Bug #77178 [Asn->Dup]: Session id collision detection is broken

From: Date: Fri, 27 Mar 2020 12:48:48 +0000
Subject: Bug #77178 [Asn->Dup]: Session id collision detection is broken
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-226283@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=77178&edit=1

 ID:                 77178
 Updated by:         cmb@php.net
 Reported by:        riikka dot kalliomaki at gmail dot com
 Summary:            Session id collision detection is broken
-Status:             Assigned
+Status:             Duplicate
 Type:               Bug
 Package:            Session related
 PHP Version:        7.2.12
 Assigned To:        yohgaki
 Block user comment: N
 Private report:     N

 New Comment:

I'm closing this as duplicate of bug #79413, because the other
ticket already has a PR attached.


Previous Comments:
------------------------------------------------------------------------
[2020-03-26 17:55:08] hakhak57 at hotmail dot com

Related To: Bug #79413

------------------------------------------------------------------------
[2020-03-05 16:36:41] hakhak57 at hotmail dot com

Developing a library on mac in a form of middleware to facilitate secure use of session. This lib
should work from PHP 7.1 legacy reasons).

Problems appear when using built in session_create_id in class method function when session is
already running (to test collision). This always end up by crashing (Segfault 11) for PHP 7.1.33,
7.2.13, 7.3.12 like in Bug #78295 (https://bugs.php.net/bug.php?id=78295) and randomly crash or
memory leak alert when op_cache disabled. Refactored the code to prevent recursive calls but problem
still occurs. (december 2019).

Then these days, I've decided to dig into PHP source code for the session ext with my rusty
rudimentary C knowledge and as described in this Bug #77178
(https://bugs.php.net/bug.php?id=77178), i found that control collision is not against  SUCCESS
but against FAILURE resulting in rejection of collision free ids 3 times and emission of warning
"Failed to create new ID » in the next « if else » block. For me it just
crashes !!

Then i found related Bug #79091 (https://bugs.php.net/bug.php?id=79091) and test my code against
7.2.27 and 7.3.14 (where new_id = NULL was added) and no more crash but warning
 « session_create_id(): Failed to create new ID in… »

Just asking if this necessary fix (pointed by @yohgaki in his comment of [2018-11-21 12:15 UTC] in
this bug #77178) is going to roll out and be implemented in a minor update and also for PHP 7.1
branch (legacy reasons)? 

Thx for your work guys :)

------------------------------------------------------------------------
[2020-03-05 16:36:41] hakhak57 at hotmail dot com

Related To: Bug #77178

------------------------------------------------------------------------
[2020-02-11 18:50:24] derek at garudacrafts dot com

The fix to bug #79091 released on Jan 23, 2020 has exposed the issue described here in bug #77178
and is causing the generation of the erroneous php warnings ("Failed to create new ID"). 
Thus, all the latest versions of php 7.4.2/7.3.14/7.2.27 have been affected. Anyone using
session_create_id() will get these error messages going forward. Time to fix bug
#77178?

------------------------------------------------------------------------
[2020-02-11 18:50:24] derek at garudacrafts dot com

Related To: Bug #77178

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=77178


--
Edit this bug report at https://bugs.php.net/bug.php?id=77178&edit=1


Thread (1 message)

  • cmb@php.net
  • Unknown Message
    • cmb@php.net
« previous php.bugs (#226283) next »