PHP 4.0 Bug #3793 Updated: session.gc_maxlifetime does not work
| From: | jmoore@php.net | Date: | Sun, 10 Dec 2000 01:20:37 +0000 |
| Subject: | PHP 4.0 Bug #3793 Updated: session.gc_maxlifetime does not work | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-40716@lists.php.net to get a copy of this message | ||
ID: 3793
Updated by: jmoore
Reported By: kori_mail@hotmail.com
Old-Status: Open
Status: Analyzed
Bug Type: *Session related
Assigned To:
Comments:
Verified on WIn 2k IIS 5, ISAPI dll.
Jani & I checked this was the case on my system too. we think it appears to be releated to atime
and ulink (We think..)
James
Previous Comments:
---------------------------------------------------------------------------
[2000-12-07 10:51:28] sniper@php.net
User feedback:
--------------
1) "session.gc_maxlifetime" does not work - I set this to 60 sec, but I can read values
from the session even this time was expired. (I start the session and then I wait
more than 60 sec before I will call other script)
2) When I set "session.gc_probability = 100" in PHP.INI, ALL other session files are
deleted (only one session can be used at the time - if are connected 2 clients to
server, the second client owerwrites or deletes session of the first client, etc.).
This bug is maybe related to "session.gc_maxlifetime" bug.
---------------
I tried this myself on Linux -> Works as expected.
But as I don't have any Windows to test this on,
I just have to trust the user that this isn't working..
User tested with php4.0.4-dev-win32-20001123
Could someone using Windows try and check this out??
--Jani
---------------------------------------------------------------------------
[2000-11-27 08:59:00] sniper@php.net
You have only misunderstood the meanings:
session.gc_maxlifetime -> Max lifetime of data. After
this time has elapsed data is considered being garbage.
session.gc_probability -> Percentual propability for
garbage cleaning to be executed.
100% probability happens always.. 1% happens less often.
--Jani
---------------------------------------------------------------------------
[2000-11-01 16:07:22] kori_mail@hotmail.com
I tested PHP version php4.0.4-dev-win32-20001022 with my sample scripts and there is my results:
Corrected bugs:
1) Session_Destroy() functions works fine. Session files are successfully deleted from Temp
directory.
2) When "session.use_trans_sid = 1", SID is attached only to A HREF, FORMS, etc tags and
is not attached to IMG tags. It's OK.
Open bugs:
1) "session.gc_maxlifetime" does not work - I set this to 60 sec, but I can read values
from the session even this time was expired. (I start the session and then I wait more than 60 sec
before I will call other script)
2) When I set "session.gc_probability = 100" in PHP.INI, ALL other session files are
deleted (only one session can be used at the time - if are connected 2 clients to server, the second
client owerwrites or deletes session of the first client, etc.).
This bug is maybe related to "session.gc_maxlifetime" bug.
------------------------
Tested OS: W2K server with SP1
Web server: Apache 3.1.12
PHP: php4.0.4-dev-win32-20001022 (CGI)
Session settings in my PHP.INI
---------------------------------------
[Session]
session.save_handler = files ; handler used to store/retrieve data
session.save_path = C:/WINNT/Temp ; argument passed to save_handler
; in the case of files, this is the
; path where data files are stored
session.use_cookies = 0 ; whether to use cookies
session.name = PHPSESSID
; name of the session
; is used as cookie name
session.auto_start = 0 ; initialize session on request startup
session.cookie_lifetime = 0 ; lifetime in seconds of cookie
; or if 0, until browser is restarted
session.cookie_path = / ; the path the cookie is valid for
session.cookie_domain = ; the domain the cookie is valid for
session.serialize_handler = php ; handler used to serialize data
; php is the standard serializer of PHP
session.gc_probability = 100 ; percentual probability that the
; 'garbage collection' process is started
; on every session initialization
session.gc_maxlifetime = 60 ; after this number of seconds, stored
; data will be seen as 'garbage' and
; cleaned up by the gc process
session.referer_check = ; check HTTP Referer to invalidate
; externally stored URLs containing ids
session.entropy_length = 0 ; how many bytes to read from the file
session.entropy_file = ; specified here to create the session id
; session.entropy_length = 16
; session.entropy_file = /dev/urandom
session.cache_limiter = nocache ; set to {nocache,private,public} to
; determine HTTP caching aspects
session.cache_expire = 180 ; document expires after n minutes
session.use_trans_sid = 0 ; use transient sid support if enabled
; by compiling with --enable-trans-sid
url_rewriter.tags = "a=href,area=href,frame=src,input=src,form=fakeentry"
-----------------------------
Sorry for my bad English :-)
-- Kori
---------------------------------------------------------------------------
[2000-11-01 05:33:44] dbeu@php.net
can you please try a actual dev version, i.e. from www.php4win.de an report which problems are still
persistent?
---------------------------------------------------------------------------
[2000-10-12 20:48:13] kori_mail@hotmail.com
I'm sorry I can't test the snapshots because I haven't MS VC++.
I tested the latest release version 4.0.3 with my sample scripts and the same PHP.INI's setting
I post with my previous comments.
I'm sorry, there are still ALL errors I reported before.
Calling Session_Destoy() function wrote: Warning: Session object destruction failed in
c:wwwsessiondestroy.php on line 7
I found a new bug, maybe :-) When the "session.use_trans_sid = 1", SID is attached to all
IMG tags in script also.
For example <img src="image.gif" width="100" height="80"
alt=""> is after execution of the script changed to <img
src="image.gif?uid=e7ad41c1e3fc6d775886a520ee4a6e50" width="100"
height="80" alt="">.
OS: Windows 2000 server with SP1
PHP: 4.0.3 php4isapi.dll with IIS or PHP.EXE with Apache 3.1.12
PHP.INI-DIST included in 4.0.3 ZIP file with session settings:
[Session]
session.save_handler = files ; handler used to store/retrieve data
session.save_path = C:/WINNT/Temp ; argument passed to save_handler
; in the case of files, this is the
; path where data files are stored
session.use_cookies = 0 ; whether to use cookies
session.name = PHPSESSID
; name of the session
; is used as cookie name
session.auto_start = 0 ; initialize session on request startup
session.cookie_lifetime = 0 ; lifetime in seconds of cookie
; or if 0, until browser is restarted
session.cookie_path = / ; the path the cookie is valid for
session.cookie_domain = ; the domain the cookie is valid for
session.serialize_handler = php ; handler used to serialize data
; php is the standard serializer of PHP
session.gc_probability = 1 (OR 100) ; percentual probability that the
; 'garbage collection' process is started
; on every session initialization
session.gc_maxlifetime = 1440 ; after this number of seconds, stored
; data will be seen as 'garbage' and
; cleaned up by the gc process
session.referer_check = ; check HTTP Referer to invalidate
; externally stored URLs containing ids
session.entropy_length = 0 ; how many bytes to read from the file
session.entropy_file = ; specified here to create the session id
; session.entropy_length = 16
; session.entropy_file = /dev/urandom
session.cache_limiter = nocache ; set to {nocache,private,public} to
; determine HTTP caching aspects
session.cache_expire = 180 ; document expires after n minutes
session.use_trans_sid = 0 ; use transient sid support if enabled
; by compiling with --enable-trans-sid
----------------------------
Please, try my sample scripts I post with my previous comments...
--Kori
---------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view the rest of the comments,
please view the bug report online.
Full Bug description available at: http://bugs.php.net/?id=3793