Bug #80291 [Opn]: Data loss in default session handler while on write operation

From: Date: Wed, 28 Oct 2020 09:49:10 +0000
Subject: Bug #80291 [Opn]: Data loss in default session handler while on write operation
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-229964@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80291&edit=1

 ID:                 80291
 User updated by:    jozyah-etienne at eerees dot com
 Reported by:        jozyah-etienne at eerees dot com
-Summary:            Data loss on session_write
+Summary:            Data loss in default session handler while on write
                     operation
 Status:             Open
 Type:               Bug
 Package:            Session related
 PHP Version:        Next Major Version
 Block user comment: N
 Private report:     N

 New Comment:

Fixed summary


Previous Comments:
------------------------------------------------------------------------
[2020-10-28 09:22:40] jozyah-etienne at eerees dot com

Description:
------------
PHP's default session handler (on all versions so far) do lock files which is good for
preventing race conditions, but it's write operation is not atomic. It directly writes data to
the destination file, which in case of failure (power outage, disk failure, crash, connection loss
to a networked storage, etc) session file will get corrupted.

The correct way to write session data to files is writing data to a temporary file (such as
/path/to/sessions/sess_id.tmp) and only on success, rename it to needed destination
(/path/to/sessions/sess_id). Then if rename was successful, the write operation was successful too,
otherwise the old data remains intact.

Also temporary file should be in the same destination directory, otherwise if temp file and
destination file are in separate devices or mount points, data loss may happen too.

In modern operating systems (POSIX OSes and NTFS on Windows 10 1607 and later, and maybe other
operating systems), rename is an atomic operation and should be used to minimize failures and
mitigate data loss.

Garbage collector can remove temporary files in case of failure, or those files can get updated in
next write operation. Also there is no need to acquire a lock on temporary files, because whole
session operation is already locked. 

More info in this Stack Overflow's thread:
https://stackoverflow.com/questions/64565698/are-php-session-writes-atomic

Expected result:
----------------
Session's write operation should be atomic.

Actual result:
--------------
Session's write operation is not atomic.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80291&edit=1


Thread (14 messages)

« previous php.bugs (#229964) next »