Bug #53295 [Asn->Csd]: if bailout is called on rshutdown, session segfault on next request

From: Date: Mon, 02 Feb 2015 09:20:55 +0000
Subject: Bug #53295 [Asn->Csd]: if bailout is called on rshutdown, session segfault on next request
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-190405@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=53295&edit=1 ID: 53295 Updated by: yohgaki@php.net Reported by: yoram dot b at zend dot com Summary: if bailout is called on rshutdown, session segfault on next request -Status: Assigned +Status: Closed Type: Bug Package: Session related Operating System: All PHP Version: 5.3.3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: I think this is already fixed in released versions. Previous Comments: ------------------------------------------------------------------------ [2010-11-11 15:50:22] yoram dot b at zend dot com Description: ------------ session sets it's handlers to NULL at rshutdown. in case of bailout in rshutdown (by other extension), this cleanup will not happen and next request will segfault. setting to NULL at RINIT works around the problem. Test script: --------------- <?php function open($save_path, $session_name) { global $sess_save_path; $sess_save_path = $save_path; return(true); } function close() { return(true); } function read($id) { global $sess_save_path; $sess_file = "$sess_save_path/sess_$id"; return (string) @file_get_contents($sess_file); } function write($id, $sess_data) { global $sess_save_path; $sess_file = "$sess_save_path/sess_$id"; if ($fp = @fopen($sess_file, "w")) { $return = fwrite($fp, $sess_data); fclose($fp); return $return; } else { return(false); } } function destroy($id) { global $sess_save_path; $sess_file = "$sess_save_path/sess_$id"; return(@unlink($sess_file)); } function gc($maxlifetime) { global $sess_save_path; foreach (glob("$sess_save_path/sess_*") as $filename) { if (filemtime($filename) + $maxlifetime < time()) { @unlink($filename); } } return true; } session_set_save_handler("open", "close", "read", "write", "destroy", "gc"); session_start(); // proceed to use sessions normally ?> ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=53295&edit=1

« previous php.bugs (#190405) next »