solution for those depending on PEAR packages with non-PEAR apps
| From: | Greg Beaver | Date: | Fri, 22 Apr 2005 03:11:21 +0000 |
| Subject: | solution for those depending on PEAR packages with non-PEAR apps | ||
| Groups: | php.pear.dev | ||
| Request: | Send a blank email to pear-dev+get-37329@lists.php.net to get a copy of this message | ||
Hi,
Lukas and others have mentioned a problem that applications have when depending on a PEAR package: if a critical bug is found, and the maintainer of the PEAR package is slow to release a new version, then it is very difficult to get a patched version of the package onto client's computers unless you patch it by hand, or instruct them to do the awkward:
$ pear upgrade http://www.yourhost.example.com/Foo-1.2.0-patched.tgz
What would be better is if there was a way to release a patched version of a package that could be used as a dependency for your application.
uri-based dependencies provide the ability to depend on a special one-shot file, but a uri-based Foo would conflict with a channel-based Foo.
Today, it occurred to me that there is a way to easily specify that a package is a patched version: put it in the package.xml.
This way, the user would only need to type
$ pear upgrade application
to get the bugfix, and calls to upgrade-all would continue to work normally. Code in the app would look like
<dependencies>
....
<package>
<name>Foo</name>
<channel>pear.php.net</channel>
<min>1.2.0.1</min>
<patch>http://www.yourhost.example.com/Foo-1.2.0.1</patch>
</package>
and in the patched package:
<package version="2.0">
<name>Foo</name>
<uri>http://www.yourhost.example.com/Foo-1.2.0.1</uri>
<patches>
<name>Foo</name>
<channel>pear.php.net</channel>
<reason>Critical bug in Bar()</reason>
</patches>
The installer, on the other hand, would not install the package automatically, but would prompt the user with "This package patches pear.php.net/Foo version 1.2.0 from uri http://www.example.com/Foo-1.2.0.1.tgz because of Critical Bug in Bar(), do not install unless you trust this source. Install? [Y]"
More details are in http://pear.php.net/bugs/4201
Greg