Possibly missing warning for `unserialize('')` - may be confused with "false"
Mantenedores costumam responder em até 1 dia
Ninguém assumiu esta issue ainda.
Avaliação
- Dificuldade
- 5/5
- Tempo estimado
- Mais de uma semana
- Facilidade para iniciantes
- 45/100
Direção de pesquisa
Start by reproducing the supplied PHP example, then read ext/standard/var.c around php_unserialize_with_options at the linked condition. Check existing unserialize behavior and tests before deciding whether empty input should warn; done means the expected behavior is agreed and covered by an appropriate regression test.
Escrita pelo modelo de indexação a partir do texto da issue.
Descrição
Description
The following code:
<?php
error_reporting(E_ALL);
ini_set('display_errors', '1');
ini_set('display_startup_errors', '1');
$a = 'b:0;'; // serialize(false);
$b = '';
var_dump($a === $b);
var_dump(unserialize($a) === unserialize($b));
Resulted in this output:
bool(false)
bool(true)
But I expected this output instead:
bool(false)
Warning: unserialize(): Empty input in /in/bjBq9 on line 11
bool(true)
Dear Developers, Artists,
Thank you for the marvel, art...
On 2026-09-18, at Libera IRC channel #php, a member ash_worksi raised this issue asking why no warning is raised in PHP, if compared to unserialize(' ');, for example.
My contention is the fact that it doesn't raise a warning like the description says. It's a very narrow edge case, but just like any "non-unserializable" string (...otherwise why would it return false?) it should raise the warning.
unserialize()returning false on it's own does not tell you whether the function failed to unserialize or if the value you unserialized was in factfalse.~ ash_worksi
Later, I tried searching for the actual reason it happens, and the condition involved is likely the following, in the function php_unserialize_with_options:
The condition explicitly checks if the string is empty, and returns "false" by design, and considering the first commits checked, it has been so for at least "20 years ago".
I believe that for so much time, it was discussed already, but just in case, is it still actually expected?
Best and kind regards
PHP Version
PHP 8.5.10 (cli) (built: Sep 19 2026 00:23:53) (NTS)
Copyright (c) The PHP Group
Built by https://github.com/docker-library/php
Zend Engine v4.5.10, Copyright (c) Zend Technologies
with Zend OPcache v8.5.10, Copyright (c), by Zend Technologies
Operating System
Kubuntu 26.10 (Docker)
- Linguagem predominante
- C
- Estrelas
- 40.4k
- Forks
- 8.2k
- Merge médio
- 2d 7h
- PRs com merge (30d)
- 153
Preparar o ambiente
- Sem Dockerfile nem arquivo Docker Compose
- Sem modelo de pull request
- Ler o guia de contribuição
Primeiros passos
- Leia a issue inteira e depois o guia de contribuição do projeto.
- Comente na issue dizendo que vai assumir — evita que duas pessoas façam o mesmo trabalho.
- Faça um fork do repositório e trabalhe em uma branch.
- Abra um pull request que referencie o número da issue.
Mais de php/php-src
-
Bug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 74/100
php/php-src#24121 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Variant analysis: 1 unfixed sibling safety gap in php-srcTalvez já em andamento @kamil-tekiela assumiu há 6 dias. Aberta
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
php/php-src#23958 · 1 responsável ·
Mantenedores costumam responder em até 1 dia
-
sapi_lsapi_ub_write does not return bytes written in lsapi modeTalvez já em andamento Um pull request vinculado a esta issue está aberto ou já foi mesclado. AbertaBug Status: Needs Triage
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
Mantenedores costumam responder em até 1 dia
-
Bug Status: Needs Triage
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 78/100
Mantenedores costumam responder em até 1 dia
-
Flaky hrtime.phpt testTalvez já em andamento @veksa assumiu há 61 dias. AbertaBug Category: Tests Status: Verified
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
Mantenedores costumam responder em até 1 dia
Todas as issues de php/php-src
Issues semelhantes
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
libsdl-org/SDL#16444 ·
Mantenedores costumam responder em até 1 dia
-
bug Component component: net
Dificuldade 1/5 Menos de uma hora Facilidade para iniciantes 90/100
RT-Thread/rt-thread#11852 · 1 comentário ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 68/100
MiSTer-devel/ao486_MiSTer#243 ·
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 66/100
siderolabs/pkgs#1710 ·
Mantenedores costumam responder em até 1 dia
-
Dificuldade 2/5 1-3 horas Facilidade para iniciantes 72/100
Mantenedores costumam responder em até 1 dia