Edit report at https://bugs.php.net/bug.php?id=70871&edit=1
ID: 70871
Updated by: yohgaki@php.net
Reported by: jacky at xsteach dot com
Summary: session_regenerate_id(): Failed to create session
ID: user (path: )
-Status: Assigned
+Status: Closed
Type: Bug
Package: Session related
Operating System: mac os x
PHP Version: 7.0.0RC6
Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2015-11-13 21:50:48] yohgaki@php.net
I've committed error message patch. Latest code will produce distinguishable error messages.
Anyway, original bug report is not a bug. I close this one. If you find any new issue, please open
new or use appropriate bug report.
------------------------------------------------------------------------
[2015-11-13 11:42:41] ab@php.net
Please check this error log records:
[Fri Nov 13 01:59:48.334695 2015] [:error] [pid 22639] [client x.x.x.x:10706] PHP Warning:
session_start(): open(/var/lib/php/sessions/sess_ngds5c5qpok0jm3lcjvmtslqh7, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 16
[Fri Nov 13 01:59:48.334860 2015] [:error] [pid 22639] [client x.x.x.x:10706] PHP Warning:
session_regenerate_id(): open(/var/lib/php/sessions/sess_mfmb9rq8qoofsbcigs8ckdhsa4, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 23
[Fri Nov 13 01:59:48.334883 2015] [:error] [pid 22639] [client x.x.x.x:10706] PHP Catchable fatal
error: session_regenerate_id(): Failed to create session ID: files (path: /var/lib/php/sessions) in
/some/path/to/file.php on line 23
[Fri Nov 13 01:59:49.738997 2015] [:error] [pid 22638] [client x.x.x.x:10707] PHP Warning:
session_start(): open(/var/lib/php/sessions/sess_ngds5c5qpok0jm3lcjvmtslqh7, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 16
[Fri Nov 13 01:59:49.739178 2015] [:error] [pid 22638] [client x.x.x.x:10707] PHP Warning:
session_regenerate_id(): open(/var/lib/php/sessions/sess_u9aqmuc73nub1g09vkisojjk11, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 23
[Fri Nov 13 01:59:49.739198 2015] [:error] [pid 22638] [client x.x.x.x:10707] PHP Catchable fatal
error: session_regenerate_id(): Failed to create session ID: files (path: /var/lib/php/sessions) in
/some/path/to/file.php on line 23
[Fri Nov 13 01:59:50.534468 2015] [:error] [pid 22637] [client x.x.x.x:10710] PHP Warning:
session_start(): open(/var/lib/php/sessions/sess_ngds5c5qpok0jm3lcjvmtslqh7, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 16
[Fri Nov 13 01:59:50.534644 2015] [:error] [pid 22637] [client x.x.x.x:10710] PHP Warning:
session_regenerate_id(): open(/var/lib/php/sessions/sess_aparjtipjng2nnn8sdm8q9drn4, O_RDWR) failed:
Permission denied (13) in /some/path/to/file.php on line 23
[Fri Nov 13 01:59:50.534663 2015] [:error] [pid 22637] [client x.x.x.x:10710] PHP Catchable fatal
error: session_regenerate_id(): Failed to create session ID: files (path: /var/lib/php/sessions) in
/some/path/to/file.php on line 23
So in my case, I can reproduce it making /var/lib/php/sessions/ not writable to PHP process. This
can explain the warning in session_regenerate_id() immediately after session_start() - namely
session_start() is failed.
Now, the original case of session_destroy()+session_regenerate_id() looks like logic. Same as
before - no session, no regenerate id. But with a custom session handler, it can be much trickier to
figure out, depends on its error reporting. All in all, it still doesn't look. Could we please
take a look at the error logs for such cases (possibly with max enabled error reporting)?
In general yes, some finer grained error messages can help on the user side.
Thanks.
------------------------------------------------------------------------
[2015-11-13 10:18:45] narf at devilix dot net
@yasuo
Yep, that's the session handler in question.
I guess I'll have to wait for your error messages patch ...
------------------------------------------------------------------------
[2015-11-13 05:23:28] bellosthomas at gmail dot com
I was also getting a fatal error (check comment above), with a custom session handler. After
yohgaki's comment about the return value of the read() method, which needs to return a string,
I checked my session handler and I saw I was returning boolean false in some cases. Casting the
return value to string, solved it.
------------------------------------------------------------------------
[2015-11-13 01:20:26] yohgaki@php.net
Oops, you are getting other kind of error.
session_regenerate_id(): Failed to create session ID: user (path: <value of
session.save_path>)
This error is raised by multiple reasons. The error messages are better to modify so that users can
distinguish the cause. Anyway, it may be raised if
- new session ID creation is failed. (Very unlikely)
- opening save handler is failed.
- session ID collision is detected and failed. (Very unlikely)
- session read with new session ID is failed.
I'll modify error messages to distinguish the cause of your problem.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=70871
--
Edit this bug report at https://bugs.php.net/bug.php?id=70871&edit=1