Skip to content

Fix deepclone_from_array() issues found by differential fuzzing - #59

Merged
nicolas-grekas merged 1 commit into
mainfrom
fuzz-from-array
Sep 29, 2026
Merged

nicolas-grekas merged 1 commit into
mainfrom
fuzz-from-array

Conversation

@nicolas-grekas

Copy link
Copy Markdown
Member

Also found by the differential fuzzing of the polyfill against the extension.

  • deepclone_from_array() rejected payloads that deepclone_to_array() produced when the array of a reference holds a & to a reference holding an object, a closure, an enum or an array: that second reference is already bound when its marker is resolved, eg with $v = [&$arr, &$arr, &$x] and $arr = ['x' => &$x].
  • A Serializable object whose data references it back, eg R:1;, unserializes to a reference, which is now unwrapped instead of being rejected. When a nested __unserialize() throws while creating one, the call fails right away instead of leaking the objects created before.
  • Typed properties are written like unserialize() and the polyfill do: null on a non-nullable one and a scalar on one typed with a backed enum throw a TypeError. deepclone_hydrate() keeps these conveniences.

When the array of a reference holds a & to a reference resolved after
it, that second reference is already bound when its marker is resolved:
dc_resolve() now dereferences the values it gets, instead of rejecting
them as not being of type int, array or string.

Serialized objects whose data references them back, eg R:1;, unserialize
to a reference, which is now unwrapped instead of being rejected. When a
delayed __unserialize() or __wakeup() call throws while unserializing
one, the call fails right away instead of leaking the objects created
before.

Typed properties are written like unserialize() and the polyfill do:
null on a non-nullable one and a scalar on one typed with a backed enum
throw a TypeError, instead of the conveniences of deepclone_hydrate().
@nicolas-grekas
nicolas-grekas merged commit 80744a2 into main Sep 29, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant