Bug #74687 [Opn->Dup]: __wakeup called for nested serialized object after Serializable::unserialize
| From: | nikic@php.net | Date: | Thu, 01 Jun 2017 10:02:47 +0000 |
| Subject: | Bug #74687 [Opn->Dup]: __wakeup called for nested serialized object after Serializable::unserialize | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-209339@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74687&edit=1
ID: 74687
Updated by: nikic@php.net
Reported by: taco at procurios dot nl
Summary: __wakeup called for nested serialized object after
Serializable::unserialize
-Status: Open
+Status: Duplicate
Type: Bug
Package: Unknown/Other Function
Operating System: linux
PHP Version: 5.6.30
Block user comment: N
Private report: N
New Comment:
Duplicate of bug #74436. TL;DR is that this is an intentional change due to a security fix. We
haven't found a way to address both the security issues this fixes and preserve the existing
behavior.
Previous Comments:
------------------------------------------------------------------------
[2017-06-01 09:55:53] taco at procurios dot nl
Description:
------------
When an object is unserialized within the unserialize method of a Serializable implementation, its
__wakeup method will be called _after_ the unserialize call is finished, making the object invalid
during the unserialize call.
Most likely (based on the changelogs of the first affected php versions) this behaviour was
introduced by the fix for this bug: https://bugs.php.net/bug.php?id=70213
Test script:
---------------
Problem: https://3v4l.org/MlbuO
.phpt file: https://gist.githubusercontent.com/tacovandenbroek/0ed29d1a449c57dfb4335d1ec4b00cae/raw/42fdc427521969f0affe719cf84f829098824ba0/php%20__wakeup%20bug.phpt
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74687&edit=1