From ce42ba8e367950d8ecd2182a8bb23908726525ca Mon Sep 17 00:00:00 2001 From: henderkes Date: Mon, 28 Sep 2026 12:10:35 +0200 Subject: [PATCH] remove zts, instead all images are always built as zts (8.6+) --- 8.6-rc/alpine3.23/cli/Dockerfile | 7 + 8.6-rc/alpine3.23/fpm/Dockerfile | 4 + 8.6-rc/alpine3.23/zts/Dockerfile | 212 ---------------- 8.6-rc/alpine3.23/zts/docker-php-entrypoint | 9 - .../alpine3.23/zts/docker-php-ext-configure | 69 ------ 8.6-rc/alpine3.23/zts/docker-php-ext-enable | 121 --------- 8.6-rc/alpine3.23/zts/docker-php-ext-install | 143 ----------- 8.6-rc/alpine3.23/zts/docker-php-source | 34 --- 8.6-rc/alpine3.24/cli/Dockerfile | 7 + 8.6-rc/alpine3.24/fpm/Dockerfile | 4 + 8.6-rc/alpine3.24/zts/Dockerfile | 212 ---------------- 8.6-rc/alpine3.24/zts/docker-php-entrypoint | 9 - .../alpine3.24/zts/docker-php-ext-configure | 69 ------ 8.6-rc/alpine3.24/zts/docker-php-ext-enable | 121 --------- 8.6-rc/alpine3.24/zts/docker-php-ext-install | 143 ----------- 8.6-rc/alpine3.24/zts/docker-php-source | 34 --- 8.6-rc/bookworm/apache/Dockerfile | 4 + 8.6-rc/bookworm/cli/Dockerfile | 4 + 8.6-rc/bookworm/fpm/Dockerfile | 4 + 8.6-rc/bookworm/zts/Dockerfile | 229 ------------------ 8.6-rc/bookworm/zts/docker-php-entrypoint | 9 - 8.6-rc/bookworm/zts/docker-php-ext-configure | 69 ------ 8.6-rc/bookworm/zts/docker-php-ext-enable | 121 --------- 8.6-rc/bookworm/zts/docker-php-ext-install | 143 ----------- 8.6-rc/bookworm/zts/docker-php-source | 34 --- 8.6-rc/trixie/apache/Dockerfile | 4 + 8.6-rc/trixie/cli/Dockerfile | 4 + 8.6-rc/trixie/fpm/Dockerfile | 4 + 8.6-rc/trixie/zts/Dockerfile | 229 ------------------ 8.6-rc/trixie/zts/docker-php-entrypoint | 9 - 8.6-rc/trixie/zts/docker-php-ext-configure | 69 ------ 8.6-rc/trixie/zts/docker-php-ext-enable | 121 --------- 8.6-rc/trixie/zts/docker-php-ext-install | 143 ----------- 8.6-rc/trixie/zts/docker-php-source | 34 --- Dockerfile-linux.template | 7 +- versions.json | 6 +- versions.sh | 2 +- 37 files changed, 52 insertions(+), 2395 deletions(-) delete mode 100644 8.6-rc/alpine3.23/zts/Dockerfile delete mode 100755 8.6-rc/alpine3.23/zts/docker-php-entrypoint delete mode 100755 8.6-rc/alpine3.23/zts/docker-php-ext-configure delete mode 100755 8.6-rc/alpine3.23/zts/docker-php-ext-enable delete mode 100755 8.6-rc/alpine3.23/zts/docker-php-ext-install delete mode 100755 8.6-rc/alpine3.23/zts/docker-php-source delete mode 100644 8.6-rc/alpine3.24/zts/Dockerfile delete mode 100755 8.6-rc/alpine3.24/zts/docker-php-entrypoint delete mode 100755 8.6-rc/alpine3.24/zts/docker-php-ext-configure delete mode 100755 8.6-rc/alpine3.24/zts/docker-php-ext-enable delete mode 100755 8.6-rc/alpine3.24/zts/docker-php-ext-install delete mode 100755 8.6-rc/alpine3.24/zts/docker-php-source delete mode 100644 8.6-rc/bookworm/zts/Dockerfile delete mode 100755 8.6-rc/bookworm/zts/docker-php-entrypoint delete mode 100755 8.6-rc/bookworm/zts/docker-php-ext-configure delete mode 100755 8.6-rc/bookworm/zts/docker-php-ext-enable delete mode 100755 8.6-rc/bookworm/zts/docker-php-ext-install delete mode 100755 8.6-rc/bookworm/zts/docker-php-source delete mode 100644 8.6-rc/trixie/zts/Dockerfile delete mode 100755 8.6-rc/trixie/zts/docker-php-entrypoint delete mode 100755 8.6-rc/trixie/zts/docker-php-ext-configure delete mode 100755 8.6-rc/trixie/zts/docker-php-ext-enable delete mode 100755 8.6-rc/trixie/zts/docker-php-ext-install delete mode 100755 8.6-rc/trixie/zts/docker-php-source diff --git a/8.6-rc/alpine3.23/cli/Dockerfile b/8.6-rc/alpine3.23/cli/Dockerfile index 8b7a7b3ef5..a9f1f889f5 100644 --- a/8.6-rc/alpine3.23/cli/Dockerfile +++ b/8.6-rc/alpine3.23/cli/Dockerfile @@ -163,6 +163,13 @@ RUN set -eux; \ --enable-phpdbg \ --enable-phpdbg-readline \ \ + \ +# https://github.com/docker-library/php/pull/939#issuecomment-730501748 + --enable-embed \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/alpine3.23/fpm/Dockerfile b/8.6-rc/alpine3.23/fpm/Dockerfile index 32369223fa..38a21abab5 100644 --- a/8.6-rc/alpine3.23/fpm/Dockerfile +++ b/8.6-rc/alpine3.23/fpm/Dockerfile @@ -168,6 +168,10 @@ RUN set -eux; \ --enable-fpm \ --with-fpm-user=www-data \ --with-fpm-group=www-data \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/alpine3.23/zts/Dockerfile b/8.6-rc/alpine3.23/zts/Dockerfile deleted file mode 100644 index a9f1f889f5..0000000000 --- a/8.6-rc/alpine3.23/zts/Dockerfile +++ /dev/null @@ -1,212 +0,0 @@ -# -# NOTE: THIS DOCKERFILE IS GENERATED VIA "apply-templates.sh" -# -# PLEASE DO NOT EDIT IT DIRECTLY. -# - -FROM alpine:3.23 - -# dependencies required for running "phpize" -# these get automatically installed and removed by "docker-php-ext-*" (unless they're already installed) -ENV PHPIZE_DEPS \ - autoconf \ - dpkg-dev dpkg \ - file \ - g++ \ - gcc \ - libc-dev \ - make \ - pkgconf \ - re2c - -# persistent / runtime deps -RUN apk add --no-cache \ - ca-certificates \ - curl \ - openssl \ - tar \ - xz - -# ensure www-data user exists -RUN set -eux; \ - adduser -u 82 -D -S -G www-data www-data -# 82 is the standard uid/gid for "www-data" in Alpine -# https://git.alpinelinux.org/aports/tree/main/apache2/apache2.pre-install?h=3.14-stable -# https://git.alpinelinux.org/aports/tree/main/lighttpd/lighttpd.pre-install?h=3.14-stable -# https://git.alpinelinux.org/aports/tree/main/nginx/nginx.pre-install?h=3.14-stable - -ENV PHP_INI_DIR /usr/local/etc/php -RUN set -eux; \ - mkdir -p "$PHP_INI_DIR/conf.d"; \ -# allow running as an arbitrary user (https://github.com/docker-library/php/issues/743) - [ ! -d /var/www/html ]; \ - mkdir -p /var/www/html; \ - chown www-data:www-data /var/www/html; \ - chmod 1777 /var/www/html - -# Apply stack smash protection to functions using local buffers and alloca() -# Make PHP's main executable position-independent (improves ASLR security mechanism, and has no performance impact on x86_64) -# Enable optimization (-O2) -# Enable linker optimization (this sorts the hash buckets to improve cache locality, and is non-default) -# https://github.com/docker-library/php/issues/272 -# -D_LARGEFILE_SOURCE and -D_FILE_OFFSET_BITS=64 (https://www.php.net/manual/en/intro.filesystem.php) -ENV PHP_CFLAGS="-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" -ENV PHP_CPPFLAGS="$PHP_CFLAGS" -ENV PHP_LDFLAGS="-Wl,-O1 -pie" - -ENV GPG_KEYS D95C03BC702BE9515344AE3374E44BC9067701A5 016895DE9A475111D537A6E69134FF30BC5A99B5 5CFF17B64DC1C244F5D0EAC3E43535E2EB19010E - -ENV PHP_VERSION 8.6.0RC2 -ENV PHP_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz" PHP_ASC_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz.asc" -ENV PHP_SHA256="ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c" - -RUN set -eux; \ - \ - apk add --no-cache --virtual .fetch-deps gnupg; \ - \ - mkdir -p /usr/src; \ - cd /usr/src; \ - \ - curl -fsSL -o php.tar.xz "$PHP_URL"; \ - \ - if [ -n "$PHP_SHA256" ]; then \ - echo "$PHP_SHA256 *php.tar.xz" | sha256sum -c -; \ - fi; \ - \ - curl -fsSL -o php.tar.xz.asc "$PHP_ASC_URL"; \ - export GNUPGHOME="$(mktemp -d)"; \ - for key in $GPG_KEYS; do \ - gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key"; \ - done; \ - gpg --batch --verify php.tar.xz.asc php.tar.xz; \ - gpgconf --kill all; \ - rm -rf "$GNUPGHOME"; \ - \ - apk del --no-network .fetch-deps - -COPY docker-php-source /usr/local/bin/ - -RUN set -eux; \ - apk add --no-cache --virtual .build-deps \ - $PHPIZE_DEPS \ - argon2-dev \ - coreutils \ - curl-dev \ - gnu-libiconv-dev \ - libsodium-dev \ - libxml2-dev \ - linux-headers \ - openssl-dev \ - readline-dev \ - sqlite-dev \ - ; \ - \ -# make sure musl's iconv doesn't get used (https://www.php.net/manual/en/intro.iconv.php) - rm -vf /usr/include/iconv.h; \ - \ - export \ - CFLAGS="$PHP_CFLAGS" \ - CPPFLAGS="$PHP_CPPFLAGS" \ - LDFLAGS="$PHP_LDFLAGS" \ -# https://github.com/php/php-src/blob/d6299206dd828382753453befd1b915491b741c6/configure.ac#L1496-L1511 - PHP_BUILD_PROVIDER='https://github.com/docker-library/php' \ - PHP_UNAME='Linux - Docker' \ - ; \ - docker-php-source extract; \ - cd /usr/src/php; \ - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; \ - case "$gnuArch" in \ - 'i686-linux-'*) \ - # php zend jit