(Some) ORM haters do get it
revision-zero.org
revision-zero.org
ORMs are powerful, because they let you say less and do more. For 90% of the queries out there, an ORM is fine.
SQL is powerful, because you can control and fine-tune your statements. For the remaining 10%, use SQL.
Are ORMs bad? No. Can you them for everything? No.
The same thing can be said for almost every technology in existence.
To me this is a bonus. The real deal is that ORMs allow you to write queries as "first-class" components of the language, hence benefiting from language features such as type checks, duck-typing, factoring, static analysis even, and more.
Compare this to stitching strings (however parametrized they are) and manually coercing your object values to strings.
This is where, IMHO, ORMs like ActiveRecord and Arel shine, as they give you access to each building block (form connection.execute to .quoted_table_name to .to_sql) so that you can place yourself at whatever level of abstraction between the two worlds you may need.
http://en.wikipedia.org/wiki/Object-relational_impedance_mis...
Still, ORM's seem to be getting better Linq to Entity Framework seems to work much better than a lot of the old ORM's I have used.
The same can be said of the goto statement, or any number of other things - used improperly, they screw up everything, but in some instances they are necessary and good.
With an ORM, no matter how much tweaking you do, it is sometimes impossible to get the performance that a well written SQL query can achieve. And that's not because of bad code, or that the ORM is a bad choice.
I have to add that this issue is much deeper than a simple efficiency issue. A perfect db with 100% availability would still not be well matched to an object system.
I listened to a podcast from 1990, the guy said "the problem with objects is that we don't know what they are". I just finished SICP, and it seems it is the same conclusion: objects with their state, their messages, their multiple parents, their instanciation, are not a proper model for many or most cases in software development.
Example of proper models include types, text files, streams (pipes), modules, maybe services.
I don't think that's true at all, as evidenced by pretty much every successful software product ever (including the early relational databases, I should add) but would be curious to see the counterargument.
The side that argues for ORM has chosen the application, the codebase, to be in charge. The central authority is the code because all the data must ultimately enter or exit through the code, and the code has more flexible abstractions and better reuse characteristics.
The reason for the disagreement comes down to disagreement about what a database is about. To the OO programmer, strong validation is part of the behavior of the objects in a system: the objects are data and behavior, so they should know what makes them valid. So the OO perspective is that the objects are reality and the database is just the persistence mechanism. It doesn't matter much to the programmer how the data is stored, it's that the data is stored, and it just happens that nowadays we use relational databases. This is the perspective that sees SQL is this annoying middle layer between the storage and the objects.
To the relational database person, the database is what is real, and the objects are mostly irrelevant. We want the database to enforce validity because there will always wind up being tools outside the OO library that need to access the database and we don't want those tools to screw up the data. To us, screwing up the data is far worse than making development a little less convenient. We see SQL not as primarily a transport between the reality of the code and some kind of storage mechanism, but rather as a general purpose data restructuring tool. Most any page on most websites can be generated with just a small handful of queries if you know how to write them to properly filter, summarize and restructure the data. We see SQL as a tremendously powerful tool for everyday tasks, not as a burdensome way of inserting and retrieving records, and not as some kind of vehicle for performance optimization.
At the end of the day, we need both perspectives. If the code is tedious and unpleasant to write, it won't be written correctly. The code must be written--the database is not the appropriate thing to be running a web server and servicing clients directly. OOP is still the dominant programming methodology, and for good reasons, but encapsulation stands at odds with proper database design. But people who ignore data validity are eventually bitten by consistency problems. OODBs have failed to take off for a variety of reasons, but one that can't be easily discounted is that they are almost always tied to one or two languages, which makes it very hard to do the kind of scripting and reporting that invariably crop up with long-lived data. What starts out as application-specific data almost invariably becomes central to the organization with many clients written in many different languages and frameworks.
We're sort of destined to hate ORM, because the people who love databases aren't going to love ORM no matter what, and people who hate databases will resent how much effort they require to use properly.
These days you just don't hear about DBAs at all any more. You used to see constant jokes about DBAs being a pain in the ass and stopping programmers doing X or Y. ORMs going to win because there aren't enough of you left. Stored procedures, triggers, etc. are going to be viewed as ancient technology back from the days of yore when people didn't understand how to code properly.
Honestly, every time I see how badly Facebook handles data and caching, I can't help but wonder why they don't use a real data store and DBAs.
(I am an engineer/developer/whatever at Facebook, and I'm always interested in hearing the perception of the company's technology from the community.)
1. I've always been under the impression that for what Facebook does, a traditional RDBMS simply cannot handle the scale (like, not even close). Is this correct?
