Bug #71599 [Asn->Csd]: trans sid handling rework broke interaction with cookies

From: Date: Wed, 06 Apr 2016 00:17:48 +0000
Subject: Bug #71599 [Asn->Csd]: trans sid handling rework broke interaction with cookies
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-200417@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71599&edit=1 ID: 71599 Updated by: yohgaki@php.net Reported by: phpbug at wisl dot de Summary: trans sid handling rework broke interaction with cookies -Status: Assigned +Status: Closed Type: Bug Package: Session related Operating System: All PHP Version: 7.0.3 Assigned To: yohgaki Block user comment: N Private report: N New Comment: The issue mentioned on this bug report is crash bug that is caused by missing zend_is_auto_global(). This is fixed. Please open new bug report for this and keep this one closed. I think I understand what is your problem, but please describe the issue in detail. Thank you. Previous Comments: ------------------------------------------------------------------------ [2016-04-05 14:59:01] phpbug at wisl dot de PHP 7.0.5 just appeared in the Gentoo package tree and I retested this version. The main bug, the broken interaction between trans sid and cookies, is *NOT* fixed, it still has the same regressions. 1.: https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06L538 By removing the condition " && PS(send_cookie)" before apply_trans_sid was set 1, now a trans sid will always be transmitted, even if a correct session cookie is available. That prevents using the trans sid as a simple fallback, because as of PHP7 if it is enabled at all, it will always send an PHPSESSID rendering any cookie support superfluous despite using cookies for session ids is the better way. 2.: https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06L1494 By no longer resetting the rewriter each call to php_session_reset_id() will add another PHPSESSID parameter instead of replacing the old one. As session_regenerate_id() is calling into this function when switching to a new session id this means, that each call to session_regenerate_id() will add another PHPSESSID parameter. For me this means, that if a visitor request the first page of my site an new session will be generated. This will add a first PHPSESSID parameter to all URLs. This new empty session will be regarded as unsafe, by my code, because its ID might have been supplied by an attacker. So my code calls session_regenerate_id() to generate a new, guaranteed to be safe, session id. This will now add a second PHPSESSID parameter, while leaving the original (possible tampered with ID) in all URLs. PHP version before PHP7 would correctly only insert the correct new session id. Both of these changes are serious regression for my code, as it means I can no longer use the trans sid in PHP7 and now need to force all my visitors to enable cookies. As the commit promised "Behavior is unchanged", I see this as bugs and not changes that were needed to make PHP7 work, so please restore the trans sid behavior as it was in PHP5. ------------------------------------------------------------------------ [2016-03-14 14:59:30] ab@php.net Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=ca61f5954bf9e64072bfa31b4a7431e211a109e7 Log: Fixed Bug #71754 Regression in PHP7.0: trivial script segfaults php-cgi Fixed Bug #71683 Null pointer dereference in zend_hash_str_find_bucket Fixed Bug #71599 trans sid handling rework broke interaction with cookies ------------------------------------------------------------------------ [2016-03-11 23:43:33] yohgaki@php.net Automatic comment on behalf of yohgaki Revision: http://git.php.net/?p=php-src.git;a=commit;h=ca61f5954bf9e64072bfa31b4a7431e211a109e7 Log: Fixed Bug #71754 Regression in PHP7.0: trivial script segfaults php-cgi Fixed Bug #71683 Null pointer dereference in zend_hash_str_find_bucket Fixed Bug #71599 trans sid handling rework broke interaction with cookies ------------------------------------------------------------------------ [2016-03-11 09:07:42] cmb@php.net > The logic wrt. the transparent session id when a cookie is > available and that multiple calls to session_regenerate_id() add > multiple PHPSESSID parameters is broken in PHP7 compared to > PHP5.X […] The latter might be caused by <https://github.com/php/php-src/commit/f248df900300c5b2201d4cf634d58d413399e2eb#diff-52eb9eb7f9d5d9125fbb1337a6541c06R1491>. ------------------------------------------------------------------------ [2016-03-11 08:08:02] phpbug at wisl dot de This is not a duplicate of #71683. The crash that I also noted might be a duplicate of #71683, but that got fixed as bug #71754. The logic wrt. the transparent session id when a cookie is available and that multiple calls to session_regenerate_id() add multiple PHPSESSID parameters is broken in PHP7 compared to PHP5.X and this can't be fixed with the crash fix from #71683 or #71754. Please reopen this bug. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=71599 -- Edit this bug report at https://bugs.php.net/bug.php?id=71599&edit=1

« previous php.bugs (#200417) next »