Bug #77363 [Com]: bundled libraries are always outdated

From: Date: Fri, 28 Dec 2018 15:54:44 +0000
Subject: Bug #77363 [Com]: bundled libraries are always outdated
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218661@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77363&edit=1 ID: 77363 Comment by: spam2 at rhsoft dot net Reported by: spam2 at rhsoft dot net Summary: bundled libraries are always outdated Status: Feedback Type: Bug Package: *General Issues PHP Version: Irrelevant Block user comment: N Private report: N New Comment: i just use Fedora over 12 years and for 10 years in production following changelogs in libraries closely and was surprised to find the year 2017 when building with the bundled one imho at least once per year there should happen a rebase, the majority of userbase has no chance to track down whatever issues root cause and i don#t get "stability risks" which would only point out demand for additional tests which should have been there anyways but then the test-suite suffers from enough bigger issues starting by more and more stuff ignores environment and the supplied "php.ini" loading the system extensions instead the fresh built ones making a lot of test completly pointless and only get covered when you fire up a rpmbuild for 7.3 on a system where 7.2 is installed Previous Comments: ------------------------------------------------------------------------ [2018-12-28 15:47:33] nikic@php.net Distributions do face stability risks. That's why distributions commonly do not update libraries wholesale, but instead backport fixes that they consider worthwhile (often only security fixes or issues specifically reported to them) on a case-by-case basis. Of course this depends on the distribution, it's general update policies and package-specific update policies. Which is why I'm asking whether there are any specific issues you have in mind here that might make a backport necessary. ------------------------------------------------------------------------ [2018-12-28 15:26:22] spam2 at rhsoft dot net let me word it differently: if there are no issues why does upstream bother with bugfix releases? when updates would carry *serious* stability risks how comes that all the distributions downstream don't face them? ------------------------------------------------------------------------ [2018-12-28 15:21:57] nikic@php.net Are there any *particular* issues that you are experiencing? We generally do not update bundled libraries on stable versions unless there is a specific reason to do so, as such updates carry stability risks. Of course we also prefer not to bundle libraries, e.g. in PHP 7.4 libsqlite and libzip will be removed from our distribution. There are currently no plans to remove the bundled libpcre though. ------------------------------------------------------------------------ [2018-12-28 13:40:02] spam2 at rhsoft dot net Description: ------------ following https://bugs.php.net/bug.php?id=77349 and "If there are bugs which affect our PCRE binding, yes. However, in my opinion, this should be filed as separate issue" it's not only about pcre it's a general thing - there is nothing like "if there are bugs which affect our PCRE binding" - bugs in a library affect PHP and the users of PHP one thing are security bugs like https://www.cvedetails.com/vulnerability-list/vendor_id-3265/opdos-1/Pcre.html but that is only part of the story ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77363&edit=1

« previous php.bugs (#218661) next »