Bug #75035 [Com]: Datetime fails to unserialize "extreme" dates

From: Date: Tue, 29 Jun 2021 16:09:30 +0000
Subject: Bug #75035 [Com]: Datetime fails to unserialize "extreme" dates
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234690@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75035&edit=1 ID: 75035 Comment by: ganbayar dot gansukh at kellpro dot com Reported by: weirdan at gmail dot com Summary: Datetime fails to unserialize "extreme" dates Status: Open Type: Bug Package: Date/time related Operating System: Debian Linux / sid PHP Version: 7.1.8 Block user comment: N Private report: N New Comment: Experiencing same bug on 7.4.19 Previous Comments: ------------------------------------------------------------------------ [2020-12-04 12:51:35] cmb@php.net Related To: Bug #80483 ------------------------------------------------------------------------ [2017-08-05 19:15:38] as@php.net https://github.com/php/php-src/pull/2672 ------------------------------------------------------------------------ [2017-08-05 17:20:35] weirdan at gmail dot com > However it is also at odds with the fix for bug #62852, which asserts that a 5-digit year > should fail to unserialize It doesn't fail *all* 5-digits years though (just mangles the data), see this output line (the number in square brackets is the timestamp, to aid with reproduction): string(59) "[1099511627775] 36812-02-20 00:36:15 => 2002-02-20 00:36:15" ------------------------------------------------------------------------ [2017-08-05 17:04:53] weirdan at gmail dot com Also, documentation[1] says: > The date and time information is internally stored as a 64-bit number so all conceivably useful > dates (including negative years) are supported. The range is from about 292 billion years in the > past to the same in the future. [1] http://php.net/manual/en/intro.datetime.php ------------------------------------------------------------------------ [2017-08-05 07:24:10] as@php.net This patch fixes the issue: https://gist.github.com/adsr/63f2bc2bc952db2f1ca62a4721648a5a However it is also at odds with the fix for bug #62852, which asserts that a 5-digit year should fail to unserialize[0]. This seems wrong for 2 reasons: (1) We already construct (via '@%d' format), serialize, and date-format 5+ digit years, and (2) ISO 8601 allows for 5+ digit years if the sender and receiver agree upon the format. [0] https://github.com/php/php-src/blob/771e5cc/ext/date/tests/bug62852.phpt ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75035 -- Edit this bug report at https://bugs.php.net/bug.php?id=75035&edit=1

« previous php.bugs (#234690) next »