Debian Bug report logs - #662126
[php5] FTBFS with PHP5_SUHOSIN=yes

version graph

Package: php5; Maintainer for php5 is (unknown);

Reported by: "info@g-com.eu" <info@g-com.eu>

Date: Sun, 4 Mar 2012 10:33:01 UTC

Severity: minor

Merged with 663710

Found in version php5/5.4.0-1

Done: Ondřej Surý <ondrej@sury.org>

Bug is archived. No further changes may be made.

Toggle useless messages

View this report as an mbox folder, status mbox, maintainer mbox


Report forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#662126; Package php5. (Sun, 04 Mar 2012 10:33:04 GMT) (full text, mbox, link).


Acknowledgement sent to "info@g-com.eu" <info@g-com.eu>:
New Bug report received and forwarded. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Sun, 04 Mar 2012 10:33:10 GMT) (full text, mbox, link).


Message #5 received at submit@bugs.debian.org (full text, mbox, reply):

From: "info@g-com.eu" <info@g-com.eu>
To: submit@bugs.debian.org
Subject: [php5] FTBFS with PHP5_SUHOSIN=yes
Date: Sun, 04 Mar 2012 11:24:09 +0100
[Message part 1 (text/plain, inline)]
Package: php5
Version: 5.4.0-1
Severity: important

--- Please enter the report below this line. ---
Buildlog attached.

Regards Alf Gaida

--- System information. ---
Architecture: amd64
Kernel:       Linux 3.2-9.towo.1-siduction-amd64

Debian Release: wheezy/sid
  990 unstable        debian.alfgaida.de
  500 unstable        packages.siduction.org
  500 unstable        ftp.debian.org
  500 testing         ftp.debian.org
  500 stable          www.scootersoftware.com
  500 stable          ftp.debian.org
  500 experimental    packages.siduction.org
    1 experimental    ftp.debian.org

--- Package information. ---
Depends                           (Version) | Installed
===========================================-+-==============
libapache2-mod-php5           (>= 5.4.0-1)  | 5.4.0-1
 OR libapache2-mod-php5filter (>= 5.4.0-1)  |
 OR php5-cgi                  (>= 5.4.0-1)  | 5.4.0-1
 OR php5-fpm                   (>= 5.4.0-1) | 5.4.0-1
php5-common                    (>= 5.4.0-1) | 5.4.0-1


Package's Recommends field is empty.

Package's Suggests field is empty.
[php5_5.4.0-1.1.build (text/plain, attachment)]

Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#662126; Package php5. (Sun, 04 Mar 2012 10:51:42 GMT) (full text, mbox, link).


Acknowledgement sent to Ondřej Surý <ondrej@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Sun, 04 Mar 2012 10:51:46 GMT) (full text, mbox, link).


Message #10 received at 662126@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@debian.org>
To: "info@g-com.eu" <info@g-com.eu>, 662126@bugs.debian.org
Cc: control <control@bugs.debian.org>
Subject: Re: [php-maint] Bug#662126: [php5] FTBFS with PHP5_SUHOSIN=yes
Date: Sun, 4 Mar 2012 11:48:37 +0100
severity 662126 minor
thank you

There's no suhosin patch for PHP 5.4. The patch will be updated as
soon as there is one.

O.

On Sun, Mar 4, 2012 at 11:24, info@g-com.eu <info@g-com.eu> wrote:
> Package: php5
> Version: 5.4.0-1
> Severity: important
>
> --- Please enter the report below this line. ---
> Buildlog attached.
>
> Regards Alf Gaida
>
> --- System information. ---
> Architecture: amd64
> Kernel:       Linux 3.2-9.towo.1-siduction-amd64
>
> Debian Release: wheezy/sid
>  990 unstable        debian.alfgaida.de
>  500 unstable        packages.siduction.org
>  500 unstable        ftp.debian.org
>  500 testing         ftp.debian.org
>  500 stable          www.scootersoftware.com
>  500 stable          ftp.debian.org
>  500 experimental    packages.siduction.org
>    1 experimental    ftp.debian.org
>
> --- Package information. ---
> Depends                           (Version) | Installed
> ===========================================-+-==============
> libapache2-mod-php5           (>= 5.4.0-1)  | 5.4.0-1
>  OR libapache2-mod-php5filter (>= 5.4.0-1)  |
>  OR php5-cgi                  (>= 5.4.0-1)  | 5.4.0-1
>  OR php5-fpm                   (>= 5.4.0-1) | 5.4.0-1
> php5-common                    (>= 5.4.0-1) | 5.4.0-1
>
>
> Package's Recommends field is empty.
>
> Package's Suggests field is empty.
>
> _______________________________________________
> pkg-php-maint mailing list
> pkg-php-maint@lists.alioth.debian.org
> http://lists.alioth.debian.org/cgi-bin/mailman/listinfo/pkg-php-maint



-- 
Ondřej Surý <ondrej@sury.org>




Severity set to 'minor' from 'important' Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Sun, 04 Mar 2012 10:52:02 GMT) (full text, mbox, link).


Forcibly Merged 662126 663710. Request was from Ondřej Surý <ondrej@debian.org> to control@bugs.debian.org. (Tue, 13 Mar 2012 14:24:15 GMT) (full text, mbox, link).


Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#662126; Package php5. (Wed, 09 May 2012 19:51:04 GMT) (full text, mbox, link).


Acknowledgement sent to Christoph Anton Mitterer <calestyo@scientia.net>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Wed, 09 May 2012 19:51:04 GMT) (full text, mbox, link).


