Bug #80291 [NEW]: Data loss on session_write
| From: | jozyah-etienne at eerees dot com | Date: | Wed, 28 Oct 2020 09:22:40 +0000 |
| Subject: | Bug #80291 [NEW]: Data loss on session_write | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-229962@lists.php.net to get a copy of this message | ||
From: jozyah-etienne at eerees dot com
Operating system:
PHP version: Next Major Version
Package: Session related
Bug Type: Bug
Bug description:Data loss on session_write
Description:
------------
PHP's default session handler (on all versions so far) do lock files
which is good for preventing race conditions, but it's write operation
is not atomic. It directly writes data to the destination file, which in
case of failure (power outage, disk failure, crash, connection loss to a
networked storage, etc) session file will get corrupted.
The correct way to write session data to files is writing data to a
temporary file (such as /path/to/sessions/sess_id.tmp) and only on
success, rename it to needed destination (/path/to/sessions/sess_id).
Then if rename was successful, the write operation was successful too,
otherwise the old data remains intact.
Also temporary file should be in the same destination directory,
otherwise if temp file and destination file are in separate devices or
mount points, data loss may happen too.
In modern operating systems (POSIX OSes and NTFS on Windows 10 1607 and
later, and maybe other operating systems), rename is an atomic operation
and should be used to minimize failures and mitigate data loss.
Garbage collector can remove temporary files in case of failure, or
those files can get updated in next write operation. Also there is no
need to acquire a lock on temporary files, because whole session
operation is already locked.
More info in this Stack Overflow's thread:
https://stackoverflow.com/questions/64565698/are-php-session-writes-atomic
Expected result:
----------------
Session's write operation should be atomic.
Actual result:
--------------
Session's write operation is not atomic.
--
Edit bug report at https://bugs.php.net/bug.php?id=80291&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80291&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80291&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80291&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80291&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80291&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80291&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80291&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80291&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80291&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80291&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80291&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80291&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80291&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80291&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80291&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80291&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80291&r=mysqlcfg