Bug #67452 [Com]: clone and serialize issue

From: Date: Fri, 12 Dec 2014 16:42:08 +0000
Subject: Bug #67452 [Com]: clone and serialize issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-189042@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67452&edit=1 ID: 67452 Comment by: nikic@php.net Reported by: remi@php.net Summary: clone and serialize issue Status: Open Type: Bug Package: *General Issues Operating System: GNU/LInux (32 bits) PHP Version: 5.4+ Block user comment: N Private report: N New Comment: Apart from the free_list issue, the patch has the additional problems that object R refs will not be created for objects created in serialize(). Consider the following script: <?php class Test implements Serializable { public function serialize() { $obj = new stdClass; return serialize([$obj, $obj]); } public function unserialize($str) { var_dump(unserialize($str)); } } unserialize(serialize(new Test)); Here an array with two identical objects is serialized and as such it also should unserialize to the same object. Current behavior: ~/dev/php-5.6$ sapi/cli/php t18.php array(2) { [0]=> object(stdClass)#2 (0) { } [1]=> object(stdClass)#2 (0) { } } After patch: ~/dev/php-5.6$ sapi/cli/php t18.php array(2) { [0]=> object(stdClass)#2 (0) { } [1]=> object(stdClass)#3 (0) { } } So just excluding objects created during serialize() might solve the test failure, but will introduce problems in other cases. I think the only way to fix this issue is to retain a reference to all objects that are serialized and drop it after serialization is finished. This avoids the possibility that object handles or memory addresses are reused during serialization. This is how this was fixed in PHP 7: https://github.com/php/php-src/commit/8be73f2650582423ec1d3c4b65a77c450f6683a0 https://github.com/php/php-src/commit/75860fa8e1d8ce0c9fd2b505bf7663a4936a7a39 However the same approach is likely not feasible in 5.x due to ABI restrictions. Previous Comments: ------------------------------------------------------------------------ [2014-06-20 12:46:44] mbeccati@php.net Bug was reproducted on NetBSD i386. The patch fixes the issue. ------------------------------------------------------------------------ [2014-06-17 09:58:32] remi@php.net This first patch seems to fix this runtime issue, and don't break other serialize tests. This is not a perfect solution, as handle free list is ignored. ------------------------------------------------------------------------ [2014-06-17 09:56:47] remi@php.net The following patch has been added/updated: Patch Name: serialize.patch Revision: 1402999007 URL: https://bugs.php.net/patch-display.php?bug=67452&patch=serialize.patch&revision=1402999007 ------------------------------------------------------------------------ [2014-06-16 11:34:03] remi@php.net This test is failing since introduced in 5.4.22 ------------------------------------------------------------------------ [2014-06-16 11:16:44] remi@php.net Enabling debug output in php_add_var_hash(), with (type, zend_objects_get_address, handle): var_no + add var (5, f6e11b18, 6): 1 + add var (4, 0, 0): 2 + add var (5, f6e1169c, 7): 3 + add var (5, f6e13d94, b): 4 + add var (1, 0, 0): 5 + add var (5, f6e1175c, 9): 6 - had var (5, f6e13d94, b): 4 ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=67452 -- Edit this bug report at https://bugs.php.net/bug.php?id=67452&edit=1

« previous php.bugs (#189042) next »