2. I'm also under the impression that due to the architecture Facebook runs on, from time to time some lesser-important data (ie: a status update or comment) can be lost (temporarily or permanently) and this is not considered unacceptable. (It seems perfectly reasonable to me for this particular use case.)
The database is where you store your data. If you have data of which its integrity is critical to your organization, a properly designed and maintained database is going to save a lot of hastle.
I believe that databases will remain important, and maintaining data will always involve restrictions on how you can use it. Restricting data is not a relational database problem - it's more often than not a business constraint. Often times you don't want programmers doing stupid things with your data :-)
I incidentally have stopped programmers from doing X or Y, but it was because the right answer was Z.
As for ORM's winning, I don't think its a war, For some things I use and recommend ORMs, but for others I recommend using pure SQL.
You may be right about perception, but nearly every system I've worked has contained a big ugly mess somewhere because the author didn't know how to use a SQL DB properly.
I admit I have no statistics, but it's been my experience that most places choose between a highly OO model + ORM and a highly relational model without.
My experience has always been a highly relational model, ORM or not, and business rules enforced in app layer or DB (or a mix of the two). I've always seen them as distinctly different decisions.
Personally, in the past I was always a "rules in the app layer" guy, because of the many advantages of doing in that way, but as I get older the more difficult but guaranteed correctness of implementing in the database is becoming more appealing (especially if it's not me that has to actually write the code!!)
Any conformant client code then must honor these rules, and oftentimes that means it must re-implement them, which is an acceptable cost if we have decided to use an RBDMS in the first place.
Now it's true, a given database may only implement a subset of all applicable business rules--maybe some fall outside the scope of the database, maybe it's preferable to offload some to a trusted client, maybe the business and database model have drifted apart over time, and no one wan't to overhaul the database model due to all the dependencies involved.
That said, any rules that the database does implement is a good thing, especially those simple rules that can be implemented as constraints. And it's good because then you can program against them, from any client, from any code, inside the database and elsewhere, and you can make guarantees about what possible states the data could be in. This is generally a useful thing.
What matters is consistency, usability, and agility. Throwing ORMs out the window will give you as much consistency as you can squeeze out of an SQL server, but will greatly reduce your agility. Using an ORM for everything will greatly increase your agility but will reduce your usability.
As in everything, there is a balance. People who fall on either side of that balance need to back away from the pulpit and rethink their stance.
Surely this is a flawed world view!
I would probably pick the data. It's what can be monetized and it's impossible to regenerate.
Having to recreate the software might even be beneficial in the long term if your engineers are careful enough to avoid second system syndrome.
> To us, what's most important is the data, so everything else must serve that end
To you, yes, and I don't fault you for defending that perspective. But the real master who must be served is maximizing "profitability" while maintaining an acceptable level of risk.
Anyone from either side of this argument who ignores the very real advantages from the other side, or the risks from their own side, are the only ones who are totally wrong. (Which would make the author of the original article the one that is most "wrong" in this discussion, as far as I'm concerned.)
This is ideological, right? What's most important is the business. Anyone that starts from the assumption that everything, EVERYTHING, must serve the end of the data, is wrong. Right?
We can make up interesting dilemas all day. How about this one. There is an optimization that facebook can make which is shown to increase monetization by 10%, but it creates soem risk of data corruption. Engineers estimate that it will corrupt 0.01% of facebook posts. Do you choose a 10% increase in monetization, or does everything have to serve the end of data integrity?
"I don't believe in hypothetical situations" -- Kenneth the Page, 30 Rock.
Speak for yourself. I love databases (note the plural form) and love ORM. ORM is a godsend for developing application that has to work against different databases (postgresql, mssql, db2, etc).
I see ORM vs relational style as a development mindset issue. We have moved using SQLAlchemy Core (not the ORM part) and the difference in development style is stunning: now it's quite easy and more importantly FUN to write performant queries, whereas when we were using Django ORM, it was very easy to write non-performant code and tedious to make it fast.
I know, there are several valid reasons to use SQL databases as key-value storages: they are likely more robust than NoSQL dbs, there are API wrappers for most of languages, etc.
But for many interesting problem domains reporting and data aggregation is raison d'être for software and that's why I would like to see more solutions in the spirit of SQLAlchemy Core that make it easier to restructure complex queries as a reusable pieces of code, but do not force to you to step into the world of ORMs.
SQL is great for what it does, but I use ORMs for reasons other than writing queries in a different way. I inherited an utter mess of a schema that wasn't even remotely close to 1NF. Imagine fields containing comma-joined sets of values, and with column names not even remotely related to what they actually held. For legacy and business purposes, updating the schema was a non-starter.
