Bug #1693 Updated: unserialize returns false

From: Date: Fri, 12 Nov 1999 03:34:42 +0000
Subject: Bug #1693 Updated: unserialize returns false
Groups: php.dev 
Request: Send a blank email to php-dev+get-12330@lists.php.net to get a copy of this message
ID: 1693 Updated by: joey Reported By: colin@whistler.net Status: Analyzed Bug Type: Misbehaving function Assigned To: Comments: I will look into this more tomorrow. Here is the reply from the reporter. Oops, should have updated or closed this one I guess. The problem is with serialized strings. If the actual length of the string is different than expected, as in the following case, unserialize() returns false. s:9:"O'Reilly"; This can happen when magic quotes is turned on. If for example, you were to read a string in from a file, serialize it, and store it in a database, there is no way to then unserialize it: file contents: O'Reilly retrieved from file: O\'Reilly serialized: s:9:"O\'Reilly"; stored in db: s:9:\"O\'Reilly\"; after stripslashes(): s:9:"O'Reilly"; If you pass the magic-quoted value to serialize, it will choke on the escaped double quotes. If you run it through stripslashes(), unserialize will choke on the string-too-short problem. You could maybe work around it via regex, but... I worked around it by turning off magic_quotes. Perhaps this is more of a gotcha than a bug, but it would be nice to make unserialize smart enough to deal with the possibility. Full Bug description available at: http://bugs.php.net/?id=1693

« previous php.dev (#12330) next »