Bug #79002 [PATCH]: Serializing uninitialized typed properties with __sleep makes unserialize throw
| From: | tandre@php.net | Date: | Fri, 20 Dec 2019 00:26:34 +0000 |
| Subject: | Bug #79002 [PATCH]: Serializing uninitialized typed properties with __sleep makes unserialize throw | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-224433@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79002&edit=1
ID: 79002
Patch added by: tandre@php.net
Reported by: tandre@php.net
Summary: Serializing uninitialized typed properties with
__sleep makes unserialize throw
Status: Open
Type: Bug
Package: Scripting Engine problem
Operating System: Any
PHP Version: 7.4.1
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Change __sleep serialization for uninitialized typed properties
On GitHub: https://github.com/php/php-src/pull/5027
Patch: https://github.com/php/php-src/pull/5027.patch
Previous Comments:
------------------------------------------------------------------------
[2019-12-19 22:53:14] requinix@php.net
Note that serialize() is already notice-ing about this. https://3v4l.org/PCLm3
On the one hand, the current behavior should be fine. (Or maybe escalate it to a warning instead of
just a notice.) The property is not set, should work the same way whether it's typed or not.
On the other hand, serialize() could check that the property is defined but typed and uninitialized,
then warn and *not* include it in the serialized data. There is precedence for special cases like
this.
------------------------------------------------------------------------
[2019-12-19 16:10:44] tandre@php.net
Description:
------------
When __sleep includes uninitialized typed properties, serialize() will succeed (behaves as if the
value was null), but unserialize() will cause a TypeError to be thrown if the value wasn't
nullable.
I didn't see any mention of how uninitialized typed properties should behave for __sleep in the
RFC or RFC/PR discussion.
Is the current behavior in 7.4 and 8.0-dev for __sleep on uninitialized properties by design, or is
it an edge case that was overlooked? It seems surprising that data serializes successfully, but
throws when it gets unserialized for the same class declaration.
I checked https://wiki.php.net/rfc/typed_properties_v2
, https://externals.io/message/102333 , and https://externals.io/message/103148 , and didn't
see any references to __sleep (just "I wouldn't lose sleep
if we wanted to keep the GA date where it is.")
I also didn't see any mention of __sleep in php/php-src#3734 , or in the changes of the PR. (or
in bugs.php.net)
Noticed in https://github.com/igbinary/igbinary/pull/250#discussion_r355812953
Test script:
---------------
<?php
class HasProp {
public int $x;
public function __sleep() { return ['x']; }
}
$x = new HasProp();
// string(28) "O:7:"HasProp":1:{s:1:"x";N;}"
var_dump($s = serialize($x));
// Fatal error: Uncaught TypeError: Typed property HasProp::$x must be int, null used in ...
unserialize($s);
Expected result:
----------------
Unserialize() should not throw, and should generate an instance of HasProp, with an uninitialized
HasProp.
Ideally, serialize() should skip over the property $x. This would make it match the original
data's representation for both typed nullable and non-nullable properties.
Actual result:
--------------
This throws a TypeError when unserializing the data it just serialized
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79002&edit=1