Problem/Motivation

D7's INSTALL.txt still mentions PHP 5.2 and MySQL 5.0 along with several other post EOL versions.

The community has been gradually updating D7's testing configuration on drupal.org in #3092260: [policy, no patch] Review and update automated testing config for 7.x branch.

The documentation page at https://www.drupal.org/docs/7/system-requirements/php-requirements is fairly up-to-date.

Proposed resolution

We need to decide on what minimum requirements are actually supported, and update all docs (+ testing config) accordingly.

In practical terms there's no intention to start introducing more modern PHP features that would break support on older PHP versions - for example D7 core will retain the long array syntax.

We do sometimes encounter issues where it'd be useful to use features that were introduced a long time ago in e.g. PHP 5.3 or 5.6, and it'd be helpful to have an official policy on where any cut off is.

Do any sites still realistically require PHP 5.3 support? Do any distros still support PHP 5.x?

There's no guarantee that the testing infrastructure for such old versions will remain available; it's getting increasingly onerous to set up those environments.

Comments

mcdruid created an issue. See original summary.

mcdruid’s picture

Looks like support for PHP 5.x is over in Debian - https://wiki.debian.org/PHP says Jessie 8 had PHP 5.6 but that went EOL mid 2020.

Ubuntu 16.04 which is still supported under ESM shipped with PHP 7.0, but actually 14.04 is covered by ESM until April 2024 now ( https://canonical.com/blog/ubuntu-14-04-and-16-04-lifecycle-extended-to-... ). Trusty (14.04) shipped with PHP 5.5.

Centos7 shipped with PHP 5.4 and still seems to be supported until mid-2024 according to https://wiki.centos.org/About/Product

So as of late 2022 it looks like a couple of the major distros still have some support for PHP 5.4 and PHP 5.5 for another ~18 months or so.

I'm inclined to say that any PHP features introduced in PHP 5.3 (or later) are okay to use, and in practical terms PHP 5.x in general is likely to receive minimal testing (I don't really expect any contrib projects are that careful about testing on such old versions).

I think the recommendation should be (/ remain) PHP 7.x or later.

mcdruid’s picture

I managed to get a PHP 5.2 environment going in docker (https://github.com/clagomess/docker-php-5.2 with the oracle stuff commented out FWIW).

It looks a lot like D7 doesn't work under PHP 5.2 at the moment anyway, which is not hugely surprising when we don't have automated testing available.

It probably wouldn't be a big deal to fix the initial problems that I ran across, as they're a few variations on this:

PHP Warning:  Unexpected character in input:  '\\' (ASCII=92) state=1 in /usr/local/apache2/htdocs/drupal/includes/bootstrap.inc on line 3948

PHP Warning:  Unexpected character in input:  '\\' (ASCII=92) state=1 in /usr/local/apache2/htdocs/drupal/includes/bootstrap.inc on line 3971

PHP Warning:  Unexpected character in input:  '\\' (ASCII=92) state=1 in /usr/local/apache2/htdocs/drupal/modules/system/system.install on line 545

PHP Warning:  Unexpected character in input:  '\\' (ASCII=92) state=1 in /usr/local/apache2/htdocs/drupal/includes/session.inc on line 293

It looks like this is down to namespaces which are not supported in PHP 5.2 so e.g.

$dom = new \DOMDocument('1.0', 'UTF-8');

...and:

if (\PHP_VERSION_ID >= 70300) {

...cause problems.

We could fix these, but I'm not sure we should. If nobody has complained (AFAIK) about this since these changes were made...

There may be other issues too, and I don't think we should devote any resources to this.

That makes me think drawing the line at PHP 5.3 (with a recommendation to upgrade beyond PHP 5.x) is fine.

poker10’s picture

I agree that fixing PHP 5.2 compatibility issues would be a inefficiently used time, unless there are good reasons to fix that (which I won't see). I doubt there is lot of sites running on PHP 5.2 and similar.

Probably the current "line" could be on PHP 5.3.3, which is anyway "required" by this SA - https://www.drupal.org/sa-core-2019-002

mcdruid’s picture

Status: Active » Needs review
StatusFileSize
new1.87 KB

First pass at updating INSTALL.txt

I've removed some of the specifics about MySQL alternatives and generally based the minimum requirements on what we know D7 core currently passes tests with.

poker10’s picture

The changes looks good to me, +1.

