Bug #77302 [Com]: Unserialize decode issue

From: Date: Tue, 22 Jan 2019 12:07:44 +0000
Subject: Bug #77302 [Com]: Unserialize decode issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219126@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77302&edit=1 ID: 77302 Comment by: o dot ilyushyn at superbody dot com Reported by: sh at analogic dot cz Summary: Unserialize decode issue Status: Feedback Type: Bug Package: Variables related PHP Version: 7.3.0 Assigned To: dmitry Block user comment: N Private report: N New Comment: No fix so far? Really? Can you rollback serialization functions like it was in 7.2? Previous Comments: ------------------------------------------------------------------------ [2019-01-14 13:23:40] dmitry@php.net The problem is caused by different order during serialisation and unserialization and therefore different reference numbering. This only happens when Serializable objects call serialize/unserialize functions few times. function serialize() { return serialize(array($this->data, parent::serialize())); } function unserialize($data) { list($this->$data, $parent_data) = unserialize($data); parent::unserialize($parent_data); } The problem can't be fixed without format change (e.g. we may use string position instead of object number). As a workaround, I propose avoiding nested serialization like parent::serialize() calls. ------------------------------------------------------------------------ [2019-01-03 10:26:02] nikic@php.net @Sjon provided the following test case with a similar issue: https://3v4l.org/BEobu That one is an instance of bug #66052 though, where the stricter validation in 7.3 makes the unserialization fail rather than return bogus data. The case in this report looks different though, as you don't have any "C:" payloads in the serialized data. ------------------------------------------------------------------------ [2018-12-25 13:43:03] php at famoser dot ch I have managed to create an example to reliably reproduce the behaviour: https://github.com/mangelio/app/blob/php-bug-%2377302/README.BUG77302.md The example is unfortunately not separated cleanly from the symfony framework and my specific project; it is therefore still hard to tell how and why the bug is hit. I will try to isolate the root cause further, but the example may already help others. ------------------------------------------------------------------------ [2018-12-23 10:36:18] me at famoser dot ch The bug has an issue in the symfony repository on github: https://github.com/symfony/symfony/issues/29459 This PR shows how the serialize/unserialize calls were used: https://github.com/symfony/symfony/pull/29621/files ------------------------------------------------------------------------ [2018-12-19 23:57:43] nikic@php.net Has the serialized string been produced by a vanilla serialize() call that is not nested within a Serializable interface or similar? The r:6 reference looks off-by-one to me. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=77302 -- Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1

« previous php.bugs (#219126) next »