Newsgroups: php.internals Path: news.php.net Xref: news.php.net php.internals:78399 Return-Path: Mailing-List: contact internals-help@lists.php.net; run by ezmlm Delivered-To: mailing list internals@lists.php.net Received: (qmail 79009 invoked from network); 27 Oct 2014 18:16:52 -0000 Received: from unknown (HELO lists.php.net) (127.0.0.1) by localhost with SMTP; 27 Oct 2014 18:16:52 -0000 Authentication-Results: pb1.pair.com header.from=dmitry@zend.com; sender-id=pass Authentication-Results: pb1.pair.com smtp.mail=dmitry@zend.com; spf=pass; sender-id=pass Received-SPF: pass (pb1.pair.com: domain zend.com designates 209.85.218.53 as permitted sender) X-PHP-List-Original-Sender: dmitry@zend.com X-Host-Fingerprint: 209.85.218.53 mail-oi0-f53.google.com Received: from [209.85.218.53] ([209.85.218.53:40631] helo=mail-oi0-f53.google.com) by pb1.pair.com (ecelerity 2.1.1.9-wez r(12769M)) with ESMTP id D0/74-56216-31C8E445 for ; Mon, 27 Oct 2014 13:16:51 -0500 Received: by mail-oi0-f53.google.com with SMTP id v63so3725845oia.26 for ; Mon, 27 Oct 2014 11:16:49 -0700 (PDT) X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20130820; h=x-gm-message-state:mime-version:in-reply-to:references:date :message-id:subject:from:to:cc:content-type; bh=CbLIzJZWBVec4MPFy9b99wet7zfuSjQ2H7xYS+J8UmM=; b=dA6qapTjQlxEsMuUiDwFCkl2B4MtTYWbSsjqa3y1jQ7ty/ajbi+lCBzD+iqPxz3CP9 klNUmRbx4DkiqshZHaxGjtuu9BGvXCMGOLJ9rsHtjeGTSROOtfQ0hK8kx2soXpnFpuYw vLihO0NhK5wSTky9uvbfku3/+4ntUZjzuiwj/tAbX1/XvLe8zPXkDDeVyD2N/a6umNo8 pKmAjV0emWvQcj8rQu5EKX9kzt9GQL04SIt/G4rV9a3fP4qAwJzpNaytDcQYBGziqrfQ +O1LuoXyjt2z25cdhzckFwdsbpwotu7iBHuzmUpDFTwWng/KiBsPAjNWy8MPNOJjuBV4 dalg== X-Gm-Message-State: ALoCoQn6SamMQzo2/mKlo/DHGuiB/M6I2T3rvBEEgkrM7Q8X4llZj34zXh1wpCA5Mvgno684RxHWWpv53Y/pQggTAQznP+swjwEbouWSuosWFon42VGXtZzTpGvkrzeJAmltnYt1v69jFx6gt6wurWjk5KsJ6zyRQg== MIME-Version: 1.0 X-Received: by 10.182.33.138 with SMTP id r10mr2783593obi.67.1414433809035; Mon, 27 Oct 2014 11:16:49 -0700 (PDT) Received: by 10.60.70.41 with HTTP; Mon, 27 Oct 2014 11:16:48 -0700 (PDT) In-Reply-To: <544DFC5F.9020408@sugarcrm.com> References: <544DFC5F.9020408@sugarcrm.com> Date: Mon, 27 Oct 2014 22:16:48 +0400 Message-ID: To: Stas Malyshev Cc: PHP Internals Content-Type: multipart/alternative; boundary=001a11c2cb9abf0f8505066b8863 Subject: Re: [PHP-DEV] [RFC] Serialize filtering From: dmitry@zend.com (Dmitry Stogov) --001a11c2cb9abf0f8505066b8863 Content-Type: text/plain; charset=UTF-8 Hi Stas, I'm not sure if this new argument to unserialize() is intuitive. May be better to use separate functions - unserialize_filtered() or something similar. Thanks. Dmitry. On Mon, Oct 27, 2014 at 11:03 AM, Stas Malyshev wrote: > Hi! > > I'd like to have a vote on unserialize() improvement proposal outlined > here: > https://wiki.php.net/rfc/secure_unserialize > > soon-ish, but since discussion on it has been more than a year ago I'd > like to give it some prior notice and some time to re-consider. I still > think it is a good improvement, not fixing all problems but allowing to > fix some at reasonable cost. I've added some outline of arguments > discussed before, but still open for comments. The patch is probably > outdated but I'll fix it if it's accepted, if not I don't want to spend > time on it. I'd like to have a vote sometime next week, but if there's > more discussion it can be postponed. > -- > Stanislav Malyshev, Software Architect > SugarCRM: http://www.sugarcrm.com/ > > -- > PHP Internals - PHP Runtime Development Mailing List > To unsubscribe, visit: http://www.php.net/unsub.php > > --001a11c2cb9abf0f8505066b8863--