Re: Problems with the fix for the BC break introduced in 5.4.29 and 5.5.13

From: Date: Wed, 18 Jun 2014 09:05:46 +0000
Subject: Re: Problems with the fix for the BC break introduced in 5.4.29 and 5.5.13
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-74975@lists.php.net to get a copy of this message
On Wed, Jun 18, 2014 at 10:15 AM, Remi Collet <remi@php.net> wrote: > Le 18/06/2014 10:03, Ferenc Kovacs a écrit : > > >> 2. The following fix allowed this behavior for user classes. > >> > > > > yes > > Hmm... do you refer to > > > http://git.php.net/?p=php-src.git;a=patch;h=20568e502814fffc41d91a22edaf75ff5ae19d5c > > I think this allow to unserialize "O:.." for "internal" classes. > allows unserialize "O:" for userland classes implementing Serializable(even if that userland class extends an internal class): [tyrael@ferencs-mbp-135 php-src.git (PHP-5.5 ✗)]$ ./sapi/cli/php -v PHP 5.5.15-dev (cli) (built: Jun 17 2014 15:33:34) (DEBUG) Copyright (c) 1997-2014 The PHP Group Zend Engine v2.5.0, Copyright (c) 1998-2014 Zend Technologies [tyrael@ferencs-mbp-135 php-src.git (PHP-5.5 ✗)]$ ./sapi/cli/php -r "var_dump(unserialize('O:11:\"ArrayObject\":0:{}'));class MyArrayObject extends ArrayObject{};var_dump(unserialize('O:13:\"MyArrayObject\":0:{}'));" Warning: Erroneous data format for unserializing 'ArrayObject' in Command line code on line 1 bool(false) object(MyArrayObject)#1 (1) { ["storage":"ArrayObject":private]=> array(0) { } } > > As for user land classes, we have newInstanceWithoutConstructor. > > yes, but that also considers any class extending/implementing an internal class/interface as internal. -- Ferenc Kovács @Tyr43l - http://tyrael.hu

« previous php.internals (#74975) next »