Re: Re: BC break in 5.4.29 and 5.5.13
| From: | Anatol Belski | Date: | Tue, 03 Jun 2014 12:41:23 +0000 |
| Subject: | Re: Re: BC break in 5.4.29 and 5.5.13 | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74707@lists.php.net to get a copy of this message | ||
On Fri, May 30, 2014 16:25, Anatol Belski wrote:
> Hi Remi,
>
>
> On Fri, May 30, 2014 15:35, Remi Collet wrote:
>
>> Le 30/05/2014 13:45, Remi Collet a écrit :
>>
>>
>>> Hi.
>>>
>>>
>>>
>>> Following http://news.php.net/php.internals/73957
>>>
>>>
>>>
>>> This change breaks at least doctrine and phpunit.
>>>
>>>
>>>
>>> Source code:
>>>
>>>
>>>
>>
>> https://github.com/doctrine/doctrine2/blob/master/lib/Doctrine/ORM/Mapp
>> in g /ClassMetadataInfo.php#L911
>>
>>
>> Fixed in doctrine
>>
>>
>>
>>
>> https://github.com/doctrine/doctrine2/commit/93c276d059b40b0783ba9a2454
>> 9a
>> 8
>> b135e257693#diff-093aaad4da679d0374260757bf7bafca
>>
>>>
>>
>> https://github.com/sebastianbergmann/phpunit-mock-objects/blob/master/s
>> rc /
>> Framework/MockObject/Generator.php#L274
>>
>>
>>
>> Fix in PHPUnit
>>
>>
>>
>>
>> https://github.com/sebastianbergmann/phpunit-mock-objects/commit/1c68f1
>> 33
>> 8
>> f1940deb8265428bb2a7cbc5bc074b5#diff-64dbbc1c21f9be2d92e2b715617ffe34
>>
>>
>> https://github.com/sebastianbergmann/phpunit-mock-objects/commit/1c68f1
>> 33
>> 8
>> f1940deb8265428bb2a7cbc5bc074b5#diff-64dbbc1c21f9be2d92e2b715617ffe34
>>
>>
> thanks for the reproduce case. As discussed on the IRC, I'll be working
> on a solution to minimize the BC break in 5.4 and 5.5. IMHO 5.6 is fine
> with that "as is", as it's correct with the current specifications of the
> Serializable and fixes wide range crash vulnerability.
>
>
> Regards
>
>
> Anatol
>
>
> --
> PHP Internals - PHP Runtime Development Mailing List
> To unsubscribe, visit: http://www.php.net/unsub.php
>
>
>
I've invented a patch fixing BC regarding this issue. It passes the
userspace classes but blocks the internal classes. While it's a must for
the stable 5.4 and 5.5, I still doubt we should put it into 5.6++. Even it
can work with userspace classes, it's highly inconsistent. For example - a
userclass implementing Serializable but throwing an exception in
unserialize() will behave wrong when instantiated that way.
Basically before I apply this fix - IMHO, it should go into 5.4 and 5.5
only, 5.6 should have clean behaviour. From the userspace perspective -
doctrine and phpunit have already fixed this using
ReflectionClass::newInstanceWithoutConstructor(), so that is fine with the
future. The fix should only go for legacy. So, what you say?
Regards
Anatol