Bug #77363 [Fbk]: bundled libraries are always outdated

From: Date: Fri, 28 Dec 2018 19:07:32 +0000
Subject: Bug #77363 [Fbk]: bundled libraries are always outdated
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-218665@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77363&edit=1 ID: 77363 Updated by: cmb@php.net Reported by: spam2 at rhsoft dot net Summary: bundled libraries are always outdated Status: Feedback Type: Bug Package: *General Issues PHP Version: Irrelevant Block user comment: N Private report: N New Comment: > imho at least once per year there should happen a rebase, […] Well, Fedora is moving very quickly: two major releases per year[1]. Other distros are moving much slower; for instance, Debian's current stable (Stretch) still ships libpcre 8.39-3[2], which is a patched 8.39 (released 14-June-2016). And then there are even LTS releases, such as the still supported Ubuntu 14.04.5 LTS, which ships libpcre 8.31-2ubuntu2.2[3], which is a patched 8.31 (released 06-July-2012). > […] which would only point out demand for additional tests which > should have been there anyways ACK. However, this world is not perfect. For instance, ext/sqlite3 has less than 100 tests[4], resulting in a coverage of roughly 80%[5], but even 100% wouldn't be sufficient to detect all potential regressions. > but then the test-suite suffers from enough bigger issues > starting by more and more stuff ignores environment and the > supplied "php.ini" […] This is already tracked as <https://bugs.php.net/76494>. Please keep separate issues separate. :) And of course, patches are welcome! [1] <https://fedoraproject.org/wiki/Releases> [2] <https://packages.debian.org/stretch/libpcre3-dev> [3] <https://packages.ubuntu.com/trusty/libpcre3-dev> [4] <https://github.com/php/php-src/tree/php-7.3.0/ext/sqlite3/tests> [5] <http://gcov.php.net/PHP_7_3/lcov_html/ext/sqlite3/index.php> Previous Comments: ------------------------------------------------------------------------ [2018-12-28 15:54:44] spam2 at rhsoft dot net i just use Fedora over 12 years and for 10 years in production following changelogs in libraries closely and was surprised to find the year 2017 when building with the bundled one imho at least once per year there should happen a rebase, the majority of userbase has no chance to track down whatever issues root cause and i don#t get "stability risks" which would only point out demand for additional tests which should have been there anyways but then the test-suite suffers from enough bigger issues starting by more and more stuff ignores environment and the supplied "php.ini" loading the system extensions instead the fresh built ones making a lot of test completly pointless and only get covered when you fire up a rpmbuild for 7.3 on a system where 7.2 is installed ------------------------------------------------------------------------ [2018-12-28 15:47:33] nikic@php.net Distributions do face stability risks. That's why distributions commonly do not update libraries wholesale, but instead backport fixes that they consider worthwhile (often only security fixes or issues specifically reported to them) on a case-by-case basis. Of course this depends on the distribution, it's general update policies and package-specific update policies. Which is why I'm asking whether there are any specific issues you have in mind here that might make a backport necessary. ------------------------------------------------------------------------ [2018-12-28 15:26:22] spam2 at rhsoft dot net let me word it differently: if there are no issues why does upstream bother with bugfix releases? when updates would carry *serious* stability risks how comes that all the distributions downstream don't face them? ------------------------------------------------------------------------ [2018-12-28 15:21:57] nikic@php.net Are there any *particular* issues that you are experiencing? We generally do not update bundled libraries on stable versions unless there is a specific reason to do so, as such updates carry stability risks. Of course we also prefer not to bundle libraries, e.g. in PHP 7.4 libsqlite and libzip will be removed from our distribution. There are currently no plans to remove the bundled libpcre though. ------------------------------------------------------------------------ [2018-12-28 13:40:02] spam2 at rhsoft dot net Description: ------------ following https://bugs.php.net/bug.php?id=77349 and "If there are bugs which affect our PCRE binding, yes. However, in my opinion, this should be filed as separate issue" it's not only about pcre it's a general thing - there is nothing like "if there are bugs which affect our PCRE binding" - bugs in a library affect PHP and the users of PHP one thing are security bugs like https://www.cvedetails.com/vulnerability-list/vendor_id-3265/opdos-1/Pcre.html but that is only part of the story ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=77363&edit=1

« previous php.bugs (#218665) next »