Bug #76631 [NEW]: Nested serialize() with shared references yields wrong result
| From: | niklas dot correnz at hcom dot de | Date: | Mon, 16 Jul 2018 12:30:52 +0000 |
| Subject: | Bug #76631 [NEW]: Nested serialize() with shared references yields wrong result | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-216348@lists.php.net to get a copy of this message | ||
From: niklas dot correnz at hcom dot de
Operating system: Ubuntu 16.04
PHP version: 7.1.19
Package: *General Issues
Bug Type: Bug
Bug description:Nested serialize() with shared references yields wrong result
Description:
------------
When implementing \Serializable a nested serialize() call will cause the
end result to be messed up.
Nested serialize() calls often occur when extending classes and
overwriting serialize with additional fields, so this is not unusual.
Our test script simulates this by nesting serialize().
The result still break, if the array with the referenced objects is not
inside the nested serialize(), but instead any additional property is
serialized with a nested call (not in the test script).
Test script:
---------------
$role1 = new \stdClass();
$role1->name = 'role1';
$role2 = new \stdClass();
$role2->name = 'role2';
class group implements \Serializable {
private $roles;
public function __construct(array $roles) {
$this->roles = $roles;
}
public function serialize() {
return serialize([serialize($this->roles)]);
}
public function unserialize($serialized) {
$this->roles = unserialize(unserialize($serialized)[0]);
}
}
$group1 = new \group([$role1, $role2]);
$group2 = new \group([$role1, $role2]);
$serialized = serialize([$group1, $group2]);
echo "$serialized\n";
Expected result:
----------------
a:2:{i:0;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i:1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}i:1;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}}
Actual result:
--------------
a:2:{i:0;C:5:"group":116:{a:1:{i:0;s:98:"a:2:{i:0;O:8:"stdClass":1:{s:4:"name";s:5:"role1";}i:1;O:8:"stdClass":1:{s:4:"name";s:5:"role2";}}";}}i:1;C:5:"group":40:{a:1:{i:0;s:22:"a:2:{i:0;r:4;i:1;r:6;}";}}}
--
Edit bug report at https://bugs.php.net/bug.php?id=76631&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=76631&r=trysnapshot54
Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=76631&r=trysnapshot55
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=76631&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=76631&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=76631&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=76631&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=76631&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=76631&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=76631&r=support
Expected behavior: https://bugs.php.net/fix.php?id=76631&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=76631&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=76631&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=76631&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=76631&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=76631&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=76631&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=76631&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=76631&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=76631&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=76631&r=mysqlcfg