Edit report at https://bugs.php.net/bug.php?id=67694&edit=1
ID: 67694
Comment by: atze at fem dot tu-ilmenau dot de
Reported by: atze at fem dot tu-ilmenau dot de
Summary: Regression in session_regenerate_id()
Status: Open
Type: Bug
Package: Session related
Operating System: GNU/Linux i386
PHP Version: 5.6.0RC2
Block user comment: N
Private report: N
New Comment:
This bug is still present in RC4 on multiple OS
Previous Comments:
------------------------------------------------------------------------
[2014-07-28 09:06:04] atze at fem dot tu-ilmenau dot de
Description:
------------
session_regenerate_id() does still regenerate the session id, it does still keep the session data,
but the session data is not stored (e.g. in session file). The session data is available in the
running PHP process after session_regenerate_id() is called, but it disappears after that. So the
next access is processed with an empty session.
Related settings in php.ini:
session.save_handler = files
session.save_path = "/var/lib/php5"
(ownership and ACLs are fine)
session.use_strict_mode = 0
session.use_cookies = 1
session.use_only_cookies = 1
session.name = PHPSESSID
session.auto_start = 0
session.cookie_lifetime = 0
session.cookie_path = /
session.cookie_domain = <FQDN of server>
session.cookie_httponly = 0
session.serialize_handler = php
session.gc_probability = 0
session.gc_divisor = 1000
session.gc_maxlifetime = 1440
session.referer_check =
session.cache_limiter = nocache
session.cache_expire = 180
session.use_trans_sid = 0
session.hash_function = 0
session.hash_bits_per_character = 5
The code in session.c looks weird, like it is supposed to delete the old session and then create a
new one, nothing that looks like "copy the data". Maybe $_SESSION is just by accident
still in memory after calling this function, but the documentation clearly states that the session
data is preserved by this function call.
The relation to bug #61470 is that the file is not created on the end of the PHP processing - it is
created never at all.
Test script:
---------------
<?php
session_start();
$session1 = session_id();
if (!isset($_SESSION['init'])) { $_SESSION['init'] = date('Y-m-d
H:i:s'); }
$init1 = @$_SESSION['init'].'<br/>';
session_regenerate_id(false);
echo $init1;
echo @$_SESSION['init'].'<br/>';
echo 'session id1 ' . $session1;
echo '<br />session id2 ' . session_id();
?>
Expected result:
----------------
Result on PHP 5.4.x:
<Timestamp of session start, does not change when pressing F5>
<session name (== session name 2 of last access>
<session name 2 (must be different)>
Actual result:
--------------
Result on PHP 5.6RC2:
<Current timestamp>
<session name (== session name 2 of last access>
<session name 2 (must be different)>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67694&edit=1