Re: Bug #1693 Updated: unserialize returns false
| From: | Colin Putney | Date: | Fri, 12 Nov 1999 02:25:11 +0000 |
| Subject: | Re: Bug #1693 Updated: unserialize returns false | ||
| References: | 1 | Groups: | php.dev |
| Request: | Send a blank email to php-dev+get-12329@lists.php.net to get a copy of this message | ||
-- Bug Database <php-dev@lists.php.net> wrote:
> Is there any more info on this bug? Is it still in 3.0.12?
> Is there a reproducable test case? Anything? :)
Oops, should have updated or closed this one I guess.
The problem is with serialized strings. If the actual length of the
string is different than expected, as in the following case,
unserialize() returns false.
s:9:"O'Reilly";
This can happen when magic quotes is turned on. If for example, you
were to read a string in from a file, serialize it, and store it in a
database, there is no way to then unserialize it:
file contents: O'Reilly
retrieved from file: O\'Reilly
serialized: s:9:"O\'Reilly";
stored in db: s:9:\"O\'Reilly\";
after stripslashes(): s:9:"O'Reilly";
If you pass the magic-quoted value to serialize, it will choke on the
escaped double quotes. If you run it through stripslashes(),
unserialize will choke on the string-too-short problem. You could maybe
work around it via regex, but...
I worked around it by turning off magic_quotes. Perhaps this is more of
a gotcha than a bug, but it would be nice to make unserialize smart
enough to deal with the possibility.
---------------------------------------------
Colin Putney colin@whistler.net
Bit Flinger (604) 932-0606 x21
Whistler Networks http://www.whistler.net/