Edit report at https://bugs.php.net/bug.php?id=77302&edit=1
ID: 77302
Comment by: felix at moches dot de
Reported by: sh at analogic dot cz
Summary: Unserialize decode issue
Status: Assigned
Type: Bug
Package: Variables related
PHP Version: 7.3.0
Assigned To: dmitry
Block user comment: N
Private report: N
New Comment:
Oh, and concerning your question: The docs at http://php.net/manual/en/serializable.serialize.php
say:
"Return Values: Returns the string representation of the object or NULL"
Although the return type declaration explicitly states "string" and not
"?string".
But this is probably not PHP7.1+ syntax anyways.
Previous Comments:
------------------------------------------------------------------------
[2019-02-26 18:00:39] felix at moches dot de
Thank you very much.
------------------------------------------------------------------------
[2019-02-21 11:08:52] nikic@php.net
@felix: I've fixed this issue in https://github.com/php/php-src/commit/af324e24df85022314787f6dcf2ac811f58b88f3.
------------------------------------------------------------------------
[2019-02-21 10:50:09] nikic@php.net
@felix: That's not quite the same bug, and something we can actually fix...
I wasn't aware that returning null from Serializable::serialize() is a thing. This was allowed
in https://github.com/php/php-src/commit/d77945ef78aead05a3adb6307ccedc12d0ca49ee,
but I'm wondering why... Do you happen to know?
------------------------------------------------------------------------
[2019-02-21 09:30:08] felix at moches dot de
I think this is the same bug, but quite simple to reproduce: https://3v4l.org/cTPe9
As soon as at least two serializable objects are pushed to a collection, it cannot be serialized
correctly anymore.
This is really bad news for any caching solution.
------------------------------------------------------------------------
[2019-01-22 20:23:56] nikic@php.net
I plan to propose and implement a new custom object serialization mechanism for PHP 7.4, to replace
the Serializable interface and all the problems that come with it.
For now, all I can suggest is to rewrite your code in a way that does not use parent::serialize(). I
don't think there is anything we can do to fix Serializable itself, unfortunately.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77302
--
Edit this bug report at https://bugs.php.net/bug.php?id=77302&edit=1