Bug #73394 [Opn->Fbk]: php_session_initialize doesn't verify s_read return value
Edit report at https://bugs.php.net/bug.php?id=73394&edit=1
ID: 73394
Updated by: cmb@php.net
Reported by: martijn at openbsd dot org
Summary: php_session_initialize doesn't verify s_read return
value
-Status: Open
+Status: Feedback
Type: Bug
Package: Session related
Operating System: irrelevant
PHP Version: 7.0.12
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
It seems to me that is fixex as of PHP 7.1.0, although in a
different way, or is there still something to improve?
Previous Comments:
------------------------------------------------------------------------
[2016-10-26 16:13:01] martijn at openbsd dot org
Description:
------------
When a read from the session backend fails it still initializes the session without data. This
causes problems during either the closing of the session or the php_session_decode (depending on the
serializer) with writing an empty session or destroying the session data respectively.
I choose E_ERROR to be in line with s_open and s_create_id function checks, but it can easily
changed into E_WARNING to be more in line with the original comment and would cause a return FALSE,
because PS(session_status) is not php_session_active.
I haven't looked into other versions, but I guess this applies to other versions as well.
Test script:
---------------
Originally found with https://github.com/php-memcached-dev/php-memcached/
as a session backend.
The script below can be tested by setting up memcached and doing a
"add memc.sess.lock.<session_id> 0 0 1" on a telnet session to memcached (make sure
that memcached.session_locking is set, which it is by default).
The request will first hang and at the end reset the session content in memcached.
<?php
ini_set('session.save_handler', 'memcached');
ini_set('session.save_path', "127.0.0.01:11211");
session_start();
var_dump($_SESSION, session_id());
$_SESSION["a"] = "b";
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=73394&edit=1
Thread (5 messages)