#20720 [NoF->Csd]: ps_files_cleanup_dir

From: Date: Sat, 25 Mar 2006 12:10:40 +0000
Subject: #20720 [NoF->Csd]: ps_files_cleanup_dir
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-94870@lists.php.net to get a copy of this message
ID: 20720 Updated by: aidan@php.net Reported By: thomas at mitom dot com -Status: No Feedback +Status: Closed Bug Type: Session related Operating System: Windows 2000 Server PHP Version: 4.2.3 New Comment: To reiterate, This is a(nother) Debian packaging problem. The bug report is here: http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=256831 The fix this, session.gc_probability = 1 session.gc_divisor = 100000000 (Note: once in a billion hits, someone will get an error message) Then, set up your own garbage collection. This is discussed already in php.ini. Previous Comments: ------------------------------------------------------------------------ [2004-07-20 23:27:59] mike at psy dot otago dot ac dot nz It turns out to be a distro problem: A debian person explained it to me: Re: Bug#256831: session-dir permission problem I'm sorry to hear that. The cause of this bug is already known: for security reasons, session files are now stored in a directory that is only readable by root, which means that PHP scripts running in either the webserver security context (user www-data) or as a per-user CGI will be unable to get a list of session files in the directory. This is by design, and will not be changed; what will be changed is to disable PHP's internal session gc and replace it with a cronjob running as root that can sweep the directory on our behalf. ------------------------------------------------------------------------ [2004-07-20 06:44:38] mike at psy dot otago dot ac dot nz I had the same problem with apache 1.3.29 and php 4.3.4 and also with apache 1.3.31 and php 4.3.8 on debian testing / unstable. The PHP notice was Notice: session_start(): ps_files_cleanup_dir: opendir(/var/lib/php4) failed: Permission denied (13) in ... It only occurred every so often. I think I have discovered the cause. In order to reproduce this consistently; update these parts of your php.ini file to: session.gc_probability = 1 ;session.gc_divisor = 100 session.gc_divisor = 1 and restart apache of course. Changing the probability of the garbage collection routines to 100% cause this to happen every time session_start() is called. I'm guessing that the session file is locked by session_start() and that the garbage collection routine ps_files_cleanup_dir? is failing? As this doesn't seem to affect the sessions a solution would be to prepend an @ to session_start() to suppress notices/errors/etc or to do you own garbage collection as suggested in the php.ini file. I hope this helps someone as I spent a good 6 hours hunting it down :-). Mike Miller. ------------------------------------------------------------------------ [2004-06-09 14:10:15] david at grant dot org dot uk False call on the above comment. It's still happening. ------------------------------------------------------------------------ [2004-06-09 13:56:45] david at grant dot org dot uk I also experienced this issue running PHP 4.3.4 on Debian. I resolved it by removing the sticky bit on the sessions directory (`chmod a-t /var/lib/php4`), although obviously this has security implications. ------------------------------------------------------------------------ [2002-12-15 01:00:04] php-bugs at lists dot php dot net No feedback was provided for this bug for over 2 weeks, so it is being suspended automatically. If you are able to provide the information that was originally requested, please do so and change the status of the bug back to "Open". ------------------------------------------------------------------------ The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online at http://bugs.php.net/20720 -- Edit this bug report at http://bugs.php.net/?id=20720&edit=1

« previous php.bugs (#94870) next »