nazir Bilal Yavuz , pgsql-hackers@postgresql.org Subject: Re: [RFC] building postgres with meson - v13 In-reply-to: <20220915022626.5xx3ccgkzpkqw5mq@awork3.anarazel.de> References: <20211012083721.hvixq4pnh2pixr3j@alap3.anarazel.de> <20220915022626.5xx3ccgkzpkqw5mq@awork3.anarazel.de> Comments: In-reply-to Andres Freund message dated "Wed, 14 Sep 2022 19:26:26 -0700" MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-ID: <3129308.1663218616.1@sss.pgh.pa.us> Date: Thu, 15 Sep 2022 01:10:16 -0400 Message-ID: <3129309.1663218616@sss.pgh.pa.us> List-Id: List-Help: List-Subscribe: List-Post: List-Owner: List-Archive: Archived-At: Precedence: bulk Andres Freund writes: > I'm inclined to build the static lib on windows as long as we do it on other > platforms. Maybe I spent too much time working for Red Hat, but I'm kind of unhappy that we build static libraries at all. They are maintenance hazards and therefore security hazards by definition, because if you find a problem in $package_x you will have to find and rebuild every other package that has statically-embedded code from $package_x. So Red Hat has, or least had, a policy against packages exporting such libraries. I realize that there are people for whom other considerations outweigh that, but I don't think that we should install static libraries by default. Long ago it was pretty common for configure scripts to offer --enable-shared and --enable-static options ... should we resurrect that? regards, tom lane