Bug #69792 [NEW]: Stack Overflow in JSON with JsonSerializable
| From: | ryat@php.net | Date: | Wed, 10 Jun 2015 12:44:30 +0000 |
| Subject: | Bug #69792 [NEW]: Stack Overflow in JSON with JsonSerializable | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-193302@lists.php.net to get a copy of this message | ||
From: ryat
Operating system: *
PHP version: 5.4.41
Package: JSON related
Bug Type: Bug
Bug description:Stack Overflow in JSON with JsonSerializable
Description:
------------
```
static void json_encode_serializable_object(smart_str *buf, zval *val,
int options TSRMLS_DC) /* {{{ */
{
...
ZVAL_STRING(&fname, "jsonSerialize", 0);
if (FAILURE == call_user_function_ex(EG(function_table), &val, &fname,
&retval, 0, NULL, 1, NULL TSRMLS_CC) || !retval) {
zend_throw_exception_ex(NULL, 0 TSRMLS_CC, "Failed calling
%s::jsonSerialize()", ce->name);
smart_str_appendl(buf, "null", sizeof("null") - 1);
return;
}
...
if ((Z_TYPE_P(retval) == IS_OBJECT) &&
(Z_OBJ_HANDLE_P(retval) == Z_OBJ_HANDLE_P(val))) {
/* Handle the case where jsonSerialize does: return $this; by going
straight to encode array */
json_encode_array(buf, &retval, options TSRMLS_CC);
} else {
/* All other types, encode as normal */
php_json_encode(buf, retval, options TSRMLS_CC);
}
zval_ptr_dtor(&retval);
}
/* }}} */
PHP_JSON_API void php_json_encode(smart_str *buf, zval *val, int options
TSRMLS_DC) /* {{{ */
{
switch (Z_TYPE_P(val))
{
...
case IS_OBJECT:
if (instanceof_function(Z_OBJCE_P(val), php_json_serializable_ce
TSRMLS_CC)) {
json_encode_serializable_object(buf, val, options TSRMLS_CC);
break;
}
```
The following code should crash PHP:
```
class JsonTest implements JsonSerializable {
public function jsonSerialize() {
return new JsonTest;
// $obj = new JsonTest;
// return array($obj);
}
}
$obj = new JsonTest;
json_encode($obj);
```
--
Edit bug report at https://bugs.php.net/bug.php?id=69792&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=69792&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=69792&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=69792&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=69792&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=69792&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=69792&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=69792&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=69792&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=69792&r=support
Expected behavior: https://bugs.php.net/fix.php?id=69792&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=69792&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=69792&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=69792&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=69792&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=69792&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=69792&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=69792&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=69792&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=69792&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=69792&r=mysqlcfg