Bug #67363 [Opn]: Unserialize corrupts data
| From: | nikic@php.net | Date: | Sat, 07 Jan 2017 22:15:21 +0000 |
| Subject: | Bug #67363 [Opn]: Unserialize corrupts data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-206366@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67363&edit=1
ID: 67363
Updated by: nikic@php.net
Reported by: mg at artigo dot pl
Summary: Unserialize corrupts data
Status: Open
Type: Bug
Package: Variables related
Operating System: Irrelavant
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
@laszlokorte: In that case you're probably hit by bug #66052 (see also my comment on bug
#73253).
Previous Comments:
------------------------------------------------------------------------
[2017-01-07 22:08:51] php at laszlokorte dot de
@jh1711 You re right. I fixed the bug in the gist. But mainDef is not correctly unserialized in
php<7 anyway and in my real application I still get the "unserialize(): Error at offset 1026
of 1348 byte error" in a similar but more complex situation (deeper nestings, more properties,
but no cycles)
------------------------------------------------------------------------
[2017-01-07 19:57:26] jh1711 at xmail dot net
@laszlokorte, there's a mistake in your gist. Definition::unserialize should pass $data to
unserialize, or use $value as a parameter. Unserializing an uninitialized variable causes the false
values, and not unserializing the parameter messes up the references. See https://3v4l.org/vioIT .
@nikic, imho the cause of bug #66085 is serializing additional data during serialization. Of course
this can result in similar behaviour. See https://3v4l.org/9hVS2 .
------------------------------------------------------------------------
[2017-01-07 18:36:19] php at laszlokorte dot de
@nikic Thanks, indeed the problem of the gist I posted is solved by php7. But in my real application
I now get many "Notice: unserialize(): Error at offset 1026 of 1348 bytes" errors.
------------------------------------------------------------------------
[2017-01-07 17:58:57] nikic@php.net
@laszlokorte: That is most likely bug #66085, which is fixed in PHP 7.0 (but not 5.6).
------------------------------------------------------------------------
[2017-01-07 17:45:03] php at laszlokorte dot de
Not sure if this is the correct issue but I came across some problem with serialize/unserialize.
(php-5.6.14)
I have created a gist to reproduce it:
https://gist.github.com/laszlokorte/3948f40873346cc1fd9b8c11ab06ae04
The problem is that if an object contains a another object as child in multiple places that child
does not get (un)serialized correctly. Not just that the identity of the multiple occurrences is not
preserved but the object is not unserialized correctly at all. It's easier to understand by
looking at gist.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=67363
--
Edit this bug report at https://bugs.php.net/bug.php?id=67363&edit=1