Re: solution for those depending on PEAR packages with non-PEAR apps

From: Date: Sun, 24 Apr 2005 00:23:37 +0000
Subject: Re: solution for those depending on PEAR packages with non-PEAR apps
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-37386@lists.php.net to get a copy of this message
On 4/21/05, Greg Beaver <cellog@php.net> wrote: > Hi, > > Lukas and others have mentioned a problem that applications have when > depending on a PEAR package: if a critical bug is found, and the > maintainer of the PEAR package is slow to release a new version, then it > is very difficult to get a patched version of the package onto client's > computers unless you patch it by hand, or instruct them to do the awkward: > > $ pear upgrade > http://www.yourhost.example.com/Foo-1.2.0-patched.tgz > > What would be better is if there was a way to release a patched version > of a package that could be used as a dependency for your application. > > uri-based dependencies provide the ability to depend on a special > one-shot file, but a uri-based Foo would conflict with a channel-based Foo. > > Today, it occurred to me that there is a way to easily specify that a > package is a patched version: put it in the package.xml. > > This way, the user would only need to type > > $ pear upgrade application > > to get the bugfix, and calls to upgrade-all would continue to work > normally. Code in the app would look like > > <dependencies> > .... > <package> > <name>Foo</name> > <channel>pear.php.net</channel> > <min>1.2.0.1</min> > > <patch>http://www.yourhost.example.com/Foo-1.2.0.1</patch> > </package> > > and in the patched package: > > <package version="2.0"> > <name>Foo</name> > > <uri>http://www.yourhost.example.com/Foo-1.2.0.1</uri> > <patches> > <name>Foo</name> > <channel>pear.php.net</channel> > <reason>Critical bug in Bar()</reason> > </patches> > > The installer, on the other hand, would not install the package > automatically, but would prompt the user with "This package patches > pear.php.net/Foo version 1.2.0 from uri > http://www.example.com/Foo-1.2.0.1.tgz because of Critical Bug > in Bar(), > do not install unless you trust this source. Install? [Y]" > > More details are in http://pear.php.net/bugs/4201 > I'd like to weigh in with a simple analogy. Both Portage (Gentoo's install system) and OpenEmbedded (the build system for Familiar and OpenZaurus) support applying patches to code. I think this is a great idea as it allows people to fix bugs and add features as they see fit without having to wait for upstream developers. It often takes a long time to get patches applied upstream and having the installer support patches is a great way to go to allow people to use *our* software but still have more control over how they can deal with bugs. I'd like to give a big +1 for including this feature and an even bigger -1 to the "put a patched version on your own channel" idea. Putting a patched version up on your onw channel has many problems. The user will either have to force the upgrade / install or deal with possibly forcing the upgrade/install when the upstream maintainer releases the new version. I had other points, but I can't remember them just now... -- Justin Patrin

« previous php.pear.dev (#37386) next »