Bug #77178 [Com]: Session id collision detection is broken
| From: | derek at garudacrafts dot com | Date: | Tue, 11 Feb 2020 17:29:00 +0000 |
| Subject: | Bug #77178 [Com]: Session id collision detection is broken | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-225503@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=77178&edit=1
ID: 77178
Comment by: derek at garudacrafts dot com
Reported by: riikka dot kalliomaki at gmail dot com
Summary: Session id collision detection is broken
Status: Assigned
Type: Bug
Package: Session related
PHP Version: 7.2.12
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
In regards to my previous comment, please be advised that I think the issue with calling
session_create_id() generating the erroneous PHP Warning "session_create_id():
Failed to create new ID in..." was introduced in the bug fix to #79091
(https://bugs.php.net/bug.php?id=79091). I have added a new comment there with details.
Previous Comments:
------------------------------------------------------------------------
[2020-02-11 15:39:20] derek at garudacrafts dot com
Since php 7.3, whenever I call session_create_id() I get the PHP Warning
"session_create_id(): Failed to create new ID in...".
However, a new session id IS created, which I can confirm by checking the directory where the
session files are saved. So my applications work fine, but my error logs fill up with this new
erroneous PHP Warning error message.
This does not happen in php 7.2. I have reproduced in both php 7.3 and 7.4, all other things being
equal.
Could the changes made to the session id collision detection as described in this bug report here
have anything to do with it?
------------------------------------------------------------------------
[2019-02-02 03:00:36] kalle@php.net
@yohgaki, given the no response from any RM, I think that since it changes the calling procedures
for session handlers, it should possibly only go into 7.4 if the way handler callbacks are called
changes for backwards compatibility to not introduce regressions for actively supported releases.
As you maintain the session module, then any part that you deep a security risk as apart of this
report should be fixed in a BC compliant manner for versions as low as 7.1.
I personally do not see a high threat here and therefore I'm gonna open the report from its
private state.
------------------------------------------------------------------------
[2018-12-10 09:36:26] yohgaki@php.net
RMs, how this should be proceeded? Fix this as normal bug or minor security fix?
------------------------------------------------------------------------
[2018-11-21 12:25:32] yohgaki@php.net
I don't mind fixing this as minor security fix. i.e. Fix this from PHP 5.6. This doesn't
require CVE, IMO. Any comments?
------------------------------------------------------------------------
[2018-11-21 12:18:47] yohgaki@php.net
I suppose this can be fixed as normal bug.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=77178
--
Edit this bug report at https://bugs.php.net/bug.php?id=77178&edit=1