Bug #70520 [Opn->Ver]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler

From: Date: Fri, 18 Sep 2015 00:06:51 +0000
Subject: Bug #70520 [Opn->Ver]: session_regenerate_id() "Failed to create session ID" with custom SessionHandler
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196064@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70520&edit=1 ID: 70520 Updated by: requinix@php.net Reported by: hpdl at oscommerce dot com -Summary: session_regenerate_id ignores defined session path +Summary: session_regenerate_id() "Failed to create session ID" with custom SessionHandler -Status: Open +Status: Verified Type: Bug Package: Session related Operating System: Win10 PHP Version: 7.0.0RC3 -Assigned To: +Assigned To: yohgaki Block user comment: N Private report: N New Comment: Okay, I see it. So rather it's a general failure when overriding SessionHandler::write(), not about the save path. (Note that the first echo needs to be commented out as it creates output which will interfere.) Tentatively assigning to @yohgaki as he did some work with session_regenerate_id() before the RC3 release. Previous Comments: ------------------------------------------------------------------------ [2015-09-17 23:11:47] hpdl at oscommerce dot com Sorry, the problem seems to be with custom session handlers. Below is a snippet that reproduces the problem. The handler used below is taken from the PHP documentation: http://php.net/manual/en/class.sessionhandler.php <?php error_reporting(E_ALL | E_STRICT); ini_set('display_errors', true); class EncryptedSessionHandler extends SessionHandler { private $key; public function __construct($key) { $this->key = $key; } public function read($id) { $data = parent::read($id); return @mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); } public function write($id, $data) { $data = @mcrypt_encrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); return parent::write($id, $data); } } ini_set('session.save_handler', 'files'); $handler = new EncryptedSessionHandler('mykey'); session_set_save_handler($handler, true); session_start(); echo session_id() . '<br>'; session_regenerate_id(true); echo session_id(); ------------------------------------------------------------------------ [2015-09-17 19:56:25] requinix@php.net Seems to be working for me. <?php session_save_path("."); session_start(); $sid1 = session_id(); $exists1 = file_exists("./sess_{$sid1}"); session_regenerate_id(); $sid2 = session_id(); $exists2 = file_exists("./sess_{$sid2}"); var_dump($exists1); // true var_dump($sid1 != $sid2); // true var_dump($exists2); // true ?> What's your test script? Can you dump session_save_path() before the session_regenerate_id() to make sure it's set appropriately? ------------------------------------------------------------------------ [2015-09-17 14:53:22] hpdl at oscommerce dot com Description: ------------ session_regenerate_id() ignores a defined session path (via session_save_path()) and uses the windows\temp directory instead. Did not occur in earlier RC releases. Test script: --------------- session_regenerate_id(); Expected result: ---------------- true Actual result: -------------- session_regenerate_id(): Failed to create session ID: user (path: C:\WINDOWS\Temp\) in C:\Users\blahblah\blah.php ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70520&edit=1

« previous php.bugs (#196064) next »