Bug #75047 [Opn]: session_regenerate_id fails with redis
| From: | yohgaki@php.net | Date: | Tue, 05 Sep 2017 09:39:30 +0000 |
| Subject: | Bug #75047 [Opn]: session_regenerate_id fails with redis | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-210957@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=75047&edit=1
ID: 75047
Updated by: yohgaki@php.net
Reported by: bartosz at kibilko dot pl
Summary: session_regenerate_id fails with redis
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Ubuntu / Docker Container
PHP Version: 7.0.22
Block user comment: N
Private report: N
New Comment:
BTW, this is caused due to session_regenerate_id() behavior change from PHP 7.0.
PHP 5.6 and less
- Old session data is not saved and creates new session without validating SID
PHP 7.0 and up
- Old session data is saved and creates new session with SID validation.
From PHP 7.0, session save handlers are required not only to implement SID validation function, but
also create session data either at "open" or "read" to make SID validation work.
I might have missed this in UPGRADING.
Previous Comments:
------------------------------------------------------------------------
[2017-09-05 08:40:26] yohgaki@php.net
> The reason that this problem exists is because PHP doesn't create the key
> in Redis if it doesn't exist. As a work-around, you need to create a key if
> one doesn't exist in the read() function of your session handler class.
> This removed the problem from my error logs:
Thank you for useful info.
I take a look at the code for session save handler "read" and "write" in
phpredis.
https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L342
https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L402
Session "read" does not send write command to redis for empty get, so it seems this is
phpredis session save handler bug.
Save handlers are supposed to create session ID data entry either
- open
or
- read
When data is created is depends on underlying storage. For instance, "files" cannot create
session data file with "read" since file is created when it is opened.
On the other hand, storage like redis/postgresql/etc cannot create session data with
"open", but "read". "open" is supposed to open connection to db.
"open" may create session data entry, though.
It seems this is phpredis issue, please close this bug if you get this fixed. If not, please let me
know issue is in session.
------------------------------------------------------------------------
[2017-09-05 06:20:40] ray at rayxis dot com
I'm also experiencing this in php 7.1.8.
The reason that this problem exists is because PHP doesn't create the key in Redis if it
doesn't exist. As a work-around, you need to create a key if one doesn't exist in the
read() function of your session handler class. This removed the problem from my error logs:
public function read ($key)
{
// Get the session data and extend the expiration.
$nkey = $this->prefix . $key;
read:
$data = $this->sess->get($nkey);
// If nothing exists, create it first because PHP has a bug. :(
if (!$data)
{
$this->write($key,TRUE);
goto read;
}
$this->sess->expire($key, getenv('SESSTTL'));
// Return the result.
return $data;
}
------------------------------------------------------------------------
[2017-08-08 10:05:26] bartosz at kibilko dot pl
Description:
------------
PHP 7.0.21
phpredis 3.1.2
redis 3.0.7 / 3.2.4
Magento 1.14.2.4
Context:
There are some problems with session_regenerate_id function when redis is used as session adapter.
Currently, I'm trying to login in Magento and session_id is stored in redis and in cookies but
nothing happens - user is not logged in. When I remove the cookie, PHP throws this:
Recoverable Error: session_regenerate_id(): Failed to create(read) session ID: redis (path:
tcp://redis:6379/?database=2).
It can be also related to phpredis, because version 3.1.3 has another bug :) - https://github.com/phpredis/phpredis/issues/1211
Expected result:
----------------
No errors, user logged in
Actual result:
--------------
Recoverable Error: session_regenerate_id(): Failed to create(read) session ID: redis (path:
tcp://redis:6379/?database=2) in
/var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php on line 141
#0 [internal function]: mageCoreErrorHandler(4096, 'session_regener...',
'/var/www/magent...', 141, Array)
#1 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php(141):
session_regenerate_id(false)
#2 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php(222):
Mage_Core_Model_Session_Abstract_Varien->start('frontend')
#3 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract.php(84):
Mage_Core_Model_Session_Abstract_Varien->init('core', 'frontend')
#4 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session.php(42):
Mage_Core_Model_Session_Abstract->init('core', 'frontend')
#5 /var/www/mage/magento/app/code/core/Mage/Core/Model/Config.php(1354):
Mage_Core_Model_Session->__construct(Array)
#6 /var/www/mage/magento/app/Mage.php(471):
Mage_Core_Model_Config->getModelInstance('core/session', Array)
#7 .........
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=75047&edit=1