Bug #81153 [Fbk]: unserialize error calls __destruct before __wakeup

From: Date: Thu, 17 Jun 2021 11:33:06 +0000
Subject: Bug #81153 [Fbk]: unserialize error calls __destruct before __wakeup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234458@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81153&edit=1 ID: 81153 Updated by: cmb@php.net Reported by: j7ur8 at qq dot com Summary: unserialize error calls __destruct before __wakeup Status: Feedback Type: Bug Package: Class/Object related Operating System: ALL PHP Version: 7.3.28 Block user comment: N Private report: N New Comment: @nikic, see <https://3v4l.org/UOHAh>. It is surprising that __get() is called before __wakeup(), especially since __wakeup() would initialize $b, so __get() is not supposed to be called at all. However, since the serialized data are corrupt, I see no need to "fix" that. Previous Comments: ------------------------------------------------------------------------ [2021-06-17 11:01:16] nikic@php.net This needs some justification as to why this is supposed to be a bug. I don't think unserialize() guarantees any particular order here, and the order in which things are called looks reasonable to me (other orders would be reasonable as well). ------------------------------------------------------------------------ [2021-06-17 09:18:55] requinix@php.net Yes, this is different. Please try to give a correct bug summary next time. https://3v4l.org/0YvfT > Notice: unserialize(): Error at offset 31 of 33 bytes in /in/0YvfT on line 22 > C::__destruct > D::__get(b) > D::__wakeup > D::__destruct Feels like the order of operations should have been > D::__wakeup - because the object was successfully created > C::__destruct - unserialization failed, begin destruction > C::__get(b) - because of the code > D::__destruct - cleaning up after C was destroyed ------------------------------------------------------------------------ [2021-06-17 09:00:45] j7ur8 at qq dot com this is another one! ------------------------------------------------------------------------ [2021-06-17 08:59:51] requinix@php.net You already reported this. ------------------------------------------------------------------------ [2021-06-17 08:49:21] j7ur8 at qq dot com Description: ------------ bad unserialize string makes __wakeup ineffective. Success: 7.0.15 - 7.0.33, 7.1.1 - 7.1.33, 7.2.0 - 7.2.34, 7.3.0 - 7.3.28, 7.4.0 - 7.4.16, 8.0.0 - 8.0.3 Fail: 5.0.0 - 5.0.5, 5.1.0 - 5.1.6, 5.2.0 - 5.2.17, 5.3.0 - 5.3.29, 5.4.0 - 5.4.45, 5.5.0 - 5.5.38, 5.6.0 - 5.6.40, 7.0.0 - 7.0.14, 7.1.0 Test script: --------------- // https://3v4l.org/4nZUm <?php class D{ public $flag=True; public function __get($a){ if($this->flag){ echo 'flag'; }else{ echo 'hint'; } } public function __wakeup(){ $this->flag = False; } } class C{ public function __destruct(){ echo $this->c->b; } } @unserialize('O:1:"C":1:{s:1:"c";O:1:"D":0:{};N;}'); Expected result: ---------------- hint Actual result: -------------- flag ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=81153&edit=1

« previous php.bugs (#234458) next »