Req #46451 [Ana]: Session module needs a hook into the evaluator

From: Date: Mon, 16 Nov 2020 16:24:39 +0000
Subject: Req #46451 [Ana]: Session module needs a hook into the evaluator
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-230390@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=46451&edit=1

 ID:                 46451
 Updated by:         cmb@php.net
 Reported by:        jost_boekemeier at yahoo dot de
 Summary:            Session module needs a hook into the evaluator
 Status:             Analyzed
 Type:               Feature/Change Request
-Package:            Scripting Engine problem
+Package:            Session related
 Operating System:   *
 PHP Version:        *
 Block user comment: N
 Private report:     N

 New Comment:

> __destruct() should be the last magic method to be called at
> shutdown. Is there any good reason for this behavior?

The early calling of all destructors during request shutdown[1] has
been introduced to fix bug #30578.  It seems to me that the session
module should call php_session_save_current_state() earlier than in
its request shutdown handler.

[1] <https://github.com/php/php-src/blob/php-7.3.24/main/main.c#L1873>


Previous Comments:
------------------------------------------------------------------------
[2013-06-27 11:00:43] yohgaki@php.net

Verified with PHP 5.4/5.5.

This is not a session problem, but a scripting engine.

__destruct() should be the last magic method to be called at shutdown. Is there 
any good reason for this behavior?

------------------------------------------------------------------------
[2008-11-01 14:19:04] jost_boekemeier at yahoo dot de

Description:
------------
If a PHP object is stored into the PHP session, __destruct() is called before __sleep().

One way to fix this bug is to change the evaluator to call session_write_close() before calling
__destruct().





Reproduce code:
---------------
<?php
/**
  * Check if __destruct() is called after __sleep()
  * exit with 1 if the test failed.
  */
class C {
  var $destroyed = false;
  function __destruct() {
    echo "destroy called\n";
    $this->destroyed = true;
  }
  function __sleep() {
    if ($this->destroyed) {echo("sleep failed. bleh!\n"); exit(1); }
    return array();
  }
  function __wakeup() {
    $this->destroyed = false;
  }
  function __toString() {
    return "C::".($this->destroyed?"destroyed":"active");
  }
}
session_id("session-write-close-bug");
session_start();
$a=@$_SESSION['a'];
if(!$a) {
  echo "new C\n";
  $a=new C();
  $_SESSION['a']=$a;
 }
$a=$_SESSION['a'];
echo "$a\n";
//session_write_close();
exit (0);
?>


Expected result:
----------------
result code 0

Actual result:
--------------
result code 1


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=46451&edit=1


Thread (3 messages)

« previous php.bugs (#230390) next »