Bug #74615 [NEW]: Unexpected session ID change on overridden SessionHandler::read() method

From: Date: Thu, 18 May 2017 15:41:45 +0000
Subject: Bug #74615 [NEW]: Unexpected session ID change on overridden SessionHandler::read() method
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-209187@lists.php.net to get a copy of this message
From: mikebranttx at gmail dot com Operating system: Mac OSX 10.10.5 PHP version: 5.6.30 Package: Session related Bug Type: Bug Bug description:Unexpected session ID change on overridden SessionHandler::read() method Description: ------------ Environment: PHP 5.6.30_6 CLI as installed via Homebrew on Mac. (Also reproduced in Travis CI Debian build environment with PHP 5.6.5 CLI). xdebug 2.5.4 PHPUnit 5.7.0 (being used to run test in which error is reproduced Loaded extensions: bcmath, bz2, calendar, Core, ctype, curl, date, dba, dom, ereg, exif, fileinfo, filter, ftp, gd, gettext, hash, iconv, json, ldap, libxml, mbstring, mhash, mysql, mysqli, mysqlnd, odbc, openssl, pcntl, pcre, PDO, pdo_mysql, PDO_ODBC, pdo_sqlite, Phar, posix, readline, Reflection, session, shmop, SimpleXML, soap, sockets, SPL, sqlite3, standard, sysvmsg, sysvsem, sysvshm, tokenizer, wddx, xdebug, xml, xmlreader, xmlrpc, xmlwriter, xsl, zip, zlib Code in which issue was surfaced is available to be installed as composer package at - https://packagist.org/packages/mikecbrant/php-ultimate-sessions with source in GitHub at https://github.com/mikecbrant/php-ultimate-sessions Issue: When working with a class extending SessionHandler (UltimateSessionHandler in referenced package), There is unexpected change of session Id within overridden read() method between the session ID passed as argument to the method that takes place after parent::read() is called. This happens on line 53 of UltimateSessionHandler where parent::read() is called and can be reproduced by either evaluating session_id() in debug session immediately after this call or calling session_id(). This issue has only been reproduced against PHP 5.6.30 when running unit (integration) tests. This library is tested against PHP 7.0, 7.1, and 7.2 (nightly) in CI environment and this problem is not surfaced in any of these environments. This may possibly be related to closed bug: https://bugs.php.net/bug.php?id=70133&edit=2 But in my case, I am not trying to provide custom session ID, but rather use session ID's generated by PHP. Test script: --------------- Pertinent part of unit test script (tests/UltimateSessionLibraryIntegrationTest.php): Starting at line 121: 121 $handler = new UltimateSessionHandler($handlerConfig); ... 132 $manager = new UltimateSessionManager($managerConfig, $changeIdCallback); ... 138 $this->assertEquals('', session_id()); 139 $manager->startSession(); Note the above unit test is run in an isolated process form main test execution. startSession() above triggers session_start() at src/UltimateSessions/UltimateSessionsManager.php line 148, where first line of startSession method is as follows: 148 $result = session_start(); The session_start() process then triggers UltimateSessionHandler::read() (src/UltimateSessions/UltimateSessionHandler.php) an overridden method for \SessionHandler::read(). The code for this method is: 50 public function read($sessionId) 51 { 52 $this->validateSessionId($sessionId); 53 $sessionData = parent::read($sessionId); 54 if($this->config->useEncryption) { 55 return $this->decrypt($sessionId, $sessionData); 56 } 57 return $sessionData; 58 } It is after line 53 executes call to parent::read() that evaluation of session_id() changes from value passed in method argument to a new session ID value. Expected result: ---------------- During session_start(), session ID passed to overridden read() method in class extending SessionHandler would be expected to be the same as session ID returned from session_id() call after session_start() has completed when parent::read() is called from method. Code works as expected in PHP 7.0.x, 7.1.x and nightly builds as shown from most recent build - https://travis-ci.org/mikecbrant/php-ultimate-sessions/builds/233290834 Note: you can see failed tests under PHP 5.6.5 build that relate to this issue. Actual result: -------------- Immediately after call to parent::read() in overriding method, session ID value as returned from session_id() differs from the value passed as argument to the read() method. -- Edit bug report at https://bugs.php.net/bug.php?id=74615&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=74615&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=74615&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=74615&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=74615&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=74615&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=74615&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=74615&r=needscript Try newer version: https://bugs.php.net/fix.php?id=74615&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=74615&r=support Expected behavior: https://bugs.php.net/fix.php?id=74615&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=74615&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=74615&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=74615&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=74615&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=74615&r=dst IIS Stability: https://bugs.php.net/fix.php?id=74615&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=74615&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=74615&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=74615&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=74615&r=mysqlcfg

« previous php.bugs (#209187) next »