Maybe it wouldn't be a bad idea if, in addition, we change the links to the PHP and MySQL/PostgreSQL/SQLite websites to the HTTPS variants, but it is only cosmetic change.

Just a note, after this will be commited, we will need to update these two pages as well:

mcdruid’s picture

StatusFileSize
new2.4 KB
new3.49 KB

Thanks - updated the links as suggested. I've not gone through and changed every URL but the new ones we're adding should all be https now.

I've also updated the DRUPAL_MINIMUM_PHP constant, and another check that happens in install.php before the constant is defined.

There are a few other mentions of PHP 5.2 dotted around - e.g.:

/var/www/drupal-7.x$ grep -rn 'PHP 5\.2' *

includes/stream_wrappers.inc:13: * Note that PHP 5.2 fopen() only supports URIs of the form "scheme://target"
includes/filetransfer/filetransfer.inc:395: * available in PHP 5.2.
includes/authorize.inc:323:      // PHP 5.2 doesn't support $class::factory() syntax, so we have to
includes/password.inc:177:  // We rely on the hash() function being available in PHP 5.2+.
includes/file.inc:2418:  // Check that the URI has a value. There is a bug in PHP 5.2 on *BSD systems
includes/file.inc:2421:  // @todo Remove when Drupal drops support for PHP 5.2.
modules/simpletest/tests/file.test:2627:    // rawurlencode() in PHP 5.2 but not in PHP 5.3, as per RFC 3986.
modules/simpletest/drupal_web_test_case.php:582:      // backwards compatibility with PHP 5.2.
modules/system/system.install:76:  // 8.04 ships with PHP 5.2.4, but includes the necessary security patch.
modules/system/system.install:78:    $requirements['php']['description'] = $t('Your PHP installation is too old. Drupal requires at least PHP 5.2.5, or PHP @version with the htmlspecialchars security patch backported.', array('@version' => DRUPAL_MINIMUM_PHP));

Some of these could now be removed, but I think that could be looked at in a followup.


As for updating the system requirements docs page, there's the issue of whether PHP versions still have upstream support from the PHP maintainers (which will soon mean only PHP 8.x) but then of course there are lots of providers that do provide extended support of one form or another.

I'd say it's sufficient to mention that it's not a good idea to run a version without some ongoing upstream / provider support but we don't really need to get into tracking those details. Newer is generally more better :)

poker10’s picture

Status: Needs review » Reviewed & tested by the community
Issue tags: +Needs change record

Let's go ahead with this. We also got +1 from @Fabianx on Slack.

It needs a change record, so people are aware of this change. It would not be possible for example to install a new Drupal 7 on PHP lower than 5.3.3 (also update.php will be blocked because of un-met requirements), see:

  if (version_compare($phpversion, DRUPAL_MINIMUM_PHP) < 0) {
    $requirements['php']['description'] = $t('Your PHP installation is too old. Drupal requires at least PHP %version.', array('%version' => DRUPAL_MINIMUM_PHP));
    $requirements['php']['severity'] = REQUIREMENT_ERROR;
    // If PHP is old, it's not safe to continue with the requirements check.
    return $requirements;
  }

  • mcdruid committed db31224 on 7.x
    Issue #3319435 by mcdruid, poker10: Update system requirements (...
mcdruid’s picture

Status: Reviewed & tested by the community » Fixed
Issue tags: -Needs change record

Draft CR: https://www.drupal.org/node/3322488 ... it's fairly light on detail so far - do we need to add more about what the increased minimum constraint actually means in practice?

Committed - thanks!

poker10’s picture

I have found this 4-years old issue discussing the similar, probably we can give credits also to the people from that issue?

#2581193: [Drupal 7] Require PHP 5.3

And yes, I think that 1 short sentence explaining possible consequences of this change will be worth, so that people are aware what can happen.

Status: Fixed » Closed (fixed)

Automatically closed - issue fixed for 2 weeks with no activity.

poker10’s picture