Skip site navigation (1)Skip section navigation (2)
Date:      Thu, 9 Feb 2012 01:28:44 +0900
From:      Svyatoslav Lempert <svyatoslav.lempert@gmail.com>
To:        freebsd-ports@freebsd.org
Subject:   Re: FreeBSD ports which are currently scheduled for deletion
Message-ID:  <CAERaTk9Csw11tQLaWCmxhph2vpTQtGmGVUi7C2BbX1HW654-DA@mail.gmail.com>
In-Reply-To: <4F327097.6080006@quip.cz>
References:  <201202070829.q178TNZw081740@portsmonj.FreeBSD.org> <CAERaTk_BirOS8rCEbT4HBm75EUJ2jqcu3E0ESVUrQGKnHxv5Jw@mail.gmail.com> <4F31CEEC.5020300@FreeBSD.org> <4F327097.6080006@quip.cz>

next in thread | previous in thread | raw e-mail | index | archive | help
2012/2/8 Miroslav Lachman <000.fbsd@quip.cz>:
> Doug Barton wrote:
>>
>> On 02/07/2012 17:13, Svyatoslav Lempert wrote:
>>>
>>> 2012/2/7<linimon@freebsd.org>:
>>>>
>>>> The ports, and the reason and date that they have been scheduled
>>>> for removal, are listed below. =C2=A0If no one has stepped forward bef=
ore
>>>> that time to propose a way to fix the problems (such as via a PR),
>>>> the ports will be deleted.
>>>>
>>>> portname: =C2=A0 =C2=A0 =C2=A0 =C2=A0 =C2=A0 lang/php52
>>>> description: =C2=A0 =C2=A0 =C2=A0 =C2=A0PHP Scripting Language
>>>> maintainer: =C2=A0 =C2=A0 =C2=A0 =C2=A0 admin@lissyara.su
>>>> deprecated because: PHP 5.2 series is not supported anymore, migrate n=
ow
>>>> expiration date: =C2=A0 =C2=A02012-03-01
>>>> build errors: =C2=A0 =C2=A0 =C2=A0 none.
>>>> overview:
>>>> http://portsmon.FreeBSD.org/portoverview.py?category=3Dlang&portname=
=3Dphp52
>>>>
>>>
>>> Why so much wish to remove lang/php52?
>>
>>
>> There are numerous security vulnerabilities in it, and so far no one has
>> stepped up to thoroughly address them. If you'd like to volunteer to
>> maintain this version that would be great. Just submit the PR with the
>> following updates:
>>
>> All security patches backported
>> Fix the dependent ports (php52-*) to use the same patches as lang/php52
>>
>> That's off the top of my head ... there may be other problems.
>
>
> Are you sure there are any known security vulnerabilities not fixed in
> lang/php52? I think that current maintainer Alex Keda <admin@lissyara.su>=
 is
> doing exelent work with backporting all needed patches to have working an=
d
> secure PHP 5.2.x in FreeBSD ports tree, so there is no need to remove thi=
s
> port.
>
> Migrating from 5.2 to 5.3 or any future version is not possible without
> modification of PHP scripts. Webhosting servers with old applications mus=
t
> stay with 5.2 until all clients migrate their code to newer version.
>
> The last version of PHP 4.4 was released 07-Aug-2008 and is still in port=
s
> tree, last version of 5.2 was released 06-Jan-2011 and is well maintained
> with security patches.
>
> I don't see any good reason to remove the port, which have active maintai=
ner
> fixing all known problems / security vulnerabilities.
>
> Miroslav Lachman

Please look to PR http://www.freebsd.org/cgi/query-pr.cgi?pr=3D164849

--=20
Svyatoslav



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?CAERaTk9Csw11tQLaWCmxhph2vpTQtGmGVUi7C2BbX1HW654-DA>