# Surprising deserialization

**URL:** <https://discourse.julialang.org/t/surprising-deserialization/26119>\
**Category:** General Usage\
**Created:** [July 7, 2019, 6:21pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119 "2019-07-07T18:21:13Z")\
**Posts on this page:** 7\
**Page:** 1

<div class="post-metadata">

**Author:** ![yakir12](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/yakir12/32/297_2.png) [@yakir12](https://discourse.julialang.org/u/yakir12)\
**Post date:** [July 7, 2019, 6:21pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/1 "2019-07-07T18:21:13Z")

</div>

This is more of a heads up for people using `de`- and `serialize` from `Serialization` than anything else. It’s very clear that serialization isn’t meant to be used this way ([see here](https://discourse.julialang.org/t/deserializing-untrusted-data/12621/2)), but thought it would be worth posting:

```julia
using Dates, Serialization
struct A
    v::Nanosecond
end
a1 = A(Nanosecond(1))
serialize("tmp.dat", a1)
a2 = deserialize("tmp.dat") # A(1 nanosecond)

# new session

using Dates, Serialization
struct A
    v::Millisecond
end
a3 = deserialize("tmp.dat") # A(1 millisecond)

```

---

<div class="post-metadata">

**Author:** ![baggepinnen](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/baggepinnen/32/693_2.png) [@baggepinnen](https://discourse.julialang.org/u/baggepinnen)\
**Post date:** [July 7, 2019, 6:36pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/2 "2019-07-07T18:36:36Z")

</div>

Similarly, if a package is updated and they change the layout of a struct you have saved, you’re in for some wacky behavior.

---

<div class="post-metadata">

**Author:** ![yakir12](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/yakir12/32/297_2.png) [@yakir12](https://discourse.julialang.org/u/yakir12)\
**Post date:** [July 7, 2019, 6:38pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/3 "2019-07-07T18:38:31Z")

</div>

> [@baggepinnen](#):
>
> a package is updated and they change the layout of a struct you have saved, you’re in for some wacky behavior

I am about to update my own package in that exact manner… Thankfully I have two users (one is me), so handling this should be straightforward… But yea, that’s how I discovered this. Thank god I tested stuff first.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [July 8, 2019, 5:22am UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/4 "2019-07-08T05:22:45Z")

</div>

> [@yakir12](#):
>
> But yea, that’s how I discovered this.

It is well-documented: `?Serialization.serialize` tells you that

> In general, this process will not work if the reading and writing are done by different versions of Julia, or an instance of Julia with a different system image.

Serialization is mostly for communication within the same program (different threads). For everything else, use HDF5, JLD2, BSON, etc.

---

<div class="post-metadata">

**Author:** ![jpsamaroo](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/jpsamaroo/32/46804_2.png) [@jpsamaroo](https://discourse.julialang.org/u/jpsamaroo)\
**Post date:** [July 8, 2019, 12:39pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/5 "2019-07-08T12:39:44Z")

</div>

That docstring doesn’t point out that serializing across different Julia sessions with the same sysimage might have unexpected results. And if you don’t know how `serialize` stores data, then it’s understandable that you might get behavior you didn’t expect, as in this example.

---

<div class="post-metadata">

**Author:** ![Tamas\_Papp](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tamas_papp/32/25949_2.png) [@Tamas\_Papp](https://discourse.julialang.org/u/Tamas_Papp)\
**Post date:** [July 8, 2019, 1:25pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/6 "2019-07-08T13:25:03Z")

</div>

Good point. Perhaps a different wording, eg “runtime image”, would be helpful.

I tend to think of the “image” as the current state of the runtime process, but that’s probably a habit brought over from Common Lisp.

---

<div class="post-metadata">

**Author:** ![ExpandingMan](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/expandingman/32/866_2.png) [@ExpandingMan](https://discourse.julialang.org/u/ExpandingMan)\
**Post date:** [July 8, 2019, 1:43pm UTC](https://discourse.julialang.org/t/surprising-deserialization/26119/7 "2019-07-08T13:43:36Z")

</div>

I think one way of looking at this is that the buffers saved and read by `serialize` and `deserialize` are “trusted”, i.e. it gets some efficiency by not validating every aspect of the data it stored. This makes sense because `Serialization`, if I understand it correctly, was primarily designed for IPC between Julia processes in a cluster. If it checked these sorts of things it would probably be much too slow for that.
