Bug->Doc #68099 [Opn]: Unable to unserialize data after implementing Serializable

From: Date: Wed, 15 Oct 2014 16:25:17 +0000
Subject: Bug->Doc #68099 [Opn]: Unable to unserialize data after implementing Serializable
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-11550@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68099&edit=1 ID: 68099 Updated by: tyrael@php.net Reported by: manuel-php at mausz dot at Summary: Unable to unserialize data after implementing Serializable Status: Open -Type: Bug +Type: Documentation Problem Package: *General Issues PHP Version: 5.6.1RC1 Block user comment: N Private report: N New Comment: hi, classes implementing the Serializable interface are using a different serialize format than used for other classes. unfortunately when this new format was introduced, there were no checks implemented to enforce this behavior, so it was possible to unserialize an instance implementing the Serialize interface using the old format, which bypassed the call for the unserialize method declared for that class. with 5.6 we implemented these checks to enforce that the unserialize calls can't be bypassed using the old serialize format. while what you are doing in your example is pretty risky, as it is prone to result in an bogus instance(the only case where it would produce the correct result is that if your class' unserialize handler writes the same properties and does no other transformation on the data), I think you are still right that we should explicitly state this behavior change in the migration guide(currently we only mention the change in the unserialize manual: http://php.net/manual/en/function.unserialize.php ). Previous Comments: ------------------------------------------------------------------------ [2014-09-25 20:31:55] manuel-php at mausz dot at Reverting c2acdbdd3deb6787329bf0aca8ab0c04ace2a50c fixes this issue ------------------------------------------------------------------------ [2014-09-25 16:23:51] manuel-php at mausz dot at Description: ------------ Consider the following case: * User implements class Foo which gets serialized and unserialized during daily use. Serialized data is stored somewhere. * User changes class Foo to implement Serializable * User still wants to transparently unserialize his old data This worked in PHP5.5 and below. It's broken in PHP 5.6.0 and above. If this is intended than this is a major BC break not mentioned in the upgrade guidelines. Test script: --------------- <?php error_reporting(E_ALL); # export ... simulates exporting old data where class Foo didn't implement Serializable $mode = (isset($argv[1]) && $argv[1] === 'import') ? 'import' : 'export'; if ($mode === 'export') { class Foo { protected $foo = null; public function __construct() { $this->foo = "something"; } } $foo = new Foo(); $data = serialize($foo); file_put_contents('/tmp/phpbug', $data); } else { class Foo implements Serializable { protected $foo = null; public function __construct() { $this->foo = "something"; } public function serialize() { echo __CLASS__ . "::serialize called\n"; return $this->foo; } public function unserialize($data) { echo __CLASS__ . "::unserialize called\n"; $this->foo = $data; } } $data = file_get_contents('/tmp/phpbug'); $foo = unserialize($data); if ($foo instanceof Foo) echo "Thumbs up!\n"; else echo "Unserialize FAILED\n"; } Expected result: ---------------- # php5.5 serialize.php export; php5.5 serialize.php import Thumbs up! Actual result: -------------- ./php-src-PHP-5.6.1/sapi/cli/php serialize.php export ; ./php-src-PHP-5.6.1/sapi/cli/php serialize.php import Warning: Erroneous data format for unserializing 'Foo' in /home/manuel/serialize.php on line 49 Notice: unserialize(): Error at offset 13 of 43 bytes in /home/manuel/serialize.php on line 49 Unserialize FAILED ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=68099&edit=1

« previous php.doc.bugs (#11550) next »