Skip to content

Reject property names that start with a NUL byte - #61

Merged
nicolas-grekas merged 1 commit into
mainfrom
nul-property-names
Sep 29, 2026
Merged

nicolas-grekas merged 1 commit into
mainfrom
nul-property-names

Conversation

@nicolas-grekas

Copy link
Copy Markdown
Member

deepclone_from_array() created properties whose name starts with a NUL byte, which aren't legal PHP: the engine refuses to access them. They're now rejected.

An array cast can give such names to a stdClass, eg (object) ["\0x" => 1], which deepclone_to_array() keeps exporting as they are, like serialize() does: checking them would cost every stdClass, and much more in the polyfill, which gets the same rejection in symfony/polyfill#712.

deepclone_from_array() created properties whose name starts with a NUL
byte, which aren't legal PHP: the engine refuses to access them. They're
now rejected, eagerly for lazy objects too. An array cast can give such
names to a stdClass, which deepclone_to_array() keeps exporting as they
are, like serialize(): checking them would cost every stdClass, and more
in the polyfill.
@nicolas-grekas
nicolas-grekas merged commit 738f14f into main Sep 29, 2026
13 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant