Re: Bug 67072 resolution for 5.4/5.5
| From: | Stas Malyshev | Date: | Mon, 23 Jun 2014 00:20:32 +0000 |
| Subject: | Re: Bug 67072 resolution for 5.4/5.5 | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-75040@lists.php.net to get a copy of this message | ||
Hi!
> for the issue to materialize you need to feed hand-crafted input to
> unserialize,
True.
> anybody doing that with user controlled data already asking
> for problems,
True in theory, in practice this is widely and commonly done.
> I prefer this over what we have in 5.4/5.5 and given how few classes
> does 1, actually mean, I think it would be an acceptable compromise, but
> let's hear what others think.
Cool, waiting for others to chime in.
> ps: I've seen that you created a pull request with the patch, if
> somebody don't wanna copypaste the patch from the mail, here it is:
> https://github.com/php/php-src/pull/701
Yes, thanks for quoting it, it seems to be green on Travis and phpunit
also seems to work fine with it. I also added a unit tests with a couple
of cases to see how it's supposed to work.
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227