Re: [RFC] Deprecations for PHP 8.6
| From: | Jakub Zelenka | Date: | Mon, 29 Jun 2026 21:32:34 +0000 |
| Subject: | Re: [RFC] Deprecations for PHP 8.6 | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-131628@lists.php.net to get a copy of this message | ||
Hi,
On Mon, Jun 29, 2026 at 7:09 PM Ilia <ilia@ilia.ws> wrote:
>
> On Mon, Jun 22, 2026 at 9:19 AM Gina P. Banyard <internals@gpb.moe> wrote:
>
>> We still have a bit of time anyone else to propose additional
>> deprecations, and if you have write access feel free to add them directly
>> to the RFC.
>> Please note that with the new RFC policy rules the RFC must be finalized
>> and in a "frozen" state by the 13th of July at the latest.
>>
>
> Before I add it to the RFC, I wanted to get a quick temperature check on
> whether people think it is finally time to deprecate and eventually remove
> open_basedir?
>
>
There are valid use cases for open_basedir where it can improve security of
the application. It just cannot be relied on as a sendbox in general sense
but removing it would be a mistake IMHO - not even mentioning that it would
require migration for many applications that might depend on it. So -1 on
it especially with such a late notice.
Kind regards,
Jakub