[RFC] Don't automatically unserialize Phar metadata outside getMetadata()
| From: | tyson andre | Date: | Wed, 08 Jul 2020 00:06:51 +0000 |
| Subject: | [RFC] Don't automatically unserialize Phar metadata outside getMetadata() | ||
| Groups: | php.internals | ||
| Request: | Send a blank email to internals+get-110871@lists.php.net to get a copy of this message | ||
Hi internals,
I've created https://wiki.php.net/rfc/phar_stop_autoloading_metadata
as mentioned earlier in https://externals.io/message/110856
This aims to add the mitigations described in https://externals.io/message/105271#105291 ,
which seemed to be the most straightforward approach to avoiding unexpected side effects of
unserialization.
- For a trusted phar, I wouldn't expect to need to unserialize metadata to check for the file
not being corrupt (e.g. there's a checksum, and people would have tested the phar manually).
- For an untrusted phar, I'd want php to avoid calling unserialize() when reading it.
https://bugs.php.net/bug.php?id=76774 goes into
more detail about the security issues this aims to fix.
Thanks,
- Tyson