Bug #77302 [Asn]: Unserialize decode issue

From: Date: Thu, 21 Feb 2019 11:08:52 +0000
Subject: Bug #77302 [Asn]: Unserialize decode issue
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219674@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77302&edit=1

 ID:                 77302
 Updated by:         nikic@php.net
 Reported by:        sh at analogic dot cz
 Summary:            Unserialize decode issue
 Status:             Assigned
 Type:               Bug
 Package:            Variables related
 PHP Version:        7.3.0
 Assigned To:        dmitry
 Block user comment: N
 Private report:     N

 New Comment:

@felix: I've fixed this issue in https://github.com/php/php-src/commit/af324e24df85022314787f6dcf2ac811f58b88f3.


Previous Comments:
------------------------------------------------------------------------
[2019-02-21 10:50:09] nikic@php.net

@felix: That's not quite the same bug, and something we can actually fix...

I wasn't aware that returning null from Serializable::serialize() is a thing. This was allowed
in https://github.com/php/php-src/commit/d77945ef78aead05a3adb6307ccedc12d0ca49ee,
but I'm wondering why... Do you happen to know?

------------------------------------------------------------------------
[2019-02-21 09:30:08] felix at moches dot de

I think this is the same bug, but quite simple to reproduce: https://3v4l.org/cTPe9

As soon as at least two serializable objects are pushed to a collection, it cannot be serialized
correctly anymore.

This is really bad news for any caching solution.

------------------------------------------------------------------------
[2019-01-22 20:23:56] nikic@php.net

I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.

For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.

------------------------------------------------------------------------
[2019-01-22 19:57:33] dmitry@php.net

7.2 and below are affected by the same problem.
The old versions don't fail, but silently produce incorrect result (not the same as was
serialized).

------------------------------------------------------------------------
[2019-01-22 18:32:59] jusiacms at gmail dot com

A year of work on the next version and release with such an error. Eh.

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77302


--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1


Thread (15 messages)

« previous php.bugs (#219674) next »