Bug #78629 [NEW]: session_start() behaviour when cookie does NOT need to be set incorrect

From: Date: Thu, 03 Oct 2019 11:45:28 +0000
Subject: Bug #78629 [NEW]: session_start() behaviour when cookie does NOT need to be set incorrect
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-223021@lists.php.net to get a copy of this message
From:             james at gogo dot co dot nz
Operating system: Ubuntu 18.04
PHP version:      7.3.10
Package:          Session related
Bug Type:         Bug
Bug description:session_start() behaviour when cookie does NOT need to be set incorrect

Description:
------------
In PHP 7.2 (I believe) session_start() was modified with regard to it's
abilities after headers had been sent.

It was stated regarding the changes (https://externals.io/message/96387)
that "it changes behavior only when there is useless session which is
fatal anyway", this is not the case.

In versions, at least in up to 5.6, if the browser sent OR if before
output you explicitly and manually set the session_id() cookie then you
could successfully and normally (save for notice/warning)
session_start() after output and that $_SESSION would be perfectly
functional and indeed get written back quite normally.

I can not speak for others, but I routinely used this method
successfully through the last decade in order to delay session starting
as long as possible (if at all) to reduce lock contention.

session_start() prior 7.2 allowed one to set just the cookie themselves
prior output and start session successfully using that cookie after
output, 7.2 forward does not.


Test script:
---------------
<?php

 if(!isset($_COOKIE[session_name()]))
 {
   session_id(uniqid('session-'));
   setcookie(session_name(), session_id(), 0, '/');
 }

 header('Content-Type: text/plain');
 echo "PHP Version: " . phpversion() . "\n";
 echo str_repeat('              ', 1024); flush(); // ensure output is
flushed
 echo "Headers Sent Before session_start(): " . (headers_sent() ? 'Y':
'N') . "\n";

 @session_start();

 echo "Incrementing session variable (should increment each reload): " .
($_SESSION['testvar'] ? $_SESSION['testvar'] : 0) . "\n";
 $_SESSION['testvar'] += 1;

?>


Expected result:
----------------
The value for "Incrementing session variable" should increase on each
reload (PHP 5.6 below)

Actual result:
--------------
The value for "Incrementing session variable" remains 0 (PHP 7.2 above)

-- 
Edit bug report at https://bugs.php.net/bug.php?id=78629&edit=1
-- 
Fix committed:                    https://bugs.php.net/fix.php?id=78629&r=fixed
Fixed in release:                 https://bugs.php.net/fix.php?id=78629&r=alreadyfixed
Need backtrace:                   https://bugs.php.net/fix.php?id=78629&r=needtrace
Need Reproduce Script:            https://bugs.php.net/fix.php?id=78629&r=needscript
Try newer version:                https://bugs.php.net/fix.php?id=78629&r=oldversion
Not developer issue:              https://bugs.php.net/fix.php?id=78629&r=support
Expected behavior:                https://bugs.php.net/fix.php?id=78629&r=notwrong
Not enough info:                  https://bugs.php.net/fix.php?id=78629&r=notenoughinfo
Submitted twice:                  https://bugs.php.net/fix.php?id=78629&r=submittedtwice
register_globals:                 https://bugs.php.net/fix.php?id=78629&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=78629&r=phptooold
Daylight Savings:                 https://bugs.php.net/fix.php?id=78629&r=dst
IIS Stability:                    https://bugs.php.net/fix.php?id=78629&r=isapi
Install GNU Sed:                  https://bugs.php.net/fix.php?id=78629&r=gnused
Floating point limitations:       https://bugs.php.net/fix.php?id=78629&r=float
No Zend Extensions:               https://bugs.php.net/fix.php?id=78629&r=nozend
MySQL Configuration Error:        https://bugs.php.net/fix.php?id=78629&r=mysqlcfg


Thread (4 messages)

« previous php.bugs (#223021) next »