assumes SSE registers, xmm0-7, are available (and "Pentium4"/SSE2 is a reasonable baseline) - # https://github.com/php/php-src/pull/22832 - # so, allow it and use SSE/SSE2 floating-point unit instead of the legacy stack - export \ - CFLAGS="$CFLAGS -msse2 -mfpmath=sse" \ - CPPFLAGS="$CPPFLAGS -msse2 -mfpmath=sse" \ - ; \ - ;; \ - esac; \ - test "$PHP_INI_DIR" != "${PHP_INI_DIR%/php}"; \ - ./configure \ - --build="$gnuArch" \ - --sysconfdir="${PHP_INI_DIR%/php}" \ - --with-config-file-path="$PHP_INI_DIR" \ - --with-config-file-scan-dir="$PHP_INI_DIR/conf.d" \ - \ -# make sure invalid --configure-flags are fatal errors instead of just warnings - --enable-option-checking=fatal \ - \ -# https://github.com/docker-library/php/issues/439 - --with-mhash \ - \ -# https://github.com/docker-library/php/issues/822 -# https://github.com/php/php-src/pull/21067/changes#diff-4b9db5b77bcd56aa33b310dc44c8bc99c729c9abb195df2e98e6985b81289ae8R130 - --enable-pic \ - \ -# --enable-mysqlnd is included here because it's harder to compile after the fact than extensions are (since it's a plugin for several extensions, not an extension in itself) - --enable-mysqlnd \ -# https://wiki.php.net/rfc/argon2_password_hash - --with-password-argon2 \ -# https://wiki.php.net/rfc/libsodium - --with-sodium=shared \ -# always build against system sqlite3 (https://github.com/php/php-src/commit/6083a387a81dbbd66d6316a3a12a63f06d5f7109) - --with-pdo-sqlite=/usr \ - --with-sqlite3=/usr \ - \ - --with-curl \ - --with-iconv=/usr \ - --with-openssl \ - --with-readline \ - --with-zlib \ - \ -# https://github.com/docker-library/php/pull/1259 - --enable-phpdbg \ - --enable-phpdbg-readline \ - \ - \ -# https://github.com/docker-library/php/pull/939#issuecomment-730501748 - --enable-embed \ - \ - --enable-zts \ -# https://externals.io/message/118859 - --disable-zend-signals \ - ; \ - make -j "$(nproc)"; \ - find -type f -name '*.a' -delete; \ - make install; \ - find \ - /usr/local \ - -type f \ - -perm '/0111' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : \ - ' -- '{}' + \ - ; \ - make clean; \ - \ -# https://github.com/docker-library/php/issues/692 (copy default example "php.ini" files somewhere easily discoverable) - cp -v php.ini-* "$PHP_INI_DIR/"; \ - \ - cd /; \ - docker-php-source delete; \ - \ - runDeps="$( \ - scanelf --needed --nobanner --format '%n#p' --recursive /usr/local \ - | tr ',' '\n' \ - | sort -u \ - | awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' \ - )"; \ - apk add --no-cache $runDeps; \ - \ - apk del --no-network .build-deps; \ - \ -# smoke test - php --version - -COPY docker-php-ext-* docker-php-entrypoint /usr/local/bin/ - -# sodium was built as a shared module (so that it can be replaced later if so desired), so let's enable it too (https://github.com/docker-library/php/issues/598) -RUN docker-php-ext-enable sodium - -ENTRYPOINT ["docker-php-entrypoint"] -CMD ["php", "-a"] diff --git a/8.6-rc/alpine3.23/zts/docker-php-entrypoint b/8.6-rc/alpine3.23/zts/docker-php-entrypoint deleted file mode 100755 index 88a016c16c..0000000000 --- a/8.6-rc/alpine3.23/zts/docker-php-entrypoint +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/sh -set -e - -# first arg is `-f` or `--some-option` -if [ "${1#-}" != "$1" ]; then - set -- php "$@" -fi - -exec "$@" diff --git a/8.6-rc/alpine3.23/zts/docker-php-ext-configure b/8.6-rc/alpine3.23/zts/docker-php-ext-configure deleted file mode 100755 index 34fc1337d5..0000000000 --- a/8.6-rc/alpine3.23/zts/docker-php-ext-configure +++ /dev/null @@ -1,69 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 ext-name [configure flags]" - echo " ie: $0 gd --with-jpeg-dir=/usr/local/something" - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -ext="$1" -if [ -z "$ext" ] || [ ! -d "$ext" ]; then - usage >&2 - exit 1 -fi -shift - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual .phpize-deps-configure $PHPIZE_DEPS - fi -fi - -if command -v dpkg-architecture > /dev/null; then - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)" - set -- --build="$gnuArch" "$@" -fi - -cd "$ext" -phpize -./configure --enable-option-checking=fatal "$@" diff --git a/8.6-rc/alpine3.23/zts/docker-php-ext-enable b/8.6-rc/alpine3.23/zts/docker-php-ext-enable deleted file mode 100755 index 41d20bbe3f..0000000000 --- a/8.6-rc/alpine3.23/zts/docker-php-ext-enable +++ /dev/null @@ -1,121 +0,0 @@ -#!/bin/sh -set -e - -extDir="$(php -d 'display_errors=stderr' -r 'echo ini_get("extension_dir");')" -cd "$extDir" - -usage() { - echo "usage: $0 [options] module-name [module-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 --ini-name 0-apc.ini apcu apc" - echo - echo 'Possible values for module-name:' - find -maxdepth 1 \ - -type f \ - -name '*.so' \ - -exec basename '{}' ';' \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?' --long 'help,ini-name:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -modules= -for module; do - if [ -z "$module" ]; then - continue - fi - if ! [ -f "$module" ] && ! [ -f "$module.so" ]; then - echo >&2 "error: '$module' does not exist" - echo >&2 - usage >&2 - exit 1 - fi - modules="$modules $module" -done - -if [ -z "$modules" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual '.docker-php-ext-enable-deps' binutils - apkDel='.docker-php-ext-enable-deps' - fi -fi - -for module in $modules; do - moduleFile="$module" - if [ -f "$module.so" ] && ! [ -f "$module" ]; then - moduleFile="$module.so" - fi - if readelf --wide --syms "$moduleFile" | grep -q ' zend_extension_entry$'; then - # https://wiki.php.net/internals/extensions#loading_zend_extensions - line="zend_extension=$module" - else - line="extension=$module" - fi - - ext="$(basename "$module")" - ext="${ext%.*}" - if php -d 'display_errors=stderr' -r 'exit(extension_loaded("'"$ext"'") ? 0 : 1);'; then - # this isn't perfect, but it's better than nothing - # (for example, 'opcache.so' presents inside PHP as 'Zend OPcache', not 'opcache') - echo >&2 - echo >&2 "warning: $ext ($module) is already loaded!" - echo >&2 - continue - fi - - case "$iniName" in - /*) - # allow an absolute path - ini="$iniName" - ;; - *) - ini="$PHP_INI_DIR/conf.d/${iniName:-"docker-php-ext-$ext.ini"}" - ;; - esac - if ! grep -qFx -e "$line" -e "$line.so" "$ini" 2>/dev/null; then - echo "$line" >> "$ini" - fi -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi diff --git a/8.6-rc/alpine3.23/zts/docker-php-ext-install b/8.6-rc/alpine3.23/zts/docker-php-ext-install deleted file mode 100755 index fbf44849c0..0000000000 --- a/8.6-rc/alpine3.23/zts/docker-php-ext-install +++ /dev/null @@ -1,143 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 [-jN] [--ini-name file.ini] ext-name [ext-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 -j5 gd mbstring mysqli pdo pdo_mysql shmop" - echo - echo 'if custom ./configure arguments are necessary, see docker-php-ext-configure' - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?j:' --long 'help,ini-name:,jobs:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -j=1 -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --jobs|-j) j="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -exts= -for ext; do - if [ -z "$ext" ]; then - continue - fi - if [ ! -d "$ext" ]; then - echo >&2 "error: $PWD/$ext does not exist" - echo >&2 - usage >&2 - exit 1 - fi - exts="$exts $ext" -done - -if [ -z "$exts" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if [ -n "$PHPIZE_DEPS" ]; then - if apk info --installed .phpize-deps-configure > /dev/null; then - apkDel='.phpize-deps-configure' - elif ! apk info --installed .phpize-deps > /dev/null; then - apk add --no-cache --virtual .phpize-deps $PHPIZE_DEPS - apkDel='.phpize-deps' - fi - fi -fi - -popDir="$PWD" -for ext in $exts; do - cd "$ext" - - [ -e Makefile ] || docker-php-ext-configure "$ext" - - make -j"$j" - - if ! php -n -d 'display_errors=stderr' -r 'exit(ZEND_DEBUG_BUILD ? 