Bug #78438 [Opn->Ver]: Data corruption when using __serialize and __unserialize in nested structures
| From: | cmb@php.net | Date: | Thu, 22 Aug 2019 14:51:37 +0000 |
| Subject: | Bug #78438 [Opn->Ver]: Data corruption when using __serialize and __unserialize in nested structures | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-222368@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=78438&edit=1
ID: 78438
Updated by: cmb@php.net
Reported by: risto at live dot nl
Summary: Data corruption when using __serialize and
__unserialize in nested structures
-Status: Open
+Status: Verified
Type: Bug
-Package: Class/Object related
+Package: Scripting Engine problem
Operating System: Linux; Fedora 30
PHP Version: 7.4.0beta2
Block user comment: N
Private report: N
New Comment:
The basic problem is that we're using two slots[1], which doesn't
work if the slots are distributed across two elements of the
linked list, in which case the first slot is in the list element
*after* the second slot.
There is also an issue with
VAR_DTOR_ENTRIES_MAX[2] which doesn't
match the actual definition[3] and at least wastes memory.
[1] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L653-L660>
[2] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L26>
[3] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L43>
Previous Comments:
------------------------------------------------------------------------
[2019-08-21 15:26:49] risto at live dot nl
Description:
------------
Data corruption seems to occur when using PHP 7.4s new __serialize and __unserialize functionality
in deeply nested data structures.
Test script:
---------------
Tested on PHP 7.4.0beta4 (cli) (built: Aug 20 2019 14:09:23) ( NTS )
However the bug has been observed in beta 1 and 2 as well.
See https://gist.github.com/Devristo/878f4dbd9e30ee3a3c235f0d2ef3431d
for a reproducer.
And https://github.com/symfony/symfony/issues/33214
for the issue in the wild.
Expected result:
----------------
When running the script I expect the unserialization to succeed as it does for deeply nested
structures, as it does for the smaller sized examples in the reproducer.
Actual result:
--------------
It seems that in the deeply nested examples in the reproducer unserialization fails with errors
like:
- Argument 1 passed to X::__unserialize() must be of the type array, unknown given
- Argument 1 passed to X::__unserialize() must be of the type array, int given
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78438&edit=1