Bug #69952 [Asn->Csd]: Data integrity issues accessing superglobals by reference

From: Date: Sun, 28 Jun 2015 14:31:21 +0000
Subject: Bug #69952 [Asn->Csd]: Data integrity issues accessing superglobals by reference
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-193962@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=69952&edit=1 ID: 69952 Updated by: bwoebi@php.net Reported by: michael dot babker at gmail dot com Summary: Data integrity issues accessing superglobals by reference -Status: Assigned +Status: Closed Type: Bug Package: Session related Operating System: N/A PHP Version: 7.0.0alpha2 Assigned To: bwoebi Block user comment: N Private report: N New Comment: Automatic comment on behalf of bobwei9@hotmail.com Revision: http://git.php.net/?p=php-src.git;a=commit;h=b477aa1fad6cac41ee6959921b229cb3dba79e6e Log: Fix bug #69952 (Dereferencing issue in session_start()) Previous Comments: ------------------------------------------------------------------------ [2015-06-28 14:09:56] michael dot babker at gmail dot com Ya, that was just me trying to reproduce what our internal code actually does as close as possible (the isset is part of our input API and the is_null check in the session startup). Either way, glad to see I haven't completely lost it :-) ------------------------------------------------------------------------ [2015-06-28 12:22:43] cmb@php.net I can confirm the issue. The following test script is sufficient to reproduce it: <?php $cookieData = &$_COOKIE; session_start(); var_dump($_SESSION); $_SESSION['foo'] = 'bar'; Apparently, the by-ref assignment causes a new session to be created on each request. @michael: The condition of the outermost if statement in your test script is always FALSE, because a variable can't be isset() and is_null(). ------------------------------------------------------------------------ [2015-06-27 17:06:58] michael dot babker at gmail dot com Description: ------------ Within Joomla, our input retrieval and setting API accesses the superglobals by reference. It appears because of some of the engine refactoring, accessing the same data is not working the same way. In the case of Joomla, this is most evident in our session boot sequence (extracted into the test script below) where data validated in the $_COOKIE superglobal is no longer returned correctly. Test script: --------------- https://github.com/mbabker/session-test/blob/purephp/index.php Expected result: ---------------- On each execution of the script, the session counter should increment by one. Actual result: -------------- On each execution of the script, the session counter's value is one. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=69952&edit=1

« previous php.bugs (#193962) next »