Bug #72171 [Nab]: unserialize() throws a Fatal Error on inaccessible parent classes
Edit report at https://bugs.php.net/bug.php?id=72171&edit=1
ID: 72171
User updated by: php at maisqi dot com
Reported by: php at maisqi dot com
Summary: unserialize() throws a Fatal Error on inaccessible
parent classes
Status: Not a bug
Type: Bug
Package: Scripting Engine problem
Operating System: Windows, Linux
PHP Version: 7.0.6
Block user comment: N
Private report: N
New Comment:
@inefedor, I know that. Thing is, there will always be someone doing it. But this «undocumented
behaviour» makes the unserialize() function unpredictable. That's not good and could be
avoided.
Previous Comments:
------------------------------------------------------------------------
[2016-05-09 11:49:42] inefedor at gmail dot com
Serialized data was never intended to be trusted if it comes from user, this is a mistake to trust
user input. For more information see https://www.owasp.org/index.php/Deserialization_of_untrusted_data
------------------------------------------------------------------------
[2016-05-06 14:43:59] php at maisqi dot com
Maybe it's as intended but it's not documented that way -- the docs don't event
mention the word «fatal».
And even if it were documented, the fact is that anything can happen when we're unserializing.
I'd say that all programmers expect unserialize() to either success or fail, not to abort the
whole script -- it's a Fatal Error not an Exception (the latter would be acceptable).
nickic, can you please make a feature request out of this? At a minimum, there's a security
flaw here (it's easy to sabotage a script if we can control the data that it tries to
unserialize).
------------------------------------------------------------------------
[2016-05-06 13:32:29] nikic@php.net
The behavior is as intended. What you are seeing is an error generated during execution of
autoloaded code -- that this error happens to be caused by an undefined class is only incidental.
The autoloader might as well cause some other fatal error, throw an exception, cause an exit etc. It
is not the job of the unserialize() function to deal with these failures (nor can it, in the general
case).
------------------------------------------------------------------------
[2016-05-06 11:48:12] php at maisqi dot com
Description:
------------
When unserialize() finds a non-defined class it tries to autload it; but if that succeeds, but that
class' base class is not "autoloadable", a Fatal Error is thrown.
This makes the unserialize() function totally unpredictable, because we should get a couple of
references to __PHP_Incomplete_Class but may just as well get the script aborted.
Test script:
---------------
<?php
// file: "test.php"
spl_autoload_register(function($className) {});
spl_autoload_register(function($className) { require_once 'ExistingClass.php'; });
$code = 'O:13:"ExistingClass":0:{}';
$o = unserialize($code);
print_r($o);
// file ends
<?php
// file: "ExistingClass.php"
class ExistingClass extends NonExistingClass {}
// file ends
Expected result:
----------------
unserialize() should return a __PHP_Incomplete_Class object.
Actual result:
--------------
It throws a Fatal Error.
This happens in PHP 7.0.6 x64 running on Windows 8 and in PHP 5.5.33 running on Linux CentOS.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=72171&edit=1
Thread (5 messages)