Bug #77302 [Fbk]: Unserialize decode issue

From: Date: Tue, 22 Jan 2019 20:23:56 +0000
Subject: Bug #77302 [Fbk]: Unserialize decode issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219140@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77302&edit=1

 ID:                 77302
 Updated by:         nikic@php.net
 Reported by:        sh at analogic dot cz
 Summary:            Unserialize decode issue
 Status:             Feedback
 Type:               Bug
 Package:            Variables related
 PHP Version:        7.3.0
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.

For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.


Previous Comments:
------------------------------------------------------------------------
[2019-01-22 19:57:33] dmitry@php.net

7.2 and below are affected by the same problem.
The old versions don't fail, but silently produce incorrect result (not the same as was
serialized).

------------------------------------------------------------------------
[2019-01-22 18:32:59] jusiacms at gmail dot com

A year of work on the next version and release with such an error. Eh.

------------------------------------------------------------------------
[2019-01-22 12:07:44] o dot ilyushyn at superbody dot com

No fix so far? Really? Can you rollback serialization functions like it was in 7.2?

------------------------------------------------------------------------
[2019-01-14 13:23:40] dmitry@php.net

The problem is caused by different order during serialisation and unserialization and therefore
different reference numbering. This only happens when Serializable objects call
serialize/unserialize functions few times.

function serialize() { 
    return serialize(array($this->data, parent::serialize())); 
}

function unserialize($data) { 
    list($this->$data, $parent_data) = unserialize($data); 
    parent::unserialize($parent_data); 
}

The problem can't be fixed without format change (e.g. we may use string position instead of
object number).

As a workaround, I propose avoiding nested serialization like parent::serialize() calls.

------------------------------------------------------------------------
[2019-01-03 10:26:02] nikic@php.net

@Sjon provided the following test case with a similar issue: https://3v4l.org/BEobu That one is an instance of bug #66052
though, where the stricter validation in 7.3 makes the unserialization fail rather than return bogus
data.

The case in this report looks different though, as you don't have any "C:" payloads
in the serialized data.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77302


--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1


Thread (15 messages)

« previous php.bugs (#219140) next »