Bug #80291 [NEW]: Data loss on session_write

From: Date: Wed, 28 Oct 2020 09:22:40 +0000
Subject: Bug #80291 [NEW]: Data loss on session_write
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229962@lists.php.net to get a copy of this message
From: jozyah-etienne at eerees dot com Operating system: PHP version: Next Major Version Package: Session related Bug Type: Bug Bug description:Data loss on session_write Description: ------------ PHP's default session handler (on all versions so far) do lock files which is good for preventing race conditions, but it's write operation is not atomic. It directly writes data to the destination file, which in case of failure (power outage, disk failure, crash, connection loss to a networked storage, etc) session file will get corrupted. The correct way to write session data to files is writing data to a temporary file (such as /path/to/sessions/sess_id.tmp) and only on success, rename it to needed destination (/path/to/sessions/sess_id). Then if rename was successful, the write operation was successful too, otherwise the old data remains intact. Also temporary file should be in the same destination directory, otherwise if temp file and destination file are in separate devices or mount points, data loss may happen too. In modern operating systems (POSIX OSes and NTFS on Windows 10 1607 and later, and maybe other operating systems), rename is an atomic operation and should be used to minimize failures and mitigate data loss. Garbage collector can remove temporary files in case of failure, or those files can get updated in next write operation. Also there is no need to acquire a lock on temporary files, because whole session operation is already locked. More info in this Stack Overflow's thread: https://stackoverflow.com/questions/64565698/are-php-session-writes-atomic Expected result: ---------------- Session's write operation should be atomic. Actual result: -------------- Session's write operation is not atomic. -- Edit bug report at https://bugs.php.net/bug.php?id=80291&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=80291&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=80291&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=80291&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=80291&r=needscript Try newer version: https://bugs.php.net/fix.php?id=80291&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=80291&r=support Expected behavior: https://bugs.php.net/fix.php?id=80291&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=80291&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=80291&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=80291&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=80291&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=80291&r=dst IIS Stability: https://bugs.php.net/fix.php?id=80291&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=80291&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=80291&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=80291&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=80291&r=mysqlcfg

« previous php.bugs (#229962) next »