Edit report at https://bugs.php.net/bug.php?id=77302&edit=1
ID: 77302
Updated by: cmb@php.net
Reported by: sh at analogic dot cz
Summary: Unserialize decode issue
-Status: Feedback
+Status: Open
Type: Bug
Package: Variables related
PHP Version: 7.3.0
Assigned To: dmitry
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2019-01-22 20:23:56] nikic@php.net
I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.
For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.
------------------------------------------------------------------------
[2019-01-22 19:57:33] dmitry@php.net
7.2 and below are affected by the same problem.
The old versions don't fail, but silently produce incorrect result (not the same as was
serialized).
------------------------------------------------------------------------
[2019-01-22 18:32:59] jusiacms at gmail dot com
A year of work on the next version and release with such an error. Eh.
------------------------------------------------------------------------
[2019-01-22 12:07:44] o dot ilyushyn at superbody dot com
No fix so far? Really? Can you rollback serialization functions like it was in 7.2?
------------------------------------------------------------------------
[2019-01-14 13:23:40] dmitry@php.net
The problem is caused by different order during serialisation and unserialization and therefore
different reference numbering. This only happens when Serializable objects call
serialize/unserialize functions few times.
function serialize() {
return serialize(array($this->data, parent::serialize()));
}
function unserialize($data) {
list($this->$data, $parent_data) = unserialize($data);
parent::unserialize($parent_data);
}
The problem can't be fixed without format change (e.g. we may use string position instead of
object number).
As a workaround, I propose avoiding nested serialization like parent::serialize() calls.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77302
--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1