|
php.net | support | documentation | report a bug | advanced search | search howto | statistics | random bug | login |
PatchesPull RequestsHistoryAllCommentsChangesGit/SVN commits
[2016-05-06 13:32 UTC] nikic@php.net
-Status: Open
+Status: Not a bug
[2016-05-06 13:32 UTC] nikic@php.net
[2016-05-06 14:43 UTC] php at maisqi dot com
[2016-05-09 11:49 UTC] inefedor at gmail dot com
[2016-05-10 19:52 UTC] php at maisqi dot com
|
|||||||||||||||||||||||||||
Copyright © 2001-2026 The PHP GroupAll rights reserved. |
Last updated: Tue Oct 06 10:00:01 2026 UTC |
Description: ------------ When unserialize() finds a non-defined class it tries to autload it; but if that succeeds, but that class' base class is not "autoloadable", a Fatal Error is thrown. This makes the unserialize() function totally unpredictable, because we should get a couple of references to __PHP_Incomplete_Class but may just as well get the script aborted. Test script: --------------- <?php // file: "test.php" spl_autoload_register(function($className) {}); spl_autoload_register(function($className) { require_once 'ExistingClass.php'; }); $code = 'O:13:"ExistingClass":0:{}'; $o = unserialize($code); print_r($o); // file ends <?php // file: "ExistingClass.php" class ExistingClass extends NonExistingClass {} // file ends Expected result: ---------------- unserialize() should return a __PHP_Incomplete_Class object. Actual result: -------------- It throws a Fatal Error. This happens in PHP 7.0.6 x64 running on Windows 8 and in PHP 5.5.33 running on Linux CentOS.