Edit report at https://bugs.php.net/bug.php?id=77302&edit=1
ID: 77302
Updated by: nikic@php.net
Reported by: sh at analogic dot cz
Summary: Unserialize decode issue
Status: Assigned
Type: Bug
Package: Variables related
PHP Version: 7.3.0
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
@felix: I've fixed this issue in https://github.com/php/php-src/commit/af324e24df85022314787f6dcf2ac811f58b88f3.
Previous Comments:
------------------------------------------------------------------------
[2019-02-21 10:50:09] nikic@php.net
@felix: That's not quite the same bug, and something we can actually fix...
I wasn't aware that returning null from Serializable::serialize() is a thing. This was allowed
in https://github.com/php/php-src/commit/d77945ef78aead05a3adb6307ccedc12d0ca49ee,
but I'm wondering why... Do you happen to know?
------------------------------------------------------------------------
[2019-02-21 09:30:08] felix at moches dot de
I think this is the same bug, but quite simple to reproduce: https://3v4l.org/cTPe9
As soon as at least two serializable objects are pushed to a collection, it cannot be serialized
correctly anymore.
This is really bad news for any caching solution.
------------------------------------------------------------------------
[2019-01-22 20:23:56] nikic@php.net
I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.
For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.
------------------------------------------------------------------------
[2019-01-22 19:57:33] dmitry@php.net
7.2 and below are affected by the same problem.
The old versions don't fail, but silently produce incorrect result (not the same as was
serialized).
------------------------------------------------------------------------
[2019-01-22 18:32:59] jusiacms at gmail dot com
A year of work on the next version and release with such an error. Eh.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77302
--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1