Re: Problems with the fix for the BC break introduced in 5.4.29 and 5.5.13
| From: | Ferenc Kovacs | Date: | Wed, 18 Jun 2014 09:05:46 +0000 |
| Subject: | Re: Problems with the fix for the BC break introduced in 5.4.29 and 5.5.13 | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-74975@lists.php.net to get a copy of this message | ||
On Wed, Jun 18, 2014 at 10:15 AM, Remi Collet <remi@php.net> wrote:
> Le 18/06/2014 10:03, Ferenc Kovacs a écrit :
>
> >> 2. The following fix allowed this behavior for user classes.
> >>
> >
> > yes
>
> Hmm... do you refer to
>
>
> http://git.php.net/?p=php-src.git;a=patch;h=20568e502814fffc41d91a22edaf75ff5ae19d5c
>
> I think this allow to unserialize "O:.." for "internal" classes.
>
allows unserialize "O:" for userland classes implementing Serializable(even
if that userland class extends an internal class):
[tyrael@ferencs-mbp-135 php-src.git (PHP-5.5 ✗)]$ ./sapi/cli/php -v
PHP 5.5.15-dev (cli) (built: Jun 17 2014 15:33:34) (DEBUG)
Copyright (c) 1997-2014 The PHP Group
Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies
[tyrael@ferencs-mbp-135 php-src.git (PHP-5.5 ✗)]$ ./sapi/cli/php -r
"var_dump(unserialize('O:11:\"ArrayObject\":0:{}'));class MyArrayObject
extends
ArrayObject{};var_dump(unserialize('O:13:\"MyArrayObject\":0:{}'));"
Warning: Erroneous data format for unserializing 'ArrayObject' in Command
line code on line 1
bool(false)
object(MyArrayObject)#1 (1) {
["storage":"ArrayObject":private]=>
array(0) {
}
}
>
> As for user land classes, we have newInstanceWithoutConstructor.
>
>
yes, but that also considers any class extending/implementing an internal
class/interface as internal.
--
Ferenc Kovács
@Tyr43l - http://tyrael.hu