Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:105014 Return-Path: Delivered-To: mailing list internals@lists.php.net Received: (qmail 17184 invoked from network); 29 Mar 2019 23:22:57 -0000 Received: from unknown (HELO mail-pf1-f181.google.com) (209.85.210.181) by pb1.pair.com with SMTP; 29 Mar 2019 23:22:57 -0000 Received: by mail-pf1-f181.google.com with SMTP id r15so1548591pfn.9 for ; Fri, 29 Mar 2019 13:17:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20161025; h=subject:to:references:from:openpgp:autocrypt:message-id:date :user-agent:mime-version:in-reply-to:content-language :content-transfer-encoding; bh=UfSgmb2pE7g4S8/uMnRZVaFcmFZ3e17J2t6e28Tkg7o=; b=DmfoI3ohzaUUBBPgeaeW85voYV1NDpV/KQBoB7T1z0GJqSjWrderr25oMtkDrnLqAe o0EL9+O/L8yZuVxI9BqG4ohjdP7/nwWrd9TY8PNrd/hlbixnydaxRwoy8KqezJ5kRJBj unG1kyxVITi+7/xPNDEsXAZ9rbl/MVWPAoIoURY+cntcGpnd8RMGRID7rGHxnK1XKdD4 N3AMRDY0JG/1bNcv7Az/Gw2mJ+Hq+DROd02GhRtwS3LeB1F0B7AfO3Zqwv7ECbcAJl+m 0byac41IMoeq+SCv6bQobO0vMA/5Ci5Dz0KDPNohZI88USiVlpRFbkBorg28lSq3y8Jm Fksw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20161025; h=x-gm-message-state:subject:to:references:from:openpgp:autocrypt :message-id:date:user-agent:mime-version:in-reply-to :content-language:content-transfer-encoding; bh=UfSgmb2pE7g4S8/uMnRZVaFcmFZ3e17J2t6e28Tkg7o=; b=AuXDC0OVmvKxFEgT06CBP1db8BGf94wzDqOtiOEUJnBx4xWhSAQdOCDCt2INeDCr4S NR7JhBhm6YCEyqllJfa3ZvcO6ffJqnPfQb8i+eJCBknxnGEBu6v5x1ubXnNRlv3Y/J8F jdaf6Z7eHox4rljRcxe5+T6jTZIGLYAxsvTkuU2byNZggmGgJQThclP24zd06d1NODzU wwn1w0TwkpoXHXZTbedVbWTWMNYKcmDlK8iVMSThGCV0UfNBYaK7Fkt2gIfMGS+yTNmr nOQZr6xBnnWr99qv0e+CVlmV3hwRCFtdv8Iv3wVNToKqgu/bjWJ144I3CnoDXBDxerc7 WdbQ== X-Gm-Message-State: APjAAAXh9BS5x0a/BY1oHWJOXnCbnnobAPnrs4fHsVcf9rPtHKqym0+0 lVMnkfeEyYVILpe2JTiqmDmDzWE= X-Google-Smtp-Source: APXvYqxWCyM6HZMmf7eG6mhqyLV+WJHE3+sI5LMaLQyhw31hPyqIdVVdqV7ASKeGrqdCcWqT+hWnoA== X-Received: by 2002:a65:5b44:: with SMTP id y4mr30417833pgr.446.1553890628682; Fri, 29 Mar 2019 13:17:08 -0700 (PDT) Received: from Stas-Pro-2016.local ([2601:646:8d01:8ee0:4034:e3e8:f506:63ea]) by smtp.gmail.com with ESMTPSA id r11sm7652316pga.87.2019.03.29.13.17.07 (version=TLS1_2 cipher=ECDHE-RSA-AES128-GCM-SHA256 bits=128/128); Fri, 29 Mar 2019 13:17:08 -0700 (PDT) To: Remi Collet , internals@lists.php.net References: Openpgp: preference=signencrypt Autocrypt: addr=smalyshev@gmail.com; prefer-encrypt=mutual; keydata= mQMuBE9mqaARCACFSqcGmNunkjQQu3X+yXnTmFeEkvM4JXZTOBdR8aEevNGmmFEfyvjaDjWi 9hcwp4E/lYtC+P7VsVjM1OSX9eq0jC/lGL0ZyRXek+mNy0n5H1NSuTpf9Y18LMqhc4G+RU+L cNiZ9K0DJuOOvNLPxW7OHZguxb3wdKPXNVa2jyRfJAKm2uaJJMT1mTmFT9a0Q8SKr+mUrrJk uG0H2o6SzrKt8Wwoint1eh67zVsJaJtQFchnEZnlawIcqP2yC4nLGR3MkubowxoEBYCZet18 aHVVRbvpG2Qtob8Lu5xrsGbmXymTkHTdpvkfcJFADa8MzOL90zOxXwbGfbIZOlh5En8jAQCX lfnx2eQL3BSW/6XANa51dbWiEp1d1BAkpGKtZvlk0Qf+M9WAi+9aXMe3xP5krxtgnRNUf2WN 6Zdy2MxL1RRJCFbytLhl0ronC49BsGYVGshdEH8xhBbiIOJKuVZ/DTl9bEm7P9c7CC7iJyVC khUAhouH6xzZQNLR+RU+QebYzXypVfl99Qk7EdMmr/WAZCHLuvanyqepC5EBsa3VnAfQemSN oBeGBKWWLiOsPjvS72+y1z4RUMAfXHn4l/sFMt8zt7/74AmJPwZquV41p4mPO12V4+xPyc6R sB84sfsk2QVivU8w8AkvGQeYjXoz7Iwao95+fWteVzZ36KRQvUckP8pGjHlDXnHxJ0HI1I/k