Bug #74687 [Opn->Dup]: __wakeup called for nested serialized object after Serializable::unserialize

From: Date: Thu, 01 Jun 2017 10:02:47 +0000
Subject: Bug #74687 [Opn->Dup]: __wakeup called for nested serialized object after Serializable::unserialize
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209339@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=74687&edit=1 ID: 74687 Updated by: nikic@php.net Reported by: taco at procurios dot nl Summary: __wakeup called for nested serialized object after Serializable::unserialize -Status: Open +Status: Duplicate Type: Bug Package: Unknown/Other Function Operating System: linux PHP Version: 5.6.30 Block user comment: N Private report: N New Comment: Duplicate of bug #74436. TL;DR is that this is an intentional change due to a security fix. We haven't found a way to address both the security issues this fixes and preserve the existing behavior. Previous Comments: ------------------------------------------------------------------------ [2017-06-01 09:55:53] taco at procurios dot nl Description: ------------ When an object is unserialized within the unserialize method of a Serializable implementation, its __wakeup method will be called _after_ the unserialize call is finished, making the object invalid during the unserialize call. Most likely (based on the changelogs of the first affected php versions) this behaviour was introduced by the fix for this bug: https://bugs.php.net/bug.php?id=70213 Test script: --------------- Problem: https://3v4l.org/MlbuO .phpt file: https://gist.githubusercontent.com/tacovandenbroek/0ed29d1a449c57dfb4335d1ec4b00cae/raw/42fdc427521969f0affe719cf84f829098824ba0/php%20__wakeup%20bug.phpt ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=74687&edit=1

« previous php.bugs (#209339) next »