Bug #73836 [NEW]: unserialize() with $options['allowed_classes'] = null behaves different

From: Date: Thu, 29 Dec 2016 19:04:17 +0000
Subject: Bug #73836 [NEW]: unserialize() with $options['allowed_classes'] = null behaves different
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-206229@lists.php.net to get a copy of this message
From: denis dot brumann at sensiolabs dot de Operating system: macOS Sierra PHP version: 7.1.0 Package: Unknown/Other Function Bug Type: Bug Bug description:unserialize() with $options['allowed_classes'] = null behaves different Description: ------------ I just built a polyfill around the $options parameter added to unserialize() in PHP 7.0. I noticed a different behaviour when allowed_classes is set to null (instead of false) when using PHP 7.0 and 7.1. See Travis builds: 7.0 (fails) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532454 7.1 (passes) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532455 This is the test that's being executed: https://github.com/dbrumann/polyfill-unserialize/blob/master/tests/UnserializeTest.php#L74 It seems that PHP 7.1 shows a warning, whereas 7.0 does not. I would expect PHP 7.0 to show the same warning. Test script: --------------- $serialized = serialize(new \stdClass()); unserialize($serialized, ['allowed_classes' => null]); Expected result: ---------------- I would expect both versions to behave the same, either both throw a warning (seems more plausible or neither does). -- Edit bug report at https://bugs.php.net/bug.php?id=73836&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=73836&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=73836&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=73836&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=73836&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=73836&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=73836&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=73836&r=needscript Try newer version: https://bugs.php.net/fix.php?id=73836&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=73836&r=support Expected behavior: https://bugs.php.net/fix.php?id=73836&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=73836&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=73836&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=73836&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=73836&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=73836&r=dst IIS Stability: https://bugs.php.net/fix.php?id=73836&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=73836&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=73836&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=73836&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=73836&r=mysqlcfg

« previous php.bugs (#206229) next »