[php-src] Issue #9186: `@strict-properties` can be bypassed using serialization

From: Date: Thu, 28 Jul 2022 19:09:59 +0000
Subject: [php-src] Issue #9186: `@strict-properties` can be bypassed using serialization
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-242059@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/9186 Author: TimWolla ### Description The following code: ```php <?php var_dump(unserialize('O:17:"Random\Randomizer":1:{i:0;a:2:{s:3:"foo";N;s:6:"engine";O:32:"Random\Engine\Xoshiro256StarStar":2:{i:0;a:0:{}i:1;a:4:{i:0;s:16:"7520fbc2d6f8de46";i:1;s:16:"84d2d2b9d7ba0a34";i:2;s:16:"d975f36db6490b32";i:3;s:16:"c19991ee16785b94";}}}}')); ``` Resulted in this output: ``` object(Random\Randomizer)#1 (2) { ["engine"]=> object(Random\Engine\Xoshiro256StarStar)#2 (1) { ["__states"]=> array(4) { [0]=> string(16) "7520fbc2d6f8de46" [1]=> string(16) "84d2d2b9d7ba0a34" [2]=> string(16) "d975f36db6490b32" [3]=> string(16) "c19991ee16785b94" } } ["foo"]=> NULL } ``` But I expected an error instead, because the ->foo property should not exist in the Randomizer as per: https://github.com/php/php-src/blob/7ab22aad9e8c1704ed76411ad1c18862fd9ae6b2/ext/random/random.stub.php#L125-L127 Not sure if this is a bug in the implementation of Randomizer or a more general unserialization bug. ### PHP Version Current git master ### Operating System _No response_

« previous php.bugs (#242059) next »