Modified: web/php/trunk/ChangeLog-5.php
===================================================================
--- web/php/trunk/ChangeLog-5.php 2010-03-04 14:20:38 UTC (rev 295823)
+++ web/php/trunk/ChangeLog-5.php 2010-03-04 16:23:16 UTC (rev 295824)
@@ -13,6 +13,170 @@
+
+Version 5.3.2
+04-March-2010
+
+Security Fixes
+
+ Improved LCG entropy. (Rasmus, Samy Kamkar)
+ Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)
+ Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)
+
+
+
+
+Upgraded bundled sqlite to version 3.6.22. (Ilia)
+Upgraded bundled libmagic to version 5.03. (Mikko)
+Upgraded bundled PCRE to version 8.00. (Scott)
+Updated timezone database to version 2010.3. (Derick)
+
+Improved LCG entropy. (Rasmus, Samy Kamkar)
+Improved crypt support for edge cases (UFC compatibility). (Solar Designer, Joey, Pierre)
+
+Changed gmp_strval() to use full range from 2 to 62, and -2 to -36. FR (David Soria Parra)
+Changed "post_max_size" php.ini directive to allow unlimited post size by setting it to 0. (Rasmus)
+Changed tidyNode class to disallow manual node creation. (Pierrick)
+
+Removed automatic file descriptor unlocking happening on shutdown and/or stream close (on all OSes). (Tony, Ilia)
+
+Added libpng 1.4.0 support. (Pierre)
+Added support for DISABLE_AUTHENTICATOR for imap_open. (Pierre)
+Added missing host validation for HTTP urls inside FILTER_VALIDATE_URL. (Ilia)
+Added stream_resolve_include_path(). (Mikko)
+Added INTERNALDATE support to imap_append. (nick at mailtrust dot com)
+Added support for SHA-256 and SHA-512 to php's crypt. (Pierre)
+Added realpath_cache_size() and realpath_cache_get() functions. (Stas)
+Added FILTER_FLAG_STRIP_BACKTICK option to the filter extension. (Ilia)
+Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check. (Stas)
+Added LIBXML_PARSEHUGE constant to override the maximum text size of a single text node when using libxml2.7.3+. (Kalle)
+Added ReflectionMethod::setAccessible() for invoking non-public methods through the Reflection API. (Sebastian)
+Added Collator::getSortKey for intl extension. (Stas)
+Added support for CURLOPT_POSTREDIR. FR . (Sriram Natarajan)
+Added support for CURLOPT_CERTINFO. FR . (Linus Nielsen Feltzing )
+Added client-side server name indication support in openssl. (Arnaud)
+
+Improved fix for bug #50006 (Segfault caused by uksort()). (Stas)
+
+Fixed mysqlnd hang when queries exactly 16777214 bytes long are sent. (Andrey)
+Fixed incorrect decoding of 5-byte BIT sequences in mysqlnd. (Andrey)
+Fixed error_log() to be binary safe when using message_type 3. (Jani)
+Fixed unnecessary invocation of setitimer when timeouts have been disabled. (Arvind Srinivasan)
+Fixed memory leak in extension loading when an error occurs on Windows. (Pierre)
+Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)
+Fixed a possible open_basedir/safe_mode bypass in session extension identified by Grzegorz Stachowiak. (Ilia)
+Fixed possible crash when a error/warning is raised during php startup. (Pierre)
+Fixed possible bad behavior of rename on windows when used with symbolic links or invalid paths. (Pierre)
+Fixed error output to stderr on Windows. (Pierre)
+Fixed memory leaks in is_writable/readable/etc on Windows. (Pierre)
+Fixed memory leaks in the ACL function on Windows. (Pierre)
+Fixed memory leak in the realpath cache on Windows. (Pierre)
+Fixed memory leak in zip_close. (Pierre)
+Fixed crypt's blowfish sanity check of the "setting" string, to reject iteration counts encoded as 36 through 39. (Solar Designer, Joey, Pierre)
+
+ (crypt crashes when invalid salt are given). (Pierre)
+ (allow underscore _ in constants parsed in php.ini files). (Jani)
+ (Custom content-length set incorrectly in Apache SAPIs). (Brian France, Rasmus)
+ (Wrong date by php_date.c patch with ancient gcc/glibc versions). (Derick)
+ (X-PHP-Originating-Script adding two new lines in *NIX). (Ilia)
+ (build fails with openssl 1.0 due to md2 deprecation). (Ilia, hanno at hboeck dot de)
+ (strip_tags() removes all tags greater then 1023 bytes long). (Ilia)
+ (php.ini directive pdo_mysql.default_socket is ignored). (Ilia)
+ (HTTP fopen wrapper does not support passwordless HTTP authentication). (Jani)
+ (stream_set_write_buffer() has no effect on socket streams). (vnegrier at optilian dot com, Ilia)
+ (system.multiCall crashes in xmlrpc extension). (hiroaki dot kawai at gmail dot com, Ilia)
+ (CURLOPT_FTP_SKIP_PASV_IP does not exist). (Sriram)
+ (exec() adds single byte twice to $output array). (Ilia)
+ (All PDOExceptions hardcode 'code' property to 0). (Joey, Ilia)
+ (Bug in garbage collector causes crash). (Dmitry)
+ (putenv does not set ENV when the value is only one char). (Pierre)
