Re: [PHP-DEV] 5.4 security only

2014-08-26 Thread Chris Wright
On 26 August 2014 18:31, Stas Malyshev wrote: > Hi! > > >> Does anyone have any objections to this being included in 5.4? >> >> Thanks, Chris >> >> [1] >> https://github.com/DaveRandom/php-src/commit/d4da5d8c1dae152f7aa5f0dd09b1f29b51f48c89 > > I think it's ok for 5.4. > Great, thanks :-) -- P

Re: [PHP-DEV] 5.4 security only

2014-08-26 Thread Stas Malyshev
Hi! > Does anyone have any objections to this being included in 5.4? > > Thanks, Chris > > [1] > https://github.com/DaveRandom/php-src/commit/d4da5d8c1dae152f7aa5f0dd09b1f29b51f48c89 I think it's ok for 5.4. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ --

Re: [PHP-DEV] 5.4 security only

2014-08-26 Thread Chris Wright
Hi Stas On 19 August 2014 00:59, Stas Malyshev wrote: > Hi! > > Moving this out of other topics into its own: according to the release > RFC, we should have 5.4 have 2 years of bugfixes & one year of security > fixes. Since 5.4 was released in March 2012, we're already past 2 year > mark. However

Re: [PHP-DEV] 5.4 security only

2014-08-22 Thread Michael Wallner
On 22/08/14 13:56, Julien Pauli wrote: > On Wed, Aug 20, 2014 at 10:45 PM, Stas Malyshev > wrote: >> Hi! >> >>> Apparently the fix for #67724 [2] caused #67865 [1], but I already have >>> a fix for the fix (oh my) [3]. >> >> I've reverted it from 5.4.32, but please commit this fix in 5.4. As phar

Re: [PHP-DEV] 5.4 security only

2014-08-22 Thread Julien Pauli
On Wed, Aug 20, 2014 at 10:45 PM, Stas Malyshev wrote: > Hi! > >> Apparently the fix for #67724 [2] caused #67865 [1], but I already have >> a fix for the fix (oh my) [3]. > > I've reverted it from 5.4.32, but please commit this fix in 5.4. As phar > is currently broken, fix for this qualifies as

Re: [PHP-DEV] 5.4 security only

2014-08-20 Thread Stas Malyshev
Hi! > Apparently the fix for #67724 [2] caused #67865 [1], but I already have > a fix for the fix (oh my) [3]. I've reverted it from 5.4.32, but please commit this fix in 5.4. As phar is currently broken, fix for this qualifies as important. -- Stanislav Malyshev, Software Architect SugarCRM: h

Re: [PHP-DEV] 5.4 security only

2014-08-20 Thread Michael Wallner
On 19/08/14 01:59, Stas Malyshev wrote: > > - EFFECTIVE IMMEDIATELY, we do not accept new non-security bugfixes into > 5.4 branch unless they are very important ones (and that is only because > people may, in theory, have pending patches and we didn't give advance > notice). Importance would have t

Re: [PHP-DEV] 5.4 security only

2014-08-19 Thread Ferenc Kovacs
2014.08.19. 1:59 ezt írta ("Stas Malyshev" ): > > Hi! > > Moving this out of other topics into its own: according to the release > RFC, we should have 5.4 have 2 years of bugfixes & one year of security > fixes. Since 5.4 was released in March 2012, we're already past 2 year > mark. However, we're

Re: [PHP-DEV] 5.4 security only

2014-08-19 Thread Julien Pauli
On Tue, Aug 19, 2014 at 1:59 AM, Stas Malyshev wrote: > Hi! > > Moving this out of other topics into its own: according to the release > RFC, we should have 5.4 have 2 years of bugfixes & one year of security > fixes. Since 5.4 was released in March 2012, we're already past 2 year > mark. However,

Re: [PHP-DEV] 5.4 security only

2014-08-19 Thread David Zuelke
I'd like to see https://github.com/php/php-src/pull/694 / https://github.com/php/php-src/pull/765 in so FPM in 5.4 will work properly with Apache 2.4.10+'s mod_proxy_fcgi. David On 19 Aug 2014, at 01:59, Stas Malyshev wrote: > Hi! > > Moving this out of other topics into its own: according

[PHP-DEV] 5.4 security only

2014-08-18 Thread Stas Malyshev
Hi! Moving this out of other topics into its own: according to the release RFC, we should have 5.4 have 2 years of bugfixes & one year of security fixes. Since 5.4 was released in March 2012, we're already past 2 year mark. However, we're still have some bugfixes in 5.4, so I'd like to do this: -