Bug #81153 [Fbk->Opn]: unserialize error calls __destruct before __wakeup

From: Date: Thu, 17 Jun 2021 11:36:02 +0000
Subject: Bug #81153 [Fbk->Opn]: unserialize error calls __destruct before __wakeup
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234459@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=81153&edit=1 ID: 81153 User updated by: j7ur8 at qq dot com Reported by: j7ur8 at qq dot com Summary: unserialize error calls __destruct before __wakeup -Status: Feedback +Status: Open Type: Bug Package: Class/Object related Operating System: ALL PHP Version: 7.3.28 Block user comment: N Private report: N New Comment: So, unserialize doesn't guarantee __wakeup executed before __destruct? The string sequence i provided is illegal(at least not so correct): O:1:"C":1:{s:1:"c";O:1:"D":0:{};N;} // https://3v4l.org/M9bQJ the orders is: >PHP Notice: unserialize(): Error at offset 31 of 35 bytes in >Notice: unserialize(): Error at offset 31 of 35 bytes in >C::__destruct >D::__get(b) >D::__wakeup >D::__destruct as we can see, __get executed before __wakeup. And if the sequence is correct: O:1:"C":1:{s:1:"c";O:1:"D":0:{}} // https://3v4l.org/UMahR the orders is : >D::__wakeup >C::__destruct >D::__get(b) >D::__destruct So, This is reasonable? Previous Comments: ------------------------------------------------------------------------ [2021-06-17 11:33:06] cmb@php.net @nikic, see <https://3v4l.org/UOHAh>. It is surprising that __get() is called before __wakeup(), especially since __wakeup() would initialize $b, so __get() is not supposed to be called at all. However, since the serialized data are corrupt, I see no need to "fix" that. ------------------------------------------------------------------------ [2021-06-17 11:01:16] nikic@php.net This needs some justification as to why this is supposed to be a bug. I don't think unserialize() guarantees any particular order here, and the order in which things are called looks reasonable to me (other orders would be reasonable as well). ------------------------------------------------------------------------ [2021-06-17 09:18:55] requinix@php.net Yes, this is different. Please try to give a correct bug summary next time. https://3v4l.org/0YvfT > Notice: unserialize(): Error at offset 31 of 33 bytes in /in/0YvfT on line 22 > C::__destruct > D::__get(b) > D::__wakeup > D::__destruct Feels like the order of operations should have been > D::__wakeup - because the object was successfully created > C::__destruct - unserialization failed, begin destruction > C::__get(b) - because of the code > D::__destruct - cleaning up after C was destroyed ------------------------------------------------------------------------ [2021-06-17 09:00:45] j7ur8 at qq dot com this is another one! ------------------------------------------------------------------------ [2021-06-17 08:59:51] requinix@php.net You already reported this. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=81153 -- Edit this bug report at https://bugs.php.net/bug.php?id=81153&edit=1

« previous php.bugs (#234459) next »