Bug #78155 [Opn]: session_start doesn't create session
Edit report at https://bugs.php.net/bug.php?id=78155&edit=1
ID: 78155
Updated by: cmb@php.net
Reported by: liangjian at oliveche dot com
Summary: session_start doesn't create session
Status: Open
Type: Bug
Package: Session related
Operating System: CentOS 7
PHP Version: 7.2.19
Block user comment: N
Private report: N
New Comment:
What happens: request A creates the session file, and locks it,
and then sleeps. Now request B opens the file, but waits for it
to be unlocked. When request A ends sleeping, it destroys the
file, so request B gets access, but the file is already unlinked,
so whatever is written to the file is effectively lost.
It seems to me that cannot be cleanly solved without having a
separate lock file. Maybe document this issue instead?
Previous Comments:
------------------------------------------------------------------------
[2019-06-13 08:09:57] liangjian at oliveche dot com
Description:
------------
---
From manual page: https://php.net/function.session-start
---
Request A and B are sent from the same browser at the same time (A prior to B) and use the same
cookie.
A destroys session and B writes session in sequence.
B is blocked on 'session_start' and resumes after A destroys the session, but it does not
create session or save the session variables.
Test script:
---------------
request A:
session_start();
sleep(5);
session_destroy();
request B:
// B will be blocked by A on the session file
session_start(); // !!!return ok but not session file!!!
// resume until A destroys(releases) it. but no session file and the 'uid' cannot
save.
$_SESSION["uid"] = 1;
Expected result:
----------------
The session file exists and session variable 'uid' is saved.
Actual result:
--------------
No session file.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=78155&edit=1
Thread (2 messages)