Skip to content

Separate the storage of ArrayObject and ArrayIterator from the payload - #62

Merged
nicolas-grekas merged 1 commit into
mainfrom
spl-array-storage
Oct 7, 2026
Merged

nicolas-grekas merged 1 commit into
mainfrom
spl-array-storage

Conversation

@nicolas-grekas

Copy link
Copy Markdown
Member

ArrayObject::__serialize() and ArrayIterator::__serialize() return their storage without separating it (php/php-src#17935), and these classes write to it in place. So writing to such an object after deepclone_to_array() changed the payload, and every clone built from it later. The storage is now separated right after calling __serialize().

The polyfill gets the same fix in symfony/polyfill#715.

ArrayObject::__serialize() and ArrayIterator::__serialize() return their
storage without separating it, and these classes write to it in place. So
writing to such an object after deepclone_to_array() changed the payload,
and every clone built from it later.
nicolas-grekas added a commit to symfony/polyfill that referenced this pull request Oct 7, 2026
…rator from the payload (nicolas-grekas)

This PR was merged into the 1.x branch.

Discussion
----------

[DeepClone] Separate the storage of ArrayObject and ArrayIterator from the payload

| Q             | A
| ------------- | ---
| Branch?       | 1.x
| Bug fix?      | yes
| New feature?  | no
| Deprecations? | no
| Issues        | -
| License       | MIT

`ArrayObject::__serialize()` and `ArrayIterator::__serialize()` return their storage without separating it (php/php-src#17935), so writing to the object after `deepclone_to_array()` changes the payload, and every clone built from it later. That breaks the snapshot `DeepCloner` is used for, eg the FormFlow data stored in the session.

This separates that storage right after calling `__serialize()`. The extension gets the same fix in symfony/php-ext-deepclone#62.

Commits
-------

35039af [DeepClone] Separate the storage of ArrayObject and ArrayIterator from the payload
@nicolas-grekas
nicolas-grekas merged commit 13e0f0e into main Oct 7, 2026
24 checks passed
nicolas-grekas added a commit to symfony/symfony that referenced this pull request Oct 7, 2026
…writes to an ArrayObject (nicolas-grekas)

This PR was merged into the 8.1 branch.

Discussion
----------

[VarExporter] Fix DeepCloner snapshots changed by later writes to an ArrayObject

| Q             | A
| ------------- | ---
| Branch?       | 8.1
| Bug fix?      | yes
| New feature?  | no
| Deprecations? | no
| Issues        | -
| License       | MIT

`ArrayObject` and `ArrayIterator` return their storage from `__serialize()` without separating it (php/php-src#17935), so writing to such an object after creating a `DeepCloner` changed the snapshot, eg the FormFlow data saved in the session. symfony/polyfill-deepclone 1.43.1 fixes it (symfony/polyfill#715), and ext-deepclone gets the same fix in symfony/php-ext-deepclone#62.

Commits
-------

345b10e [VarExporter] Fix DeepCloner snapshots changed by later writes to an ArrayObject
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant