Bug #70584 [Com]: Spontanous loss of all $_SESSION variables

From: Date: Tue, 29 Sep 2015 06:33:26 +0000
Subject: Bug #70584 [Com]: Spontanous loss of all $_SESSION variables
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196296@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70584&edit=1 ID: 70584 Comment by: buschmann at nidsa dot net Reported by: buschmann at nidsa dot net Summary: Spontanous loss of all $_SESSION variables Status: Assigned Type: Bug Package: Session related Operating System: Windows PHP Version: 7.0.0RC3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: I checked the whole code base of our application and only found 3 references relying to sessions: session_start() on every script session_cache_limiter('must-revalidate'); on the very beginning of all PDF generating scripts session_id() in my debug code. I have no call to session_regenerate_id(). I left all session related configuration parameters at default. Here is an extract from info.php on the production machine in txt format session Session Support enabled Registered save handlers files user Registered serializer handlers php_serialize php php_binary wddx Directive Local Value Master Value session.auto_start Off Off session.cache_expire 180 180 session.cache_limiter nocache nocache session.cookie_domain no value no value session.cookie_httponly Off Off session.cookie_lifetime 0 0 session.cookie_path / / session.cookie_secure Off Off session.entropy_file no value no value session.entropy_length 0 0 session.gc_divisor 1000 1000 session.gc_maxlifetime 1440 1440 session.gc_probability 1 1 session.hash_bits_per_character 5 5 session.hash_function 0 0 session.lazy_write On On session.name PHPSESSID PHPSESSID session.referer_check no value no value session.save_handler files files session.save_path no value no value session.serialize_handler php php session.upload_progress.cleanup On On session.upload_progress.enabled On On session.upload_progress.freq 1% 1% session.upload_progress.min_freq 1 1 session.upload_progress.name PHP_SESSION_UPLOAD_PROGRESS PHP_SESSION_UPLOAD_PROGRESS session.upload_progress.prefix upload_progress_ upload_progress_ session.use_cookies On On session.use_only_cookies On On session.use_strict_mode Off Off session.use_trans_sid 0 0 I dont have any assignment of $_SESSION to another variable like in bug 70013. The application has been ported from php4. I have not added any new functionality concerning session management. For my poor experience with PHP session mgmt it seems to be a straight forward, simple implementation. Thank you for your efforts, hope to help other people as well Previous Comments: ------------------------------------------------------------------------ [2015-09-29 02:11:11] yohgaki@php.net There is a bug may be related to this. https://bugs.php.net/bug.php?id=70013 Please use latest PHP 7. If bug 70013 is the cause, please close this one. Thank you. ------------------------------------------------------------------------ [2015-09-29 02:06:54] yohgaki@php.net Related RFC https://wiki.php.net/rfc/precise_session_management ------------------------------------------------------------------------ [2015-09-29 01:56:14] yohgaki@php.net I think you are using session_regenerate_id(true). Try session_regenerate_id(). i.e. Without "true". This is a known issue. https://bugs.php.net/bug.php?id=69127 If this is not related to this, please let me know. ------------------------------------------------------------------------ [2015-09-28 21:51:55] buschmann at nidsa dot net Thanks for your attention. I am not able to create a reproducible test case. I only observed it on the production System, even not on the test System. Today, I changed the application a little to avoid unchecked unset of session variables (now: if isset () then unset ()). I continued to monitor the System, but the change did not help and I got the same errors again a couple of times. I checked the Session variables before any other Statement, but they were already gone just after start_session(). I am not aware of any php function which accidently called would clear all Session variables. I suppose they should be preserved until we close the session explicitely. The Environment is Apache 2.4.16 64bit, php 7.0RC3 64bit thread safe on Win 2012R2 in a VM. I could not reproduce it on the test machine, I suppose only the production System achieves enough load (The load on the machine is quite low, mostly idling, about 10 to 20 users logged in,machine uses 1.2 GB out of 4 GB) I hope you are able to find a certain piece of code inside PHP where it is likely to clear all Session variables. Thanks ------------------------------------------------------------------------ [2015-09-28 14:54:29] ab@php.net Thanks for the report. Were it possible to have a short reproducer, not involving pg or other unrelated functionality, as a small PHP script? Thanks. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=70584 -- Edit this bug report at https://bugs.php.net/bug.php?id=70584&edit=1

« previous php.bugs (#196296) next »