Edit report at https://bugs.php.net/bug.php?id=67694&edit=1
ID: 67694
Updated by: datibbaw@php.net
Reported by: atze at fem dot tu-ilmenau dot de
Summary: Regression in session_regenerate_id()
Status: Verified
Type: Bug
Package: Session related
Operating System: GNU/Linux i386
PHP Version: 5.6.0RC2
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
I've tried to write a test case against this, but unfortunately it passes on 5.6; perhaps
somebody can improve it?
https://gist.github.com/datibbaw/6fd22f567f1ef2436ddb
Previous Comments:
------------------------------------------------------------------------
[2014-08-22 23:56:40] tyrael@php.net
sorry for not spotting this sooner (I remembered that I checked this and couldn't repro, but
maybe I just remember wrong).
I was able to reproduce the issue with RC4, from a quick search, it seems that this was introduced
with
http://git.php.net/?p=php-src.git;a=commit;h=554021d21e1b2517313a377676260c188152c2ebhttp://bugs.php.net/17860
Assigning this Yasuo, but others are also welcome to look into this.
------------------------------------------------------------------------
[2014-08-22 09:09:46] atze at fem dot tu-ilmenau dot de
This bug is still present in RC4 on multiple OS
------------------------------------------------------------------------
[2014-07-28 09:06:04] atze at fem dot tu-ilmenau dot de
Description:
------------
session_regenerate_id() does still regenerate the session id, it does still keep the session data,
but the session data is not stored (e.g. in session file). The session data is available in the
running PHP process after session_regenerate_id() is called, but it disappears after that. So the
next access is processed with an empty session.
Related settings in php.ini:
session.save_handler = files
session.save_path = "/var/lib/php5"
(ownership and ACLs are fine)
session.use_strict_mode = 0
session.use_cookies = 1
session.use_only_cookies = 1
session.name = PHPSESSID
session.auto_start = 0
session.cookie_lifetime = 0
session.cookie_path = /
session.cookie_domain = <FQDN of server>
session.cookie_httponly = 0
session.serialize_handler = php
session.gc_probability = 0
session.gc_divisor = 1000
session.gc_maxlifetime = 1440
session.referer_check =
session.cache_limiter = nocache
session.cache_expire = 180
session.use_trans_sid = 0
session.hash_function = 0
session.hash_bits_per_character = 5
The code in session.c looks weird, like it is supposed to delete the old session and then create a
new one, nothing that looks like "copy the data". Maybe $_SESSION is just by accident
still in memory after calling this function, but the documentation clearly states that the session
data is preserved by this function call.
The relation to bug #61470 is that the file is not created on the end of the PHP processing - it is
created never at all.
Test script:
---------------
<?php
session_start();
$session1 = session_id();
if (!isset($_SESSION['init'])) { $_SESSION['init'] = date('Y-m-d
H:i:s'); }
$init1 = @$_SESSION['init'].'<br/>';
session_regenerate_id(false);
echo $init1;
echo @$_SESSION['init'].'<br/>';
echo 'session id1 ' . $session1;
echo '<br />session id2 ' . session_id();
?>
Expected result:
----------------
Result on PHP 5.4.x:
<Timestamp of session start, does not change when pressing F5>
<session name (== session name 2 of last access>
<session name 2 (must be different)>
Actual result:
--------------
Result on PHP 5.6RC2:
<Current timestamp>
<session name (== session name 2 of last access>
<session name 2 (must be different)>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67694&edit=1