Req #79759 [Opn->Wfx]: Cannot unserialize payloads from PHP 7.4 on 7.3 if __serialize() is used

From: Date: Fri, 30 Jul 2021 14:25:29 +0000
Subject: Req #79759 [Opn->Wfx]: Cannot unserialize payloads from PHP 7.4 on 7.3 if __serialize() is used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-235485@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=79759&edit=1

 ID:                 79759
 Updated by:         cmb@php.net
 Reported by:        upyx dot 00 at gmail dot com
 Summary:            Cannot unserialize payloads from PHP 7.4 on 7.3 if
                     __serialize() is used
-Status:             Open
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            *General Issues
 Operating System:   any
 PHP Version:        7.4.7
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

Not quite sure what to do with this request.  Backporting anything
but security fixes to PHP-7.3 is off the table.  Adding a new
feature to PHP-7.4 is highly unlikely to happen at this point in
time.

> After some investigation, we realize that the problem, not PHP
> itself but in the many open source libraries which declare support
> of PHP prior to 7.4 but use new "__serialize()/__unserialize()"
> methods.

Well, this is clearly a downstream issue.  Guess this is a WONTFIX.


Previous Comments:
------------------------------------------------------------------------
[2020-07-26 14:36:09] fortemppp at gmail dot com

unserialize is not working properly in 7.3 and 7.4 but the same code works in 7.2 or earlier
versions. I found a solution for my code like this to resolve the issue and then unserialize.
$data = preg_replace_callback('!s:\d+:"(.*?)";!s', function($m) { return
"s:" . strlen($m[1]) . ':"'.$m[1].'";'; }, $data);

------------------------------------------------------------------------
[2020-06-29 20:02:55] upyx dot 00 at gmail dot com

Description:
------------
Hello!

In PHP 7.4 serialization mechanism has been changed in a backward-incompatible way. So it is
(sometimes) not possible to serialize data in PHP 7.4 and deserialize them in PHP 7.3. The
serialization is widely used to storing data in sessions, transfer data through message brokers,
etc.

Our site works on many servers, and the business has got to work 24/7. So we cannot upgrade all
nodes at once. When we upgrade some node to PHP 7.4, it becomes to produce serialized data to a
network that unsupported by other nodes. So we cannot update the nodes one by one. We've stuck
here.

I've asked the community how they upgraded, and a lot of them answered some like "through
pain and disgrace" because they didn't expect the problem and had to solve it when they
ran into it. After some investigation, we realize that the problem, not PHP itself but in the many
open source libraries which declare support of PHP prior to 7.4 but use new
"__serialize()/__unserialize()"  methods.

However, there is a problem, and we need a way to solve it. It is hardly possible to downgrade
libraries because of the complicated dependency graph between them. It is barely possible to
convince libraries' authors to make necessary changes because of the number of them. I propose
two variants:
a) backport "new" deserialization (but not serialization) to the next PHP 7.3 minor
version;
b) add an option to force "legacy" serialization to the next PHP 7.4 minor release.

The first variant is the easiest to use. The second variant is the easiest to implement.

By the way, we solved *our* problem with migration. It took a while, so I want to help others.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=79759&edit=1


Thread (3 messages)

« previous php.bugs (#235485) next »