Skip to content

Make MessagePack and MessagePackUnpacker not serializable - #190

Open
nicolas-grekas wants to merge 1 commit into
msgpack:masterfrom
nicolas-grekas:not-serializable
Open

nicolas-grekas wants to merge 1 commit into
msgpack:masterfrom
nicolas-grekas:not-serializable

Conversation

@nicolas-grekas

@nicolas-grekas nicolas-grekas commented Sep 29, 2026 •

Copy link
Copy Markdown

serialize() loses the options of MessagePack and the buffer of MessagePackUnpacker, and unserialize() creates objects without them.

This flags both classes as not serializable, so that serialize(), unserialize() and msgpack_pack(), which already honors the flag, throw. Other serializers that honor it, like symfony/php-ext-deepclone, then reject them too. Before PHP 8.1, which has no such flag, they get the handlers that deny serialization instead.

@nicolas-grekas

Copy link
Copy Markdown
Author

PR updated: before PHP 8.1, the classes now get the handlers that deny serialization, as suggested in phpredis/phpredis#2938, and the test runs on those versions too.

serialize() lost their options and the buffer of unpackers, and
unserialize() created objects without them. Both now throw, and so does
msgpack_pack(): from PHP 8.1 on through the ZEND_ACC_NOT_SERIALIZABLE
flag, which msgpack_pack() already honors, and before through the
zend_class_(un)serialize_deny handlers.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant