Re: Bug #1693 Updated: unserialize returns false

From: Date: Fri, 12 Nov 1999 02:25:11 +0000
Subject: Re: Bug #1693 Updated: unserialize returns false
References: 1  Groups: php.dev 
Request: Send a blank email to php-dev+get-12329@lists.php.net to get a copy of this message
-- Bug Database <php-dev@lists.php.net> wrote: > Is there any more info on this bug? Is it still in 3.0.12? > Is there a reproducable test case? Anything? :) Oops, should have updated or closed this one I guess. The problem is with serialized strings. If the actual length of the string is different than expected, as in the following case, unserialize() returns false. s:9:"O'Reilly"; This can happen when magic quotes is turned on. If for example, you were to read a string in from a file, serialize it, and store it in a database, there is no way to then unserialize it: file contents: O'Reilly retrieved from file: O\'Reilly serialized: s:9:"O\'Reilly"; stored in db: s:9:\"O\'Reilly\"; after stripslashes(): s:9:"O'Reilly"; If you pass the magic-quoted value to serialize, it will choke on the escaped double quotes. If you run it through stripslashes(), unserialize will choke on the string-too-short problem. You could maybe work around it via regex, but... I worked around it by turning off magic_quotes. Perhaps this is more of a gotcha than a bug, but it would be nice to make unserialize smart enough to deal with the possibility. --------------------------------------------- Colin Putney colin@whistler.net Bit Flinger (604) 932-0606 x21 Whistler Networks http://www.whistler.net/

« previous php.dev (#12329) next »