Bug #81163 [PATCH]: indirect in __sleep
Edit report at https://bugs.php.net/bug.php?id=81163&edit=1
ID: 81163
Patch added by: krakjoe@php.net
Reported by: krakjoe@php.net
Summary: indirect in __sleep
Status: Open
Type: Bug
Package: Reproducible crash
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
The following pull request has been associated:
Patch Name: Fix bug #81163 indirect vars in __sleep
On GitHub: https://github.com/php/php-src/pull/7169
Patch: https://github.com/php/php-src/pull/7169.patch
Previous Comments:
------------------------------------------------------------------------
[2021-06-18 05:10:52] krakjoe@php.net
Description:
------------
indirect vars returned in properties for __sleep not handled correctly
Test script:
---------------
<?php
class foo
{
private $private = 'private';
}
class bar extends foo
{
public function __sleep()
{
return (new bar());
}
}
var_dump(serialize(new bar()));
?>
Expected result:
----------------
Warning: serialize(): "private" returned as member variable from __sleep() but does not
exist in /opt/src/php-src/sec.php on line 15
string(14) "O:3:"bar":0:{}"
Actual result:
--------------
assert fail
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=81163&edit=1
Thread (3 messages)