Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:26561 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 37026 invoked by uid 1010); 14 Nov 2006 10:56:54 -0000 Delivered-To: ezmlm-scan-internals@lists.php.net Delivered-To: ezmlm-internals@lists.php.net Received: (qmail 37010 invoked from network); 14 Nov 2006 10:56:54 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 14 Nov 2006 10:56:54 -0000 Authentication-Results: pb1.pair.com header.from=cschneid@cschneid.com; sender-id=unknown Authentication-Results: pb1.pair.com smtp.mail=cschneid@cschneid.com; spf=permerror; sender-id=unknown Received-SPF: error (pb1.pair.com: domain cschneid.com from 195.226.6.42 cause and error) X-PHP-List-Original-Sender: cschneid@cschneid.com X-Host-Fingerprint: 195.226.6.42 darkcity.gna.ch Linux 2.5 (sometimes 2.4) (4) Received: from [195.226.6.42] ([195.226.6.42:55975] helo=mail.gna.ch) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 01/C2-19250-4F0A9554 for ; Tue, 14 Nov 2006 05:56:53 -0500 Received: from localhost (localhost [127.0.0.1]) by darkcity.gna.ch (Postfix) with ESMTP id 0C4CED321D; Tue, 14 Nov 2006 11:56:49 +0100 (CET) Received: from unknown by localhost (amavisd-new, unix socket) id client-XXS9rlO4; Tue, 14 Nov 2006 11:56:47 +0100 (CET) Received: from [192.168.1.42] (217-162-171-242.dclient.hispeed.ch [217.162.171.242]) (using TLSv1 with cipher DHE-RSA-AES256-SHA (256/256 bits)) (No client certificate requested) by darkcity.gna.ch (Postfix) with ESMTP id 1A914D3211; Tue, 14 Nov 2006 11:56:46 +0100 (CET) Message-ID: <4559A0DC.1090002@cschneid.com> Date: Tue, 14 Nov 2006 11:56:28 +0100 User-Agent: Thunderbird 1.5.0.8 (Macintosh/20061025) MIME-Version: 1.0 To: RQuadling@GoogleMail.com CC: php-dev References: <4558E5E7.5040809@zend.com> <10845a340611140024l4902ea09q600a43c5018e819c@mail.gmail.com> <45598955.3030604@zend.com> <10845a340611140219m7b9ddeedm452d6f4b99341776@mail.gmail.com> In-Reply-To: <10845a340611140219m7b9ddeedm452d6f4b99341776@mail.gmail.com> Content-Type: text/plain; charset=UTF-8; format=flowed Content-Transfer-Encoding: 7bit X-Virus-Scanned: amavisd-new at gna.ch Subject: Re: [PHP-DEV] fgets()/fgetss() BC break in HEAD From: cschneid@cschneid.com (Christian Schneider) Richard Quadling wrote: > And so why are we losing register_globals? For a LOT of code they work > and removing rg is sure as hell a BC for a lot of code. And we move This was done for *good* reason. You don't gain a lot of security (or even code clearity/brevity) by changing fgets. That's the difference. In favour of reverting, - Chris