Bug #70584 [Com]: Spontanous loss of all $_SESSION variables

From: Date: Tue, 29 Sep 2015 07:06:14 +0000
Subject: Bug #70584 [Com]: Spontanous loss of all $_SESSION variables
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-196297@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=70584&edit=1

 ID:                 70584
 Comment by:         buschmann at nidsa dot net
 Reported by:        buschmann at nidsa dot net
 Summary:            Spontanous loss of all $_SESSION variables
 Status:             Assigned
 Type:               Bug
 Package:            Session related
 Operating System:   Windows
 PHP Version:        7.0.0RC3
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

Sorry, in my previous comment i meant poor knowledge or understanding ("experience" stems
from wrong formal german translation ...)

Thanks


Previous Comments:
------------------------------------------------------------------------
[2015-09-29 06:33:22] buschmann at nidsa dot net

I checked the whole code base of our application and only found 3 references relying to sessions:
session_start() on every script
session_cache_limiter('must-revalidate'); on the very beginning of all PDF generating
scripts
session_id() in my debug code.

I have no call to session_regenerate_id().

I left all session related configuration parameters at default.
Here is an extract from info.php on the production machine in txt format
session

Session Support	enabled
Registered save handlers	files user
Registered serializer handlers	php_serialize php php_binary wddx
Directive	Local Value	Master Value
session.auto_start	Off	Off
session.cache_expire	180	180
session.cache_limiter	nocache	nocache
session.cookie_domain	no value	no value
session.cookie_httponly	Off	Off
session.cookie_lifetime	0	0
session.cookie_path	/	/
session.cookie_secure	Off	Off
session.entropy_file	no value	no value
session.entropy_length	0	0
session.gc_divisor	1000	1000
session.gc_maxlifetime	1440	1440
session.gc_probability	1	1
session.hash_bits_per_character	5	5
session.hash_function	0	0
session.lazy_write	On	On
session.name	PHPSESSID	PHPSESSID
session.referer_check	no value	no value
session.save_handler	files	files
session.save_path	no value	no value
session.serialize_handler	php	php
session.upload_progress.cleanup	On	On
session.upload_progress.enabled	On	On
session.upload_progress.freq	1%	1%
session.upload_progress.min_freq	1	1
session.upload_progress.name	PHP_SESSION_UPLOAD_PROGRESS	PHP_SESSION_UPLOAD_PROGRESS
session.upload_progress.prefix	upload_progress_	upload_progress_
session.use_cookies	On	On
session.use_only_cookies	On	On
session.use_strict_mode	Off	Off
session.use_trans_sid	0	0

I dont have any assignment of $_SESSION to another variable like in bug 70013.

The application has been ported from php4. I have not added any new functionality concerning session
management. For my poor experience with PHP session mgmt it seems to be a straight forward, simple
implementation. 

Thank you for your efforts, hope to help other people as well

------------------------------------------------------------------------
[2015-09-29 02:11:11] yohgaki@php.net

There is a bug may be related to this.
https://bugs.php.net/bug.php?id=70013
Please use latest PHP 7.
If bug 70013 is the cause, please close this one. Thank you.

------------------------------------------------------------------------
[2015-09-29 02:06:54] yohgaki@php.net

Related RFC
https://wiki.php.net/rfc/precise_session_management

------------------------------------------------------------------------
[2015-09-29 01:56:14] yohgaki@php.net

I think you are using session_regenerate_id(true).
Try session_regenerate_id(). i.e. Without "true".
This is a known issue.
https://bugs.php.net/bug.php?id=69127
If this is not related to this, please let me know.

------------------------------------------------------------------------
[2015-09-28 21:51:55] buschmann at nidsa dot net

Thanks for your attention.

I am not able to create  a reproducible test case.
I only observed it on the production System, even not on the test System.
Today, I changed the application a little to avoid unchecked unset of session variables (now: if
isset () then unset ()). I continued to monitor the System, but the change did not help and I got 
the same errors again a couple of times.
I checked the Session variables before any other Statement, but they were already gone just after
start_session().
I am not aware of any php function which accidently called would clear all Session variables. I
suppose they should be preserved until we close the session explicitely.

The Environment is Apache 2.4.16 64bit, php 7.0RC3 64bit thread safe on Win 2012R2 in a VM.

I could not reproduce it on the test machine, I suppose only the production System achieves enough
load (The load on the machine is quite low, mostly idling, about 10 to 20 users logged in,machine
uses 1.2 GB out of 4 GB)

I hope you are able to find a certain piece of code inside PHP where it is likely to clear all
Session variables.

Thanks

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=70584


--
Edit this bug report at https://bugs.php.net/bug.php?id=70584&edit=1


Thread (17 messages)

« previous php.bugs (#196297) next »