Message #19 received at 662126@bugs.debian.org (full text, mbox, reply):

From: Christoph Anton Mitterer <calestyo@scientia.net>
To: <662126@bugs.debian.org>, <663954@bugs.debian.org>, <657698@bugs.debian.org>
Cc: <662126-subscribe@bugs.debian.org>, <663954-subscribe@bugs.debian.org>
Subject: php 5.4.x suhosin
Date: Wed, 09 May 2012 21:48:58 +0200
Hi.

It seems that there's "initial" support for 5.4.x PHPs in the suhosin 
git now.

I haven't checked due to lack of time, but does anyone now, whether 
suhosin would have prevent the most recent disastrous security hole in 
PHP? If so,... would be a strong argument supporting my wish in #657698.


Cheers,
Chris.




Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#662126; Package php5. (Wed, 09 May 2012 20:18:04 GMT) (full text, mbox, link).


Acknowledgement sent to Alexander Wirt <formorer@debian.org>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Wed, 09 May 2012 20:18:04 GMT) (full text, mbox, link).


Message #24 received at 662126@bugs.debian.org (full text, mbox, reply):

From: Alexander Wirt <formorer@debian.org>
To: Christoph Anton Mitterer <calestyo@scientia.net>, 663954@bugs.debian.org
Cc: 662126@bugs.debian.org, 657698@bugs.debian.org, 663954-subscribe@bugs.debian.org, 662126-subscribe@bugs.debian.org
Subject: Re: Bug#663954: php 5.4.x suhosin
Date: Wed, 9 May 2012 22:13:41 +0200
On Wed, 09 May 2012, Christoph Anton Mitterer wrote:

> Hi.
> 
> It seems that there's "initial" support for 5.4.x PHPs in the
> suhosin git now.
> 
> I haven't checked due to lack of time, but does anyone now, whether
> suhosin would have prevent the most recent disastrous security hole
> in PHP? If so,... would be a strong argument supporting my wish in
> #657698.
nothing changed to #669972. 

We won't do uploads of unreleased suhosin. Full stop.

Alex
 




Information forwarded to debian-bugs-dist@lists.debian.org, Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>:
Bug#662126; Package php5. (Wed, 09 May 2012 20:30:07 GMT) (full text, mbox, link).


Acknowledgement sent to Christoph Anton Mitterer <calestyo@scientia.net>:
Extra info received and forwarded to list. Copy sent to Debian PHP Maintainers <pkg-php-maint@lists.alioth.debian.org>. (Wed, 09 May 2012 20:30:07 GMT) (full text, mbox, link).


Message #29 received at 662126@bugs.debian.org (full text, mbox, reply):

From: Christoph Anton Mitterer <calestyo@scientia.net>
To: 663954@bugs.debian.org, 657698@bugs.debian.org, 662126@bugs.debian.org
Subject: Re: Bug#663954: php 5.4.x suhosin
Date: Wed, 09 May 2012 22:26:48 +0200
[Message part 1 (text/plain, inline)]
On Wed, 2012-05-09 at 22:13 +0200, Alexander Wirt wrote:
> nothing changed to #669972.
Ah, I haven't seen that one,... nevertheless it's good to have my note
about progress on the upstream side and your note about #669972 int
these bugs now.


> We won't do uploads of unreleased suhosin.
Yeah,... well guess that's up to you... but it seems as this is actually
some final version (at least according to the changelog) and Stefan just
haven't made a tarball out of it yet.

> If it has security problems some php ***** will start a
> debian shitstorm
Well that can always happen, right? Even if it's in the form of a
tar.something ;)


Cheers,
Chris.
[smime.p7s (application/x-pkcs7-signature, attachment)]

Reply sent to Ondřej Surý <ondrej@sury.org>:
You have taken responsibility. (Thu, 29 Nov 2012 23:27:14 GMT) (full text, mbox, link).


Notification sent to "info@g-com.eu" <info@g-com.eu>:
Bug acknowledged by developer. (Thu, 29 Nov 2012 23:27:14 GMT) (full text, mbox, link).


Message #34 received at 662126-done@bugs.debian.org (full text, mbox, reply):

From: Ondřej Surý <ondrej@sury.org>
To: 662126-done@bugs.debian.org, 657698-done@bugs.debian.org
Subject: Suhosin is upstream dead for several months now and thus it won't be re-introduced to Debian PHP packages
Date: Fri, 30 Nov 2012 00:24:24 +0100
So closing bugs related to it.

O.
--
Ondřej Surý <ondrej@sury.org>



Reply sent to Ondřej Surý <ondrej@sury.org>:
You have taken responsibility. (Thu, 29 Nov 2012 23:27:15 GMT) (full text, mbox, link).


Notification sent to Alf Gaida <agaida@siduction.org>:
Bug acknowledged by developer. (Thu, 29 Nov 2012 23:27:15 GMT) (full text, mbox, link).


Bug archived. Request was from Debbugs Internal Request <owner@bugs.debian.org> to internal_control@bugs.debian.org. (Fri, 28 Dec 2012 07:25:35 GMT) (full text, mbox, link).


Send a report that this bug log contains spam.


Debian bug tracking system administrator <owner@bugs.debian.org>. Last modified: Sun Jul 2 01:55:47 2023; Machine Name: bembo

Debian Bug tracking system

Debbugs is free software and licensed under the terms of the GNU Public License version 2. The current version can be obtained from https://bugs.debian.org/debbugs-source/.

Copyright © 1999 Darren O. Benham, 1997,2003 nCipher Corporation Ltd, 1994-97 Ian Jackson, 2005-2017 Don Armstrong, and many other contributors.