+ (strtotime() does not support eighth ordinal number). (Ilia)
+ (DOMDocument::loadXML does not allow UTF-16). (Rob)
+ (copy() with an empty (zero-byte) HTTP source succeeds but returns false). (Ilia)
+ (filter_input() does not return default value if the variable does not exist). (Ilia)
+ (XML_OPTION_SKIP_TAGSTART option has no effect). (Pierrick)
+ (Broken object model when extending tidy). (Pierrick)
+ (Crash while running ldap_next_reference test cases). (Sriram)
+ (segfault in garbage collection when using set_error_handler and DomDocument). (Dmitry)
+ (compile failure: Conflicting HEADER type declarations). (Jani)
+ (Use of <stdbool.h> is valid only in a c99 compilation environment. (Sriram)
+ (declare encoding doesn't work within an included file). (Felipe)
+ (PDO::FETCH_FUNC fails with Closures). (Felipe, Pierrick)
+ (PDO-ODBC stored procedure call from Solaris 64-bit causes seg fault). (davbrown4 at yahoo dot com, Felipe)
+ (PROCEDURE db.myproc can't return a result set in the given context). (Andrey)
+ (Reference argument converted to value in __call). (Stas)
+ (performance regression handling objects, ten times slowerin 5.3 than in 5.2). (Dmitry)
+ (date_create_from_format() enforces 6 digits for 'u' format character). (Ilia)
+ (nanosleep not detected properly on some solaris versions). (Jani)
+ (php.ini parser does not allow spaces in ini keys). (Jani)
+ (crypt ignores sha512 prefix). (Pierre)
+ (Allow use of ; in values via ;; in PDO DSN). (Ilia, Pierrick)
+ (xmlrpc does not preserve keys in encoded indexed arrays). (Felipe)
+ (xmlrpc_encode_request() changes object into array in calling function). (Felipe)
+ (get_browser(null) does not use HTTP_USER_AGENT). (Jani)
+ (conflicting types for llabs). (Jani)
+ (Crash When Calling Parent Constructor with call_user_func()). (Dmitry)
+ (isset() and empty() silently casts array to object). (Felipe)
+ (pdo_mysql.default_socket in php.ini shouldn't used if it is empty). (foutrelis at gmail dot com, Ilia)
+ (Socket path passed using --with-mysql-sock is ignored when mysqlnd is enabled). (Jani)
+ (soap call Segmentation fault on a redirected url). (Pierrick)
+ (crash by ldap_get_option() with LDAP_OPT_NETWORK_TIMEOUT). (Ilia, shigeru_kitazaki at cybozu dot co dot jp)
+ (Compiling with libedit cannot find readline.h). (tcallawa at redhat dot com)
+ (segmentation fault when concatenating very large strings on 64bit linux). (Ilia)
+ (stream_copy_to_stream() produces warning when source is not file). (Stas)
+ (pg_copy_to() fails when table name contains schema. (Ilia)
+ (ldap_get_entries() return false instead of an empty array when there is no error). (Jani)
+ (Incorrectly matched docComment). (Felipe)
+ (FastCGI fails with wrong error on HEAD request to non-existant file). (Dmitry)
+ (Memory leak when fetching timestamp column from Oracle database). (Felipe)
+ (wrong working directory in symlinked files). (Dmitry)
+ (FILTER_VALIDATE_EMAIL fails with valid addresses containing = or ?). (Pierrick)
+ (ReflectionClass::hasProperty behaves like isset() not property_exists). (Felipe)
+ (property_exists: Closure object cannot have properties). (Felipe)
+ (crash while running bug35634.phpt). (Felipe)
+ (With default compilation option, php symbols are unresolved for nsapi). (Uwe Schindler)
+ (NSAPI performance improvements). (Uwe Schindler)
+ (parse_url() incorrect when ? in fragment). (Ilia)
+ (pdo_mysql doesn't use PHP_MYSQL_UNIX_SOCK_ADDR). (Ilia)
+ (Throwing through Reflection modified Exception object makes segmentation fault). (Felipe)
+ (SNMP3 warning message about security level printed twice). (Jani)
+ (pdo_pgsql prepare() re-use previous aborted transaction). (ben dot pineau at gmail dot com, Ilia, Matteo)
+ (Phar::isBuffering() returns inverted value). (Greg)
+ (crash with ftp stream in php_stream_context_get_option()). (Pierrick)
+ (Curl post upload functions changed). (Ilia)
+ (Making reference on string offsets crashes PHP). (Dmitry)
+ (import_request_variables() always returns NULL). (Ilia, sjoerd at php dot net)
+, #50451 (http wrapper breaks on 1024 char long headers). (Ilia)
+ (SimpleXML allow (un)serialize() calls without warning). (Ilia, wmeler at wp-sa dot pl)
+ (ReflectionClass::hasProperty returns true for a private property in base class). (Felipe)
+ (ini parser crashes with apache2 and using ${something} ini variables). (Jani)
+ (libxml 2.7.3+ limits text nodes to 10MB). (Felipe)
+ (DOMUserData does not exist). (Rob)
+ (imageTTFText text shifted right). (Takeshi Abe)
+ (date_format buffer not long enough for >4 digit years). (Derick, Adam)
+ (oci8: using LOBs causes slow PHP shutdown). (Oracle Corp.)
