Bug #65591 [Opn->Dup]: Segfault when calling parent::serialize in serialize().
| From: | nikic@php.net | Date: | Sun, 01 Jan 2017 12:12:42 +0000 |
| Subject: | Bug #65591 [Opn->Dup]: Segfault when calling parent::serialize in serialize(). | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206273@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65591&edit=1
ID: 65591
Updated by: nikic@php.net
Reported by: arjen at react dot com
Summary: Segfault when calling parent::serialize in
serialize().
-Status: Open
+Status: Duplicate
Type: Bug
Package: Reproducible crash
Operating System: Linux
PHP Version: 5.5.6
Block user comment: N
Private report: N
New Comment:
The PHP 7 issue is a duplicate of bug #70767, which is resolved as of PHP 7.0.14. Bug #66085 may
also be playing into this on PHP 5.
Previous Comments:
------------------------------------------------------------------------
[2015-04-21 20:15:55] dimon dot ksk at gmail dot com
Additional example:
http://3v4l.org/gMDup
https://gist.github.com/dimarick/2a116047282baecd17e8
This bug occured when serialize calls from \Serializable::serialize() more then once, and in
serialized data one object instance used once or more.
Helpful code references:
https://github.com/php/php-src/blob/PHP-5.5.24/ext/standard/var.c#L576
https://github.com/php/php-src/blob/PHP-5.5.24/ext/standard/var.c#L726
------------------------------------------------------------------------
[2014-12-06 14:39:32] andrzej at code dot eu
Problem is not resolved. It can bee seeing on url http://3v4l.org/PBT99
in UsernamePasswordToken->roles[0]->webshop is ok but
UsernamePasswordToken->roles[1]->webshop is array not instance of Webshop class
------------------------------------------------------------------------
[2014-05-22 11:41:30] arjen at react dot com
This is fixed on the PHPNG (PHP 5.7) branch: http://3v4l.org/QFDDc#v57@20140507
------------------------------------------------------------------------
[2013-12-12 11:53:30] arjen at react dot com
Still crashes, see http://3v4l.org/QFDDc
------------------------------------------------------------------------
[2013-08-30 09:03:11] arjen at react dot com
Description:
------------
From https://bugs.php.net/bug.php?id=63481&edit=3
Created new issue cause it's different from original bugreport.
See
https://gist.github.com/aurelijus/4713758
Crashes 5.4.0 - 5.5.3: http://3v4l.org/PBT99
Test script:
---------------
<?php
class Permission implements \Serializable {
protected $id = 3;
public function serialize()
{
return serialize(array($this->id));
}
public function unserialize($serialized)
{
list($this->id) = unserialize($serialized);
}
}
class UserPermission implements \Serializable {
public $permission;
public $webshop;
public function serialize()
{
return serialize(array($this->webshop, $this->permission));
}
public function unserialize($serialized)
{
list($this->webshop, $this->permission) = unserialize($serialized);
}
}
class Webshop implements \Serializable {
protected $id = 13;
public function serialize()
{
return serialize(array($this->id));
}
public function unserialize($serialized)
{
list($this->id) = unserialize($serialized);
}
}
class AbstractToken implements \Serializable {
public $roles;
public function serialize()
{
return serialize(array($this->roles));
}
public function unserialize($serialized)
{
list($this->roles) = unserialize($serialized);
}
}
class UsernamePasswordToken extends AbstractToken {
private $credentials = null;
private $providerKey = null;
public function serialize()
{
return serialize(array($this->credentials, $this->providerKey, parent::serialize()));
}
public function unserialize($str)
{
list($this->credentials, $this->providerKey, $parentStr) = unserialize($str);
parent::unserialize($parentStr);
}
}
$token = new UsernamePasswordToken();
$webshop = new Webshop;
$permission = new Permission;
$roles = array();
for ($i = 0; $i < 2; $i++) {
$roles[$i] = new UserPermission();
$roles[$i]->webshop = $webshop;
$roles[$i]->permission = $permission;
}
$token->roles = $roles;
var_dump(unserialize(serialize($token)));
Actual result:
--------------
segfault
Backtrace @ https://gist.github.com/anonymous/5720464
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65591&edit=1