Doc #73836 [Ana->Csd]: unserialize() with $options['allowed_classes'] = null behaves different

From: Date: Fri, 30 Dec 2016 13:37:25 +0000
Subject: Doc #73836 [Ana->Csd]: unserialize() with $options['allowed_classes'] = null behaves different
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-14297@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=73836&edit=1 ID: 73836 Updated by: cmb@php.net Reported by: denis dot brumann at sensiolabs dot de Summary: unserialize() with $options['allowed_classes'] = null behaves different -Status: Analyzed +Status: Closed Type: Documentation Problem Package: Variables related Operating System: macOS Sierra PHP Version: 7.1.0 -Assigned To: +Assigned To: cmb Block user comment: N Private report: N Previous Comments: ------------------------------------------------------------------------ [2016-12-30 13:37:08] cmb@php.net Automatic comment from SVN on behalf of cmb Revision: http://svn.php.net/viewvc/?view=revision&revision=341547 Log: Fix #73836: unserialize() with $options['allowed_classes'] = null behaves different ------------------------------------------------------------------------ [2016-12-30 01:00:50] cmb@php.net The warning (and bailing out with FALSE) has been introduced with the fix of bug #72785, because the supplied test script showed an unfortunate mistake, which would have caused all classes to be allowed to be unserialized. The fix had been only applied to PHP 7.1 for BC reasons, and it makes sense to treat the warning also this way for the same reasons. What is missing, however, are entries in UPGRADING and the migration guide, plus patching the unserialize() man page. Thus, I'm changing to doc-bug. As the other bug has not been classified as security issue, I take it for granted that unserialize() shouldn't be used on untrusted user input even if allowed_classes is appropriately set, what might be mentioned more explicitly in the docs. ------------------------------------------------------------------------ [2016-12-29 19:04:16] denis dot brumann at sensiolabs dot de Description: ------------ I just built a polyfill around the $options parameter added to unserialize() in PHP 7.0. I noticed a different behaviour when allowed_classes is set to null (instead of false) when using PHP 7.0 and 7.1. See Travis builds: 7.0 (fails) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532454 7.1 (passes) https://travis-ci.org/dbrumann/polyfill-unserialize/jobs/187532455 This is the test that's being executed: https://github.com/dbrumann/polyfill-unserialize/blob/master/tests/UnserializeTest.php#L74 It seems that PHP 7.1 shows a warning, whereas 7.0 does not. I would expect PHP 7.0 to show the same warning. Test script: --------------- $serialized = serialize(new \stdClass()); unserialize($serialized, ['allowed_classes' => null]); Expected result: ---------------- I would expect both versions to behave the same, either both throw a warning (seems more plausible or neither does). ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=73836&edit=1

« previous php.doc.bugs (#14297) next »