[php-src] Issue #9186: `@strict-properties` can be bypassed using serialization
| From: | TimWolla | Date: | Thu, 28 Jul 2022 19:09:59 +0000 |
| Subject: | [php-src] Issue #9186: `@strict-properties` can be bypassed using serialization | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-242059@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/9186
Author: TimWolla
### Description
The following code:
```php
<?php
var_dump(unserialize('O:17:"Random\Randomizer":1:{i:0;a:2:{s:3:"foo";N;s:6:"engine";O:32:"Random\Engine\Xoshiro256StarStar":2:{i:0;a:0:{}i:1;a:4:{i:0;s:16:"7520fbc2d6f8de46";i:1;s:16:"84d2d2b9d7ba0a34";i:2;s:16:"d975f36db6490b32";i:3;s:16:"c19991ee16785b94";}}}}'));
```
Resulted in this output:
```
object(Random\Randomizer)#1 (2) {
["engine"]=>
object(Random\Engine\Xoshiro256StarStar)#2 (1) {
["__states"]=>
array(4) {
[0]=>
string(16) "7520fbc2d6f8de46"
[1]=>
string(16) "84d2d2b9d7ba0a34"
[2]=>
string(16) "d975f36db6490b32"
[3]=>
string(16) "c19991ee16785b94"
}
}
["foo"]=>
NULL
}
```
But I expected an error instead, because the
->foo property should not exist in the
Randomizer as per:
https://github.com/php/php-src/blob/7ab22aad9e8c1704ed76411ad1c18862fd9ae6b2/ext/random/random.stub.php#L125-L127
Not sure if this is a bug in the implementation of Randomizer or a more general
unserialization bug.
### PHP Version
Current git master
### Operating System
_No response_