Bug #66052 [Opn->Wfx]: Serialized value ids are shared between nested serialization operations
| From: | nikic@php.net | Date: | Tue, 27 Apr 2021 15:41:45 +0000 |
| Subject: | Bug #66052 [Opn->Wfx]: Serialized value ids are shared between nested serialization operations | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233596@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=66052&edit=1
ID: 66052
Updated by: nikic@php.net
Reported by: crog at gustavus dot edu
Summary: Serialized value ids are shared between nested
serialization operations
-Status: Open
+Status: Wont fix
Type: Bug
Package: *General Issues
PHP Version: 5.4.21
Block user comment: N
Private report: N
New Comment:
Yes, that's correct. The Serializable interface is not salvageable and has been replaced by
__serialize() and __unserialize(). It will be (partially) deprecated in PHP 8.1
(https://wiki.php.net/rfc/phase_out_serializable).
Previous Comments:
------------------------------------------------------------------------
[2021-04-27 15:36:44] neclimdul at gmail dot com
Is safe to say Serializable is just broken in this respect and replaced by the new custom object
serialization methods in 7.4+? Maybe with a follow up to deprecating and adding warnings around this
breakage?
------------------------------------------------------------------------
[2019-01-03 10:26:02] nikic@php.net
Related To: Bug #77302
------------------------------------------------------------------------
[2017-02-17 14:03:23] hwold at hwold dot net
Still present in PHP 7.1.2. Another test case : https://3v4l.org/BXuv8
Code:
-----
<?php
class User {
public $name = "admin";
}
class UserCouple implements Serializable {
public $user1;
public $user2;
public function serialize() {
return serialize(array(42, serialize(array($this->user1, $this->user2))));
}
public function unserialize($serialized) {
list($_, $subSerialized) = unserialize($serialized);
list($this->user1, $this->user2) = unserialize($subSerialized);
}
}
$user = new User();
$couple = new UserCouple();
$couple->user1 = $user;
$couple->user2 = $user;
var_dump(unserialize(serialize($couple)));
Expected result
---------------
object(UserCouple)#3 (2) {
["user1"]=>
object(User)#4 (1) {
["name"]=>
string(5) "admin"
}
["user2"]=>
object(User)#4 (1) {
["name"]=>
string(5) "admin"
}
}
Actual result
-------------
object(UserCouple)#3 (2) {
["user1"]=>
object(User)#4 (1) {
["name"]=>
string(5) "admin"
}
["user2"]=>
int(42)
}
------------------------------------------------------------------------
[2017-01-07 23:07:06] php at laszlokorte dot de
I guess I came across the same issue.
The following gist reproduces it even in php7.0.14:
https://gist.github.com/laszlokorte/3948f40873346cc1fd9b8c11ab06ae04
------------------------------------------------------------------------
[2017-01-07 22:15:21] nikic@php.net
Related To: Bug #67363
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=66052
--
Edit this bug report at https://bugs.php.net/bug.php?id=66052&edit=1