Bug #75628 [Nab]: session_set_save_handler() prints warnings in a unit test

From: Date: Thu, 04 Oct 2018 07:46:01 +0000
Subject: Bug #75628 [Nab]: session_set_save_handler() prints warnings in a unit test
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-217400@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=75628&edit=1 ID: 75628 Updated by: yohgaki@php.net Reported by: damyon at moodle dot com Summary: session_set_save_handler() prints warnings in a unit test Status: Not a bug Type: Bug Package: Session related Operating System: Linux Mint 17.3 Rosa PHP Version: 7.2.0 Assigned To: yohgaki Block user comment: N Private report: N New Comment: The reasons why CLI command line mode respects HTTP headers/output: 1) Session manager has 2 modes "cookie" and "transid". Both of them cannot work once output is started. i.e. Cookie requires to write HTTP header for session id cookie. Transid requires to rewrite output to embed session id in it. Note: Older PHP was too tolerant for invalid usages. It allowed codes that can never work under web environment without errors. Even when it might seem to work, it didn't. PHP 7.2 session raises errors for codes that cannot work. i.e. Users can easily identify critical session management code bugs. 2) CLI has built-in web server mode. If CLI command mode behaves differently, it is very confusing. The same code work for one, but not for other. 3) CLI is used for testing. If CLI command line mode works differently, test code can be bogus that cannot work with web SAPIs including CLI's built-in web server. Technically, session module can ignore header/output. However, allowing session management code that cannot work under web environment has more harm than good. For those who have issues with stricter checks, please use ob_start(). Then your code works for all PHP versions since PHP 4. With PHPUnit, you may want to redirect errors to stderr. Previous Comments: ------------------------------------------------------------------------ [2018-10-02 10:42:46] yohgaki@php.net Checked session_set_save_handler() returns FALSE for invalid usage. i.e. Returning FALSE for code won't work correctly. There is not bug. Please read UPGRADING in PHP 7.2. ------------------------------------------------------------------------ [2018-10-02 10:35:01] yohgaki@php.net You cannot change anything for session, once you have started output. echo ".\n"; $success = session_set_save_handler(new MySessionHandler(), true); echo ($success ? 'set' : 'fail') . "\n"; echo should print 'fail', but it's not. This must be bug. I'll look into this. If you want to start output before session initialization, use ob_start() prevent PHP from start sending output. ------------------------------------------------------------------------ [2018-10-01 13:39:24] jeroen at asystance dot nl 7.1.22 are fine, and 7.3.0RC2 fails. ------------------------------------------------------------------------ [2018-09-28 15:31:18] jeroen at asystance dot nl 7.2.0alpha1 already has this regression. I'm trying to pinpoint the commit that causes this bug but it's a slow process. ------------------------------------------------------------------------ [2018-07-27 11:37:53] jeroen at asystance dot nl I've written a php test case (phpt) for this bug. It fails on a fresh build of 7.2.8 (./configure without any flags). --TEST-- Bug #75628 (session_set_save_handler() prints warnings in a unit test) --SKIPIF-- <?php if (!extension_loaded("session")) die("skip session extension not available"); ?> <?php unlink(__DIR__. '/sess_' .session_id()); ?> --INI-- session.use_cookies=0 session.cache_limiter='' --FILE-- <?php class MySessionHandler extends SessionHandler {} echo ".\n"; $success = session_set_save_handler(new MySessionHandler(), true); echo ($success ? 'set' : 'fail') . "\n"; --EXPECT-- . set This bug is clearly a regression in 7.2 and prevents users from running (PHPUnit) tests against code that sets session handlers. ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at https://bugs.php.net/bug.php?id=75628 -- Edit this bug report at https://bugs.php.net/bug.php?id=75628&edit=1

« previous php.bugs (#217400) next »