0 : 1);' > /dev/null; then - # only "strip" modules if we aren't using a debug build of PHP - # (none of our builds are debug builds, but PHP might be recompiled with "--enable-debug" configure option) - # https://github.com/docker-library/php/issues/1268 - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : - ' -- '{}' + - fi - - make -j"$j" install - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec basename '{}' '.so' ';' \ - | xargs -r docker-php-ext-enable ${iniName:+--ini-name "$iniName"} - - make -j"$j" clean - - cd "$popDir" -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi - -if [ -e /usr/src/php/.docker-delete-me ]; then - docker-php-source delete -fi diff --git a/8.6-rc/alpine3.23/zts/docker-php-source b/8.6-rc/alpine3.23/zts/docker-php-source deleted file mode 100755 index 9033d243de..0000000000 --- a/8.6-rc/alpine3.23/zts/docker-php-source +++ /dev/null @@ -1,34 +0,0 @@ -#!/bin/sh -set -e - -dir=/usr/src/php - -usage() { - echo "usage: $0 COMMAND" - echo - echo "Manage php source tarball lifecycle." - echo - echo "Commands:" - echo " extract extract php source tarball into directory $dir if not already done." - echo " delete delete extracted php source located into $dir if not already done." - echo -} - -case "$1" in - extract) - mkdir -p "$dir" - if [ ! -f "$dir/.docker-extracted" ]; then - tar -Jxf /usr/src/php.tar.xz -C "$dir" --strip-components=1 - touch "$dir/.docker-extracted" - fi - ;; - - delete) - rm -rf "$dir" - ;; - - *) - usage - exit 1 - ;; -esac diff --git a/8.6-rc/alpine3.24/cli/Dockerfile b/8.6-rc/alpine3.24/cli/Dockerfile index 5e99fe03d1..ef6e20343c 100644 --- a/8.6-rc/alpine3.24/cli/Dockerfile +++ b/8.6-rc/alpine3.24/cli/Dockerfile @@ -163,6 +163,13 @@ RUN set -eux; \ --enable-phpdbg \ --enable-phpdbg-readline \ \ + \ +# https://github.com/docker-library/php/pull/939#issuecomment-730501748 + --enable-embed \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/alpine3.24/fpm/Dockerfile b/8.6-rc/alpine3.24/fpm/Dockerfile index 26148a1b85..923487345d 100644 --- a/8.6-rc/alpine3.24/fpm/Dockerfile +++ b/8.6-rc/alpine3.24/fpm/Dockerfile @@ -168,6 +168,10 @@ RUN set -eux; \ --enable-fpm \ --with-fpm-user=www-data \ --with-fpm-group=www-data \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/alpine3.24/zts/Dockerfile b/8.6-rc/alpine3.24/zts/Dockerfile deleted file mode 100644 index ef6e20343c..0000000000 --- a/8.6-rc/alpine3.24/zts/Dockerfile +++ /dev/null @@ -1,212 +0,0 @@ -# -# NOTE: THIS DOCKERFILE IS GENERATED VIA "apply-templates.sh" -# -# PLEASE DO NOT EDIT IT DIRECTLY. -# - -FROM alpine:3.24 - -# dependencies required for running "phpize" -# these get automatically installed and removed by "docker-php-ext-*" (unless they're already installed) -ENV PHPIZE_DEPS \ - autoconf \ - dpkg-dev dpkg \ - file \ - g++ \ - gcc \ - libc-dev \ - make \ - pkgconf \ - re2c - -# persistent / runtime deps -RUN apk add --no-cache \ - ca-certificates \ - curl \ - openssl \ - tar \ - xz - -# ensure www-data user exists -RUN set -eux; \ - adduser -u 82 -D -S -G www-data www-data -# 82 is the standard uid/gid for "www-data" in Alpine -# https://git.alpinelinux.org/aports/tree/main/apache2/apache2.pre-install?h=3.14-stable -# https://git.alpinelinux.org/aports/tree/main/lighttpd/lighttpd.pre-install?h=3.14-stable -# https://git.alpinelinux.org/aports/tree/main/nginx/nginx.pre-install?h=3.14-stable - -ENV PHP_INI_DIR /usr/local/etc/php -RUN set -eux; \ - mkdir -p "$PHP_INI_DIR/conf.d"; \ -# allow running as an arbitrary user (https://github.com/docker-library/php/issues/743) - [ ! -d /var/www/html ]; \ - mkdir -p /var/www/html; \ - chown www-data:www-data /var/www/html; \ - chmod 1777 /var/www/html - -# Apply stack smash protection to functions using local buffers and alloca() -# Make PHP's main executable position-independent (improves ASLR security mechanism, and has no performance impact on x86_64) -# Enable optimization (-O2) -# Enable linker optimization (this sorts the hash buckets to improve cache locality, and is non-default) -# https://github.com/docker-library/php/issues/272 -# -D_LARGEFILE_SOURCE and -D_FILE_OFFSET_BITS=64 (https://www.php.net/manual/en/intro.filesystem.php) -ENV PHP_CFLAGS="-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" -ENV PHP_CPPFLAGS="$PHP_CFLAGS" -ENV PHP_LDFLAGS="-Wl,-O1 -pie" - -ENV GPG_KEYS D95C03BC702BE9515344AE3374E44BC9067701A5 016895DE9A475111D537A6E69134FF30BC5A99B5 5CFF17B64DC1C244F5D0EAC3E43535E2EB19010E - -ENV PHP_VERSION 8.6.0RC2 -ENV PHP_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz" PHP_ASC_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz.asc" -ENV PHP_SHA256="ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c" - -RUN set -eux; \ - \ - apk add --no-cache --virtual .fetch-deps gnupg; \ - \ - mkdir -p /usr/src; \ - cd /usr/src; \ - \ - curl -fsSL -o php.tar.xz "$PHP_URL"; \ - \ - if [ -n "$PHP_SHA256" ]; then \ - echo "$PHP_SHA256 *php.tar.xz" | sha256sum -c -; \ - fi; \ - \ - curl -fsSL -o php.tar.xz.asc "$PHP_ASC_URL"; \ - export GNUPGHOME="$(mktemp -d)"; \ - for key in $GPG_KEYS; do \ - gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key"; \ - done; \ - gpg --batch --verify php.tar.xz.asc php.tar.xz; \ - gpgconf --kill all; \ - rm -rf "$GNUPGHOME"; \ - \ - apk del --no-network .fetch-deps - -COPY docker-php-source /usr/local/bin/ - -RUN set -eux; \ - apk add --no-cache --virtual .build-deps \ - $PHPIZE_DEPS \ - argon2-dev \ - coreutils \ - curl-dev \ - gnu-libiconv-dev \ - libsodium-dev \ - libxml2-dev \ - linux-headers \ - openssl-dev \ - readline-dev \ - sqlite-dev \ - ; \ - \ -# make sure musl's iconv doesn't get used (https://www.php.net/manual/en/intro.iconv.php) - rm -vf /usr/include/iconv.h; \ - \ - export \ - CFLAGS="$PHP_CFLAGS" \ - CPPFLAGS="$PHP_CPPFLAGS" \ - LDFLAGS="$PHP_LDFLAGS" \ -# https://github.com/php/php-src/blob/d6299206dd828382753453befd1b915491b741c6/configure.ac#L1496-L1511 - PHP_BUILD_PROVIDER='https://github.com/docker-library/php' \ - PHP_UNAME='Linux - Docker' \ - ; \ - docker-php-source extract; \ - cd /usr/src/php; \ - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; \ - case "$gnuArch" in \ - 'i686-linux-'*) \ - # php zend jit assumes SSE registers, xmm0-7, are available (and "Pentium4"/SSE2 is a reasonable baseline) - # https://github.com/php/php-src/pull/22832 - # so, allow it and use SSE/SSE2 floating-point unit instead of the legacy stack - export \ - CFLAGS="$CFLAGS -msse2 -mfpmath=sse" \ - CPPFLAGS="$CPPFLAGS -msse2 -mfpmath=sse" \ - ; \ - ;; \ - esac; \ - test "$PHP_INI_DIR" != "${PHP_INI_DIR%/php}"; \ - ./configure \ - --build="$gnuArch" \ - --sysconfdir="${PHP_INI_DIR%/php}" \ - --with-config-file-path="$PHP_INI_DIR" \ - --with-config-file-scan-dir="$PHP_INI_DIR/conf.d" \ - \ -# make sure invalid --configure-flags are fatal errors instead of just warnings - --enable-option-checking=fatal \ - \ -# https://github.com/docker-library/php/issues/439 - --with-mhash \ - \ -# https://github.com/docker-library/php/issues/822 -# https://github.com/php/php-src/pull/21067/changes#diff-4b9db5b77bcd56aa33b310dc44c8bc99c729c9abb195df2e98e6985b81289ae8R130 - --enable-pic \ - \ -# --enable-mysqlnd is included here because it's harder to compile after the fact than extensions are (since it's a plugin for several extensions, not an extension in itself) - --enable-mysqlnd \ -# https://wiki.php.net/rfc/argon2_password_hash - --with-password-argon2 \ -# https://wiki.php.net/rfc/libsodium - --with-sodium=shared \ -# always build against system sqlite3 (https://github.com/php/php-src/commit/6083a387a81dbbd66d6316a3a12a63f06d5f7109) - --with-pdo-sqlite=/usr \ - --with-sqlite3=/usr \ - \ - --with-curl \ - --with-iconv=/usr \ - --with-openssl \ - --with-readline \ - --with-zlib \ - \ -# https://github.com/docker-library/php/pull/1259 - --enable-phpdbg \ - --enable-phpdbg-readline \ - \ - \ -# https://github.com/docker-library/php/pull/939#issuecomment-730501748 - --enable-embed \ - \ - --enable-zts \ -# https://externals.io/message/118859 - --disable-zend-signals \ - ; \ - make -j "$(nproc)"; \ - find -type f -name '*.a' -delete; \ - make install; \ - find \ - /usr/local \ - -type f \ - -perm '/0111' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : \ - ' -- '{}' + \ - ; \ - make clean; \ - \ -# https://github.com/docker-library/php/issues/692 (copy default example "php.ini" files somewhere