Bug #71972 [Opn->Ana]: Cyclic references causing session_start(): Failed to decode session object.
| From: | laruence@php.net | Date: | Fri, 15 Apr 2016 13:45:46 +0000 |
| Subject: | Bug #71972 [Opn->Ana]: Cyclic references causing session_start(): Failed to decode session object. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-200567@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=71972&edit=1
ID: 71972
Updated by: laruence@php.net
Reported by: b dot curtis at dfusion dot com
Summary: Cyclic references causing session_start(): Failed to
decode session object.
-Status: Open
+Status: Analyzed
Type: Bug
Package: Session related
Operating System: Ubuntu 14.04.4 LTS
PHP Version: 7.0.5
Block user comment: N
Private report: N
New Comment:
this is becuase hash table resize.... I don't have a fix now :<
Previous Comments:
------------------------------------------------------------------------
[2016-04-06 07:42:05] b dot curtis at dfusion dot com
Description:
------------
Particular combination of session data causes "PHP Warning: session_start(): Failed to decode
session object."
Found in our web application but recreated in the test CLI script below.
Steps to reproduce:
1) run this file once. Session data is saved.
2) Run again. Session cannot be decoded.
3) Remove session file /tmp/sess_sessiontest. If it wasn't already removed by the
session_decode failing.
4) Comment out the $_SESSION['boogie'] line
5) Run again, and again and again and again.......No bug!
Test script:
---------------
<?php
$session_id = 'sessiontest';
session_id($session_id);
session_start();
$_SESSION['boogie'] = 1;//NOTE: Comment out this line for step 4
$_SESSION['obj1'] = new stdClass();
for ( $x=2; $x < 20; $x++) {//NOTE: In my tests the number needed varied but was always between
10 and 20
cyclic_ref($x);
}
function cyclic_ref($num) {
$_SESSION['obj'.$num] = new stdClass();
$_SESSION['obj'.$num]->test = new stdClass();//NOTE: No bug if try commenting
out this too.
$_SESSION['obj'.$num]->obj1 = $_SESSION['obj1'];
}
Expected result:
----------------
When session successfully decoded no output.
Actual result:
--------------
#first run - success. Session written.
$ php sessiontest.php
#second run. Fail. Session cannot be decoded.
~$ php sessiontest.php
PHP Warning: session_start(): Failed to decode session object. Session has been destroyed in
/path/sessiontest.php on line 16
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=71972&edit=1