Re: Re: BC break in 5.4.29 and 5.5.13

From: Date: Tue, 03 Jun 2014 12:41:23 +0000
Subject: Re: Re: BC break in 5.4.29 and 5.5.13
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-74707@lists.php.net to get a copy of this message
On Fri, May 30, 2014 16:25, Anatol Belski wrote: > Hi Remi, > > > On Fri, May 30, 2014 15:35, Remi Collet wrote: > >> Le 30/05/2014 13:45, Remi Collet a écrit : >> >> >>> Hi. >>> >>> >>> >>> Following http://news.php.net/php.internals/73957 >>> >>> >>> >>> This change breaks at least doctrine and phpunit. >>> >>> >>> >>> Source code: >>> >>> >>> >> >> https://github.com/doctrine/doctrine2/blob/master/lib/Doctrine/ORM/Mapp >> in g /ClassMetadataInfo.php#L911 >> >> >> Fixed in doctrine >> >> >> >> >> https://github.com/doctrine/doctrine2/commit/93c276d059b40b0783ba9a2454 >> 9a >> 8 >> b135e257693#diff-093aaad4da679d0374260757bf7bafca >> >>> >> >> https://github.com/sebastianbergmann/phpunit-mock-objects/blob/master/s >> rc / >> Framework/MockObject/Generator.php#L274 >> >> >> >> Fix in PHPUnit >> >> >> >> >> https://github.com/sebastianbergmann/phpunit-mock-objects/commit/1c68f1 >> 33 >> 8 >> f1940deb8265428bb2a7cbc5bc074b5#diff-64dbbc1c21f9be2d92e2b715617ffe34 >> >> >> https://github.com/sebastianbergmann/phpunit-mock-objects/commit/1c68f1 >> 33 >> 8 >> f1940deb8265428bb2a7cbc5bc074b5#diff-64dbbc1c21f9be2d92e2b715617ffe34 >> >> > thanks for the reproduce case. As discussed on the IRC, I'll be working > on a solution to minimize the BC break in 5.4 and 5.5. IMHO 5.6 is fine > with that "as is", as it's correct with the current specifications of the > Serializable and fixes wide range crash vulnerability. > > > Regards > > > Anatol > > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > > > I've invented a patch fixing BC regarding this issue. It passes the userspace classes but blocks the internal classes. While it's a must for the stable 5.4 and 5.5, I still doubt we should put it into 5.6++. Even it can work with userspace classes, it's highly inconsistent. For example - a userclass implementing Serializable but throwing an exception in unserialize() will behave wrong when instantiated that way. Basically before I apply this fix - IMHO, it should go into 5.4 and 5.5 only, 5.6 should have clean behaviour. From the userspace perspective - doctrine and phpunit have already fixed this using ReflectionClass::newInstanceWithoutConstructor(), so that is fine with the future. The fix should only go for legacy. So, what you say? Regards Anatol

« previous php.internals (#74707) next »