-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Le 14/09/2015 14:03, Jakub Zelenka a écrit :
> Hi,
> 
> At the moment the minimal OpenSSL version is 0.9.6.
> 
> I realised yesterday that there are some types changes between
> 0.9.7 and 0.9.8 that would have to be address in overflow checks
> (EVP_DigestUpdate and related). I also noticed that 0.9.6 might not
> even compile without warnings as it's checking return type for some
> function that did not return anything in 0.9.6. We also have few
> other old places where we don't check retval because of that.
> 
> The thing is that the last update for 0.9.7 stable branch is in
> 2008 and 0.9.6 in 2005. Both of them have been long time EOL so I
> don't think that it makes any sense to spend any time on making
> them compatible for PHP 7. So I think we should bump minimal
> version to 0.9.8.
> 
> Anatol would you be ok if this is done for 7.0? I don't think that
> anyone would ever use PHP 7 and such an old version of OpenSSL
> together so there should be no issue IMHO.

+1

RHEL-7 have 1.0.1e
RHEL-6 have 1.0.1e
RHEL-5 have 0.9.8e (and already doesn't support PHP 7)

Remi


> Cheers
> 
> Jakub
> 

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2
Comment: Using GnuPG with Thunderbird - http://www.enigmail.net/

iEYEARECAAYFAlX4GbYACgkQYUppBSnxahhofgCeLMoQfhBIZM6cwxRU+r0BSVhB
nWcAn2x0NKfN3ceJH/MNmcNl9CcTmPM1
=+SqR
-----END PGP SIGNATURE-----

--
PHP Internals - PHP Runtime Development Mailing List
To unsubscribe, visit: http://www.php.net/unsub.php

Reply via email to