Hacktoberfest 2026: as issues que os mantenedores marcaram para outubro, abertas e boas para iniciantes. Ver issues do Hacktoberfest

Possibly missing warning for `unserialize('')` - may be confused with "false"

Fechada
#23,780 5 comentários 0 reações 0 responsáveis Ver no GitHub

Mantenedores costumam responder em até 1 dia

Ninguém assumiu esta issue ainda.

Avaliação

Dificuldade
5/5
Tempo estimado
Mais de uma semana
Facilidade para iniciantes
45/100
Tipo de issue
Bug
Clareza
Razoavelmente clara
Status de atividade
Ativa
Stack de tecnologia
c, php
Domínio
backend

Direção de pesquisa

Start by reproducing the supplied PHP example, then read ext/standard/var.c around php_unserialize_with_options at the linked condition. Check existing unserialize behavior and tests before deciding whether empty input should warn; done means the expected behavior is agreed and covered by an appropriate regression test.

Escrita pelo modelo de indexação a partir do texto da issue.

Descrição

Bug Status: Verified
Description

The following code:

<?php

error_reporting(E_ALL);
ini_set('display_errors', '1');
ini_set('display_startup_errors', '1');

$a = 'b:0;'; // serialize(false);
$b = '';

var_dump($a === $b);
var_dump(unserialize($a) === unserialize($b));

Resulted in this output:

bool(false)
bool(true)

But I expected this output instead:

bool(false)

Warning: unserialize(): Empty input in /in/bjBq9 on line 11
bool(true)

Dear Developers, Artists,

Thank you for the marvel, art...

On 2026-09-18, at Libera IRC channel #php, a member ash_worksi raised this issue asking why no warning is raised in PHP, if compared to unserialize(' ');, for example.

My contention is the fact that it doesn't raise a warning like the description says. It's a very narrow edge case, but just like any "non-unserializable" string (...otherwise why would it return false?) it should raise the warning.

unserialize() returning false on it's own does not tell you whether the function failed to unserialize or if the value you unserialized was in fact false.

~ ash_worksi

Later, I tried searching for the actual reason it happens, and the condition involved is likely the following, in the function php_unserialize_with_options:

https://github.com/php/php-src/blob/13cec7c276033883e1e0ee22ea92fa1838b06dca/ext/standard/var.c#L1414-L1416

The condition explicitly checks if the string is empty, and returns "false" by design, and considering the first commits checked, it has been so for at least "20 years ago".

Image

I believe that for so much time, it was discussed already, but just in case, is it still actually expected?

Best and kind regards

PHP Version
PHP 8.5.10 (cli) (built: Sep 19 2026 00:23:53) (NTS)
Copyright (c) The PHP Group
Built by https://github.com/docker-library/php
Zend Engine v4.5.10, Copyright (c) Zend Technologies
    with Zend OPcache v8.5.10, Copyright (c), by Zend Technologies
Operating System

Kubuntu 26.10 (Docker)

Linguagem predominante
C
Estrelas
40.4k
Forks
8.2k
Merge médio
2d 7h
PRs com merge (30d)
153

Preparar o ambiente

Primeiros passos

  1. Leia a issue inteira e depois o guia de contribuição do projeto.
  2. Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
  3. Faça um fork do repositório e trabalhe em uma branch.
  4. Abra um pull request que referencie o número da issue.

Mais de php/php-src

Todas as issues de php/php-src

Issues semelhantes

Mais issues de C

Receba novas issues na sua caixa de entrada

Um resumo curto de issues do GitHub para quem está começando.