+ (PDO fetchObject sets values before calling constructor). (Pierrick)
+ (Constants defined in Interfaces can be overridden). (Felipe)
+ (setAttributeNS fails setting default namespace). (Rob)
+ (Floating point NaN cause garbage characters). (Sjoerd)
+ (Compile error due to old DNS functions on AIX systems). (Scott)
+ (crash when extending PDOStatement and trying to set queryString property). (Felipe)
+ (Directives in PATH section do not get applied to subdirectories). (Patch by: ct at swin dot edu dot au)
+ (SoapClient does not honor max_redirects). (Sriram)
+ (Content-type parameter "boundary" is not case-insensitive in HTTP uploads). (Ilia)
+ (importNode doesn't preserve attribute namespaces). (Rob)
+ (extract() problem with array containing word "this"). (Ilia, chrisstocktonaz at gmail dot com)
+ ($php_errormsg is limited in size of characters) (Oracle Corp.)
+ (htmlentities() uses obsolete mapping table for character entity references). (Moriyoshi)
+ (strip_tags() truncates rest of string with invalid attribute). (Ilia, hradtke)
+ (PDOStatement->execute() returns true then false for same statement). (Pierrick)
+ (define() allows :: in constant names). (Ilia)
+ (imap_utf8() returns only capital letters). (steffen at dislabs dot de, Pierre)
+ (Failure in odbc_exec() using oracle-supplied odbc driver). (tim dot tassonis at trivadis dot com)
+
+
+
+
Version 5.2.13
25-February-2010
Modified: web/php/trunk/archive/archive.xml
===================================================================
--- web/php/trunk/archive/archive.xml 2010-03-04 14:20:38 UTC (rev 295823)
+++ web/php/trunk/archive/archive.xml 2010-03-04 16:23:16 UTC (rev 295824)
@@ -9,6 +9,7 @@
http://php.net/contact
php-webmaster@lists.php.net
+
Added: web/php/trunk/archive/entries/2010-03-04-1.xml
===================================================================
--- web/php/trunk/archive/entries/2010-03-04-1.xml (rev 0)
+++ web/php/trunk/archive/entries/2010-03-04-1.xml 2010-03-04 16:23:16 UTC (rev 295824)
@@ -0,0 +1,59 @@
+
+
+ PHP 5.3.2 Release Announcement
+ http://www.php.net/archive/2010.php#id2010-03-04-1
+ 2010-03-04T14:57:33+00:00
+ 2010-03-04T14:57:33+00:00
+
+
+
+
+
+
+
+ The PHP development team is proud to announce the immediate release of PHP
+ 5.3.2. This is a maintenance release in the 5.3 series, which includes a
+ large number of bug fixes.
+
+
+
+ Security Enhancements and Fixes in PHP 5.3.2:
+
+
+ Improved LCG entropy. (Rasmus, Samy Kamkar)
+ Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)
+ Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)
+
+
+
+ Key Bug Fixes in PHP 5.3.2 include:
+
+
+ Added support for SHA-256 and SHA-512 to php's crypt.
+ Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check.
+ Fixed bug #51059 (crypt crashes when invalid salt are given).
+ Fixed bug #50940 Custom content-length set incorrectly in Apache sapis.
+ Fixed bug #50847 (strip_tags() removes all tags greater then 1023 bytes long).
+ Fixed bug #50723 (Bug in garbage collector causes crash).
+ Fixed bug #50661 (DOMDocument::loadXML does not allow UTF-16).
+ Fixed bug #50632 (filter_input() does not return default value if the variable does not exist).
+ Fixed bug #50540 (Crash while running ldap_next_reference test
+ cases).
+ Fixed bug #49851 (http wrapper breaks on 1024 char long headers).
+ Over 60 other bug fixes.
