PHP 4.0 Bug #3793 Updated: session.gc_maxlifetime does not work

From: Date: Thu, 07 Dec 2000 15:51:32 +0000
Subject: PHP 4.0 Bug #3793 Updated: session.gc_maxlifetime does not work
Groups: php.dev 
Request: Send a blank email to php-dev+get-40389@lists.php.net to get a copy of this message
ID: 3793 Updated by: sniper Reported By: kori_mail@hotmail.com Status: Open Bug Type: *Session related Assigned To: Comments: User feedback: -------------- 1) "session.gc_maxlifetime" does not work - I set this to 60 sec, but I can read values from the session even this time was expired. (I start the session and then I wait more than 60 sec before I will call other script) 2) When I set "session.gc_probability = 100" in PHP.INI, ALL other session files are deleted (only one session can be used at the time - if are connected 2 clients to server, the second client owerwrites or deletes session of the first client, etc.). This bug is maybe related to "session.gc_maxlifetime" bug. --------------- I tried this myself on Linux -> Works as expected. But as I don't have any Windows to test this on, I just have to trust the user that this isn't working.. User tested with php4.0.4-dev-win32-20001123 Could someone using Windows try and check this out?? --Jani Previous Comments: --------------------------------------------------------------------------- [2000-11-27 08:59:00] sniper@php.net You have only misunderstood the meanings: session.gc_maxlifetime -> Max lifetime of data. After this time has elapsed data is considered being garbage. session.gc_probability -> Percentual propability for garbage cleaning to be executed. 100% probability happens always.. 1% happens less often. --Jani --------------------------------------------------------------------------- [2000-11-01 16:07:22] kori_mail@hotmail.com I tested PHP version php4.0.4-dev-win32-20001022 with my sample scripts and there is my results: Corrected bugs: 1) Session_Destroy() functions works fine. Session files are successfully deleted from Temp directory. 2) When "session.use_trans_sid = 1", SID is attached only to A HREF, FORMS, etc tags and is not attached to IMG tags. It's OK. Open bugs: 1) "session.gc_maxlifetime" does not work - I set this to 60 sec, but I can read values from the session even this time was expired. (I start the session and then I wait more than 60 sec before I will call other script) 2) When I set "session.gc_probability = 100" in PHP.INI, ALL other session files are deleted (only one session can be used at the time - if are connected 2 clients to server, the second client owerwrites or deletes session of the first client, etc.). This bug is maybe related to "session.gc_maxlifetime" bug. ------------------------ Tested OS: W2K server with SP1 Web server: Apache 3.1.12 PHP: php4.0.4-dev-win32-20001022 (CGI) Session settings in my PHP.INI --------------------------------------- [Session] session.save_handler = files ; handler used to store/retrieve data session.save_path = C:/WINNT/Temp ; argument passed to save_handler ; in the case of files, this is the ; path where data files are stored session.use_cookies = 0 ; whether to use cookies session.name = PHPSESSID ; name of the session ; is used as cookie name session.auto_start = 0 ; initialize session on request startup session.cookie_lifetime = 0 ; lifetime in seconds of cookie ; or if 0, until browser is restarted session.cookie_path = / ; the path the cookie is valid for session.cookie_domain = ; the domain the cookie is valid for session.serialize_handler = php ; handler used to serialize data ; php is the standard serializer of PHP session.gc_probability = 100 ; percentual probability that the ; 'garbage collection' process is started ; on every session initialization session.gc_maxlifetime = 60 ; after this number of seconds, stored ; data will be seen as 'garbage' and ; cleaned up by the gc process session.referer_check = ; check HTTP Referer to invalidate ; externally stored URLs containing ids session.entropy_length = 0 ; how many bytes to read from the file session.entropy_file = ; specified here to create the session id ; session.entropy_length = 16 ; session.entropy_file = /dev/urandom session.cache_limiter = nocache ; set to {nocache,private,public} to ; determine HTTP caching aspects session.cache_expire = 180 ; document expires after n minutes session.use_trans_sid = 0 ; use transient sid support if enabled ; by compiling with --enable-trans-sid url_rewriter.tags = "a=href,area=href,frame=src,input=src,form=fakeentry" ----------------------------- Sorry for my bad English :-) -- Kori --------------------------------------------------------------------------- [2000-11-01 05:33:44] dbeu@php.net can you please try a actual dev version, i.e. from www.php4win.de an report which problems are still persistent? --------------------------------------------------------------------------- [2000-10-12 20:48:13] kori_mail@hotmail.com I'm sorry I can't test the snapshots because I haven't MS VC++. I tested the latest release version 4.0.3 with my sample scripts and the same PHP.INI's setting I post with my previous comments. I'm sorry, there are still ALL errors I reported before. Calling Session_Destoy() function wrote: Warning: Session object destruction failed in c:wwwsessiondestroy.php on line 7 I found a new bug, maybe :-) When the "session.use_trans_sid = 1", SID is attached to all IMG tags in script also. For example <img src="image.gif" width="100" height="80" alt=""> is after execution of the script changed to <img src="image.gif?uid=e7ad41c1e3fc6d775886a520ee4a6e50" width="100" height="80" alt="">. OS: Windows 2000 server with SP1 PHP: 4.0.3 php4isapi.dll with IIS or PHP.EXE with Apache 3.1.12 PHP.INI-DIST included in 4.0.3 ZIP file with session settings: [Session] session.save_handler = files ; handler used to store/retrieve data session.save_path = C:/WINNT/Temp ; argument passed to save_handler ; in the case of files, this is the ; path where data files are stored session.use_cookies = 0 ; whether to use cookies session.name = PHPSESSID ; name of the session ; is used as cookie name session.auto_start = 0 ; initialize session on request startup session.cookie_lifetime = 0 ; lifetime in seconds of cookie ; or if 0, until browser is restarted session.cookie_path = / ; the path the cookie is valid for session.cookie_domain = ; the domain the cookie is valid for session.serialize_handler = php ; handler used to serialize data ; php is the standard serializer of PHP session.gc_probability = 1 (OR 100) ; percentual probability that the ; 'garbage collection' process is started ; on every session initialization session.gc_maxlifetime = 1440 ; after this number of seconds, stored ; data will be seen as 'garbage' and ; cleaned up by the gc process session.referer_check = ; check HTTP Referer to invalidate ; externally stored URLs containing ids session.entropy_length = 0 ; how many bytes to read from the file session.entropy_file = ; specified here to create the session id ; session.entropy_length = 16 ; session.entropy_file = /dev/urandom session.cache_limiter = nocache ; set to {nocache,private,public} to ; determine HTTP caching aspects session.cache_expire = 180 ; document expires after n minutes session.use_trans_sid = 0 ; use transient sid support if enabled ; by compiling with --enable-trans-sid ---------------------------- Please, try my sample scripts I post with my previous comments... --Kori --------------------------------------------------------------------------- [2000-09-18 06:35:07] sniper@php.net Please try php4.0.2 or preferrably latest CVS or snapshot. --Jani --------------------------------------------------------------------------- The remainder of the comments for this report are too long. To view the rest of the comments, please view the bug report online. Full Bug description available at: http://bugs.php.net/?id=3793

« previous php.dev (#40389) next »