Repository navigation
Separate the storage of ArrayObject and ArrayIterator from the payload - #62
Merged
Merged
Conversation
ArrayObject::__serialize() and ArrayIterator::__serialize() return their storage without separating it, and these classes write to it in place. So writing to such an object after deepclone_to_array() changed the payload, and every clone built from it later.
nicolas-grekas
added a commit
to symfony/polyfill
that referenced
this pull request
Oct 7, 2026
…rator from the payload (nicolas-grekas) This PR was merged into the 1.x branch. Discussion ---------- [DeepClone] Separate the storage of ArrayObject and ArrayIterator from the payload | Q | A | ------------- | --- | Branch? | 1.x | Bug fix? | yes | New feature? | no | Deprecations? | no | Issues | - | License | MIT `ArrayObject::__serialize()` and `ArrayIterator::__serialize()` return their storage without separating it (php/php-src#17935), so writing to the object after `deepclone_to_array()` changes the payload, and every clone built from it later. That breaks the snapshot `DeepCloner` is used for, eg the FormFlow data stored in the session. This separates that storage right after calling `__serialize()`. The extension gets the same fix in symfony/php-ext-deepclone#62. Commits ------- 35039af [DeepClone] Separate the storage of ArrayObject and ArrayIterator from the payload
nicolas-grekas
added a commit
to symfony/symfony
that referenced
this pull request
Oct 7, 2026
…writes to an ArrayObject (nicolas-grekas) This PR was merged into the 8.1 branch. Discussion ---------- [VarExporter] Fix DeepCloner snapshots changed by later writes to an ArrayObject | Q | A | ------------- | --- | Branch? | 8.1 | Bug fix? | yes | New feature? | no | Deprecations? | no | Issues | - | License | MIT `ArrayObject` and `ArrayIterator` return their storage from `__serialize()` without separating it (php/php-src#17935), so writing to such an object after creating a `DeepCloner` changed the snapshot, eg the FormFlow data saved in the session. symfony/polyfill-deepclone 1.43.1 fixes it (symfony/polyfill#715), and ext-deepclone gets the same fix in symfony/php-ext-deepclone#62. Commits ------- 345b10e [VarExporter] Fix DeepCloner snapshots changed by later writes to an ArrayObject
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
ArrayObject::__serialize()andArrayIterator::__serialize()return their storage without separating it (php/php-src#17935), and these classes write to it in place. So writing to such an object afterdeepclone_to_array()changed the payload, and every clone built from it later. The storage is now separated right after calling__serialize().The polyfill gets the same fix in symfony/polyfill#715.