Skip to content

standard: Create incomplete objects again from the C format - #24020

Merged
kocsismate merged 1 commit into
php:PHP-8.6from
nicolas-grekas:fix-unserialize-incomplete-class-c-format
Sep 30, 2026
Merged

kocsismate merged 1 commit into
php:PHP-8.6from
nicolas-grekas:fix-unserialize-incomplete-class-c-format

Conversation

@nicolas-grekas

Copy link
Copy Markdown
Contributor

Since #22058 (GH-22046), unserialize() returns false as a whole when a payload holds a C: object of a class that is missing or not in allowed_classes: that class is replaced by __PHP_Incomplete_Class, which has no unserializer either. Up to 8.5, an empty incomplete object carrying the class name came back and the rest of the payload was decoded, so allowed_classes can't be used anymore to read such payloads. This happens in practice when a class that implemented Serializable is removed, see #18128.

final class Kept { public $a = 1; }
var_dump(unserialize('a:2:{i:0;O:4:"Kept":1:{s:1:"a";i:2;}i:1;C:5:"Nope1":4:{abcd}}', ['allowed_classes' => ['Kept']]));

The incomplete class has no internal state, so creating an empty one is safe, and it's what the O: format already does for it. Real classes that have no unserializer keep failing, as #22058 intended.

Since phpGH-22046 was fixed, unserialize() fails as a whole when a `C` payload
names a class that is missing or not in allowed_classes, because the
__PHP_Incomplete_Class substituted for it has no unserializer either.

The incomplete class has no internal state, so create an empty one as
before and keep failing only for real classes that are not Serializable.
@nicolas-grekas

Copy link
Copy Markdown
Contributor Author

/cc @kocsismate
For now we have to do this kind of ugly workaround, please allow us to merge this PR :)
https://github.com/symfony/symfony/pull/66501/files

@ndossche ndossche left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

For me this is fine. Leaving final review for @kocsismate

@kocsismate
kocsismate merged commit 4bf700e into php:PHP-8.6 Sep 30, 2026
18 checks passed
kocsismate added a commit that referenced this pull request Sep 30, 2026
* PHP-8.6:
  standard: Create incomplete objects again from the `C` format (#24020)
nicolas-grekas added a commit to symfony/symfony that referenced this pull request Sep 30, 2026
… bus name of an undecodable message (nicolas-grekas)

This PR was merged into the 8.1 branch.

Discussion
----------

[Messenger] Revert the PHP 8.6 workaround for reading the bus name of an undecodable message

| Q             | A
| ------------- | ---
| Branch?       | 8.1
| Bug fix?      | no
| New feature?  | no
| Deprecations? | no
| Issues        | -
| License       | MIT

This reverts c6df1ae, the tokenizer that reads only the `BusNameStamp` list of a payload that failed to decode.

It's needed only because PHP 8.6 fails to unserialize a payload holding a `C:` object of a class that is not allowed, and php/php-src#24020 fixes that. Pending on it: the "Unit Tests (8.6)" job stays red until the fix lands in the 8.6 builds.

Commits
-------

75245e1 Revert "[Messenger] Fix reading the bus name of a message that fails to decode on PHP 8.6"
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants