Bug #69792 [NEW]: Stack Overflow in JSON with JsonSerializable

From: Date: Wed, 10 Jun 2015 12:44:30 +0000
Subject: Bug #69792 [NEW]: Stack Overflow in JSON with JsonSerializable
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193302@lists.php.net to get a copy of this message
From: ryat Operating system: * PHP version: 5.4.41 Package: JSON related Bug Type: Bug Bug description:Stack Overflow in JSON with JsonSerializable Description: ------------ ``` static void json_encode_serializable_object(smart_str *buf, zval *val, int options TSRMLS_DC) /* {{{ */ { ... ZVAL_STRING(&fname, "jsonSerialize", 0); if (FAILURE == call_user_function_ex(EG(function_table), &val, &fname, &retval, 0, NULL, 1, NULL TSRMLS_CC) || !retval) { zend_throw_exception_ex(NULL, 0 TSRMLS_CC, "Failed calling %s::jsonSerialize()", ce->name); smart_str_appendl(buf, "null", sizeof("null") - 1); return; } ... if ((Z_TYPE_P(retval) == IS_OBJECT) && (Z_OBJ_HANDLE_P(retval) == Z_OBJ_HANDLE_P(val))) { /* Handle the case where jsonSerialize does: return $this; by going straight to encode array */ json_encode_array(buf, &retval, options TSRMLS_CC); } else { /* All other types, encode as normal */ php_json_encode(buf, retval, options TSRMLS_CC); } zval_ptr_dtor(&retval); } /* }}} */ PHP_JSON_API void php_json_encode(smart_str *buf, zval *val, int options TSRMLS_DC) /* {{{ */ { switch (Z_TYPE_P(val)) { ... case IS_OBJECT: if (instanceof_function(Z_OBJCE_P(val), php_json_serializable_ce TSRMLS_CC)) { json_encode_serializable_object(buf, val, options TSRMLS_CC); break; } ``` The following code should crash PHP: ``` class JsonTest implements JsonSerializable { public function jsonSerialize() { return new JsonTest; // $obj = new JsonTest; // return array($obj); } } $obj = new JsonTest; json_encode($obj); ``` -- Edit bug report at https://bugs.php.net/bug.php?id=69792&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69792&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69792&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69792&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=69792&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=69792&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=69792&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=69792&r=needscript Try newer version: https://bugs.php.net/fix.php?id=69792&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=69792&r=support Expected behavior: https://bugs.php.net/fix.php?id=69792&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=69792&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=69792&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=69792&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69792&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=69792&r=dst IIS Stability: https://bugs.php.net/fix.php?id=69792&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=69792&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=69792&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=69792&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=69792&r=mysqlcfg

« previous php.bugs (#193302) next »