Bug #67694 [Ver->Csd]: Regression in session_regenerate_id()

From: Date: Sat, 23 Aug 2014 01:22:28 +0000
Subject: Bug #67694 [Ver->Csd]: Regression in session_regenerate_id()
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-187249@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=67694&edit=1

 ID:                 67694
 Updated by:         datibbaw@php.net
 Reported by:        atze at fem dot tu-ilmenau dot de
 Summary:            Regression in session_regenerate_id()
-Status:             Verified
+Status:             Closed
 Type:               Bug
 Package:            Session related
 Operating System:   GNU/Linux i386
 PHP Version:        5.6.0RC2
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Automatic comment on behalf of datibbaw
Revision: http://git.php.net/?p=php-src.git;a=commit;h=ce9bdae33f101ff85c08d32ce5c2c6502a451d62
Log: Fixed #67694: Regression in session_regenerate_id()


Previous Comments:
------------------------------------------------------------------------
[2014-08-23 00:47:47] datibbaw@php.net

I've tried to write a test case against this, but unfortunately it passes on 5.6; perhaps
somebody can improve it?

https://gist.github.com/datibbaw/6fd22f567f1ef2436ddb

------------------------------------------------------------------------
[2014-08-22 23:56:40] tyrael@php.net

sorry for not spotting this sooner (I remembered that I checked this and couldn't repro, but
maybe I just remember wrong).
I was able to reproduce the issue with RC4, from a quick search, it seems that this was introduced
with
http://git.php.net/?p=php-src.git;a=commit;h=554021d21e1b2517313a377676260c188152c2eb
http://bugs.php.net/17860
Assigning this Yasuo, but others are also welcome to look into this.

------------------------------------------------------------------------
[2014-08-22 09:09:46] atze at fem dot tu-ilmenau dot de

This bug is still present in RC4 on multiple OS

------------------------------------------------------------------------
[2014-07-28 09:06:04] atze at fem dot tu-ilmenau dot de

Description:
------------
session_regenerate_id() does still regenerate the session id, it does still keep the session data,
but the session data is not stored (e.g. in session file). The session data is available in the
running PHP process after session_regenerate_id() is called, but it disappears after that. So the
next access is processed with an empty session.

Related settings in php.ini:

session.save_handler = files
session.save_path = "/var/lib/php5" 
(ownership and ACLs are fine)
session.use_strict_mode = 0
session.use_cookies = 1
session.use_only_cookies = 1
session.name = PHPSESSID
session.auto_start = 0
session.cookie_lifetime = 0
session.cookie_path = /
session.cookie_domain = <FQDN of server>
session.cookie_httponly = 0
session.serialize_handler = php
session.gc_probability = 0
session.gc_divisor = 1000
session.gc_maxlifetime = 1440
session.referer_check =
session.cache_limiter = nocache
session.cache_expire = 180
session.use_trans_sid = 0
session.hash_function = 0
session.hash_bits_per_character = 5

The code in session.c looks weird, like it is supposed to delete the old session and then create a
new one, nothing that looks like "copy the data". Maybe $_SESSION is just by accident
still in memory after calling this function, but the documentation clearly states that the session
data is preserved by this function call.

The relation to bug #61470 is that the file is not created on the end of the PHP processing - it is
created never at all.

Test script:
---------------
<?php

session_start();
$session1 = session_id();
if (!isset($_SESSION['init'])) { $_SESSION['init'] = date('Y-m-d
H:i:s'); }

$init1 = @$_SESSION['init'].'<br/>';
session_regenerate_id(false);

echo $init1;
echo @$_SESSION['init'].'<br/>';
echo 'session id1 ' . $session1;
echo '<br />session id2 ' . session_id();
?>


Expected result:
----------------
Result on PHP 5.4.x:

<Timestamp of session start, does not change when pressing F5>
<session name (== session name 2 of last access>
<session name 2 (must be different)>

Actual result:
--------------
Result on PHP 5.6RC2:

<Current timestamp>
<session name (== session name 2 of last access>
<session name 2 (must be different)>


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=67694&edit=1


Thread (13 messages)

« previous php.bugs (#187249) next »