Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 1 | # Maintained branches |
| 2 | |
| 3 | At any point in time, we have a number of maintained branches consisting of: |
| 4 | |
Gilles Peskine | 991bbe7 | 2021-03-16 12:05:16 +0100 | [diff] [blame] | 5 | - The [`master`](https://github.com/ARMmbed/mbedtls/tree/master) branch: |
| 6 | this always contains the latest release, including all publicly available |
| 7 | security fixes. |
Gilles Peskine | a23df13 | 2021-03-16 12:04:44 +0100 | [diff] [blame] | 8 | - The [`development`](https://github.com/ARMmbed/mbedtls/tree/development) branch: |
Dave Rodgman | 1bc9e93 | 2021-07-01 09:20:13 +0100 | [diff] [blame^] | 9 | this is where the current major version of Mbed TLS (version 3.x) is being |
Dave Rodgman | a00e850 | 2021-04-23 16:43:13 +0100 | [diff] [blame] | 10 | prepared. It has API changes that make it incompatible with Mbed TLS 2.x, |
| 11 | as well as all the new features and bug fixes and security fixes. |
| 12 | - The [`development_2.x`](https://github.com/ARMmbed/mbedtls/tree/development_2.x) branch: |
| 13 | this branch retains the API of Mbed TLS 2.x, and has a subset of the |
| 14 | features added after Mbed TLS 2.26.0 and bug fixes and security fixes. |
Gilles Peskine | a23df13 | 2021-03-16 12:04:44 +0100 | [diff] [blame] | 15 | - One or more long-time support (LTS) branches: |
| 16 | these only get bug fixes and security fixes. |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 17 | |
| 18 | We use [Semantic Versioning](https://semver.org/). In particular, we maintain |
Gilles Peskine | 73876cf | 2021-06-08 15:33:53 +0200 | [diff] [blame] | 19 | API compatibility in the `master` branch across minor version changes (e.g. |
| 20 | the API of 3.(x+1) is backward compatible with 3.x). We only break API |
| 21 | compatibility on major version changes (e.g. from 3.x to 4.0). We also maintain |
| 22 | ABI compatibility within LTS branches; see the next section for details. |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 23 | |
| 24 | ## Backwards Compatibility |
| 25 | |
Gilles Peskine | a23df13 | 2021-03-16 12:04:44 +0100 | [diff] [blame] | 26 | We maintain API compatibility in released versions of Mbed TLS. If you have |
| 27 | code that's working and secure with Mbed TLS x.y.z and does not rely on |
| 28 | undocumented features, then you should be able to re-compile it without |
| 29 | modification with any later release x.y'.z' with the same major version |
| 30 | number, and your code will still build, be secure, and work. |
| 31 | |
Gilles Peskine | 6dd92c3 | 2021-06-07 20:44:47 +0200 | [diff] [blame] | 32 | Note that new releases of Mbed TLS may extend the API. Here are some |
| 33 | examples of changes that are common in minor releases of Mbed TLS, and are |
| 34 | not considered API compatibility breaks: |
Gilles Peskine | 1483fe4 | 2021-06-01 22:29:06 +0200 | [diff] [blame] | 35 | |
| 36 | * Adding or reordering fields in a structure or union. |
| 37 | * Removing a field from a structure, unless the field is documented as public. |
| 38 | * Adding items to an enum. |
Gilles Peskine | 6dd92c3 | 2021-06-07 20:44:47 +0200 | [diff] [blame] | 39 | * Returning an error code that was not previously documented for a function |
| 40 | when a new error condition arises. |
| 41 | * Changing which error code is returned in a case where multiple error |
| 42 | conditions apply. |
| 43 | * Changing the behavior of a function from failing to succeeding, when the |
| 44 | change is a reasonable extension of the current behavior, i.e. the |
| 45 | addition of a new feature. |
Gilles Peskine | 1483fe4 | 2021-06-01 22:29:06 +0200 | [diff] [blame] | 46 | |
Gilles Peskine | d1a8cd5 | 2021-06-07 20:42:40 +0200 | [diff] [blame] | 47 | There are rare exceptions where we break API compatibility: code that was |
| 48 | relying on something that became insecure in the meantime (for example, |
| 49 | crypto that was found to be weak) may need to be changed. In case security |
| 50 | comes in conflict with backwards compatibility, we will put security first, |
| 51 | but always attempt to provide a compatibility option. |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 52 | |
Gilles Peskine | 87d36e3 | 2021-06-07 20:42:50 +0200 | [diff] [blame] | 53 | ## Long-time support branches |
| 54 | |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 55 | For the LTS branches, additionally we try very hard to also maintain ABI |
| 56 | compatibility (same definition as API except with re-linking instead of |
| 57 | re-compiling) and to avoid any increase in code size or RAM usage, or in the |
| 58 | minimum version of tools needed to build the code. The only exception, as |
| 59 | before, is in case those goals would conflict with fixing a security issue, we |
| 60 | will put security first but provide a compatibility option. (So far we never |
| 61 | had to break ABI compatibility in an LTS branch, but we occasionally had to |
| 62 | increase code size for a security fix.) |
| 63 | |
Manuel Pégourié-Gonnard | 80c02af | 2021-02-25 12:34:58 +0100 | [diff] [blame] | 64 | For contributors, see the [Backwards Compatibility section of |
| 65 | CONTRIBUTING](CONTRIBUTING.md#cackwords-compatibility). |
| 66 | |
| 67 | ## Current Branches |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 68 | |
| 69 | The following branches are currently maintained: |
| 70 | |
Gilles Peskine | 991bbe7 | 2021-03-16 12:05:16 +0100 | [diff] [blame] | 71 | - [master](https://github.com/ARMmbed/mbedtls/tree/master) |
Gilles Peskine | a23df13 | 2021-03-16 12:04:44 +0100 | [diff] [blame] | 72 | - [`development`](https://github.com/ARMmbed/mbedtls/) |
Dave Rodgman | a00e850 | 2021-04-23 16:43:13 +0100 | [diff] [blame] | 73 | - [`development_2.x`](https://github.com/ARMmbed/mbedtls/tree/development_2.x) |
Gilles Peskine | a23df13 | 2021-03-16 12:04:44 +0100 | [diff] [blame] | 74 | - [`mbedtls-2.16`](https://github.com/ARMmbed/mbedtls/tree/mbedtls-2.16) |
Manuel Pégourié-Gonnard | 80c02af | 2021-02-25 12:34:58 +0100 | [diff] [blame] | 75 | maintained until at least the end of 2021, see |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 76 | <https://tls.mbed.org/tech-updates/blog/announcing-lts-branch-mbedtls-2.16> |
Manuel Pégourié-Gonnard | e699739 | 2021-02-25 11:40:08 +0100 | [diff] [blame] | 77 | |
| 78 | Users are urged to always use the latest version of a maintained branch. |