Re: solution for those depending on PEAR packages with non-PEAR apps
| From: | Justin Patrin | Date: | Sun, 24 Apr 2005 00:23:37 +0000 |
| Subject: | Re: solution for those depending on PEAR packages with non-PEAR apps | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-37386@lists.php.net to get a copy of this message | ||
On 4/21/05, Greg Beaver <cellog@php.net> wrote:
> Hi,
>
> Lukas and others have mentioned a problem that applications have when
> depending on a PEAR package: if a critical bug is found, and the
> maintainer of the PEAR package is slow to release a new version, then it
> is very difficult to get a patched version of the package onto client's
> computers unless you patch it by hand, or instruct them to do the awkward:
>
> $ pear upgrade
> http://www.yourhost.example.com/Foo-1.2.0-patched.tgz
>
> What would be better is if there was a way to release a patched version
> of a package that could be used as a dependency for your application.
>
> uri-based dependencies provide the ability to depend on a special
> one-shot file, but a uri-based Foo would conflict with a channel-based Foo.
>
> Today, it occurred to me that there is a way to easily specify that a
> package is a patched version: put it in the package.xml.
>
> This way, the user would only need to type
>
> $ pear upgrade application
>
> to get the bugfix, and calls to upgrade-all would continue to work
> normally. Code in the app would look like
>
> <dependencies>
> ....
> <package>
> <name>Foo</name>
> <channel>pear.php.net</channel>
> <min>1.2.0.1</min>
>
> <patch>http://www.yourhost.example.com/Foo-1.2.0.1</patch>
> </package>
>
> and in the patched package:
>
> <package version="2.0">
> <name>Foo</name>
>
> <uri>http://www.yourhost.example.com/Foo-1.2.0.1</uri>
> <patches>
> <name>Foo</name>
> <channel>pear.php.net</channel>
> <reason>Critical bug in Bar()</reason>
> </patches>
>
> The installer, on the other hand, would not install the package
> automatically, but would prompt the user with "This package patches
> pear.php.net/Foo version 1.2.0 from uri
> http://www.example.com/Foo-1.2.0.1.tgz because of Critical Bug
> in Bar(),
> do not install unless you trust this source. Install? [Y]"
>
> More details are in http://pear.php.net/bugs/4201
>
I'd like to weigh in with a simple analogy. Both Portage (Gentoo's
install system) and OpenEmbedded (the build system for Familiar and
OpenZaurus) support applying patches to code. I think this is a great
idea as it allows people to fix bugs and add features as they see fit
without having to wait for upstream developers. It often takes a long
time to get patches applied upstream and having the installer support
patches is a great way to go to allow people to use *our* software but
still have more control over how they can deal with bugs.
I'd like to give a big +1 for including this feature and an even
bigger -1 to the "put a patched version on your own channel" idea.
Putting a patched version up on your onw channel has many problems.
The user will either have to force the upgrade / install or deal with
possibly forcing the upgrade/install when the upstream maintainer
releases the new version. I had other points, but I can't remember
them just now...
--
Justin Patrin