easily discoverable) - cp -v php.ini-* "$PHP_INI_DIR/"; \ - \ - cd /; \ - docker-php-source delete; \ - \ - runDeps="$( \ - scanelf --needed --nobanner --format '%n#p' --recursive /usr/local \ - | tr ',' '\n' \ - | sort -u \ - | awk 'system("[ -e /usr/local/lib/" $1 " ]") == 0 { next } { print "so:" $1 }' \ - )"; \ - apk add --no-cache $runDeps; \ - \ - apk del --no-network .build-deps; \ - \ -# smoke test - php --version - -COPY docker-php-ext-* docker-php-entrypoint /usr/local/bin/ - -# sodium was built as a shared module (so that it can be replaced later if so desired), so let's enable it too (https://github.com/docker-library/php/issues/598) -RUN docker-php-ext-enable sodium - -ENTRYPOINT ["docker-php-entrypoint"] -CMD ["php", "-a"] diff --git a/8.6-rc/alpine3.24/zts/docker-php-entrypoint b/8.6-rc/alpine3.24/zts/docker-php-entrypoint deleted file mode 100755 index 88a016c16c..0000000000 --- a/8.6-rc/alpine3.24/zts/docker-php-entrypoint +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/sh -set -e - -# first arg is `-f` or `--some-option` -if [ "${1#-}" != "$1" ]; then - set -- php "$@" -fi - -exec "$@" diff --git a/8.6-rc/alpine3.24/zts/docker-php-ext-configure b/8.6-rc/alpine3.24/zts/docker-php-ext-configure deleted file mode 100755 index 34fc1337d5..0000000000 --- a/8.6-rc/alpine3.24/zts/docker-php-ext-configure +++ /dev/null @@ -1,69 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 ext-name [configure flags]" - echo " ie: $0 gd --with-jpeg-dir=/usr/local/something" - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -ext="$1" -if [ -z "$ext" ] || [ ! -d "$ext" ]; then - usage >&2 - exit 1 -fi -shift - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual .phpize-deps-configure $PHPIZE_DEPS - fi -fi - -if command -v dpkg-architecture > /dev/null; then - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)" - set -- --build="$gnuArch" "$@" -fi - -cd "$ext" -phpize -./configure --enable-option-checking=fatal "$@" diff --git a/8.6-rc/alpine3.24/zts/docker-php-ext-enable b/8.6-rc/alpine3.24/zts/docker-php-ext-enable deleted file mode 100755 index 41d20bbe3f..0000000000 --- a/8.6-rc/alpine3.24/zts/docker-php-ext-enable +++ /dev/null @@ -1,121 +0,0 @@ -#!/bin/sh -set -e - -extDir="$(php -d 'display_errors=stderr' -r 'echo ini_get("extension_dir");')" -cd "$extDir" - -usage() { - echo "usage: $0 [options] module-name [module-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 --ini-name 0-apc.ini apcu apc" - echo - echo 'Possible values for module-name:' - find -maxdepth 1 \ - -type f \ - -name '*.so' \ - -exec basename '{}' ';' \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?' --long 'help,ini-name:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -modules= -for module; do - if [ -z "$module" ]; then - continue - fi - if ! [ -f "$module" ] && ! [ -f "$module.so" ]; then - echo >&2 "error: '$module' does not exist" - echo >&2 - usage >&2 - exit 1 - fi - modules="$modules $module" -done - -if [ -z "$modules" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual '.docker-php-ext-enable-deps' binutils - apkDel='.docker-php-ext-enable-deps' - fi -fi - -for module in $modules; do - moduleFile="$module" - if [ -f "$module.so" ] && ! [ -f "$module" ]; then - moduleFile="$module.so" - fi - if readelf --wide --syms "$moduleFile" | grep -q ' zend_extension_entry$'; then - # https://wiki.php.net/internals/extensions#loading_zend_extensions - line="zend_extension=$module" - else - line="extension=$module" - fi - - ext="$(basename "$module")" - ext="${ext%.*}" - if php -d 'display_errors=stderr' -r 'exit(extension_loaded("'"$ext"'") ? 0 : 1);'; then - # this isn't perfect, but it's better than nothing - # (for example, 'opcache.so' presents inside PHP as 'Zend OPcache', not 'opcache') - echo >&2 - echo >&2 "warning: $ext ($module) is already loaded!" - echo >&2 - continue - fi - - case "$iniName" in - /*) - # allow an absolute path - ini="$iniName" - ;; - *) - ini="$PHP_INI_DIR/conf.d/${iniName:-"docker-php-ext-$ext.ini"}" - ;; - esac - if ! grep -qFx -e "$line" -e "$line.so" "$ini" 2>/dev/null; then - echo "$line" >> "$ini" - fi -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi diff --git a/8.6-rc/alpine3.24/zts/docker-php-ext-install b/8.6-rc/alpine3.24/zts/docker-php-ext-install deleted file mode 100755 index fbf44849c0..0000000000 --- a/8.6-rc/alpine3.24/zts/docker-php-ext-install +++ /dev/null @@ -1,143 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 [-jN] [--ini-name file.ini] ext-name [ext-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 -j5 gd mbstring mysqli pdo pdo_mysql shmop" - echo - echo 'if custom ./configure arguments are necessary, see docker-php-ext-configure' - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?j:' --long 'help,ini-name:,jobs:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -j=1 -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --jobs|-j) j="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -exts= -for ext; do - if [ -z "$ext" ]; then - continue - fi - if [ ! -d "$ext" ]; then - echo >&2 "error: $PWD/$ext does not exist" - echo >&2 - usage >&2 - exit 1 - fi - exts="$exts $ext" -done - -if [ -z "$exts" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if [ -n "$PHPIZE_DEPS" ]; then - if apk info --installed .phpize-deps-configure > /dev/null; then - apkDel='.phpize-deps-configure' - elif ! apk info --installed .phpize-deps > /dev/null; then - apk add --no-cache --virtual .phpize-deps $PHPIZE_DEPS - apkDel='.phpize-deps' - fi - fi -fi - -popDir="$PWD" -for ext in $exts; do - cd "$ext" - - [ -e Makefile ] || docker-php-ext-configure "$ext" - - make -j"$j" - - if ! php -n -d 'display_errors=stderr' -r 'exit(ZEND_DEBUG_BUILD ? 0 : 1);' > /dev/null; then - # only "strip" modules if we aren't using a debug build of PHP - # (none of our builds are debug builds, but PHP might be recompiled with "--enable-debug" configure option) - # https://github.com/docker-library/php/issues/1268 - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : - ' -- '{}' + - fi - - make -j"$j" install - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec basename '{}' '.so' ';' \ - | xargs -r docker-php-ext-enable ${iniName:+--ini-name "$iniName"} - - make -j"$j" clean - - cd "$popDir" -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi - -if [ -e /usr/src/php/.docker-delete-me ]; then - docker-php-source delete -fi diff --git a/8.6-rc/alpine3.24/zts/docker-php-source b/8.6-rc/alpine3.24/zts/docker-php-source deleted file mode 100755 index 9033d243de..0000000000 --- a/8.6-rc/alpine3.24/zts/docker-php-source +++ /dev/null @@ -1,34 +0,0 @@ -#!/bin/sh -set -e - -dir=/usr/src/php - -usage() { - echo "usage: $0 COMMAND" - echo - echo "Manage php source tarball lifecycle." - echo - echo "Commands:" - echo " extract extract php source tarball into directory $dir if not already done." - echo " delete delete extracted php source located into $dir if not already done." - echo -} - -case "$1" in - extract) - mkdir -p "$dir" - if [ ! -f "$dir/.docker-extracted" ]; then - tar -Jxf /usr/src/php.tar.xz -C "$dir" --strip-components=1 - touch "$dir/.docker-extracted" - fi - ;; - - delete) - rm -rf "$dir" - ;; - - *) - usage - exit 1 - ;; -esac diff --git a/8.6-rc/bookworm/apache/Dockerfile b/8.6-rc/bookworm/apache/Dockerfile index 0b8be7d686..9a04fdff9f 100644 --- a/8.6-rc/bookworm/apache/Dockerfile +++ b/8.6-rc/bookworm/apache/Dockerfile @@ -239,6 +239,10 @@ RUN set -eux; \ --disable-cgi \ \ --with-apxs2 \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/bookworm/cli/Dockerfile b/8.6-rc/bookworm/cli/Dockerfile index bc01130d82..42341687c7 100644 --- a/8.6-rc/bookworm/cli/Dockerfile +++ b/8.6-rc/bookworm/cli/Dockerfile @@ -178,6 +178,10 @@ RUN set -eux; \ \ # https://github.com/docker-library/php/pull/939#issuecomment-730501748 --enable-embed \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/bookworm/fpm/Dockerfile b/8.6-rc/bookworm/fpm/Dockerfile index 6ca864cdd5..2c115a1091 100644 --- a/8.6-rc/bookworm/fpm/Dockerfile +++ b/8.6-rc/bookworm/fpm/Dockerfile @@ -180,6 +180,10 @@ RUN set -eux; \ --enable-fpm \ --with-fpm-user=www-data \ --with-fpm-group=www-data \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/bookworm/zts/Dockerfile b/8.6-rc/bookworm/zts/Dockerfile deleted file mode 100644 index 42341687c7..0000000000 --- a/8.6-rc/bookworm/zts/Dockerfile +++ /dev/null @@ -1,229 +0,0 @@ -# -# NOTE: THIS DOCKERFILE IS GENERATED VIA "apply-templates.sh" -# -# PLEASE DO NOT EDIT IT DIRECTLY. -# - -FROM debian:bookworm-slim - -# prevent Debian's PHP packages from being installed -# https://github.com/docker-library/php/pull/542 -RUN set -eux; \ - { \ - echo 'Package: php*'; \ - echo 'Pin: release *'; \ - echo 'Pin-Priority: -1'; \ - } > /etc/apt/preferences.d/no-debian-php - -# dependencies required for running "phpize" -# (see persistent deps below) -ENV PHPIZE_DEPS \ - autoconf \ - dpkg-dev \ - file \ - g++ \ - gcc \ - libc-dev \ - make \ - pkg-config \ - re2c - -# persistent / runtime deps -RUN set -eux; \ - apt-get update; \ - apt-get install -y --no-install-recommends \ - $PHPIZE_DEPS \ - ca-certificates \ - curl \ - xz-utils \ - ; \ - rm -rf /var/lib/apt/lists/* - -ENV PHP_INI_DIR /usr/local/etc/php -RUN set -eux; \ - mkdir -p "$PHP_INI_DIR/conf.d"; \ -# allow running as an arbitrary user (https://github.com/docker-library/php/issues/743) - [ ! -d /var/www/html ]; \ - mkdir -p /var/www/html; \ - chown www-data:www-data /var/www/html; \ - chmod 1777 /var/www/html - -# Apply stack smash protection to functions using local buffers and alloca() -# Make PHP's main executable position-independent (improves ASLR security mechanism, and has no performance impact on x86_64) -# Enable optimization (-O2) -# Enable linker optimization (this sorts the hash buckets to improve cache locality, and is non-default) -# https://github.com/docker-library/php/issues/272 -# -D_LARGEFILE_SOURCE and -D_FILE_OFFSET_BITS=64 (https://www.php.net/manual/en/intro.filesystem.php) -ENV PHP_CFLAGS="-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" -ENV PHP_CPPFLAGS="$PHP_CFLAGS" -ENV PHP_LDFLAGS="-Wl,-O1 -pie" - -ENV GPG_KEYS D95C03BC702BE9515344AE3374E44BC9067701A5 016895DE9A475111D537A6E69134FF30BC5A99B5 5CFF17B64DC1C244F5D0EAC3E43535E2EB19010E - -ENV PHP_VERSION 8.6.0RC2 -ENV PHP_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz" PHP_ASC_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz.asc" -ENV PHP_SHA256="ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c" - -RUN set -eux; \ - \ - savedAptMark="$(apt-mark showmanual)"; \ - apt-get update; \ - apt-get install -y --no-install-recommends gnupg; \ - rm -rf /var/lib/apt/lists/*; \ - \ - mkdir -p /usr/src; \ - cd /usr/src; \ - \ - curl -fsSL -o php.tar.xz "$PHP_URL"; \ - \ - if [ -n "$PHP_SHA256" ]; then \ - echo "$PHP_SHA256 *php.tar.xz" | sha256sum -c -; \ - fi; \ - \ - curl -fsSL -o php.tar.xz.asc "$PHP_ASC_URL"; \ - export GNUPGHOME="$(mktemp -d)"; \ - for key in $GPG_KEYS; do \ - gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key"; \ - done; \ - gpg --batch --verify php.tar.xz.asc php.tar.xz; \ - gpgconf --kill all; \ - rm -rf "$GNUPGHOME"; \ - \ - apt-mark auto '.*' > /dev/null; \ - apt-mark manual $savedAptMark > /dev/null; \ - apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false - -COPY docker-php-source /usr/local/bin/ - -RUN set -eux; \ - \ - savedAptMark="$(apt-mark showmanual)"; \ - apt-get update; \ - apt-get install -y --no-install-recommends \ - libargon2-dev \ - libcurl4-openssl-dev \ - libreadline-dev \ - libsodium-dev \ - libsqlite3-dev \ - libssl-dev \ - libxml2-dev \ - zlib1g-dev \ - ; \ - \ - export \ - CFLAGS="$PHP_CFLAGS" \ - CPPFLAGS="$PHP_CPPFLAGS" \ - LDFLAGS="$PHP_LDFLAGS" \ -# https://github.com/php/php-src/blob/d6299206dd828382753453befd1b915491b741c6/configure.ac#L1496-L1511 - PHP_BUILD_PROVIDER='https://github.com/docker-library/php' \ - PHP_UNAME='Linux - Docker' \ - ; \ - docker-php-source extract; \ - cd /usr/src/php; \ - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; \ - debMultiarch="$(dpkg-architecture --query DEB_BUILD_MULTIARCH)"; \ -# https://bugs.php.net/bug.php?id=74125 - if [ ! -d /usr/include/curl ]; then \ - ln -sT "/usr/include/$debMultiarch/curl" /usr/local/include/curl; \ - fi; \ - case "$gnuArch" in \ - 'i686-linux-'*) \ - # php zend jit assumes SSE registers, xmm0-7, are available (and "Pentium4"/SSE2 is a reasonable baseline) - # https://github.com/php/php-src/pull/22832 - # so, allow it and use SSE/SSE2 floating-point unit instead of the legacy stack - export \ - CFLAGS="$CFLAGS -msse2 -mfpmath=sse" \ - CPPFLAGS="$CPPFLAGS -msse2 -mfpmath=sse" \ - ; \ - ;; \ - esac; \ - test "$PHP_INI_DIR" != "${PHP_INI_DIR%/php}"; \ - ./configure \ - --build="$gnuArch" \ - --sysconfdir="${PHP_INI_DIR%/php}" \ - --with-config-file-path="$PHP_INI_DIR" \ - --with-config-file-scan-dir="$PHP_INI_DIR/conf.d" \ - \ -# make sure invalid --configure-flags are fatal errors instead of just warnings - --enable-option-checking=fatal \ - \ -# https://github.com/docker-library/php/issues/439 - --with-mhash \ - \ -# https://github.com/docker-library/php/issues/822 -# https://github.com/php/php-src/pull/21067/changes#diff-4b9db5b77bcd56aa33b310dc44c8bc99c729c9abb195df2e98e6985b81289ae8R130 - --enable-pic \ - \ -# --enable-mysqlnd is included here because it's harder to compile after the fact than extensions are (since it's a plugin for several extensions, not an extension in itself) - --enable-mysqlnd \ -# https://wiki.php.net/rfc/argon2_password_hash - --with-password-argon2 \ -# https://wiki.php.net/rfc/libsodium - --with-sodium=shared \ -# always build against system sqlite3 (https://github.com/php/php-src/commit/6083a387a81dbbd66d6316a3a12a63f06d5f7109) - --with-pdo-sqlite=/usr \ - --with-sqlite3=/usr \ - \ - --with-curl \ - --with-iconv \ - --with-openssl \ - --with-readline \ - --with-zlib \ - \ -# https://github.com/docker-library/php/pull/1259 - --enable-phpdbg \ - --enable-phpdbg-readline \ - \ - --with-libdir="lib/$debMultiarch" \ - \ -# https://github.com/docker-library/php/pull/939#issuecomment-730501748 - --enable-embed \ - \ - --enable-zts \ -# https://externals.io/message/118859 - --disable-zend-signals \ - ; \ - make -j "$(nproc)"; \ - find -type f -name '*.a' -delete; \ - make install; \ - find \ - /usr/local \ - -type f \ - -perm '/0111' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : \ - ' -- '{}' + \ - ; \ - make clean; \ - \ -# https://github.com/docker-library/php/issues/692 (copy default example "php.ini" files somewhere easily discoverable) - cp -v php.ini-* "$PHP_INI_DIR/"; \ - \ - cd /; \ - docker-php-source delete; \ - \ -# reset apt-mark's "manual" list so that "purge --auto-remove" will remove all build dependencies - apt-mark auto '.*' > /dev/null; \ - [ -z "$savedAptMark" ] || apt-mark manual $savedAptMark; \ - find /usr/local -type f -executable -exec ldd '{}' ';' \ - | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' \ - | sort -u \ - | xargs -rt dpkg-query --search \ -# https://manpages.debian.org/trixie/dpkg/dpkg-query.1.en.html#S (we ignore diversions and it'll be really unusual for more than one package to provide any given .so file) - | awk 'sub(":$", "", $1) { print $1 }' \ - | sort -u \ - | xargs -r apt-mark manual \ - ; \ - apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \ - rm -rf /var/lib/apt/lists/*; \ - \ -# smoke test - php --version - -COPY docker-php-ext-* docker-php-entrypoint /usr/local/bin/ - -# sodium was built as a shared module (so that it can be replaced later if so desired), so let's enable it too (https://github.com/docker-library/php/issues/598) -RUN docker-php-ext-enable sodium - -ENTRYPOINT ["docker-php-entrypoint"] -CMD ["php", "-a"] diff --git a/8.6-rc/bookworm/zts/docker-php-entrypoint b/8.6-rc/bookworm/zts/docker-php-entrypoint deleted file mode 100755 index 88a016c16c..0000000000 --- a/8.6-rc/bookworm/zts/docker-php-entrypoint +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/sh -set -e - -# first arg is `-f` or `--some-option` -if [ "${1#-}" != "$1" ]; then - set -- php "$@" -fi - -exec "$@" diff --git a/8.6-rc/bookworm/zts/docker-php-ext-configure b/8.6-rc/bookworm/zts/docker-php-ext-configure deleted file mode 100755 index 34fc1337d5..0000000000 --- a/8.6-rc/bookworm/zts/docker-php-ext-configure +++ /dev/null @@ -1,69 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 ext-name [configure flags]" - echo " ie: $0 gd --with-jpeg-dir=/usr/local/something" - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -ext="$1" -if [ -z "$ext" ] || [ ! -d "$ext" ]; then - usage >&2 - exit 1 -fi -shift - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual .phpize-deps-configure $PHPIZE_DEPS - fi -fi - -if command -v dpkg-architecture > /dev/null; then - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)" - set -- --build="$gnuArch" "$@" -fi - -cd "$ext" -phpize -./configure --enable-option-checking=fatal "$@" diff --git a/8.6-rc/bookworm/zts/docker-php-ext-enable b/8.6-rc/bookworm/zts/docker-php-ext-enable deleted file mode 100755 index 41d20bbe3f..0000000000 --- a/8.6-rc/bookworm/zts/docker-php-ext-enable +++ /dev/null @@ -1,121 +0,0 @@ -#!