Doc #76606 [Csd]: Widespread regression with Serializable interface and legacy __wakeup method
| From: | westie at typefish dot co dot uk | Date: | Fri, 13 Jul 2018 08:22:05 +0000 |
| Subject: | Doc #76606 [Csd]: Widespread regression with Serializable interface and legacy __wakeup method | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-15881@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76606&edit=1
ID: 76606
User updated by: westie at typefish dot co dot uk
Reported by: westie at typefish dot co dot uk
Summary: Widespread regression with Serializable interface
and legacy __wakeup method
Status: Closed
Type: Documentation Problem
Package: Class/Object related
Operating System: All tested
PHP Version: Irrelevant
Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
For further reference, I have (for migration and curiosity purposes) created a library that
"fixes" this behaviour.
Any objects that were serialised before the class definition was changed to implement the
Serializable interface will become unserialisable once again, using oddly enough, the
unserialize method.
(The inverse is also true, __wakeup would be called when unserialising objects that no longer
support unserialisation via Serializable)
At the time of writing the support is limited to the types I can easily replicate, but I hope to
change that.
https://github.com/OUTRAGElib/unserialize
Previous Comments:
------------------------------------------------------------------------
[2018-07-11 12:54:19] cmb@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
------------------------------------------------------------------------
[2018-07-11 12:53:53] cmb@php.net
Automatic comment from SVN on behalf of cmb
Revision: http://svn.php.net/viewvc/?view=revision&revision=345303
Log: Fix #76606: Widespread regression with Serializable interface and legacy __wakeup method
We revert revision 339383. While this info was valid for PHP 5.1.0 up to
PHP 5.4.28 and 5.5.12, respectively, it is no longer, and as such it's
rather confusing.
------------------------------------------------------------------------
[2018-07-11 12:41:33] cmb@php.net
Sorry, all my mistake! I committed the respective note to the
manual[1] *after* the behavioral change had been introduced.
> [â¦] to specifically warn against the use of it for any planned
> long term storage of object data [â¦]
That's just my personal opinion, and it's not so much regarding
potential breakages in the serialization format, but rather to
prevent issues with changes to userland classes.
> [â¦] as well as a warning against relying on data being able to
> be unserialised between different versions of PHP?
Well, exchanging serialized data between different versions of PHP
should be fine, if the class definitions are identical.
[1] <http://svn.php.net/viewvc/?view=revision&revision=339383>
------------------------------------------------------------------------
[2018-07-10 21:45:18] westie at typefish dot co dot uk
Thank you @cmb and @ab for your interest and insights into this issue.
Firstly, despite a warning or two in the comments in the documentation for serialize
(https://secure.php.net/serialize) the documentation itself does not imply that output of serialize
is mutable; to quote, it says that it "[...] generates a *storable* representation of a
value" (emphasis mine)
I hope you don't find the tone of what I am going to suggest too abrasive but since this has
now been classed a documentation issue as opposed to an undocumented breaking change, perhaps the
documentation for serialize() also needs to be edited, to specifically warn against the use of it
for any planned long term storage of object data, as well as a warning against relying on data being
able to be unserialised between different versions of PHP?
Anyhow, I'm investigating alternative ways around this.
Thanks for your support!
------------------------------------------------------------------------
[2018-07-10 19:47:47] ab@php.net
Thanks for digging that deep, Christoph. The original issue was local but turned out to reveal a
common vulnerability with handling of the internal classe unserialisation. There was fixes on top of
that as well. In the end, the decision of the 5.4, 5.5 and 5.6 RMs was to keep the essential part of
the fix. Please check the links from Ferenc in the ticket you've linked. In the light of the
issues revealed, the sentence "Classes that implement this interface no longer support
__sleep() and __wakeup()." has still the precedence.
@westie sure in some grades it might be painful to migrate an app from 5.4 to 7.x. There has been
much more change than just this one in the meanwhile. The most viable way would be to recreate a
clean serialized data for your app. And, manipulated serialize strings was never promised to work.
In the end, it is a documentation issue today.
Thanks.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=76606
--
Edit this bug report at https://bugs.php.net/bug.php?id=76606&edit=1