Repository navigation
Fix deepclone_from_array() issues found by differential fuzzing - #59
Merged
Merged
Conversation
nicolas-grekas
force-pushed
the
fuzz-from-array
branch
from
September 29, 2026 21:03
4a60b32 to
042dd83
Compare
When the array of a reference holds a & to a reference resolved after it, that second reference is already bound when its marker is resolved: dc_resolve() now dereferences the values it gets, instead of rejecting them as not being of type int, array or string. Serialized objects whose data references them back, eg R:1;, unserialize to a reference, which is now unwrapped instead of being rejected. When a delayed __unserialize() or __wakeup() call throws while unserializing one, the call fails right away instead of leaking the objects created before. Typed properties are written like unserialize() and the polyfill do: null on a non-nullable one and a scalar on one typed with a backed enum throw a TypeError, instead of the conveniences of deepclone_hydrate().
nicolas-grekas
force-pushed
the
fuzz-from-array
branch
from
September 29, 2026 22:07
042dd83 to
cb0e4b3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Also found by the differential fuzzing of the polyfill against the extension.
deepclone_from_array()rejected payloads thatdeepclone_to_array()produced when the array of a reference holds a&to a reference holding an object, a closure, an enum or an array: that second reference is already bound when its marker is resolved, eg with$v = [&$arr, &$arr, &$x]and$arr = ['x' => &$x].Serializableobject whose data references it back, egR:1;, unserializes to a reference, which is now unwrapped instead of being rejected. When a nested__unserialize()throws while creating one, the call fails right away instead of leaking the objects created before.unserialize()and the polyfill do:nullon a non-nullable one and a scalar on one typed with a backed enum throw aTypeError.deepclone_hydrate()keeps these conveniences.