Bug #77302 [Fbk->Opn]: Unserialize decode issue

From: Date: Tue, 22 Jan 2019 22:59:12 +0000
Subject: Bug #77302 [Fbk->Opn]: Unserialize decode issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219141@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77302&edit=1

 ID:                 77302
 Updated by:         cmb@php.net
 Reported by:        sh at analogic dot cz
 Summary:            Unserialize decode issue
-Status:             Feedback
+Status:             Open
 Type:               Bug
 Package:            Variables related
 PHP Version:        7.3.0
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N



Previous Comments:
------------------------------------------------------------------------
[2019-01-22 20:23:56] nikic@php.net

I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.

For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.

------------------------------------------------------------------------
[2019-01-22 19:57:33] dmitry@php.net

7.2 and below are affected by the same problem.
The old versions don't fail, but silently produce incorrect result (not the same as was
serialized).

------------------------------------------------------------------------
[2019-01-22 18:32:59] jusiacms at gmail dot com

A year of work on the next version and release with such an error. Eh.

------------------------------------------------------------------------
[2019-01-22 12:07:44] o dot ilyushyn at superbody dot com

No fix so far? Really? Can you rollback serialization functions like it was in 7.2?

------------------------------------------------------------------------
[2019-01-14 13:23:40] dmitry@php.net

The problem is caused by different order during serialisation and unserialization and therefore
different reference numbering. This only happens when Serializable objects call
serialize/unserialize functions few times.

function serialize() { 
    return serialize(array($this->data, parent::serialize())); 
}

function unserialize($data) { 
    list($this->$data, $parent_data) = unserialize($data); 
    parent::unserialize($parent_data); 
}

The problem can't be fixed without format change (e.g. we may use string position instead of
object number).

As a workaround, I propose avoiding nested serialization like parent::serialize() calls.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77302


--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1


Thread (15 messages)

« previous php.bugs (#219141) next »