Bug #67363 [Opn]: Unserialize corrupts data
| From: | mg at artigo dot pl | Date: | Fri, 27 Jun 2014 11:18:52 +0000 |
| Subject: | Bug #67363 [Opn]: Unserialize corrupts data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186361@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67363&edit=1
ID: 67363
User updated by: mg at artigo dot pl
Reported by: mg at artigo dot pl
Summary: Unserialize corrupts data
Status: Open
Type: Bug
Package: Variables related
Operating System: Irrelavant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
We just had the same issue on a different server (FCGI 5.4.27)
String currupted by unserialize:
"ticketshop-promo-summer-ticket" => "ticketshop-promo.summ(NUL)r-ticket"
Previous Comments:
------------------------------------------------------------------------
[2014-06-05 15:33:46] mg at artigo dot pl
I just experienced the same issue on a totally different setup
apache + mod_php 5.5.11 + zend opcache
String "Opinion Leader des Tages"
became "Opinion Leader dfs Taes"
after unserialize.
------------------------------------------------------------------------
[2014-06-02 07:57:12] mg at artigo dot pl
Regarding the original problem with unserialize corruption issue:
In this single case "Make-up & Styling" became "Make-up ' Sty ing"
& = hex 26 became ' = hex 27
l = hex 6c became (nul) = hex 00
The changes in characters are always different and seem random.
It is worth mentioning that the issue appears out of nowhere and can be fixed by restarting the
server. It seems memory related. For this reason it is not possible to provide a bug testing
snippet, because it simply won't create the same issue on another machine, although it may get
it's own unique corruption on a random day.
The issue presents itself always on Apache server (various versions 2-2.4), mod_php or FCGI.
------------------------------------------------------------------------
[2014-06-02 06:52:16] mg at artigo dot pl
The information in comments is irrelevant. The corruption does not occur, because the object itself
changes, but it is the same with any change of it - only some combinations of values cause
corruption. The difference in serialize output is related to classes serialize method which removes
the "parent" field.
------------------------------------------------------------------------
[2014-05-30 17:18:50] mg at artigo dot pl
It turns out I simplified Case 1 too much, I attach the whole information again:
------------
It seems that serialize function has something to do with it. It returns different outputs in the
following cases:
Case 1:
unserialize(serialize($data));
echo serialize($data); // output:
https://dl.dropboxusercontent.com/u/11435743/php/serialize_unserialize_serialize.txt
Case 2:
echo serialize($data); // output:
https://dl.dropboxusercontent.com/u/11435743/php/serialize.txt
Data corruption DOES NOT occur when I run unserialize on the output of Case 1.
Data corruption DOES occur when I run unserialize on the output of Case 2.
Example of the currupted outputs are attached in the original post.
To summarize: putting additional unserialize(serialize($data)); before serialize($data); seems to
workaround the corruption by resulting in a different output of the second call of serialize
function. This output can then be safely passed to unserialize function and the corruption does not
occur.
------------------------------------------------------------------------
[2014-05-30 17:00:41] mg at artigo dot pl
Please excuse the error in the sentence:
I attach this example, because data corruption does NOT seem to occur in Case 1. It seems only to
occur in Case 2.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67363
--
Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1