PHP 5.4.0 : lang/php54

Michael Scheidell scheidell at FreeBSD.org
Tue May 15 15:17:29 UTC 2012



On 5/15/12 11:05 AM, Svyatoslav Lempert wrote:
> So I think we need release a new version without suhosin patch and
> check the compatibility of all ports that depend on it (before), and
> then when suhosin will appear (if there), then simply add it to the
> port.
>
-1
susosin patch is not a 'compatibility' issue.  it is a security issue.
I would consider recommending a lang/php54 port, for people who 
absolutely need it.  include the 'WITH_SUHOSIN_PATCH' knob and mark it 
'IGNORE' so that anyone who expects the stsndard, default, upward 
compatible security will be warned against installing this port.

leave php5.3 the default lang/php5 for now.  wait till suhosin patch is 
released.  use lang/php54 for anyone who absolutely must play with 5.4
(I am still going through pains replacing apache 13 and php5.2 with 
nginx and php53).  don't think I want to /_by default_/ open up a 
security hole.


-- 
Michael Scheidell, CTO
 >*| * SECNAP Network Security Corporation
d: +1.561.948.2259
w: http://people.freebsd.org/~scheidell


More information about the freebsd-ports mailing list