So I used SQLAlchemy to remap the schema into something usable. I wrote getters that split out those comma-joined fields and returned the desired value against tables that required indexes like:
UPPER(SUBSTR(name_delpt,1,STRPOS(name_delpt,',')))
I wrote (and therefore more importantly _documented_) the bizarre and complex way some of the tables joined together. I wrote something that was unit-testable and that could be used as a foundation for other work so that I wouldn't have to memorize the insane corner cases and reproduce them from scratch each time I needed to access the data in some little-used table.I _didn't_ write a more convenient way to say `SELECT * FROM blog`. In general, that doesn't interest me and I wouldn't have bothered with it. ORMs are great - if used well! - for encapsulating all of the little bits of business cruft in one central, easy-to-manage place. They're handy for roughly the same reasons that subroutines are handy.
I do agree that the ORM is handy for things like "Get me all the things in this table", and "update this single record using a form", but this author is dead on. There is logical reason behind the hate developers have for ORMs.
I too would like to understand.
Sure, if you're doing a simple CMS, a simple system (even with Django Auth), Django ORM is fine
If you have anything slightly complex (several relationships between models) watch it fall apart
He points out some (well known) ways that ORM's can be used inneficiently, and acknowledges the techniques that have been developed to work around these, but then seems to conclude that he has proven once and for all that ORM's are bad. I totally missed the connection on that part. Is it that SQL is better in dealing with sets than an ORM (a fact no one denies), therefore you should not use an ORM?
What if it's better structurally for the program as a whole to think about individuals?
(This is to OP rather than you)
Well if that's the argument he's making, one example I can think of, in the case of an extremely complex update, while it always can be done in pure SQL, it is much easier to logically code using an ORM, perhaps even using individuals rather than sets (the horror). And while this implementation might execute slower (.1 second vs .01 second), it is vastly simpler to read and refactor without screwing something up (ie: economically cheaper), and as for the performance argument, it only needs to be fast enough.
In respects like that, ORM's greatest benefit is also its greatest downfall. Using an ORM means you can put people who don't have a strong grasp of databases in charge of your databases. Sadly, it also means that you've put people who don't have a strong grasp of databases in charge of your databases.
For that matter, only needing to be "fast enough" is fine if you're the only kid in the playground. That's often a safe assumption to make if you're writing app code, but less so with databases. If the database is being shared by a number of applications, or if the server is hosting multiple databases, or if you have to worry about concurrency, then being "fast enough" probably isn't enough. Because you've also got to think about all the other ways that your queries could be affecting everyone else, and making sure you aren't subjecting your server to the tragedy of the commons.
Which comes to another nice thing about having a dedicated database person. It means there's someone whose official bailiwick is the DBMS. If app A isn't experiencing any performance problems itself, but is causing performance problems for app B (say, because of some perverse locking situation), that's a bug that a DB guy is best positioned to diagnose and fix. If the application isn't too tightly coupled to the database (i.e., sprocs are in place) then he can even quietly fix it on the server side without having to hassle anyone about the application code. A team that's too ORM-reliant, on the other hand, risks failing to include anybody who's even well-equipped to recognize the problem, let alone fix it.
There is a really interesting post about how writing that code is literally stealing from your clients. I tend to agree. http://ayende.com/blog/3712/stealing-from-your-client
This is not true.
At some point, you will need to extract a subset of the relational data and represent it using your application's in-memory model. If your hand is not forced by the ORM, this is unlikely to be a direct mapping of the database.
This is no different than a network protocol, wherein the protocol is not a direct representation of application state, and the application does not attempt to model the network protocol using the same constructs that it uses to model its in-memory state.
...and that is where you have just created an ORM. You don't need a library to be using an ORM. Change 'extract' to 'map' and the meaning is the same.
Getting single row by primary key which is 90% of access is overly verbose in SQL so ORM wins.
For slightly more complicated cases SQL is much faster and easy to write so people who have to increment field in all rows that satisfy simple condition go: "ORM sucks".
But for more complicated cases like trimming data tree in some places SQL quickly becomes too much of a puzzle for most programmers to deal with so they prefer ORM again because it's doable there and most of the times works. Dedicated SQL users who are not good at puzzles in such cases write full fledged program (if their SQL dialect allows for that) and instead of bringing data to their iterative or recursive programs they bring their programs to the data which creates hard to debug, unreadable often unversionable monstrosities.
There should be some merge between databases and programming languages that could combine beauty of syntax of modern programming languages and efficiency of massive data handling of modern databases.
Why is it ok to have standard hashmap implementation in a language but not file backed hashmap or btree index?
The real "problem" with ORM is when people use such tools as a way of avoiding having to understand databases (and specifically SQL). Fortunately that's becoming less common at least within the Enterprise Java world where I live and breath.
