Bug #69792 [Opn->Wfx]: Stack Overflow in JSON with JsonSerializable

From: Date: Sun, 30 Apr 2017 15:26:31 +0000
Subject: Bug #69792 [Opn->Wfx]: Stack Overflow in JSON with JsonSerializable
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-208871@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69792&edit=1

 ID:                 69792
 Updated by:         bukka@php.net
 Reported by:        ryat@php.net
 Summary:            Stack Overflow in JSON with JsonSerializable
-Status:             Open
+Status:             Wont fix
 Type:               Bug
 Package:            JSON related
 Operating System:   *
 PHP Version:        5.4.41
 Block user comment: N
 Private report:     N

 New Comment:

The proposed path won't work in PHP 7.1+ as it relies on shared global context that was changed
to an independent context because it was causing other issues and it's usage in here is also
incorrect as it's not a json depth but function call depth in this context. This is a general
problem of recursion that is not specific to json but any recursive function. As such I don't
think it should be specially addressed in here.


Previous Comments:
------------------------------------------------------------------------
[2015-06-10 13:38:12] cmb@php.net

Actually, this is a duplicate of bug #67265. This ticket had been
closed as "not a bug", but there has been some disagreement, so
I'm leaving this ticket open.

------------------------------------------------------------------------
[2015-06-10 12:44:28] ryat@php.net

Description:
------------
```
static void json_encode_serializable_object(smart_str *buf, zval *val, int options TSRMLS_DC) /* {{{
*/
{
	...
	ZVAL_STRING(&fname, "jsonSerialize", 0);

	if (FAILURE == call_user_function_ex(EG(function_table), &val, &fname, &retval, 0,
NULL, 1, NULL TSRMLS_CC) || !retval) {
		zend_throw_exception_ex(NULL, 0 TSRMLS_CC, "Failed calling %s::jsonSerialize()",
ce->name);
		smart_str_appendl(buf, "null", sizeof("null") - 1);
		return;
    }
	...
	if ((Z_TYPE_P(retval) == IS_OBJECT) &&
		(Z_OBJ_HANDLE_P(retval) == Z_OBJ_HANDLE_P(val))) {
		/* Handle the case where jsonSerialize does: return $this; by going straight to encode array */
		json_encode_array(buf, &retval, options TSRMLS_CC);
	} else {
		/* All other types, encode as normal */
		php_json_encode(buf, retval, options TSRMLS_CC);
	}

	zval_ptr_dtor(&retval);
}
/* }}} */

PHP_JSON_API void php_json_encode(smart_str *buf, zval *val, int options TSRMLS_DC) /* {{{ */
{
	switch (Z_TYPE_P(val))
	{
		...
		case IS_OBJECT:
			if (instanceof_function(Z_OBJCE_P(val), php_json_serializable_ce TSRMLS_CC)) {
				json_encode_serializable_object(buf, val, options TSRMLS_CC);
				break;
			}
```

The following code should crash PHP:

```
class JsonTest implements JsonSerializable {
    public function jsonSerialize() {
		return new JsonTest;
//		$obj = new JsonTest;
//		return array($obj);
    }
}

$obj = new JsonTest;
json_encode($obj);
```



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=69792&edit=1


Thread (3 messages)

« previous php.bugs (#208871) next »