Bug #75047 [Opn]: session_regenerate_id fails with redis

From: Date: Tue, 05 Sep 2017 09:39:30 +0000
Subject: Bug #75047 [Opn]: session_regenerate_id fails with redis
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-210957@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75047&edit=1 ID: 75047 Updated by: yohgaki@php.net Reported by: bartosz at kibilko dot pl Summary: session_regenerate_id fails with redis Status: Open Type: Bug Package: Unknown/Other Function Operating System: Ubuntu / Docker Container PHP Version: 7.0.22 Block user comment: N Private report: N New Comment: BTW, this is caused due to session_regenerate_id() behavior change from PHP 7.0. PHP 5.6 and less - Old session data is not saved and creates new session without validating SID PHP 7.0 and up - Old session data is saved and creates new session with SID validation. From PHP 7.0, session save handlers are required not only to implement SID validation function, but also create session data either at "open" or "read" to make SID validation work. I might have missed this in UPGRADING. Previous Comments: ------------------------------------------------------------------------ [2017-09-05 08:40:26] yohgaki@php.net > The reason that this problem exists is because PHP doesn't create the key > in Redis if it doesn't exist. As a work-around, you need to create a key if > one doesn't exist in the read() function of your session handler class. > This removed the problem from my error logs: Thank you for useful info. I take a look at the code for session save handler "read" and "write" in phpredis. https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L342 https://github.com/phpredis/phpredis/blob/develop/redis_session.c#L402 Session "read" does not send write command to redis for empty get, so it seems this is phpredis session save handler bug. Save handlers are supposed to create session ID data entry either - open or - read When data is created is depends on underlying storage. For instance, "files" cannot create session data file with "read" since file is created when it is opened. On the other hand, storage like redis/postgresql/etc cannot create session data with "open", but "read". "open" is supposed to open connection to db. "open" may create session data entry, though. It seems this is phpredis issue, please close this bug if you get this fixed. If not, please let me know issue is in session. ------------------------------------------------------------------------ [2017-09-05 06:20:40] ray at rayxis dot com I'm also experiencing this in php 7.1.8. The reason that this problem exists is because PHP doesn't create the key in Redis if it doesn't exist. As a work-around, you need to create a key if one doesn't exist in the read() function of your session handler class. This removed the problem from my error logs: public function read ($key) { // Get the session data and extend the expiration. $nkey = $this->prefix . $key; read: $data = $this->sess->get($nkey); // If nothing exists, create it first because PHP has a bug. :( if (!$data) { $this->write($key,TRUE); goto read; } $this->sess->expire($key, getenv('SESSTTL')); // Return the result. return $data; } ------------------------------------------------------------------------ [2017-08-08 10:05:26] bartosz at kibilko dot pl Description: ------------ PHP 7.0.21 phpredis 3.1.2 redis 3.0.7 / 3.2.4 Magento 1.14.2.4 Context: There are some problems with session_regenerate_id function when redis is used as session adapter. Currently, I'm trying to login in Magento and session_id is stored in redis and in cookies but nothing happens - user is not logged in. When I remove the cookie, PHP throws this: Recoverable Error: session_regenerate_id(): Failed to create(read) session ID: redis (path: tcp://redis:6379/?database=2). It can be also related to phpredis, because version 3.1.3 has another bug :) - https://github.com/phpredis/phpredis/issues/1211 Expected result: ---------------- No errors, user logged in Actual result: -------------- Recoverable Error: session_regenerate_id(): Failed to create(read) session ID: redis (path: tcp://redis:6379/?database=2) in /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php on line 141 #0 [internal function]: mageCoreErrorHandler(4096, 'session_regener...', '/var/www/magent...', 141, Array) #1 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php(141): session_regenerate_id(false) #2 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract/Varien.php(222): Mage_Core_Model_Session_Abstract_Varien->start('frontend') #3 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session/Abstract.php(84): Mage_Core_Model_Session_Abstract_Varien->init('core', 'frontend') #4 /var/www/mage/magento/app/code/core/Mage/Core/Model/Session.php(42): Mage_Core_Model_Session_Abstract->init('core', 'frontend') #5 /var/www/mage/magento/app/code/core/Mage/Core/Model/Config.php(1354): Mage_Core_Model_Session->__construct(Array) #6 /var/www/mage/magento/app/Mage.php(471): Mage_Core_Model_Config->getModelInstance('core/session', Array) #7 ......... ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=75047&edit=1

« previous php.bugs (#210957) next »