Bug #77363 [Com]: bundled libraries are always outdated
| From: | spam2 at rhsoft dot net | Date: | Fri, 28 Dec 2018 15:54:44 +0000 |
| Subject: | Bug #77363 [Com]: bundled libraries are always outdated | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-218661@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77363&edit=1
ID: 77363
Comment by: spam2 at rhsoft dot net
Reported by: spam2 at rhsoft dot net
Summary: bundled libraries are always outdated
Status: Feedback
Type: Bug
Package: *General Issues
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
i just use Fedora over 12 years and for 10 years in production following changelogs in libraries
closely and was surprised to find the year 2017 when building with the bundled one
imho at least once per year there should happen a rebase, the majority of userbase has no chance to
track down whatever issues root cause and i don#t get "stability risks" which would only
point out demand for additional tests which should have been there anyways
but then the test-suite suffers from enough bigger issues starting by more and more stuff ignores
environment and the supplied "php.ini" loading the system extensions instead the fresh
built ones making a lot of test completly pointless and only get covered when you fire up a rpmbuild
for 7.3 on a system where 7.2 is installed
Previous Comments:
------------------------------------------------------------------------
[2018-12-28 15:47:33] nikic@php.net
Distributions do face stability risks. That's why distributions commonly do not update
libraries wholesale, but instead backport fixes that they consider worthwhile (often only security
fixes or issues specifically reported to them) on a case-by-case basis. Of course this depends on
the distribution, it's general update policies and package-specific update policies.
Which is why I'm asking whether there are any specific issues you have in mind here that might
make a backport necessary.
------------------------------------------------------------------------
[2018-12-28 15:26:22] spam2 at rhsoft dot net
let me word it differently: if there are no issues why does upstream bother with bugfix releases?
when updates would carry *serious* stability risks how comes that all the distributions downstream
don't face them?
------------------------------------------------------------------------
[2018-12-28 15:21:57] nikic@php.net
Are there any *particular* issues that you are experiencing? We generally do not update bundled
libraries on stable versions unless there is a specific reason to do so, as such updates carry
stability risks.
Of course we also prefer not to bundle libraries, e.g. in PHP 7.4 libsqlite and libzip will be
removed from our distribution. There are currently no plans to remove the bundled libpcre though.
------------------------------------------------------------------------
[2018-12-28 13:40:02] spam2 at rhsoft dot net
Description:
------------
following https://bugs.php.net/bug.php?id=77349
and "If there are bugs which affect our PCRE binding, yes. However, in my opinion, this should
be filed as separate issue"
it's not only about pcre
it's a general thing - there is nothing like "if there are bugs which affect our PCRE
binding" - bugs in a library affect PHP and the users of PHP
one thing are security bugs like https://www.cvedetails.com/vulnerability-list/vendor_id-3265/opdos-1/Pcre.html
but that is only part of the story
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=77363&edit=1