Bug #78410 [NEW]: Cannot "manually" unserialize class that is final and extends an internal one

From: Date: Tue, 13 Aug 2019 17:19:32 +0000
Subject: Bug #78410 [NEW]: Cannot "manually" unserialize class that is final and extends an internal one
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222232@lists.php.net to get a copy of this message
From: nicolas dot grekas+php at gmail dot com Operating system: PHP version: 7.4.0beta2 Package: *General Issues Bug Type: Bug Bug description:Cannot "manually" unserialize class that is final and extends an internal one Description: ------------ I'm trying to make the VarExporter component of Symfony work on PHP 7.4 and I'm in a dead-end. What the component provides is an implementation of serialize/unserialize using PHP as the serialization format. This cannot be implemented anymore in PHP 7.4 with the new __serialize/__unserialize methods. The case that breaks is when a userland class is made final *and* extends an internal one. E.g. final class Foo extends extends \ArrayIterator {...} Because of these two conditions, ReflectionClass::newInstanceWithoutConstructor is forbidden. In PHP <=7.3, it is possible to work around the limitation by calling serialize() with a proper payload: either an empty "O:"-one when the class doesn't implement Serializable, or a "C:"-one when it does. To implement the semantics of __unserialize, I cannot use "C:"-format. And PHP 7.4 complains if I unserialize('O:8:"Foo":0:{}'). That's my dead-end: I cannot create such an instance to call __unserialize in userland. The simplest way I can think of to unlock progress is to allow unserialize('O:8:"Foo":0:{}') to work. Doing so *would not call __unserialize* but would return an empty object, as it does for classes that don't implement the method. Thank you for your help, this is a critical blocker for us. -- Edit bug report at https://bugs.php.net/bug.php?id=78410&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=78410&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=78410&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=78410&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=78410&r=needscript Try newer version: https://bugs.php.net/fix.php?id=78410&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=78410&r=support Expected behavior: https://bugs.php.net/fix.php?id=78410&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=78410&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=78410&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=78410&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=78410&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=78410&r=dst IIS Stability: https://bugs.php.net/fix.php?id=78410&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=78410&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=78410&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=78410&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=78410&r=mysqlcfg

« previous php.bugs (#222232) next »