Bug #76632 [NEW]: Nested serialize() with shared references yields wrong unserialization

From: Date: Mon, 16 Jul 2018 12:43:32 +0000
Subject: Bug #76632 [NEW]: Nested serialize() with shared references yields wrong unserialization
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216346@lists.php.net to get a copy of this message
From: niklas dot correnz at hcom dot de Operating system: Ubuntu 16.04 PHP version: 7.1.19 Package: *General Issues Bug Type: Bug Bug description:Nested serialize() with shared references yields wrong unserialization Description: ------------ When implementing \Serializable a nested serialize() call will cause the unserialized() result to be messed up. Nested serialize() calls often occur when extending classes and overwriting serialize with additional fields, so this is not unusual. Our test script simulates this by nesting serialize(). The result still break, if the array with the referenced objects is not inside the nested serialize(), but instead any additional property is serialized with a nested call (not in the test script). Test script: --------------- $role1 = new \stdClass(); $role1->name = 'role1'; $role2 = new \stdClass(); $role2->name = 'role2'; class group implements \Serializable { private $roles; public function __construct(array $roles) { $this->roles = $roles; } public function serialize() { return serialize([serialize($this->roles)]); } public function unserialize($serialized) { $this->roles = unserialize(unserialize($serialized)[0]); } } $group1 = new \group([$role1, $role2]); $group2 = new \group([$role1, $role2]); var_dump(unserialize(serialize([$group1, $group2]))); Expected result: ---------------- array (size=2) 0 => object(group)[5] private 'roles' => array (size=2) 0 => object(stdClass)[6] public 'name' => string 'role1' (length=5) 1 => object(stdClass)[7] public 'name' => string 'role2' (length=5) 1 => object(group)[8] private 'roles' => array (size=2) 0 => object(stdClass)[6] public 'name' => string 'role1' (length=5) 1 => object(stdClass)[7] public 'name' => string 'role2' (length=5) Actual result: -------------- array (size=2) 0 => object(group)[5] private 'roles' => array (size=2) 0 => object(stdClass)[6] public 'name' => string 'role1' (length=5) 1 => object(stdClass)[7] public 'name' => string 'role2' (length=5) 1 => object(group)[8] private 'roles' => array (size=2) 0 => string 'a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i:1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}' (length=98) 1 => object(stdClass)[6] public 'name' => string 'role1' (length=5) -- Edit bug report at https://bugs.php.net/bug.php?id=76632&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76632&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76632&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76632&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=76632&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=76632&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=76632&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=76632&r=needscript Try newer version: https://bugs.php.net/fix.php?id=76632&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=76632&r=support Expected behavior: https://bugs.php.net/fix.php?id=76632&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=76632&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=76632&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=76632&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76632&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=76632&r=dst IIS Stability: https://bugs.php.net/fix.php?id=76632&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=76632&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=76632&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=76632&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=76632&r=mysqlcfg

« previous php.bugs (#216346) next »