Bug #75965 [Ver->Wfx]: DateTimeZone object has not been correctly initialized after unserialization
| From: | nikic@php.net | Date: | Mon, 07 Dec 2020 13:03:57 +0000 |
| Subject: | Bug #75965 [Ver->Wfx]: DateTimeZone object has not been correctly initialized after unserialization | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230897@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75965&edit=1
ID: 75965
Updated by: nikic@php.net
Reported by: ivan at podorozhny dot ru
Summary: DateTimeZone object has not been correctly
initialized after unserialization
-Status: Verified
+Status: Wont fix
Type: Bug
Package: Scripting Engine problem
Operating System: Ubuntu 16.04.3 LTS 4.4.0-28-gene
PHP Version: 7.1.14
Block user comment: N
Private report: N
New Comment:
See https://wiki.php.net/rfc/custom_object_serialization:
> This leaves us in a situation where Serializable::unserialize() is called immediately, while
> __wakeup() is delayed. As such, the former method sees objects before they have been fully
> unserialized. For example, this makes using DateTime objects within Serializable::unserialize()
> unsafe, as they will not be fully initialized yet.
This bug is unfixable, which is part of why Serializable is being phased out. You can avoid it by
not using Serializable.
Previous Comments:
------------------------------------------------------------------------
[2020-12-07 12:27:15] cmb@php.net
That looks indeed broken: <https://3v4l.org/QEdfQ>. May
have been
caused by one of the sec fixes in PHP 7.1.1[1].
[1] <https://www.php.net/ChangeLog-7.php#7.1.1>
------------------------------------------------------------------------
[2018-02-15 14:33:03] ivan at podorozhny dot ru
Description:
------------
PHP 7.1.6-1~ubuntu16.04.1+deb.sury.org+1 (cli) (built: Jun 9 2017 08:26:34) ( NTS )
Copyright (c) 1997-2017 The PHP Group
Zend Engine v3.1.0, Copyright (c) 1998-2017 Zend Technologies
with Zend OPcache v7.1.6-1~ubuntu16.04.1+deb.sury.org+1, Copyright (c) 1999-2017, by Zend
Technologies
with Xdebug v2.5.5, Copyright (c) 2002-2017, by Derick Rethans
Test script:
---------------
class Foobar implements \Serializable
{
/** @return string */
public function serialize(): string
{
return serialize(new \DateTimeZone('Europe/Andorra'));
}
/** @param string $serialized */
public function unserialize($serialized)
{
var_dump($serialized);
var_dump(unserialize($serialized)->getName());
}
}
(new Foobar())->unserialize((new Foobar())->serialize());
var_dump(unserialize(serialize(new Foobar())));
Expected result:
----------------
The DateTimeZone object correct initialization
Actual result:
--------------
/tmp/test.php:14:
string(86)
"O:12:"DateTimeZone":2:{s:13:"timezone_type";i:3;s:8:"timezone";s:14:"Europe/Andorra";}"
/tmp/test.php:15:
string(14) "Europe/Andorra"
/tmp/test.php:14:
string(86)
"O:12:"DateTimeZone":2:{s:13:"timezone_type";i:3;s:8:"timezone";s:14:"Europe/Andorra";}"
PHP Warning: DateTimeZone::getName(): The DateTimeZone object has not been correctly initialized by
its constructor in /tmp/test.php on line 15
PHP Stack trace:
PHP 1. {main}() /tmp/test.php:0
PHP 2. unserialize() /tmp/test.php:20
PHP 3. Foobar->unserialize() /tmp/test.php:20
PHP 4. DateTimeZone->getName() /tmp/test.php:15
/tmp/test.php:15:
bool(false)
/tmp/test.php:20:
class Foobar#1 (0) {
}
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75965&edit=1