Edit report at https://bugs.php.net/bug.php?id=69127&edit=1
ID: 69127
Updated by: kalle@php.net
Reported by: rbsimao at yahoo dot com dot br
Summary: session_regenerate_id(true) randomly generates a
warning and loses session data
-Status: Analyzed
+Status: Assigned
Type: Bug
Package: Session related
Operating System: Any
PHP Version: Any
Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2017-02-17 17:24:59] cmb@php.net
Related To: Bug #74118
------------------------------------------------------------------------
[2016-04-13 22:33:46] jolyon at nixbox dot com
My bad, apparently this is a known issue with a patch in the works for ZF1 - please disregard
previous two comments. https://github.com/zendframework/zf1/issues/659
------------------------------------------------------------------------
[2016-04-13 22:14:44] jolyon at nixbox dot com
I forgot to add our issue is PHP 7.0.x only, When we switch back to PHP 5.6.20,
session_regenerate_id works fine with our memcache backend. Also, turning off memcache backend
entirely resolves the issue. For now, we can just not use regenerateId, but would prefer to keep it
enabled for session security reasons.
------------------------------------------------------------------------
[2016-04-13 22:12:11] jolyon at nixbox dot com
Is this also related to alternate session handlers? session_regenerate_id is failing for us when we
add a custom save handler (memcache, in our case) and is returning the same error:
Recoverable Error(4096) session_regenerate_id(): Failed to create(read) session ID: user (path:
/var/lib/php/session) occurred at line 320 in /var/local/app/library/Zend/Session.php
We are using version 1.12.16 of Zend Framework. After troubleshooting their library code, I believe
this is a core PHP issue, not ZF.
I think this might be indirectly related, but if not I will create a new ticket with details.
------------------------------------------------------------------------
[2016-01-13 19:06:09] yohgaki@php.net
Session module code has race condition.
When session_regenerate_id(true) is called, session module close/unlock current session, then remove
it. If there is other access for the session, it waits until unlocked and accesses empty obsolete
data.
This situation can be avoided by RDBMS's serialized level transaction isolation, but file
system based storage cannot.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=69127
--
Edit this bug report at https://bugs.php.net/bug.php?id=69127&edit=1