Re: com php-src: Fixed bug #69111 (Crash in SessionHandler::read()). Made session save handler abuse much harder than before.: NEWS
ext/session/mod_user.c ext/session/mod_user_class.c ext/session/session.c ext/session/tests/bug55688.phpt ext/session/tests/bug60634.phpt
ext/session/tests/bug60634_error_1.phpt ext/session/tests/bug60634_error_5.phpt ext/session/tests/bug67972.phpt ext/session/tests/bug69111.phpt
ext/session/tests/sessionhandler_open_00
| From: | Yasuo Ohgaki | Date: | Fri, 15 Jan 2016 08:46:32 +0000 |
| Subject: | Re: com php-src: Fixed bug #69111 (Crash in SessionHandler::read()). Made session save handler abuse much harder than before.: NEWS ext/session/mod_user.c ext/session/mod_user_class.c ext/session/session.c ext/session/tests/bug55688.phpt ext/session/tests/bug60634.phpt ext/session/tests/bug60634_error_1.phpt ext/session/tests/bug60634_error_5.phpt ext/session/tests/bug67972.phpt ext/session/tests/bug69111.phpt ext/session/tests/sessionhandler_open_00 |
||
| References: | 1 2 | Groups: | php.cvs |
| Request: | Send a blank email to php-cvs+get-90657@lists.php.net to get a copy of this message | ||
Hi Stas,
On Fri, Jan 15, 2016 at 4:39 PM, Stanislav Malyshev <smalyshev@gmail.com> wrote:
>> Commit: bfb9307b2d679a91e138fd876880470ece60942b
>> Author: Yasuo Ohgaki <yohgaki@php.net> Fri, 15 Jan 2016 13:47:45 +0900
>> Parents: d7f8d9e3a9babf0e4f0c1a5590e1feb5e69bd84a
>> Branches: PHP-5.6 PHP-7.0 master
>>
>> Link:
>> http://git.php.net/?p=php-src.git;a=commitdiff;h=bfb9307b2d679a91e138fd876880470ece60942b
>>
>> Log:
>> Fixed bug #69111 (Crash in SessionHandler::read()).
>> Made session save handler abuse much harder than before.
>
> Could you explain a bit more about this part:
>
> +/*
> +FIXME: Since session module try to write/close session data in
> +RSHUTDOWN, write() is executed twices. This is caused by undefined
> +function error and zend_bailout(). Current session module codes
> +depends on this behavior. These codes should be modified to remove
> +multiple write().
> +*/
> +
> ?>
> --EXPECTF--
> write: goodbye cruel world
> +write: goodbye cruel world
> close: goodbye cruel world
>
> Looks like it is a new behavior? This does not look like a good thing,
> doing the session write twice.
This patch makes use of PS(session_status) to disable save handler
abuse. i.e. Broken save handler usages that crash PHP.
Since current session module's codes assume "session is written
and closed always at the end of script execution", new code try to
write() twice because "undefined function error" happens in write().
Because of the assumption, it requires a lot of work to remove 2nd
write(). I agree it does not look good, but it does not affect normal
execution at all. Important thing is to prevent crash.
I may be able to fix this in PHP 7.0 w/o BC.
I'll try it later.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net