Bug #70529 [Ana->Csd]: Session read causes "String is not zero-terminated" error

From: Date: Sat, 19 Sep 2015 02:28:00 +0000
Subject: Bug #70529 [Ana->Csd]: Session read causes "String is not zero-terminated" error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196084@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70529&edit=1 ID: 70529 Updated by: yohgaki@php.net Reported by: yohgaki@php.net Summary: Session read causes "String is not zero-terminated" error -Status: Analyzed +Status: Closed Type: Bug Package: Session related Operating System: Linux PHP Version: 7.0Git-2015-09-18 (Git) Assigned To: yohgaki Block user comment: N Private report: N New Comment: Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=2f7cc862d763bcd3ca09f1164df8cdec929b75b9 Log: Fixed bug #70529 Session read causes &quot;String is not zero-terminated&quot; error Previous Comments: ------------------------------------------------------------------------ [2015-09-19 02:16:02] yohgaki@php.net This bugs cause was in ext/session/mod_files.c When zend_string is adopted, terminating null char was forgotten. This bug is only in PHP-7.0 and master. I'll commit the fix now. ------------------------------------------------------------------------ [2015-09-18 22:22:47] yohgaki@php.net Although I don't see errors if I don't use mcrypt, session module may do something wrong in these lines $data = parent::read($id); return parent::write($id, $data); I'll look into this. Could anyone look into mcrypt? ------------------------------------------------------------------------ [2015-09-18 22:13:04] yohgaki@php.net Description: ------------ While I was looking into this bug https://bugs.php.net/bug.php?id=70520 I found mcrypt_decrypt() sometimes raises "String is not zero-terminated" error. It seems mcrypt_decrypt() returns broken data sometimes also. It makes session decode fail on occasion. Warning: String is not zero-terminated (�J?w�fr, �:v�handler) (source: /home/yohgaki/git/oss/php.net/php-src/Zend/zend_execute.c:2061) in /home/yohgaki/workspace/ext/git/oss/php.net/php-src/tt2.php on line 20 Warning: session_start(): Failed to decode session object. Session has been destroyed in /home/yohgaki/workspace/ext/git/oss/php.net/php-src/tt2.php on line 38 Tested by CLI server. If I don't use mcrypt_decrypt/encrypt(), the test code will not raise errors. Test script: --------------- <?php ob_start(); error_reporting(E_ALL | E_STRICT); ini_set('session.save_path', '/tmp'); ini_set('display_errors', true); class EncryptedSessionHandler extends SessionHandler { private $key; public function __construct($key) { $this->key = $key; } public function read($id) { $data = parent::read($id); return mcrypt_decrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); //return $data; } public function write($id, $data) { $data = mcrypt_encrypt(MCRYPT_3DES, $this->key, $data, MCRYPT_MODE_ECB); return parent::write($id, $data); } } ini_set('session.save_handler', 'files'); $key = substr(sha1(random_bytes(24)), 0, 24); $handler = new EncryptedSessionHandler($key); session_set_save_handler($handler, true); echo '<pre>'; session_start(); $_SESSION['key'] = 1234; var_dump($_SESSION); echo session_id() . PHP_EOL; session_regenerate_id(true); echo session_id() . PHP_EOL; ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=70529&edit=1

« previous php.bugs (#196084) next »