/bin/sh -set -e - -extDir="$(php -d 'display_errors=stderr' -r 'echo ini_get("extension_dir");')" -cd "$extDir" - -usage() { - echo "usage: $0 [options] module-name [module-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 --ini-name 0-apc.ini apcu apc" - echo - echo 'Possible values for module-name:' - find -maxdepth 1 \ - -type f \ - -name '*.so' \ - -exec basename '{}' ';' \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?' --long 'help,ini-name:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -modules= -for module; do - if [ -z "$module" ]; then - continue - fi - if ! [ -f "$module" ] && ! [ -f "$module.so" ]; then - echo >&2 "error: '$module' does not exist" - echo >&2 - usage >&2 - exit 1 - fi - modules="$modules $module" -done - -if [ -z "$modules" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual '.docker-php-ext-enable-deps' binutils - apkDel='.docker-php-ext-enable-deps' - fi -fi - -for module in $modules; do - moduleFile="$module" - if [ -f "$module.so" ] && ! [ -f "$module" ]; then - moduleFile="$module.so" - fi - if readelf --wide --syms "$moduleFile" | grep -q ' zend_extension_entry$'; then - # https://wiki.php.net/internals/extensions#loading_zend_extensions - line="zend_extension=$module" - else - line="extension=$module" - fi - - ext="$(basename "$module")" - ext="${ext%.*}" - if php -d 'display_errors=stderr' -r 'exit(extension_loaded("'"$ext"'") ? 0 : 1);'; then - # this isn't perfect, but it's better than nothing - # (for example, 'opcache.so' presents inside PHP as 'Zend OPcache', not 'opcache') - echo >&2 - echo >&2 "warning: $ext ($module) is already loaded!" - echo >&2 - continue - fi - - case "$iniName" in - /*) - # allow an absolute path - ini="$iniName" - ;; - *) - ini="$PHP_INI_DIR/conf.d/${iniName:-"docker-php-ext-$ext.ini"}" - ;; - esac - if ! grep -qFx -e "$line" -e "$line.so" "$ini" 2>/dev/null; then - echo "$line" >> "$ini" - fi -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi diff --git a/8.6-rc/bookworm/zts/docker-php-ext-install b/8.6-rc/bookworm/zts/docker-php-ext-install deleted file mode 100755 index fbf44849c0..0000000000 --- a/8.6-rc/bookworm/zts/docker-php-ext-install +++ /dev/null @@ -1,143 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 [-jN] [--ini-name file.ini] ext-name [ext-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 -j5 gd mbstring mysqli pdo pdo_mysql shmop" - echo - echo 'if custom ./configure arguments are necessary, see docker-php-ext-configure' - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?j:' --long 'help,ini-name:,jobs:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -j=1 -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --jobs|-j) j="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -exts= -for ext; do - if [ -z "$ext" ]; then - continue - fi - if [ ! -d "$ext" ]; then - echo >&2 "error: $PWD/$ext does not exist" - echo >&2 - usage >&2 - exit 1 - fi - exts="$exts $ext" -done - -if [ -z "$exts" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if [ -n "$PHPIZE_DEPS" ]; then - if apk info --installed .phpize-deps-configure > /dev/null; then - apkDel='.phpize-deps-configure' - elif ! apk info --installed .phpize-deps > /dev/null; then - apk add --no-cache --virtual .phpize-deps $PHPIZE_DEPS - apkDel='.phpize-deps' - fi - fi -fi - -popDir="$PWD" -for ext in $exts; do - cd "$ext" - - [ -e Makefile ] || docker-php-ext-configure "$ext" - - make -j"$j" - - if ! php -n -d 'display_errors=stderr' -r 'exit(ZEND_DEBUG_BUILD ? 0 : 1);' > /dev/null; then - # only "strip" modules if we aren't using a debug build of PHP - # (none of our builds are debug builds, but PHP might be recompiled with "--enable-debug" configure option) - # https://github.com/docker-library/php/issues/1268 - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : - ' -- '{}' + - fi - - make -j"$j" install - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec basename '{}' '.so' ';' \ - | xargs -r docker-php-ext-enable ${iniName:+--ini-name "$iniName"} - - make -j"$j" clean - - cd "$popDir" -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi - -if [ -e /usr/src/php/.docker-delete-me ]; then - docker-php-source delete -fi diff --git a/8.6-rc/bookworm/zts/docker-php-source b/8.6-rc/bookworm/zts/docker-php-source deleted file mode 100755 index 9033d243de..0000000000 --- a/8.6-rc/bookworm/zts/docker-php-source +++ /dev/null @@ -1,34 +0,0 @@ -#!/bin/sh -set -e - -dir=/usr/src/php - -usage() { - echo "usage: $0 COMMAND" - echo - echo "Manage php source tarball lifecycle." - echo - echo "Commands:" - echo " extract extract php source tarball into directory $dir if not already done." - echo " delete delete extracted php source located into $dir if not already done." - echo -} - -case "$1" in - extract) - mkdir -p "$dir" - if [ ! -f "$dir/.docker-extracted" ]; then - tar -Jxf /usr/src/php.tar.xz -C "$dir" --strip-components=1 - touch "$dir/.docker-extracted" - fi - ;; - - delete) - rm -rf "$dir" - ;; - - *) - usage - exit 1 - ;; -esac diff --git a/8.6-rc/trixie/apache/Dockerfile b/8.6-rc/trixie/apache/Dockerfile index a9fef94e19..0e6c2564d5 100644 --- a/8.6-rc/trixie/apache/Dockerfile +++ b/8.6-rc/trixie/apache/Dockerfile @@ -239,6 +239,10 @@ RUN set -eux; \ --disable-cgi \ \ --with-apxs2 \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/trixie/cli/Dockerfile b/8.6-rc/trixie/cli/Dockerfile index 4d1e70fae4..7511a3ede5 100644 --- a/8.6-rc/trixie/cli/Dockerfile +++ b/8.6-rc/trixie/cli/Dockerfile @@ -178,6 +178,10 @@ RUN set -eux; \ \ # https://github.com/docker-library/php/pull/939#issuecomment-730501748 --enable-embed \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/trixie/fpm/Dockerfile b/8.6-rc/trixie/fpm/Dockerfile index 68ceaf54e6..df452eff6a 100644 --- a/8.6-rc/trixie/fpm/Dockerfile +++ b/8.6-rc/trixie/fpm/Dockerfile @@ -180,6 +180,10 @@ RUN set -eux; \ --enable-fpm \ --with-fpm-user=www-data \ --with-fpm-group=www-data \ + \ + --enable-zts \ +# https://externals.io/message/118859 + --disable-zend-signals \ ; \ make -j "$(nproc)"; \ find -type f -name '*.a' -delete; \ diff --git a/8.6-rc/trixie/zts/Dockerfile b/8.6-rc/trixie/zts/Dockerfile deleted file mode 100644 index 7511a3ede5..0000000000 --- a/8.6-rc/trixie/zts/Dockerfile +++ /dev/null @@ -1,229 +0,0 @@ -# -# NOTE: THIS DOCKERFILE IS GENERATED VIA "apply-templates.sh" -# -# PLEASE DO NOT EDIT IT DIRECTLY. -# - -FROM debian:trixie-slim - -# prevent Debian's PHP packages from being installed -# https://github.com/docker-library/php/pull/542 -RUN set -eux; \ - { \ - echo 'Package: php*'; \ - echo 'Pin: release *'; \ - echo 'Pin-Priority: -1'; \ - } > /etc/apt/preferences.d/no-debian-php - -# dependencies required for running "phpize" -# (see persistent deps below) -ENV PHPIZE_DEPS \ - autoconf \ - dpkg-dev \ - file \ - g++ \ - gcc \ - libc-dev \ - make \ - pkg-config \ - re2c - -# persistent / runtime deps -RUN set -eux; \ - apt-get update; \ - apt-get install -y --no-install-recommends \ - $PHPIZE_DEPS \ - ca-certificates \ - curl \ - xz-utils \ - ; \ - apt-get dist-clean - -ENV PHP_INI_DIR /usr/local/etc/php -RUN set -eux; \ - mkdir -p "$PHP_INI_DIR/conf.d"; \ -# allow running as an arbitrary user (https://github.com/docker-library/php/issues/743) - [ ! -d /var/www/html ]; \ - mkdir -p /var/www/html; \ - chown www-data:www-data /var/www/html; \ - chmod 1777 /var/www/html - -# Apply stack smash protection to functions using local buffers and alloca() -# Make PHP's main executable position-independent (improves ASLR security mechanism, and has no performance impact on x86_64) -# Enable optimization (-O2) -# Enable linker optimization (this sorts the hash buckets to improve cache locality, and is non-default) -# https://github.com/docker-library/php/issues/272 -# -D_LARGEFILE_SOURCE and -D_FILE_OFFSET_BITS=64 (https://www.php.net/manual/en/intro.filesystem.php) -ENV PHP_CFLAGS="-fstack-protector-strong -fpic -fpie -O2 -D_LARGEFILE_SOURCE -D_FILE_OFFSET_BITS=64" -ENV PHP_CPPFLAGS="$PHP_CFLAGS" -ENV PHP_LDFLAGS="-Wl,-O1 -pie" - -ENV GPG_KEYS D95C03BC702BE9515344AE3374E44BC9067701A5 016895DE9A475111D537A6E69134FF30BC5A99B5 5CFF17B64DC1C244F5D0EAC3E43535E2EB19010E - -ENV PHP_VERSION 8.6.0RC2 -ENV PHP_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz" PHP_ASC_URL="https://downloads.php.net/~mbeccati/php-8.6.0RC2.tar.xz.asc" -ENV PHP_SHA256="ef3fba21c311e9bbace0e2102702446d322c275b8a10e6b33b28f2561299671c" - -RUN set -eux; \ - \ - savedAptMark="$(apt-mark showmanual)"; \ - apt-get update; \ - apt-get install -y --no-install-recommends gnupg; \ - apt-get dist-clean; \ - \ - mkdir -p /usr/src; \ - cd /usr/src; \ - \ - curl -fsSL -o php.tar.xz "$PHP_URL"; \ - \ - if [ -n "$PHP_SHA256" ]; then \ - echo "$PHP_SHA256 *php.tar.xz" | sha256sum -c -; \ - fi; \ - \ - curl -fsSL -o php.tar.xz.asc "$PHP_ASC_URL"; \ - export GNUPGHOME="$(mktemp -d)"; \ - for key in $GPG_KEYS; do \ - gpg --batch --keyserver keyserver.ubuntu.com --recv-keys "$key"; \ - done; \ - gpg --batch --verify php.tar.xz.asc php.tar.xz; \ - gpgconf --kill all; \ - rm -rf "$GNUPGHOME"; \ - \ - apt-mark auto '.*' > /dev/null; \ - apt-mark manual $savedAptMark > /dev/null; \ - apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false - -COPY docker-php-source /usr/local/bin/ - -RUN set -eux; \ - \ - savedAptMark="$(apt-mark showmanual)"; \ - apt-get update; \ - apt-get install -y --no-install-recommends \ - libargon2-dev \ - libcurl4-openssl-dev \ - libreadline-dev \ - libsodium-dev \ - libsqlite3-dev \ - libssl-dev \ - libxml2-dev \ - zlib1g-dev \ - ; \ - \ - export \ - CFLAGS="$PHP_CFLAGS" \ - CPPFLAGS="$PHP_CPPFLAGS" \ - LDFLAGS="$PHP_LDFLAGS" \ -# https://github.com/php/php-src/blob/d6299206dd828382753453befd1b915491b741c6/configure.ac#L1496-L1511 - PHP_BUILD_PROVIDER='https://github.com/docker-library/php' \ - PHP_UNAME='Linux - Docker' \ - ; \ - docker-php-source extract; \ - cd /usr/src/php; \ - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)"; \ - debMultiarch="$(dpkg-architecture --query DEB_BUILD_MULTIARCH)"; \ -# https://bugs.php.net/bug.php?id=74125 - if [ ! -d /usr/include/curl ]; then \ - ln -sT "/usr/include/$debMultiarch/curl" /usr/local/include/curl; \ - fi; \ - case "$gnuArch" in \ - 'i686-linux-'*) \ - # php zend jit assumes SSE registers, xmm0-7, are available (and "Pentium4"/SSE2 is a reasonable baseline) - # https://github.com/php/php-src/pull/22832 - # so, allow it and use SSE/SSE2 floating-point unit instead of the legacy stack - export \ - CFLAGS="$CFLAGS -msse2 -mfpmath=sse" \ - CPPFLAGS="$CPPFLAGS -msse2 -mfpmath=sse" \ - ; \ - ;; \ - esac; \ - test "$PHP_INI_DIR" != "${PHP_INI_DIR%/php}"; \ - ./configure \ - --build="$gnuArch" \ - --sysconfdir="${PHP_INI_DIR%/php}" \ - --with-config-file-path="$PHP_INI_DIR" \ - --with-config-file-scan-dir="$PHP_INI_DIR/conf.d" \ - \ -# make sure invalid --configure-flags are fatal errors instead of just warnings - --enable-option-checking=fatal \ - \ -# https://github.com/docker-library/php/issues/439 - --with-mhash \ - \ -# https://github.com/docker-library/php/issues/822 -# https://github.com/php/php-src/pull/21067/changes#diff-4b9db5b77bcd56aa33b310dc44c8bc99c729c9abb195df2e98e6985b81289ae8R130 - --enable-pic \ - \ -# --enable-mysqlnd is included here because it's harder to compile after the fact than extensions are (since it's a plugin for several extensions, not an extension in itself) - --enable-mysqlnd \ -# https://wiki.php.net/rfc/argon2_password_hash - --with-password-argon2 \ -# https://wiki.php.net/rfc/libsodium - --with-sodium=shared \ -# always build against system sqlite3 (https://github.com/php/php-src/commit/6083a387a81dbbd66d6316a3a12a63f06d5f7109) - --with-pdo-sqlite=/usr \ - --with-sqlite3=/usr \ - \ - --with-curl \ - --with-iconv \ - --with-openssl \ - --with-readline \ - --with-zlib \ - \ -# https://github.com/docker-library/php/pull/1259 - --enable-phpdbg \ - --enable-phpdbg-readline \ - \ - --with-libdir="lib/$debMultiarch" \ - \ -# https://github.com/docker-library/php/pull/939#issuecomment-730501748 - --enable-embed \ - \ - --enable-zts \ -# https://externals.io/message/118859 - --disable-zend-signals \ - ; \ - make -j "$(nproc)"; \ - find -type f -name '*.a' -delete; \ - make install; \ - find \ - /usr/local \ - -type f \ - -perm '/0111' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : \ - ' -- '{}' + \ - ; \ - make clean; \ - \ -# https://github.com/docker-library/php/issues/692 (copy default example "php.ini" files somewhere easily discoverable) - cp -v php.ini-* "$PHP_INI_DIR/"; \ - \ - cd /; \ - docker-php-source delete; \ - \ -# reset apt-mark's "manual" list so that "purge --auto-remove" will remove all build dependencies - apt-mark auto '.*' > /dev/null; \ - [ -z "$savedAptMark" ] || apt-mark manual $savedAptMark; \ - find /usr/local -type f -executable -exec ldd '{}' ';' \ - | awk '/=>/ { so = $(NF-1); if (index(so, "/usr/local/") == 1) { next }; gsub("^/(usr/)?", "", so); printf "*%s\n", so }' \ - | sort -u \ - | xargs -rt dpkg-query --search \ -# https://manpages.debian.org/trixie/dpkg/dpkg-query.1.en.html#S (we ignore diversions and it'll be really unusual for more than one package to provide any given .so file) - | awk 'sub(":$", "", $1) { print $1 }' \ - | sort -u \ - | xargs -r apt-mark manual \ - ; \ - apt-get purge -y --auto-remove -o APT::AutoRemove::RecommendsImportant=false; \ - apt-get dist-clean; \ - \ -# smoke test - php --version - -COPY docker-php-ext-* docker-php-entrypoint /usr/local/bin/ - -# sodium was built as a shared module (so that it can be replaced later if so desired), so let's enable it too (https://github.com/docker-library/php/issues/598) -RUN docker-php-ext-enable sodium - -ENTRYPOINT ["docker-php-entrypoint"] -CMD ["php", "-a"] diff --git a/8.6-rc/trixie/zts/docker-php-entrypoint b/8.6-rc/trixie/zts/docker-php-entrypoint deleted file mode 100755 index 88a016c16c..0000000000 --- a/8.6-rc/trixie/zts/docker-php-entrypoint +++ /dev/null @@ -1,9 +0,0 @@ -#!/bin/sh -set -e - -# first arg is `-f` or `--some-option` -if [ "${1#-}" != "$1" ]; then - set -- php "$@" -fi - -exec "$@" diff --git a/8.6-rc/trixie/zts/docker-php-ext-configure b/8.6-rc/trixie/zts/docker-php-ext-configure deleted file mode 100755 index 34fc1337d5..0000000000 --- a/8.6-rc/trixie/zts/docker-php-ext-configure +++ /dev/null @@ -1,69 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 ext-name [configure flags]" - echo " ie: $0 gd --with-jpeg-dir=/usr/local/something" - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -ext="$1" -if [ -z "$ext" ] || [ ! -d "$ext" ]; then - usage >&2 - exit 1 -fi -shift - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual .phpize-deps-configure $PHPIZE_DEPS - fi -fi - -if command -v dpkg-architecture > /dev/null; then - gnuArch="$(dpkg-architecture --query DEB_BUILD_GNU_TYPE)" - set -- --build="$gnuArch" "$@" -fi - -cd "$ext" -phpize -./configure --enable-option-checking=fatal "$@" diff --git a/8.6-rc/trixie/zts/docker-php-ext-enable b/8.6-rc/trixie/zts/docker-php-ext-enable deleted file mode 100755 index 41d20bbe3f..0000000000 --- a/8.6-rc/trixie/zts/docker-php-ext-enable +++ /dev/null @@ -1,121 +0,0 @@ -#!