OBZSjwRwUf0dd73y6erPhbLk+gf+NdI3H9KGJBzG5/rVyWKwUeQ9d5ud4jTJRkQGvAP5pg76 vEa9dogbpe4W5Z+0BfbiJSnQmQWSHiZddj/t33ptbup44Ck6ZTgdlmFYMLF1hR47PIZTDKER EuKYGci/vq8snZvEJP9YCw/TtiHcMdrMKcY/+Lp8lQO0GHLPB9glVhnC0db6l1Xpg1CMI8/R ozBMcij30EgATggC/y2zbiqAFoS9FN9nXPbe4phStqABEyeZ+nXudt7PUYTjVgcrqo8bHZCi sBobWC7OnKyUzxVxzUeuPkIfmZuzkLaMw2McQdvwwsNvQ0DzaLP30c1Xsm/7EIYJcOWpzlVJ 5QrdmE0/BbQyU3RhbmlzbGF2IE1hbHlzaGV2IChQSFAga2V5KSA8c21hbHlzaGV2QGdtYWls LmNvbT6IegQTEQgAIgUCT2aqtAIbAwYLCQgHAwIGFQgCCQoLBBYCAwECHgECF4AACgkQL3lW vF2gS12XMwD9HuRIolSwIK77u8EY461y2u6sbX36n5/uo/LDQuxoi3sA/0MvpnvzOhv9Iufv vsZEj3E7i3h+iD5648YMwfTFCij+uQINBE9mqaAQCADfZPMpjZkkGZj3BY/7ApoLq4mwqzbh +CpLXwNn20tFNvSXfb8RdeXvVEb7Scx+W9qYpiaun2iXJgCVH8fgpZpR856ulT1q6uCG++CX ubEvip/eJkZl93/84h04KQJwsgOrAh0Om3OePRn8Pr+++0LNS0EL8uX/YHeTOGOnnmTqYTey SBVFdov6L4mepddfjekicKQqhL7mZh/xuq29JijT0uNNX8v4vDWQDu5dlAcdd+uB3gcXMD/P ginD11zp+6wtrWCm/+yBqpvDwXQX5PGUnwvbRfl7Ay3MmwmoXiecZMg0dwTSc7e0lhB4HGRH ZdBMJB4rHUVGdzqujK/ctOvrAAMFB/0Utb76Qe6sCMlHxVAmeE/fbo7Pi05btZ/x01r67dHf aMSP0riCKJ7M0OW+jAXtu9+z/BVnYisW67WWfxl2cS5tZDgiHgJARXWUOO72+sScHP8KQmTl 1z16gyKbwY3SmyBkwcpOL35nhUWNLy93syPoY6sZUTikr2bZYukHDQ33XBPs4e6MbWKfsa9q aVmnlOF3k5UqChjutfHaEa4Q7VP4wBIpphHBi9MI16oJIzzBPbGl2uoedjwiZ6QeQZnSuOVY ZxU2d3lRA8PrtfFN1VSlpEm/VcAvtieHUYWHN0wOu+cp3Slr5XJVNjTjJhl28SlinMME54mK AGf2Ldr/dRwXiGEEGBEIAAkFAk9mqaACGwwACgkQL3lWvF2gS126EQD/VVd3FgjLKglClRQP zdfU847tqDK4zJjbmRv5vLLwoE0A+wbrQs7jVGU3NrS0AIl5vUmewpp2BKzSkepy23nWmejw Message-ID: <19efc114-32c4-e02b-76b1-480bf36b336c@gmail.com> Date: Fri, 29 Mar 2019 13:17:07 -0700 User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.13; rv:60.0) Gecko/20100101 Thunderbird/60.6.1 MIME-Version: 1.0 In-Reply-To: Content-Type: text/plain; charset=utf-8 Content-Language: en-US Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] Updating bundled libs (specifially, oniguruma) on 7.1/7.2 From: smalyshev@gmail.com (Stanislav Malyshev) Hi! > 7.1 have version 5.9.6 > 7.2 have version 6.3.0 > 7.3 have version 6.9.0 (latest is 6.9.1) > 7.4 only use system library > > As we encourage system library usage (default in 7.4), and if this raise > the minimal allowed version, this will create issue for 7.4 > > Ex > RHEL have 5.9 > Debian have 6.1 Any reason why those are so far behind? 5.9 is from 2014! > I think we have to manage such change in a compatible way. > (feature availability tested in configure This creates a very bad situation, where we can not implement security improvements because we have to be compatible with a version of the library that has been released 4.5 years ago. Is there any reason why we prefer system library if actual system library is not being properly maintained by packagers? I think if most packagers neglect to keep with latest versions so much, we should keep bundling it - otherwise, we are just exposing our users to security issues and give them slower and buggier and feature-impaired library despite being completely able to do better. > P.S. from downstream PoV, as soname is different is it possible to have > compat package for library (v5.9 uses 2, v6.1 uses 4, v6.9 uses 5) Not sure what you mean here, could you explain? -- Stas Malyshev smalyshev@gmail.com