Bug #78438 [PATCH]: Data corruption when using __serialize and __unserialize in nested structures

From: Date: Thu, 22 Aug 2019 15:19:26 +0000
Subject: Bug #78438 [PATCH]: Data corruption when using __serialize and __unserialize in nested structures
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-222370@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=78438&edit=1 ID: 78438 Patch added by: cmb@php.net Reported by: risto at live dot nl Summary: Data corruption when using __serialize and __unserialize in nested structures Status: Verified Type: Bug Package: Scripting Engine problem Operating System: Linux; Fedora 30 PHP Version: 7.4.0beta2 Block user comment: N Private report: N New Comment: The following pull request has been associated: Patch Name: Fix #78438: Corruption when __unserializing deeply nested structures On GitHub: https://github.com/php/php-src/pull/4608 Patch: https://github.com/php/php-src/pull/4608.patch Previous Comments: ------------------------------------------------------------------------ [2019-08-22 14:51:37] cmb@php.net The basic problem is that we're using two slots[1], which doesn't work if the slots are distributed across two elements of the linked list, in which case the first slot is in the list element *after* the second slot. There is also an issue with VAR_DTOR_ENTRIES_MAX[2] which doesn't match the actual definition[3] and at least wastes memory. [1] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L653-L660> [2] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L26> [3] <https://github.com/php/php-src/blob/php-7.4.0beta4/ext/standard/var_unserializer.re#L43> ------------------------------------------------------------------------ [2019-08-21 15:26:49] risto at live dot nl Description: ------------ Data corruption seems to occur when using PHP 7.4s new __serialize and __unserialize functionality in deeply nested data structures. Test script: --------------- Tested on PHP 7.4.0beta4 (cli) (built: Aug 20 2019 14:09:23) ( NTS ) However the bug has been observed in beta 1 and 2 as well. See https://gist.github.com/Devristo/878f4dbd9e30ee3a3c235f0d2ef3431d for a reproducer. And https://github.com/symfony/symfony/issues/33214 for the issue in the wild. Expected result: ---------------- When running the script I expect the unserialization to succeed as it does for deeply nested structures, as it does for the smaller sized examples in the reproducer. Actual result: -------------- It seems that in the deeply nested examples in the reproducer unserialization fails with errors like: - Argument 1 passed to X::__unserialize() must be of the type array, unknown given - Argument 1 passed to X::__unserialize() must be of the type array, int given ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=78438&edit=1

« previous php.bugs (#222370) next »