+
+
+
+ For users upgrading from PHP 5.2 there is a migration guide
+ available here , detailing
+ the changes between those releases and PHP 5.3.
+
+
+
+ For a full list of changes in PHP 5.3.2, see the
+ ChangeLog .
+
+
+
+
+
Modified: web/php/trunk/include/releases.inc
===================================================================
--- web/php/trunk/include/releases.inc 2010-03-04 14:20:38 UTC (rev 295823)
+++ web/php/trunk/include/releases.inc 2010-03-04 16:23:16 UTC (rev 295824)
@@ -2,6 +2,32 @@
$OLDRELEASES = array (
5 =>
array (
+ '5.3.1' =>
+ array (
+ 'announcement' =>
+ array (
+ 'English' => '/releases/5_3_1.php',
+ ),
+ 'source' =>
+ array (
+ 0 =>
+ array (
+ 'filename' => 'php-5.3.1.tar.bz2',
+ 'name' => 'PHP 5.3.1 (tar.bz2)',
+ 'md5' => '63e97ad450f0f7259e785100b634c797',
+ 'date' => '19 Nov 2009',
+ ),
+ 1 =>
+ array (
+ 'filename' => 'php-5.3.1.tar.gz',
+ 'name' => 'PHP 5.3.1 (tar.gz)',
+ 'md5' => '41fbb368d86acb13fc3519657d277681',
+ 'date' => '19 Nov 2009',
+ ),
+ ),
+ 'date' => NULL,
+ 'museum' => false,
+ ),
'5.2.12' =>
array (
'announcement' =>
Modified: web/php/trunk/include/version.inc
===================================================================
--- web/php/trunk/include/version.inc 2010-03-04 14:20:38 UTC (rev 295823)
+++ web/php/trunk/include/version.inc 2010-03-04 16:23:16 UTC (rev 295824)
@@ -17,15 +17,15 @@
*/
/* PHP 5.3 Release */
-$PHP_5_3_RC = '5.3.2RC3'; /* false; */
+$PHP_5_3_RC = false; /* '5.3.2RC3'; */
$PHP_5_3_RC_DATE = "23 Feb 2010";
-$PHP_5_3_VERSION = "5.3.1";
-$PHP_5_3_DATE = "19 Nov 2009";
+$PHP_5_3_VERSION = "5.3.2";
+$PHP_5_3_DATE = "04 Mar 2010";
$PHP_5_3_MD5 = array(
- "tar.bz2" => "63e97ad450f0f7259e785100b634c797",
- "tar.gz" => "41fbb368d86acb13fc3519657d277681",
+ "tar.bz2" => "46f500816125202c48a458d0133254a4",
+ "tar.gz" => "4480d7c6d6b4a86de7b8ec8f0c2d1871",
);
/* PHP 5.2 Release */
Added: web/php/trunk/releases/5_3_2.php
===================================================================
--- web/php/trunk/releases/5_3_2.php (rev 0)
+++ web/php/trunk/releases/5_3_2.php 2010-03-04 16:23:16 UTC (rev 295824)
@@ -0,0 +1,53 @@
+
+
+PHP 5.3.2 Release Announcement
+
+The PHP development team is proud to announce the immediate release of PHP
+5.3.2. This is a maintenance release in the 5.3 series, which includes a
+large number of bug fixes.
+
+
+
+Security Enhancements and Fixes in PHP 5.3.2:
+
+
+ Improved LCG entropy. (Rasmus, Samy Kamkar)
+ Fixed safe_mode validation inside tempnam() when the directory path does not end with a /). (Martin Jansen)
+ Fixed a possible open_basedir/safe_mode bypass in the session extension identified by Grzegorz Stachowiak. (Ilia)
+
+
+
+Key Bug Fixes in PHP 5.3.2 include:
+
+
+ Added support for SHA-256 and SHA-512 to php's crypt.
+ Added protection for $_SESSION from interrupt corruption and improved "session.save_path" check.
+ Fixed bug #51059 (crypt crashes when invalid salt are given).
+ Fixed bug #50940 Custom content-length set incorrectly in Apache sapis.
+ Fixed bug #50847 (strip_tags() removes all tags greater then 1023 bytes long).
+ Fixed bug #50723 (Bug in garbage collector causes crash).
+ Fixed bug #50661 (DOMDocument::loadXML does not allow UTF-16).
+ Fixed bug #50632 (filter_input() does not return default value if the variable does not exist).
+ Fixed bug #50540 (Crash while running ldap_next_reference test
+cases).
+ Fixed bug #49851 (http wrapper breaks on 1024 char long headers).
+ Over 60 other bug fixes.
+
+
+
+For users upgrading from PHP 5.2 there is a migration guide
+available here , detailing
+the changes between those releases and PHP 5.3.
+
+
+
+ For a full list of changes in PHP 5.3.2, see the
+ ChangeLog .
+
+
+