Bug #72171 [Com]: unserialize() throws a Fatal Error on inaccessible parent classes

From: Date: Fri, 06 May 2016 14:44:05 +0000
Subject: Bug #72171 [Com]: unserialize() throws a Fatal Error on inaccessible parent classes
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200926@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=72171&edit=1

 ID:                 72171
 Comment by:         php at maisqi dot com
 Reported by:        php at maisqi dot com
 Summary:            unserialize() throws a Fatal Error on inaccessible
                     parent classes
 Status:             Not a bug
 Type:               Bug
 Package:            Scripting Engine problem
 Operating System:   Windows, Linux
 PHP Version:        7.0.6
 Block user comment: N
 Private report:     N

 New Comment:

Maybe it's as intended but it's not documented that way -- the docs don't event
mention the word «fatal».
And even if it were documented, the fact is that anything can happen when we're unserializing.
I'd say that all programmers expect unserialize() to either success or fail, not to abort the
whole script -- it's a Fatal Error not an Exception (the latter would be acceptable).

nickic, can you please make a feature request out of this? At a minimum, there's a security
flaw here (it's easy to sabotage a script if we can control the data that it tries to
unserialize).


Previous Comments:
------------------------------------------------------------------------
[2016-05-06 13:32:29] nikic@php.net

The behavior is as intended. What you are seeing is an error generated during execution of
autoloaded code -- that this error happens to be caused by an undefined class is only incidental.
The autoloader might as well cause some other fatal error, throw an exception, cause an exit etc. It
is not the job of the unserialize() function to deal with these failures (nor can it, in the general
case).

------------------------------------------------------------------------
[2016-05-06 11:48:12] php at maisqi dot com

Description:
------------
When unserialize() finds a non-defined class it tries to autload it; but if that succeeds, but that
class' base class is not "autoloadable", a Fatal Error is thrown.

This makes the unserialize() function totally unpredictable, because we should get a couple of
references to __PHP_Incomplete_Class but may just as well get the script aborted.

Test script:
---------------
<?php
// file: "test.php"
spl_autoload_register(function($className) {});
spl_autoload_register(function($className) {	require_once 'ExistingClass.php';	});

$code = 'O:13:"ExistingClass":0:{}';
$o = unserialize($code);

print_r($o);
// file ends

<?php
// file: "ExistingClass.php"
class ExistingClass extends NonExistingClass {}
// file ends


Expected result:
----------------
unserialize() should return a __PHP_Incomplete_Class object.

Actual result:
--------------
It throws a Fatal Error.

This happens in PHP 7.0.6 x64 running on Windows 8 and in PHP 5.5.33 running on Linux CentOS.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=72171&edit=1


Thread (5 messages)

« previous php.bugs (#200926) next »