Bug #75713 [Nab]: Serialization bug: wrong variable name length

From: Date: Wed, 20 Dec 2017 17:09:46 +0000
Subject: Bug #75713 [Nab]: Serialization bug: wrong variable name length
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-213185@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75713&edit=1 ID: 75713 Updated by: requinix@php.net Reported by: axtux at hotmail dot com Summary: Serialization bug: wrong variable name length Status: Not a bug Type: Bug Package: *Data Exchange functions Operating System: Linux/Ubuntu PHP Version: 7.0Git-2017-12-20 (Git) Block user comment: N Private report: N New Comment: > The string 'O:4:"Test":2:{s:2:"v1";N;s:8:"Testv2";N;}' > is actually what is returned by serialize function. Try it. No, actually, it isn't. Read what I said. Previous Comments: ------------------------------------------------------------------------ [2017-12-20 17:06:28] axtux at hotmail dot com You misunderstood. The string 'O:4:"Test":2:{s:2:"v1";N;s:8:"Testv2";N;}' is actually what is returned by serialize function. Try it. The reason why I set $s to it because for some reasons, unserialize(serialize($obj)) does not print a notice (maybe some optimization ?). ------------------------------------------------------------------------ [2017-12-20 16:36:40] requinix@php.net Serialized strings are binary data containing mostly printable characters. Your $s = 'O:4:"Test":2:{s:2:"v1";N;s:8:"Testv2";N;}'; is invalid. Simply echoing the original $s will not show you the full picture. Try with addslashes(). ------------------------------------------------------------------------ [2017-12-20 16:27:41] axtux at hotmail dot com Description: ------------ Versions tested and affected : PHP 7.0.28-dev (cli) (built: Dec 20 2017 16:38:38) ( NTS ) PHP 7.0.22-0ubuntu0.16.04.1 (cli) ( NTS ) PHP serialization is buggy when using private class variables. Steps to reproduce : 1. create Test class with at least one private variable 2. create an instance of this class and serialize it This leads to notice/warning/error when unserializing serialized string. See test snippet of code https://pastebin.com/D9yM4G58 Test script: --------------- error_reporting(E_ALL); class Test { public $v1; private $v2; } $t = new Test(); $s = serialize($t); echo $s; // copy value or notice is not shown $s = 'O:4:"Test":2:{s:2:"v1";N;s:8:"Testv2";N;}'; $u = unserialize($s); Expected result: ---------------- good variable name length Actual result: -------------- variable name length is 2 more than expected ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75713&edit=1

« previous php.bugs (#213185) next »