Edit report at https://bugs.php.net/bug.php?id=70584&edit=1
ID: 70584
Updated by: yohgaki@php.net
Reported by: buschmann at nidsa dot net
Summary: Spontanous loss of all $_SESSION variables
Status: Assigned
Type: Bug
Package: Session related
Operating System: Windows
PHP Version: 7.0.0RC3
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
Related RFC
https://wiki.php.net/rfc/precise_session_management
Previous Comments:
------------------------------------------------------------------------
[2015-09-29 01:56:14] yohgaki@php.net
I think you are using session_regenerate_id(true).
Try session_regenerate_id(). i.e. Without "true".
This is a known issue.
https://bugs.php.net/bug.php?id=69127
If this is not related to this, please let me know.
------------------------------------------------------------------------
[2015-09-28 21:51:55] buschmann at nidsa dot net
Thanks for your attention.
I am not able to create a reproducible test case.
I only observed it on the production System, even not on the test System.
Today, I changed the application a little to avoid unchecked unset of session variables (now: if
isset () then unset ()). I continued to monitor the System, but the change did not help and I got
the same errors again a couple of times.
I checked the Session variables before any other Statement, but they were already gone just after
start_session().
I am not aware of any php function which accidently called would clear all Session variables. I
suppose they should be preserved until we close the session explicitely.
The Environment is Apache 2.4.16 64bit, php 7.0RC3 64bit thread safe on Win 2012R2 in a VM.
I could not reproduce it on the test machine, I suppose only the production System achieves enough
load (The load on the machine is quite low, mostly idling, about 10 to 20 users logged in,machine
uses 1.2 GB out of 4 GB)
I hope you are able to find a certain piece of code inside PHP where it is likely to clear all
Session variables.
Thanks
------------------------------------------------------------------------
[2015-09-28 14:54:29] ab@php.net
Thanks for the report. Were it possible to have a short reproducer, not involving pg or other
unrelated functionality, as a small PHP script?
Thanks.
------------------------------------------------------------------------
[2015-09-25 15:40:37] buschmann at nidsa dot net
Description:
------------
We recently ported our php application to a new server and decided to go productive with php 7.
With surveying the error_logs, we observed the complete loss of all $_SESSION variables occuring
about 1 to 10 times/day, independend of a specific user or session.
Since elementary configuration data are stored in $_SESSION variables, the script is unable to
connect to the database and falls back to load the login script again.
The crucial variables are set only once by an include file from index.php, the login script, and
never changed afterwords in the other scripts.
We didn't observe it in the test phase, and cannot test it with php 5.6.13.
It seems to occur randomly, our suspicion goes to garbage collector or similar.
Sorry, but we have no expertise in php internals.
Expected result:
----------------
preservation of all $_SESSION variables throughout the session.
Actual result:
--------------
This is a log entry of a successfull login of the user
all SAM_XXXX session variables ar set only once from an include file only included from index.php
(the login screen)
[25-Sep-2015 05:01:22 Europe/Berlin] HB index.php <hidden_path>\index.php: 103 session_id=
034njrgkpk89k70ac8icqt2ad5 SESSION= Array
(
[sqlDB] => <hidden_database>
[SAM_CONNECTION_STRING] => <hidden_access_string>
