Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:57679 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 83780 invoked from network); 4 Feb 2012 08:57:05 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 4 Feb 2012 08:57:05 -0000 Authentication-Results: pb1.pair.com smtp.mail=smalyshev@sugarcrm.com; spf=pass; sender-id=pass Authentication-Results: pb1.pair.com header.from=smalyshev@sugarcrm.com; sender-id=pass Received-SPF: pass (pb1.pair.com: domain sugarcrm.com designates 207.97.245.153 as permitted sender) X-PHP-List-Original-Sender: smalyshev@sugarcrm.com X-Host-Fingerprint: 207.97.245.153 smtp153.iad.emailsrvr.com Linux 2.6 Received: from [207.97.245.153] ([207.97.245.153:52050] helo=smtp153.iad.emailsrvr.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id 7D/D7-08838-0E2FC2F4 for ; Sat, 04 Feb 2012 03:57:05 -0500 Received: from smtp45.relay.iad1a.emailsrvr.com (localhost.localdomain [127.0.0.1]) by smtp45.relay.iad1a.emailsrvr.com (SMTP Server) with ESMTP id 4488390142; Sat, 4 Feb 2012 03:57:02 -0500 (EST) X-SMTPDoctor-Processed: csmtpprox 2.7.4 Received: from localhost (localhost.localdomain [127.0.0.1]) by smtp45.relay.iad1a.emailsrvr.com (SMTP Server) with ESMTP id 2F49690143; Sat, 4 Feb 2012 03:57:02 -0500 (EST) X-Virus-Scanned: OK Received: by smtp45.relay.iad1a.emailsrvr.com (Authenticated sender: smalyshev-AT-sugarcrm.com) with ESMTPSA id D4F8390142; Sat, 4 Feb 2012 03:57:00 -0500 (EST) Message-ID: <4F2CF2DB.7000605@sugarcrm.com> Date: Sat, 04 Feb 2012 00:56:59 -0800 Organization: SugarCRM User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.6; rv:9.0) Gecko/20111222 Thunderbird/9.0.1 MIME-Version: 1.0 To: Stefan Esser CC: Pierre Joye , Soenke Ruempler - Jimdo , PHP internals , "security@php.net" , "zigo@debian.org" References: <5FB5CFDA-6FE8-4C20-A9B9-7844ED96659B@nopiracy.de> <4F2A9378.70803@thelounge.net> <4F2AC9CA.2070308@sugarcrm.com> <4F2B2ED8.4050900@jimdo.com> <72878E6C-4C17-4D94-9F73-1446769247E1@nopiracy.de> <4F2CEA7E.9010906@sugarcrm.com> <9684A843-5A7F-43BB-BFC2-86F34E27EC3B@nopiracy.de> In-Reply-To: <9684A843-5A7F-43BB-BFC2-86F34E27EC3B@nopiracy.de> Content-Type: text/plain; charset=ISO-8859-1; format=flowed Content-Transfer-Encoding: 7bit Subject: Re: [PHP-DEV] Suhosin patch disabled by default in Debian php5 builds From: smalyshev@sugarcrm.com (Stas Malyshev) Hi! > A suhosin that is merged to PHP mainline will never provide the same > security as an external solution. This is not good enough for me. That's your opinion and you completely entitled to it and I have absolutely no issue about it. As I have no issue with your preferring to keep Suhosin as a separate project - it's your code, you decide what to do with it. What I have an issue with is understanding how, after all public invitations and discussion, you claim that we refuse to cooperate and "fight you like cancer". > Also PHP.net demands that I convince them to take feature A, B and F > from Suhosin into PHP. I get ordered to sit down and write RFCs about Nobody demands anything from you. However, for a feature to be included in PHP it needs to go through certain process. It's not because we hate you and this process is not personal for you, it's because this is how projects which have more than one person must work (I'm feeling stupid spelling out obvious things, but it looks like it's impossible to avoid it) if they don't want to descend into complete chaos. If you prefer not to do it - your right, it's your time and I'm sure you have much better uses for it. But then there's no place to complain that PHP developers refuse to cooperate and mistreat you. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227