<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/php-git.git, branch php-7.0.10</title>
<subtitle>git.php.net: repository/php-src.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/'/>
<entry>
<title>sync NEWS with entries and release date</title>
<updated>2016-08-17T15:58:20+00:00</updated>
<author>
<name>Anatol Belski</name>
<email>ab@php.net</email>
</author>
<published>2016-08-17T15:58:20+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=da12ca9c1ed03084e6803f5e81e46f2e0a80460a'/>
<id>da12ca9c1ed03084e6803f5e81e46f2e0a80460a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>apply missing patch for #72681</title>
<updated>2016-08-17T14:31:00+00:00</updated>
<author>
<name>Anatol Belski</name>
<email>ab@php.net</email>
</author>
<published>2016-08-17T14:31:00+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=d6f62b7d6eeda77dc83565e994c44bf8bba7e147'/>
<id>d6f62b7d6eeda77dc83565e994c44bf8bba7e147</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>set version</title>
<updated>2016-08-17T14:25:22+00:00</updated>
<author>
<name>Anatol Belski</name>
<email>ab@php.net</email>
</author>
<published>2016-08-17T14:25:22+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=bd38aea92ccc0748aa5ab807b2f457dd37366bfc'/>
<id>bd38aea92ccc0748aa5ab807b2f457dd37366bfc</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>fix tests</title>
<updated>2016-08-17T12:00:23+00:00</updated>
<author>
<name>Anatol Belski</name>
<email>ab@php.net</email>
</author>
<published>2016-08-17T12:00:23+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=40f48594d2d12e9710271c06544402d1d5b9db2d'/>
<id>40f48594d2d12e9710271c06544402d1d5b9db2d</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #72663 - destroy broken object when unserializing</title>
<updated>2016-08-17T11:59:18+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2016-08-02T08:08:42+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=20ce2fe8e3c211a42fee05a461a5881be9a8790e'/>
<id>20ce2fe8e3c211a42fee05a461a5881be9a8790e</id>
<content type='text'>
(cherry picked from commit 448c9be157f4147e121f1a2a524536c75c9c6059)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit 448c9be157f4147e121f1a2a524536c75c9c6059)
</pre>
</div>
</content>
</entry>
<entry>
<title>fix test</title>
<updated>2016-08-17T11:53:22+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2016-08-17T08:12:33+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=8d7766a948999b990dbd13f96fa845a26d6f8f66'/>
<id>8d7766a948999b990dbd13f96fa845a26d6f8f66</id>
<content type='text'>
(cherry picked from commit ed9d916c28b042d276a28998f92eb7e6cc56025a)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit ed9d916c28b042d276a28998f92eb7e6cc56025a)
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug #72663 - part 3</title>
<updated>2016-08-17T11:52:28+00:00</updated>
<author>
<name>Nikita Popov</name>
<email>nikic@php.net</email>
</author>
<published>2016-08-10T12:46:38+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=758a0cd8b3941935b5ec10256c336544e0d6ad41'/>
<id>758a0cd8b3941935b5ec10256c336544e0d6ad41</id>
<content type='text'>
When using the php_serialize session serialization handler, do
not use the result of the unserialization if it failed.

(cherry picked from commit e0f9fbdfa61012101de7f4a8653ca5538c404a71)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
When using the php_serialize session serialization handler, do
not use the result of the unserialization if it failed.

(cherry picked from commit e0f9fbdfa61012101de7f4a8653ca5538c404a71)
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug #72663 - part 2</title>
<updated>2016-08-17T11:51:06+00:00</updated>
<author>
<name>Nikita Popov</name>
<email>nikic@php.net</email>
</author>
<published>2016-08-10T12:30:16+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=d3221181c3a27e7f1e23c6db1266fde820d471d7'/>
<id>d3221181c3a27e7f1e23c6db1266fde820d471d7</id>
<content type='text'>
If a (nested) unserialize() call fails, we remove all the values
that were inserted into var_hash during that call. This prevents
their use in other unserializations in the same context.

(cherry picked from commit 61f2f5a0f760157f9c9d32d7d3df2be47a73e74d)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
If a (nested) unserialize() call fails, we remove all the values
that were inserted into var_hash during that call. This prevents
their use in other unserializations in the same context.

(cherry picked from commit 61f2f5a0f760157f9c9d32d7d3df2be47a73e74d)
</pre>
</div>
</content>
</entry>
<entry>
<title>Bug #72663 - part 1</title>
<updated>2016-08-17T11:51:05+00:00</updated>
<author>
<name>Nikita Popov</name>
<email>nikic@php.net</email>
</author>
<published>2016-08-08T16:05:29+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=686f4e01e67da63642f709688aa578bf054c8a32'/>
<id>686f4e01e67da63642f709688aa578bf054c8a32</id>
<content type='text'>
Don't call __destruct() on an unserialized object that has a
__wakeup() method if either
a) unserialization of its properties fails or
b) the __wakeup() call fails (e.g. by throwing).

This basically treats __wakeup() as a form of constructor and
aligns us with the usual behavior that if the constructor call
fails the destructor should not be called.

The security aspect here is that people use __wakeup() to prevent
unserialization of objects with dangerous __destruct() methods,
but this is ineffective if __destruct() can still be called while
__wakeup() was skipped.

(cherry picked from commit 2135fdef9b588a34f8805b2bbf10704e36163d5a)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Don't call __destruct() on an unserialized object that has a
__wakeup() method if either
a) unserialization of its properties fails or
b) the __wakeup() call fails (e.g. by throwing).

This basically treats __wakeup() as a form of constructor and
aligns us with the usual behavior that if the constructor call
fails the destructor should not be called.

The security aspect here is that people use __wakeup() to prevent
unserialization of objects with dangerous __destruct() methods,
but this is ineffective if __destruct() can still be called while
__wakeup() was skipped.

(cherry picked from commit 2135fdef9b588a34f8805b2bbf10704e36163d5a)
</pre>
</div>
</content>
</entry>
<entry>
<title>Fix bug #72749: wddx_deserialize allows illegal memory access</title>
<updated>2016-08-17T11:46:52+00:00</updated>
<author>
<name>Stanislav Malyshev</name>
<email>stas@php.net</email>
</author>
<published>2016-08-04T07:17:42+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/php-git.git/commit/?id=d9fac3953d5b8a6b14c612b4ae351b8ae6dda481'/>
<id>d9fac3953d5b8a6b14c612b4ae351b8ae6dda481</id>
<content type='text'>
(cherry picked from commit 659a21dc20f0b64dafd8cb16573059d3b45cce6b)

Conflicts:
	ext/wddx/wddx.c

(cherry picked from commit e3829b88694460a2e5af10ad5eee9966fa55e589)
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit 659a21dc20f0b64dafd8cb16573059d3b45cce6b)

Conflicts:
	ext/wddx/wddx.c

(cherry picked from commit e3829b88694460a2e5af10ad5eee9966fa55e589)
</pre>
</div>
</content>
</entry>
</feed>