Sure, the apps I'm writing are for small-medium business, but XPO 'just works'. Context is important; if I was working on something with more users / tighter speed requirements, an ORM may or may not be the best choice. Still, this falls into the 'right tool for the job' category that good developers are already aware of.
Save methods which runs insert or updates. GetAll methods get_by_username, get_by_id, get_by_email, get_recent, get_by_foreign_keyed_object, get_by_other_foreign_keyed_object.
And all those hand coded methods directly tied to the dialect of the db the original developer used.
Using Hibernate I had to write raw SQL for some reporting. I've never written raw SQL in Django (the project I've used django on self select for simplicity).
And using SqlAlchemy/Twisted as a backend for a desktop application I haven't found a need yet, for performance or correctness. I have one query I'm eyeing for an SQL rewrite, but it'll probably be a week of work to make sure it works correctly and I'd rather release this phase than save 30 seconds on a weekly query.
I've reached a point where ORM complaints don't really make all that much sense. The issue seems to be "THe ORM breaks down doing X and Y and Z so I had to hand write SQL!"
But you'd be writing X Y and Z anyway if you weren't using an ORM, so what's the issue?
I've never encountered in real life, or during any online discussion, the all-or-nothing sentiment from advocates of ORM.
Could you link to anything online where an ORM advocate argues that you should never drop down to raw SQL?
I've met developers who can happily (and effectively) work with an ORM but hardly even know SQL! They certainly don't know SQL well enough to use it in the situations were it would be most effective.
I'm starting to feel like really effective set-based understanding of SQL is becoming sort of a lost art.
Will there be downsides one day? Probably. Will they come even close to the business value of the amount of the coding time we've saved during the critical bootstrap phase? No way in hell. As they say, those are problems I'd love to have.
Go RBAR when it doesn't matter - when it's convenient and you know how it is going to scale ahead of time. A user updating his profile. Creating an order.
Go set based the rest of the time - when you're processing a large batch of data for thousands of user accounts, offload that work into a stored procedure and call it.
ORM does exactly what it is meant to do, and if you're working with data in an OO model, you're going to be doing ORM, whether you know it or not - you will either pull a decent ORM tool off the shelf, or you WILL be writing your own very bad one.
Your average Java programmer is used to iterating over collections in a while loop, where 30,000 in-memory objects can be quickly modified. It's tempting for said programmer to do the same to ORM-backed objects and issue 30,000 sql update statements across the wire.
But this article is a breath of fresh air. I may just try Dapper for the next project
For a long time I was on the side of the ORM haters, until I tried SQLAlchemy - it truly is an awesome ORM package and I have yet to find anything like it in PHP/Ruby/etc...
i.e. if you have to write your code in a specific way to make the ORM behave correctly (constantly thinking about what kind of sql your code is generating), then the abstraction becomes a lot less useful.
As a result, huge investments were made in advancing relational databases, and other forms have languished. Today, relational maintains the substantial advantages of maturity and installed base. Performance, reliability, general polish, ease of access to support/tutorials/other literature, and general status as "the way things are done".
If you're going to use an ORM then you absolutely have to learn the mechanics to avoid n+1 queries. Every ORM is a little different, some are easier to tune than others.
I personally favor a basic mapping that the ORM does automatically combined with an advanced mapping that allows you to basically write queries for special purposes and map them to transient objects that don't necessarily exist in your schema. You have to do this for things like aggregate queries or calls that require several joins but only need a couple of columns from each table.
The OP raises some good points but I do think that ORMs can be used properly to great effect.
Do other fields get into constant pissing matches like this? Languages, libraries, process, licenses, editors, Operating systems, you name it, software engineers are fighting about how much better theirs is and how you are an idiot for not seeing the true light their vast intelligence is trying to bequeath unto you.
What is it about our brains that makes the subtlety of "use the right tool; every problem isn't a nail" so difficult? Or is it just hard wired into our need to be identified with a community?
On the other hand if somehow ORM was part of the core compiler AND database, then somehow it could be possible that even when you write a for loop on the top and have an if conditions inside the block, or perform a join, the compiler understands it and pre-compiles your code without needing such workarounds (as there aren't two separate layers to join). So you would treat objects and objects and never have to worry about how the wrapper is being generated or what kind of indexes or queries it will run finally. I'm not an expert at compilers though but for strictly typed languages it could be possible.
Apparently, Postgres has a genetic optimizer that handles this... curious to see if this is an issue or not.
Incidentally, I'd like to say that I loved the author's Relational Basics II at http://www.revision-zero.org/relational-basics-2 I've come to the conclusion that SQL is particularly limited in its application and implementation. I'd love to see a better declarative language for databases!
These days, we have languages which integrate rather nicely into the declarative mindset, so no need anymore for such bizarre "paradigm translators".