Bug->Doc #68802 [Opn->Ver]: PDO::FETCH_SERIALIZE not properly documented

From: Date: Tue, 20 Jul 2021 21:23:31 +0000
Subject: Bug->Doc #68802 [Opn->Ver]: PDO::FETCH_SERIALIZE not properly documented
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-18978@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=68802&edit=1

 ID:                 68802
 Updated by:         cmb@php.net
 Reported by:        zerkms at zerkms dot ru
-Summary:            PDO::FETCH_SERIALIZE does not unserialize object
+Summary:            PDO::FETCH_SERIALIZE not properly documented
-Status:             Open
+Status:             Verified
-Type:               Bug
+Type:               Documentation Problem
 Package:            PDO related
 PHP Version:        Irrelevant
 Block user comment: N
 Private report:     N

 New Comment:

TIL that PDO::FETCH_SERIALIZE is a thing – fascinating!

It seems to me that you must not store the serialized object, but
rather only its properties.  Otherwise it would not really make
sense to also specify the class to unserialize into.  E.g.

    $pdo->prepare('SELECT \'s:15:"My private data";\'');

would yield the expected output.  ext/pdo/tests/pdo_018.phpt seems
to confirm that.

Apparently, this needs to be documented.


Previous Comments:
------------------------------------------------------------------------
[2015-01-12 01:00:22] zerkms at zerkms dot ru

Description:
------------
PDO::FETCH_SERIALIZE flag must enable automatic deserialization of an object, while it does it in
some wrong way.

If you additionally see the passed data line you will notice that the argument passed
there contains extra data (the class name) that should not be there.

It causes the whole unserialization process to be broken.

The correspondning test https://github.com/php/php-src/blob/master/ext/pdo_mysql/tests/pdo_mysql_stmt_fetch_serialize.phpt
is also invalid since it does not check that we can assemble the original object back.

Test script:
---------------
class foo implements Serializable {
    private $data;
    public function __construct() {
        $this->data = "My private data";
    }
    public function serialize() {
        return serialize($this->data);
    }
    public function unserialize($data) {
        var_dump('passed data: ', $data);
        $this->data = unserialize($data);
    }
    public function getData() {
        return $this->data;
    }
}
$foo = new foo;
//var_dump(serialize($foo));

$stmt = $pdo->prepare('SELECT \'C:3:"foo":23:{s:15:"My private
data";}\'');
$stmt->execute();
$stmt->setFetchMode(PDO::FETCH_CLASS|PDO::FETCH_SERIALIZE, 'foo');
$data = $stmt->fetch();
var_dump($data);

Expected result:
----------------
  object(foo)#5 (1) {
    ["data":"foo":private]=>
    string(15) "My private data"
  }

Actual result:
--------------
object(foo)#4 (1) {
  ["data":"foo":private]=>
  object(foo)#5 (1) {
    ["data":"foo":private]=>
    string(15) "My private data"
  }
}


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=68802&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.doc.bugs (#18978) next »