Bug #79447 [Opn->Csd]: Serializing uninitialized typed properties with __sleep should not throw
| From: | nikic@php.net | Date: | Thu, 23 Apr 2020 08:31:23 +0000 |
| Subject: | Bug #79447 [Opn->Csd]: Serializing uninitialized typed properties with __sleep should not throw | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-226730@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=79447&edit=1
ID: 79447
Updated by: nikic@php.net
Reported by: nicolasgrekas@php.net
Summary: Serializing uninitialized typed properties with
__sleep should not throw
-Status: Open
+Status: Closed
Type: Bug
Package: Scripting Engine problem
PHP Version: 7.4.4
Block user comment: N
Private report: N
New Comment:
Automatic comment on behalf of nicolas.grekas@gmail.com
Revision: http://git.php.net/?p=php-src.git;a=commit;h=73d02c3b3eb8b828a1cc7ae04a4cc4f4875c3ddd
Log: Fix bug #79447
Previous Comments:
------------------------------------------------------------------------
[2020-04-07 13:21:58] ocramius@php.net
We (Doctrine) could return only the initialized properties in
__sleep.
The only reason __sleep exists in proxies is to avoid serializing the whole ORM and
proxy initializer closures (and transitively PDO too), but we could use reflection in
__sleep to determine which properties are initialized. The performance impact is
acceptable, since we're well out the 80/20 scenario.
Overall, the behavior of PHP-SRC makes sense to me, and the added strictness is welcome, so the
engine throwing when serialize($somethingWithBrokenSleep) seems correct, although it is
indeed a BC break.
------------------------------------------------------------------------
[2020-04-07 13:00:33] nikic@php.net
I have a bit of a hard time following these threads. In the end I didn't understand a) where
__sleep is actually defined/generated in the first place and b) why the __sleep returns
uninitialized properties. (As a bonus question, can this usage of __sleep be migrated to
__serialize?)
------------------------------------------------------------------------
[2020-04-03 15:06:57] nicolasgrekas@php.net
Description:
------------
This is a follow up of https://bugs.php.net/bug.php?id=79002
The Symfony+Doctrine community is learning to use uninitialized properties, and we're having a
bad time with __sleep().
The behavior implemented in https://github.com/php/php-src/commit/846b6479537a112d1ded725e6484e46462048b35
forbids serializing arbitrary objects (e.g.for hashing purpose). This forces us to catch and ignore
"Throwable", which in turn might hide legit errors that ppl do need to see during
development.
Here is an example issue https://github.com/doctrine/common/issues/886
where this is discussed, originating from https://github.com/doctrine/orm/issues/8030,
which in turns generates PRs like https://github.com/symfony/symfony/pull/36336
All this activity would disappear and things would work seamlessly if the engine would just ignore
uninitialized properties returned by __sleep().
On unserialize(), such properties should be unserialized back to the "uninitialized"
state. This would respect the semantics of serialize/unserialize and would solve all this complexity
we don't know how to deal with.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=79447&edit=1