Bug #76631 [Opn->Csd]: Nested serialize() with shared references yields wrong result

From: Date: Mon, 16 Jul 2018 12:39:20 +0000
Subject: Bug #76631 [Opn->Csd]: Nested serialize() with shared references yields wrong result
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216345@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76631&edit=1 ID: 76631 User updated by: niklas dot correnz at hcom dot de Reported by: niklas dot correnz at hcom dot de Summary: Nested serialize() with shared references yields wrong result -Status: Open +Status: Closed Type: Bug Package: *General Issues Operating System: Ubuntu 16.04 PHP Version: 7.1.19 Block user comment: N Private report: N New Comment: Bad report, the unserialize is the problem. Previous Comments: ------------------------------------------------------------------------ [2018-07-16 12:30:50] niklas dot correnz at hcom dot de Description: ------------ When implementing \Serializable a nested serialize() call will cause the end result to be messed up. Nested serialize() calls often occur when extending classes and overwriting serialize with additional fields, so this is not unusual. Our test script simulates this by nesting serialize(). The result still break, if the array with the referenced objects is not inside the nested serialize(), but instead any additional property is serialized with a nested call (not in the test script). Test script: --------------- $role1 = new \stdClass(); $role1->name = 'role1'; $role2 = new \stdClass(); $role2->name = 'role2'; class group implements \Serializable { private $roles; public function __construct(array $roles) { $this->roles = $roles; } public function serialize() { return serialize([serialize($this->roles)]); } public function unserialize($serialized) { $this->roles = unserialize(unserialize($serialized)[0]); } } $group1 = new \group([$role1, $role2]); $group2 = new \group([$role1, $role2]); $serialized = serialize([$group1, $group2]); echo "$serialized\n"; Expected result: ---------------- a:2:{i:0;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i:1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}i:1;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}} Actual result: -------------- a:2:{i:0;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i:1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}i:1;C:5:"group":40:{a:1:{i:0;s:22:"a:2:{i:0;r:4;i:1;r:6;}";}}} ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76631&edit=1

« previous php.bugs (#216345) next »