Bug->Doc #73836 [Opn->Ana]: unserialize() with $options['allowed_classes'] = null behaves different
| From: | cmb@php.net | Date: | Fri, 30 Dec 2016 01:00:53 +0000 |
| Subject: | Bug->Doc #73836 [Opn->Ana]: unserialize() with $options['allowed_classes'] = null behaves different | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-14294@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=73836&edit=1
ID: 73836
Updated by: cmb@php.net
Reported by: denis dot brumann at sensiolabs dot de
Summary: unserialize() with $options['allowed_classes'] =
null behaves different
-Status: Open
+Status: Analyzed
-Type: Bug
+Type: Documentation Problem
-Package: Unknown/Other Function
+Package: Variables related
Operating System: macOS Sierra
PHP Version: 7.1.0
Block user comment: N
Private report: N
New Comment:
The warning (and bailing out with FALSE) has been introduced with
the fix of bug #72785, because the supplied test script showed an
unfortunate mistake, which would have caused all classes to be
allowed to be unserialized.
The fix had been only applied to PHP 7.1 for BC reasons, and it
makes sense to treat the warning also this way for the same
reasons.
What is missing, however, are entries in UPGRADING and the
migration guide, plus patching the unserialize() man page. Thus,
I'm changing to doc-bug.
As the other bug has not been classified as security issue, I take
it for granted that unserialize() shouldn't be used on untrusted
user input even if allowed_classes is appropriately set, what
might be mentioned more explicitly in the docs.
Previous Comments:
------------------------------------------------------------------------
[2016-12-29 19:04:16] denis dot brumann at sensiolabs dot de
Description:
------------
I just built a polyfill around the $options parameter added to unserialize() in PHP 7.0. I noticed a
different behaviour when allowed_classes is set to null (instead of false) when using PHP 7.0 and
7.1.
See Travis builds:
7.0 (fails) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532454
7.1 (passes) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532455
This is the test that's being executed:
https://github.com/dbrumann/polyfill-unserialize/blob/master/tests/UnserializeTest.php#L74
It seems that PHP 7.1 shows a warning, whereas 7.0 does not. I would expect PHP 7.0 to show the same
warning.
Test script:
---------------
$serialized = serialize(new \stdClass());
unserialize($serialized, ['allowed_classes' => null]);
Expected result:
----------------
I would expect both versions to behave the same, either both throw a warning (seems more plausible
or neither does).
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73836&edit=1