Req #49649 [Opn->Csd]: unserialize() doesn't handle changes in property visibility

From: Date: Mon, 10 Jul 2017 06:27:19 +0000
Subject: Req #49649 [Opn->Csd]: unserialize() doesn't handle changes in property visibility
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209951@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=49649&edit=1 ID: 49649 Updated by: krakjoe@php.net Reported by: coolfactor at mac dot com Summary: unserialize() doesn't handle changes in property visibility -Status: Open +Status: Closed Type: Feature/Change Request Package: Class/Object related Operating System: OS X 10.5.8 PHP Version: 5.3.0 Block user comment: N Private report: N New Comment: Automatic comment on behalf of mail@pmmaga.net Revision: http://git.php.net/?p=php-src.git;a=commit;h=7cb5bdf64a95bd70623d33d6ea122c13b01113bd Log: Fix #49649 - Handle property visibility changes on unserialization Previous Comments: ------------------------------------------------------------------------ [2017-01-01 20:49:19] nikic@php.net Related To: Bug #68319 ------------------------------------------------------------------------ [2009-09-24 07:15:30] coolfactor at mac dot com Furthermore: 1. there's no way to unset() the public version. 2. using __sleep() to return the properties to serialize results in the public version being serialized again, so there's no way to migrate the values permanently without reconstructing the object from scratch. ------------------------------------------------------------------------ [2009-09-24 07:08:06] coolfactor at mac dot com Description: ------------ Unserializing an object after changing some of its class properties' from public to protected results in properties present in both states. (As a workaround, migration code can be written using get_object_vars() to update the a protected property from the corresponding public version within a __wakeup() call.) Reproduce code: --------------- (It's difficult to write reproduce code for this, so I hope the following step-by-steps are OK) 1. Object "John" of class "Person" stored in serialized form has property "age" with public visibility. 2. Change visibility of property "age" in class definition to "protected". 3. Unserialize "John". The property "age" will be present in both public and protected states. 4. Attempting to access the "age" property directly correctly returns the value stored in the protected version. 5. Using get_object_vars() returns the value stored in the public version. Expected result: ---------------- Changes in property visibility should migrate the values gracefully upon unserialization. Properties by any given name should only exist once, but the current behavior conflicts with that. Actual result: -------------- Both versions of a property (public and protected) exist in unserialized object. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=49649&edit=1

« previous php.bugs (#209951) next »