[SAM_PDF_TOOL] => ../fpdf/fpdf.php
[SAM_TFPDF_TOOL] => ../tfpdf/tfpdf.php
[SAM_TCPDF_TOOL] => ../tcpdf/tcpdf.php
[SAM_EXDATA_PATH] => <hidden_path>/ExData/
[SAM_EXDATA_WEB] => /cps/ExData/
[SAM_COLL_PATH] => <hidden_path>/Collection/
[SAM_COLL_WEB] => /cps/Collection/
[SAM_FOTO_PATH] => <hidden_path>/cpsImg/Imgs/
[SAM_FOTO_WEB] => /cps/cpsImg/Imgs/
[SAM_IMGS_PATH] => ../fixImg/
[SAM_IMGS_WEB] => /cps/fixImg/
[sqlHost] => localhost
[sqlUs] => postgres
[sqlPw] =>
[IUN] => 188
[UN] => hidden_user
[TEMP] => 22
[FI] =>
[ID] =>
[OFF] => 3
[FIL] =>
[N] =>
[ORD] =>
[OPC] =>
[LAST_DISABLED_SEASON] => 11
[MAX_RELEVANCE] => 2
[SAM_DB_TYPE] => PostgreSQL
[CU] => Array
(
[1] => USD
[2] => EUR
[3] => CNY
[4] => GBP
)
--
After being connected for several hours, we get the following error at 09:46:32
The reason is, that all session variables are gone, except those initialised at the beginning of
MenuPrincipal:
[25-Sep-2015 09:46:32 Europe/Berlin] HB MAIN_MENU <hidden_path>\MenuPrincipal.php: 84
session_id= 034njrgkpk89k70ac8icqt2ad5 SESSION= Array
(
[OPC] =>
[ID] => 0
[FIL] =>
[usAccess] => Array
(
)
)
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_connect(): in
<hidden_path>\MenuPrincipal.php on line 88
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): No PostgreSQL link opened yet in
<hidden_path>\MenuPrincipal.php on line 95
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): supplied resource is not a valid
PostgreSQL link resource in <hidden_path>\MenuPrincipal.php on line 95
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_fetch_assoc() expects parameter 1 to be
resource, boolean given in <hidden_path>\MenuPrincipal.php on line 97
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): No PostgreSQL link opened yet in
<hidden_path>\MenuPrincipal.php on line 370
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): supplied resource is not a valid
PostgreSQL link resource in <hidden_path>\MenuPrincipal.php on line 370
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): No PostgreSQL link opened yet in
<hidden_path>\MenuPrincipal.php on line 373
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_query(): supplied resource is not a valid
PostgreSQL link resource in <hidden_path>\MenuPrincipal.php on line 373
[25-Sep-2015 09:46:32 Europe/Berlin] PHP Warning: pg_fetch_assoc() expects parameter 1 to be
resource, boolean given in <hidden_path>\MenuPrincipal.php on line 380
After checking for no connection, the user is sent the login screen to log in again.
This loads all the never changed session varialbes SAM_XXXX again from the include file.
[25-Sep-2015 09:46:47 Europe/Berlin] HB index.php <hidden_path>\index.php: 103 session_id=
034njrgkpk89k70ac8icqt2ad5 SESSION= Array
(
[OPC] =>
[ID] =>
[FIL] =>
[usAccess] => Array
(
)
[sqlDB] => <hidden_database>
[SAM_CONNECTION_STRING] => <hidden_access_string>
[SAM_PDF_TOOL] => ../fpdf/fpdf.php
[SAM_TFPDF_TOOL] => ../tfpdf/tfpdf.php
[SAM_TCPDF_TOOL] => ../tcpdf/tcpdf.php
[SAM_EXDATA_PATH] => <hidden_path>ExData/
[SAM_EXDATA_WEB] => /cps/ExData/
[SAM_COLL_PATH] => <hidden_path>Collection/
[SAM_COLL_WEB] => /cps/Collection/
[SAM_FOTO_PATH] => <hidden_path>cpsImg/Imgs/
[SAM_FOTO_WEB] => /cps/cpsImg/Imgs/
[SAM_IMGS_PATH] => ../fixImg/
[SAM_IMGS_WEB] => /cps/fixImg/
[sqlHost] => localhost
[sqlUs] => postgres
[sqlPw] =>
[IUN] => 188
[UN] => <hidden_user>
[TEMP] => 22
[FI] =>
[OFF] => 3
[N] =>
[ORD] =>
[comodin] =>
[LAST_DISABLED_SEASON] => 11
[MAX_RELEVANCE] => 2
[SAM_DB_TYPE] => PostgreSQL
[CU] => Array
(
[1] => USD
[2] => EUR
[3] => CNY
[4] => GBP
)
)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=70584&edit=1