Bug #78410 [NEW]: Cannot "manually" unserialize class that is final and extends an internal one
| From: | nicolas dot grekas+php at gmail dot com | Date: | Tue, 13 Aug 2019 17:19:32 +0000 |
| Subject: | Bug #78410 [NEW]: Cannot "manually" unserialize class that is final and extends an internal one | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-222232@lists.php.net to get a copy of this message | ||
From: nicolas dot grekas+php at gmail dot com
Operating system:
PHP version: 7.4.0beta2
Package: *General Issues
Bug Type: Bug
Bug description:Cannot "manually" unserialize class that is final and extends an internal
one
Description:
------------
I'm trying to make the VarExporter component of Symfony work on PHP 7.4
and I'm in a dead-end. What the component provides is an implementation
of serialize/unserialize using PHP as the serialization format. This
cannot be implemented anymore in PHP 7.4 with the new
__serialize/__unserialize methods.
The case that breaks is when a userland class is made final *and*
extends an internal one.
E.g. final class Foo extends extends \ArrayIterator {...}
Because of these two conditions,
ReflectionClass::newInstanceWithoutConstructor is forbidden. In PHP
<=7.3, it is possible to work around the limitation by calling
serialize() with a proper payload: either an empty "O:"-one when the
class doesn't implement Serializable, or a "C:"-one when it does.
To implement the semantics of __unserialize, I cannot use "C:"-format.
And PHP 7.4 complains if I unserialize('O:8:"Foo":0:{}'). That's my
dead-end: I cannot create such an instance to call __unserialize in
userland.
The simplest way I can think of to unlock progress is to allow
unserialize('O:8:"Foo":0:{}') to work. Doing so *would not call
__unserialize* but would return an empty object, as it does for classes
that don't implement the method.
Thank you for your help, this is a critical blocker for us.
--
Edit bug report at https://bugs.php.net/bug.php?id=78410&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=78410&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=78410&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=78410&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=78410&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=78410&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=78410&r=support
Expected behavior: https://bugs.php.net/fix.php?id=78410&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=78410&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=78410&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=78410&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78410&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=78410&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=78410&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=78410&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=78410&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=78410&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=78410&r=mysqlcfg