/bin/sh -set -e - -extDir="$(php -d 'display_errors=stderr' -r 'echo ini_get("extension_dir");')" -cd "$extDir" - -usage() { - echo "usage: $0 [options] module-name [module-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 --ini-name 0-apc.ini apcu apc" - echo - echo 'Possible values for module-name:' - find -maxdepth 1 \ - -type f \ - -name '*.so' \ - -exec basename '{}' ';' \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?' --long 'help,ini-name:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -modules= -for module; do - if [ -z "$module" ]; then - continue - fi - if ! [ -f "$module" ] && ! [ -f "$module.so" ]; then - echo >&2 "error: '$module' does not exist" - echo >&2 - usage >&2 - exit 1 - fi - modules="$modules $module" -done - -if [ -z "$modules" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if \ - [ -n "$PHPIZE_DEPS" ] \ - && ! apk info --installed .phpize-deps > /dev/null \ - && ! apk info --installed .phpize-deps-configure > /dev/null \ - ; then - apk add --no-cache --virtual '.docker-php-ext-enable-deps' binutils - apkDel='.docker-php-ext-enable-deps' - fi -fi - -for module in $modules; do - moduleFile="$module" - if [ -f "$module.so" ] && ! [ -f "$module" ]; then - moduleFile="$module.so" - fi - if readelf --wide --syms "$moduleFile" | grep -q ' zend_extension_entry$'; then - # https://wiki.php.net/internals/extensions#loading_zend_extensions - line="zend_extension=$module" - else - line="extension=$module" - fi - - ext="$(basename "$module")" - ext="${ext%.*}" - if php -d 'display_errors=stderr' -r 'exit(extension_loaded("'"$ext"'") ? 0 : 1);'; then - # this isn't perfect, but it's better than nothing - # (for example, 'opcache.so' presents inside PHP as 'Zend OPcache', not 'opcache') - echo >&2 - echo >&2 "warning: $ext ($module) is already loaded!" - echo >&2 - continue - fi - - case "$iniName" in - /*) - # allow an absolute path - ini="$iniName" - ;; - *) - ini="$PHP_INI_DIR/conf.d/${iniName:-"docker-php-ext-$ext.ini"}" - ;; - esac - if ! grep -qFx -e "$line" -e "$line.so" "$ini" 2>/dev/null; then - echo "$line" >> "$ini" - fi -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi diff --git a/8.6-rc/trixie/zts/docker-php-ext-install b/8.6-rc/trixie/zts/docker-php-ext-install deleted file mode 100755 index fbf44849c0..0000000000 --- a/8.6-rc/trixie/zts/docker-php-ext-install +++ /dev/null @@ -1,143 +0,0 @@ -#!/bin/sh -set -e - -# prefer user supplied CFLAGS, but default to our PHP_CFLAGS -: ${CFLAGS:=$PHP_CFLAGS} -: ${CPPFLAGS:=$PHP_CPPFLAGS} -: ${LDFLAGS:=$PHP_LDFLAGS} -export CFLAGS CPPFLAGS LDFLAGS - -srcExists= -if [ -d /usr/src/php ]; then - srcExists=1 -fi -docker-php-source extract -if [ -z "$srcExists" ]; then - touch /usr/src/php/.docker-delete-me -fi - -cd /usr/src/php/ext - -usage() { - echo "usage: $0 [-jN] [--ini-name file.ini] ext-name [ext-name ...]" - echo " ie: $0 gd mysqli" - echo " $0 pdo pdo_mysql" - echo " $0 -j5 gd mbstring mysqli pdo pdo_mysql shmop" - echo - echo 'if custom ./configure arguments are necessary, see docker-php-ext-configure' - echo - echo 'Possible values for ext-name:' - find . \ - -mindepth 2 \ - -maxdepth 2 \ - -type f \ - -name 'config.m4' \ - | xargs -n1 dirname \ - | xargs -n1 basename \ - | sort \ - | xargs - echo - echo 'Some of the above modules are already compiled into PHP; please check' - echo 'the output of "php -i" to see which modules are already loaded.' -} - -opts="$(getopt -o 'h?j:' --long 'help,ini-name:,jobs:' -- "$@" || { usage >&2 && false; })" -eval set -- "$opts" - -j=1 -iniName= -while true; do - flag="$1" - shift - case "$flag" in - --help|-h|'-?') usage && exit 0 ;; - --ini-name) iniName="$1" && shift ;; - --jobs|-j) j="$1" && shift ;; - --) break ;; - *) - { - echo "error: unknown flag: $flag" - usage - } >&2 - exit 1 - ;; - esac -done - -exts= -for ext; do - if [ -z "$ext" ]; then - continue - fi - if [ ! -d "$ext" ]; then - echo >&2 "error: $PWD/$ext does not exist" - echo >&2 - usage >&2 - exit 1 - fi - exts="$exts $ext" -done - -if [ -z "$exts" ]; then - usage >&2 - exit 1 -fi - -pm='unknown' -if [ -e /lib/apk/db/installed ]; then - pm='apk' -fi - -apkDel= -if [ "$pm" = 'apk' ]; then - if [ -n "$PHPIZE_DEPS" ]; then - if apk info --installed .phpize-deps-configure > /dev/null; then - apkDel='.phpize-deps-configure' - elif ! apk info --installed .phpize-deps > /dev/null; then - apk add --no-cache --virtual .phpize-deps $PHPIZE_DEPS - apkDel='.phpize-deps' - fi - fi -fi - -popDir="$PWD" -for ext in $exts; do - cd "$ext" - - [ -e Makefile ] || docker-php-ext-configure "$ext" - - make -j"$j" - - if ! php -n -d 'display_errors=stderr' -r 'exit(ZEND_DEBUG_BUILD ? 0 : 1);' > /dev/null; then - # only "strip" modules if we aren't using a debug build of PHP - # (none of our builds are debug builds, but PHP might be recompiled with "--enable-debug" configure option) - # https://github.com/docker-library/php/issues/1268 - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec sh -euxc ' \ - strip --strip-all "$@" || : - ' -- '{}' + - fi - - make -j"$j" install - - find modules \ - -maxdepth 1 \ - -name '*.so' \ - -exec basename '{}' '.so' ';' \ - | xargs -r docker-php-ext-enable ${iniName:+--ini-name "$iniName"} - - make -j"$j" clean - - cd "$popDir" -done - -if [ "$pm" = 'apk' ] && [ -n "$apkDel" ]; then - apk del --no-network $apkDel -fi - -if [ -e /usr/src/php/.docker-delete-me ]; then - docker-php-source delete -fi diff --git a/8.6-rc/trixie/zts/docker-php-source b/8.6-rc/trixie/zts/docker-php-source deleted file mode 100755 index 9033d243de..0000000000 --- a/8.6-rc/trixie/zts/docker-php-source +++ /dev/null @@ -1,34 +0,0 @@ -#!/bin/sh -set -e - -dir=/usr/src/php - -usage() { - echo "usage: $0 COMMAND" - echo - echo "Manage php source tarball lifecycle." - echo - echo "Commands:" - echo " extract extract php source tarball into directory $dir if not already done." - echo " delete delete extracted php source located into $dir if not already done." - echo -} - -case "$1" in - extract) - mkdir -p "$dir" - if [ ! -f "$dir/.docker-extracted" ]; then - tar -Jxf /usr/src/php.tar.xz -C "$dir" --strip-components=1 - touch "$dir/.docker-extracted" - fi - ;; - - delete) - rm -rf "$dir" - ;; - - *) - usage - exit 1 - ;; -esac diff --git a/Dockerfile-linux.template b/Dockerfile-linux.template index a2da3cf0e9..f32636aeb2 100644 --- a/Dockerfile-linux.template +++ b/Dockerfile-linux.template @@ -25,7 +25,7 @@ def need_patch_18743: # https://github.com/docker-library/php/pull/1580 # https://github.com/php/php-src/issues/18743 "Incompatibility in Inline TLS Assembly on Alpine 3.22 with zend_jit_ir.c" - env.variant == "zts" # only needed for ZTS builds + env.variant == "zts" and is_alpine and IN(rcVersion; "8.2") ; @@ -433,7 +433,7 @@ RUN set -eux; \ --disable-cgi \ {{ ) end -}} {{ # zts + alpine special cased for embed (otherwise zts is effectively cli): https://github.com/docker-library/php/pull/1342 -}} -{{ if (env.variant == "zts") or (env.variant == "cli" and (is_alpine | not)) then ( -}} +{{ if env.variant == "zts" or (env.variant == "cli" and ((rcVersion | version_id) >= 80600 or (is_alpine | not))) then ( -}} \ # https://github.com/docker-library/php/pull/939#issuecomment-730501748 --enable-embed \ @@ -446,7 +446,8 @@ RUN set -eux; \ --enable-fpm \ --with-fpm-user=www-data \ --with-fpm-group=www-data \ -{{ ) elif env.variant == "zts" then ( -}} +{{ ) else "" end -}} +{{ if env.variant == "zts" or (rcVersion | version_id) >= 80600 then ( -}} \ --enable-zts \ # https://externals.io/message/118859 diff --git a/versions.json b/versions.json index bc42dc8528..a4d051fb45 100644 --- a/versions.json +++ b/versions.json @@ -100,17 +100,13 @@ "trixie/cli", "trixie/apache", "trixie/fpm", - "trixie/zts", "bookworm/cli", "bookworm/apache", "bookworm/fpm", - "bookworm/zts", "alpine3.24/cli", "alpine3.24/fpm", - "alpine3.24/zts", "alpine3.23/cli", - "alpine3.23/fpm", - "alpine3.23/zts" + "alpine3.23/fpm" ] } } diff --git a/versions.sh b/versions.sh index 1e1f7e71cf..f31c50de0c 100755 --- a/versions.sh +++ b/versions.sh @@ -103,7 +103,7 @@ for version in "${versions[@]}"; do "cli", "apache", "fpm", - "zts", + (if env.rcVersion | IN("8.2", "8.3", "8.4", "8.5") then "zts" else empty end), empty ) as $variant | if $suite | startswith("alpine") and $variant == "apache" then empty else